Skip to main content
Etalo

Privacy Policy

Last updated: 14 June 2026

This Privacy Policy explains how Etalo (“Etalo”, “we”, “us”) processes personal data when you use the Etalo marketplace at etalo.xyz and inside MiniPay. Two layers of law apply, and we comply with both: because our operator is established in the EU, the EU General Data Protection Regulation (GDPR) applies; and because you use Etalo from an African market, your country’s data-protection law also applies — in our launch markets, Nigeria’s Data Protection Act 2023, Ghana’s Data Protection Act 2012 (Act 843), and Kenya’s Data Protection Act 2019. Where these differ, we apply the higher standard. Etalo is a non-custodial platform: payments are held by audited smart contracts on the Celo blockchain, never by us.

1. Who is responsible (data controller)

The data controller is Etalo, operated from Belgium. For any privacy request, contact us at support@etalo.xyz. The registered legal entity and address are set out in our Terms of Service.

2. What data we collect

We collect only what is needed to run the marketplace:

  • Wallet address — the public Celo address you connect with, used to identify your account, route orders, and track seller reputation.
  • Seller profile (if you sell) — shop name, shop handle, country, description, logo, and any social links you add (Instagram, TikTok, and a WhatsApp number used for order notifications).
  • Product listings — titles, descriptions, prices, stock, and photos you upload.
  • Delivery details (when you buy) — recipient name, phone number, country, city, neighbourhood/area, and address, captured at checkout so the seller can ship to you.
  • Dispute information — messages and evidence you submit if you open or respond to a dispute.
  • Technical data — IP address and basic request metadata in our hosting logs, and your device/wallet type, used for security and reliability.
  • Local device storage — your cart, theme, and notification “last seen” markers are kept in your browser’s local storage. We do not use advertising or tracking cookies.

3. Why we use it and our legal bases

  • To perform our contract with you (GDPR Art. 6(1)(b)) — create your account, list products, process orders and escrow, enable delivery, and handle disputes.
  • Our legitimate interests (Art. 6(1)(f)) — prevent fraud and abuse, keep the service secure, maintain seller reputation, and send transactional notifications.
  • Your consent (Art. 6(1)(a)) — where you choose to add optional details such as social links, which you can remove at any time.
  • Legal obligations (Art. 6(1)(c)) — where we must retain records to comply with applicable law.

4. Blockchain data is public and permanent

Some information is recorded on the Celo public blockchain by the smart contracts — including wallet addresses, order amounts, commission, order status, and dispute records. Blockchain data is public, decentralised, and immutable: it cannot be changed or deleted by us or anyone else. Please keep this in mind before transacting. We never publish your delivery address, phone number, or name on-chain.

5. Who we share data with (processors)

We do not sell your data. We share it only with service providers that process it on our behalf, under contract:

  • Pinata — stores product images and logos on IPFS. IPFS content is public and content-addressed; once pinned it can be unpinned but is not guaranteed to be erased. Do not put identifying information in product photos.
  • Twilio — sends WhatsApp order notifications to the seller’s WhatsApp number and the buyer’s delivery phone.
  • Vercel — hosts and serves the web app.
  • Fly.io — hosts our backend service and PostgreSQL database (off-chain profile, product, order, and dispute metadata).
  • The Celo network — a public blockchain that records on-chain transactions (see section 4).

6. International transfers

Some of our processors are located outside the European Economic Area (for example in the United States, and our backend region is in Africa). Where data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision. Blockchain data is, by design, replicated globally across public nodes.

7. How long we keep it

Off-chain account and listing data is kept while your account is active and for as long as needed to provide the service. Order and dispute records are retained for the period required to resolve disputes and meet legal and accounting obligations, then deleted or anonymised. On-chain data is permanent and outside our control.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased — note that data already written to the public blockchain cannot be deleted (section 4);
  • restrict or object to certain processing;
  • receive your data in a portable format;
  • withdraw consent at any time, without affecting prior processing.

To exercise any right, email support@etalo.xyz. You also have the right to complain to the data-protection authority in your country:

  • Nigeria — Nigeria Data Protection Commission (NDPC).
  • Ghana — Data Protection Commission (DPC).
  • Kenya — Office of the Data Protection Commissioner (ODPC).
  • EU/EEA — your local authority, or, for our operator, the Belgian Data Protection Authority (Rue de la Presse 35, 1000 Brussels, dataprotectionauthority.be).

9. Security

We use encryption in transit (HTTPS), access controls on our database, and a least-privilege backend. No system is perfectly secure; you are responsible for safeguarding your wallet and its keys, which Etalo never holds.

10. Children

Etalo is not intended for anyone under 18, and we do not knowingly collect data from children.

11. Changes to this policy

We may update this policy; the “Last updated” date above will change and, for material changes, we will surface a notice in the app. Questions? Email support@etalo.xyz.