Privacy Policy

Last updated: 16 September 2026

This Privacy Policy explains how LEXIMS ("we", "us") collects, uses, and safeguards information when you use our retail and inventory management platform (the "Service"). By using the Service you agree to the practices described here.

Information we collect

  • Account & business data — your name, email, business name, branches, staff, roles, and the products, inventory, sales, and customer records you enter.
  • Payment data — subscription payments are processed by our payment partners (Paystack and Tuma/M-Pesa). We store transaction references and status, not full card details.
  • Usage & device data — log data such as IP address, browser type, and actions taken, used to operate and secure the Service.

How we use information

  • To provide, maintain, and improve the Service.
  • To process subscription billing and prevent fraud.
  • To send service, security, and (where permitted) product communications.
  • To provide support and respond to your requests.

Multi-tenancy & data isolation

LEXIMS is multi-tenant. Your business's data is logically isolated and scoped to your tenant; we do not share one tenant's data with another.

Google Calendar data

Staff members of a business using LEXIMS Services may choose to connect their own Google Calendar. When they do, LEXIMS asks Google for permission to view and edit calendar events (the calendar.events scope) and to see the email address of the connected account. We use that access for exactly two things:

  • Reading busy time — we read events in a rolling window (one day back, sixty days ahead) and store only their start and end times as blocked time, so those slots are not offered to customers. Event titles, descriptions, attendees, and attachments are not stored.
  • Writing bookings — confirmed bookings made in LEXIMS are created as events on the connected calendar, and updated or removed when the booking changes.

Google access and refresh tokens are encrypted at rest. Calendar data is never sold, never used for advertising, never used to train models, and never shared with anyone other than the business the staff member works for. A staff member can disconnect at any time from the Staff page, which deletes the stored tokens and the blocked time we pulled; the events we wrote stay on their calendar. Access can also be revoked from Google account permissions.

LEXIMS's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Sharing

We do not sell your data. We share it only with service providers who help us run the Service (e.g. hosting, payment processing, messaging) under appropriate confidentiality and data-protection terms, or where required by law.

Data security

We use encryption in transit, encrypt sensitive fields at rest, and apply role-based access controls. See our Security page for details.

Data retention

We retain your data while your account is active and for a reasonable period afterwards as needed for legal, accounting, or operational purposes. You may request deletion as described below.

Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. To exercise these rights, contact us at privacy@lexims.app.

Changes

We may update this policy from time to time. We'll post the new version here and update the date above.

Contact

Questions? Email privacy@lexims.app.

This document is provided as a general template and does not constitute legal advice. Please have it reviewed by qualified counsel for your jurisdiction before relying on it.