Privacy Policy for WheelDeal

Last Updated: 12/6/2025

1. Introduction and Scope

This Privacy Policy describes how WheelDeal ("we," "us," or "our") collects, uses, processes, and protects the personal data of users ("you" or "Data Subject") who access or use our online vehicle marketplace service (the "Service").

We are committed to protecting your privacy and ensuring compliance with the Personal Data Protection Act, No. 9 of 2022 (PDPA) of the Democratic Socialist Republic of Sri Lanka.

By using the Service, you consent to the collection and use of your personal data as described in this policy.

2. Data Controller

WheelDeal is the Data Controller responsible for the processing of your personal data collected through the Service.

Contact Details:

  • Name: WheelDeal Inc.
  • Address: Colombo, Sri Lanka
  • Email: privacy@wheeldeal.lk

3. Personal Data We Collect

We collect personal data that you voluntarily provide to us when you register for an account, list a vehicle, contact another user, or otherwise use the Service.

Category of DataExamples of Data CollectedPurpose of CollectionLegal Basis (PDPA)
Identity DataName, username, profile picture (optional)To create and manage your user account.Consent of the Data Subject
Contact DataEmail address, phone numberTo communicate with you, facilitate contact between buyers and sellers, and for account recovery.Consent of the Data Subject
Vehicle Listing DataVehicle make, model, year, price, description, images, location (city/district)To display your advertisement on the Service.Necessary for the performance of a contract
Technical DataIP address, browser type, operating system, access timesTo ensure the security and functionality of the Service and for fraud prevention.Legitimate Interest

4. How We Use Your Personal Data

  • To Provide the Service: To operate and maintain the Service, including publishing your vehicle listings and enabling communication between users.
  • Authentication: To verify your identity and manage your access to the Service.
  • Communication: To send you service-related notices, updates, and respond to your inquiries.
  • Security and Fraud Prevention: To detect, prevent, and address fraudulent or illegal activities, including fraudulent vehicle listings, in compliance with the Online Safety Act and other relevant Sri Lankan laws.
  • Content Protection: To apply watermarks to images you upload to prevent unauthorized use by third parties and to protect the integrity of the Service.
  • Improvement: To analyze usage and improve the functionality and user experience of the Service.

5. Disclosure of Your Personal Data

5.1. Other Users

When you post a vehicle listing, your Contact Data (e.g., phone number, email address) will be visible to other users to facilitate contact, as this is the core function of the marketplace.

5.2. Third-Party Service Providers

We use third-party services to operate and maintain the Service.

  • Clerk (Authentication): We use Clerk for user sign-up and sign-in. Clerk processes your Identity and Contact Data on our behalf to manage your account security. Their processing is governed by their own privacy policy.
  • Cloudinary (Media Storage): We use Cloudinary to store and serve images uploaded to the Service. Images you upload are stored on Cloudinary's servers.
  • Hosting and Analytics Providers: Providers who assist us in hosting the website and analyzing its usage.

5.3. Legal and Regulatory Authorities

We may disclose your personal data if required to do so by law or in the good faith belief that such action is necessary to comply with a legal obligation, protect and defend our rights or property, or protect the personal safety of users or the public.

6. Data Subject Rights (Your Rights under the PDPA)

Under the PDPA, you have the following rights regarding your personal data:

Right of Access

The right to obtain confirmation as to whether your personal data is being processed and to access that data.

Right to Rectification

The right to request the correction of inaccurate or incomplete personal data.

Right to Erasure

The right to request the deletion or removal of your personal data under certain circumstances.

Right to Withdraw Consent

The right to withdraw your consent to the processing of your personal data at any time, where consent is the legal basis for processing.

Right to Object

The right to object to the processing of your personal data, including for direct marketing purposes.

To exercise any of these rights, please contact our Data Protection Officer (or designated contact) using the details provided in Section 2.

7. Data Security and Retention

7.1. Security Measures: We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction. This includes using secure third-party authentication (Clerk) and secure hosting environments.

7.2. Data Retention: We will retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Generally, we will retain your data for the duration of your active account and for a reasonable period thereafter as required by law.

8. International Data Transfers

Since our Service uses third-party providers (like Clerk and hosting services) that may process data outside of Sri Lanka, your personal data may be transferred to, and processed in, countries outside of Sri Lanka.

We will only transfer your data internationally in compliance with the PDPA, ensuring that the recipient country or organization provides an adequate level of protection for personal data, or by implementing appropriate safeguards such as standard contractual clauses.

9. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically for any changes.