Last updated: 1 June 2026
Privacy Policy
This policy explains how Built Bezel collects, uses, and protects your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Built Bezel (“we”, “us”) is the data controller for personal data processed through this platform. For data protection enquiries, contact us at hello@builtbezel.com.
We are not currently required to appoint a Data Protection Officer (DPO) under Article 37 UK GDPR, as we do not carry out large-scale systematic monitoring or process special category data at scale. Should this change, we will update this policy.
2. Data We Collect
Account data: name, email address, profile information you provide.
Listing data: watch details, photographs, pricing, location.
Transaction data: purchase and sale history, shipping addresses, payout information.
Payment data: payment is processed by Stripe; we do not store card numbers. We receive transaction IDs and payout amounts.
Communications: messages sent through the platform between buyers and sellers.
Tax/compliance data: if you complete a seller tax profile: legal name, address, entity type, tax reference numbers.
Technical data: IP addresses, browser type, pages visited, timestamps — collected via Vercel hosting and our rate-limiting system.
Consent records: records of when you accepted terms and cookie preferences.
3. How We Use Your Data
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Providing the marketplace service | Contract performance (Art. 6(1)(b)) |
| Processing payments and payouts | Contract performance (Art. 6(1)(b)) |
| Identity verification and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| HMRC DAC7 seller reporting | Legal obligation (Art. 6(1)(c)) |
| Sending transactional emails (order confirmations, shipping updates) | Contract performance (Art. 6(1)(b)) |
| Sending marketing emails | Consent (Art. 6(1)(a)) — opt-in only |
| Improving the platform | Legitimate interests (Art. 6(1)(f)) |
| Complying with legal requests (law enforcement, court orders) | Legal obligation (Art. 6(1)(c)) |
4. Data Retention
Account data: retained while your account is active. On deletion request, processed within 30 days subject to legal holds.
Transaction data: retained for 7 years to comply with HMRC record-keeping requirements (Finance Act 2007).
Communications: retained for 2 years after the last message.
Audit logs: retained for 3 years.
Consent records: retained for 5 years as evidence of consent.
5. Third Parties We Share Data With
We share data with the following processors under Data Processing Agreements:
- Supabase Inc. (database, auth) — servers in EU-West. Data Processing Agreement in place under UK GDPR standard clauses.
- Stripe Inc. (payments) — US-based. Data transfers under UK International Data Transfer Agreements (IDTAs).
- Brevo (Sendinblue) (email) — EU-based. GDPR compliant.
- Vercel Inc. (hosting) — US-based. Data transfers under IDTAs.
- HMRC — we are legally required to share seller data under DAC7 digital platform reporting rules.
We do not sell your personal data to third parties.
6. Your Rights
Under UK GDPR you have the right to:
- Access — request a copy of your personal data (Subject Access Request).
- Rectification — ask us to correct inaccurate data.
- Erasure (“right to be forgotten”) — request deletion of your data. This can be done from your account settings. Note: we may retain data required for legal compliance (e.g. transaction records for HMRC).
- Portability — receive your data in a machine-readable format.
- Restriction — ask us to pause processing in certain circumstances.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — for consent-based processing (e.g. marketing emails) at any time.
To exercise any right, email hello@builtbezel.com. We will respond within one calendar month.
7. Cookies
We use cookies as described in our Cookie Policy. You can manage your preferences via the cookie banner or your browser settings.
8. Complaints
If you believe we have mishandled your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO): ico.org.uk or call 0303 123 1113.
We encourage you to contact us first at hello@builtbezel.com so we can resolve any concerns directly.
9. Changes to This Policy
We will notify registered users by email of any material changes at least 14 days before they take effect. The effective date at the top of this page will be updated on any change.