Overview & Scope
Zorexium (“we,” “our,” or “us”) operates the Zorexium marketplace platform at zorexium.io and all related services. This Privacy Policy applies to all personal data collected when you use our website, create an account, make a purchase, list hardware for sale, or otherwise interact with our platform.
By using Zorexium, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our services.
Quick Summary
- • We only collect data necessary to operate and improve our services
- • We do not sell your personal data to third parties
- • You can request deletion of your data at any time
- • We use industry-standard security measures to protect your data
Data We Collect
We collect different types of information depending on how you interact with our platform.
Account & Identity Information
Collected when you create an account or update your profile.
- Full name, username, email address
- Password (stored as a secure hash, never in plain text)
- Profile picture (if uploaded)
- Phone number (optional, for 2FA or seller verification)
- Date of account creation and last login
Transaction & Financial Information
Collected when you make purchases or set up a seller account.
- Billing and shipping addresses
- Order history, purchase amounts, and item details
- Payment method type (last 4 digits only — full card numbers handled by our secure payment processors)
- Payout account details for sellers
- Tax information required by law (for sellers)
Device & Technical Information
Automatically collected when you access our platform.
- IP address and approximate geolocation (country/region level)
- Browser type and version, operating system
- Device type (desktop, mobile, tablet) and screen resolution
- Referral URL (how you arrived at our site)
- Session duration and pages visited
Usage & Behavioral Data
Collected to improve your experience and our platform.
- Search queries and filters applied
- Products viewed, added to cart, or wishlisted
- Time spent on pages and features used
- Community posts, reviews, and messages
- Seller listing data and product specifications
Communications
Stored when you communicate through our platform.
- Messages between buyers and sellers via our messaging system
- Support ticket content and history
- Email correspondence with our team
- Dispute records and resolution documentation
How We Use Your Data
We use your data for specific, legitimate purposes. We do not use your data for purposes incompatible with those outlined here.
Account Management
Create and maintain your account, authenticate logins, and enable account features
Order Processing
Process payments, coordinate shipping, handle returns, and manage disputes
Safety & Fraud Prevention
Detect and prevent fraud, abuse, spam, and security incidents on our platform
Communications
Send order updates, support responses, and promotional emails (with your consent)
Analytics & Improvement
Understand how our platform is used and make improvements to features and performance
Legal Compliance
Comply with applicable laws, regulations, and valid legal processes
Data Security
We implement multiple layers of technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.
256-bit SSL/TLS
All data in transit is encrypted using industry-standard TLS 1.3
Password Hashing
Passwords are hashed with bcrypt before storage. We cannot view your password.
Least Privilege Access
Employee access to user data is restricted on a need-to-know basis
Your Responsibility: No system is 100% secure. You are responsible for keeping your account credentials confidential and enabling two-factor authentication. If you suspect unauthorized access to your account, contact support immediately.
Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy or as required by applicable law.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account information | Duration of account + 30 days | Operational necessity |
| Transaction records | 7 years | Legal & tax compliance |
| Chat & messages | 2 years | Dispute resolution |
| Support tickets | 3 years | Quality assurance |
| Analytics data (aggregated) | Indefinitely (anonymized) | Platform improvement |
| Marketing consent records | Until consent withdrawn + 1 year | Legal requirement |
Your Privacy Rights
Depending on your location, you may have specific rights under applicable data protection laws (including GDPR for EEA residents and CCPA for California residents). We honor these rights for all our users globally.
Right of Access
Request a copy of all personal data we hold about you, including how it is processed and who it is shared with.
Right of Rectification
Request correction of inaccurate or incomplete personal data. You can update most information directly in your account settings.
Right of Erasure (“Right to Be Forgotten”)
Request deletion of your personal data. Note: some data must be retained for legal compliance (e.g., transaction records). We will inform you of any data we cannot delete and why.
Right to Restrict Processing
Request that we restrict the processing of your data while a dispute about accuracy or lawfulness is resolved.
Right to Data Portability
Receive a copy of your data in a structured, machine-readable format to transfer to another service.
Right to Object & Opt-Out
Object to the processing of your data for marketing purposes at any time. Unsubscribe from marketing emails using the link in any email, or manage preferences in Account Settings.
To exercise any of these rights, email privacy@zorexium.io or visit your Account Settings. We will respond within 30 days. We may ask you to verify your identity before processing your request.
Children's Privacy
Zorexium is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16 years old. If you believe a child under 16 has provided us with personal information, please contact us at privacy@zorexium.io and we will promptly delete such information.
Users between the ages of 16 and 18 may use the platform only with the consent and supervision of a parent or legal guardian, who accepts responsibility for the minor's use of the service.
International Data Transfers
Zorexium operates globally and your data may be stored or processed in countries other than your country of residence. We ensure that such transfers comply with applicable data protection laws and that appropriate safeguards are in place.
For transfers of personal data from the European Economic Area (EEA) to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. For transfers from the UK, we use the UK International Data Transfer Agreement (IDTA).
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by posting a notice on our website and, where required by law, sending you an email notification at least 30 days before the change takes effect.
Your continued use of Zorexium after the effective date of any updated Privacy Policy constitutes your acceptance of the changes. We encourage you to review this page periodically.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please reach out using the options below.