Legal
Privacy Policy
This policy explains how 1XA handles website inquiries, private previews, and information processed through optional ChatGPT connections to 1XA ERP.
Last updated: September 22, 2026
Information we collect
We may collect business contact information such as name, work email, company, role, workflow focus, message content, and information you submit through forms or direct communications.
We may also collect technical and security information such as IP address, browser type, device information, referrer, page interactions, request metadata, bot detection signals, security challenge results, and logs needed to protect the website and private preview environments.
How we use information
We use information to respond to demo and partner requests, evaluate fit, schedule conversations, provide requested resources, protect the site, detect abuse, improve content, operate access controls, and maintain security and audit readiness.
We do not ask visitors to submit regulated production data, consumer data, payment card data, production system credentials, private exports, or government ID images through public website forms.
Cookies and local storage
The website may use strictly necessary cookies, local storage, and similar technologies to remember consent choices, support security controls, preserve form functionality, and improve site reliability.
Optional Google Analytics measurement loads only after you choose Accept optional. Choosing Essential only does not prevent you from browsing, contacting us, requesting a demo or trial, or using Login.
Optional connection to ChatGPT
Where enabled, an authorized 1XA ERP user can connect ChatGPT through an explicit sign-in and consent flow. 1XA checks the active company and current ERP permissions before providing information. The connection is optional and does not permit ChatGPT to change ERP records, place orders, or move money.
When you ask ChatGPT to use the connection, 1XA shares permitted aggregate record counts, monthly activity, data-freshness timestamps, and links to ERP source pages. Connection inspection also returns the connected workspace, permitted areas, expiry information, and a connection-management link. Customer contact details, credentials, prices, and individual source records are excluded from tool responses. Source and management links still require ERP authorization.
1XA processes account and company identifiers, current permissions, session validity, OAuth authorization information, and connection events to authenticate the connection, enforce access, prevent abuse, and support disconnect. The connector does not store your prompts or returned business summaries in its connection audit history. It records connection events and tool names without query contents or source records.
OpenAI receives the tool results in your ChatGPT conversation. Its handling of those results and your conversation is governed by your OpenAI account or workspace terms and settings. Disconnecting 1XA stops future connector access; it does not remove information already included in a ChatGPT conversation. Manage or delete that conversation through OpenAI. The connector does not load the marketing website analytics into your ERP workspace.
Connection authorization lasts at most one hour and may end sooner when the ERP session expires. Access tokens last ten minutes; refresh cannot extend the underlying ERP authorization beyond its expiry. At expiry the connector removes the active ERP grant and retains a limited connection receipt for up to 24 additional hours before scheduled deletion. Separate ERP records, security logs, and provider records follow their applicable retention policies; this short connection lifetime does not delete those records.
Use the management link returned by the connection tool to disconnect immediately. A change of company or permissions requires a new connection. For help disconnecting, questions about connector data, or a request to access or delete information held by 1XA, contact Support@1xa.ai. We verify the requester and may retain information required for security, legal, or audit obligations.
Optional website analytics
With your consent, we use Google Analytics 4 to understand which public pages visitors read and where they start or complete demo and free-trial requests. This helps us improve useful content and identify problems in the request process.
Our measurement sends the public page address and title, demo or trial button interactions, form starts, submission attempts, errors, and a completion event when our server accepts a request. It distinguishes demo from trial requests without sending the information you enter into the form. We exclude names, email addresses, phone numbers, company names, messages, URL query strings and fragments, and referring-page addresses from these analytics events.
Google receives browser and device information, cookie identifiers and network information such as your IP address when your browser connects to its service. Analytics can derive location information from that connection. These records are not the same as the contact information you submit to 1XA for a response.
Our marketing property does not enable Google Signals, user-provided data collection, advertising personalization, or automatic Enhanced Measurement. We do not use this setup to record form-field contents or to track your ERP workspace. Google may process information on infrastructure outside your country; our US-operated business statement is not a data-residency guarantee.
How Google uses information from websites that use its services
Sharing information
We may share information with service providers that support hosting, email delivery, security, analytics, CRM workflows, scheduling, and communications. These providers are expected to process information only for authorized business purposes.
We may disclose information when required by law, to protect rights and security, to investigate abuse, or in connection with a business transaction such as financing, merger, acquisition, or asset transfer.
Security and retention
We use administrative, technical, and organizational safeguards intended to protect information. No public internet service can be guaranteed completely secure.
We retain information for as long as reasonably needed for the purposes described in this policy, including business follow-up, legal obligations, security, audit, dispute resolution, and operational needs.
In our Google Analytics property, event-level data retention is set to 2 months and user-level data retention to 14 months. New activity can restart the user-level retention period. These settings do not limit how long Google Analytics keeps standard aggregated reports. Cookie lifetimes are described separately in the Cookie Policy.
Your choices
You can ask to update, delete, or review business contact information by emailing sales@1xa.ai. We may need to retain limited information where required for legal, security, audit, or legitimate business purposes.
Use Cookie Settings in the footer or on the Cookie Policy page, then choose Essential only to withdraw optional analytics consent. This stops further measurement and removes this property's analytics cookies where the browser permits. It does not delete information already collected. You can contact us about that information separately.
We also keep optional analytics off when your browser sends Global Privacy Control or Do Not Track. Your choices apply to that browser; you may need to make the same choice on another device or after clearing browser storage.
Contact
Privacy questions can be sent to sales@1xa.ai or mailed to 1500 N Grant St, Suite R, Denver, Colorado 80203.