General provisions
This Policy sets out how the personal data of users of the digital-goods store automation service MarketNet
(hereinafter the “Service”), located at marketnet.pro, is processed. The Policy is drawn up in accordance with Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” (hereinafter the “Personal Data Law”).
The Operator of Users’ personal data is the Service Administration. Its corporate and registration details are provided upon a written request sent to the contacts listed in section 14.
The Service is a technical tool. It connects to Marketplaces (GGsel, Digiseller) over their official programming interfaces and performs actions there on the User’s behalf and at the User’s instruction: it updates prices, delivers digital goods to Buyers, answers routine questions. The Service is not a party to the User’s transactions with Buyers, does not sell goods and does not receive money for them.
Registration with the Service means that the User has read this Policy and agrees to the conditions of processing described in it. Use of the Service by a person who does not agree with those conditions is not permitted.
The data at a glance. Full name, identity document details and telephone number are neither requested nor stored. An email address is used for signing in, and Marketplace access keys for working with the store. Access keys are stored in encrypted form and never appear in clear text in logs or in backups.
Definitions
- Service Administration — the person that operates the Service and determines the purposes and means of processing Users’ personal data.
- User — an individual registered with the Service. As a rule, a seller of digital goods on the connected Marketplaces.
- Buyer — a person who buys goods from the User on a Marketplace. The Buyer enters into no relationship with the Service.
- Marketplace — a third-party trading platform (GGsel, Digiseller) the Service connects to over its official API.
- Personal data — any information relating, directly or indirectly, to a specific identified or identifiable individual.
- Processing — any operation on personal data: collection, recording, storage, use, transfer, anonymization, deletion.
- Operator — the person who determines why and how personal data is processed.
- Processing on instruction — the case where one person processes data not for themselves but at another person’s instruction and in their interest (part 3 of article 6 of the Personal Data Law). It is on this basis that the Service processes Buyers’ data — see section 4.
Data processed
The Service processes only the data without which it cannot operate. The full list of categories is set out below.
3.1. Account
- email address — it is also the login and the only identifier of the User;
- password — stored only as an irreversible hash (the Argon2id algorithm); the original password cannot be recovered from the hash — it can only be replaced;
- interface language and time zone — so that dates are shown in the User’s own time;
- Telegram account identifier (
chat_id) — only if the User has connected the Telegram bot themselves;
- the User’s referral code and the registrations made with it — for crediting the referral program reward;
- the User’s staff — a label, Telegram identifiers and a set of permissions; they are added by the User and processed on the User’s instruction, and are kept until the User removes the staff member.
3.2. Sign-in and security
- the IP addresses used to sign in and browser details (User-Agent);
- dates and times of sign-ins, the list of active sessions on devices;
- the hash of the session token (the token itself is not stored in the database);
- the list of IP addresses the User has signed in from before — signing in from a new address requires a bot check; the list is kept for 90 days;
- two-factor authentication data, if the User has enabled it: the secret in encrypted form, the recovery codes as irreversible hashes.
3.3. Connected marketplaces
- the API access keys of the User’s store on GGsel and Digiseller;
- the seller ID on the Marketplace side;
- the store’s remaining funds as reported by the Marketplace, and the time of the last update — so that it can be shown in the app without calling the Marketplace every time a page is opened.
Access keys are stored in encrypted form. Envelope encryption is used: the data is encrypted with a working key, and the working key itself with a master key kept in a cloud key management service (KMS) which it never leaves. In plaintext the credentials exist only in memory at the moment of a call to the Marketplace; they never reach logs, database dumps or the admin panel.
The seller ID is additionally used so that the same store cannot obtain the trial period again through a new registration.
3.4. Digital goods for auto-delivery
Keys, codes and account data uploaded by the User to the Service for automatic delivery to Buyers. This information is the User’s goods, not personal data, but it is protected in the same way as access keys — by the same envelope encryption.
3.5. Payment
The Service does not receive and does not store bank card details. The following is processed: the amount and currency of a top-up, the date and status of the payment, the transaction identifier, the payment identifier issued to the User for topping up the balance, the sender’s payment identifier for an incoming payment, and the history of subscription charges.
The payment identifier issued to the User for topping up, and information about incoming payments, are checked against external data sources of the relevant payment network: this is necessary to confirm that funds have arrived and to monitor the status of the Service’s payment details.
3.6. Technical logs
- records of sign-ins to the account and the history of bulk operations;
- records of the Service’s calls to Marketplace APIs: time, method, response code, duration — without storing request bodies containing sensitive values;
- the price calculation log: the input data of a calculation and its result;
- the log of price updates sent to Marketplaces and the log of notifications sent to the User.
3.7. Support requests
The text of the request and its attachments. Used only to answer that request.
3.8. Data that is not collected
The Service neither requests nor stores:
- surname, first name, patronymic;
- phone number;
- passport or other identity documents;
- residential address;
- bank card details;
- biometric data;
- special categories of data — health, views, beliefs, national or racial origin, sex life.
A User is identified solely by the email address linked to the account.
Data of the User’s buyers
This section sets out how data relating to the User’s Buyers is processed.
In order to deliver goods to a Buyer and answer their question, the Service receives order and messaging details from the Marketplace. Of these, the following are processed:
- the Buyer’s identifier on the Marketplace side;
- the Buyer’s email address — if the Marketplace passes it and it is needed to deliver the goods;
- the chosen contact method;
- the text of the Buyer’s messages — if the User has enabled auto-replies: selecting an answer requires the message to be read;
- the Buyer’s name and the text of the review they left — to the extent published by the Marketplace;
- the IP address and browser details of a Buyer who followed the delivery link — to protect the delivery page against abuse;
- the identifier of a Buyer added by the User to their own blacklist.
Allocation of roles. The Operator of this data is
the User: the User carries on the trade, and the Buyer buys from the User. The Service processes such data
at the User’s instruction (part 3 of article 6 of the Personal Data Law) — solely in order to deliver the goods and send a reply.
It follows that the User is obliged to ensure a lawful basis for processing their Buyers’ data and compliance with the law in relations with them. The Service does not create that basis on the User’s behalf.
The Service does not use Buyers’ data for its own purposes: it builds no profiles on them, sends them no advertising, passes them to no one except the Marketplace they came from, and never merges the Buyer data of different Users.
The retention periods are set out in section 6. Raw order records are kept for 35 days, the auto-reply log together with message texts for 30 days, records of visits to the delivery link for 7 days, and reviews for 90 days. The Buyer identifier is additionally kept in the delivery log: 12 months in the main database and then in archive storage, 3 years in total — this period is required in order to prove performance of obligations in disputed orders. A blacklist entry is kept until the User deletes it. Once these periods expire, all that remains of the order data are anonymized daily amounts and counts, from which no individual Buyer can be identified.
Purposes and legal grounds
The Service processes the User’s data for the following purposes:
- Registration and sign-in. Creating an account, verifying the email, authentication, recovering access.
Legal basis: performance of the contract with the User (clause 5 of part 1 of article 6 of the Personal Data Law).
- Operation of the Service. Connecting Marketplaces, calculating and updating prices, auto-delivery of goods, auto-replies, analytics of the User’s store.
Legal basis: performance of the contract.
- Subscription payment. Balance top-ups, charges, refunds, transaction records.
Legal basis: performance of the contract; statutory accounting requirements.
- Notifications about the Service. Messages about delivery failures, problems reaching a Marketplace, the end of a subscription.
Legal basis: performance of the contract. Delivery channels are configured in the app by event category; notifications classified as critical are delivered regardless of those settings — without them the User would not learn that their store has stopped working.
- Support. Answers to requests.
Legal basis: performance of the contract.
- Security. Protection against password brute-forcing and repeated trial periods, incident investigation.
Legal basis: the legitimate interest of the Service Administration and of its users.
- Legal requirements. Responses to lawful requests from competent authorities.
Legal basis: compliance with an obligation imposed by law.
The Service does not send marketing messages. Should any appear, consent to receive them will be requested through a separate setting that is off by default, and will not be treated as given by virtue of this Policy.
Retention periods
Below are the actual periods built into the Service. Once they expire, the data is deleted or anonymized automatically.
Indefinitely
- Account — email, the fact that the trial period was used, referral relationships. Why: operation of the Service and protection against a repeated trial period.
- Subscription and financial transaction history — top-ups, charges, refunds. Why: keeping account of settlements with the User.
- The seller ID on the Marketplace and the history of the accounts it has been linked to.
Why: protection against abuse.
- Administrator action log.
Why: the ability to establish who performed which actions on the data.
- Buyer blacklist entries — until the User deletes them. Why: keeping the list is the User’s decision, and the User determines how long it is kept.
- The User’s staff — label, Telegram identifiers and the set of permissions, until the User removes the staff member.
Why: the staff member’s access to notifications and the bot is the User’s decision.
3 years
- Digital goods delivery log — the fact and time of a delivery, together with the Buyer identifier (12 months in the main database, then in archive storage).
Why: proof of performance for disputed orders.
180 days
- Delivered auto-delivery items — the goods handed to the Buyer (stored in encrypted form) and the order number.
Why: showing the item to the Buyer again via their link and proving delivery in a dispute. Once the retention period expires, the record of the delivery remains in the delivery log while the delivered goods are erased.
90 days
- Buyer reviews — the name, rating and text of a review to the extent published by the Marketplace, together with the User’s reply.
Why: managing the store’s reputation in the app.
- Price history — the price changes of each product variant.
- In-app notifications — the title and body of a message to the User.
Why: the notification feed in the app; it shows the most recent messages, and earlier ones are deleted.
35 days
- Raw order records, including Buyer data. After that only daily amounts and counts remain, with no Buyer details.
Why: a month of order history in the app and a window for handling late refunds.
30 days
- Auto-reply log, including the texts of Buyers’ messages.
- Bulk operation history.
- Sessions and sign-in records — IP address and browser details; kept while the session is valid and for 30 days after it expires or is revoked.
Why: investigation of access incidents.
14 days
10 days
- Price update jobs sent to the Marketplaces.
7 days
- Notification delivery log, including the text of messages sent to Telegram.
- Log of visits to the delivery link — the Buyer’s IP address and browser details.
Why: protecting the delivery page against abuse.
3 days
- Technical log of calls to Marketplace APIs.
24 hours
- Trash — products, money chains, auto-replies and other objects deleted in the app. They can be restored within 24 hours; after that they are permanently deleted.
The subscription term and 180 days after it ends
- The catalog, settings, money chains, auto-replies and uploaded goods. They are retained in case the subscription is resumed; Marketplace access keys are deleted immediately when it ends. The detailed procedure is in section 12.
Exchange rates, game platform prices and public Marketplace statistics are not personal data and are not covered by this list.
Data sharing
Personal data is not sold and is not disclosed for advertising purposes. It is disclosed only to those parties without whom the Service cannot operate, and only to the extent necessary for the relevant purpose:
- Marketplaces (GGsel, Digiseller) — access keys and the content of operations (new prices, reply texts for Buyers, product codes) are transmitted.
Why: running the User’s store, at the User’s instruction.
- Payment service providers — the amount, currency and transaction identifier; the email address where the selected payment method requires it.
Why: accepting payment. The list of available top-up methods is shown on the balance top-up page.
- External payment-network data sources — the payment identifier issued to the User for topping up the balance.
Why: confirming that funds have arrived and monitoring the status of the Service’s payment details.
- Cloud key management service (KMS) — encrypted data blocks only. Why: encryption of credentials and goods.
- Bot-check service (Yandex SmartCaptcha) — the IP address and technical browser details on registration, as well as on sign-in from an unfamiliar IP address or after several failed attempts.
Why: protection against automated password brute-forcing and mass registration.
- Telegram — the chat identifier and the notification text, if the User has connected the bot. Why: delivery of notifications.
- Email service provider — the email address and the body of the message. Why: email verification, password recovery, critical notifications.
- Hosting provider and object storage — the technical platform on which the Service runs and where archives are stored.
Why: hosting the infrastructure.
In addition, data may be provided to competent state authorities upon their lawful and substantiated request.
Where the data is stored
The Service databases in which the recording, systematization, accumulation, storage, updating and retrieval of personal data of citizens of the Russian Federation take place are located in the territory of the Russian Federation — as required by part 5 of article 18 of the Personal Data Law.
Certain technical services listed in section 7 process the data transmitted to them on their own systems and in accordance with their own policies; some of them are located outside the Russian Federation.
Data protection
- Passwords are stored as an irreversible hash (Argon2id). The original password is available to no one, including the Service’s staff.
- Marketplace credentials and uploaded goods are protected by envelope encryption. The master key resides in a cloud KMS and never leaves it: the application asks the KMS to decrypt the working key but never receives the master key itself. A copy of the database does not allow this information to be read without access to the KMS.
- Sessions. The access token is valid for 15 minutes and is kept only in the browser’s memory. The long-lived refresh token is passed in a secure cookie that JavaScript cannot read; only its hash is stored in the database. Any session can be revoked, including on all devices at once.
- Request rate limiting on all public endpoints — protection against brute force.
- Two-factor authentication is mandatory for administrative access and available to the User at their option.
- Administrative action log — every action of a staff member on user data is recorded.
Caveat. The measures listed substantially reduce risk and limit potential damage; complete security of information systems is, however, unattainable. On receiving information about an incident affecting a User’s data, the Service Administration notifies the User and the competent authority within the periods established by law.
Cookies
The Service uses only strictly necessary cookies:
- the cookie carrying the session refresh token — without it, signing in would have to be repeated on every page reload. The cookie is secure, unavailable to JavaScript and is not sent to third-party domains.
The Service does not use cookies for analytics, advertising, cross-site tracking or profiling. There are no third-party counters or advertising pixels on the site. The bot-check widget is shown by a third-party service and may use its own cookies on its domain.
The Service counts visits to its public pages itself, without cookies. Anonymised daily counters are stored: the page, its language, the kind of referral source, the device type, the fact that a button was clicked and the fact that the page was scrolled down to the pricing block. IP addresses, browser details and visitor identifiers are not stored.
Necessary cookies can be blocked by browser settings; in that case signing in to the app becomes impossible.
Rights of the User
The User has the right to:
- learn whether their data is processed and obtain a copy of it;
- demand that inaccurate or incomplete data be corrected;
- demand deletion of data if it is processed unlawfully or is no longer needed for the stated purposes;
- withdraw consent to processing;
- challenge the actions of the Service Administration before Roskomnadzor (the Russian data protection authority) or in court.
Some of these rights are exercised directly in the app: viewing and changing account data, revoking sessions and disconnecting Telegram are all available in the “Settings” section. Deletion of the account is carried out upon request — see section 12.
Any other requests are to be sent to support@marketnet.pro
from the email address linked to the account; sending a request in this way serves as identity confirmation. The response time is no more than 30 days.
Limitation. Withdrawing consent and deleting data make the Service impossible to operate: without an email address there is no way to sign in, and without Marketplace access keys there is no way to update prices. Withdrawing consent is therefore equivalent to ceasing to use the Service. Data whose retention is required by law (in particular, records of financial transactions) is not subject to deletion on request.
Account deletion
The account is deleted at the User’s request, sent to the support address given in section 14 from the email address linked to the account. A separate procedure applies where a subscription has ended and was not renewed.
Where the account is deleted upon the User’s request, and where access is terminated at the initiative of the Service Administration:
-
The account is marked as deleted and all sessions are terminated — signing in becomes impossible.
-
The subscription is not renewed. When it ends, the stored Marketplace access keys are deleted: from that moment the Service cannot reach the User’s store, not even technically.
-
The catalog, settings, money chains, auto-replies and uploaded goods are deleted in the same way as when the subscription ends: 180 days after it ends they are marked as deleted, and 7 days later they are deleted permanently. If the account never had a subscription, the period runs from the date the account was deleted and is 30 days: after it the data is marked as deleted, and 7 days later it is deleted permanently.
When the subscription ends:
-
If any uploaded digital goods remained in the Service, the Service compiles a file containing them and sends it to the User through two channels: as an email attachment and as a document in Telegram. No copy of the file is kept in the Service — which is why it does not appear in the list of retention periods. If there were no such goods, no file is compiled. No file is compiled where the account is deleted or where access is terminated at the initiative of the Service Administration.
-
Marketplace access keys are deleted immediately; listings that use auto-delivery are taken off sale.
-
The catalog, settings, money chains, auto-replies and uploaded goods are retained for 180 days and become available again if the subscription is resumed. Once that period expires they are marked as deleted, and 7 days later they are erased irreversibly.
In both cases the following is retained indefinitely: the email address, records of financial transactions, the subscription history and the identifier of the User’s store on the Marketplace. The first three are needed for keeping account of settlements, and the last so that a trial period cannot be obtained again through a new registration. The account record itself is not removed from the database: without it these records would lose their link.
Changes to this Policy
The Service Administration may amend this Policy. The version in force is published at marketnet.pro/privacy; the revision date is shown at the top of the page.
The Service Administration gives notice of changes that materially affect the User’s rights — new processing purposes, new categories of data, new recipients — at least 10 days before they take effect: by email and by a message in the app. Continued use of the Service after that date constitutes acceptance of the new version.
Contacts
For questions about the processing of personal data, and to exercise the rights listed in section 11, use the contacts below:
See also Terms of use — they describe the service itself, the subscription and the refund procedure.