The Infrastructure Behind Crestox
Crestox connects with a carefully selected set of third-party services to deliver payments, identity verification, communications, and platform security. Every integration is chosen based on reliability, regulatory standing, and data protection standards.
This page explains what external systems Crestox connects with, what data is shared with each, and what that means for you as a user.
Third-Party Disclosure Notice: Crestox shares certain user data with third-party service providers solely to the extent necessary to operate the platform. All data sharing is governed by Crestox's Privacy Policy, the applicable Terms of Use, and the data processing agreements in place with each provider. Crestox does not sell user data to third parties. Third-party providers operate under their own terms of service and privacy policies, which are linked in the relevant sections below.
Table of Contents
- Payments
- Identity & Verification (KYC)
- Communications
- Security & Authentication
- Future Integrations
- API Ecosystem
- Data Sharing Summary
1. Payments
How Crestox processes transactions securely.
All financial transactions on the Crestox platform — including fractal purchases, resale proceeds, and artist payouts — are processed through regulated payment infrastructure. Crestox does not store, process, or transmit payment card data directly. All sensitive payment data is handled exclusively by our payment providers in accordance with applicable Payment Card Industry (PCI-DSS) standards.
Payment Gateway
| Detail | Information |
|---|---|
| Provider | (Payment gateway partner — to be published upon commercial agreement confirmation) |
| Purpose | Processing collector purchases, secondary market transactions, and platform fee collection |
| Data Shared | Transaction amount, currency, user identifier, device metadata |
| Data NOT Shared | Full card numbers, CVV codes, bank account credentials |
| Regulatory Standard | PCI-DSS compliant |
| Provider Privacy Policy | (Link to be added) |
Payouts & Banking Infrastructure
| Detail | Information |
|---|---|
| Provider | (Banking or payout infrastructure partner — to be published upon confirmation) |
| Purpose | Processing artist and owner earnings payouts to registered bank accounts |
| Data Shared | Verified account holder name, bank account details (as provided by the user during KYC), payout amount |
| Regulatory Standard | Reserve Bank of India (RBI) compliant payment processing |
| Provider Privacy Policy | (Link to be added) |
Notice: Crestox processes all payments in Indian Rupees (INR). Currency conversion, international wire transfers, and cross-border payments are not currently supported. Payout timelines are governed by the terms of the relevant Artist Agreement or Owner Agreement and are subject to the processing schedules of the payout infrastructure provider. Crestox is not liable for delays caused by banking infrastructure partners.
2. Identity & Verification (KYC)
How Crestox verifies users and meets regulatory obligations.
Crestox is required to verify the identity of users who transact on the platform. This is a regulatory compliance requirement under applicable Indian financial regulations and is intended to protect the platform and its users from fraud, money laundering, and identity misrepresentation.
Know Your Customer (KYC) verification is mandatory for:
- Collectors before their first fractal purchase
- Artists before their first payout is processed
- Owners before artwork listings are approved
- Curators before they are authorised to manage listings
KYC Provider
| Detail | Information |
|---|---|
| Provider | (KYC / identity verification partner — to be published upon confirmation) |
| Purpose | Document verification, identity confirmation, liveness checks, and PAN/Aadhaar validation where applicable |
| Data Shared | Government-issued ID documents (as uploaded by the user), name, date of birth, address, facial biometric data (where liveness check is required) |
| Data Retention by Provider | Governed by the provider's data retention policy — refer to their Privacy Policy |
| Regulatory Basis | Prevention of Money Laundering Act (PMLA), RBI KYC directions |
| Provider Privacy Policy | (Link to be added) |
What Happens to Your KYC Data
- KYC documents and verification results are stored in accordance with Crestox's Privacy Policy and applicable legal retention requirements.
- Crestox does not use your KYC documents for any purpose other than identity verification and regulatory compliance.
- Verified status is recorded on your Crestox account. If your KYC is rejected, you will be notified and given the opportunity to resubmit with corrected documentation.
- Crestox does not share KYC data with other users, artists, collectors, or third parties other than the KYC provider and, where legally required, regulatory authorities.
Important: Failure to complete KYC will result in restricted account functionality. Specifically, collectors who have not completed KYC cannot complete fractal purchases, and artists who have not completed KYC will not receive payouts regardless of sales activity. Crestox cannot waive KYC requirements on individual request.
3. Communications
How Crestox sends you notifications, updates, and transactional messages.
Crestox uses third-party communication infrastructure to deliver email notifications, in-app alerts, and transactional messages. These services are used solely to communicate platform activity to users. Crestox does not use these providers for third-party advertising or data monetisation.
Email Infrastructure
| Detail | Information |
|---|---|
| Provider | (Email infrastructure partner — to be published upon confirmation) |
| Purpose | Transactional emails (purchase confirmations, payout notifications, submission status updates, account security alerts) and platform communications |
| Data Shared | Email address, user name, transaction or event reference, notification content |
| Marketing Emails | Sent only to users who have opted in. Opt-out is available at any time from account settings or via the unsubscribe link in any marketing email. |
| Provider Privacy Policy | (Link to be added) |
Push & In-App Notifications
| Detail | Information |
|---|---|
| Purpose | Real-time alerts for fractal purchases, resale activity, submission status changes, and security events |
| Control | Notification preferences can be managed in your account settings at any time |
| Data Shared | Device token (anonymised), notification content, user identifier |
Transactional vs. Marketing Communications: Transactional messages — including purchase confirmations, payout receipts, KYC status updates, and security alerts — are sent to all registered users and cannot be disabled, as they are necessary for the operation of your account. Marketing and promotional communications are opt-in only.
4. Security & Authentication
How Crestox protects your account and the platform.
Authentication
| Detail | Information |
|---|---|
| Method | Email and password authentication with mandatory two-factor authentication (2FA) for all accounts |
| 2FA Provider | Time-based one-time passwords (TOTP) via authenticator app, or SMS OTP |
| Session Management | Sessions expire after a defined period of inactivity. Concurrent session limits apply. |
| Password Storage | Passwords are never stored in plain text. All passwords are hashed using industry-standard cryptographic methods. |
Platform Security Monitoring
| Detail | Information |
|---|---|
| Purpose | Detection of fraudulent activity, unauthorised access attempts, unusual transaction patterns, and platform abuse |
| Data Used | IP address, device fingerprint, session metadata, transaction patterns |
| User Impact | Accounts flagged by monitoring systems may be temporarily restricted pending review. Users will be notified and given the opportunity to verify their identity. |
Data Encryption
| Detail | Information |
|---|---|
| Data in Transit | All data transmitted between your device and Crestox servers is encrypted using TLS 1.2 or higher |
| Data at Rest | Sensitive user data stored on Crestox infrastructure is encrypted at rest |
Security Incident Notification: In the event of a confirmed data breach affecting your personal information, Crestox will notify affected users in accordance with applicable data protection law, including the provisions of the Digital Personal Data Protection Act, 2023 (India). For the full security policy, refer to our Privacy Policy.
5. Future Integrations
Crestox is building institutional and cultural partnerships to expand the quality and depth of artwork available on the platform, and to create new onboarding pathways for artists and collectors.
The following categories represent integration directions under active development or consideration. These are disclosed here for transparency with enterprise partners, institutions, and developers evaluating the platform.
Galleries
| Integration Type | Purpose |
|---|---|
| Commercial Gallery Partnerships | Enable galleries to onboard their represented artists and submit artworks directly through a dedicated gallery account tier |
| Artwork Sourcing | Facilitate co-listing arrangements where gallery-authenticated artworks are made available for fractionalization on Crestox |
Status: Under development. No partner announcements at this time.
Museums & Cultural Institutions
| Integration Type | Purpose |
|---|---|
| Collection Partnerships | Explore fractionalization of museum-owned or deaccessioned works in compliance with applicable cultural property regulations |
| Heritage Collaborations | Partner with cultural institutions to bring historically significant artworks to the Crestox platform under appropriate licensing and provenance frameworks |
Status: Exploratory. Subject to regulatory, legal, and institutional approval processes.
Notice on Cultural Property: Any artwork sourced through institutional partnerships will be subject to the same submission review, authenticity verification, and grading process applied to all listings on Crestox. Crestox will not list artworks that are subject to unresolved repatriation claims, cultural property disputes, or export restrictions under applicable law.
Universities & Academic Institutions
| Integration Type | Purpose |
|---|---|
| Artist Onboarding Pipelines | Partner with art schools and universities to create verified onboarding pathways for emerging artists, including expedited profile review |
| Residency & Grant Documentation | Enable academic achievement records to be submitted as part of artist verification |
Status: Exploratory. Partnership terms to be developed.
Enterprise & Investor API Access
See API Ecosystem below.
6. API Ecosystem
Programmatic access to Crestox data and functionality.
Current Status
Crestox does not currently offer a public API. Platform data and functionality are accessible exclusively through the Crestox web and mobile applications.
Planned: Private API Access
Crestox intends to release a private API for approved enterprise partners, institutional investors, and accredited developers. This is currently under development.
The planned API will provide:
| Capability | Description |
|---|---|
| Read Access — Marketplace Data | Programmatic access to approved artwork listings, fractal availability, and aggregated price data |
| Read Access — Portfolio Data | Access to your own fractal holdings and transaction history (scoped to the authenticated account only) |
| Write Access — Transactions | Fractal purchase and listing management via API, subject to the same KYC and compliance requirements as platform transactions |
| Webhook Notifications | Event-driven notifications for transaction completions, listing status changes, and portfolio updates |
Authentication (Planned)
API access will use OAuth 2.0 with scoped access tokens. All API requests will require:
- A valid API key issued to an approved developer or enterprise account
- Bearer token authentication on every request
- Requests over HTTPS only — unencrypted connections will be rejected
Developer Documentation
Developer documentation will be published at developers.crestox.com at the time of API launch. Documentation will include endpoint references, authentication guides, rate limits, error codes, and code examples.
API Access Notice: Access to the Crestox API will be subject to a separate API Terms of Service and, where applicable, a signed Data Processing Agreement. API access will not be granted to accounts that have not completed KYC verification. Crestox reserves the right to revoke API access for violation of the API Terms of Service, platform misuse, or security concerns, with or without prior notice depending on the nature of the violation.
7. Data Sharing Summary
A consolidated reference of all third-party data sharing in one place.
| Provider Category | Data Shared | Purpose | User Can Opt Out? |
|---|---|---|---|
| Payment Gateway | Transaction amount, user ID, device metadata | Process fractal purchases and fees | No — required to transact |
| Payout Infrastructure | Account holder name, bank details, payout amount | Deliver artist and owner earnings | No — required to receive payouts |
| KYC / Identity Verification | Government ID, name, DOB, address, biometric (liveness) | Regulatory identity verification | No — required to transact |
| Email Infrastructure | Email address, notification content | Transactional and opted-in marketing emails | Partial — marketing only |
| Security Monitoring | IP address, device fingerprint, session data | Fraud detection and platform security | No — required for platform integrity |
| Push Notifications | Device token, notification content | Real-time platform alerts | Yes — via account settings |
For full details on data collection, retention, and your rights as a data subject under the Digital Personal Data Protection Act, 2023, refer to the Privacy Policy.
Questions About Integrations or Data Sharing?
If you have questions about how Crestox uses third-party services or how your data is handled, contact us:
- Email: privacy@crestox.com
- Help Centre: help.crestox.com
- Response Time: Within 5 business days for data-related queries
To submit a formal data access, correction, or deletion request, use the process described in the Privacy Policy.
Last updated: June 2026 Integration details, provider names, and API specifications are subject to change. This page will be updated as partnerships are confirmed and new integrations are launched.