XurOps

Privacy Policy

Last updated 31 August 2026

TechXur (techxur.com) built XurOps to run its own business: projects, staffing, sales leads, calendars, and payroll. You get an account when one of our admins invites you, which covers our staff along with the contractors and partners we work with. There is no public sign-up, and we don't sell or license the app to anyone.

What we collect

  • Your work record: name, work email, role, the projects you're staffed on, and your pay details. An admin enters all of it.
  • Your login: Supabase Auth handles sign-in for us, so your password never reaches our servers.
  • Your Google account: only when you connect a calendar yourself.

Google Calendar access

Connecting a Google account asks you for two scopes. We request nothing beyond these:

calendar.readonly
We read your primary calendar. We never create, edit, or delete an event on it.
userinfo.email
We read your address, so the app can label the connection.

We pull your events from Google at the moment you open the calendar or a reminder goes out, and that includes the title, time, description, location, meeting link, and guest list. None of it reaches our database. Once the page finishes rendering, we no longer hold it. Two things do stay with us: your Google address, and a refresh token that we encrypt before saving, so you don't have to reconnect every session.

What Google sends us has one job, showing you your own calendar inside XurOps. It never goes to an advertiser, another company, or a model anyone trains.

Disconnecting and deletion

Open the calendar page and disconnect the account whenever you like. We revoke the token with Google and delete our copy of it. You can also cut us off from your Google account directly at myaccount.google.com/permissions. For the rest of your data, ask your admin or write to hr@techxur.com. We do keep some payroll records after that, since accounting and tax rules make us.

Sharing and processors

We don't sell or rent your data. It touches the services we run XurOps on: hosting, our database and login provider, email delivery, file storage, and Slack for notifications. Each one processes it on our instructions and for nothing else.

Security

You need an invited account to get in, and your role decides what you see once you do. We encrypt refresh tokens before they reach the database, and every request travels over HTTPS.