FlyerWall

Privacy Policy

Effective date: April 13, 2026

1. Who We Are

FlyerWall is a community classifieds and auction platform operated by WebQ9 ("we", "us", "our"). Our service is available at flyerwall.app.

2. Information We Collect

2.1 Account holders

When you create an account, we collect:

  • Email address and display name (required for account creation).
  • Profile information you provide (optional).
  • Flyer listings you create: titles, descriptions, contact details, images, and location data you enter.
  • Auction activity: bids placed, auctions created, watch lists.
  • Community memberships and roles.
  • Billing status — we store your Stripe customer ID but never your credit card details.

2.2 Visitors (unauthenticated)

  • Standard server logs (IP address, browser type, timestamps) collected by our hosting provider, Vercel.
  • Cookies required for authentication and language preference (see Section 5).

3. How We Use Your Information

  • Provide the service: Display flyers, manage communities, process auction bids.
  • Authentication: Verify your identity when you log in.
  • Notifications: Send emails about auction activity (outbid, won, ending).
  • Billing: Process featured listing and auction commission payments via Stripe.
  • Safety: Prevent fraud, abuse, and shill bidding.

We do not use your data for advertising, profiling, or automated decision-making.

4. Google Sign-In & Google User Data

FlyerWall offers "Sign in with Google" as an authentication option, powered by Google OAuth 2.0 via Supabase Auth.

4.1 Data received from Google

When you choose to sign in with Google, we request the following OAuth scopes and receive:

  • Email address — used as your account identifier and for transactional notifications.
  • Name & profile picture — used to populate your FlyerWall display name and avatar.
  • Google account ID (sub) — used internally to link your Google identity to your FlyerWall account.

We do not request access to Gmail, Google Drive, Google Calendar, or any other Google services. We only request the minimum scopes needed to create and authenticate your account (openid, email, profile).

4.2 How we use Google user data

  • To create and authenticate your FlyerWall account.
  • To display your name and avatar within the app.
  • To send you transactional emails (auction activity, account notices).

4.3 Storage and sharing

Google user data is stored in our Supabase database (EU region). We do not sell, rent, or share your Google user data with any third party, except as necessary to operate the service (Supabase for storage, Resend for email delivery). Data received from Google APIs is not used to train AI/ML models, develop advertising products, or for any purpose beyond operating FlyerWall for the signed-in user.

4.4 Revoking access

You can revoke FlyerWall's access to your Google account at any time via Google Account Permissions. Revoking access does not delete your FlyerWall account; contact privacy@webq9.com to request account deletion.

FlyerWall's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Third-Party Services

6. Cookies

We use only essential cookies:

  • Authentication cookies — managed by Supabase Auth to keep you signed in.
  • Language preference — stores your chosen locale (e.g., "en" or "de").
  • App registration — confirms your account is linked to FlyerWall.

We do not use advertising or analytics cookies. No third-party tracking is employed.

7. Data Retention

  • Account data is retained while your account is active.
  • Flyer listings expire or can be deleted by you at any time.
  • Auction records (bids, outcomes) are retained for legal compliance for 6 years after the auction ends.
  • Server logs are retained for up to 30 days.

8. Your Rights (GDPR)

Under the UK and EU GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate data.
  • Erase your data ("right to be forgotten") — note: auction bid records may be retained for legal compliance.
  • Restrict or object to processing.
  • Data portability.
  • Lodge a complaint with the UK ICO or your local data protection authority.

To exercise any of these rights, email privacy@webq9.com.

9. Data Security

We use industry-standard measures to protect your data: encrypted connections (TLS), Row Level Security in our database, hashed passwords, and secure environment variable management. However, no method of transmission over the Internet is 100% secure.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users by email of material changes at least 14 days before they take effect.

11. Contact

For privacy enquiries, contact us at privacy@webq9.com.