Explore
Crea AI
About Us
PRODUCT

Integrations

The third-party infrastructure behind Crestox — what we connect with, what data is shared, and why.

Last updated · June 8, 2026

The Infrastructure Behind Crestox

Crestox connects with a carefully selected set of third-party services to deliver payments, identity verification, communications, and platform security. Every integration is chosen based on reliability, regulatory standing, and data protection standards.

This page explains what external systems Crestox connects with, what data is shared with each, and what that means for you as a user.

Third-Party Disclosure Notice: Crestox shares certain user data with third-party service providers solely to the extent necessary to operate the platform. All data sharing is governed by Crestox's Privacy Policy, the applicable Terms of Use, and the data processing agreements in place with each provider. Crestox does not sell user data to third parties. Third-party providers operate under their own terms of service and privacy policies, which are linked in the relevant sections below.


Table of Contents

  1. Payments
  2. Identity & Verification (KYC)
  3. Communications
  4. Security & Authentication
  5. Future Integrations
  6. API Ecosystem
  7. Data Sharing Summary

1. Payments

How Crestox processes transactions securely.

All financial transactions on the Crestox platform — including fractal purchases, resale proceeds, and artist payouts — are processed through regulated payment infrastructure. Crestox does not store, process, or transmit payment card data directly. All sensitive payment data is handled exclusively by our payment providers in accordance with applicable Payment Card Industry (PCI-DSS) standards.

Payment Gateway

Detail Information
Provider (Payment gateway partner — to be published upon commercial agreement confirmation)
Purpose Processing collector purchases, secondary market transactions, and platform fee collection
Data Shared Transaction amount, currency, user identifier, device metadata
Data NOT Shared Full card numbers, CVV codes, bank account credentials
Regulatory Standard PCI-DSS compliant
Provider Privacy Policy (Link to be added)

Payouts & Banking Infrastructure

Detail Information
Provider (Banking or payout infrastructure partner — to be published upon confirmation)
Purpose Processing artist and owner earnings payouts to registered bank accounts
Data Shared Verified account holder name, bank account details (as provided by the user during KYC), payout amount
Regulatory Standard Reserve Bank of India (RBI) compliant payment processing
Provider Privacy Policy (Link to be added)

Notice: Crestox processes all payments in Indian Rupees (INR). Currency conversion, international wire transfers, and cross-border payments are not currently supported. Payout timelines are governed by the terms of the relevant Artist Agreement or Owner Agreement and are subject to the processing schedules of the payout infrastructure provider. Crestox is not liable for delays caused by banking infrastructure partners.


2. Identity & Verification (KYC)

How Crestox verifies users and meets regulatory obligations.

Crestox is required to verify the identity of users who transact on the platform. This is a regulatory compliance requirement under applicable Indian financial regulations and is intended to protect the platform and its users from fraud, money laundering, and identity misrepresentation.

Know Your Customer (KYC) verification is mandatory for:

KYC Provider

Detail Information
Provider (KYC / identity verification partner — to be published upon confirmation)
Purpose Document verification, identity confirmation, liveness checks, and PAN/Aadhaar validation where applicable
Data Shared Government-issued ID documents (as uploaded by the user), name, date of birth, address, facial biometric data (where liveness check is required)
Data Retention by Provider Governed by the provider's data retention policy — refer to their Privacy Policy
Regulatory Basis Prevention of Money Laundering Act (PMLA), RBI KYC directions
Provider Privacy Policy (Link to be added)

What Happens to Your KYC Data

Important: Failure to complete KYC will result in restricted account functionality. Specifically, collectors who have not completed KYC cannot complete fractal purchases, and artists who have not completed KYC will not receive payouts regardless of sales activity. Crestox cannot waive KYC requirements on individual request.


3. Communications

How Crestox sends you notifications, updates, and transactional messages.

Crestox uses third-party communication infrastructure to deliver email notifications, in-app alerts, and transactional messages. These services are used solely to communicate platform activity to users. Crestox does not use these providers for third-party advertising or data monetisation.

Email Infrastructure

Detail Information
Provider (Email infrastructure partner — to be published upon confirmation)
Purpose Transactional emails (purchase confirmations, payout notifications, submission status updates, account security alerts) and platform communications
Data Shared Email address, user name, transaction or event reference, notification content
Marketing Emails Sent only to users who have opted in. Opt-out is available at any time from account settings or via the unsubscribe link in any marketing email.
Provider Privacy Policy (Link to be added)

Push & In-App Notifications

Detail Information
Purpose Real-time alerts for fractal purchases, resale activity, submission status changes, and security events
Control Notification preferences can be managed in your account settings at any time
Data Shared Device token (anonymised), notification content, user identifier

Transactional vs. Marketing Communications: Transactional messages — including purchase confirmations, payout receipts, KYC status updates, and security alerts — are sent to all registered users and cannot be disabled, as they are necessary for the operation of your account. Marketing and promotional communications are opt-in only.


4. Security & Authentication

How Crestox protects your account and the platform.

Authentication

Detail Information
Method Email and password authentication with mandatory two-factor authentication (2FA) for all accounts
2FA Provider Time-based one-time passwords (TOTP) via authenticator app, or SMS OTP
Session Management Sessions expire after a defined period of inactivity. Concurrent session limits apply.
Password Storage Passwords are never stored in plain text. All passwords are hashed using industry-standard cryptographic methods.

Platform Security Monitoring

Detail Information
Purpose Detection of fraudulent activity, unauthorised access attempts, unusual transaction patterns, and platform abuse
Data Used IP address, device fingerprint, session metadata, transaction patterns
User Impact Accounts flagged by monitoring systems may be temporarily restricted pending review. Users will be notified and given the opportunity to verify their identity.

Data Encryption

Detail Information
Data in Transit All data transmitted between your device and Crestox servers is encrypted using TLS 1.2 or higher
Data at Rest Sensitive user data stored on Crestox infrastructure is encrypted at rest

Security Incident Notification: In the event of a confirmed data breach affecting your personal information, Crestox will notify affected users in accordance with applicable data protection law, including the provisions of the Digital Personal Data Protection Act, 2023 (India). For the full security policy, refer to our Privacy Policy.


5. Future Integrations

Crestox is building institutional and cultural partnerships to expand the quality and depth of artwork available on the platform, and to create new onboarding pathways for artists and collectors.

The following categories represent integration directions under active development or consideration. These are disclosed here for transparency with enterprise partners, institutions, and developers evaluating the platform.

Galleries

Integration Type Purpose
Commercial Gallery Partnerships Enable galleries to onboard their represented artists and submit artworks directly through a dedicated gallery account tier
Artwork Sourcing Facilitate co-listing arrangements where gallery-authenticated artworks are made available for fractionalization on Crestox

Status: Under development. No partner announcements at this time.


Museums & Cultural Institutions

Integration Type Purpose
Collection Partnerships Explore fractionalization of museum-owned or deaccessioned works in compliance with applicable cultural property regulations
Heritage Collaborations Partner with cultural institutions to bring historically significant artworks to the Crestox platform under appropriate licensing and provenance frameworks

Status: Exploratory. Subject to regulatory, legal, and institutional approval processes.

Notice on Cultural Property: Any artwork sourced through institutional partnerships will be subject to the same submission review, authenticity verification, and grading process applied to all listings on Crestox. Crestox will not list artworks that are subject to unresolved repatriation claims, cultural property disputes, or export restrictions under applicable law.


Universities & Academic Institutions

Integration Type Purpose
Artist Onboarding Pipelines Partner with art schools and universities to create verified onboarding pathways for emerging artists, including expedited profile review
Residency & Grant Documentation Enable academic achievement records to be submitted as part of artist verification

Status: Exploratory. Partnership terms to be developed.


Enterprise & Investor API Access

See API Ecosystem below.


6. API Ecosystem

Programmatic access to Crestox data and functionality.

Current Status

Crestox does not currently offer a public API. Platform data and functionality are accessible exclusively through the Crestox web and mobile applications.

Planned: Private API Access

Crestox intends to release a private API for approved enterprise partners, institutional investors, and accredited developers. This is currently under development.

The planned API will provide:

Capability Description
Read Access — Marketplace Data Programmatic access to approved artwork listings, fractal availability, and aggregated price data
Read Access — Portfolio Data Access to your own fractal holdings and transaction history (scoped to the authenticated account only)
Write Access — Transactions Fractal purchase and listing management via API, subject to the same KYC and compliance requirements as platform transactions
Webhook Notifications Event-driven notifications for transaction completions, listing status changes, and portfolio updates

Authentication (Planned)

API access will use OAuth 2.0 with scoped access tokens. All API requests will require:

Developer Documentation

Developer documentation will be published at developers.crestox.com at the time of API launch. Documentation will include endpoint references, authentication guides, rate limits, error codes, and code examples.

API Access Notice: Access to the Crestox API will be subject to a separate API Terms of Service and, where applicable, a signed Data Processing Agreement. API access will not be granted to accounts that have not completed KYC verification. Crestox reserves the right to revoke API access for violation of the API Terms of Service, platform misuse, or security concerns, with or without prior notice depending on the nature of the violation.


7. Data Sharing Summary

A consolidated reference of all third-party data sharing in one place.

Provider Category Data Shared Purpose User Can Opt Out?
Payment Gateway Transaction amount, user ID, device metadata Process fractal purchases and fees No — required to transact
Payout Infrastructure Account holder name, bank details, payout amount Deliver artist and owner earnings No — required to receive payouts
KYC / Identity Verification Government ID, name, DOB, address, biometric (liveness) Regulatory identity verification No — required to transact
Email Infrastructure Email address, notification content Transactional and opted-in marketing emails Partial — marketing only
Security Monitoring IP address, device fingerprint, session data Fraud detection and platform security No — required for platform integrity
Push Notifications Device token, notification content Real-time platform alerts Yes — via account settings

For full details on data collection, retention, and your rights as a data subject under the Digital Personal Data Protection Act, 2023, refer to the Privacy Policy.


Questions About Integrations or Data Sharing?

If you have questions about how Crestox uses third-party services or how your data is handled, contact us:

To submit a formal data access, correction, or deletion request, use the process described in the Privacy Policy.


Last updated: June 2026 Integration details, provider names, and API specifications are subject to change. This page will be updated as partnerships are confirmed and new integrations are launched.

← Back to Home