Privacy Policy
Last updated: June 2026
1. Data controller
WornBloom operates this platform and acts as the data controller for personal data collected through it. For privacy-related questions, contact privacy@wornbloom.com.
2. Data we collect
We collect the data you provide on registration (email address, display name, handle), verification data (government ID, selfie) for sellers, payment-related data processed by Stripe, and usage data (pages visited, search queries, device type, IP address).
3. How we use your data
We use your data to operate your account, process transactions, verify seller identity, provide customer support, detect and prevent fraud and abuse, comply with legal obligations, and improve our services. We do not sell your personal data to third parties.
4. Verification data
Seller ID documents and selfies are stored in a private, access-controlled storage bucket. They are only accessed by the WornBloom moderation team for the purpose of verification and are deleted upon account closure unless we are required by law to retain them.
5. Payment data
All payment processing is handled by Stripe, Inc. WornBloom does not store full card numbers or bank details. Stripe's privacy policy governs the handling of payment information at stripe.com/privacy.
6. Cookies
We use essential cookies to keep you logged in and remember your preferences. We may use analytics cookies to understand how the platform is used in aggregate. You can manage cookie preferences in your browser settings.
7. Data sharing
We share your data with Stripe (payments), Supabase (database and authentication infrastructure), and Resend (transactional email). All processors are contractually obligated to protect your data. We may disclose data to law enforcement when required by valid legal process.
8. Data retention
Account data is retained for as long as your account is active. Upon deletion, personal data is removed within 30 days except where retention is required by law (e.g. financial records).
9. Your rights
Depending on your jurisdiction, you may have the right to access, rectify, erase, restrict, or port your personal data, and to object to certain processing. To exercise these rights, email privacy@wornbloom.com. EU/EEA residents have rights under GDPR.
10. Security
We use industry-standard measures including TLS encryption in transit, encrypted storage, and row-level security in our database. No system is perfectly secure; we will notify you of any breach that affects your personal data as required by law.
11. Changes
We may update this policy at any time. Material changes will be communicated by email. Continued use after the effective date constitutes acceptance. Last updated: June 2026.