Draft — pending legal review

Privacy Policy

Operated by ECOMFORWARD LLC · Effective 1 July 2026

1. Controller

ECOMFORWARD LLC operates EcomFlips and is the controller for personal data processed on the platform. Contact: privacy@ecomflips.co.

2. What we process, and why (lawful bases)

  • Account data (email, name, country, sign-in events) — to provide the service (contract, Art. 6(1)(b) GDPR).
  • Listing and transaction data (listing details, financial figures, offers, agreement acceptances with timestamp and IP, checklist confirmations, escrow status) — contract performance and our legitimate interest in a reliable, evidenced marketplace (Art. 6(1)(b), (f)).
  • Deal-room messages — contract performance; messages are scanned automatically for contact details to enforce platform rules (legitimate interest, Art. 6(1)(f)); flagged messages are reviewed by our team.
  • Audit records — legitimate interest and legal obligations: state transitions and platform actions are kept as an append-only record for dispute resolution and fraud prevention.
  • Transactional email (via Resend) — contract performance. We log sent notifications.

3. Escrow.com

Payments and KYC happen directly with Escrow.com, an independent controller. We share the deal parties' email addresses and the transaction parameters with Escrow.com to create the escrow transaction, and we receive transaction status updates. Escrow.com's own privacy policy governs their processing.

4. Anonymity between users

Public listings and deal rooms show anonymized handles (e.g. “Seller #S-1042”), never names or emails. Identity is disclosed to the counterparty in the course of the escrow transaction, as described in the Transaction Agreement.

5. Storage, hosting, and retention

  • We aim to host EU user data in the EU where practical; current infrastructure: managed Postgres and hosting on EU regions where available.
  • Transaction, agreement, and audit records are retained for as long as needed for legal claims and bookkeeping obligations, then deleted or anonymized.
  • Accounts inactive for extended periods may be anonymized on request or per retention schedule.

6. Your rights

You have the rights of access, rectification, erasure, restriction, portability, and objection under GDPR. Email privacy@ecomflips.co — we export or delete your data on request, except records we must keep (e.g. transaction and audit records tied to executed deals). You can lodge a complaint with your supervisory authority.

7. Cookies

EcomFlips uses only strictly necessary cookies: session authentication and CSRF protection. We set no analytics, advertising, or other non-essential cookies, and nothing non-essential is set before consent. If that changes, we will ask for consent first.