Gleam It

Legal

Privacy Policy

Last updated 3 August 2026

This policy explains how Gleam It processes personal data when you browse the service, create an account, buy a membership, list an item, exchange goods, contact support, or use community features.

1. Controller and scope

Gleam It, NIF 321972163, Rua de Alcântara 35, piso 1, 1300-027 Lisboa, Portugal, is the controller for the marketplace service. Privacy questions and rights requests may be sent to [email protected].

2. Data we collect

  • Waitlist data: name, email, Lisbon municipality, the ages - not names - of children in the household, inviter/referral attribution, acquisition source, language, consent timestamp, and verification, withdrawal, and registration status.
  • Account and profile data: email, name, profile photo, language, Lisbon municipality, and the ages - not names - of children in the household.
  • Listing and exchange data: photographs, descriptions, brand, category, condition, original-price estimate, points value, saved items, requests, confirmations, cancellations, messages, ratings, reports, and moderation records.
  • Membership and payment data: plan, billing interval, subscription status, Stripe customer/subscription identifiers, invoice status, and renewal dates. Gleam It does not store full card numbers.
  • Technical and usage data: a one-way HMAC hash of IP address for waitlist rate limiting and abuse review, device/browser and referrer information, consent choices, diagnostics, and - only with consent - product analytics.
  • Communications: waitlist verification and launch emails, Contact Us and support messages, the sender’s name and email, and account-administration correspondence.

3. Why and legal bases

  • Contract: create and secure accounts, provide listings, messages, swaps, points, memberships, billing, and support.
  • Legitimate interests: prevent fraud, moderate content, keep an auditable points ledger, improve reliability, diagnose errors, and protect members, balanced against member rights.
  • Consent: waitlist communications, optional analytics, and any optional marketing communication. Waitlist consent can be withdrawn through the unsubscribe link in every waitlist email.
  • Legal obligations: tax/accounting records, consumer rights, lawful requests, dispute handling, and establishment or defence of legal claims.

4. AI-assisted listings

Uploaded listing photos may be processed to clean backgrounds, identify item details, check safety/content, and research a retail-value estimate. AI suggestions can be inaccurate; members must review listing details before publication. Do not upload faces, addresses, documents, or other unnecessary personal data.

5. Sharing and processors

  • Supabase for authentication and database services; Railway for application hosting and background jobs; Cloudflare for image delivery and related infrastructure.
  • Stripe for checkout, recurring billing, invoices, and subscription administration; Resend for transactional email.
  • PhotoRoom and Anthropic for photo and listing-assistance workflows; Sentry for error diagnostics; PostHog for optional analytics after consent.
  • Google where a member chooses Google sign-in, and professional advisers or authorities where legally required.

6. International transfers

Some suppliers may process data outside Portugal or the EEA. We use provider commitments, adequacy decisions, Standard Contractual Clauses, and supplementary safeguards where required. Counsel should confirm and document the final processor locations before production launch.

7. Retention

  • Waitlist data is kept until you unsubscribe, create an account, or for up to 12 months after the launch campaign ends, whichever comes first, unless we need a narrow retention period for fraud prevention or legal claims.
  • Account data is kept while the account is active and then deleted or anonymised, subject to lawful retention.
  • Points ledger, billing, fraud, moderation, dispute, and audit records may be retained for the applicable limitation, accounting, and legal periods.
  • Contact requests are retained only as long as needed to answer and document the request, normally no longer than 24 months unless a dispute or law requires longer.
  • Deleted message bodies and listing media are removed or anonymised through the deletion workflow; transaction facts may remain without directly identifying profile content.

8. Your GDPR rights

Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; and complain to Portugal’s Comissão Nacional de Proteção de Dados (CNPD). We may need to verify identity. Rights requests can be sent to [email protected].

9. Children

Gleam It is for adults. Children may not create accounts. Household age information is used only to improve marketplace relevance; members must not post a child’s name, face, contact information, school, or other identifying details.

10. Security and changes

We use role-based access, protected provider credentials, database controls, encrypted transport, audit records, and monitoring. No service is completely secure. Material policy changes will be communicated in the service or by email where required.

Gleam It
NIF 321972163
Address: Rua de Alcântara 35, piso 1, 1300-027 Lisboa
[email protected]