Privacy Policy
Effective Date: 1 June 2026 · Last Updated: 1 September 2026
This Privacy Policy explains how XCAPE Group LLC ("XCAPE", "we", "us", or "our") collects, uses, stores, and protects your personal information when you visit xcapetaxacademy.com or enroll in XCAPE Academy programs. This policy applies globally, with specific provisions for residents of the EU/EEA, UK, California (CCPA), Australia (Privacy Act 1988), the Philippines (Data Privacy Act 2012), India (Digital Personal Data Protection Act 2023), and other applicable jurisdictions.
1. Who We Are
XCAPE Group LLC is a U.S.-registered business services and education company and acts as the data controller or Data Fiduciary, as applicable, for personal data collected through this website and academy platform.
Registered address (Mock): 100 Placeholder Avenue, Wilmington, Delaware 19801, United States.
Privacy and Data Protection Contact (Mock): Jordan Example, Privacy Officer and Data Protection Officer, at privacy@xcapegroup.com.
EU representative (Mock): Placeholder EU Privacy Services, 1 Example Square, Dublin 2, Ireland, eu-representative@example.com.
UK representative (Mock): Placeholder UK Privacy Services, 1 Example Street, London EC1A 1AA, United Kingdom, uk-representative@example.com.
2. What Data We Collect
Information you provide directly:
- Full name and email address (when joining our waitlist or applying)
- Country of residence, used to determine which rights framework and service requirements apply to you; we may compare it with IP-based approximate location to identify errors or fraud
- Professional background (optional, provided during application)
- Payment information — collected and processed exclusively by our payment processor (Stripe). We never store card numbers.
- Communications with our support team
Information collected automatically:
- IP address and approximate location
- Browser type, operating system, and device type
- Pages visited, time on page, and referral source
- Cookies and similar tracking technologies (see our Cookie Policy)
3. How We Use Your Data
We use the personal information we collect to:
- Process your application and manage your enrollment
- Deliver course content and track your progress
- Send transactional emails (enrollment confirmations, payment receipts, password resets)
- Send program updates and relevant educational content (you may opt out at any time)
- Operate, maintain, and improve our platform
- Comply with legal obligations
- Prevent fraud and ensure platform security
Legal basis (EU/UK): We process your data on the basis of (a) contract performance — when delivering your enrollment; (b) legitimate interests — for platform security and service improvement; (c) consent — for marketing communications and non-essential cookies.
4. Data Sharing & Third Parties
We do not sell personal information. California law treats some disclosures for cross-context behavioural advertising as “sharing” even where no money changes hands. Where an advertising or marketing technology constitutes sharing, we provide the legally required notice and opt-out choice; optional analytics and marketing technologies can also be refused through Cookie Settings. We otherwise disclose data only to:
- Base44 — our platform provider (hosting, authentication, database). Data Processing Agreement in place.
- Stripe — payment processing. Stripe handles all card data under PCI-DSS compliance.
- Email service provider — for transactional and marketing emails. Data Processing Agreement in place.
- Analytics providers — aggregated, anonymised usage data only.
- Legal / regulatory bodies — where required by applicable law.
5. International Data Transfers
XCAPE Group is based in the United States, and our service providers may process personal information in the countries where they or their infrastructure operate. We do not claim that platform processing occurs only in the United States. Before relying on a transfer mechanism, we verify the relevant processor locations and contractual terms.
For EU/EEA and UK transfers, we use an applicable adequacy decision or appropriate safeguards such as European Commission Standard Contractual Clauses and the UK International Data Transfer Addendum or Agreement. For Australia, we take reasonable steps under Australian Privacy Principle 8 before disclosing personal information overseas, including contractual protections with processors.
For the Philippines, we remain accountable under Section 21 of the Data Privacy Act for personal information transferred to and processed by our overseas processors, and we use contractual protections to ensure a comparable level of protection. For India, we act as a Data Fiduciary under the DPDP Act 2023 and require our Data Processors to protect personal data contractually, subject to any transfer restrictions notified by the Indian Government.
6. Your Rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
EU/EEA & UK (GDPR / UK GDPR):
- Right to access your data
- Right to rectification (correct inaccurate data)
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent at any time
- Right to lodge a complaint with your local supervisory authority; UK residents may complain to the Information Commissioner’s Office (ICO)
California (CCPA/CPRA):
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to limit the use and disclosure of sensitive personal information, where applicable
- Right to opt out of the sale or sharing of personal information
- Right to non-discrimination for exercising your rights
Australia (Privacy Act 1988, Australian Privacy Principles):
- Right to know why we collect your personal information and how we use it
- Right to access the personal information we hold about you; we do not charge a fee for making an access request under APP 12
- Right to correction of inaccurate, out-of-date, incomplete, or misleading information
- Right to make a complaint to us, and if unresolved, to the Office of the Australian Information Commissioner (OAIC)
Philippines (Data Privacy Act of 2012, NPC rules):
- Right to be informed, to object, to access, and to correct, block, or erase personal data
- Right to damages and to data portability, where applicable
- Right to lodge a complaint with the National Privacy Commission (NPC)
Our designated Data Protection Officer’s published contact details appear in Sections 1 and 11. We assess and complete NPC registration where required, including if our processing reaches an applicable threshold for sensitive personal information.
India (Digital Personal Data Protection Act 2023):
- Right to access a summary of personal data and processing activities
- Right to correction, completion, and erasure
- Right to withdraw consent, and to grievance redress through us
- Right to nominate a person to exercise rights in the event of death or incapacity, and to approach the Data Protection Board of India
Privacy notices are available in English and, on request, in any of the 22 languages listed in the Eighth Schedule to the Constitution of India.
Other countries: If the law of your country grants rights beyond those listed above, we will honour those rights on request where they apply to us.
To exercise any of these rights, contact us at privacy@xcapegroup.com. EU/EEA and UK requests are handled within one calendar month and may be extended by up to two further months for complex or numerous requests, with notice of the extension. California requests are acknowledged within 10 business days and answered within 45 calendar days, extendable once by a further 45 days with notice. Philippine data subject requests are generally answered within 15 working days, subject to applicable NPC rules. Australian and Indian requests are handled within the periods required by applicable law. If we cannot resolve an Australian complaint, you may contact the OAIC. UK complaints may be taken to the ICO, Philippine complaints to the NPC, and eligible Indian grievances to the Data Protection Board of India.
7. Data Retention
We retain your personal data for as long as necessary to fulfill the purposes outlined in this policy:
- Enrollment and progress data: retained for the duration of your enrollment plus 3 years
- Payment records: retained for 7 years for tax and accounting compliance
- Marketing contact records: retained until you unsubscribe or request deletion
- Support correspondence: retained for 2 years
8. Security
We implement technical and organisational measures to protect your personal data, including HTTPS encryption in transit, access controls and role-based permissions, and protected data storage via our platform provider. Security incidents are assessed when identified. Independent security reviews will be recorded when they are performed; this policy does not claim that periodic or regular reviews already occur. No system is 100% secure. In the event of a data breach that poses a risk to your rights, we will notify affected individuals and relevant authorities as required by applicable law: within 72 hours for EU/UK GDPR; as soon as practicable under Australia's Notifiable Data Breaches scheme (OAIC); to the National Privacy Commission in the Philippines where required; and under India's DPDP Act 2023, including any direction of the Data Protection Board.
9. Children's Privacy
XCAPE Academy is intended for adults aged 18 and over. We do not knowingly collect personal data from individuals under 18. If we become aware that a minor has submitted personal data, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify enrolled students of material changes via email. Continued use of our platform after such notice constitutes acceptance of the updated policy.
11. Contact Us
For privacy-related questions, data requests, or complaints, contact our Privacy Team:
Privacy Officer / DPO (Mock): Jordan Example
Email: privacy@xcapegroup.com
Registered address (Mock): 100 Placeholder Avenue, Wilmington, Delaware 19801, United States
EU representative (Mock): Placeholder EU Privacy Services, 1 Example Square, Dublin 2, Ireland; eu-representative@example.com
UK representative (Mock): Placeholder UK Privacy Services, 1 Example Street, London EC1A 1AA, United Kingdom; uk-representative@example.com
General: support@xcapegroup.com