Legal

Privacy Policy

What happens to the file you send us, who else can see it, how long we keep it, and how to make us delete it.

Effective August 3, 2026

01The short version

A business sends us an export of its own records. We read it, produce reports, and give them back. The business decides what to send and why; we act on their instructions and use it for nothing else.

In data-protection terms: the business is the controller and XPRNS LLC is the processor. That arrangement is the reason for nearly every clause below.

02What is in the files we receive

Whatever the business's own system exports. Typically: a customer name, an email address or phone number, sometimes a postal code, what was bought, when it was bought and delivered, how much it cost, and which employee handled it.

We ask that nothing else be sent. Payment card numbers, government identifiers and health records have no use in any report we produce, and we delete them unread if they arrive.

03What we do with it

We match records that belong to the same person so that repeat visits can be counted, we group them into days and visits, and we compute the figures in the reports. That is the whole purpose.

We do not sell it, share it between customers, pool it into a dataset, or use it to train anything. One business's file never informs another business's report.

Where a report is written in plain English by a language model, the model is given the finished figures and never the underlying file. It is not in a position to see a customer record, because it is never sent one.

04Where it is processed

The software that reads a file has no network access of its own. It takes a file, computes, and writes a report — it does not call out to anything, and it has no third-party dependencies.

As things stand today there is no upload page and no customer database. Files are handled per engagement rather than accumulated in a shared system. That is a limitation of what is currently built as much as a deliberate choice, and we would rather say so than imply infrastructure we do not have. If that changes, this clause and the effective date change with it.

05Who else sees it

Nobody, by default. We use no advertising networks, no analytics on customer data, and no third-party enrichment service. We do not buy data about your customers and we do not append anything to your file.

xprns.io is a static marketing site hosted by an infrastructure provider. It has no login, no tracking pixel and no cookie banner because it sets no cookies. Visiting it does not identify you.

We may disclose data where legally required. If we are compelled to produce a business's file, we will tell that business unless we are forbidden to.

06How long we keep it

A working copy of a file is kept for up to 30 days after a report is delivered, so the report can be re-run or corrected, and is then destroyed.

Where a business has asked us to track history across several exports — which is what makes repeat-visit and lapsed-customer reporting possible at all — we keep the resolved history for as long as they are a customer.

When an engagement ends, the business tells us whether to return or destroy what we hold. If they tell us nothing, we destroy it.

07If you are the business

Ask us at any time to show you what we hold, correct it, return it or delete it, and we will act within 30 days. You do not need a reason.

One limit we would rather state than hide: deleting the resolved history also removes the ability to say who is a repeat customer, because that answer is the history. Reports run afterwards will treat everybody as new until enough exports accumulate again.

08If you are named in a file somebody sent us

You may be reading this because a shop, salon, gym or restaurant you visit uses us, and your name is in their export. You never chose us, and that is exactly why this clause exists.

We hold your details only because that business asked us to produce a report for them. They decide what is collected and why, so the fastest route is to ask them directly — they can have us delete it, and we act on their instruction.

You can also write to us at support@xprns.io. We will pass the request to the business responsible and confirm to you that we have done so, within 30 days. We will not disclose that business's records to you in the process, and we will not quietly ignore you either.

09Security

Traffic runs over TLS. Access to files is limited to the people working on the engagement. Card data is out of scope by design, because it never arrives — we take no payments through the site and there is no checkout to attack.

No system is perfectly secure. If we discover a breach affecting a file we hold, we will notify the business it belongs to without undue delay so that they can meet their own obligations, and we will notify authorities where the law requires it of us.

10Children

The service is sold to businesses and is not directed at children. We do not knowingly seek children's data, and a business should not send records of children to us without a lawful basis of its own.

11Changes

If this policy changes materially, the effective date at the top of this page changes with it, and we tell current customers directly rather than relying on them re-reading the page.