unify

legal

privacy policy

how unify collects, uses, shares and protects your personal data across the unify student marketplace — and the rights you have over it.

effective date
15 August 2026
version
2.0
applies to
all Student Users, Partner Vendors and Visitors
region
UK & US operations

summary — what you need to know

Unify collects the personal data necessary to operate a student marketplace: your account details, transaction records, listing content and platform usage analytics. We do not sell your data. We do not collect device location. Payment card data is handled exclusively by our payment processor (Stripe) and never passes through our servers. You have the right to access, correct, delete and export your data at any time. For any questions, contact hello@unifymarketplace.com.

01Who we are and how to contact us

Unify Marketplace Ltd (“Unify”, “we”, “us”, or “our”) is a company incorporated under the laws of England and Wales. We operate the Unify marketplace platform — a student-exclusive digital and campus-based marketplace available via our website and mobile applications (collectively, the “Platform”).

Registered address: Unify Marketplace Ltd, 46 Marlborough Place, London NW8 0PL, United Kingdom.

Privacy contact: hello@unifymarketplace.com

Data controller: Unify Marketplace Ltd is the data controller for all personal data processed in connection with the Platform.

Data protection officer: Unify does not currently have a formally designated Data Protection Officer (DPO). All data protection enquiries should be directed to hello@unifymarketplace.com. A DPO will be appointed as the business scales, and this Policy will be updated to reflect that appointment.

For users located in the United States, Unify Marketplace Ltd is the responsible entity for data processed in connection with your use of the Platform, subject to the additional US state-specific disclosures set out in Section 13 of this Policy.

02Scope of this policy

This Privacy Policy applies to all personal data collected, processed, or stored by Unify in connection with:

  • Registration and use of the Unify Platform (website and mobile applications);
  • All Student User accounts and associated activity;
  • Partner Vendor accounts and onboarding;
  • Use of the AI-assisted listing tool;
  • Transactions processed through the Platform;
  • Use of messaging, community, and society hub features;
  • Marketing and communications sent by Unify; and
  • Any other interaction with Unify’s services, whether online, at a campus handover, or at a Unify Collect collection point.

This Policy does not govern the privacy practices of Partner Vendors, who are independent data controllers in respect of personal data they separately collect from Student Users.

03Personal data we collect

3.1 Account and identity data

  • Full name;
  • University institutional email address (used for eligibility verification and platform login);
  • Graduation year and university course;
  • University or campus affiliation (derived from your institutional email domain);
  • Encrypted password (Unify does not store or have access to your plaintext password);
  • Date of account creation;
  • Profile information you choose to make publicly visible on the platform, including your display name and profile photo (if uploaded); and
  • Account settings and preferences.

3.2 Transaction data

  • Records of items listed, purchased, or exchanged on the Platform;
  • Transaction amounts and timestamps;
  • Agreed meetup location and time records, and handover confirmation records (including the transaction confirmation code issued to the Buyer and entered by the Seller);
  • Unify Collect booking, collection, storage, and condition records (including the photographs taken at the point of collection);
  • Dispute submissions and resolution records; and
  • Commission and settlement records (for Partner Vendors).

3.3 Listing and AI tool data

When you create a listing using the Platform, including where you use the Unify AI-assisted listing tool, we collect and store:

  • Item descriptions, titles, and category information you submit;
  • Images you upload in connection with a listing;
  • AI-generated description drafts produced in response to your inputs; and
  • Your edits and the final approved listing content.

important: how your AI listing data is used

Images and text you upload when using the AI listing tool are processed on Unify’s own servers to generate listing descriptions. This content is retained for the duration the listing is active and for up to 12 months thereafter for platform integrity and dispute resolution purposes. Your uploaded content is not used to train, fine-tune, or otherwise improve any AI or machine learning model. It is processed solely for the purpose of generating your listing output.

3.4 Platform usage and analytics data

We collect behavioural and technical data about how you interact with the Platform, including:

  • Pages and features accessed, and navigation sequences;
  • Listing views, clicks, search queries, and time spent on listings;
  • Session duration and frequency of use;
  • Device type, operating system, and browser type;
  • IP address (used for security and fraud prevention only); and
  • Referral source (how you arrived at the Platform).

We do not collect or process device GPS or precise location data at any point. Your campus affiliation is determined solely by your institutional email address at registration.

3.5 Communications data

  • Messages exchanged through the Unify in-platform messaging system and community features;
  • Content posted within society hubs, course groups, and accommodation channels;
  • Dispute submissions and supporting evidence submitted to the disputes portal;
  • Support and enquiry correspondence sent to Unify; and
  • Marketing communication preferences and opt-in records.

3.6 Partner Vendor data

In addition to the above, Partner Vendors provide:

  • Business registration details and legal entity information;
  • Authorised signatory name and contact details;
  • Bank account details for settlement remittance (stored securely and used solely for payment purposes);
  • VAT or tax identification numbers; and
  • Settlement statements and financial transaction records.

3.7 Data we do not collect

For the avoidance of doubt, Unify does not collect:

  • Payment card numbers, CVV codes, or full bank account details from Student Users — these are handled exclusively by Stripe and never transmitted to or stored on Unify’s servers;
  • Device GPS or precise location data of any kind;
  • Biometric data; or
  • Special category data as defined under UK GDPR Article 9 — unless voluntarily provided in a support context, in which case it is treated with the highest level of protection and processed solely to address the matter raised.

3.8 Calendar integration data

Where you choose to connect a third-party calendar service to the Unify platform — including Google Calendar or Microsoft Outlook — Unify requests read-only access to your calendar solely for the following purposes: (a) displaying your existing schedule within the Unify calendar interface so you can identify availability for meetings, handovers, and events; (b) placing your confirmed tickets, RSVPs, and pickups alongside that schedule inside the Unify calendar; and (c) surfacing society schedules and recurring events you have subscribed to within the platform. Unify never creates, edits, or deletes events in your connected calendar — the integration only reads from it.

Unify reads your primary calendar only, covering events from approximately 30 days in the past onwards. For each event we store the title, description, location, start and end times, whether it is an all-day event, whether it has been cancelled, and a small set of provider identifiers (the provider’s own event ID, a link back to the event in Google Calendar or Outlook, a version tag, and, for repeating events, the recurring-event ID). We do not access attendee or guest lists, video-call join links, attachments, or any calendar other than your primary one.

These events are stored on Unify’s servers, linked to your account and visible only to you, for as long as the calendar remains connected. Disconnecting a calendar revokes the access grant and deletes every event Unify pulled from it; deleting your account deletes them along with the rest of your data. We do not share calendar data with any third party, including Partner Vendors, and we never use it for advertising or to develop, improve, or train any AI or machine learning model. Connecting a calendar service is entirely optional and can be disconnected at any time through your account settings. The legal basis for processing calendar data is your consent, which may be withdrawn at any time without affecting your ability to use other platform features.

google api services user data policy

Unify’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google Workspace API user data — raw, aggregated, anonymised, or derived — is never used, transferred, or sold to develop, improve, or train generalised or foundational artificial intelligence or machine learning models, and is never transferred to any third-party AI or ML service. Unify’s AI features operate only on content you post to the Unify platform itself and have no access to calendar data.

04How we use your personal data

The table below sets out the primary purposes for which we use personal data, the legal basis under UK GDPR, and the applicable retention period.

Category of dataPurposeLegal basis (UK GDPR)Retention period
Account & identityAccount creation and management; student eligibility verification; login and authentication.Contract (Art. 6(1)(b))Account active period + 2 years post-closure
TransactionProcessing purchases; escrow and handover confirmation; Unify Collect bookings and storage; dispute resolution; Vendor settlement statements.Contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c))6 years from transaction date
AI listing toolGenerating AI-assisted listing descriptions from uploaded images and text. Not used for model training.Contract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f))Active listing period + 12 months
Platform analyticsUnderstanding usage patterns; improving features; fraud and abuse detection; platform security.Legitimate interests (Art. 6(1)(f))13 months rolling, then anonymised
Communications & communityResponding to enquiries; dispute management; moderation of community features; audit trail of platform interactions.Contract; Legitimate interests3 years from last interaction
Marketing preferencesSending opt-in promotional emails and push notifications about new vendors, features, and platform updates.Consent (Art. 6(1)(a)) — withdrawable at any timeUntil consent withdrawn + 1 year suppression record
Vendor financialProcessing commission deductions and settlements; issuing invoices; tax and financial reporting compliance.Contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c))6 years from transaction date
Security & fraudDetecting fraudulent listings, account misuse, payment fraud, and prohibited item listings. IP address analysis.Legitimate interests (Art. 6(1)(f)); Legal obligation12 months active; flagged cases 3 years
Calendar integrationRead-only sync of your connected calendar for display within Unify; placing confirmed tickets, pickups and society schedules alongside it. Never used for advertising or AI/ML model training.Consent (Art. 6(1)(a)) — withdrawable at any timeUntil you disconnect the calendar or delete your account; disconnecting deletes the synced events

Where we rely on ‘legitimate interests’ as our legal basis, we have assessed that our interests do not override your fundamental rights and freedoms. You may request a copy of our legitimate interests assessment by contacting hello@unifymarketplace.com.

05Legal bases for processing

We process your personal data under one or more of the following legal bases under UK GDPR:

  • Contract performance (Article 6(1)(b)): processing necessary to deliver platform services, process transactions, manage listings, coordinate campus handovers, and operate the Unify Collect service.
  • Legal obligation (Article 6(1)(c)): processing required to comply with applicable law, including financial record-keeping, tax reporting, and responding to lawful requests from regulatory authorities.
  • Legitimate interests (Article 6(1)(f)): processing for our legitimate business purposes including fraud prevention, platform security, and analytics, where these interests are proportionate and do not override your rights.
  • Consent (Article 6(1)(a)): processing based on your freely given and informed consent, used for marketing communications and calendar integration. You may withdraw consent at any time without affecting the lawfulness of prior processing.

06How we share your personal data

We do not sell your personal data. We do not share your data with third parties for their own marketing purposes. Data is shared only in the following circumstances:

6.1 Other platform users

When you transact with another user, limited information necessary to complete the transaction is shared — for example, a display name, the agreed campus meetup location and time, and the transaction confirmation code used to confirm handover. Your full name, institutional email address, and financial details are never shared with other users, with one exception you opt into: where an Ambassador reaches Campus Lead status under clause 25 of our Terms of Service, that reward includes a named profile visible to other Users at their university, published only as part of accepting the role. Additionally, certain information you submit to the platform is publicly visible to all registered Unify users by default. This includes your display name, profile photo (if uploaded), and all active listing content — including item descriptions, images, prices, and condition details. Unify operates as an open campus marketplace, meaning listing images and content are visible to any logged-in user browsing the platform. You should not include personal contact details, sensitive information, or anything you would not wish other users to see within your listing descriptions or profile. Unify is not responsible for any information you voluntarily make public through your listings or profile.

6.2 Partner Vendors

When you purchase from a Partner Vendor, the Vendor receives only the minimum information necessary to fulfil the specific transaction. Partner Vendors are contractually prohibited from using this data for any other purpose. They are independent data controllers for any data they separately collect.

6.3 Payment processor (Stripe)

Payment transactions are processed by Stripe (or an equivalent regulated payment provider). When you make a payment, you interact directly with Stripe’s secure environment. Unify does not receive, store, or process your payment card number, CVV, or full bank account details. Stripe’s processing of your payment data is governed by Stripe’s own Privacy Policy at stripe.com/privacy.

6.4 Technology and service providers

We engage third-party service providers acting as data processors on our behalf, under binding data processing agreements that meet UK GDPR requirements. These include cloud hosting providers, analytics providers, email delivery providers, and customer support tooling. We do not permit processors to use your data for their own purposes.

6.5 Legal and regulatory disclosure

We may disclose personal data to law enforcement, regulators, or courts where required by applicable law, or where we have a good-faith belief that disclosure is necessary to comply with a legal obligation, protect the safety of users or the public, or detect and prevent fraud or criminal activity.

6.6 University authorities

In cases involving serious breach of academic integrity, credible safety threats, or conduct that violates both Unify’s Termsand a university’s code of conduct, Unify reserves the right to share relevant information with the relevant university authority. We will do so only where there is a clear legal basis or overriding legitimate interest, and will inform the user where legally permissible.

6.7 Business transfer

In the event of a merger, acquisition, or sale of Unify’s business assets, personal data may be transferred to the acquiring entity, subject to equivalent data protection obligations. Users will be notified of any transfer that materially affects how their data is used.

6.8 Data we do not sell, and our approach to data value

Unify does not sell personal data to any third party and has no intention of doing so. Where Unify derives commercial value from platform data, it does so exclusively through privacy-respecting means that do not involve the transfer of personal data. For example, Unify may produce and share aggregated, fully anonymised insights with universities, student services, or Partner Vendors — such as category-level demand trends or platform usage patterns at a given campus. Such reports contain no personal data, cannot be used to identify any individual, and require no user consent. No raw, identifiable, or pseudonymised personal data is included in or derivable from these reports.

07International data transfers

Unify operates in both the United Kingdom and the United States. Personal data collected from UK users may be transferred to and processed in the US in connection with our US operations, and vice versa. Where we transfer personal data from the UK to countries not deemed adequate by the ICO, we rely on one or more of the following safeguards:

  • UK International Data Transfer Agreements (IDTAs) or equivalent standard contractual clauses approved by the ICO;
  • The UK-US Data Bridge (where applicable); or
  • Another lawful transfer mechanism recognised under UK GDPR.

You may request further information about the specific transfer mechanisms in place by contacting hello@unifymarketplace.com.

08Data security

Unify implements appropriate technical and organisational security measures to protect personal data against unauthorised access, loss, destruction, or disclosure, including:

  • Encryption of data at rest and in transit using industry-standard protocols;
  • Encrypted storage of user passwords (plaintext passwords are never stored);
  • Access controls restricting data access to authorised personnel on a need-to-know basis;
  • Regular security reviews and vulnerability assessments;
  • Data processing agreements with all third-party processors; and
  • Incident response procedures for data breaches.

No method of transmission over the internet is 100% secure. In the event of a personal data breach likely to result in risk to your rights and freedoms, we will notify you and the ICO in accordance with UK GDPR Articles 33 and 34.

09Cookies and tracking technologies

Unify uses cookies and similar tracking technologies on our website and mobile applications to operate the platform, maintain session security, and collect the analytics data described in Section 3.4. We use the following categories of cookies:

  • Strictly necessary cookies: required for the Platform to function. These cannot be disabled. They include session management, login authentication, and security tokens.
  • Analytics cookies: used to understand how users interact with the Platform (pages visited, session duration, feature usage). Data is collected in pseudonymised or aggregated form. These cookies are enabled by default but can be disabled via your account settings or browser controls.
  • Preference cookies: used to remember your settings and preferences (e.g. language or notification preferences). These are optional and can be disabled without affecting core platform functionality.
  • Marketing and advertising cookies: used to deliver relevant promotional content and, where applicable, to enable third-party advertising or retargeting tools. These cookies are not enabled by default and are only activated where you have given your explicit, prior opt-in consent via our cookie consent interface. You may withdraw consent at any time through your account settings or browser controls, and withdrawal will take effect within 5 business days. As of the Effective Date of this Policy, marketing cookies are not currently active on the Unify platform. If and when they are introduced, you will be notified and asked for fresh consent before any marketing cookie is placed on your device.

We do not permit third-party advertisers to place cookies on our platform without your explicit consent. You can manage all cookie preferences through your browser settings or, where applicable, through the in-app settings menu. Disabling analytics or preference cookies will not affect your ability to use the core platform.

Our public website and blog are partly ad-funded and do use advertising and analytics cookies — but only with your consent. Those are covered separately by our Cookie Policy, and you can change your choices at any time via the “cookie settings” link in the footer of every page.

10Marketing communications

We send marketing communications — including promotional emails and push notifications about new vendors, platform features, and updates — only where you have given your prior opt-in consent at registration or through your account settings.

You may withdraw consent at any time by:

  • Clicking the ‘Unsubscribe’ link in any marketing email;
  • Adjusting notification preferences in the Unify app settings; or
  • Contacting hello@unifymarketplace.com.

Please allow up to 5 business days for opt-out requests to take effect. We retain a record of your consent and withdrawal for compliance purposes for 1 year following withdrawal. We do not share your contact details with Partner Vendors or third parties for their own marketing.

11Data retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. The specific retention periods are set out in Section 4. Our general principles are:

  • Active accounts: data is retained for the full duration your account is active.
  • Closed accounts: transaction records, dispute records, and compliance data are retained for 6 years after account closure in accordance with UK legal retention requirements. Account profile data is deleted or anonymised within 90 days of closure, subject to outstanding disputes or legal obligations.
  • AI listing tool data: retained for the period the listing is active and up to 12 months thereafter. Content connected to disputes may be retained for the duration of the dispute resolution process.
  • Analytics data: retained on a rolling 13-month basis, then aggregated and anonymised.
  • Marketing records: consent and withdrawal records retained for 1 year following withdrawal.
  • Ratings and reviews: retained for platform integrity purposes for 3 years following account closure, after which they are anonymised.
  • Calendar data: events synced from a connected Google Calendar or Outlook calendar are retained for as long as that calendar remains connected. Disconnecting it deletes them immediately; they are also deleted when you close your account.

Where data is no longer required, it is securely deleted or anonymised. Anonymised data that can no longer identify individuals may be retained indefinitely for statistical purposes.

12Your rights as a data subject

Under UK GDPR, you have the following rights. We will respond to all valid requests within one calendar month, extendable by two further months for complex requests with prior notice.

  • Right of access (Article 15): request a copy of the personal data we hold about you and how we use it.
  • Right to rectification (Article 16): request correction of inaccurate or incomplete data.
  • Right to erasure (Article 17): request deletion of your data where it is no longer needed, consent is withdrawn, or processing is unlawful, subject to legal retention obligations.
  • Right to restriction (Article 18): request that we restrict processing of your data in certain circumstances, such as while an accuracy dispute is resolved.
  • Right to data portability (Article 20): receive your personal data in a structured, machine-readable format where processing is based on consent or contract and carried out by automated means.
  • Right to object (Article 21): object to processing based on legitimate interests, including profiling. You have an absolute right to object to direct marketing, which we will honour immediately.
  • Right to withdraw consent (Article 7(3)): withdraw consent at any time where processing is consent-based. Withdrawal does not affect the lawfulness of prior processing.
  • Right to lodge a complaint: lodge a complaint with the ICO at ico.org.uk if you believe we have mishandled your data.

To exercise any of the above rights, contact hello@unifymarketplace.comwith the subject line “Data Subject Request” and include verification of your identity. We do not charge for standard requests but may apply a reasonable fee for manifestly unfounded or excessive requests.

13Additional rights for US users

Unify is committed to complying with applicable US state privacy legislation across all US campus locations. As our US presence expands, state-specific disclosures will be incorporated into the relevant Campus Addendum. The following rights apply where mandated by applicable state law.

13.1 California users (CCPA / CPRA)

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • The right to know what personal information we collect, use, disclose, and sell (we do not sell personal information);
  • The right to delete personal information we hold about you, subject to legal exceptions;
  • The right to correct inaccurate personal information;
  • The right to opt out of the sale or sharing of personal information for cross-context behavioural advertising (Unify does not sell or share personal information for advertising purposes);
  • The right to limit the use of sensitive personal information; and
  • The right to non-discrimination for exercising your privacy rights.

To submit a CCPA/CPRA request, contact hello@unifymarketplace.comwith the subject line “CCPA Request”. We will respond within 45 calendar days, extendable by a further 45 days where reasonably necessary.

13.2 Other US state users

Users in Virginia (VCDPA), Colorado (CPA), Texas (TDPSA), and other states with active comprehensive privacy legislation have rights broadly equivalent to those described in Section 12, including rights of access, correction, deletion, portability, and opt-out from certain data processing. These rights are available upon request via hello@unifymarketplace.com. Campus Addenda will be updated to reflect state-specific requirements as Unify’s operations expand.

13.3 No sale of personal data

Unify does not sell personal data to any third party. Unify does not share personal data with third parties for cross-context behavioural advertising. This applies to users in all jurisdictions. Advertising cookies on our public website and blog run only with your consent and are described in our Cookie Policy.

14Users under 18

The Unify Platform is designed and operated as a student community. Eligibility is based on enrolment at a recognised university or higher education institution rather than on age, verified through a valid institutional email address, which means a small number of Users may be under the age of 18. We do not knowingly collect personal data from any individual who is not an enrolled student. If we become aware that we have inadvertently collected data from a person who is not eligible to use the Platform, we will take prompt steps to delete it.

Where a User is under 18, their personal data is processed on the same legal bases and subject to the same retention periods set out in this Policy, together with the additional protections set out in clause 26 of our Terms of Service. Our platform design principles are consistent with the UK Children’s Code (Age Appropriate Design Code) to the extent applicable to our platform and user base, and we do not use manipulative design techniques or engagement-maximising mechanisms that could be harmful to younger users.

Reports concerning the safety of a User who is or may be under 18 are treated as the highest priority. Such reports are reviewed by a human member of the Unify team and are not subject to automated processing alone, and relevant data is preserved and disclosed to law enforcement and child protection authorities where required by law. To raise such a concern, contact hello@unifymarketplace.com marked URGENT — CHILD SAFETY.

15Automated decision-making and profiling

Unify uses automated systems for limited purposes, including fraud and abuse detection, content moderation filtering, and analytics-based personalisation within the Platform. None of these processes produce legally significant or similarly significant decisions without human review. Where an automated flag results in account suspension or listing removal, a member of the Unify team reviews the decision before any permanent action is taken. You have the right to request human review of any automated decision that affects your account.

16Third-party links and external platforms

The Platform may contain links to Partner Vendor websites or other external resources. These third parties operate independently and are not governed by this Privacy Policy. We encourage you to review the privacy policy of any third-party site you visit via a link on the Unify Platform.

17Changes to this privacy policy

We may update this Policy from time to time. Where changes are material — meaning they significantly affect how we collect or use your data or reduce your rights — we will notify you by email to your registered address and via in-platform notification at least 14 calendar days before the changes take effect.

The current version of this Policy, with its effective date, is always accessible within the Platform and on our website. Continued use of the Platform after the effective date of any update constitutes acceptance of the revised Policy.

18How to contact us

For any questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact us at the details below. We aim to respond to all privacy enquiries within 5 business days.

  • Email: hello@unifymarketplace.com
  • Post: Data Privacy Team, Unify Marketplace Ltd, 46 Marlborough Place, London NW8 0PL, United Kingdom
  • UK supervisory authority: Information Commissioner’s Office (ICO), ico.org.uk · 0303 123 1113

For urgent matters (data breach notifications, time-sensitive rights requests), please mark your communication: URGENT — DATA PRIVACY.

© 2026 Unify Marketplace Ltd. All rights reserved. Published in accordance with UK GDPR Articles 13 & 14 and applicable US state privacy legislation.

see also: cookie policy — how we use cookies on the website and blog