RareLister.com Privacy Policy
Last Updated: 19 November 2025
This Privacy Policy explains how RareLister.com (“RareLister”, “we”, “us”, “our”) collects, uses, stores, and protects your personal data under GDPR and international law. It complements the Terms & Conditions and User Agreement.
1. Data Controller
RareLister OĂś (Estonia) is the Data Controller for all data processed.
Email: support@rarelister.com
2. Categories of Personal Data We Collect
2.1 Data You Provide
- Account details (name, email, phone).
- Address & shipping information.
- Identity documents (passport, ID card).
- Proof of address.
- Payment-related details (processed via third parties).
- Listing photos, descriptions, certifications.
- Packaging/unboxing videos for dispute resolution.
- Messages sent through the platform.
2.2 Data Collected Automatically
- IP address.
- Device & browser info.
- Login logs.
- Auction activity.
- Cookies and similar technologies.
- Fraud analysis data.
2.3 Data from Third Parties
- Payment processors (Stripe, Revolut).
- Verification partners.
- Shipping carriers.
- Anti-fraud services.
3. Purposes of Data Processing
We use your data for:
- Account creation and authentication.
- Managing auctions, listings, and payments.
- Fraud prevention and risk scoring.
- Dispute resolution (video/photos).
- Customer support.
- Legal compliance (AML/KYC).
- Improving platform performance.
- Security monitoring and access control.
4. Legal Bases for Processing
We process your data under:
- Contract necessity (bidding, selling, payments).
- Legitimate interest (fraud prevention, security).
- Legal obligations (KYC/AML, tax laws, accounting).
- Consent (cookies, marketing emails).
5. Automated Decision-Making & Profiling
RareLister uses automated systems for:
- Fraud detection and account risk scoring.
- Automatic bidding mechanisms.
- Auto-suspension triggers for suspicious activity.
Your Rights: You may request a human review of any automated decision affecting you.
6. How We Use Your Data
Examples:
- Verify your identity.
- Detect fraudulent activity.
- Compare videos for dispute resolution.
- Match buyers and sellers.
- Analyze usage to improve features.
- Enforce platform rules.
7. How We Share Your Data
We may share data with:
- Payment processors.
- Fraud detection providers.
- Shipping carriers.
- Identity verification services.
- Legal authorities (when required).
We never sell personal data.
8. International Data Transfers
Data may be stored or processed outside the EU. Transfers follow GDPR protections such as:
- Standard Contractual Clauses (SCCs).
- Adequacy decisions.
- Data Processing Agreements.
9. Data Retention
- Account data: as long as the account is active.
- Transaction data: minimum 5 years (legal requirement).
- Videos/photos for disputes: up to 12 months.
- Technical logs: 12 months.
- Messages: retained for audit & safety.
10. Your GDPR Rights
You have the right to:
- Access your data.
- Correct inaccurate information.
- Request deletion.
- Restrict processing.
- Object to certain processing.
- Data portability.
- Withdraw consent.
Requests: support@rarelister.com
11. Cookies & Tracking
We use cookies for:
- Login sessions.
- Bidding functionality.
- Fraud prevention.
- Analytics.
- Preferences.
See our Cookie Policy for full details.
12. Security Measures
We use:
- SSL encryption.
- Encrypted video/photo upload.
- Access control.
- Fraud monitoring systems.
- Secure servers.
No system is 100% secure. Users must keep credentials safe.
13. Minors
RareLister is not intended for users under 18. We do not knowingly process children’s data.
14. Law Enforcement Requests
We may provide user data to law enforcement when required by law.
15. Updates to This Policy
We may update this Privacy Policy at any time. The latest version will be posted on the Platform.
16. Contact
Email: support@rarelister.com
RareLister OÜ – Estonia