Privacy Policy
Last updated: July 27, 2026
1. Who We Are
Xylo ("we," "us," or "our") operates the website xylomcp.comand the Xylo REST API (collectively, the "Service"). Xylo provides a simplified API layer that enables developers and businesses to interact with the advertising APIs of Meta (Marketing API), Google (Google Ads API), TikTok (Marketing API), and X (Ads API) for advertising campaign management, reporting, and optimization, and to read connected commerce and marketing data from Shopify (Admin API) and Klaviyo.
Contact us at: support@xylomcp.com
2. Data We Collect
2.1 Information You Provide Directly
- Account registration data: email address used to create your Xylo account and receive your API key.
- Organization name: derived from your email or provided during setup.
2.2 Data Obtained via Meta Platform
When you connect your Meta ad account through our OAuth flow, we access the following data from Meta's Marketing API on your behalf:
- Ad account information: account ID, account name, currency, timezone, spend caps, and account status.
- Campaign data: campaign names, statuses, objectives, budgets, and scheduling.
- Ad set data: targeting parameters, bid strategies, optimization goals, and budgets.
- Ad data: ad creative details, headlines, body text, images, links, and call-to-action settings.
- Performance metrics: spend, impressions, clicks, CTR, CPC, CPM, reach, frequency, conversions, cost per conversion, and ROAS.
- Audience data: custom audience names and configurations, lookalike audience parameters.
- Page engagement data: page IDs associated with ad creatives (accessed via the pages_read_engagement permission).
2.3 Data Obtained via Google (Google Ads API)
When you connect your Google Ads account through Google's OAuth flow, you grant Xylo the https://www.googleapis.com/auth/adwords scope. Using this authorization we access the following data from the Google Ads API on your behalf:
- Account information: Google Ads customer ID, account name, currency, timezone, and manager (MCC) linkage.
- Campaign, ad group, and ad data: names, statuses, types, budgets, bidding strategies, schedules, and ad creative content (headlines, descriptions, URLs, images, and assets such as sitelinks, callouts, and structured snippets).
- Keyword and search-term data: keywords, match types, negative keywords, search terms, and keyword plan ideas.
- Performance metrics: impressions, clicks, cost, CTR, CPC, conversions, conversion value, and derived metrics such as ROAS and quality scores.
- Audience and conversion data: remarketing and Customer Match user-list configurations, conversion actions, and offline conversion uploads that you initiate.
2.4 Data Obtained via X (Ads API)
When you connect an X Ads account through our OAuth flow, we access the following data from the X Ads API on your behalf:
- Account information: account ID, name, timezone, approval status, permissions, and funding-instrument information.
- Campaign data: campaigns, ad groups, promoted tweets, media, cards, budgets, bids, statuses, and schedules.
- Performance metrics: impressions, engagements, spend, video activity, conversions, reach, and frequency.
- Audience and measurement data: targeting criteria, audience configurations, conversion tags, catalogs, and A/B tests.
2.5 Data Obtained via Shopify (Admin API)
When you install the Xylo app from the Shopify App Store or connect a store from the Xylo dashboard, we access the following data from Shopify's Admin API on your behalf, on a read-only basis:
- Store information: shop name, domain, contact email, currency, timezone, country, and plan.
- Products, inventory, and locations: product titles, variants, prices, stock levels, and store locations.
- Analytics reports:aggregate sales, order, and customer metrics (for example revenue over time, top products, repeat-purchase rates) via Shopify's analytics (ShopifyQL).
- Orders and customers:where your connection's permissions allow it, order and customer records (such as order contents, totals, and customer names and emails) are read to answer the specific requests you or your AI agent make. We pass this data through to you; we do not persist individual customer records in our database.
Your merchant's customers do not interact with Xylo directly, and we collect no information from them directly. We honor Shopify's mandatory privacy webhooks: when a store uninstalls the app or Shopify issues a redaction request, we delete the store's access token, connection records, and cached data.
2.6 Data Obtained via Klaviyo
When you connect a Klaviyo account, we access your Klaviyo data (campaigns, flows, segments, lists, profiles, metrics, and revenue reports) on your behalf to answer the requests you or your AI agent make, and to perform the writes you explicitly request. Profile data is passed through to you and cached only transiently; we do not build our own store of your subscribers.
2.7 Automatically Collected Data
- API usage logs: endpoints called, response times, status codes, timestamps, and whether responses were served from cache.
- IP addresses: collected for rate limiting and abuse prevention.
- Advertising measurement data: landing-page attribution, the page where registration occurred, a random event identifier, event type and time, IP address, browser user agent, and first-party measurement or attribution cookies.
3. How We Use Your Data
We process your data for the following purposes:
- Providing the Service: proxying your requests to the connected platform APIs (Meta Marketing API, Google Ads API, TikTok Marketing API, X Ads API, Shopify Admin API, and Klaviyo API), translating data formats, caching responses for performance, and returning clean API responses to your applications and AI agents.
- Authentication and authorization: verifying your API key, validating your connection to specific platform accounts, and managing OAuth tokens and secrets.
- Usage tracking and billing: counting API calls for plan limits and billing purposes.
- Rate limiting and abuse prevention: enforcing per-minute request limits and preventing unauthorized access.
- Service improvement: analyzing aggregate usage patterns to improve API reliability and performance.
- Advertising measurement: attributing completed registrations to our advertising, reporting campaign performance, and optimizing ad delivery.
- Communication: sending transactional emails such as API key delivery and token expiration alerts.
4. Meta Platform Data Usage
Xylo uses Meta's Business Tools (Marketing API) to access your advertising data. Our use of data received from Meta APIs adheres to the Meta Platform Terms and Meta Developer Policies. Specifically:
- We only access Meta data that you have explicitly authorized through the OAuth consent flow.
- We do not use your advertising data for any purpose other than providing the Service to you.
- We do not use your advertising data to build user profiles for advertising or retargeting.
- We keep each advertiser's data separated from other advertisers' data.
- We do not sell, license, or otherwise distribute your Meta advertising data to third parties.
- Advertising performance data is used only to serve your API requests and is not used on an individual basis for any other purpose.
5. Google API Services User Data Policy
Xylo's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only access Google Ads data that you have explicitly authorized through Google's OAuth consent flow.
- We use Google user data solely to provide and improve the user-facing features of the Service — proxying your requests to the Google Ads API, transforming data, and returning results to your applications and AI agents.
- We do not use Google user data for serving advertisements, for building advertising or retargeting profiles, or to train, develop, or improve generalized or general-purpose AI or machine-learning models.
- We do not sell, license, or transfer Google user data to data brokers, information resellers, or any other party for the purposes prohibited by the Google API Services User Data Policy.
- We do not allow humans to read Google user data unless we first obtain your affirmative agreement for specific data, doing so is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data has been aggregated and anonymized.
- We keep each advertiser's Google Ads data separated from other advertisers' data.
6. Data Sharing
We share your data only in the following circumstances:
- With the platforms you connect:we send API requests to Meta's Marketing API, the Google Ads API, TikTok's Marketing API, the X Ads API, Shopify's Admin API, and/or Klaviyo's API on your behalf using your authorized access tokens. This is necessary to provide the Service.
- Service providers: we use Supabase for database hosting, Vercel for web hosting, and Resend for transactional email. These providers process data on our behalf under contractual obligations.
- Advertising measurement partners: we share website and conversion measurement data with Meta and OpenAI to attribute registrations, report campaign performance, and optimize advertising. OpenAI acts as an independent controller for most OpenAI Ad Tools processing, as described in its Ad Tools Data Processing Addendum.
- Legal requirements: we may disclose data if required by law, regulation, legal process, or governmental request.
We do not sell your personal data, your Meta, Google, TikTok, or X advertising data, or your Shopify or Klaviyo data to any third party.
7. Data Storage and Security
We implement the following security measures:
- Token encryption: platform access tokens (Meta, Google, TikTok, X, Shopify, and Klaviyo) are encrypted at rest using AES-256-GCM encryption. Encryption keys are stored separately from the database in environment variables.
- API key hashing: API keys are stored as SHA-256 hashes. The plaintext key is shown to you once at creation and never stored.
- HTTPS only: all API and web traffic is encrypted in transit via TLS.
- Access controls: API keys are scoped to organizations, and each organization can only access its own connected ad accounts.
- Audit logging: every API request is logged with endpoint, status code, and timing for security monitoring.
8. Data Retention
- Account data: retained for as long as your account is active. Deleted upon account deletion request.
- Meta OAuth tokens: encrypted tokens are retained while the connection is active (up to 60 days per token lifecycle). Expired tokens are automatically refreshed or marked as expired.
- Google Ads OAuth tokens: the encrypted refresh token is retained while the connection is active and is used to obtain short-lived access tokens. It is deleted when you disconnect the Google account or revoke access, or when Google invalidates it.
- X OAuth tokens: the encrypted OAuth token and token secret are retained while the connection is active and are deleted when you disconnect the X Ads account or revoke access.
- Shopify access tokens: the encrypted token is retained while the app is installed and the store is connected. It is deleted when you uninstall the app, disconnect the store, or Shopify sends its
shop/redactprivacy webhook. - Klaviyo API keys: the encrypted key is retained while the connection is active and deleted when you disconnect the account.
- Cached API responses: automatically expire based on data type (5 minutes to 24 hours) and are purged after expiration. We do not retain individual Shopify customer or order records beyond these transient caches.
- Usage logs: retained for billing and analytics purposes for up to 12 months, then deleted.
9. Your Rights and Data Deletion
You have the right to:
- Access your data: request a copy of the personal data we hold about you.
- Correct your data: request correction of inaccurate personal data.
- Delete your data: request deletion of your account, API keys, connected accounts, cached data, and usage logs.
- Disconnect Meta accounts:revoke Xylo's access to your Meta ad accounts at any time through your Meta Business Settings.
- Disconnect Google accounts:revoke Xylo's access to your Google Ads account at any time from your Google Account permissions page. When you revoke access, we delete the stored Google refresh token and cached data associated with that account.
- Disconnect X Ads accounts: disconnect X in Xylo or revoke the Xylo application from your X account. We delete the stored OAuth token, token secret, and cached data associated with that connection.
- Disconnect Shopify stores:uninstall the Xylo app from your Shopify admin at any time. On uninstall (or a Shopify redaction request) we delete the store's access token, connection records, and cached data.
- Data portability: request your data in a machine-readable format.
To exercise any of these rights, contact us at support@xylomcp.com. We will respond to all requests within 30 days.
You may also delete your data by revoking Xylo's access in your Meta Business Integrations settings. When you revoke access, we will delete all stored tokens and cached data associated with your ad accounts.
10. Cookies and Advertising Measurement
Xylo uses essential cookies for authentication and OAuth flows. We also use Vercel Analytics, Meta Pixel, and the OpenAI Ads Measurement Pixel to understand marketing-page visits and measure actions such as completed registrations, connected accounts, and purchases. These services may set first-party measurement or attribution cookies. For completed registrations and connected integrations, Xylo may also send OpenAI the event identifier and time, attribution value, source page, IP address, and browser user agent through the OpenAI Ads Conversions API. We do not include your Xylo email address, account ID, or connected advertising-account data in OpenAI conversion events.
You can block or delete cookies through your browser settings. Xylo also honors the browser Global Privacy Control signal by suppressing OpenAI page-view, registration, and integration conversion events when the signal is enabled.
11. Children's Privacy
Xylo is a developer tool and is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at support@xylomcp.com.
12. International Data Transfers
Xylo is established in the United States and is not established in Europe. Your data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place for international data transfers in compliance with applicable data protection laws, including standard contractual clauses where required.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Email: support@xylomcp.com