Privacy Policy
Version 2.0 · Effective July 23, 2026
This Privacy Policy explains how Crexora ("Crexora", "we", "us") collects, uses, discloses, and safeguards personal information globally. It applies to all users of the Crexora website, mobile applications, APIs, and services (the "Platform"). Capitalized terms not defined here have the meaning given in our Terms of Service.
1. Data controller & scope
The Crexora operating entity acts as the "data controller" (GDPR / UK-GDPR), "business" (CCPA/CPRA), or equivalent for the personal information described here, unless we act as a "processor" on behalf of a Hirer, in which case that Hirer's own privacy notice applies to their processing.
2. Information we collect
- Account data — email, phone number, display name, handle, avatar, cover image, biography, country, language, and industry.
- Identity & verification data — biometric liveness signals, government-issued ID images, one-time-password codes, and social account handles submitted for social verification. Stored encrypted at rest and access-restricted to authorized reviewers.
- Marketplace activity — posts, campaigns, applications, offers, projects, messages, reviews, saved items, and search history.
- Payment metadata — Payoneer identifiers, USDT (TRC20) wallet addresses, transaction hashes, and handshake receipts. Crexora is non-custodial for user-to-user payments; we do not receive card numbers or bank credentials.
- Device & log data — IP address, browser and OS type, device identifiers, referrer, timezone, and interaction events used for security and analytics.
- Cookies & similar technologies — session cookies, secure authentication cookies, and, with consent where required, analytics cookies.
- Support communications — the content of messages you send to us or to counterparties on the Platform.
3. How we use information (legal bases)
Under GDPR, UK-GDPR, and equivalent frameworks, we rely on the following bases:
- Contract — to create accounts, run campaigns, process applications, deliver Academy courses, and operate the Wallet ledger.
- Legal obligation — identity verification, sanctions and anti-money-laundering screening, tax reporting, and responding to lawful government requests.
- Legitimate interests — securing the Platform, preventing fraud, product analytics, and communicating relevant updates. We balance these against your rights.
- Consent — marketing emails, optional analytics cookies, and processing of sensitive data (such as biometric liveness) where required by law. Consent can be withdrawn at any time.
4. How we share information
- Other users — profile fields, posts, campaigns, and messages are visible to the counterparties you engage with (and, for public posts, to any Platform user).
- Service providers (processors) — hosting (Cloudflare, Supabase), analytics, error monitoring, and email/SMS delivery. All are bound by data-processing agreements.
- Payment counterparties — where you use a third-party rail (Payoneer, Wise, USDT wallets), you interact directly with that provider under their own terms and privacy notices.
- Legal & safety — to comply with law, enforce our Terms, protect rights, life, or property, and respond to valid legal process.
- Corporate transactions — in a merger, acquisition, or asset sale, with continued protection consistent with this Policy.
We do not sell personal information for monetary consideration, and we do not share personal information for cross-context behavioral advertising as defined by California's CPRA.
5. International transfers
Crexora operates globally. Personal information may be transferred to and processed in countries other than your own. Where required, we use appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and equivalent mechanisms, together with technical and organizational measures.
6. Data retention
- Account data — for the life of your account.
- Verification data — up to 24 months after verification, or longer if required by law.
- Transaction and payment metadata — up to 7 years for tax and anti-fraud compliance.
- Marketing consent records — until withdrawn plus 24 months for evidence.
- Backups — up to 90 days after deletion, then purged on rolling cycles.
7. Your rights
Depending on your location, you may have rights to:
- Access, correct, port, or delete your personal information.
- Restrict or object to certain processing.
- Withdraw consent (without affecting the lawfulness of prior processing).
- Opt out of marketing at any time.
- Lodge a complaint with your local data protection authority (e.g., EU DPAs, UK ICO, Canada OPC, California AG).
- California residents (CCPA/CPRA): right to know, delete, correct, limit use of sensitive personal information, and non-discrimination for exercising these rights.
- EU/UK residents (GDPR / UK-GDPR): the rights above plus rights against automated decision-making with legal effect.
- Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), South Africa (POPIA), Japan (APPI), India (DPDPA): we honor equivalent rights where applicable.
Submit requests via privacy@crexora.com or in-app Settings → Privacy. We respond within 30 days (extendable where the law permits).
8. Security
We implement industry-standard technical and organizational measures, including TLS in transit, encryption at rest for sensitive fields, role-based access, mandatory 2FA for privileged accounts, audit logging, and regular vulnerability scans. No system is perfectly secure; you should also protect your credentials and enable 2FA on your account.
9. Children
Crexora is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact privacy@crexora.com and we will delete it.
10. Automated decisions
We may use automated tooling to detect fraud, spam, and abuse, and to rank content. These systems inform, but do not solely determine, decisions with legal effect. You can request human review of any account-affecting decision by contacting support.
11. Cookies
We use strictly necessary cookies to operate the Platform and, with consent where required, optional analytics cookies. You can manage cookies in your browser and in Settings → Privacy.
12. Do Not Track & Global Privacy Control
We honor Global Privacy Control (GPC) signals from browsers that send them, treating GPC as an opt-out of any sharing that would qualify as a "sale" or targeted advertising under applicable law.
13. Changes
We may update this Policy. Material changes will be announced in-app and by email at least 14 days before taking effect.
14. Contact
Privacy inquiries and data-subject requests: privacy@crexora.com. For EU/UK matters, you may also contact our EU/UK representative at the same address until a separate representative is appointed.