Skip to content
Give great clothes a second life · New pieces added every day
galerija

Menu

Legal

Privacy Policy

Last updated:

This Privacy Policy explains how [REGISTERED LEGAL ENTITY NAME] (“galerija”, “we”), as data controller, collects, uses and protects personal data when you use galerija. We process personal data in accordance with the Law on Personal Data Protection of the Republic of North Macedonia(harmonised with the EU GDPR).

1. Who we are (controller)

[REGISTERED LEGAL ENTITY NAME], [REGISTERED ADDRESS, North Macedonia]. Company registration number [COMPANY REGISTRATION NUMBER (EMBS)]. For any privacy request, contact [PRIVACY / DATA-PROTECTION EMAIL].

2. What personal data we collect

  • Account & profile data — the email and profile details you provide when you register, and your seller profile (shop name, public handle, location if you choose to add it).
  • Content you create — listings (title, description, brand, size, price and images) and messages you send to other users.
  • Subscription & billing metadata — records that a subscription was purchased, its plan, status and dates, and a non-sensitive transaction reference from our payment provider. We do not collect or store your card number or card security data — see section 7.
  • Technical & usage data — information such as your IP address, device/browser type and interactions with the service, collected through server logs and essential cookies (see the Cookie Policy).

3. How and why we use it (legal bases)

  • To provide the marketplace — create your account, publish listings, enable buyer–seller messaging (performance of a contract).
  • To operate the seller subscription and process the related payment (performance of a contract).
  • To keep the service secure, prevent fraud and abuse, and comply with legal obligations (legitimate interests / legal obligation).
  • To communicate with you about your account, transactions and support requests (contract / legitimate interests).

4. Who we share data with (processors)

We share personal data only with service providers that process it on our behalf under a data-processing agreement, and only as needed to run the service:

  • Cloud database, authentication and file storage — our infrastructure provider (Supabase), hosting the database, authentication and image storage.
  • Application hosting — our cloud host (see Contact), located in the EU region.
  • Payment processing — CaSys (Casys AD Skopje), which processes the seller subscription payment. Card data is handled by the provider, not by us (section 7).

We do not sell your personal data. We may disclose data where required by law or to protect our rights and users.

5. International transfers

Our providers may process data in the EU/EEA. Where data is transferred outside the Republic of North Macedonia or the EEA, we rely on appropriate safeguards (such as adequacy decisions or standard contractual clauses).

6. How long we keep it (retention)

We keep personal data only as long as necessary for the purposes above: account and listing data for as long as your account is active; billing and transaction records for the period required by tax and accounting law; and messages for as long as needed to provide the service. When no longer needed, data is deleted or anonymised. Specific retention periods: [RETENTION PERIODS — confirm with adviser].

7. Payment card data (PCI DSS)

galerija never receives, processes or stores your payment card number, expiry date or security code. Card details are entered on the secure, PCI-DSS-compliant hosted payment page of our payment provider, CaSys (Casys AD Skopje), and are transmitted directly to it. We receive only a non-sensitive confirmation (such as success/failure and a transaction reference) so we can activate your subscription. See Payments & Security.

8. How we protect data

  • All traffic is served over encrypted HTTPS/TLS connections.
  • The database enforces row-level security so users can reach only the data they are entitled to; the privileged service key is server-side only.
  • Uploaded images are stored in a private bucket and served through short-lived signed URLs, never public links.
  • Authentication is handled by a dedicated identity provider; we never store your password.

9. Your rights

Subject to applicable law, you have the right to access, rectify, erase, restrict or object to the processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. To exercise these rights, contact [PRIVACY / DATA-PROTECTION EMAIL]. You also have the right to lodge a complaint with the Agency for Personal Data Protection of the Republic of North Macedonia (https://azlp.mk).

10. Children

galerija is not directed to children under 18 and we do not knowingly collect their personal data.

11. Changes and contact

We may update this policy; the “Last updated” date reflects the current version. Questions or requests: [PRIVACY / DATA-PROTECTION EMAIL], or see Contact & Support.

Template grounded in how galerija operates; not legal advice. Have it reviewed for compliance with the Law on Personal Data Protection of the Republic of North Macedonia (and GDPR where relevant) before publication.

Privacy Policy · galerija