Language: EN · LT
Privacy Policy
1. Data Controller
- MB Kodar, company code 308040494
- Address: Laisvės al. 85E-5, LT-44297 Kaunas, Lithuania
- Email: info@kodar.lt
Hereinafter referred to as "we", "us", "our" or "Kodar".
2. General Provisions
This Privacy Policy explains how we collect, use, store and protect your personal data when you use the Kodar mobile application and the website kodar.lt (the "Service"). We comply with the EU General Data Protection Regulation (GDPR) and the Law on Legal Protection of Personal Data of the Republic of Lithuania.
3. Data We Collect
3.1. Account data
- First and last name
- Email address
- Phone number — required to publish a listing; verified by SMS code and used for additional identity confirmation on sensitive actions (changing the payout bank account, withdrawing funds, deleting the account)
- Profile picture (optional)
- Password hash (we do not store plain passwords)
3.2. Transaction and shipping data
- Purchase / sale history
- Shipping address, parcel locker selection
- Payment data (processed by Stripe; we do not store card details)
- Seller payout details (bank account) are provided directly to Stripe during payout account onboarding — we do not store them in our systems
- Identity verification data (identity document and matching photo) — only for sellers who reach the DAC7 reporting threshold; processed by Stripe Identity, we receive only the verification result
3.3. Communication data
- Messages between buyer and seller
- Support requests
- Ratings and reviews
- Violation reports, dispute descriptions and appeals, together with the evidence submitted with them (photos, PDF documents)
- Records of moderation measures applied — removed content, account restrictions and their reasons
3.4. Publicly visible data
The following data is publicly visible to other users of the Platform:
- Username, profile picture, registration date
- Active listings with their photos and descriptions
- Ratings received and their comments
- For business sellers — the company name and identification details that must be made available to the buyer under the EU Digital Services Act (Regulation (EU) 2022/2065); they also appear on the invoice issued to the buyer
The real first and last name, email address, phone number and addresses of private users are not shown publicly. Shipping details are disclosed only to the seller of that specific order and to the carrier, to the extent needed to deliver the parcel.
3.5. Technical data
- Device model, OS version
- App version
- IP address
- Push notification token
- Usage events (errors, session duration)
- Crash reports — device model, OS and app version, the location of the error in the code, account ID; email, phone, addresses and payment details are not included in crash reports
- Pseudonymous usage statistics (e.g., viewed item or category, search phrase, checkout started or completed). Statistics use an app-instance identifier, not the advertising ID — advertising-ID collection is disabled
Photo metadata. Photos you upload are re-encoded in the app, so EXIF metadata (including GPS coordinates) never reaches listings, messages or disputes. The app does not collect location data.
4. Legal Basis and Purposes
| Purpose | Legal Basis |
|---|---|
| Account creation and management | Performance of contract |
| Transaction processing and shipping | Performance of contract |
| Fraud prevention and security | Legitimate interests |
| Content moderation, handling of illegal content reports and appeals | Legal obligation (Regulation (EU) 2022/2065) and legitimate interests |
| Product safety compliance and removal of dangerous goods | Legal obligation (Regulation (EU) 2023/988) |
| Push notifications about orders | Performance of contract |
| App stability (crash reports) and improvement (pseudonymous usage statistics) | Legitimate interests |
| Marketing communications | Consent |
| Seller income reporting to the tax authority (DAC7) | Legal obligation |
| Legal obligations | Legal obligation |
Automated decision-making. We do not make solely automated decisions that produce legal effects for you (GDPR Art. 22). Automated tools are used only for fraud prevention (e.g., payment risk scoring by Stripe) — decisions about accounts and disputes are always reviewed by a human.
5. Data Sharing
We do not sell your data. We may share it with these processors:
- Google Firebase (Google Ireland Ltd.) — authentication, database, cloud functions, push notifications
- Google Analytics for Firebase (Google Ireland Ltd.) — pseudonymous app usage statistics (no advertising ID; data is not used for advertising or cross-app tracking)
- Sentry (Functional Software, Inc.; data hosted in an EU data centre) — app crash reports and performance monitoring
- Stripe Payments Europe, Ltd. — payment processing, seller payouts (Stripe Connect) and identity verification (Stripe Identity)
- NoParcels — shipping label generation and delivery arrangement
- Omniva, LP Express, Venipak, SmartPost — delivery services (parcel lockers and couriers)
- Apple, Google — Sign in with Apple / Google (if used)
- Email service providers — for system notifications
- The Lithuanian State Tax Inspectorate (VMI) — income and identity data of sellers exceeding the EU DAC7 thresholds (30 transactions or €2,000 per calendar year), as required by law
- Other competent authorities — when required by law
6. International Data Transfers
Some processors (e.g., Google) may transfer data outside the European Economic Area. In such cases we ensure appropriate safeguards (EU Standard Contractual Clauses).
7. Retention Periods
- Account data — while account exists, plus 12 months after deletion
- Transaction records — 10 years (accounting law requirement)
- Messages — up to 2 years after the last transaction
- Support requests — up to 2 years
- Violation reports, moderation decisions and appeals with evidence — up to 2 years from the decision; records needed to assess repeat violations — up to 3 years
- Technical logs — up to 90 days
8. Your Rights
Under GDPR you have the right to:
- Access your data
- Rectify inaccurate data
- Erase data ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent at any time
- Lodge a complaint with the State Data Protection Inspectorate (vdai.lrv.lt)
To exercise these rights, contact info@kodar.lt. For account deletion see Data Deletion.
9. Data Security
We use TLS/HTTPS encryption for data in transit, secure access controls, password hashing and regular security reviews. However, no system is 100% secure — users are responsible for keeping their password confidential.
If we detect a personal data breach, we will notify the State Data Protection Inspectorate within 72 hours as required by law, and if the breach poses a high risk to your rights and freedoms, we will also inform you directly.
10. Minors
The Service is intended for users 18 years and older. If we discover that we have collected data from a minor, we will delete it promptly.
11. Cookies
The kodar.lt website uses minimal cookies. See Cookie Policy.
12. Policy Changes
We may update this Policy. We will notify you of material changes in the app or via email before they take effect.
13. Contact
Data protection questions:
Email: info@kodar.lt
Address: Laisvės al. 85E-5, Kaunas