Privacy policy

Your data should move only when the feature does.

This notice explains what Adalysta processes for its marketplace, which features are optional, and which provider-dependent services remain inactive until they are explicitly enabled.

Last updated September 2, 2026

1. Who controls marketplace data

Adalysta determines why and how personal data is used for the Adalysta marketplace and acts as the controller for that processing. Privacy and data-rights requests can be opened through authenticated in-app support or the paths described on our Support page.

Other companies may be separate controllers for services you deliberately use, such as a login provider, identity-verification provider, payment provider, delivery service, or an external marketplace. Their own notices apply to their processing.

2. Data we collect

  • Account and profile: name, handle, account identifiers, login-provider details, business role, preferences, badges, ratings, review responses, and verified-sale history.
  • Marketplace content: listings, photos, descriptions, prices, categories, fulfillment and payment terms, saved items, offers, messages, reviews, and seller replies.
  • Trust and support: reports, evidence references, blocked users, support tickets, dispute or recovery context, moderation actions, and account-deletion requests.
  • Device and use: session, security, diagnostics, notification tokens, feature usage, language, theme, and similar device or browser information.
  • Location: a place you enter or approximate location derived with device permission, used to rank nearby listings and estimate distance.
  • Business information: organization, dealership, wholesaler, or dropseller details and inventory records submitted for a business workspace.

Do not place passwords, payment-card details, wallet seed phrases, government identifiers, or unrelated sensitive information in listings, messages, reports, or support tickets.

3. Why we process it

We process data to create and secure accounts; publish and find listings; calculate marketplace relevance; enable messages, offers, reviews, support, and notifications; operate business workspaces; prevent fraud and abuse; investigate reports; enforce marketplace rules; maintain records; and comply with legal obligations.

Depending on the country and context, the basis is performance of our service agreement, your consent, our legitimate interests in a useful and safe marketplace, or a legal obligation. Withdrawing optional consent does not make the manual, non-AI marketplace unavailable where the underlying feature does not need that consent.

4. Optional AI and assistant features

The free marketplace is designed to work without AI. Ada workflows such as drafting, enrichment, translation, price guidance, semantic search, negotiation assistance, or support summaries are optional and must be deliberately invoked. When a workflow is enabled and requested, it may process the listing, message, instruction, or other context needed to return that result.

AI provider access, quotas, model routing, MCP tools, and external-channel export or publishing are capability-gated. Describing a future workflow does not mean it is active, and Adalysta does not silently publish a listing to another marketplace. Before a new provider is activated for personal data, its role, location, retention terms, safeguards, and any required consent must be established.

Fraud detection, service security, and moderation may use automated signals under a safety or legitimate-interest basis rather than optional AI consent. Material enforcement decisions should remain reviewable by a person, and users can challenge a decision through support.

5. Identity verification and badges

Identity verification is separate from social login. If verification is available and you choose or are required to start it for a privileged account, an approved KYC provider may receive identity-document, selfie, liveness, and related verification data. Adalysta may receive the outcome, provider reference, verified attributes, and risk signals needed to issue or revoke an Identity Verified badge.

A verification control shown as unavailable does not send KYC data. A badge reduces uncertainty but is not a guarantee that a person, item, payment, or transaction is safe.

6. Location, physical goods, and payments

You can enter a location manually or grant device location permission. We use location to show relevant physical-goods listings and estimated distance. You can deny or withdraw device permission and use a manually selected area instead. Avoid publishing an exact home address in a public listing.

Seller-selected cash, bank, card, crypto, shipping, and pickup options can be declarations of accepted terms rather than Adalysta checkout. Unless a protected checkout capability is explicitly shown as active, Adalysta does not process or protect that payment. When a payment or payout provider is enabled and you use it, the provider receives the transaction, identity, bank, tax, device, and risk data it requires under its own terms.

Monolythium crypto settlement and other future payment methods remain provider-gated. A disabled or future payment label does not create a wallet, move funds, or disclose payment data.

7. When data is shared

Public profile and listing fields are visible to marketplace visitors. Messages, offers, reports, identity details, and support records are not public by default. We share only what is necessary with configured hosting, database, search, media, communications, analytics, security, moderation, identity, payment, and professional-service providers; with another user to complete an action you requested; or with authorities when legally required or necessary to address an immediate and credible safety risk.

Login providers such as Apple, Google, Facebook, GitHub, Discord, or Telegram receive data only when that provider is configured and you choose it. External inventory and marketplace connectors, including future Amazon inventory or channel-export tools, remain inactive until configured and invoked.

We do not describe user reports as police reports and do not automatically file a police report. Users remain responsible for contacting the appropriate authority when they want to make an official report.

8. International operation

Adalysta is intended to operate across multiple countries, initially including markets in North America, Europe, Asia, Latin America, and Australia. Hosting, support, and configured providers may process data outside the country where you live. Where required, we use an approved transfer mechanism and provider safeguards. Local consumer, privacy, and law-enforcement rights still vary by market.

9. Retention and deletion

We keep account and marketplace data while the account is active and as needed to provide the service. Retention can continue for fraud prevention, payment or tax records, disputes, chargebacks, safety investigations, moderation appeals, legal claims, and other legal obligations. Different records can therefore have different retention periods.

You can submit an authenticated deletion request in the app or on the Delete account page. Requests use a cooling-off and processing workflow rather than claiming immediate erasure. After processing, data is deleted or de-identified unless a lawful reason requires limited retention. Content another user must retain for their own transaction, safety, or legal record may not disappear from that user's records.

10. Your choices and rights

You can edit profile and listing information, control device permissions and notifications, avoid optional AI, block users, and request account deletion. Depending on local law, you may also ask to access, correct, export, restrict, object to, or erase personal data; withdraw consent; challenge an automated outcome; or complain to a privacy regulator.

Use authenticated support so we can verify that a requester controls the account. We may ask for proportionate verification before disclosing or deleting data. Privacy choices do not remove records we must keep or prevent processing needed to secure the service.

11. Security and changes

We use access controls, scoped service credentials, encryption where appropriate, audit records, and provider gates intended to limit unauthorized processing. No online service can promise absolute security. Report suspected account compromise through Support and contact your login or payment provider directly when relevant.

We will update this notice when processing materially changes and will request new consent where the law requires it. A newly announced feature stays unavailable until its operational, security, provider, and legal gates are satisfied.