LUTE MARKETPLACE

Privacy Policy

Effective Date: April 21, 2026 | Last Updated: April 21, 2026


PLEASE READ THIS PRIVACY POLICY CAREFULLY. BY ACCESSING OR USING LUTE MARKETPLACE, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTAND THIS POLICY AND CONSENT TO THE COLLECTION, USE, AND DISCLOSURE OF YOUR INFORMATION AS DESCRIBED BELOW. IF YOU DO NOT AGREE, DO NOT ACCESS OR USE THE PLATFORM.

Lute Marketplace (the "Platform," "we," "us," or "our") is an independent, student-created peer-to-peer marketplace designed exclusively for members of the Pacific Lutheran University ("PLU") community. The Platform is owned and operated by an individual student at PLU and is not affiliated with, endorsed by, sponsored by, or officially connected to Pacific Lutheran University. This Privacy Policy describes how we collect, use, disclose, and protect information in connection with your use of the Platform. It is incorporated by reference into our Terms and Conditions.


1. Scope of This Policy

This Privacy Policy applies solely to information we collect through the Platform (web application located at lutemarketplace.com and any related services we operate).

This Policy does NOT apply to:

  • Any information you share with other users directly off the Platform (including but not limited to phone, text message, in-person exchange, or third-party payment apps such as Venmo, PayPal, Zelle, or Cash App);
  • Any information collected by Pacific Lutheran University, third-party websites, social networks, or services linked from the Platform;
  • Any information collected by our service providers under their own privacy policies (see Section 5); or
  • Any transaction, communication, delivery, or dispute occurring between users outside the Platform.

You use the Platform and interact with other users at your own risk. We are not responsible for the privacy practices of other users, third parties, or off-Platform activity.


2. Information We Collect

2.1 Information You Provide Directly

Category Examples
Account Registration Full name, PLU email address (@plu.edu), password (hashed by our authentication provider)
Profile Information Display name, optional profile photo, optional bio
Listing Content Item title, description, price, category, condition, location, and up to three (3) images per listing
Messaging Content Text messages and optional image attachments sent to other users through the Platform
Favorites / Saved Items The listings you save and the time you saved them
Reports and Support Requests Content of any report, takedown notice, dispute, deletion request, or support inquiry you submit

2.2 Information Collected Automatically

When you access the Platform, we (or our service providers) may automatically collect:

  • Technical Data: IP address, browser type and version, operating system, device identifiers, screen size, and referring URLs;
  • Usage Data: Pages viewed, features accessed, listings viewed, search queries, session duration, timestamps, and clickstream data;
  • Authentication Data: Sign-in timestamps, verification status, and session tokens;
  • Cookies and Similar Technologies: See Section 6.

2.3 Information from Third Parties

We may receive limited information from our infrastructure providers (e.g., Firebase/Google) necessary to authenticate you, deliver notifications, and operate the Platform. We do not purchase personal information from data brokers.

2.4 Information We Do NOT Knowingly Collect

We do not request, require, or intentionally collect:

  • Payment card numbers or bank account information (all transactions occur off-Platform);
  • Government identification numbers, Social Security numbers, or driver's license numbers;
  • Precise geolocation data (GPS coordinates);
  • Health information, biometric data, or information about protected characteristics;
  • Information from children under 13 (see Section 11).

Do not submit any of the categories above through listings, messages, or profile fields. If you do so voluntarily, you assume all risk associated with that disclosure, and you waive any claim against us arising from our processing of such information in the ordinary course of operating the Platform.


3. How We Use Information

We use the information described above only for the following purposes:

  • Operate the Platform: Create and maintain your account, display listings, deliver messages, show favorites, and provide core functionality;
  • Authenticate and Secure: Verify your PLU email, prevent unauthorized access, detect and prevent fraud, abuse, spam, or violations of our Terms;
  • Communicate With You: Send verification emails, transactional notifications (e.g., new message, item saved, listing expiring), and respond to support inquiries;
  • Enforce Our Terms: Investigate and address violations, respond to reports, and cooperate with law enforcement requests;
  • Improve the Platform: Analyze usage trends, diagnose technical issues, and develop new features;
  • Comply with Law: Satisfy legal obligations, respond to subpoenas, court orders, and valid governmental requests; and
  • Any other purpose disclosed at the time of collection or to which you consent.

We do not use your personal information for targeted advertising, profiling for automated decisions that produce legal or similarly significant effects, or any purpose incompatible with those listed above.


4. Legal Bases for Processing

Where applicable law (e.g., the EU/UK GDPR) requires a legal basis for processing, we rely on one or more of the following:

  • Performance of a Contract: To provide the Platform you have requested to use;
  • Legitimate Interests: To secure the Platform, prevent abuse, and improve our services, where those interests are not overridden by your rights;
  • Consent: Where you have given us consent (e.g., push notifications, optional profile fields). You may withdraw consent at any time without affecting the lawfulness of prior processing; and
  • Legal Obligation: To comply with applicable law.

5. How We Share Information

We do not sell, rent, trade, or share your personal information for monetary or other valuable consideration, and we do not share your personal information for cross-context behavioral advertising. We disclose information only as follows:

5.1 With Other Users

  • Public Profile Information: Your display name, profile photo (if provided), bio (if provided), account creation date, active listings, and seller-related metrics are visible to other authenticated users.
  • Listing Content: Listings are visible to all authenticated users of the Platform.
  • Messages: Message content and any images you send are visible to the other participant in the conversation.

5.2 With Service Providers

We rely on third-party service providers to operate the Platform. These providers process information on our behalf under their own privacy and security policies. Our primary providers include:

Provider Purpose Privacy Policy
Google / Firebase (Authentication, Firestore, Storage, Cloud Messaging) Authentication, data storage, image hosting, push notifications https://policies.google.com/privacy
Vercel (or Firebase Hosting) Web application hosting and content delivery https://vercel.com/legal/privacy-policy (or https://firebase.google.com/support/privacy)

We select providers that contractually commit to appropriate confidentiality and security practices. We are not responsible for the independent practices of these providers beyond the scope of the services they perform for us.

5.3 For Legal and Safety Reasons

We may disclose information when we believe in good faith that disclosure is necessary to:

  • Comply with applicable law, subpoena, court order, or governmental request;
  • Enforce our Terms and Conditions or investigate potential violations;
  • Detect, prevent, or address fraud, security, or technical issues;
  • Protect the rights, property, or safety of Lute Marketplace, our users, or the public; or
  • Cooperate with PLU Campus Safety, local law enforcement, or other authorities in response to a credible threat or reported crime.

5.4 Business Transfer

If the Platform is transferred to another operator (e.g., through assignment, sale, or dissolution), user information may be transferred as part of that transaction. We will provide notice by in-platform banner or email before information becomes subject to a different privacy policy.

5.5 With Your Consent

We may share information for any other purpose with your explicit consent.


6. Cookies and Similar Technologies

The Platform uses cookies, local storage, and similar technologies to:

  • Maintain your authenticated session;
  • Remember your preferences (e.g., theme, saved filters);
  • Measure aggregate usage and diagnose performance issues; and
  • Protect against fraud and abuse.

You may configure your browser to refuse or delete cookies. If you disable cookies, certain features (including sign-in) may not function. We do not use third-party advertising cookies. We do not respond to "Do Not Track" browser signals at this time, because no common industry standard exists; however, we do not engage in cross-site tracking for advertising purposes.


7. Data Retention

We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including:

Data Type Retention Period
Account and profile data For the life of your account, plus up to ninety (90) days after deletion for backup and abuse-prevention purposes
Active listings Until deleted by the seller or auto-expired for inactivity
Deleted / sold listings Soft-deleted and retained for audit, chat continuity, and dispute resolution for up to twelve (12) months
Messages Retained to preserve conversation history for both participants; deletion of a listing does not delete prior messages
Log and usage data Up to twenty-four (24) months, after which data is aggregated or deleted
Reports, moderation records, and legal records As long as necessary to establish, exercise, or defend legal claims, or as required by law

We may retain anonymized or aggregated data that cannot reasonably be used to identify you indefinitely.


8. Your Rights and Choices

8.1 Account Controls

You may, at any time, while logged in:

  • Update your display name, profile photo, or bio;
  • Edit or delete your listings;
  • Delete messages you have sent (subject to the recipient's copy remaining in their thread);
  • Manage your notification preferences; or
  • Request account deletion by emailing info@lutemarketplace.com.

8.2 Privacy Rights (California, Washington, EU/UK, and Others)

Depending on your jurisdiction, you may have some or all of the following rights with respect to your personal information:

  • Access / Know: Request confirmation of, and a copy of, the personal information we hold about you;
  • Correction: Request correction of inaccurate personal information;
  • Deletion: Request deletion of your personal information, subject to legal exceptions;
  • Portability: Request a copy of your data in a portable format;
  • Opt-Out of Sale / Sharing: We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of;
  • Restriction or Objection: Request that we restrict or object to certain processing;
  • Withdraw Consent: Withdraw any consent you previously provided;
  • Non-Discrimination: We will not discriminate against you for exercising these rights;
  • Appeal / Complaint: If we deny a request, you may appeal by replying to our response email, or lodge a complaint with your local data protection authority (EU/UK) or state attorney general.

How to exercise your rights: Email info@lutemarketplace.com from the PLU email address associated with your account, with the subject line "Privacy Request." We will respond within the time required by applicable law (generally forty-five (45) days for U.S. state privacy laws, thirty (30) days for GDPR). We may require additional information to verify your identity before fulfilling your request.

8.3 Push Notifications

You can disable push notifications through your device's operating system settings or through your Platform profile settings at any time.


9. Data Security

We implement reasonable administrative, technical, and physical safeguards intended to protect personal information against unauthorized access, disclosure, alteration, and destruction, including:

  • Transport Layer Security (TLS/HTTPS) for data in transit;
  • Encryption at rest as provided by our infrastructure providers;
  • Firebase authentication and Firestore security rules restricting access to authorized users;
  • Password hashing by our authentication provider (we never store plaintext passwords); and
  • Routine review of access controls and security configurations.

NO SYSTEM OR METHOD OF TRANSMISSION OVER THE INTERNET IS 100% SECURE. WE CANNOT AND DO NOT GUARANTEE THE ABSOLUTE SECURITY OF ANY INFORMATION YOU PROVIDE, AND WE EXPRESSLY DISCLAIM ANY LIABILITY ARISING FROM UNAUTHORIZED ACCESS TO, ALTERATION OF, OR DISCLOSURE OF YOUR DATA TO THE MAXIMUM EXTENT PERMITTED BY LAW. You are responsible for maintaining the confidentiality of your account credentials. Notify us immediately at info@lutemarketplace.com if you suspect unauthorized access to your account.


10. International Users and Data Transfers

The Platform is operated from, and data is processed and stored in, the United States. Our service providers may process data in other countries where they maintain infrastructure. If you access the Platform from outside the United States, you consent to the transfer, processing, and storage of your information in the United States and other countries whose data protection laws may differ from those of your jurisdiction. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for cross-border transfers.

The Platform is intended for use by members of the PLU community. We make no representation that the Platform is appropriate or available in any particular jurisdiction, and users access it at their own initiative and risk.


11. Children's Privacy

The Platform is not directed to, and is not intended for use by, children under the age of thirteen (13). We do not knowingly collect personal information from children under 13 in violation of the Children's Online Privacy Protection Act (COPPA). If we learn that we have inadvertently collected such information, we will delete it promptly. A parent or guardian who believes their child under 13 has provided personal information to the Platform may contact us at info@lutemarketplace.com to request deletion.

Users between 13 and 17 may use the Platform only with verifiable parental or guardian consent, as required by our Terms and Conditions.


12. Third-Party Links and Services

The Platform may contain links to third-party websites, services, or payment applications. We do not control and are not responsible for the content, privacy practices, or security of third parties. Any information you share with a third party is governed by that third party's privacy policy, not this one. We encourage you to review the privacy policies of any third party before providing information.


13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by in-platform notice or email at least seven (7) days before the changes take effect, and we will update the "Last Updated" date above. Your continued use of the Platform after the effective date of any update constitutes your acceptance of the revised Policy. If you do not agree, you must cease using the Platform.


14. Disclaimer and Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, LUTE MARKETPLACE AND ITS OPERATOR DISCLAIM ALL LIABILITY FOR:

  • Any unauthorized access to, alteration of, or disclosure of your information resulting from causes outside our reasonable control;
  • Any act or omission of any other user, including any misuse of information you choose to share through listings, messages, or your profile;
  • Any loss or damage arising from off-Platform communications, transactions, or payments, all of which are conducted solely between users at their own risk; and
  • Any data processing by third-party service providers governed by their own privacy policies.

Our aggregate liability for any claim arising out of or relating to this Privacy Policy is subject to the limitations set forth in the Terms and Conditions, including the cap of fifty U.S. dollars ($50.00). The disclaimers of warranties, limitations of liability, indemnification, governing law, dispute resolution, arbitration, class action waiver, and venue provisions of the Terms and Conditions are incorporated into this Privacy Policy by reference and apply equally here.


15. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the State of Washington, without regard to its conflict of law provisions. Any dispute arising under this Policy is subject to the dispute resolution, arbitration, and class action waiver provisions of our Terms and Conditions.


16. Contact Us

For questions, concerns, privacy requests, or to report a suspected privacy violation, please contact:

Lute Marketplace Email: info@lutemarketplace.com Platform: lutemarketplace.com


17. Acknowledgment

BY CREATING AN ACCOUNT OR USING THE PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THIS PRIVACY POLICY AND OUR TERMS AND CONDITIONS.


For Lutes, By Lutes | Lute Marketplace