World for Sale · Legal
Privacy policy
What we need to run World for Sale, what becomes public, and the choices you have.
Updated
Who is responsible
Aleksei Petukhov, Individual Entrepreneur (Einzelunternehmer), Plievierpark 10, 81737 Munich, Germany, is responsible for the processing described here for World for Sale at worldsale.io. Email pekkipodev@gmail.com for privacy requests. Our Legal notice includes telephone and postal contact details.
Data used to provide the service
- Listings: product or channel name, destination, category, benefit, description, logo, saved preview image and selected boards; placement totals, provenance and history. Public maker attribution is shown when supplied for that purpose.
- Guest access: placing a product can create a pseudonymous Supabase guest identity and authentication cookies without a public signup. These secure private order access. A guest identifier is not proof of ownership of an unrelated product.
- Transactions: confirmation email, billing and tax information where required, order and Stripe references, amounts, payment/refund status, accepted contract text and early-service choice. Invitation eligibility and credit are recorded separately from paid money.
- Requests and correspondence: name and contact details, contract or listing reference, declaration, requested timing, receipt timestamp, delivery status and operator decisions. Illegal-content notices include a reason and good-faith declaration; a legally permitted child-abuse notice can omit contact details.
- Technical and security information: request time, network address and device/request details processed by the site and its providers. Abuse prevention can use a keyed hash of a network address and durable attempt counters. A hash may still be personal data.
Do not include sensitive personal information in public listings or send passwords, full card numbers or private access links in support messages. Required transaction and request fields are marked in the form; without them we may be unable to provide or acknowledge the requested service. Browsing does not require a purchase or an account.
Why we process data
We process listing, access and transaction data to carry out your requested service and contract (Article 6(1)(b) GDPR). Accounting, consumer declarations and legally required notice handling may require processing under Article 6(1)(c). Necessary security, fraud prevention, aggregate click measurement and proportionate dispute handling serve our legitimate interests in operating and protecting the service (Article 6(1)(f)). Optional session counting and PostHog analytics use consent (Article 6(1)(a)). You may object to processing based on legitimate interests.
We do not sell personal data or use submitted content to train AI models. Analytics consent is voluntary and does not affect your ability to browse, place a product or exercise a right.
Public listings and saved previews
Published names, descriptions, images, destination links and placement standings are public and may be copied, shared, cached or indexed elsewhere. Billing details, contract emails, private order links and reporter identities are not part of the public listing. Country choice is symbolic placement and does not disclose or verify your location.
When preview generation is enabled, our server sends a submitted public website URL to ScreenshotOne to create an image. For supported YouTube and TikTok links, it requests public metadata and thumbnails from those services and their image hosts. The destination and its public content can contain personal data. We store the resulting image and serve that saved copy through World for Sale; the preview does not load an interactive social embed in each visitor’s browser.
Following a product link leaves World for Sale. The independent site or platform then receives your request under its own privacy practices. Local fonts and map geometry do not require a third-party font or map request.
Product click totals
The outbound counter stores a cumulative count for each product and its first and latest count times. The counter itself does not store visitor identities, IP addresses or a browsing history, and sets no tracking identifier. Clicks are not unique people or purchases. Hosting and security infrastructure can still receive technical request data; this aggregate counter is separate from optional PostHog analytics.
Browser storage and optional analytics
Necessary browser storage supports guest authentication, private order access, requested browsing context, saved records and your privacy choice. Blocking or clearing it can remove saved context or guest access. Contact us if you need help with a contract after losing access.
Where configured, PostHog EU Cloud measures selected public page views and interactions: map/list changes, country/category choices, product previews and outbound clicks, and starting a placement. Search events include query length and result count, not the words you entered. Analytics stay off until you choose Allow analytics. Reject analytics and Turn analytics off are available in Privacy settings on the map and legal pages. We honor detected Do Not Track and Global Privacy Control signals by keeping this collection off.
Events include a route family, environment, temporary pseudonymous identifiers and limited product/board fields. We exclude email, payment details, form text, full URLs and query strings. Account, checkout, request, admin and other private pages are excluded. Screen recording, automatic interaction capture and person profiles are disabled. The SDK keeps its identifiers in page memory, without persistent analytics cookies or identifiers. PostHog receives the network request; suppressing IP fields in events does not mean its infrastructure never receives an IP address.
We save your choice with the notice version, time and expiry in this browser for at most 180 days. Expired or older unversioned permission cannot authorize collection. We ask again for a materially changed consent notice. Withdrawing stops future collection; it does not delete earlier events or make earlier lawful processing unlawful. Make your choice separately on other devices.
With your permission, we also count visits to the public map and product pages. A random browser session identifier groups refreshes and tabs; it expires after 30 minutes of inactivity or 24 hours. It is removed when you turn analytics off or when we next observe an expired choice. The server stores only a hash for duplicate prevention, removed after 25 hours by scheduled maintenance, and an aggregate visit total. Separate security hashes limit repeated submissions for one hour. We do not attach these counters to accounts, products or browsing history. These sessions are not unique people and exclude visitors who decline analytics or send a detected privacy signal. Aggregate totals remain.
Strictly necessary storage serves the function you request under section 25(2) TDDDG; optional storage or access requires permission under section 25(1). The control states when optional analytics are disabled in the current environment.
Service providers and recipients
- Vercel: connected website hosting and delivery, including technical request and security information.
- Supabase: connected database, file storage and guest/administrative authentication. The configured project region is eu-west-1.
- Stripe: checkout, payment records, billing/tax information, refunds and payment disputes.
- Resend: transactional email delivery when configured, using the recipient address and message contents.
- PostHog: optional consent-based usage events sent to the EU Cloud endpoint.
- ScreenshotOne: server-side website image generation from the public destination URL when enabled.
- Google/YouTube and TikTok: server-side public metadata and image retrieval for supported previews.
- Google Gmail: support, privacy requests and other messages sent to our contact mailbox.
Providers may act as processors or, for some purposes such as payment compliance, independent controllers. Their subprocessors and support operations can involve countries outside the EEA. An EU endpoint or storage region is not a guarantee that every processing operation stays in the EU. Applicable transfers require an adequacy decision or appropriate safeguards, such as standard contractual clauses.
The complete provider agreement and transfer-safeguard inventory is still being verified. This notice does not claim that every agreement or setting has been verified. Contact pekkipodev@gmail.com for the arrangements applicable to your data. We may also disclose necessary information when required by law, to address a payment dispute or to protect rights and safety.
Retention and deletion
Listings and saved images remain while needed for the published service. Orders, accepted terms and contribution history remain as needed to fulfill the contract, handle refunds and preserve accurate records. Notices, support and correspondence remain for their handling, evidence and any applicable legal claims. Financial records are kept for the statutory period applicable to the record. Security and rate limit data are limited to their protection and investigation purpose. These are purpose-based retention criteria, not a promise that an automatic deletion schedule has been implemented for every record.
The privacy-choice record expires after at most 180 days; this does not set PostHog’s event retention. Its event period depends on the active provider plan, and the current project period has not yet been verified. See PostHog’s storage and deletion information. We cannot yet state verified deletion periods for all provider logs, email copies and backups. You can request details or deletion from us; we will explain what must remain and why.
Removing a public listing does not immediately erase backups, legally required records or copies made by third parties. Clearing local browser data does not submit a connected deletion request.
Your rights and complaints
Subject to the GDPR’s conditions, you may request access, correction, erasure, restriction and portability, object to processing based on legitimate interests and withdraw consent. Email pekkipodev@gmail.com. We may ask for proportionate identity information and respond within one month, or explain a lawful extension within that period.
You may ask for human review of a moderation or access decision. We do not use solely automated decisions with legal or similarly significant effects. You may complain to a competent supervisory authority, including the Bavarian Data Protection Authority (BayLDA).
Changes to this notice
The date above identifies this notice. We update it when the service or data practices change and seek fresh permission where required. Contact pekkipodev@gmail.com if anything is unclear.