xTrackly

Privacy Policy

Last updated: August 12, 2026

1. Introduction

xTrackly Inc. (“xTrackly,” “we,” “us,” or “our”) operates a cloud-based analytics platform that helps restaurants and food-service businesses understand their sales performance. This Privacy Policy explains how we collect, use, disclose, and protect personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.

By creating an account or using xTrackly, you consent to the practices described in this policy. If you do not agree, do not create an account or use our services.

2. Definitions

  • Subscriber — A business owner or authorized representative who creates an xTrackly account.
  • End Customer — A patron of the Subscriber’s restaurant whose transaction data is processed through a connected POS system.
  • POS Data — Transaction records, order details, and associated customer information imported from point-of-sale integrations (Stripe, Square, Toast, Clover).
  • Personal Information — Information about an identifiable individual, as defined under PIPEDA.

3. Information We Collect

3.1 Subscriber Account Information

When you register, we collect:

  • Email address and password (hashed with bcrypt; we never store plaintext passwords)
  • Full name and phone number (optional)
  • Business name, type, description, and website URL
  • Operating hours, timezone, and currency preference
  • Country and region/province

3.2 POS Transaction Data (End-Customer Information)

When you connect a POS system, we import transaction records that may include End-Customer personal information provided by your POS provider:

  • Customer name, email address, and phone number
  • Geographic location (city, region/province, country)
  • External customer identifiers from the POS system
  • Payment method type (e.g., “credit card,” “debit”) — we do not store card numbers
  • Order details: item names, quantities, prices, discounts, taxes, tips
  • Transaction metadata: timestamps, order type (dine-in, takeout, delivery), server name, table number

Important: As a Subscriber, you are the data controller for your End-Customers’ personal information. You are responsible for ensuring you have the legal basis (including any required notices to your patrons) to share their data with xTrackly for analytics purposes. We process this data solely on your behalf as a data processor.

3.3 Payment Information

Subscription payments are processed entirely by Stripe. We never receive, store, or have access to your credit card number, CVV, or banking details. We store only your Stripe customer ID and subscription ID to manage your billing relationship.

3.4 Automatically Collected Information

  • IP addresses (logged during staff support access for audit purposes)
  • Browser type and device information (via standard HTTP headers)
  • Authentication tokens and session data

3.5 Bug Reports

If you submit a bug report, we collect the title, description, any screenshots you attach, and technical debugging metadata (browser info, timestamps) to diagnose and resolve the issue.

4. How We Use Your Information

We use personal information for the following purposes:

  • Providing the Service: Generating analytics dashboards, charts, reports, and performance metrics from your POS data.
  • AI-Powered Insights: Generating business summaries, suggestions, and answering your questions about your data (see Section 7).
  • Account Management: Authenticating your identity, managing your subscription, and processing payments.
  • Communications: Sending transactional emails (password resets, email verification, account invitations). We do not send marketing emails.
  • Customer Support: Our staff may view your account data to assist you (see Section 6).
  • Service Improvement: Diagnosing bugs, improving performance, and developing new features.
  • Legal Compliance: Responding to legal requests and preventing fraud.

5. Legal Basis for Processing

Under PIPEDA, we process personal information based on:

  • Consent: You provide meaningful consent when you create an account and agree to this Privacy Policy. You may withdraw consent at any time by deleting your account, though this will terminate your access to the Service.
  • Contractual Necessity: Processing is necessary to fulfill our obligations under the Terms of Service — we cannot provide analytics without processing your POS data.
  • Legitimate Interest: We process limited data (IP addresses, access logs) for security, fraud prevention, and service reliability.

6. Staff Support Access

Authorized xTrackly staff with administrator privileges may view your account data for the following purposes:

  • Responding to your support requests
  • Diagnosing technical issues
  • Managing subscription billing (comps, plan changes)
  • Investigating potential fraud or terms violations

Staff access is subject to the following safeguards:

  • Read-Only: Staff can only view your data; they cannot modify your transactions, POS connections, or business profile while viewing your account.
  • Full Audit Trail: Every staff access is logged with the administrator’s identity, your account ID, the specific data accessed (API path), the administrator’s IP address, and a timestamp.
  • Restricted Grant: Administrator privileges cannot be granted through the application interface — they require direct database access, limiting the scope of who can be designated as staff.

You may request a copy of the access log for your account at any time by contacting our Privacy Officer.

7. AI-Powered Features & Third-Party Data Sharing

xTrackly uses Anthropic’s Claude AI to generate business summaries, actionable suggestions, and to answer your questions about your data. When these features are used, the following information is sent to Anthropic’s servers:

  • Your business name, type, country, region, and operating hours
  • Aggregate financial metrics (total revenue, transaction counts, fees — not individual transactions)
  • Top-performing product/menu item names and their aggregate sales figures
  • Daily revenue time series (date and total amount only)
  • Your questions and prior conversation turns (for the chat feature)

What is NOT sent to Anthropic: Individual End-Customer names, email addresses, phone numbers, or any other End-Customer PII. Only aggregate business metrics are shared.

Anthropic processes this data under their own privacy policy and data processing terms. Anthropic does not use API-submitted data to train their models.

AI features are optional. Basic plan subscribers receive AI summaries only; Pro plan subscribers also receive suggestions and chat. The service functions fully without AI features if you prefer not to use them.

8. Other Third-Party Service Providers

  • Stripe: Processes all subscription payments. Receives your email address to create a billing customer record. Subject to Stripe’s Privacy Policy.
  • POS Providers (Square, Toast, Clover): We access your POS data through their APIs using OAuth tokens you authorize. We request read-only access to transactions, orders, and merchant profiles. Each provider’s own privacy policy governs how they handle your data independently of xTrackly.
  • Email Service (Resend/SMTP): Delivers transactional emails on our behalf. Receives only the recipient email address and message content.

We do not sell, rent, or trade personal information to any third party for marketing or advertising purposes.

9. Data Security

We implement the following technical safeguards:

  • Encryption at Rest: POS OAuth access tokens and refresh tokens are encrypted using Fernet symmetric encryption (AES-128-CBC with HMAC-SHA256 verification).
  • Password Hashing: All passwords are hashed with bcrypt before storage. We never store or log plaintext passwords.
  • Encryption in Transit: All connections between your browser and our servers use TLS (HTTPS). API communications with POS providers and Stripe are encrypted.
  • Authentication: API access is protected by JWT tokens with configurable expiration (default: 30 minutes).
  • CORS Protection: Cross-origin requests are restricted to authorized frontend domains.
  • Trusted Host Enforcement: In production, only requests from configured hostnames are accepted.
  • Access Control: Staff administrator access is read-only and fully audited (see Section 6).

10. Data Retention

  • Active Accounts: We retain your data for as long as your account is active and you maintain a subscription.
  • Cancelled Subscriptions: After subscription cancellation, your account and data are retained for 90 days to allow for reactivation. After 90 days, you may request deletion.
  • Deleted Accounts: Upon account deletion request, we delete your personal information, POS data, and transaction records within 30 days. Some data may be retained longer where required by law (e.g., billing records for tax purposes).
  • Audit Logs: Staff access logs are retained for 2 years for accountability purposes.
  • AI-Generated Content: Cached AI summaries and suggestions are tied to your account and deleted when your account is deleted.

11. Your Rights Under PIPEDA

You have the right to:

  • Access: Request a copy of the personal information we hold about you and your End-Customers.
  • Correction: Request correction of inaccurate or incomplete personal information.
  • Withdrawal of Consent: Withdraw your consent to our processing at any time. Note that withdrawing consent will require account deletion, as we cannot provide the Service without processing your data.
  • Complaint: File a complaint with the Office of the Privacy Commissioner of Canada if you believe we have violated your privacy rights.
  • Data Portability: Request an export of your data in a machine-readable format.
  • Deletion: Request deletion of your personal information, subject to legal retention requirements.

To exercise any of these rights, contact our Privacy Officer (see Section 14). We will respond within 30 days.

12. Data Breach Notification

In the event of a data breach involving personal information that creates a real risk of significant harm, we will:

  • Notify the Office of the Privacy Commissioner of Canada as soon as feasible
  • Notify affected individuals directly, describing the nature of the breach, the data involved, steps we are taking, and steps they can take to mitigate harm
  • Maintain records of all breaches for a minimum of 24 months, as required by PIPEDA

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by displaying a prominent notice in the dashboard before the changes take effect. Your continued use of xTrackly after the effective date constitutes acceptance of the updated policy.

14. Privacy Officer & Contact

For privacy inquiries, data access requests, or complaints, contact our Privacy Officer:

xTrackly Inc.

Privacy Officer

Email: privacy@xtrackly.com

15. Jurisdiction

This Privacy Policy is governed by the laws of Canada and the Province of Ontario. Personal information may be stored and processed in Canada. By using xTrackly, you consent to the transfer and processing of your information in Canada.