Privacy
Mindy Market is a neighbourhood listing service. We process seller account details, listing photos, and buyer offer details so people nearby can arrange a sale themselves.
What we collect
- Seller name, email (via Clerk), WhatsApp number, and private unit. The seller's number is used for seller safety checks and support contact, never shown to buyers.
- Listing photos, titles, prices, and category.
- Buyer name, WhatsApp number, offer amount, and optional message.
- Feedback sent through a private seller link. It is tied to the seller account that received it so we can understand the context, and it is not shown to other residents.
- Payment references for selling packages (Paystack). We do not store card numbers.
- Short-lived abuse-prevention signals. We do not keep raw IP addresses for long.
What stays private
- Unit numbers are never shown publicly.
- Exact collection address is arranged privately between buyer and seller.
- Sellers only see leads on their own listings.
- Buyer contact details are not shown to other buyers.
Retention (pilot)
Pilot product rules delete unattached uploads after 24 hours, warn then remove inactive drafts after 30 days, and remove sold or expired listing images after the Recently sold window plus 90 days unless the item is relaunched. Buyer contact fields are kept for seller follow-up for up to 90 days after closure or expiry, then removed. Sent notification bodies drop buyer contact 30 days after delivery. Feedback links expire after 30 days. Written feedback and its seller-account link are removed after 90 days; anonymous answer themes may remain for product improvement. The marketplace owner receives submitted seller feedback by email so it can be reviewed.
Legal, accounting, payment, security, and audit retention periods are not final. The owner must confirm the exact periods with a qualified adviser before launch. Provider retention details stay in the internal owner register until those periods are confirmed.
Correction and deletion
Signed-in sellers can request a correction or account deletion. Deletion records a case for our retention job. It does not erase immutable payment, security, or audit facts required for disputes. Contact the support address named on the Safety page for help.
Providers
Clerk (sign-in), Paystack (package checkout), Resend (seller email), Cloudflare (hosting, database, images, queues), and Sentry (error monitoring) process data on our behalf. Provider retention must be checked and disclosed before launch. Do not treat assumed periods as facts.