Our Privacy Promise
At Rune Heaven, your privacy is sacred. We believe in simple, clear data practices. Your personal information belongs to you, not us. We don't sell your data, we don't spam you, and we only collect what we need to make trading safe.
What Information We Collect
Account Information
When you create an account, we collect:
- Email address (must be real and verified)
- Username
- Password (encrypted)
- Profile information (optional: avatar, bio, trading preferences)
Trading Information
To protect the community and prevent scams:
- Listings you create (title, description, price, category)
- Messages between traders (for dispute resolution)
- Transaction history (what you sold, bought, when, for how much)
- Reviews and ratings you leave
Technical Information
We collect minimal technical data:
- IP address (for security)
- Browser type (to optimize our site)
- Pages you visit (understand what works)
- Login times and locations (prevent unauthorized access)
How We Use Your Information
Safety & Security
Your data helps us keep Rune Heaven safe. We use it to prevent scams, detect fraud, and block bad actors.
Service Delivery
We need your info to make trading work: calculating reputation, processing trades, sending notifications.
Communication
We only email you about:
- Account changes (password reset, email change)
- Trade notifications (message received, item delivered, review requested)
- Important updates (policy changes, service announcements)
- Optional: promotions and new features (you can unsubscribe)
NOT We Use Your Data For
- ❌ Selling to third parties
- ❌ Marketing outside Rune Heaven
- ❌ Sharing with advertisers
- ❌ Mining for personal profit
Data Sharing & Third Parties
Who We Share With
Your data stays with us, except:
- Supabase: Our database provider (encrypted)
- Law enforcement: Only if legally required (with notice when possible)
- Other traders: Only what you publicly post or agree to share
International Transfers
Your data may be stored or processed outside your country. We use encryption and standard contracts to keep it safe.
Your Rights
You Can:
- Access: See all data we have on you
- Download: Download your data in machine-readable format
- Delete: Request account deletion (we remove all personal data)
- Correct: Update any wrong information anytime
- Opt-out: Stop receiving promotional emails
Make a request: contact@runeheaven.com with your request. We'll respond within 30 days.
Security
We protect your data with:
- Encryption: Passwords encrypted with bcrypt (unreadable even to us)
- SSL/TLS: All data travels encrypted over the internet
- Two-Factor Authentication: Optional 2FA for extra account protection
- Regular Audits: Security checks to find and fix vulnerabilities
- Limited Access: Only admin staff access personal data (when necessary)
Cookies & Tracking
We use cookies to:
- Remember you're logged in
- Remember your preferences (dark mode, language)
- Prevent CSRF attacks (security)
We do NOT use cookies for:
- ❌ Tracking you across the web
- ❌ Selling behavioral data
- ❌ Third-party advertising
You can disable cookies in your browser. The site will still work, but some features may be limited.
Children's Privacy
Rune Heaven is not intended for children under 13. We don't knowingly collect data from kids. If we find out about a child's account, we'll delete it immediately.
Changes to This Policy
We'll update this policy if needed. We'll notify you of major changes via email. Continued use of Rune Heaven means you accept the updated policy.
Last updated: April 2026
Questions or Concerns?
Contact our privacy team: privacy@runeheaven.com