Privacy and data handling
Mallello collects only the account, transaction, fulfillment, communication, and attribution data needed to operate the marketplace and applies access, retention, and deletion controls.
What this feature does
Mallello collects only the account, transaction, fulfillment, communication, and attribution data needed to operate the marketplace and applies access, retention, and deletion controls.
This guide describes the behavior implemented by Mallello, the people allowed to use it, and the operational checks that keep it dependable.
Detailed workflow
- Disclose data categories and purposes before or when collected.
- Limit access by role and ownership.
- Use processors such as Supabase, Stripe, Resend, hosting, and mailbox providers under appropriate terms.
- Honor supported access, correction, deletion, and marketing opt-out requests.
- Retain financial, dispute, audit, and legal records only as required.
Rules and permissions
- Deletion can be restricted by legal retention duties and active transactions.
- Analytics and campaign attribution avoid collecting unnecessary full URLs or sensitive content.
- Email suppression records may be retained to ensure no further marketing is sent.
- Cross-border processing and subprocessors require accurate policy disclosure.
Failure handling and edge cases
- Deleting an auth identity before application records are handled can orphan data.
- Exports must authenticate the requester and avoid including other users.
- A breach requires the documented incident and notification process.