Last Updated: March 2, 2026
Quick Summary: We collect only the data necessary to provide myBidly services. Your data is processed in compliance with GDPR. You have full control over your data with rights to access, correct, delete, and port your information.
Next Commerce GmbH ("we", "us", "our") operates myBidly and takes the protection of your personal data very seriously. We process your personal data in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and other applicable data protection laws.
This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights regarding your personal data.
The responsible party for data processing on this website is:
The responsible party is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).
When you register as a merchant, we collect:
When end-customers place bids through your widget, we collect:
We process your personal data for the following purposes:
We store your personal data only as long as necessary for the purposes outlined above:
We share your data with the following third parties to provide our services:
We use Stripe for payment processing. Stripe processes payment data according to their Privacy Policy. Stripe is PCI-DSS Level 1 certified.
We use Resend to send transactional emails (bid confirmations, order notifications). Resend processes data in accordance with GDPR.
Our platform is hosted on Vercel. Server locations are in the EU. Vercel complies with GDPR and has appropriate data processing agreements in place.
Customer and bid data is stored in a PostgreSQL database hosted within the EU with encryption at rest and in transit.
We use the following cookies:
We do NOT use third-party tracking cookies, advertising cookies, or analytics tools that track you across websites.
This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries you send to us as the site operator. You can recognize an encrypted connection by the browser address line changing from "http://" to "https://" and by the lock icon in your browser.
When SSL/TLS encryption is activated, the data you transmit to us cannot be read by third parties.
You have the following rights regarding your personal data:
You can request a copy of all personal data we hold about you.
You can correct inaccurate or incomplete data.
You can request deletion of your data, unless we are required to retain it for legal reasons (e.g., tax compliance, ongoing contracts).
You have the right to receive your data in a structured, commonly used, and machine-readable format (e.g., CSV, JSON) and transfer it to another provider.
You can withdraw your consent to data processing at any time by sending an email to info@next-commerce.io. The withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
You can object to processing of your data for direct marketing purposes at any time.
If you believe we have violated data protection laws, you can file a complaint with the competent supervisory authority. The supervisory authority responsible for data protection issues is the State Data Protection Officer of the federal state where our company is based. A list of data protection officers and their contact details can be found at: https://www.bfdi.bund.de.
We implement appropriate technical and organizational measures to protect your data, including:
Important: We note that data transmission over the Internet (e.g., via email) may have security gaps. Complete protection of data from access by third parties is not possible.
The use of contact data published within the framework of the imprint obligation to send unsolicited advertising and information materials is hereby expressly prohibited. The operators of these pages expressly reserve the right to take legal action in the event of unsolicited sending of advertising information, such as spam emails.
All personal data provided to us unsolicited (e.g., applications, cover letters with personal data) will not be stored or otherwise processed by us but will be immediately and irrevocably deleted without notification to the sender.
The legally required data protection officer is Next Commerce GmbH.
Contact: info@next-commerce.io
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes via email or by posting a notice on our website.
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at: