Privacy Policy
Last updated: 15 March 2025
At OraSpot, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our marketplace platform at oraspot.co.uk. We are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who We Are
OraSpot is a UK-based online marketplace that connects buyers with independent sellers. For the purposes of data protection law, OraSpot is the data controller for the personal data we collect through our platform.
Contact us: If you have any questions about this policy or your data, please email us at support@oraspot.co.uk.
What Data We Collect
We collect different types of personal data depending on how you interact with OraSpot:
Account Information
- ●Full name, email address, username, and phone number
- ●Password (stored securely using industry-standard hashing)
- ●Account type (buyer or seller)
Seller Information
- ●Business name, business email, business phone number
- ●Business type and social media handles
- ●VAT registration number (if applicable)
- ●Stripe Connect account details for payment processing
Order & Payment Data
- ●Delivery addresses, order history, and order status
- ●Payment amounts and transaction records (processed securely via Stripe)
- ●We do not store your full card details — these are handled entirely by Stripe
Usage Data
- ●Pages visited, products viewed, and search queries
- ●Device type, browser, IP address, and approximate location
- ●Cookies and similar technologies (see our Cookie Policy)
How We Use Your Data
We use your personal data for the following purposes:
To provide our services: Creating accounts, processing orders, facilitating payments between buyers and sellers, and delivering order notifications
To communicate with you: Order confirmations, shipping updates, delivery notifications, and seller approval/rejection notifications
To improve our platform: Analysing usage patterns, fixing bugs, and enhancing user experience
To ensure security: Preventing fraud, verifying seller identities, and maintaining platform integrity
To comply with legal obligations: Tax reporting, regulatory compliance, and responding to lawful requests
Legal Basis for Processing
Under UK GDPR, we process your data based on the following legal grounds:
Contract performance: Processing your orders, managing your account, and facilitating transactions between buyers and sellers
Legitimate interests: Improving our services, preventing fraud, and ensuring platform security
Legal obligation: Tax compliance, financial record-keeping, and responding to regulatory requirements
Consent: Marketing communications (where applicable) — you can withdraw consent at any time
How We Share Your Data
We only share your personal data when necessary:
With sellers: When you place an order, we share your name and delivery address with the seller to fulfil the order
With Stripe: We use Stripe for payment processing. Your payment data is handled according to Stripe's Privacy Policy
With Brevo: We use Brevo (formerly Sendinblue) to send transactional emails such as order confirmations and shipping updates
With Cloudinary: Product images and media are hosted on Cloudinary's CDN
With law enforcement: If required by law, court order, or regulatory authority
We never sell your personal data to third parties.
Data Retention
We retain your data for as long as necessary to provide our services and comply with legal obligations:
Account data
While active
Retained while your account is active. If you delete your account, we anonymise your personal data but retain order records for tax and legal compliance.
Order & payment records
7 years
Retained for 7 years to comply with HMRC requirements.
Usage data
Up to 24 months
Retained for up to 24 months for analytics purposes.
Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
Right of access
Download all your personal data from your account settings at any time
Right to rectification
Update your personal information through your profile settings
Right to erasure
Delete your account from your settings. We will anonymise your data and deactivate your account
Right to data portability
Download your data in a machine-readable format (JSON) from your account settings
Right to object
Object to processing based on legitimate interests by contacting us
Right to restrict processing
Contact us to request a restriction on how we process your data
To exercise any of these rights, visit your account settings or email us at support@oraspot.co.uk. We will respond within 30 days.
Data Security
We implement appropriate technical and organisational measures to protect your data:
- All data is transmitted over HTTPS with TLS encryption
- Passwords are hashed using industry-standard algorithms
- Payment processing is handled by PCI-DSS compliant Stripe infrastructure
- Access to personal data is restricted to authorised personnel only
- We conduct regular security reviews and maintain audit logs of administrative actions
International Transfers
Your data is primarily processed within the UK and EU. Where data is transferred outside the UK (for example, to service providers like Stripe or Cloudinary), we ensure appropriate safeguards are in place, including Standard Contractual Clauses or adequacy decisions.
Children's Privacy
OraSpot is not intended for children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top and, for significant changes, notify you via email or a prominent notice on our platform.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data protection rights have been violated.
Shopify integration
When a brand (“seller”) connects their Shopify store to OraSpot, we process the following data through Shopify's Admin API and webhooks:
Data we read from the connected Shopify store
- Products, variants, images, prices, tags, metafields, and stock levels — used to list the brand's catalogue on oraspot.co.uk.
- Store profile (shop name, primary domain, locations) — used to route stock and identify the connection.
- Fulfilment events on orders WE pushed — tracking number, URL, carrier, and status — used to update our own order and email the buyer.
Data we write to the connected Shopify store
- New orders — one order per OraSpot shipment routed to that seller. We do NOT modify or delete any pre-existing Shopify orders.
Data we do NOT collect from the connected Shopify store
- Customer records (buyers, order history, saved cards, etc.)
- Marketing lists, analytics, or storefront traffic
- Payment or payout data
- Staff account information
Storage and location
Shopify data is stored on servers hosted in the United Kingdom, in a private network behind Cloudflare and Caddy. The seller's Shopify Admin API access token is stored server-side only and never exposed to browsers. The connection can be revoked by the seller at any time from the OraSpot seller dashboard, or by uninstalling the OraSpot app from their Shopify admin (which fires our app/uninstalled webhook and marks the token dead within seconds).
GDPR mandatory webhooks
OraSpot receives and processes Shopify's three mandatory GDPR webhooks — customers/data_request, customers/redact, shop/redact — from every connected store. Because we do not currently pull customer records from the connected Shopify, these webhooks acknowledge receipt with no data to redact. If our processing scope changes in future, the same handlers will begin performing actual redaction.
Data-request contact: For any request relating to Shopify-integrated data, email team@oraspot.co.uk — we respond within one UK business day and have the data returned or deleted within 30 days.