Privacy policy
[FORMA JURIDICA][CUI][ADRESA][EMAIL][DE VERIFICAT JURIDIC: art. 37 GDPR și Legea 190/2018; codul fiscal al vânzătorilor îl prelucrăm pe temei de obligație legală, nu de interes legitim][DE VERIFICAT JURIDIC: termenul contabil și fiscal, 5 sau 10 ani][DE VERIFICAT JURIDIC: termenul din Codul fiscal pentru evidențele DAC7][DE VERIFICAT JURIDIC: regiunea de prelucrare și certificarea DPF a celor doi furnizori pentru aceste servicii][DE VERIFICAT JURIDIC: mecanismul de transfer, DPF sau clauze standard]
This page explains what data about you reaches us when you use Secondaro, what we use it for, how long we keep it and what you can ask for. We wrote each thing once, in a table, so you can quickly find what interests you.
1. Who is responsible for your data
The data controller, within the meaning of Regulation (EU) 2016/679 (GDPR), is Monea Software [FORMA JURIDICA], [CUI], [ADRESA], Romania, which runs the Secondaro platform (seconda.ro). For any question about your data write to [EMAIL]. We answer within 30 days at most.
At our current size we are not legally required to appoint a data protection officer (DPO) [DE VERIFICAT JURIDIC: art. 37 GDPR și Legea 190/2018; codul fiscal al vânzătorilor îl prelucrăm pe temei de obligație legală, nu de interes legitim]. The contact person for data matters is at the address above.
2. In short: what we do not do
- We do not sell data and do not give it to advertising companies.
- We have no third-party adverts and use no tracking cookies. The only cookies are the strictly necessary ones described in the Cookie policy.
- We do not see or store your card number: payment happens in the payment provider's form.
- We do not keep a copy of your identity document: identity verification is done by the payment provider.
- We do not read your messages unless one of you asks us to settle a problem or the law requires it.
- We make no automated decisions with legal effect on you. Automated programs only check the form of a listing and the photos on upload; decisions are made by a person.
3. What data we keep, why, on what basis and for how long
The legal bases (GDPR, Article 6) are: the contract with you (the service you ask for when you create an account, sell or buy), a legal obligation (tax, accounting, anti-money-laundering, DSA), our legitimate interest (platform safety, fraud prevention, moderation) and, where stated, your consent, which you can withdraw at any time.
| The data | What it is used for | Basis | How long we keep it |
|---|---|---|---|
| Email address, password (only its hash, not the password), display name, language, country, date of birth | the account: login, notifications, checking the age of 18 | contract | as long as the account exists |
| The 6-digit code sent by email (only its hash) | confirming the address, new password | contract | 24 hours |
| Phone (optional), profile photo (optional), profile description | contact for delivery, public profile | contract; consent for the photo and description | until you delete them or delete the account |
| Delivery addresses | orders, shipping labels | contract | until you delete them or delete the account; on closed orders, as long as we keep the order |
| Listings: title, description, photos, category, condition, price, country and city | selling; search; automatic translation of the title and description | contract | until you delete them; sold listings as long as we keep the order |
| Orders: items, amounts, protection fee, shipping, statuses, deadlines, parcel tracking, problems and decisions | fulfilling the order, Buyer Protection, accounting records | contract; legal obligation | 5 years from the end of the year the order was made [DE VERIFICAT JURIDIC: termenul contabil și fiscal, 5 sau 10 ani] |
| Payment: the payment and refund identifiers at the payment provider, amount, currency, last 4 digits and type of card (shown by the provider) | collecting, refunding, disputes with the bank | contract; legal obligation | as long as we keep the order |
| Your payment account (sellers): the account identifier at Stripe, verification status, country, currency | paying out the money from sales | contract; legal obligation (anti-money-laundering) | as long as the account exists, then 5 years |
| Tax details (sellers): legal name, tax number (CNP or TIN), country of tax residence, date of birth, address, IBAN (at the payment provider), number of sales and amounts per year | DAC7 reporting to ANAF | legal obligation | at least 5 years from the reporting year, including after the account is deleted [DE VERIFICAT JURIDIC: termenul din Codul fiscal pentru evidențele DAC7] |
| Business details (Pro sellers): name, tax number, Trade Register number, address, contact, declaration of conformity | shown on the listing, as the law requires | legal obligation (DSA art. 30; Omnibus directive) | as long as the account is Pro, then 5 years |
| Messages and offers: text, time, detected language, automatic translation (kept so we do not translate twice) | the link between buyer and seller; negotiation | contract | until you delete the conversation or the account; the translation as long as the message |
| Problems opened on orders and reports: reason, text, photos, replies, the decision and its reasons | Buyer Protection; moderation; proof of decisions | contract; legitimate interest (platform safety) | 3 years from the decision |
| Reviews: rating, text, transaction | trust between users | contract | as long as the transaction exists; on account deletion they stay without a name |
| Favourites, followed sellers, saved searches, notification settings | personalising the feed and notifications | contract | until you delete them or delete the account |
| Sessions: hash of the login token, device (browser), IP address, last use | staying logged in; seeing and removing devices from the account | contract; legitimate interest (security) | 30 days from login or until you log out |
| Technical server logs: IP address, time, page requested, browser | server safety, limiting abuse, debugging | legitimate interest | 30 days |
| Acceptance of the terms: version, date and time, IP address | proof that you accepted the terms | legal obligation; legitimate interest | as long as the account exists, then 3 years |
4. Automatic translation
Listing titles and descriptions and messages between users are translated automatically into the reader's language. For this we send only the text (without your name, email address or account identifier) to Microsoft's translation service (Azure); as a fallback, when it does not respond, to Google Cloud Translation. The translation is kept with us, linked to the message, so we do not request it twice. The language of a message is detected on our own server, without outside companies.
Do not write in messages data you do not want a translation service to see (card numbers, documents). They are not needed for the transaction anyway.
5. Photos
Listing photos and the profile photo are resized on our server and saved in three sizes. On upload, an automated program on our own servers checks them for content that is not allowed (nudity, violence); a rejected photo is not published and you get the reason. Hidden file data (where the photo was taken, the device) is removed from the photos.
You do not upload photos of other recognisable people without their consent. If you appear in a photo without consent, report it and we remove it quickly.
6. Who we share data with
We give data to no one for their own purposes. Data reaches providers who work for us, under our instructions, and the other party of the transaction, as much as they need:
- The other party of the order: the seller sees the buyer's display name, delivery address or pickup point and phone (for the shipping label); the buyer sees the seller's display name, city and country, and for Pro sellers the business details.
- Stripe (Stripe Payments Europe, Ltd., Ireland, with Stripe, Inc., USA): collecting payments, refunds, sellers' payment accounts, identity verification (you upload your identity document there, not with us). Stripe is certified under the EU-US Data Privacy Framework (DPF) and uses the standard contractual clauses as a fallback.
- The couriers: Sameday, FAN Courier, Cargus (Romania) and Packeta (international), depending on the one chosen at the order: name, phone, address or pickup point of the sender and of the recipient, weight and class of the parcel.
- Microsoft (Azure, translation service) and, as a fallback, Google (Cloud Translation): the text to translate, without identifying data. We ask for processing in the Europe region where the service allows it [DE VERIFICAT JURIDIC: regiunea de prelucrare și certificarea DPF a celor doi furnizori pentru aceste servicii].
- Resend (Resend, Inc., USA): sending account and order emails (email address, email content) [DE VERIFICAT JURIDIC: mecanismul de transfer, DPF sau clauze standard].
- Hetzner Online GmbH (Germany): the servers, the database and photo storage, in the European Union.
We give data to authorities (ANAF for DAC7, ANCOM, ANPC, police, courts) only when the law requires it or when a legal request compels us. On signs of a serious crime we inform the authorities, as the DSA requires.
7. Where the data is stored
The servers and the database are in Germany, in the European Union. Stripe, Microsoft, Google and Resend are companies based in the United States: the transfer is made under the EU-US Data Privacy Framework (DPF) or, as a fallback, under the European Commission's standard contractual clauses. On request we give you a copy of the safeguards.
8. Your rights
You have the right to ask for: access to your data, its correction, erasure, restriction of processing, portability (a copy in a machine-readable format) and to object to processing based on legitimate interest. Consent (profile photo and description, optional notifications) can be withdrawn at any time from Settings, without affecting what was done before.
How you exercise them, without writing to us: from Settings you can correct your data, download a copy of it ("Your data", JSON file) and delete the account. For the rest, write to [EMAIL]; we answer within 30 days at most. So that we do not give your data to someone else, we may ask you to confirm from your account or from the account's email address.
9. Deleting the account
From Settings, "Delete account": you confirm with your password and the account is deleted at once. If you have orders in progress, deletion waits until they are closed (you or the other party have money or parcels in motion). If you no longer have access to the account, write to us from the account's email address and we delete it within 30 days at most.
What disappears
- Email address, password, name, photo, phone, date of birth, addresses, sessions, codes, favourites, follows, saved searches, settings.
- Your active listings and their photos.
- The link between you and your messages, reviews and orders: they remain for the other party, but without your name ("deleted user").
What remains, because the law requires it
- DAC7 tax details and business details, for as long as the law requires (see the data table).
- Orders, payments and refunds, in the accounting records, without your profile.
- Problems, reports and moderation decisions, 3 years, as proof.
- Technical logs, until they expire (30 days).
The email address is released: another account can be created with it.
10. Minimum age
Secondaro is for people aged at least 18: an account means sales contracts and payments. We ask for the date of birth at sign-up and do not knowingly process minors' data. If we learn that an account belongs to a minor, we close it and delete the data. Parents can write to us at [EMAIL].
11. Security
All connections are encrypted (HTTPS). Passwords are kept only as a hash, through a one-way function. Login tokens are kept hashed. The tax number and the other tax details are stored encrypted in the database and shown masked. Access to the database is limited to those who administer the platform. After 10 wrong passwords in 15 minutes, login is blocked for a while. If a security breach that concerns you occurs, we inform you as the law requires.
13. Complaints
If you believe we have not complied with the law, write to us first at [EMAIL]. You can also complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, www.dataprotection.ro, or to the data protection authority of your own European Union country.
14. Changes
When we change something in this policy, we change the date at the top and, for important changes, we tell you in your account and by email before they take effect. Old versions are available on request.