Your Privacy Matters
RoMart ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our marketplace platform. Please read this policy carefully to understand our practices regarding your personal data.
1. Information We Collect
1.1 Information You Provide
- Account Information: Email address, username, password (hashed), and profile preferences when you create an account
- Roblox Account Information: Roblox username, user ID, and account verification status
- Seller Credentials: Encrypted Roblox session cookies (.ROBLOSECURITY) for sellers who list items for sale
- Payment Information: Billing details processed through Stripe; cryptocurrency wallet addresses for deposits
- Communication Data: Messages sent to support, feedback, and dispute information
- Identity Verification: Government-issued ID and proof of address for users meeting KYC thresholds
1.2 Information Collected Automatically
- Usage Data: Pages visited, features used, items viewed, search queries, and transaction history
- Device Information: Browser type and version, operating system, device type, screen resolution
- Network Information: IP address, approximate location (country/region), internet service provider
- Cookies and Tracking: Session identifiers, authentication tokens, and preference cookies
- Log Data: Access times, error logs, and system activity
1.3 Information from Third Parties
- Roblox API: Public profile information, inventory data, and trade history (with your authorization)
- Payment Processors: Transaction status and fraud indicators from Stripe
- Blockchain Networks: Public cryptocurrency transaction data
2. How We Use Your Information
We use your personal information for the following purposes:
Service Operations
- Create and manage your account
- Process transactions and send related notifications
- Execute Roblox trades on behalf of sellers
- Verify Roblox account ownership and inventory
- Provide customer support and respond to inquiries
Security & Compliance
- Prevent fraud, abuse, and unauthorized access
- Detect and block suspicious transactions
- Comply with anti-money laundering (AML) regulations
- Verify user identity for KYC requirements
- Enforce our Terms of Service
Improvements & Analytics
- Analyze usage patterns to improve the platform
- Personalize your experience and recommendations
- Test new features and functionality
- Generate aggregated, anonymized statistics
3. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), we process your data based on:
- Contract Performance: Processing necessary to provide our services to you (account management, transactions, trade execution)
- Legal Obligations: Processing required by law (AML/KYC compliance, tax reporting, law enforcement requests)
- Legitimate Interests: Processing for fraud prevention, security, service improvements, and analytics (balanced against your rights)
- Consent: For marketing communications and optional cookies (which you can withdraw at any time)
4. Data Security
We implement robust security measures to protect your information:
Encryption
All sensitive data, including Roblox cookies, is encrypted using AES-256-GCM with unique keys
Transport Security
All data transmission uses TLS 1.3 encryption
Access Controls
Strict role-based access, multi-factor authentication for admin accounts
Monitoring
24/7 security monitoring, intrusion detection, and regular audits
Security Notice
While we employ industry-standard security practices, no system is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and should never share your password or session cookies with others.
5. Information Sharing & Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
- Service Providers: Third parties that help us operate the platform:
- Stripe – Payment processing
- Cloud hosting providers – Data storage and infrastructure
- Email services – Transactional notifications
- Transaction Partners: Limited information shared with other users as necessary to complete trades (e.g., Roblox username)
- Legal Requirements: When required by law, court order, or government request; to protect our rights, property, or safety; to investigate fraud or security incidents
- Business Transfers: In connection with a merger, acquisition, bankruptcy, or sale of assets (you will be notified of any such transfer)
- Aggregated Data: We may share anonymized, aggregated statistics that cannot identify you personally
6. Cookies & Tracking Technologies
We use cookies and similar technologies for the following purposes:
| Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, security, session management | Session / 7 days |
| Functional | Preferences, language, theme settings | 1 year |
| Analytics | Usage statistics, performance monitoring | 2 years |
You can manage cookie preferences through your browser settings or our cookie consent tool. Disabling essential cookies may affect platform functionality. See our Cookie Policy for more details.
7. Your Privacy Rights
Depending on your location, you may have the following rights:
Access
Request a copy of the personal data we hold about you
Rectification
Request correction of inaccurate or incomplete data
Erasure
Request deletion of your data ("right to be forgotten")
Restriction
Request limited processing of your data
Portability
Receive your data in a machine-readable format
Objection
Object to processing based on legitimate interests
To exercise these rights, email us at privacy@romarket.gg. We will respond within 30 days. For EEA residents, you also have the right to lodge a complaint with your local data protection authority.
8. Data Retention
We retain your information for the following periods:
- Account Data: Retained while your account is active, plus 30 days after deletion request
- Transaction Records: Retained for 5 years as required by anti-money laundering regulations (UK MLR 2017)
- KYC Documents: Retained for 5 years after business relationship ends
- Support Communications: Retained for 2 years after resolution
- Log Data: Retained for 90 days for security purposes
After retention periods expire, data is securely deleted or anonymized for statistical purposes.
9. Children's Privacy
Age Restrictions
- Users must be at least 13 years old to create an account and browse the marketplace
- Users must be at least 18 years old to sell items or use payment services
- We do not knowingly collect personal information from children under 13
- If we discover we have collected data from a child under 13, we will delete it immediately
If you believe a child under 13 has provided us with personal information, please contact us at privacy@romarket.gg.
10. International Data Transfers
Your information may be transferred to and processed in countries outside your country of residence. These countries may have different data protection laws.
When we transfer data internationally, we implement appropriate safeguards:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions where applicable
- Binding Corporate Rules for intra-group transfers
- Your explicit consent where required
11. Third-Party Links
Our platform may contain links to third-party websites, including Roblox.com and payment providers. We are not responsible for the privacy practices of these external sites. We encourage you to read the privacy policies of any third-party sites you visit.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Posting the updated policy on this page with a new "Last updated" date
- Sending an email notification for material changes
- Displaying a notice on the platform
Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
13. Contact Us
For questions or concerns about this Privacy Policy or our data practices:
- Privacy Inquiries: privacy@romarket.gg
- Data Protection Officer: dpo@romarket.gg
- General Support: support@romarket.gg
- Discord: discord.gg/DWMtWR4zsh
California Privacy Rights (CCPA)
California residents have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected, used, and shared
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising your privacy rights
To exercise these rights, contact privacy@romarket.gg or call our toll-free number.