GDPR Data Protection Addendum for ShopAndSell.ca

1. Introduction

This GDPR Data Protection Addendum (“Addendum”) is part of the Terms and Conditions of ShopAndSell.ca ("Platform") and outlines the commitments made by us, as the data controller, and your rights as a user, concerning the processing of your personal data.

By using our services, you acknowledge and agree to the collection, processing, and transfer of your personal data as outlined in this Addendum.

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person (the "Data Subject").

  • Processing: Any operation or set of operations performed on Personal Data, such as collection, storage, or transfer.

  • Data Controller: The entity that determines the purposes and means of processing personal data. In this case, ShopAndSell.ca.

  • Data Processor: Any third party that processes Personal Data on behalf of the Data Controller.

  • Data Subject: A natural person whose personal data is being processed.

3. Types of Data We Collect

We may collect and process the following types of Personal Data:

  • Identity Data: Name, username, password, date of birth, and gender.

  • Contact Data: Email address, phone number, and mailing address.

  • Transaction Data: Payment information related to featured listings or other paid services (processed via PayPal).

  • Technical Data: IP address, browser type and version, time zone, browser plug-in types, operating system, device identifiers, and other technical details automatically collected when accessing the Platform.

  • Profile Data: Profile information including user-generated content (ads, reviews, etc.) and preferences.

  • Usage Data: Information about how users interact with the Platform (e.g., pages visited, clicks, and search queries).

4. Purpose of Processing Personal Data

We process your Personal Data for the following purposes:

  • To provide and manage our services, including the creation of user accounts and user profiles.

  • To allow the placement and management of classified ads on our platform.

  • To facilitate payment processing for any featured ads or services through PayPal.

  • To personalize your experience on the Platform, including targeted advertisements or suggestions.

  • To comply with legal obligations, resolve disputes, and enforce our agreements.

  • To communicate with you regarding platform updates, changes to policies, or promotional content.

5. Legal Basis for Processing Personal Data

We rely on the following legal bases for processing your Personal Data under GDPR:

  • Consent: You provide consent by agreeing to our Terms and Conditions and Privacy Policy.

  • Contractual Necessity: Processing is necessary for the performance of a contract, such as processing your ad listings or payments for paid services.

  • Legitimate Interests: We process data in ways that are expected by users and beneficial to our business, such as improving user experience and platform performance.

  • Legal Obligation: We may process data to comply with any legal obligations, such as record-keeping or responding to lawful requests from authorities.

6. Data Sharing and Transfer

  • Third-party Processors: We may share your data with trusted third-party service providers, such as PayPal for payment processing, web hosting services, email providers, and analytics platforms. These parties act as Data Processors on our behalf.

  • International Transfers: Your personal data may be transferred to and processed in countries outside of the UK or EU. In such cases, we will ensure adequate protection measures are in place, such as Standard Contractual Clauses, to safeguard your data.

7. Your Rights Under GDPR

As a user of ShopAndSell.ca, you have the following rights under GDPR:

  • Right to Access: You can request access to your Personal Data and request details on how it is processed.

  • Right to Rectification: You can update or correct any inaccurate Personal Data we hold about you.

  • Right to Erasure: You may request the deletion of your Personal Data under certain conditions (e.g., if it's no longer necessary for the purposes it was collected).

  • Right to Restrict Processing: You can request that we limit the processing of your Personal Data under specific circumstances.

  • Right to Data Portability: You may request your data in a commonly used, machine-readable format to transfer it to another service.

  • Right to Object: You can object to the processing of your Personal Data for direct marketing or other legitimate interests.

  • Right to Withdraw Consent: If we rely on your consent to process Personal Data, you can withdraw it at any time.

To exercise any of these rights, please contact us at [your contact email address].

8. Data Retention

We will retain your Personal Data for as long as necessary to fulfill the purposes outlined in this Addendum, including compliance with legal, accounting, or reporting requirements. Once your data is no longer needed, it will be securely deleted or anonymized.

9. Security of Personal Data

We take appropriate technical and organizational measures to protect your Personal Data from unauthorized access, alteration, or destruction. These measures include encryption, secure storage systems, and controlled access to sensitive information.

10. Changes to This Addendum

We may update this Addendum from time to time to reflect changes in our practices or legal requirements. Any changes will be posted on this page with an updated "Effective Date". We recommend that you review this Addendum periodically to stay informed about how we are protecting your Personal Data.

11. Contact Information

If you have any questions or concerns about this GDPR Data Protection Addendum or our privacy practices, please contact us here


Effective Date: 08/29/2024