Gavelist ("we," "us," or "our") operates the gavelist.com website and the Gavelist auction cataloging platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
1. Information We Collect
Account Information
When you create an account, we collect the information you provide through our authentication provider, including your name, email address, and profile picture. Account authentication is managed by Clerk, a third-party identity provider.
Photos and Catalog Data
When you use the Service, you upload photos of items to be cataloged. We store these photos and the AI-generated descriptions, lot assignments, and export data you create. This is the core data you entrust to us, and we treat it with the highest level of care.
Payment Information
Payment processing is handled entirely by Stripe. We do not store your credit card number, bank account details, or other sensitive financial information on our servers. We receive only a confirmation of payment status and your Stripe customer ID.
Usage Data
We automatically collect certain information when you access the Service, including your IP address, browser type, operating system, referring URLs, pages visited, and timestamps. We use Google Analytics and Meta Pixel for aggregated website analytics and advertising measurement.
Cookies and Tracking
We use cookies and similar technologies for authentication session management, analytics, and advertising measurement. Essential cookies are required for the Service to function. Analytics and advertising cookies help us understand usage patterns and measure the effectiveness of our marketing.
2. How We Use Your Information
We use the information we collect to:
- Provide the Service — process your photos through AI models to generate auction catalog descriptions, store your lots and exports, and deliver the cataloging functionality you signed up for.
- Process payments — manage your subscription, track usage-based billing, and handle invoicing through Stripe.
- Improve our AI — analyze aggregated, de-identified usage patterns to improve the quality of our AI-generated descriptions. We do not use your individual photos to train AI models without your explicit consent.
- Communicate with you — send service-related emails such as account confirmations, billing receipts, and important product updates.
- Maintain security — detect and prevent fraud, abuse, and security incidents.
- Analyze usage — understand how people use the Service so we can improve it.
3. How We Store Your Data
Your photos and catalog data are stored using cloud storage services provided by Cloudflare (R2 object storage) and Google Cloud Storage. These providers maintain industry-standard security certifications and encryption practices. All data is encrypted in transit (TLS) and at rest.
Our application infrastructure, including the database that stores your account information, lot data, and AI-generated descriptions, is hosted on secure servers in data centers with physical and network security controls.
4. Third-Party Services
We share data with the following third-party services, each of which has its own privacy policy:
- Clerk — authentication and user management. Clerk receives your email, name, and login credentials. Clerk Privacy Policy
- Stripe — payment processing and subscription management. Stripe receives your payment method and billing details. Stripe Privacy Policy
- Google Cloud / Gemini AI — your photos are sent to Google's Gemini AI models for description generation. Photos are processed per Google's API terms and are not used to train Google's models. Google Cloud Privacy Notice
- Cloudflare — photo storage (R2) and content delivery. Cloudflare stores your uploaded photos. Cloudflare Privacy Policy
- Google Analytics — website usage analytics. Collects anonymized browsing data. Google Privacy Policy
We do not sell your personal information to any third party. We share data with these providers only as necessary to operate the Service.
5. Data Retention
We retain your account information and catalog data for as long as your account is active. If you delete your account, we will delete your personal information and photos within 30 days, except where we are required to retain data for legal or compliance reasons.
Aggregated, de-identified analytics data may be retained indefinitely as it cannot be linked back to you.
6. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — request that we correct inaccurate or incomplete data.
- Deletion — request that we delete your personal data and photos.
- Export — request a machine-readable export of your data.
- Opt out — opt out of analytics cookies and marketing communications at any time.
To exercise any of these rights, contact us at support@gavelist.com. We will respond within 30 days.
7. Children's Privacy
The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
8. Security
We implement industry-standard security measures to protect your data, including encryption in transit and at rest, secure authentication, rate limiting, and regular security reviews. However, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security, but we take reasonable steps to protect your information.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by posting a notice on the Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
10. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, contact us at:
Gavelist
Pittsburgh, PA
support@gavelist.com