Skip to main content
Legal

Privacy Policy

Learn how Xpandaz collects, uses, and protects your personal data.

Last updated: February 16, 2026

11. Introduction

Xpandaz is committed to protecting your privacy. This policy describes how we collect, use, and protect your personal information when you use our services.

22. Data Collection

Information you provide

  • Account information: Email, password, display name when registering
  • Profile information: Avatar, bio, social media links (optional)
  • Payment information: Processed by PayPal - we do not store card information
  • Contact information: Email and content when you contact support

Information automatically collected

  • Access logs: IP address, browser, device, operating system
  • Cookies: Essential cookies for authentication and analytics cookies (with consent)
  • Usage data: Pages viewed, resources downloaded, access times

33. Data Usage

  • Provide and maintain services
  • Process payments and subscriptions
  • Send important account notifications
  • Improve user experience
  • Customer support
  • Detect and prevent fraud

44. Data Sharing

We do not sell personal data. We only share information in the following cases:

  • Payment processing: PayPal for transaction processing
  • Legal requirements: When required by law or legal authorities
  • Rights protection: To protect the rights, property, or safety of Xpandaz

55. Cookies

We use the following types of cookies:

  • Essential cookies: Required for authentication and security (always on)
  • Analytics cookies: Help us understand how you use the website (requires consent)

66. Your Rights (GDPR)

Under GDPR, you have the following rights:

  • Right of access: View data we store about you
  • Right to rectification: Correct inaccurate information
  • Right to erasure: Request deletion of personal data
  • Right to data portability: Export your data in a standard format
  • Right to object: Object to data processing in certain cases

77. Security

We implement the following security measures:

  • HTTPS encryption for all connections
  • Password encryption with bcrypt
  • Time-limited authentication tokens
  • Rate limiting to prevent attacks

88. Data Retention

  • Account data: Until you delete your account + 30 days
  • Transaction history: 5 years (legal requirement)
  • Access logs: 90 days
  • Analytics data: 2 years

99. Children

Our services are not intended for children under 13. We do not knowingly collect data from children.

1010. Policy Changes

We may update this policy from time to time. Significant changes will be notified via email or website notification.

1111. Contact

If you have questions about this privacy policy, please contact:

Privacy Policy - Xpandaz | Xpandaz