Skip to main content

Privacy Policy

Last updated: September 2026

Overview

XO Report ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our Excel add-in and related services.

XO Report is the data controller for your personal data. For privacy-related inquiries, contact us at .

Data Controller

XO Report is operated by Clovis Global. For privacy inquiries: .

Information We Collect

Account Information

When you authenticate with Xero, we collect:

  • Your email address and name (from your Xero profile)
  • Your Xero user identifier
  • Names and identifiers of Xero organizations you authorize
  • Subscription and billing information (via Stripe)

Xero Data Access

XO Report connects to Xero using OAuth 2.0 with read-only access to your accounting data. We never create, modify, or delete any data in your Xero account. We access your Xero data only to provide the functionality you request (pulling data into Excel) and do not store your Xero financial data permanently on our servers.

We access the following Xero data based on your usage (read-only):

  • Chart of Accounts
  • Contacts (customers and suppliers)
  • Invoices and Bills
  • Payments and Credit Notes
  • Financial Reports (P&L, Balance Sheet, etc.)
  • Tracking Categories
  • Tax Rates and Currencies

Usage Data and Error Reporting

We collect limited data to improve our service and fix issues. Website page and event analytics are collected through Vercel Web Analytics and PostHog. They run by default everywhere so we can see which pages are useful and where visitors leave. Vercel Web Analytics is cookieless. There are two purposes you can control in Privacy settings; the notice asks about one thing only: advertising measurement:

  • Aggregate website page views and a small number of named site events (Vercel Web Analytics and PostHog)
  • Advertising measurement: campaign context such as a Google Ads click ID stored in your browser so we can tell which advertising works (see Campaign Attribution below)
  • Which add-in features you use (anonymized)
  • Error reports via Sentry (includes error messages, stack traces, and device/browser info)
  • Performance metrics

In the EEA, the UK, Switzerland, and every country we have not individually reviewed, PostHog keeps its identifiers in memory only, so analytics stores nothing on your device. Other things may still be saved in your browser: your own privacy choices, your display preference such as dark mode, strictly necessary cookies (see Cookies below), and, only if you allow advertising measurement, campaign attribution (see Campaign Attribution above) together with Google's own advertising storage. The notice you see asks about one thing only: advertising measurement. The notice offers two buttons: Allow all, or Cookie settings to decide per purpose. Until you allow it, advertising measurement stays off and no advertising consent, campaign context, or consent receipt is recorded; analytics runs as described above. You can switch analytics off at any time under Privacy settings in the footer; that choice is stored in your browser and remembered.

In the reviewed markets (currently the United States, Australia, New Zealand, and South Africa) analytics and advertising measurement are active by default without a notice, PostHog stores its identifiers in your browser's local storage, and the same Privacy settings switch both off.

Error reports help us identify and fix bugs. They may include technical details about your session but do not include your Xero financial data.

Campaign Attribution

We capture limited marketing-campaign context: UTM parameters (utm_source, utm_medium, utm_campaign, utm_term, and utm_content), ad-click identifiers (gclid and gad_source), the domain of the site that referred you, the landing page path, and the first and most recent times you arrived from a campaign link. We store this information in your browser's localStorage and, if you start Xero sign-in from our website, send it with that sign-in request to understand which campaigns lead to sign-ups. This website-to-account attribution is sent as an optional acquisition_context object.

Whether we capture this depends on where you are and on your choice:

  • EEA, UK, Switzerland, and other unreviewed countries: we capture campaign context only if you accept the advertising measurement purpose in the consent notice. If you reject it, or make no choice, we store nothing.
  • Reviewed default-on markets (United States, Australia, New Zealand, South Africa): campaign capture is active by default. An explicit "Reject" choice, a Global Privacy Control signal, or turning advertising measurement off in Privacy Settings opts you out and clears any stored attribution value.

We decide which rule applies using an approximate country classification derived from your IP address through Vercel's x-vercel-ip-country header. Its accuracy varies, so misclassification is possible and accepted.

The legal basis is your consent where we ask for it (the advertising measurement choice) and our legitimate interest in measuring marketing effectiveness elsewhere, together with contract performance for the website-to-account link.

How We Use Your Information

We use your information to:

  • Provide the XO Report service
  • Process your subscription and payments
  • Send important service updates
  • Provide customer support
  • Improve our product

We process your data based on:

  • Contract performance: Providing the service you subscribed to
  • Legitimate interests: Analytics operates under our legitimate interest in understanding site usage. It is collected through our own domain by the processors named above, is not used to identify you personally, and does not track you across other sites. In the opt-in regions its identifiers are held in memory only, so analytics itself stores nothing on your device, and you can turn it off durably at any time in Privacy settings.
  • Consent: Advertising measurement is under consent in the opt-in regions and under a notice-and-opt-out approach in the reviewed markets. The opt-in regions are the EEA, the UK, Switzerland, and every country we have not individually reviewed.
  • Legitimate interests: Error reporting, security, and service improvement other than the consent choices described above
  • Legal obligations: Tax records and fraud prevention

Data Security

We implement industry-standard security measures to protect your data:

  • All data is transmitted using TLS encryption
  • OAuth tokens are stored securely and never shared
  • We use Supabase for secure data storage with row-level security
  • We do not store your Xero password

AI and Machine Learning

Your Xero financial data is never used for AI training, machine learning, or any form of automated profiling. We do not sell, share, or provide your data to third parties for AI/ML purposes. Your data is used solely to deliver the XO Report service to you.

Data Retention

We retain your account information for as long as your account is active. Xero financial data is cached temporarily to improve performance and automatically purged:

  • Financial reports (P&L, Balance Sheet, etc.): cached for up to 30 minutes
  • Reference data (Chart of Accounts, Contacts, Tax Rates, etc.): cached for up to 1 hour

No Xero financial data is permanently stored on our servers. You can request deletion of your account data at any time.

When you allow advertising measurement, or turn analytics back on after switching it off, we record an affirmative receipt on our server for that grant, including the purpose settings recorded at that moment (analytics, advertising measurement), the consent version, notice ID and fingerprint, choices presented, service, server-received time, and a random receipt/grant identifier. Leaving the notice unanswered records no consent and sends no receipt. A refusal made in Privacy settings with no earlier grant is stored only locally in your browser and writes no receipt. The same is true of a Save in Privacy settings, made before any receipted grant, that only switches a purpose off or keeps your current choices: it writes no receipt, and whatever it needs to remember is kept only in your browser. Turning a purpose back on that was off is a grant and is receipted as described above. Changing your choices after a receipted grant sends one linked receipt for that change (a narrowing or a withdrawal) so the record of what you allowed stays accurate. In the reviewed default-on markets, analytics and advertising measurement may run without a prompt, subject to Global Privacy Control and your opt-out. The receipt also records the country and the consent policy our server observed for the request. The region is attested by our server, never claimed by your browser. A deployment identifier is included when available.

Consent receipts contain no IP address or user agent, are stored privately in Vercel's EU region, and are removed after approximately 24 months by a monthly sweep. When a best-effort withdrawal receipt is delivered, it links to the earlier grant.

Third-Party Services

We use the following third-party services:

  • Xero:Accounting data provider (subject to Xero's privacy policy)
  • Stripe:Payment processing (subject to Stripe's privacy policy)
  • Supabase: Database and authentication
  • Vercel (hosting):Web hosting for this site and the XO Report account portal (subject to Vercel's privacy policy)
  • Vercel Web Analytics: Subject to the analytics choice described above, this measures aggregate page views and a small number of named site events. For Analytics events, XO Report removes query strings and fragments from the event URL. Analytics processes the sanitized page path, referrer, approximate country, region and city, device type, operating-system and browser versions, and timestamp. Vercel derives a short-lived session hash from the incoming request; the IP address is used to derive it but is not stored in Analytics, and the hash is discarded after 24 hours. Vercel may process data internationally under its data-processing terms; private consent receipts in the EU do not limit all Vercel processing to the EU.
  • PostHog (analytics processor):As described above, PostHog measures anonymous website usage: page views, clicks, referrer, and campaign parameters (e.g. UTM tags), with an approximate location derived from your IP address. PostHog does not track you across other sites, and we never send it your name, email, or account identity. In opt-in regions, PostHog keeps its identifiers in memory only; in reviewed default-on markets, PostHog stores its identifiers in your browser's local storage. PostHog never uses a cookie for analytics. If you switch analytics off, PostHog records that opt-out flag in your browser so it stays off. Requests are routed through our own domain (not PostHog's), and are stored and processed in PostHog Cloud EU (Frankfurt). PostHog uses Cloudflare as a global network subprocessor at the connection edge, so this EU-residency guarantee covers where your data is stored and processed, not where the network connection first terminates.
  • Google Ads (advertising measurement): When the advertising measurement purpose is active, campaign identifiers such as a Google Ads click ID are stored in your browser. When advertising-measurement tags are enabled, this data is shared with Google for conversion measurement, and Google acts as an independent controller for that measurement under How Google uses information from sites or apps that use our services. This is measurement only: no personalized advertising takes place, and Google's ad_personalization signal is denied.
  • Sentry: Error monitoring and performance tracking
  • Microsoft: Excel add-in platform
  • Twilio SendGrid:Transactional / operational email relay for service notifications (subject to Twilio's privacy policy)

Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR) and similar laws, you have the following rights regarding your personal data:

  • Right to Access (Art. 15): Request a copy of all personal data we hold about you
  • Right to Rectification (Art. 16): Correct inaccurate or incomplete personal data
  • Right to Erasure (Art. 17):Request deletion of your personal data ("right to be forgotten"), available self-service from your account portal or by contacting us
  • Right to Restriction (Art. 18): Restrict the processing of your personal data in certain circumstances
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format
  • Right to Object (Art. 21): Object to processing of your personal data based on legitimate interests
  • Automated Decision-Making (Art. 22): We do not make automated decisions about you. Your data is never used for profiling or automated decision-making.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a data-protection supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee. If you are in another EU/EEA country, you may also complain to your local authority.

How to Exercise Your Rights

You can exercise your rights in two ways:

  • Self-service deletion:Use "Delete My Account" from your account portal under Advanced. Your account enters a 30-day cooling-off period during which you can cancel the deletion. After 30 days, all personal data is permanently deleted.
  • Email: Contact for any rights request. We will respond within 30 days as required by GDPR.

Delete Your Account

You can permanently delete your account and all associated personal data at any time. Here is how the process works:

  • How to request: Go to your account portal > Advanced > "Delete My Account", or email .
  • 30-day cooling-off period: After requesting deletion, your account enters a 30-day cooling-off period. During this time, you can cancel the deletion request from your account page (a banner at the top shows the scheduled deletion date and a Cancel Deletion button).
  • Immediate effects: Upon requesting deletion, your Xero access is disconnected, XO Report starts any related cache-cleanup work, and any active subscription enters the cancellation process.
  • After 30 days: All personal data is permanently and irreversibly deleted, including your account information, Xero organization data, authentication tokens, and error reports linked to your account.
  • Billing records: Anonymized billing records (with no personally identifiable information) are retained for 7 years as required by applicable accounting law.
  • Audit trail: An anonymized record of the deletion event is kept for compliance purposes. This record contains only a one-way hash of your user ID (not reversible to your identity) and the deletion timestamp.

Cookies

Our website uses necessary cookies for authentication and session management. We also use browser localStorage to remember your consent choices. If your browser cannot read or save your consent choice there, we set one strictly necessary cookie, xo-report-consent-failsafe (and the same marker in your browser's session storage), that keeps analytics and advertising measurement switched off after a reload and in your other open tabs (and, while the cookie is stored, in any tab you open later) until a later choice can be saved normally; both are removed at that point and the cookie otherwise expires after 12 months. Analytics stays cookie-free: Vercel Web Analytics is cookieless, and PostHog keeps its identifiers in memory only in opt-in regions and in your browser's local storage in reviewed default-on markets. PostHog never uses a cookie for analytics, so neither provider ever sets an analytics cookie.

The website always works before you make a choice. In the EEA, the UK, Switzerland, and every unreviewed country, a notice appears when you first visit and asks about advertising measurement only. The notice offers two buttons: Cookie settings and Allow all. Advertising measurement does not run until you choose; analytics runs as described above. In the reviewed default-on markets (United States, Australia, New Zealand, South Africa) both purposes are on by default and no notice is shown; Privacy settings in the footer turns both off at any time.

A grant is valid for 12 months. A refusal remains until you change it or the scope materially changes. In August 2026 we added the advertising measurement purpose and therefore, in the jurisdictions where we ask for consent up front (the EEA, the UK, Switzerland, and every unreviewed country), re-asked prior refusals (once) whether they also wanted to allow it; their earlier refusal stayed in force until they answered. A durable refusal in a reviewed default-on market remains honoured there without a new prompt. Withdrawal takes effect immediately. A Global Privacy Control signal detected when the page loads is treated as a refusal of both purposes worldwide, including in the default-on markets.

Children's Privacy

XO Report is not intended for use by children under 16. We do not knowingly collect information from children.

International Data Transfers

Your data may be processed in countries outside your own, including the United States (where our infrastructure providers operate). We ensure appropriate safeguards are in place, including Standard Contractual Clauses where required.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes via email or through our service.

Governing Law

This Privacy Policy is governed by the laws of the European Union, specifically the General Data Protection Regulation (GDPR).

Contact Us

If you have questions about this Privacy Policy, email us at .