1. Who We Are
Snagged Auctions is operated by Snagged Domains. This Privacy Policy explains what personal information we collect when you use our auction platform at snagged.com (and subdomains), why we collect it, how we use it, with whom we share it, and the rights you have.
2. Information We Collect
We collect the following categories of personal data:
- Identity & contact: name, email, phone, company name, country.
- Verification: payment-method verification details (last four digits and card brand from our payment processor); identity or business verification documents where required for high-value auctions.
- Account & bidding activity: registration date, approval status, bid history, maximum-bid configurations, email subscription preferences.
- Device & usage: IP address, browser/device identifiers, pages visited, timestamps, referring URL.
- Communications: emails you send us and our replies, support tickets.
3. How We Use It
- Operate the auction platform (registration, approval, bidding, settlement).
- Verify identity and payment methods to prevent fraud and shill bidding.
- Communicate with you about bids, outbid notifications, auction results, and account events.
- Send marketing emails about future auctions, only with your consent (you may unsubscribe at any time).
- Comply with legal obligations, enforce our Terms, and respond to lawful requests.
- Improve the platform (analytics, debugging, security monitoring).
4. Legal Bases (GDPR / UK GDPR)
For users in the EEA, UK, or other jurisdictions with a lawful-basis regime, we rely on: (a) performance of a contract for processing necessary to operate auctions you participate in; (b) legitimate interest for fraud prevention, platform security, and direct marketing of comparable services to existing customers (subject to opt-out); (c) consent for non-essential cookies and prospect-list marketing; and (d) legal obligation for tax, record-keeping, and law-enforcement requests.
7. Retention
- Account and bidder-profile records: while your account is active and for 7 years thereafter for tax/legal records.
- Bid history: for as long as reasonably necessary to maintain auction records, enforce rights, and comply with legal obligations.
- Verification documents (if collected): retained only as required by applicable law, then deleted.
- Email-only subscribers (no account): until you unsubscribe.
- Server logs: 90 days unless required for an active investigation.
8. Security
We apply industry-standard safeguards including TLS in transit, encrypted storage of credentials and tokens, role-based access controls, and audit logging. Card data is handled by Stripe and never stored on our servers. No system is perfectly secure; you are responsible for keeping your account password confidential.
9. Your Rights
Depending on your jurisdiction you may have rights to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- delete data (subject to legal retention requirements);
- restrict or object to processing;
- data portability;
- withdraw consent at any time;
- lodge a complaint with a supervisory authority.
To exercise these rights, email privacy@snagged.com. We will respond within 30 days.
10. Cross-Border Transfers
Our infrastructure is hosted in the United States. If you are accessing the Platform from outside the US, your data will be transferred to and processed in the US. Where required (e.g., for EEA/UK users), we rely on Standard Contractual Clauses or equivalent transfer mechanisms with our processors.
11. Children
The Platform is not directed to children under 18. We do not knowingly collect personal data from anyone under 18.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised “Last updated” date and, where appropriate, notified to active users by email.
13. Contact
Privacy questions or rights requests: privacy@snagged.com.