Privacy Policy
Last updated: August 16, 2026 · Version 2.1 · We keep this policy plain-spoken. If something is unclear, write to privacy@tovora.example.
01What we collect
Only what the marketplace needs to run: your name, email and shipping address when you order; payment details (processed by Stripe and PayPal — we never see your full card number); order and browsing history; messages you send to sellers or support; and device data like language, currency and screen size so the site works properly.
Sellers additionally provide business verification documents, tax IDs and payout bank details. We do not sell personal data to anyone, ever.
02How we use it
- To fulfil orders, process payments, deliver the gopora Buyer Promise and keep you informed about delivery.
- To keep the marketplace safe: fraud screening, sanction checks and counterfeit detection.
- To personalise what you see — recommendations, recently viewed items and your saved lists.
- To comply with tax, customs and anti-money-laundering law.
- To improve the product — aggregated, anonymised analytics only.
03Legal bases (GDPR)
Where GDPR applies, we process your data on these bases: contract performance (orders and payments), legal obligation (tax, fraud law), legitimate interest (security, aggregate analytics, platform improvement) and consent (marketing emails, non-essential cookies). You can withdraw consent at any time without affecting the parts of the service that still need your data.
05International transfers
gopora is a global marketplace, so data moves between regions. Transfers out of the EEA/UK use the EU Standard Contractual Clauses (and the UK addendum) or rely on adequacy decisions. You can request a copy of the relevant safeguards at any time.
06How long we keep it
Account data: while your account is open. Order and payment records: 7 years (tax law), then deleted or irreversibly anonymised. Messages: 2 years, unless a dispute is open. Marketing consent: until you withdraw it.
07Your rights
Under GDPR you may access, correct, delete, port or restrict your data, and object to processing. Under CCPA you may request the categories and specific pieces of data we hold, and opt out of the sale of your data — which we don’t do anyway. To exercise any right: privacy@tovora.example. We answer within 30 days, usually much faster, and never charge.
Complaints: you can also contact your local data-protection authority (e.g. the ICO in the UK, CNIL in France, BfDI in Germany) or the EU supervisory authority of your residence.
08Security
All traffic is encrypted in transit (TLS 1.3), card data never touches our servers, and access to personal data is role-limited and audited. If a breach ever puts your data at risk, we’ll tell you and the authorities within 72 hours of discovery, as required.
Data protection officer: dpo@tovora.example · gopora Inc., 88 Market Street, Wilmington, DE 19801, USA · EU representative: gopora B.V., Herengracht 280, Amsterdam, NL.