Privacy Policy
Last updated: 27 August 2026
BrandMyX is operated from the United Kingdom. Company registration is in progress — the registered entity's name, number and address will appear here on incorporation.
1. Who is responsible for your data
The operator of brandmyx.com is the data controller for the personal data described in this policy. Contact: [email protected]. This policy is written to comply with the UK GDPR and the Data Protection Act 2018.
2. What we collect
- Account data: your email address, handle, and optional bio. Sign-in is by magic link or one-time code — we never store a password.
- Listing and proof photos: photos of your objects and applied stickers. Photos can contain personal data (faces, number plates, home interiors) — think before you shoot, and use the blur tools we nudge you towards. We strip all EXIF metadata, including GPS location, server-side on upload, before any version of the photo is stored or shown publicly.
- Sponsor content: logos, brand names, and brand website URLs.
- Marketplace activity: bids, orders, strikes, reports you file, and click counts on sponsor links (IP addresses used for click counting and rate limiting are hashed).
- Payment and identity data: processed by Stripe. Card numbers never touch our servers. Listers receiving payouts complete Stripe's identity verification (name, date of birth, address, bank details) directly with Stripe, as described in Stripe's own privacy notice.
- Location: city-level only, and only where you choose to show it on a listing. We never publish coordinates — and because of the EXIF stripping above, your photos can't leak them either.
- Usage data: standard server logs (IP address, user agent, pages requested) kept briefly for security and debugging.
3. Why we use it (lawful bases)
| What we do | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Running your account, listings, auctions, orders, and payouts | Contract — we can't run the marketplace for you without it |
| Content moderation, fraud and shill-bid prevention, rate limiting, security logs | Legitimate interests — keeping the marketplace real and safe (balancing test on file) |
| Reusing your photos in marketing beyond the platform's own share features | Consent — asked for separately, withdrawable any time |
| Tax, accounting, and platform-reporting obligations (including HMRC reporting where it applies) | Legal obligation |
| Transactional emails (outbid, won, proof reminders) | Contract — they are part of the service, not marketing |
4. Automated image screening
Uploaded photos and logos are screened automatically for safety and policy compliance using xAI's image models. Anything flagged goes to human review — no decision with legal or similarly significant effect on you (such as rejecting your listing or closing your account) is made solely by automated means, in line with UK GDPR Article 22. If your content is rejected, you can contest the decision at [email protected].
5. Who receives your data
We share personal data only with the processors and recipients needed to run the service:
| Recipient | Purpose | Location / transfer safeguard |
|---|---|---|
| Stripe | Payments, payouts, identity verification | US/EU — UK–US Data Bridge / UK addendum to SCCs |
| Brevo | Sending sign-in links and transactional email | EU (France/Germany, Belgium) — no international transfer for this processing |
| Cloudflare | CDN, DDoS protection, secure tunnel to our server | US/global — UK–US Data Bridge / IDTA safeguards |
| Hetzner | Server hosting (the application and database) | EU (Germany/Finland) — UK adequacy for the EEA |
| xAI | Automated image safety screening (see section 4) | US — IDTA / UK addendum safeguards |
| HMRC | Where UK digital-platform reporting rules (SI 2023/817) apply, we may be legally required to report seller identity and earnings | UK — legal obligation |
For transfers outside the UK we rely on the UK–US Data Bridge where the recipient is certified, and otherwise on the International Data Transfer Agreement or the UK addendum to the EU Standard Contractual Clauses, with transfer risk assessments where required. We do not sell personal data. Ever.
6. How long we keep it
- Account data: while your account is open, then deleted or anonymised within 90 days of closure (except records we must keep — below).
- Rejected or removed content (listings, photos, logos that failed moderation): deleted within 90 days.
- Transaction and payout records: kept 6 years for tax, accounting, and dispute-evidence purposes.
- Server and security logs: rotated within 30 days.
7. Your rights
Under UK GDPR you have the right to:
- access your personal data (a data subject access request — just email us; no special format needed);
- rectify inaccurate data;
- erase data we no longer need to keep;
- restrict or object to processing based on legitimate interests;
- data portability for data you provided to us under contract or consent;
- withdraw consent at any time, where consent is the basis.
Send any request to [email protected]. We respond within one month. If you are unhappy with how we handle your data or your request, you can complain to the UK Information Commissioner's Office: ico.org.uk/make-a-complaint or 0303 123 1113. We'd appreciate the chance to sort it out first, but you don't need our permission to go to the ICO.
8. Cookies
We set one essential session cookie so you stay signed in. That's it. No advertising cookies, no cross-site tracking, no third-party analytics cookies. Because the only cookie is strictly necessary for the service, no consent banner is required — and you won't find one.
9. Changes to this policy
If we change this policy in any meaningful way, we'll email account holders and update the date at the top. Minor clarifications may be posted without notice. See also our Terms of Service.