Legal · version 2026-09-26
Privacy Policy
Plain English first, legal detail second. We collect what a licensed buyer of used electronics has to collect, protect it, and delete it on a schedule.
The short version
- We never sell or share your personal information for advertising. No ad cookies, no data brokers.
- To buy a device from you we need your name, contact details, a shipping address, a payout method and — because Idaho secondhand-dealer rules require it — a government ID and date of birth. The ID number is encrypted and deleted 3 years after your last sale.
- Phone IMEI/serial numbers are checked against lost/stolen databases and may be reported to law enforcement as required by local ordinance.
- All personal data on the device itself is erased to NIST SP 800-88 before resale or recycling. You receive a certificate.
- You can access, export, correct or delete your data at any time from your account or via this form.
1. Who we are
DoctorPCB LLC (doing business as DoctorPCB), 123 Example Street, Meridian, ID 83642 ("we", "us"), is the data controller for personal data processed through https://doctorpcb.com. Privacy contact: privacy@doctorpcb.com · (208) 555-0100.
2. What we collect and why
| Data | Purpose | Legal basis (GDPR) | Kept for |
|---|---|---|---|
| Device model and condition answers; a temporary quote cookie | Produce and remember your offer | Pre-contract steps (Art. 6(1)(b)) | Unaccepted quotes: 90 days |
| Name, email, phone, password hash, Google account ID (if you use Google sign-in) | Your account, notifications about your offer | Contract (6(1)(b)) | Until you delete your account, then anonymised |
| Ship-from address | Prepaid label, return of declined devices, address verification via EasyPost | Contract (6(1)(b)) | Duration of account; transaction snapshot 7 years |
| Legal name, date of birth, government ID type, issuer and number (encrypted), last four digits | Secondhand-dealer identification and record-keeping under Idaho municipal ordinances; 18+ verification; fraud prevention | Legal obligation (6(1)(c)); legitimate interest in fraud prevention (6(1)(f)) | 3 years after your last transaction |
| IMEI / serial number, activation-lock attestation | Stolen-device screening; ordinance reporting; resale eligibility | Legal obligation (6(1)(c)); legitimate interest (6(1)(f)) | 7 years (transaction ledger) |
| Hazard disclosures (battery/glass/liquid) and your acceptance record (terms version, time, hashed IP) | Carrier and DOT hazmat compliance; proof of agreement | Legal obligation (6(1)(c)); contract | 7 years |
| Payout details: Stripe Connect account ID, or PayPal email, or payee name for a check. We never store bank or card numbers. | Paying you | Contract (6(1)(b)) | 7 years (financial records) |
| Inspection photos and findings | Justify a revised offer; dispute evidence | Contract; legitimate interest | 7 years |
| Hashed IP address, user agent, security and audit logs | Security, rate limiting, breach investigation | Legitimate interest (6(1)(f)) | 12 months |
| Cookie consent record | Prove your consent choice | Legal obligation (ePrivacy) | 182 days |
| Analytics (Google Analytics 4, IP anonymised) | Understand which pages help sellers | Consent (6(1)(a)) — only if you accept analytics cookies | 14 months (GA4 setting) |
| Contact form messages | Answer you | Legitimate interest | 24 months |
We do not collect race, religion, health or other special-category data, and we do not knowingly deal with anyone under 18.
3. Who receives your data (processors)
- Stripe, Inc. — payouts via Stripe Connect. Stripe collects your bank details directly under its own privacy policy; we only receive an account identifier and payout status.
- EasyPost and the carrier on your label (USPS, UPS or FedEx) — address verification, labels and tracking.
- Hostinger — web hosting.
- Google — optional Google sign-in; reCAPTCHA on public forms; Analytics only with consent.
- Email delivery provider — transactional email.
- Law enforcement and municipal licensing authorities — transaction records where an ordinance, subpoena or court order requires it.
- Certified electronics recyclers — receive devices only after data sanitisation; they never receive your personal data.
We do not sell personal information and have not done so in the preceding 12 months. We do not "share" it for cross-context behavioural advertising (CCPA/CPRA definitions).
4. International transfers
We are a US business. If you are in the EU/UK your data is transferred to the United States under the processors' Standard Contractual Clauses and, where they are certified, the EU-US Data Privacy Framework.
5. Your rights
Wherever you live, you can:
- Access / export a machine-readable copy of your data (JSON) instantly from your account.
- Correct your profile and addresses yourself; ask us to correct anything else.
- Delete your account. We remove your name, contact details, addresses, identity document and login immediately. Records we must keep by law (the 7-year transaction ledger, the 3-year identity record for completed purchases) are retained under GDPR Art. 17(3)(b) and pseudonymised where the law allows.
- Object to processing based on legitimate interest, restrict processing, and withdraw consent (cookies: cookie settings; marketing: your account).
- Lodge a complaint with your supervisory authority (EU/UK) or the Idaho Attorney General's Consumer Protection Division.
Submit any request at https://doctorpcb.com/privacy/my-data or email privacy@doctorpcb.com. We verify requests by email and respond within 30 days (45 days for California residents, extendable once). We will not discriminate against you for exercising your rights. You may designate an authorised agent; we will ask the agent for proof of your written permission.
6. Security
TLS on every page; passwords hashed with bcrypt; government ID numbers encrypted at rest with AES-256-GCM using a key held outside the web root; access to decrypted values is logged per view; inspection photos stored outside the web root; IP addresses stored only as salted hashes; sessions expire after inactivity; CSRF tokens and rate limiting on all forms; content-security-policy with per-request nonces. Read more at Data security.
Breach notification. If a breach of unencrypted personal information occurs we will notify affected Idaho residents without unreasonable delay in accordance with Idaho Code §28-51-104 through §28-51-107, and EU/UK data subjects within 72 hours where required by GDPR Art. 33–34.
7. Cookies
See the Cookie Policy. Strictly necessary cookies only, unless you opt in to analytics. We honour the Global Privacy Control signal as an opt-out of analytics.
8. Children
Our service is for adults 18 and over. We do not knowingly collect data from anyone under 18; if you believe a minor has provided data, contact us and we will delete it.
9. Changes
We will post changes here with a new version number and, for material changes, email account holders. This version: 2026-09-26.
Questions: privacy@doctorpcb.com.