This Privacy Policy describes how Winixx Inc. (“Winixx,” “we,” “us,” or “our”) collects, uses, discloses, and protects your personal information when you use our products, services, applications, websites, and digital marketplace (collectively, the “Services”). This Policy applies to all users of Winixx Services, including consumers, families, enterprise customers, marketplace buyers, marketplace sellers, and third-party application publishers.
By using any Winixx Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Services.
Who We Are and How to Contact Us
Winixx Inc. is the data controller for personal information processed through the Services. Winixx is incorporated under the laws of the State of New York, United States.
For privacy-related inquiries, please contact our privacy team at privacy@winixx.com.
For users in the European Economic Area, United Kingdom, or Switzerland, Winixx’s EU/UK representative is: Judith Norwoski.
Information We Collect
We collect information in three ways: information you provide to us directly, information collected automatically, and information received from third parties.
2.1 Information You Provide Directly
| Category | Examples | Required? |
|---|---|---|
| Account & Identity | Name, email, password, date of birth, profile photo, display name, language, timezone | Yes — to create a Winixx ID |
| Contact Information | Email address, phone number, mailing address | Yes — for account and billing |
| Payment & Billing | Card details (tokenized via Stripe), Winixx Pay balance, billing address | Yes — for paid subscriptions |
| Seller & Payout Info | Bank account, routing numbers, SSN/EIN, 1099 tax forms, business registration | Yes — for marketplace sellers |
| KYB/KYC Data | Government-issued ID, business registration, beneficial ownership info (via ClearTrust) | For sellers requiring verification |
| Marketplace Activity | Purchase history, product listings, reviews, ratings, wishlists, download history | Generated through use |
| User Content | Files, images, code, comments, messages, feedback submitted through Services | Optional — based on use |
| Support Communications | Messages, emails, and chat logs when you contact Winixx support | When you contact us |
2.2 Information Collected Automatically
When you use the Services, we automatically collect:
- Device information: device type, operating system, browser type and version, device identifiers, hardware model;
- Log data: IP address, access times, pages viewed, features used, search queries, referral URLs, error logs;
- Location data: general location derived from IP address; precise GPS only with your explicit consent;
- Usage data: features accessed, time spent, click patterns, app launch frequency, session duration;
- Cookies and tracking technologies: session cookies, persistent cookies, pixel tags, local storage (see Section 7);
- Communications metadata: email open rates, notification interaction data for communications you opt into.
2.3 Marketplace-Specific Data
In connection with the Winixx Marketplace, we collect:
- Buyer data: purchase history, browsing history within the marketplace, product ratings and reviews, wishlists, saved items, download history, and personalization preferences;
- Seller data: product listings, sales volume, payout history, tax documentation, bank account information, seller ratings, customer communications, and compliance review data;
- Third-party publisher data: app metadata, privacy policy URLs, data collection declarations, compliance review records.
2.4 Information from Third Parties
- Authentication providers: if you sign in via a third-party OAuth provider, we receive basic profile information (name, email, photo) as authorized by you;
- Payment processors: Stripe provides tokenized payment confirmation and fraud signals;
- Identity verification: ClearTrust provides KYC/KYB verification status and identity confidence scores;
- Third-party app publishers: when a third-party app accesses your Winixx ID, we receive the access request and scope; the publisher’s own data collection is governed by their privacy policy.
How We Use Your Information
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Account creation & management | Identity, contact, authentication data | Contract performance |
| Providing and improving Services | Usage data, device data, account data | Contract / Legitimate interests |
| Marketplace transactions | Purchase data, seller payout data, buyer identity | Contract performance |
| Personalization & recommendations | Purchase history, browsing, ratings, wishlist | Legitimate interests / Consent |
| Billing and payment processing | Payment data, subscription data | Contract performance |
| Seller payouts & tax compliance | Bank details, tax ID, 1099 data | Legal obligation / Contract |
| Seller & app compliance review | KYB data, app metadata, policy declarations | Legal obligation / Legitimate interests |
| Security & fraud prevention | IP address, device data, behavioral signals | Legitimate interests / Legal obligation |
| Customer support | Communications, account data, usage context | Contract / Legitimate interests |
| Legal compliance | Any data necessary for regulatory obligations | Legal obligation |
| Marketing & communications | Email, notification preferences, engagement data | Consent (opt-in) |
| Analytics & product research | Aggregated usage and engagement data | Legitimate interests |
Marketplace-Specific Privacy Practices
4.1 Winixx as Merchant of Record
For all marketplace transactions, Winixx Inc. is the merchant of record. All payments are processed through Winixx Pay. We collect and retain transaction data — including purchase amount, product purchased, buyer and seller identifiers, and payment method details — as necessary for payment processing, fraud prevention, tax reporting, and dispute resolution.
4.2 Buyer Data and Personalization
We use your marketplace activity — including purchase history, browsing behavior, product ratings, reviews, and wishlists — to:
- Provide personalized product recommendations within the marketplace;
- Surface relevant products based on your history;
- Improve search results and category navigation;
- Send you notifications about items on your wishlist (with your consent);
- Detect and prevent fraudulent purchases.
You may adjust your personalization preferences at any time through your Winixx ID account settings. Opting out of personalization does not affect your ability to use the marketplace.
4.3 Seller Data
If you register as a marketplace seller, we collect and process:
- Payout information: bank account details and routing numbers for ACH/direct deposit disbursements through Winixx Pay;
- Tax information: SSN or EIN for IRS Form 1099 reporting where required. Winixx will issue 1099-K or 1099-NEC forms to qualifying sellers in accordance with applicable IRS thresholds;
- KYB verification: business registration documents, beneficial ownership information, and government-issued identification, reviewed by ClearTrust;
- Seller performance data: sales volume, customer ratings, dispute records, and compliance review outcomes.
4.4 Third-Party App Publishers
Developers and publishers who list applications on the Winixx Marketplace are subject to the Winixx Developer Policy, which requires:
- Disclosure of all data collected by their applications from users;
- Submission of a privacy policy URL meeting minimum content standards;
- Compliance review by Winixx before listing approval;
- Ongoing compliance with applicable privacy laws;
- Prompt notification to Winixx of any data breach affecting Winixx users.
Third-party publishers’ data collection practices are governed by their own privacy policies. Winixx is not responsible for third-party publishers’ data practices beyond the compliance review at the time of listing. We recommend reviewing a publisher’s privacy policy before installing or purchasing their application.
4.5 Marketplace Reviews and Public Content
Product reviews, ratings, and comments you submit to the marketplace may be publicly visible to other users. Your display name will be associated with your reviews. You may edit or delete your reviews at any time through your account settings.
How We Share Your Information
Winixx does not sell your personal information. We share your information only in the following circumstances:
5.1 Service Providers
We share information with trusted third-party service providers who perform services on our behalf, including payment processing (Stripe), identity verification (ClearTrust), cloud infrastructure, communications providers, and analytics infrastructure. All service providers are contractually bound to process your data only as instructed by Winixx.
5.2 Marketplace Sellers
When you purchase a product from a marketplace seller, we share with that seller only the information necessary to fulfill the transaction: your display name, the product purchased, and purchase date. We do not share your payment details, email address, or other personal information with sellers without your explicit consent.
5.3 Legal Requirements
We may disclose your information when required to: (a) comply with applicable law or legal process; (b) respond to lawful government requests; (c) protect the rights, property, or safety of Winixx, our users, or the public; or (d) enforce our Terms of Service.
5.4 Business Transfers
If Winixx is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you prior to your information being subject to a materially different privacy policy.
5.5 With Your Consent
We may share your information with third parties when you have explicitly consented to such sharing.
5.6 Aggregated and De-Identified Data
We may share aggregated or de-identified information that cannot reasonably be used to identify you with partners, researchers, or the public for industry analysis and product improvement.
Data Retention
We retain your personal information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements.
| Data Category | Retention Period | Basis |
|---|---|---|
| Account & identity data | Duration of account + 30-day grace period | Service provision |
| Transaction & billing records | 7 years from transaction date | Tax & accounting obligations |
| Seller tax documentation (1099) | 7 years from issuance | IRS legal obligation |
| Seller KYB/KYC records | 5 years from seller offboarding | AML/BSA legal obligations |
| Marketplace purchase history | Duration of account | Legitimate interests (personalization) |
| Security & fraud logs | 2 years | Fraud prevention / Legal |
| Support communications | 3 years from case closure | Legitimate interests |
| Marketing engagement data | Until opt-out or account deletion | Consent |
| Aggregated analytics data | Indefinitely (cannot identify individuals) | Legitimate interests |
| Enterprise audit logs | 2 years (configurable by org admin) | Legal / Contract |
When you delete your Winixx ID account, a thirty (30) day grace period begins during which your account is suspended. After thirty days, your personal data is permanently deleted, except where retention is required by law. You may cancel a pending deletion by signing back in during the grace period.
Cookies and Tracking Technologies
7.1 Types of Cookies We Use
| Cookie Type | Purpose | Can You Opt Out? |
|---|---|---|
| Strictly Necessary | Authentication, session management, security. Required for the Services to function. | No — required for operation |
| Functional | Remembering preferences (language, theme, region). Enhancing your experience. | Yes — via cookie settings |
| Analytics | Understanding how users interact with the Services. Aggregated, not linked to individuals. | Yes — via cookie settings |
| Personalization | Marketplace recommendations, purchase history-based suggestions. | Yes — via privacy settings |
| Communications | Tracking email open rates and notification interactions for opt-in communications only. | Yes — by unsubscribing |
7.2 Managing Your Cookie Preferences
You can manage your cookie preferences at any time through:
- The Winixx cookie preference centre, accessible from the footer of any Winixx website;
- Your browser settings, which allow you to block or delete cookies;
- Your Winixx ID privacy settings for personalization and communications preferences.
Disabling strictly necessary cookies will impair your ability to use the Services. Opting out of analytics and personalization cookies will not affect your access to any feature.
International Data Transfers
Winixx is headquartered in the United States. If you are located outside the United States, your personal information will be transferred to and processed in the United States and other countries where Winixx or its service providers operate.
For transfers of personal data from the European Economic Area, United Kingdom, or Switzerland to countries not providing adequate data protection, Winixx relies on:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- UK International Data Transfer Agreements (IDTAs) where applicable;
- Binding Corporate Rules (BCRs), subject to approval — [to be confirmed by legal counsel].
You may request a copy of the applicable transfer mechanisms by contacting privacy@winixx.com.
Your Privacy Rights
9.1 Rights Available to All Users
Access
Request a copy of the personal information we hold about you.
Correction
Request correction of inaccurate or incomplete personal information.
Deletion
Request deletion of your personal information, subject to legal retention requirements.
Portability
Receive your data in a structured, machine-readable format.
Opt Out of Marketing
Opt out of marketing communications at any time, without affecting your account.
Object to Processing
Object to processing based on legitimate interests in certain circumstances.
9.2 Additional Rights for EEA, UK, and Swiss Residents (GDPR)
- Right to restrict processing in certain circumstances;
- Right to object to processing based on legitimate interests;
- Rights related to automated decision-making and profiling;
- Right to lodge a complaint with your local supervisory authority.
9.3 Additional Rights for California Residents (CCPA/CPRA)
- Right to know what personal information we collect, use, and disclose;
- Right to delete personal information we have collected;
- Right to correct inaccurate personal information;
- Right to opt out of sale or sharing — Winixx does not sell personal information;
- Right to limit use of sensitive personal information to what is necessary to provide the Services;
- Right to non-discrimination — we will not discriminate against you for exercising your privacy rights.
9.4 How to Exercise Your Rights
To exercise any of the above rights:
- Submit a request through your Winixx ID account portal at account.winixx.net;
- Email privacy@winixx.com with the subject line “Privacy Rights Request;”
- For California residents, use the “Do Not Sell My Information” link in the website footer.
We will respond to verifiable requests within thirty (30) days (or forty-five (45) days where permitted by law with notice). We may need to verify your identity before processing your request.
Children’s Privacy
The Services are not directed to children under the age of thirteen (13). Winixx does not knowingly collect personal information from children under 13 without verifiable parental consent. If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact privacy@winixx.com immediately. We will promptly delete such information.
For users between the ages of 13 and 17 accessing the Services through a Family Account, the Family Organizer is responsible for supervising the minor’s use and may apply parental controls through the Winixx ID family management dashboard. We limit data collection from minors to what is necessary for the Services and do not use minor users’ data for marketing purposes.
Data Security
Winixx implements industry-standard technical, organizational, and administrative security measures designed to protect your personal information. Our security measures include:
- Encryption of data in transit using TLS 1.2 or higher;
- Encryption of sensitive data at rest using AES-256;
- Access controls and role-based permissions limiting data access to authorized personnel;
- Multi-factor authentication options for all user accounts;
- Regular security assessments, penetration testing, and vulnerability scanning;
- Incident response procedures for detecting, containing, and reporting data breaches.
No security system is impenetrable. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law.
To report a security vulnerability, please contact security@winixx.com.
Third-Party Applications and Links
The Services may contain links to third-party websites and applications not operated by Winixx. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party service you access through the Services.
Applications available on the Winixx Marketplace developed by third-party publishers are subject to those publishers’ own privacy policies. Winixx reviews all listed applications for compliance with our Developer Policy before approval, but is not responsible for third-party publishers’ ongoing data practices. You should review the privacy policy of any application before installation.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Sending an email to the address associated with your Winixx ID at least thirty (30) days before the effective date;
- Posting a prominent notice in your Winixx ID account portal;
- Updating the “Effective Date” at the top of this Policy.
Your continued use of the Services after the effective date of any change constitutes your acceptance of the updated Policy.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
| Privacy inquiries | privacy@winixx.com |
| Data rights requests | privacy@winixx.com — Subject: “Privacy Rights Request” |
| Security issues | security@winixx.com |
| GDPR / EU representative | Judith Norwoski — jud.norwoski@winixx.net |
| California privacy (CCPA) | Use “Do Not Sell My Information” link in footer, or email privacy@winixx.com |
| Mailing address | Winixx Inc., Attn: Privacy Team, 149 E 23rd St, PO Box 11205, New York, NY 10010 — Elizabeth Holmes |