Xahelo
PartsHow it worksFor businessHelp
Search partsSign inStart a repair
Search partsSign inStart a repair
XaheloXahelo

Replacement-part identification, reverse engineering, manufacturing, quality evidence, and fulfillment in one connected system.

Engineering review required before manufacturing release
PlatformRepair a partFind a partPartsFor business
LearnReplacement partsDiscontinued partsReverse engineeringGuides
ManufacturingCustom 3D printed partsMaterialsManufacturersCustomer dashboard
TrustIntellectual propertyProduct safetyPoliciesPrivacyRefunds & remakesSupport
© 2026 Xahelo. All rights reserved.Your broken part, remade.
© XaheloLegalTermsPrivacyCA privacyRefunds & remakesShippingProduct safetyRestricted partsIPPrivacy requestsSeller informationAccessibility
Legal hubTermsPrivacyCalifornia PrivacyRefund & RemakeShippingProduct SafetyRestricted PartsIPPrivacy RequestsCookies & AnalyticsAI NoticeSeller InformationAccessibility
Privacy & data

Privacy Policy

This policy explains what Xahelo collects, why it is used, which service providers may process it, how long it is retained, and how people can exercise privacy choices.

Effective August 13, 2026Questions: support@xahelo.com
Consumer-rights safeguard.Nothing in this policy waives or limits rights or remedies that cannot lawfully be waived or limited. If this policy conflicts with mandatory consumer-protection law, the mandatory law controls.
On this page1. Scope2. Notice at collection3. Categories of information4. Sources of information5. How Xahelo uses information6. AI-assisted processing7. Service providers and disclosures8. Sale, sharing, advertising, and tracking9. Retention10. Security11. Privacy rights and choices12. California privacy disclosures13. Children14. International processing15. How to make a privacy request16. Policy changes and contact

1. Scope

This Privacy Policy applies to xahelo.com, Xahelo customer accounts, repair and part-identification requests, catalog and checkout activity, customer support, manufacturing and quality records linked to customers, and related online services.

Xahelo is designed for replacement-part and manufacturing workflows, not for collecting highly sensitive personal information. Do not place Social Security numbers, government ID numbers, medical records, financial-account credentials, passwords, or other unnecessary sensitive information into repair descriptions, photos, CAD files, or support messages.

2. Notice at collection

At or before relevant collection points, Xahelo may collect identifiers and contact information; account and authentication information; repair photos and files; product, model, label, measurement, and compatibility information; order, payment-status, tax, shipping, and fulfillment information; support communications; device, security, and log information; and first-party usage or analytics events.

Xahelo collects these categories to provide accounts and authentication, analyze repair requests, identify parts, create and manage quotes, manufacture and quality-check parts, process payments, fulfill orders, provide support, prevent abuse, secure the service, maintain records, improve reliability, and comply with law.

Xahelo does not currently sell personal information or share personal information for cross-context behavioral advertising.

3. Categories of information

  • Identifiers and contact data, such as name, email address, shipping address, and account identifiers.
  • Account and authentication data, including session and security information. Password handling is provided through the authentication system; Xahelo personnel should not ask you to send your password.
  • Repair and engineering submissions, including photos, CAD files, drawings, measurements, product type, brand, model number, part number, labels, damage descriptions, and intended-use information.
  • Commercial and transaction data, including quotes, order history, payment status, refunds, taxes, shipping, fulfillment, and reorder activity. Payment processors may handle full payment-card data; Xahelo's application is designed to rely on payment-provider tokens and transaction metadata rather than storing full card numbers.
  • Manufacturing and quality records, including material, revision, production, quality, fit-feedback, and fulfillment evidence connected to a request or order.
  • Communications, including support messages, repair discussions, notifications, and feedback.
  • Technical and security data, such as IP address, browser/device information, request logs, security events, and similar data used to operate and secure the service.
  • First-party analytics events used to understand whether core pages and workflows function and are used.

4. Sources of information

  • Directly from you when you create an account, submit a repair, upload files, request a quote, place an order, contact support, or provide feedback.
  • Automatically from your browser or device when you use the website, including ordinary server, security, and first-party analytics data.
  • From service providers involved in authentication, hosting, payment processing, email delivery, shipping, security, AI-assisted analysis, and related operations.
  • From product catalogs, compatibility information, public product information, or business records used to identify a part or product, where lawful.

5. How Xahelo uses information

  • Provide, authenticate, personalize, and secure accounts.
  • Analyze repair photos and files, identify likely parts, estimate scope, create quotes, and route uncertain work for human review.
  • Manufacture, inspect, certify internally where applicable, fulfill, support, and improve replacement parts.
  • Process payments and refunds and maintain transaction records.
  • Communicate about requests, orders, support, security, policy changes, and required operational notices.
  • Detect abuse, prevent fraud, enforce restrictions, investigate incidents, and protect users and the service.
  • Improve reliability, usability, accessibility, catalog quality, and manufacturing knowledge.
  • Comply with tax, accounting, legal, regulatory, recordkeeping, and dispute-resolution obligations.

6. AI-assisted processing

Xahelo may send relevant images, visible text, product information, and other request content to AI service providers when automated analysis is used. AI processing may help identify a part, read labels, compare catalog information, or assist engineering triage.

Do not include sensitive personal information in repair media unless it is genuinely necessary and you are authorized to provide it. Automated results are not treated as final safety approval for high-risk manufacturing decisions.

7. Service providers and disclosures

Xahelo may disclose information to service providers only as reasonably necessary for services such as hosting, database/storage, authentication, payments, AI-assisted analysis, email, shipping, fraud prevention, logging, and security.

Current core technology providers may include Supabase for authentication/database/storage, Vercel for application hosting, Stripe for payment processing, Google AI services for AI-assisted analysis when enabled, and delivery or email providers used for customer communications and fulfillment. Provider use can change as the platform evolves.

Xahelo may also disclose information when reasonably necessary to comply with law, protect rights or safety, investigate fraud or security incidents, complete a business transaction such as a merger or asset transfer subject to applicable privacy obligations, or respond to a valid legal process.

8. Sale, sharing, advertising, and tracking

Xahelo does not currently sell personal information and does not currently share personal information for cross-context behavioral advertising.

Xahelo does not currently run third-party behavioral advertising on the core service. If that practice changes, this policy and any legally required controls will be updated before or when the practice begins.

Because Xahelo does not currently use legacy Do Not Track signals to enable or disable cross-site behavioral advertising, a legacy browser Do Not Track signal does not change the core service. Where legally required and technically applicable, Xahelo will honor recognized opt-out preference signals such as Global Privacy Control.

9. Retention

Xahelo retains information for no longer than reasonably necessary for the purpose collected, taking into account account activity, active repair and order workflows, engineering revision history, fit and quality evidence, customer-support needs, fraud prevention, security, legal claims, tax/accounting obligations, and applicable law.

Different categories can require different retention periods. When information is no longer reasonably necessary, Xahelo will delete, deidentify, or securely dispose of it where practicable and permitted by law.

10. Security

Xahelo uses administrative, technical, and organizational safeguards designed to protect personal information. No online system can be guaranteed perfectly secure.

Xahelo intends to maintain security procedures and practices appropriate to the nature of the personal information it maintains and to use contractual and operational safeguards with service providers where required by applicable law.

Security measures include authentication, role-based authorization, server-side access controls for privileged operations, security headers, restricted service-role data access, logging, and operational safety gates. Customers should use strong account security and promptly report suspected compromise.

11. Privacy rights and choices

Depending on where you live and which privacy law applies to Xahelo, you may have rights to request access to personal information, correction, deletion, a portable copy, information about disclosures, restriction or limitation of certain processing, or an opt-out of certain sales or sharing.

Xahelo provides a privacy-request process even where a particular statutory right does not apply. Providing the process voluntarily does not mean Xahelo admits that every privacy statute applies to every request.

California law may provide additional rights when Xahelo meets the legal definition and thresholds of a covered business. If those requirements apply, Xahelo will provide the notices, methods, response timing, opt-out controls, and nondiscrimination protections required by law.

The statutory definition of a CCPA-covered business includes size and data-processing thresholds that can change through statutory adjustment. Xahelo does not state that it currently meets those thresholds merely by publishing this policy. Xahelo will reassess applicability as revenue, data volume, advertising practices, and processing activities change.

California privacy regulations effective in 2026 include additional requirements for certain covered businesses involving risk assessments, cybersecurity audits, and automated decisionmaking technology. Xahelo will evaluate those obligations if and when their applicability criteria are met; publishing this notice is not a representation that Xahelo is presently subject to every such requirement.

12. California privacy disclosures

California's Online Privacy Protection Act requires covered commercial websites that collect personally identifiable information from California consumers to conspicuously post a privacy policy describing categories collected and shared, change procedures, the effective date, and specified tracking disclosures. This policy is designed to provide those disclosures.

The California Consumer Privacy Act, as amended, applies only when statutory applicability requirements are met. Xahelo does not rely on this policy to claim an exemption; applicability is reviewed as the business grows.

If Xahelo becomes subject to the CCPA, the privacy policy and request process will be reviewed at least annually and updated with the disclosures, metrics, methods, and controls then required.

13. Children

Xahelo's purchasing and custom-manufacturing services are intended for adults and are not directed to children under 13. Xahelo does not knowingly seek personal information directly from children under 13.

Xahelo is a general-audience repair and manufacturing service. If Xahelo obtains actual knowledge that personal information was submitted by a child under 13, Xahelo will evaluate the information and take the deletion, consent, or other steps required by applicable children's privacy law.

If you believe a child submitted personal information without appropriate authorization, contact support@xahelo.com so the situation can be reviewed.

14. International processing

Xahelo and its service providers may process information in the United States and other locations where providers operate. Where cross-border transfer rules apply, Xahelo will use appropriate mechanisms required by applicable law.

15. How to make a privacy request

Use the Privacy Requests page or email support@xahelo.com with the subject 'Privacy Request.' Describe the request and the account or email address involved. Do not send passwords, Social Security numbers, full payment-card information, or government ID images unless Xahelo specifically requests a lawful and proportionate verification method.

Xahelo may take reasonable steps to verify identity before providing, correcting, or deleting personal information. Verification information is used only as necessary for the request and related security or legal obligations.

16. Policy changes and contact

Material changes will be identified by an updated effective date and, when appropriate, additional notice through the service or email.

Privacy questions and requests may be sent to support@xahelo.com with an appropriate subject line.

Xahelo may update this policy prospectively when its services, legal obligations, or business practices change. Material changes will be identified by an updated effective date and, when appropriate, an additional notice.

Back to Legal & Policies