Privacy Policy
Version 2026-09-26 · Last updated 26 September 2026 · Movibyte Studio
The store app is the scanner. The Vondi Market app launches soon. Buying, boosts and messages stay closed until shipping works here. No date.
This Privacy Policy explains how Movibyte Studio processes personal data when you use Vondi Market on vondi.co and the same Market backend in the Vondi app. It is the controller notice for Market. Contact: info@movibytestudio.com.
This notice replaces the previous web draft. In particular: the website does not mint anonymous Supabase users so that guests can browse. Guests read live listings with the publishable anon key. A session is created only when you log in or sign up.
1. Controller
The controller is Movibyte Studio, operator of Vondi. Movibyte Studio, Hamerbijl 32, 4906 LJ Oosterhout, the Netherlands, is registered with the Netherlands Chamber of Commerce (KvK) under number 99969696 (VAT number NL005422508B44); Vondi is a trade name of Movibyte Studio. There is no appointed Data Protection Officer at this scale; privacy requests go to the same inbox.
2. Whose data and which service
We process data of visitors (country and legal acceptance), account holders, and people whose data a user types into an address or chat. The Market database is shared with the Vondi app. Scanner-only data (scan images, quota, RevenueCat entitlements) is described in the app’s scanner notices and is not required for website browsing. This Policy covers Market processing on web and the shared Market tables.
3. Categories of data
- Gate and preferences: country, legal-version acceptance, language, theme.
- Account: email, password hash (held by Supabase Auth), display name, account timestamps. Passwords are not stored in the clear.
- Profile and address: ship-from / ship-to fields (name, street, number, postal code, city, country, state, phone) in profile preferences; public face (handle, bio, avatar, country).
- Listings: title, brand, price, photos, notes, pack size, department, category, city, pool.
- Engagement: saves, follows, reviews, wish/want strings you store.
- Chat: message body, sender id, listing id, time. Off-platform contact is blocked and not meant to be stored as a successful send.
- Deals and money: listing id, parties, status, Ask, buyer total, postage, limited Stripe identifiers returned to the app. We do not store full card numbers. Wallet ledger lines (credit, spend, refund, payout).
- Connect / payout: Stripe account id and onboarding flags (charges enabled, details submitted, identity block, legal name as Stripe returns it).
- Shipping: label and tracking references, carrier events, addresses sent to the carrier.
- DAC7: when required, legal name, TIN (encrypted), birth date, country, and summary figures of released sales.
- Moderation: listing text flags, photo-review results, strike or ban flags.
- Technical: IP address used for rate limiting in the edge middleware, security logs, and standard server logs. No advertising pixels are loaded on this website.
Acceptance records. When you create an account or accept a new version of our documents, we store the document version, the date and time, the channel, the language, and the IP address and browser identification used. Legal basis: Art. 6(1)(b) and (f) GDPR (performing and proving the contract, establishing and defending legal claims). We keep these records while your account exists and for up to five years after it ends (the general Dutch limitation period), or longer while a dispute is pending.
4. Purposes and legal bases (GDPR Art. 6)
| Purpose | Base |
|---|---|
| Show the correct pool and record that you accepted these notices | Art. 6(1)(b) contract / steps; Art. 6(1)(c) where proof of consent is required; cookies: see the Cookie Notice |
| Create and secure the account, login, password change | Art. 6(1)(b) |
| Publish listings, chat, saves, profiles, deals | Art. 6(1)(b) |
| Hold, release, refund and payout via Stripe; prevent double sale | Art. 6(1)(b) and (f) (fraud / sold-lock) |
| Print labels and track parcels | Art. 6(1)(b) |
| Moderate prohibited listings and luxury photos | Art. 6(1)(f) (safety and legal compliance); Art. 6(1)(c) where criminal content must be blocked |
| DAC7 reporting and TIN collection after the threshold | Art. 6(1)(c) legal obligation |
| Rate limits, abuse, security headers | Art. 6(1)(f) |
| Theme and language cookies | Art. 6(1)(f) / consent as described in the Cookie Notice |
| Defend claims, bookkeeping | Art. 6(1)(f) and (c) |
Where we rely on legitimate interest, you may object under Article 21 GDPR unless we demonstrate compelling grounds or the processing is needed for legal claims.
5. Recipients and processors
- Supabase — hosting of accounts, listings, chat, deals and photos.
- Stripe — payments, Connect payouts and identity checks. Stripe is an independent controller for much of the payment data; see stripe.com/privacy.
- Carriers (PostNL and DHL; labels through EasyPost) — the postal or parcel carrier shown at checkout for that lane, who receive only the shipper and receiver data needed for that label.
- Cloudflare — DNS, CDN, Turnstile on sign-in and sign-up, and abuse protection when the site is served through it.
- An email provider (Resend) — transactional mail such as confirm and reset from info@movibytestudio.com.
- Automated image-review providers (Google Gemini) — listing photos may be sent for a trust or luxury visual check. A pass is not a certificate. We do not use this to train a public catalogue for others.
- Authorities — Dutch Tax Administration (DAC7), police or courts where legally required.
- The other party to a Deal or chat (name, address as needed to perform the contract, messages).
We do not sell personal data and we do not run advertising networks on this website.
6. International transfers
Pools include the United Kingdom, the United States and Canada. Stripe, some carriers and some subprocessors may process data in those countries or in the United States. Where GDPR applies, transfers outside the EEA use an adequacy decision (including the UK) or Standard Contractual Clauses and supplementary measures from the processor. You may ask us for a copy of the relevant mechanism, redacted for confidentiality.
7. Retention
- Gate cookies: up to 13 months (set as one year, plus a short overlap).
- Account: until you delete it, plus a short closure period.
- Listings and photos: while live or paused, then until you delete them or the account is erased, subject to Deal evidence.
- Chat: for the life of the thread and a reasonable dispute period.
- Deals, wallet, Stripe ids: at least the bookkeeping and chargeback period (typically seven years in the Netherlands for tax records where they form part of our administration).
- DAC7: as required by the DAC7 implementing rules (generally several years after the reporting year).
- Security / rate-limit logs: days to a few months unless needed for an incident.
8. Security
We use TLS, httpOnly session cookies via Supabase SSR, least-privilege column selects, row-level security, payload size limits, rate limits, and security headers (CSP, HSTS, frame denial). Passwords are handled by Supabase Auth. TIN values are stored encrypted. No measure is perfect; you must keep your password secret.
9. Automated decisions
Listing text filters, photo moderation and the luxury visual check are automated and can pause or refuse a listing. They do not produce a legal effect equivalent to a credit score. You can ask a human review by emailing us with the listing id. A visual-check fail is not a finding that you committed a crime.
10. Children
The Service is for persons 18 and over. We do not knowingly create Market accounts for children. Listings that sexualise minors or offer a person as a product are forbidden and may be reported to authorities.
11. Your rights
If GDPR or UK GDPR applies, you may request access, rectification, erasure, restriction, portability, and to object to legitimate-interest processing. You may withdraw cookie consent by clearing cookies or writing to us (the site cannot run the catalogue without the strictly necessary cookies). You may complain to the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or your local EEA / UK authority.
Users in California or other US states may have similar access and deletion rights under local law. We do not sell or “share” personal information for cross-context behavioural advertising. Send the request to the same email and tell us which right you exercise.
Account deletion is available in the Vondi app today (including the cooling-off period described there). Email us from the registered address if you need website-side erasure. We may keep data that we must keep (Deals, DAC7, legal claims).
12. Cookies
See the Cookie Notice for the exact names, purpose and storage period.
13. Sources, public data and marketing
Most data comes from you (gate, account, address, listings, chat, tax form). We also receive data from Stripe (payment and Connect status), carriers (tracking events), moderation vendors (verdicts), and from other users (messages to you, reviews after a Deal, follows). We do not buy marketing lists.
Visible to others in your pool: live listing content and photos, your public face (handle, bio, avatar, country), and reviews tied to completed Deals. Chat, ship-to address, TIN, wallet and Stripe identifiers are not public catalogue fields.
This website does not send marketing newsletters. Mail from info@movibytestudio.com is transactional (confirm, reset, Deal mail if enabled). Scanner or app store messages are outside this notice.
14. How to exercise your rights
Email info@movibytestudio.com from the address on the account, state which right you exercise, and give enough detail (listing id, Deal id, date range). We may ask for extra identification if the request is not obviously yours. We respond within one month, or tell you if we need a further two months for complexity. We may refuse a manifestly unfounded or excessive request and will say why.
15. Breaches
If a personal-data breach is likely to result in a risk to your rights, we will notify the Autoriteit Persoonsgegevens without undue delay and, where required, within 72 hours of becoming aware. Where the risk is high, we will also inform you.
16. Changes
We will publish a new version and bump vondi_legal when the change is material, so you accept again before using gated pages.