Skillvel

Privacy Policy

What we hold, and what leaves.

Skillvel collects little, but what it does collect includes files you upload — and one of the checks those files go through sends them to a company that is not us. That is section 4, and it is the part of this policy most worth your time.

The rest is what you would expect of a marketplace: an account, the things you list, the things you buy, and the record of the money moving between the two.

Last updated 13 August 2026

  1. 01

    Who is responsible

    The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is:

    Controller
    [LEGAL NAME]
    Address
    [ADDRESS]
    Email
    [CONTACT EMAIL]
    Data protection officer
    [DPO OR “NONE APPOINTED”] — a DPO is not required for an operation of this size, but if one is appointed their contact details belong here.

    The full provider details are on the Imprint page.

  2. 02

    What we collect from you

    Only what an account and a marketplace actually need.

    • To sign up: an email address and a password. The password is handled by our authentication provider and is stored only as a hash — it never reaches Skillvel’s own tables and nobody operating the site can read it. You may give a display name; without one it is derived from the part of your email address before the @.
    • Optional, on your profile: your school or university, a LinkedIn profile address, an avatar image address, and a contact email address that is separate from your login address.
    • If you sell: your listings, and the files you upload — the project file, a cover image, and any preview file or screenshots. For each file we store its original filename, its size and its SHA-256 hash.
    • If you report a listing: the reason you pick and the description you write.

    The avatar and LinkedIn fields hold addresses, not uploads. Nothing is copied into Skillvel’s storage — which also means an avatar image is loaded from whatever host you point it at, and that host will see the request.

  3. 03

    What we record about what you do

    • Purchases and sales: who bought what from whom, the amount, the split between the seller, Stripe and the platform commission, the Stripe payment identifier, and the date.
    • Certificates: a Creator Certificate stores a snapshot of the seller’s name, the project title, the date, and the institution where the listing had that switched on. It is a snapshot on purpose — changing your name later does not rewrite a certificate someone is already holding.
    • Payouts: the amount, the Stripe payout identifier and the date it reached the bank. Bank details themselves are held by Stripe, not by us.
    • Scan results: the hash of each uploaded file and whether it came back clean or flagged.
    • Notifications: a copy of every notice sent to you, so the dashboard can show it.
    • Suspensions: if an account is suspended, the reason and the date.
  4. 04

    Malware scanning sends your file to a third party

    Every main project file is scanned before a listing can be published. The scan runs in two steps, and only the second one sends the file:

    • First, the hash alone. We compute the file’s SHA-256 hash and ask VirusTotal whether it already knows it. Only the 64-character hash leaves our servers. A hash cannot be turned back into the file.
    • Then, if the answer is no, the file. VirusTotal can only analyse a file it has, so an unknown hash means the complete file — up to 95 MB — is uploaded to VirusTotal together with its original filename, which VirusTotal uses for type detection and reports back.

    For work you made yourself, the second step is what normally happens: your file is by definition one VirusTotal has not seen. VirusTotal is operated by Google and shares files submitted to it with the security vendors and researchers in its network, who may retain and inspect them. Treat uploading a project file to Skillvel as publishing it to that network.

    What is not sent: preview files, screenshots and cover images are never submitted to VirusTotal, and neither is anything about who uploaded a file. VirusTotal receives the bytes and the filename, not your name, your email address or your listing.

    The legal basis is our legitimate interest in not distributing malware to buyers (Art. 6(1)(f) GDPR). There is no way to opt out and still publish a listing, because an unscanned file is never published — so the practical control is the choice of what to upload, and the filename you upload it under.

  5. 05

    What other people can see

    Some of this is public to the whole internet, not just to members.

    • Your seller profile: display name, avatar, LinkedIn address, and your institution where you allowed the listing to show it. Your login email address, your Stripe identifiers and your account status are never public.
    • Your listings: everything on them, once published.
    • Cover images, preview files and screenshots are stored in a public bucket, which means anyone holding the address can open them without signing in. Do not put anything in a preview file you would not publish.
    • Certificates: anyone with a certificate ID can check it and will see the seller’s name, the project, the date, and the institution if that was enabled. That is the point of a certificate.

    Paid project files are not public. They live in a private bucket and are released only through short-lived signed links, generated per download for the buyer who paid or the seller who uploaded. No such link is ever put in an email.

    After a purchase, the buyer receives the seller’s contact email address, but only where the seller enabled that on the listing. The exchange goes one way: the seller is told a sale happened and for how much, and is not told who bought it.

  6. 06

    Why we are allowed to process it

    • Art. 6(1)(b) — performing a contract: your account, your listings, purchases, downloads, certificates and payouts. Without this data there is no marketplace.
    • Art. 6(1)(f) — legitimate interests: malware scanning, the file-hash duplicate check, investigating reports, preventing fraud and keeping the service secure.
    • Art. 6(1)(c) — legal obligations: keeping transaction records for as long as commercial and tax law requires.
    • Art. 6(1)(a) — consent: the optional profile fields, and the switches that decide whether your institution and LinkedIn address appear on a listing. You can withdraw it by clearing the field or turning the switch off, which does not affect what was lawful before.
  7. 07

    Who else processes it

    Skillvel does not sell personal data and does not share it for advertising. It does depend on these providers to run at all:

    Supabase
    Database, authentication and file storage. Holds essentially everything described above. Hosted in the European Union — [CONFIRM REGION], understood to be AWS eu-west-1 in Ireland.
    Vercel
    Hosts and runs the site itself, and therefore processes the requests you make to it. [CONFIRM REGION].
    Stripe
    Payments and seller verification. Receives your email address, the purchase amount and the listing title. If you sell, Stripe collects your name, address and identity documents directly, on its own pages — that verification data never passes through Skillvel, and Skillvel never sees card details.
    Resend
    Sends every email the platform sends — receipts, notifications, address confirmation and password resets. Receives the recipient address and the contents of the message.
    VirusTotal
    Malware scanning. Receives file hashes and, where a hash is unknown, the file itself — see section 4.

    [CONFIRM TRANSFER MECHANISM]— several of these are US companies or have US parents, so some processing takes place outside the EU. Transfers rely on the EU–US Data Privacy Framework where the provider is certified under it, and otherwise on standard contractual clauses. Which applies has to be confirmed per provider and named here, and a data processing agreement has to be in place with each.

    If a fraud report is confirmed, a document package recording the seller’s details and the transaction may be passed to law enforcement. Whoever filed the report is not named in it.

  8. 08

    Cookies and tracking

    Skillvel runs no analytics, no advertising and no third-party tracking. There is nothing here to consent to, which is why there is no cookie banner.

    • Session cookies keep you signed in. They are strictly necessary; without them you could not stay logged in.
    • One local storage entry remembers whether you chose the light or dark theme. It never leaves your browser.
  9. 09

    How long it is kept

    Account and profile data is kept while the account exists. Some records outlive it, and it is fairer to say why than to imply everything disappears:

    • Orders and the files behind them. A buyer keeps permanent access to what they paid for, which is also why a listing can be paused but never deleted. Removing a sold file would take away something someone bought.
    • Certificates. They are issued to be checked by third parties, so they stay verifiable — including when they have been invalidated, since someone holding the ID is owed an answer either way.
    • Transaction records. German commercial and tax law requires business records, including those relating to payments, to be retained for up to ten years. While that applies, the data is restricted rather than deleted.
    • Suspension records. Kept so that a suspension cannot be undone by signing up again.

    [DEFINE RETENTION PERIODS] — the criteria above are what the system actually does today; concrete periods for each category still need to be set and stated here.

  10. 10

    Your rights

    Under the GDPR you can ask us to:

    • tell you what we hold about you, and give you a copy (Art. 15);
    • correct anything wrong (Art. 16);
    • delete it (Art. 17), subject to the records in section 9 that we are required or obliged to keep;
    • restrict how we use it (Art. 18);
    • hand it over in a portable form (Art. 20);
    • stop processing based on legitimate interests (Art. 21);
    • and withdraw any consent you gave, at any time (Art. 7(3)).

    Most profile data you can change yourself in your account settings. There is currently no self-service account deletion — write to the address in section 1 and it will be handled by hand.

    You can also complain to a data protection supervisory authority. The one responsible for us is [SUPERVISORY AUTHORITY], and you may instead complain to the authority where you live or work.

  11. 11

    How it is protected

    • Paid project files, certificate PDFs and fraud documentation sit in private storage and are reachable only through short-lived signed links issued per request.
    • Database access is restricted row by row, so one account cannot read another’s orders, certificates or profile.
    • Sensitive columns — account status, Stripe identifiers, scan results — cannot be written by the browser at all, only by the server.
    • Card details never reach Skillvel; payment happens on Stripe’s own pages.
    • Passwords are stored only as hashes, by the authentication provider.
  12. 12

    Younger users

    Skillvel is built for students and expects that some are under 18. If you are, you need your parent or guardian’s consent to use it, and selling requires them to set up the Stripe account and receive the payouts — so Stripe holds their details, not yours. Your Skillvel account and your certificates stay in your own name. A parent or guardian can exercise any of the rights in section 10 on your behalf.

  13. 13

    Changes to this policy

    This policy will change as Skillvel does — a new provider or a new feature means a new entry here. The revision date at the top says when it last changed, and material changes are announced by email to registered users.