OCX app is now live on Play Store. Download now for exclusive mobile experience!

OCX Privacy Policy

Effective date: [17 November 2025] · Version: [v1.0]

We take privacy seriously because trust is the product. This Privacy Policy explains how PT OCX PLATFORM INDONESIA and our affiliates ("OCX", "we", "us", "our") collect, use, share, store, protect, and delete personal information when you interact with our website, mobile app, marketplace features (listing, buying, selling, offers), Escrow by default, OCX Vault custody, AI Pre-Grading + expert validation, optional third-party grading submissions, shipping and insurance, community features, events, marketing, and support (the "Service"). It also covers social media, live events, and other activities described below.

1) Who We Are

  • Legal entity (controller): PT OCX PLATFORM INDONESIA and affiliates supporting the Service.
  • Contact: <support@theocx.com>

2) Scope & Audience

  • Covered: website, app, marketplace tools, Escrow, Vault, AI Pre-Grading, expert validation, submissions to grading partners (opt-in), logistics and insurance, payments and payouts, community and UGC, recruiting, and support.
  • Audience: visitors, account holders (buyers, sellers, consignors), community members, job candidates, partners.
  • Third-party sites/services: their policies apply when you use their tools or links.

3) Changes to This Policy

  • We update this page with a new effective date for each revision.
  • Material changes may trigger in-app/email notice where required.
  • Unless stated otherwise, changes are effective upon posting.

4) Personal Information We Collect

  • Identity & KYC (where lawful/required): full name, DOB, nationality, government ID (e.g., KTP/passport), tax ID (NPWP where applicable), selfie/liveness checks, sanctions/PEP screening outcomes.
  • Contact & Account: email, phone, shipping/billing addresses, username/handle, avatar, language/currency/timezone, notification and marketing preferences.
  • Profile & Social: links to social profiles, bios, referral codes, influencer/affiliate IDs.
  • Credentials: hashed passwords if you register by email; tokens if you use single-sign-on.
  • Wallet (if you link one): wallet address(es), signature proofs, chain/network, public on-chain activity relevant to the Service.
  • Marketplace & Transactions: listings, titles/descriptions, high-res photos/scans, prices/offers, carts, orders, Escrow milestones, returns/disputes, payout requests, provenance events (custody, seal IDs, grading status).
  • Grading & Authentication: AI inputs (images), model outputs (condition predictions, saliency, risk flags), expert grader notes, tamper-evident seal IDs, QA/audit trail.
  • Logistics & Insurance: courier names, tracking numbers, pickup/dropoff scans, delivery proof, loss/damage photos, claim files.
  • Communications: emails, messages, chat and support tickets, call recordings (with notice), feedback forms, surveys.
  • User-Generated Content (UGC): profile pictures, photos/videos, comments, ratings/reviews, and associated metadata (time, device, edit history, geotags if you enable).
  • Device & Technical: IP address, device IDs, OS/browser, app version, referrer, session IDs, crash/performance logs, security signals.
  • Usage & Analytics: pages/screens viewed, navigation paths, time on page, search queries, funnels, A/B test assignments, feature flags, email opens/clicks.
  • Data about Others (you share): contacts you invite (name/email/phone). Only provide if you have permission.
  • Other data disclosed at collection or with your consent.

5) Where We Get It

  • Directly from you: registration, KYC, listing/upload, checkout, payouts, support, events.
  • Automatically: cookies, pixels, SDKs, beacons, logs, session replay (if enabled with masking/consent where required).
  • Third parties:
  • Payments & Payouts: processors, e-wallets, banks.
  • KYC/AML/Sanctions: verification vendors and watchlist providers.
  • Grading partners (opt-in): data required to complete submissions; returned grades/cert numbers.
  • Couriers/Insurers: shipping/claims events.
  • Analytics/Ads/Attribution: analytics platforms, ad networks, affiliate platforms.
  • Social/SSO: platforms you choose to connect.
  • Public Sources: public records, social media, and public blockchains relevant to the Service.

6) Automatic Collection Technologies

  • Cookies: session, persistent, first-party, and third-party for auth, preferences, analytics, and advertising.
  • Local Storage: HTML5/IndexedDB/SDK caches for performance and app features.
  • Web Beacons/Pixels: email open tracking, conversion measurement.
  • SDKs: analytics, crash reporting, push notifications, social sign-in, optional advertising.
  • Controls: cookie banner and settings center; browser/OS controls; unsubscribe links for emails.

7) Do Not Track / Global Privacy Control

  • We do not respond to legacy "Do Not Track" signals.
  • Where applicable by law, we honor Global Privacy Control (GPC) for targeted advertising opt-outs.

8) How We Use Personal Information

  • Provide & Operate the Service (contract): create/maintain accounts; listings; AI Pre-Grading + expert validation; Escrow; Vault custody; payouts; notifications; returns/disputes; provenance ledger.
  • Security, Trust & Safety (legal obligation/legitimate interests): KYC/AML/sanctions, fraud and risk scoring, abuse prevention, moderation, chargebacks, auditing, compliance logs.
  • Logistics & Insurance (contract/legitimate interests): shipping labels, tracking, delivery confirmations, loss/damage claims.
  • Product Analytics & Research (legitimate interests/consent): usage measurement, A/B tests, feature performance, crash/perf analysis, model quality improvement.
  • Marketing & Communications (consent or legitimate interests, depending on jurisdiction): newsletters, promotions, announcements.
  • Opt out anytime via email footer or settings.
  • Community & UGC (legitimate interests/consent): enable posts, comments, ratings, and social features you choose to use.
  • Recruiting (legitimate interests/legal obligation): evaluate candidates, manage interviews, maintain necessary compliance files.
  • Legal/Tax/Regulatory (legal obligation): bookkeeping, taxes, regulator/judicial requests.
  • Anonymization/Aggregation (legitimate interests): create de-identified insights and statistics that do not identify you.

9) AI Pre-Grading Transparency

  • Inputs: images/scans and item attributes you provide.
  • Outputs: condition predictions, feature/saliency maps, duplicate/forgery risk flags, confidence ranges.
  • Human-in-the-loop: expert validation for edge cases; escalation and audit trail.
  • Quality: model versioning, drift checks, fairness evaluations, rollback plans, periodic third-party testing where feasible.
  • Choices: you may list without AI outputs where supported or opt into third-party grading; we retain artifacts for provenance, integrity, and disputes.

10) Cookies, Analytics, and Advertising

  • Technical Operation: sign-in/auth, Escrow/Vault state, rate limiting, anti-bot/fraud.
  • Functional: language, currency, saved filters, accessibility.
  • Analytics/Performance: most/least viewed pages, funnels, product improvements, crash/perf telemetry, session replay (masked and consented where required).
  • Advertising/Attribution: retargeting, frequency capping, campaign measurement, affiliate tracking (consent or lawful opt-out where required).
  • Your Controls: cookie settings, browser/OS ad-ID controls, unsubscribe links, and (where available) GPC.

11) How We Share Personal Information

  • Service Providers (processors): hosting/CDN, storage, analytics/A-B testing, messaging (email/SMS/push), support desk, fraud/risk, KYC/AML, payments, payouts, Vault/warehouse ops, couriers, insurers, computer-vision/AI.
  • Grading Partners (opt-in): only what's necessary to fulfill your submission; returned grade and cert number may appear on listings.
  • Marketplace/Integration Partners (if enabled): only as needed to display items or complete actions you direct.
  • Linked Third-Party Services/SSO: if you log in or connect through a third party, that service receives data per your settings and its policy.
  • Professional Advisors: lawyers, auditors, bankers, insurers under confidentiality.
  • Authorities & Others: to comply with laws; protect rights, property, and safety; enforce terms; prevent fraud/abuse.
  • Business Transfers: merger, acquisition, financing, or sale with continued protections.
  • Other Users & Public (UGC): content you choose to make public may be seen, copied, cached, or indexed elsewhere; share thoughtfully.

12) International Data Transfers

  • Your data may be processed outside your country.
  • Safeguards include Standard Contractual Clauses or local equivalents, vendor due diligence, encryption, and access controls.
  • You may request a summary of transfer safeguards relevant to you.

13) Security Measures

  • Encryption: TLS in transit; encryption at rest for sensitive stores; tokenization via payment partners.
  • Access: least-privilege IAM, role-based access, MFA/SSO, short-lived credentials, periodic access reviews.
  • App/Infra: WAF/CDN, bot protection, rate limiting, code review, SAST/DAST, dependency scanning, secret rotation, signed builds.
  • SDLC: staged releases, canary/rollback, change control with segregation of duties.
  • Monitoring/Response: centralized logging, SIEM alerts, incident playbooks, forensics, post-incident corrective actions.
  • Vendors: DPAs, transfer safeguards, periodic assessments, remediation SLAs, audit rights where applicable.
  • People: background checks where lawful, training, NDAs, rigorous offboarding.

14) Retention & Deletion

  • Account & Profile: retained while active, then 2 years after closure for fraud/disputes.
  • KYC/AML: 5–10 years after last relevant transaction as required by law.
  • Transactions/Escrow/Payouts: 7 years for tax/accounting/audit.
  • Logistics/Insurance: claim lifecycle + 3 years.
  • Grading/Authentication Artifacts: 5 years for provenance and antifraud.
  • Analytics Raw Events: 12–18 months; aggregated stats up to 24 months.
  • Marketing/Attribution: until you opt out; suppression logs ~90 days.
  • Support Tickets/Call Recordings: 2 years unless legal hold applies.
  • Community/UGC: until you delete or close your account; backups expire per rotation.
  • Backups: rolling 30–90 days; extended under legal hold.
  • Disposal: secure deletion or irreversible de-identification after retention ends.

15) Your Choices & Controls

  • Access/Update: log in to your account to view or edit certain profile fields.
  • Marketing Opt-Out: use the unsubscribe link in emails or manage settings; service/transactional messages will still arrive.
  • Cookies/Ads: manage via cookie settings, browser/OS controls, and (where applicable) GPC.
  • Linked Services: adjust permissions in the third-party account; revoking access does not affect data already received lawfully.
  • Declining to Provide Data: some features require certain data; we may be unable to deliver those features without it.

16) Your Privacy Rights (Jurisdiction-Dependent)

  • Possible rights: access, correction, deletion, restriction, portability, objection (including to targeted ads/profiling), withdraw consent, and lodge a complaint with a regulator.
  • How to exercise: email [<support@theocx.com>] with your name, account email, country, and request type.
  • Verification: we may request reasonable information (and in sensitive cases, a government ID match) to verify identity.
  • Timelines: we respond within legal deadlines and will notify you if an extension is permitted and needed.

17) Community & UGC Responsibilities

  • Post only content you have the right to share and avoid exposing others' private information.
  • We may moderate or remove content that violates law or our policies.
  • Repeated abuse can lead to account actions under our Terms.

18) Invitations and Contacts

  • If you invite someone, ensure you have permission to share their contact details.
  • We send the invitation and may store minimal details to manage the invite flow and opt-outs.

19) Automated Decision-Making & Profiling

  • Automated areas: fraud/risk/anomaly detection, limited content integrity checks.
  • Human review: available where required for decisions with legal or similarly significant effects.
  • Safeguards: threshold calibration, monitoring false positives/negatives, appeal channels.

20) Children & Eligibility

  • Intended for individuals 18+ or the age of majority in your jurisdiction.
  • We do not knowingly collect data from children below applicable digital consent ages.
  • Parents/guardians may contact [<support@theocx.com>] to request deletion where required.

21) Regional Notes

  • Indonesia (PDP Law): we honor consent/legitimate interest bases, breach notification, and data subject rights; statutory retention may apply.
  • Southeast Asia (PDPA variants): we follow local consent/opt-out standards and cross-border transfer rules.
  • EU/UK (GDPR/UK GDPR): legal bases listed above; SCCs for transfers; DPO/representative if required; DPIAs for high-risk features.
  • US (CPRA/CPA/etc.): we do not "sell" personal information as defined; where "sharing" for cross-context behavioral advertising applies, we provide opt-outs.

22) Complaints & Escalation

  • Contact us first at [<marketing@theocx.com>] so we can address your concerns.
  • If unresolved, you may contact your local data protection authority.

23) Data Breaches & Incident Handling

  • Detection and triage via continuous monitoring and alerts.
  • Containment, eradication, and forensics per documented playbooks.
  • Notifications to regulators and affected users where legally required, including actions you can take.

24) Data Minimization & Accuracy

  • We collect only what we need for stated purposes.
  • We prefer pseudonymized/aggregated data where feasible.
  • Please keep your account information accurate and up to date.

25) Access Governance & Logging

  • Role-based, least-privilege access with periodic recertification.
  • Administrative actions logged; sensitive operations require MFA and, where appropriate, just-in-time elevation.

26) APIs, Webhooks & Integrations

  • TLS, signature verification, key rotation, secret vaulting.
  • Limited scopes/permissions; periodic vendor reviews and DPAs.

27) Recruiting & HR (If You Apply)

  • Data used to evaluate your candidacy, schedule interviews, conduct lawful background checks, and meet legal obligations.
  • Retention aligned to Section 14; you may exercise rights as applicable.

28) Payments & Crypto/Wallet Notes

  • Payment card or e-wallet data is processed by third-party processors per their privacy policies.
  • Wallet addresses are public on chain; we may reference on-chain activity relevant to your actions on the Service.
  • Always review the privacy terms of your selected payment/crypto providers.

29) Other Sites and Services

  • Links or embedded content from third parties are not endorsements.
  • Their collection and use of data are governed by their own policies.
WhatsApp