1. Data Controller
The data controller responsible for your personal data is:
Market Mirae605 N Preston Rd, Suite 200 PMB 3012
Gunter, TX 75078, United States
privacy@marketmirae.com
2. What We Collect
We collect only the minimum data needed to operate the Service.
| Category | Data | Lawful Basis | Retention |
|---|---|---|---|
| Account | Name, email, profile picture (Google auth), hashed password (email auth) | Contract necessity (Art. 6(1)(b) GDPR) | Until account deletion |
| Consent record | Timestamp and version of ToS/Privacy Policy consent; age confirmation | Legal obligation (Art. 6(1)(c) GDPR); legitimate interest | Until account deletion + 1 year |
| Scan history | Marketplace URLs submitted, AI-generated verdicts, trust scores | Contract necessity (Art. 6(1)(b) GDPR) | Until account deletion |
| Payment data | Subscription tier, Stripe customer/session IDs. We never see card numbers. | Contract necessity; legal obligation (tax/financial records) | 7 years (legal requirement) |
| Uploaded images | Images submitted for scanning. Re-encoded server-side; originals deleted immediately. | Contract necessity | Not persisted — discarded after scan |
| Security / audit logs | IP address, user-agent, timestamps of key account events (login, password change, data requests) | Legitimate interest (fraud prevention, security) | 90 days |
| Session cookie | session_token — strictly necessary to maintain your login state | Necessary for the service to function (no consent required) | 7 days or until logout |
3. How We Use Your Data
- To operate the Service: run scans, deduct credits, display scan history.
- To process subscription payments and manage billing through Stripe.
- To verify your email address and secure your account.
- To detect fraud, abuse, and security threats.
- To respond to your Data Subject Access Requests (DSARs).
- To send transactional emails (email verification, password reset, subscription receipts). No marketing without separate consent.
- To improve product quality. We do not sell or rent your data to advertisers or data brokers.
4. Data Processors & Third Parties
We share the minimum necessary data with the following processors, each of which operates under a Data Processing Agreement (DPA) with us.
| Processor | Purpose | Data transferred |
|---|---|---|
| Google (OAuth) | Social sign-in via Emergent Auth | Name, email, profile picture |
| Stripe | Payment processing, subscription management | Email, billing details |
| OpenAI | AI image analysis (listing scans) | Sanitized listing images, listing URLs |
| Anthropic | AI text analysis (listing verdicts) | Listing text, product descriptions |
| ScraperAPI | Marketplace listing retrieval | Listing URLs submitted |
| Resend | Transactional email delivery | Your email address only |
| Upstash Redis | Rate limiting, login security | Hashed IP addresses, rate-limit keys |
| Emergent Labs | Platform hosting, infrastructure | All data (as host) |
5. International Data Transfers
Market Mirae is based in the United States. If you are accessing the Service from the EU/EEA, UK, or other regions with data-protection laws, your personal data is transferred to the US under the following safeguards:
- Standard Contractual Clauses (SCCs) — EU Commission-approved SCCs are in place for transfers to processors (Stripe, OpenAI, Anthropic, Resend) that are not covered by an adequacy decision.
- EU-US Data Privacy Framework — where processors are certified (Stripe, Google).
- UK IDTA — UK International Data Transfer Agreements are used for UK user data where applicable.
You may request a copy of applicable transfer safeguards by emailing privacy@marketmirae.com.
6. Your Privacy Rights
Depending on your location, you may have the following rights. You can exercise most of these directly from your Account page.
We will respond to all verifiable requests within 30 days (extendable to 90 days for complex requests, with notice). Email privacy@marketmirae.com for requests that cannot be completed self-service.
7. Cookies & Tracking
We use one strictly necessary cookie: session_token, which keeps you logged in for up to 7 days. This cookie is HttpOnly, Secure, and SameSite=Lax. It is essential for the Service to function and does not require your consent under the ePrivacy Directive.
We use no tracking, analytics, or advertising cookies. We do not share your browsing data with any third party for advertising purposes.
To remove the session cookie, simply log out or delete your browser cookies.
8. Children's Data
Market Mirae is not directed to individuals under the age of 16. We do not knowingly collect personal data from anyone under 16. If we learn that we have inadvertently collected such data, we will delete it immediately. Parents or guardians who believe a child under 16 has created an account should contact us at privacy@marketmirae.com.
This age minimum complies with GDPR Article 8 (EU minimum 16), and exceeds the COPPA minimum of 13 in the United States.
9. Automated Decision-Making
The AI trust scores and verdict assessments produced by Market Mirae are generated automatically using large language models (LLMs) and computer vision. These assessments are informational only and do not produce legal or similarly significant effects on you. They represent estimates to help you evaluate marketplace listings; they do not determine credit, employment, or other legally protected outcomes.
You may object to any automated processing of your data by submitting a request via Account → Object to processing. We will respond within 30 days.
10. Security
We implement industry-standard technical and organisational measures to protect your data:
- TLS 1.2+ encryption for all data in transit.
- Passwords hashed with bcrypt (cost factor 12). Plaintext passwords are never stored.
- Rate limiting, CAPTCHA, and exponential back-off on login to prevent brute force.
- Server-side EXIF stripping and image re-encoding for all uploads (no hidden payloads stored).
- Antivirus scanning (ClamAV) of all uploaded images before processing.
- Strict Content-Security-Policy, HSTS, and other security headers on all responses.
- SSRF protection: server-side scraping is restricted to public addresses only.
- Admin access requires two-factor authentication (TOTP).
In the event of a personal data breach affecting your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of discovery, as required by GDPR Article 33.
11. Data Retention
We retain personal data only as long as necessary for the stated purpose:
- Account and scan data — retained while your account is active. Deleted within 30 days of account deletion request.
- Payment / transaction records — retained for 7 years for legal/tax compliance.
- Security and audit logs — retained for 90 days, then purged.
- Uploaded images — not stored; discarded after each scan.
- Consent records — retained until account deletion + 1 year (legal obligation).
- Session tokens — expire after 7 days or logout, whichever is earlier.
12. Regional Supplements
European Union / UK (GDPR / UK GDPR)
The lawful bases for processing are: contract necessity (Art. 6(1)(b)), legal obligation (Art. 6(1)(c)), and legitimate interest (Art. 6(1)(f)) for security and fraud prevention. You have the right to lodge a complaint with your local supervisory authority (e.g., ICO in the UK, CNIL in France, or your national DPA in the EU).
California (CCPA/CPRA)
We do not sell or share personal information. California residents have the right to know, delete, correct, and opt out. We do not use sensitive personal information for inferring characteristics. To exercise rights, contact privacy@marketmirae.com.
India (DPDP Act 2023)
Indian users may exercise rights of access, correction, erasure, and grievance redressal by contacting our Data Fiduciary at privacy@marketmirae.com.
Brazil (LGPD)
Brazilian users may exercise rights under the Lei Geral de Proteção de Dados, including access, correction, deletion, portability, and information about processors. Contact privacy@marketmirae.com.
Canada (PIPEDA)
Canadian users may access, correct, or withdraw consent for their personal information. Complaints may be directed to the Office of the Privacy Commissioner of Canada.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced in-app. Continued use of the Service after the effective date constitutes acceptance. The "Last updated" date at the top of this page reflects the most recent revision.
14. Contact & DPO
For privacy inquiries, Data Subject Access Requests, or complaints:
Privacy / Data Protection OfficeMarket Mirae
605 N Preston Rd, Suite 200 PMB 3012
Gunter, TX 75078, United States
privacy@marketmirae.com
We aim to respond to all requests within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction.