Version 4Effective from 22 September 2026Български

PartsMarkt Privacy Policy

This Privacy Policy explains what personal data the PartsMarkt platform (partsmarkt.com) collects, why it collects it, who it is shared with, and what rights you have. PartsMarkt is an online platform (marketplace) for used auto parts on which sellers (traders — vehicle dismantlers and salvage yards) offer parts to buyers. We have tried to write in plain language. If anything is unclear, write to us at support@partsmarkt.com.

1. Who is responsible for your data (controller)

1.1. The controller of the personal data processed through the platform is "Clyde Management" EOOD, UIC (EIK) 208422678, VAT No BG208422678, with registered seat and management address at 12 "Boris Arsov" St., Lozenets district, 1421 Sofia, Bulgaria ("PartsMarkt", "we").

1.2. Contact for all personal data matters: support@partsmarkt.com.

1.3. We have not appointed a Data Protection Officer (DPO), as we are not required to do so under Article 37 of the GDPR. For all privacy-related questions, use the email address above.

1.4. An important clarification about roles: when you make a purchase, the sale contract is concluded between you and the respective seller (the dismantler-trader) — see the Buyer Terms. For the data the seller receives in order to fulfil your order (names, phone number, delivery address), the seller is an independent controller for its own legal obligations (e.g. accounting).

2. Who this policy applies to

2.1. This policy applies to:

  • buyers — users with an account, as well as guests who order without registering;
  • sellers — traders (legal entities) and the natural persons who represent them or work with their account;
  • visitors to the site without an account;
  • third parties whose data (for example, a vehicle registration plate) appears in photos published on the platform — see Section 4.2.

3. What data we collect

3.1. Account data: email address, password hash (never the password itself), names, preferred interface language.

3.2. Seller business data: company name, EIK (company registration number), city and address, phone number, parcel handover address, bank/payment account details (via Stripe), identity verification documents (KYC) — see Section 7.

3.3. Listing data: part descriptions, photos, prices, condition (grades A/B/C/R), make/model compatibility.

3.4. Order and delivery data: ordered items, amounts, payment method, recipient names and phone number, delivery address or selected Speedy office, order history. For guest orders: names, email, phone number and delivery address, as well as a link (token) for tracking the order.

3.5. Payment data: processed by Stripe. We never see or store your full card number — see Section 7.

3.6. In-platform messages: the content of conversations between buyers and sellers — see Section 9.

3.7. Enquiries to sellers: names, email, phone number, text of the enquiry.

3.8. Buyer’s saved vehicles: make/model/year, if you choose to save a vehicle in your profile for easier filtering of compatible parts.

3.9. Consent records (cookies and registration): type of consent, decision (yes/no), date and time, policy version and a hashed (SHA-256) IP address at registration — see Section 6.

3.10. Terms acceptance records (click-consents): including your IP address in raw (unhashed) form — detailed in Section 5.

3.11. Technical data: IP address and request data for security and abuse-prevention purposes (rate limiting), technical logs and error reports, and — only with your consent — analytics data about the use of the site.

4. Purposes and legal bases

4.1. We process personal data only when we have a legal basis under Article 6 of the GDPR:

PurposeExample dataLegal basis
Creating and maintaining an account; publishing listings; concluding and fulfilling orders; escrow holding and release of payments; delivery; messages between buyer and sellerAccount, listing, order, delivery and message dataPerformance of a contract — Art. 6(1)(b)
Issuing invoices, accounting and tax reporting; seller identity verification (KYC) and anti-money-laundering measures via StripeOrder and payment data, company and KYC dataLegal obligation — Art. 6(1)(c)
Proving the conclusion and content of contracts; establishing, exercising and defending legal claimsTerms acceptance records (Section 5), consent recordsPerformance of a contract — Art. 6(1)(b); legitimate interest — Art. 6(1)(f)
Platform security: abuse limitation, fraud prevention, error monitoring and stabilityIP address, technical logs, error reportsLegitimate interest — Art. 6(1)(f)
Distribution of the listings catalog (parts data, not buyers’ personal data) to the Meta Commerce CatalogListing dataLegitimate interest — Art. 6(1)(f)
Site usage analytics; advertising measurement (Meta Pixel and Conversions API)Browsing events, hashed email on purchase (CAPI only)Consent — Art. 6(1)(a), given via the cookie banner
Marketing communications by emailEmail, namesConsent — Art. 6(1)(a), separate and withdrawable at any time
Automated checking of images in listings and seller profiles for contact details, references to other websites and readable vehicle registration plates; handling reports and requests for reviewImage content; a record of what was found (phone numbers, e-mail addresses and plates masked; website domains and social-media handles kept in full); keyed hashes (HMAC) of detected phone numbers, e-mail addresses, handles and domains; the id and note of a user who submits a reportLegitimate interest — Art. 6(1)(f) (integrity of the escrow model, prevention of fraud and of circumvention of the platform; protection of third parties whose data appear in images, including a plate — see Section 4.2); performance of a contract — Art. 6(1)(b), where the seller is a natural person, for enforcement of the Seller Terms

4.2. Vehicle registration plates and other people's data in images. Photos published on the platform sometimes show the registration plate of a vehicle. A readable registration plate constitutes personal data of a third party who is not party to the listing, and publishing it does not rest on that person's consent or on our contract with the seller. That is why, once our automated checks are fully in operation, we check photos in listings and seller profiles for readable registration plates (currently in the Bulgarian format) and blur every plate the check detects in a photo stored on our platform, usually within minutes of upload — regardless of the seller, and regardless of whether that seller has accepted our applicable terms — as our own measure to protect that third party's data. Plates the check cannot confirm are reviewed by a member of our staff, who may blur them. Automated detection is not perfect, and we cannot blur a photo hosted outside our platform: if a photo on the platform shows your vehicle's registration plate — whether stored with us or an external link — write to us at support@partsmarkt.com and we will blur the plate or remove the photo. Before automated enforcement is switched on ("log only" mode), a detected plate is only recorded, in masked form, and the photo is not changed. As a rule, the unaltered original of a blurred photo stored on our platform is removed from its public address within about two days of the action and kept in restricted storage so that an erroneous action can be reversed; it is deleted 7 days after the action or, if the seller's review request is still pending then, once that request has been decided. If moving it into restricted storage temporarily fails, we retry daily and the original stays at its public address until then; the same applies while the same file is still used elsewhere on the platform. We do not identify vehicle owners, do not contact them, and do not use or combine this data to identify anyone. Providing information individually to every person whose plate appears in a photo would require a disproportionate effort within the meaning of Article 14(5)(b) GDPR; in accordance with that provision, we therefore make this information publicly available here, including how to contact us (earlier in this paragraph). The legal basis is our legitimate interest under Art. 6(1)(f) GDPR in protecting these third parties' personal data and in not publishing more personal data than a listing needs (data minimisation, Art. 5(1)(c) GDPR).

5. Terms acceptance records (click-consents)

5.1. When you accept a legal document on the platform by ticking a checkbox and confirming (so-called "clickwrap") — for example the Buyer Terms, the Seller Terms, the Commission Schedule or the Shipping Schedule — we record evidence of that acceptance.

5.2. Each record contains: your user identifier; the exact document and its version; date and time; your IP address in raw (unhashed) form; browser/device data (user agent); the interface language; the manner of acceptance (e.g. checkbox ticked); and a cryptographic fingerprint (SHA-256 hash) of the exact text of the document you saw.

5.3. We say this plainly and clearly: for these records we store your IP address in raw form, not hashed as we do for cookie consent records (Section 6). The reason is evidentiary — the raw IP address is part of the body of data that makes it possible to prove in court who accepted what, and when.

5.4. Purpose and basis: proving the conclusion and content of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in establishing, exercising and defending legal claims (Art. 6(1)(f) GDPR).

5.5. Retention period: at least 5 years after account closure — in line with the limitation periods for contractual claims under Bulgarian law and the requirements of the VAT Act for storing electronic documents with guaranteed integrity.

5.6. The records are immutable — once created, they cannot be edited or replaced. When your account is deleted, they are not deleted but are retained in pseudonymised form (without data directly identifying you in our other systems), on the basis of Art. 17(3)(e) GDPR — establishment, exercise or defence of legal claims.

6. Consent records for cookies and at registration

6.1. Separately from the records under Section 5, we maintain an audit trail of your consents: at registration we record the date, the policy version and a hashed (SHA-256) IP address; on every change of your choices in the cookie banner we record the type of consent (analytics/advertising), the decision and the date. These records allow us to prove that we have honoured your choices, including at server level (e.g. advertising events are sent only where consent is recorded).

7. Payments and identity verification (KYC)

7.1. Card payments are processed by Stripe. Card details are entered into Stripe’s secure fields — we have no access to the full card number and do not store it.

7.2. Sellers undergo identity verification (KYC) via Stripe Connect in order to be able to withdraw funds. When this verification is initiated, we transmit to Stripe your IP address in raw form and your browser data together with the moment of acceptance — Stripe requires them as evidence of acceptance of its own terms of service.

7.3. Identity documents and supporting documents uploaded for KYC purposes are stored in a separate, restricted storage space in Cloudflare R2 with controlled access and are transmitted to Stripe for verification.

8. Delivery data — sharing with the seller and Speedy

8.1. In order for your order to be fulfilled, we transmit to the seller and to the courier Speedy (the platform’s only integrated courier) the delivery data required: recipient names, phone number, delivery address or selected Speedy office, and — for cash on delivery — the amount to be collected. Details of the delivery process are in the Shipping Schedule.

8.2. For the purposes of the courier service, Speedy acts as an independent controller in accordance with its own privacy policy.

8.3. Shipment tracking (scans and statuses from Speedy) is stored against the order so that you can see its movement in real time.

9. In-platform messages

9.1. Conversations between buyers and sellers take place on the platform and their content is stored. It is visible to both parties to the conversation, and in the event of a dispute it may be reviewed by our team as evidence.

9.2. When a buyer’s account is deleted, conversations are anonymised (the link to your profile is removed), and the content is retained for the seller’s record-keeping — see Section 14.5.

10. Recipients and processors

10.1. We use the following service providers. We have a data processing agreement (DPA) with each processor; for transfers outside the European Economic Area, the European Commission’s Standard Contractual Clauses (SCCs) or another valid mechanism under Chapter V of the GDPR apply.

ProviderWhat forLocation / safeguards
SupabaseDatabase and authenticationEU (Frankfurt)
VercelWeb hosting and image processing (automated checks for contact details and vehicle registration plates)EU processing region; DPA/SCCs
CloudflareCDN, storage of images and of KYC documents (R2)EU CDN; DPA/SCCs
StripeCard payments, payouts to sellers (Connect), KYCEU/USA; SCCs
SpeedyCourier delivery and cash on deliveryBulgaria (independent controller)
ResendTransactional emails (support@partsmarkt.com)EU; DPA/SCCs
UpstashAbuse limitation (rate limiting) — short-term processing of IP addressesDPA/SCCs
SentryError monitoring for security and stabilityEU
PostHogProduct analytics — only with analytics consentEU
Meta Platforms IrelandCommerce Catalog (listing data); Meta Pixel and Conversions API — only with advertising consentEU; see Section 11

10.2. We do not sell your personal data to anyone.

10.3. We may disclose data to competent authorities where the law obliges us to do so.

11. Sharing with Meta / Facebook

11.1. We share listing data (not buyers’ personal data) with Meta Platforms Ireland Limited so that parts can be discovered on Facebook and used in remarketing through our own Commerce Catalog. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in market distribution).

11.2. Catalog synchronisation: title, description, photos, price, condition, make/model and the listing’s internal identifier are sent to Meta’s Commerce Catalog when a listing is created, edited or removed. Sellers who delete their account have their listings removed from Meta’s catalog within 30 days.

11.3. Meta Pixel (browser): browsing events (page view, search, content view) are sent only after you accept advertising cookies. We do not share email or phone number directly via the Pixel.

11.4. Conversions API (server): on a completed purchase we send Meta a "Purchase" event (value, currency, order number and an email hashed with SHA-256) — only if you have recorded advertising consent. Guests and users without such consent are skipped entirely.

11.5. Data from buyers’ enquiries and messages is never shared with Meta.

11.6. You can withdraw your consent at any time via "Cookie Settings" in the footer — withdrawal stops the Pixel and the server-side advertising events.

12. Cookies and similar technologies

12.1. We use cookies and similar technologies in three categories. Strictly necessary ones are always active; analytics and advertising ones are loaded only with your consent, given via the banner on your first visit.

  • Strictly necessary — sign-in and session (Supabase), language choice, payment protection (Stripe) and error monitoring for security and stability (Sentry). Required for the site to work; no consent needed.
  • Analytics — product usage and performance (PostHog, Vercel Analytics). Loaded only if you allow analytics.
  • Advertising — marketing measurement and personalisation (Meta Pixel and Conversions API). Loaded/sent only if you allow advertising.

12.2. You can change or withdraw your consent at any time via the "Cookie Settings" link in the footer. Withdrawal stops the corresponding tracking and is as easy as giving consent.

13. Retention periods

13.1. We keep data only for as long as necessary for the purpose for which it was collected, or for as long as the law requires:

DataPeriod
Account dataUntil the account is deleted; deletion/anonymisation without undue delay, at the latest within 30 days of the request
Listing dataWhile the account is active
Orders, invoices and accounting documentsFor the periods required by Bulgarian tax and accounting legislation (including the VAT Act)
Terms acceptance records (Section 5)At least 5 years after account closure; after account deletion — in pseudonymised form
Consent records (Section 6)While the account is active and thereafter to the extent necessary to demonstrate compliance
In-platform messagesWhile the account is active; on deletion — anonymised (Section 9.2)
Enquiries to sellers12 months
Analytics data12 months
Technical queues and notifications (email queue, system notifications)Short periods; periodic automatic deletion
Original of a photo stored on our platform that was hidden or blurred by the automated check (Section 4.2) — including an original from a Listing the Platform published on the seller's instructions (Section 5.8 of the Seller Terms)As a rule, removed from its public address within about two days of the action; deleted from restricted storage 7 days after the action or, if a review request is still pending then, once it has been decided. If the move into restricted storage temporarily fails, we retry every day, and until it succeeds the public copy stays at its address; while the file is still used elsewhere on the Platform, its public copy stays unchanged. A photo hosted outside the Platform is not moved or blurred (Section 4.2)
Record from the automated photo check, its related decision data, and — where a photo was hidden, blurred, reported, placed in our staff review queue or subject to a review request — the evidence of that decisionWhile the database row for the listing or seller profile exists (today, deleting a listing or a seller profile only marks it deleted — it does not remove the row); if the photo is not tied to a kept decision above, the checking record is deleted at the latest 12 months after the listing or profile is marked deleted
Keyed hashes (HMAC) used to count repeats across a seller's photosUp to 12 months from creation, or sooner if the listing or seller is deleted; copies of a hash held inside the checking record or decision data above follow that record's period instead
Id and note of a user who reported a photoAnonymised at the latest 6 months after the case is closed; for users who delete their account, immediately

14. Your rights

14.1. Under the GDPR you have the right to: access your data; rectification; erasure ("right to be forgotten"); restriction of processing; data portability; objection to processing based on legitimate interest; and withdrawal of consent at any time (without affecting the lawfulness of processing before the withdrawal).

14.2. Exporting your data: while signed in to your account, you can download a machine-readable copy of your data (profile, listings, orders, conversations, messages, enquiries, consent records) from /api/gdpr/export.

14.3. Account deletion: use the /data-deletion page or the deletion function in your profile settings. Deletion removes your account, your saved listings/vehicles and your link to conversations.

14.4. Limits of erasure: some data is retained even after account deletion, where the law permits or requires it — order data, invoices and accounting documents (legal obligation — Art. 17(3)(b) GDPR), the terms acceptance records in pseudonymised form (legal claims — Art. 17(3)(e) GDPR, Section 5.6), and the evidence of any automated photo-check decision (a hide, blur, report, staff-review referral or review request) tied to a listing or seller profile, for as long as the underlying database row exists — see Section 13 (legal claims — Art. 17(3)(e) GDPR).

14.5. The content of conversations is retained in anonymised form for the seller’s record-keeping (Section 9.2).

14.6. To exercise your rights, write to support@partsmarkt.com. We respond without undue delay and at the latest within one month.

14.7. Complaint to the supervisory authority: you have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP) — 2 "Prof. Tsvetan Lazarov" Blvd., 1592 Sofia, cpdp.bg, kzld@cpdp.bg. You do not need to contact us first, but we would be glad to try to resolve the matter.

15. Automated decision-making and profiling

15.1. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Information about how listings are ordered and about paid featuring can be found in the Buyer Terms and the Seller Terms.

15.2. A clarification concerning the automated image checks under Section 4.2 and the Seller Terms: where we hide or blur a single image from a Listing that remains published, or from a seller's profile that remains active, we consider that this alone does not produce legal effects for the seller and does not similarly significantly affect the seller within the meaning of Art. 22 GDPR — the seller may request a review by a person at any time through the review link in our notice or at support@partsmarkt.com (for a licence-plate blur this right does not depend on accepting any of our terms — the blur rests on our own legal ground under Section 4.2). This assessment is our own and does not affect your right to challenge it with the supervisory authority or in court.

16. Data security

16.1. We apply technical and organisational measures appropriate to the risk: encryption of the connection (HTTPS), database-level access control (row-level access policies), separate and restricted storage of sensitive documents (KYC), abuse limitation and monitoring for errors and incidents. No system is absolutely secure; in the event of a security breach that poses a risk to your rights, we will notify the CPDP and — where the risk is high — you as well, in accordance with Arts. 33–34 GDPR.

17. Minors

17.1. The platform is intended for persons aged 18 or over. We do not knowingly collect children’s data; if we learn of such a case, we will delete the data.

18. Changes to this policy and final provisions

18.1. The number of the current version of this policy and its effective date are shown at the top of the page at its permanent address. Each version has a permanent address and remains available after a new version is issued.

18.2. In the event of material changes we will notify you via the platform and/or by email and, where applicable, will ask for renewed acceptance. Previous versions remain available at their permanent addresses.

18.3. This policy is drawn up in Bulgarian and English. The Bulgarian version is authoritative and prevails in the event of a conflict between the language versions.

18.4. Related documents: Buyer Terms, Seller Terms, Commission Schedule, Shipping Schedule.

Content SHA-256: a041b7239c333eebf0b491598455a41fe1b36338dc54b32179c0a69d2c1d7dbc