Privacy Policy
Last updated: 30 May 2026
This policy explains how Rewear Malta ("Rewear", "we", "us") collects and uses personal information when you use rewearmalta.com, our iOS app, and related services. By using Rewear, you agree to this policy. For marketplace rules, see our Terms of Service.
1. Who this applies to
Rewear is a local marketplace for pre-loved fashion, focused on Malta. This policy covers buyers, sellers, and visitors who browse or create an account on the web or in our native iOS app. The same account and data apply across web and app unless we say otherwise.
2. Information we collect
Account and profile. When you sign up, we collect information such as your email address, display name, username, and profile details you choose to add. If you use social or email sign-in, our authentication provider processes credentials on our behalf.
Marketplace activity. We store listings you create (descriptions, prices, photos, status), messages you send or receive, favourites, follows, offers, and similar in-app actions. Other users can see information you publish on the marketplace according to normal product behaviour (for example, public listings and profile fields).
Photos and media. Listing and chat images you upload are stored so we can show them to you and other users. On mobile, you may grant access to the camera or photo library only when you choose to capture or pick an image.
Location. We do not track your location in the background. If you choose to share a meetup location in chat, the app may request location access at that moment to attach a place to your message.
Notifications. If you enable push notifications, we store a device token or web push subscription linked to your account so we can deliver alerts about messages, favourites, listing updates, and similar events. You can control notification categories in your account settings.
Seller billing.If you subscribe to Premium or Pro, buy boost credits, or manage billing, payment is processed by Stripe. We receive subscription status, billing period dates, and related metadata — not your full card number. On iOS, where Apple's EU external purchase rules apply, we may also record that you saw Apple's disclosure and receive compliance tokens associated with that flow.
Shop integrations. Pro sellers who connect Shopify or WooCommerce provide shop domain or store URL and access credentials (stored encrypted) so we can sync inventory. Disconnecting removes ongoing access according to our integration flow.
Technical and usage data. We collect logs and analytics needed to run the service securely — for example IP address, browser or app user agent, device type, pages or screens viewed, and product events (such as searches or checkout starts). We use this to debug issues, measure performance, and understand how features are used.
Support and email. If you contact us or join a waitlist, we use your email and message content to respond. We may send transactional email about your account, billing, or security.
3. How we use information
- Provide the marketplace — accounts, listings, search, chat, and shops
- Process seller subscriptions, boosts, and related entitlements
- Send notifications you have opted into
- Keep Rewear secure, prevent abuse, and enforce our terms
- Improve reliability and product experience through analytics
- Comply with law, tax, and payment obligations where applicable
4. Legal bases (EEA / UK users)
Where GDPR applies, we rely on: contract (to provide the service you signed up for); legitimate interests (security, analytics, improving the product — balanced against your rights); consent (where required, for example optional notifications or certain permissions); and legal obligation where we must retain or disclose data.
5. iOS app permissions
The Rewear iOS app may ask for permission to use the camera, photo library, or location only in context (for example, adding listing photos or sharing a meetup spot). You can decline; features that need those permissions will not work until you allow them in iOS Settings. Push notifications are optional and can be turned off in the app or in system settings.
6. Payments
Seller plans and boost purchases are billed through Stripein EUR. Stripe's privacy policy applies to payment details you enter on their checkout pages. On iPhone, checkout may open in your browser (including Apple's external purchase disclosure where required). Buyer-to-seller payments for items are arranged between users unless we introduce integrated checkout later.
7. Service providers
We use trusted processors to run Rewear. They access data only to perform services for us:
- Supabase — authentication, database, and file storage
- Stripe — payments and billing portal
- Vercel — hosting and infrastructure
- PostHog — product analytics (where enabled)
- Resend — transactional and service email
- Apple — push notification delivery (APNs) and, on iOS, external purchase compliance APIs where applicable
We may also disclose information if required by law, to protect users and Rewear, or in connection with a merger or acquisition, with appropriate safeguards.
8. International transfers
Our providers may process data in the European Economic Area, the United Kingdom, the United States, or other countries. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for transfers outside your country.
9. Retention
We keep information while your account is active and as needed to provide the service, resolve disputes, enforce terms, and meet legal obligations. You can delete your account at any time from Settings → Delete account in the app (web or iOS). Some data may be retained in backups or records for a limited period where the law requires.
10. Your choices and rights
- Update profile and notification preferences in the app
- Decline optional permissions on mobile
- Manage or cancel seller billing via the billing portal or account settings
- Delete your account from Settings → Delete account (permanent; cancels seller subscriptions)
- Request access, correction, deletion, or restriction of your personal data
- Object to processing based on legitimate interests, where applicable
- Withdraw consent where processing is consent-based
- Lodge a complaint with your local data protection authority (in Malta, the IDPC)
To exercise these rights, delete your account in the app (Settings → Delete account) or email info@rewearmalta.com or use our contact page. We may need to verify your identity before responding.
11. Security
We use technical and organisational measures appropriate to a consumer marketplace — including encryption in transit (HTTPS), access controls, and provider security practices. No online service is completely secure; please use a strong password and keep your login details private.
12. Children
Rewear is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will take appropriate steps.
13. Changes
We may update this policy from time to time. We will post the new version on this page and update the "Last updated" date. Material changes may also be communicated in the app or by email where appropriate.
14. Contact
Privacy questions or requests: info@rewearmalta.com or contact us.