Company Logo

Privacy Policy

Last updated: July 2025

This Privacy Policy explains how TRUZH collects, uses, shares, and protects your personal data.

1. Controller Information

TRUZH (operated by [Your Legal Entity]) is the data controller.

Contact: contact@truzh.com

Address: [Your company address in Spain]

DPO: [Name], email: dpo@truzh.com

2. Data We Collect & Why

Data CollectedPurposeLegal Basis (GDPR Art. 6)
Account info (name, email, profile)Account creation, login, identity verificationPerformance of contract (GDPR Art. 6(1)(b))
Listings & transactionsMarketplace functioning, chat, order coordinationPerformance of contract (6(1)(b)); legitimate interest (6(1)(f))
Payments & billing dataProcessing purchases (card/cash)Performance of contract (6(1)(b)); legal obligation (6(1)(c))
Usage analytics & cookiesImprove service, personalizationConsent (6(1)(a)); legitimate interest (6(1)(f))
Support messagesCustomer service & dispute resolutionLegitimate interest (6(1)(f))
Legal thresholds (DAC7 reporting)Tax compliance for high-volume sellersLegal obligation (6(1)(c))

3. How We Use Cookies & Tracking

We use:

  • • Strictly necessary cookies: essential for login and site operation
  • • Analytical cookies: track usage to optimize performance
  • • Advertising cookies: support marketing, only with consent

Full details appear in our Cookie Policy. You can accept/decline via our consent banner.

4. Sharing Your Data

We may share your data with:

  • • Payment providers (e.g. Stripe, PayPal) for processing
  • • Service providers (hosting, analytics, email delivery)
  • • Tax authorities under EU DAC7 where required
  • • Legal or regulatory bodies if required by law

5. Your Rights (GDPR)

You may:

  • • Access, correct, or delete your data
  • • Restrict or object to processing
  • • Request data portability
  • • Withdraw consent anytime

Requests via: contact@truzh.com or DPO email. You may also file complaints with the Spanish Data Protection Agency (AEPD).

6. Data Retention

  • • Account & listing data: retained until account deletion
  • • Support/chat logs: up to 2 years
  • • Legal/tax records: up to 10 years as legally required

7. International Transfers

Data stays within the EEA. If transferred elsewhere, we ensure GDPR-compliant safeguards (e.g., Standard Contractual Clauses).

8. Security Measures

We use encryption (HTTPS), secured servers, access controls, and staff training to safeguard your data.

9. Policy Updates

We may update this policy. We’ll notify changes via email or app where appropriate. Continued use means acceptance.