Version 1Effective from 12 July 2026Български

PartsMarkt Privacy Policy

DRAFT — pending review by a Bulgarian-qualified lawyer. Not final legal text.

This Privacy Policy explains what personal data the PartsMarkt platform (partsmarkt.com) collects, why it collects it, who it is shared with, and what rights you have. PartsMarkt is an online platform (marketplace) for used auto parts on which sellers (traders — vehicle dismantlers and salvage yards) offer parts to buyers. We have tried to write in plain language. If anything is unclear, write to us at support@partsmarkt.com.

1. Who is responsible for your data (controller)

1.1. The controller of the personal data processed through the platform is [OPERATOR: company/name of the legal entity, EIK (company registration number), VAT number, registered seat and management address — to be completed] (“PartsMarkt”, “we”).

1.2. Contact for all personal data matters: support@partsmarkt.com.

1.3. We have not appointed a Data Protection Officer (DPO), as we are not required to do so under Article 37 of the GDPR. For all privacy-related questions, use the email address above.

1.4. An important clarification about roles: when you make a purchase, the sale contract is concluded between you and the respective seller (the dismantler-trader) — see the Buyer Terms. For the data the seller receives in order to fulfil your order (names, phone number, delivery address), the seller is an independent controller for its own legal obligations (e.g. accounting).

2. Who this policy applies to

2.1. This policy applies to:

  • buyers — users with an account, as well as guests who order without registering;
  • sellers — traders (legal entities) and the natural persons who represent them or work with their account;
  • visitors to the site without an account.

3. What data we collect

3.1. Account data: email address, password hash (never the password itself), names, preferred interface language.

3.2. Seller business data: company name, EIK (company registration number), city and address, phone number, parcel handover address, bank/payment account details (via Stripe), identity verification documents (KYC) — see Section 7.

3.3. Listing data: part descriptions, photos, prices, condition (grades A/B/C/R), make/model compatibility.

3.4. Order and delivery data: ordered items, amounts, payment method, recipient names and phone number, delivery address or selected Speedy office, order history. For guest orders: names, email, phone number and delivery address, as well as a link (token) for tracking the order.

3.5. Payment data: processed by Stripe. We never see or store your full card number — see Section 7.

3.6. In-platform messages: the content of conversations between buyers and sellers — see Section 9.

3.7. Enquiries to sellers: names, email, phone number, text of the enquiry.

3.8. Buyer’s saved vehicles: make/model/year, if you choose to save a vehicle in your profile for easier filtering of compatible parts.

3.9. Consent records (cookies and registration): type of consent, decision (yes/no), date and time, policy version and a hashed (SHA-256) IP address at registration — see Section 6.

3.10. Terms acceptance records (click-consents): including your IP address in raw (unhashed) form — detailed in Section 5.

3.11. Technical data: IP address and request data for security and abuse-prevention purposes (rate limiting), technical logs and error reports, and — only with your consent — analytics data about the use of the site.

4. Purposes and legal bases

4.1. We process personal data only when we have a legal basis under Article 6 of the GDPR:

PurposeExample dataLegal basis
Creating and maintaining an account; publishing listings; concluding and fulfilling orders; escrow holding and release of payments; delivery; messages between buyer and sellerAccount, listing, order, delivery and message dataPerformance of a contract — Art. 6(1)(b)
Issuing invoices, accounting and tax reporting; seller identity verification (KYC) and anti-money-laundering measures via StripeOrder and payment data, company and KYC dataLegal obligation — Art. 6(1)(c)
Proving the conclusion and content of contracts; establishing, exercising and defending legal claimsTerms acceptance records (Section 5), consent recordsPerformance of a contract — Art. 6(1)(b); legitimate interest — Art. 6(1)(f)
Platform security: abuse limitation, fraud prevention, error monitoring and stabilityIP address, technical logs, error reportsLegitimate interest — Art. 6(1)(f)
Distribution of the listings catalog (parts data, not buyers’ personal data) to the Meta Commerce CatalogListing dataLegitimate interest — Art. 6(1)(f)
Site usage analytics; advertising measurement (Meta Pixel and Conversions API)Browsing events, hashed email on purchase (CAPI only)Consent — Art. 6(1)(a), given via the cookie banner
Marketing communications by emailEmail, namesConsent — Art. 6(1)(a), separate and withdrawable at any time

5. Terms acceptance records (click-consents)

5.1. When you accept a legal document on the platform by ticking a checkbox and confirming (so-called “clickwrap”) — for example the Buyer Terms, the Seller Terms, the Commission Schedule or the Shipping Schedule — we record evidence of that acceptance.

5.2. Each record contains: your user identifier; the exact document and its version; date and time; your IP address in raw (unhashed) form; browser/device data (user agent); the interface language; the manner of acceptance (e.g. checkbox ticked); and a cryptographic fingerprint (SHA-256 hash) of the exact text of the document you saw.

5.3. We say this plainly and clearly: for these records we store your IP address in raw form, not hashed as we do for cookie consent records (Section 6). The reason is evidentiary — the raw IP address is part of the body of data that makes it possible to prove in court who accepted what, and when.

5.4. Purpose and basis: proving the conclusion and content of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in establishing, exercising and defending legal claims (Art. 6(1)(f) GDPR).

5.5. Retention period: at least 5 years after account closure — in line with the limitation periods for contractual claims under Bulgarian law and the requirements of the VAT Act for storing electronic documents with guaranteed integrity.

5.6. The records are immutable — once created, they cannot be edited or replaced. When your account is deleted, they are not deleted but are retained in pseudonymised form (without data directly identifying you in our other systems), on the basis of Art. 17(3)(e) GDPR — establishment, exercise or defence of legal claims.

6. Consent records for cookies and at registration

6.1. Separately from the records under Section 5, we maintain an audit trail of your consents: at registration we record the date, the policy version and a hashed (SHA-256) IP address; on every change of your choices in the cookie banner we record the type of consent (analytics/advertising), the decision and the date. These records allow us to prove that we have honoured your choices, including at server level (e.g. advertising events are sent only where consent is recorded).

7. Payments and identity verification (KYC)

7.1. Card payments are processed by Stripe. Card details are entered into Stripe’s secure fields — we have no access to the full card number and do not store it.

7.2. Sellers undergo identity verification (KYC) via Stripe Connect in order to be able to withdraw funds. When this verification is initiated, we transmit to Stripe your IP address in raw form and your browser data together with the moment of acceptance — Stripe requires them as evidence of acceptance of its own terms of service.

7.3. Identity documents and supporting documents uploaded for KYC purposes are stored in a separate, restricted storage space in Cloudflare R2 with controlled access and are transmitted to Stripe for verification.

8. Delivery data — sharing with the seller and Speedy

8.1. In order for your order to be fulfilled, we transmit to the seller and to the courier Speedy (the platform’s only integrated courier) the delivery data required: recipient names, phone number, delivery address or selected Speedy office, and — for cash on delivery — the amount to be collected. Details of the delivery process are in the Shipping Schedule.

8.2. For the purposes of the courier service, Speedy acts as an independent controller in accordance with its own privacy policy.

8.3. Shipment tracking (scans and statuses from Speedy) is stored against the order so that you can see its movement in real time.

9. In-platform messages

9.1. Conversations between buyers and sellers take place on the platform and their content is stored. It is visible to both parties to the conversation, and in the event of a dispute it may be reviewed by our team as evidence.

9.2. When a buyer’s account is deleted, conversations are anonymised (the link to your profile is removed), and the content is retained for the seller’s record-keeping — see Section 14.5.

10. Recipients and processors

10.1. We use the following service providers. We have a data processing agreement (DPA) with each processor; for transfers outside the European Economic Area, the European Commission’s Standard Contractual Clauses (SCCs) or another valid mechanism under Chapter V of the GDPR apply.

ProviderWhat forLocation / safeguards
SupabaseDatabase and authenticationEU (Frankfurt)
VercelWeb hostingEU processing region; DPA/SCCs
CloudflareCDN, storage of images and of KYC documents (R2)EU CDN; DPA/SCCs
StripeCard payments, payouts to sellers (Connect), KYCEU/USA; SCCs
SpeedyCourier delivery and cash on deliveryBulgaria (independent controller)
ResendTransactional emails (support@partsmarkt.com)EU; DPA/SCCs
UpstashAbuse limitation (rate limiting) — short-term processing of IP addressesDPA/SCCs
SentryError monitoring for security and stabilityEU
PostHogProduct analytics — only with analytics consentEU
Meta Platforms IrelandCommerce Catalog (listing data); Meta Pixel and Conversions API — only with advertising consentEU; see Section 11

10.2. We do not sell your personal data to anyone.

10.3. We may disclose data to competent authorities where the law obliges us to do so.

11. Sharing with Meta / Facebook

11.1. We share listing data (not buyers’ personal data) with Meta Platforms Ireland Limited so that parts can be discovered on Facebook and used in remarketing through our own Commerce Catalog. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in market distribution).

11.2. Catalog synchronisation: title, description, photos, price, condition, make/model and the listing’s internal identifier are sent to Meta’s Commerce Catalog when a listing is created, edited or removed. Sellers who delete their account have their listings removed from Meta’s catalog within 30 days.

11.3. Meta Pixel (browser): browsing events (page view, search, content view) are sent only after you accept advertising cookies. We do not share email or phone number directly via the Pixel.

11.4. Conversions API (server): on a completed purchase we send Meta a “Purchase” event (value, currency, order number and an email hashed with SHA-256) — only if you have recorded advertising consent. Guests and users without such consent are skipped entirely.

11.5. Data from buyers’ enquiries and messages is never shared with Meta.

11.6. You can withdraw your consent at any time via “Cookie Settings” in the footer — withdrawal stops the Pixel and the server-side advertising events.

12. Cookies and similar technologies

12.1. We use cookies and similar technologies in three categories. Strictly necessary ones are always active; analytics and advertising ones are loaded only with your consent, given via the banner on your first visit.

  • Strictly necessary — sign-in and session (Supabase), language choice, payment protection (Stripe) and error monitoring for security and stability (Sentry). Required for the site to work; no consent needed.
  • Analytics — product usage and performance (PostHog, Vercel Analytics). Loaded only if you allow analytics.
  • Advertising — marketing measurement and personalisation (Meta Pixel and Conversions API). Loaded/sent only if you allow advertising.

12.2. You can change or withdraw your consent at any time via the “Cookie Settings” link in the footer. Withdrawal stops the corresponding tracking and is as easy as giving consent.

13. Retention periods

13.1. We keep data only for as long as necessary for the purpose for which it was collected, or for as long as the law requires:

DataPeriod
Account dataUntil the account is deleted; deletion/anonymisation without undue delay, at the latest within 30 days of the request
Listing dataWhile the account is active
Orders, invoices and accounting documentsFor the periods required by Bulgarian tax and accounting legislation (including the VAT Act)
Terms acceptance records (Section 5)At least 5 years after account closure; after account deletion — in pseudonymised form
Consent records (Section 6)While the account is active and thereafter to the extent necessary to demonstrate compliance
In-platform messagesWhile the account is active; on deletion — anonymised (Section 9.2)
Enquiries to sellers12 months
Analytics data12 months
Technical queues and notifications (email queue, system notifications)Short periods; periodic automatic deletion

14. Your rights

14.1. Under the GDPR you have the right to: access your data; rectification; erasure (“right to be forgotten”); restriction of processing; data portability; objection to processing based on legitimate interest; and withdrawal of consent at any time (without affecting the lawfulness of processing before the withdrawal).

14.2. Exporting your data: while signed in to your account, you can download a machine-readable copy of your data (profile, listings, orders, conversations, messages, enquiries, consent records) from /api/gdpr/export.

14.3. Account deletion: use the /data-deletion page or the deletion function in your profile settings. Deletion removes your account, your saved listings/vehicles and your link to conversations.

14.4. Limits of erasure: some data is retained even after account deletion, where the law permits or requires it — order data, invoices and accounting documents (legal obligation — Art. 17(3)(b) GDPR) and the terms acceptance records in pseudonymised form (legal claims — Art. 17(3)(e) GDPR, Section 5.6).

14.5. The content of conversations is retained in anonymised form for the seller’s record-keeping (Section 9.2).

14.6. To exercise your rights, write to support@partsmarkt.com. We respond without undue delay and at the latest within one month.

14.7. Complaint to the supervisory authority: you have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP) — [OPERATOR: CPDP address and contact details to be confirmed — website www.cpdp.bg]. You do not need to contact us first, but we would be glad to try to resolve the matter.

15. Automated decision-making and profiling

15.1. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Information about how listings are ordered and about paid featuring can be found in the Buyer Terms and the Seller Terms.

16. Data security

16.1. We apply technical and organisational measures appropriate to the risk: encryption of the connection (HTTPS), database-level access control (row-level access policies), separate and restricted storage of sensitive documents (KYC), abuse limitation and monitoring for errors and incidents. No system is absolutely secure; in the event of a security breach that poses a risk to your rights, we will notify the CPDP and — where the risk is high — you as well, in accordance with Arts. 33–34 GDPR.

17. Minors

17.1. The platform is intended for persons aged 18 or over. We do not knowingly collect children’s data; if we learn of such a case, we will delete the data.

18. Changes to this policy and final provisions

18.1. This policy is version 1 (the first version published through the platform's versioned legal-documents system) and is effective from [OPERATOR: effective date — to be completed]. Each version has a permanent address; the current one is available at /legal/privacy_policy/v/1.

18.2. In the event of material changes we will notify you via the platform and/or by email and, where applicable, will ask for renewed acceptance. Previous versions remain available at their permanent addresses.

18.3. This policy is drawn up in Bulgarian and English. The Bulgarian version is authoritative and prevails in the event of a conflict between the language versions.

18.4. Related documents: Buyer Terms, Seller Terms, Commission Schedule, Shipping Schedule.

Content SHA-256: 9efd414ec2029261f153846c9beb7cce6d51687ee974542d6a38a6c43a47eb6f