Privacy Policy
Last updated: March 6, 2026
🔒 GDPR Compliant • Your Privacy Matters • Transparent Data Practices
Privacy at a Glance
📊
Data Minimization
We collect only what's necessary
🔐
Strong Security
Enterprise-grade protection
🇪🇺
GDPR Rights
Full control over your data
Trusted Third-Party Services
| Service | Purpose | Location | Compliance |
|---|---|---|---|
| Stripe | Payment Processing | United States | GDPR, PCI DSS |
| Supabase | Database & Authentication | United States | GDPR, SOC 2 |
| Vercel | Hosting & Analytics | United States | GDPR |
1. Introduction
AuctionXFlow ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our educational platform. We comply with the General Data Protection Regulation (GDPR) and other applicable privacy laws.
2. Information We Collect
We collect information you provide directly to us, including:
• Account Information: Name, email address, password
• Profile Information: Trading experience level, learning goals
• Payment Information: Processed securely by Stripe (we do not store full payment details)
• Usage Data: Course progress, simulation results, interaction patterns
• Communications: Support requests, feedback, survey responses
3. Automated Data Collection
We automatically collect certain information when you use our Platform:
• Device Information: IP address, browser type, operating system
• Usage Information: Pages visited, features used, time spent
• Cookies and Similar Technologies: To enhance user experience and analyze platform performance
• Analytics: We use Vercel Analytics for platform optimization
4. How We Use Your Information
We use your information to:
• Provide and maintain the Platform
• Personalize your learning experience
• Process payments and manage subscriptions
• Send important updates and educational content
• Improve platform features and develop new ones
• Ensure platform security and prevent fraud
• Comply with legal obligations
5. Data Sharing and Third Parties
We share your information with trusted third-party service providers:
• Stripe: Payment processing (GDPR compliant)
• Supabase: Database and authentication (GDPR compliant)
• Vercel: Hosting and analytics (GDPR compliant)
• Email Service Providers: Transactional and marketing communications
We do not sell your personal information to third parties. We may disclose information if required by law or to protect our rights.
7. Data Security
We implement appropriate technical and organizational measures to protect your information:
• Encryption of data in transit and at rest
• Regular security assessments and updates
• Access controls and authentication mechanisms
• Secure payment processing through Stripe
While we strive to protect your information, no security system is impenetrable.
8. Data Retention
We retain your information for as long as necessary to:
• Provide the services you requested
• Comply with legal obligations
• Resolve disputes and enforce agreements
• Maintain business records
You may request deletion of your information as described in Section 10.
9. Your Rights (GDPR Compliance)
Under GDPR, you have the right to:
• Access your personal information
• Correct inaccurate information
• Delete your information (right to be forgotten)
• Restrict or object to processing
• Data portability
• Withdraw consent at any time
To exercise these rights, contact us at privacy@auctionxflow.com.
10. Account Deletion and Data Removal
You may delete your account at any time through your account settings or by contacting us. Upon deletion:
• Your personal information will be removed from our active databases
• Some information may be retained for legal or legitimate business purposes
• Anonymized usage data may be retained for analytics
Deletion requests are processed within 30 days.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including:
• Standard Contractual Clauses approved by the European Commission
• Privacy Shield certification for US-based providers (where applicable)
• Data processing agreements with all third-party providers
12. Children's Privacy
Our Platform is not intended for children under 16. We do not knowingly collect information from children under 16. If we become aware that we have collected information from a child under 16, we will take steps to delete such information.
13. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or through the Platform. The "Last Updated" date at the top indicates when changes were made.
14. Contact Us
For questions about this Privacy Policy or to exercise your privacy rights, contact us at:
AuctionXFlow Privacy Team
privacy@auctionxflow.com
Data Protection Officer: dpo@auctionxflow.com
Exercise Your Privacy Rights
Your Trust is Our Priority
We are committed to transparent data practices and protecting your privacy. If you have any concerns or questions about how we handle your information, please don't hesitate to contact our Privacy Team.
This Privacy Policy applies to AuctionXFlow educational platform only. We regularly review and update our privacy practices to ensure compliance with evolving regulations and best practices.