reebee

Privacy statement

Last updated: 13 July 2026

This statement explains which personal data reebee processes, why, and what rights you have (GDPR).

reebee by Network-IT BV · BE 0553.500.113 · Adegemstraat 88, 2800 Mechelen

1. What data we process

Account and profile: email address, username, display name, location, avatar and language preference. Listings: titles, descriptions, photos and product codes you add.

Transactions: orders, payment and refund references (your card or bank details stay with the payment provider, never with us), shipping addresses and tracking data, invoices.

Messages: the content of your conversations on the platform, including an automatic safety score (scam detection).

Verification and security: phone number (OTP), identity-verification status with the chosen provider (itsme/Stripe Identity — we store the outcome, not your ID document), login times and IP addresses.

Tax (legal obligation, DAC7): above the reporting thresholds also national registry or VAT number, address and IBAN.

2. Purposes and legal bases

Performance of the contract: account, listings, buying/selling, payments, shipping, disputes and support.

Legal obligation: accounting and invoices, DAC7 reporting to the tax authorities.

Legitimate interest: fraud and scam prevention, platform security.

Consent: only where required; you can withdraw it at any time.

3. Who we share data with

Service providers needed to run the platform: payment provider (e.g. Stripe or Mollie), shipping partner (e.g. Sendcloud or bpost), identity provider (e.g. itsme or Stripe Identity), email delivery (SMTP) and hosting.

AI services: for optional features such as photo recognition and price suggestions, your listing content may be sent to the administrator-configured AI provider; messages are scanned locally for suspicious patterns.

Authorities: DAC7 seller data to the Belgian tax administration; data to competent authorities where legally required.

We never sell your data and use no advertising tracking.

4. Retention periods

Your account is kept until you delete it. Invoices and accounting data are kept for 7 years (legal obligation); DAC7 reports according to statutory periods. Login data (IPs) and logs are kept for a limited time for security.

AI requests: to monitor cost and quality we keep a technical log per AI request (timestamp, model, tokens, cost, errors). The text sent is truncated by default and stripped of e-mail addresses, phone numbers and bank account numbers; of photos we keep only their number and size by default, not the photo itself. This log is visible only to authorised administrators and is deleted automatically after the configured retention period (30 days by default).

When you delete your account, your profile data is anonymised; transaction data we must legally retain remains, decoupled from your identity where possible. The AI log is decoupled from your identity and its stored content erased.

5. Your rights

You have the right of access, rectification, erasure, restriction, portability and objection. On your profile page you can export your data and delete your account; for other requests use the contact form.

Complaints can be addressed to the Belgian Data Protection Authority (dataprotectionauthority.be).

6. Cookies

We only use our own functional cookies: your session (login) and your language choice. There are no third-party tracking, advertising or analytics cookies on this site and we do not build profiles — our visitor statistics work entirely without cookies. That is why there is no cookie banner.

One exception, with a clear purpose: if you arrive via another member's invitation link (a link containing “?ref=”), we remember only that invitation code so that we can credit the right person if you sign up. That cookie is limited to your browser session (gone when you close the browser), contains no personal data, is not readable by scripts and is shared with no one. If you never click an invitation link, it is never set.

7. Security

Passwords are hashed (scrypt), sensitive configuration is stored encrypted (AES-GCM), connections use HTTPS and every status or money change is recorded in an audit log.