Privacy Policy

Effective: 30 March 2026 · Last updated: 30 March 2026

GDPR Compliant No Tracking Cookies Cyprus Law 125(I)/2018

This Privacy Policy explains how She.cy Ltd. ("she.cy", "we", "us") collects, uses, and protects your personal data when you use the she.cy platform. We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR) 2016/679 and Cyprus Law 125(I)/2018.

1. Data Controller

The data controller responsible for your personal data is:

She.cy Ltd.

Nicosia, Republic of Cyprus

Republic of Cyprus

General enquiries: legal@she.cy

Data Protection Officer: dpo@she.cy

For any data protection concerns, rights requests, or complaints, please contact our Data Protection Officer (DPO) directly at dpo@she.cy.

2. Data We Collect

We collect the following categories of personal data:

2.1 Account Data (provided by you)

  • Full name (first name, last name)
  • Email address
  • Password (stored as a secure bcrypt hash — we never store your plain-text password)
  • Phone number (optional)
  • Account type (individual / business)
  • Profile photo / avatar URL (optional)
  • Bio and location information (optional)

2.2 Activity Data (generated automatically)

  • Listings you create (products, services, jobs)
  • Messages exchanged with other users through the Platform
  • Wishlist items and favourite shops
  • Reviews and ratings submitted
  • Loyalty points and transaction history

2.3 Technical Data (automatically collected)

  • Session identifiers (via HTTP-only session cookie)
  • IP address (used for security and fraud prevention — not stored long-term)
  • Browser type and device type (for compatibility)
  • Pages visited and features used (aggregate, non-identifying logs)
  • Language preference (stored in your browser's local storage)

We do not collect: financial payment card data, government ID numbers, biometric data, or any special categories of personal data as defined by GDPR Article 9, unless explicitly required and with your explicit consent.

4. How We Use Your Data

We use your personal data to:

  • Create and manage your account on the Platform.
  • Display your public profile, listings, shop, and reviews to other users.
  • Enable messaging between buyers and sellers.
  • Send transactional emails (account verification, password reset, purchase confirmations).
  • Calculate and award loyalty points.
  • Detect and prevent fraud, abuse, and violations of our Terms.
  • Respond to your support requests and legal enquiries.
  • Comply with legal and regulatory obligations under Cyprus and EU law.
  • Improve and personalise your experience on the Platform.
  • Send marketing communications, only with your explicit opt-in consent.

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.

5. Data Sharing

We may share your data only in the following circumstances:

5.1 With Other Users

Your public profile information (name, avatar, bio, location, shop details, listings, and reviews) is visible to other users of the Platform. Private messages are only visible to the sender and recipient.

5.2 Service Providers (Data Processors)

We use trusted third-party providers who process data on our behalf under Data Processing Agreements (DPAs) in compliance with GDPR Article 28:

  • Replit Inc. — cloud hosting and database infrastructure (USA; SCCs/adequacy decision applies)
  • Transactional email provider — for sending verification and notification emails

5.3 Legal Requirements

We may disclose your data if required by a court order, legal process, or competent authority in Cyprus or the EU, including the Cyprus Police, Tax Department, or the Cyprus Commissioner for Personal Data Protection.

5.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity, subject to the same privacy protections and with prior notice to you.

6. Data Retention

Data TypeRetention Period
Account dataDuration of account + 30 days after deletion
Transaction records7 years (Cyprus VAT/tax law requirement)
MessagesDuration of account + 30 days
Server logs (IP)90 days
Session cookiesSession or 7 days (remember me)
Reports / abuse records3 years (for legal defence)

When data is no longer needed and there is no legal basis for continued retention, it is securely deleted or anonymised.

7. Cookies & Tracking Technologies

We use cookies in accordance with the Cyprus Electronic Communications and Postal Services Regulation Law 112(I)/2004, which implements the EU ePrivacy Directive 2002/58/EC.

We do NOT use:

  • ✕ Google Analytics or any other analytics tracking
  • ✕ Facebook Pixel or social media tracking
  • ✕ Advertising cookies or retargeting
  • ✕ Third-party tracking scripts
  • ✕ Fingerprinting or behavioural profiling

Cookies We Do Use:

CookieCategoryPurposeDurationParty
she.cy.sidStrictly NecessaryMaintains your login session. HTTP-only, secure, SameSite=None in production. Without this cookie you cannot log in.Session or 7 days1st party
shecy_lang
(localStorage)
FunctionalRemembers your preferred language (EN/EL/AR/RU). Stored in browser localStorage, not transmitted to our servers.Persistent1st party

The session cookie is strictly necessary for the authenticated features of the Platform and does not require consent under the ePrivacy exemption for technically necessary cookies. The language preference uses browser localStorage (not a cookie) and is purely functional.

You may delete these at any time through your browser settings, but doing so will log you out of your account.

8. Security

We implement appropriate technical and organisational security measures in accordance with GDPR Article 32 to protect your personal data against unauthorised access, loss, or misuse. These measures include:

  • Encryption in transit: All data is transmitted over HTTPS/TLS (enforced via HSTS header).
  • Password hashing: Passwords are hashed using bcrypt with a cost factor of 12. We never store plain-text passwords.
  • HTTP-only session cookies: Session tokens are not accessible to JavaScript, protecting against XSS attacks.
  • Secure cookie flags: Session cookies use Secure and SameSite=None in production to prevent CSRF.
  • Content Security Policy (CSP): Strict CSP headers prevent injection attacks.
  • X-Frame-Options / X-Content-Type-Options: Protection against clickjacking and MIME sniffing.
  • Rate limiting: Authentication endpoints are rate-limited to prevent brute-force attacks.
  • Input validation: All user input is validated and sanitised on the server side.
  • Database encryption: Database connections use TLS. The database is hosted in an access-controlled environment.

In the event of a personal data breach, we will notify affected users and the Cyprus Commissioner for Personal Data Protection within 72 hours as required by GDPR Article 33, where the breach is likely to result in a risk to your rights and freedoms.

9. Your Rights Under GDPR

As a data subject under GDPR and Cyprus Law 125(I)/2018, you have the following rights:

Art. 15

Right of Access

Request a copy of all personal data we hold about you.

Art. 16

Right to Rectification

Correct inaccurate or incomplete data.

Art. 17

Right to Erasure

Request deletion of your data ('right to be forgotten').

Art. 18

Right to Restriction

Restrict processing while a dispute is being resolved.

Art. 20

Right to Portability

Receive your data in a structured, machine-readable format.

Art. 21

Right to Object

Object to processing based on legitimate interests or for direct marketing.

Art. 22

Rights re: Automated Decisions

Not be subject to solely automated decision-making with significant effects.

Art. 7(3)

Right to Withdraw Consent

Withdraw consent at any time without affecting prior processing.

To exercise any of these rights, please contact our Data Protection Officer at dpo@she.cy. We will respond within 30 days. We may ask you to verify your identity before processing your request.

If you believe your rights have been violated, you have the right to lodge a complaint with the supervisory authority — the Cyprus Commissioner for Personal Data Protection:

Cyprus Commissioner for Personal Data Protection

1 Iasonos Street, 1082 Nicosia, Cyprus

Tel: +357 22 818 456

Website: https://www.dataprotection.gov.cy

10. International Data Transfers

Your data is primarily stored and processed within the European Economic Area (EEA). Where we use service providers outside the EEA (such as cloud infrastructure providers located in the USA), we ensure appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs) as adopted by the European Commission.
  • Adequacy decisions by the European Commission where applicable.
  • Binding Corporate Rules (BCRs) where applicable.

For details about specific transfers, please contact our DPO at dpo@she.cy.

11. Children's Privacy

she.cy is not directed at, and we do not knowingly collect personal data from, individuals under 18 years of age. In Cyprus, the age of digital consent is 14 years under Law 125(I)/2018, Article 8; however, as a marketplace platform, our minimum age is 18.

If you believe a child under 18 has provided us with personal data, please contact us immediately at dpo@she.cy and we will take steps to delete that data promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in law, our practices, or our services. We will notify you of material changes by:

  • Email notification sent to your registered email address at least 30 days before the change takes effect.
  • A prominent notice on the Platform.
  • Updating the "Last updated" date at the top of this Policy.

Your continued use of the Platform after the effective date of an updated Policy constitutes acceptance of the new Policy. If you do not accept the changes, you should stop using the Platform and may request deletion of your account.

13. Contact & Complaints

For any privacy-related enquiries, rights requests, or complaints, please contact us:

Data Protection Officer

She.cy Ltd.

Nicosia, Republic of Cyprus

dpo@she.cy

Supervisory Authority

Cyprus Commissioner for Personal Data Protection

1 Iasonos Street, 1082 Nicosia

https://www.dataprotection.gov.cy

We take all privacy complaints seriously and will respond within 30 days. You also have the right to escalate directly to the supervisory authority at any time without first contacting us.

For full details of the rules governing your use of she.cy, please also read our Terms & Conditions.