Updated for Xenodia Commerce OS version 2026.1.
1. Data Collection & Processing
Xenodia operates as a Data Processor on behalf of its merchant clients ("Data Controllers"). When a customer interacts with a Xenodia-powered storefront, we collect: full name, email address, phone number, delivery address, order details, and payment metadata. This data is processed solely to fulfill orders and provide customer support services on behalf of the merchant.
2. Encryption & Data Protection
All Personally Identifiable Information (PII) is encrypted at rest using AES-256 column-level encryption. Encryption keys are managed through Google Cloud Key Management Service (KMS) with automatic rotation every 90 days. Data in transit is protected via TLS 1.3 across all endpoints. No PII is ever stored in application logs or error reporting systems.
3. Data Retention & Cold Archiving
Active transaction records are retained in the production database for 30 days. After this period, records are automatically migrated to a read-optimized cold archive database. Archived records are stripped of direct contact identifiers upon client request, maintaining data minimization principles. Merchants may request full data deletion for specific customers, which is processed within 72 hours.
4. Courier GPS & Telemetry Data
The Xenodia Driver module collects courier GPS coordinates exclusively during active delivery shifts. Telemetry data is used for: route optimization, customer ETA calculations, workforce performance metrics, and delivery proof logging. GPS tracking terminates automatically when a courier ends their shift. Raw GPS coordinates are archived after 7 days and aggregated into anonymized performance metrics.
5. Immutable Audit Trail
Every system action — including ticket interventions, order status overrides, refund approvals, and account modifications — generates an immutable, cryptographically signed ledger entry. Each entry records: the authenticated operator email, IP address, timestamp (UTC), action type, and affected record IDs. Audit logs cannot be modified or deleted and are retained for a minimum of 7 years.
6. Third-Party Data Sharing
Xenodia does not sell, share, or transfer customer data to third parties for marketing or advertising purposes. Data is shared only with: (a) Google Cloud Platform for infrastructure hosting, (b) payment processors as configured by the merchant, and (c) law enforcement agencies when required by valid legal process. All third-party processors are bound by Data Processing Agreements (DPAs).
7. Cookie & Analytics Policy
Xenodia storefronts use essential session cookies required for shopping cart functionality and authentication state. No third-party tracking cookies, ad pixels, or behavioral analytics scripts are injected by the platform. Merchants may add their own analytics tools via the Admin console, which falls under their own privacy obligations.
8. Data Subject Rights
End customers may exercise the following rights by contacting the merchant (Data Controller): right of access, right to rectification, right to erasure ("right to be forgotten"), right to data portability, and right to restrict processing. Merchants can fulfill these requests through the Xenodia Admin Management Center. For direct inquiries to Xenodia as Data Processor, contact xenodiaonline@gmail.com.
9. Breach Notification
In the event of a data breach affecting customer PII, Xenodia will notify affected merchants within 48 hours of confirmed detection, provide a detailed incident report within 5 business days, and cooperate with regulatory authorities as required. All breach events are logged in the immutable audit trail.
1. Service Description
Xenodia provides a multi-module commerce operating system delivered as a Software-as-a-Service (SaaS) platform. The service includes but is not limited to: storefront hosting, kitchen operations management, customer support ticketing, courier dispatch tracking, DSM documentation management, workforce scheduling, and administrative dashboards. All services are deployed on Google Cloud Platform infrastructure.
2. Early Access Terms
The Xenodia ecosystem is currently in active development. Early Access partners acknowledge that: (a) features may be added, modified, or deprecated during development, (b) service availability targets during Early Access are best-effort rather than contractual, (c) Early Access pricing is introductory and may be adjusted at general availability, and (d) Early Access partners receive priority onboarding, direct engineering support, and input on product roadmap decisions.
3. Service Availability & SLA
Upon general availability, Xenodia commits to a 99.9% uptime SLA for all production subdomains. Scheduled maintenance windows are restricted to 03:00–05:00 UTC with a minimum of 48 hours advance notice. Unscheduled downtime exceeding the SLA threshold entitles clients to service credits as specified in their subscription agreement. The SLA excludes force majeure events and third-party infrastructure outages.
4. Account Security & Authentication
Operators accessing Xenodia dashboards via .online domains must authenticate using unique passkeys. Passkey rotation is enforced every 90 days for Enterprise tier accounts. IP whitelisting is available for all tiers and recommended for production environments. Xenodia bears no liability for unauthorized access resulting from: shared credentials, compromised client devices, or disabled security controls.
5. Acceptable Use Policy
Merchants agree not to use Xenodia for: (a) any illegal activity or sale of prohibited goods, (b) transmitting malware, spam, or phishing content through the platform, (c) attempting to access, modify, or extract data from other tenants' databases, (d) circumventing rate limits, API throttles, or security controls, or (e) reselling Xenodia access without a written partnership agreement.
6. Multi-Store Tenancy & Isolation
Each merchant operates within an isolated database schema. Enterprise customers may opt for full database node isolation. Resource limits (concurrent database connections, request throughput, storage capacity) are determined by the selected subscription tier. Automated rate-limiting guards activate when usage patterns risk degrading shared infrastructure performance. Persistent overages may require a tier upgrade.
7. Intellectual Property
All Xenodia software, documentation, user interfaces, and system architecture are the exclusive intellectual property of Xenodia. White-label deployments grant merchants a limited, non-transferable license to present the platform under their brand. Merchants retain full ownership of their business data, product catalogs, customer lists, and transaction records stored on the platform.
8. Delivery Dispatch Liability
Xenodia provides courier dispatch routing software and GPS coordinate mapping. Xenodia does not employ couriers, manage vehicle fleets, or control physical food preparation. The merchant assumes full operational liability for: courier conduct, delivery delays, order accuracy, food safety compliance, and payment processing. Xenodia's liability is limited to the software functioning as documented.
9. Subscription & Billing
Subscriptions are billed monthly or annually as selected at signup. Annual plans receive a 20% discount and are billed upfront. Cancellations take effect at the end of the current billing period. No pro-rata refunds are issued for partial billing periods. Early Access pricing is locked for the duration of the Early Access program and for 12 months following general availability.
10. Termination
Either party may terminate the agreement with 30 days written notice. Upon termination, Xenodia will: (a) provide a full data export in JSON format within 14 days of the termination date, (b) delete all merchant data from production systems within 30 days, and (c) retain anonymized, aggregated analytics data for platform improvement purposes only. Xenodia reserves the right to immediately terminate accounts that violate the Acceptable Use Policy.
11. Limitation of Liability
Xenodia's total aggregate liability arising from or related to this agreement shall not exceed the total fees paid by the merchant in the 12 months preceding the claim. Xenodia shall not be liable for indirect, incidental, consequential, or punitive damages, including lost profits or business interruption, regardless of the theory of liability.
12. Governing Law
These terms shall be governed by and construed in accordance with the laws of the jurisdiction in which the service provider is registered, without regard to conflict of law principles. Any disputes shall be resolved through binding arbitration in accordance with standard commercial arbitration rules.