Privacy Policy & Security Standards
This document outlines how your identity metrics, geolocations, and financial pathways are insulated under our local application layer protocols.
1. Data Elements We Collect
To safely verify user permissions and run local clean-out transactions, the platform collects the following mandatory registration points:
- Account Properties: Legal name, validated email address string channels, and hashed password strings.
- Venue Boundaries: Physical street addresses, target cities, and zip codes provided exclusively by Sellers to map out local driveway pickup obligations.
- Compliance Metrics: Completion star ratings and unverified pickup tracking percentages calculated locally to prevent fraud or platform abandonment.
2. Real-Time Geolocation Visibility Restrictions
We respect the privacy of a Seller's personal property lines. When a Seller creates an auction event catalog, the application layer strictly suppresses the exact house number and street location coordinates from public indexes. Outside buyers can only view the general target city, state, and zip code boundary lines.
The Release Hook: The exact driveway collection address is encrypted on our data tables and is automatically released strictly to winning Buyers via itemized billing receipts *only* after their multi-item consolidated invoice has been cleared by Stripe processing nodes.
3. Insulation of Cardholder Financial Metadata
Self-Service Auctions does not store, transmit, or record raw credit card digits, CVV codes, or bank account parameters onto our local hosting directory lines. All card verification checks, 3D Secure 2FA loops, payout split setups, and balance encryptions are offloaded directly to **Stripe API payment nodes** over tokenized channels.
Your processing interaction operates cleanly within Stripe’s PCI-DSS Level 1 compliant financial framework layers.
4. Automated Communications & Staging Queue
Transactional messages (invoice distributions, outbid alerts, and multi-item manifests) are formatted on our servers and logged as pending data arrays inside our localized database `email_queue`. These records are securely parsed and transferred asynchronously to **Resend API lines** every 60 seconds by our cron engines. Your email profiles are used strictly for operational auction tracking alerts and are never rented, sold, or shared with external marketing brokers.
5. Session Hardening & Shared Server Isolation
As an adaptive security shield against shared cPanel directory sniffing vectors, this application overrides public server cache bins. All raw user session data arrays are routed away from the common `/tmp` path and saved into an isolated, protected folder structure (`/includes/sessions/`) locked to owner-only read restrictions (`0700`). This completely prevents neighboring shared-server partitions from inspecting or capturing active profile authorization keys.
6. Platform Maintenance Contact
This privacy wrapper and data flow matrix is engineered and maintained by Darr Web Solutions. For specific administrative details, database profile removal tracking requests, or system compliance architecture questions, users are encouraged to submit an official support ticket directly via the platform core tracking console dashboard.