Privacy Policy

Last updated: September 10, 2026

This policy describes how Xumulus, Inc. ("Xumulus," "we") handles information in connection with the XSearch service ("Service"). The Service is used by BigCommerce merchants ("merchants"); for merchant catalog data we act as a processor / service provider on the merchant's behalf.

Information we collect

  • Catalog data — products, categories, brands, custom fields, and channel assignments from the merchant's BigCommerce store, used to build and serve the merchant's search index.
  • Store and account information — store name, domain, plan, currency, and the store owner's email address, as provided by BigCommerce at install time.
  • Configuration — settings the merchant creates in the admin (schema, facets, ranking, promotions, badges).
  • Support communications — name, email, and message content when a merchant contacts support.
  • Service logs — operational logs (timestamps, request metadata, errors) needed to run and secure the Service.
  • Storefront search analytics — search terms, result counts, storefront channel, response timing, and product-result clicks and positions. These events do not contain a shopper name, account, email address, cookie, or IP address.

Information we do not collect

We do not store shopper identities. Storefront search queries and result clicks are recorded for merchant analytics but are not tied to shopper accounts or other direct identifiers. We do not use tracking cookies on this website.

How we use information

To provide, operate, secure, support, and improve the Service; to communicate with merchants about the Service; and to comply with law. We may use aggregated, de-identified usage data for service analytics. We do not sell or share personal information for advertising.

Sub-processors

The Service runs on the following infrastructure providers:

  • Vercel — application hosting (USA)
  • Neon — configuration database (USA)
  • Hosted Elasticsearch/OpenSearch (Bonsai) — search index (USA)
  • Inngest — background job processing (USA)
  • Slack and Resend — support message delivery (USA)

We will update this list when sub-processors change.

Data retention and deletion

Catalog indices, search analytics, user records, OAuth credentials, external-service credentials, and operational data are removed when the app is uninstalled. Eligible plans may retain merchant-authored search schema, display, and merchandising configuration to support a later reinstall; storefront delivery is disabled and retained records are stripped of store contact information. Merchants may request deletion of retained configuration at support@xumulus.com. Raw search and click events are removed after 30 days while aggregated merchant reports may be retained while the app remains installed. Operational logs are retained for no more than 30 days for security and debugging.

Security

Data is encrypted in transit. Access to production systems is limited to authorized personnel. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

Your choices and rights (US state privacy laws)

Where state privacy laws (such as the CCPA/CPRA) apply, we act as a "service provider" / "processor" with respect to catalog data processed for merchants, and we process it only per our agreement with the merchant. We do not sell or share personal information as those terms are defined in such laws. Merchants and individuals may contact us at support@xumulus.com to exercise applicable rights.

International visitors (GDPR)

The Service is operated from the United States and directed to US merchants. If we process personal data subject to the GDPR on a merchant's behalf, we do so as a processor under the merchant's instructions; a data processing addendum is available on request at support@xumulus.com.

Children

The Service is a business tool and is not directed to children under 13; we do not knowingly collect their information.

Changes to this policy

We will post updates on this page and revise the "Last updated" date; material changes will be communicated to merchants by email or in-app notice.

Contact

Xumulus, Inc. — support@xumulus.com