Core Privacy Commitments

1. Who We Are

XGrowth (the "Service" or "Platform") is operated by SNDP-Design ("we", "us", or "our"). This Privacy Policy governs all data processed through our website (https://www.xgrowth.uno) and application workspace (https://www.xgrowth.uno/app/).

For inquiries regarding data protection, you may reach our Data Protection Officer at privacy@xgrowth.uno or hello@xgrowth.uno.

2. Information We Collect

2.1 Account & Authentication Information

When you authenticate using Google Sign-In, we receive basic identity profile details:

We only request openid, email, and profile scopes. We do not access your Gmail, Google Drive, Calendar, or contacts during sign-in.

We use your name and email to send account emails such as the welcome message after you first sign in. These are service notices about your XGrowth account, not marketing campaigns.

2.2 Workspace & GTM Intelligence Data

When you use XGrowth agents, we store and process:

2.3 Payment & Billing Data

Subscription management and checkout are operated by Dodo Payments (PCI-DSS Level 1 compliant). We receive transaction identifiers, subscription status, and billing cycle dates. We never receive or store your raw payment card numbers.

3. Zero AI Model Training Commitment

We understand that your GTM strategy, product roadmaps, and customer positioning are proprietary trade secrets. We enforce the following strict AI data processing architecture:

4. European General Data Protection Regulation (GDPR / UK GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, you hold specific legal rights under GDPR (Articles 12–23):

Legal Bases for Processing: We process your data based on: (1) Contractual necessity to provide the XGrowth service you requested; (2) Legitimate interest in securing, optimizing, and operating our platform; and (3) Consent where explicitly requested.

5. California Consumer Privacy Act & CPRA (CCPA)

If you are a California resident, the California Consumer Privacy Act (as amended by CPRA) provides you with specific rights:

6. Third-Party Sub-Processors

We work with trusted infrastructure sub-processors who adhere to strict data protection standards:

Sub-Processor Purpose Location Data Transferred
Cloudflare, Inc. API gateway, edge compute (Workers), D1 database, and rate limiting Global / USA Encrypted workspace data & IP addresses
Google Cloud / Firebase Authentication, user accounts, and Gemini Live Voice API USA / Global Email, name, user ID, voice session tokens
OpenAI, LLC Structured LLM reasoning & decision extraction (Enterprise API) USA Product facts, ICP queries, campaign drafts (zero-retention)
Dodo Payments Hosted checkout, subscription billing, invoices (PCI-DSS Level 1) USA / Global Subscription ID, customer reference, billing country
Resend, Inc. Transactional account email delivery (welcome and service notices) USA Recipient email, display name, and message content
PostHog, Inc. Product telemetry and usage diagnostics USA / EU Pseudonymized usage events and interaction metrics
Hotjar Ltd. Anonymous usability analysis, heatmaps, and session insights EU / Global Device, browser, page interaction, and session data; private workspace content is suppressed and input data is masked

7. How to Exercise Your Rights (Self-Service)

We provide instant self-service controls directly within the XGrowth platform:

8. Security Architecture

Security is built into our platform from the ground up:

9. Contact Us

If you have any questions, feedback, or concerns regarding this Privacy Policy or our compliance practices, please contact us: