Privacy Policy

Last updated: August 25, 2026

This page explains what data is collected on "Data Marketplace" (the "Service"), why, who it is shared with, and how to exercise your rights.

1. What data is collected

  • User account: email address, full name, organization and role, collected when you sign in (email/password or Google account, via our authentication provider Auth0).
  • Usage data: actions performed on the Service (browsing the catalog, downloads, calls to the datasets you have subscribed to), used for usage-based billing and Service security.
  • Payment data: card payments are processed directly by Stripe. The Service never receives or stores your card number.
  • Content uploaded by data producers: some datasets sold on the Service may contain personal data about third parties (not Service users). In that case, the organization that uploads the dataset declares the applicable purpose, legal basis and retention period — this information is shown on the relevant product page, and that organization remains responsible for the lawfulness of the original collection of that data.

2. Why this data is processed

  • Providing the Service: creating and managing your account, subscriptions, and invoices.
  • Security: detecting and preventing fraudulent or abusive use.
  • Legal obligations: keeping accounting records, responding to requests from competent authorities.

The legal basis for this processing is, depending on the case, performance of the contract that binds you to the Service, the legitimate interest of its publisher (security), or compliance with a legal obligation.

3. Who the data is shared with

The Service uses the following providers, each acting as a data processor, solely for the purposes described above:

  • Auth0 (Okta, Inc.) — authentication and sign-in management.
  • Stripe — card payment processing.
  • Brevo — sending transactional emails (invoices, notifications).
  • Backblaze B2 — encrypted, off-site backup of the Service's data.
  • OVHcloud — hosting of the Service's servers, in France.

Some of these providers (Auth0, Stripe) may involve a data transfer to the United States, governed by their own compliance mechanisms (standard contractual clauses or equivalent). No data is sold to third parties.

4. Retention period

Your account data is kept for as long as your account remains active, then for the period required by our legal obligations (particularly accounting) after it is closed.

5. Cookies

The Service uses a single cookie, strictly necessary for signing in (keeping your session). No advertising or third-party tracking cookie is used.

6. Your rights

Under applicable personal data protection regulations, you have the right to access, rectify, erase, restrict, port and object to your data. You can exercise these rights by writing to data.marketplace.contact@gmail.com. You also have the right to lodge a complaint with the competent data protection authority.

7. Security

Exchanges with the Service are encrypted (HTTPS). Each client organization's data is technically isolated from other organizations' data. Access to data is restricted to the people and systems that need it to provide the Service.

8. Changes to this policy

This policy may be updated; the date at the top of the page shows the last change. Any substantial change will be notified to you.

9. Contact

For any question about this policy or your data: data.marketplace.contact@gmail.com.

Data Marketplace is a service published by Noureddine Mokhtari, sole trader.