PLAZI
🇪🇸ES🇺🇸EN🇨🇳ZH
PRIVACY POLICY

Privacy and Data Protection Policy

Plazi SAS · Framework: Colombian Law 1581 of 2012 (Habeas Data)

Last updated: May 21, 2026

At Plazi we respect your privacy and are committed to protecting your personal data. This policy describes what data we collect, how we use it, who we share it with, and what your rights are as a data subject.

1. Data controller

Plazi SAS (hereinafter "Plazi")
NIT: [TO BE ASSIGNED]
Domicile: Bogotá D.C., Colombia
Email: privacy@plazi.co

Plazi acts as Data Controller for personal data collected through the Platform.

2. Personal data we collect

Identification data: first name, last name, document number (ID, NIT, Passport), email, mobile phone.

Location data: delivery address, city, department, country.

Financial data: in card or bank transactions, data is collected directly by Wompi (Bancolombia S.A.); Plazi does not store sensitive payment information.

Browsing data: IP address, device type, browser, pages visited, products viewed, cart items (cookies and analytics tools).

Seller data: additionally, RUT (tax registry), bank account, tax regime, banking certification.

3. Purposes of processing

Plazi collects and processes your personal data to:
1. Operate the account, process Orders, and deliver products
2. Make payments to Sellers and collect payments from Buyers
3. Verify Seller identity (KYC)
4. Send transactional communications (confirmations, order status, support)
5. Marketing and commercial communications (with prior consent)
6. Comply with tax and legal obligations
7. Prevent fraud and protect Platform security
8. Improve service through aggregated and anonymous analytics

We do not use your data for automated profiling with legal effects without your express consent.

4. Data processors (third parties)

Plazi shares strictly necessary data with the following processors, all subject to data processing agreements:

- Supabase Inc. (United States) · database and authentication
- Wompi · Bancolombia S.A. (Colombia) · payment processing
- Resend Inc. (United States) · transactional email
- Vercel Inc. (United States) · Platform hosting
- Servientrega / Coordinadora / other logistics operators (Colombia) · shipping
- Truora SAS (Colombia) · Seller KYC verification
- Sentry (United States) · technical monitoring (no PII)

International transfers are made under contracts ensuring a level of protection equivalent to Colombian law.

5. Retention period

We retain your personal data while your account is active, plus:
- 5 years after account closure for tax obligations
- 10 years for accounting records required by DIAN (Colombian Tax Authority)
- Until expiration of any potential legal claims

After these periods, data is securely anonymized or deleted.

6. Data subject rights

Under Law 1581 of 2012 and Decree 1377 of 2013, you have the right to:

1. Know the data we hold about you
2. Update or rectify inaccurate data
3. Suppress data when you consider it is not processed according to law
4. Request proof of authorization granted to Plazi
5. Revoke authorization and/or request deletion
6. Free access to your data

To exercise these rights, send a request to privacy@plazi.co from your registered email. We will respond within 15 business days per legal procedure.

7. Cookies and similar technologies

We use cookies for:
- Essential: keep your session active, remember your cart
- Analytics: measure site performance (Vercel Analytics)
- Functional: remember preferences (language, city)

You can manage cookies from your browser. Disabling essential cookies may affect Platform functionality.

8. Security

We implement reasonable technical, administrative, and physical security measures to protect your data:
- Encryption in transit (TLS 1.3) and at rest
- Secure authentication (email OTP)
- Database Row-Level Security
- Access auditing
- Encrypted backups

Even with these measures, no Internet transmission is 100% secure. In case of data breach, we will notify affected parties and the SIC within legal timeframes.

9. Minors

Plazi is not directed to minors under 18. We do not knowingly collect minors' data. If we detect minor accounts, we suspend them.

Parents or guardians who detect a minor's account can contact us at privacy@plazi.co for immediate deletion.

10. Changes to this policy

This policy may be updated. We will notify substantial changes at least 15 days in advance. The "Last updated" date above reflects the current version.

11. Supervisory authority

If you do not receive a satisfactory response to your requests, you may file a complaint with the Colombian Superintendence of Industry and Commerce (SIC):
- Web: https://www.sic.gov.co
- Phone: +57 601 587 0000
To exercise your rights or inquire about privacy:
Plazi SAS · Data Protection Officer
📧 privacy@plazi.co
📧 dpo@plazi.co
🏢 Bogotá D.C., Colombia

This document must be reviewed by a data protection lawyer before final publication, especially to ensure full compliance with Law 1581 and internal processing manuals.

← Plazi.co