Privacy Policy
Last updated: 7 September 2026
1. Data controller
The JustSell platform is operated by Cubus Arts S.R.L. (cubus.ro), acting as data controller within the meaning of EU Regulation 2016/679 (GDPR). Contact us at: suport@justsell.ro.
2. What data we collect and why
Account data
When you create an account we collect: your email address, name and profile photo (if you sign in via Google or Facebook). Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
User-generated content
Photos and product descriptions you upload are stored to provide the automated listing creation service. Photos are transmitted to a third-party AI analysis provider for processing (see section 4). Legal basis: performance of a contract.
Seller location
To publish listings, sellers must declare a country and a region (county / state / province) on their seller profile. The profile may optionally include the city, the street address and GPS coordinates (latitude/longitude). The data we store and how it is used:
| Field | Public on listings? | Purpose |
|---|---|---|
| Country | Yes | Required — establishes which country's marketplace the listing belongs to |
| Region (county / state / province) | Yes | Required — buyers expect to know roughly where the item is |
| City | Yes (when provided) | Optional — helps buyers find local items and improves search relevance |
| Street address | No — never displayed publicly | Optional, kept only for the seller's own reference and for future shipping integrations |
| GPS coordinates (latitude / longitude) | No — never displayed publicly | Optional, kept only for future "items near me" map features. We do not currently use this data for any other purpose. |
Country, region and city are embedded in the listing's structured data
(schema.org Product with availableAtOrFrom) so search engines
can correctly rank the listing for local searches. Street address and GPS coordinates
are never included in any structured data, public page, API response,
or sitemap.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) for the required fields (country and region); consent (Art. 6(1)(a) GDPR) for the optional fields, given by the explicit consent checkbox on the seller profile form.
Trial uploads (no account required)
Visitors may try our automated listing service without creating an account by uploading
photos at /try. For trial users we collect and store only:
the uploaded photos, the AI-generated listing content (title, description, price estimate),
a session-scoped random token (used solely so the visitor can return to their own trial
result page within the browser session), and a per-IP counter used for rate limiting (max
3 trial uploads per IP every 24 hours). No personal data, no email, no name is collected.
Trial uploads are stored anonymously for a maximum of 7 days. If the visitor does not create an account within that window, all trial data — photos, listing content, session token — is permanently and automatically deleted. If the visitor signs up during the window, their trial listing is transferred to their new account and becomes a normal draft listing subject to the rest of this policy. Legal basis: legitimate interests (Art. 6(1)(f) GDPR) — letting prospective users evaluate the service before committing to an account.
Photos that may contain other people
Our automated content screening rejects uploads where a real human face is the primary subject (selfies, portraits — see section 4a on automated decision-making). However, listings legitimately showing items in use may incidentally include third parties (e.g. background figures). You are responsible for ensuring you have the right to upload any image containing identifiable people: either by being the subject yourself, having obtained the subject's consent, or by ensuring the third parties cannot be reasonably identified. Any third party who appears in a photo on our platform may exercise their GDPR rights (access, deletion, objection) by contacting suport@justsell.ro; we will process such requests in accordance with section 5 below and may remove the affected listing.
Usage data
We collect technical data (IP address, browser type, pages visited) for security and diagnostic purposes. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
Preferences and settings
We store your language preference and other account settings. Legal basis: performance of a contract.
Credit balance and transaction history
We maintain a credit balance and a record of all credit purchases tied to your account. This constitutes financial account data and is processed for the performance of our service contract. Credit purchase records (amounts, Stripe session IDs, timestamps) are retained for 5 years in accordance with Romanian accounting legislation (Legea contabilității nr. 82/1991). Legal basis: legal obligation (Art. 6(1)(c) GDPR).
Moderation incidents
Each time the automated moderation system rejects a piece of content you submit (an image upload, a listing field, or a message), we record a moderation incident on your account containing: the type of violation detected, which field triggered it, the rejected content (truncated to 500 characters), the affected listing or message identifier where applicable, and a timestamp.
These records are used to apply the automated suspension policy described in section 4a below and to defend the integrity of the platform against repeated abuse. They are not used for any other purpose, are not shared with third parties, and are deleted along with the rest of your data when you delete your account. Legal basis: legitimate interests (Art. 6(1)(f) GDPR) — protecting the platform and its users from unlawful, abusive or fraudulent content, and complying with our obligations under the EU Digital Services Act.
Browser extension (publishing to other marketplaces)
If you connect our browser extension to your account in order to publish listings on third-party marketplaces (see section 4), we store the following on your account:
| Data | What it is | Purpose |
|---|---|---|
| Pairing token (digest only) | A SHA-256 digest of the pairing code. The code itself is shown to you once and is never stored by us. | Lets the extension act on your behalf without a password. Revoking it from Settings disconnects the extension immediately. |
| Token usage: last used at, last used from (IP address) | The time of the most recent request the extension made with the token and the IP address it came from. Only the latest value is kept — each use overwrites the previous one; we do not keep a history. | Security — so that you can see on the Settings page whether the token is in use and from where, and so that a stolen token can be recognised and revoked. Legal basis: legitimate interests (Art. 6(1)(f) GDPR). |
| Publication record, per listing and marketplace | Which marketplace, the state (pending / published / failed), the public address of the advert once you have published it, the advert's identifier on that marketplace, the time of the last report, a short error description if the last attempt failed, and a fingerprint (hash) of the listing content that was handed to the extension. | Lets your listing link to the live advert, shows you whether the listing has changed since it was published there, and shows why an attempt failed. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). |
Nothing about your activity on the marketplace itself is collected. The extension does not read your messages, your other adverts, your contacts or anything else on those sites — see section 4 for exactly what it can access and what it sends back.
3. How long we keep your data
- Account and active listings: for as long as the account is active
- Seller profile (location and public contact details): for as long as the account is active; deleted with the account
- Deleted listings: 30 days, then permanently removed
- Trial uploads (no account): 7 days from upload, then permanently and automatically removed if no account has been created
- Moderation incidents: for as long as the account is active; immediately deleted on account deletion
- Technical logs: up to 90 days
- Browser-extension pairing tokens: for as long as the account is active, including after you revoke one (the revoked record is kept so that a leaked code cannot be reused); all are deleted with the account
- Marketplace publication records: for as long as the listing exists; deleted with the listing, and with the account
- Billing data and credit purchase records: 5 years under Romanian accounting law (Legea contabilității nr. 82/1991)
4. Who we share data with
Hetzner Cloud (hosting and storage)
Servers and object storage (images) are hosted by Hetzner Online GmbH, based in Germany, in compliance with GDPR. Data remains within the European Union.
AI analysis provider
Product photos are transmitted to a third-party AI analysis provider to generate automated descriptions, titles, and price estimates. The provider acts as a data processor. Where the provider is located outside the European Economic Area, the transfer is made under Standard Contractual Clauses (SCCs) approved by the European Commission. Your data is not used for AI model training. The current provider's identity can be obtained on request via suport@justsell.ro.
Google Sign-In (OAuth 2.0)
When you choose to sign in with Google we request the following OAuth 2.0 scopes:
email and profile. These are non-sensitive, basic account scopes.
We do not request access to Gmail, Google Drive, Google Calendar, Google Contacts,
or any other Google service beyond your basic identity.
The specific data we receive from Google and how we use it:
| Data field | Purpose | Stored? |
|---|---|---|
| Email address | Unique account identifier; used to send transactional notifications (listing confirmations, password reset) | Yes |
| Display name | Pre-fill your profile name; displayed on your listings | Yes |
| Profile photo URL | Display your avatar within the platform | URL only (image served by Google) |
| Google Account ID | Uniquely link your Google identity to your JustSell account to enable future sign-ins without a password | Yes — as an opaque identifier |
| Preferred language | Set your default UI language | Yes — as a two-letter locale code |
Data usage restrictions: Google user data is used solely for the purposes described above. It is never sold, rented, or shared with any third party for advertising or marketing purposes. It is never used to train or improve AI or machine-learning models. It is never used for any purpose that is not directly necessary to operate the JustSell service.
Storage: All Google user data is stored in our PostgreSQL database hosted on Hetzner Cloud servers in Germany (EU). Data does not leave the European Economic Area.
Retention: Google user data is retained for as long as your account exists. Deleting your JustSell account permanently removes all associated Google user data from our systems.
Revoking access: You can disconnect Google Sign-In at any time by visiting Google Account → Security → Third-party apps and removing JustSell. You can also delete your JustSell account directly from Settings → Danger zone, which removes all your data from our systems immediately and permanently.
Facebook Sign-In (OAuth)
When you choose to sign in with Facebook we request the email and
public_profile permissions. We receive and store: your email address,
display name, profile photo URL, and Facebook user ID — used for the same purposes as
described in the Google section above. Facebook user data is subject to the same usage
restrictions: never sold, never used for AI training, never shared with third parties.
If you remove the JustSell app from your Facebook settings, Facebook automatically sends us a signed deletion request and your data is removed immediately — no further action required.
Observability and error monitoring (APM)
We use an application performance monitoring (APM) system to capture technical errors and performance traces. Error reports may include contextual data such as anonymised user identifiers and the action being performed at the time of the error. This data is processed solely for diagnosing and fixing technical issues. It is not used for any other purpose, is not shared with third parties, and is retained for a maximum of 90 days. Legal basis: legitimate interests (Art. 6(1)(f) GDPR) — ensuring the reliability and security of the service.
Stripe (payment processing)
Credit purchases are processed by Stripe, Inc., a PCI DSS Level 1 certified payment processor. When you make a purchase, you are redirected to a Stripe-hosted checkout page. JustSell does not receive or store your card number, CVV, or any other raw payment card data.
We receive from Stripe: a payment confirmation event, the amount and currency paid, and your email address (used only to identify your account). We store the Stripe session ID and payment intent ID for audit and dispute resolution purposes. Billing records are retained for 5 years in accordance with Romanian accounting legislation.
Stripe's privacy policy is available at stripe.com/privacy.
Browser extension and third-party marketplaces (OLX.ro, Okazii.ro, Facebook Marketplace)
We offer a browser extension that fills in the posting form of a third-party marketplace with the content of one of your listings. It is important to be precise about the data flow here, because it is not what the word "sharing" usually means:
We do not transmit your listing to any marketplace. The extension runs in your own browser. When you press "Send to OLX" (or Okazii, or Facebook Marketplace), the extension downloads the listing — title, description, price, condition, category hint, and reduced-size copies of the photos — from our servers to your browser, over your own connection, and types it into the marketplace's form in the browser tab where you are already signed in to that marketplace. The marketplace sees a form being filled in by you, from your device and your IP address. Nothing is sent from our servers to theirs, and the extension never presses Publish: you review the form and submit it yourself. From that moment the content is held by that marketplace under its privacy policy, which we do not control.
We never hold credentials for those sites. The extension does not ask for, see or store your OLX, Okazii or Facebook password, and it does not use their APIs on your behalf. Disconnecting is a matter of revoking the pairing token in Settings or removing the extension from your browser.
What the extension can access. Your browser will tell you that the extension
can "read and change" data on olx.ro, okazii.ro and
facebook.com/marketplace. Here is what it actually does with that access, and
all it does:
- On a marketplace posting form that the extension itself opened for one of your listings, it locates the form fields and fills them in. To decide what to fill, it reads the form: whether a field exists, whether it is empty, on OLX whether a "resume your unfinished advert" prompt is shown (which it leaves for you to answer), and on Okazii the option lists of the category picker, to find the one matching your listing's category. Contact and location fields that the marketplace has already pre-filled from your account there are never overwritten.
- After you publish, it watches the address bar of that tab for the resulting advert's URL, so that it can report the advert's address back to us.
- On any other page of those sites — your feed, messages, other adverts, a form you opened yourself — it does nothing. Each job is tied to the single tab the extension opened for it, and the extension refuses to fill a tab it did not open.
What the extension sends to us. Exactly three things, and nothing else read
from the marketplace: (1) a request for the listing content, authenticated with your
pairing token; (2) once you have published, the public address of the advert;
(3) if it could not fill the form, a short technical description of why, which may
include the address path of the page it was on (for example /adding). It does
not send us your marketplace account details, the content of pages it visits, the values the
marketplace pre-filled, or any browsing activity. A diagnostic trace of the extension's own
steps is kept locally in the extension's storage in your browser and never leaves
it.
On Facebook specifically. The extension is restricted to
facebook.com/marketplace pages only. It has no access to the rest of Facebook.
It is unrelated to "Sign in with Facebook" above: connecting the extension does not require
a Facebook login on our side, and no data is exchanged with Meta by us.
Legal basis for the processing described here: performance of a contract (Art. 6(1)(b) GDPR) — you asked us to help you publish a listing elsewhere. The extension's source code is provided to you in full when you install it and can be inspected at any time.
4a. Automated decision-making (GDPR Art. 22)
We operate three automated decision systems that may affect your use of the platform. All three operate without prior human review. Each is described below together with its purpose, the data it processes, and how you can contest its outcome.
1. Image moderation
When you upload photos, our AI automatically screens the content. If the AI determines that an upload contains prohibited content (illegal items, explicit material, weapons, personal identity documents, or unsuitable personal photos), the listing or upload is automatically rejected and the images are permanently deleted. The same screening is applied to photos added later via the "add more photos" workflow.
2. Text moderation
Listing titles, descriptions, hints, keywords, and messages between users are screened for HTML markup (which is rejected immediately by a deterministic rule) and for explicit or pornographic language, hate speech, threats, harassment, and promotional spam (which are detected by AI). Submissions that fail this screening are rejected and the offending content is not saved.
3. Automated account suspension
Each rejection (image or text) is recorded as a moderation incident on your account. If your account accumulates more than 10 moderation incidents within a rolling window of 7 days, your account is automatically suspended. A suspended account cannot create or edit listings, send messages, or sign in to the platform. The threshold and time window may be adjusted by us at any time, in good faith — see Terms of Service section 10.2 for details.
Legal basis and your rights
The legal basis for all three automated decisions is our legitimate interest (Art. 6(1)(f) GDPR) in preventing unlawful, abusive or fraudulent content from appearing on the platform, complying with our obligations under the EU Digital Services Act (Regulation (EU) 2022/2065), and protecting our other users.
Your right to contest: Under GDPR Article 22(3) and DSA Article 20 you have the right to obtain human intervention, to express your point of view, and to contest any of these automated decisions. To do so, email suport@justsell.ro within 14 days of a content rejection or 30 days of an account suspension. Your appeal is reviewed by a person who was not involved in the automated decisions. If we find that the decision was incorrect we will reverse it promptly and, where appropriate, clear the underlying incidents from your record.
5. Your rights (GDPR)
Under GDPR you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your data ("right to be forgotten")
- Restriction — limit processing of your data
- Portability — receive your data in a structured format (JSON/CSV)
- Objection — object to processing based on legitimate interests
- Withdrawal of consent — at any time, without retroactive effect
To exercise your rights, email suport@justsell.ro. We will respond within 30 days.
How to delete your account and data
You can delete your account at any time, instantly and automatically, from Settings → Danger zone or via this page. The deletion is immediate and permanent: your account, every listing, every photo, and any OAuth connection (Google, Facebook) are removed from our databases. We retain only a non-personal confirmation code as proof the deletion happened.
Facebook users: if you remove the app from your Facebook settings, Facebook automatically sends us a deletion request and your data is removed based on the signed confirmation received from Facebook — no further action required on your side.
6. Supervisory authority
If you believe your rights have not been respected, you may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP):
- Website: www.dataprotection.ro
- Email: anspdcp@dataprotection.ro
- Address: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania
6a. Email and marketing consent
We send account-related emails. They fall into two categories:
- Transactional / legally required — account confirmation, password reset, listing rejection (requires your action), batch publish report, account deletion. These are always sent regardless of your preferences, as they are necessary to deliver the service (Art. 6(1)(b) GDPR — performance of contract).
-
Optional — new message about one of your listings,
a listing of yours has been approved and is now live, weekly reminder
about unpublished listings. You can opt out of each of these categories:
- Directly from the footer of any such email (the "Do not send me emails like this" link).
- From your account settings, "Email preferences" section.
The unsubscribe link in our emails uses a signed token and acts instantly without requiring login — in line with GDPR and CAN-SPAM best practice. Re-subscribing is a single tick away from your settings page.
7. Security
All communications are encrypted via HTTPS/TLS. Passwords are hashed with bcrypt. Data access is restricted through role-based access control (RBAC). We conduct periodic security audits.
8. Public seller information (contact and location)
To publish listings on JustSell, sellers must complete a Seller Profile that contains:
- A location — at minimum the country and region (county / state / province), with optional city. See section 2 ("Seller location") for the full list of fields and which are public versus private;
- At least one public contact method — phone number, email address, or Facebook page — that the seller agrees to display publicly on their listings.
By saving a seller profile, the seller explicitly consents to the publication of the selected information on all their active listings. A single consent checkbox covers both location and contact details, and the consent is recorded with a timestamp. Sellers may update or remove any field at any time from Account Settings.
If the seller removes their public contact methods, or clears the country/region from their location, the profile becomes invalid for publishing and any subsequent listing cannot be published until the profile is completed again. Existing published listings are not retroactively unpublished by editing — they remain visible until the seller explicitly unpublishes them or deletes them.
Public seller information (country, region, city, contact details) is visible to any visitor of the platform and may be indexed by search engines. JustSell is not responsible for third-party use of publicly displayed seller information. Street address and GPS coordinates are never displayed publicly under any circumstance.
9. Changes to this policy
We reserve the right to update this policy. Significant changes will be communicated by email at least 14 days before they take effect. The date of last update is shown at the top of this page.