Last updated: 13 August 2026
Privacy Policy
This document is provided for transparency and product operation purposes. It is not legal advice.
1. Scope of this policy
XFatora is a software product owned and operated by Mobileaders. Mobileaders is the legal operator of xfatora.com, the XFatora software platform, and official XFatora mobile applications.
This Privacy Policy explains how Mobileaders, through the XFatora product, collects, uses, stores, discloses, and protects information when you use xfatora.com, the XFatora web platform, support and demo services, and XFatora-branded mobile applications.
The mobile applications covered include XFatora HR & People, XFatora Manufacturing, XFatora Sales & CRM, and other XFatora applications that link to this policy. A feature may be available only in certain apps, plans, organizations, devices, or regions.
This policy applies to customers, organization administrators, employees and other invited users, trial users, website visitors, prospects, support contacts, and other people who interact with XFatora.
2. Our role and your organization’s role
For customer business data, the customer organization usually decides what information is entered, why it is processed, which users may access it, and how long it should be kept. In that context, Xfatora processes the information to provide and secure the service on the organization’s instructions.
Xfatora is responsible for information it collects for its own account administration, billing, website operation, product security, service analytics, support, and direct communications. If you use Xfatora through an employer or another organization, that organization’s privacy notices and internal policies may also apply.
3. Account, profile, and commercial information
We may collect information needed to identify the user, connect the user to an organization, administer access, and manage the commercial relationship.
- Name, profile image, business name, employee or user identifier, job title, department, role, email address, phone number, country or region, preferred language, and organization or workspace.
- Login and authentication information, invitations, assigned roles and permissions, account status, active sessions, and records of security or account changes. We do not ask users to send passwords or secret access tokens to support.
- Plan, subscription, billing-contact, invoice, payment-status, renewal, cancellation, and transaction-confirmation information. Payment card details may be handled directly by a payment provider or app store rather than stored by Xfatora.
4. Customer business data
Customer business data is information entered, uploaded, imported, generated, scanned, captured, or stored by customers and their users in Xfatora. Its contents depend on the modules and workflows selected by the organization.
- Customer, lead, supplier, employee, contractor, project, task, asset, inventory, purchase, sales, quotation, invoice, payment, accounting, payroll, attendance, leave, expense, helpdesk, fleet, logistics, manufacturing, quality, warranty, approval, survey, goal, compliance, and audit records.
- Documents, photos, receipts, invoices, profile images, attachments, notes, comments, signatures, barcode or QR data, and other evidence a user chooses to upload or capture.
- Reports, dashboards, exports, workflow history, approvals, notifications, and records generated from customer inputs and user actions.
5. Mobile app, device, and diagnostic data
When an Xfatora app is installed or used, we may receive technical information needed to operate, secure, diagnose, and improve it.
- Device type and model, operating system and version, app name and version, language, time zone, IP address, network information, session timestamps, and organization or tenant identifier.
- App events and feature usage, authentication events, error and crash reports, performance measurements, security logs, and diagnostic details associated with a support request.
- A device or installation identifier and push-notification token used to maintain sessions, protect the account, register the device, and deliver notifications. These identifiers may change when the app is reinstalled, the device is reset, or notification settings change.
6. Optional device permissions
An Xfatora app requests a device permission only when a related feature needs it. The permission prompt and the feature shown in the app provide additional context. You can deny or later revoke a permission in device settings, although the related feature may then be unavailable.
- Camera: to scan a barcode or QR code, photograph a receipt, invoice, item, profile image, manufacturing record, or other business evidence selected by the user.
- Photos and files: to select, upload, preview, download, or save documents, images, reports, and attachments requested by the user.
- Location: where enabled by the customer organization, to support attendance, check-in, field visits, routes, deliveries, fleet, or other location-based workflows. The app may use approximate or precise location, and foreground or background access only where the device permission, in-app disclosure, and configured workflow allow it.
- Notifications: to deliver approvals, task updates, reminders, attendance or workflow events, security notices, and other organization-related alerts. Notification settings can be changed on the device.
7. Website, support, and communication data
We may collect pages visited, forms submitted, referring pages, cookie choices, browser information, IP address, approximate region, campaign or analytics data, and interaction records when you use xfatora.com.
We also process demo requests, support tickets, emails, calls, meeting notes, feedback, survey responses, screenshots, issue reports, and troubleshooting information that you choose to provide. More information about website technologies is available in the Cookie Policy.
8. How information is collected
We collect information directly from users; from the customer organization that creates, configures, imports, or administers an account; automatically from the website, web platform, mobile apps, and service logs; from connected services at the customer’s or user’s direction; and from payment providers, app stores, or business partners where needed to confirm a transaction or deliver a requested service.
9. How we use information
We use information only for relevant service, security, support, legal, and business purposes.
- Provide sign-in, mobile and web features, customer-selected modules, data synchronization, reports, exports, approvals, alerts, and workflow automation.
- Create and administer organizations, accounts, profiles, users, roles, permissions, devices, subscriptions, invoices, and support relationships.
- Operate optional features requested by the user or organization, including document capture, barcode or QR scanning, attendance, field operations, and push notifications.
- Diagnose errors, respond to support requests, monitor performance, investigate security incidents, prevent fraud or abuse, and maintain service reliability.
- Analyze aggregated or service-usage patterns, improve usability, onboarding, documentation and features, and measure website or campaign effectiveness.
- Comply with contractual, legal, tax, accounting, employment, security, regulatory, and dispute-resolution obligations, and enforce Xfatora policies.
10. Legal bases
Depending on applicable law and context, Xfatora relies on performance of a contract, steps requested before a contract, the customer’s documented instructions, legitimate interests in operating and securing a business service, consent where required, compliance with legal obligations, and protection of rights, users, and service integrity. A user may withdraw consent for optional processing, but withdrawal does not affect processing already performed lawfully.
11. How information is disclosed
Xfatora does not sell personal information, and does not use customer business data to create advertising profiles for third parties. We disclose information only as needed for the following recipients and purposes.
- The customer organization, its authorized administrators and users, and recipients selected through roles, settings, exports, sharing, or workflow actions.
- Vendors that support hosting, storage, backups, security, monitoring, diagnostics, analytics, communications, customer support, billing, and payment processing, subject to appropriate confidentiality and data-protection obligations.
- Apple, Google, device-platform services, and push-notification services where needed for app distribution, purchases, device permissions, diagnostics, or notifications. Their independent processing is governed by their own policies.
- Customer-authorized integrations and third-party services. Data sent to an integration is also governed by the recipient’s terms and privacy practices.
- Professional advisers, a buyer or successor in a business transaction, and public authorities where required by applicable law, valid legal process, or protection of rights and safety.
12. International processing
Information may be processed or stored outside the user’s or customer’s country. Where applicable law requires it, Xfatora uses safeguards appropriate to the transfer, which may include contractual protections, security controls, access restrictions, and vendor review.
13. Retention and deletion
We retain information only for as long as reasonably needed for the service, the customer relationship, security, backups, dispute resolution, and applicable legal, tax, accounting, employment, payment, fraud-prevention, and contractual requirements. Retention periods vary by data category, customer instructions, configuration, and applicable law.
Users can request account deletion through a supported app under Profile or More, then Account and privacy, or through the Account and Data Deletion page. Deleting an individual user account does not automatically erase records controlled by the user’s employer or customer organization. Information that must be retained for legal, security, accounting, employment, or dispute purposes may be restricted and retained for the required period. Deleted information may remain in protected backups until the applicable backup cycle replaces it.
14. Security
We use administrative, technical, and organizational safeguards designed to reduce the risk of unauthorized access, loss, misuse, alteration, or disclosure. Measures may include access controls, authentication, role-based permissions, logging, monitoring, backups, encryption in transit or at rest where appropriate, vendor controls, and internal access restrictions.
No online or mobile service can guarantee absolute security. Users and customer organizations must protect credentials and devices, configure permissions appropriately, review access, secure downloaded files and exports, and notify Xfatora promptly about suspected unauthorized access.
15. Rights and user controls
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, object to, withdraw consent for, or receive a copy of certain personal information. Requests may be sent to support@xfatora.com. We may verify identity and authority before acting.
When information is customer business data controlled by an employer or another customer organization, the request should normally be made to that organization. Xfatora may assist the organization where appropriate. Users can also manage app permissions and notifications through device settings and manage website cookies through available cookie controls.
16. Children, third-party services, and policy changes
Xfatora is a business service and is not directed to children. Users must not submit children’s personal information unless their organization has a lawful basis, the service configuration supports it, and all required notices and permissions have been provided.
Xfatora may link to or integrate with third-party services. Xfatora is not responsible for independent third-party privacy practices. We may update this policy to reflect changes in our apps, services, vendors, or legal obligations. The updated version will be published on xfatora.com with a revised date; material notices may also be provided in an app, by email, or through the service where appropriate.
17. Contact
For privacy questions, rights requests, or concerns about the Xfatora website, web platform, or mobile apps, contact support@xfatora.com. For account deletion, you may also use the Account and Data Deletion page. Website: xfatora.com.