Privacy Policy
Last updated: 3 September 2026
This policy explains how Collectiverse General Trading LLC (License No. 1639822), Dubai, United Arab Emirates (“Collectiverse”, “we”) collects, uses and protects personal data when you use collectiverse.me. We process personal data in line with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and other applicable law.
1. What we collect
- Account data — name, email, password (stored as a secure hash by our auth provider), phone if you add it.
- Order data — items bought, amounts, currency, shipping address, delivery tracking.
- Payment data — handled by our payment providers (Stripe for cards and Apple Pay; Tabby for pay-in-instalments). We receive payment status and references only; we never see or store your full card number. If you choose Tabby, the name, email, phone number and delivery address you enter are sent to Tabby to open the payment, and Tabby assesses your eligibility under its own privacy policy.
- Card Analyzer images — the card photos you upload to our Card Analyzer tool, which are sent to an AI provider (Anthropic) to produce the condition estimate and are not used to train their models. Results are linked to your account so you can see your history; the tool requires an account and is rate-limited per user.
- Newsletter data— email, confirmation status, and delivery events (bounces, complaints) so we never email people who don't want it. Subscription uses double opt-in.
- Trading data — listings and offers you create, which are shown to relevant users as described on the Site. Offer messages are stored and may be reviewed by our team for safety, fraud prevention and moderation.
- Technical data— IP address, device and browser information, and analytics data about how the Site is used. Security systems (rate limiting, bot protection, audit trails) process IP addresses to protect the platform. When you check out, we store the analytics identifiers from your browser's Google Analytics cookie with your order, so that a completed purchase can be attributed to the visit that led to it, along with your IP address, browser user agent and approximate location (city and country) for fraud prevention and order-abuse detection. Where the Meta Pixel is active, the same applies to the Pixel's browser and ad-click identifiers (the _fbp and _fbc cookies), stored with your order for the purchase reporting described below.
2. Why we use it
- To operate your account, process orders, ship goods, and provide support (performance of a contract).
- To send transactional messages — order confirmations, shipping updates, security emails (contractual necessity).
- To send marketing emails only where you have confirmed a subscription, with one-click unsubscribe in every message (consent).
- To prevent fraud, enforce our Terms, secure the platform, and keep audit records of administrative actions (legitimate interest / legal obligation).
- To comply with UAE legal, tax and accounting obligations.
We do not sell personal data, and we do not display third-party advertising on the Site. We use Google Analytics to understand how the Site is used; Google processes this data as described in the Cookies section below. We also advertise Collectiverse on Google and use Google Ads conversion tracking to measure which ads lead to orders, subscriptions and enquiries (legitimate interest in measuring our own marketing). Conversion measurement happens both in your browser and from our servers: when an order is confirmed paid, our systems report the purchase (order number, amount, items) to Google Analytics so the sale is counted even if your browser blocks analytics scripts. On the order confirmation page, the email address and phone number you gave at checkout are passed to Google's tag, which one-way hashes them in your browser before sending (Google's 'enhanced conversions'); Google uses the hashes only to match the purchase to an ad click, never to contact you. We have also enabled Google Signals, which lets Google Analytics combine our site data with the profiles of users who are signed in to Google and have Ads Personalization switched on, giving us aggregate demographic and cross-device reporting — you can turn this off for your Google account at adssettings.google.com. We advertise on Meta platforms (Facebook and Instagram) and use the Meta Pixel to measure those campaigns on the same basis. When an order is confirmed paid, our servers also report the purchase to Meta together with your email address, phone number and (if you have an account) your Collectiverse account ID, each protected by one-way hashing (SHA-256), plus the IP address and browser user agent recorded at checkout and the Pixel's own browser and click identifiers. Meta uses these only to match the event to an ad interaction and to de-duplicate it against the Pixel; your email and phone are never sent in readable form.
3. Who we share it with
We share data only with the service providers needed to run the platform, each bound by their own data protection commitments:
- Supabase — database, authentication and file storage.
- Stripe — card and Apple Pay payment processing.
- Tabby — pay-in-instalments checkout; receives your name, email, phone and delivery address to open and assess the payment.
- Anthropic — AI analysis of the card photos you upload to the Card Analyzer; images are processed to return a result and are not used for model training.
- Resend — email delivery.
- Vercel — hosting and privacy-friendly analytics.
- Google — website analytics (Google Analytics) and advertising conversion measurement (Google Ads), including server-side purchase reporting (order number, amount and items) when an order is confirmed paid and browser-hashed email and phone on the confirmation page for enhanced conversions; and the Google Customer Reviews programme (order number, email, delivery country and date) only when you opt in on the confirmation page, as described in the Cookies section.
- Meta — advertising measurement on Facebook and Instagram (Meta Pixel and Conversions API). Confirmed purchases are reported from our servers with your email address, phone number and account ID one-way hashed (SHA-256), together with checkout IP address, browser user agent and Pixel identifiers, for matching and de-duplication only, as described in the Cookies section.
- Cloudflare — bot protection on our public forms (Turnstile), which analyses browser signals and IP address to distinguish humans from automated traffic.
- Upstash — rate limiting, which briefly processes IP addresses to block abusive request volumes.
- Shipping carriers — name, address and phone, to deliver your orders.
We may also disclose data where required by law, court order, or to protect our rights, users, or the public, and as part of a business transfer subject to this policy.
4. International transfers
Some providers process data outside the UAE (for example on infrastructure in Asia, Europe or the United States). Where data leaves the UAE we rely on the safeguards permitted by the PDPL, including processing necessary for the performance of our contract with you and providers' contractual data protection commitments.
5. Retention
Account and order records are kept while your account is active and thereafter as required for legal, tax and accounting purposes (generally at least 5 years for transaction records under UAE law). Newsletter data is kept until you unsubscribe; suppression records (bounces, complaints, unsubscribes) are kept so we don't email you again. Security and audit logs are retained for as long as needed for their purpose. Trade chat messages are automatically and permanently deleted 30 days after they are sent; limited copies may be preserved longer where reasonably required for dispute investigation, fraud prevention or legal obligations.
6. Security
We use industry-standard measures: encrypted connections (TLS), hashed passwords, two-factor authentication (mandatory for administrator accounts), database row-level access controls, role-based admin access with audit logging and idle-session timeouts, rate limiting, bot protection, signed and verified payment webhooks, and strict security headers. No system is perfectly secure — if we become aware of a breach affecting your data we will act in accordance with the PDPL, including notification where required.
7. Your rights
Subject to the PDPL, you can:
- request access to and a copy of your personal data;
- ask us to correct inaccurate data (name and profile details can be edited in your account);
- request deletion of your account and data, subject to records we must keep by law;
- withdraw marketing consent at any time — every email has a one-click unsubscribe;
- object to or ask us to restrict certain processing, and complain to the UAE Data Office.
To exercise any right, email hello@collectiverse.me. We may need to verify your identity before acting.
8. Cookies
We use three kinds of cookies and similar technologies:
- Essential — authentication session cookies (httpOnly, secure) that keep you signed in, and security cookies that protect forms and admin sessions. The Site cannot work without these.
- Security— Cloudflare Turnstile may set cookies while verifying that you are human on our public forms. See Cloudflare's privacy policy for details.
- Analytics — Google Analytics sets cookies (such as
_ga) to measure how the Site is used. You can opt out with Google's browser add-on (tools.google.com/dlpage/gaoptout) or by blocking these cookies in your browser — the Site works fully without them. Vercel Analytics is cookie-free and aggregate. - Advertising — Google Ads sets cookies and similar identifiers to attribute a purchase or signup back to an advertisement you clicked. They measure our own advertising; we do not sell your data and we do not show third-party ads on the Site. You can opt out at adssettings.google.com or by blocking these cookies in your browser — the Site works fully without them. We use Google's Consent Mode: if you visit from the European Economic Area, the United Kingdom or Switzerland, advertising and analytics cookies are switched off by default and Google receives only cookieless, aggregate signals.
- Google Customer Reviews — after a confirmed order, Google may show a small prompt on our confirmation page asking whether you would like to rate your purchase. If you say yes, Google receives your order number, email address, delivery country and estimated delivery date (and the product barcodes), and emails you one survey after delivery. Google may set and read cookies or use similar technologies on that page in connection with the programme; you can manage or block them in your browser settings. If you say no or ignore the prompt, nothing is sent and no survey is emailed.
- Advertising (Meta) — the Meta Pixel sets cookies and identifiers so we can measure Facebook and Instagram campaigns and reach similar audiences. Purchases are additionally confirmed from our servers (with one-way-hashed email, phone and account ID, plus the Pixel identifiers, IP address and browser details recorded at checkout) and de-duplicated against the Pixel, so blocking the cookies does not stop your order from working. You can control this in your Meta ad preferences or by blocking these cookies — the Site works fully without them.
We do not display third-party advertising on the Site, and we do not use these cookies to build profiles for anyone else.
9. Children
The Site is for adults. We do not knowingly collect data from anyone under 18; if you believe a minor has created an account, contact us and we will delete it.
10. Changes & contact
We may update this policy as the platform evolves; the date above reflects the latest version, and material changes will be communicated on the Site or by email. Data controller: Collectiverse General Trading LLC · License No. 1639822 · Dubai, United Arab Emirates · hello@collectiverse.me.