Privacy Policy

Last updated: 28 June 2026

This policy explains what personal data we collect when you use the hunta Marketplace Fee API and website, why we collect it, and your rights under UK data protection law (the UK GDPR and the Data Protection Act 2018).

1. Who we are (data controller)

The controller of your personal data is hunta, a sole trader established in the United Kingdom, contactable at 20-22 Wenlock Road, London, N1 7GU, United Kingdom and [email protected]. We have not appointed a Data Protection Officer (none is legally required for processing of this kind); the contact above handles all data protection queries.

2. Data we collect

DataWhy
Email address (at sign-up)To create your account, deliver your API key, and contact you about the Service.
API usage metadata (endpoint, request volume, timestamps)To meter usage, enforce plan limits, bill correctly, and secure and improve the Service.
Billing reference dataCard payments are processed directly by Stripe. We do not store your card number — we receive only a customer/subscription reference and limited billing metadata.
Server & security logs (incl. IP address)To operate, secure and debug the Service and protect against abuse.

We do not retain the eBay listings or prices you query beyond what is needed to compute and meter a response; query inputs are processed transiently to return your result.

3. How we use it & legal basis

4. Recipients, processors & sub-processors

We do not sell your personal data. We share it only as needed to run the Service:

5. Cookies

The marketing website is static and sets no advertising or tracking cookies. Only strictly necessary cookies (for example those Cloudflare may set for security) are used, for which no consent banner is required. If we ever introduce analytics or any non-essential cookie, we will first add a compliant consent mechanism (where rejecting is as easy as accepting, with no pre-ticked boxes) and update this policy.

6. Retention

7. Your rights

Under UK data protection law you have the right to access, rectify, erase, restrict or object to processing of your personal data, the right to data portability, and — where we rely on consent — the right to withdraw that consent at any time. To exercise any of these, contact us below; we aim to respond within one month. You may also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

8. International transfers

Some recipients (for example Stripe) may process personal data outside the UK. Where they do, we rely on an appropriate safeguard — the UK Extension to the EU–US Data Privacy Framework (where the recipient is certified) and/or the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

9. Data breaches

If a personal data breach is likely to result in a risk to your rights, we will notify the ICO and, where required, you, in line with our legal obligations.

10. Contact

Privacy questions or to exercise your rights: [email protected].