Open Marketplace
Privacy Policy
This policy explains what Open Marketplace collects, what optional Facebook Login, TikTok Login Kit, Reddit identity connection, and PayPal Login can add, and how you can remove those links. Anyone can read it. You do not need an account.
Who we are
Open Marketplace is an independent marketplace. People browse listings without signing in. People who want to publish or manage a listing create an account with an email address and password.
Facebook and Meta are external account providers, not the operator of this marketplace. A Facebook link never moves a listing onto Facebook, and it never makes Facebook responsible for a sale.
TikTok is also an external account provider. A TikTok link never moves a listing onto TikTok, and it never makes TikTok responsible for a sale.
Information we handle
When you use an account, we handle:
- The name and email address you give us.
- Sign-in, session, and security records needed to keep you signed in and to protect the account.
- Public profile, listing, and payment-destination details that you choose to publish.
- Marketplace catalog records for those listings and the account they belong to.
Photographs
Listing image bytes remain on the seller's device or on a host the seller chooses. The public catalog keeps listing metadata and content hashes, not the photographs themselves.
Facebook Login
Signed-in people can choose Connect. That uses Facebook Login and asks for public_profile, user_link, user_hometown, user_location, user_gender, and user_age_range. We use the public name, profile photo, profile link, hometown, current city, and gender and age range Facebook returns so the seller in Account settings and buyers on listings see those same official Facebook details. A seller also sees the buyer’s official connectors in Messages. A listing connector can open that Facebook profile. Facebook no longer returns a bio, cover photo, locale, or website to apps. Those Facebook details stay with the Facebook link. They do not replace your Open Marketplace name or email.
Facebook Login is not a way to create or open an Open Marketplace account.
What Facebook does not give us
Open Marketplace does not ask Facebook for:
- Facebook email permission.
- Facebook birthday or mobile phone permission.
- Facebook friends or followers.
- Facebook Pages.
- Facebook Marketplace data.
- Facebook listings or listing photos.
- Facebook Commerce data.
- Government-identity verification, or any “Facebook verified” label.
TikTok Login Kit
Signed-in people can choose Connect TikTok. That optional connection uses TikTok Login Kit OAuth and asks for user.info.basic, user.info.profile, and user.info.stats. After the user authorizes TikTok, our server exchanges the authorization code and reads the TikTok app-scoped open_id, display name, username, profile link, avatar, and follower count TikTok returns. We use those fields to show the linked TikTok identity on the existing Open Marketplace account and, when connected, on listings and Social Credit. Official fields include display name, username, profile link, avatar, bio, follower count, following count, likes, and video count when TikTok returns them. Those TikTok details stay with the TikTok connector. They do not replace your Open Marketplace name, email, or image.
TikTok Login Kit is not a way to create or open an Open Marketplace account. Open Marketplace does not post to TikTok, read TikTok videos, or read TikTok messages.
TikTok access tokens, refresh tokens, and the client secret remain server-side. They are not placed in public profile pages, public listing records, or public project files.
Reddit Integration
Signed-in people can choose Connect Reddit. This optional connection uses Reddit OAuth and requests only the identity scope. After authorization, our server reads the Reddit user identifier and username from /api/v1/me to prove voluntary control of the account.
Open Marketplace adheres strictly to Reddit's Responsible Builder Policy:
- We do not scrape or analyze Reddit posts, comments, voting history, or subreddit participation.
- We do not ingest karma, account age, moderator status, or friends.
- Reddit data is never used to build a reputation score, calculate Social Credit, or influence search ranking or marketplace discovery.
- We do not infer sensitive characteristics, train AI/ML models on Reddit data, or target advertising using Reddit activity.
- We never sell or license Reddit-derived data.
Reddit OAuth access tokens and credentials remain encrypted server-side and are never exposed in public listings, client bundles, or URLs.
PayPal Login
Signed-in people can choose Log in with PayPal. That uses official PayPal Login and asks for openid only. If PayPal also returns an email or a paypal.me address, we may use that as the public pay-to after you connect. Listings can show whether PayPal is currently linked. PayPal Login is not a way to create or open an Open Marketplace account, and this marketplace does not take, hold, or send PayPal payments.
You can remove the PayPal link in Account settings. PayPal tokens stay on the server. They are not placed in public listing records.
How provider credentials are kept
Facebook access credentials and tokens remain server-side. They are not placed in public profile pages, public listing records, or public project files.
TikTok Login Kit tokens and the TikTok client secret also remain server-side. They are not placed in public profile pages, public listing records, or public project files.
PayPal Login tokens and the PayPal client secret also remain server-side. They are not placed in public profile pages, public listing records, or public project files.
Why we use this information
We use it to:
- Operate accounts and keep sessions working.
- Show the marketplace features you asked for.
- Protect the service against abuse.
- Link a Facebook account when a signed-in person chooses Connect.
- Link a TikTok identity to an existing marketplace account when a signed-in person chooses Connect TikTok.
- Link a Reddit identity to an existing marketplace account as proof of account control when a signed-in person chooses Connect Reddit.
- Link a PayPal identity to an existing marketplace account when a signed-in person chooses Log in with PayPal.
How long we keep it
Account and listing records stay while the account is open and the listing is on the catalog. Facebook Login tokens and the Connected profile are removed when you disconnect, or when Facebook asks us to delete that link. TikTok Login Kit tokens and the linked TikTok identity are removed when you disconnect TikTok. Reddit OAuth tokens and the linked Reddit account details are removed immediately when you disconnect Reddit. PayPal Login tokens and the linked PayPal identity are removed when you disconnect PayPal. We do not keep a separate advertising profile.
Deleting Facebook data
Account Settings offers Disconnect now. Disconnect removes the active linked Facebook account credentials and tokens and the Facebook name and photo shown next to Connected, stops future Facebook access, and leaves the Open Marketplace account and session intact.
Step-by-step instructions, including what to do from Facebook's own Apps and Websites page, are on Open the Facebook data deletion instructions.
Deleting TikTok data
Account Settings offers Disconnect now. Disconnect removes the active linked TikTok authorization and tokens and the TikTok display name shown next to Connected, stops future TikTok access, and leaves the Open Marketplace account and session intact.
You can also remove Open Marketplace from TikTok's own connected apps settings. That revocation causes later Open Marketplace checks to fail closed. Account Settings then shows Needs reconnect with Disconnect and Connect TikTok, and does not keep displaying a stale Connected state.
Deleting Reddit data
Account Settings offers Disconnect now. Disconnect immediately purges the active Reddit OAuth tokens and unlinks the Reddit username from your profile, stops all future Reddit API interactions, and leaves your Open Marketplace account and session intact.
You can also revoke Open Marketplace access directly from Reddit's Authorized Applications settings in your Reddit account preferences.
Children
Open Marketplace is not directed at children under 13. Facebook Login is only available to people Facebook already allows to use that product. TikTok Login Kit is only available to people TikTok already allows to use that product. Reddit Connect is only available to people Reddit already allows to use that product. PayPal Login is only available to people PayPal already allows to use that product.
Effective date
22 August 2026
Other social Connect
Signed-in people can also Connect Instagram, X, LinkedIn, and Discord when those official apps are configured on this copy of the site. Instagram Login asks for
instagram_business_basiconly. It does not import posts or read messages. LinkedIn Sign In with OpenID Connect asks foropenid,profile, andemail. Discord asks foridentify,email,guilds, andconnections. Only public fields the provider returns after Connect are stored: every public profile field the provider already returns after Connect — handle, display name, first and last name, profile link, avatar, banner, bio, location, website, account type, locale, created date, and public counts such as followers, following, likes, posts, lists, or Discord servers. LinkedIn and Discord may also confirm that the provider email is verified; those provider emails are not published on listings and do not replace your Open Marketplace email. More official fields raise Social Credit. That social signal is the first line of defense before verified buys and sells exist. Typed usernames and pasted links are not accepted. A provider verified mark is not an Open Marketplace verification badge. These links are not a way to create or open an Open Marketplace account.