PRIVACY
Privacy Policy
This Privacy Policy explains how personal information is collected, used, disclosed, stored and protected when you visit or use Varitya, including the public marketplace, Buyer accounts, Seller stores, Seller staff accounts, checkout, messaging, reviews, returns, payment integrations, subscriptions and administrative services.
We recognise that a marketplace involves several different relationships. In particular, Varitya operates the marketplace platform, while independent Sellers operate their own Stores and fulfil Buyer Orders. This Policy explains when Varitya handles information for its own purposes and how Seller-related processing may also involve the relevant Seller.
Privacy at a glance
- Varitya uses personal information to operate and secure the marketplace, provide accounts, support Orders and administer Seller services.
- Independent Sellers receive the Buyer information they reasonably need to fulfil their own Orders and provide customer service.
- Marketplace customer payments are ordinarily processed through the relevant Seller's enabled payment provider; Varitya does not need to receive a Buyer's full card number or security code in order to operate the marketplace.
- Seller Subscription billing is separate from Seller customer-sale payments.
- We do not sell personal information to advertisers.
- We use appropriate technical and organisational safeguards, but no internet service can guarantee absolute security.
- You may have rights including access, correction, erasure, restriction, portability and objection, depending on the circumstances.
- You can object to direct marketing at any time.
1. Who we are
Varitya is an online marketplace operated by [LEGAL ENTITY NAME], trading as Varitya ("Varitya", "we", "us" or "our").
Company number: [COMPANY NUMBER]
Registered office: [REGISTERED OFFICE ADDRESS]
Privacy contact: [PRIVACY EMAIL]
Data Protection Officer: [DPO DETAILS / "We are not required to appoint a DPO"]
ICO registration number: [ICO REGISTRATION NUMBER, IF APPLICABLE]
For personal information for which Varitya determines the purposes and essential means of processing, the legal entity identified above is the data controller.
2. Scope of this Policy
This Policy applies to personal information handled through or in connection with:
- varitya.com and related Varitya web pages;
- the public marketplace and Store pages;
- Buyer registration and Buyer account areas;
- Seller registration, onboarding and Store management;
- Seller staff invitations, permissions and security administration;
- Product listings, wishlists and recently viewed items;
- cart, checkout, Orders and stock reservation;
- payment-provider integrations;
- returns, refunds, cancellations and disputes;
- reviews and ratings;
- Buyer–Seller messaging;
- Seller analytics and Platform Admin analytics;
- notifications and transactional email;
- Seller Subscription billing;
- security monitoring and audit logging;
- the Varitya progressive web application or browser-installed experience, where used; and
- support, legal, compliance and administrative communications.
This Policy does not replace a Seller's own privacy notice where that Seller independently determines how it uses personal information for its own business purposes.
3. Varitya, Sellers, controllers and processors
3.1 Varitya as controller
Varitya acts as controller for processing necessary to operate and administer the Platform, such as account administration, marketplace security, Platform communications, Seller subscriptions, Platform analytics, moderation and compliance.
3.2 Sellers as independent controllers
A Seller may act as an independent controller when it determines why and how to use Buyer information for its own sale, fulfilment, delivery, customer service, tax, warranty, returns, fraud-prevention or legal obligations.
3.3 Processor relationships
In some circumstances one organisation may process personal information on behalf of another under a written data-processing arrangement. Whether an organisation is a controller or processor depends on the actual processing activity and who decides its purposes and essential means.
3.4 Seller privacy responsibilities
Sellers must provide any privacy information that they are independently required to provide, use Buyer information only for lawful purposes and protect it appropriately.
4. Our data-protection principles
We aim to handle personal information in accordance with the following principles:
- Lawfulness, fairness and transparency: we identify a lawful basis and explain material uses of information.
- Purpose limitation: information is collected for specified and legitimate purposes.
- Data minimisation: we seek to use information that is adequate, relevant and limited to what is necessary.
- Accuracy: we take reasonable steps to keep important account and transaction information accurate.
- Storage limitation: we do not intend to retain identifiable information indefinitely without a legitimate reason.
- Security: we use appropriate technical and organisational safeguards.
- Accountability: we maintain policies, controls and records appropriate to our processing activities.
5. Personal information we collect
Depending on how you use Varitya, we may process the following categories.
| Category | Examples |
|---|---|
| Identity information | Name, account role, Seller contact name, staff name, Store ownership/association. |
| Contact information | Email address, telephone number, billing or delivery contact details. |
| Account information | User ID, role, account status, email-verification status, authentication metadata, notification preferences. |
| Delivery/address information | Recipient name, address lines, city, postcode, country, contact details and saved address labels. |
| Seller/Store information | Business/store name, country, currency, timezone, locale, selling markets, shipping zones, branding, policies, websites/social links and Store status. |
| Product and commercial information | Listings, SKUs, images, pricing, variants, stock, promotions, order records, returns and refunds. |
| Payment-related information | Payment-provider name, transaction/reference identifiers, payment state, currency, amount, refund status and merchant-connection status. |
| Subscription information | Seller plan, billing cycle, subscription status, trial status, billing-provider references and billing events. |
| Communications | Buyer–Seller messages, support requests, dispute communications and notification records. |
| Review information | Ratings, review text, moderation status and verified-purchase relationship. |
| Preference information | Marketplace country, Grid/List catalogue view, wishlist, recently viewed items, notification settings and interface preferences. |
| Technical information | IP address, user-agent/browser information, request identifiers, timestamps, route/method metadata, security events and cookie/browser-storage identifiers. |
| Usage information | Pages/features used, marketplace interactions, Seller analytics, Order status activity and operational metrics. |
| Compliance information | Information needed to investigate fraud, safety, prohibited products, disputes, legal requests, Seller verification or reporting obligations. |
Special category information
Varitya is not designed to require health, biometric, political, religious, sexual-life or other special category information for ordinary marketplace use. Please do not send such information through general marketplace messaging unless it is genuinely necessary and lawful. If we need to process special category information in an exceptional case, we will identify an appropriate legal basis and additional condition where required.
Criminal-offence information
We do not routinely request criminal-offence information. We may, however, receive or create information connected with suspected fraud, theft, prohibited transactions or law enforcement enquiries. Where such processing constitutes criminal-offence data, we will handle it only where legally permitted.
6. Where we obtain personal information
We may obtain information:
- directly from you when you register, edit your account, save an address, create a Store, list a Product, message another User or contact support;
- from Sellers when they create or manage Orders, fulfilment records, staff invitations, refunds or returns;
- from Buyers when they place Orders, submit reviews or raise requests;
- from Payment Providers through redirects, callbacks, APIs and webhook events;
- from hosting and security infrastructure through request logs and technical events;
- from your browser/device through cookies, local storage and HTTP/network information;
- from publicly available sources where necessary for lawful verification, rights protection or compliance;
- from competent authorities or professional advisers where relevant to a lawful enquiry; and
- from service providers that support delivery of the Platform.
7. Purposes and lawful bases for using personal information
The lawful basis depends on the specific processing. More than one basis may apply to different elements of the same service.
| Purpose | Typical information | Likely lawful basis |
|---|---|---|
| Create and administer User accounts | Identity, contact, account and authentication data | Contract; legitimate interests in secure account administration |
| Operate Buyer marketplace functions | Country preference, wishlist, recents, saved addresses and account data | Contract; legitimate interests |
| Facilitate Seller Orders | Buyer, address, Order, Product, payment-status and fulfilment data | Contract; legitimate interests; legal obligation where applicable |
| Provide Seller tools | Store, staff, Product, inventory, Order, analytics and payment-connection data | Contract |
| Administer Seller Subscription billing | Plan, billing-provider, transaction and subscription data | Contract; legal obligation for financial records |
| Secure the Platform | IP address, user agent, account activity, security events and request metadata | Legitimate interests; recognised legitimate interest or legal obligation where applicable |
| Prevent fraud and marketplace abuse | Orders, accounts, technical data, payment status, returns and security records | Legitimate interests; recognised legitimate interest where applicable; legal obligation where applicable |
| Resolve disputes and enforce rules | Orders, messages, reviews, tracking, returns and account activity | Contract; legitimate interests; legal claims |
| Comply with tax, accounting or regulatory duties | Seller, Order, transaction, reporting and identity information | Legal obligation |
| Send essential service communications | Email, account, Order, security and subscription data | Contract; legitimate interests; legal obligation |
| Send direct marketing | Email/contact preferences | Consent or legitimate interests/soft opt-in where permitted by PECR and data-protection law |
| Analyse and improve the Platform | Aggregated/usage information and technical diagnostics | Legitimate interests; consent where required for non-essential storage/access technologies |
| Respond to rights requests and complaints | Identity verification, correspondence and relevant account information | Legal obligation; legitimate interests |
Legitimate interests
Where we rely on legitimate interests, our interests may include operating a secure and commercially sustainable marketplace, preventing fraud, protecting Users, enforcing marketplace rules, improving service reliability and establishing or defending legal claims. We assess whether the processing is necessary and whether your rights and interests override those interests.
Consent
Where consent is the lawful basis, you may withdraw it at any time. Withdrawal does not make earlier lawful processing unlawful.
Contract
Some information is required in order to create an account, provide Seller tools, facilitate an Order or provide another service you request. If required information is not provided, we may be unable to provide that function.
8. Buyer information
Buyer accounts may include name, email address, password-derived authentication records, saved addresses, marketplace-country preference, wishlist, recently viewed Products, Orders, messages, returns and review history.
We use Buyer information to:
- provide and secure the Buyer account;
- remember selected marketplace country and interface preferences;
- display Products available for the selected marketplace country;
- maintain wishlists and recently viewed items;
- create and administer store-separated Orders;
- provide Order history and tracking information;
- support returns, refunds and disputes;
- allow verified-purchase reviews;
- facilitate Buyer–Seller messaging; and
- send Order, account and security notifications.
9. Seller and Seller staff information
9.1 Seller Owners
We process Seller Owner information to create and administer Stores, connect marketplace payment methods, configure countries/currencies, shipping, branding, Products, staff and Seller Subscriptions.
9.2 Seller staff
Store Owners may invite staff by work email and assign roles/permissions. We may process staff name, email, invitation token/status, role, permissions, sign-in activity and security/audit events.
9.3 Seller payment credentials
Where the Platform permits a Seller to enter payment-provider credentials, those credentials are intended to be encrypted at rest. Sensitive merchant credentials are not made available to Buyer Users or ordinary Seller staff who lack the relevant owner-level access.
9.4 Seller verification and reporting
We may collect additional Seller identity, business or tax information where required for compliance, platform integrity, payment-provider requirements or digital-platform reporting. The precise information collected may depend on applicable law and the Seller's country.
10. Orders, fulfilment and returns
Varitya separates marketplace transactions by Store. An Order record may contain:
- Buyer identity and contact information;
- delivery address;
- Seller and Store identifiers;
- Product and variant snapshots;
- quantity, currency, price, discount, shipping and total information;
- payment-provider/reference and payment status;
- stock reservation and inventory movement information;
- carrier/tracking information;
- fulfilment/status history;
- return, cancellation, refund and dispute records; and
- messages relevant to the Order.
We preserve appropriate Order snapshots so that historical transactions remain intelligible even if a Seller later changes a Product listing.
11. Payments and Payment Providers
11.1 Buyer payments to Sellers
Customer payments for marketplace Orders are ordinarily processed through the relevant Seller's enabled payment integration. Depending on Store and country, this may include Stripe Connect, Paystack, Flutterwave or another provider enabled by Varitya.
The Payment Provider may collect card, bank, wallet or other financial information directly. Varitya ordinarily receives transaction references and status information needed to update the Order, rather than the Buyer's complete payment-card credentials.
11.2 Payment-provider privacy
Payment Providers process information under their own privacy notices and legal responsibilities. Buyers and Sellers should review the notice presented by the relevant provider.
11.3 Webhooks and verification
Varitya receives and verifies payment-related server notifications and may perform server-side transaction verification. We use these events to prevent duplicate processing, update payment state, reconcile transactions and administer refunds.
12. Seller Subscription billing
Seller Subscription billing is separate from Buyer payments to Sellers. We may process:
- Seller and Store identifier;
- plan and billing cycle;
- trial and subscription status;
- billing-provider customer/subscription references;
- invoice/payment state;
- billing events and webhook identifiers; and
- information needed to provide billing-portal access.
Where Stripe Billing or another billing provider is used, that provider also processes information under its own privacy notice.
13. Country, localisation and international shopping
Varitya uses a marketplace-country setting to determine which Products and Sellers are relevant to a visitor. An initial country may be inferred from hosting/proxy/browser signals or a Platform default, but Users can manually change the marketplace country.
We may store the User's chosen marketplace country in a cookie or browser storage so that the preference persists. The selected marketplace country is not intended to be a precise geolocation record.
A Buyer's delivery country and address are processed separately where needed for an Order.
14. Messages and customer support
Marketplace messaging is designed for Product enquiries and Order-related conversations. We may store message content, sender/recipient identifiers, Store/Order/Product context, timestamps and read/unread status.
We may access relevant messages where reasonably necessary to:
- provide support;
- resolve disputes;
- investigate fraud, harassment or prohibited activity;
- enforce Terms and marketplace policies; or
- comply with law.
Do not send passwords, complete card details or other unnecessary sensitive information through marketplace messages.
15. Reviews, ratings and public content
A published review may be visible to other marketplace visitors together with information necessary to present it appropriately, such as rating, text, date and an appropriately limited reviewer identity.
We may process Order linkage to verify that a review relates to a genuine purchase. Sellers cannot unilaterally edit or remove Buyer reviews, although Platform Admin may moderate content under applicable policies.
Do not include another person's private information in a public review.
16. Images, logos and Cloudinary-hosted media
Varitya supports uploads such as Product images, Store logos/banners and Platform branding. Where Cloudinary is configured, uploaded media may be transmitted to and hosted by Cloudinary or its infrastructure.
Uploaded images may contain personal information if a User chooses to include identifiable people, documents, addresses or other personal details. Users should avoid uploading unnecessary personal information in marketplace images.
17. Security, audit logs and fraud prevention
To protect Users and the Platform, we may record security events including:
- successful and failed sign-ins;
- blocked sign-in attempts;
- access-denied events;
- attempts by Seller staff to access owner-only areas;
- staff invitations, role changes, suspensions and removals;
- request route and HTTP method;
- IP address;
- browser/user-agent information;
- request ID;
- date/time and severity; and
- Store/User context where relevant.
Security logs are not intended to store passwords, payment-provider secret keys or complete payment-card credentials.
18. Technical, device and usage information
Web servers and application infrastructure ordinarily receive technical information when a User accesses Varitya. This may include IP address, request time, browser/user-agent, requested URL, referring page, response/status information and security metadata.
We use technical information for service delivery, debugging, performance, abuse prevention, security investigation and aggregate operational analysis.
20. Analytics and service improvement
Varitya creates operational analytics for Sellers and Platform Admin. These may include sales, Orders, Products, countries, fulfilment, reviews, payment-gateway usage, subscription status, refunds and other marketplace metrics.
We aim to present financial reporting in a currency-safe manner and avoid combining unlike currencies into misleading totals.
Where possible, we use aggregated or de-identified information for trend analysis. If a third-party analytics service that uses non-essential cookies or similar technologies is introduced, this Policy and the cookie controls should be updated before deployment.
21. Marketing communications
We may send marketing only where permitted by applicable data-protection and electronic communications rules.
For individual subscribers, we will generally obtain consent unless a lawful soft opt-in or another permitted rule applies. Where a soft opt-in is relied on, it will be limited to circumstances in which the legal requirements are met.
Marketing consent is separate from accepting Terms or creating an account. We do not use pre-ticked boxes as evidence of consent.
Every applicable electronic marketing message will provide a simple means of opting out. You can also contact [MARKETING/PRIVACY EMAIL].
22. Transactional notifications
Operational communications are different from direct marketing. We may send messages that are necessary or reasonably expected for your use of Varitya, including:
- account verification and password-reset messages;
- security alerts;
- Seller staff invitations;
- Order and payment-status updates;
- shipping/tracking updates;
- return/refund/dispute updates;
- new marketplace message notifications;
- inventory or low-stock notifications to Sellers;
- Seller Subscription and billing notices; and
- material legal or service notices.
Where Varitya offers notification preferences, some non-essential operational notices may be configurable, while critical security or legal notices may not be optional.
24. Information shared with Sellers
When a Buyer places an Order, the relevant Seller needs sufficient information to perform the sale. This may include:
- Buyer/recipient name;
- delivery address;
- contact information reasonably needed for fulfilment;
- Order items, variants and quantities;
- Order value/currency;
- payment-status information;
- Buyer messages and return/refund requests; and
- other information necessary to meet Seller legal obligations.
Sellers must not use Buyer information obtained through Varitya for unrelated marketing unless they independently have a lawful basis and comply with applicable electronic marketing rules.
25. Service providers and subprocessors
Varitya uses third-party technology to operate the Platform. Production providers may include, where configured:
| Provider/category | Purpose | Typical data involved |
|---|---|---|
| Hostinger / hosting infrastructure | Application and database hosting, network delivery and infrastructure | Account, Order, database, technical and log data as required to host the service |
| Cloudinary | Image/media upload, processing and delivery | Uploaded Product/Store/branding media and technical metadata |
| Stripe | Seller-connected payments and/or Varitya Seller Subscription billing where enabled | Transaction, account and billing information relevant to the service |
| Paystack | Seller customer-payment processing where enabled | Transaction and payment information |
| Flutterwave | Seller customer-payment processing where enabled | Transaction and payment information |
| SMTP/email provider | Transactional emails and permitted marketing | Email address, message content and delivery metadata |
Publication requirement: this table must be checked against the providers actually enabled in production. If Varitya maintains a separate Subprocessors page, that page should be kept consistent with this Policy.
27. Corporate transactions and business transfers
If Varitya or its operating company is involved in a merger, acquisition, financing, restructuring, sale of assets or transfer of the marketplace business, personal information may be disclosed to professional advisers, potential counterparties and successors where reasonably necessary and subject to appropriate confidentiality and data-protection safeguards.
28. International transfers
Varitya is designed for international commerce and may use providers whose infrastructure, support personnel or group companies are located outside the United Kingdom.
Where UK data-protection rules treat a disclosure as a restricted international transfer, we will use an appropriate transfer mechanism where required. Depending on the destination and provider, this may include:
- UK adequacy regulations;
- the UK Extension to the EU–US Data Privacy Framework where applicable;
- the UK International Data Transfer Agreement (IDTA);
- the UK Addendum to approved EU Standard Contractual Clauses;
- binding corporate rules or another approved safeguard; or
- a lawful exception where strictly applicable.
Where required, we assess the circumstances of transfers and any supplementary safeguards. You may contact us for information about the relevant safeguards.
29. How long we keep information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, tax, fraud-prevention, security, dispute-resolution and enforcement requirements.
| Record type | Draft retention approach — verify before publication |
|---|---|
| Active account/profile information | For the life of the account, then for [ACCOUNT CLOSURE RETENTION PERIOD] unless a longer period is required for specific records. |
| Orders, refunds, transaction and tax/accounting records | [VERIFY PERIOD, commonly aligned with applicable accounting/tax limitation requirements]. |
| Seller Subscription billing records | [VERIFY FINANCIAL RECORD RETENTION PERIOD]. |
| Security/audit logs | [VERIFY SECURITY LOG RETENTION PERIOD], extended where needed for an active investigation or legal claim. |
| Buyer–Seller messages | [VERIFY MESSAGE RETENTION PERIOD], taking account of Order disputes and legal claims. |
| Reviews | For as long as the review remains relevant/published, plus any limited moderation/audit retention needed after removal. |
| Staff invitations | Invitation token expires after the configured invitation period; associated audit records retained according to the security-retention schedule. |
| Password-reset/verification tokens | Until expiry or use, subject to short technical/log retention. |
| Marketing preferences | While relevant, including a minimal suppression record where needed to respect an opt-out. |
| Support/legal cases | For the case plus [VERIFY PERIOD] based on legal/claims requirements. |
We may retain anonymised or effectively de-identified statistical information for longer where it no longer identifies an individual.
30. How we protect personal information
We use technical and organisational measures proportionate to the nature of the Platform and the risks involved. Measures built into or planned for Varitya include:
- password hashing rather than storing plain-text passwords;
- signed HTTP-only session cookies;
- secure-cookie settings in production where appropriate;
- CSRF protection for browser write actions;
- rate limiting on authentication and sensitive write routes;
- security headers;
- server-side validation and role/permission checks;
- Store-scoped Seller staff permissions;
- encrypted storage for supported Seller payment-provider credentials;
- webhook signature verification and duplicate-event protection;
- request IDs and structured operational/error logging;
- security and access auditing;
- restricted access to owner-only payment and billing controls;
- database constraints/application validation appropriate to the hosting environment;
- graceful process handling and health/readiness checks; and
- controlled production deployment practices.
No method of internet transmission or storage is completely secure. Users must also protect their credentials and promptly report suspected account compromise.
31. Personal-data breaches
We maintain processes to assess suspected personal-data breaches. Where a breach meets the applicable legal reporting threshold, we will notify the Information Commissioner's Office within the legally required timeframe and provide further information as required.
Where a breach is likely to result in a high risk to affected individuals and notification is legally required, we will also communicate relevant information to those individuals without undue delay, subject to applicable exceptions.
32. Your data-protection rights
Depending on the processing and applicable law, you may have rights to:
- be informed about how your information is used;
- access your personal information and receive supplementary information;
- rectify inaccurate or incomplete information;
- erase personal information in applicable circumstances;
- restrict processing in applicable circumstances;
- data portability for qualifying information and processing;
- object to certain processing;
- withdraw consent where processing relies on consent; and
- receive protections in relation to certain automated decisions and profiling.
These rights are not all absolute. For example, legal retention obligations, the rights of others, fraud prevention or the establishment/defence of legal claims may affect what we can delete or disclose.
To exercise a right, contact [PRIVACY EMAIL]. We may request proportionate information to confirm identity and protect accounts from unauthorised requests.
33. Access requests
You may request confirmation of whether we process your personal information and, where applicable, a copy of that information together with legally required supplementary details.
We may need to redact information relating to other people or apply another lawful exemption. We will respond within the applicable statutory timeframe, subject to any lawful extension for complex or multiple requests.
34. Deletion and account closure
Closing an account does not necessarily mean that every record is immediately erased. We may need to retain limited information relating to completed Orders, refunds, payment records, tax/accounting duties, fraud prevention, disputes, safety investigations, security events or legal claims.
Where deletion is appropriate, we will delete or anonymise information in accordance with our retention process and technical capabilities.
35. Your right to object
You have the right to object to processing based on legitimate interests in certain circumstances. You also have an absolute right to object to the use of your personal information for direct marketing.
To stop electronic marketing, use the unsubscribe/opt-out mechanism in the message or contact [PRIVACY / MARKETING EMAIL].
We may keep a minimal suppression record after an opt-out so that we can respect your request.
36. Automated decision-making and profiling
Varitya uses automated logic for ordinary technical and marketplace functions, for example determining country eligibility, sorting/ranking Products, validating stock, checking access permissions, applying promotions and updating states from verified payment events.
[VERIFY BEFORE PUBLICATION] Varitya does not currently intend to make decisions based solely on automated processing that produce legal or similarly significant effects on an individual without appropriate safeguards.
If we introduce such processing, we will update this Policy and provide legally required information about the logic, significance, consequences and applicable rights.
37. Children's privacy
[CHOOSE AND VERIFY THE APPROPRIATE POSITION BEFORE PUBLICATION]
Option A — service not intended for children
Varitya is intended for adults who can lawfully enter into marketplace transactions and for authorised business Sellers. We do not knowingly invite children to create Seller accounts. If we learn that personal information has been collected from a child in circumstances where it should not have been collected, we will take appropriate steps.
Option B — service may be likely to be accessed by children
If Varitya is likely to be accessed by children in the UK, we will assess and implement the protections required by applicable law and the ICO's Children's Code, including consideration of children's best interests, age-appropriate transparency, data minimisation, privacy by default, geolocation, profiling and data-sharing practices.
38. Third-party sites and services
Varitya may contain links to Seller websites, social profiles, Payment Providers, carriers and other third-party services. Those third parties control their own websites and may have separate privacy practices.
This Policy does not govern independent third-party processing merely because Varitya links to or integrates with the service.
39. Changes to this Privacy Policy
We will review this Policy when our processing, service providers, legal obligations or Platform functionality materially change.
The "Last updated" date will be changed when this Policy is revised. Where a new use of personal information is materially different or otherwise requires specific notice or consent, we will provide additional information before beginning that processing where required by law.
40. Complaints and the Information Commissioner's Office
If you have a privacy concern, please contact us first so that we have an opportunity to investigate: [PRIVACY EMAIL].
You also have the right to complain to the UK Information Commissioner's Office (ICO) if you believe that your personal information has been handled unlawfully. You can obtain current complaint and contact information from the ICO's official website.
If you are located outside the UK, you may also have rights to contact a competent local data-protection authority where applicable.
41. How to contact us
[LEGAL ENTITY NAME] trading as Varitya[REGISTERED OFFICE ADDRESS]
Privacy: [PRIVACY EMAIL]
Support: [SUPPORT EMAIL]
DPO (if applicable): [DPO EMAIL]
When contacting us about a privacy request, please do not send passwords, complete payment card details or unnecessary identity documents by ordinary email.
42. Platform Admin publication checklist
This section is an internal publication checklist and should be removed from the public Privacy Policy once all items have been completed.
- Insert and verify the legal entity operating Varitya.
- Insert company number and registered office.
- Insert privacy and support contact addresses.
- Confirm whether a DPO is legally required and insert contact details if applicable.
- Insert ICO registration number if applicable.
- Confirm the live Hostinger hosting region and contractual data-protection terms.
- Confirm Cloudinary's production data-processing location(s) and transfer safeguards.
- Confirm every live Payment Provider and update the provider table.
- Confirm the live SMTP/email provider and its processing location(s).
- Review the public Subprocessors page so it matches this Policy.
- Adopt and insert actual retention periods in section 29.
- Create/verify a Record of Processing Activities and retention schedule.
- Complete legitimate-interest assessments where legitimate interests is relied on.
- Confirm which browser storage/cookies are actually set in production.
- Implement/update a Cookie Policy and consent manager before enabling non-essential tracking.
- Confirm whether any third-party analytics or advertising technology is enabled.
- Confirm actual direct-marketing workflow, consent records and unsubscribe mechanism.
- Confirm whether Varitya is likely to be accessed by children and complete a Children's Code assessment/DPIA if required.
- Confirm whether any automated decisions create legal or similarly significant effects.
- Document UK international-transfer safeguards for each relevant provider.
- Document the data-controller relationship between Varitya and Sellers for key Order flows.
- Ensure Seller Terms require Sellers to protect Buyer personal information and issue their own privacy notice where legally required.
- Confirm data-subject request workflow and identity-verification procedure.
- Confirm personal-data breach response and escalation procedure.
- Confirm digital-platform Seller reporting/verification requirements.
- Have the final Policy reviewed by a UK-qualified data-protection solicitor or suitably qualified privacy professional before publication.