Controller and contact
The operator responsible for the website and customer relationship is Not supplied yet, based at Not supplied yet (Not supplied yet). Privacy contact: Not supplied yet.
The full merchant identity and a working privacy contact must be supplied before real sales.
Data and purposes
When you create an account, we store your name, email, password hash, verification status, account preferences and consent timestamps. For a seller application, we also collect the applicant’s business identity, contact details, activity address, product categories, shipping and return policies, and application decision.
Cart, saved products, followed stores, addresses, orders, payment status and identifiers, return/withdrawal requests, messages, reports and uploaded product images are stored to provide the functions you request. Technical logs and login-attempt IP addresses help protect accounts. No raw card number is collected by DARMI; card entry takes place on Stripe-hosted Checkout when live payments are enabled.
Basis and recipients
Account, checkout, messaging and delivery data are used to perform the service or take pre-contractual steps; security and fraud prevention rely on the operator’s legitimate interests where applicable; legal accounting records may be retained where required. Marketing email preference is separate and optional, and can be changed in account settings. The exact legal basis must be reviewed for the merchant’s jurisdiction.
The hosting/database provider, transactional email provider, Stripe for payment, and the relevant approved seller for fulfillment or an order conversation may receive data needed for their roles. Administrators can access moderation and support data. We do not claim that data never leaves your country; provider locations and safeguards must be verified before live operation.
Retention and rights
An account and its related records remain stored while required for the service and any applicable legal obligations. Verification/reset tokens expire; a scheduled maintenance command deletes expired tokens and older login-attempt records. A guest-cart identifier can last up to 30 days. A request to delete an account is recorded for manual review; it does not automatically erase order or legal records. A documented retention schedule must be completed by the merchant before live operation.
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and withdraw optional marketing consent. Use account settings or contact Not supplied yet. You may complain to the competent data-protection authority where that right applies.
External services and changes
Google Fonts may receive your IP address when the browser loads website fonts; the Stripe-hosted payment page has its own privacy information. No analytics or advertising tracker is deliberately installed in this release. We will update this policy when actual providers, jurisdictions or processing change. Last updated: 1 October 2026.
Last updated: 1 October 2026
