1 Overview
Cosmic Trading ("CosmicTRD", "we", "us") operates the customer portal at cosmictrd.io and associated platforms. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
2 Information We Collect
2.1 Information You Provide
| Data Type | Examples | Purpose |
|---|---|---|
| Identity | Name, email, phone number, profile photo | Account creation & authentication |
| Financial | Payment records, wallet transactions, bank transfer proofs | Processing payments & invoicing |
| Order Data | Product queries, order details, shipping addresses | Fulfilling your sourcing requests |
| Communication | Messages to support, query discussions, feedback | Customer service & order coordination |
| KYC Documents | Government ID, business registration (for loan services) | Financial services compliance |
2.2 Information Collected Automatically
| Data Type | Examples | Purpose |
|---|---|---|
| Device Info | Browser type, OS, screen resolution | Platform optimization |
| Usage Data | Pages visited, features used, timestamps | Improving user experience |
| Network Data | IP address, approximate location | Security & fraud prevention |
3 How We Use Your Information
We use collected information to:
- Provide Services: Process queries, fulfill orders, manage shipping and payments
- Communicate: Send order updates, shipping notifications, and payment confirmations via email, SMS, Telegram, or WhatsApp
- Improve Platform: Analyze usage patterns to enhance features and fix issues
- Security: Detect fraud, prevent unauthorized access, and protect our platform
- Legal Compliance: Meet regulatory requirements for international trade and financial services
- Customer Support: Respond to your inquiries and resolve issues
5 Data Storage & Security
5.1 Storage
Your data is stored on secured servers hosted by Hostinger with infrastructure protection provided by Cloudflare. Databases are encrypted and access is restricted to authorized personnel only.
5.2 Security Measures
We implement the following security measures:
- SSL/TLS encryption for all data transmission (HTTPS)
- HSTS (HTTP Strict Transport Security) with preload
- Content Security Policy (CSP) headers
- Two-Factor Authentication (2FA) for admin access
- Rate limiting and brute-force protection
- WAF (Web Application Firewall) via Cloudflare
- Regular security audits and monitoring
- Role-based access control for admin operations
5.3 Breach Notification
In the event of a data breach that affects your personal information, we will notify you via email and/or platform notification within 72 hours of becoming aware of the breach.
7 Third-Party Services
Our platform integrates with the following third-party services, each with their own privacy policies:
- Clerk — User authentication and account management
- Cloudflare — CDN, security, and DDoS protection
- EPS Payment Gateway — bKash/Nagad payment processing
- Telegram — Order notification delivery
- Google Analytics — Platform usage analytics
- Hostinger — Web hosting and server infrastructure
We recommend reviewing the privacy policies of these services for more information on how they handle your data.
8 Your Rights
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data. You can update most information directly through Clerk's account management.
- Deletion: Request deletion of your personal data, subject to our legal obligations to retain certain records (financial transactions, order history).
- Data Portability: Request your data in a machine-readable format.
- Withdraw Consent: Opt out of non-essential communications through your notification settings.
- Restrict Processing: Request that we limit how we use your data in certain circumstances.
To exercise any of these rights, contact us at support@cosmictrd.com. We will respond within 30 days.
9 Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Account Information | Until account deletion | Service operation |
| Order & Transaction Records | 7 years after completion | Legal & tax compliance |
| Payment Records | 7 years | Financial regulations |
| Communication Logs | 3 years | Dispute resolution |
| Usage Analytics | 2 years | Platform improvement |
| KYC Documents | 5 years after loan closure | Regulatory compliance |
10 Children's Privacy
Our platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a person under 18, we will take steps to delete that information promptly.
11 International Data Transfers
As a China-to-Bangladesh trading platform, your data may be processed in multiple jurisdictions. Specifically:
- Order and shipping data is shared with our operations team in China for fulfillment.
- Authentication data is processed by Clerk (United States).
- CDN and security data is processed by Cloudflare (global network).
We ensure that any international data transfers are conducted with appropriate safeguards to protect your information.
12 Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. We will notify you of significant changes through:
- A prominent notice on the platform
- Email notification to your registered address
- Updating the "Last Updated" date at the top of this page
We recommend reviewing this policy periodically. Your continued use of the platform after changes constitutes acceptance of the updated policy.
13 Contact Us
For any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:
- Company: Cosmic Trading (CosmicTRD)
- Email: support@cosmictrd.com
- Platform: cosmictrd.io
- WhatsApp: Available via the platform chat widget
We aim to respond to all privacy-related inquiries within 30 business days.
