IXTAbox · Legal
Privacy Policy
How IXTAbox AB collects, uses, and protects personal data in the Buyer Portal and Ops Console.
Last updated 26 August 2026
1. Who we are
This policy is issued by IXTAbox AB (org. no. 559369-5488, VAT SE559369548801), Holmsätersgatan 7, 504 58 Borås, Sweden (“IXTAbox”, “we”, “us”). We are the data controller for personal data processed in this application.
Contact: info@ixtabox.se · +46-70-222 3250.
Pickup and logistics for some orders are handled with GLT Herrljunga AB, Hudenevägen 34, 524 92 Herrljunga. The public store at ixtabox.com is a separate Shopify site with its own privacy policy.
2. What this policy covers
This application has two surfaces:
- Buyer Portal customers configure IXTAbox cargo systems, request proposals, review quotes, place orders, track production, and open documents.
- Ops Console IXTAbox staff manage inventory, capacity, procurement, production, proposals, and customer requests.
It applies when you create an account, sign in, browse authenticated pages, submit a request, place an order, or otherwise use the service. By using the service you also accept our Terms of Service.
3. Information we collect
Account. Full name, email address, password (stored hashed by our authentication provider, not in readable form), phone number, delivery address, car model, and preferred display currency.
Requests and sales chat. Intended use of the box, vehicle details, delivery address (street, city, postal code, country), phone number, and the messages you send to sales. You can delete a request from the portal; staff will then no longer see it.
Configuration and orders. Product line, size, options, accessories, quantity, delivery location, order notes, order stages, and commercial documents (proposals, specifications, invoices, shipping papers).
Payment matching. If you report a bank transfer we store transfer date, amount, name on the paying account, payment reference, sending account details if you provide them, and any notes so we can match the payment. Card numbers are not collected in this application; checkout is by bank transfer / invoice.
Staff accounts. For employees we store name, email, role, department, and login times. If a staff member connects Gmail to send proposals, we store their Google account identifier, Gmail address, and OAuth tokens on the server so the app can send mail on their behalf. We request send permission only.
Technical data. Authentication session, last login and logout times, preferred currency, and (when you have not chosen a currency) an approximate country derived from request headers or IP address so we can show SEK, EUR, NOK, or DKK. We do not run advertising pixels or third-party analytics in this application.
4. How we use the information
- Create and secure your account, and keep you signed in.
- Show catalog prices in your currency and remember that choice.
- Configure products, save requests, issue proposals, and fulfil orders.
- Match bank transfers, plan production, and send order and proposal documents.
- Let staff reply to buyer requests and email proposals from a connected Gmail account.
- Keep records required for accounting, tax, and product safety.
- Protect the service against abuse and diagnose faults.
5. Legal bases (GDPR)
We process personal data only where a GDPR legal basis applies:
- Contract creating an account, handling requests, proposals, orders, payment matching, and delivery.
- Legal obligation invoices and bookkeeping under Swedish law.
- Legitimate interests keeping the service secure, remembering currency and country preferences, and operating the Ops Console. These interests do not override your rights.
- Consent optional communications such as a newsletter, if you subscribe. You can withdraw consent at any time.
7. International transfers
Our processors may store or access data in the EU/EEA or in other countries. Where data leaves the EU/EEA we rely on an adequacy decision or Standard Contractual Clauses (or equivalent) from the processor. Google and Supabase publish their current transfer mechanisms on their privacy sites.
8. How long we keep data
- Account profile while the account is open, then until you ask us to delete it (subject to records we must keep).
- Orders, invoices, and payment matching — generally seven years to meet Swedish bookkeeping rules.
- Open requests and proposals while the commercial relationship is active, then as needed for follow-up and disputes.
- Gmail connection tokens until the staff member disconnects Gmail or leaves IXTAbox.
- Session and draft configuration until you sign out, close the browser tab (for session storage), or the cookie expires.
10. Your rights
If you are in the EU/EEA or Sweden you can ask us to access, correct, delete, or restrict your data, to object to processing based on legitimate interests, and to receive a portable copy of data you provided. You can also withdraw consent for optional processing.
Update profile fields from your account page. To delete an account or exercise other rights, email info@ixtabox.se. We may need to keep invoices and similar records even after an account is closed.
You may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or with your local supervisory authority.
11. Security
Access to the Buyer Portal and Ops Console requires a signed-in account. Passwords are handled by our authentication provider. Staff Gmail refresh tokens stay on the server. No method of transmission or storage is perfectly secure; we take reasonable technical and organisational measures appropriate to a manufacturing and sales system.
12. Children
The service is for adult buyers and IXTAbox staff. We do not knowingly collect personal data from children under 16.
13. Changes
We may update this policy when the product or the law changes. The date at the top is the latest version. Material changes will be reflected on this page.
14. Contact
IXTAbox AB
Holmsätersgatan 7, 504 58 Borås
Sweden
info@ixtabox.se
+46-70-222 3250