Back to Uselist · SE/en

Operator (Imprint): Roman Usov · Enskild firma (sole proprietorship) registered in Sweden · Postal address: [to be filled before public launch — see TASK-0177] · Personnummer / Org. nr: [to be filled] · VAT (where applicable): [OSS registration via Skatteverket] · Email: [email protected]

Privacy Policy · Sweden

Effective date: 2026-05-10 · Jurisdiction: Sweden (SE)

1. Controller

The data controller is Roman Usov, a sole proprietorship (enskild firma) registered in Sweden, operating Uselist (the "Service"). Contact: [email protected].

Under GDPR Article 37, we are not required to designate a Data Protection Officer (we do not carry out large-scale systematic monitoring, are not a public authority, and do not process special-category data at scale). Privacy questions are handled directly by the controller via the contact above.

2. What we process and why

DataPurposeLawful basis
Telegram ID, name, optional photo URLAccount identification, login via Telegram Login WidgetContract (Art. 6(1)(b))
Email (optional, for receipts)Billing, support communicationsContract (Art. 6(1)(b))
Item descriptions, photos, pricesInventory storage; the core function of the ServiceContract (Art. 6(1)(b))
Card detailsPayment processing — handled directly by Stripe; we never see the card numberContract (Art. 6(1)(b))
Country, language, planLocalization, marketplace selection, plan-based feature gatingContract (Art. 6(1)(b))
IP address (hashed for signup), browser fingerprintAnti-abuse, fraud prevention, rate limitingLegitimate interest (Art. 6(1)(f))
Product analytics eventsUnderstand feature usage to improve the ServiceConsent (Art. 6(1)(a)) — opt-in via cookie banner; opt-out via Settings → Privacy
Support correspondenceResolve your support requestsLegitimate interest + Contract

3. Sub-processors

We use the following sub-processors. Each is bound by a Data Processing Agreement consistent with GDPR Article 28.

ProcessorRoleData categoryRegion
Cloudflare, Inc.CDN, WAF, DNSHTTP traffic, IP, request metadataEU edge
Stripe Payments Europe, Ltd.Payment processingCard details, email, billing countryIreland (EU)
Telegram Messenger LLPBot platform, Login WidgetTelegram ID, name, photo URL, optional usernameMulti-region
Google Ireland Ltd. (Gemini)AI inference for listingsItem name + photoEU + US (regions vary)
PostHog Inc. (Cloud EU)Product analytics — opt-in onlyPseudonymous Telegram ID, plan, country, languageEU (Frankfurt + Helsinki)
Hetzner Online GmbHServer hostingAll data at restFinland / Germany
Cloudflare R2Photo storageItem photos uploaded by usersEU

4. Cross-border transfers

Most processing happens in the EU/EEA. Two sub-processors may transfer data outside the EEA:

5. Retention

6. Your rights (GDPR Articles 15–22)

We respond to verified requests within one calendar month per Art. 12, extendable by two months for complex requests with notice.

7. Cookies and similar technologies

Strictly necessary cookies (consent, country, language preference, anti-bot) are set without consent because they are required to deliver features you actively requested. Analytics cookies (PostHog) are set only after you accept via the cookie banner; you can withdraw consent at any time via Settings → Privacy.

8. Security

We use TLS for all traffic, encrypt secrets at rest, store no plaintext passwords (Telegram authentication only), and rotate API tokens. Access to production data is limited to the controller. We notify affected users and the supervisory authority of personal-data breaches likely to result in risk to data subjects, in line with GDPR Articles 33–34.

9. Right to lodge a complaint

You have the right to lodge a complaint with the Swedish Authority for Privacy Protection:

Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm
[email protected] · imy.se

You may also contact the supervisory authority of your habitual residence or place of work.

10. Changes

We may update this Privacy Policy to reflect product, legal, or regulatory changes. The "Effective date" line at the top tracks the latest version. Material changes affecting your data will be communicated by email or in-app at least 30 days before they take effect.

11. Contact

Privacy questions, data subject requests, security disclosures: [email protected].