1. What we collect
We collect only what we need to run an escrow service and meet our legal obligations.
- Account data: your name, email address, password hash, and optional phone, address and business details.
- Transaction data: the escrows you create or accept, amounts, descriptions, timestamps and status changes.
- Payment data: the deposit proofs you upload and the payout details you enter. We never ask for, or store, full card numbers.
- Verification data: identity, address or business documents you submit for KYC.
- Communications: messages you exchange with a counterparty, dispute evidence and support tickets.
- Technical data: IP address, browser user agent, and login timestamps, used for security and fraud prevention.
2. Why we use it
- To operate escrows — holding funds, releasing them and settling disputes.
- To verify identity where the law or our risk controls require it.
- To detect and prevent fraud, money laundering and account takeover.
- To notify you about transactions you are party to.
- To answer support requests and improve the service.
3. Legal basis
We process account and transaction data to perform the contract between us. We process verification and monitoring data to meet legal obligations. We rely on legitimate interests for fraud prevention and service improvement, and on consent for optional marketing email — which you can withdraw at any time from your notification settings.
4. Who we share it with
We do not sell your personal data. We share it only where necessary:
- With your counterparty on a transaction — they see your display name, rating, verification badge and the messages you send them. They never see your email address, address book, bank details or documents.
- With service providers who host our infrastructure, deliver our email and store uploaded files, under contract and only for those purposes.
- With regulators or law enforcement where we are legally required to respond.
5. How we protect it
- Passwords are hashed with bcrypt and never stored in readable form.
- Two-factor secrets and other sensitive values are encrypted at rest with AES-256-GCM.
- Uploaded documents are served only to the people entitled to see them, through authenticated requests.
- Every privileged administrative action is written to an immutable audit log.
- Access to production data is restricted to staff who need it.
6. How long we keep it
Transaction and ledger records are retained for as long as required by financial record-keeping rules, typically several years after the transaction closes, even if you close your account.
Verification documents are kept for the retention period our compliance obligations require, then deleted.
Closing your account soft-deletes your profile: you can no longer sign in, and your data stops being visible to other users, but records tied to completed transactions are preserved for audit.
7. Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to certain processing.
- You can view and correct most of your data directly in Settings.
- For access, export or deletion requests, write to support@escrowixa.com.
- We will respond within the period required by applicable law, normally one month.
- Some rights are limited where we must retain records for legal or anti-fraud reasons.
8. Cookies
Escrowixa uses a small number of strictly necessary cookies: a session cookie to keep you signed in, and a CSRF token to protect form submissions. We do not use advertising or cross-site tracking cookies.
9. International transfers
Our infrastructure providers may process data in countries other than your own. Where that happens we rely on recognised safeguards such as standard contractual clauses.
10. Changes and contact
We will announce material changes to this policy in the app or by email.
Questions or complaints can be sent to support@escrowixa.com, or by post to 100 Market Street, Suite 900, San Francisco, CA 94105.