Privacy by design

PublicMarket Privacy Notice

How PublicMarket collects, uses, protects, retains, and shares personal information, and how data subjects can exercise their rights.

Version 1.13-2026-08Effective August 1, 2026
PublicMarket processes account, business-profile, inquiry, review, subscription, billing, security, and privacy-request information only for declared platform, contractual, security, legal, and support purposes. Precise payment-card data, CVV values, passwords, reset tokens, gateway credentials, webhook secrets, and authentication secrets are not part of PublicMarket's application records. Personal information may be shared only as necessary with service-provider categories such as payment gateways, hosting and object-storage providers, email delivery services, analytics providers, professional advisers, and lawful authorities. Each provider must receive only the information required for its documented purpose and remain subject to appropriate contractual and security safeguards. Retention is assigned by data category. Account and business data is kept while the service relationship is active and for a documented closure period. Billing, accounting, fraud-prevention, security, legal-claim, audit, and regulatory records may be retained longer where a legitimate obligation applies. Information is securely deleted or anonymized when its approved retention period expires and no legal hold or other lawful reason remains. Depending on the applicable legal basis and limitations, data subjects may request access, correction, objection, erasure or blocking, portability, and consent or preference changes through the authenticated Privacy Center. Requests are identity-verified, tracked, and audited. Consent can be withdrawn for optional processing without affecting processing that remains necessary under another lawful basis. PublicMarket uses role-based access control, least privilege, secure authentication, encryption in transit, protected cookies, request validation, rate limiting, audit records, and incident-response procedures. A centralized incident and personal-data-breach register supports risk assessment, containment, decision records, and required notification workflows, including the applicable 72-hour escalation timeline. Questions or privacy requests may be submitted through the PublicMarket Contact page or the authenticated Privacy Center. This notice is a product baseline and must be reviewed with the deployed operator's current contact details, processors, retention schedule, and National Privacy Commission obligations before production launch.