Skip to main content
Philmarket

Privacy Policy

Last updated: 2026-05-21

1. Data controller

Philmarket Oy (business ID 3636423-6), Finland, is the controller for the processing of your personal data on philmarket.eu. Contact: privacy@philmarket.eu.

2. Data we collect

  • Account data: Email address, name (optional).
  • Transaction data: Bids, purchases, payment status, amounts.
  • KYC / identity verification: Performed by Stripe Inc. — we store only the verification status and time.
  • Listing content: Title, description, images, catalogue numbers.
  • Seller statistics: For sellers, we derive figures from your own orders — including how often an order did not complete — and publish some of them on your public profile under the rule in § 5 of the Terms.
  • Tax details for sellers: When you activate seller mode we collect the details the law requires us to report — among them your tax identification number (for a private individual normally the personal identity number, for a company its business identification number) and the state that issued it. We do so because we are obliged to: the reporting duty on platform operators under Act 1267/2022 and Council Directive (EU) 2021/514. The details are submitted annually to the Finnish Tax Administration (Verohallinto), which in turn shares them with the tax authority in your state of residence. If you stop being a seller without having made any reportable sale, we delete them; if you have made one, we keep them for as long as the law requires.
  • Technical data: Session token (session cookie, strictly necessary).
  • Data we check without storing: Your phone number is used to verify you and is never stored — we keep a one-way checksum and the time, not the number.

3. Legal basis (GDPR Art. 6)

  • Performance of a contract (Art. 6(1)(b)): Account management, auctions, purchases, payments.
  • Legal obligation (Art. 6(1)(c)): Accounting vouchers such as invoices and receipts are retained for at least six years from the end of the year in which the accounting period ended, and the financial statements and accounting books for at least ten years from the end of the accounting period (Accounting Act 1336/1997, ch. 2 s. 10), KYC/AML data for 5 years (Anti-Money Laundering Act); and reportable sellers are reported to the Finnish Tax Administration under DAC7 (Directive (EU) 2021/514; Act 1267/2022).
  • Legitimate interest (Art. 6(1)(f)): Fraud prevention, platform security, and measuring and improving our grading tools — when you correct a grading, the correction is used to measure whether the tool judges correctly. A correction is used for as long as it can be compared against the AI model that made the assessment, and for twelve months after that model is replaced. You may object to this (Art. 21), and the tool works the same if you do.
  • Legal obligation (Art. 6(1)(c)) — trader sellers: If you declare that you sell as a trader, your name and geographical address are shown publicly to buyers and appear on the model withdrawal form for each sale, as required by Directive 2011/83/EU Art. 6(1)(b)–(c). Recipients: all visitors to the site. Retained for the term of the contracts concluded plus the limitation period. This does not apply to private sellers, whose address is never published.

4. Cookies

We use a single strictly necessary session cookie (__Secure-next-auth.session-token) required for sign-in. It is exempt from consent requirements under the ePrivacy Directive. At checkout (Stripe), Stripe's own fraud-prevention cookies may be set — these are governed by Stripe's privacy policy.

5. Third-party recipients

  • Stripe Inc.: Payment processing, identity verification (KYC), payouts. USA — safeguards: EU–US Data Privacy Framework.
  • DeepL SE: Automatic translation of user-generated text — listing titles and descriptions, messages between users, forum posts and appraisal estimates. EU.
  • Anthropic Inc.: AI-based condition assessment of stamp images. USA — safeguards: standard contractual clauses (SCC).
  • Hetzner Online GmbH: Server operations and image storage. EU (Nuremberg).
  • Sweego (Mindbaz SAS): Transactional email and SMS. Email: your address, the subject line and the content of the message — sign-in links, order confirmations, decisions on notices and the receipts we are obliged to send. SMS: your phone number and the text message, for seller phone verification. EU (France).
  • Finnish Tax Administration (Verohallinto): where you are a reportable seller, your identity and tax details and your gross proceeds are reported annually under DAC7. The authority shares the data with your country of residence. FI. The reporting thresholds are set by law, not by Philmarket (Directive (EU) 2021/514; Act 1267/2022).

6. Your rights (GDPR Art. 15–22)

  • Access (Art. 15): Request a copy via Export my data.
  • Rectification (Art. 16): Update your name and email in the account settings.
  • Erasure (Art. 17): Delete your account via Delete my account. Note: accounting vouchers are retained under the Accounting Act (at least six years from the end of the accounting year) and KYC/AML data under the Anti-Money Laundering Act (5 years).
  • Data portability (Art. 20): Download your data via Export my data.
  • Objection (Art. 21): Contact privacy@philmarket.eu.

You have the right to lodge a complaint with the Office of the Data Protection Ombudsman (Tietosuojavaltuutettu) in Finland, tietosuoja.fi, or with the supervisory authority in the EU country where you reside.

7. Security

Personal data is transmitted encrypted (TLS 1.3). Access to the data is controlled in the application layer: every request is bound to the signed-in account and to the data that account owns, and access is restricted to authorised systems. Personal data breaches are always documented. Where a breach is likely to result in a risk to you, we report it to the competent supervisory authority within 72 hours; where the risk is high, we also notify you directly (GDPR Art. 33 and 34).

8. Language

This notice is provided in the languages the service is offered in. It describes your rights rather than setting contract terms, so no language version takes precedence over another — each is meant to be correct on its own. If you find a discrepancy between versions, tell us at privacy@philmarket.eu and we will correct it.

9. Contact

Data protection contact: privacy@philmarket.eu.