Privacy Policy
This Privacy Policy explains how Appmercat collects, uses, stores, and protects personal data when you use our platform. Appmercat helps users discover public street markets, review municipal rules, create accounts, save favorites, and manage vendor stall information.
Last updated: 25 of March of 2026
Introduction
We are committed to handling personal data responsibly and transparently. This policy applies to information collected through the Appmercat website and related services.
Appmercat does not sell personal data. We only process personal information where there is a legitimate reason to do so in connection with operating and improving the service.
Data Controller
The data controller for Appmercat is:
Artur Hospedales i Catot
Passeig d'Amunt 17, 08024 Barcelona, Spain
info@appmercat.com
Data We Collect
Depending on how you use the platform, we may collect the following categories of data:
- Account information, such as name, email address, and authentication identifiers.
- User profile information, including account preferences and role-related details.
- Favorites and saved items associated with your account.
- Vendor and stall submission data, including edits, descriptions, and related contact details you provide.
- Role request information, such as vendor access requests and supporting explanations.
- Basic technical and usage data, such as IP address, browser type, device information, access times, and interaction logs.
- Basic technical analytics that help us understand performance, reliability, and general product usage.
How We Use Data
We may use personal data to:
- Provide access to Appmercat accounts and authentication features.
- Maintain user profiles, favorites, and personalized account functions.
- Allow vendors to create, edit, and manage stall information.
- Review and process role requests or support requests.
- Operate, secure, troubleshoot, and improve the platform.
- Monitor technical performance and prevent abuse, fraud, or unauthorized activity.
- Comply with applicable legal obligations.
Legal Bases for Processing
Where the GDPR or similar laws apply, we rely on one or more of the following legal bases:
- Performance of a contract, including providing account and platform features you request.
- Legitimate interests, such as platform security, service improvement, moderation, and analytics.
- Compliance with legal obligations.
- Consent, where consent is required for a specific processing activity.
Data Sharing
We may share personal data only when necessary and appropriate, including with:
- Service providers that support hosting, infrastructure, analytics, and authentication.
- Supabase, which we use for authentication and database services.
- Professional advisors or competent authorities when required by law or necessary to protect our rights.
We do not sell personal data to third parties.
International Transfers
Some service providers may process data outside your country of residence. When personal data is transferred internationally, we aim to use appropriate safeguards required by applicable law, such as contractual protections or other recognized transfer mechanisms.
Data Retention
We keep personal data only for as long as necessary for the purposes described in this policy, including account administration, vendor management, security, compliance, and dispute resolution.
Retention periods may vary depending on the type of data, legal requirements, and whether you maintain an active account.
Your Rights
Subject to applicable law, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your personal data.
- Request restriction of processing or object to certain processing activities.
- Request portability of data where applicable.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a competent data protection authority.
To exercise these rights, please contact us at [EMAIL]. We may request information necessary to verify your identity.
Security
We use reasonable technical and organizational measures to protect personal data against unauthorized access, loss, misuse, or alteration. However, no online system can be guaranteed to be completely secure.
Children
Appmercat is not intended for children under the age at which they can lawfully consent to data processing under applicable law. We do not knowingly collect personal data from children in violation of legal requirements.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will publish the revised version on this page and update the "Last updated" date above.
Contact
If you have questions about this Privacy Policy or our data practices, contact us at:
Artur Hospedales i Catot
Passeig d'Amunt 17, 08024 Barcelona, Spain
info@appmercat.com