allstarbids.com

Privacy Policy

1. Introduction

Welcome to AllStarBids.com (“AllStarBids,” “we,” “us,” or “our”). AllStarBids operates an online auction marketplace that enables registered users worldwide to buy, bid on, and sell collectibles, trading cards, memorabilia, and related goods. The Platform is owned and operated from the Province of Ontario, Canada.

The present Privacy Policy (“Policy”) explains how we collect, use, disclose, store, retain, and protect your personal information when you access or use our website located at allstarbids.com, our services, and all related features and tools (collectively, the “Services”). It also describes the rights available to you regarding your personal information and how you may exercise them.

By accessing the Platform, creating an account, or otherwise using the Services, you acknowledge that you have read and understood this Policy. Where your consent is required as a legal basis for processing, your continued use of the Services following publication of any amendments shall constitute your acceptance of the revised Policy.

2. Governing Privacy Legislation

AllStarBids processes personal information in compliance with the following privacy and data protection frameworks, as applicable to the individual User based on jurisdiction of residence:

Canada: The Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (“PIPEDA”), together with the Breach of Security Safeguards Regulations, SOR/2018-64.

European Union: Regulation (EU) 2016/679 of the European Parliament and of the Council (the “General Data Protection Regulation” or “GDPR”).

United Kingdom: The UK General Data Protection Regulation (“UK GDPR”) as retained under the Data Protection Act 2018.

United States: The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CCPA/CPRA”), where applicable.

Where a conflict arises between the provisions of this Policy and any mandatory requirement under applicable law, the applicable legal requirement shall prevail.

3. Scope of Application

This Policy applies to all visitors to allstarbids.com, registered Buyers and Sellers, account holders, and individuals who contact us through any channel. It governs the processing of personal information collected through the Platform, including information provided directly by Users, information collected automatically through technological means, and information received from third-party sources.

This Policy does not apply to the practices of third-party websites, services, or platforms linked from or integrated with AllStarBids, each of which is governed by its own privacy policy. Users are encouraged to review the privacy policies of any third-party service they access.

4. Information We Collect

4.1 Information You Provide Directly

When you register for an account, create listings, place bids, or communicate with us, we may collect the following categories of personal information: full legal name; username; email address; telephone number; billing and shipping address; credit card and payment information (processed through secure third-party payment processors); government-issued identification (where required for identity verification); tax identification numbers (where required by law); seller account and business information; auction listings, item descriptions, and photographs; and communications with customer support.

4.2 Information Collected Automatically

When you access or interact with the Services, we may automatically collect certain technical and usage information through cookies and similar tracking technologies (as described in our Cookie Policy), including: IP address; device type, model, and unique device identifiers; browser type and version; operating system; pages visited and time spent on each page; auction activity, bidding history, and watchlist interactions; referral URLs and exit pages; log data and error reports; and geographic location inferred from IP address. Where third-party advertising services are enabled on the Platform, including Google AdSense operated by Google LLC, additional data points may be collected automatically, such as advertising identifiers, ad interaction and click-through data, and interest-based profiling information, as governed by the applicable third-party provider’s own privacy policy.

4.3 Information from Third Parties

We may receive personal information about you from the following categories of third-party sources: identity verification providers; fraud prevention and risk assessment services; payment processors; marketing and analytics partners; and social media platforms (where you interact with our Services through social media integrations).

5. Purposes of Collection and Use

We collect and use personal information for the following specific purposes:

5.1 Provision and Administration of Services. Creating, maintaining, and administering user accounts; facilitating auctions, bidding, and transactions; processing the 9.5% marketplace operations commission; issuing settlement invoices; enabling post-auction communication between Buyers and Sellers; and providing customer support.

5.2 Security, Fraud Prevention, and Trust. Verifying user identity; detecting and preventing fraudulent bidding, listing, or selling activity; monitoring suspicious account behaviour; enforcing our Terms of Service, User Agreement, Buyer Agreement, and Seller Agreement; and administering our trust and safety programme.

5.3 Legal and Regulatory Compliance. Complying with applicable tax reporting obligations; fulfilling anti-money laundering requirements; responding to lawful requests from law enforcement or regulatory authorities; maintaining records as required by PIPEDA’s breach of security safeguards record-keeping obligations (SOR/2018-64); and enforcing or defending legal claims.

5.4 Platform Improvement and Analytics. Analysing user behaviour and engagement patterns to improve website performance, functionality, and the user experience; conducting internal research; developing new features; and generating aggregated, de-identified statistical reports.

5.5 Communications. Sending transactional messages, including account confirmations, bid confirmations, auction notifications, and settlement invoices; and, where you have provided express consent in accordance with Canada’s Anti-Spam Legislation, S.C. 2010, c. 23 (“CASL”), sending commercial electronic messages relating to upcoming auctions, promotions, and platform updates.

5.6 Advertising. Delivering advertisements through third-party advertising platforms integrated with the Platform, including Google AdSense operated by Google LLC; measuring advertisement performance, impressions, and engagement metrics; supporting interest-based and contextual advertising where the User has provided consent in accordance with applicable law; and analysing advertising effectiveness for the purpose of improving the relevance of advertisements displayed on the Platform.

6. Legal Bases for Processing

For Users in the European Union and the United Kingdom, we process personal data on the basis of one or more of the following lawful grounds under the GDPR and UK GDPR:

Performance of a Contract: Processing that is necessary to perform our obligations under the Terms of Service, User Agreement, Buyer Agreement, or Seller Agreement, or to take pre-contractual steps at your request.

Legitimate Interests: Processing that is necessary for our legitimate interests (or those of a third party), provided that such interests are not overridden by your rights and freedoms. Our legitimate interests include fraud prevention, platform security, enforcement of our policies, and business analytics.

Legal Obligation: Processing that is necessary to comply with a legal obligation to which we are subject, including tax reporting, anti-money laundering requirements, and breach notification obligations.

Consent: Processing that is based on your freely given, specific, informed, and unambiguous consent, including the use of non-essential cookies and the sending of marketing communications. You may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

For Users in Canada, we rely on the knowledge and consent of the individual as the primary basis for collection, use, and disclosure of personal information, in accordance with Principle 3 of Schedule 1 to PIPEDA, except where an exemption to the consent requirement applies under the Act.

7. Sharing and Disclosure of Information

We may share personal information with the following categories of recipients, and only to the extent necessary for the purposes identified in Section 5:

7.1 Service Providers. Third-party vendors that provide services on our behalf, including payment processors, cloud hosting and storage providers, analytics platforms, email service providers, fraud detection services, and identity verification providers, and advertising network providers, including Google AdSense (operated by Google LLC), which may collect and process User data in connection with the delivery of advertisements on the Platform in accordance with Google’s Privacy Policy, available at https://policies.google.com/privacy. All service providers are bound by contractual obligations to protect your personal information and to use it solely for the purposes for which it was disclosed.

7.2 Other Users. In connection with completed auctions, certain information is shared between Buyers and Sellers to facilitate transaction completion, as described in the Terms of Service and User Agreement. Publicly visible information on the Platform may include your username, auction listings, and bid history (as displayed on the Site). Sensitive personal information is not publicly displayed.

7.3 Legal Authorities. We may disclose personal information when required to do so by law, regulation, subpoena, court order, or governmental request, or where we believe in good faith that disclosure is necessary to protect our rights, your safety, the safety of others, or to investigate fraud or respond to a government request.

7.4 Business Transfers. In the event of a merger, acquisition, reorganization, asset sale, or similar transaction, personal information may be transferred as part of that transaction. We will provide notice before personal information becomes subject to a different privacy policy.

8. International Data Transfers

AllStarBids operates globally, and your personal information may be transferred to, stored in, and processed in countries outside your country of residence, including Canada and other jurisdictions where our service providers maintain infrastructure. Where personal information originating from the European Economic Area, the United Kingdom, or Switzerland is transferred to a country that has not received an adequacy decision from the European Commission or the UK Secretary of State, we implement appropriate safeguards, including Standard Contractual Clauses approved by the European Commission (Commission Implementing Decision (EU) 2021/914), to ensure an adequate level of protection.

For Users in Canada, we ensure that personal information transferred to third parties outside Canada for processing receives a comparable level of protection, in accordance with Principle 1 (Accountability) of Schedule 1 to PIPEDA and guidance issued by the Office of the Privacy Commissioner of Canada.

9. Data Retention

We retain personal information only for as long as reasonably necessary to fulfil the purposes for which it was collected, as identified in this Policy, or as required or permitted by applicable law. Specific retention periods are determined based on the following criteria:

Account Information: Retained for the duration of your active account and for a period of five (5) years following account closure or termination, to comply with legal, tax, and regulatory obligations and to resolve any disputes that may arise.

Transaction Records: Retained for a minimum of seven (7) years following the date of the transaction to satisfy tax reporting and audit requirements under the Income Tax Act, R.S.C. 1985, c. 1 (5th Supp.), and equivalent legislation in other jurisdictions.

Breach Records: Retained for a minimum of twenty-four (24) months following the date of discovery, in compliance with the Breach of Security Safeguards Regulations, SOR/2018-64, under PIPEDA.

Marketing Consent Records: Retained for as long as the consent remains valid, and for a reasonable period thereafter to demonstrate compliance with CASL.

Automated Data (Logs, Analytics): Retained for up to twenty-four (24) months, unless a longer period is necessary for security investigation or legal proceedings.

Upon expiration of the applicable retention period, personal information will be securely deleted, destroyed, or de-identified in accordance with our internal data disposal procedures.

10. Children’s Privacy

The Services are not directed at, and are not intended for use by, individuals under eighteen (18) years of age. AllStarBids does not knowingly collect, solicit, or process personal information from minors. If we become aware that we have collected personal information from a person under eighteen (18), we will take prompt steps to delete such information from our systems. If you believe that a minor has provided personal information to AllStarBids, please contact us immediately at support@allstarbids.com.

11. Security Measures

We implement and maintain reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, destruction, loss, and theft. Measures employed include, but are not limited to: encryption of personal information in transit and at rest using industry-standard protocols; access controls limiting personnel access to personal information on a need-to-know basis; secure server infrastructure with firewalls and intrusion detection systems; regular security assessments and vulnerability testing; and employee training regarding data protection responsibilities.

While we take commercially reasonable steps to protect your personal information, no method of electronic transmission or storage is entirely secure, and we cannot guarantee absolute security. In the event of a breach of security safeguards involving personal information under our control that creates a real risk of significant harm to an individual, we will comply with the notification requirements set forth in sections 10.1 through 10.3 of PIPEDA and the Breach of Security Safeguards Regulations, SOR/2018-64, and with equivalent requirements under the GDPR (Articles 33 and 34), the UK GDPR, or other applicable legislation.

12. Your Privacy Rights

Depending on your jurisdiction of residence, you may have some or all of the following rights regarding your personal information:

Right of Access: The right to request confirmation of whether we process your personal information and to obtain a copy of such information.

Right to Rectification: The right to request correction of inaccurate or incomplete personal information.

Right to Erasure (Right to Be Forgotten): The right to request deletion of your personal information, subject to applicable legal retention requirements.

Right to Restriction of Processing: The right to request that we restrict the processing of your personal information in certain circumstances.

Right to Object: The right to object to processing based on legitimate interests or for direct marketing purposes.

Right to Data Portability: The right to receive your personal information in a structured, commonly used, and machine-readable format and to transmit it to another controller.

Right to Withdraw Consent: Where processing is based on consent, the right to withdraw such consent at any time, without affecting the lawfulness of processing prior to withdrawal.

Rights Under PIPEDA: Canadian residents have the right to access their personal information held by AllStarBids, to challenge its accuracy and completeness, and to have it amended as appropriate, in accordance with Principles 9 and 10 of Schedule 1 to PIPEDA.

Rights Under the CCPA/CPRA: California residents may have additional rights, including the right to know what personal information is collected, disclosed, or sold; the right to request deletion; the right to opt out of the sale or sharing of personal information; and the right to non-discrimination for exercising their privacy rights.

To exercise any of the foregoing rights, please contact us at support@allstarbids.com. We will respond to verifiable requests within the timeframes prescribed by applicable law. We may request reasonable verification of your identity before processing your request.

13. Cookies and Tracking Technologies

AllStarBids uses cookies and similar tracking technologies as described in our Cookie Policy, which should be read in conjunction with this Privacy Policy. You may manage your cookie preferences through the cookie consent mechanism presented upon your first visit to the Site (where required by law) and through your browser settings. Please note that disabling essential cookies may impair the functionality of certain features, including bidding and account access. Where Google AdSense is enabled on the Platform, Google may place cookies and similar tracking technologies on your device for the purpose of serving personalized or contextual advertisements, measuring advertisement performance, and conducting interest-based audience profiling. Data collected and processed by Google in connection with AdSense is governed by Google’s Privacy Policy, available at https://policies.google.com/privacy, and by Google’s Advertising Privacy Terms. You may manage your Google advertisement personalization preferences at https://myadcenter.google.com. For Users located in the European Union or the United Kingdom, AdSense advertising cookies will only be activated after you have provided explicit consent through the Platform’s cookie consent mechanism, in accordance with the ePrivacy Directive and applicable national transpositions thereof.

14. Third-Party Links and Integrations

The Platform may contain links to third-party websites, services, or applications that are not owned or controlled by AllStarBids. We are not responsible for the privacy practices, content, or security of any third-party site. We encourage you to review the privacy policy of every third-party service you access through or in connection with the Platform.

15. Changes to This Privacy Policy

We may update this Policy from time to time to reflect changes in our practices, applicable law, or regulatory guidance. When material changes are made, we will revise the “Last Updated” date at the top of this document and, where required by law, notify you through reasonable means, which may include email notification or a prominent notice upon login. Your continued use of the Services following publication of any amendments constitutes acceptance of the revised Policy to the extent permitted by applicable law.

16. Contact Information and Privacy Inquiries

If you have any questions, concerns, or complaints regarding this Privacy Policy or our handling of your personal information, or if you wish to exercise any of your privacy rights, please contact us at:

Email: support@allstarbids.com
Website: https://allstarbids.com.

If you are located in Canada and are not satisfied with our response to your privacy inquiry, you may file a complaint with the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca.

If you are located in the European Union or the United Kingdom and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.