Data Protection & Regulatory Compliance

Privacy & Data Protection Policy

Effective Date: July 22, 2026 | Document Revision: 3.0 | Regimes Covered: EU GDPR (2016/679), UK GDPR / DPA 2018, CCPA / CPRA (Cal. Civ. Code § 1798.100)

1. Data Controller Identification & Statutory Scope

FURRT Inc. ("FURRT," "we," "our," or "us") operates as the primary Data Controller for personal data processed through furrt.com, our mobile applications, and custom marketplace infrastructure (Corporate Headquarters: 16192 Coastal Highway, Lewes, DE 19958, United States; Tel: +1 (848) 900-1687). For privacy inquiries or to exercise statutory rights, contact our Data Protection Officer at privacy@furrt.com.

2. Categories of Personal Data Collected

  • Identity & Account Data: Full legal name, business registration entity details, tax identification numbers (EIN/SSN/VAT ID), workshop physical address, and magic-link authentication credentials.
  • Transactional & Financial Escrow Tokens: Transaction reference IDs, milestone allocation metrics, broker commission logs, and payment tokens managed directly via Escrow.com. (FURRT never stores full payment card or bank account credentials on company servers).
  • Custom Order Specifications & Communications: Custom request blueprints, CAD files, dimensional specifications, finish choices, progress media, and chat conversation records.
  • Technical & Telemetry Data: IP address, browser user-agent strings, cookie identifiers, device hardware markers, and Socket.io connection logs.

3. Lawful Bases for Processing (GDPR Article 6)

We process personal data strictly pursuant to recognized lawful processing grounds:

  • Performance of Contract (Art. 6(1)(b)): Executing custom furniture commissions, managing escrow pre-authorizations, coordinating freight delivery, and routing message communications.
  • Compliance with Legal Obligations (Art. 6(1)(c)): Verifying seller identity (KYC/KYB) under the EU Digital Services Act (DSA 2022/2065), complying with tax reporting rules, and enforcing anti-money laundering regulations.
  • Legitimate Business Interests (Art. 6(1)(f)): Protecting platform security, preventing fee evasion, mediating disputes, and optimizing marketplace performance.

4. Authorized Sub-Processors & Data Transfers

FURRT shares data strictly with vetted sub-processors necessary to fulfill platform operations:

• Escrow.com (Fidelity National Financial): Financial escrow processing and payment disbursement.

• Freight & Logistics Carriers: Delivery address and Bill of Lading (BOL) generation.

• Cloud Infrastructure Providers (AWS S3 / Cloudflare R2): Encrypted storage for blueprints and images.

• Firebase FCM: Mobile push notifications.

Non-Sale Guarantee (CCPA § 1798.120): FURRT HAS NEVER SOLD, RENTED, OR TRADED PERSONAL DATA TO THIRD-PARTY ADVERTISERS OR DATA BROKERS FOR MONETARY OR OTHER VALUABLE CONSIDERATION, AND WILL NEVER DO SO.

5. Statutory Retention Schedule & Data Subject Rights

Retention Periods: Financial transaction & tax logs are retained for 7 years pursuant to statutory tax compliance. Order chat records are retained for 3 years post-order completion to support warranty and dispute claims.

Your Statutory Rights (GDPR Arts. 15-22 / CCPA): Users possess the right to request access to personal data, rectification of inaccuracies, erasure ("Right to be Forgotten"), data portability, and restriction of processing by submitting a request to privacy@furrt.com.