Privacy Policy
Effective date: August 4, 2026 · Last updated: August 4, 2026
Privacy at a glance
- XPOrders is operated by XP Vault in Ontario, Canada.
- We use account and connected-inbox data to provide order-management features you request.
- We do not sell personal information or use connected email data for advertising.
- Google Workspace API data is handled in accordance with Google’s Limited Use requirements.
- You can disconnect an inbox, manage billing, or request deletion of your account and data.
1. Scope and accountability
This Privacy Policy explains how XP Vault, operating the XPOrders product (“XPOrders,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information when you visit xporders.com, create an account, purchase or manage a subscription, download or use the XPOrders desktop application, connect an inbox, contact support, or use related services.
We are responsible for personal information under our control and designate our Privacy Officer to oversee compliance with this Policy and applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act where applicable.
2. Information we collect
Information you provide
- Account information: email address, display name, authentication provider, and account preferences.
- Billing information: subscription status, Stripe customer and subscription identifiers, plan, trial dates, renewal dates, and invoice-related information. Payment-card details are collected and processed by Stripe; XPOrders does not store full card numbers or card security codes.
- Support information: messages, attachments, diagnostic details, and other information you provide when requesting help or reporting an issue.
- Business and order information: information you enter or import into XPOrders, such as products, retailer accounts, order details, shipping status, expenses, sales, inventory, and analytics inputs.
Information collected automatically
- Usage and device data: IP address, device and operating-system information, browser type, application version, timestamps, pages or features used, error logs, and security events.
- Authentication and session data: access tokens, session identifiers, and login activity used to keep your account signed in and protect access.
- Download and release data: installer version requested, download timestamp, authorization result, and related security or troubleshooting logs.
Information from third parties
Depending on the features you use, we receive information from authentication providers such as Google or Microsoft, payment services such as Stripe, and other services you authorize. The information received depends on your choices and the permissions shown to you.
3. Connected inbox data
XPOrders lets you connect supported email accounts using OAuth. OAuth allows you to authorize access without giving XPOrders your email password. We request only the permissions presented during the connection process and use connected inbox information to provide user-facing order detection, import, organization, synchronization, and account-health features.
What may be accessed
Subject to the permissions you approve, XPOrders may access message metadata and content needed to identify supported retailer communications, such as sender, subject, date, order number, products, quantities, pricing, shipping address, fulfillment status, and related order details. We may store extracted order information and technical identifiers needed to prevent duplicate imports and maintain synchronization.
What we do not do
- We do not sell connected inbox data.
- We do not use connected inbox data for targeted advertising, credit decisions, or data-broker purposes.
- We do not use connected inbox data to train or improve a generalized artificial-intelligence or machine-learning model.
- Our personnel do not read connected email content except when you provide explicit consent for support, when reasonably necessary to investigate abuse or a security incident, or when required by law.
XPOrders’ use and transfer of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You may revoke access through XPOrders, your Google or Microsoft account settings, or by deleting your XPOrders account. Revoking access stops future retrieval, but information already imported may remain until you delete it or request account deletion, subject to the retention terms below.
4. How we use information
We use personal information for purposes that a reasonable person would consider appropriate in the circumstances, including to:
- create, authenticate, secure, and administer your account;
- provide inbox connection, order detection, import, organization, analytics, inventory, seller tools, cloud synchronization, downloads, and updates;
- verify trials, subscriptions, access grants, and eligibility to download or use XPOrders;
- process payments, provide invoices, and allow billing management through Stripe;
- send transactional communications such as authentication, security, billing, service, and release notices;
- provide support and troubleshoot errors;
- monitor reliability, prevent fraud or abuse, and protect users, XPOrders, and third parties;
- improve user-facing features, performance, accessibility, and security using information that is reasonably necessary for those purposes;
- comply with legal obligations and enforce our agreements.
Where consent is required, you may withdraw it subject to legal or contractual restrictions and reasonable notice. Withdrawal may prevent us from providing features that depend on the information.
6. Retention and deletion
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide your account, maintain order history and synchronization, comply with tax or accounting obligations, resolve disputes, prevent fraud, and enforce agreements.
- Account and application data is generally retained while your account is active.
- Billing and transaction records may be retained for legally required accounting, tax, chargeback, and audit periods.
- Security logs and backups may remain for a limited period after deletion before being overwritten.
- De-identified information that cannot reasonably identify you may be retained for analytics, reliability, and security purposes.
You may request deletion through your account settings, when available, or by emailing privacy@xporders.com. We will verify the request and delete or de-identify information unless retention is required or permitted by law. Deleting your XPOrders account does not automatically cancel an active Stripe subscription; cancel billing through the customer portal before deleting your account.
7. Security
We use administrative, technical, and organizational safeguards appropriate to the sensitivity of the information, including encrypted network transport, authentication and authorization controls, restricted administrative access, row-level database controls, private release access, monitoring, and service-provider safeguards.
No system can be guaranteed completely secure. You are responsible for protecting your account credentials, using a secure device, and notifying us promptly if you suspect unauthorized access. For more information, see our Security Overview.
8. Your choices and rights
Subject to applicable law, you may:
- access and correct personal information associated with your account;
- disconnect a connected inbox or revoke OAuth access;
- manage or cancel your subscription through the Stripe customer portal;
- request a copy of certain account information;
- withdraw consent where processing depends on consent;
- request deletion of your account and personal information;
- ask questions or challenge our compliance with this Policy.
We may need to verify your identity before completing a request. We may deny or limit a request where permitted by law and will explain the reason where required.
9. International processing
XPOrders and its service providers may process and store information in Canada, the United States, and other countries where they operate. Information processed outside your province or country may be subject to the laws and lawful-access requirements of that jurisdiction. We use contractual, technical, and organizational measures intended to protect information when it is processed by service providers.
10. Children
XPOrders is intended for adults and is not directed to children under 13. You must be at least the age of majority in your jurisdiction to purchase a subscription. If we learn that we collected personal information from a child without appropriate authorization, we will take reasonable steps to delete it.
11. Changes to this policy
We may update this Policy as XPOrders, our providers, or legal requirements change. We will post the revised Policy with a new “Last updated” date. If a change materially affects how we use personal information, we will provide additional notice and obtain consent where required before applying the new use.
12. Contact and complaints
Privacy Officer — XP Vault / XPOrders
Ontario, Canada
Email: privacy@xporders.com
Please describe your question or request and include the email associated with your account. We will investigate privacy complaints and respond within a reasonable period. You may also have the right to contact the Office of the Privacy Commissioner of Canada or another applicable privacy regulator.
