Last Updated: July 2026
Data Governance Protection

Privacy Policy & Security Standards

This document outlines how your identity metrics, geolocations, and financial pathways are insulated under our local application layer protocols.

🛡️ Cryptographic Anonymization Protocol Active: To protect users from marketplace profile harvesting or targeted tracking, all public bidding ledgers completely mask individual stakeholder identities. Public-facing data arrays convert core tracking indices into cryptographically salted, non-reversible tokens (e.g., Bidder #4a8d). Your personal identity remains invisible to the public during all bidding wars.

1. Data Elements We Collect

To safely verify user permissions and run local clean-out transactions, the platform collects the following mandatory registration points:

  • Account Properties: Legal name, validated email address string channels, and hashed password strings.
  • Venue Boundaries: Physical street addresses, target cities, and zip codes provided exclusively by Sellers to map out local driveway pickup obligations.
  • Compliance Metrics: Completion star ratings and unverified pickup tracking percentages calculated locally to prevent fraud or platform abandonment.

2. Real-Time Geolocation Visibility Restrictions

We respect the privacy of a Seller's personal property lines. When a Seller creates an auction event catalog, the application layer strictly suppresses the exact house number and street location coordinates from public indexes. Outside buyers can only view the general target city, state, and zip code boundary lines.

The Release Hook: The exact driveway collection address is encrypted on our data tables and is automatically released strictly to winning Buyers via itemized billing receipts *only* after their multi-item consolidated invoice has been cleared by Stripe processing nodes.

3. Insulation of Cardholder Financial Metadata

Self-Service Auctions does not store, transmit, or record raw credit card digits, CVV codes, or bank account parameters onto our local hosting directory lines. All card verification checks, 3D Secure 2FA loops, payout split setups, and balance encryptions are offloaded directly to **Stripe API payment nodes** over tokenized channels.

Your processing interaction operates cleanly within Stripe’s PCI-DSS Level 1 compliant financial framework layers.

4. Automated Communications & Staging Queue

Transactional messages (invoice distributions, outbid alerts, and multi-item manifests) are formatted on our servers and logged as pending data arrays inside our localized database `email_queue`. These records are securely parsed and transferred asynchronously to **Resend API lines** every 60 seconds by our cron engines. Your email profiles are used strictly for operational auction tracking alerts and are never rented, sold, or shared with external marketing brokers.

5. Session Hardening & Shared Server Isolation

As an adaptive security shield against shared cPanel directory sniffing vectors, this application overrides public server cache bins. All raw user session data arrays are routed away from the common `/tmp` path and saved into an isolated, protected folder structure (`/includes/sessions/`) locked to owner-only read restrictions (`0700`). This completely prevents neighboring shared-server partitions from inspecting or capturing active profile authorization keys.

6. Platform Maintenance Contact

This privacy wrapper and data flow matrix is engineered and maintained by Darr Web Solutions. For specific administrative details, database profile removal tracking requests, or system compliance architecture questions, users are encouraged to submit an official support ticket directly via the platform core tracking console dashboard.