Open. Pay by card, Apple Pay & Google Pay (Stripe) — verified sellers, discreet delivery. Questions? contact@weared.ch. Updated 12.09.2026 à 22h23. · Social-media influencer? Get in touch to learn more
Legal notice

Privacy Policy

Privacy is not optional at Weared: it is the very heart of the house. We process your data in accordance with the Swiss Federal Act on Data Protection (nFADP) and, where it applies to persons located in the European Union, with the General Data Protection Regulation (GDPR) in its extraterritorial reach.

1. Data controller

The data controller within the meaning of the nFADP and Article 4 GDPR is Weared, an entity established in Switzerland (identity and address: legal notice). For any question, exercise of rights or incident concerning your data: contact@weared.ch. No data protection officer and no representative in Switzerland or in the EU has been designated to date.

Requests are handled within the statutory time limits (30 days under the nFADP, 1 month under the GDPR), in French, German, Italian or English, with no justification required for exercising a right.

2. Data we process

We limit collection to what is strictly necessary:

  • Registration data: pseudonym, confidential contact address, technical identifiers, technical fingerprint of the browser computed at sign-up (anti-fraud);
  • Verification data: proof of age and identity (see the Verification page);
  • Transaction data: order history, payment references (Lightning, or Stripe for cards), shipping information — pickup point, or name and postal address if you choose home delivery; for a purchase without an account: e-mail, declaration of majority and delivery address;
  • Technical data: connection logs necessary for security;
  • Declared Instagram account: if you take part in the social-media offer, the Instagram username you declare is recorded on your account. It links your Weared pseudonym to a real public identity: the declaration is voluntary, and its removal may be requested at any time;
  • Screenshots submitted as evidence: those you attach to that same offer (profile, story, share) may show your account, your followers and sometimes private conversations. They are neither published nor served by the site — they are stored outside the public folder and can only be viewed by moderation.

3. Intimate-sphere data and explicit consent

What you entrust to us here — your listings, your preferences, your conversations, your purchases — may reveal elements belonging to your private, intimate sphere. The nFADP (art. 5 let. c) and the special categories of Article 9 GDPR class such information as sensitive data and grant it the highest level of protection. Its processing rests on your explicit consent (nFADP art. 6 para. 7 let. a). We do not ask for it at registration: at that point you have entrusted nothing to us yet, and a mandatory box to get in would not be a choice. We collect it where the processing really begins — at the time of identity verification and when you put a listing online — and we keep its date and the version of the text accepted, so as to know what you said yes to. You withdraw it by deleting your account, at any time, with no need to justify yourself.

We never infer, enrich or share this data for advertising-profiling purposes. It serves solely for the performance of the service and compliance with our legal obligations.

4. Purposes and legal bases

Your data is processed to: carry out the introduction and the transaction; frame the direct payment between members and neutral shipping; verify age and identity; prevent fraud, abuse and trafficking; comply with our Swiss legal obligations.

The legal bases are, as the case may be, performance of the contract, explicit consent for sensitive data, legal obligation and the legitimate interest in the security of the house.

5. Anonymity between members

By design, members know one another only by pseudonym. By default, shipping to a PickPost pickup point or My Post 24 locker and the systematic use of pseudonyms mean that neither the seller nor the buyer accesses the other's details; if the buyer chooses home delivery, the seller receives the name and address they provided for shipping. Weared stands as a discreet curtain between the parties.

Members directory. Pro and Max members can browse a list of members on the other side (sellers see buyers, buyers see sellers) in order to start a conversation on the platform. This list only shows the username, avatar, country, badges (verified identity, subscription tier), the number of completed purchases or sales, the number of listings online and an indication of recent activity — never an e-mail address, postal address or history. Any member can leave the directory at any time in their settings: they no longer appear in it and nobody can open a conversation with them from the directory.

6. Recipients and processors

Your data is shared only with the providers that are strictly necessary. We name all of them, with their role and country:

  • Didit (Didit Protocol, Spain — EU): identity and age verification.
  • Infomaniak (Switzerland): mail hosting and delivery of the e-mails we send you or that you send us.
  • Cloudflare, Inc. (United States): site protection and delivery. All traffic passes through this provider, which therefore sees IP addresses and the data submitted through forms.
  • Swiss Post: neutral parcel delivery.
  • Stripe (Stripe Payments Europe Ltd, Ireland — Stripe, Inc. group, United States): card payments, subscriptions and billing. If you pay by card, the payment page is hosted by Stripe: your card number never passes through our servers and we never see it. Stripe receives your e-mail address, your IP address, your country and your payment method details; it returns to us only your customer record identifier, the subscription status, its next renewal date, the card brand and its last four digits.
  • Stripe Connect (same company): payouts in Swiss francs to sellers who request them. If you sell and choose to be paid to a bank account, Stripe opens a payout account in your name and asks you, on its own pages, for the information it must verify as a financial institution: first name, surname, date of birth, address, phone number, identity document and IBAN. Weared passes on only your pseudonym, your e-mail address, your country and your shop address; it never sees any of that information and does not store it. In return it receives only your payout account identifier, its verification status and, where applicable, the reason for a refusal. Staying paid in bitcoin involves none of this data.
  • DeepL SE (Germany): automatic translation of listing texts into the visitor's language.
  • GitHub, Inc. (United States): storage of an encrypted backup copy of the database and uploaded files.

Crypto payments, for their part, involve no third-party provider. Every processor is bound by confidentiality and security commitments.

If you pay with Apple Pay or Google Pay, the wallet provider takes part in the transaction under its own terms; we receive no data from it. The card itself runs on the Visa or Mastercard network, which sees the transaction as it would any other purchase.

Hosting and processing take place in Switzerland, on infrastructure operated by the site operator. Identity verification is processed in the European Union by Didit (certified ISO/IEC 27001:2022 and SOC 2, under a data processing agreement): since Switzerland recognises the EEA as providing adequate protection, no additional safeguard is required. Details: Didit's privacy notice. Weared receives no copy of the identity document, no photo and no video. No name or address is ever passed to Weared.

Cloudflare and GitHub may process data outside Switzerland and the EU. Those transfers rely on the standard contractual clauses recognised by the Federal Data Protection Commissioner (art. 16 and 17 revFADP).

Embedded third-party content. On an order's payment page, a widget from the exchange Mt Pelerin (Switzerland) is displayed in an embedded frame, so you can buy bitcoin without leaving the site. It is not a processor: if you use it, you deal directly with Mt Pelerin under its own terms. That frame is loaded only if you click the “Buy sats in CHF” button; that click then sends your IP address to that company, before you interact with the widget at all.

No data is sold to third parties. Disclosure occurs only under a legal obligation issued by a competent Swiss authority.

7. Retention period

We apply the following periods:

  • Identity photo and verification video — what our provider Didit calls biometric data in its privacy notice: never stored by Weared. They remain with Didit, where the retention period is set to 1 month, after which they are automatically deleted from its servers. Didit's audit logs (who triggered which verification, without documents) are kept for 365 days.
  • Proof of verification (result, date, control reference, date of birth): kept for as long as the account exists, deleted when it is closed.
  • Accounting and transaction records: 10 years, pursuant to art. 958f CO.
  • Account and content: when the account is closed, content is deleted and the account anonymised; orders are kept for 10 years (accounting rule above) without name or address; listing photos quarantined by moderation are erased at the latest 12 months after closure.
  • Audience data (page views, anonymised technical fingerprint): 30 days.
  • Log of sent e-mails (recipient, subject, body, delivery status): 24 months, then automatic purge.
  • Reports and technical browser reports (IP address, browser): 12 months at most.
  • Stripe payout account (sellers): the link between your Weared account and your payout account is kept for as long as your account exists, and deleted when it is closed. The accounting record of the transfer follows the 10-year rule above. The account opened with Stripe does not belong to us: we can ask for it to be closed, but the information Stripe must keep for its own obligations stays with Stripe.

You may request early deletion of your verification data at any time: contact@weared.ch.

8. Your rights

In accordance with the nFADP and the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw your consent at any time. You may exercise these rights through the site's confidential channels.

You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, or with an EU supervisory authority where applicable.

9. Security

We implement appropriate technical and organisational measures: encrypted connections (TLS), hashed passwords, encrypted backups, restricted administrative access and logging. Discretion and minimisation guide every one of our technical choices.

10. EU Digital Services Act (DSA)

Where members located in the European Union access the platform, Weared qualifies as an intermediary hosting service within the meaning of Regulation (EU) 2022/2065 (Digital Services Act, DSA). Weared is not a very large online platform (VLOP) or a very large online search engine (VLOSE) under Article 33 DSA, as its average monthly EU audience remains well below the threshold of 45 million active users.

  • Single point of contact — authorities: contact@weared.ch, languages accepted: French, German, Italian, English (Articles 11 and 12 DSA).
  • Single point of contact — users: contact@weared.ch.
  • EU legal representative (Article 13 DSA): none has been designated to date; their identity will be published on this page as soon as they are designated.
  • Notice-and-action mechanism (Article 16 DSA): any third party may notify content it considers illegal via contact@weared.ch or the dedicated form on the platform, with a precise description of the content, its location (URL), the grounds of illegality and the notifier's contact details. Weared confirms receipt without delay and decides in a diligent, non-arbitrary and objective manner, notifying its reasoned decision and available redress (out-of-court dispute settlement under Article 21 DSA, judicial redress).
  • Trusted flaggers (Article 22 DSA): notifications from entities recognised as trusted flaggers by a Digital Services Coordinator are handled as a priority.
  • Terms and transparency (Articles 14, 15, 24 DSA): restrictions imposed on members, moderation and individual decisions are set out in clear and accessible terms; moderation statistics are published annually where the applicable threshold requires it.
  • Advertising and profiling: Weared displays no targeted advertising based on profiling using special categories of data within the meaning of Article 9 GDPR (Article 26 DSA), and does not knowingly address minors (Article 28 DSA).

These commitments come in addition to, and do not replace, the obligations arising under the nFADP, the GDPR and Swiss law.

11. Cookies, trackers and audience measurement

Weared loads no third-party advertising tracker: measurement is carried out by our own servers.

What depends on your country. In Switzerland, the law requires that you be informed of the purpose and of your right to refuse (Telecommunications Act, art. 45c let. b): measurement runs until you have refused. From the European Union, the EEA or the United Kingdom, it requires your prior consent (ePrivacy Directive, art. 5 §3): until you have answered the banner, nothing is written — no visit cookie, no page view, no fingerprint. The country is inferred from an indication supplied by our edge host Cloudflare; in its absence, the most protective regime applies.

The cookies.

  • Session cookie — strictly necessary: keeps you signed in for a rolling 30 days from your last visit, and at most 90 days after signing in. Without it, staying signed in is impossible.
  • “wc” — strictly necessary: remembers your choice in the banner, for 6 months. Without it, the question would be put to you again on every page.
  • “wv”subject to your choice: a random visitor identifier, valid for 6 months, inaccessible to the page’s JavaScript. It is used for audience measurement and for de-duplicating clicks. If you refuse, it is not set — and if it already existed, it is deleted.
  • “weared_lang” — strictly necessary: remembers the language you chose, for one year.
  • “aff” — set for one year when you arrive through a partner link, to attribute your sign-up to that partner. It is not set if you refused in the banner, nor — from the EU, the EEA or the United Kingdom — until you have accepted the marketing purpose.

What we record when measurement is active. On your first visit: the landing page, the site you came from (referrer), your browser (user-agent), the language requested, Cloudflare’s country indication, and — if they appear in the address — the campaign parameters utm_source, utm_medium, utm_campaign, utm_term, utm_content as well as the advertising click identifiers gclid, fbclid, msclkid and ttclid. Thereafter: the pages viewed, with their date. This audience data is kept for 30 days (§7).

What refusing actually switches off. The “wv” cookie, the visit record and its attribution, the advertising click identifiers, the technical fingerprint, fine-grained measurement in the browser — scroll depth, time spent on a page, form submission — and any event sent back to an ad network. What remains is a plain count of the pages served, which carries neither a visitor identifier nor an account identifier, and is therefore attached to no one. Refusing takes nothing away from the service.

Technical fingerprint of the visitor. A fingerprint of the browser’s technical characteristics is computed on our server, for anti-fraud purposes and to protect accounts. For audience measurement it follows the same rule as the rest: no measurement, no fingerprint. A fingerprint is, however, computed at sign-up, regardless of your choice, to limit multiple accounts and fraud. It is never used to follow you from one site to another, nor for advertising.

Browser local storage. The site stores your display preferences in your browser (localStorage) — theme, discreet mode, guided tours already seen — without sending them to the server.

Robots. No cookie is set and no record is written for an indexing robot.

Ad networks. An event (sign-up, purchase) is sent back to the network that brought the visit only if you have accepted the marketing purpose in the banner. It is sent from our server, with hashed identifiers (SHA-256) — never your e-mail address in the clear. As long as no campaign is running, this mechanism is inactive in any case and nothing is sent.

You can change your mind at any time: add ?cookies=1 to the address of any page to reopen the banner. “Necessary only” counts as a withdrawal there.

Frequently asked questions
Is my data considered sensitive?

Yes. Anything belonging to the intimate sphere is sensitive data under the nFADP and Article 9 GDPR; its processing rests on your explicit consent, revocable at any time.

Can other members learn my identity?

Not by default: pseudonyms are mandatory and shipping is via a neutral pickup point. The only exception: if you choose home delivery, the seller receives the name and address you provide.

Can I request the deletion of my data?

Yes, subject to legal retention obligations (notably accounting and protection of minors).

Which authority can I complain to?

The FDPIC in Switzerland, or an EU data-protection authority if you are located there.

Legal notice