This Privacy Policy explains what information we collect when you use the site, how we use it, and the choices you have.
Information we collect
- Account information you provide: name, email, phone (optional), and account and tenant-role information. Passwords are handled by our authentication provider rather than stored as readable platform records.
- Auction activity: registrations, bids, invoices, payments, pickups, and related operational records.
- Communications and relationship information: contact inquiries, preferences, suppressions, document acceptances, and—where an auction house uses our relationship tools—internal relationship labels, tasks, tags, and notes.
- Catalog media you or authorized staff submit for an auction, including photos and tenant logos. After security processing, normalized catalog images are stored in public object storage and are retrievable by anyone with the object URL, including before the related listing is published. Catalog media must not show titles, IDs, documents, addresses, identifiable people, financial or tax records, bidder-verification material, estate paperwork, ownership evidence, or other confidential or sensitive content.
- Private supporting documents submitted for pre-approval, consignment, or support workflows. These use private, purpose-specific storage and authorization-aware delivery rather than the catalog-media buckets.
- Technical and security information needed to operate and secure the site. Our application host processes request IP and header data in transit. Where the application needs IP-based security evidence, it records a salted hash rather than a raw IP address.
- App installation and notification information when you use an installed app or choose browser push notifications: an app-generated installation identifier, device and browser platform, app version, notification permission and subscription status, and the tenant and notification categories you select. If you enable push, we also store the push subscription endpoint and associated delivery keys. These identify an app installation and may be associated with your account; they are not proof of account access.
How we use information
To create and manage your account, run auctions, process payments, send transactional and (where permitted) auction notifications, provide support, prevent abuse, and meet legal and accounting obligations. Staff may use optional catalog-assistance tools to prepare draft descriptions; an enabled research feature can send selected lot facts and search queries to a third-party AI/search provider. Staff review remains required before a catalog change is published.
Installation information helps us keep notification settings working across your devices, diagnose delivery failures, and deactivate a subscription when you sign out or remove an account. Browser notification permission alone does not enroll you in our push messages. We request a separate choice for each auction house and notification category before push delivery. Push alerts can appear on a device lock screen; account details load after you open the app.
Optional app usage measurement
An auction house may enable optional measurement after publishing its settings. Collection starts off. When it is enabled, the app explains whether you need to allow it first or can turn it off. Your choice applies to your signed-in account and this app installation; you can change it in your account settings. The app also stops optional collection when your browser signals Global Privacy Control or Do Not Track.
Allowed events describe app installation, foreground return, bid outcome status, and app reliability. We record the event name, time, limited status or version, an app installation identifier, browser or device platform, app version, and related consent evidence. We do not put bid maximums, payment details, document contents, push endpoints, page URLs, or free-form text in these events. Revoking your choice stops future optional events from this account and installation; it does not retroactively remove events already collected.
Payments
Card payments are processed by our payment processor (Stripe). The auction house you are transacting with is the merchant of record for its own sales; the platform receives a service fee on completed transactions. We do not store full card numbers. For each sale, Stripe Customer and payment records for that transaction are created in the auction house's own payment account, so the auction house receives those records as merchant of record (and acts as an independent controller of that sale-related payment data).
SMS messages
SMS notifications are strictly optional and require a separate opt-in. See the SMS Program Terms. Message frequency varies with your account and auction activity, and message and data rates may apply. You can stop texts at any time by replying STOP.
Mobile numbers, SMS opt-in data, and consent records are not shared with third parties or affiliates for their marketing or promotional purposes. We may share this information with service providers only as needed to operate the SMS program and deliver the messages you requested.
Sharing
We share information with service providers that help us operate the site, including hosting, database/storage, payment, and—when configured for the relevant service—email or SMS delivery providers. We share relevant records with the auction house that is merchant of record for a sale you complete, which receives the tenant-scoped payment and customer records for that sale. When push is enabled, the browser's push service and our delivery provider process the subscription data needed to route your alerts. We do not provide push endpoints to auction houses or use them for their marketing without your separate choice.
An auction house may separately configure an authorized CRM connection. That connection can receive reviewed contact snapshots, restrictive consent changes (such as an opt-out), and lifecycle milestones; it does not receive payment credentials, tax documents, proxy maxima, raw bid streams, or a consent grant. We may also disclose information when required by law. We do not sell personal information.
Retention and security
We keep information as long as needed to operate the site and meet legal and financial record-keeping requirements, subject to the limits described here. Sent, skipped, or cancelled notification rows are currently kept for 90 days; failed notification rows for 180 days. If privacy-gated engagement telemetry is activated, raw events are kept for 90 days and monthly aggregates for up to 13 months; collection honors Global Privacy Control and Do Not Track. Optional app usage measurement has a separate limit: raw events are kept for no more than 30 days and daily aggregates for no more than 90 days. Consent records and related audit evidence are retained as needed to document your choice.
Private pre-approval documents remain while active and may be subject to a legal hold; after continuous archival for more than one year without a hold, their stored bytes may be removed while operational evidence remains. AI provenance and quality evidence currently has no general automatic deletion; short-lived failed or unconfirmed capture uploads follow their specific security-cleanup rules. We use technical, access-control, tenant-isolation, audit, and encryption safeguards appropriate to the data category.
We keep active installation and push-subscription records while needed to provide the service. Sign-out, account switching, subscription expiration, or account deletion deactivates affected subscriptions; associated records are then removed under our operational retention process, except where we must retain limited evidence for security, legal, or accounting purposes. Push endpoints and delivery keys are restricted to server-side use.
Unpublishing or deleting a catalog listing stops or restricts future platform discovery, but does not retract catalog image bytes already fetched, shared, logged, indexed, or cached. A public object may remain directly retrievable until origin cleanup completes, and copies held elsewhere may remain after cleanup.
Your choices
You can update your account details and manage notification preferences. You can decline or revoke push permission in your browser or device settings and change push categories in your account. Turning off push does not turn off email or SMS preferences, which have separate controls. You may contact us about an access, correction, or account-lifecycle request; available rights and any deletion/export process remain subject to applicable law, record-keeping obligations, and the workflow in effect when your request is made. See the Contact page.
Changes
Material changes will be reflected in the version and effective date above.