LEGAL

Privacy Policy

Last updated 3 September 2026. How Zntrix handles personal data across its website, Commerce platform, suppliers, and dealer portals.

1. Who operates Zntrix and what this policy covers

Zntrix is a brand operated by Elijah Espela, an individual based in the Philippines ("Zntrix", "we", "us", or "our"). This Privacy Policy explains how we handle personal data when you visit Zntrix websites, contact us, request a trial, create or administer a supplier workspace, use a dealer portal, receive support, or otherwise interact with Zntrix.

For personal data that Zntrix collects for its own account, security, billing administration, support, website, and service-operation purposes, Zntrix generally acts as the personal information controller or equivalent controller under applicable law. For dealer, customer, sales-agent, staff, order, and similar personal data a supplier places in its workspace for the supplier’s own business purposes, the supplier is generally the controller and Zntrix acts as its processor or personal information processor. The Zntrix Data Processing Addendum applies to that processor relationship.

This service is intended for businesses and professional users. A supplier remains responsible for its own privacy notices, lawful bases, permissions, and instructions concerning the personal data it controls.

2. Personal data we may process

Account and identity data may include name, work email, protected password credentials, email-verification status, workspace membership, role, account settings, authentication records, and session information.

Trial, sales, and support data may include company or website details, intended use, trial-request information, contact-form messages, support tickets, correspondence, and information reasonably needed to review eligibility or prevent abuse.

Supplier workspace data may include company profiles, catalogs, prices, media, dealers and customers, sales agents, staff roles, quotations, orders, inventory information, payment-status records or payment-proof files, custom-domain settings, import files, and other information the supplier chooses to place in its tenant.

Technical and security data may include IP or network information where available, browser and device information, timestamps, request and authentication events, error information, security signals, rate-limit information, and operational logs needed to operate, troubleshoot, measure, and secure the service.

Subscription and billing data may include plan, billing cycle, subscription status, Paddle customer, transaction, price, or subscription identifiers, invoices or receipt references, and related billing metadata. Paddle processes payment credentials and full card data for subscription purchases; Zntrix does not intentionally store full payment-card numbers.

3. Sources of personal data

We receive data directly from people who create accounts, submit forms, communicate with support, or use the service; from the supplier or its authorized users when they upload, import, or invite people into a workspace; automatically from browsers, devices, and service activity; and from service providers such as Paddle when they send billing or subscription information needed to administer the service.

4. Why we process personal data and our legal bases

We process personal data to provide and administer accounts, trials, subscriptions, workspaces, dealer portals, catalogs, pricing, orders, support, authentication, security, infrastructure, and other requested functionality. Where applicable, this processing is necessary to perform a contract or take steps requested before entering a contract.

We process data to protect accounts and tenants, detect fraud and abuse, enforce service limits, troubleshoot incidents, maintain reliability, improve the service, communicate operational information, and defend legal claims. Where applicable, we rely on our legitimate interests or the legitimate interests of our Customers, balanced against the rights of affected people.

We process information where necessary to comply with legal, tax, accounting, regulatory, security, dispute, or law-enforcement obligations. Where consent is the appropriate or required basis, we rely on consent and allow withdrawal as required by law. For data processed solely on a supplier’s documented instructions, the supplier is responsible for establishing the lawful basis for that processing.

5. Trial review and automated processing

Zntrix may use account, company, domain, device, network, and anti-abuse signals to help review trial requests and protect the service. Trial approval is currently manually reviewed. We do not currently use solely automated decision-making that produces legal or similarly significant effects for an individual without human involvement.

6. How we share personal data

We do not sell personal data. We do not create a public directory of a supplier’s dealers or use one supplier’s private customer list to market another supplier’s products.

We disclose information to service providers and subprocessors only as reasonably necessary to provide, secure, support, bill, and maintain Zntrix. Current providers may include Vercel for application hosting and deployment; Supabase and PostgreSQL infrastructure for database services; Cloudflare R2 for object and media storage; Resend for transactional or support email; and Paddle for subscription checkout, billing, tax, invoices, receipts, and merchant-of-record services.

Paddle acts as merchant of record for applicable subscription transactions and may independently determine how it must process payment, tax, fraud, compliance, and transaction data under its own privacy terms. Zntrix receives the billing information needed to administer the Customer’s subscription but does not control every aspect of Paddle’s independent processing.

We may use additional or replacement infrastructure providers as Zntrix evolves. GreenCloud may be used as a hosting or VPS provider if that infrastructure is deployed in the future. Where required, we will update applicable disclosures or subprocessor information before or when a material provider change takes effect.

We may disclose information when required by applicable law or valid legal process; to investigate fraud, abuse, security incidents, or violations of our Terms; to protect users, Customers, Zntrix, or the public; or in connection with a bona fide financing, incorporation, merger, reorganization, acquisition, or transfer of the Zntrix business, subject to applicable legal safeguards.

7. Cookies, browser storage, analytics, and advertising

Zntrix uses essential cookies or equivalent browser storage for authentication, sessions, security, workspace routing, and preferences needed to operate the service. These technologies are necessary for core product functionality.

Zntrix does not currently use third-party advertising pixels, behavioral advertising, or non-essential analytics tracking on the marketing site as part of the present service. If we later introduce analytics, advertising, or other non-essential tracking, we will update this Policy and provide consent or preference controls where required by applicable law.

8. International processing

Zntrix is operated from the Philippines and serves business users internationally. Our infrastructure and service providers may store or process personal data in the Philippines, the United States, or other countries in which they or their subprocessors operate. Those countries may have privacy laws different from the country where a person is located.

Where applicable law requires safeguards for an international transfer, Zntrix or the relevant Customer will use an appropriate lawful transfer mechanism, contractual safeguard, or other permitted basis. Suppliers are responsible for any additional transfer obligations arising from their own instructions, locations, or dealer/customer relationships.

9. Data retention and deletion

We retain account and active workspace information while reasonably necessary to provide the service. When a no-card trial expires or paid access effectively ends, the dealer portal is paused and Zntrix currently retains active workspace data for 60 calendar days so an eligible supplier can reactivate. There is no general right to continue using or export the workspace during this retention period.

If the workspace is not reactivated before the retention period expires, we may permanently delete or anonymize active tenant data, including catalogs, portal records, uploaded media, and related workspace information. Deletion from active systems may not immediately remove encrypted backup copies, which expire through normal backup rotation.

We may retain limited records for longer when reasonably necessary for payment, tax, accounting, fraud prevention, security, abuse prevention, dispute resolution, legal claims, regulatory obligations, or enforcement of our agreements. Paddle and other independent providers retain information according to their own legal obligations and policies.

10. Data security

We use administrative, technical, and organizational measures intended to protect personal data, including authenticated access, role and tenant controls, secure session handling, encrypted network transport, restricted storage, security logging, rate limiting, and operational safeguards appropriate to the service. Security measures evolve as risks and the service change.

No internet service, storage system, or security measure can guarantee absolute security. Customers must use appropriate passwords, protect their own devices, assign permissions carefully, and notify support@zntrix.com promptly if they reasonably suspect unauthorized access or a security incident involving their workspace.

11. Your privacy rights

Depending on applicable law and Zntrix’s role for the relevant data, individuals may have rights to be informed about processing; obtain access to personal data; correct inaccurate data; object to certain processing; request erasure, blocking, restriction, or deletion where legally available; obtain data portability where applicable; withdraw consent where processing is based on consent; and seek compensation or other remedies for unlawful processing.

Individuals covered by the Philippine Data Privacy Act may also have rights recognized by that law and may lodge a complaint with the National Privacy Commission. People in other jurisdictions may have additional mandatory rights under their local law.

To exercise a right concerning data Zntrix controls, email support@zntrix.com. We may need to verify identity, authority, jurisdiction, and the request before acting. Where Zntrix processes the relevant data only on behalf of a supplier, dealers, customers, agents, and supplier staff should normally direct their request to that supplier first; we will reasonably assist the supplier as required by the DPA and applicable law.

12. Marketing communications

You may opt out of non-essential promotional email from Zntrix using the method provided in the message or by contacting support@zntrix.com. We may still send account, security, billing, legal, support, and service messages that are necessary to administer an account or provide the service.

13. Children

Zntrix Commerce is a B2B service intended for businesses and professional users and is not directed to children. We do not knowingly invite children to create supplier workspaces. If you believe a child has provided personal data to Zntrix inappropriately, contact support@zntrix.com.

14. Changes to this Policy

We may update this Privacy Policy when the product, providers, business, or applicable law changes. The Last updated date will identify the current public version. We will provide additional notice of material changes where appropriate or legally required.

15. Contact

The Zntrix privacy contact is Elijah Espela, operating Zntrix from the Philippines. Privacy questions, requests, complaints, or security concerns may be sent to support@zntrix.com.

Related: Terms of Service · Refund Policy · Data Processing Addendum · Contact

Privacy Policy — Zntrix — Zntrix