Privacy policy
Last updated Oct 11, 2026
This policy explains what personal data Silvertistel collects, why, who else handles it, how long it’s kept and what rights you have. We collect as little as we can.
Who we are
Silvertistel is based in Sweden and is responsible for the personal data described here (the controller, in data protection terms). You can reach us at contact@example.com.
What we collect and why
- Your account. With an email and password we store your name, email address and a hashed version of your password, never the password itself. If you sign in with Google, Google gives us your name, email address and profile picture, and we store an ID linking your Google account along with the sign-in tokens Google issues. We also store whether your email is verified and when you joined. We use this to provide your account (legal basis: contract).
- Favorites. The pieces you save, so you can find them again (contract).
- Sourcing requests. Your message, budget if you give one and the piece you ask about, linked to your account. We use them to look for the piece and reply to your account’s email address (contract).
- Corrections. Your message, your email address if you give one, and your account if you’re signed in. We use them to keep the archive accurate and, if needed, to ask you a question (legitimate interest).
- Emails you send us. Your message and email address, to answer you (legitimate interest).
- IP addresses. When you sign in, create an account, reset your password, search or send a form, your IP address (and for some actions your account or a hashed version of your email address) is used briefly to limit repeated attempts. Our hosting provider also records technical details of requests, such as IP address, browser and page, in its server logs. This keeps the site secure and working (legitimate interest).
- Page views. We count visits with analytics that doesn’t use cookies or identify you: the page, the site you came from, and your country, browser, operating system and type of device. We use this to see which parts of the archive people use (legitimate interest).
- Error reports. When something on the site fails, a report goes to our error monitoring provider: what failed, on which page, and technical details such as your browser and operating system. Reports don’t include your IP address, account, cookies or what you typed into forms. We use them to find and fix problems (legitimate interest).
When you follow a “Search resale” link, we count the click for that piece and platform without storing your IP address, account or device.
Cookies
We only use cookies the site needs to work: one that keeps you signed in, and a few that protect sign-in and remember which page to return to afterwards. We don’t use analytics, advertising or tracking cookies.
Emails we send
We only email you about your account (verifying your email address, resetting your password) and in reply to your sourcing requests or messages. We don’t send newsletters or marketing.
Who we share it with
We don’t sell your personal data. We use service providers for hosting, the database, email delivery, image storage, rate limiting, analytics and error monitoring. They handle data only on our behalf, under their data processing terms.
If you sign in with Google, Google’s own privacy policy applies to that sign-in. When you follow a link to a resale platform, you leave Silvertistel, and that platform (and any affiliate network) handles your visit under its own policies; we don’t send it your account details.
We may also share data when the law requires it.
Transfers outside the EU
Some of our service providers are based in, or process data in, the United States. These transfers are covered by the EU–US Data Privacy Framework or the European Commission’s standard contractual clauses. Error reports are stored in the EU.
How long we keep it
- Account details, favorites and sourcing requests: until you delete your account.
- Corrections: kept to maintain the archive. If you delete your account, they’re no longer linked to it. Ask us and we’ll delete yours.
- Emails you send us: as long as we need them to handle your message.
- Email verification links expire after 24 hours and password reset links after 1 hour.
- Rate limiting data expires automatically, at the latest after one day.
- Server logs: for the limited time our hosting provider keeps them.
- Error reports: deleted automatically, at the latest after 90 days.
Your rights
You can ask to access, correct or delete your personal data, to restrict or object to how we use it, and to receive it in a portable format. Email us to use these rights; we may need to confirm that a request comes from the account holder, and we reply within one month. You can also delete your account yourself on your profile page.
If you think we handle your data wrongly, you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, imy.se) or the data protection authority where you live.
Changes
When this policy changes, the date at the top changes too. We’ll point out significant changes on the site.