IXTAbox · Legal

Privacy Policy

How IXTAbox AB collects, uses, and protects personal data in the Buyer Portal and Ops Console.

Last updated 26 August 2026

1. Who we are

This policy is issued by IXTAbox AB (org. no. 559369-5488, VAT SE559369548801), Holmsätersgatan 7, 504 58 Borås, Sweden (“IXTAbox”, “we”, “us”). We are the data controller for personal data processed in this application.

Contact: info@ixtabox.se · +46-70-222 3250.

Pickup and logistics for some orders are handled with GLT Herrljunga AB, Hudenevägen 34, 524 92 Herrljunga. The public store at ixtabox.com is a separate Shopify site with its own privacy policy.

2. What this policy covers

This application has two surfaces:

  • Buyer Portal customers configure IXTAbox cargo systems, request proposals, review quotes, place orders, track production, and open documents.
  • Ops Console IXTAbox staff manage inventory, capacity, procurement, production, proposals, and customer requests.

It applies when you create an account, sign in, browse authenticated pages, submit a request, place an order, or otherwise use the service. By using the service you also accept our Terms of Service.

3. Information we collect

Account. Full name, email address, password (stored hashed by our authentication provider, not in readable form), phone number, delivery address, car model, and preferred display currency.

Requests and sales chat. Intended use of the box, vehicle details, delivery address (street, city, postal code, country), phone number, and the messages you send to sales. You can delete a request from the portal; staff will then no longer see it.

Configuration and orders. Product line, size, options, accessories, quantity, delivery location, order notes, order stages, and commercial documents (proposals, specifications, invoices, shipping papers).

Payment matching. If you report a bank transfer we store transfer date, amount, name on the paying account, payment reference, sending account details if you provide them, and any notes so we can match the payment. Card numbers are not collected in this application; checkout is by bank transfer / invoice.

Staff accounts. For employees we store name, email, role, department, and login times. If a staff member connects Gmail to send proposals, we store their Google account identifier, Gmail address, and OAuth tokens on the server so the app can send mail on their behalf. We request send permission only.

Technical data. Authentication session, last login and logout times, preferred currency, and (when you have not chosen a currency) an approximate country derived from request headers or IP address so we can show SEK, EUR, NOK, or DKK. We do not run advertising pixels or third-party analytics in this application.

4. How we use the information

  • Create and secure your account, and keep you signed in.
  • Show catalog prices in your currency and remember that choice.
  • Configure products, save requests, issue proposals, and fulfil orders.
  • Match bank transfers, plan production, and send order and proposal documents.
  • Let staff reply to buyer requests and email proposals from a connected Gmail account.
  • Keep records required for accounting, tax, and product safety.
  • Protect the service against abuse and diagnose faults.

5. Legal bases (GDPR)

We process personal data only where a GDPR legal basis applies:

  • Contract creating an account, handling requests, proposals, orders, payment matching, and delivery.
  • Legal obligation invoices and bookkeeping under Swedish law.
  • Legitimate interests keeping the service secure, remembering currency and country preferences, and operating the Ops Console. These interests do not override your rights.
  • Consent optional communications such as a newsletter, if you subscribe. You can withdraw consent at any time.

6. Who we share data with

We do not sell personal data. We share it only with:

  • Supabase authentication and the application database.
  • Google if staff connect Gmail, Google processes the connected mailbox and outbound proposal emails.
  • Hosting and infrastructure the platform that serves the application, including country headers used to pick a default currency.
  • IP geolocation if no currency cookie is set, we may send your public IP to ipwho.is solely to resolve a country code for currency. We do not send your name or account details there.
  • Banks and logistics partners payment details needed to identify a transfer, and name, address, and phone needed to manufacture and deliver a box (including GLT Herrljunga AB where relevant).
  • Authorities when the law requires it.

IXTAbox staff see buyer data only as needed to quote, produce, and support orders.

7. International transfers

Our processors may store or access data in the EU/EEA or in other countries. Where data leaves the EU/EEA we rely on an adequacy decision or Standard Contractual Clauses (or equivalent) from the processor. Google and Supabase publish their current transfer mechanisms on their privacy sites.

8. How long we keep data

  • Account profile while the account is open, then until you ask us to delete it (subject to records we must keep).
  • Orders, invoices, and payment matching — generally seven years to meet Swedish bookkeeping rules.
  • Open requests and proposals while the commercial relationship is active, then as needed for follow-up and disputes.
  • Gmail connection tokens until the staff member disconnects Gmail or leaves IXTAbox.
  • Session and draft configuration until you sign out, close the browser tab (for session storage), or the cookie expires.

9. Cookies and local storage

We use a small set of strictly necessary and functional cookies and browser storage. We do not use advertising or social-media tracking cookies in this application.

Cookies and browser storage used by this application
NameStored inPurposeKept for
ixtabox-currencyCookieRemember display currency (EUR, SEK, NOK, DKK)1 year
ixtabox-portal-authLocal storageKeep you signed in (Supabase session)Until you log out
ixtabox-buyer-configSession storageHold a box configuration until checkoutBrowser session
ixtabox-preferred-country-v2Local storageRemember a chosen country on address forms. Defaults to Sweden.Until you clear site data
sidebar_stateCookieRemember Ops Console sidebar layout7 days
portal_nav_collapsedLocal storageRemember buyer portal sidebar layoutUntil you clear site data

You can block cookies in your browser. If you do, sign-in and currency memory may not work. Blocking cookies does not stop us processing account data you submit in forms.

10. Your rights

If you are in the EU/EEA or Sweden you can ask us to access, correct, delete, or restrict your data, to object to processing based on legitimate interests, and to receive a portable copy of data you provided. You can also withdraw consent for optional processing.

Update profile fields from your account page. To delete an account or exercise other rights, email info@ixtabox.se. We may need to keep invoices and similar records even after an account is closed.

You may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or with your local supervisory authority.

11. Security

Access to the Buyer Portal and Ops Console requires a signed-in account. Passwords are handled by our authentication provider. Staff Gmail refresh tokens stay on the server. No method of transmission or storage is perfectly secure; we take reasonable technical and organisational measures appropriate to a manufacturing and sales system.

12. Children

The service is for adult buyers and IXTAbox staff. We do not knowingly collect personal data from children under 16.

13. Changes

We may update this policy when the product or the law changes. The date at the top is the latest version. Material changes will be reflected on this page.

14. Contact

IXTAbox AB
Holmsätersgatan 7, 504 58 Borås
Sweden
info@ixtabox.se
+46-70-222 3250