Privacy Statement
To run our business and provide you with the Services we need to process your personal data. By accepting our Terms of Use, you are confirming that you have read this policy and consent to us using your information in the ways we describe. If you don’t want us to collect or process your personal information in the ways described in this policy, you shouldn’t use the Services. We are not responsible for the content or the privacy policies of any of our members, websites hosted through GPBox, third-party websites, or third-party apps.
GPBox’s Terms of Use require all account owners or account managers to be at least 18 years of age. Those under 18 years of age and at least 13 years of age are permitted to use accounts only if the accounts are managed by someone over 18.
By using the Services, you authorise GPBox to use your information in the United Kingdom and any other country where GPBox operates. Please be aware that the privacy laws and standards in certain countries, including the rights of authorities to access your personal information, may differ from those that apply in the country in which you reside. We will transfer personal data only to these countries to which we are permitted by law to transfer personal information, and we will take steps to ensure that your personal information continues to enjoy appropriate protections.
1. Accepting the Privacy Policy
To run our business we need to process your personal information. By accepting our Terms of Use you are confirming that you have read and understand this policy including how and why we use your information. If you don’t want us to collect or process your personal information in the ways described in this policy, you shouldn’t use the Services. We are not responsible for the content or the privacy policies or practices of any of our members.
We require all account owners to be at least 18 years of age. Minors between 18 years of age and 13 years of age are permitted to use GPBox services only with the correct permission and under direct supervision of the account owner. Children under age 13 are not permitted to use GPBox or any of our services. You will be held responsible for any and all account activity conducted by a minor on your account.
By using the Services, you acknowledge that GPBox will use your information in the United Kingdom and any other country where GPBox operates. Please be aware that the privacy laws and standards in certain countries, including the rights of authorities to access your personal information, may differ from those that apply in the country in which you reside. We will transfer personal information only to these countries to which we are permitted by law to transfer personal information, and we will take steps to ensure that your personal information continues to enjoy appropriate protections.
2. Information Collected or Received
Whilst providing our Services we need to collect or receive your personal information in a few different ways. Often, you choose what information to provide, but sometimes we require certain information for you to use and for us to provide you the Services.
Registration, Account Setup, Service Usage: In order to use GPBox, you need to provide us with a valid email address, and for Services that require registration, a name associated with your account that you can choose and that represents your identity on GPBox. You may review, change, or remove that name through your account settings. You will also need to provide us with a user name, this can not be updated but can be deleted. This information is required in order to us our services. Depending on which services you choose to use, additional information, such as a shop name, billing and payment information (including billing contact name, address, telephone number, credit card information), a telephone number, and/or a physical postal address, may be necessary in order for us to provide a particular service. You are not required to provide us with this information to sign up, but we will need it to provide certain services. For example, we need a physical postal address if you are buying something on the Site for delivery. We may need to store credit card information (or arrange for it to be stored) and use it for both billing and payment purposes. Depending on your local jurisdiction, you can also choose to allow us to save your credit card information to facilitate the checkout process for future purchases. GPBox may contact individual shop owners confidentially to request more information about their shops or items listed through the Services, or to ensure compliance with our rules and applicable law.
Profile: You may provide your name and other personal information (such as birthday, gender, location) in connection with your account and activity. You can edit or remove this information through your account settings.
The name associated with your account, which you may review and change in your account settings, is publicly displayed and connected to your GPBox activity. Other people may see the date you joined; ratings, reviews and related photos for items you purchased or sold; your profile information; items you listed for sale; your shop pages and policies; your Favourites, followers, and those you follow; sold item listings and the number of items sold; comments you post in our community spaces; and information you decide to share via social networks.
Automated Information: GPBox automatically receives and records information from your browser or your mobile device when you visit the Site, such as your IP address or unique device identifier, cookies and data about which pages you visit in order to allow us to operate and provide the Services. This information is stored in log files and is collected automatically. We may combine this information from your browser or your mobile device with other information that we or our partners collect about you, including across devices. This information is used to prevent fraud and to keep the Services secure, to analyse and understand how the Services work for members and visitors.
Location Information: We may collect information about your use of the Services for advertising, analytics, to serve content and to protect the Services, including your IP address, browser information (including referrers), device information (such as iOS IDFA, IDFV for limited non-advertising purposes, Android AAID, and, when enabled by you, location information provided by your device). You may choose to publish your location when you sell on GPBox.
We may obtain location information you provide in your profile or your IP address. Certain non-precise location services, such as for security and localised policies based on your IP address or submitted address, are critical for the site to function. We will only share your geo-location details with third parties (like our mapping, payments, or, to the extent applicable, advertising providers) in order to provide you with the Services.
Analytics Information: We use data analytics to ensure site functionality and improve the Services. We use mobile analytics software to allow us to understand the functionality of the Apps on your phone. This software may record information such as how often you use the Apps, what happens within the Apps, aggregated usage, performance data, app errors and debugging information, and where the Apps were downloaded from. We do not link the information we store within the analytics software to any personally identifiable information that you submit within the mobile application.
Information from Third Parties: Some members or visitors may choose to connect to GPBox or register a GPBox account using an external third-party application, such as Facebook, Instagram or Google. GPBox may receive information from those connected third-party applications. Connecting your GPBox account to third-party applications or services is optional. If you choose to connect your account to a third-party application, GPBox may receive information from that application. We may also collect public information in order to connect with you. We may use that information as part of providing the Services to you. You can also choose to share your activity on GPBox on certain social media networks which are connected to your GPBox account, and you can revoke your permission anytime in your account settings.
Non-Member Information: GPBox may receive or obtain information (for example, an email address or IP address) about a person who is not yet a registered GPBox member (a “Guest”) in connection with certain features, such as when a guest chooses to subscribe to our newsletter, a member invites a non-member to visit the Site, a member uploads non-member information using the contact uploader feature, a non-member engages in a transaction, or a member sends a gift card code to a non-member, or a non-member uses the Guest Checkout feature when making a purchase through one of the Services. Non-member information is used only for the purposes disclosed when it was submitted to GPBox or to facilitate action authorised by the non-member.
3. Choice & Control
We are aware that it is now compulsory for our members to have control over their own information, GPBox has provided the functionalities for you to be able to edit and/or remove certain information, as well as choices about how we contact you. You may change or correct your GPBox account information through your account settings. You may also remove certain optional information that you no longer wish to be publicly visible through the Services, such as your name. You can also request the deletion of the personal information in your account.
Depending on your location, you may also have certain additional rights with respect to your information, such as: (i) data access and portability (including the right to obtain a copy of your personal data you provided to GPBox, via your settings); (ii) data correction (including the ability to update your personal data, in many cases via settings); (iii) data deletion (including the right to instruct GPBox to delete your personal information, except information we are required to retain, by contacting us); and (iv) withdrawal of consent or objection to processing (including, in limited circumstances, the right to ask GPBox to stop processing your personal data, with some exceptions, by contacting us).
We use non-technically necessary cookies and similar technologies. A more detailed explanation of the technologies we use, and how to opt out when applicable, can be found in GPBox's Cookie Policy.
You may also control the receipt of certain types of communications from GPBox in your account settings. GPBox may send you messages about the Services or your activity. Some of these messages are required, service-related messages for members (such as transactional messages or legal notices). Other messages are not required, such as newsletters. You can control which optional messages you choose to receive by changing your account settings.
We partner with third parties to manage our advertising on other sites. Our third-party partners may use cookies or similar technologies in order to provide you with advertising based upon your browsing activities and interests. If you have chosen to connect your account to an external third-party application, such as Facebook, or an app developed using the API, you can change your settings and remove permission for the app by changing your account settings.
If you no longer wish to use the Services or receive service-related messages (except for legally required notices), then you may close your account.
4. Messages from GPBox
GPBox likes to keep in contact with you. Primarily, these messages are delivered by email or by push notifications, and every account is required to keep a valid email address on file to receive messages. Occasionally GPBox may also contact you by telephone to provide member support or for transaction-related purposes if you request that we call you. Additionally, and with your consent, GPBox may send you an SMS (or similar) message or physical mail in order to provide you with customer support or to provide you with information about products and features that you may find of interest. You may update your contact preferences in your account settings.
Some messages from GPBox are service-related and necessary for members and Guest Checkout users. You agree that GPBox can send you non-marketing emails or messages, such as those related to transactions, your account, security, or product changes. Examples of service-related messages include an email address confirmation/welcome email when you register your account, notification of an order, service availability, modification of key features or functions, relaying conversations with buyers, and correspondence with the GPBox support team.
When you register for an account, subscribe to a newsletter, or provide us with your email address or phone number such as for a Guest Checkout purchase, you receive notice of and agree (in some jurisdictions and situations, by an additional unambiguous consent) to receive marketing emails and messages from us. You can unsubscribe at any time from marketing emails through the opt-out link included in marketing emails or messages. Members may also control some marketing emails or messages through their account settings as well as through the opt-out link included in marketing emails or messages.
5. Community
GPBox is both a marketplace and a community. We offer several features that allow members to connect and communicate in public or semi-public spaces, such as Forums and Groups. You don’t have to use these features, but if you do, please use common sense and good judgment when posting in these community spaces or sharing your personal information with others through the Services. Be aware that any personal information that you choose to submit there can be read, collected, or used by others, or could be used to send unsolicited messages to you. We may engage certain third parties to assist in providing community services to you and, in the context of that relationship, we need to share some of your information with such third parties in order to provide that service. As a rule, GPBox generally does not remove content from community spaces, and your posts may remain public after your account is closed, although your name will no longer be displayed alongside the post. You are responsible for the personal information that you choose to post in community spaces through the Services.
6. Information Uses, Sharing & Disclosure
When you access or use the Services, we collect, use, share, and otherwise process your personal information as described in this policy. We rely on a number of legal bases to use your information in these ways. These legal bases include where:
- necessary to perform the contractual obligations in our Terms of Use and in order to provide the Services to you;
- you have consented to the processing, which you can revoke at any time;
- necessary to comply with a legal obligation, a court order, or to exercise or defend legal claims;
- necessary for the purposes of our or a third party’s legitimate interests, such as those of visitors, members, or partners;
- you have expressly made the information public;
- necessary in the public interest; and
- occasionally necessary to protect your vital interests, or those of others.
Note that we principally rely on consent (i) to send marketing messages, (ii) for third-party data sharing related to advertising, and, to the extent applicable, (iii) for the use of location data for advertising purposes.
Where we process your information on the basis of legitimate interests, we do so as follows:
Providing and improving our Services: We may use your information to improve and customise our Services, including sharing of your information for such purposes, and we do so as it is necessary to pursue our legitimate interests of improving our Services for our users. This is also necessary to enable us to pursue our legitimate interests in understanding how our Services are being used, and to explore and unlock ways to develop and grow our business. It is also necessary to allow us to pursue our legitimate interests in improving our Services, efficiency, interest in Services for users and obtaining insights into usage patterns of our Services.
Keeping our Services safe and secure: We may also use your information for safety and security purposes, including sharing of your information for such purposes, and we do so because it is necessary to pursue our legitimate interests in ensuring the security of our Services, including enhancing protection of our community against spam, harassment, intellectual property infringement, crime, and security risks of all kind.
We use your data as stated above but we respect your privacy and will not disclose your name, email address or other personal information to third parties without your consent, except as specified in this policy.
We use your information to provide and improve the Services and our products, for billing and payments, for identification and authentication, for targeted online and offline marketing including tools like Facebook Custom Audience and Google Customer Match, to contact members or interested parties, and for general research and aggregate reporting. We may learn the sorts of products that you’re interested in from your browsing and purchasing behaviour on (and off) the Site and suggest potential purchases as a result. As a core part of our Services, we have a legitimate interest in customising your on-site experience to help you discover relevant items and recommended purchases. Similarly, we or our sellers may advertise our Services or our sellers’ products through a variety of different mediums and rely on your consent to do so off-site. As part of this, we may work with advertising partners such as Facebook or Google.
Buying and Selling: To facilitate the buying and selling process we need to allow the sharing of information between the two members involved in the transaction. This information will in include member’s shipping address and payment information. By making a sale or a purchase through GPBox you are directing us to share your information in this way. Since this is an important part of the Services we provide, we need to do this in order to perform our obligations under our Terms of Use. We expect you to respect the privacy of the member whose information you have received. GPBox has not granted a license to you to use the information for unsolicited commercial messages or unauthorised transactions. Without express consent from that person, you must not add any member to your email or physical mailing list or otherwise use or store any member’s personal information.
Legal and Safety: GPBox may also keep, store, or release your personal information to a third party in the following limited circumstances: in response to lawful requests by public authorities, including to meet legitimate national security or law enforcement requirements; to protect, establish, or exercise our legal rights or defend against legal claims, including to collect a debt; to comply with a court order, legal process, or other legal requirement; or when we believe in good faith that such disclosure is reasonably necessary to comply with the law, prevent imminent physical harm or financial loss, or investigate, prevent, or take action regarding illegal activities, suspected fraud, threats to our property, or violations of GPBox Terms of Use. In these cases, our use of your information may be necessary for the purposes of our or a third party’s legitimate interest in keeping our Services secure, preventing harm or crime, enforcing or defending legal rights, or preventing damage. Such use may also be necessary to comply with a legal obligation, a court order, or to exercise or defend legal claims. It may also be necessary in the public interest (such as to prevent crime) or to protect vital interests (in rare cases where we may need to share information to prevent loss of life or personal injury).
Should GPBox receive a lawful, verified request for a member’s records or information in one of the limited circumstances described in the previous paragraph, GPBox may disclose personal information, which may include, but may not be limited to, a member’s name, address, phone number, email address, and company name.
Affiliated Businesses: GPBox works closely for a number of different purposes, including assisting us to perform and improve the Services. These businesses may sell items or services to you through the GPBox or, with your consent, offer promotions (including email promotions) to you. When an affiliated business assists in facilitating your transaction, we may need to share information related to the transaction with that affiliated business in order to facilitate your transaction, and this forms part of the Services we provide in accordance with our Terms of Use. We rely on consent (which can be withdrawn at any time) to send marketing messages and for third-party sharing relating to advertising.
Aggregated Information: GPBox may share demographic information with business partners, but it will be aggregated and de-personalised, so that personal information is not revealed.
Service Providers: It is essential for GPBox to engage with third-party companies and individuals (such as payment processors, research companies, and analytics and security providers) to help us operate, provide, and market the Services. These third parties only have limited access to your information, may use your information only to perform these tasks on our behalf, and are obligated to GPBox not to disclose or use your information for other purposes. Our engagement of service providers is often necessary for us to provide the Services to you, particularly where such companies play important roles like processing payments and shipments and helping us keep our Service operating and secure. In some other cases, these service providers aren’t strictly necessary for us to provide the Services, but help us make it better, like by helping us conduct research into how we could better serve our users. In these latter cases, we have a legitimate interest in working with service providers to make our Services better.
Business Reorganisation: In the event of a sale, merger, liquidation, receivership or transfer of assets member information is typically one of the business assets that is transferred. If GPBox intends to transfer information about you we will notify you by email or by putting a prominent notice on the Site, and you will be afforded an opportunity to opt out before information about you becomes subject to a different privacy policy.
Third Parties: Third-party plug-ins also may collect information about your use of the Site. These interactions are subject to the privacy policy of the third-party site. In addition, certain cookies and other similar technologies on the Site are used by third parties for targeted online marketing and other purposes. These technologies allow a partner to recognise your computer or mobile device each time you use the Services. Please be aware that when you use third-party sites or services, their own terms and privacy policies will govern your use of those sites or services.
We can speak only for ourselves; this policy does not apply to the practices of third parties that GPBox does not own or control or individuals that GPBox does not employ or manage. If you provide your information to others, different practices may apply to the use or disclosure of the information that you provide to them. GPBox does not control the privacy policies of third parties, including other members who sell using the Services. GPBox is not responsible for the privacy or security practices of these sellers, API users, or other websites on the Internet, even those linked to or from the Services. We encourage you to read the privacy policies and ask questions of third parties before you disclose your personal information to them. For the purposes of European law, these sellers and API users are independent controllers of data, which means that they are responsible for providing and complying with their own policies relating to any personal information they obtain in connection with the Services.
7. Data Transfers
Model Clauses
The European Commission has adopted standard contractual clauses (also known as Model Clauses), which provide safeguards for personal information that is transferred outside of Europe. We often use these Model Clauses when transferring personal information outside of Europe.
Contract between GPBox and our members.
We provide a voluntary service; you can choose whether or not you want to use the Services. However, if you want to use the Services, you need to agree to our Terms of Use, which set out the contract between GPBox and its members. As we operate in countries worldwide (including in the US) and use technical infrastructure in the UK to deliver the Services to you, in accordance with the contract between us, we need to transfer your personal information to the UK and to other jurisdictions as necessary to provide the Services. Simply put, we can’t provide you with the Services and perform our contract with you without moving your personal information around the world.
8. Security
We follow generally accepted standards to protect the personal information submitted to us, both during transmission and after it is received. Your account information is protected by a password. It is important that you protect against unauthorised access to your account and information by choosing your password carefully and by keeping your password and computer secure, such as by signing out after using the Services. Unfortunately, no method of transmission over the internet or method of electronic storage is 100% secure. Therefore, while we strive to protect your personal information, we can’t guarantee its absolute security.
9. Retention
We will keep your information only for as long as is necessary for the purposes set out in this policy. As long as your account is active, as described in this policy, or as needed to provide the Services to you we will retain this data. If you no longer want GPBox to use your information to provide the Services to you, you should close your account. GPBox will retain and use your information to the extent necessary to comply with our legal obligations (for example, if we are required to retain your information to comply with applicable tax/revenue laws), resolve disputes, enforce our agreements, and as otherwise described in this policy. In addition, GPBox sellers may also be required to retain and use your information in order to comply with their legal obligations. Please note that closing your account may not free up your email address, username, or shop name (if any) for reuse on a new account. We also retain log files for internal analysis purposes. These log files are generally retained for a brief period of time, except in cases where they are used for site safety and security, to improve site functionality, or we are legally obligated to retain them for longer time periods.
10. Your Rights
If you would like to manage, change, limit, or delete your personal information, you can do so via your GPBox account settings or by contacting us. You can receive a copy of all the persona data held by GPBox through the ´Download my data´ button in your account settings. By visiting your account settings, you can access, correct, change, and delete certain personal information associated with your account. In certain cases where we process your information, you may also have a right to restrict or limit the ways in which we use your personal information. In certain circumstances, you also have the right to request the deletion of your personal information, and to obtain a copy of your personal information in an easily accessible format.
If we process your information based on our legitimate interests as explained above, or in the public interest, you can object to this processing in certain circumstances. In such cases, we will cease processing your information unless we have compelling legitimate grounds to continue processing or where it is needed for legal reasons. Where we use your data for direct marketing purposes, you can always object using the unsubscribe link in such communications or changing your account settings.
11. Your Responsibilities
If you sell using our Services you may receive personal information, such as when communicating with users and entering into transactions with buyers. This means you process personal information (for example, buyer name, email address, and shipping address) and, to the extent you do so, under EU law, you are an independent controller of data relating to other users that you may have obtained through the Services.
You are responsible for protecting user personal information you receive or process and complying with all relevant legal requirements when you use the Services. This includes applicable data protection and privacy laws that govern the ways in which you can use a user’s information. Such laws may require that you post, and comply with, your own privacy policy, which must be accessible to GPBox users you interact with and compatible with this policy and our Terms of Use. For more information on the General Data Protection Regulation, see more resources at https://gdpr-info.eu and https://gdprandyou.ie.
As a data controller, to the extent that you process user personal information outside of the Services, you may be required under applicable data protection and privacy laws to honour requests for data access, portability, correction, deletion, and objections to processing. For example, you may receive a buyer’s email address or other information as a result of entering into a transaction with that buyer. This information may only be used for GPBox communications or for GPBox facilitated transactions. You may not use this information for unsolicited commercial messages or unauthorised transactions. Without the buyer’s consent, and subject to other applicable GPBox policies and laws, you may not add any GPBox member to your email or physical mailing list, use that buyer’s identity for marketing, or obtain or retain any payment information. Please bear in mind that you’re responsible for knowing the standard of consent required in any given instance.
If GPBox and you are found to be joint data controllers of personal information, and if GPBox is sued, fined, or otherwise incurs expenses because of something that you did as a joint data controller of buyer personal information, you agree to indemnify GPBox for the expenses it occurs in connection with your processing of buyer personal information.
12. Withdrawing Consent
Where you have provided your consent, you have the right to withdraw your consent to our processing of your information and your use of the Services. For example, you can withdraw your consent to email marketing by using the unsubscribe link in such communications or by changing your account settings. You can choose to withdraw your consent to our processing of your information and your use of the Services at any time by closing your account through your account settings and then contacting us to request that your personal information be deleted, except for the information that we are required to retain. This deletion is permanent and your account cannot be reinstated.
13. Privacy Policy Changes
We may amend or update this policy from time to time. If we believe that the changes are material, we’ll let you know by doing one (or more) of the following: (i) posting the changes on or through the Services, (ii) sending you an email or message about the changes. We encourage you to check back regularly and review any updates.