Overview
Disc.Market ("Disc.Market," "we," "us") operates an online marketplace where independent third-party Pro Shops list disc golf gear for sale. We don't manufacture, warehouse, or ship the items listed on the platform ourselves. We do process payments, handle shipping logistics, and provide the software that connects buyers and sellers.
This Privacy Policy explains what personal information we collect when you use disc.market, our mobile apps, and our related services (together, the "Services"); how we use it; who we share it with; and the choices and rights you have regarding that information. It applies to everyone who uses the Services — visitors, buyers, guest purchasers, and Pro Shop operators and their staff.
Our free Bag Tags club tracker at tags.disc.market is also covered by this policy, with a short supplemental Bag Tags Privacy Notice that explains the few things specific to it — most importantly that a player's display name and standings are shown on a public leaderboard.
The short version: we collect what we need to run a marketplace, we don't sell your personal information, advertising trackers stay off unless you turn them on, and you can see, export, or delete your data at any time. The rest of this policy is the detail behind that sentence.
By creating an account, posting a listing, making a purchase, or otherwise using the Services, you consent to the practices described in this policy. If you don't agree, please don't use the Services.
Information We Collect
1. Information you provide directly
When you create a buyer account
- Email address. Stored with your account by our authentication provider (Supabase Auth) and in our database. Used for login, transactional email, and account recovery.
- Password. Hashed and stored exclusively by Supabase Auth. We never see or store your password in plaintext.
- Display name. Required at signup. Used on reviews, messages, and public Pro Shop pages.
- Username. Public — appears in URLs, reviews, and Pro Shop pages. Screened by our word filter before it's accepted.
- Profile photo (avatar). Optional. Uploaded directly from your browser to our image host (Cloudflare Images); only an image identifier is stored in our database.
- Social sign-in. If you sign in with Google or Facebook, we receive only your name, email address, and profile picture from the provider — never your password, contacts, or anything else. See our Data Deletion page for how to disconnect.
When you check out as a guest (no account)
- Email address. Used to send order confirmation and tracking emails, and a post-delivery invitation to review your order.
- Shipping address. Name, street, city, state, ZIP, country. A snapshot is stored on the order record.
When you make a purchase
- Shipping address. Stored as a snapshot on the order. Optionally saved to your address book for future checkouts.
- Saved addresses. Name, street, city, state, ZIP, country. User-managed; you can delete them at any time from Account → Addresses.
- Order history. Items, prices, taxes, shipping, and totals. Retained indefinitely as a financial record.
- Payment method. Card number, CVC, and expiry are submitted directly from your browser to Stripe via Stripe's embedded payment form. We never see, store, or log them. We store only Stripe's payment reference against the order.
- Saved payment method (auctions). To place a bid in an auction you authorize a reusable payment method through Stripe. Stripe stores a tokenized reference to that card on a Stripe customer record linked to your account so that, if you win, the winning bid can be charged automatically when the auction closes — without you being present (“off-session”). As with all card data, the raw card number, CVC, and expiry never touch our servers; we keep only Stripe's payment-method and customer identifiers. The saved method stays on file with Stripe until you remove it (Account → Payment methods) or delete your account; your only payment method cannot be removed while it is backing an active high bid or an unsettled won auction — add a replacement first. See Data Retention and our Data Deletion page.
- Bids. When you place a bid we record the bid amount, the listing, and a timestamp, tied to your account, and retain it as a transaction record. On public auction pages we mask bidder identities (for example showing “B***s” rather than your full display name); the Pro Shop and our admins can see the bidder for fulfillment and moderation.
When you apply to be a Pro Shop
- Legal first and last name, email, phone, country, state.
- Pro Shop name and description.
- Business background. Prior selling experience, monthly listing volume (a range), links to existing storefronts (Facebook, eBay, other).
- Identity verification (KYC). Handled entirely by Stripe Connect. Stripe collects your SSN/EIN, date of birth, bank account or debit card, and (when their risk review demands it) a government ID. None of that data ever touches our servers or database — we only persist the resulting Stripe account identifier.
- Ship-from address. Used for shipping-label origin and address verification, and registered with our shipping provider (EasyPost) for that purpose.
- Electronic signature on the Pro Shop Agreement. A signature image produced by an in-browser signature pad, plus your IP address and a timestamp at signing. Retained as a legal audit trail of the agreement.
When you communicate with us or other users
- Buyer ↔ Pro Shop messages. Message text, optional photo attachment, read/unread state, and timestamps. Messaging is subject to anti-abuse rate limits.
- Support tickets. Your messages plus any photos you attach.
- Live chat. Pre-chat form (optional name + email), the chat transcript, optional photo attachments, and your IP address — captured for abuse detection and session attribution.
- Live-chat contact form. Name, email, category, and message — used to open a support ticket.
- Listing Q&A. Public question/answer threads on each listing. Your display name is shown alongside.
- Reviews. Rating 1–5, optional written review, optional photos, and an optional public reply from the Pro Shop.
- Disputes. Reason, description, and supporting evidence photos. Visible to our admin team and the opposing party in the dispute thread.
Push notifications (mobile app)
- If you enable notifications in the Disc.Market mobile app, Firebase Cloud Messaging issues a device-specific token. We store the token, platform (Android/iOS/web), and an internal device ID so we can deliver push notifications. Unregister at any time — the record is removed.
2. Information we collect automatically
- IP addresses. Used transiently for rate limiting and abuse prevention. Persisted in two places: (a) on live-chat sessions, and (b) at the moment you e-sign the Pro Shop Agreement. Additionally, our hosting provider (Vercel) and DNS provider (Cloudflare) log source IPs for every request in their platform logs.
- Device and browser info. Browser type, operating system, screen size, approximate geographic region derived from IP — collected by analytics and error-monitoring tools (subject to your cookie consent).
- Approximate city for our live-visitor admin view. When you load a public page, our hosting provider supplies an approximate city/region/country and a city-level coordinate derived from your IP at the network edge. We store this — without your IP — for at most 5 minutes against a short-lived anonymous identifier so administrators can see an aggregate live-visitor map. Internal dashboard pages are excluded, and the coordinates are reduced to city-block precision before storage. This coarse signal is the only location data we ever see, and it never leaves our hosting and database environment.
- Usage data. Pages viewed, listings clicked, search terms, filter selections, tagged button clicks, and page-performance timings. Subject to the Analytics toggle in our cookie banner.
- Log data. Request URLs, timestamps, response codes — surfaced in our server logs and our error-monitoring tool (Sentry) for debugging and abuse detection.
3. Information we generate about you
- Pro Shop performance metrics. Rating average, on-time-ship rate, total shipments, late shipments — all derived from your order and review history.
- Order, shipment, and payout status history. A full timeline of every state transition (paid, shipped, delivered, refunded, payout-released).
- Moderation flags. If your account is banned, an item is hidden, or a report is filed/resolved — those records are kept for audit.
- Sales-tax nexus totals. Per-state totals of orders shipped, used to track when we cross an economic-nexus threshold in a new state.
- AI usage logs. If a Pro Shop uses AI Listing Auto-Fill, or an admin uses the AI Support Reply drafter, we log token counts, the model used, whether the suggestion was applied, and a rating — used for cost tracking and quality improvement.
4. What we do not collect
- Precise device geolocation. We never ask your browser or phone for its location through a geolocation API, and the mobile app does not request location permission. The approximate city derived from your IP by our hosting provider — described in section 2 — is the only location signal we ever see. State/ZIP for orders comes from forms you fill in, not from your device. (At checkout and during Pro Shop setup, an optional address autocomplete uses Google's Places service to finish an address you are typing — it completes text you enter, it does not read your device's location. See the sub-processor list below.)
- Biometric data. No fingerprint, face, voice, retina, or other biometric identifiers are collected.
- Device fingerprints (by us). No fingerprinting library is loaded by Disc.Market. Note: Stripe's embedded payment form and Stripe Radar fingerprint your device for fraud detection on the checkout page — that data flows directly from your browser to Stripe and never passes through us.
- Phone numbers from buyers. Buyer accounts do not have a phone-number field. Pro Shops provide a phone number on the Pro Shop application; buyers never do.
- SSN, EIN, bank account, or government ID. Pro Shop KYC is collected by Stripe directly. We don't see it.
How We Use Your Information
We use the information we collect to:
Operate and provide the marketplace
- Create and authenticate your account
- Enable buyer ↔ Pro Shop transactions, messaging, reviews, and listing Q&A
- Process payments, calculate sales tax, and facilitate Pro Shop payouts through our payment-hold flow
- Generate shipping labels, get calculated carrier rates, and confirm deliveries via carrier tracking
- Send transactional email and push notifications — order confirmations, shipping updates, dispute notifications, payout receipts, password resets, Pro Shop Agreement receipts, staff invites, and more
Keep the marketplace safe and fair
- Detect and prevent fraud, unauthorized access, abuse, and harassment
- Enforce our Terms of Service, our Pro Shop Agreement, and our word-filter content rules
- Apply automated and human content moderation (prohibited terms, restricted items, suspicious patterns)
- Track sales-tax nexus across all 50 U.S. states so we register and remit in new states when economic thresholds are crossed
- Verify and, where required by the federal INFORM Consumers Act, collect and disclose information about high-volume sellers
Improve and personalize the experience
- Analyze usage patterns to fix bugs, prioritize features, and improve search and discovery
- Personalize listing recommendations and the recently-viewed list (stored in your browser's local storage)
- Power AI-assisted features for Pro Shops (Listing Auto-Fill) and admins (Support Reply drafts)
Communicate with you
- Respond to support requests submitted via ticket, live chat, or the Contact page
- Send you information about your account, your orders, your Pro Shop performance, your payouts, and your disputes
- Send marketing or promotional messages only if you opt in via the newsletter sign-up. Every newsletter has a one-click unsubscribe link in the footer.
Comply with legal obligations
- Retain order, tax, and payout records as required by law
- Respond to lawful subpoenas, court orders, and government requests
- Issue 1099-K tax forms to Pro Shops who exceed IRS reporting thresholds (handled by Stripe)
We use your information only for the purposes described in this policy or otherwise disclosed to you at the time of collection. We do not sell it. By default we do not use it for cross-context behavioral advertising; that only happens if you turn on the optional Marketing cookie category, and you can turn it back off at any time — see How We Share Your Information and Cookies below.
Automated Processing
We use limited automated processing on user content to keep the marketplace safe. Automated systems do not make decisions that legally or significantly affect you without a human in the loop.
Automated content moderation (word filter)
We screen listing titles, descriptions, reviews, messages, and Q&A content for prohibited content across 12 categories (hate speech, scam patterns, contact info that attempts to circumvent the platform, etc.). Most matches result in a flag for human review, not an automatic account action. A small set of permanent-ban categories (slurs, explicit hate speech) blocks submission at the form level so the content is never published.
Fraud and security signals
We use automated signals to detect suspicious activity — unusual login patterns, rapid-fire account creation, payment-fraud heuristics, automated-bot detection on checkout, and similar. These signals may trigger additional verification or temporarily restrict account actions. Significant actions (suspending an account, reversing a payout) are reviewed by a human before taking effect.
AI-assisted features
Two features use third-party AI models. AI Listing Auto-Fill sends a hosted photo of a Pro Shop's item plus the Pro Shop's typed context to a vision-capable model — routed through Vercel's AI Gateway to Anthropic's Claude by default — and suggests listing fields (title, brand, plastic, color, weight, condition). The Pro Shop reviews and edits the suggestion before saving — nothing is auto-published. AI Support Reply sends a customer-service ticket or live-chat transcript to OpenAI and suggests a reply draft to our admin team; the admin edits and approves before anything is sent to you. Both flows log token usage, an applied flag, and a rating internally. Our AI providers are used through their business APIs, which do not use submitted inputs to train their models.
Payment Security
All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. Card numbers, CVC codes, and bank account details never touch Disc.Market's servers — they go directly to Stripe from your browser over an encrypted connection.
Our marketplace uses a payment-hold model. When you place an order, Stripe charges your card and the funds land in Disc.Market's platform account — not the Pro Shop's. The Pro Shop is not paid immediately. Once delivery is confirmed (via carrier tracking) and a 3-day dispute window passes, we instruct Stripe to transfer the Pro Shop's share to their connected Stripe account, minus our 10% platform fee on the item subtotal + shipping plus a flat $0.35 per-order processing fee. Sales tax is never part of the commission base. Both fees come out of the Pro Shop's share only — buyers never pay a marketplace fee.
This payment-hold design protects you: if something goes wrong before delivery, we can refund you directly from the funds on file, without needing to recover them from the Pro Shop. On a full refund or lost chargeback, the sold listing automatically returns to the marketplace visibility it had before the sale so other buyers can find it again.
Auctions. To bid you save a payment method, which Stripe stores as a reusable, tokenized reference on a Stripe customer record (the raw card never touches our servers). When an auction closes and you are the high bidder, we instruct Stripe to charge that saved method automatically, for your winning bid plus shipping and tax, even though you aren't actively at checkout (“off-session”). The resulting order then follows the same payment-hold flow as any other purchase.
Every payment event we receive from Stripe is logged and de-duplicated before it's processed, so no payment is ever processed twice.
Mobile App Permissions
Our mobile app is a thin shell that loads disc.market inside a secure WebView. It uses these native capabilities on top of the web app:
- Push notifications — registers a Firebase Cloud Messaging token so we can deliver alerts (new orders, shipping updates, payouts, messages). You can disable notifications in your device's system settings or unsubscribe from individual categories in Account → Notifications.
- Camera and photo library — used by the Pro Shop listing form so you can shoot a photo of a disc and upload it directly. The image goes to Cloudflare Images; no photo is uploaded without your action.
- Share sheet — used when you tap "Share" on a listing or Pro Shop. Hands off to your device's native share menu.
- Haptics — small vibrations on certain UI events. Purely cosmetic.
- App preferences — a small on-device key/value store for native settings.
- Network status — detects offline state so we can show a graceful fallback page.
- Status bar / splash screen — chrome only. No data collection.
- Crash reporting — Firebase Crashlytics captures uncaught native crashes (stack trace, device model, OS version). No personally identifying info is intentionally attached.
- In-app review prompt — uses the platform's native review API to occasionally invite you to rate the app.
The mobile app does NOT request access to your location, contacts, microphone, calendar, or Bluetooth. No location permission is declared in the app's manifest on either platform.
Data Retention
We retain different categories of information for different periods, driven by scheduled cleanup jobs and a few intentional long-term records. The high-level shape:
Kept long-term (financial / audit / safety)
- Order records. Orders, order items, shipments, status history, payouts, refunds, and disputes are kept for tax reporting, dispute resolution, and regulatory compliance (some state sales-tax audits look back 7+ years).
- Reviews, listing Q&A, conversations, support tickets. Persisted indefinitely. If a review or listing is removed by moderation, the record is hidden rather than deleted (the audit trail stays).
- Payment and shipping event logs. Required so repeated webhook deliveries can't double-process a payment.
- Email log. Sends, deliveries, opens, clicks, bounces, and complaint events.
- Pro Shop applications, setup progress, e-signature and signing IP. Legal audit trail for the Pro Shop Agreement.
- Sales-tax nexus totals. Per-state running totals needed for tax compliance.
- Bid records. Bids placed in auctions are kept as part of the transaction record and as a fairness/audit trail for the auctions you took part in.
- AI usage logs and training feedback. Attributed to the operator/admin who used the feature; not joined to buyer data.
- Newsletter subscribers. Until you click the one-click unsubscribe link in any newsletter email — the record stays marked "unsubscribed" thereafter so we don't accidentally re-add you.
Auto-deleted on a schedule
- Abandoned checkouts. Unpaid checkout sessions are deleted by a frequent cleanup job once their payment attempt is no longer active.
- Live-chat sessions. Inactive sessions auto-close, closed sessions auto-archive (default ~30 days), and image attachments on archived sessions are deleted (default ~90 days); the transcript text stays.
- Orphaned images. A daily job compares every stored image against every database reference and deletes any unreferenced image.
- Unused shipping labels. Labels with no carrier scan are voided and refunded before the carrier refund window closes.
- Temporary bans. If your account was temporarily banned, the ban expires on schedule and the flag is cleared.
Push tokens, cart, favorites, addresses, saved cards
- Push tokens. Until you explicitly unregister, or your account is deleted.
- Saved addresses. Until you delete them from Account → Addresses.
- Cart items, favorites. Until you remove them or the listing is removed.
- Saved payment method (auctions). Stays on file with Stripe until you remove it or your account is deleted (at which point we detach and delete it at Stripe). It can't be removed while it backs an active high bid or an unsettled won auction.
Third-party retention
- Server logs, error reports. Vercel and Sentry retain logs and error events per their own policies (typically 30–90 days).
- Analytics. Google Analytics retains per its default (currently 14 months).
- Backups. Encrypted database backups follow Supabase's backup policy.
When you delete your account
We anonymize your email, username, and display name, delete your cart, favorites, push tokens, and saved addresses, and remove your active profile from public surfaces. Order history, financial records, dispute records, and the e-signature audit trail are retained as required by law — anonymized so they no longer identify you. Full details on our Data Deletion page; see the Your Rights section below for how to request deletion.
Your Rights
You have the following rights regardless of where you live:
- Access / export. Download a machine-readable JSON archive of everything we hold about you — profile, addresses, orders, reviews, favorites, conversations, support tickets, push tokens, Pro Shop records (if applicable). Go to Account → Settings and click "Export your data."
- Correction. Edit your display name, username, avatar, addresses, Pro Shop profile, and notification preferences at any time from your account settings.
- Deletion. Delete your account from Account → Settings (Danger Zone), or follow the steps on our Data Deletion page. We anonymize your personally identifying information and delete optional records. Order, payout, dispute, and e-signature records are retained as required by law and tax-authority audits.
- Unsubscribe from marketing. Every newsletter has a one-click unsubscribe link in the footer. You can also toggle the newsletter off from your account settings. Transactional emails (order confirmations, dispute notifications, payout receipts, etc.) continue — these are not marketing.
- Turn off analytics. Toggle the Analytics category off via Privacy Settings in the footer, or send a Global Privacy Control signal from your browser. We honor GPC platform-wide.
- Your privacy choices — opt out of advertising "sharing." The advertising (Marketing) cookie category is off by default. To keep it off, or to turn it off later, open Privacy Settings in the footer, or send a Global Privacy Control signal — we honor it as a "do not sell or share" opt-out.
- Turn off push notifications. Disable in your device settings, or toggle individual categories at Account → Notifications.
California residents (CCPA / CPRA)
The table below maps what we collect to the categories defined in California law, the purposes, and who it's disclosed to. We collect it directly from you, from your devices, and from our payment and sign-in providers; we have collected each of these categories in the preceding 12 months.
| CCPA category | Examples on Disc.Market | Disclosed to (service providers) |
|---|---|---|
| Identifiers | Name, email, username, shipping address, IP address | Database/auth host, payment processor, shipping provider, email provider |
| Commercial information | Orders, cart, favorites, payout records | Database host, payment processor |
| Internet / network activity | Pages viewed, searches, clicks, device/browser info | Analytics (consent-gated), error monitoring, hosting logs |
| Geolocation (coarse only) | Approximate city derived from IP; never precise GPS | Hosting provider (edge network) |
| Audio/visual | Photos you upload (avatar, listings, reviews, disputes) | Image host (CDN) |
| Professional information | Pro Shop application details (business background) | Database host; KYC details go to the payment processor only |
| Inferences | Pro Shop performance metrics derived from order/review history | Database host |
We do not collect biometric information, precise geolocation, or (ourselves) government identifiers. If you're a California resident, you have the right to:
- Know what categories of personal information we collect, the sources, the purposes, and the categories of third parties with whom we share it (this section plus Information We Collect and How We Share above).
- Access a portable copy of the specific pieces of personal information we hold about you (use "Export your data" in account settings).
- Delete your personal information, subject to the exceptions in CCPA § 1798.105 (we retain order history, tax records, and fraud-prevention records as required by law).
- Correct inaccurate personal information.
- Limit use of sensitive personal information — we don't use sensitive PI for any purpose other than what's strictly necessary to provide the Services, so this right is automatically honored.
- Opt out of "sale" or "sharing" of your personal information. We never sell your personal information. We also do not "share" it for cross-context behavioral advertising unless you turn on the optional Marketing cookie category — which is off by default. When Marketing is on, the advertising pixels (Meta, TikTok, Pinterest, Snapchat, Microsoft) receive limited event data and a pixel identifier (never your name, email, or phone), which may be a "sale" or "share" under some state laws. You can exercise this opt-out at any time by leaving Marketing off — or turning it off — in Privacy Settings, and we honor the Global Privacy Control signal as an opt-out automatically. We have no actual knowledge of selling or sharing the personal information of consumers under 16.
- Non-discrimination for exercising any of these rights. We will not deny service, charge different prices, or provide a different level of service.
To exercise these rights, use the Contact page. We may need to verify your identity (typically by confirming the email address on your account) before processing the request. You may also designate an authorized agent to act on your behalf; we'll require written proof of the authorization.
Other state residents (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others)
Several other US states have enacted comprehensive privacy laws giving residents substantially similar rights to California's: Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), and others as they take effect. If you are a resident of one of these states, you have the right to access, correct, delete, and obtain a copy of your personal information, and to opt out of the sale of personal data and targeted advertising. We extend these rights to residents of any US state with a comprehensive privacy law, regardless of whether we technically meet the law's threshold for applicability — it's simpler to honor them universally. (Nevada residents: under Nevada law you may opt out of the sale of covered information; we do not sell covered information.)
To exercise these rights, use the Contact page with the subject "Privacy Rights Request." If we deny your request and your state law provides for an appeal, you may appeal by submitting a follow-up message marked "Appeal" within 60 days.
EU / UK / EEA residents (GDPR / UK GDPR)
If you're in the EU, UK, or EEA, you have the additional rights to: restrict processing, object to processing based on legitimate interests, data portability, and to lodge a complaint with your local supervisory authority. Our legal basis for processing is: contract (to operate the marketplace), legitimate interests (fraud prevention, security, service improvement), consent (marketing emails, optional analytics), and legal obligation (tax, records retention).
International data transfers rely on standard contractual clauses where required. The Services are operated from the United States, and orders currently ship to U.S. addresses only.
How long it takes us to respond
We aim to respond to all rights requests within 30 days, which is the shortest deadline across the US state privacy laws. If we need more time we'll let you know within that window with an estimated completion date and the reason for the extension. Requests that require additional verification (e.g., for sensitive deletion requests) may take longer; we'll keep you posted.
Children's Privacy
Disc.Market is intended for adults age 18 and older. The Services are not directed to children, and we do not knowingly collect personal information from anyone under 18. If we become aware that we have received personal information from a person under 18 without verifiable parental consent, we will promptly delete it.
Parents and guardians: if you believe a child has provided us with personal information, please reach us via the Contact page with the subject "Children's Privacy" and we'll take prompt action — typically deleting the account and any associated data within 7 days.
We comply with the Children's Online Privacy Protection Act (COPPA) for users under 13 and apply the same protections to anyone we identify as under 18. We have no actual knowledge of selling or sharing the personal information of consumers under 16, and we do not knowingly share a minor's personal information with the optional advertising pixels. We do not target ads to minors, and we do not display interest-based ads to anyone — minor or adult — on the Services.
Security
We take reasonable and appropriate measures to protect your information, including:
- TLS (HTTPS) encryption for all traffic between your browser and our servers
- Password hashing handled by our authentication provider (never stored in plaintext)
- Per-user authorization enforced on every authenticated request
- Strict allow-list validation on every state-changing request, so a malicious request can't overwrite fields it shouldn't
- Tiered rate limiting on authentication, messaging, uploads, and other sensitive operations
- De-duplicated processing of every payment and shipping event we receive, so replayed events can't cause double-charges or double-payouts
- HTTP-only auth cookies; passwords and session tokens are never accessible to scripts running in the page
- Sanitization of every piece of user-authored content rendered to other users, to prevent script injection
- Automated bot detection on checkout
- Regular dependency scans and security updates
- Encrypted database backups via our infrastructure provider (Supabase / AWS)
Despite these measures, no online service is 100% secure. In the event of a security incident that affects your personal information, we will notify you and any required regulators without undue delay and in accordance with applicable law.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business. When we do, we'll revise the "Last updated" date at the top of this page. If changes are material, we'll also post a notice on the homepage and email users with active accounts at least 7 days before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.
Contact Us
For privacy-specific questions, data-rights requests, or complaints, please use the Contact page and select the topic that fits your inquiry, or email support@disc.market. The contact form routes directly to our team and is the fastest way to reach us.
We aim to respond to all privacy inquiries within 10 business days and to data-rights requests within 30 days (or sooner if required by law). If we need more time, we'll let you know within that window with an estimated completion date and the reason.
Disc.Market LLC, a Missouri limited liability company, is the controller of your personal information.