XYZ Marketplace (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and share information when you use our platform.
1. Information We Collect
Information you provide
- Account registration: name, email address, password
- Creator onboarding: display name, bio, profile photo, payout details
- Product uploads: titles, descriptions, files, pricing
- Communications: support tickets, reviews, messages
Information collected automatically
- Usage data: pages visited, searches, clicks, purchases
- Device information: browser type, OS, screen size
- IP address and approximate location
- Cookies and similar tracking technologies
Payment information
Payment processing is handled by Paystack. We do not store full card numbers. We receive transaction metadata (amount, reference, status) from Paystack.
2. How We Use Your Information
- To provide, maintain, and improve our services
- To process transactions and deliver digital products
- To send transactional emails (receipts, download links, payout confirmations)
- To send marketing emails (you can unsubscribe at any time)
- To detect and prevent fraud and abuse
- To comply with legal obligations
- To generate anonymised analytics about platform usage
3. How We Share Your Information
We do not sell your personal data. We share data with:
- Paystack – payment processing. See Paystack's Privacy Policy.
- Supabase – database and authentication hosting.
- Cloudflare – file storage and CDN.
- Resend – transactional email delivery.
- PostHog – anonymised product analytics.
- Law enforcement when required by applicable law.
Creator public profiles (display name, bio, product listings) are visible to all visitors. Your email address is never shown publicly.
4. Cookies
We use essential cookies for authentication and functional cookies for preferences. We use analytics cookies (PostHog) to understand how people use our platform. You can disable non-essential cookies in your browser settings.
5. Data Retention
We retain your data for as long as your account is active. If you close your account, we delete personal data within 90 days, except where retention is required by law (e.g. financial records for 7 years).
6. Your Rights
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Opt out of marketing communications
- Port your data in a machine-readable format
To exercise these rights, email us at privacy@xyzm.com.
7. Security
We use industry-standard security measures including TLS encryption, Row-Level Security on our database, and access controls. No system is 100% secure; please use a strong, unique password.
8. Children's Privacy
Our services are not directed at children under 16. We do not knowingly collect data from children. If you believe we have done so inadvertently, please contact us.
9. Changes to This Policy
We may update this Privacy Policy. Material changes will be communicated by email or in-platform notification with at least 14 days notice.
10. Contact
Questions or concerns? Email privacy@xyzm.com.