Privacy Policy
Last updated 21 April 2026
Nyxo respects your privacy. This policy explains what we collect, why, and how you can control it. It is aligned with the Digital Personal Data Protection Act 2023 (India) and GDPR.
1. What we collect
- Account data — name, email, password hash, country, language, timezone.
- Creator data — your bio, products, services, courses, bank account for payouts, GSTIN / PAN if provided.
- Buyer data — orders you place, courses you're enrolled in, bookings, email preferences.
- Usage data — login times, device + IP for session activity, audit log of privileged actions.
- Payment data — processed by Razorpay and Stripe. We never store card numbers or CVVs.
2. How we use it
- To run the platform — publish sites, process payments, deliver downloads, send transactional email.
- To detect and prevent fraud, abuse, and platform misuse.
- To issue receipts and meet GST + KYC obligations.
- We do not sell your data to third parties.
3. Sharing
We share data only with service providers required to operate the platform:
- Razorpay and Stripe (payment processing)
- Resend (transactional email)
- AWS / Cloudflare R2 (file storage)
- Cloudflare (custom-domain SSL provisioning)
- Anthropic (when you opt in to AI features — prompt contents are sent to generate output)
4. Your rights
You can exercise these rights any time from Settings → Data & Privacy (creators) or My Account → Privacy (buyers):
- Right to access — download a JSON bundle of everything we store about you.
- Right to rectification — correct any inaccurate information.
- Right to erasure — delete your account with a 30-day grace window.
- Right to data portability — all data is exportable in standard JSON.
- Right to object — unsubscribe from marketing emails in one click.
5. Retention
Account data is kept while your account is active. If you delete your account, we purge personal data within 30 days; anonymized order records may be retained for tax + audit compliance (up to 7 years for Indian GST rules).
6. Security
Passwords are hashed with bcrypt. Data in transit is TLS-encrypted. Payment details never touch our servers — they're posted directly to the gateway via tokenization. Admin actions are audit-logged and multi-factor-protected.
7. Contact
Privacy questions or data requests: privacy@nyxo.store. Per DPDPA §11, we'll respond within 30 days.
See also: Terms of Service