Privacy Policy
Last updated: March 2026
MFK Group Inc. ("we," "us," or "our") operates MFKVault, an AI skills marketplace. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Platform. We are committed to protecting your privacy and complying with applicable privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada and the General Data Protection Regulation (GDPR) for users in the European Union.
1. Information We Collect
We collect the following types of personal information:
Account Information
- Email address: Used for account creation, authentication, and communication
- Name: Display name for your profile and public interactions
- Username: Unique identifier for your account
- Profile picture: Optional avatar for your account (if provided)
- Role: Whether you are a buyer, seller, or both
Transaction Information
- Purchase history: Skills you have purchased and transaction dates
- Sales history: Skills you have sold (for sellers)
- Payment information: Processed securely through Stripe (we do not store full card numbers)
Content Information
- Skills submitted: Skills you create and submit to the marketplace
- Reviews: Reviews and ratings you leave for skills
- Messages: Communications sent through the Platform
Technical Information
- IP address and device information
- Browser type and version
- Pages visited and time spent on the Platform
- Referral source
2. How We Use Your Information
We use your personal information for the following purposes:
- Account Management: Creating, maintaining, and securing your account
- Service Delivery: Providing access to the marketplace, processing purchases, and delivering skills
- Payment Processing: Processing transactions and payouts through Stripe
- Communication: Sending important updates, notifications, and responding to inquiries
- Security: Detecting and preventing fraud, abuse, and security threats
- Improvement: Analyzing usage patterns to improve the Platform
- Legal Compliance: Complying with applicable laws and regulations
3. Third-Party Services
We use the following third-party services to operate the Platform:
Supabase
Database and authentication services. Your account data is stored securely on Supabase infrastructure.
Supabase Privacy PolicyStripe
Payment processing. Stripe handles all payment information securely. We never store your full credit card details.
Stripe Privacy PolicyResend
Email delivery service. Used to send transactional emails and notifications.
Resend Privacy Policy4. We Do NOT Sell Your Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
Your data is only shared with third parties as necessary to provide our services (as described above) or when required by law.
5. Cookies and Analytics
We use cookies and similar technologies to:
- Essential Cookies: Required for authentication and basic functionality
- Preference Cookies: Remember your settings and preferences
- Analytics Cookies: Help us understand how users interact with the Platform
You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the Platform.
6. Your Rights
You have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information (subject to legal obligations)
- Portability: Request your data in a portable format
- Objection: Object to certain processing of your information
- Withdrawal of Consent: Withdraw consent where processing is based on consent
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
7. Data Retention
We retain your personal information for as long as necessary to:
- Provide our services and maintain your account
- Comply with legal obligations (e.g., tax records, transaction history)
- Resolve disputes and enforce our agreements
When you delete your account, we will delete or anonymize your personal information within 90 days, except for information we are required to retain for legal or legitimate business purposes.
8. PIPEDA Compliance (Canada)
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and its ten fair information principles:
- Accountability for personal information
- Identifying purposes for collection
- Obtaining consent
- Limiting collection to what is necessary
- Limiting use, disclosure, and retention
- Ensuring accuracy
- Implementing safeguards
- Being open about policies and practices
- Providing individual access
- Providing recourse for complaints
9. GDPR Compliance (EU Users)
For users in the European Union, we comply with the General Data Protection Regulation (GDPR). In addition to the rights listed above, EU users have the right to:
- Lodge a complaint with a supervisory authority
- Know the legal basis for processing
- Restrict processing in certain circumstances
Legal Basis for Processing: We process your data based on:
- Contract performance (providing our services)
- Legitimate interests (security, improvement)
- Legal obligations (compliance with laws)
- Consent (where applicable)
10. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit and at rest
- Secure authentication mechanisms
- Regular security assessments
- Access controls and monitoring
While we take reasonable precautions, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security of your information.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.
12. Governing Jurisdiction
This Privacy Policy is governed by the laws of the Province of Ontario, Canada. Any disputes arising from this policy shall be resolved in the courts of Ontario, Canada.
13. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:
We will respond to all privacy-related inquiries within 30 days.
Please also review our Terms of Service for the complete terms governing your use of MFKVault.