Privacy Policy
Last updated 2026-09-20
TeamBlackBox Private Limited provides Going Once as a commercial service. This Privacy Policy explains how we collect, use, disclose, and protect Personal Information when you visit our website, create an account, join an organization, submit documents, or participate in an auction.
If you choose to use Going Once, you agree to the collection and use of information in relation to this Policy. We use Personal Information to provide and improve the service, operate auction workflows, keep member records accurate, and support audit and dispute resolution. We do not sell Personal Information.
Information we collect
- Account information: name, email address, profile photo, phone number, organization membership, role, and sign-in details.
- Organization and KYC information: configured profile fields, identity or eligibility documents, proposer and seconder endorsements, admin review notes, and profile-change requests.
- Auction information: catalogues, lots, lot media, bids, sale results, prompt dates, statements, delivery information, notifications, and audit events created while using the platform.
- Usage and log data: IP address, browser or device information, dates and times of use, pages or features accessed, diagnostic logs, and error information.
How we use it
- To create accounts and manage organization membership.
- To verify eligibility, KYC status, and role-based access.
- To operate catalogues, bidding, notifications, and settlement.
- To maintain auction audit trails, investigate disputes, prevent misuse, and protect the integrity of member-only auctions.
- To troubleshoot the service, understand aggregate usage, improve reliability, and communicate service changes.
Who sees it
Your organization’s administrators can view profile information, KYC or eligibility documents, review notes, auction participation, and settlement records required to run the organization. Auctioneers can see information needed to prepare their catalogues and operate their active auction stages. Buyers and sellers see auction information relevant to their own lots, bids, wins, sales, statements, and delivery workflows.
We may share information with service providers who help us provide, secure, host, analyze, or support Going Once. These providers are permitted to process information only for the tasks assigned to them on our behalf. We may also disclose information when required by law, to enforce our terms, or to protect rights, safety, and auction integrity.
Cookies and similar technologies
Going Once and the service providers we use may rely on cookies or similar technologies for sign-in, security, preferences, analytics, and reliability. You may refuse cookies through your browser settings, but some parts of the service may not work correctly without them.
Optional auction QR scanning
If you choose Scan QR code in the mobile app, the operating system scanner reads an auction entry code. On iPhone this requests camera access; on Android it uses Google Code Scanner without granting camera permission to Going Once. Going Once does not upload or save camera images. You can enter the auction code instead. Scanning does not join an auction, accept terms, or place a bid.
To limit code guessing, we keep pseudonymous account, installation and network-source attempt counters. These counters do not contain raw IP addresses, email addresses or auction content and are scheduled for cleanup seven days after their last accepted attempt. Cleanup may occur later. Minimal code-routing reservations are retained to prevent an old printed code from being reassigned to a different auction.
Optional mobile diagnostics
In the Going Once mobile app, Firebase Analytics automatic collection and screen reporting and Firebase Crashlytics collection are off by default. You can enable or disable optional diagnostics for that app installation from Account settings. Going Once custom events use only fixed screen and bid-state labels; we do not attach your name, email, organization, auction, lot, bid amount, bid ID, or request ID. Firebase may process technical app-installation and device information when the setting is enabled. Turning it off tells the app and those SDKs to stop further collection on that installation. Signing out or losing the authenticated session also turns optional diagnostics off.
Security and retention
We use commercially reasonable safeguards to protect Personal Information. No method of transmission over the internet or electronic storage is completely secure, so we cannot guarantee absolute security. KYC documents, auction records, bid history, and settlement records may be retained for as long as needed to support organization operations, audit obligations, dispute resolution, legal requirements, and legitimate business purposes.
Free Launch blocks raw identity-document uploads. Its closed-auction media is scheduled for deletion after the published 90-day product window. Completed bid, sale, acceptance, security, and audit records may be retained or pseudonymized where deletion would undermine fraud prevention, dispute evidence, legal duties, or transaction integrity. Our internal retention register identifies the purpose, owner, and disposal rule for each category.
Your choices
You can request access, export, correction, restriction, or deletion of your Personal Information through the organization administrator who manages your membership and through the support contact below. Some auction, KYC, and settlement records may need to be retained where deletion would break audit trails, dispute resolution, legal obligations, or the integrity of completed transactions.
Signed-in members can open My data & privacyto download an active-organization export or submit a review request. The Going Once mobile app also provides a whole-account deletion request in Account. It disconnects linked Apple access, revokes active Going Once sessions and notification devices, and queues each organization for governed deletion review; records that must be retained will be identified during that review.
Children’s privacy
Going Once is intended for business and organization users. It is not directed to children under 13, and we do not knowingly collect Personal Information from children under 13. If we learn that such information has been provided, we will take appropriate steps to delete it.
Links to other sites
The service may contain links to external sites. We are not responsible for the content, privacy policies, or practices of third-party sites or services. Please review their policies before providing information.
Changes to this Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date, and material changes may also be notified through the service or to organization administrators.
Contact
Questions or requests about this Policy can be raised through your organization administrator, or by contacting Team Black Box.