Xoido | Privacy Policy
Xoido Privacy Policy
Effective Date
September 1, 2026
This Privacy Policy explains how Xoido L.L.C. collects, uses, discloses, retains, and protects personal information in connection with Xoido.com, Xoido APIs, Xoido Travel, payment interfaces, merchant and administrative portals, developer tools, applications, and other services that reference this Policy (collectively, the "Services").
Xoido L.L.C. ("Xoido," "we," "us," or "our") provides payment orchestration technology that connects businesses and their customers with supported payment methods, financial institutions, payment processors, digital asset and stablecoin infrastructure, blockchain networks, identity and compliance providers, and other service providers.
Depending on the Services and transaction, Xoido may process personal information for its own purposes or as a service provider or processor acting on behalf of a business customer. By accessing or using the Services, you acknowledge the practices described in this Privacy Policy.
1. Information We Collect
The information we collect depends on how you interact with Xoido, the product and payment method you use, the merchant involved, your location, and the providers required to complete or support a transaction.
Information You Provide
- Contact and profile information, including name, email address, telephone number, mailing or business address, account credentials, and customer or merchant identifiers.
- Business information, including legal name, trade name, formation information, business address, industry, website, tax information, ownership information, and information concerning directors, officers, beneficial owners, or authorized representatives.
- Transaction and support information, including payment instructions, order or booking details, receipts, customer support communications, and information submitted through forms, applications, merchant onboarding, or account settings.
Identity and Compliance Information
Certain Services or financial providers may require identity verification, Know Your Customer, Know Your Business, anti-money-laundering, sanctions screening, fraud prevention, or other compliance checks. Information may include legal name, date of birth, address, government-issued identification information, tax identification information, business formation and ownership records, verification results, screening results, and other information required by law or a regulated provider. A third-party provider may collect some information directly from you.
Payment and Financial Information
- Payment amount, currency or digital asset, payment method, merchant information, transaction identifiers, payment status, fees, conversion information, exchange rates, settlement information, and payout destination.
- Bank name, account-holder name, account and routing information, account type, ownership or verification information, authentication tokens, payment instructions, and transaction or settlement status.
- Card-related information received from a payment processor or secure payment component, such as a token, card brand, expiration date, last digits of the card number, and transaction information. Xoido does not intend to receive or store complete payment card numbers or card security codes when those details are collected by a third-party processor.
Digital Asset and Blockchain Information
When a transaction involves cryptocurrency, stablecoins, digital wallets, or blockchain networks, we may process public wallet addresses, network and asset type, transaction hash, amount, smart-contract address, confirmations, network fees, timestamps, screening or risk information, and other publicly available blockchain information. Public blockchain records may be permanent, and Xoido generally cannot modify or delete information recorded on a public blockchain.
Device, Usage and Risk Information
- IP address, device and browser information, operating system, approximate location derived from IP address, referring URLs, pages or features accessed, session information, API activity, login history, diagnostics, and error or performance data.
- Fraud, security, and risk information, including device history, transaction velocity, failed attempts, access patterns, geographic indicators, risk scores, fraud indicators, account restrictions, sanctions screening, and blockchain analytics.
Information from Other Sources
We may receive information from merchants, travel providers, financial institutions, payment networks, identity and compliance providers, fraud-prevention providers, blockchain analytics providers, public records, and other service providers or counterparties involved in a transaction.
2. How We Use Information
- Provide, operate, maintain, and support the Services and accounts.
- Initiate, route, authorize, convert, reconcile, settle, refund, reverse, or otherwise administer payments and payouts.
- Connect users and merchants with third-party financial services and provide transaction receipts, statements, webhooks, API notifications, and service communications.
- Verify identities and businesses; perform KYC, KYB, AML, sanctions, fraud, transaction-monitoring, and risk checks; and maintain audit and compliance records.
- Authenticate users, prevent unauthorized access, investigate suspicious activity, protect accounts, and secure the Services.
- Provide customer and merchant support and resolve disputes, chargebacks, refunds, and operational issues.
- Analyze and improve reliability, performance, usability, and product functionality and develop new services.
- Enforce our agreements and policies, comply with legal obligations and lawful requests, and protect Xoido, our customers, providers, users, and the public.
3. How We Disclose Information
We may disclose personal information as described below or as otherwise permitted or required by law.
- Merchants and business customers. If you use Xoido in connection with a merchant, travel provider, or other business, we may provide that business information needed to process, reconcile, support, refund, or administer the transaction or service.
- Financial and payment providers. We may disclose information to banks, financial institutions, payment processors and acquirers, card networks, bank-connectivity providers, digital asset and stablecoin infrastructure providers, onramp and offramp providers, wallet or custody providers, blockchain infrastructure providers, and settlement or payout providers. The provider used may vary based on payment method, currency, asset, geography, availability, pricing, risk, or regulatory requirements.
- Identity, compliance, fraud and security providers. We may disclose information to providers that perform identity verification, KYC or KYB, sanctions screening, AML monitoring, fraud detection, blockchain analytics, cybersecurity, or other compliance and risk-management services.
- Operational providers and professional advisers. We may use providers for hosting, cloud infrastructure, communications, analytics, monitoring, support, accounting, insurance, legal services, and other business operations. They may access information as needed to perform services for us, subject to applicable contractual and legal requirements.
- Legal, regulatory and safety disclosures. We may disclose information to comply with law, regulation, legal process, or lawful government requests; cooperate with regulators or law enforcement; investigate unlawful activity; enforce agreements; or protect rights, property, safety, or the security and integrity of the Services.
- Corporate transactions. Information may be disclosed or transferred in connection with a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar corporate transaction, subject to applicable law.
- With your direction or consent. We may disclose information when you direct us to do so or provide consent.
4. Our Role for Business Customers
Businesses using Xoido may determine why and how certain personal information is processed, with Xoido processing that information on their behalf. If a merchant or other business provided your information to Xoido, you may need to contact that business regarding certain privacy requests. Xoido may process some information independently when necessary for transaction processing, security, fraud prevention, legal compliance, financial recordkeeping, or our legitimate business purposes.
5. Cookies and Similar Technologies
We may use cookies, local storage, pixels, software development kits, and similar technologies to maintain sessions, authenticate users, remember preferences, protect accounts, prevent fraud, understand use of the Services, diagnose issues, and improve performance. Where required, we will provide appropriate notice or consent choices. Browser controls may allow you to block or delete cookies, but doing so may impair parts of the Services.
Some browsers offer a Do Not Track setting. Because there is no uniform industry standard for responding to that setting, the Services do not currently respond to Do Not Track signals. Where required by applicable law, we will recognize legally valid opt-out preference signals for the processing to which they apply.
6. Third Party Services
The Services may integrate with or direct you to independent third-party services. Those providers may collect information directly from you and process it under their own privacy notices and legal obligations. Xoido does not control the privacy practices, security, or content of independent third parties.
7. Data Retention
We retain personal information for as long as reasonably necessary to provide the Services and fulfill the purposes described in this Policy. Financial, transaction, identity-verification, compliance, fraud, security, tax, accounting, dispute, and audit records may be retained longer when required or permitted by law, contract, provider requirements, or legitimate security and compliance needs. When information is no longer required, we may delete, anonymize, or otherwise dispose of it in accordance with our retention practices. Information recorded on a public blockchain generally cannot be deleted or modified by Xoido.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, destruction, or loss. Safeguards may include access controls, encryption, authentication, monitoring, audit logging, network protections, secrets management, and vendor security controls. No system, network, transmission method, or storage technology is completely secure, and we cannot guarantee absolute security.
9. International Processing
Xoido and our providers may process information outside the country where you reside. Where required, we use measures designed to protect personal information transferred internationally. The availability of Services, payment methods, financial providers, digital assets, and settlement methods may vary by jurisdiction.
10. Your Privacy Rights
Depending on where you live and applicable law, you may have rights to request access, correction, deletion, restriction, objection, or portability; withdraw consent where processing is based on consent; or appeal certain decisions concerning a privacy request. These rights are subject to exceptions, including obligations to retain transaction, fraud, tax, accounting, compliance, or other records. We may need to verify your identity and authority before acting on a request.
To submit a request, contact us using Section 15. If Xoido processes your information on behalf of a merchant or other business, we may direct your request to that business.
11. United States State Privacy Disclosures
Residents of California and certain other U.S. states may have additional rights under applicable privacy laws, such as rights to know or access, correct, delete, or obtain a copy of personal information and rights concerning certain disclosures or uses.
Xoido does not sell personal information for monetary consideration. If Xoido engages in activity defined as selling, sharing, or targeted advertising under an applicable law, we will provide notices and opt-out methods required by that law. We will not unlawfully discriminate against you for exercising applicable privacy rights.
12. European Economic Area, United Kingdom and Switzerland
Where the GDPR, UK GDPR, or similar law applies, Xoido relies on one or more lawful bases, which may include performance of a contract, compliance with legal obligations, legitimate interests, consent, and the establishment, exercise, or defense of legal claims. You may also have the right to complain to a competent supervisory authority. Where required by applicable law, Xoido will designate an appropriate data protection officer or local representative and publish the applicable contact information in this Privacy Policy.
13. Children's Privacy
The Services are not intended for anyone under 18 years of age, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us so that we can take appropriate action.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the revised version and update the Last Updated date. If required by law, we will provide additional notice or obtain consent. Your use of the Services after the effective date of an updated Policy is subject to the updated Policy.
15. Contact Us
Questions, concerns, and privacy requests may be submitted to:
Xoido L.L.C.
Attn: Privacy
30 N Gould St, Ste. N
Sheridan, WY 82801
Email: support@xoido.com