Kairos launches soon. An account starts your store's verification now, and the list gets the first listings. Join the seller waitlist

Privacy Policy

ZENOX MARKETING MANAGEMENT - FZCO, trading as Kairos Exchange ("Kairos", "we"), is the controller of the personal data described here. This policy says exactly what we collect, why, on what legal basis, who receives it, how long we keep it, and what you can do about it. Our data footprint is small and this policy names all of it - no vague categories.

Effective 2026-07-20

Who Is Responsible

In plain terms: A UAE company runs Kairos. One email reaches the people who handle privacy.

Controller: ZENOX MARKETING MANAGEMENT - FZCO, Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates. Contact for anything in this policy: info@kairosexchange.com.

Because we serve users in the European Union and the United Kingdom from outside those territories, we are in the process of appointing an EU representative under Article 27 GDPR and a UK representative under the UK GDPR. Until those appointments are published here, contact us directly at the address above - your request is handled the same way, within the same deadlines.

What We Collect

In plain terms: Six categories, nothing else: your account, connected store data, funds verification, messages, consent records, and deal records.

Account data: name, email, password (stored only as a bcrypt hash - we cannot read it), whether you are a buyer or a seller, and your country or state for the geographic rules.

Connected store data (sellers): when you connect a store, we read order history through a read-only API connection - for Shopify, up to 24 months of orders, which we aggregate into monthly revenue, refund, and volume figures to verify your listing. Read-only means we can look and never change or post anything. The access token you give us is stored encrypted (AES-256-GCM), and revoking it in your own store admin removes our access going forward.

Funds verification (buyers): if you ask to be funds-verified, we collect your legal name, country and state, and the amount of funds you attest to, and an admin reviews it.

Messages and activity: listing questions, deal room messages, offers, unlock history. Deal room messages are visible to the buyer, the seller, and Kairos admins - the shared record is the point of the deal room.

Consent records: when you accept the Buyer NDA or the Terms of Service, we record which version, when, and the IP address and browser used. This is the evidence trail both sides can rely on.

Deal and payment records: offers, deals, milestones, invoices, and deposit status. Card details never touch Kairos - they go directly to Stripe.

What Buyers See, and What Happens to Seller Data in a Sale

In plain terms: Buyers see banded numbers until they accept the NDA and unlock. We show metrics derived from your store data - we never hand over your customer database.

A listing shows the public, anonymised view by default: banded figures, no brand name. A buyer sees exact figures, the real brand name, and the verification memo only after accepting the Buyer NDA and unlocking the listing, and the store URL only after a separate access grant. Kairos logs every acceptance and unlock.

What we display to buyers is financial metrics derived from your connected data (revenue, refunds, volumes) - not your customers' personal data. Kairos does not transfer a seller's customer or order database to anyone. If a sale closes and the business's own customer data changes hands as part of the assets, that transfer happens between seller and buyer under the purchase agreement, and each of them is responsible for making it lawful in their jurisdictions - for EU customer lists this typically needs specific safeguards, and our transfer documentation templates flag it.

A buyer who receives listing information under the NDA processes it as an independent controller of anything personal in it. The NDA is a confidentiality agreement, not a data processing agreement.

Who Receives Your Data

In plain terms: Seven named providers, each for one job. Stripe and Escrow.com act as controllers in their own right - the rest process only on our instructions.

Processors acting on our instructions: Vercel (US - hosting, and file storage for listing media), Railway (US - our Postgres database), Resend (US - transactional email delivery), DocuSign (US - e-signature of deal documents). Shopify is the data source you connect - we pull from your store under the token you create; we do not send them your Kairos data.

Independent controllers we work with: Stripe (payment processing for deposits and invoices - Stripe also processes card and fraud data under its own privacy policy) and Escrow.com (deal settlement - it runs its own identity checks and holds funds under its own terms). When you pay or enter escrow, you share data with them directly and their policies apply alongside ours.

Internal operations: when something needs the team's attention (a new due diligence lead, a flagged trust signal), it appears in our internal admin console for a team member to review - there is no automated push alert to a phone or messaging app.

Beyond these: only if the law requires it (a binding order), to enforce our terms in legal proceedings, or - with notice to you - if Kairos itself is merged or acquired. We never sell personal data to anyone.

International Transfers

In plain terms: Kairos runs from the UAE with US-based providers. Neither has an EU adequacy decision, so transfers ride on standard contractual clauses - and Stripe's own EU-US certification.

Your data is processed in the United Arab Emirates (where Kairos operates) and the United States (where the providers above run). Neither country holds a general EU adequacy decision.

For data of EU, UK, and Swiss users, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum) in our agreements with our processors, and on a provider's own certification under the EU-US Data Privacy Framework where it holds one - Stripe is DPF-certified. You can request a copy of the relevant safeguards at info@kairosexchange.com.

How Long We Keep It

In plain terms: Real periods per category - no vague forever clauses.

Account data: while your account is active, then deleted or anonymised within 12 months of closure, unless a legal obligation or an open dispute requires longer.

Connected store data: we stop reading the moment the token is revoked. Aggregated verification snapshots stay part of the listing and deal record they verified, for as long as that record is kept.

Funds verification data: 5 years from submission, in line with financial recordkeeping norms.

Consent records (NDA and terms acceptances, with IP address): 6 years from the date of acceptance, or until the end of any dispute in which they are evidence, whichever is later - they exist to prove what was agreed.

Deal, offer, and invoice records: 7 years from the end of the deal or the invoice date, to meet tax and accounting obligations.

Messages: while your account is active, then removed with the account data unless part of a retained deal record.

Waitlist emails: until we have launched what you signed up to hear about, or immediately on unsubscribe.

Your Rights

In plain terms: Access, correction, export, deletion, restriction, objection - one email, answered within a month, and you can always go to your data protection authority.

Under the GDPR, the UK GDPR, and similar laws, you can ask for access to your data, correction, export in a portable format, deletion, restriction of processing, and you can object to processing based on legitimate interest. Where processing rests on consent, you can withdraw it at any time without affecting past processing.

Send requests to info@kairosexchange.com. We respond within one month; if a request is unusually complex we may extend by up to two further months, and we tell you within the first month if so, with reasons. Exercising your rights is free.

Some records we must keep despite a deletion request - consent trails during their retention period, invoices during tax retention - and if that applies we tell you exactly what we kept and why.

You also have the right to complain to a data protection supervisory authority, in particular in the EU or UK country where you live or work.

US State Privacy Rights

In plain terms: Same rights, same email, whichever US state you are in. We do not sell or share personal data - there is nothing to opt out of.

For residents of California and other US states with privacy laws: the categories we collect are identifiers (name, email), commercial information (offers, deals, invoices), financial information (funds verification), and internet activity limited to the session and consent records described above. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is no sale or sharing to opt out of. You have the same access, correction, and deletion rights described above, through the same contact, and we do not discriminate against you for using them. You may use an authorised agent; we will verify the request either way.

Security and Breaches

In plain terms: Encryption where it matters, least access, and if a breach ever affects you, you hear it from us.

Passwords are stored as bcrypt hashes. Store access tokens are encrypted at rest with AES-256-GCM. Sessions use signed, httpOnly cookies. Access to admin functions is role-gated and logged. Money never touches Kairos systems - settlement runs through the escrow provider and payments through Stripe.

If a personal data breach occurs, we notify the competent supervisory authority within the legally required timeframe (72 hours under the GDPR where notification is required) and tell affected users without undue delay when the breach is likely to put them at high risk.

Who This Platform Is For

In plain terms: Businesses and adults only.

The Platform is for business use by people aged 18 or over. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a minor has created an account, tell us and we will delete it.

Data at Launch

In plain terms: Sample stores are labelled sample stores.

Where the platform shows demo listings, they are illustrative test data, labelled as such - not real stores, not real sellers.

Changes to This Policy

In plain terms: Material changes come with notice, not surprises.

When this policy changes materially, we notify account holders by email before the change takes effect and update the effective date above. Earlier versions are available on request at info@kairosexchange.com.