Privacy / Prelaunch
Privacy
1. Controller
Mono Jacobi, Stargarder Straße 17, 10437 Berlin, Germany. Contact: hello@thenintharchive.com.
2. Account and application data
When the server is configured, account credentials, waitlist requests and seller applications are processed by the application server and stored in its Postgres database. Passwords are salted and hashed. Seller applications collect contact details and inventory descriptions; tax and identity documents are not collected by the public application form.
3. Access and privacy choices
An essential HTTP-only session cookie expires after eight hours and is revoked on sign-out. Session tokens are stored only as keyed hashes on the server. Invitations are personal and single-use. Local storage retains privacy choices and prototype preferences. Optional analytics is off unless expressly accepted; no advertising pixels are loaded.
4. Payment and email previews
Seller membership billing uses Stripe Checkout and the Stripe Customer Portal when configured. Payment details are entered on Stripe, not on this website. The platform stores Stripe customer and subscription identifiers, membership status and minimal event receipts; invoices are retrieved from Stripe. Email previews in the marketplace prototype are not sent messages. Marketplace orders and payouts are not yet connected to live payment processing.
5. Deletion
Browser settings can clear local prototype data. Clearing browser storage does not delete server-side accounts, applications, sessions or billing records. Contact the controller about access, correction or deletion; billing and statutory record-retention obligations must be assessed before deletion.
6. Personalisation
Where enabled, recommendations are derived from explicit follows, saved items, views and purchases. Users can reject optional preference storage. The beta does not use sensitive attributes for recommendations.
7. Production operation
Before production launch, this notice must be legally reviewed and completed for hosting, database storage, authentication, payment providers, email delivery, moderation, retention periods, legal bases, recipients, consent withdrawal and data-subject rights.