1. About This Policy
This Privacy Policy applies to all users of xyjzxy.store (“we”, “us”, “our”)—a website currently in development (with a “work in progress” notice) that will eventually offer products or services (details to be updated post-launch). It governs the collection, use, storage, protection, and disclosure of your personal data when you interact with our site, including browsing the pre-launch page, creating an account (once available), subscribing to updates, or contacting support.
We comply with global data protection laws, including the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and regional equivalents (e.g., Virginia Consumer Data Protection Act), to ensure transparent and ethical data handling. “Personal data” refers to any information that identifies or could reasonably identify you, such as your full name, email address, phone number, postal address, device information (IP address, browser type/version), browsing activity (e.g., time spent on the pre-launch page), and preferences (e.g., communication opt-ins for launch updates).
This Policy does not cover third-party websites or services linked from our site (e.g., LinkedIn, Instagram, Facebook)—we encourage you to review their privacy policies independently before engaging with them.
2. Data Controller & Contact Information
The data controller responsible for managing your personal data is the operator of xyjzxy.store. For privacy-related inquiries, requests (e.g., accessing your data, updating preferences, withdrawing consent), or complaints, contact our Privacy Team:
- Email: support@xyjzxy.store (Subject Line: “Privacy Inquiry”)
- Response Commitment: We acknowledge all requests within 1 business day and aim to resolve them within 30 days. For complex requests (e.g., exporting your data record), we may extend this timeline by up to 2 months, but will notify you of delays in writing and provide biweekly updates.
3. What Personal Data We Collect
We collect personal data only for specific, legitimate purposes and do not gather more information than necessary. Currently, during the pre-launch phase, data collection is limited to interactions with the “work in progress” page and future post-launch activities (details below):
3.1 Data Collected During Pre-Launch Browsing (No Account Required)
While the site is under development, visiting the pre-launch page automatically collects technical data to maintain basic functionality and prepare for launch:
- IP Address: To identify your general geographic region (e.g., country/state) for two key purposes:
- Pre-launch planning: Understanding user traffic origins to optimize future shipping logistics, language settings, or regional promotions.
- Fraud prevention: Blocking unauthorized access or suspicious activity from high-risk IP ranges (e.g., IPs linked to cyberattacks).
- Visit Metrics: Date and time of your visit, duration on the pre-launch page, and whether you clicked on linked social media icons (LinkedIn, Instagram, Facebook). This helps us measure pre-launch interest and refine the site’s post-launch structure.
- Device & Browser Details: Browser type/version (e.g., Chrome 120, Safari 17.3), operating system (e.g., iOS 18, Windows 11), and device model (e.g., iPhone 15, Samsung Galaxy S24). This ensures the post-launch site is compatible with popular devices and resolves potential display issues.
- Referral Source: How you found our pre-launch page (e.g., Google search, social media link, direct entry) to evaluate pre-launch marketing effectiveness and prioritize future promotion channels.
Legal Basis: This collection is based on Article 6(1)(f) GDPR (our legitimate interest in preparing a functional, user-friendly site for launch) and CCPA Section 1798.100 (reasonable business purposes for pre-launch planning).
3.2 Data Collected for Post-Launch Account Registration (Future Functionality)
Once the site launches, creating an account (optional) will allow you to access full features (e.g., product browsing, ordering). At that time, we will collect voluntarily provided data:
- Full Name: To personalize your account (e.g., “Welcome back, [Name]”) and verify your identity for future orders or support inquiries.
- Email Address: To send account confirmations (activating your account post-launch), password reset links, launch notifications (e.g., “xyjzxy.store is now live!”), and order updates (once purchasing is available).
- Encrypted Password: Stored using industry-standard hashing technology (e.g., bcrypt with a high work factor)—we never access or store your raw password, even internally.
- Optional Phone Number: For SMS alerts (e.g., launch reminders, delivery updates post-purchase) if you explicitly opt in during registration. You can disable this via account settings post-launch.
- Communication Preferences: Consent to receive marketing emails (e.g., post-launch sales, new product alerts) or promotional SMS—separate from transactional communications (e.g., receipts) and revocable anytime.
3.3 Data Collected for Post-Launch Purchases (Future Functionality)
After launch, if you place orders for products (details to be announced), we will collect transactional data to fulfill your purchase and comply with legal obligations:
- Delivery Address: Full address (including apartment numbers, postal codes) and special instructions (e.g., “Leave at front door”) to ensure accurate shipping.
- Billing Address: To verify your payment method (e.g., matching the address on your credit card statement) and meet anti-money laundering requirements.
- Payment Identifiers: Last 4 digits of a credit card, PayPal ID, or Apple Pay/Google Pay token. We never store full credit card details—all payments will be processed by PCI DSS (Payment Card Industry Data Security Standard)-compliant providers (e.g., Stripe, PayPal) who encrypt financial data.
- Order Details: Product name, quantity, price, and customizations (if applicable) to ensure correct delivery and resolve post-purchase issues (e.g., missing items).
Legal Basis: This collection will be based on Article 6(1)(b) GDPR (necessary to fulfill our contractual obligation to deliver purchased products) and CCPA Section 1798.100 (contractual and regulatory compliance).
3.4 Data Collected via Cookies & Tracking Tools
We use cookies (small text files stored on your device) and web pixels to enhance your experience—even during the pre-launch phase. You can manage cookie preferences via the “Cookie Settings” link in the site footer (available post-launch; pre-launch uses minimal cookies):
| Cookie Type | Purpose | Legal Basis |
|---|---|---|
| Strictly Necessary Cookies | Enable core pre-launch/launch functionality (e.g., remembering if you’ve viewed the “work in progress” notice, maintaining session continuity post-launch). Cannot be disabled. | Article 6(1)(f) GDPR (legitimate interest) |
| Functional Cookies | Save preferences post-launch (e.g., saved shipping address, language setting) to avoid re-entering information. | Article 6(1)(f) GDPR (legitimate interest) |
| Performance/Analytics Cookies | Collect anonymous data (e.g., pre-launch page load time, post-launch browsing patterns) to improve site speed and layout. | Consent (if required) or Article 6(1)(f) GDPR |
| Marketing Cookies | Track interactions with pre-launch/launch promotions (e.g., clicking a “notify me on launch” link) to deliver targeted updates (e.g., “Your saved product is now available”). | Explicit consent (GDPR/CCPA) |
Web pixels (invisible images) track pre-launch email opens (e.g., “Did you view our launch teaser email?”) and post-launch purchase conversions—data is anonymized unless you consent to linking it to your account.
4. How We Use Your Personal Data
We use your data exclusively for the purposes it was collected—no unstated use without your explicit consent:
4.1 Pre-Launch Planning & Communication
- Site Development: Use browsing data (IP region, device details) to optimize the post-launch site (e.g., prioritizing mobile compatibility if 70% of pre-launch users visit via phones).
- Launch Updates: Send email/SMS notifications (if opted in) about site launch timelines, early access opportunities, or pre-launch teasers (e.g., “Coming soon: Our first product line!”).
4.2 Post-Launch Order Fulfillment (Future Functionality)
- Process Payments: Share billing details with PCI DSS providers to verify funds, process transactions securely, and prevent fraud (e.g., flagging stolen credit cards).
- Arrange Shipping: Share your name, delivery address, and order number with carriers (e.g., UPS, FedEx) to ensure timely delivery—share your phone number (with consent) for SMS delivery alerts.
- Send Updates: Notify you via email/SMS (if opted in) about order status post-launch: “Order Confirmed,” “Shipped” (with tracking), “Out for Delivery,” or “Refunded.”
4.3 Account Management (Future Functionality)
- Maintain Preferences: Update saved addresses, communication opt-ins, or product favorites post-launch to streamline future interactions.
- Secure Your Account: Use IP/device data to detect unauthorized access (e.g., a login from a new country) and send security alerts (e.g., “We noticed a login from France—was this you?”).
- Personalize Recommendations: Post-launch, use your browsing/purchase history to suggest relevant products (e.g., “You viewed this item—save 15% at launch”).
4.4 Security & Compliance
- Detect Fraud: Use IP address, billing/delivery address matching (post-launch), and order patterns to flag suspicious activity (e.g., multiple pre-launch email sign-ups from the same IP, post-launch orders with mismatched addresses).
- Comply With Laws: Retain pre-launch communication records and post-launch order data for 7 years to meet tax/accounting requirements (e.g., IRS audits) and disclose data if required by law (e.g., court orders).
5. How We Share Your Personal Data
We never sell your personal data to third parties for marketing purposes. We only share data with trusted partners bound by strict privacy obligations:
5.1 Pre-Launch/Post-Launch Technical Partners
- Hosting & Analytics Providers: Share anonymized browsing data (e.g., pre-launch page visits, post-launch product views) with providers like AWS (hosting) and Google Analytics (analytics) to maintain site performance, detect cyber threats (e.g., DDoS attacks), and refine user experience. Anonymized data cannot be linked to individual users (e.g., IP addresses are truncated).
5.2 Post-Launch Payment & Shipping Partners
- Payment Providers: Share billing address and payment identifiers (last 4 digits of a card) with PCI DSS-compliant providers (e.g., Stripe) to process transactions securely—they retain data only for the transaction lifecycle (typically 30 days).
- Shipping Carriers: Share your name, delivery address, and order number (post-launch) with carriers to deliver products—carriers delete your data post-delivery and cannot use it for marketing.
5.3 Marketing Partners (If Opted In)
- Share your email/phone number (with consent) with providers like Mailchimp (email) or Twilio (SMS) to send pre-launch updates and post-launch promotions—partners are contractually required to protect your data and honor opt-outs.
5.4 Legal Authorities
- Disclose data if required by law (e.g., tax audits, fraud investigations)—we share only the minimum data needed and notify you unless prohibited (e.g., sealed court orders).
6. Data Security & Retention
6.1 Security Measures
- Encryption: All data transmitted (e.g., pre-launch email sign-ups, post-launch payments) uses SSL/TLS 1.3 technology to prevent interception.
- Secure Storage: Sensitive data (encrypted passwords, post-launch order records) is stored on servers with physical security (24/7 guards, biometric entry) and digital controls (multi-factor authentication for staff).
- Regular Audits: Pre-launch and post-launch, we conduct quarterly security audits and penetration testing (by third-party firms) to fix vulnerabilities (e.g., weak password policies).
- Breach Response: If a breach exposes your data (e.g., pre-launch email addresses, post-launch order details), we notify you and regulators within 72 hours (per GDPR/CCPA) and provide steps to protect yourself (e.g., password resets).
6.2 Retention Periods
- Pre-Launch Data: Browsing data (IP, visit metrics) is anonymized/deleted within 3 months of your last visit; email sign-up data is retained until launch + 30 days (or longer if you opt in to post-launch updates).
- Account Data: Retained while your account is active post-launch—deleted 30 days after closure (unless legal obligations apply).
- Post-Launch Order Data: Retained for 7 years (tax compliance)—anonymized after 7 years.
- Marketing Data: Retained only while you opt in—deleted within 7 days of unsubscribing.
7. Your Privacy Rights
Under GDPR/CCPA, you have the following rights—email support@xyjzxy.store with proof of identity (e.g., pre-launch email confirmation, government ID with sensitive details redacted) to exercise them:
- Right to Access: Request a copy of your data (e.g., pre-launch sign-up history, post-launch order records) in a machine-readable format (free for first request per 12 months).
- Right to Rectification: Correct inaccurate data (e.g., outdated email address for launch updates).
- Right to Erasure: Request deletion if data is no longer needed (e.g., you no longer want launch updates) or collected unlawfully.
- Right to Restrict Processing: Limit data use if you dispute accuracy (e.g., incorrect delivery address post-launch).
- Right to Data Portability: Receive your data in a format to transfer to another service provider (post-launch).
- Right to Object: Opt out of marketing or object to legitimate interest processing (e.g., pre-launch browsing data use).
- Right to Withdraw Consent: Revoke consent for non-essential processing (e.g., marketing emails) at any time.
- Right to Complain: File a complaint with a data protection authority (e.g., ICO in the UK, California AG’s Office).
8. Changes to This Policy
We will update this Policy post-launch to reflect new features (e.g., product categories, payment methods) or legal changes. Updates will be posted with a new “Last Updated” date—account holders will receive 7 days’ email notice for material changes. Continued use of the site means you accept the changes.
9. Children’s Privacy
We do not collect data from children under 13 (or the age of majority in your region). Parents must ensure minors do not provide data (e.g., pre-launch email sign-ups). If we accidentally collect child data, we delete it within 7 days—contact support@xyjzxy.store
