B. Privacy Policy

Thank you for using Spondise Marketplace ("the Platform"). This Privacy Policy is designed to help you understand how we collect, use, and safeguard your personal information.
It also outlines the choices you have regarding your information.
This Privacy Policy aims to fully conform with the General Data Protection Regulation (GDPR).

This Privacy Policy applies to all users of the Platform, including Creators, Sponsors, Visitors, Team Members, and any other user roles.

The latest update to this Privacy Policy was made on: 01. December 2024.
We may update this Privacy Policy periodically. We will notify you of significant changes through email or by prominently posting a notice on the Platform.

Account Information: We collect details such as your name, email address, phone number, postal address, date of birth, and profile photo when you create an account. Additional data may depend on the features you use.
Listing Information: Includes details about products, services, and other data users share in public listings.
Files Provided: Uploaded and stored files on the Platform.
Verification and Payment Details: Including government-issued IDs, selfies for verification, and bank/payment account details.
Additional Profile Information: Information such as gender, preferred language(s), city, and personal descriptions may be publicly visible based on your account settings.
Information About Others: Data related to a payment instrument owned by another user or others, provided with their permission.
Other Information: Includes data provided in forms, surveys, promotions, support interactions, and other user activities.
Legal Basis for Processing: We process personal data based on the necessity to perform a contract (Article 6(1)(b) GDPR) or based on the user’s consent (Article 6(1)(a) GDPR). When we process sensitive personal data, such as government-issued IDs or payment details, we do so based on legal obligations (Article 6(1)(c) GDPR) or explicit consent (Article 9(2)(a) GDPR).

Payment Details: To facilitate transactions, we collect payment information (e.g., credit card and bank details) and may transfer this data to third-party providers like Stripe. Spondise's Finance Policy applies.
Data Minimization and Security: We ensure that the payment information collected is limited to what is necessary to process transactions, and we employ appropriate security measures in line with Article 32 of the GDPR to protect such data.

Log Data: Information such as IP addresses, browser type, and device information about Platform usage.
Data Retention and Usage: Personal data collected through usage information is retained only as long as necessary for the purposes specified and is used in accordance with Article 6(1)(f) GDPR (legitimate interests) to analyze and improve our platform’s functionality.

Content of Communications: Messages exchanged between Creators and Sponsors are stored and may be accessed by Team Members to resolve support cases.

Geolocation Information: Precise or approximate location data, depending on device settings.
Usage Data: Pages visited, searches performed, and other actions taken on the Platform.
Device Information: Includes hardware, software, IP address, and crash data.
Cookies and Similar Technologies: Used for analytics and improving the user experience.
Payment Transaction Data: Information such as payment method, amount, and transaction timestamps.

Third-Party Services: Data from linked services (e.g., Google, Facebook). If Users link, connect, or log in to the Spondise Platform using a third-party service (such as Google, Facebook, or Instagram), they authorize the service to send Spondise information like their registration details, friends list, and profile information, as controlled by that service or as permitted by their privacy settings.
Enterprise Product Invitations and Account Management: Organizations utilizing Spondise's Enterprise products may provide personal information to streamline account management and send invitations for the use of enterprise-level products.
Referrals and Invitations: Personal information shared to send invitations.
Other Sources: Subject to applicable legal provisions, Spondise may receive additional information from third-party service providers and partners to help with tasks such as fraud detection and safety assessments. This could include references, demographic data, or alerts related to fraud. Spondise may also receive information about the User's activities on and off the platform, as well as insights into their experiences and interactions from its partners.

Facilitate transactions and communication between Creators and Sponsors.
Generate user contracts (Sponsor and Creator Contracts).
Personalize and improve the Platform.
Ensure the security and integrity of the Platform.
To protect against fraud, abuse, and unauthorized access to Spondise's services.
Comply with legal obligations and respond to requests.
Authenticate and verify user information.
Enforce the platform's Terms and other policies.
Send updates, newsletters, and marketing materials.
To establish API linkings to/from social media as per their privacy policy.
In cases where Users provide contact information of friends or acquaintances, Spondise may process this data for purposes such as facilitating referral invitations, preventing fraud, and responding to authorized requests.
Resolve disputes with Spondise Users, which may include sharing information.
Resolve disputes and enforce agreements.
Evaluate User interactions with the Spondise Platform and information obtained from third parties. In rare instances, automated processes may restrict or suspend User access if they detect activities that pose a safety or other risk to Spondise, its community, or third parties. Users who wish to challenge decisions based on automated processes can contact Spondise.
Lawful Basis for Processing: The processing of personal data is carried out based on the necessity for performance of a contract (Article 6(1)(b) GDPR), legitimate interests (Article 6(1)(f) GDPR), legal obligations (Article 6(1)(c) GDPR), or user consent (Article 6(1)(a) GDPR).

Send promotional messages and personalized advertisements.
Personalize, measure, and enhance advertising efforts.
Administer referral programs, rewards, surveys, sweepstakes, contests, and promotional activities.
Analyze User characteristics and preferences to deliver targeted promotional messages and advertisements.
Extend invitations to events and relevant opportunities.
Send promotional messages and marketing materials based on User preferences, with consent.
Marketing Consent: We will only send marketing communications based on user consent (Article 6(1)(a) GDPR), which can be withdrawn anytime.

Users can link their Spondise account with third-party services, such as social networks.
Information shared through these links may be publicly displayed on the User's profile.
User activities on Spondise may be visible to their Friends on both Spondise and third-party services.
A link to the User's public profile on third-party services may be integrated into their Spondise profile.
Other Users may view common Friends and shared affiliations like schools or groups.
Information shared through these links may be used for fraud prevention, security investigations, and risk assessment.
Information display depends on the User's settings and authorizations on both platforms.
Users typically have the opportunity to view and control the data fields accessed during account linking.

Personal information is used to enable or facilitate third-party Payment Services.
Detect and prevent money laundering, fraud, abuse, and security incidents through risk assessments.
Comply with legal and regulatory obligations, including anti-money laundering regulations.
Enforce Payment Terms and related policies.
Provide and improve Payment Services in accordance with Spondise's Finance Policy.
Processing of Payment Information: Payment-related personal data is handled in accordance with GDPR’s Article 6(1)(b) (contract performance) and 6(1)(c) (legal compliance).

Other Users: Information necessary for transaction and communication.
Service Providers: Third-party services assisting in the operation of the Platform.
We may share your information when required by law, regulation, legal process, or government request.
In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of the transaction.

To facilitate transactions or other interactions between Users, especially when they are located in jurisdictions with varying levels of data protection, information may be shared in the following situations:
Between Sponsors, Creators, and Spondise Team Members
When an offer is made or a dispute is submitted, information such as partial or fully profile details, name, cancellation history, review information, user-provided feedback, and any other information voluntarily shared and submitted.
Upon confirmation of an offer, additional details may be shared to assist with coordinating the interaction, including some profile information and information retrieved from connected social media links.
When a Sponsor has a confirmed offer, specific information is shared with the Creator to facilitate the transaction. This may include the partial or full Sponsor's profile, full name, and the address of the listed item.
Communication with Spondise Team Members
When Users communicate with each other, information shared may include names, profile pictures, and the content of messages.
Personal messages, content voluntarily shared and submitted via chat, and any technical data required for the functionality of chat and ticket features.

Users have the option to make certain information publicly visible to others on the Spondise Platform. This includes:
Public Profile Page: Users can maintain a public profile page that displays information such as their profile photo, first name (or initials where applicable), a brief description, linked social media statistics, country, language preferences, general statistics, and nearest city. This page is part of their Spondise account. Privacy and visibility settings for the public profile page may have limited or no customization options.
Listing pages may include information such as an approximate or precise location description of the Sponsor or Creator, profile photo, uploaded files, multimedia content, links to the public profile page, aggregated metrics (e.g., page views over time), and any additional details the Users choose to disclose.
Users can submit and view publicly accessible information, such as reviews, ratings, completed contracts, links to relevant listings, and other feedback. These contributions are visible to all users and visitors on the platform.
Content in Community or Discussion Spaces: Any content shared in public spaces, such as forums, blogs, feedback forms, reviews, or social media posts hosted on or linked to the Spondise Platform, may be visible to other users and the public.
Portions of the public profile or other publicly shared content, such as listing details, may be displayed on third-party websites, platforms, or applications to enhance visibility and reach.platforms, or applications to enhance visibility and reach.
Indexing by Search Engines: Publicly shared information on the Spondise Platform may be indexed by third-party search engines, making it discoverable through internet searches.

Spondise shares personal information with both affiliated and unaffiliated service providers, as well as their service providers, to facilitate various aspects of its business operations. These collaborations serve multiple purposes, including:
Identity Verification: Verifying User identity and authenticating identification documents.
Database Checks: Checking information against public databases.
Security Measures: Conducting background checks, fraud prevention, security investigations, and risk assessments.
Product Development and Maintenance: Performing product development, maintenance, and debugging.
Integration with Third-Party Platforms: Enabling the provision of Spondise Services through third-party platforms and software tools, such as through API integration.
Customer Service, Advertising, and Payments Services: Providing customer service, advertising, and payment services.
Additional Services: Offering additional services selected by Users.
Communication Review: Reviewing, scanning, and analyzing communications on the Spondise Platform for specific purposes, such as evidence of child exploitation (refer to the Analyzing and Sharing Your Communications section for additional details).

In the event that Spondise engages in a merger, acquisition, reorganization, sale of assets, bankruptcy, or insolvency event, the company may sell, transfer, or share some or all of its assets. This includes the potential transfer of the User’s information in connection with such a transaction or during the phase preceding it. Should such a scenario occur, Spondise commits to notifying the Users affected before the personal information is transferred and becomes subject to a different privacy policy.

If your personal data is transferred outside of the European Economic Area (EEA), we ensure that appropriate safeguards are in place to protect your information in accordance with the GDPR, such as using Standard Contractual Clauses (Article 46 GDPR).