Last Updated: July 2026
We at X4U Marketplace are committed to providing transparency regarding how we handle data. We operate under a strict privacy-first framework designed to guarantee secure transactions while protecting the anonymity of honest buyers and sellers.
We do not collect personal identifiers such as physical addresses, social media profiles, or financial credentials unless required for active escrow transaction settlements.
- No Commercial Trackers: The Platform does not execute third-party ad network scripts, tracking pixels, or data collection telemetry.
- Encrypted Storage: Any credentials, chat histories, or trade proofs submitted during an active transaction are encrypted at rest and stored securely.
To process cryptocurrency transactions securely and audit settlements:
- Public Ledger Data: We record public blockchain wallet addresses and transaction hashes (TXIDs) for deposits and payouts. This data is permanently recorded on public blockchains.
- No Linkage to PII: We do not link blockchain transaction records with real-world names, physical addresses, or personal identities.
During a P2P trade (for game accounts, app keys, or gift cards):
- Active Trade Data: All correspondence inside transaction chat rooms and details of account transfers are stored temporarily to facilitate escrow resolution.
- Arbitration Access: This data is only accessible to Platform administrators if a trade dispute is raised.
- Automatic Purge: Once a transaction is completed and the verification period expires without disputes, active chat room history and transaction documents are automatically pruned from our system within 30 days.
Most of our secure utilities (including Authenticator, Password Generator, and Spreadsheet De-merger) process data completely offline inside your local browser sandbox.
- No Server Transfers: No secrets, seeds, or files are ever transmitted to or processed by our servers.
- No Third-Party Handover: Because we do not store or compile these details, it is structurally impossible for us to share or handover user credentials to any external entity or game publisher.
To maintain Platform security and prevent DDoS attacks, automated dictionary scans, and payment fraud:
- Standard server engines record metadata, including request timestamps, user-agent strings, and masked IP headers.
- These security logs are stored in encrypted vaults and automatically deleted within 14 days, except when flagged for fraud investigations.
To prevent P2P trading fraud (such as reclaiming sold game accounts, using invalid gift cards, or distributing cloned keys):
- Seller Fraud Exemption: In the event that a Seller retrieves/reclaims a sold game account, or delivers fraudulent gift card codes, the Platform reserves the absolute right to disclose transaction identifiers, log files, wallet addresses, and masked IP records to the defrauded Buyer or relevant cyber-crime authorities to facilitate legal recourse.
- Standard Disclosure: For honest users, we do not share network logs or transaction data with third parties unless compelled by a valid, legally binding court order issued by a competent court of law, determined in our sole and absolute discretion.
Our server engines, reverse proxy configurations, and CDNs are distributed globally. Physical server locations (Vietnam, offshore, or bulletproof nodes) are kept strictly confidential to defend physical assets from external harassment.