Privacy Policy
BeForAll · Last updated: 24 August 2026
This Privacy Policy explains how personal data is collected, used, shared, stored and protected when users interact with BeForAll.
1. Information We Collect
Account and profile data
- email address, user ID and account status;
- display name, username, profile image and profile information;
- authentication and account-recovery information handled through services such as AWS Cognito;
- security, session and access metadata reasonably necessary to protect accounts.
Seller and creator data
- creator or brand name, description, country, city, website and social-profile information;
- Private or Professional Seller status;
- application, approval, verification and moderation information;
- logo, banner and other Seller images;
- business, identity, registration, tax, VAT or product-safety information where required for lawful marketplace operation, payment onboarding or regulatory reporting.
Product and image data
- Product names, descriptions, prices, stock, sizes, materials and categories;
- Product photographs and other uploaded images;
- AI-generated or AI-edited Product-cover outputs where a user chooses an AI feature;
- reviews, ratings and other submitted content.
Shopping, order and delivery data
- favourites, cart activity and recently viewed items where supported;
- Orders, Order items, status history, timestamps and transaction references;
- delivery name, phone number, address, city and postal code;
- courier selections, pickup-point information, tracking numbers and tracking status;
- returns, refunds, size exchanges, return destinations, evidence and status history;
- Buyer Protection, settlement and payout-status information needed to operate the marketplace.
Messages, reports and support
- messages and conversation metadata;
- follow relationships and similar social interactions;
- reports concerning users, Sellers, Products or messages;
- support communications and evidence supplied for disputes or claims.
Payment data
Payments and Seller onboarding are processed through Stripe Connect or another notified payment provider. BeForAll may receive transaction IDs, payment status, refund information, connected-account identifiers, payout status and limited payment metadata. BeForAll does not store complete card numbers or card security codes on its own systems.
Device and security data
BeForAll may process device or app identifiers, push-notification tokens, request metadata, timestamps, security events, authentication events and logs where necessary to provide the service, prevent fraud, diagnose failures and protect users.
Photo-library access and sensitive categories
BeForAll may access images selected by a user when the user chooses an upload feature and grants the relevant system permission or selection access. BeForAll does not intentionally collect health data, biometric templates, microphone recordings or precise continuous GPS location unless a future feature clearly requires such data and users are appropriately informed.
2. How We Use Information
- to create, authenticate, secure and recover accounts;
- to operate profiles, Seller applications and Listings;
- to process Orders, delivery, tracking, Buyer Protection, returns, refunds and exchanges;
- to process payments and Seller payouts;
- to provide messaging, reviews, social features and support;
- to generate or edit Product-cover images when a user requests an AI image feature;
- to detect fraud, abuse, unsafe Products and policy violations;
- to send transactional email and push notifications;
- to comply with legal, tax, accounting, consumer, product-safety and regulatory obligations;
- to maintain, debug and improve App reliability and security.
3. Legal Bases Under GDPR
- Contract where processing is necessary to provide an account, marketplace transaction, Seller service, Order, return, messaging or requested feature.
- Legal obligation where records or processing are required for tax, accounting, consumer protection, product safety, regulatory reporting or lawful requests.
- Legitimate interests for proportionate fraud prevention, security, abuse prevention, platform integrity, dispute handling and service improvement.
- Consent where legally required for optional permissions or communications.
4. Service Providers and Recipients
BeForAll does not sell personal data. Data may be shared where necessary with:
- AWS for cloud hosting, authentication, storage, databases, serverless processing and email infrastructure;
- Stripe for payments, connected Seller accounts, fraud controls, refunds, disputes and payouts;
- couriers and tracking providers, including services such as 17TRACK, to fulfil or track Orders and returns;
- Sellers and Buyers to the extent necessary to complete an Order, return or exchange;
- AI/image-processing providers when a user chooses an AI image feature;
- Apple and push-notification infrastructure where necessary for App distribution, Sign in with Apple or push delivery;
- professional advisers, regulators, courts or law-enforcement authorities where lawfully necessary.
5. Payments and Stripe
Stripe may process identity, business, payment, card, bank, fraud-prevention, transaction and payout information under its own privacy terms and legal obligations. Some Stripe processing may be carried out as an independent controller.
6. Shipping and 17TRACK
BeForAll may send or receive tracking numbers, carrier information and shipment-status information through couriers or tracking providers such as 17TRACK. Tracking data may update an Order automatically, trigger Buyer Protection timing, confirm delivery of an original shipment or return, begin refund processing or complete an exchange workflow.
7. Images and AI Processing
Users and Sellers may upload profile images, logos, banners and Product photographs. Where a user voluntarily selects an AI image or cover feature, the selected Product image and related instructions may be transmitted to an AI/image-processing service to generate the requested output, subject to the provider arrangements in place at that time.
8. Messages, Reports and Moderation
Messages, reports and evidence may be processed to deliver communications, investigate complaints, enforce platform rules, prevent fraud and protect users. Relevant information may be preserved or disclosed where required or permitted by law.
9. Push Notifications and Email
BeForAll may use device push tokens and email addresses to send transactional communications concerning security, Orders, messages, shipping, delivery, returns, refunds, exchanges and other service events. Marketing communications, if introduced, will be handled separately with any legally required consent or opt-out.
10. International Transfers
Some service providers may process personal data outside Cyprus or the European Economic Area. Where GDPR transfer restrictions apply, BeForAll will rely on an applicable lawful transfer mechanism such as an adequacy decision, standard contractual clauses or another recognised safeguard.
11. Data Retention
BeForAll keeps personal data only as long as reasonably necessary for the purposes described and for applicable legal, tax, accounting, consumer, safety, fraud-prevention and dispute-resolution requirements. Account deletion does not necessarily require immediate deletion of every transaction or security record where retention is required or permitted by law.
12. Your GDPR Rights
- access personal data;
- correct inaccurate data;
- request deletion;
- request restriction;
- object to certain processing;
- receive portable data where the legal conditions apply;
- withdraw consent where processing is based on consent;
- lodge a complaint with a competent data-protection authority.
- access personal data;
- correct inaccurate data;
- request deletion;
- request restriction;
- object to certain processing;
- receive portable data where the legal conditions apply;
- withdraw consent where processing is based on consent;
- lodge a complaint with a competent data-protection authority.
Users may lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus. Website: https://www.dataprotection.gov.cy/
13. Security
BeForAll uses technical and organisational safeguards designed to protect personal data, including managed authentication, controlled cloud access, encryption capabilities, logging, access controls and specialised payment providers. No online service can guarantee absolute security.
14. Children
BeForAll is not intended to enable children to enter marketplace contracts independently where they lack legal capacity. Where parental or guardian involvement is required, users must comply with that requirement.
15. Changes
This Policy may be updated when BeForAll changes its services, providers, data practices or legal obligations. Material changes will be communicated where required.
16. Contact
Data controller: Adamos Kyriakou
Platform: BeForAll
Registered business name: BFALL MARKETPLACE
Place of business and correspondence address: Digeni Akrita 27B & Nafpaktou 2, Pelecanos Court 10, Office 202, Agios Antonios, 1055 Nicosia, Cyprus
Country: Cyprus
Email: [email protected]