Legal
Privacy Policy
1. Who is responsible
1.1 XAGlobal, registered in Thailand, of 108/1 Moo. 2, Umphur Chawang, Thambon NaGaCha, Nakorn Sri Thammarat, Thailand, 80150 ("XAG", "we", "us") runs this website and our business apps and developer tools (together, "the Services").
1.2 We have two roles:
- For our own data about visitors, account holders, billing and technical records, we decide why and how the data is used. In the language of Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA"), we are the "data controller" for that data.
- For information that you put into a Service about your own clients, leads, members, staff or contacts, you decide why and how it is used, and we process it for you. For that data, we are the "data processor".
1.3 If you are a client or contact of one of our customers and you want to know what that business holds about you, please ask that business first. We will help them answer you.
1.4 This policy says what we commit to doing. It is written with the PDPA as its baseline. We do not claim any certification or approval under any law or scheme.
1.5 The Services are in private preview, and sign-ups are closed for now. This policy covers the Services as they run today and will be updated as they change.
2. What we collect
2.1 When you visit this website. We do not ask you to create an account. We do not set cookies. The website loads everything from our own address and makes no requests to other companies. Like any website, our hosting provider handles technical request data such as your IP address, browser type, the page requested and the time.
2.2 When you write to us. If you email hello@xaglobal.stream, we receive your email address, your name if you give it, and whatever you write. Emails sent to this address reach the person who runs XAG through an email forwarding and inbox service.
2.3 Account data. When you have an account, we hold your email address, your name if you give it, your workspace or company name, your role, whether you have confirmed your email, and your password as a one-way hash, which means we cannot read it. If you are invited to a workspace, we also hold the invitation (your email address and role).
2.4 Billing data. Stripe handles payments. We keep your Stripe customer and subscription identifiers, your plan status and your trial dates. Your card details go to Stripe and never to us. When you check out, we send Stripe your email address and an identifier for your workspace and product.
2.5 Your Data. This is what you or your team put into a Service. In business apps it can include names, email addresses, phone numbers, postal and site addresses, notes, quotes, invoices, deals, memberships, licence and certificate details, review text and reviewer names, and message templates. In developer tools it can include web addresses and settings you register, such as API endpoints and webhook addresses, headers and signing secrets (stored encrypted), and the events, costs, spending decisions, dispute records and other data that your programs send to our API. Some developer tools are built to avoid storing sensitive values, for example by storing a one-way hash, a data shape or a credential's name instead of the value itself. If you want to know what a tool stores, ask us at hello@xaglobal.stream. Please do not send us secrets or personal data that the tool does not need, and do not enter sensitive data such as payment card numbers, passwords, government ID numbers or medical records.
2.6 Usage, audit and notification records. We keep counts of what you use (for example checks, decisions or drafts), a log of important actions in your workspace (such as sign-up, invitations, API key creation and password changes, with details like the email address involved), and the notices we show you in the Service.
2.7 Technical and error records. When something goes wrong, we record an error reference, the error message, the page or path, the request method, the status, the app version and your browser type (user agent). We also record slow responses, rejected sign-in attempts and server health checks. If you press "Report a problem", we record the message you write. We do not write passwords or the contents of requests to our logs. Our application does not save your IP address in our database. It uses it briefly in memory to limit abuse, and our hosting providers may keep it in their logs.
2.8 Emails and texts. We send emails such as email confirmation, password reset, invitations, alerts, reminders and digests. Some Services also send emails or texts to your own contacts on your behalf, for example review requests, quotes, payment reminders and follow-ups. We use the contact details that you gave us for that purpose.
2.9 Passwords. When you choose a new password, we check it against a public list of leaked passwords without sending the password itself or your email address. Only the first five characters of a one-way hash leave our server. Section 4 gives the details.
2.10 What we do not collect. We do not use advertising identifiers, we do not track your location, and we do not ask for payment card numbers or sensitive personal data.
3. Why we use your data, and our legal basis
3.1 The PDPA requires a legal basis for each use of personal data. These are ours:
- To create your account, run the Services and give you support. Legal basis: it is needed to carry out our contract with you.
- To take payments, keep accounting and tax records and meet other legal duties. Legal basis: legal obligation, and our contract with you.
- To keep the Services secure, prevent abuse, find and fix errors, and keep the Services working. Legal basis: our legitimate interests, which we balance against your rights.
- To answer your emails and requests. Legal basis: our legitimate interests, and our contract with you where you are a customer.
- To tell you about changes to the Services or these policies. Legal basis: our contract with you, and our legitimate interests.
- To do anything else, we will ask for your consent first. You can withdraw consent at any time. We do not send marketing emails at the moment.
3.2 For Your Data, we use it only to run the Services for you, on your instructions. You are responsible for having a lawful basis to put it in.
3.3 We do not sell personal data and we do not use it for advertising. A person reviews any AI draft before it is used. Some developer tools apply rules that you set, for example to allow or block a spend or to settle a dispute between two parties. They act on your rules, not on ours.
4. Who we share your data with
4.1 We share data only with providers that help us run the Services, and only as needed. At the moment, these are:
- Supabase: our database provider. It stores account data, Your Data and technical records. Its servers may be outside Thailand.
- Render: runs our product servers. Its servers may be outside Thailand.
- Vercel: hosts this website and our products' websites, and triggers scheduled jobs. It handles request data such as IP address and browser type.
- Stripe: processes subscription payments. Stripe also uses some data for its own legal duties, such as fraud prevention. Our Stripe account is registered in Thailand.
- Our email service provider: we send our emails, such as email confirmations, password resets, invitations and alerts, through a third-party email service, which handles the addresses and content of those emails.
- Anthropic: an AI provider, used only by products that have an AI feature and only when the feature is switched on. For example, a review-reply feature sends it the review text, the reviewer's name, the star rating, the name of the review site and the business name to draft a reply.
- Twilio: sends text messages. Only products with a text feature use it, and only when the feature is switched on. It receives the phone number and the message.
- GitHub: hosts our source code and may also hold encrypted backups of our database.
- Have I Been Pwned: a public service that checks whether a password has leaked. It receives only the first five characters of a one-way hash of the password, so it cannot tell which password or whose account it is.
- Cloudflare: where a product's website has a connection check and cannot reach its own server, your browser makes one connection test to a Cloudflare address so that the page can tell whether your internet is down. Cloudflare can see your IP address in that request, like any website you visit.
- Our email forwarding and inbox provider, for messages sent to hello@xaglobal.stream.
4.2 We may also share data with professional advisers, with authorities when the law requires it, and with a buyer if we sell or reorganise our business, if your data stays protected as this policy describes.
4.3 We expect our providers to use the data only to provide their service to us, under their own terms and privacy commitments.
5. Moving data between countries
5.1 Our providers run servers in several countries, which may include the United States and other countries outside Thailand. Your data may therefore be processed outside Thailand and outside your own country.
5.2 When we send personal data abroad, we use only what is needed, we choose providers that publish security and privacy commitments, and we use encrypted connections. We aim to have contractual safeguards in place that meet the PDPA's rules on sending data abroad.
6. How long we keep data
6.1 Account and workspace data: while your account is open. When you ask us in writing to close your account or delete your data, we will do it within 30 days, except for what the law requires us to keep.
6.2 Backups: we may keep encrypted backups of our database. We keep each one for up to 30 days, so deleted data leaves them within that time.
6.3 Billing and tax records: as long as tax and accounting law requires.
6.4 Some developer tools delete old technical data automatically, for example check results after 90 days, a check log after 30 days, and raw cost events after about 40 days, while hourly totals are kept.
6.5 Error, audit and health records: we aim to keep them for no longer than 12 months. If you ask us in writing to delete records about you, we will act on your request within 30 days.
6.6 Emails to hello@xaglobal.stream: as long as needed to deal with your request, and then up to 2 years.
6.7 Sign-in sessions end after 30 days, or when you change or reset your password. Invitation links last 7 days, password reset links last 1 hour and email confirmation links last 2 days.
7. How we keep data safe
7.1 These are the main measures we use.
- Our websites and servers use encrypted connections (HTTPS), and we tell browsers to always use them.
- Passwords are stored as one-way hashes. They must be at least 10 characters and are checked against a list of leaked passwords.
- Sign-in tokens are signed, expire after 30 days and stop working when you change your password.
- API keys, invitation links, reset links and confirmation links are stored only as one-way hashes. An API key is shown once, when you create it.
- Some tools store sensitive settings, such as headers you register, encrypted.
- Each workspace's data is kept separate in our application, and browsers cannot read our database directly.
- We limit how often sign-in and API calls can be made, to slow down abuse.
- Our servers refuse to be pointed at private or internal network addresses.
- We do not write passwords or request contents to our logs.
- We limit access to our production systems and data to the people who need it to run the Services.
7.2 No online service is completely secure, and we cannot promise that nothing will ever go wrong. If a breach affects your personal data, we will tell you without undue delay and notify the authorities as the law requires.
8. Your rights and how to use them
8.1 Under the PDPA, and under similar laws elsewhere, you may have the right to:
- ask for access to your personal data and for a copy of it;
- ask us to correct data that is wrong or out of date;
- ask us to delete your data;
- ask us to limit how we use your data;
- object to a use of your data;
- ask for your data in a form you can move to another service;
- withdraw consent where we rely on it.
8.2 To use any of these rights, email hello@xaglobal.stream. We may need to check that you are who you say you are. We will answer within 30 days. We do not charge for ordinary requests.
8.3 If your request is about Your Data, which we process for a customer, we may pass it to that customer so they can answer.
8.4 If you are not happy with how we handled your data, please tell us first. You may also complain to Thailand's Personal Data Protection Committee, or to the data protection authority in the country where you live.
9. Cookies and tracking on this website
9.1 This website sets no cookies. It has no analytics, advertising or tracking tools, and it loads no scripts, fonts, images or other files from other companies.
9.2 The website uses your browser's session storage for one item, called "xag-intro". It remembers that you have already seen the opening animation during this visit. It stays in your browser, we never receive it, and it is cleared when you close the tab or browser.
9.3 The website reads a few of your device settings, such as reduced motion, data saver and reduced transparency, to adjust its animation. They are used on your device only and are not sent anywhere.
9.4 A small light in the top bar shows whether your connection is working. It does this by asking our own website for one of its own files every 60 seconds while the page is open, and when your connection changes. The request goes only to our own website and carries nothing beyond what every web request carries, such as your IP address.
9.5 Our products' websites set no cookies and have no analytics or advertising tools. They keep your sign-in token and your chosen workspace in your browser's local storage so that you stay signed in, and some keep your language or display currency. You can clear these from your browser settings, which signs you out.
10. Children
10.1 The Services are for businesses and for adults aged 18 or over. They are not meant for children, and we do not knowingly collect personal data from children. If you think a child has given us personal data, please tell us and we will delete it.
11. If you are in the EU, the UK or Australia
11.1 This part is a short note for people in those places. It does not add to or replace the rest of this policy.
- EU and UK: where the GDPR or the UK GDPR applies to you, the controller is the business named in section 1. Our legal bases are those in section 3. You may complain to your local data protection authority. For transfers out of the EU or the UK, we aim to use recognised safeguards such as standard contractual clauses.
- Australia: if the Privacy Act 1988 applies, you may complain to the Office of the Australian Information Commissioner. We will notify eligible data breaches as the law requires.
12. Changes to this policy
12.1 We may update this policy. When we do, we change the "Last updated" date at the top.
12.2 For changes that matter, we will tell you by email or in the Service at least 14 days before they take effect.
13. Contact
13.1 Questions, requests and complaints: hello@xaglobal.stream.
13.2 XAGlobal, registered in Thailand, 108/1 Moo. 2, Umphur Chawang, Thambon NaGaCha, Nakorn Sri Thammarat, Thailand, 80150.