This Privacy Policy explains how Spixor collects, uses, stores and protects personal data in connection with the Spixor Alpha environment, including the website, account system, dashboard, builder, file handling, exports, Spixor Share functionality, support channels and operational update notices. This is an Alpha product. Practices may evolve as the product grows.
1. Who we are
Spixor is a no-code website builder operating from the Netherlands. Spixor is currently in pre-launch Alpha development. For data protection questions, please use the Support page.
2. Data we collect
- Account data: email address, username, display name, password hash, verification status and account metadata.
- Access request data: role, project description, how you found Spixor and test intent submitted during early access.
- Service usage data: projects, files, exports, share configurations and product activity needed to operate the service.
- Technical and security data: IP-derived identifiers, browser user agent, login attempts, activation events, access logs and administrative audit records.
- Support data: messages, email addresses, attachments and context submitted through support channels.
- Email data: verification logs, password reset events, unsubscribe status and transactional mail records.
- File uploads: files uploaded through File Manager, attached to exports or used in builder projects.
3. How we use data
- To create and secure accounts and verify email addresses.
- To issue and manage activation keys and access requests.
- To operate the dashboard, builder, exports, files, share functionality and support.
- To detect abuse, investigate incidents, maintain audit trails and protect the platform.
- To send transactional notices: account verification, password reset, support activation, maintenance alerts.
- To send optional product updates and feedback requests where you have subscribed.
4. Legal bases
We process personal data to provide requested services, perform pre-contractual steps, meet legal obligations, protect platform security and pursue legitimate interests including product development, fraud prevention and support. Where required by applicable law, we rely on appropriate legal bases for each processing purpose.
5. Cookies and similar technologies
Spixor uses strictly necessary cookies for session management, security and login. Optional cookies for preferences, analytics and marketing are only activated after your consent through the cookie banner. You can manage or withdraw cookie consent at any time using the Cookie settings link in the footer.
6. Analytics and usage data
Analytics and usage tracking are only activated after explicit consent. During Alpha, usage data may be collected in minimal form to understand product health and improve the experience. No advertising profiling is performed.
7. Referral and source data
If you access Spixor through a referral link, affiliate or campaign URL, source identifiers may be captured for operational and growth analysis. Marketing-grade tracking is only activated after consent.
8. Email and retention communication
Transactional emails (verification, password reset, support activation, security alerts) are functional and cannot be opted out of. Non-essential emails (product updates, Alpha feedback requests) can be unsubscribed at any time via the unsubscribe link in the email or through the email preferences page.
9. Sharing with processors
We do not sell personal data. We may use infrastructure, hosting, email delivery, analytics, logging or payment processors that process data on our behalf. Stripe handles payment processing for Orbit subscriptions when available. Each processor is bound by appropriate data processing terms.
10. International users
Spixor may be accessed internationally. The service is operated from within the European Union context. By using the service, you understand that your data may be processed in jurisdictions where different data protection laws apply, subject to appropriate safeguards.
11. Data retention
We retain data for as long as reasonably necessary to operate the Alpha, manage access, support users, investigate incidents, enforce policies and comply with legal obligations. Some data may remain in backups for a limited additional period after deletion requests are actioned.
12. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, port or object to processing of your personal data, or to withdraw consent for certain communications. Contact us through the Support page to exercise applicable rights.
13. Security
We apply reasonable administrative, technical and organizational measures to protect personal data. However, no internet-based service can guarantee absolute security, particularly during pre-launch development.
14. Children
The service is not intended for children below the minimum legal age in the applicable jurisdiction without appropriate authorization.
15. Changes to this policy
We may update this Privacy Policy as the product evolves. Material changes will be communicated through the service or by email where applicable. Continued use after changes constitutes acceptance.
16. Contact
For privacy-related questions or requests, please use the Support page. We aim to respond to data-related requests within a reasonable timeframe.
