Privacy Policy

Last updated: 15 May 2026

This Privacy Policy explains how ZAPTOS LTD(“we”, “us”, “Flips Flap”) collects, uses, and protects personal data when you use the Flips Flap website and platform (the “Service”). It is written to comply with the EU General Data Protection Regulation (GDPR) and the UK GDPR.

1. Data controller

ZAPTOS LTD, 5th Floor, 167–169 Great Portland Street, London W1W 5PF, United Kingdom. Companies House #12201879. Contact: info@artikunocommerce.com.

2. Data we collect

  • Account data — email address, username, password hash. Created when you sign up.
  • Profile data — optional avatar image and short bio that you choose to publish.
  • Activity data — flips (listings) you post, flaps (bids) you place, Sandal Points balance, transactions, voucher files you upload, messages you write to other users.
  • Technical data — IP address, browser type, session cookies needed to keep you logged in. Collected automatically by our authentication provider.

3. Legal basis and purposes

  • Contract performance (Art. 6(1)(b) GDPR) — to provide the Service: account creation, hosting your listings, processing bids, transferring Sandal Points.
  • Legitimate interest (Art. 6(1)(f) GDPR) — to keep the platform secure, prevent abuse, and improve the Service.
  • Legal obligation (Art. 6(1)(c) GDPR) — to respond to lawful requests from competent authorities and to fulfil record-keeping duties.

4. Who we share data with

We do not sell your data. We share the minimum necessary with the following processors:

  • Supabase Inc. — database, authentication, and file storage. Servers located in Frankfurt, Germany (EU). Data Processing Agreement in place.
  • Vercel Inc. — website hosting and content delivery, where the Service is deployed.

Public profile information (username, avatar, listings, bids you post) is visible to other users by design.

5. Vouchers and uploaded files

When a host accepts a winning bid, the host's uploaded voucher file is revealed to the winning bidder only. Vouchers can contain sensitive content (codes, tickets, contact info) — do not upload anything you would not want shared with the eventual winner. We do not access voucher files except for security or abuse investigations.

6. Retention

We keep account and activity data for as long as your account exists. If you delete your account, we erase your profile and listings within 30 days, except where retention is required by law (e.g. financial or audit records) or where data is anonymised for aggregate analytics.

7. Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you (Art. 15)
  • Have inaccurate data corrected (Art. 16)
  • Have your data deleted (Art. 17), subject to legal retention duties
  • Restrict processing (Art. 18) or object to it (Art. 21)
  • Receive your data in a portable format (Art. 20)
  • Lodge a complaint with a supervisory authority — in Austria, the Datenschutzbehörde (dsb.gv.at); in the UK, the ICO (ico.org.uk).

To exercise any of these rights, email info@artikunocommerce.com.

8. Cookies

We use strictly necessary cookies for authentication (keeping you logged in). We do not use advertising or third-party tracking cookies. No consent banner is therefore required beyond the standard browser controls.

9. International transfers

Our primary data location is the EU (Frankfurt). If data is transferred outside the EEA or UK in the future — for example to support services in the United States — we will rely on Standard Contractual Clauses or equivalent safeguards under Art. 46 GDPR.

10. Changes to this policy

We may update this Privacy Policy. The current version is always at this URL, dated at the top. Material changes will be announced in-app to logged-in users.