Start typing — brands, models, or categories
Legal

Privacy Policy

Effective June 30, 2026 · Terms of Service →
The short version: We collect what we need to run a marketplace and nothing more. We do not sell your data, share it with advertisers, or use it to build ad profiles. No tracking pixels, no third-party analytics that follow you across the web. The platform is operated by HiFi Registry LLC and owned by High Fidelity Holdings LLC, both incorporated in Arizona.

1. Who we are

The HiFi Registry marketplace at hifiregistry.com is operated by HiFi Registry LLC, an Arizona limited liability company. The platform, including all software, content, brand assets, and intellectual property, is owned and licensed by High Fidelity Holdings LLC, also an Arizona limited liability company. Where this policy refers to “HiFi Registry,” “we,” “us,” or “our,” it refers to HiFi Registry LLC acting on behalf of, and under license from, High Fidelity Holdings LLC.

For purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), and similar data protection laws, HiFi Registry LLC is the controller of personal data collected through hifiregistry.com. HiFi Registry LLC determines the purposes and means of processing your personal data in operating the platform. High Fidelity Holdings LLC's role is limited to ownership of the platform software, intellectual property, and platform data; it does not process personal data on a day-to-day basis or determine how personal data is handled in the operation of the platform.

Both entities are incorporated in Arizona, United States. For privacy-related correspondence, see Section 11.

2. What we collect

We collect information in three ways:

You give it to us — email address (account creation, waitlist), name, shipping address, payment details (processed by PayPal — we never see raw card numbers), listing content (photos, descriptions, prices), and optionally your phone number.

Stripe Identity gives it to us — Government ID type, name, and address for seller verification. We receive a verification result (pass/fail) and a reference ID. We do not store copies of your government ID.

Automatically — Standard server logs (IP address, browser type, pages visited, timestamps). We use these for security monitoring and abuse detection. Logs are retained for 90 days and then deleted.

Aggregate analytics — We run a self-hosted instance of Umami inside our own AWS account to count page views and learn which features get used. Umami does not set cookies, does not fingerprint visitors, and does not track you across sites or sessions. The data never leaves our servers and is never shared with any third party. See Section 8 for full details.

3. What we never do with your data

We will never:

  • Sell your personal information to data brokers or third parties
  • Share your data with advertisers or ad networks
  • Use your data to build advertising or behavioral profiles
  • Place third-party tracking pixels on our pages
  • Use Google Analytics, Meta Pixel, TikTok Pixel, or any other third-party analytics or advertising SDK
  • Sell access to your email address to any party for any purpose
  • Use your listing photos for any purpose other than displaying your listing and recording the transaction

4. How we use your information

  • To operate the marketplace — show your listings, process payments, communicate transaction status
  • To verify seller identity before their first listing goes live
  • To detect and prevent fraud, fake listings, and account abuse
  • To send transactional emails (new messages, listing activity) via Amazon SES
  • To notify you when early access opens (waitlist only — one email)
  • To publish anonymized, aggregated transaction data on the public sold-price database

5. Identity verification via Stripe Identity

Verification process
Seller verification is handled entirely by Stripe Identity, a regulated financial-services provider. Your government ID is transmitted directly to Stripe — HiFi Registry does not receive, process, or store images of your ID document. We receive only a pass/fail result and a reference token.

Stripe's handling of identity data is governed by the Stripe Privacy Policy. You may contact Stripe directly to request deletion of your identity verification data.

6. Public sold-price database

When a transaction completes, the following information is published to our public sold-price database: item title, category, condition grade, sale price, and date of sale. Buyer and seller personal information (name, username, address) is not included in the sold-price record. The seller's username is visible on the listing page during the sale but is not surfaced in the sold-comps database.

7. Cookies and local storage

We use a single session cookie to keep you signed in. We do not use tracking cookies, advertising cookies, or persistent identifiers shared with third parties. We use browser localStorage to remember filter preferences on the browse page and to support our first-party site analytics (see Section 8). No data stored locally is sent to any third party. Our self-hosted Umami analytics (described in Section 8) does not set any cookies.

8. Site analytics

We use Umami, a privacy-focused, self-hosted analytics tool, to understand how the platform is used in aggregate — which pages are most viewed, which referrers send traffic, which features are exercised. Umami runs on our own AWS infrastructure under umami.hifiregistry.com and is loaded into the page from our own domain. No analytics data is shared with, transmitted to, or made available to Google, Meta, or any other third party.

Umami is configured cookieless. To distinguish unique visitors for aggregate counts, it uses a salted hash of your IP address and browser user-agent that rotates daily and is not linkable across days. We do not retain individual visitor session timelines, do not record your interactions, do not replay your activity, and do not assign you a persistent identifier.

We do not use Google Analytics, Meta Pixel, or any third-party analytics or advertising SDKs of any kind.

9. Data sharing

We share specific categories of data with the following sub-processors solely to operate the platform. We do not sell or share personal information for any other purpose, and we do not authorize these sub-processors to use your data for their own marketing or profiling.

  • PayPal, Inc.— listing fee processing only. We transmit your email address and the listing fee amount so PayPal can collect payment from you and remit it to us. We do not receive your card number, bank account, PayPal balance, linked accounts, or transaction history. PayPal's privacy practices: paypal.com/privacy.
  • Stripe, Inc. (Stripe Identity only)— optional, seller-initiated identity verification only. Stripe Identity receives your government ID and selfie and returns a pass/fail verification status to us. Stripe does not process any payments on HiFi Registry. We do not store images of your ID. Stripe's privacy practices: stripe.com/privacy.
  • Amazon Web Services (AWS)— cloud infrastructure provider operating in the United States. AWS provides our compute, database, authentication, photo storage and delivery (S3 + CloudFront), transactional email (SES), and SMS (SNS, only if you opted into SMS notifications). AWS acts strictly as a processor on our instructions and does not use your data for its own purposes. AWS's privacy practices: aws.amazon.com/privacy.

Site analytics are handled in-house via self-hosted Umami; see Section 8. We do not use Google Analytics, Meta Pixel, or any third-party analytics or advertising SDK.

None of the sub-processors listed above are authorized to use your data for their own marketing, profiling, or to disclose it to further third parties.

10. Data retention

  • Account data (email, username, profile) — retained while your account is active. Deleted within 30 days of account closure, except as required by tax law or for the immutable sold-comps record described in Section 6.
  • Listing data — retained until sold or withdrawn. Completed sales contribute to the sold-price database with personal seller information stripped.
  • On-platform messages — retained for 24 months from the last message in a thread. If a dispute is opened on a transaction, messages tied to that transaction are retained indefinitely as part of the dispute record.
  • Dispute records — retained permanently as part of the platform's accountability system.
  • Transaction records — retained indefinitely for the sold-price database and tax reporting requirements.
  • Phone number — retained only while stored on your account. Removed upon account deletion or upon request. SMS opt-in consent records are retained for 4 years for TCPA compliance.
  • Server logs — retained 90 days, then deleted.
  • Waitlist emails — deleted upon platform launch notification or upon request.

11. Your rights

You may request a copy of your personal data, correction of inaccurate data, or deletion of your account by emailing privacy@hifiregistry.com. We acknowledge requests within 5 business days and respond substantively within 30 days.

Data portability. Upon request we will provide a machine-readable export of your account data — username, email, listings, messages, watchlists, follow lists, and feedback — in JSON or CSV format, delivered within 30 days at no charge.

EEA and UK residents. Under the GDPR and UK GDPR you have rights of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing. Our legal basis for processing is contract performance and our legitimate interests in operating a secure marketplace. HiFi Registry LLC is the controller of record (see Section 1).

California residents. Under the California Consumer Privacy Act (CCPA), you have the right to know what data is collected about you, to request deletion, and to opt out of any sale or sharing of personal information.

We do not sell or share personal informationas those terms are defined under the CCPA. We do not sell personal information to data brokers, do not share it for cross-context behavioral advertising, and do not otherwise engage in commerce involving personal data. As a result, we provide no “Do Not Sell or Share My Personal Information” opt-out link — there is no sale or sharing for you to opt out of.

Transaction records (item, condition, price, date) in the sold-price database cannot be deleted on request — they are part of the immutable price history that buyers rely on. Your name and username are not attached to those records.

12. Changes to this policy

We will notify registered users by email of any material changes to this Privacy Policy at least 30 days before they take effect. The effective date at the top of this page reflects the most recent version. The previous version is available upon request at privacy@hifiregistry.com.

13. Children under 13

HiFi Registry is not directed to children. We do not knowingly collect personal information from anyone under the age of 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly. If you believe a child has provided us with personal information, contact us at privacy@hifiregistry.com and we will investigate. Account creation requires users to be at least 18 years old, as set forth in our Terms of Service.

14. Do Not Track

Some browsers transmit a “Do Not Track” (DNT) signal to indicate a preference not to be tracked across sites. HiFi Registry does not engage in cross-site tracking, behavioral profiling, or interest-based advertising under any circumstances — there is no tracking to opt out of. We therefore honor DNT by default, because our default behavior already matches what DNT requests.
Terms of Service →Fee Schedule →Moderation Policy →