Legal
Privacy Policy
Last updated: March 2026
CX Mate (“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and share information about you when you use our services.
1. Information We Collect
We collect information you provide directly to us, such as:
- Account information: Your name, email address, and password when you create an account.
- Business information: Company name, website, industry, business stage, and other information you provide during onboarding.
- Usage data: Information about how you interact with our services, including pages visited, features used, and actions taken.
- Communications: Messages you send us, including support requests and feedback.
We also collect information automatically when you use our services:
- Log data: IP address, browser type, operating system, referring URLs, and pages viewed.
- Cookies and similar technologies: We use cookies and local storage to maintain your session and preferences. See our Cookie section below.
- Analytics: We use PostHog to understand how users interact with our product. PostHog may collect device information, usage patterns, and session recordings to help us improve CX Mate.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Generate personalized CX journey maps and recommendations using AI
- Send transactional emails (account confirmation, password reset, results digest)
- Respond to your comments, questions, and support requests
- Monitor and analyze trends, usage, and activity to improve our product
- Detect, investigate, and prevent security incidents and abuse
- Comply with legal obligations
AI processing: Your business data is sent to Anthropic’s Claude API to generate journey maps and recommendations. We do not use your data to train AI models. Anthropic’s data handling is governed by their Privacy Policy.
3. Sharing Your Information
We do not sell your personal information. We share your information only in the following circumstances:
- Service providers: We share data with third-party vendors who help us operate our services (Supabase for database, Resend for email, Anthropic for AI, PostHog for analytics, Freemius for payments). Each is bound by data processing agreements.
- Legal requirements: We may disclose information if required by law, regulation, or legal process.
- Business transfers: If CX Mate is acquired or merged, your information may be transferred as part of that transaction.
4. Data Retention
We retain your account information for as long as your account is active or as needed to provide our services. Journey maps, CX reports, and playbook data are retained until you delete your account. Anonymous preview data (stored in your browser only) is not retained on our servers.
You can request deletion of your account and associated data by contacting us at hello@cxmate.io.
5. Cookies and Tracking
We use the following types of cookies and storage:
- Essential cookies: Required for authentication and security. Cannot be disabled.
- Analytics cookies: PostHog uses cookies to track usage and session recordings. You can opt out via our cookie banner.
- Session storage: We temporarily store your journey data in your browser’s session storage during the anonymous preview flow. This data is not sent to our servers unless you create an account.
6. Your Rights
Depending on your location, you may have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your personal data.
- Portability: Request a copy of your data in a portable format.
- Opt-out: Opt out of analytics tracking via our cookie banner.
To exercise these rights, contact us at hello@cxmate.io. We will respond within 30 days.
7. Security
We implement industry-standard security measures including encryption in transit (HTTPS/TLS), encryption at rest for database content, and row-level security on all user data. However, no method of transmission over the Internet is 100% secure.
8. Children's Privacy
CX Mate is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.
9. International Transfers
Your information may be transferred to and processed in countries other than your own. Our servers are located in the United States. If you are accessing CX Mate from outside the United States, please be aware that your information may be transferred to, stored, and processed in the U.S.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page with an updated date, or by email if the changes significantly affect your rights.