Privacy Policy
Last updated: March 2026
1. Introduction
FragSwop ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use the FragSwop website and services.
We are the data controller for the personal data we process. We are registered in England and Wales and operate in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By using our Service, you consent to the collection and use of information in accordance with this policy.
2. Data We Collect
2.1 Information You Provide
When you register and use FragSwop, you provide us with:
- Account Information: Name, email address, password, phone number (optional)
- Profile Information: Display name, bio, avatar, location
- Address Information: Shipping and billing addresses
- Financial Information: Payment details (processed by Stripe), bank account details for seller payouts
- Identity Verification: For sellers: date of birth, identity documents (processed by Stripe Identity)
- Communications: Messages sent through our platform, support requests
- Listing Content: Product descriptions, images, pricing information
2.2 Information Collected Automatically
When you use our Service, we automatically collect:
- Device Information: Browser type, operating system, device identifiers
- Usage Information: Pages visited, features used, time spent on site
- Location Information: IP address, approximate geographic location
- Cookies and Tracking: See our Cookie Policy for details
2.3 Information from Third Parties
We may receive information from:
- Stripe: Payment verification status, account status for sellers
- Met Office: Weather data for shipping hold decisions (no personal data)
3. How We Use Your Data
We process your personal data for the following purposes:
3.1 Contract Performance (GDPR Article 6(1)(b))
- Creating and managing your account
- Processing transactions and payments
- Facilitating communication between buyers and sellers
- Processing seller payouts
- Handling disputes and refunds
- Delivering purchased items
3.2 Legitimate Interests (GDPR Article 6(1)(f))
- Improving our services and user experience
- Detecting and preventing fraud
- Ensuring platform security
- Analytics and performance monitoring
- Customer support
3.3 Legal Obligations (GDPR Article 6(1)(c))
- Tax and accounting requirements
- Responding to legal requests
- CITES compliance verification
3.4 Consent (GDPR Article 6(1)(a))
- Marketing communications (where you have opted in)
- Non-essential cookies and tracking
4. Data Sharing
We share your personal data with:
4.1 Service Providers
- Stripe: Payment processing and seller identity verification
- Mailgun: Email delivery services
- Twilio: SMS notifications
- Google Analytics: Website analytics
- Cloudflare: Content delivery and security
4.2 Other Users
When you use FragSwop, certain information is visible to other users:
- Sellers can see buyer shipping addresses for order fulfilment
- Buyers can see seller display names, ratings, and location
- Public profile information you choose to share
4.3 Legal Requirements
We may disclose your information if required by law, court order, or government request, or to protect our rights, property, or safety.
5. International Transfers
Some of our service providers are located outside the UK. When we transfer your data internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses approved by the UK ICO
- Transfers to countries with adequate data protection laws
- Binding Corporate Rules where applicable
6. Data Retention
We retain your personal data for:
- Account data: Duration of your account plus 3 years
- Transaction records: 7 years (tax and accounting requirements)
- Messages: 2 years after account closure
- Analytics data: 26 months (Google Analytics default)
- Marketing preferences: Until you withdraw consent
7. Your Rights
Under UK GDPR, you have the following rights:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Request limitation of how we use your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
To exercise these rights, contact us at [email protected]. We will respond within one month.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data:
- Encryption of data in transit (TLS/SSL)
- Encryption of sensitive data at rest
- Regular security assessments
- Access controls and authentication
- Employee training on data protection
9. Cookies
We use cookies and similar tracking technologies. For detailed information about the cookies we use and how to manage them, please see our Cookie Policy.
10. Children's Privacy
FragSwop is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or platform notification. The "Last updated" date at the top of this policy indicates when it was last revised.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us:
- Email: [email protected]
- Website: fragswop.co.uk
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data protection rights have been violated.