Privacy Policy

Last updated: May 10, 2026

1. Introduction

This Privacy Policy explains how Zexpy ("we", "us", "our") collects, uses, and protects your personal information when you use our website at zexpy.site ("the Site"). We are committed to respecting your privacy and complying with applicable data protection laws including GDPR and CCPA.

2. Information We Collect

Information you provide:

  • Account information: Email address and password when you register
  • Profile data: Display name, bio, profile picture, and banner image
  • User content: Photos, GIFs, stories, comments, and collections you create
  • Payment data: Processed securely through Stripe — we never store your full card details

Information collected automatically:

  • Usage data: Pages visited, features used, and time spent on the Site
  • Device data: Browser type, device type, and operating system
  • Analytics data: Anonymized visitor hashes (not raw IP addresses) for traffic analysis
  • Cookies: Session cookies for authentication and preference cookies (see Section 7)

3. How We Use Your Information

  • To provide and maintain the Site and your account
  • To process payments for supporter features
  • To personalize your experience (favorites, collections, recommendations)
  • To improve our Site through analytics
  • To communicate important account or service updates
  • To enforce our Terms of Service and prevent abuse

4. Legal Basis for Processing (GDPR)

We process your data based on:

  • Consent: When you create an account or accept cookies
  • Contract: To fulfill services you requested (account features, payments)
  • Legitimate interest: To improve our services and prevent fraud

5. Data Sharing

We do not sell your personal data. We may share information with:

  • Stripe: For payment processing (subject to Stripe's Privacy Policy)
  • Analytics providers: Anonymized usage data for site improvement
  • Law enforcement: When required by law or to protect our rights

6. Data Retention

We retain your account data for as long as your account is active. You can delete your account at any time by contacting us. Analytics data is anonymized and retained for up to 12 months. Payment records are kept as required by financial regulations.

7. Cookies

We use the following types of cookies:

  • Essential cookies: Required for authentication and site functionality (always active)
  • Preference cookies: Remember your age verification status and display preferences
  • Analytics cookies: Help us understand how visitors use the Site (can be declined)

You can manage cookie preferences through our cookie consent banner or your browser settings.

8. Your Rights

Depending on your location, you may have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Portability: Receive your data in a structured format
  • Objection: Object to certain processing activities
  • Withdraw consent: Withdraw previously given consent at any time

CCPA (California residents): You have the right to know what data we collect, request deletion, and opt out of data sales (we do not sell data).

9. Security

We implement industry-standard security measures including encrypted connections (HTTPS/TLS), hashed passwords (bcrypt), and secure payment processing through Stripe. However, no system is 100% secure, and we cannot guarantee absolute security.

10. Children's Privacy

This Site is strictly for adults aged 18 and over. We do not knowingly collect data from minors. If we discover that a minor has created an account, we will terminate it immediately and delete all associated data.

11. Changes to This Policy

We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy regularly.

12. Contact Us

For privacy-related inquiries, data requests, or concerns, contact us at [email protected].