Privacy Policy
Last updated:
This Privacy Policy explains how Xtudio handles personal information when you use our management system for furniture makers, its mobile app and web panel (together, the “Service”), and when you visit x-tudio.com. We comply with the Egyptian Personal Data Protection Law No. 151 of 2020 (“PDPL”) and draw on internationally recognised principles, including those reflected in the EU GDPR.
Two roles you should understand. Xtudio is the data controller for the small set of information we receive directly to run the Service and this website: account credentials, subscription and billing details, website analytics and early-access requests. For the far larger set of information a workshop records about its own customers and team — contact details, quotations, jobs, payments, expenses, delivery addresses, photos of work in progress — the workshop is the data controller and Xtudio acts as its data processor. The workshop decides what is recorded, who may see it and how long it is kept; Xtudio stores and processes it only on the workshop’s instructions.
1. Who we are
Xtudio is a management system for furniture makers: freelance carpenters and small workshops. It brings customers, the materials price list, quotations, cutting lists, jobs and production stages, payments and expenses, delivery and reports together in one mobile app with a web panel. For any privacy-related question, contact us at [email protected].
2. Information we receive directly
From account holders (the workshop owner and any team members they add)
- Account credentials: name, email address, phone number, hashed password, optional two-factor authentication secret.
- Profile basics: avatar, role, language preference.
From the subscribing workshop (for billing)
- Business name, billing contact, tax registration number where applicable, and business address.
- Subscription plan, billing cycle and payment method tokens. We do not store full card numbers; payment data is tokenised by our payment processor.
From the Xtudio mobile app
- Device push token (Firebase Cloud Messaging), device model, OS version, app version, IP address, timezone.
- Photos you choose to attach to a job or production stage, and files you generate such as quotation and receipt PDFs.
From visitors to x-tudio.com
- Early-access requests: workshop or business name, your name, email, phone number, country and message, submitted through the contact form and protected by Google reCAPTCHA.
- Analytics and server logs as described in section 11.
Automatically (security and operations)
- Server logs — IP address, user agent, request paths, timestamps — used for security, abuse prevention and debugging.
- An audit log of significant actions inside a workshop’s account (creations, updates, deletions, exports).
3. Customer and team data recorded by workshops
The Service is a platform that workshops use to run their business. A workshop records information in Xtudio about its customers — names, phone numbers, addresses, measurements, quotations, jobs, deposits, payments and outstanding balances, delivery details and photos of the work — and about its team, such as staff accounts and the stages they work on. Xtudio does not collect this information itself; it is entered or generated by the workshop in the course of using the Service, and Xtudio processes it strictly on the workshop’s behalf as a data processor.
The workshop, as controller, is responsible for having a lawful basis to record its customers’ details and for telling them how they are used, for example when it sends a quotation or receipt over WhatsApp.
If you are a customer of a workshop, that workshop is the controller of your details. Questions about what is stored about you, who can see it and how long it is kept should be directed to the workshop. We support workshops in responding, and if you cannot reach the workshop you may contact us directly (section 8).
4. Why we process this information
- Performance of contract: to deliver the features of the plan the workshop uses, in the mobile app and the web panel.
- Legal obligation: issuing tax invoices for paid subscriptions and meeting our own tax and accounting obligations.
- Consent: for early-access follow-ups and product newsletters, which you can withdraw at any time.
- Legitimate interest: security monitoring, fraud prevention and product improvement using aggregated, non-identifying data.
5. How long we keep information
- Workshop-recorded customer and team data: retained while the workshop’s account is active. The workshop controls correction and deletion through Xtudio. When an account is closed, the workshop can export its data; we delete it after the agreed hand-over period.
- User accounts: personal data (name, email, phone, profile) is purged within 30 days of account deletion. Account identifiers are retained for up to 90 days for audit and dispute resolution, then deleted.
- Early-access requests: kept for 12 months from the last contact, then deleted unless an account follows.
- Mobile push tokens and notification preferences: removed immediately on account deletion or device unregistration.
- Server logs: 90 days, except where a longer period is necessary for an open security incident.
- Backups: encrypted backups are kept on a rolling schedule and expire automatically; deleted data disappears from backups as they rotate.
6. Who we share information with
Xtudio does not sell personal data and does not use workshops’ customer data for advertising. We share data only with vetted processors that help us deliver the Service, and only to the extent necessary:
- Cloud hosting and content delivery — hosts the application, workshop databases and encrypted backups, and protects the site at the network edge.
- Messaging — Meta’s WhatsApp Business Platform, Messenger and Instagram, when a workshop connects its own accounts (sections 12 and 13); SMS providers for one-time codes where enabled.
- Push notifications — Google Firebase Cloud Messaging for the mobile app.
- Transactional email — for account emails such as password resets and alerts.
- Payment processing — for Xtudio subscription billing on paid plans.
- Website analytics and anti-abuse — Google Analytics and reCAPTCHA on x-tudio.com only.
Some of these processors operate outside Egypt. Data transferred internationally is encrypted in transit and protected by contractual safeguards recognised under PDPL Article 12.
7. How we keep information safe
- Encryption in transit (TLS 1.2+) and at rest for databases and backups.
- Isolation per workshop: each workshop’s data is kept separate, and no workshop can read another’s records.
- Role-based access for team accounts, so prices and profit can be hidden from staff unless the owner allows it, and optional two-factor authentication.
- Rate limiting and brute-force protection on authentication endpoints; per-user logins so every action is attributable.
- Audit logging of sensitive actions and exports; security review of new releases; strict security headers on all responses.
In the event of a personal data breach, Xtudio will notify the Personal Data Protection Centre and the affected workshop without undue delay in accordance with PDPL, and support the workshop in notifying affected people where required. To report a suspected security issue, contact [email protected].
8. Your rights
Under PDPL and equivalent regimes you have rights of access, correction, deletion, restriction, portability, objection and withdrawal of consent.
If you are a customer of a workshop, requests about your details should go to that workshop (the controller), which can act on them directly in Xtudio. Requests that concern Xtudio directly — for example deleting your own Xtudio account, or an early-access request you sent us — can be sent to [email protected]. If you cannot reach the workshop, contact us and we will assist. We respond within 30 days and may ask you to verify your identity first.
9. Account deletion
You can delete your Xtudio account from the mobile app under Settings → Account → Delete account. On confirmation:
- All active sessions and access tokens are revoked across every device.
- The account is marked as deleted and can no longer sign in.
- Mobile push tokens and notification preferences are removed immediately.
- Personal data (name, email address, phone number, profile) is permanently purged within 30 days. Account identifiers may be retained for up to 90 days solely for audit and dispute resolution, after which they are deleted.
- If you are a team member, the business records you created for the workshop (quotations, jobs, payments) stay with the workshop, which is the data controller for them.
No app access? Email [email protected] and we will process the request manually.
10. Children’s data
Xtudio is a business tool and is not directed at children under 18. If you believe a minor has registered an account, contact us and we will remove it.
11. Cookies & analytics
We use essential cookies (sign-in sessions, CSRF protection, language preference) across the platform, and your browser’s local storage to remember the light or dark theme. On our public marketing site (x-tudio.com) we also use Google Analytics to understand how visitors find and use the site; this sets Google cookies and shares usage data such as pages visited, device type and approximate location with Google. We do not use analytics inside the web panel or the app, and analytics data is never linked to a workshop’s customer records. You can block analytics cookies in your browser or via Google’s opt-out tools without affecting the site; blocking essential cookies may break sign-in.
12. Facebook Messenger & Instagram Direct messaging
Some Xtudio workshops connect their official Facebook Page and Instagram Business account so they can reply to customer messages from a single inbox, alongside WhatsApp. When you message one of these connected accounts, the workshop operating that account is the data controller for the conversation and Xtudio acts as a data processor, storing and displaying the messages on the workshop’s behalf. Our processing is consistent with Meta’s Platform Terms, Developer Policies, Messenger Platform Policy and Instagram Messaging API Policy.
What we receive from Meta and store when you message a connected account:
- A platform identifier — a Page-Scoped User ID (PSID) for Messenger or an Instagram-Scoped User ID (IGSID). These are specific to the account you messaged and cannot be used to identify you on other Pages or apps.
- Your public profile basics — the display name, username (Instagram only) and profile picture associated with your Facebook or Instagram account. We cache a copy of the profile picture so the inbox continues to display it after Meta’s temporary image link expires.
- Message content — the text, images, audio, video and files you send, together with timestamps, delivery and read receipts, reactions and button or quick-reply selections.
- Messaging-window timing — we log when your last message arrived so replies stay within Meta’s 24-hour standard messaging window, as required by Meta’s Platform Policy.
12.1 Instagram-specific data
When you contact a connected Instagram Business account, we additionally receive and store the following Instagram-specific items so the inbox can render the conversation faithfully:
- Story mentions — if you @-mention the connected account in your Instagram Story, the mention event (with a temporary media URL) is delivered to us so the workshop can see and reply. We do not download or persist the Story media beyond the link Meta gives us.
- Shared posts and Reels — when you share a Reel or post into the DM thread, we store the Meta-supplied reference (post ID and caption excerpt) so the workshop can see what you sent.
- Message reactions — emoji reactions you add to messages, anchored to the specific message ID they apply to.
- Read receipts — Instagram delivers a read receipt keyed to a specific message ID, and we mark only that message and earlier ones as read.
- Quick-reply selections — if you tap a quick-reply button, we receive its payload value (not the button title), used to route your reply inside the inbox.
Instagram conversations are stored under your Instagram-Scoped User ID (IGSID), which is unique to the account you contacted; it does not identify you on any other Page, app or Instagram account.
Automated replies. If a connected account is configured to send any automated reply, you will be told at the start of the conversation that you are chatting with an automated assistant and that a human can take over, in compliance with Meta’s Messenger and Instagram automation-disclosure rules.
Retention. Messenger and Instagram conversation data follows the retention periods in section 5: personal data is purged within 30 days of a deletion request and identifiers are kept for up to 90 days for audit, after which they are deleted.
Deleting your messaging data. You can remove Xtudio’s access from your Facebook settings (Settings & privacy → Settings → Apps and Websites) or your Instagram settings (Settings → Apps and Websites → Active). Doing so triggers our Data Deletion Callback at https://x-tudio.com/api/meta/data-deletion, which permanently deletes the conversations linked to your PSID (Messenger) or IGSID (Instagram) across our systems and returns a confirmation code you can use to track the request. You can also email [email protected] to request deletion manually.
13. WhatsApp messaging
Workshops use WhatsApp to reach their customers: sharing a quotation or receipt PDF, confirming a delivery date or following up on a balance. Where a workshop connects its own WhatsApp Business Account to Xtudio, these messages go out through the workshop’s own number. The workshop is the data controller for these conversations and Xtudio acts as a data processor.
What we store when you message, or are messaged by, a connected workshop on WhatsApp:
- Your phone number in international format, used as the WhatsApp address.
- Message content — the text, images, documents, audio, video, location and contact cards exchanged, plus any template variables filled in (for example your name and a quotation number).
- Delivery and read status — sent, delivered, read or failed receipts per message.
- Messaging-window timing — we log when your last inbound message arrived so replies stay within WhatsApp’s 24-hour customer-service window; outside it, only Meta-approved message templates are sent, as required by the WhatsApp Business Policy.
Consent. Workshops send WhatsApp messages only to customers who have agreed to be contacted that way. You can withdraw consent at any time by replying to ask the workshop to stop or by contacting the workshop.
Automated replies. If a workshop configures an automated reply, you are told at the start of the conversation that you are chatting with automation and how to reach a human.
Retention. WhatsApp conversation data follows the retention periods in section 5: personal data is purged within 30 days of a deletion request and identifiers are kept up to 90 days for audit, then deleted.
Deleting your WhatsApp data. Because WhatsApp is not a Facebook-login product, WhatsApp deletion requests are handled directly: email [email protected] (or ask the workshop) and we permanently delete the conversations tied to your phone number. (The Meta Data Deletion Callback at https://x-tudio.com/api/meta/data-deletion covers Messenger and Instagram, which are Facebook-login based.)
14. Changes to this policy
We may update this Privacy Policy from time to time. Material changes are notified to account owners by email at least 14 days in advance, and the date at the top of this page reflects the latest version.
15. Contact
- Privacy questions: [email protected]
- Security disclosures: [email protected]
- Data-subject requests: the workshop that holds your details, or [email protected] if you cannot reach it