Privacy Policy
Last updated: 1 January 2025
CashTo Ltd ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard information when you use the CashTo platform at cashto.co.
1. Data Controller
CashTo Ltd is the data controller for personal data collected through this platform. We are registered in England and Wales. Contact: hello@cashto.co.
2. What Data We Collect
Seller data:
- Name, email address, and profile information you provide on registration
- Stripe account details (account ID, onboarding status) — stored securely via Stripe Connect
- Listing details (titles, descriptions, images, prices)
Buyer data:
- Name, email address, and delivery address entered at checkout
- Payment details — processed and stored solely by Stripe; CashTo never sees card numbers
- Order and transaction records associated with purchases
Usage data:
- Page views and listing views (anonymised counters)
- Browser type and device information via standard server logs
3. How We Use Your Data
- To operate the platform and facilitate payments between sellers and buyers
- To communicate with you about your account, orders, and platform updates
- To comply with legal obligations including fraud prevention and financial regulation
- To improve the platform and user experience
4. Legal Basis for Processing
We process personal data on the following legal bases under UK GDPR:
- Contract: to fulfil our service agreement with you
- Legitimate interests: fraud prevention, platform security, and improving our services
- Legal obligation: compliance with applicable law
5. Sharing Your Data
We do not sell your personal data. We share data only with:
- Stripe: our payment processor. Stripe handles all card data and identity verification under their own Privacy Policy.
- Law enforcement or regulators when required by law.
6. Data Retention
We retain your account data for as long as your account is active. Transaction records are retained for 7 years to comply with UK financial regulations, even after account deletion. You may request deletion of other personal data by contacting us.
7. Your Rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request erasure of your data (subject to legal retention requirements)
- Object to processing or request restriction of processing
- Data portability
- Lodge a complaint with the ICO (Information Commissioner's Office) at ico.org.uk
8. Cookies
CashTo uses a session cookie to keep you logged in to your seller account. This is a strictly necessary cookie and does not require consent. We do not use tracking or advertising cookies.
9. Security
We use industry-standard security practices including HTTPS encryption for all data in transit. Payment data is handled exclusively by Stripe and is never stored on CashTo servers.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email. Continued use of the platform constitutes acceptance of the updated policy.
11. Contact Us
For any privacy-related enquiries or to exercise your rights, contact us at hello@cashto.co.
See also: Terms & Conditions