BazaarBox Beta notice
Privacy
Location privacy
GPS permission is optional. On a first homepage visit, the browser may ask for permission; a person can deny it and enter a PIN instead. A buyer device point is sent only to the nearby-search and nearest-postal database functions for that request. BazaarBox stores the resolved public postal-office point and readable locality/PIN as browsing state; it does not place the device coordinate in the URL, cookie, local storage, HTML, or public response. Exact optional seller coordinates are stored separately behind owner-only policies. Public listings expose only a postal/locality search point, locality and rounded distance.
Listing photos
Supported listing images are decoded and re-encoded in the browser before upload to remove embedded metadata such as EXIF GPS. Images are held in a private bucket and become publicly retrievable only after the listing and image metadata are approved.
Account data
Authentication data stays in Supabase Auth. Public seller profiles are separated from private verification records, coordinates and contact details. Phone numbers are not public by default.
Marketplace activity
Listings, saved items, messages, blocks, reports and beta feedback have distinct ownership rules. Messages are participant-only. Reports and beta feedback remain private under database access controls.
Providers and retention
Supabase, Vercel, image processing, email, analytics and any future geocoding provider must be documented before a general commercial launch, together with retention and deletion rules.
