Start free

Privacy Policy

We collect the minimum we need, never sell your data, and let you see, correct or delete it.

Plain-English baseline. This is a clear, good-faith starting draft — not legal advice. Have your counsel review and adapt it before relying on it for your jurisdiction.
Version 2.1 · Effective 2026-10-04

1. The short version

We collect the minimum we need to run xigzag, we never sell or "share" your personal data for cross-context advertising, and you can see, correct, export or delete it. This policy covers account holders (people who build sites with xigzag) and visitors to xigzag.com, for whom Arad Soft Ltd. is the controller. For the shoppers, members and visitors of sites built on xigzag, the business that owns the site is the controller and we are its processor under our Data Processing Addendum; that business's own privacy notice applies, and requests go to them first (we will forward any we receive).

2. What we collect and where it comes from

  • Account data (from you): name, email, password (stored only as a salted hash), optional phone and two-factor settings.
  • Billing data (from you and Stripe): billing name and address, VAT number, invoice history, a Stripe customer reference. Card numbers go to Stripe and never reach us.
  • Content (from you): your sites, text, images, products, settings and messages to our support.
  • Domain registrant data (from you, when you buy a domain): name, address, email, phone, as ICANN requires.
  • Technical and usage data (from your device): IP address, browser type, pages viewed, timestamps, security logs.
  • Sign-in data (from Google, Apple or Microsoft, only if you choose that sign-in): your name, email and an account identifier.

On xigzag.com we use privacy-friendly analytics: no advertising cookies, no third-party trackers, and, unless you allow analytics cookies, a daily-rotating anonymous hash to count visits that cannot be linked across days or back to you. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects (Art. 22 GDPR).

3. Purposes, lawful bases and how long we keep it

  • Providing the service, hosting your sites, support: lawful basis contract (Art. 6(1)(b)). Kept: while your account is open, then 30 days for recovery.
  • Billing, invoices, tax records: lawful basis legal obligation (Art. 6(1)(c)) and contract. Kept: invoices and payment records 7 years (bookkeeping and tax law).
  • Domain registration: lawful basis contract and the registry's rules. Kept: for the registration, then as ICANN requires (up to 2 years).
  • Security, fraud and abuse prevention, security logs: lawful basis legitimate interests (Art. 6(1)(f)): keeping the service and its users safe. Kept: access and security logs 90 days; abuse records up to 2 years; both deleted automatically.
  • Service and transactional emails (receipts, security alerts, policy changes): lawful basis contract and legitimate interests. Kept: with the account.
  • Product news and marketing emails: lawful basis consent (Art. 6(1)(a)), which is also express consent under Canada's Anti-Spam Legislation (CASL), withdrawable at any time with one click; we record when and where you gave it; every message names us, gives our mailing address and has a working unsubscribe link that takes effect at once (CASL allows up to 10 business days). Kept: until you unsubscribe.
  • Analytics cookies on xigzag.com: lawful basis consent (ePrivacy Art. 5(3)); cookieless counts: legitimate interests. Kept: see the Cookie Notice.
  • Backups: lawful basis legitimate interests: recovering from failures. Kept: encrypted, rolling 14 days locally and up to 30 days offsite.
  • Responding to legal claims and authorities: lawful basis legal obligation / legitimate interests. Kept: as long as the matter requires.

Providing account and billing data is necessary to use the service (a contractual requirement); without it we cannot open an account. Everything else is optional.

4. Who receives it

We do not sell personal data and do not share it for cross-context behavioural advertising. We disclose it only to the sub-processors that help us run xigzag, under written data-processing terms, to the providers you ask us to connect, to professional advisers under confidentiality, to a buyer in a merger or acquisition (with notice to you), and to authorities where the law requires it. Our current sub-processors:

  • [HOSTING PROVIDER]: Servers that host the platform and every site. Data: All service data. Location: [HOSTING COUNTRY]. Transfer safeguard: Adequacy or SCCs where outside the EEA. DPA / SCCs: [HOSTING PROVIDER DPA URL].
  • [OFFSITE BACKUP STORAGE PROVIDER]: Encrypted offsite backups (the provider cannot read them). Data: Encrypted copies of all service data. Location: [BACKUP REGION]. Transfer safeguard: SCCs where outside the EEA. DPA / SCCs: [BACKUP PROVIDER DPA URL].
  • Stripe, Inc. / Stripe Payments Europe, Ltd.: Platform subscription billing; card payments on storefronts that connect Stripe. Data: Name, email, billing address, payment details (held by Stripe, not us). Location: Ireland / USA. Transfer safeguard: EU-US Data Privacy Framework; SCCs. DPA / SCCs: https://stripe.com/legal/dpa.
  • NameSilo, LLC: Domain registration and renewal (registrant details are required by ICANN). Data: Registrant name, address, email, phone. Location: USA. Transfer safeguard: SCCs; ICANN registration-data rules. DPA / SCCs: [NAMESILO REGISTRATION AGREEMENT / DPA URL].
  • Cloudflare, Inc.: Bot protection on forms (Turnstile) and DNS for connected domains. Data: IP address, browser signals; DNS records. Location: Global network / USA. Transfer safeguard: EU-US Data Privacy Framework; SCCs. DPA / SCCs: https://www.cloudflare.com/cloudflare-customer-dpa/.
  • Google LLC / Google Ireland Ltd.: Optional Google sign-in, Calendar and Maps features. Data: Profile/email for sign-in; calendar events when connected. Location: Ireland / USA. Transfer safeguard: EU-US Data Privacy Framework; SCCs. DPA / SCCs: https://business.safety.google/processorterms/.
  • Telegram FZ-LLC: Operational alerts to our on-call staff. Data: No personal data: the alert type, route, internal ids and a link to our console (personal data is stripped before sending). Location: UAE / global. Transfer safeguard: Not a transfer of personal data. DPA / SCCs: Not needed: no personal data is sent (https://telegram.org/privacy).
  • [ERROR MONITORING PROVIDER, OR "self-hosted"]: Error monitoring (ERROR_WEBHOOK_URL). Data: Error reports: route, message, stack trace, request id. Location: [REGION]. Transfer safeguard: SCCs where outside the EEA. DPA / SCCs: [ERROR MONITORING DPA URL].

Used only when you choose the feature:

5. International transfers

We are established in Canada. The European Commission has recognised Canada as providing adequate protection (Decision 2002/2/EC, for organisations subject to PIPEDA), so personal data can flow from the EU/EEA to us in Canada without further safeguards; the UK and Switzerland recognise Canada the same way. Our servers are in [HOSTING COUNTRY]. Before personal data leaves Quebec we assess the transfer as Quebec's Law 25 requires. When personal data goes to a country without an adequacy decision we use the European Commission's Standard Contractual Clauses (2021/914), the UK International Data Transfer Addendum, and for US providers certified under it, the EU-US Data Privacy Framework (and its UK and Swiss extensions), with supplementary measures such as encryption where needed. Ask us for a copy of the safeguards at privacy@xigzag.com.

6. Your rights (EU, EEA and UK)

You have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interests (and always to direct marketing), and to withdraw consent at any time without affecting earlier processing. Most of it you can do yourself in the Studio (export, edit, delete account); otherwise email privacy@xigzag.com or use the privacy request form. We acknowledge every request at once and answer within 30 days (extendable by two months for complex requests) and may need to verify your identity. You can complain to a supervisory authority, in particular in your country of residence or work; our lead authority is the Office of the Privacy Commissioner of Canada; in Quebec matters, the CAI. EU/EEA residents may complain to the data protection authority of their own country (we have no EU establishment), and in the UK the Information Commissioner's Office (ico.org.uk).

6a. Canada (PIPEDA and Quebec Law 25)

Arad Soft Ltd. is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Quebec residents, the Act respecting the protection of personal information in the private sector as amended by Law 25. We apply PIPEDA's ten fair information principles:

  • Accountability: our privacy officer, Privacy Officer, support@xigzag.com (privacy@xigzag.com), is responsible for compliance and is also the person in charge of the protection of personal information under Law 25.
  • Identifying purposes: section 3 states why we collect each kind of data.
  • Consent: we rely on your meaningful consent, express for anything sensitive or unexpected, and you may withdraw it subject to legal or contractual limits.
  • Limiting collection: we collect only what the purposes in section 3 need.
  • Limiting use, disclosure and retention: we use data only for those purposes, disclose it only as section 4 says, and keep it only for the periods in section 3.
  • Accuracy: you can correct your data in the Studio or by asking us.
  • Safeguards: see section 8.
  • Openness: this policy, our sub-processor list and our DPA are public.
  • Individual access: you may access your data and have it corrected; we answer within 30 days.
  • Challenging compliance: you may complain to us first and then to the regulator below.

Privacy by default (Law 25): the most privacy-protective settings are on by default: no analytics cookies without consent and no marketing without opt-in. Breaches: we keep a register of every breach of security safeguards / confidentiality incident for at least 24 months, and where a breach creates a real risk of significant harm we notify the Office of the Privacy Commissioner of Canada (and the CAI for Quebec residents) and the affected individuals as soon as feasible. You may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca); in Quebec matters, the Commission d'accès à l'information du Québec (CAI).

7. California residents (CCPA / CPRA notice at collection)

In the last 12 months we collected these categories of personal information: identifiers (name, email, IP address), customer records (billing address), commercial information (plans bought, invoices), internet activity (pages viewed, security logs), and account login credentials. We use them for the purposes in section 3 and keep them for the periods stated there. Account login credentials are sensitive personal information; we use them only to let you sign in and keep the account secure, never to infer characteristics, so there is no need for a "Limit the use" link.

We do not sell personal information and do not share it for cross-context behavioural advertising, and we have no actual knowledge of selling or sharing data of consumers under 16. We honour the Global Privacy Control signal as an opt-out. You have the right to know, delete and correct, and not to be discriminated against for exercising them. You or an authorised agent may submit a request at privacy@xigzag.com; we verify the request by matching it to your account email.

8. Security

We protect personal data with appropriate technical and organisational measures: a separate database per site, TLS everywhere with HSTS, salted password hashes, sealed secrets, encrypted backups, two-factor sign-in, least-privilege staff access with every support session logged, and rate limiting. See Security & Trust. If a breach is likely to put your rights at high risk we will tell you without undue delay.

9. Children

xigzag is not directed to children under 16 and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.

10. Changes and contact

We will post any change here with a new version and effective date, and tell account holders of material changes at least 30 days in advance. Questions or requests: privacy@xigzag.com, the privacy request form.

Who we are

xigzag is operated by Arad Soft Ltd., a company established in Ontario, Canada. Privacy officer (the person in charge of the protection of personal information): Privacy Officer, support@xigzag.com, privacy@xigzag.com; requests can also be made at /privacy/request. EU representative: [EU REPRESENTATIVE (Art. 27) OR "not required"]. UK representative: [UK REPRESENTATIVE OR "not required"]. General contact: hello@xigzag.com.

Change log

  • 2.1 (2026-10-04): Added PIPEDA (ten principles, privacy officer, breach notification), Quebec Law 25, CASL consent for marketing, the EU adequacy decision for Canada, the privacy request form and retention periods enforced in code.
  • 2.0 (2026-10-04): Rewritten to GDPR Art. 13/14: controller and DPO, purposes with lawful bases, retention periods, recipients and sub-processors, transfers (SCCs / UK addendum), complaint right; added the CCPA/CPRA notice at collection, sale/share and sensitive-data statements, Global Privacy Control.
  • 1.0 (2026-06-01): First published version.

For a material change we give at least 30 days' notice by email and in the Studio before it takes effect, except where a change is required by law or to address abuse or security.

Questions?

We're happy to talk it through.

Email hello@xigzag.com →