Pre-launch privacy notice. This Privacy Policy is a working version for the MVP landing page. It must be replaced or confirmed by qualified privacy counsel before analytics, accounts, payments, KYC, marketing automation, advertising pixels, cookies beyond essential use or marketplace sales are activated.
1. Who is responsible for the data
The final data controller must be identified before commercial launch. Until then, the pre-launch project team operating the 1MP validation website handles reservation-interest communications and project enquiries.
2. What data the MVP may collect
The MVP may let visitors generate an email expressing interest. Depending on what the visitor enters, this may include name, brand name, email address, country, interested package, message, intended URL and any voluntary information included in the message.
The current form is designed to open the visitor’s email application. If a visitor sends the email, the information is handled through the sender’s email provider and the recipient email account configured by 1MP.
3. Technical and hosting data
The hosting provider, browser and security infrastructure may process technical data such as IP address, device type, browser type, referring page, access time, pages visited, error logs, security logs and performance information. This may be necessary to serve the website, detect abuse and maintain security.
4. No payment, account or KYC data in the MVP
The current MVP does not collect card details, does not process payments, does not create user accounts, does not perform identity checks and does not run winner verification. Those functions require separate privacy disclosures, processor agreements, security controls and retention rules before launch.
5. Cookies and similar technologies
The current website should only use technologies necessary to operate the page unless analytics or marketing tools are intentionally added. If cookies, analytics, advertising pixels, heatmaps or tracking tools are added, a separate Cookie Policy and consent mechanism may be required depending on the user’s location.
6. Purposes of processing
- Responding to enquiries and reservation interest.
- Evaluating demand and commercial viability.
- Preparing the marketplace launch and prioritising interested buyers.
- Improving the website, messaging and product roadmap.
- Preventing spam, fraud, abuse and security incidents.
- Documenting communications and legal/commercial decisions.
7. Possible legal bases
Depending on the final operator and user location, processing may rely on consent, steps requested before entering into a contract, legitimate interests, legal obligations or another lawful basis. The final policy must map each processing activity to the appropriate legal basis.
8. Sharing of data
Data may be handled by hosting providers, email providers, security providers, technical contractors, legal advisors, tax advisors and future payment, KYC or moderation providers. The final launch must identify key processors or categories of processors and put required agreements in place.
9. International transfers
Because the website may be viewed globally and providers may operate in multiple countries, personal data may be processed outside the visitor’s country. The final policy must define transfer safeguards where required, especially for users in the European Economic Area, the United Kingdom or other regulated privacy jurisdictions.
10. Data retention
| Data category | Indicative MVP retention | Reason |
|---|---|---|
| Reservation emails | Until no longer needed for pre-launch follow-up or until deletion is requested, subject to lawful retention needs. | Responding to interest and documenting communications. |
| Technical logs | According to hosting/security provider settings. | Security, debugging and abuse prevention. |
| Legal correspondence | As reasonably needed for legal, tax or dispute purposes. | Compliance and evidence. |
11. User rights
Depending on applicable law, users may have rights to access, correct, delete, restrict, object to processing, withdraw consent, request portability and lodge a complaint with a supervisory authority. EU data protection rules recognise rights including information, access, rectification and erasure for personal data processing. Final operational procedures must be established before launch.
12. Children
The MVP is not intended for children. The future marketplace should set a minimum age and implement additional controls if required by the jurisdictions in which it operates.
13. Security
1MP should use appropriate technical and organisational measures such as secure hosting, access control, backups, malware protection, encrypted connections, least-privilege access and admin account protection. No internet service can guarantee absolute security.
14. Future marketplace privacy changes
Before commercial launch, the privacy framework must cover accounts, billing data, invoices, payment providers, tax data, moderation logs, content uploads, buyer dashboards, fraud prevention, KYC/KYB, country restrictions, prize eligibility if applicable and data subject request workflows.
15. Contact
Privacy questions can be sent to the contact email configured on the 1MP website. Final controller details, privacy contact and any required DPO or representative details must be added before launch.