Privacy Policy
Version 1.0 · Effective from: 1 July 2026
This Privacy Policy describes how the Global Mario platform ("the Platform", "we") collects, uses and protects users' personal data when using the services at globalmario.com.
We collect the following categories of data:
- Registration data: name, email, phone number, country
- Company data (for suppliers): company name, registered address, tax/VAT number, bank details
- Verification data (KYC/KYB): identity or company documents, photographs
- Transaction data: history of enquiries, orders and payments
- Delivery and recipient addresses — when placing an order
- Content of conversations in the Platform chat
- Technical data: IP address, browser type, cookie data, session time
The collected data is used to:
- Register and verify your account
- Operate the Platform and enable communication between buyers and suppliers
- Process subscription and verification payments
- Arrange delivery of orders
- Automatically translate product descriptions and messages into the other party's language
- Prevent fraud and comply with legal requirements
- Improve service quality and personalisation
- Send notifications about new enquiries, messages and Platform updates
We do not sell personal data to third parties. Data is shared with processors only to the extent necessary for the relevant Platform function to work:
- Stripe — payment processing and payouts to suppliers
- Shufti Pro — identity and company verification (KYC/KYB)
- Vonage — phone number confirmation by SMS
- Zoho ZeptoMail — sending Platform emails
- Anthropic — automatic translation of product descriptions and messages, chat moderation
- Voyage AI — building the search index over product descriptions
- Shippo, Sendcloud — shipping arrangements and rate calculation, including recipient address
- Supabase, Hetzner — data storage and Platform server operation
- Cloudflare — site delivery, attack protection, network traffic handling
- Public authorities — upon lawful request
Some processors are located outside the European Economic Area. Transfers to such processors are made on the basis of the European Commission's Standard Contractual Clauses (SCC) or other mechanisms provided for by the GDPR.
Personal data is stored on secure servers within the EU (Germany). Retention period — 5 years from the last account activity, unless otherwise required by law.
When an account is deleted, data is removed within 30 days, except for information the Platform is legally obliged to retain.
Under the GDPR you have the right to:
- Access your personal data
- Rectify inaccurate or outdated data
- Erase your data ("right to be forgotten")
- Restrict or object to processing
- Port your data to another service (data portability)
- Withdraw consent to processing at any time
- Lodge a complaint with a data protection supervisory authority
To exercise these rights, contact: [email protected]. Response time — up to 30 days.
We apply technical and organisational measures to protect data:
- Encryption of data in transit (SSL/TLS)
- Access control within the team
- Regular security audits
- Bank card data is not stored on Platform servers
We reserve the right to update this Policy. We notify users of changes by email or via a Platform notification at least 14 days before they take effect.
Continued use of the Platform after the changes take effect constitutes acceptance of the updated Policy.
For questions about the processing of personal data:
- Email: [email protected]
- Response time: up to 2 days
- Global Mario Platform · Brescia, Italy