Privacy Policy

How FinDech UAB processes personal data when you use GLWS (Good Luck With Sale).

Last updated · Version 2026-08-31.2

This Privacy Policy explains how FinDech UAB, company code 307632436, registered office at Architektų g. 56-101, Vilnius, LT-04111, Lithuania (“FinDech”, “we”, “us”, or “our”) processes personal data as controller for GLWS (Good Luck With Sale).

GLWS is a service operated by FinDech UAB. GLWS is not a separate legal entity.

Using the Service is not blanket consent to all processing. Where we rely on contract, legitimate interests, or a legal obligation, we do so on those bases. Consent is used only where it is the genuine legal basis, such as optional marketing or non-essential cookies if those are introduced.

Data-rights and privacy requests: legal@findech.com. Ordinary product communications: help@glws.com.

1. Who is the controller

FinDech UAB is the controller for GLWS platform processing described here, unless a particular Business/API arrangement makes FinDech a processor. Processor processing is covered by the Data Processing Addendum and does not convert all GLWS processing into processor processing.

A bank, EMI, payment institution, acquirer, escrow provider, or KYC provider may act as an independent controller for its own regulatory and payment purposes. FinDech does not control a partner’s legally required processing.

2. Data we process

The categories below reflect the current product. We do not process a category simply because it is listed if you never use the related feature.

Account and identity

  • email address, display name, organisation name and membership where used;
  • authentication data (password hashes are stored by the authentication provider, not in GLWS application logs);
  • account status (active, suspended, closed);
  • guest-session identifiers and pending (unverified) email for compose-first deal creation.

Public profile

  • a self-provided public display name, optional username, and optional profile photo;
  • a stable public profile link (/@username or /u/…) used to recognise a seller;
  • historical seller presentation captured when a buyer starts a transaction (public name, username at the time, profile link, and capture time).

A public name is not a verified legal identity. Email confirmation, when shown, is only evidence that the current account email was confirmed. It is not published as the email address itself. Buyer names and emails stay private under the existing deal policy.

Avatars are stored separately from deal evidence. Profile pages are unlisted and are not added to a public directory.

Deal and transaction data

  • deal title, type, mode, amount, currency, notes, terms;
  • seller and buyer names and emails where provided;
  • public codes, invitation data, use limits, expiry;
  • deal status and event timeline;
  • buyer claim records;
  • handover codes and handover confirmation timestamps (handover codes are seller-facing and are not included in public deal responses);
  • receipts and receipt identifiers.

Evidence and files

  • user-uploaded evidence and proof files (images and PDFs within configured type and size limits);
  • file metadata, hashes, storage object keys, and signed upload/download URLs.

Payment metadata

  • organization billing customer and subscription references (Stripe customer/subscription IDs, plan, period, status);
  • seller connected-account references and capability status (not card numbers, CVC, or bank credentials);
  • payment quotes, payment references, application-fee amounts, and later refund/dispute/reversal events;
  • recorded payment status derived from a verified provider webhook or trusted server-side provider lookup.

Card details, CVC, bank credentials, and Stripe secrets are not stored in GLWS. Stripe-hosted Checkout, Customer Portal, and Connect onboarding carry payment and KYC data to Stripe.

A GLWS status of Paid is a recorded provider payment status. It is not a guarantee that the payment cannot later be refunded, reversed, disputed, or charged back.

Verification and risk

  • selected evidence requirements and whether they are recorded as submitted;
  • system-check results for facts the system actually tests (for example link usage, expiry, recorded payment status, handover-workflow completion);
  • rate-limit and abuse-control data;
  • a “suspicious” deal status exists in the data model; it is used if and when a deal is marked that way.

Technical, security, and audit data

  • IP / network information used for rate limiting, security, and legal-acceptance evidence (stored as a hash for acceptance records);
  • device/browser user-agent (hashed for acceptance records);
  • CSRF tokens and session cookies;
  • API request logs with secret redaction;
  • append-only deal events and admin audit events;
  • legal-acceptance records (participant identifier, policy, version, timestamp, source, hashed request metadata).

Support and legal communications

  • support requests submitted at https://glws.com/support, including topic, message, optional deal reference, report reason, and follow-up messages;
  • mailbox-verification and short-lived follow-up access records (token hashes, not reusable plaintext secrets);
  • internal staff notes, which are not sent to requesters;
  • emails and other messages you send to help@glws.com or legal@findech.com.

Inbound email to help@glws.com is handled by staff and is not automatically turned into a ticket message. Support records are retained as needed for security, legal claims, and complaint handling, then deleted or redacted. Append-only conversation history does not mean we keep all support content forever.

We do not currently operate a third-party marketing or advertising analytics pixel on the GLWS website.

Purpose Typical data Legal basis
Provide the Service, accounts, guest sessions, deal rooms, invitations, evidence, handover, receipts Account, deal, evidence, receipt data Contract (Art. 6(1)(b))
Authenticate users and keep sessions secure Auth, cookies, security logs Contract; legitimate interests (Art. 6(1)(f)) in securing the Service
Fraud, abuse, and security prevention Technical, risk, deal, and rate-limit data Legitimate interests; legal obligation where applicable
Payment orchestration and partner connection when a partner is configured Payment metadata, deal context Contract; legitimate interests; partner/legal obligation where applicable
Customer support Contact and deal context Contract; legitimate interests
Product improvement using first-party funnel events (for example create-flow steps) Coarse event names, not marketing profiles Legitimate interests
Legal claims, accounting, and compliance Records, acceptance logs, deal history Legal obligation (Art. 6(1)(c)); legitimate interests
Optional marketing (not currently a default GLWS feature) Email Consent (Art. 6(1)(a)), if used

We do not treat Privacy Policy acknowledgement as consent to processing that is necessary for the contract or our legitimate interests.

4. Automated processing

GLWS uses rules and system checks (for example use limits, expiry, rate limits, whether a handover code was confirmed, whether a payment status was recorded). These are not fully automated decisions producing legal or similarly significant effects about creditworthiness or access to essential services.

If a process later has a legal or similarly significant effect, applicable GDPR safeguards will apply, including the right to obtain human review where required. We do not promise that automated checks detect all fraud.

5. Sharing

We do not sell personal data.

We share data only as needed:

  • Counterparties — Deal Room content is shared with the other party so the Deal can proceed.
  • Payment and KYC partners — if and when configured, relevant deal and identity data is shared so that partner can provide its service. That partner may be an independent controller.
  • Service providers — currently including hosting (Vercel), authentication and object storage (Supabase), and PostgreSQL hosting. These process data on our instructions as processors, except where a provider is an independent controller for its own service (for example authentication emails sent by the auth provider).
  • Stripe — when you purchase a GLWS subscription or a seller connects Stripe for deal payments, Stripe processes payment, billing, and onboarding data as an independent controller for its payment services. GLWS stores operational references (customer, subscription, connected-account, and payment identifiers) and disclosed fee amounts. GLWS does not store card numbers, CVC, or bank credentials.
  • Legal and safety — when required by law, court order, or to protect rights, security, or users.
  • Corporate transactions — in a merger, acquisition, or asset transfer, subject to this Policy.

6. Cookies and similar technologies

See the Cookie Policy. GLWS currently uses strictly necessary authentication, guest, buyer-claim, and CSRF cookies. There is no cookie banner because we do not currently set non-essential analytics or marketing cookies.

Create-flow drafts may be stored in your browser’s localStorage. That storage stays on your device unless you submit a deal.

7. Retention

We do not claim a single fixed retention period for all data. Retention depends on the category and purpose:

  • Account data — while the account is active and for a period afterwards as needed to close the account, prevent abuse, and meet legal claims.
  • Deal, event, evidence metadata, and receipts — for as long as needed to provide the Service and then for contract evidence, fraud prevention, security, accounting, partner reconciliation, and lawful requests.
  • Proof files — while needed for the Deal and residual legal/security purposes; they are stored in a private bucket, not published.
  • Guest sessions — until expiry, claim, or closure.
  • Legal-acceptance records — for the life of the relevant contract evidence and limitation periods.
  • Security and rate-limit logs — for a period proportionate to security and abuse prevention.

We do not promise immediate deletion on account closure where retention is lawfully necessary. We also do not promise permanent retention.

8. International transfers

The Service is operated from the EU and may use infrastructure that processes data in other countries (including where a hosting, auth, or storage provider stores or accesses data). Where we transfer personal data outside the EEA/UK, we use appropriate safeguards required by law, such as the European Commission’s Standard Contractual Clauses, where those are actually in place with the relevant provider.

We do not claim that a specific transfer tool is in place with every vendor beyond what that vendor’s current terms provide. If you need more detail about a particular transfer, contact legal@findech.com.

9. Security

We use technical and organisational measures designed to reduce risk, including HTTPS, httpOnly session cookies, CSRF controls, access-token authentication for private APIs, private object storage with signed URLs, append-only deal events, and secret redaction in application logs. No method of transmission or storage is completely secure. We do not claim ISO, SOC 2, PCI DSS, or similar certifications.

10. Your rights

Where GDPR applies, you may have the right to access, rectify, erase, restrict, object, and data portability, and to withdraw consent where processing is based on consent.

  • Erasure may be limited where we must retain records for contracts, legal claims, security, fraud prevention, accounting, or other lawful purposes.
  • You may object to processing based on legitimate interests. We will stop unless we have compelling legitimate grounds or the processing is for legal claims.

To exercise rights, email legal@findech.com. You also have the right to lodge a complaint with a supervisory authority.

The competent Lithuanian authority is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI): https://vdai.lrv.lt/en/.

If you are in California or another jurisdiction with similar rights, we do not sell or share personal information for cross-context behavioural advertising as those terms are commonly defined. We will honour applicable local rights on request.

11. Children

The Service is not intended for persons under 18, and we do not knowingly collect personal data from them. If you believe a child has provided data, contact legal@findech.com and we will take appropriate steps.

12. Changes

We may update this Policy. Material changes will be posted with a new effective date. Where legally required, we will provide additional notice.

13. Contact

Controller: FinDech UAB, Architektų g. 56-101, Vilnius, LT-04111, Lithuania, company code 307632436.

Privacy and data-rights: legal@findech.com
Ordinary product communications: help@glws.com