Privacy Policy

1. Data Collected

We collect information that you provide directly to us, including:

  • Account information (name, email address, profile photo)
  • Business data (projects, leads, invoices, timesheets, suppliers)
  • Usage data (how you interact with the Service)
  • Payment information (processed securely through Stripe)

2. How Data is Used

We use your data to:

  • Provide, maintain, and improve the Service
  • Process transactions and send related information
  • Send technical notices and support messages
  • Respond to your comments and questions
  • Monitor and analyze usage patterns

3. Google OAuth Data Handling

When you sign in with Google OAuth, we receive your email address, name, and profile photo. This information is used solely for authentication and account management. We do not access your Google account data beyond what is necessary for authentication.

4. Stripe Billing Information

Payment information is processed securely through Stripe. We do not store your full credit card details. Stripe handles all payment processing in accordance with PCI DSS standards.

5. File Storage

Files you upload to Xische OS are stored securely in Supabase Storage. Files are encrypted at rest and in transit. Each tenant's files are isolated and accessible only to authorized users within that tenant.

6. Cookies

We use essential cookies for authentication and session management. These cookies are necessary for the Service to function properly. We do not use tracking cookies or third-party analytics cookies.

7. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. If you delete your account, we will retain your data for 90 days before permanent deletion, allowing for account recovery if needed.

8. Data Deletion

You can request deletion of your account and all associated data at any time through your account settings. Upon deletion, your data will be permanently removed after the 90-day retention period, except where retention is required by law.

9. Third-Party Processors

We use the following third-party services to operate the Service:

  • Supabase: Database and file storage
  • Stripe: Payment processing
  • Vercel: Hosting and deployment
  • Google: Authentication (OAuth)

All third-party processors are contractually obligated to protect your data and use it only for the purposes we specify.

10. GDPR Rights

If you are located in the European Economic Area, you have the following rights:

  • Right to access your personal data
  • Right to rectify inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing

To exercise these rights, please contact us using the information provided below.

11. Data Security

We implement industry-standard security measures to protect your data, including:

  • Encryption at rest and in transit
  • Row-level security (RLS) for database access
  • Regular security audits and updates
  • Access controls and authentication

12. Contact Information

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at:

Email: privacy@xischeos.com
Address: [Your Company Address]

Last updated: 1/20/2026