What this notice covers
This notice covers the AssetDelta marketplace: what we collect, where it goes, who sees it, and how long it stays.
AssetDelta is operated by magpiexyz, which is the controller of the personal data described here. Most of what we hold is business information — company numbers, trading addresses, equipment serials, prices. Some of it is personal data about the people running those businesses. And some of it, specifically the service invoices you upload, is more revealing than it first looks.
Clause 03 is the part most people have not thought about. If you read one section of this notice, read that one.
What we collect
Seven categories. This is the complete list.
- Account
- Name, email address, password (stored hashed — we never see it), and whether you signed up to sell or to buy.
- Business
- Company number, registered and trading name, VAT number, trading address, collection postcode, phone number, and your Stripe account identifier.
- Photographs
- The eight required angles for each unit, including the nameplate photograph — which carries the serial number.
- Documents
- Service invoices, maintenance dockets, Gas Safe and F-Gas certificates. These typically name your maintenance contractor, the engineer who attended, your site address, the dates they were on site, and what you paid.
- Listing and trade
- Prices, declared faults, access notes, offers, orders, and the messages between you and a counterparty.
- Payment
- Amounts, commission and Stripe identifiers. Not card numbers — those go straight to Stripe and never reach us.
- Technical
- Pages viewed, product events, approximate location from your IP address, browser and device, and any gclid or utm_ values on the link you arrived on.
We do not ask for anything outside this list, and we do not buy data about you from anyone else.
Your uploads are processed by an AI provider
The photographs and documents you upload leave this platform in order to be read.
There is no version of the condition report that happens entirely on our own servers. Reading a stamped nameplate, extracting text from a scanned invoice and scoring a photograph are all done by a third-party model, and we would rather tell you that in the body of this notice than in a sub-clause.
One technical note, because it changes where a file has been: photographs taken on an iPhone arrive as HEIC, and the Gemini API rejects that format. Those files are converted to JPEG on our servers before they are sent. Nothing else is done to them.
Where files are stored, and who sees them
Photographs on a live listing are public. Your invoices never are.
Files are held in Supabase storage with row-level access control, in the region configured for the Supabase project. Access is enforced at the database, not in the browser.
- Listing photographs
- Public once the listing is live. That is their purpose — they are the evidence in the listing.
- Service invoices
- Never public. Visible to you, and to a buyer only once funds are held on an order for that unit.
- Condition report
- Public once the listing is live. The documents behind it are not.
- Messages
- Visible to the two parties in the thread, and to nobody else.
Contact details, and when they are revealed
Contact details are masked until funds are held on an order, then revealed to both sides.
Until then, phone numbers, email addresses and off-platform links in messages are masked, and you can see that the mask is there. On funds held, each party receives the other’s name, business name, phone number and the collection address — because a unit has to be collected from a real building at a real time, by someone with a van.
This is one-way. Once your address has been given to a buyer it cannot be un-given. If you do not want that to happen for a particular unit, do not accept an offer on it.
Analytics
We measure whether the product works, not who you are.
Product analytics run through PostHog. The question they answer is narrow: does a seller who starts a listing actually finish all eight photograph angles and get a report? Events are recorded against a pseudonymous identifier, and against your account once you sign in.
We do not sell this data, we do not build advertising profiles from it, and we do not share it with ad networks. Analytics requests are proxied through this site’s own domain so that an ad blocker does not silently break the measurement — the destination is still PostHog either way.
If you arrived from a paid advertisement, the gclid and utm_ values on that link are kept in your browser’s session storage so the click can be attributed to the visit. They are cleared when you close the tab.
Payments
Stripe processes payments, escrow and payouts.
Card details are entered on Stripe’s side and never touch our servers. For sellers, Stripe runs its own identity and bank verification and acts as its own controller for that — under its agreement with you, not under this notice.
What we hold is the transaction shape: amounts, commission, order status, and the Stripe identifiers needed to hold funds and release them.
Transactional email only, sent through Resend.
- Sign-in and password reset.
- Offer received, offer accepted.
- Funds held, to both buyer and seller.
- Collection scheduled.
- Funds released, and payout sent.
- Anything raised as a dispute.
We do not send marketing email unless you have asked for it, and you can stop it from settings at any time. Transactional email about a live order cannot be switched off while that order is open.
Legal bases
Under UK GDPR, this is why each thing is lawful.
Purpose to legal basis
| Running your account | Contract |
|---|---|
| Generating the report | Contract |
| Revealing contact on funds held | Contract |
| Masking contact, fraud checks | Legitimate interests |
| Product analytics | Legitimate interests |
| Transaction and tax records | Legal obligation |
| Marketing email | Consent |
Where we rely on legitimate interests, the interest is keeping the marketplace honest and knowing whether the product works. You can object — see clause 12.
How long we keep things
Six years on anything that forms part of a completed transaction.
Retention periods
| Account and business | Account life, then 6 years |
|---|---|
| Live listing photographs | Until the listing is removed |
| Service invoices | 6 years from the sale |
| Report snapshot on an order | 6 years |
| Messages | 2 years |
| Analytics events | 24 months |
| Session attribution | Until the tab closes |
Six years is not arbitrary: it is the accounting retention period, and it is how long the evidence needs to survive if a dispute over a sale is raised later. Drafts that never became a listing are deleted with the draft.
Your rights
You can ask for a copy, a correction, a deletion, a portable export, or that we stop.
Ask through help. We will respond within one month. You do not have to give a reason, and asking will not affect your listings or your account standing.
Two limits, stated honestly rather than buried:
- We cannot delete the record of a completed transaction while an accounting or legal obligation still applies to it — see clause 11.
- We cannot retract a file that has already been processed by a third-party provider under clause 03. We can only delete our copy of it.
If you think we have handled your data badly you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you told us first, but that route is yours regardless.
Who else processes your data
Seven sub-processors. Naming them is the point.
- Supabase
- Database, file storage and sign-in.
- Google (Gemini)
- Reads your uploaded photographs and documents to generate the condition report — clause 03.
- Stripe
- Payments, escrow and payouts.
- PostHog
- Product analytics.
- Resend
- Transactional email.
- Vercel
- Hosting and request logs.
- fal
- Generates the illustrative equipment imagery used in the demo catalogue. Nothing you upload is ever sent here.
Changes to this notice
The version and issue date are at the top of this document.
If we add a sub-processor, or change what is sent to one, the version changes and the change is stated. Material changes are notified by email before they take effect. We do not quietly widen what leaves the platform.
Status of this document
Plain English: this is an MVP experiment, and this notice has not been reviewed by a data protection lawyer.
It describes what the software actually does today, which is the most useful thing it can do. It is not a finished legal instrument and it is not a substitute for the operator’s own review.
- If you operate this
- Clause 03 is the one that needs work before real invoices are uploaded: a data processing agreement with the AI provider, a transfer assessment, and in all likelihood a DPIA. Do that first.
- If you use this
- Clause 03 is also the one to read. Your maintenance records leave the platform to be processed, and you are entitled to decide whether that is acceptable before you upload them.
- If something is unclear
- Ask through help before you upload, rather than after.
Saying this plainly costs us nothing we were entitled to keep. It is the same reason every listing on this site publishes what its report could not see.