xBoox Privacy Policy
Draft privacy notice for development review. Not approved, published, or in effect.
DEVELOPMENT PREVIEW — DRAFT — NOT APPROVED OR IN EFFECT This incomplete draft may be displayed only as a clearly labelled preview on the development Portal. It must not be presented as an effective privacy notice until the release blockers below are resolved, the production service is verified, and Canadian privacy counsel approves the final text.
- Operator: XFUTURE SYSTEMS LTD.
- Product and brand: xBoox
- Effective date: Not assigned
Last updated: July 13, 2026
Release blockers — complete before publication
The Privacy Officer role is assigned by title, and admin@xboox.ca is approved as the public privacy-request channel. The following information is still required before this policy can be approved or published:
- the legal and business address of XFUTURE SYSTEMS LTD.;
- operational delivery, monitoring, and backup coverage for the approved
admin@xboox.ca privacy channel and approval of its intended additional security-report and legal-notice scope;
- implementation and legal review of the Executive-approved Canadian
age-of-majority and business-purpose direction, including province/territory-specific requirements, invited users, access from outside Canada, temporary access or relocation, and minors or other people whose information may appear in a Workspace;
- implementation and testing of the approved non-renewal Workspace lifecycle
and approval of the remaining category-level retention/deletion rules, backup/provider residual handling, legal holds, and deletion evidence;
- verified service-provider contracting entities, material processing
locations, subprocessors, applicable contract or data-processing terms, and retention and deletion controls;
- activation and testing of the internal [Privacy Request and Retention
Runbook](../internal/privacy-request-runbook.md), including access, correction, deletion, consent withdrawal, complaint, identity verification, deadlines, and secure case records; and
- approved consent and notice experiences for any processing that requires
consent or a separate just-in-time explanation; and
- completion of
LQ-026before Receipt Capture OCR is enabled inprd,
including Google Cloud account/contract review, DPA applicability, administrators, subprocessors, request-metadata retention, key handling, cross-border wording, and final production configuration.
The final policy must also be rechecked against the production service and the actual practices in effect on its proposed effective date.
1. About this policy
This policy explains how XFUTURE SYSTEMS LTD. ("XFUTURE," "we," "us," or "our") collects, uses, discloses, retains, and otherwise processes personal information when providing xBoox.
xBoox is a bookkeeping application organized by Workspace. A Workspace may contain information about its owner, accountants, contacts, payees, suppliers, customers, tenants, properties, and other individuals. The person using xBoox may therefore provide personal information about themselves and about other people.
The current product is structured around Canadian business bookkeeping for self-employed/sole-proprietor and corporation Workspaces and invited accountants or advisers. British Columbia is expected to be the principal early market, and early adoption may be concentrated there; that commercial focus is not an exclusive service territory or a BC-location requirement. Professionals and businesses elsewhere in Canada are part of the intended product market. The final account-eligibility and acceptance controls have not been implemented or made effective, and a tax setting does not prove service availability or location. This product positioning does not limit this policy or the privacy rights of an account user or any other person whose information is processed in a Workspace, including a person in another province, territory, or country.
This policy applies to the xBoox application, Portal, Help Center, and related services operated by XFUTURE, including XFUTURE's use of service providers acting on its behalf. It does not govern the independent practices of a third-party website or service that a user chooses to visit or use under that third party's own privacy notice.
2. Key privacy considerations
xBoox may process sensitive bookkeeping, banking, tax, property, attachment, and audit information. The main privacy considerations are that:
- information in a Workspace may be available to authorized Workspace members,
including an invited accountant or adviser;
- service providers process information as needed to authenticate users and
operate, host, secure, and support xBoox;
- personal information may be processed in another jurisdiction and may be
subject to that jurisdiction's laws, as described in section 7;
- invitation links, attachments, reports, and exports can expose sensitive
information if they are sent to or accessed by an unintended person;
- a Workspace user may enter information about customers, suppliers, tenants,
employees, or other people and must have authority to do so; and
- declining to provide information, or withdrawing consent where consent is the
basis for processing, may prevent xBoox from providing a requested feature.
Where we rely on consent, we will provide understandable information about the nature, purpose, and consequences of the processing, including these material privacy implications and any other significant risk that applies to the feature being used.
3. Personal information we process
The information processed depends on the features a user chooses and the information entered or uploaded to a Workspace.
Account, identity, and login information
Auth0 provides xBoox with identity claims such as an Auth0 user identifier, email address, and display name. xBoox also processes authentication, session, and sign-in information needed to provide and protect an account.
Workspace and accountant-access information
xBoox processes Workspace names and identifiers, membership role, permission level, membership status, invitation email, invitation status and expiry, inviting and accepting users, and revocation information.
An active Workspace member may see information made available through that Workspace according to their role and permissions. Invitation links should be treated as confidential and shared only with the intended recipient.
Business Profile and tax setup
xBoox may process a business name, currency, business structure, fiscal-year settings, sales-tax settings, and related Business Profile configuration.
Contacts, categories, and tags
A Workspace user may add contact names, contact types, email addresses, phone numbers, websites, notes, tag names, colours, and category or account information. These records may identify people other than the signed-in user.
Bookkeeping, banking, and tax records
xBoox processes records such as transaction dates, descriptions, payees or payers, amounts, currency, payment method or account, categories, notes, tax amounts and rates, deductible percentages, source information, matching and reconciliation state, journal entries, reports, and audit history.
When a user imports statement information, xBoox processes the selected file and the account and transaction information it contains. A user should review imported information before using it for bookkeeping or reporting.
Attachments
A Workspace user may upload attachments such as receipts, invoices, and other supporting documents. These files and their associated information may contain names, addresses, account details, tax details, or other personal and financial information selected by the user.
Receipt Capture and OCR
In the current dev Receipt Capture workflow, a user may select or photograph a JPEG or PNG receipt. The browser compresses the image before upload. xBoox stores the receipt in private attachment storage and may process merchant, date, currency, subtotal, tax, tip, total, OCR text and annotation data, confidence, Category suggestions, duplicate indicators, review status, and OCR usage information.
For online OCR, the Worker sends the compressed receipt image to the Google Cloud Vision US regional endpoint and receives extracted text and annotation results. The request does not include the xBoox Workspace ID, Auth0 token, payment account, Category, or user profile. Google states that online image requests are governed by its Cloud service terms and documentation. The final production provider terms, metadata handling, and deletion behaviour have not yet been approved, and this draft does not promise a provider retention or deletion outcome. Receipt Capture remains a dev feature; its final production provider facts and public wording are release blockers.
Property and working-paper information
Depending on the features used, xBoox may process property addresses, costs, allocations, sale information, notes, area or use information, and other details needed to prepare property or working-paper calculations.
Audit, device, and request information
xBoox and its service providers may process device, browser, IP address, request, session, date and time, and application-activity information. xBoox may also maintain audit information about actions taken in a Workspace and the records affected by those actions.
Browser-local information
xBoox and its authentication provider use browser storage, cookies, or similar technologies to support authentication, sessions, preferences, Workspace selection, security, and continuity between related product steps. Browser and device settings may allow a user to clear or restrict some of this information, which may sign the user out or affect product functions.
Support and other communications
When a person contacts xBoox, we process the contact details, message contents, attachments, and related communication information they choose to provide.
4. How we collect personal information
We may collect personal information:
- directly from a user when they create or use a Workspace, enter records,
upload an attachment, capture or select a receipt image, select a .qbo file, generate an invitation, or contact support;
- from Auth0 when a user authenticates;
- from a Workspace Owner, member, or invited accountant who enters information
or uses a sharing or invitation function; and
- automatically from browsers, devices, and network requests when the Portal,
application, or API is used.
5. Why we process personal information
We process personal information as reasonably necessary to:
- authenticate users and maintain account and sign-in activity;
- create, select, operate, and protect Workspaces;
- enforce Workspace membership and permission levels;
- provide bookkeeping entry, statement import, matching, reconciliation,
reporting, year-end, property, working-paper, attachment, and export features;
- provide Receipt Capture, extract receipt text, generate draft review
suggestions, detect possible duplicates, and track feature usage when that workflow is enabled;
- generate, review, accept, refresh, and revoke accountant-access links;
- maintain records of changes and investigate errors, misuse, security events,
and privacy incidents;
- respond to support requests initiated by a user;
- diagnose errors and maintain the reliability of the service; and
- meet obligations or exercise rights permitted or required by applicable law.
Where consent is required, it must be sought in a form appropriate to the information and purpose. Some processing is necessary to provide a feature the user requests; declining to provide that information may mean the feature cannot operate. A new materially different purpose must be reviewed and communicated before the information is used for that purpose, unless applicable law permits otherwise.
6. When personal information is disclosed
Personal information may be disclosed in the following circumstances.
Within a Workspace
Information may be available to the Workspace Owner and active Workspace members, including an accountant, according to their role, permission level, and access rights. A Workspace Owner can grant or revoke accountant access. Users should add only people who are authorized to access the Workspace and should review access when a person's role or authority changes.
An invited accountant or adviser is chosen by the Workspace Owner and may process Workspace information for the Owner, their own firm, or both. They do not process that information as XFUTURE's employee or agent merely because they use xBoox. Their firm does not become an xBoox customer merely because an individual accepts an invitation, unless the firm is expressly identified as a customer in an effective agreement.
Service providers
We use service providers to operate xBoox. Current providers include:
- Cloudflare, which provides application hosting, network, processing,
database, and file-storage infrastructure; and
- Auth0 (Okta), which provides authentication and identity services.
The current dev Receipt Capture workflow also uses Google Cloud Vision for online receipt OCR through a US regional endpoint. It must not be enabled in prd until the vendor/privacy review in LQ-026 is completed and the final policy accurately describes the approved production arrangement.
We may also use providers for content delivery, communications, support, and other operational functions. These providers may process personal information and technical information needed to perform those functions, subject to the final verified arrangements and applicable law. The final policy will reflect the verified providers and material processing arrangements in effect when it becomes effective.
Legal and organizational events
We may use or disclose personal information where permitted or required by applicable law, including to respond to lawful process, protect legal rights, investigate fraud or security incidents, or support a proposed financing, reorganization, sale, or transfer of all or part of the business, subject to applicable legal safeguards.
7. Processing locations and cross-border access
Release-blocker notice: The locations from which XFUTURE, its service providers, and their subprocessors may store or access personal information must be verified before publication.
The dev Receipt Capture implementation sends online OCR requests to a Google Cloud Vision US regional endpoint. That code selection does not by itself prove all contractual processing, support, request-metadata, or subprocessor locations. The final policy must reflect the reviewed production arrangement.
Personal information may be processed outside the province, territory, or country where a person lives. When information is processed in another jurisdiction, it may be subject to that jurisdiction's laws and lawful access by courts, regulators, law-enforcement agencies, or other authorities. The final policy will identify material processing geographies based on verified facts.
8. Retention and deletion
For an ordinary failure to complete a required renewal, XFUTURE has approved the following business direction: ordinary use is suspended immediately while a single 12-month retention/restoration period begins on the non-renewal effective date; authenticated export-only access is available during the first 90 days of that period; after day 90 the affected Workspace is closed to ordinary/export access and its data remains in a restricted recoverable archive for the balance of the same 12-month period; renewal within the overall 12 months may restore ordinary use of that Workspace; and expiry of the overall period triggers deletion or de-identification of primary Workspace data. Non-renewal of one Workspace does not by itself close the person's identity account or another Workspace to which they retain valid access.
The minimum implementation direction is to limit export-only and renewal access for a non-renewed Workspace to its Workspace Owner and end invited-user access when ordinary use is suspended. A different representative may be considered only after XFUTURE verifies appropriate legal authority under an approved process. This access rule is not implemented or effective.
This direction does not override a valid privacy request, legal hold, live dispute, applicable retention requirement, security restriction, or separately approved minimum company record. Deletion from primary systems may not immediately remove a residual copy governed by a verified backup or service- provider lifecycle. Information that a user downloads, exports, or shares is controlled by that user and any recipient after it leaves xBoox.
Receipt images, OCR text and annotations, extraction fields, usage records, attachments, and any confirmed transaction created from a receipt are subject to the applicable approved Workspace, attachment, transaction, provider, and legal-hold rules. Deleting a pending capture or transaction is not represented as a complete provider, backup, audit, or legal-record purge until the final workflow is implemented and verified.
Release-blocker notice: the lifecycle above is not implemented or effective. Export scope, access-state transitions, restoration, notices, deletion across D1/R2/Auth0/providers/backups, exception handling, evidence, and the remaining category-level periods must be implemented, tested, and legally reviewed before publication. A product export must not be described as containing all personal or Workspace information unless that scope is verified.
For other categories, we will retain personal information using criteria appropriate to the purpose for which it was collected, the sensitivity of the information, legal, tax, accounting, and regulatory requirements, security and fraud prevention needs, dispute resolution, and the establishment or defence of legal claims. When information is no longer required under the approved criteria, it will be deleted, anonymized, or otherwise disposed of in accordance with the verified process and applicable law.
9. Safeguards and incidents
We use administrative, technical, and organizational safeguards designed to protect personal information against loss, theft, and unauthorized access, use, disclosure, alteration, or destruction. These safeguards include account and access controls, Workspace permissions, restricted service access, and activity records appropriate to the nature of the service. No safeguard or system can eliminate every risk.
If a privacy or security incident occurs, XFUTURE SYSTEMS LTD. will assess and respond to it and will report to regulators and notify affected individuals when required by applicable law. The public contact and operational escalation details remain release blockers.
10. Access, correction, deletion, and other choices
Depending on applicable law and subject to lawful exceptions, a person may have rights to:
- ask whether we hold personal information about them;
- request access to that information and information about its use or
disclosure;
- challenge its accuracy and request a correction;
- withdraw consent where processing depends on consent, understanding that this
may affect requested features;
- request deletion or another permitted restriction; and
- make a privacy complaint to us or an applicable privacy regulator.
Product exports may not include all personal information we hold and may not be a complete response to a privacy access or portability request. Some information about a person may also have been provided by a Workspace Owner or another member, so a request may require coordination and verification of identity and authority.
Release-blocker notice: admin@xboox.ca is the approved privacy-request channel, the Privacy Officer role is assigned, and an internal request runbook exists. Mailbox monitoring, backup coverage, secure case storage, the category-level retention schedule, and the actual access/correction/deletion capabilities must still be activated and tested before publication.
11. Workspace users and information about other people
A Workspace user must have lawful authority to enter, upload, use, or share personal information about another person. Where required, the user is responsible for providing notices and obtaining consent appropriate to the user's collection and use of that information.
Workspace Owners are responsible for choosing appropriate members and permissions, sending invitation links securely, reviewing access, and revoking access that is no longer required. Users should enter only information that is reasonably needed for an authorized bookkeeping or business purpose and should protect attachments, reports, and exports from unauthorized access.
These user responsibilities do not remove XFUTURE's obligations under applicable privacy law for the personal information it processes.
12. Minors
The approved initial eligibility direction would require account users to have reached the age of majority in their Canadian province or territory. This business direction is approved but has not been implemented or made effective and remains a release blocker. Even if minor account users are prohibited, a Workspace could contain information about a minor entered for an authorized business purpose. The final policy and service design must address both situations and establish the approved consent, verification, restriction, and response procedure for the applicable jurisdictions.
13. Changes to this policy
We may update the final policy when the service, data practices, vendors, or applicable legal requirements change. The published policy will show its last updated date. We will provide any additional notice or obtain consent where required by applicable law.
14. Contact and complaints
RELEASE BLOCKER — DO NOT PUBLISH WITH PLACEHOLDERS - Privacy Officer/person responsible: Privacy Officer, XFUTURE SYSTEMS LTD. (public title; personal name not published) - Privacy email or request channel: admin@xboox.ca (approved; also proposed as the minimum security-report and legal-notice channel; operational delivery, monitoring, scope approval, and backup coverage not yet verified) - Legal/business address: Not confirmed - Telephone or alternate accessible channel: Not confirmedThe final section must explain how to submit a privacy question, access or correction request, deletion request, consent withdrawal, or complaint; how identity will be verified; and how to contact the applicable privacy regulator after the regulator pathways applicable to the person, organization, and processing involved have been confirmed.