Privacy Policy
This Privacy Policy explains what data is processed when you use the Mysels web application (the “Service”), for what purposes, and under what conditions. The Service is intended for users aged 18+ and is aimed primarily at audiences in the Russian Federation and the Republic of Moldova.
1. Data controller
Controller: Ribalca Serghei, natural person, Bender, Republic of Moldova.
Privacy contact: srybalka07@gmail.com. A dedicated address privacy@mysels.com on the mysels.com domain may be used when available; the current contact is always stated in the active version of this Policy.
2. Data we process
Depending on your role, we may process:
- Clients (storefront visitors): anonymous client/device identifier, favorites, filter settings, cart contents, checkout draft (name, phone, email, delivery address, Telegram, comment), support chat message text, and service context (app role, clientId, platform, app version).
- Masters: name, city, phone, profile description, photos, geolocation and map links, social/messenger contacts, portfolio and price list, secret phrase hash, recovery question hashes (mother’s maiden name, birth city, school number — only hashes are stored on the server, not plaintext).
- Shops (markets): name, tagline, cities, phone, logo, website, geo data and map links, contacts, YML feed URL, secret phrase hash, recovery question hashes (same approach as for masters).
- Orders: name, phone, email, Telegram, delivery method and address, pickup point, comment, order line items (products, prices, quantities).
- Technical data: session tokens (hashed on the server), abuse-prevention rate-limit identifiers, app version when contacting support (if enabled).
3. Purposes
- providing Service features (discovery, master/shop cabinets, orders);
- registration, sign-in, and master/shop cabinet recovery;
- delivering order data to shop owners and notifying them via chosen channels;
- handling support requests and generating replies (including via an AI assistant);
- preventing duplicate cabinets and abuse;
- storing profile media;
- operating and securing the Service.
4. Legal bases
- Consent — when registering a master or shop cabinet (acknowledgement of this Policy, consent to personal data processing, confirmation of age 18+, and consent to cross-border transfer as described in Section 7) and when placing an order (acknowledgement of this Policy and consent to personal data processing to submit the order to the shop).
- Performance of the user flow — cabinet sign-in, access recovery after registration, profile and catalog management, storefront and cart use without checkout.
- Legitimate interest — abuse prevention and technical rate limiting.
5. Storage on your device
The Service does not use HTTP cookies for core functionality. localStorage and sessionStorage are used for sessions, cart, checkout drafts, and registration progress. Recovery answers and new secret phrases are not persisted in sessionStorage.
When installed as a PWA, a service worker may cache static app assets.
6. Where data is stored and retention
- Primary database and media storage — Supabase, EU (Frankfurt, eu-central-1).
- Frontend and support API hosting — Vercel, North America (Washington, D.C., USA).
- Uploaded profile, portfolio, price list, logo, and product images — Cloudinary (media CDN/hosting; processing region depends on the provider, typically outside the RF/MD).
- Master and shop recovery challenges — 15-minute TTL, then scheduled cleanup.
- Other retention follows Service needs and legal obligations; see Section 9 for requests.
7. Third parties (processors and recipients)
- Supabase — database and file storage (EU, Frankfurt).
- Vercel — site and API hosting (USA).
- Resend — order notification emails to addresses configured by shop owners (USA and other regions).
- Telegram — order notifications to chats configured by shop owners.
- Yandex Maps — map display in the user’s browser (JavaScript API).
- Cloudinary — hosting and delivery of uploaded images (profiles, portfolios, products; CDN, typically USA and other regions).
- OpenAI — AI assistant replies in support chat (USA and other regions; message text and user service context are transmitted).
- Shop owner webhook URL — order data may be POSTed to URLs configured by the shop (CRM, ERP, etc.). Mysels acts as a platform; further processing is the shop owner’s responsibility.
Data may be transferred outside your country of residence, including to countries where these providers operate (EU, USA, etc.), to deliver the Service.
8. Account recovery
Self-service recovery is available for master and shop cabinets using profile data and secret questions, with a new secret phrase issued after successful verification.
9. Your rights
You may:
- request information about processing of your data;
- request correction, restriction, or deletion where data are inaccurate or outdated;
- withdraw consent where processing is consent-based (without retroactive effect).
Send requests to srybalka07@gmail.com. We aim to respond within a reasonable time, typically within 30 calendar days.
10. Security
Secret phrases and recovery answers are stored as cryptographic hashes. Database access is restricted. No online service can guarantee absolute security; keep your secret phrase safe.
11. Changes
We may update this Policy when features or processors change. The current version is published at mysels.com/privacy-en with the effective date. Continued use after publication means acceptance of the updated Policy where permitted by law.
12. Planned updates
When we add payment providers for subscriptions and other new processors, this Policy will be updated. The latest version is always available at the links above.