Legal

Privacy Policy

Draft date: 20 July 2026

1. Controller and scope

OCEBASE LTD is the intended data controller for Subplaza. Its registered address is OCEBASE LTD, Office 15301, Initial Business Centre, Unit 7 Wilson Business Park, Manchester, M40 8WN, United Kingdom. This Policy covers accounts, orders, Marketplace activity, payment coordination, support, marketing and related Services. Independent sellers, brands, payment providers and wallet operators process data under their own notices.

2. Data we collect

We may collect account and contact details; password hashes and authentication records; identity, business, tax, KYC/AML and source-of-funds material; order, delivery, seller, settlement, refund and dispute records; support messages and evidence; reviews and uploaded content; marketing preferences; IP address, device, browser, language, time zone and identifiers; cookies and consent choices; page, click, referral and pixel events; security, fraud, sanctions and wallet-risk signals; and approximate location inferred from network data. Do not submit irrelevant sensitive information.

3. Why and on what basis we use data

We use data to perform contracts, create accounts, process and deliver orders, coordinate payments and withdrawals, provide support, prevent fraud, meet legal and sanctions obligations, secure and improve the Services, keep records, resolve disputes and send consented marketing. Depending on the jurisdiction, the basis is contract, legal obligation, legitimate interests, consent, or establishment and defence of legal claims. Consent may be withdrawn without affecting earlier lawful processing.

4. Cookies, pixels and communications

Strictly necessary cookies support login, security, preferences, checkout and consent records. Analytics, advertising and personalisation technologies are used only where the consent configuration and applicable law permit. Pixel configurations may be supplied through the admin service and loaded only on matching pages. We may communicate by account inbox, email, SMS or customer-support chat. Marketing messages include an opt-out where required; transactional and security messages remain necessary.

5. Sharing

We disclose only what is reasonably necessary to sellers and buyers involved in a transaction; payment, wallet and withdrawal providers shown in the transaction flow; identity, KYC/AML, sanctions and anti-fraud vendors; hosting, database, storage, backup, logging, email, SMS and support providers; professional advisers; affiliates; and authorities or transaction successors where lawful. We do not sell personal data in the ordinary meaning of a cash sale.

6. International transfers and hosting

The main application servers and server backups are hosted on ECS infrastructure in Singapore. Database, object storage, data backups and logs use Supabase; the actual region of each Supabase project must be verified before publication. Where data moves internationally, we use an applicable adequacy mechanism, contractual safeguards or another lawful transfer basis.

7. Current Subprocessor List

  • Singapore ECS hosting provider — application hosting and server backup; Singapore; exact legal entity and backup retention must be confirmed.
  • Supabase, Inc. — database, authentication-related platform services where enabled, object storage, database backups and logs; project region and service configuration must be confirmed.
  • Payment and wallet providers displayed in the applicable checkout or withdrawal flow — payment, refund, payout, AML and fraud processing; provider and region vary by transaction.
  • Cloudflare, Inc. — DNS, CDN/security, Turnstile and, if enabled, web analytics or email routing; processing locations depend on the service.
  • Email, SMS, customer-support, identity/KYC/AML and anti-fraud providers — the production vendors, entities, regions and retention periods must be confirmed before publication.
  • 8. Retention and security

    We retain data only for account operation, warranties, disputes, fraud prevention, tax, accounting, AML, sanctions, security and legal claims, then delete or anonymise it. Exact category-by-category periods and backup deletion windows must be confirmed. We use access controls, encryption in transit, logging, backups and incident procedures, but no system is risk-free.

    9. Your rights

    Depending on location, you may request access, correction, deletion, restriction, portability, objection, consent withdrawal or review of certain automated decisions, and may complain to a regulator. We may verify identity, preserve legally required records and explain lawful exceptions. Requests: [email protected].

    10. Children, changes and contact

    The Services are not directed to persons under 18. We may update this Policy and will give material notice where required. Privacy contact: [email protected]. General support: [email protected].