recash

Data Protection Policy

Valid from: 01.02.2025


1. Who is responsible for data processing?

In accordance with the General Data Protection Regulation (GDPR), the responsible entity is:

Circular Service GmbH
Gustav-Schwab-Str. 9
81673 Munich, Germany

Commercial Register: HRB 290030
Registration Court: Munich
Email: info@getrecash.com

We have appointed a Data Protection Officer who can be contacted at the above address or by email.


2. What data do we collect and why?

When using our website or the recash app:

Automatically collected data:

  • IP address
  • Device ID
  • Browser and OS information
  • Date/time of access
  • Referrer URL
  • Session and interaction data

Purpose:
To operate and secure the website/app (Art. 6 para. 1 lit. f GDPR).


User-provided data (during registration and platform use):

  • Name and address of the company
  • Company location
  • Name of registered individuals, profile pictures, email addresses, preferred language
  • Username and password
  • Contact phone numbers
  • Email addresses
  • Account and payment data
  • Tax ID

Purpose:
To provide a user account, enable contract formation, and fulfill platform obligations (Art. 6 para. 1 subpara. 1 (b) and (f) GDPR).

We assign an ID number to every registered person.

Support and Account Assistance (User Impersonation):
To resolve reported technical bugs, address support requests, and provide assisted account management (such as uploading inventory on behalf of the partner upon request), authorized recash personnel may temporarily access your account interface. This access is restricted strictly to authorized staff and used only for these designated purposes.

Purpose: Technical support, platform functionality, and customer service (Art. 6 para. 1 lit. b and f GDPR).

Direct marketing:
We may use your data, particularly contact data, for direct advertising via email if obtained during service/product sale (Art. 6 para. 1 subpara. 1 (f) GDPR).

Credit checks:
Rarely, we may use your data to verify creditworthiness (Art. 6 para. 1 subpara. 1 (f) GDPR).


Processing order data:
Details of orders processed on the platform are stored to fulfill contracts and maintain legal clarity (Art. 6 para. 1 subpara. 1 (b) and (f) GDPR).

Processing creditworthiness data:
In rare cases, we may use data from third-party sources (e.g. Schufa, Creditreform, trade registers) (Art. 6 para. 1 subpara. 1 (f) GDPR).


Tracking data:
We collect browser/device/user behavior data to ensure safe operation. If not technically necessary, processing is based on your consent (Art. 6 para. 1 subpara. 1 (a) GDPR).


3. Who can obtain your data?

We may pass on your data to third parties to execute contracts and manage the platform.

Recipients include:

  • Trade partners
  • Suppliers
  • Carriers and freight forwarders
  • Service providers (e.g., for payments, administration, and advertising)

Legal basis:
Art. 28 GDPR or other contractual agreements.

International transfers:
When outside the EU/EEA, we ensure data protection standards via adequacy decisions (Art. 45 GDPR) or other safeguards (Art. 46 GDPR).

Recipients of your data:

  • Stripe | Name, email, company, billing address, payment data | Payment processing and seller payouts | Ireland, USA
  • Supabase | All account, company, order and catalogue data, uploaded files | Database, login and file storage | EU (Frankfurt)
  • Vercel | IP address, browser data | Website hosting and delivery | USA
  • Trigger.dev | Order, product and account data | Background processing (imports, invoices, labels, emails) | USA, EU
  • Brevo | Name, email, language, order data | Transactional email and newsletters | Germany, India, USA, Canada
  • DHL | Name, company, address and phone number of sender and recipient | Shipping labels, tracking and delivery | Germany
  • Sentry | IP address, user ID, technical error context | Error diagnostics | EU
  • PostHog | Usage and session data | Product analytics (see 4.7) | EU (Frankfurt)
  • Cloudflare | IP address, device signals | Bot protection on our forms | USA
  • Trustpilot | Data you enter yourself when leaving a review | Review widget after checkout | Denmark
  • Slack | Name, email, phone number, conversation content | Support escalation from our chat assistant | USA
  • Hubspot | Name, address, email, payment data, phone number, tax number | Sales | Germany, USA
  • eBay, Odoo | Account and listing data | Only if you connect these accounts yourself | USA, Belgium
  • AI providers | See section 5 | Chat assistant, catalogue import, product data | USA

Product-data services (Keepa, DataForSEO and our image-processing providers) receive article data only and no personal data.


4. Analytics and Third-Party Tools

4.1. Cookies

Used for functionality and analytics.

  • Necessary cookies: Art. 6 para. 1 lit. f GDPR
  • Other cookies: Art. 6 para. 1 lit. a GDPR

4.2. Google Analytics

Used for visitor analytics and service optimization.

  • Provider: Google Ireland Limited
  • Legal basis: Art. 6 para. 1 lit. a GDPR
  • Data transfer: USA (EU-U.S. Data Privacy Framework)
  • Retention: 14 months
  • DPA: Concluded

4.3. Brevo (Sendinblue GmbH)

Used to send transactional emails.

  • Legal basis: Art. 6 para. 1 lit. b GDPR
  • Recipients: Brevo
  • Third-country transfers: India, USA (SCCs), Canada (adequacy decision)
  • Retention: 14 months
  • DPA: Concluded

4.4. Google Tag Manager

Used to manage and fire tracking/analytics tags.

  • Legal basis: Art. 6 para. 1 lit. a GDPR
  • Recipient: Google Ireland Limited
  • Data collected: IP, usage, referrer, geo-location
  • Retention: Tag Manager itself stores no personal data

4.6. Cookie Consent Management – Cookiebot (Usercentrics)

Manages and documents consent.

  • Legal basis: Art. 6 para. 1 lit. c GDPR
  • Provider: Usercentrics GmbH, Munich
  • Data collected: Consent info, IP, timestamp, banner language, settings
  • Retention: 1 year
  • No third-country transfer

4.7. PostHog (Product Analytics and Session Replay)

We use PostHog to analyze user behavior and record user sessions (including mouse movements, clicks, and scrolling). This helps us identify technical bugs and improve the user experience. Sensitive text inputs are masked and not recorded.

  • Provider: PostHog, Inc.
  • Legal basis: Art. 6 para. 1 lit. a GDPR (Consent via our cookie banner)
  • Data location: Exclusively within the EU (Frankfurt, Germany)

4.8. Vercel (Hosting and Infrastructure)

Our frontend platform is hosted on Vercel's Edge Network. When you visit our website, Vercel automatically and temporarily processes standard connection data, including your IP address and browser information, to route traffic efficiently, ensure platform stability, and prevent DDoS attacks.

  • Provider: Vercel Inc.
  • Legal basis: Art. 6 para. 1 lit. f GDPR (Legitimate interest in secure and efficient technical operation)

5. Use of Artificial Intelligence

We use AI language models in several parts of the platform. No AI system decides about you on its own — every result can be reviewed and corrected by you or by us.

Where we use AI:

  • Chat assistant: to answer your questions about the platform, products and orders.
  • Catalogue import: when you upload a product list (CSV/Excel), an AI model reads the file, maps the columns to our product fields and asks clarifying questions.
  • Product data: to generate product descriptions, assign categories and process product images.

What data is transmitted:

  • Chat assistant: your name, email address, company name, country, telephone number, language, and the content of your messages.
  • Catalogue import: the contents of the file you upload, including any personal data it contains.
  • Product data: article data and product images. No personal data.

Providers:
Requests are routed through OpenRouter to the model providers Anthropic, OpenAI and Google. Processing may take place in the USA on the basis of standard contractual clauses (Art. 46 GDPR).

Legal basis:
Art. 6 para. 1 lit. b GDPR (performance of the contract) for the chat assistant and catalogue import, and Art. 6 para. 1 lit. f GDPR (our legitimate interest in an efficient platform) for product-data processing.

Automated decision-making:
We do not make any decisions with legal effect for you, or which significantly affect you in a similar way, based solely on automated processing (Art. 22 GDPR).

Retention:
Chat conversations are stored in your account so the assistant can refer back to earlier messages. You can request their deletion at any time.


6. Social Media & Embedded Third-Party Content

When clicking external links (e.g., YouTube, social media), their own privacy policies apply.
No data is shared unless you interact (e.g., click a link).


7. How long do we store your data?

Data is retained only as long as needed for processing or legal compliance.
Afterward, it is deleted unless statutory retention periods apply.


8. Your rights

Under the GDPR, you have the right to:

  • Access (Art. 15)
  • Rectification (Art. 16)
  • Erasure (Art. 17)
  • Restriction (Art. 18)
  • Data portability (Art. 20)
  • Object (Art. 21)
  • Withdraw consent (Art. 7 para. 3)
  • Lodge a complaint (Art. 77)

Supervisory Authority:
Bayerisches Landesamt für Datenschutzaufsicht
Promenade 18, 91522 Ansbach, Germany


9. Updates to this policy

This privacy policy may be updated at any time to reflect legal or service changes.
The current version will always be available on our website.