Privacy Policy & Cookies

 

Effective Date: 9/29/25
 

Newel Auctions (“Newel,” “we,” “our,” or “us”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website (www.newelauctions.com), mobile application, and related services (the “Services”).

By accessing or using our Services, you agree to the terms of this Privacy Policy.

1. Introduction

Newel Auctions, LLC (“Newel,” “we,” “us,” or “our”) values your privacy and is committed to protecting your personal information. This Privacy Policy describes how we collect, use, disclose, and secure your personal information when you use our website (www.newelauctions.com), mobile application, and related services (collectively, the “Services”). It explains the types of information we collect, why we collect it, how we share it, and the rights you have under applicable laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and the EU/UK General Data Protection Regulation (GDPR). By accessing or using our Services, you agree to the collection and use of information in accordance with this Policy.

This Policy serves as our Notice at Collection for California residents, detailing the categories of personal information we collect and the purposes for collection.

This Policy serves as our Notice at Collection for California residents, detailing the categories of personal information we collect and the purposes for collection.

2. Data Controller

Newel Auctions, LLC is the data controller of the personal information collected through the Services. Our address is 32-00 Skillman Avenue, 1st Floor, Long Island City, NY 11101, USA. We are not required to appoint a Data Protection Officer under GDPR, but you may contact us at the details in Section 14 for any GDPR inquiries or to exercise your rights.

3. Categories of Information Collected and Purposes

We collect personal information directly from you, automatically through your use of our Services, and from third parties. For California residents, this also describes the categories of personal information (as defined under CCPA/CPRA) we have collected in the preceding 12 months. We do not collect protected classification characteristics, biometric information, professional/employment information, education information, audio/visual/sensory data, or non-public education information unless incidentally provided by you.
The categories, sources, and specific purposes are as follows:

A. Account Information (Categories: Identifiers; California Customer Records information) Sources: Directly from you during registration. Examples: Name, email address, phone number, postal address, login credentials. Purposes: To establish and manage your account (contractual necessity), authenticate your identity (legitimate interests in fraud prevention), and communicate with you regarding your account and Services (contractual necessity or consent for marketing).
 
B. Auction Participation Data (Categories: Financial information; Sensitive personal information) Sources: Directly from you during bidding/purchases; third parties like payment providers. Examples: Bidding and purchase history, payment details (e.g., credit card, billing address), verification documents (e.g., government-issued ID). Purposes: To process bids, confirm sales, facilitate payments and deliveries (contractual necessity), verify identity to prevent fraud (legitimate interests and legal compliance, e.g., anti-money laundering laws), and comply with tax/auction regulations (legal compliance).
 

C. Consignment and Appraisal Data (Categories: Identifiers; Commercial information) Sources: Directly from you during submissions. Examples: Photos, descriptions, provenance, ownership details of items. Purposes: To provide consignment and appraisal services, list items for sale, and verify provenance (contractual necessity and legitimate interests).
 

D. Communications (Categories: Identifiers; Internet or other electronic network activity) Sources: Directly from you via email, phone, chat, or video. Examples: Information provided in inquiries or support requests. Purposes: To respond to inquiries, provide customer support, and send Service-related notices (e.g., bid updates) (contractual necessity or legitimate interests).
 

E. Usage and Device Data (Categories: Internet or other electronic network activity; Geolocation data; Inferences drawn from other personal information) Sources: Automatically collected. Examples: Device type, OS, browser, IP address, approximate geolocation (if enabled), pages viewed, searches, interactions. Purposes: To operate and improve Services (legitimate interests), enhance performance, analyze usage for analytics/fraud prevention (legitimate interests), and provide personalized recommendations (consent or legitimate interests).
 

F. Cookies and Tracking Technologies See Section 11 for details. Purposes: As described therein (consent for non-essential).

Providing certain information (e.g., name, payment details) is a contractual requirement for features like bidding or account creation; without it, you may be unable to use those features. We do not engage in automated decision-making or profiling with legal or significant effects, within the meaning of GDPR Article 22.

4. Legal Bases for Processing (GDPR/UK Users)

For EEA/UK residents, we process data on lawful grounds:
-Contractual Necessity: For executing bids, consignments, and providing Services (e.g., processing payments).
-Legal Compliance: For tax, anti-money laundering, or regulatory obligations (e.g., recordkeeping).
-Legitimate Interests: For fraud prevention, security, and Service improvements (balanced against your rights).
-Consent: For marketing or non-essential cookies (withdrawable anytime).

5. Sharing of Personal Information

We share data as follows (categories of recipients and purposes):
 -Service Providers: With vendors (e.g., payment processors for transactions, shipping for deliveries, IT/cloud for storage/support) to perform functions on our behalf. We do not allow service providers to use your personal information for their own purposes.
-Auction Platforms: With third parties like LiveAuctioneers to facilitate participation.
-Affiliates/Business Partners: With related entities under common control, consistent with this Policy.
-Legal/Regulatory Authorities: When required by law (e.g., subpoenas).
-Corporate Transactions: In mergers/sales, subject to protections.

We never sell personal information. We also do not "share" it for cross-context behavioral advertising (as defined under CCPA/CPRA) without consent.

6. Data Retention

We retain data only as necessary, using these criteria and mapping to categories:
-Account Information, Auction Participation Data, and Consignment and Appraisal Data: As long as your account is active, plus 7 years for tax/legal compliance (e.g., transaction records).
-Communications and Usage and Device Data: Up to 2 years for support/analytics, or longer for fraud/legal claims.
-Sensitive Personal Information (e.g., government-issued ID, payment details): Limited to the verification/transaction period, then deleted or anonymized unless required longer by law (e.g., for compliance). After the retention period, we securely delete or anonymize data. Contact us for specifics on any category.

7. Data Security

We implement appropriate measures, including encryption in transit (HTTPS) and at rest where feasible, firewalls, access controls, regular audits, and staff training. No system is 100% secure; in the event of a data breach, we comply with breach notification laws if needed, including GDPR Articles 33/34 for EU/UK users and U.S. state laws (such as California Civil Code §1798.82).

8. International Data Transfers

Data may transfer to the U.S. We rely on the European Commission’s Standard Contractual Clauses (SCCs) or other legally recognized transfer mechanisms where appropriate for GDPR compliance. Where required, we also implement supplementary measures (such as encryption and access restrictions) to ensure an essentially equivalent level of protection.

9. Your Privacy Rights

A. GDPR (EU/UK Residents): Rights to access, rectification, erasure, restriction, objection, portability, withdraw consent, and lodge a complaint with a supervisory authority (e.g., via edpb.europa.eu). We respond without undue delay and in any event within one month, extendable by two additional months where necessary.
 

B. CCPA/CPRA (California Residents): Rights to:
-Know/Access: Request disclosure of the categories of personal information we have collected/disclosed about you (including sources, purposes, and third parties shared with), AND the specific pieces of personal information we have collected about you (including preceding 12-month details).
-Correct: Request correction of inaccurate personal information.
-Delete: Request deletion (subject to exceptions).
-Limit Use/Disclosure of Sensitive PI: Request limitation for sensitive personal information (e.g., government-issued ID, payment details—used only for transactions/compliance). We only use sensitive personal information for the purposes reasonably expected by an average consumer (e.g., payment processing, fraud prevention, legal compliance).
-Opt-Out of Sale/Sharing: Direct us not to sell or share (not applicable here).
-Non-Discrimination: Not be denied services or charged differently for exercising rights. 

To exercise rights, submit a verifiable request (see Section 14). We verify via account matching or codes. You may use an authorized agent; if so, we may require you to verify your identity and provide written authorization to the agent. Responses: Within 1 month (GDPR, extendable) or 45 days (CCPA/CPRA, extendable to 90). No fees unless excessive.

10. How to Opt-Out of Marketing

Withdraw consent anytime via email unsubscribes or contacting us; we stop marketing but may send transactional messages.

11. Cookies & Tracking Technologies

We use them to remember sessions, track activity, and measure performance. We do not use cookies for cross-context behavioral advertising. If this changes, we will provide a “Do Not Share My Personal Information” link as required by California law. Manage via browser or our banner; disabling may limit features.

13. Changes to This Policy

Our Services are not for children or persons under the age of 18. We do not knowingly collect personal information from children under the age of 18. If we learn we have collected such data, we will delete it promptly.

12. Children’s Privacy