Privacy Policy
Effective date: 19 September 2026
1. Who we are and how to contact us
Propelva ("we", "us") is operated by:
Propeller Plan Sp. z o.o.
ul. Święty Marcin 29/8, 61-806 Poznań, Polska
NIP: 7831837046 · REGON: 388949083 · KRS: 0000899016
Kapitał zakładowy: 5 000,00 PLN
We are the controller of personal data processed for the purposes described
here, under the General Data Protection Regulation (GDPR). This policy
covers the Propelva app, propelva.app, our launch waitlist, country-interest
forms and correspondence with us.
For privacy questions and requests, contact [email protected] or our postal address above. For support, contact [email protected]. This policy provides information; accepting our Terms is not consent to all the processing described here.
2. Where data comes from and what we collect
We receive data from you, your use of the service, people you deal with and our providers. Providers supply authentication, payment, identity-check and delivery results. Other users may supply ratings, reports and evidence about you.
Account and profile
We process your email, account identifier, authentication and verification records, profile name or username, optional avatar and bio, selected city and country, city coordinates, language and preferences. Public profiles include your username, avatar, bio, city, seller type, applicable badges, ratings and completed-deal count. Listings also show location information. City coordinates support approximate distance; they do not establish your precise home location.
Email and phone numbers are not public profile fields. We collect a phone number when you provide it for features such as shipping; it is not required simply to create every account. Apple or Google sign-in supplies identity information that may include a name, email or Apple relay address, and credentials needed for that integration. We do not receive your Apple or Google password.
Listings and marketplace activity
We process listing details, condition, language, prices, swap terms, delivery choices and photos; saved listings, wishes and looking-for requests; searches, filters, matches, offers and notification preferences. Listings and looking-for requests intended for discovery are visible to other users. A private wish is not automatically a public looking-for post. Photos and free text can contain personal information you choose to include.
Deals, payment and seller verification
We keep the parties, items, amounts, fees, currencies and conversion records, payment and payout references and status, cancellations, refunds and delivery records. Stripe collects payment credentials directly; Propelva does not store full card numbers or card security codes.
Seller payout onboarding takes place with Stripe. Depending on the seller and applicable requirements, Stripe may request legal identity, date of birth, address, business details, identification documents and bank details. We receive account references and onboarding/payment capability results. Information supplied directly to Stripe is also covered by Stripe's privacy notice. Tax-reporting information is addressed separately in §5.
Shipping, communications and safety
Shipping may require sender and recipient names, emails, phone numbers, pickup-point identifiers and addresses, including street, house and apartment number, city, postal code, region and country. Requirements depend on the method selected. We process labels, tracking numbers and carrier events. Information needed for delivery can be visible to the other party, including through the shipping label.
We store messages and chat photos, ratings and reviews, blocked-user relationships, reports, support correspondence, and dispute descriptions and evidence. Messages are available to conversation participants. Authorised staff may access relevant records for support, investigations and disputes. Avoid unnecessary sensitive information or another person's private details in listings or evidence.
Website waitlist and country-interest forms
The website waitlist collects your email and city and may attach a country inferred from the site language, a source label and a submission record. The form sends this information to Salesforce. The requested consent is for launch emails, not unrelated promotional campaigns.
The app's country-interest form collects your email and selected country, submission time and a hash of an app-generated device identifier to limit repeat submissions. This separate record is stored in Supabase. A hashed identifier is not necessarily anonymous. You can withdraw a launch-email request through [email protected] without an app account.
Technical data, analytics and operational measurement
Infrastructure and providers process IP addresses, request times, device, operating-system and app versions, error details and security logs. We store a push token when notifications are enabled, consent choices and account setup/deletion records. We do not promise that IP addresses are processed only transiently: provider logging and retention also matter.
Optional PostHog analytics requires an opt-in through the consent prompt or Settings. Events can include screen use and marketplace actions, an account-linked identifier, signup time and device/app metadata. These are personal data even without a name or email attached.
Separately, the backend measures marketplace operation using listing, offer and deal counts, daily search-result aggregates, consent coverage, onboarding milestones and limited account-linked counters of initial search results. The account-linked records remain personal data; reporting totals does not make the underlying records anonymous. This is distinct from optional PostHog analytics.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provide accounts, profiles, listings, requested search/matching, saved items, offers, messaging and deal services | Contract, GDPR Article 6(1)(b) |
| Arrange payment, payouts and selected shipping | Contract, Article 6(1)(b); applicable statutory records under Article 6(1)(c) |
| Send necessary account and deal communications, including enabled service push notifications | Contract, Article 6(1)(b) |
| Collect, verify, retain and report seller information where DAC7 or another law requires it; handle lawful authority and data-rights requests | Legal obligation, Article 6(1)(c) |
| Handle support, prevent fraud and abuse, secure accounts, moderate content, investigate disputes, and establish or defend legal claims | Legitimate interests in a safe, functioning marketplace and protecting legal rights, Article 6(1)(f); legal obligation where a specific law requires action |
| Diagnose failures and measure service and marketplace operation, including the limited backend records in §2 | Legitimate interests in maintaining and managing the service, Article 6(1)(f), subject to necessity, minimisation and balancing your rights |
| Optional PostHog product analytics | Consent, Article 6(1)(a) |
| Send requested launch notifications | Consent, Article 6(1)(a), with the electronic-communications consent required by applicable law |
| Prevent duplicate or abusive form submissions | Legitimate interests in protecting the forms and service, Article 6(1)(f) |
Required account, payment, shipping or statutory seller information is needed for the corresponding feature or legal duty. Without it, that feature may be unavailable. Optional profile content, launch emails and product analytics are voluntary. Refusing or withdrawing analytics consent does not prevent use of the marketplace.
4. Who receives data
Other users receive public content and deal information as explained in §2. Authorised personnel and professional advisers may receive information needed for support, legal, accounting and compliance work. Authorities, courts and regulators may receive data when lawfully required, or where necessary and lawful to protect rights or safety.
Our providers include the following. A recipient is not necessarily our processor for every activity: payment providers, identity providers and carriers may also act as independent controllers.
| Provider / recipient | Purpose and information involved |
|---|---|
| Supabase | Database, authentication and storage, including account, marketplace, message, file and country-interest records |
| Stripe / Stripe Connect | Payments, refunds, verification and payouts; identity/payment data supplied to Stripe and transaction/reference data exchanged with us |
| InPost, Packeta, Furgonetka and the carrier fulfilling the selected service | Labels, delivery and tracking; sender/recipient contact and address data, pickup points, parcel and declared-value information |
| Amazon Web Services — SES | Authentication and other service/form-related emails; recipients, content and delivery metadata |
| Salesforce | Website waitlist records and administration of requested launch communications |
| Sentry | Diagnostics, device/app metadata and error context |
| PostHog | Consented app analytics and account-linked identifiers |
| Expo, with Apple/Google for push delivery | App updates and delivery metadata; push tokens and notification content for enabled notifications |
| Apple / Google | Optional sign-in and associated authentication/revocation exchanges |
| Google Places | City resolution using city query, country and language sent through our backend |
| Cloudflare | Website hosting, delivery, security and, where enabled, Web Analytics; network/request metadata and traffic measurements |
External hosts serving game artwork or linked content can receive connection metadata necessary to serve it. External sites you choose to open apply their own privacy notices.
Sentry is configured to disable default personal-information collection and filter email addresses and credential-like fields. This reduces exposure; it does not guarantee every payload is anonymous or every identifier removed. Session replay and performance tracing are not enabled in our current Sentry configuration.
We do not sell personal data or give it to third parties for unrelated marketing. Providers acting on our instructions must have the required data-processing arrangements. Independent controllers have their own duties and privacy notices.
5. Seller tax reporting — DAC7
Where Propelva is a reporting platform operator, DAC7 and national law require seller due diligence and annual reporting. The rules can cover individuals and entities, regardless of the account label chosen.
For sales of goods, the small-seller exclusion generally requires fewer than 30 relevant sales AND total consideration paid or credited of no more than €2,000 in the calendar year. Therefore, 30 or more sales OR more than €2,000 can make a seller reportable, subject to other statutory conditions and exclusions. These are reporting rules, not a tax-free allowance or a business-status test. Information may need to be requested before a threshold is reached.
Required data can include legal name, primary address, tax residence, tax identification number and issuing jurisdiction, date of birth, business registration or VAT details, financial-account identifiers, and consideration, activity counts and fees by reporting period. Reportable data goes to the competent tax authority, in Poland the Head of the National Revenue Administration (Szef KAS), and may be exchanged with authorities in the seller's tax residence. Affected sellers must also receive the information about them that the law requires us to supply. See DAC7, Annex V.
6. International transfers
Providers may use infrastructure or support teams outside the European Economic Area. EU hosting does not exclude overseas access. The repository configures EU PostHog ingestion, an EU Sentry setup and AWS SES in Frankfurt; this does not verify every processing location.
Transfers requiring GDPR safeguards must use a valid adequacy decision or appropriate safeguards, such as the European Commission's Standard Contractual Clauses and any necessary supplementary measures. The EU–US Data Privacy Framework can cover only a qualifying transfer to a currently certified recipient. These mechanisms are not interchangeable. You can request details and copies of applicable safeguards through [email protected], with protected information redacted if needed.
7. Retention and account deletion
We keep data only as long as needed for the stated purpose, considering open deals, statutory duties, claims and security needs. The mechanisms and criteria below do not promise that every copy disappears when a profile is removed.
| Record | Retention / deletion approach |
|---|---|
| Account and public profile | For account operation, then removal or minimisation when closure is processed, subject to justified legal exceptions |
| Deal, payment, shipping and tax records | For completion/refunds, then the applicable statutory recordkeeping or claims period, with access limited to those purposes |
| Messages, ratings, reports and support | While needed for conversations, shared deal history, case handling or claims; consider other participants' rights and remove unnecessary identifying content |
| Resolved/closed dispute description and evidence | Scheduled clearing of description and evidence references after 90 days from the recorded resolution date; storage-file removal is separate |
| App country-interest submissions | Scheduled deletion after 12 months; earlier requests can be made by email |
| Website Salesforce waitlist | Up to 24 months from signup, or until consent is withdrawn (whichever is earlier); a separately justified minimal consent/objection record may be retained |
| Analytics, diagnostics, logs, backups and erasure audits | Limited periods appropriate to purpose and provider settings; backups expire through their backup lifecycle |
You can request deletion in Settings or by email. The in-app flow currently refuses a request while a deal is active. This technical restriction does not prevent a GDPR request by email: we assess what can be erased now and explain specific legal reasons for retaining anything else.
Account closure replaces the public username, removes profile details and clears private contact, address, payment-reference and device fields from the marketplace profile. It takes active listings out of circulation. Authentication blocking and Apple token revocation form part of the workflow. Completion can require operator action.
Transactions, messages, ratings, reports, authentication records and other linked records may still identify you after profile fields are cleared. Replacing a username is not necessarily anonymisation. Retained personal data remains protected by GDPR. A yearly transaction total without legally required seller identity is not sufficient DAC7 compliance.
8. Cookies, device storage and choices
The app stores session and preference information on your device. Relevant features request device permissions, such as taking/selecting photos and push notifications; you can manage these in device settings.
PostHog product analytics is off by default. You can grant or withdraw consent in Settings. Withdrawal stops future optional collection; it does not invalidate earlier lawful processing or automatically delete historical events. You can request deletion under §10.
Cloudflare Web Analytics is designed to measure traffic without analytics cookies or persistent cross-site identifiers. Security/bot challenges are separate and may use cookies or similar technologies. Non-essential storage or access requiring consent must be disclosed and controlled before it occurs. See Cloudflare's collection documentation.
9. Automated processing
Software filters/orders listings and matches requests using market availability, your selections and marketplace data. It also applies payment, cancellation and settlement rules, including automatic completion in the Terms. Contact [email protected] to contest an outcome and request review.
10. Your rights
Subject to GDPR conditions, you can request access, correction, erasure or restriction. You can obtain data you provided in a structured, commonly used, machine-readable format where processing is automated and based on consent or contract, and request direct transmission where technically feasible. Other people's rights and applicable legal retention duties also apply.
You may object to legitimate-interest processing on grounds relating to your situation. We must stop unless we demonstrate overriding compelling grounds or need the data for legal claims. You may object to direct marketing at any time; we will stop that use. Consent can be withdrawn without affecting earlier lawful processing.
Contact [email protected] or our postal address. Your account email helps verify identity but is not a condition for making a request. We may ask for proportionate verification where needed. Requests are normally free. We respond without undue delay and within one month. Where complexity or number of requests justifies up to two further months, we notify you within the first month and explain why. A refusal will explain reasons and remedies. Exports are currently handled manually. See GDPR Articles 12–22.
You may complain to the President of the Personal Data Protection Office (Prezes UODO) in Poland through UODO, or the supervisory authority in your country of habitual residence, work or the alleged infringement. You may also seek a judicial remedy.
11. Age policy
Our draft Terms require 16 for an account and 18 to buy, sell or swap. These are platform rules. GDPR Article 8 concerns consent-based processing for children; it does not grant 16-year-olds contractual capacity or permission to use every service.
Contact [email protected] if you believe we collected data from someone below the permitted age. We will assess the situation, take appropriate account action and erase information not lawfully needed.
12. Security and changes
We use encrypted connections, access controls and restricted access to private files. Public profile/listing content is intended to be shared. No service can guarantee absolute security; report concerns to [email protected].
We update this policy when processing changes and provide appropriate notice of material changes. A policy update or continued use alone does not supply consent for a new purpose that requires it.