Table of Contents

  1. Overview & Scope
  2. Data Controller
  3. Information We Collect
  4. How We Use Your Information
  5. Legal Basis for Processing
  6. Information Sharing & Disclosure
  7. Data Storage & Residency
  8. Data Security
  9. Data Retention
  10. Your Rights
  11. Cookies & Tracking
  12. Children's Privacy
  13. Geofencing & Location Data
  14. International Data Transfers
  15. Changes to This Policy
  16. Contact Us

1. Overview & Scope

This Privacy Policy describes how CommunityXO ("we", "us", "our") — the multi-community SaaS platform at communityxo.com — collects, uses, discloses, and safeguards your personal data when you access or use our platform, websites, mobile applications, APIs, and related services (collectively, the "Platform").

This Policy applies to all users of the Platform including Community Owners, Members, and visitors. It complies with the EU General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act (DPDPA) 2023, and other applicable data protection laws.

2. Data Controller

CommunityXO acts as the Data Processor (technology platform provider). Each Community Owner acts as the Data Fiduciary / Data Controller for the personal data collected within their community.

For data processed directly by CommunityXO (e.g., account registration, platform analytics), CommunityXO is the Data Controller. For data collected by communities (member profiles, posts, donations), the Community Owner is the Data Controller and CommunityXO processes it on their behalf.

3. Information We Collect

CategoryData TypesPurpose
Account DataName, email, phone, profile photo, bioAccount creation, authentication, profile display
PreferencesLanguage, timezone, currency, notification settingsLocalization, personalized experience
Community DataCommunity memberships, roles, custom field values, engagement metricsCommunity management, analytics, rewards
Content DataPosts, comments, reactions, messages, media uploadsPlatform functionality, moderation
Transaction DataOrder details, donation records, payment method typePayment processing, receipts, accounting
Device & Usage DataDevice type, OS, app version, IP address, session duration, actions takenAnalytics, security, performance optimization
Location DataApproximate location (if geofencing enabled & user opted in)Geofenced notification delivery only — never stored

4. How We Use Your Information

BasisExamples
ConsentLocation services, marketing emails, optional profile fields
ContractAccount creation, community membership, marketplace transactions
Legitimate InterestSecurity monitoring, fraud prevention, analytics, platform improvement
Legal ObligationTax compliance, law enforcement requests, data retention regulations

6. Information Sharing & Disclosure

We do not sell your personal data. We may share information with:

7. Data Storage & Residency

CommunityXO stores data on self-hosted Supabase (PostgreSQL) infrastructure with regional deployment:

Auto-routing based on user IP ensures data residency compliance. All data is encrypted at rest (AES-256) and in transit (TLS 1.3).

8. Data Security

We implement industry-standard security measures including:

9. Data Retention

We retain your data only as long as necessary to fulfil the purposes described in this Policy:

10. Your Rights

Depending on your jurisdiction, you have the following rights:

RightDescriptionHow to Exercise
AccessObtain a copy of your personal dataSettings → Privacy → Request My Data, or email hello@communityxo.com
RectificationCorrect inaccurate dataEdit Profile, or email hello@communityxo.com
ErasureRequest deletion of your dataSettings → Account → Delete Account, or email hello@communityxo.com
PortabilityExport your data in machine-readable formatSettings → Privacy → Export Data
RestrictionLimit processing of your dataEmail hello@communityxo.com
ObjectionObject to processing based on legitimate interestEmail hello@communityxo.com
Withdrawal of ConsentWithdraw consent at any timeSettings → Privacy, or email hello@communityxo.com
Nomination (DPDPA)Nominate someone to exercise rights on your behalfEmail hello@communityxo.com

We will respond to all rights requests within 30 days. Identity verification via OTP may be required.

11. Cookies & Tracking

Our web platform uses essential cookies for authentication and session management. We use analytics tools (Google Analytics, Mixpanel) to understand usage patterns. You can control cookies through your browser settings. Our mobile apps use device identifiers for push notifications (FCM tokens) which can be disabled in app settings.

12. Children's Privacy

CommunityXO is not intended for children under 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children under this age. If we become aware that a child has provided personal data, we will take steps to delete it promptly. Parents or guardians should contact us at hello@communityxo.com if they believe their child's data has been collected.

See our Child Safety Standards for comprehensive details.

13. Geofencing & Location Data

Privacy-first geofencing: User location is never stored. Admins cannot track member locations. Only notification delivery is measured.

14. International Data Transfers

If your data is transferred across borders, we ensure adequate protection through Standard Contractual Clauses (SCCs), data processing agreements with sub-processors, and compliance with applicable transfer mechanisms under GDPR and DPDPA.

15. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via in-app notification and email at least 15 days before taking effect. The "Effective" date at the top of this page indicates the latest revision.

16. Contact Us

Privacy Inquiries

Website
Registered Office
#501, Rebello Enclave, Subash Nagar, MIDC, Andheri E, Mumbai 400093, India