Privacy Policy
Effective date: 2026-03-14 Last updated: 2026-03-14
This policy explains what personal data we collect when you use the Marketplace, why we collect it, how we use and share it, how long we keep it, and what rights and choices you have. We aim to be straightforward — this notice describes our current product, not aspirational plans.
1. Who This Policy Applies To
This policy applies to everyone who uses the Marketplace, including:
- visitors browsing Listings on the Website
- Buyers who purchase, download, or use Skill Bundles through the Website, Telegram Bot, or Mini App
- Sellers who upload, publish, and manage Listings
- anyone who submits an interest form, support request, or contacts us
- anyone who leaves a review or interacts with Marketplace features
What this policy does not cover:
- Telegram's own data processing under Telegram's Privacy Policy. Telegram is a separate platform with its own terms.
- Payment and platform data that Telegram processes on its own infrastructure outside of our systems.
- Third-party websites or services linked from Listings, support materials, or Seller content.
2. Who Controls Your Data
| Field | Detail |
|---|---|
| Operator | ФОП Крючков Костянтин Андрійович (trading as Forgedemy) |
| Operating form | FOP (sole proprietorship under Ukrainian law) |
| Country | Ukraine |
| Registration number / ІПН / ЄДРПОУ | 3478909918 |
| Address | Odesa, Ukraine |
| Website | forgedemy.org |
| Telegram Bot | @forgedemy_bot |
| IBAN | UA673220010000026001310045384 |
For full contact and business details, see the Legal & Contact Information page.
The Operator is the data controller for the personal data described in this policy. For questions about how your data is handled, contact us at [email protected].
3. What Data We Collect
We collect different categories of data depending on how you use the Marketplace:
Account and identity data
Telegram user ID, chat ID, Telegram username, Telegram first name, Seller handle, Seller name, internal account IDs, install-state flags, and token-delivery timestamps.
Contact and request data
Name, Telegram handle or email address, role selection, freeform request message, and support communications.
Purchase and Entitlement data
Listing ID, purchase intent IDs, Entitlement IDs, payment amount, currency (Telegram Stars / XTR), Telegram payment charge ID, paid status, timestamps, and Delivery/download history.
Marketplace activity data
Library state, install state, review ratings and text, moderation state, account access status, and Seller listing activity.
Seller-submitted content
Uploaded packages, screenshots, Listing metadata, changelogs, compatibility claims, package Manifests, and support policy content. Seller uploads may unintentionally contain personal data, credentials, or third-party content. We reserve the right to scan, review, or remove such content for safety and compliance.
Technical and device-side data
Request metadata, service logs, approximate diagnostics, and abuse-prevention and security events.
Local device storage: The web application stores a Seller authentication token in your browser's localStorage. This is not a cookie, but it is information stored on your device. It persists until you clear your browser storage or the token is overwritten. We use this token solely to maintain your Seller session. See Section 9 for more details.
4. How We Collect Data
We collect data through the following channels:
- Directly from you — when you browse Listings, submit forms, connect your Telegram account, create Listings, make purchases, download Skill Bundles, leave reviews, or contact support.
- From Telegram — when you authenticate through Telegram login or Mini App identity flows, or when you make a purchase using Telegram Stars. We receive only the Telegram account data needed for account linking and purchase handling.
- Automatically — through service logs, security checks, and account/session handling as part of normal Marketplace operations.
- From Seller uploads — content that Sellers choose to submit, including packages, metadata, and screenshots.
We do not currently use cookies, analytics SDKs, advertising trackers, or newsletter tools. If this changes, we will update this policy before introducing them.
5. Why We Use Your Data (Legal Bases)
For Users in the EU, UK, or jurisdictions that require a stated legal basis, here is how we justify each use:
| Purpose | Legal basis |
|---|---|
| Provide the Marketplace, connect accounts, deliver purchased Skill Bundles, manage Seller access | Performance of a contract or pre-contractual steps at your request |
| Process purchases, maintain transaction records, prevent fraud, handle disputes | Contractual necessity, legitimate interests, and where required, legal obligations |
| Moderate Listings, detect malware, enforce the Terms of Service and Acceptable Use Policy, respond to takedowns | Legitimate interests (safety, integrity, and trust of the Marketplace) |
| Respond to support requests, onboarding inquiries, and interest forms | Legitimate interests or pre-contractual steps |
| Meet tax, accounting, consumer-protection, and law-enforcement obligations | Legal obligation |
| Send optional marketing communications (not currently active) | Consent — only if and when we actually introduce marketing communications |
We do not currently send marketing emails or run profiling systems. We do not make solely automated decisions with legal or similarly significant effects on Users. If either changes, we will update this policy.
6. When We Share Data
We share personal data only in the following circumstances:
Infrastructure processors
Hosting, storage, database, and object-storage providers that process data on our behalf under data processing agreements (DPAs) in accordance with GDPR Article 28. These providers act as processors under our instructions.
Telegram
Telegram is involved in login, account linking, messaging, and Telegram Stars payments. The exact controller/processor split between us and Telegram is not fully resolved for all processing activities. At minimum:
- Telegram acts as a separate controller for data it processes under its own terms.
- We receive only the Telegram data needed for account linking, purchase handling, and messaging.
- For Telegram Stars payments, Telegram processes payment data through its own infrastructure.
For more information, see Telegram's Privacy Policy.
Service providers
If we later add providers for security scanning, moderation tools, support platforms, or analytics, they will operate under processor agreements. We will update this policy before introducing them.
Legal authorities or counterparties
Where required by applicable law, regulation, legal process, or enforceable governmental request, or to protect rights, safety, or property.
Rights holders or claimants
When handling a credible takedown or dispute under the IP/Takedown Policy, but only to the extent necessary for resolving the matter.
What we do not do
- We do not sell personal data.
- We do not run third-party advertising or build advertising profiles.
- We do not share Buyer identity with Sellers except where necessary for Delivery, support, or dispute handling. Buyers remain pseudonymous to Sellers unless the situation requires otherwise.
7. International Transfers
Data may be processed outside your country of residence. Our infrastructure providers and Telegram may process data in jurisdictions other than where you are located.
For transfers of personal data from the European Economic Area (EEA), UK, or Switzerland to countries without an adequacy decision:
- We rely on Standard Contractual Clauses (SCCs) with our infrastructure processors.
- Telegram's own transfers are governed by Telegram's terms and transfer mechanisms.
Ukraine note: Ukraine does not currently hold an EU adequacy decision. Transfers from the EEA to the Operator in Ukraine require SCCs or another valid transfer mechanism. We maintain SCCs with our infrastructure providers for this purpose.
The Operator will put appropriate data processing agreements in place with infrastructure providers as required.
8. Storage, Security, and Retention
Security measures
We use reasonable technical and organizational measures to protect your data, including access controls, token-based authentication, environment separation, logging, and content scanning for Seller uploads. We do not claim to encrypt everything or guarantee absolute security — no online service can.
Retention periods
We retain personal data only as long as needed for the purposes described in this policy, subject to the following category-specific periods:
| Data category | Retention period |
|---|---|
| Interest and onboarding requests | Until handled + up to 12 months for follow-up, then deleted or anonymized |
| Account and Entitlement data | While the account is active + 3 years after account closure |
| Payment and purchase records | The longer of 5 years or the applicable statutory limitation period |
| Reviews and Listing history | While the Listing is live + 12 months after removal |
| Seller uploads and moderation records | While the Listing is active + 12 months after removal or account closure |
| Logs and security data | 90-day rolling window, unless extended for a specific incident investigation or legal hold |
| Device-side storage (localStorage Seller token) | Until you clear your browser storage or the token is overwritten — we cannot control client-side retention directly |
| Evidence from IP/takedown complaints | 3 years after final resolution |
After the applicable retention period, data is deleted or anonymized unless a legal hold or active investigation requires longer retention.
9. Telegram and Third-Party Platform Disclosures
The Marketplace relies on Telegram for account authentication, messaging, payment processing (Telegram Stars), and Delivery channels. You should understand the boundary between what we control and what Telegram controls:
- Authentication: We use Telegram login and Mini App identity flows. We store your Telegram user ID, username, and first name for account linking. Telegram processes login data on its own infrastructure.
- Messaging: The Telegram Bot sends you purchase confirmations, Delivery instructions, and support responses through Telegram messaging. Telegram processes message delivery.
- Payments: Purchases use Telegram Stars. Telegram processes the payment transaction. We receive a payment charge ID, amount, and currency for our records.
- Mini App: If you use the Mini App, Telegram provides session context to the Marketplace. We receive only the data needed for Marketplace functions.
We do not control Telegram's infrastructure, terms, or availability. Service disruptions, API changes, Telegram Stars rule changes, or bot suspension by Telegram may affect Marketplace operations. See the Terms of Service for more on Telegram dependency.
Local device storage (localStorage)
The web application stores a Seller authentication token in your browser's localStorage. This token:
- Is used solely to maintain your authenticated Seller session on the Website.
- Persists on your device until you clear your browser's local storage or the token is overwritten.
- Is not a cookie and is not used for tracking, analytics, or advertising.
- Is strictly necessary for the Seller authentication service you requested.
To remove this token, clear your browser's local storage for the Marketplace domain, or use your browser's developer tools to delete the specific localStorage entry.
10. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or incomplete personal data.
- Deletion — ask us to delete your personal data, subject to the exceptions below.
- Restriction — ask us to restrict processing of your data in certain circumstances.
- Objection — object to processing based on our legitimate interests.
- Portability — request your data in a structured, machine-readable format where technically feasible.
- Complaint — lodge a complaint with a supervisory authority in your jurisdiction if you believe your data protection rights have been violated.
Practical choices available now
- Request deletion of interest-form or contact data by emailing [email protected].
- Request account closure by contacting [email protected].
- Disconnect Telegram-linked access where the product supports it.
- Clear your browser's
localStorageto remove the Seller token from your device.
At launch, rights requests are handled by email. We do not currently offer self-serve privacy controls or self-serve account deletion — these may be added later.
DSAR Workflow (Data Subject Access Requests)
Here is how we handle rights requests:
- Submit your request. Send your request to [email protected]. Include your Telegram username or the email address associated with your account so we can locate your data.
- Identity verification. Before processing any request, we verify your identity by confirming your associated Telegram account, purchase history, or other account-linked information. This protects you from unauthorized access to your data.
- Response timing. We aim to respond within 30 calendar days of receiving a verified request. If your request is complex or we are handling a high volume of requests, we may extend this period by up to 60 additional days and will notify you of the extension and the reasons for it.
- Who handles requests. At launch, DSARs are handled directly by the founder or a designated team member. We do not have a dedicated privacy team at this stage — we are a small team and will handle your request personally.
How Deletion and Correction Interact with Other Obligations
We honor deletion and correction requests, but certain data may be retained where we have a legal basis or obligation to do so:
- Active Entitlements: If you request deletion but hold active Entitlements to purchased Skill Bundles, we retain the minimum records needed to continue honoring those Entitlements (Entitlement ID, purchase proof, Delivery status). Full deletion may result in loss of access to purchased content. We will explain your options before proceeding.
- Accounting and tax records: Payment and transaction records subject to statutory retention obligations (tax, accounting) cannot be deleted on request during the applicable retention period (see Section 8).
- Fraud prevention: Records relevant to ongoing or recent fraud investigations may be retained for the duration of the investigation and any resulting enforcement action.
- Active disputes: If your deletion request arrives during an open dispute, Refund claim, or takedown proceeding, we retain relevant records until the matter is fully resolved.
- Correction scope: Correction requests apply to factual inaccuracies in your account or profile data. We are not required to alter transaction records, published review content, or system-generated timestamps in response to a correction request.
11. Children and Age Limits
The Marketplace is not intended for children below the minimum age required by applicable law or Telegram's own platform rules. By using the Marketplace, you confirm that you meet the minimum age requirement in your jurisdiction and are legally able to enter into the applicable agreements. We do not knowingly collect personal data from children. If we learn that we have collected data from a child below the applicable minimum age, we will take steps to delete that data promptly.
12. Ukraine-Specific Compliance Note
The Operator is registered and operates in Ukraine. Ukrainian data protection law — the Law of Ukraine "On Protection of Personal Data" (Law No. 2297-VI) — applies to our processing activities.
Key points:
- We process personal data with a defined lawful basis and purpose, as required by Ukrainian law.
- Ukrainian data subjects have rights under this law, including the right to know what data is processed, to access it, and to request correction or deletion.
- Although the practical enforcement environment in Ukraine differs from the EU, we take our obligations under Ukrainian law seriously and apply them alongside the GDPR-aligned standards described in this policy.
A Ukrainian-language version may be published in the future.
13. How to Contact Us
| Purpose | Contact |
|---|---|
| Privacy and data requests | [email protected] |
| General support | [email protected] |
| Abuse, IP, and takedown reports | [email protected] |
| Legal notices | [email protected] |
| Telegram support | t.me/latand |
Business address: Odesa, Ukraine
For details on privacy rights, see Section 10. For IP and takedown matters, see the IP/Takedown Policy. For Refund and payment issues, see the Refund Policy.
14. Changes to This Policy
We may update this policy as the Marketplace and our practices evolve. When we make material changes, we will notify you through the Website, Telegram Bot, or account notice where feasible. The effective date at the top of this page shows when this version took effect.
We encourage you to review this policy periodically. Continued use of the Marketplace after changes take effect constitutes acceptance of the updated policy, to the extent permitted by applicable law.
Last updated: 2026-03-14