Privacy Policy
Effective July 11, 2026
This policy applies to the Base Sepolia test environment. Vex Market does not offer mainnet commerce.
Who handles your information
Vex Market operates the testnet marketplace described in this policy. Privacy questions and requests are handled manually through [email protected].
Information we collect
- Account and authentication data, including email, username, email-verification status, linked sign-in provider identifiers, passkey public credentials and metadata, recovery-code records, and session records. Vex Market does not receive the biometric or device unlock data used by your device to authorize a passkey.
- Profile and marketplace content, including biography, avatar and banner image identifiers, public contact details you choose to provide, listings, listing images, stock, messages, and feedback.
- Order and payment records, including buyer and seller identifiers, order notes, payout and buyer wallet addresses, network, token, amounts, transaction hashes, refund attempts, status history, and public-chain verification results.
- Trust and safety records, including reports, report snapshots, moderation decisions, notifications, account restrictions, and operator audit events.
- Policy and support records, including the policy-bundle version and time you accepted it and correspondence you send to support. Legal acceptance does not store your IP address or user agent.
- Technical and usage data, including security and application logs, approximate device and location labels derived from request data, page and feature events, job state, error reports, and browser information sent in ordinary HTTP requests.
Where information comes from
We receive information from you, your browser or device, linked authentication and wallet providers, Base Sepolia and related public-chain infrastructure, other marketplace users who interact with you, and operators who review activity. Public blockchains independently publish wallet and transaction data.
How we use information
- Provide accounts, authentication, listings, messages, orders, stock coordination, payment verification, notifications, and support.
- Secure the service, prevent abuse, investigate reports, enforce policies, preserve audit history, and diagnose failures.
- Measure product use, maintain performance, improve features, communicate service information, and meet legal obligations.
Depending on your location and the activity, these uses may rely on performing our agreement with you, our legitimate interests in operating and securing the service, your consent, or compliance with law. We do not sell personal information or use it for third-party behavioural advertising.
Public marketplace and blockchain records
Usernames, profiles, seller contact details you publish, active listings, listing images, seller statistics, and feedback may be public. Messages and order details are restricted to their intended participants and authorized operator review, subject to security and legal needs. Wallet addresses, transaction hashes, token transfers, and smart-contract events written to Base Sepolia are public and may be copied by anyone. Vex Market cannot edit or erase records controlled by a public blockchain.
Service providers
We disclose only the information reasonably needed for providers to perform their services. Current infrastructure can include OVH for hosting, Cloudflare for edge security, Turnstile, email routing, image delivery, and object storage, Google and Discord for optional OAuth sign-in, Coinbase CDP for embedded-wallet infrastructure, Alchemy for blockchain verification, and Sentry for application error monitoring. These providers process data under their own terms and may operate in other countries. We may also disclose information when required by law, to protect users or the service, or as part of a future service reorganization that is communicated as required.
Cookies and browser storage
Vex Market uses a session cookie to keep you signed in. Theme preference may be stored in local storage, and short-lived interface state may be stored in session storage. Cloudflare Turnstile and other providers may use their own necessary browser storage. Vex Market does not use advertising cookies.
Retention and deletion
Retention depends on the record and why it is needed. Inactive login sessions expire after about 30 days. Operational logs, metrics, error data, and routine backups are generally kept for about 30 days. Unattached listing images are scheduled for cleanup after about 24 hours, and images on listings archived for more than about 30 days are scheduled for cleanup. Account, listing, message, order, payment, report, moderation, notification, acceptance, support, and audit records may be kept longer where needed for marketplace integrity, safety, fraud prevention, dispute context, or legal obligations.
Accounts with order history cannot currently be self-deleted because their marketplace records must remain coherent. Deleting an eligible account removes its relational account data and places associated Cloudflare images into retryable cleanup. Provider backups and logs may retain limited copies until their normal expiry, and public-chain records cannot be deleted by Vex Market.
Your choices and requests
You can edit supported profile and contact fields in account settings, remove optional public contact details, revoke sessions, unlink supported sign-in providers when another sign-in method remains, and delete an eligible account. Depending on where you live, you may also have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or review by a privacy authority. Send a request to [email protected]. We may need to verify your account and may retain or refuse changes where law, security, other users' rights, or record-integrity needs permit. Automated data export is not currently offered.
International handling
Vex Market and its providers may process information in Canada, the United States, Europe, and other locations where infrastructure or providers operate. Privacy protections and government-access rules can differ from those in your location. Use of this testnet service does not represent that every regional requirement has been resolved.
Security
Vex Market uses access controls, encrypted connections, scoped credentials, session protections, audit records, and other technical and organizational safeguards. No service, wallet, network, or storage system is completely secure. Protect your own email, devices, passkeys, recovery codes, and wallets, and report suspected compromise promptly.
Age and contractual capacity
Vex Market is not directed to children. Account and commerce features require you to have reached the age of majority where you live and to be able to enter the agreement. Contact us if you believe a person who lacks that capacity provided personal information.
Policy changes
We may update this policy as the service and legal requirements change. The effective date and bundle version identify the current text. A material change requires renewed acknowledgement before protected account or commerce features can be used.