Privacy Policy

Last updated: June 2026

BidVault is committed to keeping your personal information safe and using it only for the purposes you would reasonably expect. This page explains what we collect, why we collect it and who it's shared with.

What we collect

  • Your name, email address and password (stored securely, hashed and salted).
  • Your address, phone number and company name if you provide them — these are used for seller verification and for revealing collection addresses to winning buyers.
  • Bid history and listing history, so that you can see your past activity and so sellers can see bids on their auctions.
  • Messages you send through the platform, so that the other party can receive and reply to them.
  • Basic usage data (pages visited, device type) for analytics and debugging. We do not use third-party advertising cookies.

Who it's shared with

Information is shared only with the other party in a transaction (your name is shown on your bids and messages, your collection address is shown to the winning buyer after payment) and with the service providers we rely on to operate the platform. These currently are Heroku (hosting), Mailgun (email delivery) and Cloudinary (image hosting). Personal data is not sold to anyone.

How long we keep it

We keep account information for as long as your account is open, and for a reasonable period afterwards to handle any outstanding disputes. You can request deletion of your account and data at any time via the Contact page.

Your rights

Under UK GDPR you have the right to access your data, to have it corrected if inaccurate, to have it deleted, and to object to certain uses of it. Contact us using the details on the Contact page to exercise any of these rights.

Cookies

We use strictly necessary cookies only — session cookies for login state and CSRF protection, and a cookie that remembers your dark/light theme preference. We do not use advertising or tracking cookies.