Who is accountable
StorBids is responsible for personal information under its control. The StorBids Privacy Officer oversees privacy questions, access requests, corrections, complaints, service-provider safeguards, retention practices, and incident response.
Contact the Privacy Officer at support@storbids.com with the subject line Privacy Request. We will verify identity before disclosing or changing account information.
Information we collect
- Account details such as name, username, email, phone, role, verification state, sign-in activity, and support correspondence.
- Buyer activity such as watched auctions, bids, wins, notification preferences, pickup steps, disputes, and voluntary travel-area preferences.
- Prospective-bidder details such as email address, postal-code area, selected travel range, confirmation state, alert consent, and conversion to a registered buyer account.
- Facility information such as manager authority, business contact details, facility location, listing media, unit information, software-integration requests, and operational notes.
- Payment references such as Stripe customer, SetupIntent, PaymentIntent, card brand, last four digits, and payment status. StorBids does not receive or store full card numbers or CVCs.
- Technical information such as IP-derived request identifiers, browser and device information, security logs, timestamps, cookies, and similar session storage required to operate and protect the service.
Why we use information
- Create and secure accounts, verify buyers and facilities, and provide the correct role-based workspace.
- Operate listings, bids, proxy bids, auction close, payments, pickup, cleanout proof, notifications, support, and audit records.
- Prevent fraud, shill bidding, account abuse, payment misuse, privacy exposure, unsafe listings, and unauthorized access.
- Understand bidder travel demand and marketplace coverage so StorBids can recruit relevant facilities and improve auction discovery.
- Meet legal, tax, accounting, dispute, security, and provider obligations and enforce marketplace rules.
Bidder location and market intelligence
Buyers may choose a city, region, postal code, travel scope, and radius so StorBids can surface relevant auctions and measure facility demand. People without an account may join launch alerts by providing an email, postal code, travel radius, and explicit consent. No email-confirmation step is required to join this list. We retain the consent date and distinguish unverified signups from email-verified bidder demand. StorBids may geocode this information to an approximate point for distance calculations; it does not request continuous device location for this feature.
A prospective-bidder record is kept separate from a registered buyer profile and is deduplicated by email when an account is created. Facility managers receive aggregate demand information only, and cohorts smaller than five are suppressed. They do not receive identities, exact locations, proxy maxima, or individual travel profiles. Founder administrators may access controlled internal detail when required for operations, privacy, support, fraud review, or marketplace planning.
Consent and auction messages
We obtain consent appropriate to the sensitivity and purpose of the information. Information required for account security, bids, payment, pickup, or legal compliance is integral to the service. Optional auction alerts and market notifications are presented separately and can be turned off in buyer settings.
Commercial electronic messages identify StorBids and include a working unsubscribe method. We process unsubscribe requests without charge and maintain the minimum suppression record needed to avoid sending again.
Retention and deletion
We retain personal information only as long as reasonably needed for the identified purpose, legal obligations, payment and tax records, dispute periods, fraud prevention, security, and the integrity of auction audit trails. When information is no longer required, we delete, de-identify, or securely dispose of it.
Some auction, bid, payment-reference, consent, withdrawal, and incident records must be retained after account closure to preserve transaction integrity and legal evidence. Suppression records may also be retained so an unsubscribe request remains effective.
Safeguards and incidents
StorBids uses role-based access, private object storage, signed media access, encrypted transport, restricted production credentials, audit logs, rate limits, provider controls, monitoring, and tested backup procedures appropriate to the information and pilot stage.
No service can promise absolute security. We investigate suspected incidents, contain exposure, preserve evidence, and provide legally required notices and reports when a breach creates a real risk of significant harm.
Access, correction, and choices
- Ask whether StorBids holds personal information about you and request access to it, subject to lawful exceptions and identity verification.
- Ask us to correct incomplete or inaccurate personal information.
- Withdraw optional consent or turn off promotional alerts. Withdrawing information needed to operate an account may require closing or restricting that account.
- Challenge our privacy practices by contacting the Privacy Officer. If unresolved, you may contact the Office of the Privacy Commissioner of Canada or another regulator with jurisdiction.
Policy changes
We will update the effective date and version when this policy changes. Material changes to collection, use, disclosure, or buyer-location analysis will be communicated clearly and may require renewed consent.