Privacy

Privacy policy

What Quixo Marketing collects on this website and in the platform, why, how it is isolated and shared, how long it is kept, and your rights.

Last updated: 26 September 2026. Effective date: 26 September 2026. Data map version: 2026-09-24.1.

This policy explains what Quixo Marketing collects on quixomarketing.com, in the Quixo Audit and in the client portal (portal.quixomarketing.com), why we collect it, who we share it with, where it is processed, how long we keep it, and the rights you have.

Who we are

Quixo Marketing is a trading name of Quixo Hub FZC, a free zone company with limited liability, licensed in the United Arab Emirates under licence number 50228 issued by the Ajman Free Zones Authority. Our working address is Dubai Silicon Oasis, Dubai, United Arab Emirates. We are not currently registered for VAT.

For the personal data described in this policy we are the "controller" (the party that decides why and how the data is used), except where we say we act for our customers as a "processor".

Our data protection contact, for any privacy question or request, is hello@quixomarketing.com.

Where the EU or UK GDPR applies to you, you have the rights described in that law, and this policy is written to meet them.

When we act for our customers

Our customers use the portal to manage their own contacts, leads, WhatsApp conversations, ad accounts and content. For that data the customer is the controller and we process it only on their instructions, to provide the service. If you are a contact of one of our customers (for example, you received a WhatsApp message from a business that uses Quixo Marketing), please contact that business first. We will help them answer your request. A data processing agreement (DPA) is available to customers on request.

What we collect

When you browse this website. We use Cloudflare Web Analytics to measure page views and page performance. Our hosting provider (Cloudflare) processes technical request data, such as your IP address, browser type and the page requested, to deliver the page and protect the site from abuse. If you visit one of our offer test pages, we set one cookie to show you the same version each time (see "Cookies and similar technologies").

When you order a Quixo Audit. Your email address, the website you want audited, up to five competitor websites, the tier you picked, your language, and a record that you ticked "I am allowed to request an audit of this website" (with the version of that text and the time). We send you a link to confirm your email address. We then examine only publicly available information on your website and on the competitor websites you name (or that we suggest). We never ask for a login to your website to run an audit. After you pay, you can choose whether to connect your accounts (optional, read-only); the price is the same either way (see "Accounts you connect").

When you pay. Payments are handled by Stripe. We receive the order, amount, currency, payment status and a Stripe reference. We do not receive or store your full card number.

When you use the portal. Your name, work email, role and team memberships; sign-in records (sign-in links are single use and valid for 15 minutes); session records including your browser type and a shortened IP address (the last part is removed); optional two-factor authentication settings; and the security and activity log of actions taken in your workspace.

Content you and your team add. Contacts, leads, deals and quotes in the CRM; WhatsApp and email messages; knowledge-base documents; brand files, deliverables, calendars and uploads; and the prompts you send to our AI features and the outputs they return.

Accounts you connect. If you connect an ad or listing account (Meta, Google Ads, Google Business Profile, Google Search Console, LinkedIn, TikTok, Snap or Microsoft Bing), we receive the account details and performance data that the permissions you grant allow (see "Ad platforms and Google data"). Access tokens are encrypted (AES-256-GCM) and are never exported or shown back to anyone.

WhatsApp Business messaging. If a customer connects a WhatsApp Business number, we process the phone numbers, names, messages, delivery status and consent status (opted in or opted out) of the people that business messages. See "WhatsApp messaging".

Lead generation. If a customer uses our lead-generation feature, we obtain business contact details (such as name, job title, company and business email) of prospects that match the customer's target profile from a third-party prospect data provider (see "Who we share data with"). Nothing is imported or contacted until the customer approves it.

Performance measurements in the portal. The portal sends page speed measurements (for example, loading time) with the page type only. They contain no names, emails, record ids or query strings.

When you contact us. Whatever you include in your email or WhatsApp message to us.

Why we use it and our legal basis

• To provide the service you asked for (contract): run and deliver your Quixo Audit, run your workspace, CRM, messaging and reports, and apply changes you approve.
• To take payment and keep financial records (contract and legal obligation): process payments, invoices and refunds, and keep tax records as UAE law requires.
• To keep the service secure (legitimate interest and legal obligation): authenticate users, prevent fraud and abuse, and keep an append-only activity log.
• To send messages on a customer's behalf (the customer's instructions, and the recipient's consent): WhatsApp messages go only to people recorded as opted in.
• To measure and improve the service (legitimate interest): page speed measurements, and experiment results counted on paid orders only.
• To comply with the law (legal obligation): answer lawful requests and keep proof that we handled privacy requests.

We do not sell personal data. We do not use your data, or data from accounts you connect, for advertising to you or to anyone else.

AI features

Some features use artificial intelligence: the Quixo Audit write-up, caption and ad-copy drafts, the monthly marketing plan, the CRM assistant, WhatsApp reply drafts, and review reply drafts. We use only two AI providers: Anthropic (United States) and Cloudflare Workers AI. Our system refuses any other provider.

• Your data is not used to train Anthropic's or Cloudflare's models.
• AI output is a proposal. Messages, posts, ad changes and replies are sent or published only after a person approves them. WhatsApp reply drafts are never made for people who have opted out, and complaints, refund requests, legal questions and requests for a human are passed to a person.
• We keep AI prompts and outputs for 1 year so you can see how a result was produced.

Ad platforms and Google data

You choose which accounts to connect, and you can disconnect them at any time (see "How to delete your data"). We request only the permissions listed below. Write permissions exist only so that changes you approve can be applied.

• Meta: ads_read, ads_management (and business_management for agency connections); WhatsApp: whatsapp_business_management, whatsapp_business_messaging
• Google Ads: https://www.googleapis.com/auth/adwords
• Google Business Profile: https://www.googleapis.com/auth/business.manage
• Google Search Console: https://www.googleapis.com/auth/webmasters.readonly
• LinkedIn: r_ads, r_ads_reporting, rw_ads
• TikTok: ads.read, reporting.read
• Snap: snapchat-marketing-api
• Microsoft Bing Webmaster: webmaster.read

What we do with this data: show your campaign, listing, search and review performance in the portal and in reports; suggest changes; apply changes only after you approve them; draft replies to your Google Business Profile reviews (the review text is processed by our AI providers to write the draft, which you approve before it is posted); and use aggregated performance figures in your monthly marketing plan.

Google API Services: Limited Use. Quixo Marketing's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

• We use Google user data only to provide and improve the user-facing features described above.
• We do not transfer it to others except to provide those features (for example, to our hosting and AI providers under contract), to comply with law, or as part of a merger or acquisition with notice to you.
• We do not use it for advertising, including retargeting or personalised ads, and we do not sell it.
• We do not use it to train general-purpose AI or machine-learning models.
• Our staff do not read it unless you ask us to (for example, for support), it is needed for security or to investigate abuse, or the law requires it.

Data from connected ad and listing accounts is kept for 3 years, and deleted sooner if you delete your workspace. When you disconnect an account, we revoke our access token and stop collecting new data from it.

WhatsApp messaging

Businesses that use Quixo Marketing can send WhatsApp messages through the WhatsApp Business Platform (Meta).

• Opt-in. A business may send marketing or campaign messages only to people recorded as opted in, with evidence of how they agreed. We check consent at the moment of sending, including for retries and queued messages. A bulk contact upload can never turn an opted-out person back to opted in.
• Opt-out. You can stop messages at any time by replying with STOP (also: UNSUBSCRIBE, CANCEL, END, QUIT, OPT OUT, REMOVE ME, or in Arabic إيقاف, توقف, إلغاء, إلغاء الاشتراك). Your opt-out is recorded at once and any messages already queued to your number are cancelled.
• Opting back in. Reply START (or SUBSCRIBE, UNSTOP, ابدأ, اشتراك) to receive messages again.
• The business that messaged you controls its contact list. You can also ask it, or us at hello@quixomarketing.com, to remove your number.
• WhatsApp messages and conversation records are kept for 2 years.

Who we share data with

We use these service providers ("subprocessors"). Each processes data only to provide its service to us.

• Cloudflare, Inc. Hosting, databases, file storage, queues and Workers AI. Regions: Cloudflare's global network; primary database and file storage location in the EU.
• Anthropic PBC. AI text generation. Region: United States.
• Stripe Payments Europe, Ltd. Payments, invoices and card processing. Regions: EU and United States.
• Microsoft. Staff single sign-on (Entra ID) and delivery of our emails (Microsoft 365). Regions: EU; staff directory in UAE North.
• Meta Platforms. WhatsApp Business Platform and Meta ad accounts that customers connect. Regions: United States and EU.
• Google. Google Ads, Business Profile and Search Console accounts that customers connect. Regions: United States and EU.
• LinkedIn, TikTok, Snap and Microsoft Bing. Only when a customer connects an account on that platform, to read performance data and apply changes the customer approves. Regions: each platform's own infrastructure, including the United States.
• Prospect data provider. Supplies business contact details of prospects, only when a customer uses lead generation. Email hello@quixomarketing.com for the provider's name and processing region.

We may also share data with professional advisers, with authorities when the law requires it, or with a buyer of our business (you will be told first). A domain registrar will be added before domain services are offered.

Where your data is processed

Quixo Marketing runs on Cloudflare's global network. We do not promise that your data stays in the UAE, unless your signed contract says so. Our main database and file storage location is in the EU, and some providers (Anthropic, Stripe, Meta, Google) process data in the United States.

When personal data is transferred outside the UAE, we rely on either adequate protection in the destination or contractual safeguards (a data processing agreement and standard contractual clauses) with the provider.

How long we keep data

• Invoices, payments and orders: 5 years (UAE tax record keeping). Kept after workspace deletion only for as long as the law requires.
• Security and activity log: 7 years. Kept after workspace deletion as legal evidence.
• Records of privacy requests (export and deletion): 7 years, as proof we handled them.
• WhatsApp and email messages: 2 years.
• Ad and listing performance data: 3 years.
• Quixo Audit inputs, evidence and reports: 3 years.
• Quixo Audit requests that are never paid for (email address and website): 90 days.
• AI prompts and outputs: 1 year.
• Analytics and attribution events: 13 months (395 days).
• Temporary cache: up to 30 days.
• Data export files: 7 days (the download link works for 24 hours).
• Accounts, team members, CRM contacts, knowledge base, deliverables, uploads and other workspace records: while your workspace is active, then deleted when the workspace is deleted.
• Sign-in sessions: end after 30 minutes without activity, and after 12 hours at most.

If we are legally required to keep data (for example, because of a dispute or an official request), we may place it on a legal hold and keep it until the hold ends.

Your rights

You can ask us to:

• Access the personal data we hold about you.
• Get a copy in a portable format. Workspace owners can ask us by email to export all workspace data; the export is ready within 72 hours.
• Correct data that is wrong or incomplete.
• Delete your data. Workspace owners can have the whole workspace deleted (see "How to delete your data").
• Restrict or object to processing, including processing based on our legitimate interests and decisions made only by automated means.
• Withdraw consent at any time, where we rely on consent (for example, WhatsApp marketing messages). This does not affect what was done before.

To use any of these rights, email hello@quixomarketing.com from the address linked to your account. We may ask you to confirm your identity. We answer within 30 days. If the GDPR applies to you, you can also complain to your local data protection authority.

How to delete your data

Delete your workspace. Workspace owners: email hello@quixomarketing.com from the owner's address and ask us to delete the workspace. We may ask you to confirm your identity and the workspace before we delete it. All workspace data is deleted from every store within 30 days, backups expire within 30 days of deletion, and you receive a deletion certificate. Only invoices, payment records, the security log and privacy-request records are kept, for the periods listed above, because the law requires it.

Remove Quixo Marketing's access to your Facebook, Instagram or WhatsApp data. You can do either or both of these:

1. Ask us to disconnect the account by emailing hello@quixomarketing.com. We revoke our access token and stop collecting data from it.
2. On Facebook, go to Settings and privacy, then Settings, then Business integrations (or Apps and websites), find Quixo Marketing and remove it.

Then, to have the data we already received deleted, email hello@quixomarketing.com with the subject "Data deletion request" and the Facebook page, ad account or WhatsApp number concerned. We confirm by email and complete deletion within 30 days.

Quixo Audit buyers without a portal account. Email hello@quixomarketing.com from the address you used for the audit.

Cookies and similar technologies

We ask for your consent before setting any cookie that is not strictly necessary. Use "Cookie settings" in the footer to change your choice at any time. Browsers that send a Global Privacy Control signal are treated as having declined.

• _fbp and _fbc (quixomarketing.com, only if you accept): set by the Meta Pixel to measure the results of our Meta advertising. Without your consent the pixel is not loaded and Meta receives nothing from this website. Withdrawing consent deletes them.
• qm_vid (quixomarketing.com, offer test pages only): a random id so you see the same version of the page each time, and so we can count paid orders per version. Lasts 180 days. It holds no name or email address, and you can block or delete it in your browser settings at any time.
• __Host-qm_sid (portal): keeps you signed in. Strictly necessary. Ends after 30 minutes without activity or 12 hours at most.
• __Host-qm_oidc (portal, staff sign-in only): protects the sign-in step. Lasts 10 minutes.
• Session storage (audit order page, this tab only): remembers the email you typed, the tier you picked and your language until you close the tab.

Website performance is measured with Cloudflare Web Analytics. See Cloudflare’s documentation for how this works. Analytics events within the portal are stored only with consent, without IP addresses or browser details.

Security

Each customer workspace is isolated from others. Access tokens and credentials are encrypted, sign-in links are single use, and staff can view a customer workspace only with the customer's consent: those views are read-only, end after 30 minutes, can be revoked, and are logged. Every important action is written to an append-only, tamper-evident log. No system is completely secure; if a breach affects your personal data, we will tell you and the authorities as the law requires.

Children

Our services are for businesses. They are not directed at anyone under 18, and we do not knowingly collect children's personal data.

Changes to this policy

We will post any change on this page and update the date at the top. If a change is significant, we will also tell account owners by email before it takes effect.

Contact

Quixo Hub FZC, Dubai Silicon Oasis, Dubai, United Arab Emirates. Data protection contact: hello@quixomarketing.com.