EL Log in Sign up
Privacy

Privacy Policy

Last update: 19 June 2026
Car For Sale Cyprus respects your personal data. Here we explain what we collect, why, who we share it with and what your rights are (GDPR).

1. Data controller

This English text is a translation provided for convenience. If it differs from the Greek text, the Greek text prevails.

Car For Sale Cyprus — Cyprus · Email: [email protected] (or via the contact form). We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and Cypriot law.

2. What data we collect

  • Account: email (optional for mobile-number accounts), name (optional), encrypted password, area, profile photo (optional) and your notification preferences.
  • Phone & SMS verification: your mobile number and temporary one-time codes (OTP) for login/verification. One verified number = one account (identity).
  • Third-party login (Facebook/Google): if you choose to log in with a social account, we receive an identifier from the provider and the basic details it shares (e.g. name, email, photo) to create/link your account.
  • Listings: vehicle details, photos, price, location, contact phone number. Active listings are public.
  • Messages: your conversations with other users within the Platform.
  • Business details (dealers): business name, address, opening hours, website, shop coordinates — shown publicly on the profile.
  • Payments: order history, Pro subscription status and wallet balance/transactions. Card payments are made through Stripe; we do not store card details.
  • Reviews: any rating/comment you leave, together with the name/area shown — public only with your consent.
  • Activity: favourites, saved searches and notifications (in-app/email/SMS/push, depending on your choices).
  • Technical: IP address, browser type, error logs, an anonymised fingerprint of listing views (hash of IP + day) and a log of phone number reveals (anti-abuse).
  • Photo EXIF data: on upload, metadata is removed from the public versions; any GPS coordinates are used only — if the location is missing — for the listing’s area.

4. Third-party recipients / processors

We share data only with providers who help us operate, to the extent necessary:

  • SMS.to: sending SMS codes and (optional) SMS notifications.
  • Stripe: secure processing of card payments.
  • Facebook / Google: only if you choose to log in with them (social login).
  • Google Analytics / Google AdSense: traffic statistics and advertisements on the public pages. See Google’s policy.
  • OpenStreetMap: maps load tiles from OSM servers when you open them.
  • Cloudflare: content delivery network and website protection.
  • Email provider (SMTP): sending confirmation emails, notifications and receipts.

We do not sell personal data to third parties.

5. International transfers

Some providers (e.g. Google, Stripe, Cloudflare) may process data outside the European Economic Area. In such cases, the transfer is based on appropriate safeguards (e.g. the EU Standard Contractual Clauses).

6. Retention period

  • Account & listings: for as long as you keep your account. On deletion, your profile details are anonymised and your listings are withdrawn.
  • SMS codes (OTP): kept for the shortest time and expire shortly after use.
  • Messages: kept for the safety of both parties and the resolution of disputes.
  • Payments: records are kept for as long as tax/accounting law requires.
  • Log/security records: for a limited period, for technical and anti-abuse reasons.

7. Your rights

You have the right of access, rectification, erasure (“right to be forgotten”), restriction, portability and objection. You can:

  • correct your details in your Account settings,
  • delete your account from Settings (a permanent action),
  • withdraw your consent to notifications/public reviews at any time,
  • contact us about any request via the contact form.

If you believe your rights are being infringed, you can lodge a complaint with the Office of the Commissioner for Personal Data Protection of Cyprus.

8. Security

We use HTTPS everywhere, password encryption (bcrypt), CSRF protection, rate limiting, access control and logging of administrative actions. No system is 100% impenetrable — we notify users of any serious incident as required by law.

9. Changes

Any updates to this policy will be published here with a new date.