BuyerReq
Browse RequestsHow It WorksBuyer ProtectionSellHelp

Privacy policy

Policy version 1.0 · effective 6 Sep 2026

Subject to legal review. Marketplace payment protection is not a licensed escrow or banking service.

Subject to legal review

This Privacy Policy explains how BuyerReq (“we”) handles personal data. It is subject to legal review and may change when our stack or processors change.

Who we are

BuyerReq operates a reverse marketplace at buyerreq.com. Contact: support@buyerreq.com.

Data we collect

Account data: name, email, handle, password hash, city/region/country, bio, avatar. Marketplace data: requests, offers, orders, messages, reviews, dispute evidence, verification submissions. Technical data: session cookies, IP and device signals used for security, and basic diagnostics when you report a problem. Payment references: PSP checkout/session IDs and status — not full card PAN/CVC (handled by the PSP).

How we use data

To operate accounts and sessions, match buyers and sellers, process orders, prevent fraud, send transactional email, improve reliability, and comply with law. We do not sell personal data.

Retention

Account and order records are kept while your account is active and for a reasonable period afterward for disputes, accounting, and legal obligations. Session tokens expire or are rotated on logout / security events. Outbox and diagnostic logs are retained only as long as needed for delivery and debugging.

Deletion

You may request account closure and deletion of personal data that is not required for legal, dispute, or financial retention by contacting support@buyerreq.com. Some transaction records may be retained in anonymized or restricted form where required.

Cookies and sessions

We use essential session cookies to keep you signed in and to protect against abuse. These are required for the product to function. We do not run third-party advertising trackers as part of the core app.

Processors and hosting (current stack)

Hosting: application on a Hostinger VPS (Docker). Database: PostgreSQL used by the app. File storage: local disk under the app storage volume, and optionally Cloudflare R2 (S3-compatible) when configured for media. Email: SMTP and/or a transactional provider when configured; otherwise messages may queue in a local outbox until delivery is enabled. Payments: Stripe (or configured PSP) for checkout. Sessions: signed server-side session cookies tied to your account.

International transfers

Because we host on VPS infrastructure and may use cloud storage/email/PSP vendors, data may be processed in more than one country. We use contractual and technical safeguards appropriate to the providers we configure.

Security

We use hashed passwords, session versioning, access controls for admin tools, and HTTPS in production. No method of transmission or storage is perfectly secure; report suspected incidents to support@buyerreq.com.

Minors

BuyerReq is not directed at children under 18. We do not knowingly collect data from minors. If you believe a minor created an account, contact us to remove it.

Marketing

Transactional messages (order, security, verification) are part of the service. Promotional email, if introduced, will include an unsubscribe option. We do not send marketing SMS by default.

Your choices

Update profile details in account settings, manage email confirmation, and contact support for deletion or access requests where applicable.

Changes

We may update this policy and bump the policy version shown on this page. Material changes will be reflected in the published CMS version.