ORDER PROTECTION ON ELIGIBLE PURCHASES · SHIPPING SHOWN BEFORE PAYMENT

Privacy Policy

1. Data Controller

ITZCULTURE, Inc. ("Platform," "we," "us," "our") is the data controller for personal information collected through itzculture.com. We are committed to protecting your privacy and handling your data transparently.

Contact: privacy@itzculture.com

2. Information We Collect

Information You Provide Directly:

  • Account Data: Name, email address, phone number, password (protected with strong one way password hashing and never stored in plaintext)
  • Profile Data: Display name, avatar, bio, social media links
  • Transaction Data: Shipping address, billing address, order history, payment method type (card details are tokenized and processed by Stripe — we never store full card numbers)
  • Communications: Messages you send through the platform, support tickets, feedback
  • Seller Data: Business name, tax identification number (for verified sellers), bank account details (stored exclusively by Stripe Connect)

Information Collected Automatically:

  • Device Data: IP address, browser type and version, operating system, device identifiers, screen resolution
  • Usage Data: Pages viewed, products clicked, search queries, time spent on pages, referring URLs
  • Location Data: Approximate location derived from IP address (we do not use GPS tracking)
  • Cookie Data: Session identifiers, preferences, analytics tokens (see our Cookie Policy)

3. How We Use Your Data

We process your personal information for the following purposes:

  • Process and fulfill orders, including payment processing and shipping coordination
  • Create and manage your account
  • Personalize product recommendations and search results based on browsing history
  • Prevent fraud, detect suspicious activity, and enforce platform policies
  • Send transactional communications (order confirmations, shipping updates, delivery notifications)
  • Send marketing communications (opt-in only; you may unsubscribe at any time)
  • Improve platform performance, features, and user experience
  • Respond to your inquiries and provide customer support
  • Comply with legal obligations, including tax reporting and law enforcement requests
  • Generate anonymized, aggregate analytics about platform usage

Legal Bases for Processing (GDPR): Contract performance (orders, account management), legitimate interest (fraud prevention, platform improvement), consent (marketing), and legal obligation (tax compliance).

4. Data Sharing

We share your data only with the following categories of recipients:

  • Stripe, Inc.: Payment processing (PCI-DSS Level 1 certified). Stripe receives your payment card details directly and provides us only with tokenized references.
  • Amazon Web Services (AWS): Cloud infrastructure, email delivery (SES), image and file storage (S3). Data is encrypted at rest and in transit.
  • Sellers: When you place an order, the seller receives your name, shipping address, and email address solely for order fulfillment purposes.
  • Shipping Carriers: Name and address for delivery when sellers use integrated shipping label generation.
  • Analytics Providers: Anonymized, non-personally-identifiable usage data for platform improvement.
  • Law Enforcement: When required by valid legal process (subpoena, court order, or statutory requirement).

We never sell your personal data to third parties. We do not share data with advertisers or data brokers. We do not participate in ad networks or cross-site tracking.

5. Data Retention

  • Account data: Retained while your account is active, plus 30 days after deletion request to allow recovery
  • Order records: 7 years (required for tax compliance and legal obligations)
  • Behavioral/usage data: 12 months in identifiable form, then permanently anonymized
  • Support tickets: 3 years from resolution
  • Marketing consent records: Retained for the duration of consent plus 3 years
  • Server logs: 90 days, then deleted

6. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

  • Right of Access: Request a complete copy of all personal data we hold about you
  • Right to Correction: Update or correct inaccurate information
  • Right to Deletion: Request permanent deletion of your account and associated data (subject to legal retention requirements)
  • Right to Portability: Receive your data in a structured, machine-readable format (JSON or CSV)
  • Right to Restrict Processing: Limit how we use your data while a dispute is resolved
  • Right to Object: Object to processing based on legitimate interest
  • Right to Opt-Out of Sale: Under CCPA, you may opt out of the "sale" of personal information (note: we do not sell data)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

Signed-in account holders can submit and track privacy rights requests in the Privacy Center. You may also email privacy@itzculture.com if you cannot use the account workflow or are acting as an authorized agent. We verify identity before fulfillment and use the response dates shown in your request record; if additional time is required, the updated date and reason are recorded and communicated.

7. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to know what personal information is collected, used, and shared
  • Right to delete personal information held by us and our service providers
  • Right to opt-out of the sale or sharing of personal information
  • Right to correct inaccurate personal information
  • Right to limit use of sensitive personal information

We do not sell or share personal information as defined under CCPA/CPRA. In the preceding 12 months, we have collected the categories of information described in Section 2 above.

8. International Transfers

Your data is processed and stored in the United States. If you are located outside the US, by using the Platform you consent to the transfer of your data to the United States. We implement appropriate safeguards including encryption and contractual protections with our service providers.

For EU/EEA/UK users: transfers are made pursuant to Standard Contractual Clauses approved by the European Commission.

9. Security

We use administrative, technical, and organizational safeguards designed to protect personal information.

  • HTTPS for data sent between your browser and the Platform
  • Strong one way password hashing
  • Access controls for protected workspaces
  • Rate limiting and monitoring for sensitive actions
  • Payment processing through Stripe-hosted payment fields

No system is completely secure. If a security incident requires notification, we will notify affected people and regulators in accordance with applicable law.

10. Children's Privacy

The Platform is not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a person under 18, we will delete it immediately. If you believe a minor has provided us with personal information, please contact privacy@itzculture.com.

11. Do Not Track

Browsers do not currently provide a uniform Do Not Track standard. Where required, optional analytics and advertising technologies are controlled through the consent choices available on the Platform.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered users at least 30 days before taking effect. The "Last revised" date at the top of this page indicates when the policy was most recently updated. Continued use of the Platform after the effective date constitutes acceptance of the revised policy.

13. Contact Us

For privacy-related inquiries, data requests, or complaints:

ITZCULTURE, Inc.
Email: privacy@itzculture.com
Legal Department: legal@itzculture.com

If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.