Wix App Market Privacy Policy
Effective Date: October 10, 2025
Last Updated: August 14, 2026
Version: 1.3
Summary
At Vortex Files, we believe privacy is a fundamental right. This policy explains in plain language what data we collect, why we need it, how we protect it, and your rights to control it. We never sell your data, and we only collect what's necessary to deliver our service.
1. About Us
Company: QVXX Ltd.
Company Number: 16612070
Registered: England and Wales
Address: Flat 3 Misterton Court, Westbridge Road, London, SW11 3NL
Product: Vortex Files - Project-based client delivery platform
Contact: support_vortexfiles@qvxx.ai
Privacy Officer: compliance_vortexfiles@qvxx.ai
2. What Data We Collect
2.1 Information You Provide
- Account Information: Name, email address, company name, phone number
- Project Data: Project names, descriptions, status, deadlines
- File Content: Files you upload, file names, file metadata
- Communications: Comments, messages, support tickets
- Payment Information: Processed securely by Wix for Wix App Market subscriptions. We do not store full card details.
2.2 Data from Wix Integration
When you connect Vortex Files to your Wix site, we receive:
- Site Information: Site ID, domain name, business name
- User Information: Name, email, role (owner/contributor)
- Wix API Credentials: Short-lived access tokens requested from Wix when an authorized API operation needs them. We do not persist Wix access or refresh tokens.
- Billing Data: Subscription status, plan level, payment events
2.3 Automatically Collected Data
- Technical Data: IP address, browser type, device type, operating system
- Usage Data: Features used, pages viewed, time spent, actions taken
- Performance Data: Load times, errors, crash reports
- Cookies: Session management, preferences, security (see Cookie Policy)
2.4 Public Product Demos
- Essential demo access: We store opaque demo, share, and session identifiers needed to deliver the requested read-only demo and prevent abuse. Demo visitors do not receive a Vortex Files account.
- Optional interaction analytics: We record pseudonymous demo actions only when analytics cookies are enabled in the site-wide cookie preferences. Demo analytics exclude email addresses, file names, free text, IP addresses, and user-agent strings.
- Requested email and feedback: We store an email address only when you ask us to send a continuation link or consent to follow-up. Free-text feedback is stored only when you submit it. Neither action subscribes you to marketing.
2.5 Ebook resource downloads
- Demo access is independent: You can use the read-only demo without creating an account, submitting an email address, or signing up for marketing.
- Separate marketing choice: To receive an ebook, you provide your email and actively tick the unticked marketing-consent checkbox. This consent is separate from cookie analytics: accepting analytics does not subscribe you, and declining analytics does not stop an ebook request or a separately opted-in email.
- Subscriber evidence: We keep the email, the ebook/resource version, the form provenance, privacy notice version, and the consent timestamp needed to demonstrate what was requested. If analytics consent is granted, this evidence may also reference opaque demo-session attribution. If analytics is declined, no demo-session attribution is attached to the subscriber evidence. If you later withdraw analytics consent, we detach the stored demo-session, instance, and campaign attribution from that evidence.
- Private delivery: The ebook is delivered through a private, short-lived download capability rather than a permanent public file URL. The capability expires and is not used as an analytics identifier.
- Unsubscribe and suppression: Every marketing message includes an unsubscribe route. We keep the minimum suppression evidence needed to honour an unsubscribe or other marketing withdrawal.
- Analytics boundary: Subscriber email addresses never enter demo analytics events or their properties.
- Not the demo continuation email: “Email me this demo” is a requested transactional continuation link. It is recorded separately and does not create ebook subscriber evidence or marketing consent.
Client Portal Privacy Addendum (Clients)
This addendum explains how we handle data for invited clients who access the Vortex Files portal via magic links. It supplements the main Privacy Policy and focuses on the data we process when you review deliverables from your agency.
- What we collect: Your email, project assignment, login events, file views/downloads, comments, IP address, and device/user agent (for security and audit).
- Why: To verify access, show your agency what has been delivered or viewed, prevent fraud, and keep an immutable consent record.
- Who sees it: Only your agency and Vortex Files operations staff under strict access controls. We never sell or share this data for advertising.
- How long: Consent and audit logs are kept as long as the project is active or needed for legal defense; file access telemetry aligns with the agency's retention policy.
You can export your portal data or request deletion at any time from Portal Settings → Legal (or by emailing compliance_vortexfiles@qvxx.ai). When you ask us to delete your account, we deactivate access, delete non-essential personal data, and retain only what is required for legal, billing, or security purposes.
Consent is required before you enter the portal. If terms change materially, we will request re-consent and show what changed. If you decline, your agency can still share deliverables by other means, but portal access will remain blocked until consent is provided.
3. How We Use Your Data
3.1 Service Delivery (Contractual Necessity)
- Provide and maintain the Vortex Files platform
- Process and store your files securely in Cloudflare R2
- Enable project collaboration and client portal access
- Process payments and manage subscriptions through Wix for this Wix-connected workspace
- Send transactional emails (magic links, notifications, receipts)
3.2 Platform Improvement (Legitimate Interest)
- Analyze usage patterns to improve features
- Monitor performance and fix bugs
- Conduct user research and testing
- Develop new features based on user needs
3.3 Security & Compliance (Legal Obligation)
- Detect and prevent fraud, abuse, and security threats
- Maintain audit logs for security investigations
- Comply with legal obligations and regulatory requirements
- Respond to valid legal requests from authorities
3.4 Marketing Communications (Consent-Based)
- Send product updates and feature announcements (opt-in)
- Share educational content and best practices (opt-in)
- Promotional offers and discounts (opt-in)
- You can opt out anytime via unsubscribe links
Client Portal Privacy
This section applies to clients using the Vortex Files portal to access project files.
What we collect
- Downloads, views, and comments to keep agencies informed
- Login timestamps and IP addresses for security
- Files you access within invited projects
How it’s used
- Agencies see your portal activity to coordinate work
- Other clients cannot see your activity
- No sharing with third parties for advertising
Your rights
You may request a copy of your portal data, request deletion (subject to legal obligations), and export activity history. Contact compliance_vortexfiles@qvxx.ai or your agency.
4. Legal Basis for Processing (GDPR)
| Data Type | Legal Basis |
|---|---|
| Account & project data | Contract performance |
| Payment processing | Contract performance |
| Analytics & improvements | Legitimate interest |
| Security & fraud prevention | Legitimate interest + Legal obligation |
| Marketing communications | Consent (opt-in) |
| Public demo interactions | Requested service/pre-contract steps; consent for optional analytics and follow-up; legitimate interests for essential abuse prevention |
| Legal compliance | Legal obligation |
4.1 Processing Activity Register (Summary)
We maintain an internal GDPR processing register that maps core platform activities to legal basis, data categories, retention, and the consent-vs-contract rationale.
| Activity | Primary Basis | Rationale |
|---|---|---|
| Session management | Contract + Legitimate interest | Required for secure authenticated access |
| File access logs | Contract + Legitimate interest | Supports collaboration accountability and abuse detection |
| Product analytics (first-party) | Consent (+ limited legitimate interest analysis) | Optional analytics collection with user choice controls |
| Marketing emails | Consent | Opt-in only, withdraw anytime via preferences/unsubscribe |
| Security monitoring | Legal obligation + Legitimate interest | Necessary for incident response, fraud prevention, and compliance |
Full register: docs/specs/data-processing-register.md
5. How We Share Your Data
5.1 Third-Party Service Providers (Subprocessors)
We share data only with trusted partners who help us deliver our service. This table is our living subprocessor list for core platform operations.
| Provider | Purpose | Data Categories | Location |
|---|---|---|---|
| Supabase | Database, auth, API services | Account data, project metadata, access logs | US (AWS) |
| Cloudflare R2 | File storage and delivery | Uploaded files, file metadata | Global (EU options) |
| Resend | Transactional email delivery | Email address, message metadata | US |
| Vercel | Application hosting | Service logs, performance telemetry | Global |
| Wix | OAuth, billing, app integration | Site/account identifiers, billing events | Global |
| Sentry | Error monitoring and security diagnostics | Error traces, service logs, browser/device metadata, account/session identifiers, and fully masked error-triggered diagnostic replay (no routine session sampling; page text masked and media blocked) | US/EU |
We use provider contractual terms and data-protection terms appropriate to the service and our account with that provider. Available terms, certifications, regions, and transfer mechanisms differ by provider and may change. If we add or replace a subprocessor in a way that materially affects data processing, we will update this list and provide notice through this legal page and/or direct customer communication where required by law. Our customer DPA template is available at /legal/dpa.
5.2 Your Authorized Users
Data is shared with:
- Project collaborators you invite
- Clients with portal access to their projects
- Team members within your organization
5.3 Legal Requirements
We may disclose data if required by:
- Valid legal processes (subpoena, court order)
- Law enforcement requests with proper authority
- Protection of our rights, property, or safety
- Prevention of fraud or criminal activity
5.4 What We Never Do
- ✗ Sell your personal information
- ✗ Share data with advertisers
- ✗ Use your files for AI training
- ✗ Rent or trade user lists
- ✗ Access your files without permission (except for abuse investigation)
6. Data Storage & Security
6.1 Where We Store Data
- Files: Cloudflare R2 (global CDN with EU data residency options)
- Database: Supabase (US - AWS)
- Application: Vercel (global edge network)
- Backups: Encrypted, geographically distributed
6.2 Security Measures
- Encryption in Transit: HTTPS/TLS supported by our application and infrastructure providers
- Encryption at Rest: Provider-managed encryption for database, object-storage, and backup systems
- Access Controls: Role-based permissions, short-lived links/tokens, and provider account controls
- Authentication: Magic link flow + OAuth (Wix)
- Infrastructure: SOC 2 Type II compliant hosting
- Monitoring: Application error, billing, security, and infrastructure alerts
- Reviews: Automated security checks, dependency scanning, access reviews, and incident follow-up
6.3 Data Breach Protocol
In the unlikely event of a data breach:
- Immediate containment and investigation
- Notification within 72 hours (GDPR requirement)
- Detailed report of impact and affected data
- Remediation measures and prevention steps
- Support for affected users (credit monitoring if needed)
7. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data | Active + 2 years | Service continuity |
| Project files | Active + 1 year | Client access needs |
| Deleted files | 30 days (soft delete) | Recovery option |
| Analytics (detailed) | 6 months | Service improvement |
| Analytics (aggregated) | 2 years | Trend analysis |
| Security logs | 1 year | Security audits |
| Access logs | 90 days | Debugging, support |
| Public demo contact details | 30 days, then redacted | Requested continuation and optional follow-up |
| Ebook subscriber evidence | While consent remains valid and under periodic review; after withdrawal, limited consent-audit and suppression evidence only | Deliver the requested ebook and honour unsubscribe |
| Public demo feedback text | 90 days, then redacted | Product research |
| Public demo events | 90 days, then deleted | Consented usage analysis and operational integrity |
| Public demo sessions | Active for the configured session lifetime; inactive record retained with the demo instance | Pseudonymous lifecycle and linked-record integrity |
| Legal/tax records | 7 years | UK legal requirements |
You can request early deletion of your data at any time by contacting compliance_vortexfiles@qvxx.ai
8. Your Rights
8.1 GDPR Rights (EU/UK Users)
- Right to Access: Request a copy of all your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: "Right to be forgotten" - delete your data
- Right to Portability: Receive data in machine-readable format (JSON/CSV)
- Right to Restriction: Limit how we process your data
- Right to Object: Object to processing based on legitimate interest
- Right to Withdraw Consent: Remove consent for marketing
- Right to Lodge a Complaint: File complaint with ICO (UK) or local authority
8.2 CCPA Rights (California Users)
- Right to Know: What personal information we collect and how we use it
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt out of sale of personal information (we don't sell)
- Right to Non-Discrimination: Equal service regardless of privacy choices
8.3 How to Exercise Your Rights
Email: compliance_vortexfiles@qvxx.ai
Portal: Account Settings → Privacy & Data Management
Response Time: Within 30 days (GDPR) or 45 days (CCPA)
Verification: We may ask for verification to protect your security
9. Cookies & Tracking
9.1 Essential Cookies (Required)
- Session management and authentication
- Security tokens and CSRF protection
- User preferences and settings
9.2 Analytics Cookies (Opt-In)
- First-party analytics only (no third-party trackers)
- Usage patterns and feature adoption
- Performance monitoring
9.3 Managing Cookies
You can control cookies through:
- Our cookie consent banner (shown on first visit)
- Account settings → Privacy preferences
- Browser settings (may affect functionality)
See our full Cookie Policy for details.
10. International Data Transfers
10.1 Transfer Mechanisms
As a UK-based company serving global users, we may transfer data internationally. We protect these transfers through:
- Standard Contractual Clauses (SCCs): EU-approved transfer agreements
- UK IDTA: UK International Data Transfer Agreement
- Adequacy Decisions: Transfers to approved countries
- Data Localization: EU data residency options for files
10.2 Data Locations
- Primary database: United States (Supabase/AWS)
- File storage: Global CDN with EU options (Cloudflare R2)
- Application hosting: Global edge network (Vercel)
- Backups: Multiple regions for redundancy
11. Children's Privacy
Vortex Files is not directed to children under 16. We do not knowingly collect personal information from children under 16.
If we become aware that we have collected data from a child under 16, we will:
- Delete the information immediately
- Notify the account holder
- Prevent future access until age verification
Parents or guardians concerned about children's data can contact compliance_vortexfiles@qvxx.ai
12. Wix Integration Privacy
12.1 Data from Wix
When you connect Vortex Files through the Wix App Market:
- We only access data you explicitly authorize
- We request short-lived Wix API access tokens on demand and do not persist Wix access or refresh tokens
- We use Wix data solely for service provision
- Uninstalling the app revokes Vortex Files access to the Wix site and marks the workspace uninstalled. It does not by itself cancel Wix billing or immediately delete the workspace, projects, files, or required billing/audit records.
- To stop Wix charges, cancel the subscription in Wix Billing. To request erasure, use Account Settings → Privacy & Data Management or contact our Privacy Officer. We verify billing, storage, workspace data, client/collaborator access, and authentication separately before confirming completion.
12.2 Your Responsibilities
- You remain the data controller for your Wix site visitors
- Your site's privacy policy should disclose Vortex Files integration
- We act as a data processor following your instructions
12.3 Wix Privacy Policy
Wix's data handling is governed by their privacy policy: https://www.wix.com/about/privacy
13. Marketing Communications
13.1 Types of Communications
Transactional (Cannot opt out):
- Magic link authentication emails
- Project notifications and alerts
- Payment receipts and billing updates
- Security alerts and account changes
Marketing (Opt-in required):
- Product updates and feature announcements
- Educational content and best practices
- Promotional offers and discounts
- Event invitations and webinars
13.2 Opt-Out Options
- Click "Unsubscribe" link in any marketing email
- Manage preferences in Account Settings
- Email unsubscribe@qvxx.ai
14. Privacy Policy Updates
We may update this Privacy Policy to reflect changes in our practices or for legal reasons.
14.1 Notification of Changes
- Material changes: 30-day advance notice via email
- Minor updates: Notification in-app
- Effective date updated at top of policy
- Previous versions available upon request
14.2 Continued Use
Continued use of Vortex Files after changes constitutes acceptance. If you disagree with changes, you may close your account before the effective date.
15. Contact & Complaints
Privacy Officer
Email: compliance_vortexfiles@qvxx.ai
Address: Flat 3 Misterton Court, Westbridge Road, London, SW11 3NL
Data Protection Authority (UK)
Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113
16. Additional Resources
- Terms of Service - Legal agreement for using Vortex Files
- Cookie Policy - Detailed information about cookies
- Acceptable Use Policy - Rules for platform usage
- Security Practices - How we protect your data
- Data Processing Agreement (DPA) - Enterprise data processing terms and downloadable template