Skip to main content
Xoxoday Plum processes personal data in full compliance with the California Consumer Privacy Act (CCPA), supporting data subject access requests, erasure rights, and opt-out controls across all reward and incentive workflows.
When organisations deploy rewards and incentives programs, they need a platform that handles employee and recipient data responsibly under applicable law. Xoxoday Plum is built to comply with the California Consumer Privacy Act (CCPA) and comparable state-level data protection frameworks across the United States. Compliance is embedded into the product — not layered on as an afterthought. Xoxoday Plum processes several categories of personal data to deliver reward experiences: contact information such as email addresses and phone numbers, network identifiers including IP addresses, and behavioural data such as reward preferences and redemption history. Each data category is collected, stored, and used strictly within the purposes disclosed to users at the time of collection. Under CCPA, California residents have the right to know what personal data is collected about them, to request deletion, and to opt out of certain data uses. Xoxoday Plum supports Data Subject Access Requests (DSARs) through defined workflows, enabling your organisation to respond within the timelines required by law. Erasure rights are also fully supported, allowing individuals to have their personal data removed upon a verified request. Xoxoday Plum provides a dedicated privacy notice that clearly communicates data collection practices, the purposes for processing, and available opt-out mechanisms. Recipients interacting with Xoxoday Plum — whether through an integration with Workday, SAP SuccessFactors, or Darwinbox — are informed of their data rights before and during their session. This transparency is a core CCPA requirement and is treated as a non-negotiable standard across all product workflows. Xoxoday Plum applies a privacy-by-design approach, meaning data minimisation, purpose limitation, and access control principles are factored into product development from the ground up. All personal data is encrypted in transit and at rest. Role-based access controls restrict data visibility to authorised personnel only, and regular internal audits validate these controls on an ongoing basis. Consider an HR team running a peer recognition program integrated with Slack and Microsoft Teams. When a reward notification is triggered and a recipient redeems a gift, Xoxoday Plum governs the associated personal data under the same CCPA-compliant controls. The entire data lifecycle — from collection through redemption to post-program deletion — is documented under policies that align with both ISO 27001 and SOC 2 Type II standards. Learn more: Xoxoday Plum Help Centre — Data, Policy & Privacy

GDPR Compliance

Learn how Xoxoday Plum processes personal data in compliance with the General Data Protection Regulation for organisations operating in or serving the European Union.

Data Retention Policy

Understand how Xoxoday Plum defines retention periods for personal data and how your organisation can manage deletion timelines across reward programs.