1. Who we are
Xenvious Development (“Xenvious,” “we,” “us,” or “our”) operates xenvious.dev, the Xenvious Store, and the XenLogs logging platform (collectively, the “Services”). This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and the choices you have.
For questions about this policy, reach us via Discord through our Support page.
2. Scope
This policy applies to information we collect when you visit our website, create an account, purchase products, install or use our scripts, or use XenLogs to ingest logs from your servers. It does not apply to third-party services we link to or integrate with, each of which has its own privacy practices (see Third-party services below).
3. Information we collect
3.1 Account information
We use Discord OAuth as our primary authentication method. When you sign in we receive your Discord user ID, username, global display name, avatar, and email address (if you have granted Discord email scope). We may also store linked identities you connect, such as Cfx.re / FiveM. We do not receive or store your Discord password.
3.2 Purchase and billing information
Store purchases are processed by Tebex. XenLogs subscriptions are processed by Stripe. Payment card details are entered directly with those processors and we never see or store your full card number. We do receive and retain transaction metadata such as the order ID, line items, amount, currency, billing country, partial card details (brand and last four digits), and subscription status.
3.3 Service usage and content
When you use XenLogs we receive and store the log events and metadata your servers send to us, including event categories, timestamps, server identifiers, role and permission settings, and community membership records. You control what your servers send and may delete logs subject to your subscription's retention window.
3.4 Technical and device data
We automatically collect IP address, user agent, referrer, approximate region (derived from IP), pages visited, and basic performance telemetry. This is used for security, abuse prevention, debugging, and aggregate analytics.
3.5 Cookies and similar technologies
We use first-party cookies and equivalent storage to keep you signed in, remember preferences, secure form submissions (CSRF), and run anonymized analytics. We do not use cross-site advertising cookies. You can clear cookies in your browser at any time, but doing so will sign you out.
3.6 Communications
If you contact us through Discord tickets we retain the contents of that conversation for support, quality assurance, and product-improvement purposes.
4. How we use information
- Provide, operate, and maintain the Services.
- Authenticate you, secure your account, and prevent fraud or abuse.
- Process purchases and subscriptions, deliver licenses, and send transactional notifications.
- Power product features such as role permissions, log search, alerts, and exports in XenLogs.
- Respond to support requests and improve our products based on feedback and aggregate usage.
- Comply with legal obligations and enforce our Terms of Service.
5. Legal bases (EEA / UK users)
If you are in the European Economic Area or United Kingdom, our legal bases for processing are: contractual necessity (to provide the Services you sign up for), legitimate interests (to secure, debug, and improve the Services and to understand how they are used), consent (where required, e.g. for optional analytics cookies), and legal obligation (e.g. tax records).
6. How we share information
We do not sell your personal information. We share it only with:
- Service providers who help us operate the Services (hosting, database, email delivery, error monitoring, analytics) under contractual confidentiality and data protection obligations.
- Payment processors — Tebex (store) and Stripe (XenLogs subscriptions) — to process transactions and prevent fraud.
- Identity providers — Discord and Cfx.re — to authenticate you and link accounts you choose to connect.
- Other members of your community — when you join a XenLogs community, your basic profile (name, email, avatar, role) is visible to that community's owner and staff so they can manage access.
- Legal and safety — when required to comply with law, lawful government requests, or to protect the rights, property, or safety of Xenvious, our users, or others.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to the same protections described in this policy.
7. Third-party services
The Services integrate with the following third parties. Their handling of your data is governed by their own policies:
8. Data retention
We retain personal information only as long as necessary to deliver the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Concretely:
- Account profile data — for as long as your account is active, then up to 30 days after deletion (longer if required by law or for fraud prevention).
- Transaction records — at least 7 years where required by tax and accounting law.
- Log data ingested into XenLogs — according to the retention window of your active plan; deleted automatically once it ages out, or when you delete your community.
- Operational logs (e.g. request logs, security events) — up to 90 days, then aggregated or deleted.
9. Your rights and choices
Depending on where you live you may have the right to access, correct, export, restrict, or delete personal information we hold about you, and to object to certain processing. You can:
- Update your profile and connections from your account page.
- Disconnect linked identities (Discord, Cfx.re) at any time from your account page. Disconnecting Discord will sign you out and prevent future logins.
- Request account deletion or a copy of your data via the Support page. We will verify your identity through your linked Discord account before acting.
- Cancel a XenLogs subscription at any time from billing.
If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority. If you are a California resident, the CCPA/CPRA grants you specific rights including the right to know, delete, correct, and not be discriminated against for exercising those rights.
10. Security
We use industry-standard safeguards including TLS in transit, encryption at rest for credentials and tokens, scoped API keys, rate limiting, and least-privilege access controls. No system is perfectly secure; if we become aware of a breach affecting your personal information we will notify you and the appropriate authorities as required by law.
11. International data transfers
We operate primarily in the United States. If you access the Services from elsewhere, your information will be transferred to and processed in the United States and other countries where we or our service providers operate. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses for transfers out of the EEA/UK.
12. Children
The Services are not directed to children under 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes we will revise the “Last updated” date above and, where appropriate, notify you in product or by email. Continued use of the Services after the updated policy takes effect constitutes acceptance of the changes.
14. Contact
Questions, concerns, or requests about this policy or your data can be sent through our Support page. We respond to all privacy requests within a reasonable time and at most within the period required by applicable law.