Cross MatcherBack to sign up

Privacy Policy

Version 2026-07-26.1 · Effective July 26, 2026

This Policy explains what we collect, how we use it, and the choices you have. It should be read together with our Terms of Service.

1. Introduction

This Privacy Policy explains how Crossmatcher Inc., a corporation incorporated under the Canada Business Corporations Act (corporation number 1798474-0), with its registered office at 2102-400 Adelaide St E, Toronto, Ontario M5A 4S3, Canada, operating the Cross Matcher service ("Cross Matcher", "we", "us", "our"), collects, uses, shares, and protects personal information when you use the Cross Matcher website, applications, and services (the "Service"). It should be read together with our Terms of Service.

By creating an account, checking the acceptance box, or otherwise using the Service, you acknowledge that you have read this Policy. Where your consent is required by applicable law, your acceptance constitutes that consent. We record the version you accept and the date of acceptance.

The Service is intended only for adults (18+) and is not directed to children.

2. Information you provide

Account: your email address, password (stored only as a salted hash — we never store it in plain text), language preference, and your acceptance of the Terms and this Policy.

Profile: the display name and avatar you choose, and the profile you write describing your role, your location or market, and what you can offer or need. Please do not include sensitive personal data you don't want shared with potential counterparties.

Content: requests you post; messages, ratings, and reviews you exchange with a counterparty in a deal; files you upload to a deal chat or as dispute evidence; and feedback or support tickets you send us.

Point purchases: the package selected, points, price, currency, purchase and refund status, and Stripe references such as Checkout Session, PaymentIntent, Charge, refund, and dispute identifiers. Stripe collects your payment credentials directly; Cross Matcher does not receive or store your full card number or CVC.

Security: if you enable an authenticator, we store an encrypted TOTP secret (never the codes themselves).

3. Information collected automatically

Usage & device: limited technical data such as IP address, approximate region, device/browser type, and timestamps of sign-ins and key actions — used to operate the Service, keep it secure, and prevent abuse.

Public Confessional views: to keep public-hall view counts resistant to repeated refreshes, we store a one-way per-account/per-public-record marker. The marker does not contain the account ID or a view timestamp and is used only to maintain the aggregate view count and hot/fresh ordering shown in the hall.

Sessions & local storage: we use first-party session tokens (including an optional 'remember this device' token) and local storage to keep you signed in and remember preferences. We do not use third-party advertising cookies or sell your data to advertisers.

4. How we use your information

To provide the Service: create and secure your account, match complementary needs, run deals, deliver in-app and email notifications, and provide support.

Purchases and accounting: create Stripe Checkout sessions, verify payment, deliver points, maintain the points and purchase ledgers, reconcile payments, handle refunds and payment disputes, prevent duplicate delivery, and provide transaction support.

Safety & integrity: to moderate content, detect and prevent fraud, abuse, sock-puppets, and policy violations, and to operate the community-jury dispute process.

Improvement: to understand aggregate usage and improve matching quality and reliability.

Legal: to comply with law, enforce our Terms, and protect the rights, safety, and property of users and the public.

5. Automated processing & AI

Matching: your profile and request text are converted into numerical embeddings so the system can suggest complementary counterparties. This is automated and is not a decision producing legal or similarly significant effects about you.

Moderation: text, images, and video keyframes you submit may be screened automatically (including by AI models) to enforce safety policies before content goes live; some items are additionally reviewed by a human moderator.

Translation: to support a bilingual community, some user-visible text may be machine-translated. Automated outputs can be imperfect; you can contact us if a moderation outcome seems wrong.

6. How we share information

With other users: your display name, avatar, level, reputation counts, and the content you choose to post or send are visible to the counterparties and community contexts they're meant for (e.g., a request on the board, a message in your deal, redacted previews to a jury). Your email and password are never shown to other users.

Service providers (processors): we use trusted vendors to run the Service under contract and only for the services they provide — including cloud hosting and databases, transactional email delivery, machine translation, AI moderation (provided via Amazon Web Services and similar processors), and Stripe for Checkout, payment processing, fraud prevention, refunds, and payment disputes. Stripe may process payment information as described in its own privacy notice and applicable agreements.

Legal & safety: we may disclose information if required by law or to protect rights, safety, and integrity.

Business transfers: if Cross Matcher is involved in a merger, acquisition, or asset sale, information may be transferred subject to this Policy.

We do not sell your personal information.

7. International transfers

We operate cloud infrastructure that may process and store data in regions outside your country. Where required, we rely on appropriate safeguards for cross-border transfers. By using the Service you understand your information may be processed in those regions.

8. Data retention

We keep personal information for as long as your account is active and as needed to provide the Service, then for a reasonable period to meet legal, security, dispute-resolution, and anti-abuse needs, after which it is deleted or anonymized.

Some content tied to a completed deal or dispute (e.g., the record that a deal occurred) may be retained to preserve the integrity of reputation and the points ledger. Uploaded chat and evidence files are removed on a routine schedule after a deal settles.

Purchase, payment-provider reference, refund, dispute, and related ledger records may be retained for the period required for accounting, tax, fraud prevention, chargeback handling, and other legal obligations, including after account closure. Where possible, account identifiers may be separated or minimized while financial records are retained.

A public Confessional's aggregate counters and one-way anti-refresh view markers remain only while that public record exists. They are deleted with the public record when its owner or an administrator withdraws it.

Moderation decisions, rejection or revocation reasons, support notices, and platform-wide announcements written by an authorized administrator in that role are Crossmatcher Inc. institutional records, not the administrator's personal user content. They may remain after that administrator leaves or deletes an account so the Service can explain and enforce company decisions. Administrators are instructed not to place their own or another person's unnecessary personal information in those records.

9. Your rights and choices

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can edit your profile or start verified account deletion directly in Settings. Deletion immediately suspends access, removes or anonymizes identifying profile and content data, and deletes stored files after already-issued upload permissions expire.

We retain pseudonymous purchase, refund, dispute, tax, and points-ledger records only where needed for accounting, fraud prevention, chargeback handling, or another legal obligation. Those records are separated from your direct identity and scheduled for deletion when the applicable retention period ends.

You can unsubscribe from non-essential emails. We may still send essential service messages (e.g., security or transactional notices).

We will not discriminate against you for exercising these rights. To make a request, contact us using the details below; we may need to verify your identity first.

10. Security

We use technical and organizational measures to protect your information — including encryption in transit, hashed passwords, encrypted authenticator secrets, scoped access to private file storage, restricted payment-provider credentials, signed Stripe webhook verification, and access controls. Payment credentials are entered on Stripe-hosted Checkout and do not pass through Cross Matcher servers. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security.

11. Children

The Service is for adults (18+). We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.

12. Changes to this Policy

We may update this Policy from time to time. When we make material changes we will update the version and effective date above and, where appropriate, notify you or request renewed acknowledgement. Before an existing account's first paid-points purchase under this version, we require affirmative acceptance of the updated Terms and this Policy.

13. Contact us

Questions or privacy requests? Contact Crossmatcher Inc. at privacy@crossmatcher.com or by mail at 2102-400 Adelaide St E, Toronto, Ontario M5A 4S3, Canada.