Who we are (Data Controller)
This Privacy Policy explains how we collect, use, and protect your personal data when you use the MarketDay mobile application and website (the "Service"). The Service is provided only to users in the Republic of Ireland, and we process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Irish Data Protection Act 2018.
The data controller responsible for your personal data is:
- Controller — MarketDay (sole trader)
- Trading as — MarketDay
- Address — 14 Dame Street, Dublin 2, D02 X285, Ireland
- Email — privacy@marketday.app
MarketDay is operated by a single individual. We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR — all privacy queries should be sent to the email address above.
Scope of the Service
The Service allows buyers to discover local farmer markets in Ireland, browse vendor products, and place pre-orders for collection in person at the market stall.
We do not process payments. All payment for pre-ordered goods takes place directly between you and the vendor at the point of collection. We do not collect or store card details, bank details, or any financial information.
Personal data we collect
Data you provide directly:
- Account (all users) — email address; password, stored only as a cryptographic hash — we never store your password in readable form; your Google account identifier, email, and name, if you choose to sign in with Google; and an optional display name.
- Buyers — order contents (products, quantities, prices), optional notes attached to an order, and your order history.
- Vendors — business or stall name, business description and product category, product listings (names, descriptions, prices, images), profile and product images you upload, and the market at which you trade.
Data collected automatically:
- Push notification token — an anonymous identifier issued by Expo/Apple/Google, used solely to send you notifications about your orders.
- Location — approximate or precise location, only if you grant location permission, and only to show markets near you. Your location is used on-device and in transient queries — we do not store a history of your location.
- Technical and log data — IP address, device type, operating system version, app version, and timestamps of requests, recorded in server logs for security and troubleshooting.
Special category data: we do not intentionally collect special category data (Article 9 GDPR) such as health, religious, or political data. Please do not include such information in free-text fields, for example order notes. Note that dietary preferences you voluntarily disclose in a note may reveal such information — we ask you not to provide it.
Why we use your data and our legal basis
For each purpose below, we rely on one of the legal bases set out in Article 6 GDPR:
- Creating and managing your account — email, password hash, Google ID, and role — necessary to perform our contract with you (Art. 6(1)(b)).
- Processing and fulfilling pre-orders — order details and buyer/vendor details — necessary to perform our contract with you (Art. 6(1)(b)).
- Sending transactional notifications about your order status — push token and order status — necessary to perform our contract with you (Art. 6(1)(b)).
- Sending password reset codes by email — email address and a one-time code — necessary to perform our contract with you (Art. 6(1)(b)).
- Showing markets near your location — device location — based on your consent, given through the device permission and withdrawable at any time in settings (Art. 6(1)(a)).
- Displaying vendor profiles and products publicly in the app — vendor business data and product data — necessary to perform our contract with the vendor (Art. 6(1)(b)).
- Keeping the Service secure, preventing abuse and fraud, diagnosing faults — log data and IP address — our legitimate interest in operating a secure service (Art. 6(1)(f)).
- Retaining order records after account closure — anonymised order data — our legitimate interest in the integrity of vendor records (Art. 6(1)(f)).
- Optional marketing or product-update emails, if introduced — email address — based on your consent, opt-in and withdrawable at any time (Art. 6(1)(a)).
Where we rely on legitimate interests, we have carried out a balancing assessment and consider that our interest in operating a secure and reliable service does not override your rights and freedoms. You may object to this processing at any time — see Your rights below.
Who we share your data with
Important for buyers: when you place a pre-order, the vendor receives your display name, email address, order contents, and any notes you include. This is necessary so the vendor can prepare and hand over your order. Vendors act as independent data controllers in respect of the order information they receive, and are responsible for their own use of that information.
We use the following service providers to operate the Service. Each processes data only on our documented instructions, under a data processing agreement:
- Railway Corp. — application and database hosting — all account, order, and log data — USA / EU regions.
- Cloudflare, Inc. (R2) — image storage — product and profile images — global CDN.
- Expo (650 Industries, Inc.) — push notification delivery — push tokens, notification content — USA.
- Resend (Plus Five Five, Inc.) — transactional email delivery — email address, email content — USA.
- Google Ireland Ltd. / Google LLC — "Sign in with Google" authentication — email, name, Google account ID — EU / USA.
- Vercel Inc. — hosting of the administrative dashboard — administrator session data — USA.
We do not sell your personal data, and we do not share it with advertisers or data brokers.
We may also disclose personal data where required by Irish or EU law, by court order, or to establish, exercise, or defend legal claims.
International transfers
Some of our providers are established in the United States. Where personal data is transferred outside the European Economic Area, we rely on:
- Standard Contractual Clauses approved by the European Commission (Article 46(2)(c) GDPR), incorporated into our agreements with each provider; and
- where applicable, the provider's certification under the EU–US Data Privacy Framework (Article 45 GDPR adequacy decision).
You may request a copy of the relevant safeguards by contacting us at privacy@marketday.app.
How long we keep your data
- Account data (active account) — kept until you delete your account.
- Account data after deletion request — anonymised immediately — see below.
- Order records — 6 years from the date of the order, in anonymised form after account deletion.
- Password reset codes — 15 minutes, then deleted.
- Refresh tokens — until logout, password reset, or expiry (7 days).
- Server and security logs — 30 days.
- Push notification tokens — until you uninstall the app or disable notifications.
Anonymisation instead of deletion: when you request deletion of your account, we replace your identifying data (email, name, Google ID, password hash, push token) with irreversible placeholder values. Your order records remain in the system in a form that can no longer be linked to you, because vendors need accurate historical records of transactions and we may need them for tax and accounting purposes. Once anonymised, the data is no longer personal data under the GDPR.
Security
We apply technical and organisational measures appropriate to the risk, including:
- Passwords hashed with bcrypt; plaintext passwords are never stored or logged.
- All traffic encrypted in transit using TLS.
- Database encryption at rest, as provided by our hosting provider.
- Short-lived access tokens and rotating refresh tokens.
- Rate limiting on authentication and password-reset endpoints.
- Access to production systems restricted to the operator of the Service alone.
No system is completely secure. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours and, where the risk is high, we will notify you directly.
Your rights
Under the GDPR you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted, subject to the anonymisation approach described above.
- Restriction — ask us to limit how we use your data.
- Portability — receive your data in a structured, machine-readable format, or have it transmitted to another controller.
- Object — object to processing based on legitimate interests.
- Withdraw consent — at any time, where processing is based on consent — this does not affect the lawfulness of processing carried out before withdrawal.
- Not be subject to automated decision-making — we do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
To exercise any of these rights, email privacy@marketday.app. We will respond within one month — this period may be extended by two further months for complex requests, in which case we will tell you within the first month. Exercising your rights is free of charge, unless a request is manifestly unfounded or excessive.
Account deletion can also be carried out directly in the app under Profile → Settings → Delete account.
Children's privacy
The Service is not intended for children. Under section 31 of the Data Protection Act 2018, the digital age of consent in Ireland is 16 — you must be at least 16 years old to create an account. If we become aware that we hold personal data relating to a person under 16, we will delete it without undue delay.
Cookies and similar technologies
The mobile application does not use cookies. It stores authentication tokens in the device's secure storage, which is strictly necessary for you to remain signed in.
The administrative dashboard, used only by our own staff, uses strictly necessary cookies to maintain a login session. We do not use analytics, advertising, or tracking cookies anywhere in the Service. If this changes, we will request your consent in advance in accordance with the ePrivacy Regulations (S.I. No. 336 of 2011).
Changes to this policy
We may update this policy from time to time. The "last updated" date at the top will always reflect the current version. If we make material changes — for example, introducing online payments or a new category of processing — we will notify you in the app or by email before the changes take effect.
Complaints
If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Irish supervisory authority:
- Data Protection Commission — 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland — www.dataprotection.ie — +353 (0)1 765 0100 / 1800 437 737.
You may also lodge a complaint with the supervisory authority of your habitual residence or place of work.