Design preview. Sample products, no real payments.
roavmarket.

A clear foundation for the community

Privacy policy

Working draft · 25 September 2026 · Not effective launch terms

Prepared for product and legal review.

Bracketed items are unresolved decisions. This prototype does not process real payments or deliver real products.

1. Who is responsible

The intended controller is [LEGAL ENTITY], at [REGISTERED ADDRESS], in [COUNTRY / STATE]. Privacy contact: [PRIVACY CONTACT]. The operator, applicable jurisdictions, and any required representative or data protection officer remain to be confirmed. This is a draft dated 25 September 2026, not a verified notice for a launched marketplace.

2. What this prototype does

The prototype keeps demo account status, saved items, cart contents, sample purchases, proposals, advertisement text, and seller preferences in browser memory for the current mounted session. Reloading or leaving the application can reset them. These demo forms do not submit their contents to a marketplace backend, Stripe, Roblox, or any hub. Do not enter sensitive information into sample fields.

The code does not install advertising trackers or analytics and does not request card details, identity documents, crypto wallet addresses, or Roblox credentials. Normal hosting or development-server requests can include technical information such as IP address and browser details. The hosting provider, its logs, and retention must be audited for any actual deployment. Artwork is served from local project assets.

3. Proposed production data inventory

If the full service is built, an updated notice will specify the actual collection: account identifiers and contact details; seller business and verification status; listings and uploaded files; order, license, and delivery records; commission briefs, proposals, messages, and dispute evidence; support records; advertisement content; account-link permissions; and security logs.

Payment details should be collected through the approved payment provider's interface. The precise transaction metadata returned to roavmarket and who receives identity documents must be documented. OAuth scopes, hub access tokens, public blockchain data, and Roblox identifiers must be assessed before the related features are enabled. This draft does not claim those integrations currently operate.

4. Why data would be used

The intended purposes are account access, product discovery, purchases, authorized file delivery and whitelisting, commission coordination, seller settlement, support, fraud prevention, and legal recordkeeping. Each purpose must have a documented lawful basis where required. Proposed mappings include contract for requested services, legal obligation for required records, legitimate interests following a balancing assessment for proportionate security, and consent where optional tracking or marketing requires it.

Do not bundle optional advertising or analytics consent into a purchase or account registration. If a feature changes the purposes of collection, update the notice and obtain any required permission before collecting or sharing the data.

5. Who would receive information

A vendor should receive only the order and user identifiers needed to deliver, support, and document that sale. Buyers should receive the information needed to identify their seller and obtain support. Commission counterparties receive the brief, proposal, messages, and files intentionally shared with them. Public listings, profiles, reviews, and ads must clearly distinguish public information from private records.

The eventual provider list must name the actual hosting, database, storage, payments, support, and communication services. A user-selected hub connection may share product, purchase, and linked account identifiers for delivery or whitelisting; disclose the recipient and purpose before connecting. Legal or safety disclosures must be limited to the circumstances and data permitted or required by law. No undocumented processors or blanket data-sharing arrangements are asserted here.

6. Cookies, ads, and international transfers

The prototype uses contextual sample advertisements, not behavioral targeting. It adds no application cookies or browser storage for demo preferences. A production cookie and storage inventory must identify essential session data and any optional measurement technology, together with the required controls and retention.

The actual hosting and provider locations remain undecided. Before international transfers begin, document the destination countries, provider roles, and applicable transfer mechanism and safeguards. Merely using the site should not be treated as a universal waiver of transfer protections.

7. Retention and security

Before launch, define retention periods for account records, licenses, financial records, commission messages, dispute evidence, uploads, logs, backup copies, and disconnected-hub tokens. Do not promise indefinite file access or immediate erasure of legally required records without an operational basis. Explain what happens to licenses and counterparties' records after closure.

The security design should include appropriate access controls, protected secrets, private file storage, scoped integrations, revocable download access, and incident procedures. These are implementation requirements, not claims that an unaudited system has already met them. No online service can promise absolute security.

8. Your rights and young users

Depending on the applicable law, people may have rights to access, correct, delete, or receive a copy of their data; object to or restrict processing; withdraw consent; appeal a decision; and complain to a regulator. Publish a working contact and reasonable verification process, applicable deadlines, and the relevant authority before launch. Do not request more identifying information than needed to handle a request.

[DECISION REQUIRED: audience ages, guardian involvement, seller eligibility, age assurance, and child-specific privacy measures.] A payment provider's age restrictions do not replace the site's own privacy obligations. Any production experience for young users requires a specific assessment before collection, profiling, or advertising is enabled.

9. Updates and contact

The final notice must describe actual practices at launch. Material changes should be explained through an appropriate notice, with fresh consent where required. Fill in [PRIVACY CONTACT], [POSTAL ADDRESS], [REGULATOR / COMPLAINT ROUTE], and [EFFECTIVE DATE] before this policy is made operative.

Research references

These are original, project-specific drafts. The reference policies helped identify topics to review; their entity details, jurisdiction, liability exclusions, provider lists, and operational claims have not been adopted.