Privacy Policy
This policy explains what the operator of Navar collects when you use Navar at https://navar.app, why, how long it is kept, and what you can ask us to do about it. Questions and requests go to legal@navar.app.
The short version. We collect what the app needs to keep your records and nothing to sell. We do not sell or share personal information, we do not serve advertising, we do not track you across other sites, and we do not train machine-learning models on your data. The app does not read your email and holds no credentials to any account but its own.
1. Who is responsible for what
We are the controller of your account: your sign-in identity, your settings, and how you use the Service.
For the records you enter about other people, principally your buyers, you are the controller and we are your processor. We handle that data on your instructions to provide the Service. Your obligations as controller are in section 13 of the Terms.
2. What we collect
| Category | What it is | Why |
|---|---|---|
| Account | Email address, display name, an avatar image if you upload one, your Google account identifier if you sign in with Google, display currency, and a password hash if this deployment allows password sign-in | To create and secure your account |
| Business records | Inventory, products, purchase costs, sales, expenses, and the notes and tags you write | This is the Service |
| Your customers | Names, handles and platform, phone, email, Discord ID, notes, tags, order history, and shipping addresses and tracking numbers on invoices and shipments | To let you run direct sales and fulfilment |
| Technical | IP address, request metadata and error diagnostics in server logs; rate-limit counters; a session cookie | Security, abuse prevention, and keeping you signed in |
Do not enter special categories of data. Payment card numbers, government identification numbers, and health information have no place in this app and must not be typed into notes or any other free-text field. We do not process payments and never receive card details.
3. Where the data goes
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose it only to the service providers below, each acting on our instructions, and only where the deployment has enabled them:
| Provider | Role |
|---|---|
| Vercel | Application hosting and request logs |
| The configured Postgres provider | Primary database storage |
| Google (if enabled) | Sign-in identity (email and profile only) |
| Upstash (if enabled) | Rate-limit counters |
| Cloudflare Turnstile (if enabled) | Bot defence on public reservation forms |
| StockX (if enabled) | Market prices for sneakers, apparel and sealed product |
| eBay (if enabled) | Completed-sale comparables for graded cards |
| TCGplayer (if enabled) | Trading-card market prices |
Market price lookups send only the product being priced, meaning a model number, a card name, a grade. They never send you or your customers. We may also disclose data where legally required, to enforce the Terms, to protect someone’s safety, or to a successor in a merger or sale of assets, in which case this policy continues to apply until you are told otherwise.
4. How long it is kept
- Your records. Kept until you delete them or close your account.
- Shipping addresses and tracking numbers on completed orders. Minimised on the operator’s schedule, typically one year, once they are no longer needed for fulfilment or returns.
- Server logs and rate-limit counters. Short-lived, kept for security and debugging.
- Closed accounts. Deleted, except anything we must keep by law.
A scheduled job performs this minimisation; it is not done by hand.
5. Security
Sessions are encrypted and time-limited, and can be revoked server-side. The app stores no credentials to any third-party account of yours. Database access is least-privilege and requires TLS. The app applies a content security policy, rate limits sensitive operations, and separates every query by account.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data we will notify you and any regulator as the law requires. Vulnerability reports go to legal@navar.app.
6. Your rights
Wherever you live, you can ask us to:
- tell you what we hold about you and why;
- give you a copy, though the reports screens export your records directly at any time;
- correct anything inaccurate;
- delete your account and its data;
- restrict or object to a particular use.
Email legal@navar.app. We will verify the request against your account and respond within the time the applicable law allows, which is 45 days under US state laws and one month under the GDPR. We will not treat you worse for asking. If we refuse, we will say why and you may appeal by replying; you can also complain to your data protection authority or state attorney general.
If your request concerns data a Navar user holds about you as their customer, we will refer you to that user, who is the controller of it.
United States
We do not sell personal information or share it for cross-context behavioural advertising, under the CCPA as amended or any other state privacy law, and we do not use or disclose sensitive personal information beyond what is necessary to provide the Service. Residents of California and other states with comprehensive privacy laws have the rights listed above, including the right to know, delete, correct, and opt out, and an authorised agent may act for you.
Europe and the United Kingdom
Where the GDPR or UK GDPR applies, we rely on: contract, to provide the Service you asked for; legitimate interests, to keep it secure and prevent abuse; and legal obligation where one applies. You also have the right to data portability and to lodge a complaint with your supervisory authority.
7. International transfers
The providers in section 4 may process data in the United States and elsewhere. Where data moves out of the UK or the European Economic Area, we rely on the safeguards those providers offer, including standard contractual clauses. Contact legal@navar.app for details or to request a copy.
8. Cookies
The app sets a session cookie so you stay signed in, and stores your theme and display preferences in your browser. These are strictly necessary to provide a service you requested, so there is no consent banner. We set no advertising or analytics cookies and run no third-party trackers.
9. Children
The Service is for adults running a resale business and is not directed to children. We do not knowingly collect data from anyone under 18. If you believe a child has provided data, write to legal@navar.app and we will delete it.
10. Changes
We will post any update here with a new version identifier, and give reasonable advance notice of material changes by email or in the Service. Changes are not applied retroactively to data already collected under an earlier version without your consent where consent is required.
11. Contact
legal@navar.app