PhiXenia
PrivacyTermsSMS termsSecurity
Join beta
PhiXenia business legal terms

PhiXenia Privacy Policy

How PhiXenia collects, uses, discloses, and protects personal information.

Effective date
July 16, 2026
Version
Attorney Review Draft 0.9
Download the source document (.docx)
Attorney review draft

This version is available for private beta review and provider-registration testing. It is not represented as counsel-approved. Removing this notice requires approval from Utah counsel and payments counsel plus a verified public business mailing address.

This Privacy Policy explains how PhiXenia LLC (“PhiXenia,” “we,” “us,” or “our”) handles personal information when people visit https://phixenia.com, create or administer a PhiXenia business account, use our software and apps, communicate with us, or interact with a business using PhiXenia-powered booking, waiver, portal, checkout, messaging, or other experiences (the “Services”).

PhiXenia is a business platform. A business using PhiXenia (“Business Customer”) generally decides why and how information about its customers, guests, participants, and staff is collected. For that information, the Business Customer is the controller or business and PhiXenia acts as its processor or service provider. The Business Customer’s own privacy notice also applies. PhiXenia acts as an independent controller for business-account administration, direct marketing, security, fraud prevention, billing, legal compliance, and our own website operations.

1. Scope

This Policy applies to PhiXenia’s Services in the United States. It does not govern a Business Customer’s independent practices, a linked third-party website or service, or a Payment Provider’s independent collection and use of information. When payment information is entered in a provider-hosted payment form, the Payment Provider’s privacy notice applies to that collection.

2. Personal information we collect

2.1 Business account and identity information

  • name, title, work email, mobile number, username, account role, authentication and recovery information;
  • business legal and display names, entity type, addresses, locations, website, industry, products and services;
  • EIN or other tax information, tax classification, ownership or controlling-person information, and verification records; and
  • support requests, implementation details, contracts, acceptance records, feedback, and communications with us.

2.2 Information processed for Business Customers

  • customer and guest identifiers and contact details, including names, email addresses, telephone numbers, addresses, and customer IDs;
  • booking, attendance, purchase, refund, store-credit, loyalty, promotion, membership, and transaction information;
  • waiver and release information, including date of birth or age, electronic signature, guardian relationship, minor participant information, acknowledgments, and uploaded records;
  • staff, applicant, contractor, franchise, referral-partner, or vendor information entered by a Business Customer;
  • messages, notes, tasks, call or chat records, customer-service history, and preferences; and
  • optional information a Business Customer chooses to collect, such as accessibility, safety, emergency-contact, or accommodation information.

2.3 Payment and financial information

Payment Providers collect card numbers, bank-account details, and card security codes through secure provider-controlled forms. PhiXenia receives payment tokens, brand and last four digits, expiration data, billing contact information, transaction status, fees, disputes, refunds, payout records, and fraud or verification signals. PhiXenia does not intentionally store full payment-card numbers or card security codes.

2.4 Device, usage, and technical information

  • IP address, device and browser type, operating system, language, approximate location derived from IP, and identifiers stored in cookies or similar technologies;
  • pages and features viewed, referring URLs, clicks, search and filter activity, session timestamps, performance, crash, and diagnostic information; and
  • security and audit logs, login events, permission changes, API and integration activity, and records used to detect abuse or fraud.

2.5 AI feature information

If an authorized user enables or uses an AI feature, we process the submitted prompt, selected account context, attachments, and generated output to provide, secure, evaluate, and support that feature. We do not use Customer Personal Data to train a public or general-purpose AI model without the Business Customer’s express authorization.

3. Sources of information

We collect information directly from account owners, users, customers, guests, guardians, and waiver participants; automatically from devices and use of the Services; from Business Customers and their authorized users; from connected integrations and Payment Providers; from identity, fraud, and verification vendors; and from lawful public or commercial sources such as business registries.

4. How we use personal information

  • provide, configure, maintain, personalize, and support the Services;
  • process bookings, payments, refunds, waivers, communications, credits, loyalty, reporting, and other instructions from a Business Customer;
  • authenticate users, manage permissions, verify businesses, prevent fraud and abuse, protect accounts, and investigate security events;
  • communicate about transactions, support, service changes, incidents, renewals, invoices, and account administration;
  • analyze performance, fix errors, develop features, and create aggregated or deidentified analytics and benchmarks;
  • comply with law, court orders, tax and financial requirements, sanctions, card-network rules, and enforce our agreements; and
  • market PhiXenia to business contacts where permitted, honoring opt-outs and applicable consent requirements.

Where privacy law requires a legal basis, we process information to perform a contract, follow documented Business Customer instructions, comply with legal obligations, protect legitimate interests such as security and product improvement, or based on consent where required.

5. How we disclose personal information

We disclose personal information only as reasonably necessary for the purposes described above, including to:

  • the relevant Business Customer and its authorized locations, administrators, staff, franchise entities, or partners according to configured permissions;
  • Payment Providers, banks, card networks, and fraud or identity-verification vendors for payment, payout, onboarding, dispute, and compliance functions;
  • hosting, security, analytics, support, communications, document, integration, AI, and professional-service providers bound to appropriate restrictions;
  • third-party services intentionally enabled by an authorized user;
  • government authorities, courts, regulators, law enforcement, or other parties when disclosure is required or reasonably necessary to protect rights, safety, security, or prevent fraud; and
  • a buyer, successor, financing source, or advisor in a merger, financing, reorganization, bankruptcy, or sale of all or part of our business, subject to appropriate confidentiality and legal requirements.

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, and we do not use Customer Personal Data for targeted advertising. We do not sell mobile numbers or share SMS opt-in data or consent with third parties or affiliates for their marketing or promotional purposes. Communications providers may process that information only to deliver and support messages requested through the Services.

6. Cookies and similar technologies

We use strictly necessary cookies and local storage for login, security, preferences, and core functionality. We may use limited analytics technologies to understand performance and use. If we add advertising or other nonessential cookies, we will provide legally required notice and choices before using them. Browser controls may block cookies but can prevent some Services from working. Where legally required and technically supported, we honor applicable opt-out preference signals such as Global Privacy Control for activities treated as a sale or sharing; we currently do not engage in those activities.

7. Payments

PhiXenia Payments is currently enabled through Square and may use additional or replacement Payment Providers. Payment Providers process information under their own terms and privacy notices and may act independently for legal, underwriting, fraud, card-network, and reporting purposes. A Business Customer may be required to create or connect a provider account. Changing providers may require new verification, terms, or payment credentials.

8. Children and minor participants

PhiXenia business accounts are not for children under 18. The Services may process information about minors when a Business Customer offers activities to families or uses waiver tools. Children under 13 may not independently create an account, make a submission, or sign a waiver through PhiXenia. A parent or legal guardian, or the Business Customer acting under lawful authority, must provide and authorize the minor’s information.

A Business Customer that operates a child-directed or mixed-audience service is responsible for determining whether the Children’s Online Privacy Protection Act or similar law applies, providing direct parental notice, obtaining verifiable parental consent, limiting collection, and honoring parental rights. PhiXenia will process such information only under the Business Customer’s documented instructions and will reasonably assist with deletion or access requests. Parents should contact the relevant Business Customer first or privacy@phixenia.com if they cannot identify the business.

9. Sensitive and regulated information

The Services may process account credentials, financial account and payment information, precise identity-verification records, dates of birth, electronic signatures, and information about minors. We use sensitive information only to provide requested Services, verify and secure accounts, process payments, comply with law, or other purposes permitted without a right to limit under applicable law. Do not submit Social Security numbers, full card data, medical records, or other highly sensitive data unless the field expressly requests it.

PhiXenia is not a HIPAA-compliant medical-record service by default. A Business Customer may not submit protected health information regulated by HIPAA unless PhiXenia has signed a Business Associate Agreement for the applicable service.

10. Security

We maintain reasonable administrative, technical, and organizational safeguards designed to protect personal information, including access controls, encryption in transit, secure software practices, logging and monitoring, incident response, backups, and vendor review appropriate to the risk. Payment credentials are collected through Payment Provider-controlled components. No security method is perfect; users should use unique credentials, enable available multi-factor authentication, protect devices, and promptly report suspected compromise to security@phixenia.com.

11. Retention

We retain information for as long as reasonably necessary to provide the Services and for the purposes described in this Policy. Retention depends on the type of record, Business Customer instructions and configuration, legal and tax requirements, waiver and transaction retention needs, fraud and security risk, disputes, and backup cycles. After account termination, we ordinarily make Customer Data available for a limited export period and then delete or deidentify active copies, while retaining limited billing, tax, security, consent, dispute, and backup records as legally or operationally necessary. A Business Customer may set longer retention for its own records and is responsible for that choice.

12. Your choices and privacy rights

Depending on where you live and the role in which PhiXenia handles your information, you may have the right to request access, correction, deletion, or a portable copy; obtain categories of information, sources, purposes, and recipients; opt out of sale, sharing, or targeted advertising; limit certain sensitive-information uses; withdraw consent; or appeal a denied request. We do not discriminate for exercising privacy rights.

If your information was collected for a Business Customer, submit the request to that business first because it controls the record. We will assist the business as required. For information PhiXenia controls, email privacy@phixenia.com with “Privacy Request” in the subject. We may verify your identity and authority and may deny or limit a request where permitted by law. An authorized agent may submit a request with proof of authority. To appeal, reply to the decision with “Privacy Appeal.”

Marketing emails include an unsubscribe option. Transactional and account-security messages may continue while an account remains active. For SMS, reply STOP where supported or contact the sending Business Customer. You may update business-account profile information in account settings.

13. California and other U.S. state disclosures

During the preceding 12 months, the categories of personal information we may have collected are identifiers; customer-record information; commercial information; internet or electronic-network activity; approximate geolocation; audio, electronic, or visual information when submitted; professional or employment-related information; inferences used for security or product assistance; and sensitive personal information described in Section 9. Sources, business purposes, and recipient categories are described in Sections 3 through 5. We do not sell or share these categories for cross-context behavioral advertising.

When PhiXenia processes information for a Business Customer, our contract restricts us from retaining, using, or disclosing it outside the limited and specified business purposes, selling or sharing it, or combining it with information from other sources except as permitted by law. State rights apply only when the relevant law covers PhiXenia or the Business Customer; we may honor a verified request voluntarily even when not legally required.

14. International access

The Services are operated from the United States and are initially offered to U.S. Business Customers. If information is submitted from another country, it may be transferred to and processed in the United States, where law may differ. A Business Customer may not use the Services for regulated European Economic Area, United Kingdom, or Swiss processing until any required international transfer terms have been executed with PhiXenia.

15. Changes to this Policy

We may update this Policy to reflect changes in the Services, law, or our practices. We will post the updated version and effective date and will provide additional notice for material changes when required. If a change requires consent, it will apply only after consent is obtained.

16. Contact us

Privacy questions and requests: privacy@phixenia.com. Security reports: security@phixenia.com. Mail: PhiXenia LLC, Attn: Privacy, [PUBLIC BUSINESS MAILING ADDRESS], Herriman, Utah 84096. Website: https://phixenia.com.

17. Business-account acceptance

For a Business Customer opening an account, checking the acceptance box confirms that the authorized representative has received and reviewed this Policy and understands the controller/processor distinction described above. PhiXenia may retain the document version, checkbox text, signer and business identifiers, timestamp, IP address, and device or session information as evidence of notice and acceptance.

PhiXenia

Booking and business operations software for U.S. businesses.

Privacy policyService termsSMS termsAcceptable useData processingTransaction termsSubprocessorsSecurity
support@phixenia.comprivacy@phixenia.comlegal@phixenia.com