This document applies when using the “Used Parts – Nupirkpigiau.lt” platform and its features.
Privacy Policy
This Privacy Policy explains how the “Used Parts – Nupirkpigiau.lt” platform collects, uses, stores and discloses personal data.
The data controller is MB “RYHA”, company registration number 306987936, address Gėlių g. 2A, Kretingalė, Klaipėda district, Lithuania. Privacy enquiries may be sent to info@nupirkpigiau.lt.
**Translation notice.** This English text is provided for convenience. Where interpretation differs, the Lithuanian version prevails, except where mandatory law requires otherwise.
1. Scope
This Policy applies to visitors, registered users, buyers, private and business sellers, support requesters and other persons whose data is processed through the platform.
Payment, identity verification, delivery and other partners may act as independent controllers and provide their own privacy notices.
2. Data we process
Depending on the features used, we may process:
- account information, including name, email, phone number, password hash, account status and settings;
- seller information, including seller type, personal or business name, company and VAT numbers, address, dispatch city and verification status;
- listing information, including title, description, price, photographs, SKU, part codes, compatibility, condition and category;
- transaction information, including orders, prices, fees, delivery data, tracking numbers, returns, disputes and payout status;
- communications, including platform messages, support requests, attachments, notifications and administrative notes;
- usage and technical information, including IP address, browser information, login time, security logs, activity history and cookie preferences;
- rating and reputation information, including reviews, reports and moderation outcomes;
- import data, including CSV content, image URLs, import status and error reports;
- information required by law for tax authorities, law enforcement or other public bodies.
The platform does not store full payment card details. Where payments are active, they are processed by a licensed payment provider under its own terms.
3. Sources of data
We receive data directly from you, automatically through use of the website, from other transaction participants, from payment, delivery and verification partners, from public registers or lawful sources, and from public authorities or fraud-prevention sources where permitted.
4. Purposes and legal bases
We process data to:
- create and administer accounts and provide platform features – performance of a contract;
- publish listings and administer orders, delivery, returns and disputes – performance of a contract;
- verify identity, seller status and lawful activity – legal obligation and legitimate interests;
- detect fraud, abuse, cyberattacks and rule violations – legitimate interests and, where applicable, legal obligations;
- comply with accounting, tax, DAC7, law-enforcement and other legal duties – legal obligation;
- provide customer support, improve quality and preserve evidence – contract performance and legitimate interests;
- personalise recommendations and search – legitimate interests;
- perform analytics or marketing – consent where required;
- send news or commercial communications – consent or legitimate interests where permitted.
Where data is necessary for a contract or legal obligation, failure to provide it may prevent access to the relevant feature.
5. Public information
Publicly visible information may include display name, avatar, verification badges, seller type, reputation, account age, listing statistics, listing content, photographs, price, condition, compatibility and public reviews.
Private address, phone number, email, payment information and identity documents are not publicly displayed unless disclosure is legally required for a business seller or the user deliberately publishes such information.
6. Recipients
Data may be disclosed to hosting and infrastructure providers, email and maintenance providers, delivery providers including DPD, payment and identity-verification partners, accounting, legal, audit and fraud-prevention providers, public authorities and courts, another transaction participant where necessary, or a lawful business successor.
Service providers receive only the data necessary for their function and must apply appropriate confidentiality and security measures.
7. Seller data and DAC7
Where digital platform reporting obligations apply, we may collect, verify, retain and report seller identity, address, tax identification, transaction and income data to the State Tax Inspectorate or another competent authority.
Sellers must provide accurate information. Where required data is missing or cannot be verified, selling features or payouts may be restricted as permitted by law.
8. Automated analysis and moderation
The platform may automatically assess risk signals relating to listings, accounts and transactions, such as unusual listing volume, duplicate content, reports, dispute frequency or technical security indicators.
An automated signal may result in temporary holding of a listing, additional review or a feature restriction. Significant decisions may be reviewed by an administrator where appropriate and legally required. Users may challenge decisions through the Help Centre.
9. Retention periods
Data is retained only for as long as necessary for the purpose for which it was collected, legal obligations, dispute resolution, fraud prevention and enforcement of agreements.
Typical retention periods depend on the data category. Accounting and tax records may be retained for statutory periods; transaction and dispute evidence may be retained for the limitation period; security logs are generally retained for a shorter operational period; temporary exports and files are deleted after their stated expiry. Active legal holds suspend deletion where necessary.
10. Security
We use organisational and technical measures such as access controls, password hashing, encrypted connections, audit logs, backups, request protection, monitoring and least-privilege access. No system can be completely risk-free, and users should protect their credentials and devices.
11. Transfers outside the EEA
Where a provider processes data outside the European Economic Area, we use a legally recognised transfer mechanism where required, such as an adequacy decision, standard contractual clauses or another lawful safeguard.
12. Your rights
Subject to legal conditions, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent at any time. You may also request human review of a significant automated decision where applicable.
Requests can be submitted through the Privacy Centre or by email. We may ask for identity verification. Certain data may be retained where required by law or necessary for legal claims, security or fraud prevention.
You may lodge a complaint with the Lithuanian State Data Protection Inspectorate or the competent authority in your country of residence.
13. Cookies
We use essential cookies for sessions, security and preferences. Analytics and marketing cookies are used only where connected and where consent is required and obtained. Details are available in the Cookie Policy and Cookie Settings.
14. Minors
The platform is not intended for persons under 18. We do not knowingly create accounts for children. If we learn that a minor’s data has been processed without a lawful basis, we will take appropriate steps to delete or restrict it.
15. Changes to this Policy
This Policy may be updated when legal requirements, platform features or service providers change. Material changes will be communicated through the platform or by email where appropriate.
16. Contact and complaints
MB “RYHA”
Company registration number: 306987936
Address: Gėlių g. 2A, Kretingalė, Klaipėda district, Lithuania
Email: info@nupirkpigiau.lt
Loading...
