Privacy Policy
Last updated: 23.04.2026
1. Data Controller
Cross.ge is an online car marketplace operating in Georgia, available at cross.ge. As the data controller, we are responsible for the processing of your personal data in accordance with the Law of Georgia on Personal Data Protection.
2. Data We Collect
- Phone number — for account verification and listing publication (SMS code)
- Email — for authentication, sign-up confirmation, password reset, and transactional notifications
- Name — displayed to other users on your listings
- Listing data — vehicle information, photos, prices you publish
- Messages — communications between users via the built-in chat
- Pseudonymized usage signals — viewed listings and search queries, stored on your device (localStorage) to personalize recommendations. If you consent to analytics (see Section 6), we also use third-party web analytics services — see Section 5.1 for details.
- IP address hash — a one-way cryptographic hash of your IP address (not the IP itself) used to prevent view count manipulation
3. Purpose of Processing
- Account creation and authentication via OTP
- Publishing and managing car listings
- Enabling communication between buyers and sellers
- Ensuring platform security and preventing fraud
- Improving the service based on aggregated usage patterns
4. Legal Basis
We process your data based on: (a) your consent when creating an account; (b) contract performance — providing the marketplace service; (c) legitimate interest — platform security and fraud prevention.
5. Data Storage
Your data is stored on secure servers within the EU (Supabase infrastructure). Data is retained for as long as your account is active. Upon account deletion, all personal data is permanently removed within 30 days.
5.1. Sub-processors
To deliver the service we use the following data processors, each bound by confidentiality and providing an adequate level of protection:
- Supabase (EU, Ireland) — database, file storage, authentication.
- Vercel (USA, SCC) — frontend hosting and serverless functions. Data transfer to the USA under Standard Contractual Clauses.
- Cloudflare (USA, SCC) — DNS, DDoS protection, Turnstile captcha. Turnstile collects anonymized browser behavioral signals (mouse movements, timing, fingerprint) to distinguish humans from bots; these signals are not linked to your account. Cloudflare also processes IP addresses and request metadata for security purposes.
- Resend (EU, Ireland) — transactional email (sign-up confirmation, password reset).
- Twilio (USA, SCC) — SMS for phone verification on the first listing publication.
- Anthropic (USA, SCC) — processing of AI-search and AI-assistant queries (query text only, not linked to your account), and refining the location of license plates in vehicle photos before automatic masking.
- Telegram — admin-only service notifications about registrations and errors.
- PostHog (USA) — web analytics and session recording for logged-in users; only activates after you consent to analytics via the cookie banner.
- Google Analytics (Google Ireland Ltd., EU/USA) — website traffic analytics; only activates after you consent to analytics via the cookie banner.
- Sentry (USA) — technical error and crash tracking to keep the service reliable.
- Upstash (USA) — temporary storage for rate-limiting and pending registration data until email confirmation.
- PlateRecognizer (image processing) — automatic detection of license plates in vehicle photos so they can be masked before a listing is published.
6. Cookies & Local Storage
We use strictly necessary cookies for session management and authentication (cross_session). If you accept optional analytics, in addition to storing browsing signals locally (localStorage), we also use third-party web analytics services — PostHog and Google Analytics — to understand site usage; these only activate after your consent and do not run before that. We do not use third-party advertising cookies and do not share data with advertising networks — ads on the site are served directly, without third-party ad technology. You can change your preferences at any time via the cookie banner or the link in the site footer.
7. IP Hash Collection for View Tracking
When you view a listing, we collect a one-way cryptographic hash of your IP address. This is not your IP address itself — it is an irreversible transformation that cannot be used to identify you or determine your location.
We use this hash solely to prevent view count manipulation and ensure fair ranking of listings on our platform.
Anonymous view records (those not linked to a registered account) are automatically deleted after 30 days.
Legal basis: legitimate interest — fraud prevention and ensuring the integrity of the marketplace ranking system, under the Law of Georgia on Personal Data Protection.
You have the right to request deletion of any data associated with your IP hash by contacting us at support@cross.ge.
8. Your Rights
Under the Law of Georgia on Personal Data Protection, you have the following rights:
- Right of access — request a copy of your personal data
- Right to rectification — correct inaccurate data
- Right to erasure — delete your account and all associated data
- Right to restriction — limit how your data is processed
- Right to portability — receive your data in a structured format
- Right to object — object to data processing
- Right to withdraw consent — at any time without affecting prior processing
9. International Data Transfer
Primary data storage is in the EU (Supabase, Ireland). Part of the processing is performed by third-party providers in the USA (Vercel, Cloudflare, Twilio, Anthropic) — see section 5.1. Transfers to the USA are carried out under Standard Contractual Clauses (SCCs), which provide a level of protection equivalent to EU and Georgian law. No data is transferred to jurisdictions without such guarantees.
10. Children's Privacy
Our service is intended for users aged 18 and older. We do not knowingly collect data from children under 18. If we discover that a child under 18 has created an account, we will promptly delete it.
11. Security Incident Notification
In the event of a security breach that poses a risk to your rights and freedoms, we will notify you and the supervisory authority (the Personal Data Protection Service of Georgia, PDPS) within 72 hours of becoming aware of the incident, as required by the Law of Georgia on Personal Data Protection. The notification will describe the nature of the incident, the categories of data affected, the likely consequences, and the measures being taken.
12. Supervisory Authority
You have the right to lodge a complaint with the Personal Data Protection Service of Georgia (PDPS) at pdps.ge if you believe your data protection rights have been violated.
Contact
For any questions regarding your personal data, contact us at: support@cross.ge