XpressBase

Privacy Policy

Effective September 28, 2026

This policy explains what XpressBase Inc. collects, why we collect it, who we share it with, and the choices you have. It covers xpressbase.com and our products, including XpressBooks, our accounting and bookkeeping service.

1. Who we are

XpressBase Inc. (“XpressBase,” “we,” “us”) is a California corporation located at 112 E. Amerige Ave, Fullerton, CA 92832. We build and operate business software, including XpressOps, XpressManage, XpressDesk, XpressBooks, XpressFlux, XpressPlace, XpressWorks, and Xpress Designer (each a “Service”).

This policy applies to our websites and to the Services. Where we provide a Service to a business that is itself our customer, that business controls the data it puts into the Service, and we process that data on its behalf.

2. Information we collect

Information you give us

  • Account information — your name, email address, and password. Passwords are stored only as salted hashes; we never see or store your password in readable form.
  • Business information — company name, address, phone, tax identification number, logo, and similar details you enter to appear on documents such as invoices.
  • Financial records you create or upload — invoices, estimates, bills, payments, customers and vendors, products and prices, chart of accounts, and uploaded documents such as bank statement PDFs and receipts.
  • Communications — messages you send us, including support requests and early-access enquiries.

Information from your bank, through Plaid

If you choose to connect a bank account, that connection is made by Plaid Inc., not by us. You enter your banking credentials with Plaid; they never reach XpressBase and we cannot see them. Plaid returns a read-only access token that lets us retrieve account details, balances, and transaction history — typically up to 24 months at the time of connection, and new transactions thereafter. We cannot move money with this connection. Plaid’s handling of your information is governed by its own End User Privacy Policy. You can disconnect a bank at any time, which revokes our token.

Information from your calendar, through Microsoft 365

If you connect a Microsoft 365 calendar to XpressFlux bookings, you sign in with Microsoft and choose one calendar. Your Microsoft password never reaches XpressBase. Microsoft returns an access token, which we store encrypted. With it, XpressFlux:

  • reads your name and email address from your Microsoft account, and the names of your calendars, so you can confirm the connection and pick a calendar;
  • reads only the start and end times, busy status, and cancellation status of events on the calendar you chose, so it doesn’t offer times you’re already busy. It doesn’t read the titles, attendees, locations, or notes of your events;
  • adds, moves, and removes an event for each booking made through XpressFlux. These events carry the service, the time, the booking number, and the customer’s name and phone number.

You can disconnect the calendar at any time from the Bookings page, which deletes our stored token. Events already added to your calendar stay there until you remove them. Microsoft’s handling of your information is governed by the Microsoft Privacy Statement.

Text messages

When you call XpressBase, our phone attendant may offer to text you appointment confirmations and reminders, the details you asked for, or a note that we got your message. We text you only after you agree on the call. We keep your mobile number, the fact and time you agreed, and a record of the texts we sent, and we use them only to send the texts you agreed to. You can reply STOP at any time to stop the texts, or HELP for help. We don’t sell or share mobile numbers or text messaging consent with third parties or affiliates for their marketing or promotional purposes. Our texting provider, Telnyx, delivers the messages for us.

Information collected automatically

  • Technical and usage data — IP address, browser and device type, pages viewed, and timestamps, used to operate and secure the Services.
  • Security and audit logs — records of authentication events and of significant actions taken in your account, retained so that you and we can investigate problems.

Payment information

Payments are processed by Stripe, Inc. We do not receive or store full payment card numbers. We retain a record of the transaction, the last four digits, and the card brand.

3. How we use information

  • To provide, maintain, and improve the Services.
  • To import, categorize, and reconcile financial transactions, and to produce the books, reports, and documents you ask for.
  • To send transactional messages, such as an invoice you asked us to email to your customer.
  • To take payment, prevent fraud and abuse, and secure the Services.
  • To respond to you, and to send service notices. Marketing email is separate and optional.
  • To comply with law and enforce our agreements.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use the contents of your financial records to advertise to you.

4. Automated processing and AI features

Some features use third-party artificial-intelligence services to read and interpret your data. Specifically:

  • Transaction categorization — transaction descriptions, amounts, dates, and merchant names may be sent to an AI provider to suggest an accounting category.
  • Statement and document extraction — when you upload a bank statement or similar document, its contents may be sent to an AI provider to extract the transactions within it.

We currently use Anthropic and OpenAI for this processing, under commercial API terms that prohibit them from using your data to train their models. These features produce suggestions, not decisions: categorizations are yours to review, correct, and approve, and no legal or financial determination about you is made automatically.

5. Who we share information with

We share information with service providers who process it on our behalf, under contract, for the purposes described above:

  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting and content delivery.
  • Plaid — bank account connections.
  • Microsoft — calendar connections you choose to make, described in section 2.
  • Stripe — payment processing.
  • Resend — delivery of transactional email.
  • Anthropic and OpenAI — the AI processing described in section 4.

We also disclose information when required by law or valid legal process, to protect our rights or the safety of others, and in connection with a merger, acquisition, or sale of assets — in which case we will give notice before your information becomes subject to a different policy.

6. How we protect information

  • Data is encrypted in transit with TLS 1.2 or higher, and at rest with AES-256.
  • Each account’s data is isolated at the database level, so one customer’s records cannot be read by another.
  • Bank access tokens are encrypted with a key held separately from the database.
  • Administrative access requires multi-factor authentication and follows least privilege.
  • Authentication and data-access events are logged.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and any regulator as required by law.

7. How long we keep information

We keep your information for as long as your account is active and for as long as needed to provide the Services. When you delete your account, we revoke connected bank tokens within 24 hours and permanently delete your data within 30 days, except where we must retain records to comply with law, resolve disputes, or enforce our agreements. Backups are purged on their own rotation, no later than 90 days.

8. Your rights and choices

Whatever your location, you may access, correct, export, or delete your data from within the Service, or by contacting us.

California residents

Under the CCPA/CPRA you have the right to know what personal information we collect and how we use and disclose it; to request deletion or correction; and to be free from discrimination for exercising these rights. We do not sell or share personal information as those terms are defined by that law, and we do not knowingly process the personal information of anyone under 16.

EEA and UK residents

Where the GDPR or UK GDPR applies, our legal bases are performance of a contract with you, compliance with legal obligations, and our legitimate interests in operating and securing the Services. You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your supervisory authority. Where we transfer data outside your region, we rely on Standard Contractual Clauses.

To exercise any right, email privacy@xpressbase.com. We will verify your request and respond within the time the law allows.

9. Financial information

Some information we handle is nonpublic personal financial information subject to the Gramm-Leach-Bliley Act. We use it only to deliver the Services you have requested and as permitted by law, and we do not disclose it to third parties for their own marketing.

10. Cookies

We use cookies and similar local storage that are necessary for the Services to function — keeping you signed in and maintaining your session — and a limited amount of privacy-respecting analytics to understand aggregate usage. We do not use advertising cookies.

11. Children

The Services are for business use and are not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact us and we will delete it.

12. Changes to this policy

We may update this policy. If a change is material, we will notify you by email or in the Service before it takes effect. The effective date above always reflects the current version.

13. Contact us

XpressBase Inc.
112 E. Amerige Ave, Fullerton, CA 92832
privacy@xpressbase.com