Privacy Policy for TrixMart
Effective Date: April 12, 2026
1. Introduction and Scope of Application
This Privacy Policy delineates the data governance protocols, processing activities, and privacy safeguards implemented by TrixMart (hereinafter referred to as "The Organization", "we", "us", or "our"). This document governs the collection, utilization, storage, and cross-border transfer of personal data across the TrixMart application, website, and related digital services (collectively, "The Platform").
TrixMart utilizes a multi-tenant architecture designed to serve distinct educational institutions globally. As we expand across various academic campuses and international jurisdictions, we remain committed to localized data isolation and global privacy standards. Within Nigeria, The Organization operates formally as a Data Controller of Major Importance as defined by the Nigeria Data Protection Act (NDPA) 2023 and the General Application and Implementation Directive (GAID) 2025.
Cross-Border Data Transfers and Hosting
The primary database infrastructure and servers supporting the TrixMart platform are hosted in the West EU region (specifically Ireland). By registering an account and utilizing The Platform, you explicitly consent to the cross-border transfer, processing, and storage of your personal data in this jurisdiction. These transfers are executed in compliance with standard data protection frameworks ensuring a level of security commensurate with the NDPA 2023.
This Policy applies to all registered users, encompassing academic consumers ("Buyers"), marketplace merchants ("Sellers"), and authorized administrative personnel ("Admins").
2. Categories of Personal Data Collected
We collect data through direct user provision, automated generation during platform usage, and via secure integration with authorized third-party service providers.
2.1 Information Directly Provided by the User
- Profile Identity Data: Full legal name, username, and associated academic affiliations (School ID) utilized to verify presence within specific educational communities.
- Contact Information: Valid email addresses and localized phone numbers utilized for account verification, security alerts, and transactional communications.
- Authentication Data: Cryptographic hashes of passwords and security credentials. We do not store plain-text passwords.
- User-Generated Content: Profile avatars, product reviews, supplementary JSON metadata, and peer-to-peer communications. This also includes **Social Metrics** such as follower counts, which are publicly visible to other users within your institution's partition.
- Dispute & Reporting Data: Information collected via the 'Report Product' or 'Process Dispute' features, including narrative reports, evidence of non-conformity, and communications during a mediation process.
2.2 Payment Integration & Tokenization (Paystack)
TrixMart integrates with Paystack for secure transaction processing. While we do not store full credit or debit card numbers, we do manage:
- Authorization Tokens: Secure recurring payment tokens provided by Paystack to facilitate "saved account" functionality.
- Transaction Metadata: Authorization codes and reference IDs necessary for payment reconciliation and refunds.
All payment tokens and authorization metadata are permanently disabled and purged upon the successful deletion of a user account.
2.3 Specialized Information Collected from Marketplace Sellers
To ensure marketplace integrity and comply with national financial regulations, Sellers are subject to enhanced data collection:
- Commercial Identity: Registered shop names, operational email addresses, business phone numbers, external website links, and detailed shop descriptions.
- Verification and Financial Data: Government-issued identification documentation, Bank Verification Numbers (BVN), and National Identity Numbers (NIN) required to facilitate payouts and complete mandatory Know Your Customer (KYC) onboarding.
- Operational Metrics: System-generated data including cumulative completed orders, calculated average ratings, and applied shipping fee structures.
2.4 Automated Data Generation and Telemetry
- System Telemetry: IP addresses, device fingerprints, session durations, and interaction logs.
- Logistics & Delivery Tracking: Data related to order fulfillment, including delivery status, timestamps, and physical receipt confirmations utilized to trigger the release of escrowed funds.
- Algorithmic Risk Scoring: TrixMart dynamically calculates risk assessment scores for Sellers based on account modifications, verification status, and transactional histories.
- Operational Logs: Timestamp data detailing account creation, profile modifications, suspension events, and product visibility states.
Cookies, Local Storage, and Device Tracking
The Platform utilizes local device storage and secure mobile caching mechanisms (rather than traditional web cookies) to maintain active user sessions, store authentication tokens, and optimize app performance. We may also utilize authorized third-party software development kits (SDKs) to collect anonymized crash reports and screen-view analytics to continuously improve the user experience.
3. Lawful Basis and Purpose of Processing
TrixMart processes personal data strictly upon the establishment of a recognized lawful basis:
| Purpose | Data Categories | Lawful Basis |
|---|---|---|
| Account Creation & Platform Access | Profile Identity, Authentication Data | Contractual Necessity |
| Marketplace Transactions | Contact Info, Commercial Identity | Contractual Necessity |
| Financial Settlement & KYC | Verification and Financial Data | Legal Obligation |
| Security & Risk Mitigation | Algorithmic Scoring, Operational Logs | Legitimate Interest |
4. Automated Decision-Making and Algorithmic Profiling
4.1 Seller Risk Scoring and Visibility Cascading
The Platform utilizes an automated risk assessment algorithm to continuously evaluate the operational integrity of registered Sellers. The algorithm processes variables such as the frequency of profile modifications and verification protocols. This automated processing dynamically determines the public visibility status of a Seller's store.
4.2 Rights Regarding Automated Processing
Sellers possess statutory rights concerning these algorithmic operations and hold the right to:
- Obtain an explanation of the underlying logic utilized by the risk-scoring algorithm.
- Formally contest the automated decision.
- Request human intervention and a manual review.
5. Multi-Tenancy, Third-Party Disclosures, and Data Sharing
We do not sell personal data. However, the operational reality of maintaining a secure, global e-commerce environment necessitates controlled data sharing with:
- Academic Institutions: TrixMart partitions data via specific School IDs. We cooperate with university authorities only in cases of severe disciplinary infractions or fraud.
- Transactional Disclosure: To facilitate post-purchase communication and fulfillment, contact information is shared between Buyers and Sellers via transactional documents, such as receipts and invoices generated by The Platform.
- Financial Processors: We integrate with licensed payment service providers for transaction execution and KYC compliance.
- Law Enforcement: We will disclose personal data to regulatory and legal authorities when served with a valid court order.
6. Data Retention Protocols and Financial Archiving
6.1 Right to Erasure (Data Deletion) and Operational Limits: Users can exercise their right to data deletion directly within the TrixMart application by navigating to the 'Account Settings' and selecting 'Delete Account'. Please note: This right to erasure cannot be exercised if a User has active, unfulfilled orders, unresolved disputes, or pending wallet balances. All active marketplace contracts must be concluded before the system will process a deletion request. Upon successfully triggering this action, non-financial profile data is permanently erased or irreversibly anonymized within ninety (90) days.
6.2 Extended Retention: Pursuant to AML legislation, financial records and KYC artifacts are legally mandated to be maintained for ten (10) years.
7. Statutory Rights of the Data Subject
You are granted comprehensive rights including: Information and Access, Rectification, Erasure (Right to be Forgotten), Data Portability, and the Right to Object/Withdraw Consent.
8. Age Requirements and Protection of Minors
TrixMart is a marketplace designed specifically for university students. By registering an account on The Platform, you represent that you are at least eighteen (18) years of age, or that you have obtained the explicit consent and supervision of your parent or legal guardian to use our services. We do not knowingly collect personal data from children under the age of thirteen (13). If we become aware that we have inadvertently collected personal data from a child under 13, we will take immediate steps to delete such information.
9. Data Security and Breach Notification
In the event of a severe security incident, TrixMart will officially notify the relevant data protection authorities within seventy-two (72) hours.
10. Governance, Complaints, and Contact Information
Email: trixmartng@gmail.com
Physical Address: Plot 681, Cadastral Zone C-OO Research & Institution Area, Jabi Airport Bypass, Abuja FCT, 900001, Nigeria
