This policy describes how Xenmark handles data on the marketing site and inside the Xenmark application. This document reflects Xenmark's current data-handling practices. For questions, contact [email protected].
1. Scope
This policy applies to the Xenmark marketing website (www.xenmark.app) and the Xenmark application (my.xenmark.app). The marketing site is static and does not collect personal data through forms or accounts. All account-related data handling happens inside the Xenmark application.
2. What the marketing site does
The marketing site does not require an account, does not store user data, and does not process payments. It serves static HTML, CSS, and JavaScript only.
- No login or signup happens on the marketing site.
- No drawings, comments, or project data live on the marketing site.
- Server logs may record standard request metadata (IP address, user agent, request path) for security and operational purposes.
3. What the Xenmark application collects
When you create an account in the Xenmark application, Xenmark collects the information needed to operate the service:
- Account information — name, email address, and authentication credentials.
- Project data — projects, drawings, revisions, comments, replies, statuses, and member assignments you create or upload.
- Usage telemetry — basic operational logs needed to run the service reliably.
- Billing information — billing is handled by Stripe. Stripe processes payment details directly; Xenmark does not store full card numbers.
4. How data is used
- To operate the Xenmark application and deliver the features you use.
- To maintain account security and detect abuse.
- To communicate with you about your account, the service, and important changes.
- To improve the product based on aggregate, non-identifying usage patterns.
Xenmark does not sell user data.
5. Data sharing
Xenmark relies on a small set of third-party processors to operate the service:
- Cloudflare — domain registration and DNS, frontend hosting and CDN for the marketing site and application, R2 object storage for project files and attachments, and Workers for token-gated storage access and serverless processing.
- Supabase — authentication, relational database (projects, drawings, revisions, comments, members), Edge Functions for server-side logic, and Vault for secrets management.
- Resend — transactional email delivery (account notifications, archive expiry reminders, and other service emails).
- Stripe — billing and payment processing for paid plans. Stripe processes payment details directly; Xenmark does not store full card numbers.
- Backblaze — encrypted operational backup storage for selected project files, attachments, and object metadata. Used for internal recovery and incident response only; not a customer-facing feature.
- Google Fonts — static web-font delivery for the marketing site and application. A visitor's browser connects to fonts.googleapis.com and fonts.gstatic.com to load fonts. Google may receive IP address and ordinary HTTP request metadata. No project content is transmitted.
- UNPKG — public CDN used to deliver the pdf-lib JavaScript library in the application. A user's browser may send IP address and ordinary request metadata when the library is loaded. No project content is transmitted.
Each processor handles only the data necessary for their specific function. For a full list of subprocessors and data transfer details, see the Data Processing page.
6. Data retention
Project data persists for as long as your account is active. When an account is deleted, associated project data is removed within a reasonable period, except where retention is required for legal, accounting, or security reasons.
7. Your rights
You may request access to, correction of, export of, or deletion of personal data associated with your account. If you are signed in, you can request a data export or account deletion from Account & Security in the Xenmark app. You can also submit a data request by emailing [email protected] or using the contact page.
8. Security
Xenmark uses standard security practices including encryption in transit (HTTPS), access-controlled project isolation, and role-based permissions. No system is perfect, and Xenmark recommends following normal account hygiene (strong passwords, prompt response to suspicious activity).
9. Cookies
The marketing site does not set tracking cookies. The Xenmark application uses cookies and similar technologies as needed for authentication and session management.
10. Changes to this policy
Material changes to this policy will be communicated through the application and reflected in the "Last updated" line above.
11. Contact
Xenmark is operated by Xenmark AS, org. nr. 937 996 799, Norway.
Questions about privacy? Email [email protected] or use the contact page and we'll get back to you.