Privacy Policy

Version v1.2.0 · Effective 2026-08-05

1. Overview

Xerothread builds aggregated sell-through insights from independent retailers. This policy explains what we collect, how we use and share it, how long we keep it, and the choices available to you.

We design the panel so shopper personal data is not collected: the data we take in is limited to business fields such as products, quantities, prices, and timestamps.

2. Data we collect

Merchant business data: store identity and profile, POS connection metadata, product catalog fields, and the transaction line items needed for aggregation. Our POS integrations and file imports request and store only business fields; customer data fields such as names, emails, phone numbers, and loyalty identifiers are excluded before storage, and we do not ask shoppers for any personal information.

Account data: authentication identifiers handled by our authentication provider, and contact details you submit to us (for example through buyer lead forms or support requests).

Agreement acceptance records: signed Merchant Data Agreement acceptances record the signer name, title (if provided), timestamp, and IP address.

Business outreach records: contact and outreach information about retail stores we may invite to the panel, such as store name, address, business phone, owner or staff contact names, and notes from our outreach. Sources: public listings, industry directories, trade events, and our own conversations. Purposes: inviting stores to join the panel and managing those relationships.

Technical logs: our systems and hosting providers log technical data such as IP address, browser user agent, requested URLs, timestamps, and approximate location derived from IP address.

3. How we use data

We use data to:

Operate store dashboards and POS sync.

Produce suppressed, anonymized aggregates for the Trend Index and concierge buyer reports.

Respond to inbound buyer leads and merchant support requests, and invite stores to join the panel.

Maintain records of Merchant Data Agreement acceptances.

Secure and debug the services, including rate limiting and abuse prevention.

4. Cookies and similar technologies

The store dashboard uses first-party cookies that are necessary to run the service: authentication and session cookies, and short-lived security cookies used during POS connection.

Our authentication provider's infrastructure may set its own cookies and collect related technical data when you use the dashboard.

We do not use advertising cookies, third-party analytics, or session-replay tools anywhere. Our marketing site sets no cookies.

5. How we share data

Buyer-facing products only include aggregated cells that pass k-anonymity and dominance suppression. We do not sell store-identifiable data or personal contact information.

Xerothread maintains and uses released aggregates only in deidentified form and will not attempt to reidentify any store or individual, except as permitted by law to test deidentification.

We use service providers ("processors") that process data on our behalf under contracts or service terms that limit their use of the data: cloud hosting and database, authentication, email delivery, object storage, workflow and event processing (Inngest), AI-assisted product classification (Anthropic - receives product and catalog data only, solely to generate classifications for us; its terms do not permit training its AI models on that data), and UPC catalog lookup (upcitemdb - receives only UPC codes, which identify products, not stores or people).

We may disclose data where required by law, or to protect the rights, safety, or security of Xerothread, our users, or others.

6. Data retention

We keep each category of data only as long as needed for the purposes above. Our retention criteria:

Raw merchant transaction and catalog rows: kept while the merchant participates in the panel, and deleted or de-identified within 90 days after the merchant's participation terminates, except records kept to comply with law or a POS platform's requirements, to resolve disputes, or to evidence the parties' agreement.

Published aggregates: retained as historical panel products; they contain no store-identifiable or personal information.

Import error samples used for troubleshooting: deleted within 90 days.

Buyer lead and outreach records: kept while a commercial conversation or relationship is active; we delete them no later than 24 months after the last interaction, unless law requires longer.

Merchant Data Agreement acceptance records: kept for the life of the merchant relationship and as long afterward as needed to evidence the agreement.

Store profile and POS connection records: kept while the merchant participates in the panel; the store-profile record may be retained afterward as part of agreement and relationship records, consistent with the Merchant Data Agreement.

Technical logs: kept for short periods, typically 90 days or less.

Account data: kept while your account is active and deleted on request or after account closure, except where law requires longer.

7. Your rights and choices

Merchants may disconnect POS access at any time and terminate future panel inclusion under the Merchant Data Agreement.

Individuals may request access to, correction of, or deletion of their personal account or contact data by emailing xerothreaddev@gmail.com. This includes business outreach records: a store owner or staff member may ask us to correct or delete their contact details and outreach notes. We respond within a reasonable time, generally within 45 days.

Deletion requests cannot reach aggregate cells that have already been published: those cells contain no personal or store-identifiable information, and consistent with the Merchant Data Agreement, already-published aggregates remain part of historical panel products.

8. Children's privacy

Our services are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 16. Product names appearing in trade data (for example toy products) are inventory records, not information about people. If you believe a child has provided us personal information, contact us and we will delete it.

9. Security

We apply encryption in transit, restricted admin access, and encrypted storage of POS access tokens.

10. Changes to this policy

We may update this policy. Updated versions are posted on this page with a new version number and effective date.

If we make a material change to how we collect, use, or share personal data, we will notify you before the change takes effect by a prominent notice on our sites or, for account holders and known contacts, by email. Material changes apply only going forward.

11. Contact

Privacy questions, complaints, and requests: xerothreaddev@gmail.com