Skip to main content

Wix App Market Privacy Policy

Effective Date: October 10, 2025

Last Updated: August 14, 2026

Version: 1.3

Summary

At Vortex Files, we believe privacy is a fundamental right. This policy explains in plain language what data we collect, why we need it, how we protect it, and your rights to control it. We never sell your data, and we only collect what's necessary to deliver our service.

1. About Us

Company: QVXX Ltd.

Company Number: 16612070

Registered: England and Wales

Address: Flat 3 Misterton Court, Westbridge Road, London, SW11 3NL

Product: Vortex Files - Project-based client delivery platform

Contact: support_vortexfiles@qvxx.ai

Privacy Officer: compliance_vortexfiles@qvxx.ai

2. What Data We Collect

2.1 Information You Provide

  • Account Information: Name, email address, company name, phone number
  • Project Data: Project names, descriptions, status, deadlines
  • File Content: Files you upload, file names, file metadata
  • Communications: Comments, messages, support tickets
  • Payment Information: Processed securely by Wix for Wix App Market subscriptions. We do not store full card details.

2.2 Data from Wix Integration

When you connect Vortex Files to your Wix site, we receive:

  • Site Information: Site ID, domain name, business name
  • User Information: Name, email, role (owner/contributor)
  • Wix API Credentials: Short-lived access tokens requested from Wix when an authorized API operation needs them. We do not persist Wix access or refresh tokens.
  • Billing Data: Subscription status, plan level, payment events

2.3 Automatically Collected Data

  • Technical Data: IP address, browser type, device type, operating system
  • Usage Data: Features used, pages viewed, time spent, actions taken
  • Performance Data: Load times, errors, crash reports
  • Cookies: Session management, preferences, security (see Cookie Policy)

2.4 Public Product Demos

  • Essential demo access: We store opaque demo, share, and session identifiers needed to deliver the requested read-only demo and prevent abuse. Demo visitors do not receive a Vortex Files account.
  • Optional interaction analytics: We record pseudonymous demo actions only when analytics cookies are enabled in the site-wide cookie preferences. Demo analytics exclude email addresses, file names, free text, IP addresses, and user-agent strings.
  • Requested email and feedback: We store an email address only when you ask us to send a continuation link or consent to follow-up. Free-text feedback is stored only when you submit it. Neither action subscribes you to marketing.

2.5 Ebook resource downloads

  • Demo access is independent: You can use the read-only demo without creating an account, submitting an email address, or signing up for marketing.
  • Separate marketing choice: To receive an ebook, you provide your email and actively tick the unticked marketing-consent checkbox. This consent is separate from cookie analytics: accepting analytics does not subscribe you, and declining analytics does not stop an ebook request or a separately opted-in email.
  • Subscriber evidence: We keep the email, the ebook/resource version, the form provenance, privacy notice version, and the consent timestamp needed to demonstrate what was requested. If analytics consent is granted, this evidence may also reference opaque demo-session attribution. If analytics is declined, no demo-session attribution is attached to the subscriber evidence. If you later withdraw analytics consent, we detach the stored demo-session, instance, and campaign attribution from that evidence.
  • Private delivery: The ebook is delivered through a private, short-lived download capability rather than a permanent public file URL. The capability expires and is not used as an analytics identifier.
  • Unsubscribe and suppression: Every marketing message includes an unsubscribe route. We keep the minimum suppression evidence needed to honour an unsubscribe or other marketing withdrawal.
  • Analytics boundary: Subscriber email addresses never enter demo analytics events or their properties.
  • Not the demo continuation email: “Email me this demo” is a requested transactional continuation link. It is recorded separately and does not create ebook subscriber evidence or marketing consent.

Client Portal Privacy Addendum (Clients)

This addendum explains how we handle data for invited clients who access the Vortex Files portal via magic links. It supplements the main Privacy Policy and focuses on the data we process when you review deliverables from your agency.

  • What we collect: Your email, project assignment, login events, file views/downloads, comments, IP address, and device/user agent (for security and audit).
  • Why: To verify access, show your agency what has been delivered or viewed, prevent fraud, and keep an immutable consent record.
  • Who sees it: Only your agency and Vortex Files operations staff under strict access controls. We never sell or share this data for advertising.
  • How long: Consent and audit logs are kept as long as the project is active or needed for legal defense; file access telemetry aligns with the agency's retention policy.

You can export your portal data or request deletion at any time from Portal Settings → Legal (or by emailing compliance_vortexfiles@qvxx.ai). When you ask us to delete your account, we deactivate access, delete non-essential personal data, and retain only what is required for legal, billing, or security purposes.

Consent is required before you enter the portal. If terms change materially, we will request re-consent and show what changed. If you decline, your agency can still share deliverables by other means, but portal access will remain blocked until consent is provided.

3. How We Use Your Data

3.1 Service Delivery (Contractual Necessity)

  • Provide and maintain the Vortex Files platform
  • Process and store your files securely in Cloudflare R2
  • Enable project collaboration and client portal access
  • Process payments and manage subscriptions through Wix for this Wix-connected workspace
  • Send transactional emails (magic links, notifications, receipts)

3.2 Platform Improvement (Legitimate Interest)

  • Analyze usage patterns to improve features
  • Monitor performance and fix bugs
  • Conduct user research and testing
  • Develop new features based on user needs

3.3 Security & Compliance (Legal Obligation)

  • Detect and prevent fraud, abuse, and security threats
  • Maintain audit logs for security investigations
  • Comply with legal obligations and regulatory requirements
  • Respond to valid legal requests from authorities

3.4 Marketing Communications (Consent-Based)

  • Send product updates and feature announcements (opt-in)
  • Share educational content and best practices (opt-in)
  • Promotional offers and discounts (opt-in)
  • You can opt out anytime via unsubscribe links

Client Portal Privacy

This section applies to clients using the Vortex Files portal to access project files.

What we collect

  • Downloads, views, and comments to keep agencies informed
  • Login timestamps and IP addresses for security
  • Files you access within invited projects

How it’s used

  • Agencies see your portal activity to coordinate work
  • Other clients cannot see your activity
  • No sharing with third parties for advertising

Your rights

You may request a copy of your portal data, request deletion (subject to legal obligations), and export activity history. Contact compliance_vortexfiles@qvxx.ai or your agency.

4. Legal Basis for Processing (GDPR)

Data TypeLegal Basis
Account & project dataContract performance
Payment processingContract performance
Analytics & improvementsLegitimate interest
Security & fraud preventionLegitimate interest + Legal obligation
Marketing communicationsConsent (opt-in)
Public demo interactionsRequested service/pre-contract steps; consent for optional analytics and follow-up; legitimate interests for essential abuse prevention
Legal complianceLegal obligation

4.1 Processing Activity Register (Summary)

We maintain an internal GDPR processing register that maps core platform activities to legal basis, data categories, retention, and the consent-vs-contract rationale.

ActivityPrimary BasisRationale
Session managementContract + Legitimate interestRequired for secure authenticated access
File access logsContract + Legitimate interestSupports collaboration accountability and abuse detection
Product analytics (first-party)Consent (+ limited legitimate interest analysis)Optional analytics collection with user choice controls
Marketing emailsConsentOpt-in only, withdraw anytime via preferences/unsubscribe
Security monitoringLegal obligation + Legitimate interestNecessary for incident response, fraud prevention, and compliance

Full register: docs/specs/data-processing-register.md

5. How We Share Your Data

5.1 Third-Party Service Providers (Subprocessors)

We share data only with trusted partners who help us deliver our service. This table is our living subprocessor list for core platform operations.

ProviderPurposeData CategoriesLocation
SupabaseDatabase, auth, API servicesAccount data, project metadata, access logsUS (AWS)
Cloudflare R2File storage and deliveryUploaded files, file metadataGlobal (EU options)
ResendTransactional email deliveryEmail address, message metadataUS
VercelApplication hostingService logs, performance telemetryGlobal
WixOAuth, billing, app integrationSite/account identifiers, billing eventsGlobal
SentryError monitoring and security diagnosticsError traces, service logs, browser/device metadata, account/session identifiers, and fully masked error-triggered diagnostic replay (no routine session sampling; page text masked and media blocked)US/EU

We use provider contractual terms and data-protection terms appropriate to the service and our account with that provider. Available terms, certifications, regions, and transfer mechanisms differ by provider and may change. If we add or replace a subprocessor in a way that materially affects data processing, we will update this list and provide notice through this legal page and/or direct customer communication where required by law. Our customer DPA template is available at /legal/dpa.

5.2 Your Authorized Users

Data is shared with:

  • Project collaborators you invite
  • Clients with portal access to their projects
  • Team members within your organization

5.3 Legal Requirements

We may disclose data if required by:

  • Valid legal processes (subpoena, court order)
  • Law enforcement requests with proper authority
  • Protection of our rights, property, or safety
  • Prevention of fraud or criminal activity

5.4 What We Never Do

  • ✗ Sell your personal information
  • ✗ Share data with advertisers
  • ✗ Use your files for AI training
  • ✗ Rent or trade user lists
  • ✗ Access your files without permission (except for abuse investigation)

6. Data Storage & Security

6.1 Where We Store Data

  • Files: Cloudflare R2 (global CDN with EU data residency options)
  • Database: Supabase (US - AWS)
  • Application: Vercel (global edge network)
  • Backups: Encrypted, geographically distributed

6.2 Security Measures

  • Encryption in Transit: HTTPS/TLS supported by our application and infrastructure providers
  • Encryption at Rest: Provider-managed encryption for database, object-storage, and backup systems
  • Access Controls: Role-based permissions, short-lived links/tokens, and provider account controls
  • Authentication: Magic link flow + OAuth (Wix)
  • Infrastructure: SOC 2 Type II compliant hosting
  • Monitoring: Application error, billing, security, and infrastructure alerts
  • Reviews: Automated security checks, dependency scanning, access reviews, and incident follow-up

6.3 Data Breach Protocol

In the unlikely event of a data breach:

  1. Immediate containment and investigation
  2. Notification within 72 hours (GDPR requirement)
  3. Detailed report of impact and affected data
  4. Remediation measures and prevention steps
  5. Support for affected users (credit monitoring if needed)

7. Data Retention

Data TypeRetention PeriodReason
Account dataActive + 2 yearsService continuity
Project filesActive + 1 yearClient access needs
Deleted files30 days (soft delete)Recovery option
Analytics (detailed)6 monthsService improvement
Analytics (aggregated)2 yearsTrend analysis
Security logs1 yearSecurity audits
Access logs90 daysDebugging, support
Public demo contact details30 days, then redactedRequested continuation and optional follow-up
Ebook subscriber evidenceWhile consent remains valid and under periodic review; after withdrawal, limited consent-audit and suppression evidence onlyDeliver the requested ebook and honour unsubscribe
Public demo feedback text90 days, then redactedProduct research
Public demo events90 days, then deletedConsented usage analysis and operational integrity
Public demo sessionsActive for the configured session lifetime; inactive record retained with the demo instancePseudonymous lifecycle and linked-record integrity
Legal/tax records7 yearsUK legal requirements

You can request early deletion of your data at any time by contacting compliance_vortexfiles@qvxx.ai

8. Your Rights

8.1 GDPR Rights (EU/UK Users)

  • Right to Access: Request a copy of all your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: "Right to be forgotten" - delete your data
  • Right to Portability: Receive data in machine-readable format (JSON/CSV)
  • Right to Restriction: Limit how we process your data
  • Right to Object: Object to processing based on legitimate interest
  • Right to Withdraw Consent: Remove consent for marketing
  • Right to Lodge a Complaint: File complaint with ICO (UK) or local authority

8.2 CCPA Rights (California Users)

  • Right to Know: What personal information we collect and how we use it
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt out of sale of personal information (we don't sell)
  • Right to Non-Discrimination: Equal service regardless of privacy choices

8.3 How to Exercise Your Rights

Email: compliance_vortexfiles@qvxx.ai

Portal: Account Settings → Privacy & Data Management

Response Time: Within 30 days (GDPR) or 45 days (CCPA)

Verification: We may ask for verification to protect your security

9. Cookies & Tracking

9.1 Essential Cookies (Required)

  • Session management and authentication
  • Security tokens and CSRF protection
  • User preferences and settings

9.2 Analytics Cookies (Opt-In)

  • First-party analytics only (no third-party trackers)
  • Usage patterns and feature adoption
  • Performance monitoring

9.3 Managing Cookies

You can control cookies through:

  • Our cookie consent banner (shown on first visit)
  • Account settings → Privacy preferences
  • Browser settings (may affect functionality)

See our full Cookie Policy for details.

10. International Data Transfers

10.1 Transfer Mechanisms

As a UK-based company serving global users, we may transfer data internationally. We protect these transfers through:

  • Standard Contractual Clauses (SCCs): EU-approved transfer agreements
  • UK IDTA: UK International Data Transfer Agreement
  • Adequacy Decisions: Transfers to approved countries
  • Data Localization: EU data residency options for files

10.2 Data Locations

  • Primary database: United States (Supabase/AWS)
  • File storage: Global CDN with EU options (Cloudflare R2)
  • Application hosting: Global edge network (Vercel)
  • Backups: Multiple regions for redundancy

11. Children's Privacy

Vortex Files is not directed to children under 16. We do not knowingly collect personal information from children under 16.

If we become aware that we have collected data from a child under 16, we will:

  1. Delete the information immediately
  2. Notify the account holder
  3. Prevent future access until age verification

Parents or guardians concerned about children's data can contact compliance_vortexfiles@qvxx.ai

12. Wix Integration Privacy

12.1 Data from Wix

When you connect Vortex Files through the Wix App Market:

  • We only access data you explicitly authorize
  • We request short-lived Wix API access tokens on demand and do not persist Wix access or refresh tokens
  • We use Wix data solely for service provision
  • Uninstalling the app revokes Vortex Files access to the Wix site and marks the workspace uninstalled. It does not by itself cancel Wix billing or immediately delete the workspace, projects, files, or required billing/audit records.
  • To stop Wix charges, cancel the subscription in Wix Billing. To request erasure, use Account Settings → Privacy & Data Management or contact our Privacy Officer. We verify billing, storage, workspace data, client/collaborator access, and authentication separately before confirming completion.

12.2 Your Responsibilities

  • You remain the data controller for your Wix site visitors
  • Your site's privacy policy should disclose Vortex Files integration
  • We act as a data processor following your instructions

12.3 Wix Privacy Policy

Wix's data handling is governed by their privacy policy: https://www.wix.com/about/privacy

13. Marketing Communications

13.1 Types of Communications

Transactional (Cannot opt out):

  • Magic link authentication emails
  • Project notifications and alerts
  • Payment receipts and billing updates
  • Security alerts and account changes

Marketing (Opt-in required):

  • Product updates and feature announcements
  • Educational content and best practices
  • Promotional offers and discounts
  • Event invitations and webinars

13.2 Opt-Out Options

  • Click "Unsubscribe" link in any marketing email
  • Manage preferences in Account Settings
  • Email unsubscribe@qvxx.ai

14. Privacy Policy Updates

We may update this Privacy Policy to reflect changes in our practices or for legal reasons.

14.1 Notification of Changes

  • Material changes: 30-day advance notice via email
  • Minor updates: Notification in-app
  • Effective date updated at top of policy
  • Previous versions available upon request

14.2 Continued Use

Continued use of Vortex Files after changes constitutes acceptance. If you disagree with changes, you may close your account before the effective date.

15. Contact & Complaints

Privacy Officer

Email: compliance_vortexfiles@qvxx.ai

Address: Flat 3 Misterton Court, Westbridge Road, London, SW11 3NL

General Support

Email: support_vortexfiles@qvxx.ai

Response time: Within 48 hours

Data Protection Authority (UK)

Information Commissioner's Office (ICO)

Website: ico.org.uk

Helpline: 0303 123 1113

Data Protection Authority (EU)

Contact your local supervisory authority

List: EDPB Members

16. Additional Resources

    Wix App Market Privacy | Vortex Files | Vortex Files