Quidio Privacy Policy

Last updated: 13 July 2026

This Privacy Policy explains how Quidio Ltd, a company registered in England and Wales with company number 17082575 ("Quidio", "we", "us", or "our"), collects, uses, shares, stores, retains, protects, and otherwise processes personal information when you use Quidio.

This policy applies to the Quidio websites, mobile applications, seller tools, AI-assisted listing tools, Quidio-hosted seller pages and storefronts, checkout and order-related features, payment and payout-related features, support services, and related services (together, the "Service").

For data protection law, Quidio Ltd is the controller of personal information processed for the purposes described in this policy, except where another party, such as Stripe, acts as an independent controller for its own services.

1. Who can use Quidio

Quidio is intended only for people aged 18 or over. We do not knowingly allow children to create seller accounts or knowingly collect personal information from anyone under 18.

If we become aware that a person under 18 has provided personal information, we may restrict or delete the relevant account and information, subject to any legal, security, fraud-prevention, dispute, or regulatory retention requirements.

2. Information we collect

We collect personal information when you create or use an account, create or manage listings, purchase an item, communicate with us, use support or safety-reporting functions, connect payment or payout services, or otherwise use the Service.

2.1 Seller account and contact information

This may include:

  • Full legal name.

  • Email address.

  • Telephone number.

  • Address.

  • User ID, account identifier, seller alias, and shop name.

  • Login, authentication, account status, and email-verification information.

  • Communication and account preferences.

  • Information provided through account management, support, safety, or compliance processes.

For seller accounts, we collect the seller's full legal name during sign-up. This is required to create and manage the seller account and may be used for account administration, payout setup, compliance, support, fraud prevention, platform safety checks, legal, security, or audit purposes.

The full legal name is stored against the seller account and may be visible to authorised Quidio users in seller or account-administration views where needed for those purposes. Access is limited to authorised users who need the information for their role.

2.2 Buyer and order information

Buyers may purchase through Quidio as guests without creating a Quidio account. We may collect information needed to process and manage an order, including:

  • Buyer name and email address.

  • Delivery name, delivery address, and related fulfilment information.

  • Items purchased, prices, order totals, and order status.

  • Transaction and payment references.

  • Delivery, dispatch, and tracking information.

  • Refund, chargeback, complaint, dispute, fraud, and risk information.

  • Communications with the seller or Quidio where supported.

Relevant buyer information may be shared with the seller where necessary to fulfil the order, provide delivery, handle support, or resolve a dispute. Seller access should be limited to information reasonably required for those purposes.

2.3 Listing and user content

This may include:

  • Product photographs and other uploaded images.

  • Listing titles, descriptions, categories, attributes, condition details, prices, and seller notes.

  • Corrections, edits, hints, and feedback provided by users.

  • AI-generated titles, descriptions, classifications, and suggested prices.

  • Product identifiers and listing metadata.

  • Public seller profile and storefront information.

  • Buyer-seller or support communications where supported.

Sellers are responsible for reviewing and correcting AI-generated listing content before publishing or relying on it.

2.4 Audio and voice information

Where voice-note or audio features are available, we may collect audio recordings, voice notes, transcriptions, and related metadata to help create or improve a listing or provide the requested feature.

2.5 Transaction, payment, payout, and verification information

Quidio uses Stripe for payment processing, seller payouts, Stripe Connect onboarding, identity verification, fraud checks, and related financial services.

Payment card details, bank-account details, and full identity-verification documents are entered into and handled through Stripe's systems. Quidio does not receive or store full payment card numbers and does not normally receive complete identity-verification documents.

Quidio may receive limited operational information from Stripe, such as:

  • Stripe account, customer, payment, payout, or transaction references.

  • Seller onboarding and verification status.

  • Payment and payout status.

  • Refund, dispute, and chargeback information.

  • Fraud, risk, and account-restriction signals.

  • Other records needed to provide, secure, administer, or reconcile the Service.

Stripe processes information under its own terms and privacy notices where it acts as an independent controller.

2.6 Technical, device, usage, and security information

When you use the Service, we and our service providers may automatically collect:

  • IP address.

  • Device type, operating system, browser, and app version.

  • Language and regional settings.

  • Device, installation, session, and account identifiers.

  • Usage events, product interactions, and referring URLs.

  • Date and time of access.

  • Security, authentication, audit, and activity logs.

  • Crash reports, performance data, and diagnostics.

  • Approximate location derived from technical information, where applicable.

We use this information to operate, secure, monitor, troubleshoot, measure, and improve the Service.

2.7 Information from third parties

We may receive information from third parties that help us provide, secure, or improve the Service, including:

  • Stripe and other payment, payout, verification, and fraud-prevention providers.

  • Cloud hosting, storage, and infrastructure providers.

  • Authentication and email providers.

  • AI providers.

  • Analytics, diagnostics, crash-reporting, monitoring, and security providers.

  • App stores and operating-system providers.

  • Sellers, buyers, or other users who communicate with us or report a concern.

3. AI-assisted features

Quidio uses external AI providers to identify items and generate or improve listing information. Our current provider arrangements may include OpenAI as the primary provider, with Anthropic and Google Gemini available as fallback providers.

Depending on the feature used, we may send product photographs, listing information, seller-provided hints, audio or transcriptions, and related metadata to an AI provider under Quidio's provider account.

We use this information to:

  • Identify and classify items.

  • Generate draft titles and descriptions.

  • Suggest categories, attributes, and prices.

  • Improve image-based listing tools.

  • Detect misuse, prohibited content, fraud, or safety risks.

  • Test, evaluate, secure, and improve Quidio's AI-assisted features.

AI-generated results may be inaccurate or incomplete. Sellers must review listing content before publishing it.

4. How we use personal information

We may use personal information to:

  • Create, verify, authenticate, and manage accounts.

  • Create and manage seller profiles, shops, and listings.

  • Provide AI-assisted listing tools.

  • Process and manage orders, payments, payouts, refunds, delivery, and disputes.

  • Support seller onboarding and Stripe Connect setup.

  • Provide customer support and respond to questions or complaints.

  • Send account, order, payment, payout, security, support, and policy communications.

  • Prevent, detect, and investigate fraud, abuse, prohibited activity, illegal content, and security incidents.

  • Moderate listings and protect users, Quidio, service providers, and third parties.

  • Maintain records required for tax, accounting, legal, regulatory, security, and audit purposes.

  • Enforce our Terms of Use and other policies.

  • Monitor, troubleshoot, measure, and improve the Service.

  • Develop and improve AI-assisted features, product-recognition tools, valuation tools, fraud-prevention tools, analytics, and Product Intelligence.

  • Comply with law, legal process, regulatory requests, and enforceable obligations.

5. Lawful bases

Where UK GDPR or EU GDPR applies, we rely on one or more lawful bases depending on the purpose:

  • Contract: where processing is necessary to create and manage an account, provide seller tools, process an order, provide support, or otherwise deliver the Service.

  • Legal obligation: where processing is required for tax, accounting, regulatory, law-enforcement, or other legal requirements.

  • Legitimate interests: where processing is necessary for security, fraud prevention, platform safety, service administration, product improvement, diagnostics, dispute management, or protecting Quidio and its users, provided those interests are not overridden by individual rights.

  • Consent: where consent is required, including certain marketing, analytics, tracking, audio, or similar activities.

6. Product improvement and Product Intelligence

We may use listing content, item data, images, descriptions, corrections, prices, sale information, transaction-derived insights, and related metadata to improve the Service and develop Product Intelligence.

This may include testing and improving AI models, item-recognition tools, valuation tools, marketplace intelligence, fraud-prevention systems, analytics, APIs, datasets, and model-based services.

Where reasonably possible, we use aggregated, anonymised, de-identified, or non-personal information. Information that identifies an individual, or raw user-submitted content that constitutes personal information, will only be used, shared, licensed, or commercialised where Quidio has an appropriate lawful basis, contractual right, user permission, or other valid legal basis.

7. When we share information

We may share personal information with:

  • Sellers, where buyer information is necessary to fulfil and manage an order.

  • Stripe and other payment, payout, identity-verification, and fraud-prevention providers.

  • Cloud hosting, storage, infrastructure, authentication, email, support, security, analytics, diagnostics, and monitoring providers.

  • AI providers used to process images, listing content, hints, audio, transcriptions, or related data.

  • Professional advisers, auditors, insurers, and legal representatives.

  • Regulators, courts, law-enforcement bodies, or public authorities where required or permitted by law.

  • A buyer, investor, or successor in connection with a merger, acquisition, financing, restructuring, sale of assets, or business transfer, subject to appropriate safeguards.

We may also share information where necessary to enforce our terms, investigate fraud or misuse, protect rights or safety, respond to legal process, or bring or defend legal claims.

We do not sell personal information to data brokers. We do not use personal information for third-party cross-context behavioural advertising unless this is clearly disclosed and any required consent is obtained.

8. Public information

Information included in a public seller profile, storefront, or listing may be visible to anyone who accesses the relevant page or link. This may include the seller's shop name or alias, listing photographs, titles, descriptions, prices, and other information the seller chooses to publish.

Sellers should not include unnecessary personal information in public listings, images, descriptions, or profile content.

9. Cookies, SDKs, analytics, and similar technologies

We may use cookies, browser storage, mobile app storage, SDKs, device identifiers, pixels, and similar technologies to:

  • Keep users signed in.

  • Remember settings and preferences.

  • Secure the Service.

  • Understand product usage.

  • Measure performance.

  • Diagnose errors and crashes.

  • Prevent fraud and abuse.

  • Improve the Service.

  • Support marketing where permitted.

Where required by law, we will request consent before using non-essential cookies, tracking technologies, or similar tools. Further information is provided in the Quidio Cookie Policy.

10. International transfers

Quidio is based in the United Kingdom, but some service providers may process personal information outside the United Kingdom or European Economic Area.

Where required, we use recognised safeguards for international transfers, such as adequacy regulations or decisions, standard contractual clauses, the UK International Data Transfer Agreement, the UK Addendum, or another lawful transfer mechanism.

11. How long we keep information

We keep personal information only for as long as reasonably necessary for the purposes described in this policy, including legal, tax, accounting, fraud-prevention, security, dispute, payment-provider, and regulatory requirements.

Our general retention position is:

  • Account data: for the life of the account and generally for up to 12 months after account closure or deletion.

  • Transaction, payment, tax, and accounting records: generally for 7 years where required for legal, tax, accounting, dispute, or audit purposes.

  • Dispute records: generally for 120 days after completion or until the dispute is resolved, whichever is later, unless longer retention is required.

  • Device and usage data: generally for up to 12 months.

  • Security, fraud, support, and audit records: for as long as reasonably necessary for the relevant security, fraud-prevention, support, legal, or audit purpose.

  • Listings and user content: for as long as required to provide the Service and, after removal or account deletion, where retention remains necessary or permitted for legal, security, fraud-prevention, dispute, backup, or Product Intelligence purposes.

Backups may retain deleted information for a limited period before it is overwritten or securely deleted.

Aggregated, anonymised, de-identified, or non-personal information may be retained for longer where it no longer identifies an individual.

12. Account deletion and data deletion

Users can request account deletion through the app where available or by contacting us.

When an account is deleted, we will delete, anonymise, or de-identify associated personal information where reasonably possible, unless retention is required or permitted for legal, tax, accounting, fraud-prevention, security, dispute, regulatory, payment-provider, backup, or legitimate business purposes.

Deleting an account may remove seller profiles, listings, settings, and user content from active display. It may not remove information that has already been lawfully retained in transaction records, shared with an independent controller, or converted into aggregated, anonymised, de-identified, or non-personal information.

Further information is available at:

https://quidio.ai/account-deletion

13. Your data protection rights

Depending on applicable law and your location, you may have rights to:

  • Request access to personal information.

  • Request correction of inaccurate or incomplete information.

  • Request deletion of personal information.

  • Request restriction of processing.

  • Object to certain processing.

  • Request portability of information.

  • Withdraw consent where processing is based on consent.

  • Object to direct marketing.

  • Complain to a data protection authority.

We may need to verify your identity before responding. Some rights are subject to legal limitations and exemptions.

To exercise your rights, contact contact@quidio.ai.

UK users may also complain to the Information Commissioner's Office.

14. Marketing communications

Where permitted, we may send marketing communications about Quidio. You can unsubscribe using the link in the communication or by contacting us.

Even after opting out of marketing, you may still receive service-related messages, including account, security, order, payment, payout, support, or legal notices.

15. Security

We use technical and organisational measures designed to protect personal information against accidental or unlawful loss, misuse, alteration, unauthorised access, or disclosure.

These measures may include access controls, encryption, secure hosting, authentication controls, monitoring, logging, staff-access restrictions, vendor review, and security-review processes.

No system is completely secure. Users are responsible for protecting their account credentials and should notify us promptly if they suspect unauthorised account access.

16. Third-party services and links

The Service may link to or integrate with third-party services, including Stripe, app stores, delivery providers, and other external services. Their handling of personal information is governed by their own privacy notices and terms where they act independently of Quidio.

17. Changes to this policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date when changes are made.

Where changes are material, we may provide additional notice through the Service, website, app, email, or another appropriate method.

18. Contact us

For privacy questions, requests, or complaints, contact:

Quidio Ltd
Venture House, 2 Arlington Square
Downshire Way
Bracknell, England
RG12 1WA
Company number: 17082575
Email: contact@quidio.ai