Back

Privacy Policy

Last updated: 5.03.2026

1. Data Controller

The data controller is Terra Market. Data is processed in accordance with the General Data Protection Regulation (GDPR).

Data Controller

Owner: Jacek Krupa
Address: Lubotyń Włoki 25a, 07-303 Stary Lubotyń, PL
Contact: hello@terramarket.eu, tel: +48 606 171 824
Business type: Unregistered business activity

2. Scope of Collected Data

We collect the following data:

  • Account data (email, username)
  • Profile data (address, phone number - optionally)
  • Transaction data (orders, payments)
  • Technical data (IP address, cookies)
  • Phone number (for verification purposes only)

3. Purpose of Processing

Data is processed for the following purposes:

  • Payment transaction processing: Processing data to handle payments for products, subscriptions (PRO/ELITE) and paid listings through the Stripe Connect system
  • Authentication and login: Processing data to ensure secure login and user account management through the Supabase system
  • Transactional email sending: Processing data to send email notifications regarding transactions, orders, and subscriptions through the Resend system
  • Platform service provision (publishing listings, communication between users)
  • Account security verification: Processing phone number for identity verification (2FA/OTP) and fraud prevention
  • Fulfillment of legal obligations

4. Data Recipients

Personal data may be transferred to the following recipients:

External service providers

  • Stripe (Stripe Payments Europe Limited, Irlandia) - processing payments for products, subscriptions, and paid listings through the Stripe Connect system. Stripe processes data according to its own privacy policy available at: stripe.com/privacy
  • Supabase (Supabase Inc., USA) - storing data in the database, user authentication, infrastructure hosting. Supabase processes data according to its own privacy policy available at: supabase.com/privacy
  • Resend (Resend Inc., USA) - sending transactional emails and notifications. Resend processes data according to its own privacy policy available at: resend.com/privacy
  • Twilio (Twilio Inc., USA) - sending SMS verification codes (OTP) solely for account security and identity verification purposes. Twilio processes data according to its own privacy policy available at: twilio.com/legal/privacy

Data transfer to Stripe

For payment processing and fraud prevention, we transfer the following data to Stripe:

  • Buyer's first and last name
  • Email address
  • Transaction data (amount, currency, product description)
  • IP address (for security verification)

Terra Market does not have access to payment card data or full bank account numbers of users. Payments are processed directly by Stripe Payments Europe, Ltd.

Data may also be shared with state authorities based on applicable legal provisions.

5. Seller Verification Data

Sensitive data provided during Stripe Connect onboarding is processed directly by Stripe.

As part of the identity verification process (KYC/AML), sellers transfer to Stripe:

  • Personal data (first name, last name, date of birth)
  • PESEL number or other identification number
  • Identity document scans (ID card, passport)
  • Bank account data (IBAN number) for payouts
  • Additional documents required by regulations (depending on country)

Terra Market does not have full access to verification data. We only see the verification status of the seller's account (e.g., "verified", "awaiting verification") and basic information necessary for platform operation.

All verification data is stored and processed by Stripe according to their privacy policy and regulatory requirements (including GDPR).

6. Security and Rate Limiting

We apply appropriate technical and organizational measures to protect personal data, including:

  • Connection encryption (HTTPS)
  • Secure data storage in the database
  • Rate Limiting mechanisms to protect user accounts from unauthorized access
  • Session verification and access authorization
  • Regular security updates

Rate Limiting

To protect user accounts from brute-force attacks and unauthorized access, we use request rate limiting mechanisms (Rate Limiting). This means that after exceeding the limit of login or registration attempts from one IP address, access may be temporarily blocked.

7. User Rights

The user has the right to:

  • Access their data
  • Rectify data
  • Delete data
  • Restrict processing
  • Data portability
  • Object to processing

To exercise their rights, the user can contact us at: hello@terramarket.eu

8. Cookies

The platform uses cookies to ensure proper service operation and traffic analysis. The user can manage cookie settings in their browser.

Contact

For matters regarding personal data protection, please contact:

Email: hello@terramarket.eu
Phone: +48 606 171 824

Need help? Write to us!