Legal & Policies
XILA ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our marketplace platform, including our website, mobile applications, and related services (collectively, the "Platform").
By using the Platform, you consent to the data practices described in this Privacy Policy. If you do not agree with the practices described in this policy, please do not use the Platform.
To provide you with a seamless and personalized experience, we collect various types of information, which can be broadly categorized as information you provide to us directly and information we collect automatically.
When you register for a XILA account, we collect essential contact and identity details. This includes your email address, phone number, full legal name, date of birth, and optional demographic data such as gender and geographic location. For business accounts, we also collect formal business registration details and tax identification numbers necessary for compliance and verification.
To help you connect with others in the marketplace, you may choose to provide additional profile information. This includes personal biographies, cover photos, external website links, social media handles, professional business descriptions, employment history, verified certifications, and specific interests or preferences.
We facilitate communication between users for product inquiries, service bookings, and job applications. We collect message content (text, files, images, videos) and associated metadata (timestamps, sender/receiver IDs, read receipts). Conversations linked to specific marketplace entities (e.g., a product listing) are also tracked.
For users utilizing our integrated voice and video calling features, we collect call metadata, including call duration, participant identities, timestamps, and network quality metrics. We strictly do not record audio or video content unless explicitly authorized by all participants or required by a valid legal process.
We collect transaction history, billing addresses, and records of credit purchases. Financial transactions are securely processed by our payment partner, Stripe. XILA does not directly store your full credit card numbers or raw bank account details on our servers.
As you navigate the platform, we automatically log technical data. This includes your device specifications, IP address, operating system, browser type, pages visited, specific features utilized, search queries, application crash reports, and the referral sources that led you to our platform.
When you upload content, we collect the files themselves (images, videos, PDF documents) along with inherent file metadata, such as file names, sizes, formats, and the exact timestamps of upload.
We maintain a comprehensive record of your interactions within the marketplace ecosystem. This encompasses product listings created, service appointments booked, job applications submitted, rental reservations made, lead unlocks, detailed transaction records, and the ratings and reviews you publish or receive.
If you choose to connect a calendar or meeting provider to Xila Calendar, we process provider account and calendar-related data that is necessary to deliver the features you enable. Connections are user-initiated, require you to be an authenticated Xila user, and request only the permissions needed for the features you select.
Google Workspace / Google Calendar. When you connect Google Calendar, we may process: your Google account identifiers (such as email and profile name returned by Google); OAuth tokens used to access Google Calendar on your behalf; calendar list and calendar identifiers; event details you sync or create (such as titles, descriptions, times, time zones, locations, attendees, and recurrence); and free/busy or availability information needed for scheduling.
We do not use Google Calendar connect to access your Gmail, Google Drive, Google Contacts, Google Photos, Google Docs, or other Google products beyond the Google Calendar / Workspace Calendar APIs required for the calendar features you enable.
Zoom. When you connect Zoom, we may process Zoom user identifiers, OAuth tokens, and meeting identifiers and join links created for your Xila calendar events or bookings.
Outlook / Microsoft Graph. When you connect Outlook, we may process Microsoft account identifiers, OAuth tokens, calendar and event data synced via Microsoft Graph, and Microsoft Teams meeting join links created for your events.
We use your information to:
Provide, maintain, and improve the Platform
Process transactions and manage subscriptions
Enable communication features (chat, calls)
Facilitate marketplace transactions
Manage user accounts and profiles
Provide customer support
We use your information to:
Personalize your experience on the Platform
Recommend products, services, jobs, or rentals
Show relevant content and advertisements
Customize features and settings
We use your information to:
Send transactional emails (confirmations, receipts, notifications)
Send marketing communications (with your consent)
Respond to your inquiries and support requests
Send important updates about the Platform
We use your information to:
Detect and prevent fraud, abuse, and security threats
Verify user identities
Enforce our Terms and Conditions
Protect the rights and safety of users
We use your information to:
Analyze Platform usage and performance
Improve our services and features
Conduct research and development
Generate aggregated, anonymized statistics
We use your information to:
Comply with applicable laws and regulations
Respond to legal requests and court orders
Enforce our legal rights
Protect our users and the Platform
The following information may be publicly visible:
Public profiles: Name, profile photo, bio (if profile is set to public)
Business profiles: Business name, description, services (publicly listed)
Listings: Products, services, jobs, rentals you list (publicly searchable)
Public posts: Social media posts set to public visibility
Reviews: Reviews you write (may be visible to other users)
We share information necessary for marketplace transactions:
Buyer information: Shared with sellers for order fulfillment
Seller information: Shared with buyers for transaction completion
Service providers: Shared with clients for service delivery
Job applicants: Shared with employers for hiring processes
Information shared through communication features:
Chat messages: Shared with intended recipients
Call information: Participant information shared with other call participants
Group communications: Shared with group members
We share information with third-party service providers who perform services on our behalf:
Cloud hosting providers: For data storage and processing
Payment processors: For payment processing (see Section 6.3)
Communication services: Agora for chat and calls (see Section 6.1 and 6.2)
Email service providers: For sending emails
Analytics providers: For usage analytics
Customer support tools: For providing customer support
These service providers are contractually obligated to protect your information and use it only for the purposes we specify.
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change in ownership.
We may disclose your information if required by:
Law, regulation, or legal process
Government requests or court orders
To protect our rights, property, or safety
To protect the rights, property, or safety of our users
We may share your information in other ways with your explicit consent.
Xila's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
This section applies to Google Workspace APIs that Xila uses (currently Google Calendar). We process Google user data only to provide or improve user-facing features that are prominent in the requesting application's user interface.
We do not use Google Workspace data (raw or derived) to train, improve, or fine-tune generalized AI or machine learning models.
We do not sell or rent Google user data, and we do not use Google user data for advertising, including personalized or interest-based advertising.
We do not use Google Calendar connect to access Gmail, Drive, Contacts, Photos, Docs, or other Google products beyond the Calendar / Workspace Calendar APIs required for the features you enable.
The following summarizes how Xila processes data for each connected calendar or meeting provider. Setup and removal steps are described in the linked operational guides—not in this Privacy Policy.
Purpose: Sync calendars and events between Xila Calendar and Google Calendar.
Data processed: Google account identifiers; calendar and event data; free/busy information as needed for scheduling.
Permissions (high level): Identify your Google account; read and write calendars and events you authorize for sync.
Tokens: OAuth tokens are stored encrypted (see Data Security).
Disconnect: You can disconnect Google Calendar in Xila Calendar Settings. You may also revoke access in your Google Account permissions. After disconnect, stored OAuth tokens are deleted or made unusable.
Commitments: Google Workspace API Limited Use applies (see Section 5). Google Calendar data is not used for advertising or to train generalized AI models.
Purpose: Create Zoom meetings and join links for Xila calendar events and bookings on your Zoom account.
Data processed: Zoom user identifiers; OAuth tokens; meeting identifiers and join URLs created for your events.
Permissions (high level): Identify your Zoom account; create and delete online meetings as needed for linked Xila events.
Tokens: OAuth tokens are stored encrypted (see Data Security).
Disconnect: You can disconnect Zoom in Xila Calendar Settings and/or remove the app in the Zoom Marketplace. After disconnect, stored OAuth tokens are deleted or made unusable.
See /docs/zoom-integration for setup and removal instructions. Zoom data is not used for advertising or to train generalized AI models.
Purpose: Sync calendars and events with Outlook via Microsoft Graph and create Microsoft Teams meeting links when you choose that option.
Data processed: Microsoft account identifiers; OAuth tokens; calendar and event data; Teams meeting join links created for your events.
Permissions (high level): Identify your Microsoft account; read and write calendars; create online meetings.
Tokens: OAuth tokens are stored encrypted (see Data Security).
Disconnect: You can disconnect Outlook in Xila Calendar Settings and/or revoke Xila's access in your Microsoft account. After disconnect, stored OAuth tokens are deleted or made unusable.
See /docs/outlook-integration for setup and removal instructions. Outlook / Graph data is not used for advertising or to train generalized AI models.
| Provider | Purpose | OAuth | Used for model training | Advertising |
|---|---|---|---|---|
| Google Calendar (Workspace APIs) | Calendar sync | Yes | No | No |
| Zoom | Meeting creation | Yes | No | No |
| Outlook (Microsoft Graph) | Calendar sync + Teams links | Yes | No | No |
We may add additional calendar or meeting providers in the future. Any new integrations will be described in this Privacy Policy before they are made available.
Xila uses third-party AI providers to generate responses and assistive content when you use Xila AI features. We distinguish inference (running a model to produce an output for your request) from training (using your data to improve a model). Xila does not use connected calendar or meeting provider data (Google, Zoom, or Outlook) to train generalized AI or machine learning models.
When you ask Xila AI to help schedule or draft something, we send the prompt and related instructions you provide (for example: "Suggest three 30-minute meeting times next week labeled Team Sync")—not a bulk dump of your connected provider calendars—to the AI provider for inference. If you then choose to create an event, Xila writes to the connected provider through that provider's API after generation, under your authorization.
| Provider | Primary purpose | Connected provider data used | Model training |
|---|---|---|---|
| OpenAI | Assistive generation and related Xila AI tasks | No | No |
| Anthropic | Assistive generation and related Xila AI tasks | No | No |
| Perplexity | Search-augmented answers and related Xila AI tasks | No | No |
"Connected provider data" means Google Calendar, Zoom, and Outlook / Microsoft Graph data obtained through those integrations. AI providers may process the prompts and context you submit for inference under their own terms; Xila does not authorize use of connected provider data for their model training.
Your data is stored on secure servers. We may transfer and store your data in other locations for redundancy, performance, or legal compliance purposes.
Active accounts: Messages are retained for 2 years from the date of the message
Deleted accounts: Messages are retained for 30 days after account deletion
Archived messages: May be retained longer if you choose to archive them
Legal requirements: Messages may be retained longer if required by law
Call logs: Retained for 1 year from the date of the call
Call metadata: Retained according to the same schedule
Call recordings: If recordings are made (with consent), retained according to consent terms or legal requirements
Active accounts: Media files are retained while your account is active and within storage quotas
Storage quotas: Subject to your subscription plan (see Terms and Conditions)
Deleted files: Permanently deleted 30 days after deletion
Account deletion: All media files deleted 30 days after account deletion
Active accounts: Data retained while account is active
Inactive accounts: Data retained for 90 days after last activity
Deleted accounts: Most data permanently deleted after 30 days
Legal requirements: Some data may be retained longer for legal, tax, or regulatory purposes
Transaction records: Retained for 7 years (for tax and legal compliance)
Payment information: Retained according to payment processor policies and legal requirements
Invoice records: Retained for 7 years
OAuth tokens: Deleted or made unusable immediately after you disconnect a calendar or meeting provider (or after provider de-authorization is processed).
Synced event records: Remain only while required to provide the service or to meet legal obligations. Disconnecting a provider does not automatically delete past Xila calendar event records; you may delete those events in Xila.
Our chat and messaging features are powered by Agora Chat SDK. When you use chat features:
Data processing: Messages and chat data are processed by Agora
Data storage: Chat data may be stored on Agora's servers
Privacy practices: Agora's privacy practices apply to chat data processing
Security: Agora implements security measures to protect chat data
Our voice and video calling features are powered by Agora RTC SDK. When you use calling features:
Data processing: Call data and metadata are processed by Agora
Media streams: Audio and video streams are transmitted through Agora's infrastructure
Privacy practices: Agora's privacy practices apply to call data processing
No recording: We do not record calls unless explicitly authorized and required by law
Payment processing is handled by third-party payment processors (e.g., Stripe). When you make payments:
Payment data: Payment information is processed by the payment processor
Data storage: Payment processors store payment data according to their policies
Security standards: Payment processors comply with PCI DSS security standards
Privacy practices: Payment processor privacy practices apply to payment data
We do not store full credit card numbers. For more information, please review your payment processor's Privacy Policy.
We may use other third-party services for:
Analytics: Google Analytics, Mixpanel, or similar services
Email services: For sending transactional and marketing emails
Cloud storage: For storing and serving media files
Customer support: For providing customer support services
These services have their own privacy policies governing data collection and use.
We implement industry-standard security measures to protect your information:
Encryption: Data in transit is encrypted using TLS/SSL
Secure storage: Data at rest is encrypted
Access controls: Limited access to personal data on a need-to-know basis
Authentication: Secure authentication and authorization systems
Monitoring: Continuous monitoring for security threats
Regular audits: Security audits and vulnerability assessments
Connected provider tokens:OAuth access tokens for calendar and meeting providers are encrypted at rest, transmitted over encrypted connections, accessible only to the authenticated user's connection and least-privilege internal systems that operate the integration, and refreshed as needed when they expire
In the event of a data breach that may affect your personal information, we will:
Notify affected users within 72 hours (where required by law)
Provide information about the nature of the breach
Explain steps we are taking to address the breach
Recommend steps you can take to protect yourself
You play an important role in protecting your information:
Use strong, unique passwords
Enable two-factor authentication
Do not share your account credentials
Log out when using shared devices
Report suspicious activity immediately
You have the right to:
Access your personal information
Request a copy of your data
Review what information we have about you
Contact: support@xila.io
You have the right to:
Correct inaccurate information
Update your personal information
Modify your profile data
You can update most information through your account settings.
You have the right to:
Request deletion of your personal information
Delete your account and associated data
Request deletion of specific data
Note: Some information may be retained for legal, tax, or regulatory purposes even after account deletion.
You have the right to:
Receive your data in a structured, commonly used format
Transfer your data to another service
Export your data from the Platform
Contact: support@xila.io
You have the right to:
Object to processing of your personal information
Restrict processing of your personal information
Opt out of certain data uses
Contact: support@xila.io
Where processing is based on consent, you have the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing before withdrawal.
For connected calendar and meeting providers, you can:
Connect a provider from Xila Calendar Settings
Disconnect a provider in Xila Calendar Settings
Reconnect after disconnect or when re-authorization is required
Revoke access at the provider (for example Google Account permissions, Zoom Marketplace, or Microsoft account permissions)
Delete account to remove your Xila account and associated data subject to retention rules in this Policy
Export your data by requesting a data export in Account & Security settings
We use the following types of cookies:
Essential cookies: Required for Platform functionality
Performance cookies: For analyzing Platform performance
Functionality cookies: For remembering your preferences
Advertising cookies: For showing relevant advertisements
You can manage cookies through:
Your browser settings
Our cookie preference center (if available)
Opt-out tools provided by third-party services
Note: Disabling certain cookies may affect Platform functionality.
Third-party services may use tracking technologies on our Platform. We do not control these tracking technologies. Please review third-party privacy policies for information about their tracking practices.
You Can Update Your Cookie Choices at Any Time.
The Platform is not intended for children under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete such information promptly.
If you believe we have collected information from a child, please contact us at support@xila.io.
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws than your country.
When transferring data internationally, we implement appropriate safeguards, including:
Standard contractual clauses
Adequacy decisions (where applicable)
Other legal mechanisms to ensure data protection
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
You have the right to know:
What personal information we collect
How we use your personal information
Whether we sell or share your personal information
Who we share your personal information with
You have the right to request deletion of your personal information, subject to certain exceptions.
You have the right to opt-out of the sale or sharing of your personal information. We do not sell your personal information.
We will not discriminate against you for exercising your CCPA rights.
To exercise your CCPA rights, contact us at support@xila.io.
If you are located in the European Economic Area (EEA) or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR):
We process your personal information based on:
Consent: Where you have given consent
Contract: To perform our contract with you
Legal obligation: To comply with legal obligations
Legitimate interests: For our legitimate business interests
In addition to the rights described in Section 8, you have:
Right to erasure: Right to have your data deleted ("right to be forgotten")
Right to restriction: Right to restrict processing of your data
Right to data portability: Right to receive and transfer your data
Right to object: Right to object to processing based on legitimate interests
For GDPR-related inquiries, you may contact our Data Protection Officer at: support@xila.io
You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have violated your privacy rights.
We may update this Privacy Policy from time to time. We will notify you of material changes by:
Posting the updated policy on the Platform
Sending email notifications to registered users
Updating the "Last Updated" date
Your continued use of the Platform after changes become effective constitutes acceptance of the updated Privacy Policy. If you do not agree to the changes, you must stop using the Platform and delete your account.
If you have any questions or concerns about this Privacy Policy, how we handle your personal information, or if you wish to exercise your privacy rights, please contact our privacy team. We are committed to transparency and will respond to all privacy-related inquiries promptly.