Privacy Policy

1. Introduction


Welcome to STUBAY. STUBAY (PVT) LTD ("we," "us," "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, share, and protect your Personal Data when you use our platform, https://www.stubay.shop (the "Platform").

This policy has been developed in accordance with the Personal Data Protection Act, No. 9 of 2022 of Sri Lanka. By using our Platform, you consent to the data practices described in this policy.


2. What Information We Collect


We collect Personal Data to provide and improve our services. The types of data we collect are:

2.1. Information You Provide Directly:

  1. Account Registration Data: When you create an account, we collect your name, email address, phone number, and password.
  2. Vendor-Specific Data: To register as a Vendor, we require additional verification information, which may include your university name, student registration number, and a copy of your student identification card or other proof of student status.
  3. Profile Information: Information you choose to add to your public profile, such as a profile picture, store name, and bio.
  4. Product Listing Data: Information you provide when listing a product, including descriptions, photos, and pricing.
  5. Transaction Data: When you make a purchase or sale, we collect information necessary to process the transaction, such as your shipping address and contact details. Note: We do not directly store your full credit/debit card information; this is handled by our secure third-party payment processors.
  6. Communications: Any information you send to us directly (e.g., support requests) or communications between you and other users through the Platform's messaging system.

2.2. Information We Collect Automatically:

  1. Usage Data: Information about how you interact with our Platform, such as pages viewed, products searched, time spent on the Platform, and features used.
  2. Device and Log Data: Information about your device, including your IP address, browser type, operating system, and device identifiers.
  3. Location Data: We may collect your approximate location based on your IP address to personalize your experience.

2.3. Information from Third Parties:

  1. We may receive information from our third-party service providers, such as payment processors (transaction confirmation) and analytics providers (aggregated usage data).


3. How We Use Your Information


We use your Personal Data for the following purposes, based on a lawful basis for processing:

  1. To Provide and Manage Our Services (Contractual Necessity):
  2. To create and maintain your account.
  3. To verify Vendor eligibility (student status).
  4. To facilitate transactions, including processing payments and coordinating delivery between Buyers and Vendors.
  5. To enable communication between users.
  6. To Improve and Personalize the Platform (Legitimate Interest):
  7. To understand how our users interact with the Platform to enhance user experience.
  8. To provide personalized content and product recommendations.
  9. For Safety and Security (Legitimate Interest & Legal Obligation):
  10. To prevent fraud, abuse, and other harmful activities.
  11. To verify user identities and enforce our Terms and Conditions.
  12. For Marketing and Communications (Consent):
  13. To send you promotional materials, newsletters, and other information about STUBAY, only where you have given your explicit consent. You can opt-out at any time.
  14. To Comply with Legal Obligations:
  15. To respond to lawful requests from public authorities and to comply with our legal and regulatory responsibilities.


4. How We Share Your Information


We do not sell your Personal Data. We only share it in the following circumstances:

  1. Between Users: To complete a transaction, we share necessary information between the Buyer and Vendor, such as name, shipping address, and contact information. Vendor store names and product listings are publicly visible.
  2. With Service Providers: We share data with trusted third-party companies that perform services on our behalf, such as payment processing, data hosting, analytics, and customer support. These providers are contractually obligated to protect your data.
  3. For Legal Reasons: We may disclose your information if required by law, court order, or in response to a valid legal request from a governmental authority.
  4. Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your Personal Data may be transferred as part of that transaction.


5. Your Data Protection Rights


Under Sri Lanka's Personal Data Protection Act, you have the following rights regarding your Personal Data:

  1. Right of Access: You can request a copy of the Personal Data we hold about you.
  2. Right to Rectification: You can request to correct any inaccurate or incomplete data.
  3. Right to Erasure (Right to be Forgotten): You can request the deletion of your Personal Data, subject to certain legal limitations.
  4. Right to Withdraw Consent: Where we process data based on your consent, you have the right to withdraw it at any time.
  5. Right to Object to Processing: You have the right to object to our processing of your data based on legitimate interests.

To exercise any of these rights, please contact our Data Protection Officer using the details below.


6. Data Security


We implement appropriate technical and organizational security measures to protect your Personal Data from unauthorized access, alteration, disclosure, or destruction. These measures include data encryption, access controls, and regular security assessments.


7. Data Retention


We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. This includes retaining data to comply with our legal obligations (e.g., financial records), resolve disputes, and enforce our agreements. When your data is no longer needed, we will securely delete or anonymize it.


8. Cookies and Tracking Technologies


We use cookies and similar technologies to help operate our Platform, analyze performance, and personalize your experience. For more detailed information, please refer to our [Link to Cookie Policy].


9. Children's Privacy


The STUBAY Platform is not intended for use by individuals under the age of 18. We do not knowingly collect Personal Data from children under 18. If we become aware that we have collected such data, we will take steps to delete it immediately.


10. Changes to This Privacy Policy


We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and/or by sending you an email notification. We encourage you to review this policy periodically.


11. Contact Us (Data Protection Officer)


If you have any questions, concerns, or requests regarding this Privacy Policy or your Personal Data, please contact our Data Protection Officer at:

STUBAY (PVT) LTD

Admin

No 344, Karumpulliyan, Naddankandal

Email: privacy@stubay.shop

Phone: 0742796812