Legal

Privacy Policy

Last updated: April 9, 2026
~10 min read

This Privacy Policy describes how Xidisk Software Solutions ("Xidisk," "we," "us," or "our") collects, uses, discloses, and safeguards your information when you use Sprint Bridge and related services. Please read this policy carefully. By using Sprint Bridge, you agree to the practices described here.

01

Introduction

Xidisk Software Solutions operates Sprint Bridge, an enterprise agile project management platform ("the Service"). This Privacy Policy explains our practices regarding the collection, use, and disclosure of personal information we receive from users of Sprint Bridge, our website at sprint-bridge.com, and related applications and services (collectively, "Services").

We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about this policy or our practices with regard to your personal information, please contact us at privacy@xidisk.com.

This Privacy Policy applies to all information collected through our Services, as well as any related services, sales, marketing, or events. It does not apply to information collected by third parties, including any websites, services, and applications that you may access through our Services.

Roles Under GDPR

For users accessing Sprint Bridge through their employer or organization, Xidisk Software Solutions acts as a data processor on behalf of the organization (the data controller). When you interact directly with our marketing website or request a demo, we act as a data controller. The applicable role determines which provisions of this policy apply to your situation.

02

Information We Collect

We collect information you provide directly to us, information we collect automatically when you use our Services, and information we receive from third parties.

Information You Provide Directly

We collect information you provide when you create an account, request a demo, submit a support ticket, or otherwise communicate with us. This includes:

  • Account information: name, work email address, company name, job title, and password (stored using bcrypt hashing).
  • Profile information: professional details, profile photo, and preferences you configure within the platform.
  • Payment information: billing address and payment method details, which are processed by our third-party payment processor and never stored on our servers.
  • Communications: messages you send us via email, support tickets, or the contact form, including any attachments.
  • Demo and sales requests: information submitted through our Get Started Free or Request Demo forms, including availability preferences and workflow information.
  • User-generated content: project data, sprint plans, backlog items, comments, file attachments, and other content you create within the platform.

Information Collected Automatically

When you use our Services, we automatically collect certain information about your device and usage, including:

  • Log data: IP address, browser type and version, pages visited, time spent on pages, referring URLs, and access timestamps. All API calls and user actions are logged for security and audit purposes.
  • Device information: operating system, device type, screen resolution, and device fingerprint used for session security and fraud prevention.
  • Usage data: features used, workflows configured, sprint and project activity, and performance metrics that help us improve the Service.
  • Location data: approximate geographic location derived from your IP address, used for security monitoring (such as detecting logins from new geographic regions) and for compliance with regional data protection laws.
  • Session data: session tokens, authentication events, MFA verifications, and device trust status stored securely in Redis with automatic expiration.

Information from Third Parties

We may receive information about you from third parties in the following circumstances:

  • Single Sign-On providers: if you authenticate using Google Workspace or Microsoft Azure Active Directory via Auth0, we receive your name, email address, profile photo, and organizational details from those providers.
  • Payment processors: we receive transaction confirmations and billing status updates from our payment processing partners, but not full payment card details.
  • Customer organizations: your employer or organization may provide us with your account information when provisioning access to Sprint Bridge on your behalf.
03

How We Use Your Information

We use the information we collect for the following purposes, relying on the legal bases described below:

To Provide and Maintain the Service

  • Create and manage your account, authenticate your identity, and enable access to Sprint Bridge features.
  • Process transactions and send you related information, including purchase confirmations and invoices.
  • Provision organizational workspaces and configure permissions according to your role and your organization's settings.
  • Provide customer support and respond to inquiries, including processing support tickets through the Sprint Bridge Support Portal.
  • Send transactional emails such as password reset links, login verification, sprint notifications, and workspace invitation emails.

For Security and Fraud Prevention

  • Monitor authentication events, detect brute-force attempts, and automatically block suspicious IP addresses including known Tor exit nodes and VPN proxies.
  • Calculate risk scores (0–100) per authentication event using IP reputation, device fingerprint, geographic signals, and behavioral patterns.
  • Maintain tamper-evident audit logs of all user actions, API calls, and configuration changes for security incident response and compliance reporting.
  • Enforce session security policies including idle timeouts, concurrent session limits, and force-logout capabilities.

For Compliance and Legal Obligations

  • Generate SOX, GDPR, SOC 2, PCI DSS, and ASC 350-40 compliance reports, audit trails, and financial documentation as required by your organization's compliance obligations.
  • Maintain records as required by applicable law, including financial records, access logs, and data processing agreements.
  • Respond to lawful requests from public authorities, including law enforcement and regulatory agencies, where required by applicable law.

To Improve and Develop the Service

  • Analyze usage patterns, feature adoption, and performance metrics to improve Sprint Bridge functionality and user experience.
  • Conduct internal research and development to build new features, with data aggregated and anonymized where possible.
  • Send product update emails, release notes, and service announcements — you may opt out of non-transactional communications at any time.
AI Feature Data Processing

Sprint Bridge offers optional AI-powered features including story enhancement, test generation, and acceptance criteria drafting. When you use these features, the relevant content (user story text, acceptance criteria, etc.) is transmitted to your configured AI provider (OpenAI, Google, or Anthropic) for processing. We do not use your project data to train AI models. Each provider's data usage is governed by their respective terms of service, which we encourage you to review.

04

Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following limited circumstances:

Service Providers

We share information with trusted third-party vendors who assist us in operating our Services. These providers are contractually bound to use your information only as directed by us and in accordance with this Privacy Policy. Current categories of service providers include:

  • Authentication: Auth0 (Okta) for identity management, single sign-on, and multi-factor authentication.
  • Infrastructure: cloud hosting and database services for platform operation, backup, and disaster recovery.
  • Email delivery: transactional email service providers for sending system notifications, invitations, and support communications.
  • Payment processing: PCI DSS-compliant payment processors for handling subscription billing. We receive no raw card data.
  • AI providers: OpenAI (GPT-4), Google (Gemini), and Anthropic (Claude) for optional AI-assisted features, used only when you explicitly invoke those features.
  • Analytics: aggregated, anonymized usage analytics to understand platform performance. We do not share personally identifiable information with analytics providers.

Within Your Organization

If you access Sprint Bridge through your employer or organization, your account information, activity logs, and project data are accessible to administrators within your organization according to the roles and permissions configured by your organization's administrator. Xidisk Software Solutions is not responsible for your organization's privacy practices with respect to this data.

Legal Requirements

We may disclose your information if required to do so by law or in response to valid legal process, including a court order, subpoena, search warrant, or other lawful request. We will attempt to notify you of such requests in advance where legally permissible and where we have a means of contacting you.

Business Transfers

If Xidisk Software Solutions is involved in a merger, acquisition, financing, or sale of business assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our website if such a transfer occurs and if it results in a material change to this Privacy Policy.

With Your Consent

We may share your information with third parties when you have given us your explicit consent to do so, including when you authorize integrations with third-party services through the Sprint Bridge integrations marketplace.

05

Data Retention

We retain personal information for as long as necessary to provide our Services, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods depend on the type of data and the reason for its collection:

  • Account data: retained for the duration of your active account, plus a reasonable period following account closure to allow for account recovery and to fulfill legal obligations.
  • Project and workspace data: retained throughout the subscription period. Upon termination of your organization's subscription, a 90-day data export window is provided, after which data is permanently deleted from our systems.
  • Audit logs and security events: retained for a minimum of 12 months, and up to 7 years where required by SOX, GDPR, or other applicable compliance frameworks. Retention duration is configurable by organization administrators within the bounds of applicable law.
  • Financial records: retained for a minimum of 7 years to satisfy applicable accounting standards and tax regulations.
  • Support ticket data: retained for 3 years following ticket closure, or longer if required by ongoing legal or compliance matters.
  • Marketing and sales inquiry data: retained for up to 2 years following your last interaction with us, after which it is anonymized or deleted.
  • Session data: stored in Redis with automatic expiration based on your organization's configured session timeout policies.

You may request deletion of your personal data at any time, subject to our legal obligations to retain certain categories of information. See Section 8 (Your Rights) for details on how to submit a deletion request.

06

Data Security

We implement and maintain technical, organizational, and administrative security measures designed to protect your personal information against unauthorized access, disclosure, alteration, and destruction. Our security practices include:

  • Encryption: all data transmitted between your browser and our servers is encrypted using TLS. Sensitive data including passwords is hashed using bcrypt with a minimum of 10 salt rounds and is never stored in plaintext.
  • Access control: granular role-based access controls ensure users access only the data necessary for their role. Administrative access to production systems is limited, logged, and requires multi-factor authentication.
  • Infrastructure security: our application runs in Docker-containerized environments with non-root user execution, regular security patching, and continuous vulnerability monitoring.
  • Authentication security: Auth0-powered identity management with support for TOTP authenticator apps, SMS OTP, email magic links, and risk-based step-up authentication challenges.
  • Audit logging: all system access, data modifications, configuration changes, and security events are logged with cryptographic integrity verification to detect tampering.
  • Backup and recovery: automated encrypted backups are performed regularly with tested recovery procedures. Point-in-time recovery is supported with transaction consistency guarantees.
  • Penetration testing and security reviews: we conduct regular security reviews and testing of our platform, including assessment of third-party dependencies.

Despite our efforts, no security measure is perfect or impenetrable. If you discover a potential security vulnerability in Sprint Bridge, please report it responsibly to security@xidisk.com. We are committed to working with security researchers to verify and address reported issues promptly.

In the event of a data breach that is likely to affect your rights or freedoms, we will notify you and applicable regulatory authorities as required by applicable law, including within 72 hours where required by GDPR.

07

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to operate and improve our Services, authenticate users, and analyze usage patterns. Below is a summary of the types of cookies we use:

Strictly Necessary Cookies

These cookies are essential for the Services to function and cannot be disabled. They include session cookies that maintain your authenticated state, CSRF protection tokens, and security cookies used to detect and prevent fraudulent activity. These cookies do not require your consent under applicable cookie laws.

Performance and Analytics Cookies

We use cookies to collect information about how visitors interact with our website — which pages are visited most, how long users spend on each page, and whether errors occur. This information is used in aggregated, anonymized form to improve our Services. You may opt out of performance cookies through your browser settings or our cookie preference center.

Preference Cookies

These cookies remember your settings and preferences — such as your chosen theme, language, and display options within Sprint Bridge — so you do not need to reconfigure them each time you log in.

Managing Cookies

Most web browsers allow you to control cookies through browser settings. You can instruct your browser to refuse all cookies or to alert you when cookies are being sent. However, disabling strictly necessary cookies may prevent Sprint Bridge from functioning correctly. Your browser's help documentation will explain how to manage cookie settings for your specific browser.

Our Services do not respond to "Do Not Track" browser signals at this time, as there is no consistent industry standard for how to respond to such signals.

08

Your Privacy Rights

Depending on your location, you may have certain rights with respect to your personal information. We honor these rights for all users regardless of jurisdiction, as we believe privacy is a fundamental right rather than a compliance checkbox.

Right of Access

Request a copy of the personal information we hold about you, including how it is being used and with whom it has been shared.

Right of Rectification

Request correction of inaccurate or incomplete personal information we hold about you. Many details can be updated directly in your account settings.

Right of Erasure

Request deletion of your personal information ("right to be forgotten"), subject to our legal obligations to retain certain data for compliance purposes.

Right to Restrict Processing

Request that we restrict the processing of your personal information in certain circumstances, such as while we verify the accuracy of data you have contested.

Right to Data Portability

Request a machine-readable export of your personal information in a commonly used format (JSON or CSV). All project data is exportable at any time from your account settings.

Right to Object

Object to our processing of your personal information where we rely on legitimate interests as our legal basis, including for direct marketing communications.

California Residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information is collected, the right to delete personal information, the right to opt out of the sale of personal information (we do not sell personal information), the right to non-discrimination for exercising your privacy rights, and the right to correct inaccurate personal information.

To exercise these rights, please contact us at privacy@xidisk.com with the subject line "CCPA Privacy Request." We will respond to verified requests within 45 days.

How to Exercise Your Rights

To exercise any of the rights described above, please submit a request to privacy@xidisk.com. We will respond to all verified requests within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing your request. We will not discriminate against you for exercising your privacy rights.

If you are located in the European Economic Area and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection authority.

09

International Data Transfers

Xidisk Software Solutions is based in the United States. If you are located outside the United States, please be aware that information we collect will be transferred to, processed, and stored in the United States and other countries where our service providers operate. These countries may have data protection laws that are different from the laws of your country.

For transfers of personal data from the European Economic Area, United Kingdom, or Switzerland to countries not deemed adequate by the European Commission, we rely on the following transfer mechanisms:

  • Standard Contractual Clauses (SCCs): we use the European Commission's approved Standard Contractual Clauses for data transfers from the EEA to our service providers in third countries.
  • Data Processing Agreements: we maintain Data Processing Agreements (DPAs) with all third-party service providers who process personal data on our behalf, ensuring they maintain appropriate safeguards.
  • Adequacy Decisions: where applicable, we rely on adequacy decisions issued by the European Commission for transfers to countries with recognized adequate levels of data protection.

To obtain a copy of the Standard Contractual Clauses or Data Processing Agreement applicable to your data, please contact us at privacy@xidisk.com.

10

Children's Privacy

Sprint Bridge is a business-to-business enterprise software platform and is not directed at or intended for use by children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us at privacy@xidisk.com and we will take steps to delete such information as promptly as possible.

If we become aware that we have collected personal information from a child under 16 without verifiable parental consent, we will take steps to remove that information from our servers promptly. If you believe we might have any information from or about a child under 16, please contact us immediately.

11

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services we offer, applicable laws, or for other operational, legal, or regulatory reasons. We will notify you of any material changes by:

  • Posting the updated Privacy Policy on this page with an updated "Last Updated" date at the top.
  • Sending an email notification to the primary email address associated with your account, at least 30 days before material changes take effect.
  • Displaying a prominent notice within the Sprint Bridge application at your next login.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of Sprint Bridge after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

For changes that materially affect your rights or how we process your personal information, we will seek your explicit consent where required by applicable law. If you disagree with material changes to this Privacy Policy, you may terminate your account and request deletion of your data before the changes take effect.

Policy Version History

We maintain a version history of this Privacy Policy. Previous versions are available upon request by contacting privacy@xidisk.com. The current version was last updated on April 9, 2026, and supersedes all prior versions.

12

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the information below. We are committed to resolving privacy-related questions promptly and transparently.

Privacy & Data Protection Contact

For all privacy-related inquiries, data subject requests, or to exercise your rights under GDPR, CCPA, or other applicable law, please reach out to us at any of the following:

Privacy enquiries: privacy@xidisk.com
Security issues: security@xidisk.com
General enquiries: enterprise@xidisk.com
Mailing address: Xidisk Software Solutions, Attn: Privacy, United States

If you are located in the European Economic Area and you are not satisfied with our response to your privacy inquiry, you have the right to lodge a complaint with the data protection supervisory authority in your member state. A list of EEA supervisory authorities and their contact details is available at edpb.europa.eu.