1. Who is responsible for data
Xsender is the controller for account, authentication, billing, security, marketing, support, and abuse-prevention data.
Customers decide which lead lists, recipients, messages, targeting, schedules, and campaign purposes to use. For personal data processed only to carry out those instructions, the customer is the controller or business and Xsender is the processor or service provider.
2. Data we process
- Account data: email address, Google sign-in data, authentication provider, workspace identifiers, and preferences.
- Connected-account data: X handles, account identifiers, connection state, and assigned browser workers.
- Campaign data: lead lists, recipient handles, message text, replies, campaign settings, schedules, variants, results, delivery states, and error codes.
- Customer-directed integration data: webhook destination configuration, signing and delivery metadata, and the campaign, contact, selected lead fields, conversation, and message data sent to an endpoint that the customer configures.
- Device and security data: installation identifiers, scoped worker credentials, IP address, user agent, timestamps, logs, cooldowns, task leases, and worker health.
- Billing data: subscription and trial status, invoices, payment evidence, tax information, and limited payment records supplied by Stripe. Xsender does not receive or store full card details.
- Trial-abuse marker: an irreversible keyed HMAC of the normalized verified login email, plus short-lived checkout reservation state. The raw email is not stored in this ledger.
- Communications: support messages, legal requests, feedback, abuse reports, and related attachments.
- Telemetry: normalized event categories, status and timing buckets, coarse counters, extension version, browser family, and rotating pseudonymous identifiers.
- Optional website analytics: consented page visits, clicks, navigation, section and scroll reach, pricing choices, signup and checkout steps, heatmap coordinates, frontend errors, Core Web Vitals, device and browser characteristics, viewport, approved campaign parameters, landing referrer, and coarse location enrichment.
- Optional session recordings: masked visual snapshots and interactions on acquisition pages. Every input is masked; request and response headers and bodies, console logs, canvas content, passwords, authentication tokens, recovery and OAuth codes, Stripe session identifiers, payment details, and customer campaign content are excluded.
3. Chrome worker and X data
The Chrome worker uses the cookies permission to read the active X account identifier and CSRF credential needed to use the signed-in X session. X passwords are never collected.
X authentication cookies and CSRF credentials stay in the user’s Chrome profile and are not stored by Xsender. The worker uses them in the browser to resolve the selected recipient, check DM availability, execute the exact dashboard-approved message, and synchronize bounded replies for the exact campaign thread.
The worker stores connection state, scoped platform tokens, device credentials, task lease state, execution receipts, cooldowns, retry data, and deduplication records in Chrome storage. It uses tabs to supervise an X tab and alarms for polling, heartbeats, lease renewal, backoff, and recovery.
4. Where data comes from
Data comes from users and customers, connected browser workers, X pages and campaign threads needed for approved tasks, authentication providers such as Google, Stripe, service providers, and security or support interactions.
5. Why we use data
- Provide accounts, connect workers, execute approved campaign tasks, synchronize campaign-thread replies, and show results.
- Authenticate users, maintain sessions, secure the service, prevent abuse, investigate failures, and enforce limits.
- Support customers, respond to rights requests, resolve disputes, and comply with law.
- Investigate support requests and reported or detected abuse and enforce the Acceptable Use Policy.
- Analyze reliability and improve Xsender using normalized telemetry and, only after optional consent, website analytics, heatmaps, errors, performance metrics, and masked acquisition-page session recordings.
- Administer trials, subscriptions, payments, taxes, refunds, accounting, and one-trial-per-identity abuse prevention.
- Send relevant B2B marketing until the recipient opts out, and send required service, billing, legal, or security messages.
Depending on the context, the legal basis may be contract, steps requested before a contract, legitimate interests, consent, or compliance with a legal obligation. Customers are responsible for selecting and documenting the lawful basis for their outreach and lead data.
6. Support, security, and enforcement access
Xsender does not routinely review or hold campaigns before sending. Authorized staff may access relevant customer data only when needed for a support request, a reported or detected security or abuse issue, a legal request, or enforcement. Access is limited to the people who need it and recorded where appropriate.
8. International transfers
Some providers may process data outside the European Economic Area. Where required, we use an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism and assess supplementary safeguards.
Normalized product telemetry is sent to Xsender’s PostHog EU Cloud project. Client IP data is discarded by the analytics project.
Consented browser website analytics and masked session recordings are processed in PostHog EU Cloud through Xsender’s first-party managed proxy. Canonical consent-gated checkout and subscription events may be sent directly by Xsender’s backend to PostHog EU ingestion. PostHog may enrich browser events with coarse geographic, browser, and device information; the project is configured to discard client IP data.
9. Retention
- Full campaign data: archived for up to two years after campaign or account closure.
- Dashboard deletion: may remove active access without immediately erasing a restricted archive.
- Security logs: 30 days.
- Customer audit records: 180 days.
- Webhook delivery metadata: retained with the customer account until the endpoint, source message, campaign, or account is deleted.
- Backups: up to 90 days.
- Normalized extension product telemetry: retained under the existing PostHog raw-event retention setting.
- Consented website analytics events may be linked to an account after sign-in and are retained under the existing PostHog raw-event retention setting.
- Consented acquisition-page session recordings: 30 days.
- Invoices, payment evidence, and accounting records: at least ten years where Lithuanian accounting law requires it.
The irreversible trial-abuse HMAC marker is intentionally retained after account deletion so deleting and recreating the same verified login identity does not create another trial. It cannot be used to recover the raw email without the separately protected server secret.
A valid erasure right overrides ordinary retention unless tax, fraud prevention, security, litigation, or another legal obligation requires continued storage. When data is no longer needed, it is deleted, anonymized, or isolated until deletion is possible.
Deleting a campaign removes it from the dashboard immediately and creates a restricted service-only archive. The archive is automatically eligible for deletion after two years and is removed sooner when a verified erasure right applies or the account is deleted, unless law requires retention.
Account deletion is immediate and irreversible. It revokes sessions, removes the authentication user and cascading tenant data, and schedules retryable cleanup of non-cascading configuration tombstones. Legally required Stripe transaction and accounting evidence is not erased by deleting the Xsender account.
10. Your privacy rights
We offer GDPR-style rights globally: access, correction, deletion, portability, restriction, objection, and withdrawal of consent. These rights can be limited where law permits, including where identity cannot be verified or retention is legally required.
Optional website analytics and session recording are off until a valid choice enables them. Use “Privacy choices” on the website to accept, reject, customize, or withdraw consent. Withdrawal stops future browser capture and recording, resets the analytics identity, clears PostHog persistence, and updates the server-side conversion preference for an authenticated account. You may also request deletion of identifiable analytics data by email.
Send a request from your account email to [email protected], identify the right you want to exercise, and include enough detail to locate the relevant data. We may ask for information needed to verify identity and authority. We normally respond within one month, subject to lawful extensions. If Xsender processes data only for a customer, we may direct the request to that customer and assist them.
You may complain to the Lithuanian State Data Protection Inspectorate or another competent supervisory authority, including the authority in your country of residence where applicable.
11. Marketing and required messages
We may send relevant B2B marketing where permitted by law. Every marketing message should provide a practical way to opt out. Required service, billing, legal, and security messages are not marketing and may continue while an account or legal obligation remains.
12. Sensitive data
Customers may process sensitive data only when they have a valid lawful basis and satisfy consent or notice requirements, minimization, security, and any required data-protection impact assessment. Xsender may reject or remove data it cannot safely or legally process. Xsender does not claim HIPAA or other regulated-data compliance.
13. Security
We use reasonable technical and organizational safeguards, including scoped worker credentials, HTTPS, access controls, payload minimization, signed customer webhooks, encrypted webhook secrets, pacing and duplicate-send controls, and revocation options. No system is perfectly secure, so we cannot promise absolute security.
14. Children
Xsender is for people aged 18 and over and is not directed to children. Contact us if you believe a child has provided personal data.
15. Changes to this policy
We may update this policy to reflect product, provider, or legal changes. Material changes will receive reasonable notice and a new effective date. English is the authoritative language.
Contact
Use the contact below for support, privacy requests, legal notices, intellectual-property complaints, and abuse reports.
XsenderNot VAT-registeredConstanza Hauser, 213 Curtis Dr, Pennsville, NJ 08070, United States[email protected]