1. Introduction
Masterlinq Solutions LLC ("Masterlinq," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, website, and services (collectively, the "Services").
Our Services connect bicycle retailers ("Retailers"), product suppliers ("Suppliers"), and end consumers ("Customers"). This policy applies to all users of our platform, regardless of their role.
By using our Services, you consent to the data practices described in this policy. If you do not agree with our policies, please do not use our Services.
2. Information We Collect
We collect different types of information depending on your role and how you interact with our Services:
From Retailers:
- Business information: company name, address, tax ID, business licenses
- Account credentials: email address, password, user roles
- Payment information: bank account details for payouts, billing address
- Storefront data: branding assets, product selections, pricing configurations
- Transaction history: orders, fulfillment records, customer communications
From Suppliers:
- Business information: company name, address, tax ID, manufacturer details
- Account credentials: email address, password, API keys
- Product catalog: SKUs, descriptions, images, pricing, inventory levels
- Fulfillment data: shipping origins, carrier accounts, delivery records
- Financial information: payment terms, commission structures
From Customers:
- Contact information: name, email address, phone number
- Shipping information: delivery address, shipping preferences
- Payment information: credit card details (processed by Stripe)
- Order history: purchases, returns, communications with retailers
- Account preferences: saved addresses, wishlist items
Automatically Collected Information:
- Device information: IP address, browser type, operating system
- Usage data: pages visited, features used, time spent on platform
- Location data: general geographic location based on IP address
- Cookies and tracking technologies: see our Cookie Policy for details
3. How We Use Information
We use the information we collect for the following purposes:
- Provide and maintain our Services, including processing transactions and fulfilling orders
- Create and manage your account, including authentication and access control
- Process payments and facilitate payouts between parties
- Communicate with you about orders, updates, and support requests
- Improve our platform through analytics and user feedback
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations and enforce our terms
- Send marketing communications (with your consent where required)
- Personalize your experience and recommend relevant products
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process personal data based on the following legal grounds:
- Contract Performance: Processing necessary to fulfill our contractual obligations to you, such as processing orders and managing accounts
- Legitimate Interests: Processing necessary for our legitimate business interests, such as fraud prevention, security, and service improvement, where these interests are not overridden by your rights
- Legal Obligations: Processing necessary to comply with applicable laws and regulations
- Consent: Processing based on your explicit consent, such as for marketing communications or optional features
You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
5. Information Sharing
We share your information only as described in this policy:
With Platform Participants:
- Customer information is shared with Retailers to fulfill orders
- Order details are shared with Suppliers for fulfillment purposes
- Retailer storefront information is visible to Customers
With Service Providers:
- Stripe: payment processing and fraud prevention
- ShipEngine and BikeFlights: shipping and logistics
- Mailgun: transactional and marketing emails
- Cloud hosting providers: data storage and processing
- Analytics providers: platform usage analysis
For Legal Reasons:
- To comply with legal process or government requests
- To protect our rights, privacy, safety, or property
- To enforce our terms and agreements
- In connection with a merger, acquisition, or sale of assets
We do not sell your personal information to third parties.
6. International Data Transfers
Masterlinq is based in the United States. If you access our Services from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
For transfers from the EEA, UK, or Switzerland, we rely on:
- Standard Contractual Clauses approved by the European Commission
- Data processing agreements with appropriate safeguards
- Adequacy decisions where applicable
By using our Services, you acknowledge that your information may be transferred internationally as described in this policy.
7. Data Retention
We retain your personal information for as long as necessary to provide our Services and fulfill the purposes described in this policy, unless a longer retention period is required by law.
- Account data: retained while your account is active and for 3 years after closure
- Transaction records: retained for 7 years for tax and legal compliance
- Communication logs: retained for 2 years for support and dispute resolution
- Analytics data: retained in aggregated, anonymized form indefinitely
Upon account termination, you may request export of your data. See our Terms of Service for data export procedures.
8. Your Rights
Depending on your location, you may have certain rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information
- Portability: Request your data in a structured, machine-readable format
- Restriction: Request that we limit how we use your information
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent for optional processing activities
To exercise these rights, contact us at privacy@masterlinq.io. We will respond within 30 days (or as required by applicable law).
9. GDPR Rights
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):
- Right to be informed about how your data is collected and used
- Right to lodge a complaint with your local supervisory authority
- Right not to be subject to automated decision-making, including profiling
- Right to request information about safeguards for international transfers
Our EU representative for GDPR inquiries can be contacted at privacy@masterlinq.io.
10. CCPA Rights
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of personal information collected, used, and shared
- Right to Delete: Request deletion of your personal information
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt out of the sale or sharing of personal information
- Right to Non-Discrimination: Not be discriminated against for exercising your rights
- Right to Limit Use: Limit use of sensitive personal information
We do not sell personal information as defined by the CCPA. To exercise your rights, contact us at privacy@masterlinq.io or call our toll-free number at 1-800-XXX-XXXX.
You may designate an authorized agent to make requests on your behalf. We may require verification of your identity and authorization.
11. Security Measures
We implement appropriate technical and organizational measures to protect your personal information:
- Encryption: All data transmitted via TLS/SSL; sensitive data encrypted at rest
- Access Controls: Role-based access, multi-factor authentication, regular access reviews
- Infrastructure Security: SOC 2 compliant hosting, regular security audits, penetration testing
- Payment Security: PCI DSS Level 1 compliance through Stripe
- Incident Response: Documented procedures for security incident detection and response
- Employee Training: Regular security awareness training for all staff
While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but commit to promptly notifying affected users of any breach as required by law.
12. Children's Privacy
Our Services are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@masterlinq.io.
If we discover that we have collected personal information from a child under 16 without parental consent, we will take steps to delete that information promptly.
13. Cookies and Tracking
We use cookies and similar tracking technologies to collect and store information about your interactions with our Services. For detailed information about the types of cookies we use and how to manage them, please see our Cookie Policy.
You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of our Services.
14. Changes and Contact
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Last Updated" date. For significant changes, we may also notify you via email or through the platform.
Your continued use of our Services after changes become effective constitutes acceptance of the revised policy.
Contact Us:
If you have questions about this Privacy Policy or our data practices, please contact us:
- Email: privacy@masterlinq.io
- Mail: Masterlinq Solutions LLC, Attn: Privacy Team, [Address]
- Phone: 1-800-XXX-XXXX
For general legal inquiries, contact support@masterlinq.io.