XAG

Privacy Policy

1. Who is responsible

1.1 XAGlobal, registered in Thailand, of 108/1 Moo. 2, Umphur Chawang, Thambon NaGaCha, Nakorn Sri Thammarat, Thailand, 80150 ("XAG", "we", "us") runs this website and our business apps and developer tools (together, "the Services").

1.2 We have two roles:

1.3 If you are a client or contact of one of our customers and you want to know what that business holds about you, please ask that business first. We will help them answer you.

1.4 This policy says what we commit to doing. It is written with the PDPA as its baseline. We do not claim any certification or approval under any law or scheme.

1.5 The Services are in private preview, and sign-ups are closed for now. This policy covers the Services as they run today and will be updated as they change.

2. What we collect

2.1 When you visit this website. We do not ask you to create an account. We do not set cookies. The website loads everything from our own address and makes no requests to other companies. Like any website, our hosting provider handles technical request data such as your IP address, browser type, the page requested and the time.

2.2 When you write to us. If you email hello@xaglobal.stream, we receive your email address, your name if you give it, and whatever you write. Emails sent to this address reach the person who runs XAG through an email forwarding and inbox service.

2.3 Account data. When you have an account, we hold your email address, your name if you give it, your workspace or company name, your role, whether you have confirmed your email, and your password as a one-way hash, which means we cannot read it. If you are invited to a workspace, we also hold the invitation (your email address and role).

2.4 Billing data. Stripe handles payments. We keep your Stripe customer and subscription identifiers, your plan status and your trial dates. Your card details go to Stripe and never to us. When you check out, we send Stripe your email address and an identifier for your workspace and product.

2.5 Your Data. This is what you or your team put into a Service. In business apps it can include names, email addresses, phone numbers, postal and site addresses, notes, quotes, invoices, deals, memberships, licence and certificate details, review text and reviewer names, and message templates. In developer tools it can include web addresses and settings you register, such as API endpoints and webhook addresses, headers and signing secrets (stored encrypted), and the events, costs, spending decisions, dispute records and other data that your programs send to our API. Some developer tools are built to avoid storing sensitive values, for example by storing a one-way hash, a data shape or a credential's name instead of the value itself. If you want to know what a tool stores, ask us at hello@xaglobal.stream. Please do not send us secrets or personal data that the tool does not need, and do not enter sensitive data such as payment card numbers, passwords, government ID numbers or medical records.

2.6 Usage, audit and notification records. We keep counts of what you use (for example checks, decisions or drafts), a log of important actions in your workspace (such as sign-up, invitations, API key creation and password changes, with details like the email address involved), and the notices we show you in the Service.

2.7 Technical and error records. When something goes wrong, we record an error reference, the error message, the page or path, the request method, the status, the app version and your browser type (user agent). We also record slow responses, rejected sign-in attempts and server health checks. If you press "Report a problem", we record the message you write. We do not write passwords or the contents of requests to our logs. Our application does not save your IP address in our database. It uses it briefly in memory to limit abuse, and our hosting providers may keep it in their logs.

2.8 Emails and texts. We send emails such as email confirmation, password reset, invitations, alerts, reminders and digests. Some Services also send emails or texts to your own contacts on your behalf, for example review requests, quotes, payment reminders and follow-ups. We use the contact details that you gave us for that purpose.

2.9 Passwords. When you choose a new password, we check it against a public list of leaked passwords without sending the password itself or your email address. Only the first five characters of a one-way hash leave our server. Section 4 gives the details.

2.10 What we do not collect. We do not use advertising identifiers, we do not track your location, and we do not ask for payment card numbers or sensitive personal data.

3. Why we use your data, and our legal basis

3.1 The PDPA requires a legal basis for each use of personal data. These are ours:

3.2 For Your Data, we use it only to run the Services for you, on your instructions. You are responsible for having a lawful basis to put it in.

3.3 We do not sell personal data and we do not use it for advertising. A person reviews any AI draft before it is used. Some developer tools apply rules that you set, for example to allow or block a spend or to settle a dispute between two parties. They act on your rules, not on ours.

4. Who we share your data with

4.1 We share data only with providers that help us run the Services, and only as needed. At the moment, these are:

4.2 We may also share data with professional advisers, with authorities when the law requires it, and with a buyer if we sell or reorganise our business, if your data stays protected as this policy describes.

4.3 We expect our providers to use the data only to provide their service to us, under their own terms and privacy commitments.

5. Moving data between countries

5.1 Our providers run servers in several countries, which may include the United States and other countries outside Thailand. Your data may therefore be processed outside Thailand and outside your own country.

5.2 When we send personal data abroad, we use only what is needed, we choose providers that publish security and privacy commitments, and we use encrypted connections. We aim to have contractual safeguards in place that meet the PDPA's rules on sending data abroad.

6. How long we keep data

6.1 Account and workspace data: while your account is open. When you ask us in writing to close your account or delete your data, we will do it within 30 days, except for what the law requires us to keep.

6.2 Backups: we may keep encrypted backups of our database. We keep each one for up to 30 days, so deleted data leaves them within that time.

6.3 Billing and tax records: as long as tax and accounting law requires.

6.4 Some developer tools delete old technical data automatically, for example check results after 90 days, a check log after 30 days, and raw cost events after about 40 days, while hourly totals are kept.

6.5 Error, audit and health records: we aim to keep them for no longer than 12 months. If you ask us in writing to delete records about you, we will act on your request within 30 days.

6.6 Emails to hello@xaglobal.stream: as long as needed to deal with your request, and then up to 2 years.

6.7 Sign-in sessions end after 30 days, or when you change or reset your password. Invitation links last 7 days, password reset links last 1 hour and email confirmation links last 2 days.

7. How we keep data safe

7.1 These are the main measures we use.

7.2 No online service is completely secure, and we cannot promise that nothing will ever go wrong. If a breach affects your personal data, we will tell you without undue delay and notify the authorities as the law requires.

8. Your rights and how to use them

8.1 Under the PDPA, and under similar laws elsewhere, you may have the right to:

8.2 To use any of these rights, email hello@xaglobal.stream. We may need to check that you are who you say you are. We will answer within 30 days. We do not charge for ordinary requests.

8.3 If your request is about Your Data, which we process for a customer, we may pass it to that customer so they can answer.

8.4 If you are not happy with how we handled your data, please tell us first. You may also complain to Thailand's Personal Data Protection Committee, or to the data protection authority in the country where you live.

9. Cookies and tracking on this website

9.1 This website sets no cookies. It has no analytics, advertising or tracking tools, and it loads no scripts, fonts, images or other files from other companies.

9.2 The website uses your browser's session storage for one item, called "xag-intro". It remembers that you have already seen the opening animation during this visit. It stays in your browser, we never receive it, and it is cleared when you close the tab or browser.

9.3 The website reads a few of your device settings, such as reduced motion, data saver and reduced transparency, to adjust its animation. They are used on your device only and are not sent anywhere.

9.4 A small light in the top bar shows whether your connection is working. It does this by asking our own website for one of its own files every 60 seconds while the page is open, and when your connection changes. The request goes only to our own website and carries nothing beyond what every web request carries, such as your IP address.

9.5 Our products' websites set no cookies and have no analytics or advertising tools. They keep your sign-in token and your chosen workspace in your browser's local storage so that you stay signed in, and some keep your language or display currency. You can clear these from your browser settings, which signs you out.

10. Children

10.1 The Services are for businesses and for adults aged 18 or over. They are not meant for children, and we do not knowingly collect personal data from children. If you think a child has given us personal data, please tell us and we will delete it.

11. If you are in the EU, the UK or Australia

11.1 This part is a short note for people in those places. It does not add to or replace the rest of this policy.

12. Changes to this policy

12.1 We may update this policy. When we do, we change the "Last updated" date at the top.

12.2 For changes that matter, we will tell you by email or in the Service at least 14 days before they take effect.

13. Contact

13.1 Questions, requests and complaints: hello@xaglobal.stream.

13.2 XAGlobal, registered in Thailand, 108/1 Moo. 2, Umphur Chawang, Thambon NaGaCha, Nakorn Sri Thammarat, Thailand, 80150.