1. Introduction
NexudeIT is operated by Nexude LLC, a New Jersey limited liability company (NJ Entity ID 0451490388). Nexude LLC ("we," "us," or "our") operates the NexudeIT marketplace platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website, mobile applications, and services (collectively, the "Platform"). By accessing or using the Platform, you agree to the terms of this Privacy Policy.
2. Information We Collect
Account Information: When you register, we collect your name, email address, username, and password (stored as a cryptographic hash). You may also provide optional profile details such as gender, avatar image, and cover image.
Transaction Data:When you place an order, we collect the name, email address, phone number, and shipping address you enter at checkout (including a separate address for a seller, if you choose one), together with the items, quantities, prices, shipping option, tax, discount, and any promo code applied to the order. We store the shipping name, address, and phone number encrypted; the email address you enter is used to send your order confirmation. You pay on the payment processor's own page — Stripe for cards, PayPal for PayPal, or Square where it is offered — or with a card you saved with Stripe (see Saved Payment Cards below), so the processor, not NexudeIT, collects your payment details: we keep the processor's payment reference, the amount, currency, and status, and never your full card number. We also keep your order history and communication between buyers and sellers. No purchases can be made during the open beta, so no orders, billing details, or payment method details are collected until full launch (see Section 2a).
Who Can See Your Orders:An order's details can be opened only by you (the buyer), the seller or sellers whose items are in it, and NexudeIT administrators. A seller is given what they need to fulfil their order: your name, your account email address, the contact details and shipping address you entered, and the items and totals. If a seller has added staff to their store, those staff can also export the store's order list (order references, your account identifier, totals, and statuses) and its customer list, which includes your username and account email address. Checkouts with items from several sellers are split into one order per seller, so each seller sees only their own order (Terms Section 9b). An order can also be looked up without signing in, but only by someone who enters both its order number and the email address on your account; that look-up shows the order's status, items, totals, and store name, never your name, address, or payment details, and repeated attempts are rate-limited. Promo-code redemptions are recorded against the order; when an unpaid order is cancelled, replaced, or released (Terms Section 8e), its redemption record is deleted.
Saved Payment Cards: If you choose to save a card for faster checkout — either on Stripe's hosted payment page or via the "Add a card" form in Account → Payment cards — the full card details are collected and stored by Stripe, our PCI-compliant payment processor. NexudeIT never sees or stores your full card number or CVV. We store only a Stripe payment-method reference and limited display metadata (card brand, last 4 digits, and expiry month/year) so you can recognise the card. You may view, set a default, or remove saved cards at any time in Account → Payment cards; removing a card also detaches it from Stripe.
Usage Data: We automatically collect information about how you interact with the Platform, including pages visited, products viewed, search queries, device type, browser, IP address, and referring URLs.
Recently Viewed Products:When you are signed in, we record the products you view so your "Recently viewed" list can sync across your devices and appear as a recently-viewed strip on the home page. For each viewed product we store a product reference/slug, name, image URL, price, category, and a viewed-at timestamp, linked to your account. This is not collected for logged-out visitors, whose recently-viewed history remains local to their device only.
Saved Searches & Alerts: If you save a marketplace search, we store the search name, its query text, the selected filter set, an enabled flag, and timestamps, linked to your account. We use this to notify you with in-app alerts when new listings matching your saved search appear. You can edit or delete a saved search at any time.
Launch Waitlist:Before NexudeIT opens to the public, you may join our launch waitlist. We collect your email address (and, optionally, your name and whether you intend to open a store) for the sole purpose of emailing you when the Platform launches. That email is sent once, at full launch, when purchases open — opening the open beta does not trigger it, and it still reaches you if you have created an account in the meantime. We do not sell this information or use it for unrelated marketing, and you may ask us to remove you from the waitlist at any time by contacting us. Once you have been notified of launch, your launch-waitlist entry is no longer used to contact you.
User-Generated Content: Reviews, ratings, messages, feedback, media uploads (images, videos), and community posts you create on the Platform.
Photo Metadata:Photos can carry hidden details added by the camera or phone (often called EXIF metadata), such as the date and time a photo was taken, the device model, and — if location tagging was on — the GPS location where it was taken. Photos you take with the in-app camera on the Sell page are re-saved without this metadata before they are uploaded, and so is a photo you crop with the website's crop tool (if you skip cropping, the original file is uploaded). Other photos and files you upload are stored and shown exactly as you send them, so any metadata they contain stays in the file, and anyone who can see the photo can download it and read that metadata. NexudeIT does not extract or use the details in this metadata itself (uploads are only scanned automatically for hidden code). If you do not want to share where a photo was taken, turn off location tagging in your camera settings or remove the location before you upload.
Support Messages: When you contact us through the Contact page (whether or not you are signed in), we collect the name and email address you enter, your subject and message, and, if you are signed in, your account identifier. Messages sent from the Contact panel in your account dashboard are linked to your account. We store these messages so our support team can read and answer them, and messages from the Contact page are also emailed to that team.
Cart & Checkout Activity: Your cart itself is kept on your device: on the website, in your browser's local storage, so each browser has its own cart; in the mobile app, in the app's own storage on your phone. The website and the app do not share a cart. A cart you build while signed in stays in that browser or app after you sign out and comes back when you sign in there again, and in the app, items you add before signing in move into your account's cart on that phone when you sign in. Clearing the browser's site data or the app's storage removes the cart. If you use Share cart on the website, we store the product identifiers and quantities from that cart (no prices, addresses, or payment details), linked to your account, under a random link that anyone you give it to can open; the link stops working after 30 days. To power cart reminders and enable a smooth resume-at-checkout experience, we also record a snapshot of your website cart (item identifiers, quantities, thumbnail URLs, prices at the time of addition) together with the time of last activity; the app does not send us this snapshot. For signed-in users this is tied to your account. For guests, it is tied to a randomly generated "nx_cart_session" cookie; no personal identifiers are attached. You can disable cart reminders at any time in Account → Settings → Email preferences, or by clearing the cookie.
Carrier & Shipping Data: When a seller links a carrier account (USPS, UPS, FedEx, DHL, Canada Post, Royal Mail, EasyPost, Shippo, etc.) we store their carrier API keys, account numbers, and meter numbers encrypted at rest with AES-256-GCM. These credentials are decrypted in memory only when generating a rate quote, buying a label, or pulling tracking events on the seller's behalf. When a buyer checks out with a seller who offers live carrier rates, we send the buyer's name, shipping address, and phone number, with the parcel details, to the carrier or aggregator that provides those rates, both while the buyer is choosing shipping and again when the order is placed. When a buyer purchases an item, we share the buyer's shipping address, the parcel weight, and the order reference with the carrier (or aggregator) chosen for that shipment so they can produce a rate, label, and tracking events. We do not share carrier credentials between sellers, and we never share buyer payment data with carriers.
2a. During the Open Beta
Before its full launch, NexudeIT runs an open beta in which the Platform is open but all purchases and payments are paused (see Terms Section 4a). While the open beta runs:
- No orders, and no card data for purchases. Checkout, card holds, and adding a new saved card are paused, so no orders are placed (and nothing is held for one), and neither NexudeIT nor its payment processors collect or process payment-card data for purchases during the open beta. Cards you saved before the open beta stay stored by Stripe as described above (Saved Payment Cards), and you can still view or remove them in Account → Payment cards.
- Beta feedback. If you send feedback or a bug report — through the Feedback or Report Bug options on the chat button, the form in the open beta guide, or Send feedback in the mobile app — we collect the subject and details you write, your account identifier (you must be signed in to send feedback), and the time it was sent; feedback from the mobile app also records the name of the screen it was sent from. We use it to find and fix problems, decide what to improve before full launch, and reply to you. Section 15c has the details.
- The beta checklist and banner choices stay on your device. The checklist in the open beta guide saves your ticks only on your device (in your browser's local storage on the website, or in the app's own storage in the mobile app), and if you dismiss the open-beta banner on the website, that choice is remembered there for a week. Neither is sent to NexudeIT. If you are signed in, the guide also checks your own account (whether you own a store or have a saved search) to tick those steps for you; that reads information we already hold and stores nothing new.
- Cart-reminder emails are held. Because checkout is paused, we do not send cart-reminder emails during the open beta. The on-site reminder may still point you to your cart, and your email preferences (Section 7a) are unchanged.
- Usage data. We use the ordinary usage data described in Section 2 (for example, which pages and features are used) to understand how the open beta is working and what to fix before full launch. The open beta does not add any separate analytics or tracking tool.
- Launch announcement. Opening the open beta sends no emails. At full launch we will announce on the Platform that purchases are open and send the one launch email to everyone on the launch waitlist (see Launch Waitlist above).
- Everything else is unchanged. The retention periods in Section 12, your rights and choices in Section 13, and the rest of this Policy apply during the open beta exactly as they will after full launch.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Platform and its features
- Process transactions, payments, and fulfillment between buyers and sellers
- Verify your identity and prevent fraud or unauthorized access
- Send transactional communications (order confirmations, shipping updates)
- Remind you about items left in your cart — on-site/in-app banners for all users, plus re-engagement emails for signed-in users who have opted in. These reminders highlight items whose availability may be about to change (timed deals, low stock, one-of-a-kind listings) and may include clearly labelled sponsored suggestions from NexudeIT advertisers. You can disable both the banner and the email at any time in Account → Settings → Email preferences
- Personalize your experience, including product recommendations, recently-viewed products, and search results
- Notify you with in-app alerts when new listings match a search you have saved
- Respond to support requests and feedback
- Comply with legal obligations and enforce our Terms of Service
4. Cookies and Tracking Technologies
We use cookies and similar technologies to maintain your session, remember your preferences (language, currency, theme), and analyze usage patterns. Essential cookies are required for the Platform to function. You may manage cookie preferences through our cookie consent banner or your browser settings.
Essential Cookies: Session authentication (
nexude_session), shopping cart persistence, locale preferences, theme settings.Functional Cookies:
nx_cart_session— a random identifier set for guests so that, if you return to the site without logging in, we can recognise the same browser and show you the items you left in your cart. It contains no personal information. It lasts 90 days, and clearing it or disabling cart reminders in settings stops the reminder flow.Analytics Cookies: Anonymous usage statistics to help us improve the Platform. These are only used with your consent.
5. Messaging and Communication Data
When you use the Platform's messaging features to communicate with sellers, buyers, or NexudeIT support, the content and metadata of those messages (timestamps, participants, read status) are stored to facilitate communication, provide customer support, and resolve disputes.
Messages may be reviewed by NexudeIT in cases involving reported abuse, fraud, policy violations, or dispute mediation. We do not sell or share private message content with third parties except as required by law or to protect the safety of our users.
Encryption.On the website, chat messages are end-to-end encrypted when both participants use the website's chat, and we store those messages only as ciphertext we cannot read. When you send a message on the website, its text also reaches our servers over an encrypted connection so that our automated safety screening (Section 11) can check it; we do not store that text unless the screening flags the message, in which case a copy may be kept for safety review as Section 11 describes. The mobile app does not support end-to-end encryption yet: messages sent from the app are encrypted in transit and stored encrypted at rest with keys we control. For those messages, and any others that are not end-to-end encrypted, we can access the content where this Policy allows — for example, to investigate a report or mediate a dispute (see Terms Section 24).
6. Gifting and Recipient Data
When you send an item as a gift, we collect the greeting message you provide. This message is included with the delivery to the recipient. We do not use gift messages for marketing purposes or share them with parties other than the delivery provider and the recipient.
If you are the recipient of a gift, the sender's identity and your delivery address may be shared with the seller for fulfillment purposes. Your personal data as a recipient is treated with the same protections as all user data under this policy.
7. Coupons, Promotions, and Preferences
We collect data about your use of coupons, promotional codes, and discount offers, including which codes you apply, redemption history, and promotional eligibility. This data is used to prevent fraud, enforce coupon terms (validity dates, limits on the total number of uses, minimum order amounts, and which seller's items a code covers), and improve promotional offerings. A redemption is recorded against the order it discounted, together with your account identifier and the amount taken off, and it is deleted if that order is cancelled, replaced, or released before it is paid (Terms Section 8e). Coupon usage data is not shared with third parties except the issuing seller, who may see redemption counts for their own coupons.
7a. Cart Reminders and Sponsored Content
What we store. If you add items to your cart on the website and do not complete checkout, we keep a snapshot of those items (identifiers, quantities, prices, thumbnail URLs), the time of last activity, and a record of when we last reminded you. For signed-in users this is linked to your account. For guests it is linked only to the
nx_cart_session cookie.How we remind you. When you return to NexudeIT (web or mobile app) with a recently abandoned cart we may show you a dismissable banner on the home screen. If you are signed in and have opted in, we may also email you after several hours of inactivity, not more than once every 24 hours per cart. Reminders highlight scarcity signals such as deals ending soon, low stock, and one-of-a-kind items so you can act before availability changes.
Sponsored suggestions.Cart reminders may include clearly labelled sponsored content from NexudeIT advertisers. Advertisers do not receive your identity, email address, cart contents, or any other personal information — they pay for a placement slot and NexudeIT serves the ad on their behalf. Sponsored suggestions are only shown to users who have not opted out of promotional content. Opting out of promotional offers reduces the sponsored portion of the reminder but does not affect your ability to receive the cart reminder itself.
Your controls.In Account → Settings → Email preferences you can (a) turn off on-site/in-app cart reminders, (b) separately turn off cart reminder emails, and (c) toggle general promotional offers on or off. Disabling cart reminders also disables the reminder email. Clearing your cookies (or signing out and clearing cookies as a guest) removes the association between our snapshot and your browser.
Retention. Abandoned cart snapshots are retained only as long as needed to deliver the reminder flow. A snapshot is cleared when you complete checkout, when you manually empty your cart, or after extended inactivity. You can also request deletion at any time by contacting support.
8. Returns and Refund Data
When you initiate a return, we collect return request details (reason, item condition, timestamps) and communicate these to the relevant seller. Return and refund history is retained in your account for reference and may be used to detect patterns of abuse. This data is accessible only to you, the seller, and NexudeIT support staff.
9. Third-Party Services
We share information with third-party service providers only as necessary to operate the Platform. Each provider operates under its own privacy policy:
- Stripe — Payment processing, including the optional Stripe Connect onboarding for sellers receiving payouts, and secure storage of saved payment cards. Stripe collects and processes card and bank data directly; NexudeIT does not store full card numbers. For cards you choose to save, NexudeIT retains only a Stripe payment-method reference and card brand/last-4/expiry; the full card details remain with Stripe. (Stripe Privacy Policy)
- PayPal — Payment method when NexudeIT offers it at checkout and you choose it; PayPal collects your payment details on its own pages, and we send it the order's items, amounts, and order references (not your shipping address). Sellers may connect a PayPal account to receive their share. (PayPal Privacy Policy)
- Square — Payment method NexudeIT may offer at checkout (it may not be available at launch); if you pay with Square, Square collects your payment details on its own page, and we share the order numbers and amount needed to create the payment link. Sellers may connect a Square account to receive their share. (Square Privacy Policy)
- AWS S3 / CloudFront — Optional cloud storage and CDN for user-uploaded media (images and videos). Media is encrypted in transit and at rest.
- flagcdn.com — Country flag images for the locale picker. Only your IP address is sent (a normal HTTP request).
- QR generation API — Server-side QR code generation for product, store, and authenticity tags. Only the encoded URL is transmitted; no personal data is sent.
- SMTP / Email Provider — Used to send verification, password reset, order confirmation, 2FA codes, cart reminder emails (opt-in, see Section 7a), and re-engagement campaigns.
- Cloud Hosting Provider — Servers securely store your data with industry-standard encryption.
- VPN / Geolocation Detection Provider — Detect VPNs and approximate location for fraud prevention and registration analytics. Only IP-derived signals are processed; no precise GPS data is collected.
We do not sell or rent your personal information to third parties. The transfers above are limited to what is strictly necessary to deliver the service you requested.
10. Data Security and Encryption
We implement comprehensive technical and organizational measures to protect your data, including:
- At-Rest Encryption: Sensitive personal data — saved and order shipping addresses, phone numbers, messages sent from the mobile app, the contacts you add, and linked carrier credentials — is encrypted using AES-256-GCM before storage. Your account email address is not encrypted, because we use it to sign you in and to contact you; like the rest of our database, it is protected by access controls and encrypted in transit. Encryption keys are managed separately from data stores
- Password Security: Passwords are stored as cryptographic hashes using PBKDF2 with unique salts — we never store plaintext passwords
- Transport Security: All data transmitted between your device and our servers is encrypted using HTTPS/TLS
- Session Security: Session-based authentication with httpOnly cookies, Content Security Policy headers, and automatic session expiration
- Two-Factor Sign-In (optional): If you turn it on (on the website, under Account → Account Manager → Security & privacy), every sign-in on the website or in the mobile app also needs a six-digit code that we email to you. We store each code with its expiry time so we can check it; a code expires after 10 minutes, and requesting a new one cancels the old one
- Regular Audits: We conduct regular security audits and update our practices in response to emerging threats
In the event of a security incident, encrypted data remains unreadable without the corresponding decryption keys. We will notify affected users in accordance with applicable data breach notification laws.
11. Automated Safety Monitoring
To protect the safety of our users and the community, NexudeIT employs automated systems that periodically scan user-generated content — including messages, comments, reviews, and live chat — for patterns that may indicate:
- Threats of violence or planned harm
- Self-harm or suicidal ideation
- Child exploitation or grooming
- Fraud, scams, or identity theft
- Illegal trade (drugs, weapons, counterfeit goods)
- Emergency distress situations (kidnapping, domestic violence, active threats)
- Severe targeted harassment, stalking, or doxxing
How This Data Is Used: Flagged content is encrypted and stored securely for review by NexudeIT administrators. It is not used for advertising, profiling, or any purpose other than user safety and legal compliance. Content that is determined to be safe after review is resolved in the system and the flagged status removed.
Law Enforcement: NexudeIT may report credible threats, criminal activity, or child exploitation material to relevant law enforcement authorities as required by law or deemed necessary for the immediate safety of users.
Your Rights: You may contact us to inquire about safety flags on your account. False positives are reviewed and resolved promptly.
11a. Automated Decision-Making
NexudeIT uses automated systems in several places. We are transparent about each use and provide a path to human review where decisions could meaningfully affect you:
- Auto-fill from image — When you upload an image to the sell form and tap "Auto-fill," the image (as uploaded, including any photo metadata described in Section 2) is sent to a third-party image-analysis provider that returns a suggested title, description, category, tags, and price range. These suggestions are never auto-published; you must review and confirm before submitting
- Automated content moderation — Reviews, messages, comments, and listings are scanned for prohibited content (Section 11). High-confidence violations may be temporarily hidden pending human review
- Threat detection — Pattern matching on messages and chat for threats of violence, exploitation, fraud, and self-harm. Critical matches escalate to human moderators
- Search ranking and recommendations — Product search results and "Suggested for you" sections use behavioural signals (your views, searches, purchases) to rank content. Rankings are not based on protected characteristics
- Carbon / sustainability score — Listing carbon estimates use category baselines and condition multipliers. Estimates are informational only and not audited
- Loyalty tier calculation — Buyer loyalty tier is calculated automatically from lifetime spend
- VPN / fraud detection — Risk signals on registration and login may trigger CAPTCHA, additional verification, or account holds
- Community Jury (optional) — Disputes can be routed to a randomized jury of opted-in users who vote on the outcome. Jury decisions are advisory; NexudeIT administrators retain final decision authority
No solely automated decisions with legal effects: NexudeIT does not make decisions that produce legal or similarly significant effects on you (account suspension, ban, payment refusal) without human review, except where strictly necessary to prevent imminent harm or fraud.
Human review: If you believe an automated system has made an incorrect decision affecting you, contact us at support and request human review. We will respond within 14 days.
12. Data Retention
We retain different categories of personal data for different periods, based on the purpose for which we collected them and applicable legal obligations:
- Account profile data — retained while your account is active. On account deletion, profile fields are erased within 30 days. A minimal record (user ID + deletion timestamp) is kept for fraud prevention
- Transaction records (orders, payments, invoices) — retained for 7 years after the transaction date to comply with tax, accounting, and consumer protection laws
- Messages and chat threads — retained for 2 years after the last message. Encrypted at rest. You may request earlier deletion of message history via the Contact page
- Authentication logs (login events, IP, user agent) — retained for 365 days for security investigations
- Pageview / analytics events — retained for 180 days in raw form, then aggregated indefinitely with no personal identifiers
- Flagged content for safety review — retained for 2 years in encrypted storage
- Banned IPs / Level-3 banned accounts — retained indefinitely to enforce platform bans
- Cookies — see Section 4 for individual cookie expirations
When the retention period expires, data is securely deleted or anonymised. You may request earlier deletion at any time via the Contact page (subject to legal hold exceptions).
Deceased account holders. Special retention, export, and deletion rules apply to the accounts of users who have passed away. Legacy Contacts, executors, or family members can initiate a Memorialise, Transfer, Data-Only Export, or Delete request through /support/legacy-request. Each path has its own notice window, document requirements, and fraud-prevention checks. End-to-end encrypted message content cannot be recovered after death by design — only metadata is retained, and only for 30 days. The full legal framework is in Terms §§ 18–23, and step-by-step guidance for both pre-planning and bereavement is provided in the Safety Centre guides: legacy-setup, legacy-bereaved, legacy-e2e-messages, legacy-counterparty, legacy-reversal, legacy-fraud-prevention, legacy-ledger, and legacy-estate-planning.
12a. Legal Bases for Processing (GDPR Article 6)
For users in the European Economic Area, United Kingdom, and Switzerland, NexudeIT relies on the following lawful bases under Article 6 of the GDPR:
- Contract (Art 6(1)(b)) — to provide the marketplace services you requested: account creation, order processing, payment, shipping, dispute resolution
- Legitimate interests (Art 6(1)(f)) — to prevent fraud, secure the Platform, detect VPN/proxy abuse, conduct safety monitoring of public content, defend against legal claims, and improve the service. We balance our interests against your fundamental rights and you may object at any time
- Consent (Art 6(1)(a)) — for non-essential cookies, marketing emails, optional features (newsletter subscription, auto-fill from image), and any processing where consent is the most appropriate basis. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal
- Legal obligation (Art 6(1)(c)) — to comply with tax, accounting, anti-money-laundering, consumer protection, and law enforcement requests
- Vital interests (Art 6(1)(d)) — in rare safety incidents involving threats of harm to a person, we may process and disclose information necessary to protect that person
We do not process special categories of personal data (health, religion, political opinions, biometric, etc.) except where you voluntarily disclose them in user-generated content, in which case Article 9(2)(e) applies (data manifestly made public by you).
13. Your Rights
Depending on your jurisdiction, you have the following rights:
For all users:
- Access — Request a copy of the personal data we hold about you
- Rectification — Request correction of inaccurate or incomplete data
- Erasure ("right to be forgotten") — Request deletion of your data, subject to retention periods required by law
- Portability — Export your data in a structured, machine-readable format (JSON)
- Restriction — Ask us to limit how we process your data
- Objection — Object to processing based on legitimate interests, including profiling and direct marketing
- Withdraw consent — For any processing based on consent, withdraw at any time
- Lodge a complaint — File a complaint with your local data protection authority. EU users can find their authority at edpb.europa.eu
- Not be subject to automated decisions — Where decisions about you are made solely by automated means with significant effects, you may request human review (see Section 11a)
For California residents (CCPA / CPRA):
- Right to know — Categories of personal information collected, sources, purposes, and third parties to whom it is disclosed. See Sections 2 and 9
- Right to delete — Subject to exceptions (e.g. completing a transaction, complying with legal obligations)
- Right to correct — Update inaccurate personal information
- Right to opt out of sale or sharing — NexudeIT does not sell personal information and does not share personal information for cross-context behavioural advertising. No opt-out is required because we do not engage in those activities. If this changes in the future, we will provide a "Do Not Sell or Share My Personal Information" link prominently on the Platform
- Right to limit sensitive personal information — We do not use sensitive PI (e.g. precise geolocation, government IDs, biometrics) for purposes beyond the necessary operation of the Platform
- Right to non-discrimination — NexudeIT will not deny service, charge different prices, or provide a lower quality of service in retaliation for exercising any privacy right
- Authorised agent — You may designate an authorised agent to make a request on your behalf with proof of authorisation
How to submit a request: Use our Contact page, email [email protected], or use the in-app data export tool at Account > Settings > Export My Data. We respond within 30 days (extendable to 60 days for complex requests).
Identity verification: To protect your data, we will verify your identity before fulfilling rights requests. We may ask for your account credentials and a second form of verification.
14. Children's Privacy
NexudeIT is intended for users aged 16 and over. The minimum age (16) is enforced at registration and aligns with the GDPR's default age of digital consent. In jurisdictions with a higher minimum age (e.g. some U.S. states require 13 under COPPA, but NexudeIT applies the stricter 16+ rule globally), the higher age applies.
We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16 without verified parental consent, we will delete the information and the associated account promptly.
Parents and guardians who believe their child has created an account on NexudeIT or provided personal data should contact us at support or [email protected]. We will verify the request and act within 14 days.
15. International Data Transfers
Your data may be stored and processed in countries other than your own, including the United States. When personal data is transferred outside the European Economic Area, United Kingdom, or Switzerland, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) — We rely on the European Commission's Standard Contractual Clauses (Module Two: Controller to Processor) for transfers to processors in third countries
- Adequacy decisions — Where the European Commission has determined a country provides an adequate level of protection, we rely on those decisions
- Supplementary measures — Encryption in transit and at rest, access controls, and minimisation of personal data sent to third countries
You may request a copy of the safeguards in place for transfers affecting your data via the Contact page.
15a. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, NexudeIT will:
- Notify the relevant supervisory authority (e.g. Data Protection Commission, ICO) within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33
- Notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34)
- Provide details of the nature of the breach, the categories and approximate number of users affected, the likely consequences, and the measures taken or proposed
- Document all breaches internally regardless of notification obligations
15b. Data Protection Officer and EU Representative
For all data protection enquiries, including requests to exercise your rights under the GDPR and complaints about how we handle your data, you may contact:
- Data Protection Officer (DPO): [email protected]
- EU Representative (if applicable when serving EU users): To be appointed once NexudeIT establishes regular and substantial monitoring of EU data subjects in accordance with GDPR Article 27. Until then, EU users may direct enquiries to [email protected]
- Supervisory Authority: You have the right to lodge a complaint with the data protection authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement
15c. In-App Feedback Widget
NexudeIT offers in-app feedback forms: the Feedback and Report Bug options on the floating chat button shown on most screens while you are signed in, the form in the open beta guide, and Send feedback on the Account tab of the mobile app. When you submit feedback we collect: the subject and text of your message; a screenshot, where the form offers one and you choose to attach it; your account identifier (feedback can only be sent while signed in) so we can reply; the time it was sent; and, for feedback from the mobile app, the name of the screen it was sent from.
We do not silently capture passwords, payment details, or messages from your inbox. Feedback is used to triage bugs, prioritise features, reply to you, and produce anonymised aggregate trends; it is not shared with sellers, advertisers, or third parties unrelated to fixing the issue you raised. Retention is for the lifetime of the underlying issue plus a reasonable archival window. Email [email protected]to request deletion of your individual feedback. The legal framework for the widget is in Terms § 37h.
15d. Beta and Closed-Test Programs
NexudeIT runs invitation-only beta programs (closed Android tests, early-access feature flags, Founder cohorts). Participation is optional and may include data handling that differs from general availability. (The platform-wide open beta is different: it is described in Section 2a, and the points below do not apply to it.) For invitation-only programs:
- Beta features may produce additional diagnostic logs (performance traces, crash dumps, anonymised event streams) used solely to evaluate the feature
- Cohort recruitment is sometimes outsourced to a vendor (for example, TestersCommunity). Vendors operate under their own privacy and terms during the program
- Test-only content (listings, messages, transactions) created inside a beta program may be reset, archived, or migrated when the program ends, with reasonable notice if user-created content is affected
- You may exit a beta program at any time via Account → Settings or by emailing [email protected]. Exiting may delete program-specific state that does not transfer to general availability
The legal framework for beta programs is in Terms § 37g.
15e. Privacy Assurance Summary
A glanceable list of the protections in place by default for every NexudeIT user, regardless of plan:
- Encrypted buyer–seller messaging — end-to-end (ECDH key exchange + AES-256-GCM) on the website when both people use the website's chat, so NexudeIT stores those messages only in a form its staff cannot read (they are still screened automatically for safety as they are sent); messages sent from the mobile app are encrypted in transit and at rest, but not yet end-to-end (Section 5)
- PBKDF2-SHA256 password hashing — 200,000 iterations and unique salts; no plaintext passwords ever stored
- Contact details encrypted at rest — AES-256-GCM on phone numbers, shipping addresses, and the contacts you add (your account email is kept unencrypted so you can sign in with it)
- HTTPS/TLS everywhere — API, mobile app, and CDN
- Two-factor sign-in available — an emailed one-time code at every sign-in, on the website and in the mobile app (Section 10)
- No sale of personal data — no cross-context behavioural advertising
This summary is non-binding shorthand for the full commitments described elsewhere in this Policy. If anything below the surface conflicts with this summary, the specific section governs.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through a notice on the Platform. Your continued use of the Platform after changes constitutes acceptance of the updated policy.
17. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please reach out through our Contact page (no account needed) or email [email protected].
