Privacy Policy

How OrzShop Handles Member Data

This policy explains what data OrzShop collects, why it is used, and how account, payment, wallet, and marketplace records are protected.

Last updated: July 20, 2026

Data We Collect

  • Account data such as display name, email address, password hash, role, seller permissions, and verification status.
  • Marketplace data such as cart items, purchases, reviews, product uploads, payout methods, wallet ledger entries, refund requests, and mailbox notifications.
  • Payment references such as Stripe checkout session IDs, payment intent IDs, charge IDs, refund IDs, payment status, currency, and net/fee amounts.
  • Operational security data such as CSRF tokens, rate-limit counters, admin activity logs, and hashed IP references.

How We Use Data

  • To create accounts, verify email ownership, keep carts and purchases tied to a member ID, and unlock downloads after payment.
  • To operate creator wallets, payout requests, affiliate credits, refunds, product moderation, and marketplace support workflows.
  • To reconcile Stripe payment records with internal wallet ledgers and to prevent duplicate purchases, fraud, abuse, or unauthorized access.
  • To send in-site MailBox notices and optional email notifications for payments, product status, refund, payout, and security events.

Payment Data

OrzShop does not store full card numbers or bank credentials. Stripe processes card, Link, and PromptPay payments. OrzShop stores only the references needed to verify payment, refund, dispute, and wallet allocation status.

Retention And Access

Purchase, wallet, refund, payout, and admin activity records are retained for audit, tax, fraud prevention, and customer support. Private product assets are stored outside the public web root whenever possible. Admin access is limited by role and logged for review.

Contact

For privacy questions or data requests, contact the marketplace administrator through the support email configured in Payment Settings.