Privacy Policy
Hestasales is a marketplace brand and service operated by Oskar Fornstedt AB, org. no. 559561-1020, VAT SE559561102001, Bemersberg 3, 743 82 Bälinge, Sweden. Contact: org.hestasales@gmail.com.
This page is maintained by Oskar Fornstedt AB. It is not legal advice and does not constitute independent certification.
1. Data controller
Oskar Fornstedt AB, org. no. 559561-1020, Bemersberg 3, 743 82 Bälinge, Sweden, is the controller for personal data processed to operate Hestasales, unless a specific processing activity has a different verified legal role. Contact: org.hestasales@gmail.com.
2. Categories of personal data
- Authentication user identifier (UUID) and email address.
- Profile name, language and currency preferences, country, region and city.
- Age-band declaration and guardian-approval declaration.
- Contact information you choose to make available on your listings: email, telephone number, WhatsApp information, Messenger information, and the seller-selected contact methods.
- Seller type (private or business) and, where applicable, business identity information (legal name, organisation or registration number, country of registration, business postal address, business contact email, VAT number).
- Listing content: horse information, images, videos, video poster images.
- Private message content: the text you write, and any images or videos you attach.
- Attachment information: the original file name of the uploaded file, file type (MIME type), media type (image or video), file size, upload timestamp, the internal storage location of the file, the identifier of the user who uploaded it, and the message and conversation the file belongs to.
- Messaging metadata: conversation identifier, the listing a conversation relates to, sender and recipient identifiers, message timestamps, read/unread status, a short preview of the most recent message, blocking records, and rate-limit counters used to enforce technical limits.
- Favorites and notifications.
- Invitation records where invite-only mode is in force.
- Moderation information (status, admin comments, review timestamps).
- Legal acceptance records (document type, document version, action type, context, timestamp).
- Reports and complaints you submit or that concern you.
- Platform administrator role records.
- Account-deletion job records for audit.
- Technical and security logs collected by providers.
- Local browser storage (localStorage / sessionStorage) as described in the Cookie Policy.
3. Contact visibility
- Contact information is hidden from anonymous visitors.
- Authenticated users may retrieve seller-selected contact methods for an approved, active and unsold listing.
- Listing owners and authorized administrators may access contact information where necessary.
- Ordinary buyers see only the contact methods the seller has selected.
- Communication takes place outside Hestasales through the seller's chosen contact methods.
4. Private messages and attachments
Hestasales includes a private messaging function connected to listings. A message may contain text, images and videos. Everything you write or attach is stored on the Platform so that the conversation can be delivered and displayed.
We process this information to provide private messaging between users, to deliver and display attachments, to keep message and unread status up to date, to protect the service against misuse, to enforce technical and security limits (such as the number, type and size of files and how often files may be uploaded), and to investigate reports and legal complaints.
- Attachments are stored in a private storage area. They are never shown in the public listing feed or on public listing pages.
- Through the normal Hestasales interface, attachment information and files can only be accessed by signed-in users who take part in that specific conversation.
- Files are displayed using time-limited access links that are generated for a participant and expire after a short period.
- Messages and attachments are not end-to-end encrypted. Data is protected in transit and by access controls, but it is technically accessible to the controller and its processors.
- Authorised Hestasales personnel with administrator rights may access message content and attachments where necessary — in particular to investigate a report, prevent abuse, meet a legal obligation or handle a legal claim.
- Our hosting, database and storage provider processes and stores the files on our behalf as a processor.
- Information may be disclosed to authorities or other parties where we are legally required to do so or where it is necessary to establish, exercise or defend legal claims.
- When a conversation is reported, a copy of the most recent messages in that conversation, including a record of their attachments, is stored with the report so it can be reviewed.
Please only send images or videos you are entitled to share, and avoid sending unnecessary sensitive personal information about yourself or other people.
5. Purposes and legal bases
- Provide accounts, listings and platform features — performance of the user agreement (Art. 6(1)(b) GDPR).
- Provide private messaging and the sending, storage and display of message attachments you choose to send — performance of the user agreement (Art. 6(1)(b) GDPR).
- Operate, secure, moderate and improve the Platform, prevent fraud and abuse, enforce technical and security limits, enforce rules and protect legal claims — legitimate interests (Art. 6(1)(f) GDPR).
- Comply with legal obligations (tax, consumer, e-commerce, complaint handling), including retaining or disclosing information where required by law — legal obligation (Art. 6(1)(c) GDPR).
- Document your legal acceptances and business seller declarations — legitimate interests and, where applicable, legal obligation.
- Optional processing that genuinely depends on your choice — consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
Consent is not the legal basis for account processing generally, and uploading a file to a conversation is not treated as GDPR consent.
6. External services we currently use
Hestasales is built on Lovable Cloud, which uses Supabase for authentication, database, storage and edge functions. Supabase acts as processor on behalf of Oskar Fornstedt AB for Hestasales personal data, including private messages and message attachments, which are stored in Supabase database and storage. According to our project configuration, this infrastructure is provisioned in an EU region (Ireland).
Authentication verification emails are sent through the email provider used by Supabase Auth. Your browser also connects directly to the following third-party services to load presentation resources or reference data; those services may receive normal technical request data (IP address, browser details, request time):
- Google Fonts (fonts.googleapis.com) — web fonts.
- FlagCDN (flagcdn.com) — country flag images.
- Frankfurter.dev (api.frankfurter.dev) — foreign-exchange rates for the currency filter.
We do not currently use analytics providers, marketing pixels, advertising trackers or payment processors. Private messaging is provided within the Platform itself; we do not currently use a separate external messaging provider. Message attachments are not sent to third-party services other than the hosting and storage provider described above.
7. International transfers
Some providers may process data outside Sweden or the EU/EEA. Where this happens, Oskar Fornstedt AB seeks to rely on legally recognized safeguards (such as European Commission adequacy decisions or Standard Contractual Clauses) where required. You may request further information at org.hestasales@gmail.com.
8. Retention
- Account and profile data — while the account is active and needed to provide the service.
- Listing data — while necessary to operate, moderate and document the listing.
- Active profile, listing, contact and media data — removed through the tested account-deletion workflow when you delete your account.
- Messages and message attachments — kept for as long as the conversation exists, so that both participants can continue to see it. Attachment records are removed together with the message or conversation they belong to. Files that fail to attach to a message during sending are removed again.
- We have not set a fixed calendar period after which ordinary message attachments are deleted automatically; they are retained under the criteria above and removed or anonymised when they are no longer required for the purposes described in this policy.
- Messages, attachments or copies of them connected to a report, dispute, suspected fraud, rule enforcement or a legal obligation may be retained longer than the ordinary conversation, for as long as reasonably needed for that purpose.
- Automatic database backups — deleted database information may remain in backups for up to approximately 14 days before the backup expires or is overwritten.
- Browser draft data — remains locally until submitted, deleted, cleared by the application or removed by you or your browser.
- Legal acceptance records — retained as long as reasonably necessary to document agreements and to establish, exercise or defend legal claims.
- Report and moderation records — retained only as long as reasonably needed to investigate, enforce rules, meet legal duties or handle legal claims.
- Security and provider logs — retained under provider-controlled settings for as long as reasonably necessary for security, operations, legal obligations or legal claims.
No category is retained indefinitely. Information that is no longer required is deleted or anonymised.
9. Your rights
Subject to conditions in the GDPR, you have the right to access, correction, deletion, restriction, objection, data portability (where applicable) and, where processing is based on consent, withdrawal of consent. These rights also cover personal data contained in private messages and in images and videos you have sent or received through the Platform.
These requests are handled manually; there is currently no automatic self-service export or deletion function for message content. Note that a conversation involves another person, so a request may also affect information that concerns them, which can limit what we are able to delete or disclose.
Submit requests to org.hestasales@gmail.com. We may need to reasonably verify your identity before fulfilling a request. Some data may need to be retained where required by law or necessary to establish, exercise or defend legal claims.
You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, imy.se.
10. Automated decisions
Hestasales does not currently make solely automated decisions that produce legal or similarly significant effects concerning you.
11. Security
We use appropriate technical and organizational measures — including access control, row-level security, private storage with participant-only access rules, time-limited access links for message attachments, encryption in transit, restricted admin roles and audit records — to protect personal data. Messages and attachments are not end-to-end encrypted. No system is completely secure.
12. Minors
- Public browsing has no age restriction.
- Accounts require age 13 or older.
- Users aged 13–17 require guardian approval, may only use ordinary buyer functionality, and may not act as a seller.
- Seller activity requires age 18 or older.
- Hestasales does not intentionally allow accounts for children under 13. If you believe such an account exists, please contact us so we can delete it.
13. Contact
Oskar Fornstedt AB
Bemersberg 3, 743 82 Bälinge, Sweden
org.hestasales@gmail.com
