How we collect, use, share and protect your personal data
Effective date: 12 November 2025 • Last updated: 12 November 2025
We are committed to protecting and respecting your privacy. This policy explains how we collect, use, share and protect your personal data when you visit our website, register or bid in our online auctions, consign goods, or otherwise engage with us. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We only process personal data when we have a lawful basis. The table below summarises typical activities.
| Purpose | Examples | Lawful basis |
|---|---|---|
| Account set‑up & verification | Registering bidders/sellers, identity checks, refundable deposits | Contract; Legal obligation; Legitimate interests (fraud prevention) |
| Running auctions & fulfilment | Processing bids, invoicing, payments, collections/delivery | Contract; Legitimate interests |
| Consignments | Onboarding sellers, cataloguing, settlement | Contract; Legitimate interests; Legal obligation |
| Customer support & communications | Responding to enquiries, service notifications | Contract; Legitimate interests |
| Marketing | Newsletters, auction alerts, look‑alike audiences (where permitted) | Consent where required; Legitimate interests with opt‑out |
| Security & fraud prevention | Monitoring unusual activity, chargeback defence | Legitimate interests; Legal obligation |
| Legal & compliance | Tax/financial records, AML, complaints handling | Legal obligation; Legitimate interests |
We may share personal data with service providers and partners that help us deliver our services. These include:
We do not sell your personal data. Where we use processors, they act under our instructions and are bound by confidentiality and data protection terms.
We use cookies and similar technologies to operate our site, remember preferences, analyse usage and, with your consent where required, for marketing. You can manage consent through our cookie banner and your browser settings.
Some providers may process data outside the UK. Where this occurs, we ensure appropriate safeguards (e.g. UK International Data Transfer Agreement or Standard Contractual Clauses) so that your data remains protected.
When retention periods expire, we securely delete or anonymise data.
We implement appropriate technical and organisational measures to protect personal data, including secure hosting, encryption in transit, access controls, staff training and regular reviews. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Under UK GDPR you have the right to:
To exercise your rights, please contact us at support@castlers.com. We may need to verify your identity before responding.
We do not make decisions based solely on automated processing that have legal or similarly significant effects on individuals. We may use automated tools to help detect fraud or unusual bidding behaviour; these tools support human decision-making.
Our services are not directed to persons under 18 years of age. If we become aware that we have collected personal data from a child without appropriate consent, we will delete it.
Where CCTV operates at our premises, it is used for security and crime prevention. Footage may be shared with law enforcement when necessary and is generally retained for a short period unless required for an investigation.
Please contact us first so we can resolve your concern. We will also aim to provide you with a response within 5 working days.
We may update this policy from time to time. The latest version will always be available on this page. We may notify registered users by email of significant changes.
You will be able to unsubscribe at any time. Read our privacy policyhere.