IslandMarket is a marketplace platform for island vendors and branch storefronts. This page is the operating privacy policy for the current product. It is not a substitute for a lawyer-reviewed agreement before a broader public launch.
Information we collect
- Account details such as name, email, phone, password, and role.
- Vendor application and branch details, including business name, island, WhatsApp number, and optional custom domain.
- Product, image, location, and inventory records that vendors publish.
- Customer inquiry details: name, phone, location, selected pickup point, items, and estimated total.
- Support form submissions: name, email, topic, message, and the page you sent it from.
- Usage events such as storefront views, searches, inquiries, WhatsApp handoffs, and client errors.
- Technical data needed to run the site, including session identifiers and the page path.
How we use information
- Operate the marketplace, branch storefronts, vendor admin, and platform admin tools.
- Create vendor applications, team invites, and customer inquiries.
- Review contact-form messages in platform admin.
- Send transactional email such as confirmation, password reset, invites, and application updates.
- Show vendors aggregate analytics, not raw shopper browsing trails.
- Detect outages, failed inquiries, failed uploads, and client errors.
Who can see data
Public visitors can see active vendors, products, and pickup locations. Vendor owners, managers, and staff can see their own inventory, inquiries, and team records. Platform admins can review applications, vendor status, and support issues. Raw analytics events are platform-admin-only.
Retention
- Raw analytics events are kept for 90 days, then should be deleted or anonymized.
- Daily vendor metrics are kept for 24 months to support operations and premium reporting.
- Inquiries stay with the vendor account through their status history instead of being deleted.
- Archived products stay hidden from shoppers but remain available in vendor admin.
- Deleted product images are removed from storage and their database rows are deleted.
- Account deletion is handled through the support form.
Cookies and similar storage
IslandMarket uses local browser storage for a session identifier used in analytics and for authentication session state provided by Supabase Auth. We do not use third-party advertising cookies.
Processors
Hosting runs on Amazon Web Services. Transactional email is sent through Resend. Application data, authentication, and image storage run on Supabase. Maps use MapTiler when a map key is configured. WhatsApp is opened by the shopper on their own device; IslandMarket does not send the WhatsApp message for them.
Contact
Privacy questions and deletion requests go through the support form.