ZipXO

Privacy Policy

How ZipXO handles Personal Data

Effective Date: 11 January 2027 · Last Updated: 28 August 2026 · Version: 1.0

This Privacy Policy is published by the persons operating the ZipXO Platform pending incorporation under the trade name ZipXO. Until incorporation, they act as the Data Fiduciary for Personal Data processed on the Platform. On 11 January 2027, and upon incorporation, this Policy becomes the notice of Replace[LEGAL ENTITY NAME — insert on incorporation]. Fields marked for insertion are placeholders until incorporation is complete.

6 placeholder insertions still marked for incorporation.

Key rules

Data Fiduciary

Pending incorporation — dummy entity fields marked below

Minimum age

18+

Sale of data

We do not sell Personal Data

KYC visibility

PAN, bank, and UPI are never shown to other Users

Account restore

30 days after delete from Settings

Processors

Razorpay, Supabase, Stream, Cloudinary, OneSignal, Google, Meta, Sentry, Netlify, Railway

  • 1. Introduction & relationship with the Terms
  • 2. Privacy definitions
  • 3. Information we collect
  • 4. Sources
  • 5. Purposes and legal basis
  • 6. Cookies and similar technologies
  • 7. Social login and connected accounts
  • 8. AI and automated processing
  • 9. Sharing and disclosure
  • 10. International transfers
  • 11. Retention and your rights
  • 12. Children, security, marketing, and contact

1. Introduction & relationship with the Terms

This Policy explains how ZipXO collects, uses, shares, retains, and protects Personal Data on the Platform. Commercial rules (fees, Safe Pay, revisions, usage rights, fund disputes) are in the Terms and Conditions, not here.

1.1 Who this Policy applies to

ZipXO ("ZipXO," "we," "our," or "us") is operated by the persons operating the ZipXO Platform pending incorporation. This Policy applies to Personal Data processed in connection with zipxo.in, the ZipXO applications, and related services, whether you are a visitor, Brand, Creator, authorised representative, or someone who writes to us.

It applies however you access the Platform (website, app, or integration). Statutory rights under the Digital Personal Data Protection Act, 2023 and other Applicable Data Protection Laws are not limited by this Policy.

1.2 Relationship with the Terms

This Policy should be read with the Terms and Conditions. Capitalised commercial terms (ZIP, XO, Safe Pay, Brand, Creator, Collaboration) have the meanings in the Terms. If this Policy and the Terms conflict on Personal Data, this Policy prevails for privacy and data protection only. The Terms continue to govern everything else.

1.3 When this Policy binds you

Necessary processing to run your account, Collaborations, Safe Pay, KYC, tax, and security is described here and is not based on mere browsing. Optional processing (marketing, non-essential analytics where consent is required) needs a separate consent you can withdraw. If you do not accept this Policy, do not create an account or submit Personal Data.

1.4 Changes

We may update this Policy for law, security, or Platform changes. Material changes will be notified through the Platform or email where required. The Last Updated date at the top is the current revision. Authenticated use after a material update takes effect is acknowledgment, except where DPDP requires fresh consent for a new optional purpose.

2. Privacy definitions

These terms are used in this Policy. Marketplace definitions live in the Terms and are not repeated.

2.1 Defined terms

  • "Applicable Data Protection Laws" means the Digital Personal Data Protection Act, 2023 and any other binding rules on Personal Data that apply to ZipXO or you.
  • "Consent" means a free, specific, informed, unconditional, and unambiguous indication of agreement to processing of Personal Data, where DPDP requires it.
  • "Cookies" means cookies, pixels, SDKs, local storage, and similar technologies on a browser or device.
  • "Data Fiduciary" means the person who determines the purpose and means of processing Personal Data. Until incorporation, that is the persons operating the ZipXO Platform pending incorporation; thereafter Replace[LEGAL ENTITY NAME — insert on incorporation].
  • "Data Principal" means the individual to whom Personal Data relates.
  • "Personal Data" means any data about an identified or identifiable individual as defined under DPDP.
  • "Processing" means any operation on Personal Data, including collection, storage, use, sharing, transfer, or deletion.
  • "Sensitive Personal Data" is not a separate DPDP category in the same way as older Indian SPDI rules; we still treat KYC, government IDs, and payment identifiers with stricter access controls.

3. Information we collect

Not every category applies to every person. What we collect depends on the features you use and what you choose to provide.

3.1 Categories

CategoryExamples
Account and profileName, email, phone, role (Brand or Creator), photo, company name, handle, bio, categories, pricing you publish
KYC and payoutPAN, GSTIN, bank last-4/IFSC, UPI ID, and related verification documents needed for payouts and Indian law.
Social OAuthIf you connect Google, Instagram, YouTube, or Facebook: account identifiers and analytics those platforms expose under the permissions you grant (followers, audience breakdowns, content metrics)
Campaign and deal recordsZIPs, XOs, briefs, Deliverables, revision history, usage-rights level selected, shipping contact after Safe Pay, Dispute files
PaymentsRazorpay references, amounts, refunds, chargebacks, invoices. We do not store full card numbers; Razorpay processes cards.
CommunicationsIn-app chat (Stream), support emails, and notification history
Device and usageIP address, browser, device, logs, crash reports, session cookie
AI and safety signalsMatching inputs, fraud/risk indicators, moderation flags generated to run the marketplace

4. Sources

4.1 Where data comes from

  • Directly from you (registration, KYC, briefs, chat, support).
  • From official social APIs after you authorise them (Google, Meta, YouTube).
  • From Razorpay (payment status, payout, refund, chargeback signals).
  • Generated by the Platform (logs, audit trails, matching scores, verification status).

You must only submit Personal Data you are allowed to share. Brands and Creators remain responsible for Personal Data they put in briefs, Deliverables, or chat about third parties.

5. Purposes and legal basis

DPDP requires a lawful basis. We do not rely on “you browsed the site” as consent for all processing.

5.1 Purpose × basis

PurposeMain DPDP basis
Account, ZIP/XO workflow, chat, DeliverablesPerformance of the contract (Terms)
Safe Pay, payouts, invoices, GST/TDS records, KYC at payout thresholdsContract and legal obligation
Fraud, security, Dispute evidence, ToS enforcementLegitimate use / legal obligation (security and compliance)
Matching, ranking, showing creator stats to BrandsContract (core marketplace)
Service notifications (payment, deadline, Dispute)Contract
Marketing email or promotional pushConsent (withdraw anytime)
Optional analytics beyond what is needed to run the serviceConsent where required; otherwise legitimate use for security and improvement
Responding to government or court ordersLegal obligation

Withdrawing marketing or social-connect consent does not unwind processing already done, or processing we must keep for tax, AML, Disputes, or security.

6. Cookies and similar technologies

6.1 What we use

  • Essential: session cookie (zipxo_session) and security cookies needed to stay logged in. Disabling these breaks the app.
  • Errors: Sentry may receive technical diagnostics (which can include IP or device data) to fix crashes.
  • Push: OneSignal may store a device push token if you allow notifications.

You can block non-essential cookies in your browser. Marketing is not bundled into the session cookie; it needs its own consent.

7. Social login and connected accounts

7.1 Google, Instagram, YouTube, Facebook

You may sign in with Google. Creators may connect Instagram, YouTube, or Facebook through official OAuth/APIs. We request only the permissions needed to verify the account and show analytics to Brands. We do not take passwords for those platforms.

Disconnecting a social account stops future collection from that platform. Analytics already used for a completed Collaboration may be kept with that deal record. You can also revoke access in Google or Meta account settings. If Meta or Google change or shut an API, related features may stop; that is not extra collection by us.

8. AI and automated processing

8.1 How models use data

We may use automated systems on Personal Data and usage data to match Brands and Creators, rank search, flag fraud or spam, and assist moderation. These are operational tools. They are not legal, tax, or investment advice — the Terms cover that disclaimer.

We do not make solely automated decisions that produce legal or similarly significant effects (for example, a court-like determination of your rights) without human involvement where DPDP or other law requires it. Account enforcement and Safe Pay fund routing are not decided by an unsupervised model acting as a court.

9. Sharing and disclosure

9.1 We do not sell Personal Data

ZipXO does not sell, rent, or trade Personal Data for money. Sharing happens only as described here.

9.2 Processors we actually use

ProcessorWhy
Razorpay / RazorpayXPay-in, Safe Pay holding, refunds, payouts, related KYC
SupabaseDatabase, authentication, storage
Stream ChatIn-app messaging
CloudinaryImage and media delivery
OneSignalPush and in-app notifications
GoogleSign-In and YouTube Data API
MetaInstagram and Facebook OAuth / insights
SentryError and performance diagnostics
Netlify / RailwayHosting the website and API

Each processor is bound by its contract and its own policy. We also disclose data if required by law, a court, or a regulator, or to protect Users and the Platform from crime or serious harm.

9.3 Visible to other Users

The Platform is a marketplace. Creator profiles and connected social statistics are visible to Brands. During a Collaboration, both parties see what they need to finish the deal (names, submissions, shipping details after Safe Pay). PAN, bank, and UPI details are never shown to the other User.

10. International transfers

10.1 Where data may go

Some processors (including Supabase, Stream, Cloudinary, Sentry, Netlify, Railway, Google, and Meta) may process or store Personal Data outside India. We transfer data only as needed to run the Platform and in line with DPDP and any government restriction list then in force. We use contracts, access control, and encryption in transit as reasonable safeguards. Destination laws may differ from India's.

11. Retention and your rights

11.1 How long we keep data

  • Account delete from Settings: the account is hidden immediately. You may restore it by signing in within 30 days.
  • After that window, Personal Data is removed from active systems. Encrypted backups and logs are cleared within 90 days.
  • Transaction, invoice, KYC, and tax records are retained as required by Indian tax, accounting, and AML law (typically several years), in identifiable or anonymised form as the law allows.
  • Dispute files are kept as long as needed to resolve and document the Dispute.
  • If you do not use ZipXO for 3 years, we will send a 48-hour warning (push and in-app). If you still do not sign in, we erase Personal Data from active systems the same way as a completed deletion, subject to legal holds.

11.2 DPDP rights

Subject to DPDP and legal exceptions, you may: access Personal Data we hold; correct it; request erasure (subject to legal retention); withdraw consent for optional processing (marketing, connected social accounts); nominate another person to exercise rights; and raise a grievance.

Send requests to privacy@zipxo.com or the Grievance Officer below. We may need to verify identity. We acknowledge grievances within 24 hours and aim to dispose of them within 15 days.

12. Children, security, marketing, and contact

12.1 Children

ZipXO is not for anyone under 18. We do not knowingly collect Personal Data from minors. If you believe a minor has an account, contact us and we will delete it.

12.2 Security and breaches

We use encryption in transit, access controls, and restricted handling of KYC. No system is perfectly secure. Keep your credentials confidential and tell us if you suspect unauthorised access.

If a Personal Data breach is likely to cause harm, we will investigate, contain it, and notify affected Data Principals and the Data Protection Board where DPDP requires. This Policy does not add a liability cap; that is in the Terms.

12.3 Marketing

Promotional email or push is sent only with consent (or another lawful basis if the law allows). You can opt out in settings or the message itself. We still send service messages (payments, deadlines, security, legal notices).

12.4 Grievance Officer and contact

  • Data Fiduciary: Replace[LEGAL ENTITY NAME — insert on incorporation] (pending incorporation: the persons operating the ZipXO Platform pending incorporation)
  • CIN: Replace[CIN — insert on incorporation]
  • GSTIN: Replace[GSTIN — insert when registered]
  • Correspondence address: Ho no 4673, Sector 11, Jind, Haryana, 126102
  • Grievance Officer: Replace[GRIEVANCE OFFICER NAME / PHONE — insert]
  • Grievance email: grievance@zipxo.com
  • Privacy requests: privacy@zipxo.com
  • Support: Zipxosupport@zipxo.com
  • Website: https://www.zipxo.in

The Grievance Officer name and phone are placeholders until appointment. Use the grievance and privacy emails above in the meantime.

See also Terms and Conditions and Collaboration Agreement.

© 2026 ZipXO. All rights reserved.