Legal & Compliance
Last Updated: 25 August 2026
RetroTechCollector is a service operated by RetroTechCollection (retrotechcollection.com).
This section holds the policies that govern the service: what you are agreeing to, what we do with your data, what you may and may not do here, and how buying and selling works.
The Documents
📜 Terms of Service
The agreement between you and RetroTechCollection covering your account, your content, payment for a paid plan, and the limits of our liability.
Read Terms →
🔒 Privacy Policy
What personal data we collect, why we collect it, who we share it with, and how long we keep it.
Read Privacy →
🇬🇧 UK GDPR
Your data protection rights and how to exercise them, our lawful bases, the retention periods we actually enforce, and the fact that our servers are in the United States.
Read GDPR →
🤖 AI Features & the EU AI Act
The three places we use AI (photo identification, condition grading and description drafting), what each is allowed to decide, what data reaches the model provider, and what we keep.
Read AI Policy →
🍪 Cookie Policy
The three cookies that sign you in and keep you safe, the analytics we run, and how the app, this documentation site and the marketing site each differ.
Read Cookies →
✅ Acceptable Use Policy
What you may and may not post, send or list; what cannot be sold here; how to report something; and exactly what we can do about it if you break the rules.
Read AUP →
🛍️ Marketplace Terms
The seller agreement: listing rules, fees, payment and payout, shipping, returns, trades, ratings and the dispute process.
Read Terms →
Five Things Worth Knowing Before You Read Any of It
Selling costs 0%, on every plan. A launch fee holiday is in effect. The platform takes nothing from a sale, and no plan buys a cheaper selling rate. If that changes we will publish the new rate and give notice first. See Marketplace Terms.
Your data is processed in the United States. The application, the database and your uploaded images run on Google Cloud in the us-central1 region in Iowa. That is a restricted transfer under UK GDPR and we treat it as one, under Standard Contractual Clauses and the UK International Data Transfer Addendum. GDPR sets out the safeguards and names every processor.
Messaging is encrypted at rest, not end to end. Messages are encrypted in our database with a key we hold. We can decrypt them, and when a message is reported our moderators read it in order to act on the report. Anyone describing this as end-to-end encryption is wrong, including us if we ever do.
We are not VAT-registered. No VAT is charged or added by the platform. If you sell here, your own tax position is yours. See Marketplace Terms.
The AI suggests; it never decides. Nothing about your account, your access, your money or your standing is determined by a model or by an automated rule on its own. Every AI output is a suggestion you accept, edit or reject first. AI Features and the EU AI Act explains each feature and what it can and cannot do.
Your Rights
Under UK GDPR you can:
- Get a copy of the personal data we hold about you
- Correct anything inaccurate, most of which you can edit yourself in settings
- Delete your account and your data, subject to records we are legally required to keep
- Export your collection in a portable format: JSON, CSV or Excel, straight from the app
- Restrict or object to particular processing
- Withdraw consent where consent is what we relied on
- Complain to the ICO at ico.org.uk, with or without coming to us first
GDPR explains how to exercise each one, what we need from you, and how long we take.
The Rules We Work To
- UK GDPR and the Data Protection Act 2018: data protection
- PECR: cookies and electronic marketing, covered in Cookies
- Online Safety Act 2023: illegal and harmful content, covered in Acceptable Use
- EU AI Act (Regulation (EU) 2024/1689): we treat our AI features as subject to its transparency obligations, and we are applying them now, ahead of the deadline
- Consumer Rights Act 2015: relevant to anyone selling to UK consumers here
We do not claim certifications or audits we do not hold. Card details never reach us: payments and payouts run through Stripe, which is PCI-DSS certified, and we neither see nor store a card number.
Data Protection in Practice
What we hold
- Account information: email, username, profile
- Your collection: items, images, notes, valuations
- Marketplace activity: listings, offers, transactions, messages, disputes
- Operational and security records: sign-in attempts, security events, audit logs
How it is protected
Sensitive fields, including message content, are encrypted at rest with AES-256-GCM. Everything in transit is over TLS. Administrative access is role-based with granular permissions, and every administrative action is written to an audit log recording who did what, when, and what changed.
How long it is kept
Security and operational records are purged automatically on fixed schedules: sign-in attempts after 180 days, security events after a year, administrative audit records after two years, and so on. The full table is in GDPR. Your own content is kept while your account is open. Completed transactions and their financial records outlive an account closure because tax law requires it.
What you control
- Privacy and data settings: visibility, discoverability, notifications
- Export your collection: JSON, CSV or Excel, whenever you like
- Account deletion, from settings
When These Change
We update these pages as the product changes and as the law changes. Every page carries a "Last Updated" date. For a change that materially affects your rights or your obligations, we will tell you.
Questions and Reports
Legal questions: [email protected] Privacy and data rights: [email protected] Data Protection Officer: [email protected] Report a breach of the rules: [email protected] Report a security flaw: [email protected] Appeal a moderation decision: [email protected]
For anything else, contact support.