1. Core Privacy Principles
Torzon Market operates under a zero-knowledge model. We are technically incapable of identifying, tracking, or profiling users.
- No personal data collection — ever.
- No IP address logging — not even temporarily.
- No session tracking — no cookies, no fingerprints.
- No metadata retention — connection times, durations, or routes are never stored.
We cannot comply with data requests because we have no data to provide.
2. End-to-End Encryption
All communications are protected with military-grade encryption:
- PGP mandatory for vendor-buyer messages and support tickets.
- TLS 1.3 for all .onion connections.
- Forward secrecy ensures past sessions remain secure even if keys are compromised.
- Escrow transactions use multi-signature Bitcoin and Monero with ring signatures.
3. Infrastructure & Logging
Our servers are configured for maximum privacy:
- RAM-only operation — all data wiped on reboot.
- No access logs, error logs, or analytics.
- Self-hosted in privacy-respecting jurisdictions.
- Regular third-party audits (results published via PGP-signed reports).
4. User Data & Account Security
We store only what is strictly necessary — and even that is encrypted:
- Username & PGP public key — stored encrypted at rest.
- 2FA secrets — never in plaintext.
- Escrow wallet addresses — generated per transaction, never reused.
- No email, no phone, no KYC — ever.
You control your data. Delete your account — all traces are permanently erased within 24 hours.
5. Transaction Privacy
We support privacy-first cryptocurrencies:
- Monero (XMR) — default for maximum anonymity (ring signatures, stealth addresses).
- Bitcoin (BTC) — with CoinJoin mixing via integrated wallet.
- Escrow funds held in cold storage multi-sig — never on hot wallets.
- No transaction graph analysis — we do not link inputs to outputs.
6. What We Never Collect
To be absolutely clear — the following are never collected:
- Real names, addresses, or government IDs
- Browsing history or clicked links
- Device fingerprints or hardware IDs
- Referral sources or UTM parameters
- Chat logs beyond active disputes (auto-deleted after 30 days)
7. Third-Party Services
We do not use external analytics, CDNs, or tracking pixels.
- All assets (CSS, JS, fonts) are self-hosted.
- No Google Fonts, no Cloudflare, no external scripts.
- Mirrors are PGP-signed and verified on-chain.
8. Legal Requests & Compliance
We operate in full compliance with privacy laws — but with a critical difference:
- We cannot respond to subpoenas, warrants, or data requests.
- No backdoors, no master keys, no cooperation with surveillance.
- In the event of legal pressure, we will shut down rather than compromise user privacy.
9. Data Retention & Deletion
Minimal retention, automatic deletion:
- Support tickets: deleted 30 days after resolution.
- Dispute logs: deleted 90 days after closure.
- Account deletion: immediate + full wipe within 24 hours.
- Backups: encrypted, rotated weekly, destroyed after 7 days.
10. Contact & Privacy Inquiries
For privacy concerns, audits, or data requests:
privacy@torzon-trust.com
All inquiries must include your PGP public key. Responses are encrypted.
11. Policy Updates
We may update this policy to reflect technical or legal changes.
Significant changes will be announced via PGP-signed message on the platform and mirrors.
Your privacy is non-negotiable. We built Torzon to protect it — not exploit it.