Policies & Terms

Data Usage Policy

How data across sales, vendors, customers, and transactions is used

Effective August 13, 2026

On this page

1.Purpose and Scope

This Data Usage Policy describes how U and Me Communication, Inc. collects, processes, uses, and governs data within the ZUTTO eCommerce platform (the “Platform”). It complements the Privacy Policy by focusing on operational data — in particular data relating to customers, vendors, sales, and financial transactions. It applies to all users, staff, and service providers who access Platform data.

2.Categories of Data

2.1 Customer data

Identity and contact details, account preferences, and delivery addresses.

Order history, cart activity, wish lists, reviews, and support interactions.

Payment method tokens and billing details used to complete purchases.

2.2 Vendor data

Business identity, registration, tax IDs, and authorized contacts.

Product catalogs, inventory, pricing, and fulfillment performance.

Payout account references, commission terms, and settlement history.

2.3 Sales data

Order records, line items, quantities, discounts, and status.

Fulfillment, shipping, delivery, and return records.

Product performance metrics and conversion analytics.

2.4 Transaction and financial data

Payment amounts, currencies, timestamps, and transaction identifiers.

Commissions, platform fees, taxes collected, refunds, and chargebacks.

Vendor settlements, disbursements, and reconciliation ledgers.

Audit trails linking each financial movement to its originating order.

3.How Data Is Used

3.1 Operating the marketplace

Routing orders from customers to the correct vendors and enabling fulfillment.

Displaying relevant product, pricing, and availability information.

Managing accounts, authentication, and user preferences.

3.2 Financial processing

Capturing customer payments and calculating platform commissions and taxes.

Computing and disbursing vendor payouts net of fees, refunds, and chargebacks.

Reconciling ledgers and maintaining accurate financial records for each transaction.

3.3 Analytics and improvement

Measuring sales trends, vendor performance, and customer behavior in aggregate.

Improving search, recommendations, and Platform features.

Forecasting demand and detecting anomalies.

3.4 Trust, safety, and compliance

Detecting and preventing fraud, abuse, and unauthorized access.

Resolving disputes between customers and vendors using transaction records.

Meeting tax, accounting, audit, and other legal obligations.

4.Data Ownership and Access

Customers retain rights in their personal data. Vendors retain rights in their business and catalog data. U and Me Communication, Inc. owns aggregated, de-identified, and derived analytics generated from Platform activity. Access to data is granted on a need-to-know basis:

Customers can access their own account, order, and transaction data.

Vendors can access their own listings, sales, and payout/settlement data, plus the order details necessary to fulfill customer orders.

Administrators can access data required to operate, support, and secure the Platform, subject to role-based controls.

5.Data Sharing

Between transacting parties, limited to what is needed to complete and support an order.

With service providers (payment processing, hosting, logistics, analytics) under contract and instruction.

With authorities where required by law or to protect the Platform and its users.

Aggregated or de-identified data that cannot reasonably identify an individual may be used and shared for reporting, benchmarking, and product development.

6.Financial Data Handling

Financial and transaction data receives heightened protection given its sensitivity:

Full card numbers and sensitive authentication data are processed by PCI-DSS compliant processors and are not stored in plaintext on ZUTTO systems.

Transaction ledgers are maintained with integrity controls and audit logging.

Access to payout and settlement data is restricted and monitored.

Financial records are retained for the periods required by tax and commercial law.

7.Data Retention

Data is retained only as long as necessary for the purposes described here or as required by law. Operational data may be minimized or de-identified once its active purpose ends. Financial transaction records are retained for the statutory minimum for tax, audit, and dispute-resolution purposes, after which they are securely deleted or archived.

8.Data Security

Encryption in transit (TLS) and encryption or tokenization of sensitive data at rest.

Role-based access control, least-privilege principles, and access logging.

Segregation of production financial systems and regular security reviews.

Incident response procedures for suspected data breaches.

9.User Rights Over Data

Access and export of your own account, order, and transaction data.

Correction of inaccurate information.

Deletion of personal data, subject to legal and financial retention obligations.

Objection to certain non-essential processing, such as marketing analytics.

Requests may be submitted to legal@shopzutto.com and are subject to identity verification.

10.Third-Party and Automated Processing

Where the Platform uses automated processing (for example, fraud scoring or recommendations), decisions with legal or significant effects are reviewed by appropriate safeguards. Third-party processors act only on documented instructions and are bound by confidentiality and security obligations.

11.Changes to This Policy

We may update this Data Usage Policy as the Platform evolves or as legal requirements change. Material changes will be posted with a revised effective date.

12.Contact

Questions about data usage may be directed to legal@shopzutto.com — U and Me Communication, Inc., Data Governance.