🎉
Use code WB7S8XVW to save 15% on your order !
Privacy Policy | ShopCrossway

Privacy Policy

Protecting Your Privacy Worldwide with Transparency and Control

Last Updated: May 2026 Effective Immediately Version 3.1.4

Welcome to ShopCrossway

Welcome to https://shopcrossway.com (the "Site"). This Privacy Policy explains how we collect, use, share, and protect your personal data when you visit our platform or use our services.

We are committed to safeguarding your privacy. If you have any questions about this policy, contact us at [email protected].

Data Collection

Transparent information gathering practices

Your Rights

Full control over your personal information

Global Compliance

GDPR, CCPA, and international standards

Security

Advanced encryption and protection measures

Information We Collect & How We Use It

Information Collection

We collect personally identifiable information that you provide directly, as well as data automatically generated when you use our Site:

  • Name, email address, phone number
  • Shipping and billing addresses
  • Payment details (processed securely)
  • Purchase history and browsing behavior
  • Device information and IP address
  • Marketing and communication preferences

How We Use Your Data

Your data helps us deliver a seamless global shopping experience:

  • Process orders and manage shipments worldwide (Contract Performance, GDPR Art. 6(1)(b))
  • Personalize your experience across devices (Legitimate Interest, GDPR Art. 6(1)(f))
  • Provide multilingual customer support (Legitimate Interest, GDPR Art. 6(1)(f))
  • Improve our services through analytics (Legitimate Interest, GDPR Art. 6(1)(f))
  • Send marketing communications (with consent) (Consent, GDPR Art. 6(1)(a))
  • Prevent fraud and enhance platform security (Legitimate Interest, GDPR Art. 6(1)(f))

Data Sharing & International Transfers

Global Data Processing

As a global marketplace, your data may be processed in multiple jurisdictions to provide our services:

  • EU data: processed under GDPR adequacy decisions
  • US data: protected under EU-US Data Privacy Framework
  • International transfers safeguarded by Standard Contractual Clauses
Transfer Safeguards: When we transfer your personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy Decisions for countries deemed to provide adequate protection
  • Where applicable, Binding Corporate Rules (BCRs)

You may request a copy of the SCCs or other transfer mechanisms by contacting us at [email protected].

Global Headquarters

Yingzhi Technology Co., Ltd.
Tax ID: 91440300MAE22AUC1X
Lantian Road, Shuguang Community, Xili Street
Nanshan District, Shenzhen City, China

EU Representative

Axitera GmbH
Kreuznacher Str. 30
60486 Frankfurt am Main, Germany

Third-Party Sharing

We share data only when necessary with trusted partners:

  • Payment processors (Stripe, PayPal, etc.)
  • Shipping carriers (DHL, FedEx, national posts)
  • Verified retailers for order fulfillment
  • Customer support and analytics platforms
Retailer Access: Retailers receive only necessary order information and are contractually bound to protect your data.

Data Protection & Your Rights

Security Measures

  • Limited employee access on a need-to-know basis
  • Regular security audits and penetration testing
  • SSL/TLS encryption for all data transmission
  • PCI DSS compliant payment processing
  • Data breach response and notification protocols

Your Privacy Rights

  • Access: Receive a copy of your personal data
  • Rectification: Correct inaccurate information
  • Erasure: Request deletion of your data
  • Portability: Receive data in a machine-readable format
  • Objection: Object to certain processing activities

Or email: [email protected]

Data Breach Notification

In the event of a personal data breach, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (as required under GDPR Article 33)
  • Communicate the breach to affected data subjects without undue delay if the breach is likely to result in a high risk to their rights and freedoms (as required under GDPR Article 34)
  • Take immediate steps to contain the breach and mitigate potential harm
Report a breach: If you believe your data has been compromised, please contact us immediately at [email protected].

Third-Party Data Processors

We engage the following third-party processors to handle your personal data. Each processor is bound by a Data Processing Agreement (DPA):

ProcessorPurposeLocationDPA Status
WooCommerceE-commerce platformUSASigned
ElementorPage builderIsraelSigned
CloudflareCDN & SecurityUSASigned
CookieYesCookie consentUSASigned
Jetpack (Automattic)AnalyticsUSASigned
PayPalPayment processingUSASigned
DokanMulti-vendor marketplaceIndiaSigned

We regularly review our processors to ensure ongoing compliance.

Children's Privacy

Our services are not directed at children under 18. We do not knowingly collect personal data from minors. If we become aware of such data, we will promptly delete it.

Policy Updates

We may update this policy periodically. Significant changes will be communicated via email or a prominent notice on our Site. The latest version always appears here.

Data Retention Periods

5Y
Transaction Records

Financial and order history

3Y
Customer Accounts

Inactive user profiles

2Y
Marketing Data

With active consent

1Y
Website Analytics

Anonymized usage data

Contact Us About Privacy

For any privacy-related inquiries or to exercise your data rights, reach our Global Privacy Team:

[email protected]

You can also via our secure form.

Last Updated: May 2026 · Version 3.1.4

Shopping Cart (0)

Cart is empty No products in the cart.