Privacy Policy
Last updated: 24 August 2026
This document is in draft and has not completed legal review.
It describes how the Auctionomy platform actually works today and is published so that prospective customers and bidders can read it, but it has not been settled by a qualified lawyer in any market and does not yet bind anyone. Points still awaiting a lawyer are marked in the text and listed at the foot of the page. If you are negotiating an agreement with us, the signed order form governs — not this page.
This policy covers information Auctionomy handles for itself. When you bid on an auction house's site, that auction house is the organisation responsible for your information and Auctionomy acts on its instructions — section 1 explains which is which.
1. Who is responsible for your information
This policy explains how Auctionomy collects, holds, uses and discloses personal information when you visit auctionomy.com, enquire about the platform, create or administer an auction-house account, use the operator dashboard, or contact our support.
If you are a bidder on an auction house's website, that auction house is the organisation that decides how your information is used — it is the controller, or in United States terms the business. Auctionomy is its processor, or service provider, acting on its instructions. Read that auction house's own privacy policy alongside this one. Requests about your bidding records generally go to them; section 8 explains how we route a request that reaches us first.
Auctionomy is an independent controller for a narrower set of purposes: administering auction-house accounts, platform billing, securing the service, providing support, preventing fraud, and meeting our own legal obligations. This policy describes that second role in full and the first only so far as it affects you.
The provider is Pending legal review: the full legal entity name, entity type, company or business registration number and registered address of the entity that is the data controller — no entity is named here because none has been confirmed.
Like the Terms, this policy has a shared global core with one market module attached — AU, US, EU or a conservative international fallback. The module comes from our approved entity and operating-market facts, not from your IP address or browser locale. Where your own location gives you additional mandatory rights, you keep them. Pending legal review: confirm the approved role matrix, the lawful bases for each purpose, and the United States service provider or contractor contract terms.
2. What we collect
Depending on how you use the platform, we may hold:
- identity and contact details — name, business name, job title, email address, telephone number, postal address and profile image;
- account and authentication details — user identifiers, role, membership, verification status, and session and security events. We do not store plain-text passwords;
- auction-house and commercial details — branding, domain, subscription plan, billing contact, currency, timezone and preferences;
- auction and participation records — catalogues, lots, consignments, registrations, bidder handles, watchlists, bids, messages, invoices, purchases, notifications and audit logs;
- transaction records — invoice number, amount, currency, payment status, Stripe checkout and payment identifiers, receipt links, failure reasons, refunds and any dispute information made available to us;
- communications and support records — enquiries, feedback, complaint correspondence and troubleshooting material;
- technical and usage information — IP address, device and browser data, pages and features used, timestamps, diagnostics, security signals, cookie identifiers, and error and performance events; and
- anything else you choose to provide, or an auction house lawfully instructs us to process.
We do not collect full payment card numbers through Auctionomy forms. Card details are entered on Stripe-hosted pages; we receive the transaction metadata needed to reconcile the payment.
We do not routinely ask for government identifiers, identity documents, or health, biometric or criminal-record information. If a high-value or regulated auction ever requires identity verification, we will not add that collection without first settling the purpose, the lawful basis, the collection notice, the access model, the provider and the retention rule. Pending legal review: the minimum age for platform and bidder accounts, any guardian process, and whether identity verification for anti-money-laundering purposes will be in scope for the first markets.
3. Why we use it
We handle personal information to run and secure the platform. Specifically, to:
- provide, configure, host, authenticate and administer the service;
- create auction-house tenants, manage authorised users, resolve domains and apply branding;
- operate auction, bidding, streaming, messaging, invoicing and payment features;
- send service, security, auction, bid, invoice, payment and support messages;
- provide support, diagnose faults and respond to requests and complaints;
- secure accounts and auctions, apply rate limits, prevent fraud and abuse, and investigate suspected incidents or disputed bidding;
- process subscriptions and facilitate Stripe-mediated invoice payments;
- keep records, audit the service, enforce agreements, and establish or defend legal claims;
- understand and improve reliability, accessibility and performance — only with your consent where that involves analytics storage on your device; and
- comply with law, court orders and lawful regulatory requests.
We will not use personal information for an unrelated purpose unless you have consented or the law permits it. Consent to optional marketing is separate from the operational messages needed to run or secure the service, and opting out of marketing does not stop transactional, security, auction, invoice or legal notices.
4. Who receives it
We disclose personal information only as reasonably necessary — to the auction house whose site, auction, account or invoice you used; to authorised staff, contractors, professional advisers, auditors and insurers under confidentiality obligations; to the service providers listed below; to financial institutions and payment networks in connection with a payment or a dispute; to law enforcement, regulators and courts where the law permits or requires it; and to a counterparty in a merger, financing or sale, subject to lawful safeguards.
The list below is generated from a registry in our source code, not maintained by hand. Every entry is bound by an automated test to a fact about the codebase — an installed dependency, a configured credential, or a literal in our own source — so a provider cannot quietly be added or removed without this page changing with it.
| Provider | What it does for us | Consent |
|---|---|---|
| Convex | Primary application database and realtime backend. Stores every record in convex/schema.ts. | Strictly necessary |
| Vercel | Application hosting and edge network for all three apps. Processes request metadata including IP address. | Strictly necessary |
| Stripe | Tenant subscription billing and bidder invoice payment processing. | Strictly necessary |
| Cloudflare R2 | Object storage for lot images, consignment media, and rendered invoice PDFs. | Strictly necessary |
| Agora | Live video and audio streaming during live auctions. | Strictly necessary |
| Vercel AI Gateway | Routes the two AI features on tenant websites to model providers: lot-title suggestions on the consignment form, and the CMS content helper (rewrite, expand, summarise, translate). Forwards the submitted text to the selected provider and returns the generated text. | Strictly necessary |
| Resend | Transactional email delivery — registration, outbid alerts, invoices, approvals. | Strictly necessary |
| Better Stack | Error and performance monitoring for the marketing site, dashboard, and tenant websites. | Strictly necessary |
| Google (Sign in with Google) | Optional federated sign-in for auction-house staff on the dashboard. | Strictly necessary |
| Google Maps Platform (Places) | Address autocomplete in profile, customer, consignment, and tenant settings forms. | Strictly necessary |
| PostHog | Product analytics and session replay for the marketing site and the operator dashboard — page views, CTA clicks, and a replay of the operator's own session. Replaced OpenPanel in #1140. Deliberately NOT loaded on tenant auction-house websites, so no bidder is measured by it. | Requires your analytics consent |
| Tinybird | Per-tenant web analytics on auction-house websites, via the self-hosted flock.js tracker. | Requires your analytics consent |
| OpenAI | Drafts a lot title from a consignment enquiry. The market, description, condition and provenance the person typed are sent in the prompt (apps/website/src/utils/ai.ts). | Strictly necessary |
Two of those providers receive free text a person wrote. Text submitted in a consignment enquiry is sent to a language model to draft a lot title, and text edited in the website content editor is sent to a language model to rewrite it. Do not put information in those fields that you would not want processed by a third-party model. Pending legal review: whether the AI providers must be contractually constrained on retention and model training before further customer-written text is sent to them, and whether their use needs its own notice at the point of collection rather than only here.
Booking a setup call from the dashboard sends you to a third-party scheduling site. That is an outbound link rather than an embedded service — no information leaves Auctionomy to reach it until you go there and enter something, at which point that provider's own privacy policy applies.
We do not exchange personal information for money. Privacy laws in some jurisdictions define selling, sharing and targeted advertising more broadly than a cash sale. Pending legal review: confirm that the current analytics configuration supports a 'no sale and no sharing' representation under the applicable United States state laws before that representation is relied on.
5. Where it goes
Our providers and their personnel may store or access personal information in more than one country. Using a global cloud provider does not by itself answer where a disclosure or a restricted transfer occurs, so the answer is per provider rather than a single blanket statement.
Pending legal review: the provider-by-provider transfer register — recipient entity, processing location, onward transfer path and the safeguard relied on — including an Australian Privacy Principle 8 analysis for Australian personal information and a GDPR Chapter V analysis, with transfer impact assessments where standard contractual clauses are relied on.
No data residency is promised, because none is configured. No processing region is pinned in the product: object storage uses a non-jurisdictional endpoint and no application declares a hosting region. If residency matters to your organisation, raise it before signing rather than assuming it.
6. How we protect it
We use technical and organisational measures appropriate to the information and the risks — tenant scoping so one auction house cannot read another's data, access controls, authentication, transport security, logging, rate limiting and incident response.
We hold no security certification and this page does not imply one. No internet service is risk-free: use unique credentials, protect your devices, and tell us promptly if you suspect misuse.
If a security incident occurs we will assess it, contain the harm, preserve evidence, cooperate with the affected auction houses, and make the notifications the law requires. Pending legal review: the named incident owner, the contractual notification period, and the per-market breach matrix covering the Notifiable Data Breaches scheme and the GDPR breach articles.
7. How long we keep it
We keep personal information only as long as reasonably necessary for the purpose it was collected for, and for the service, security, disputes, financial and audit records, backup integrity and legal obligations that follow from it. A scheduled daily sweep deletes records in the categories that have a defined retention period once that period expires.
Records outside those categories are retained until they are deleted on request or under an agreed schedule. Closing an account does not erase every record: bid history, invoices, payment records, audit logs and tax records may have to be kept, and where that is the case the record is retained rather than silently removed.
Pending legal review: the retention period for each remaining category — leads and enquiries, operator accounts, auction-house tenant data, bidder records held for an auction house, bids, invoices, payments, support correspondence, logs, stream recordings, analytics and backups — plus the legal-hold process. Confirm each proposed period against the statutory minimums for financial and tax records in each market.
8. Your rights, and how to use them
Depending on where you are and which law applies, you may be able to ask for access to your information, correction of it, erasure, restriction of processing, objection, portability, withdrawal of consent, an opt-out, or an internal appeal. We may verify your identity and authority, clarify what you are asking for, and apply the exceptions the law allows. We will not treat you differently for exercising a right.
What exists today rather than in principle: a bidder can request an export of their data or erasure of it from their own account settings on an auction house's site, and an auction-house operator can action either request from the bidder's record in the dashboard. Each request is logged with a due date so it cannot quietly lapse, and an erasure produces a record of what was removed and what had to be kept.
Where the information is held for an auction house, we will route or coordinate the request with that auction house, because they decide the outcome. We will not disclose another person's information, confidential commercial material or security-sensitive records unless the law requires it.
Requests and privacy questions go to privacy@auctionomy.com. Pending legal review: confirm the monitored privacy contact, the responsible role, a postal address, the response deadline consistent with the actual procedure, and whether an EU representative or a data protection officer must be appointed.
9. Cookies and analytics
Storage that is strictly necessary to run the site — keeping you signed in, protecting forms, routing you to the right auction house, and remembering your cookie choice — is used without asking, because the site cannot work without it. Analytics storage is not loaded at all until you allow it, and you can change or withdraw that choice at any time from the footer of any page.
The Cookie Policy sets out the categories, the providers behind each, and how to change your mind.
10. Market modules
AU. Where the Privacy Act 1988 (Cth) applies, we handle personal information in line with the Australian Privacy Principles, including open privacy management, collection notices, use and disclosure limits, direct marketing rules, overseas disclosure under APP 8, data quality, security, and access and correction under APPs 12 and 13. Eligible data breaches are notified under the Notifiable Data Breaches scheme. If you are not satisfied with our response to a privacy complaint you may complain to the Office of the Australian Information Commissioner (OAIC). Pending legal review: confirm whether the Privacy Act applies to the contracting entity or whether the small business exemption is in play, the APP 8 recipient countries and safeguards, and the named Notifiable Data Breaches owner.
US. Applicability is assessed state by state, and California's CCPA is one input rather than a nationwide template. Pending legal review: which state laws apply, the category-by-category notice each requires, sale, share and targeted-advertising opt-outs, sensitive data rules, appeals, authorised agents, universal opt-out signals, and the service provider or contractor terms with each vendor.
EU. Where the GDPR applies, we must identify each controller, any representative and a data protection officer if one is required; the purposes and Article 6 lawful bases; recipients; retention criteria; your rights and your supervisory authority; and any automated decision-making. Processor handling requires Article 28 terms, and restricted transfers require adequacy, standard contractual clauses or another Chapter V basis. Pending legal review: the establishment and targeting analysis, the lawful-basis table, member-state overlays, the lead supervisory authority, and whether an Article 27 representative is required.
INTL. The international fallback states our global categories, purposes, disclosures, safeguards, retention criteria and request channel. It is not a jurisdiction: it narrows no right, authorises no transfer, creates no consent and displaces no mandatory local law.
11. Changes and complaints
We update this policy when our practices, our providers or the law change, and the current version and its effective date are published here. Where a change materially affects existing handling we will give additional notice, or seek consent where the law requires it. We do not treat silence as consent where valid consent is needed.
To make a privacy complaint, write to privacy@auctionomy.com describing the concern and the Auctionomy or auction-house account it relates to. We will acknowledge it, investigate fairly, coordinate with the relevant auction house or provider where necessary, and respond. Pending legal review: the complaint acknowledgement and response timeframes, matched to the procedure that will actually be staffed. Handling a complaint internally does not delay or waive your right to go to a regulator or a court.
Points still awaiting legal review
13 points in this document need a qualified lawyer, or a fact only we can supply, before the document is settled. They are listed here rather than left for a reader to find.
- 1. Who is responsible for your information — the full legal entity name, entity type, company or business registration number and registered address of the entity that is the data controller — no entity is named here because none has been confirmed
- 1. Who is responsible for your information — confirm the approved role matrix, the lawful bases for each purpose, and the United States service provider or contractor contract terms.
- 2. What we collect — the minimum age for platform and bidder accounts, any guardian process, and whether identity verification for anti-money-laundering purposes will be in scope for the first markets.
- 4. Who receives it — whether the AI providers must be contractually constrained on retention and model training before further customer-written text is sent to them, and whether their use needs its own notice at the point of collection rather than only here.
- 4. Who receives it — confirm that the current analytics configuration supports a 'no sale and no sharing' representation under the applicable United States state laws before that representation is relied on.
- 5. Where it goes — the provider-by-provider transfer register — recipient entity, processing location, onward transfer path and the safeguard relied on — including an Australian Privacy Principle 8 analysis for Australian personal information and a GDPR Chapter V analysis, with transfer impact assessments where standard contractual clauses are relied on.
- 6. How we protect it — the named incident owner, the contractual notification period, and the per-market breach matrix covering the Notifiable Data Breaches scheme and the GDPR breach articles.
- 7. How long we keep it — the retention period for each remaining category — leads and enquiries, operator accounts, auction-house tenant data, bidder records held for an auction house, bids, invoices, payments, support correspondence, logs, stream recordings, analytics and backups — plus the legal-hold process. Confirm each proposed period against the statutory minimums for financial and tax records in each market.
- 8. Your rights, and how to use them — confirm the monitored privacy contact, the responsible role, a postal address, the response deadline consistent with the actual procedure, and whether an EU representative or a data protection officer must be appointed.
- 10. Market modules — confirm whether the Privacy Act applies to the contracting entity or whether the small business exemption is in play, the APP 8 recipient countries and safeguards, and the named Notifiable Data Breaches owner.
- 10. Market modules — which state laws apply, the category-by-category notice each requires, sale, share and targeted-advertising opt-outs, sensitive data rules, appeals, authorised agents, universal opt-out signals, and the service provider or contractor terms with each vendor.
- 10. Market modules — the establishment and targeting analysis, the lawful-basis table, member-state overlays, the lead supervisory authority, and whether an Article 27 representative is required.
- 11. Changes and complaints — the complaint acknowledgement and response timeframes, matched to the procedure that will actually be staffed.