Legal

Privacy Policy

Last updated July 27, 2026

Who we are (Data Controller)

This Privacy Policy explains how we collect, use, and protect your personal data when you use the MarketDay mobile application and website (the "Service"). The Service is provided only to users in the Republic of Ireland, and we process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Irish Data Protection Act 2018.

The data controller responsible for your personal data is:

  • Controller — MarketDay (sole trader)
  • Trading as — MarketDay
  • Address — 14 Dame Street, Dublin 2, D02 X285, Ireland
  • Email — privacy@marketday.app

MarketDay is operated by a single individual. We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR — all privacy queries should be sent to the email address above.

Scope of the Service

The Service allows buyers to discover local farmer markets in Ireland, browse vendor products, and place pre-orders for collection in person at the market stall.

We do not process payments. All payment for pre-ordered goods takes place directly between you and the vendor at the point of collection. We do not collect or store card details, bank details, or any financial information.

Personal data we collect

Data you provide directly:

  • Account (all users) — email address; password, stored only as a cryptographic hash — we never store your password in readable form; your Google account identifier, email, and name, if you choose to sign in with Google; and an optional display name.
  • Buyers — order contents (products, quantities, prices), optional notes attached to an order, and your order history.
  • Vendors — business or stall name, business description and product category, product listings (names, descriptions, prices, images), profile and product images you upload, and the market at which you trade.

Data collected automatically:

  • Push notification token — an anonymous identifier issued by Expo/Apple/Google, used solely to send you notifications about your orders.
  • Location — approximate or precise location, only if you grant location permission, and only to show markets near you. Your location is used on-device and in transient queries — we do not store a history of your location.
  • Technical and log data — IP address, device type, operating system version, app version, and timestamps of requests, recorded in server logs for security and troubleshooting.

Special category data: we do not intentionally collect special category data (Article 9 GDPR) such as health, religious, or political data. Please do not include such information in free-text fields, for example order notes. Note that dietary preferences you voluntarily disclose in a note may reveal such information — we ask you not to provide it.

Who we share your data with

Important for buyers: when you place a pre-order, the vendor receives your display name, email address, order contents, and any notes you include. This is necessary so the vendor can prepare and hand over your order. Vendors act as independent data controllers in respect of the order information they receive, and are responsible for their own use of that information.

We use the following service providers to operate the Service. Each processes data only on our documented instructions, under a data processing agreement:

  • Railway Corp. — application and database hosting — all account, order, and log data — USA / EU regions.
  • Cloudflare, Inc. (R2) — image storage — product and profile images — global CDN.
  • Expo (650 Industries, Inc.) — push notification delivery — push tokens, notification content — USA.
  • Resend (Plus Five Five, Inc.) — transactional email delivery — email address, email content — USA.
  • Google Ireland Ltd. / Google LLC — "Sign in with Google" authentication — email, name, Google account ID — EU / USA.
  • Vercel Inc. — hosting of the administrative dashboard — administrator session data — USA.

We do not sell your personal data, and we do not share it with advertisers or data brokers.

We may also disclose personal data where required by Irish or EU law, by court order, or to establish, exercise, or defend legal claims.

International transfers

Some of our providers are established in the United States. Where personal data is transferred outside the European Economic Area, we rely on:

  • Standard Contractual Clauses approved by the European Commission (Article 46(2)(c) GDPR), incorporated into our agreements with each provider; and
  • where applicable, the provider's certification under the EU–US Data Privacy Framework (Article 45 GDPR adequacy decision).

You may request a copy of the relevant safeguards by contacting us at privacy@marketday.app.

How long we keep your data

  • Account data (active account) — kept until you delete your account.
  • Account data after deletion request — anonymised immediately — see below.
  • Order records — 6 years from the date of the order, in anonymised form after account deletion.
  • Password reset codes — 15 minutes, then deleted.
  • Refresh tokens — until logout, password reset, or expiry (7 days).
  • Server and security logs — 30 days.
  • Push notification tokens — until you uninstall the app or disable notifications.

Anonymisation instead of deletion: when you request deletion of your account, we replace your identifying data (email, name, Google ID, password hash, push token) with irreversible placeholder values. Your order records remain in the system in a form that can no longer be linked to you, because vendors need accurate historical records of transactions and we may need them for tax and accounting purposes. Once anonymised, the data is no longer personal data under the GDPR.

Security

We apply technical and organisational measures appropriate to the risk, including:

  • Passwords hashed with bcrypt; plaintext passwords are never stored or logged.
  • All traffic encrypted in transit using TLS.
  • Database encryption at rest, as provided by our hosting provider.
  • Short-lived access tokens and rotating refresh tokens.
  • Rate limiting on authentication and password-reset endpoints.
  • Access to production systems restricted to the operator of the Service alone.

No system is completely secure. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours and, where the risk is high, we will notify you directly.

Your rights

Under the GDPR you have the right to:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted, subject to the anonymisation approach described above.
  • Restriction — ask us to limit how we use your data.
  • Portability — receive your data in a structured, machine-readable format, or have it transmitted to another controller.
  • Object — object to processing based on legitimate interests.
  • Withdraw consent — at any time, where processing is based on consent — this does not affect the lawfulness of processing carried out before withdrawal.
  • Not be subject to automated decision-making — we do not carry out automated decision-making or profiling that produces legal or similarly significant effects.

To exercise any of these rights, email privacy@marketday.app. We will respond within one month — this period may be extended by two further months for complex requests, in which case we will tell you within the first month. Exercising your rights is free of charge, unless a request is manifestly unfounded or excessive.

Account deletion can also be carried out directly in the app under Profile → Settings → Delete account.

Children's privacy

The Service is not intended for children. Under section 31 of the Data Protection Act 2018, the digital age of consent in Ireland is 16 — you must be at least 16 years old to create an account. If we become aware that we hold personal data relating to a person under 16, we will delete it without undue delay.

Cookies and similar technologies

The mobile application does not use cookies. It stores authentication tokens in the device's secure storage, which is strictly necessary for you to remain signed in.

The administrative dashboard, used only by our own staff, uses strictly necessary cookies to maintain a login session. We do not use analytics, advertising, or tracking cookies anywhere in the Service. If this changes, we will request your consent in advance in accordance with the ePrivacy Regulations (S.I. No. 336 of 2011).

Changes to this policy

We may update this policy from time to time. The "last updated" date at the top will always reflect the current version. If we make material changes — for example, introducing online payments or a new category of processing — we will notify you in the app or by email before the changes take effect.

Complaints

If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Irish supervisory authority:

  • Data Protection Commission — 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland — www.dataprotection.ie — +353 (0)1 765 0100 / 1800 437 737.

You may also lodge a complaint with the supervisory authority of your habitual residence or place of work.

Contact us

Questions about this policy or your data? Reach our privacy team directly, or visit our Contact page.

Email: privacy@marketday.app
Post: MarketDay, 14 Dame Street, Dublin 2, D02 X285, Ireland
MarketDay
MarketDay

Pre-order the freshest produce from your local market. Made in Dublin, for market days everywhere.

© 2026 MarketDay. All rights reserved.