# Payments and Wallet
Source: https://help-plum.xoxoday.com/account-administration/reporting/payments
See how to view and track payment records for your Plum account, including wallet top-ups and reward-related transactions.
*Plum's reports offer detailed insights into Reward transactions, enabling admins to manage organizational activities effectively.*
Plum keeps track of all the transactions of Reward Points, Reward Codes, Reward Links, Perks History, and Plum GiftCard API. Reports allow you to check the status of your transactions along with details like invoice date, amount, invoice note, balance, and comments. You can also view the redemption history of the recipients.
Plum diligently keeps track of all transactions involving Reward Points, Reward Codes, Reward Links, Perks History, and interactions via the Plum GiftCard API. Through detailed reports, users gain insight into the status of their transactions, including crucial details such as invoice dates, transaction amounts, invoice notes, current balance, and any accompanying comments. Additionally, users have the ability to delve into the redemption history of recipients, providing a comprehensive understanding of reward utilization.
***
## Accessing Reports as an Admin
To access the plethora of reports available as a Super Admin, users simply need to navigate to the designated "Reports" section within the admin dashboard's navigation menu. Super Admins are granted access to a wide array of reports encompassing various transactional activities within the organization.
**Note:** Admins view only their sent rewards, while Super Admins access all reports.
It's important to note that while regular Admins are limited to viewing reports related to rewards they've issued, Super Admins have the privilege of accessing all types of reports, providing a more holistic view of organizational activities.
Navigate to the "Reports" section in the admin dashboard's navigation menu as a Super Admin.
* Access various reports covering organizational transactions.
* Review scheduled future rewards and cancel them if needed.
* Download reports via the "Download" button in the top right corner.
In addition to viewing transactional reports, users can also manage scheduled future rewards, with the ability to cancel them if necessary, offering flexibility and control over reward disbursements.
Furthermore, users can easily download reports by simply clicking on the "Download" button located in the top right corner of the page, facilitating seamless access to comprehensive transactional data.
***
## Exploring Payment Details
### Checking Payments
* Click on 'Wallet icon on the nav menu
* Click on 'Transaction history'
* Customize payment reports using filters.
* Explore payment details including invoice, amount, recharge, date, and status.
* Export Excel reports to your email.
Upon accessing the "Reports" section, users will encounter a screen similar to the one depicted in the provided image. To delve into payment details, users can simply click on the "View Report" option under the "Wallet History" section, initiating a deeper exploration into payment-related activities.
**Pro tip:** Once within the payment report interface, users have the flexibility to customize their view by utilizing various filters to cater to specific requirements. This customization empowers users to extract pertinent information efficiently.
Within the payment section, users can review detailed payment information, including invoice details, transaction amounts, the entity responsible for the recharge, transaction dates, and current payment statuses. This comprehensive overview enables users to gain valuable insights into financial activities within the organization.
Furthermore, users can seamlessly export payment details in Excel format to their designated email addresses, facilitating easy access and further analysis of transactional data.
By leveraging these robust reporting capabilities, users can effectively monitor and manage transactional activities within the Xoxoday Plum application, ensuring transparency, accountability, and informed decision-making.
# Plum Gift Cards API Report
Source: https://help-plum.xoxoday.com/account-administration/reporting/plum-gift-cards-api-report
Learn how to access and read the Plum gift cards API report, used to track gift card transactions sent through the API.
*Access detailed Gift Card reports for insights on product usage and recipient details.*
***
## Accessing Gift Card Reports
Follow these steps to view detailed reports for Gift Card Reports:
Go to dashboard and click "**Reports**".
Within the "**Reports**" section, click on "**Gift Card**". You can select the sent date by clicking in the box "**Sent Date UTC**".
Here you'll find detailed reports containing the following information fields:
* Order ID
* Product Name
* Product ID
* Recipient Email
* Currency
* Denominations
* Date with Timestamp
* Amount Charged
* Status
* Actions
By following these steps, you can easily access and review reports specific to gift cards, providing valuable insights into product usage and recipient details.
***
## Filter the Report
Click on the filter icon to filter the report by:
* Order ID
* Recipient Email
* Sent Date
* Delivered Date
* Status
* PO Number
* Tag
***
## Manage Columns
Click on ||| Columns Icon to manage the columns you wish to show in the report. Simply check or uncheck the boxes based on your requirement.
The reports can be downloaded using the "Download" button on the top right.
Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Reports
Source: https://help-plum.xoxoday.com/account-administration/reporting/reporting-faqs
Find answers to frequently asked questions about generating, reading, and troubleshooting reward reports in Plum.
***
## Can your reporting tools provide both a unified and department/program-specific breakdown so we can track performance and metrics across teams?
Absolutely. The Xoxoday reward marketplace platform includes advanced reporting tools that offer both holistic and granular insights. Admins can view cross-team performance data or generate custom reports for specific departments or programs, helping stakeholders monitor redemption trends, participant engagement, and ROI.
***
### Is monthly reporting on points requests, including accepted and rejected transactions, supported?
Yes, the Xoxoday survey rewards platform offers detailed monthly reports covering all redemption activities, including accepted and rejected requests. Admins can access, export, and schedule these reports to maintain full transparency and auditability across all rewards-related transactions.
*FAQ on Notification and Cancellation*
***
## How do I receive notifications if scheduled rewards are not sent?
In the event that scheduled rewards are canceled due to low balance or exceeding threshold limits, both admins and Super Admins will receive notifications. These notifications will provide detailed information about the canceled rewards, allowing swift corrective action to maintain a seamless rewarding experience for all users.
***
## Can I cancel rewards in bulk?
Yes, users now have the ability to cancel rewards in bulk. Simply select all the users for whom you wish to cancel rewards and click on the "Cancel reward" button, as illustrated below:
# Overview
Source: https://help-plum.xoxoday.com/account-administration/reporting/reporting-overview
Get an overview of Plum's reporting tools, covering how to track reward distribution, spend, and redemption activity across your account.
*Explore insights into various reports within Plum*
This article provides an overview of the reports available within Plum, a platform for managing rewards, incentives, and payments efficiently. Below are the different report types offered:
* **Rewards API Report** — This report provides detailed insights regarding the usage of the Rewards API within Plum. Users can track API usage, performance metrics, and any issues encountered during API transactions.
* **Reward Code Report** — The Reward Code report offers a comprehensive overview of all reward codes generated and redeemed within the platform. Users can monitor the distribution of reward codes, redemption rates, and any associated trends or patterns.
* **Reward Link Report** — Users can leverage the Reward Link report to analyze the effectiveness of reward links distributed through Plum. This report provides insights on link clicks, conversions, and overall engagement with the reward links.
* **Integration Report** — The Integration report provides insights into Xoxoday Plum's integration with external systems. Users can monitor integration status, track data synchronization, and troubleshoot any related issues.
* **Payment and Wallet Report** — This report focuses on providing users with a detailed overview of payment transactions and wallet activities within Plum. Users can track payments, withdrawals, account balances, and any financial transactions processed through the platform.
Through these reports, users can effectively monitor, analyze, and optimize their reward, incentive, and payment strategies within Plum. Whether it's tracking API performance, analyzing reward distribution, or monitoring financial transactions, these reports offer valuable insights to drive informed decision-making and enhance overall platform performance.
Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Reward Code Report
Source: https://help-plum.xoxoday.com/account-administration/reporting/reward-code-report
See how to generate and interpret the reward code report in Plum, covering distribution status and redemption activity.
*Discover how to access detailed transaction reports for Reward Code*
To view transaction reports for Reward Code, navigate to the Reports and then to the "Reward Code" tab. The reports provide detailed information such as recipient name, recipient email, date of delivery, campaign details, status, and more.
***
## How to Access Reward Code Reports
To view the report for Reward Code, simply navigate to the "**Reward Code**" section.
In this section, you'll find comprehensive transaction details, including "**Unique ID**", "**Payment Reference ID**", "**Recipient Name**", and "**Recipient Email**", along with other relevant information.
To download the report, click on "**Download**" at the top right corner of the page.
Select your desired time frame for viewing reports by clicking Send Date UTC.
***
## Tracking Email and SMS Activity in Rewards Code Report
You can easily track Email and SMS activity in the Rewards Code report, enabling you to monitor and analyze the communication activities related to rewards distribution.
Navigate to **Admin Dashboard > Reports > Reward Code.** Click the **'three dots icon'** to move ahead.
Click **'View Details'** and, using the dropdown menu, view **'Activity Timeline'.**
***
## Filter the Report
Click on the filter icon to filter the report by the options given.
***
## Manage Columns
Click on ||| Columns Icon to manage the columns you wish to show in the report. Simply check or uncheck the boxes based on your requirement.
Feedback or Questions - Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Reward Link Report
Source: https://help-plum.xoxoday.com/account-administration/reporting/reward-link-report
See how to generate and interpret the reward link report in Plum, covering distribution status and redemption activity.
*Discover how to access and navigate detailed Reward Link reports with filtering options.*
To view transaction reports for Reward Links, navigate to **Reports > Reward Link.**
The reports provide detailed information such as recipient name, recipient email, date of delivery, campaign details, status, and more.
***
## How to Access Reward Links Reports
* Click on **Reports >> Reward Link**
* Explore detailed reports for Reward Links, including **recipient name, recipient email, date of delivery, campaign details, status**, and more.
* Utilize the filter options provided to obtain specific reports based on criteria such as **recipient name, recipient email, batch ID, phone number, generation date range,** and more.
* Download the report using the top **download button.**
* Select your desired time frame by clicking on **Sent Date (UTC)** and choosing the range.
***
## Filter the Report
Click on the filter icon to filter the report by:
* Unique ID
* Payment Reference ID
* Recipient Name
* Recipient Phone
* Sent Date (UTC)
* Redemption Date (UTC)
* Status
* Campaign
* Batch ID
***
## Manage Columns
Click on ||| Columns Icon to manage the columns you wish to show in the report. Simply check or uncheck the boxes based on your requirement.
Feedback or Questions - Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Reward Points Reports
Source: https://help-plum.xoxoday.com/account-administration/reporting/reward-points-reports
Learn how to generate and interpret reward points reports in Plum, covering points issued, redeemed, and outstanding balances.
*Easily view and download Reward Points transaction reports.*
To view transaction reports for Reward Point, navigate to **Reports > Wallet History > Reward Point** tab. The reports provide detailed information such as recipient name, recipient email, date of delivery, campaign details, status, and more.
***
## How to Access Reward Points Reports
* Navigate to **Reports.**
* Click on **Reward Points.**
* Utilize the filter options to obtain specific reports based on criteria such as recipient name, recipient email, batch ID, phone number, generation date range, and more.
* Download the report using the top **download button.**
* You can also select your desired time frame by clicking on Sent Date (UTC) and choosing the range.
Select your desired time frame by clicking on **Sent Date (UTC)** and choosing the range.
***
## Tracking Email and SMS Activity in Rewards Reports
You can easily track Email and SMS activity in the Rewards Points report, enabling you to monitor and analyze the communication activities related to rewards distribution.
Navigate to **Admin Dashboard > Reports > Wallet History > Reward Points.** Click the **'three dots icon'** to move ahead.
Click **'Take Action'** and the using dropdown view **'Activity Timeline'.**
***
## Filter the Report
Click on the filter icon to filter the report.
***
## Manage Columns
Click on ||| Columns Icon to manage the columns you wish to show in the report. Simply check or uncheck the boxes based on your requirement.
Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Manage Admins
Source: https://help-plum.xoxoday.com/account-administration/user-management/add-admin-user
Learn how to add a new admin user to your Plum account, including how to set their access level and permissions during setup.
The **All Admins** page enables Super Admins to manage users who have access to the Plum Admin Dashboard. Super Admins can add Admins, assign or modify roles, configure rewarding thresholds, or delete Admin.
To access the **All Admins** page, navigate to **Settings > Admin > All Admins**.
## Add an Admin
To add a new Admin:
1. On the **All Admins** page, click **Add New**.
2. In the **Add Admin** form, enter the user's **Name** and **Email Address**.
3. Select the appropriate role:
* **Admin:** Provides access to the Plum Admin Dashboard with the permissions assigned to the Admin role, including the configured rewarding threshold.
* **Super Admin:** Provides full access to the account and Super Admin features.
4. Click **Save**.
The new user can sign in to the Plum Admin Dashboard with the permissions assigned to their role.
## Edit Admin
Super Admins can change an Admin's role at any time.
To change an Admin's role:
1. Locate the user in the **All Admins** list.
2. Click the **three-dot menu** under the **Actions** column.
3. Select **Edit Admin**.
4. Change the **Role** to **Admin** or **Super Admin**.
5. Click **Save**.
The user's permissions are updated automatically based on the newly assigned role.
* Changing an **Admin** to a **Super Admin** grants access to Super Admin features.
* Changing a **Super Admin** to an **Admin** removes access to Super Admin-only features.
The updated settings take effect immediately.
## Change to Report View
Super Admins can change an Admin's access to **Report View**, where applicable. Report View provides access to relevant reporting information without providing the administrative permissions available to an Admin or Super Admin.
To change an Admin to Report View:
1. Locate the Admin in the **All Admins** list.
2. Click the **three-dot menu** under the **Actions** column.
3. Select **Edit Admin**.
4. Change the access or role to **Report View**.
5. Click **Save**.
The user's access is updated based on the permissions associated with **Report View**. Administrative actions that are not included in Report View are no longer available to the user.
## Delete an Admin
Super Admins can delete an Admin to revoke their access to the Plum Admin Dashboard.
To delete an Admin:
1. Locate the Admin in the **All Admins** list.
2. Click the **three-dot menu** under the **Actions** column.
3. Select **Delete Admin**.
4. Confirm the action.
Once deleted, the user can no longer sign in to the Plum Admin Dashboard. Historical activity associated with the user is retained for audit purposes.
# Manage Thresholds
Source: https://help-plum.xoxoday.com/account-administration/user-management/managing-threshold
See how to configure approval thresholds for admin users in Plum, controlling how much they can send without additional sign-off.
## Edit Rewarding Threshold
Super Admins can configure or modify the **rewarding threshold** for an Admin. The rewarding threshold defines the maximum amount that the Admin is permitted to reward, based on the limits configured for the account.
To edit the rewarding threshold:
1. Locate the Admin in the **All Admins** list.
2. Click the **three-dot menu** under the **Actions** column.
3. Select **Edit Admin**.
4. Update the **Rewarding Threshold** as required.
5. Click **Save**.
The updated rewarding threshold takes effect immediately and applies to subsequent rewards initiated by the Admin.
## Reset Amount Spent
Super Admins can reset the **Amount Spent** for an Admin from the **All Admins** page. This resets the amount accumulated against the Admin's rewarding threshold without changing the threshold itself.
To reset the amount spent:
1. Navigate to **Settings > Admin > All Admins**.
2. Locate the required Admin.
3. Click the **three-dot menu** under the **Actions** column.
4. Select **Edit**.
5. Click on Reset and Update
Once the action is confirmed:
* The **Amount Spent** is reset to **0**.
* The **Rewarding Threshold** remains unchanged.
* The Admin's available balance is restored based on the existing threshold.
* Previous reward transactions remain unchanged.
**Example:** If an Admin has a rewarding threshold of **USD 1,000** and has spent **USD 800**, resetting the amount spent changes the amount spent to **USD 0** and restores the available balance to **USD 1,000**.
**Note:** Resetting the amount spent only resets the spending counter. It does not change the Admin's rewarding threshold or delete historical reward transactions.
# Switching Account
Source: https://help-plum.xoxoday.com/account-administration/user-management/switching-account
See how to switch between multiple Plum accounts as an admin, useful if you manage rewards across more than one organization.
The **Switch Account** feature allows you to switch between multiple Xoxoday Plum accounts associated with your login credentials.
To switch between accounts:
You are redirected to the selected account and can access it based on the permissions assigned to your user profile.
If the required account is not available in the list, ensure that your user profile has been added to that account.
Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Manage Profile and Password
Source: https://help-plum.xoxoday.com/account-administration/user-management/updating-profile-password
The **Profile** section allows administrators to manage their account information and update their password from the Plum Admin Dashboard.
You can only change/update Name and Password. Please reach out to [cs@xoxoday.com](mailto:cs@xoxoday.com).
## Update Profile Information
To update your profile information:
1. Sign in to the **Plum Admin Dashboard**.
2. Click the **Profile** icon in the top-right corner.
3. Select the option to edit your profile.
4. Update the required information, such as your **Name** or **Password**.
5. Save the changes.
The updated information is applied to your Plum account.
Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Overview
Source: https://help-plum.xoxoday.com/account-administration/user-management/user-management
Get an overview of user management in Plum, covering how to add, remove, and control access for admin users on your account.
Plum supports two administrative roles: **Super Admin** and **Admin**. These roles determine the level of access a user has within the Plum Admin Dashboard.
By default, the user who creates a Plum account is assigned the Super Admin role.
## Super Admin
A Super Admin has full access to the Plum Admin Dashboard and can manage users, company settings, campaigns, reports, and wallet operations.
## Admin
An Admin has access to operational features required to send rewards and manage day-to-day activities. Access to administrative settings and account-level configurations is restricted.
## Permissions Comparison
| Feature | Super Admin | Admin |
| :--------------------------------------------------------- | :---------------------------------- | :---------------------------------------------------------------- |
| Recharge Company Wallet | ✓ | ✗ |
| Reward Spending Limit | Unlimited | Restricted by the assigned spending threshold |
| View Reports | Access to all reports | Access to self-reports only; company-level reports are restricted |
| Maker–Checker Capabilities | Can be assigned as Maker or Checker | Can be assigned as Maker or Checker |
| Add, Edit, or Deactivate Admins | ✓ | ✗ |
| Set Admin Spending Thresholds | ✓ | ✗ |
| View All Admins and Spending Thresholds | ✓ | ✗ |
| Self-Approval | Not allowed | Not allowed |
| Send Rewards (Xoxo Points, Reward Codes, and Reward Links) | ✓ | ✓ |
| Campaigns | Create, modify, and use campaigns | Use existing campaigns only; cannot create new campaigns |
| Access to Plum Pro | Full access | Can distribute brand vouchers |
| Edit Company Details | ✓ | ✗ |
If Maker–Checker workflows are enabled for your organization, users can be assigned as either a Maker or a Checker. However, users cannot approve their own requests, even if they are assigned both roles.
Feedback or Questions: Reach out to [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Admin Settings
Source: https://help-plum.xoxoday.com/account-settings/admin/admin-settings
The **Admin Settings** page allows Super Admins to control the features and capabilities available to other Admins across the organisation. These settings help manage information visibility, reporting access, and approval workflows.
To access **Admin Settings**, navigate to **Settings > Admin > Admin Settings**.
All settings on this page are **toggle-based**. Super Admins can enable or disable each setting based on the organisation's requirements.
## Show Wallet Balance to Admins
Allows Admins to view the organisation's available wallet balance during the reward flow.
When enabled, Admins can view the available wallet balance while sending rewards. This helps Admins track the available balance and avoid initiating rewards when sufficient funds are not available.
## Show Redemption Data to Admins
Allows Admins to view redemption data while creating or managing campaigns.
When enabled, Admins can access redemption information to understand how rewards are being used and make informed decisions when managing campaigns.
## Enable Custom Reports
Allows Super Admins to create and share custom reports with designated **Report Viewers**.
When enabled, Super Admins can grant or revoke access to custom reports. Users with access can view the reports and dashboards shared with them.
## Enable Workflow Requests
Enables an approval workflow for supported Admin actions.
When enabled, selected actions performed by Admins are submitted as requests and require approval from a designated approver before they take effect. This provides additional control over administrative changes and helps organisations maintain appropriate governance over platform activities.
# Report Settings
Source: https://help-plum.xoxoday.com/account-settings/admin/report-setting
The **Report Settings** page allows Super Admins to create and manage **Custom Reports** for their organization. Super Admins can configure the data included in each report and control which users have access to view the reports.
To access **Report Settings**, navigate to **Settings > Admin > Report Settings**.
## Create a Custom Report
Super Admins can create custom reports based on the organisation's reporting requirements.
When creating a custom report, you can:
* Enter a **Report Name**.
* Select the **Columns** to include in the report.
* Assign the report to one or more users.
Each report can be configured independently based on the requirements of different teams or users.
## Share a Custom Report
Super Admins can provide selected users with access to a custom report.
Once a report is assigned to a user, the user can access it from the **Reports** section of the Plum Admin Dashboard. A user can be assigned to multiple custom reports based on their responsibilities.
## Edit a Report Configuration
Super Admins can update an existing custom report at any time.
You can:
* Change the **Report Name**.
* Add or remove **Report Columns**.
* Add or remove users who have access to the report.
Any changes to the report configuration are reflected the next time the user accesses the report.
## Revoke Report Access
Super Admins can remove a user's access to a custom report at any time.
If a user is no longer assigned to any custom reports, their **Report Viewer** access is automatically removed.
## Example
Custom reports can be configured for different teams based on the information they require.
For example:
* A **Finance Report** can include fields such as order value, cost, and markup.
* A **Customer Support Report** can include fields such as customer name, product, and delivery status.
This allows each user to access only the reports and information relevant to their responsibilities.
# Configure IP Whitelisting
Source: https://help-plum.xoxoday.com/account-settings/api/ip-whitelisting
IP Whitelisting is a security feature that restricts access to the Rewards API to approved IP addresses. Once enabled, only API requests originating from whitelisted IP addresses are accepted. Requests from any other IP address are rejected.
This feature helps organizations secure their API integrations and ensure that only trusted servers can communicate with the Rewards API.
## Benefits of IP Whitelisting
IP Whitelisting can help organizations:
* Secure access to the Rewards API.
* Restrict API requests to trusted servers or networks.
* Prevent unauthorized access to API credentials.
* Meet internal security and compliance requirements.
## How It Works
After one or more IP addresses are whitelisted:
* API requests from approved IP addresses are processed normally.
* API requests from any other IP address are rejected.
* Changes to the IP allowlist take effect immediately.
If a request is made from an IP address that is not on the allowlist, the API returns an error indicating that the request originated from a non-whitelisted IP address.
Example: If your organization whitelists the public IP addresses of its office network or application servers, only requests originating from those IP addresses can access the Rewards API. Requests from any other location are blocked.
## Add a Whitelisted IP Address
To add an IP address to the allowlist:
The IP address is added to the allowlist and can immediately be used to access the Rewards API.
## Manage Whitelisted IP Addresses
Organizations can whitelist multiple IP addresses to support different servers or environments.
To remove an IP address:
Once removed, requests originating from that IP address are no longer authorized to access the Rewards API.
# Overview
Source: https://help-plum.xoxoday.com/account-settings/email-domain-auth/email-domain-authentication-overview
Get an overview of email domain authentication in Plum and how it improves the deliverability of your reward emails.
*Using your brands custom domain in Xoxoday*
Domain authentication serves as a proactive step to boost the delivery, security, and trustworthiness of your reward emails. This, in turn, aids in the effectiveness of your email marketing endeavors and cultivates favorable connections with recipients.
### Why you should consider Authenticating your Domain:
Check out below
***
## Improved Email Deliverability
Authenticating your domain increases the likelihood that your reward emails will be delivered successfully to recipients' inboxes. Email service providers often prioritize authenticated domains, reducing the chances of emails being marked as spam or bouncing.
## Enhanced Security
Domain authentication helps prevent unauthorized use of your domain for sending emails. By confirming ownership of your domain, you reduce the risk of phishing attacks and other fraudulent activities that could damage your organization's reputation.
## Credibility and Trust
Authenticated domains convey credibility and trustworthiness to recipients. When recipients see emails coming from an authenticated domain, they are more likely to trust the content and take desired actions, such as opening the email and engaging with its contents.
## Brand Recognition
By authenticating your domain, you reinforce your brand identity in recipients' minds. Consistently sending emails from a verified domain helps recipients recognize and remember your brand, leading to increased brand loyalty and engagement.
## Compliance with Email Standards
Domain authentication aligns with industry standards and best practices for email communication. It demonstrates your commitment to adhering to email authentication protocols, such as SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance).
## Reduced Risk of Spam Filtering
Authenticated domains are less likely to trigger spam filters, ensuring that your reward emails reach recipients' primary inboxes instead of being diverted to spam or junk folders. This maximizes the visibility and effectiveness of your email campaigns.
Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Email Whitelisting
Source: https://help-plum.xoxoday.com/account-settings/email-domain-auth/email-whitelisting
Learn how to whitelist Plum's sending domain with your email provider so reward emails don't get filtered as spam.
*Learn how to whitelist your email.*
For emails to not land in spam and properly open images in email services like Microsoft Outlook and Gmail, follow the steps below.
***
## Microsoft Outlook Email Whitelisting Process
### Option 1: For Individual Email Addresses to be whitelisted from inside email message
In an open message that was sent from a particular email address or domain, right-click on a blocked item.
Do one of the following:
* Click Add Sender to Safe Senders List.
* Click Add the Domain \[@domain] to Safe Senders List.
***
### Option 2: For Email Address to be whitelisted from settings
Untick the option which says "Don't download pictures automatically in HTML email messages or RSS items."
***
### Option 3: For Email Address to be whitelisted from Microsoft Admin
Step by Step Instructions (Admin Side)
* Login to [https://portal.microsoftonlie.com](https://portal.microsoftonlie.com/)
* Go to **Admin > Exchange > Mail Flow**
Mail Flow enables you to set rules on the server before the email is delivered to Outlook.
* This is similar to setting rules using Outlook's built in rules.
* New rule details in Office 365. Click to view larger.
* Click the + and select Bypass Spam Filtering
* Apply this rule if… > The sender… > domain is
Enter the domain name (example: rolet.com)
* Under specify domain, be sure to click the + to add the domain to the list.
You can come back to this rule and add domain names for each domain you want to whitelist. There is no need to create additional global rules in Mail Flow for each domain.
* Click ok
* Check Stop processing more rules
* Click save
***
## Google Email Whitelisting Process
* In the Admin console Go to **Apps > G Suite Gmail > Advanced settings.**
* Scroll to the Spam section, hover over the setting, and click **"Configure".**
* Enter a unique name for the setting.
* Check the Bypass spam filters for messages received from addresses or domains within this approved senders lists box.
* Click **"Use existing or Create a new one"**, enter a new list name, and click **"Create".**
* Hover over the list name, click **"Edit"**, and then click **"Add".**
* Enter domain name 'abc.com'
* **Save**
***
## DMARC Quarantine Issue
Error Message:
DMARC Message from domain xoxoday.com, DMARC fail, (SPF aligned False, DKIM aligned False) DMARC policy is quarantine, applied policy is quarantine.
For the above Error, please do the whitelisting process for your respective email services.
Feedback or Questions: Reach out to us [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Authenticate Domain
Source: https://help-plum.xoxoday.com/account-settings/email-domain-auth/step-by-step-guide-to-authenticate-your-domain
Follow this step-by-step guide to authenticate your email domain so reward communications from Plum reach recipients reliably.
The **Domain Authentication** feature allows organisations to use their own custom domain to send reward communications from Plum.
Authenticating your domain verifies that the organisation owns the domain and helps ensure that emails sent from the domain are recognised as legitimate. This can improve the credibility and deliverability of reward communication and prevent the sender address from displaying **“via [notifications@xoxoday.com](mailto:notifications@xoxoday.com)”** to recipients.
Check out this for entire list of benefits and why you should consider authenticating your domain [Email Domain Authentication](/account-settings/email-domain-auth/email-domain-authentication-overview)
***
## Prerequisites
Before authenticating your domain, ensure that:
* **KYB (Know Your Business)** verification has been approved.
* You have **Super Admin** access to the Plum Admin Dashboard.
* You have access to your organisation's **DNS Manager** or hosting provider.
* If you do not have DNS access, coordinate with your organisation's IT or DNS administrator to add the required records.
**Tip:** If you do not have access to the DNS Manager, you can use the email option in Plum to send the required DNS records to your IT or DNS administrator.
***
## Step by step guide to Authenticate Your Domain
Ensure you are logged in as Super Admin with approved KYB. If not done already, head over to: Submitting Verification Details
Navigate to **Settings > Notifications.** Click on **'Authenticate your Domain'.**
Now click on **'Save and Proceed'.**
The following DNS records need to be added in your DNS Settings. Access your DNS provider portal and input these records. Note that all records are CNAME.
**Send DNS Records to IT Admin**
If you lack access to the DNS Manager Portal, forward these DNS records to your IT Admin or DNS Manager. The records will be sent via email along with a CSV file.
**Pro tip:** Coordinate with your company's IT Admin responsible for DNS management. You can use the inbuilt emailing tool to send the DNS records to your IT Admin colleague.
We will send DNS records in email along with CSV to your IT Admin.
After the IT Admin has added the records:
* Check the box 'Please verify that your records have been added'.
* Once selected, the Verify button will activate. Click on **'Verify'.**
If your DNS records are added correctly and given sufficient time to take DNS changes to take place, on verification your domain is now authenticated.
Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Troubleshoot
Source: https://help-plum.xoxoday.com/account-settings/email-domain-auth/troubleshoot-domain-authentication
Troubleshoot the most common issues that come up while setting up email domain authentication for your Plum account.
After you've connected your domain or **email-sending domain, it can take up to 24 hours for the DNS changes to propagate and reflect in Xoxoday. If your domain** isn't connecting as expected after 24 hours, follow the steps below to troubleshoot your domain.
***
## Check the status of your Domain Authentication
Verify that the DNS records have been updated in Xoxoday and in your domain host.
* In your Xoxoday Plum account, go to **Settings > Notifications.**
* In the left sidebar menu, navigate to **Website > Domains & URLs.**
If your domain has **pending**, then acknowledge that Records are added and click Verify to authenticate domain.
* If your domain connection failed, you need to **Verify** again.
* If Xoxoday cannot connect your domain. There are three error types:
**Typo:** the record added to your domain host is different from what's in Xoxoday.
**Missing record:** Xoxoday is unable to identify the record in your domain host.
**Conflicting record:** there is a conflicting DNS record in your domain host.
To resolve these errors, ensure that the records in your domain host match what's in Xoxoday.
You should also check the status of your DNS records in your domain host.
* Log in to your DNS host.
* Confirm that the CNAME records match the Host(name) and Values provided by Xoxoday during the connection process.
* If you've confirmed that your DNS records have been updated correctly, you can click either Refresh or **check them again** in the domain setup within Xoxoday to confirm your records have been updated and your domain can be connected. **If this does not work, you can try copying and pasting the provided values again, or review the following common DNS record issues.**
***
## Common DNS issues
If you are unable to connect your domains, here are some common DNS issues that you can check for in your DNS host.
### Duplicated Domain
Some domain hosts will add a root domain to your CNAME records by default. For example, when entering xox\*\*.\_domainkey.example.com\*\*, an additional domain will be added. The records would then propagate as xox\*.\_domainkey.example.com.example.com\*.
You can use external tools to check for a duplicated root domain. For example, you can use [Dig](https://toolbox.googleapps.com/apps/dig/) to check your email sending domains or [Whatsmydns](https://www.whatsmydns.net/) for your site domains.
If your domain name was duplicated in your CNAME record:
* Keep the domain manager tool open in your browser.
* In a new tab or window, log in to your DNS provider and navigate to your DNS Zone File (sometimes appears as Domain Files, Manage DNS).
* Enter your **host(name) values** without the domain. This will look different for domains and email-sending domains. For example:
Domain: you can enter info. rather than [info.example.com](http://info.example.com/).
Email sending domain: you can enter xox.\_domainkey rather than xox\*\*.\_domainkey.example.com\*\*.
### Records invalidated by domain host
If your domain name was not duplicated in your CNAME record, but you're seeing a record invalid error in your domain manager, the updated records may have been invalidated by your domain host.
Your DNS provider may have invalidated your CNAME record because of certain characters, such as an underscore ("\_") or a hyphen ("--"). You should contact your provider's support team for further assistance.
The CNAME records that appears in your Xoxoday email sending domain setup strictly adheres to the DKIM protocol and are supported by most major DNS providers.
***
## Use Whatsmydns to troubleshoot site domains
Whatsmydns is a tool used to check DNS records and DNS propagation for your site domains.
You can use Whatsmydns to confirm that your DNS records have been correctly updated and are propagating successfully.
Navigate to [Whatsmydns.net](https://www.whatsmydns.net/)
In the top left, enter the **domain** you're trying to connect to in Xoxoday.
Click the dropdown menu and select **CNAME.**
Click **Search.**
If your DNS update was successful, the results should correspond to the values provided in Xoxoday.
If the Whatsmydns results do not match the value provided in Xoxoda, this means that the DNS record may have been incorrectly updated or is not propagating correctly. You can try updating your DNS record again, or reach out to your domain provider to troubleshoot further.
If you're still seeing problems after completing the troubleshooting steps above, you can reach out to [cs@giift.com](mailto:cs@giift.com)
# Email Settings
Source: https://help-plum.xoxoday.com/account-settings/notification/email-setting
The **Email Settings** page allows Admins to customise the emails sent to reward recipients. Admins can configure the email footer, sender details, and PDF gift certificate settings.
To access **Email Settings**, navigate to **Settings > Notifications**.
## Customize the Email Footer
The **Custom Footer** setting allows Admins to add custom text to the footer of reward emails.
You can use the footer to include:
* Company contact information
* Support details
* Legal disclaimers
* Other relevant information that should appear in reward emails
The configured footer is included in reward emails sent to recipients.
## Configure the Sender Name
The **Sender Name** determines the name displayed in the **From** field of reward emails.
By default, **Xoxoday** is displayed as the sender. Admins can replace this with a custom sender name, such as **Acme Rewards** or **HR Team**, to provide a branded email experience.
## Configure the Sender Email Address
The **Sender Email** determines the email address displayed in the **From** field of reward emails.
By default, reward emails are sent from [**notifications@xoxoday.com**](mailto:notifications@xoxoday.com). Organiszations can configure a custom sender email address, such as [**rewards@company.com**](mailto:rewards@company.com), to align reward communications with their corporate domain.
A custom sender email address requires **domain authentication** using SPF, DKIM, and DMARC DNS records. Without domain authentication, emails may be delivered to spam folders or rejected by recipient mail servers.
## Enable PDF Generation
The **Enable PDF Generation** setting allows reward emails to include a **PDF gift certificate** as an attachment.
The PDF contains the relevant reward or gift card details and can be downloaded or printed by the recipient.
This setting is available for:
* **Reward Codes (Xoxo Codes)**
* **Gift Cards (Plum Pro)**
# Reminders
Source: https://help-plum.xoxoday.com/account-settings/notification/low-balance-alerts
# **Low Balance Alert**
The **Low Balance Alert** feature helps organizations monitor their Plum wallet balance and avoid interruptions to their reward programs. Super Admins can configure a minimum wallet balance and receive email notifications when the wallet balance falls below the specified threshold.
These alerts allow administrators to add funds to the wallet in advance and help prevent failed rewards, bookings, or order cancellations due to insufficient balance.
## Set Up Low Balance Alerts
To enable Low Balance Alerts:
1. Navigate to **Settings > Notifications**.
2. Locate the **Low Balance Notification** section.
3. Turn on the notification toggle.
4. Enter the **wallet balance threshold** at which the notification should be triggered.
5. Click **Save Changes**.
## How Low Balance Alerts Work
When the wallet balance falls below the configured threshold, Plum sends an email notification to the **Super Admin**.
The notification includes:
* The current wallet balance.
* An **Add Funds to Wallet** button that redirects to the wallet recharge page.
If the wallet balance remains below the configured threshold, the platform sends up to **two reminder emails**.
Once the wallet is recharged, the reminder counter is automatically reset. Future notifications will be triggered again when the wallet balance falls below the configured threshold.
# Emails for Redemption
The **Reminder Emails for Redemption** feature allows organizations to automatically notify recipients about rewards that have not yet been redeemed. These reminders help recipients redeem their rewards before they expire.
## Reminder Types
You can configure the following types of redemption reminders:
### Scheduled Reminders
Scheduled reminders are sent at regular intervals until the reward is redeemed or expires. This option is useful for rewards with longer validity periods.
The available frequencies are:
* **Monthly**
* **Quaterly**
### Pre-Expiry Reminders
Pre-expiry reminders are sent once before the reward expires. These reminders encourage recipients to redeem their rewards before the expiry date.
The available reminder intervals are:
* **30 days before expiry**
* **15 days before expiry**
* **7 days before expiry**
## Configure Reminder Emails
To configure Reminder Emails for Redemption:
1. Navigate to **Settings > Notifications**.
2. Locate the **Reminder Emails** section.
3. Select the required reminder type and frequency.
4. Click **Save Changes**.
Once configured, the platform automatically sends reminder emails according to the selected schedule. Scheduled reminders continue until the reward is redeemed or expires, while pre-expiry reminders are sent once before the reward expires.
# Branding
Source: https://help-plum.xoxoday.com/account-settings/storefront/branding
The **Storefront** page allows Admins to customise the Plum storefront and manage the rewards available to users. You can configure the storefront URL, company logo, favicon, theme colour, and global reward catalog.
To access these settings, navigate to **Settings > Storefront**.
## Redemption Marketplace URL
The Storefront URL (also referred to as the Marketplace URL or Domain) is the unique web address for your Plum storefront, for example:
`https://stores.xoxoday.com/{company-name}`
The storefront URL is generated automatically during account setup based on your company name and can be configured only once.
Once your account is created, the storefront URL cannot be changed from the Plum Admin Dashboard. If you need to update your storefront URL, please contact the Xoxoday Plum Support team.
***
## Company Logo
You can also upload a custom logo. Navigate to **Settings > Storefront > Company Logo** and click on **"Change".**
* Choose a transparent logo file (maximum size: 240 x 80 px).
* Upload it to the platform and click **"Save".**
Your brand logo will prominently appear in the upper left corner of your website and in all email communications. Switch to the storefront to preview its placement and appearance.
***
## Update the Favicon
The favicon is the small icon displayed in the browser tab when users open your storefront.
Navigate to **Settings > Storefront > Branding** and click **Change** under Favicon.
Choose the favicon image and upload it to the platform. Click **Save**.
The uploaded favicon replaces the default Xoxoday icon and is displayed in the browser tab whenever users visit your storefront.
***
## Storefront Theme
The theme color controls the primary color used across your storefront.
Navigate to **Settings > Storefront > Branding** and select or enter your preferred theme color (Hex code). Click **Save**.
The selected color is applied across the storefront, including buttons, the navigation bar, category highlights, and call-to-action (CTA) links, giving your storefront a consistent branded appearance.
***
## Hero Banner
The **Hero Banners** feature allows you to add promotional banners to the homepage of your Plum storefront. You can use banners to highlight campaigns, offers, announcements, or other relevant information.
Banners are displayed vertically on the storefront homepage in the order configured by the Admin.
## Add a Hero Banner
To add a banner:
1. Navigate to **Settings > Storefront**.
2. Locate the **Hero Banner** section.
3. Click **Add Banner**.
4. Upload the **Banner Image**.
* The image must be in **PNG or JPG** format.
* The maximum file size is **2 MB**.
5. Enter a **Banner Name**.
6. Enter the **Redirect URL**. This is the URL that opens when a user clicks the banner.
7. Click **Save Banner**.
## Manage Promotional Banners
You can manage the banners displayed on your storefront homepage.
* Banners are displayed **vertically** on the homepage.
* Banners do not rotate automatically.
* Banners cannot be scheduled for specific dates or times.
* You can **drag and drop** banners to change their display order.
The updated banner order is reflected on the storefront homepage.
***
## Global Reward Catalog
This feature allow to customise the reward catalog shown in our marketplace. You can enable or disable categories like Gift Cards, Merchandise, Experience and Perks along with control of restricting some catalog for different countries.
Navigate to **Settings > Storefront > Global Reward Catalog** and click on **"Customize".**
Define the value range by entering a minimum and maximum denomination.
Filter your results by selecting the specific countries or geographic regions you wish to include.
You can choose to view and customise the global reward catalog of 1000+ brand vouchers. You can see a list of categories which includes:
* Gift Card
* Merchandise
* Lounge
* Charity
* Experience
* Perks
* Flights
* Hotels
* Miles
* Mobile Top-ups
Click on "**Customise**" next to the catalog item.
You will a list of items here. Simply check and uncheck the box to include or exclude the item on storefront.
Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Customization
Source: https://help-plum.xoxoday.com/account-settings/storefront/customization
The Customization section allows Admins to configure various settings for the Plum storefront. You can customise the points terminology, payment options, redemption requirements, storefront footer, and delivery address settings.
To access these settings, navigate to **Settings > Storefront > Customization**.
## Change Point Name
You can customise the name used to refer to points on the Plum storefront. This allows organisations to use terminology that is consistent with their internal rewards program.
For example, an organisation may refer to points as **Ace Points**, **Coins**, or **Credits**.
To change the point name:
1. Navigate to **Settings > Storefront > Customise**.
2. Click **Change Point Name**.
3. Enter the preferred point name.
4. Save the changes.
The updated point name is displayed across the storefront wherever points are referenced.
## Change Points Icon
The **Change Points Icon** setting allows you to customise the icon displayed next to the points balance in the storefront header. You can upload a custom icon to replace the default coin icon.
To change the points icon:
1. Navigate to **Settings > Storefront > Customise**.
2. Locate **Change Points Icon**.
3. Upload the required icon.
4. Save the changes.
The uploaded icon is displayed next to the points balance in the storefront header.
**See where it appears**: Open the storefront to view the updated points icon.
## Allow Digital Payments
The **Allow Digital Payments to Users** setting allows users to make partial payments using a personal credit or debit card or bank account when their available points or codes do not cover the full purchase amount.
This option is enabled by default.
To enable or disable digital payments:
1. Navigate to **Settings > Storefront > Customise**.
2. Locate **Allow Digital Payments to Users**.
3. Turn the toggle **on** or **off** based on your requirements.
When disabled, users cannot use a personal payment method to pay the remaining amount after applying their available points or codes.
## Set a Minimum Value for Points Redemption
The **Set a Minimum Value for Reward Points Redemption** setting allows you to define the minimum number of points a user must accumulate before they can redeem rewards.
To configure the minimum redemption value:
1. Navigate to **Settings > Storefront > Customise**.
2. Turn on **Set a Minimum Value for Reward Points Redemption**.
3. Enter the required minimum points value.
4. Save the changes.
Users can redeem rewards only after their available points meet the configured minimum value.
## Enable Storefront Footer
The **Enable Storefront Footer** setting allows you to display a footer at the bottom of your Plum storefront.
To enable or disable the storefront footer:
1. Navigate to **Settings > Storefront > Customise**.
2. Locate **Enable Storefront Footer**.
3. Turn the toggle **on** or **off**.
4. Save the changes.
When enabled, the footer is displayed to users on the storefront.
## Manage Delivery Addresses
The **Saved Addresses** feature allows Admins to save delivery addresses for physical rewards, such as merchandise and physical gift cards. Saved addresses can be reused across eligible reward campaigns, reducing the need to enter the same delivery details for each order.
### Add a Delivery Address
To add a delivery address:
1. Navigate to **Settings > Storefront > Customise**.
2. Click **Add New Address**.
3. Enter the required delivery details.
4. Click **Save**.
### Edit or Delete a Delivery Address
To manage an existing delivery address:
1. Navigate to **Settings > Storefront > Customise**.
2. Select the saved address.
3. Choose **Edit** or **Delete**.
4. Make the required changes or confirm the deletion.
Saved addresses can be used across eligible reward campaigns unless **Lock Delivery Address** is enabled.
## Lock Delivery Address
The **Lock Delivery Address** setting allows organisations to restrict deliveries to a specific verified or approved address.
When this setting is enabled:
* The delivery address is pre-filled during checkout.
* Users cannot edit, delete, or replace the locked address.
* Users cannot add a new delivery address during checkout.
Users must use the locked delivery address to complete the order. If the address is incorrect, contact the organisation or program administrator for assistance.
# Admin Activity
Source: https://help-plum.xoxoday.com/admin/admin-activity
The **Admin Activity** page provides an audit trail of threshold changes made for administrators within an organisation. It enables Super Admins to track threshold updates, monitor amount-spent resets, and identify the Super Admin who performed each action.
The **Admin Activity** page is available only to Super Admins.
To access the page, navigate to **Settings > Admins > Admin Activity**.
## Activity Details
Each activity record includes the following information:
| Field | Description |
| :--------------------- | :---------------------------------------------------------------------------------------------------------------------------------------- |
| **Date** | The date on which the action was performed. |
| **Action** | The type of update performed, such as **Threshold Increased**, **Threshold Decreased**, **Threshold Updated**, or **Amount Spent Reset**. |
| **Account Affected** | The administrator whose threshold or spending details were updated. |
| **Existing Threshold** | The threshold value before the change. |
| **New Threshold** | The updated threshold value after the change. |
| **Amount Spent** | The amount spent by the administrator when the activity was recorded. |
| **Admin Balance** | The remaining available balance after the update. |
| **Action Taken By** | The Super Admin who performed the action. |
## Filter Activity
Use the available filters to find specific activity records.
* **Date Range:** Filter activities by a specific date range. By default, the page displays activity from the last **30 days**.
* **Account Affected:** View activities for a specific administrator.
* **Action Taken By:** View activities performed by a specific Super Admin.
* **Action:** Filter activities by the type of action performed:
* **Threshold Increased**
* **Threshold Decreased**
* **Threshold Updated**
* **Amount Spent Reset**
## Customize the Table
The **Columns** option allows Super Admins to select the information displayed in the activity table.
The **Date** and **Action** columns are always displayed and cannot be hidden.
## Download Activity
Click **Download** to export the activity log as a CSV file.
The exported file includes the activity details available in the log and can be used for reporting, auditing, or record-keeping purposes.
# Delete or Disable Campaign
Source: https://help-plum.xoxoday.com/campaigns/campaign-management/delete-or-disable-a-reward-campaign
See how to permanently delete a reward campaign, or disable it temporarily without losing its configuration, in Plum.
*Learn how to delete or disable a campaign*
***
## Reward Code Campaign
Whilst it is not possible to delete your Reward Code Campaign, you can disable it by clicking the "**Disable" button under the "Actions**" tab.
Now click on the "**Disable**" button on the screen above.
You can also choose to "**Enable**" it later if you ever change your mind.
***
## Reward Link Campaign
Click on the "Reward Link Campaign" section.
You can now choose to disable a Reward Link Campaign, by clicking on the "Disable" button under the "**Actions**" tab.
# Edit Campaign
Source: https://help-plum.xoxoday.com/campaigns/campaign-management/edit-a-reward-campaign
Learn how to edit an existing reward campaign in Plum, including updating its budget, recipients, and reward details after launch.
*Learn how to edit your reward link or reward code campaigns*
***
## Editing the Reward Campaigns
Go to the **"Campaign**" section in the Admin Dashboard.
Now, under the "Actions", choose to **"Edit"** the Campaign.
You can now change the name of the campaign and update the campaign accordingly.
You can choose to select/deselect the categories and subcategories to include in the campaign.
You can also choose the customize the mailer.
Congratulations! You have successfully updated your campaign.
***
Feedback or Questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Overview
Source: https://help-plum.xoxoday.com/campaigns/campaigns-overview
Get an overview of reward campaigns in Plum, including how to distribute gift cards, reward links, and reward codes to groups at scale.
*Learn how to create and manage customized campaigns in Xoxoday Plum.*
***
## Campaigns
Xoxoday Plum enables Super Admins and Admins to create and manage bespoke campaigns, enriching the rewarding experience for end-users by offering customizable storefronts and personalized rewards, thereby boosting engagement and satisfaction levels.
Within Plum, you can seamlessly create two types of campaigns:
* **Reward Code Campaign**
* **Reward Link Campaign**
Each campaign type offers unique features and benefits, catering to diverse requirements. Whether it's an employee recognition program, customer loyalty initiative, or any other rewarding campaign, Plum provides comprehensive solutions.
In the following section, we'll guide you through the step-by-step process of creating, editing, and disabling your Plum campaigns. You'll learn everything from naming your campaign to customizing email and SMS content, ensuring unforgettable reward experiences for your audience.
***
**Pro Tip**
Maximize engagement by periodically refreshing your campaign content and rewards to keep your audience excited and motivated. Experiment with different customization options and monitor performance metrics to optimize your campaigns for maximum impact.
***
Feedback or Questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Create Reward Code Campaign
Source: https://help-plum.xoxoday.com/campaigns/create-a-reward-code-campaign
Learn how to create a reward code campaign in Plum so you can distribute reward codes to a large group of recipients in bulk.
*Learn how to create a Reward Code Campaign*
Plum lets you customize Reward Code Campaigns with tailored storefronts and custom landing pages for enhanced user engagement and redemption experiences.
***
## Creating a Reward Code Campaign
**Customize Catalog**
Customize the email subject and content to align with your campaign goals.
- You can also edit the logo by clicking on "Edit Logo" and uploading a new logo.
* You can also edit the logo by clicking on "Edit Logo" and uploading a new logo.
* Xoxoday Plum allows for editing or removing the banner. Click on "**Edit/Remove Banner**" and follow the steps.
- Click on "Edit Message" to make changes to the message.
#
* Click on "Edit Message" to make changes to the message.
* **Configure Message Details** Toggle the recipient's name on or off and choose from our library of greetings (or create a custom one). Define your message by entering a title and body text, then adjust the content alignment to your preference.
## \*\*Step 6: Setting Up the Campaign
## **Step 6: Setting Up the Campaign Once all configurations are complete, click "Create**" to launch your Reward Code Campaign. Once all configurations are complete, click "Create\*\*" to launch your Reward Code Campaign.
Navigate to Settings > Campaigns, select Reward Code and click "**Create Reward Code Campaign**."
Start by giving your campaign a name. You can then choose the specific categories you wish to include or exclude.
Utilize the campaign to tailor the storefront for your end-users. This customization encompasses options such as country, brand, and categories. Once adjustments are made, remember to save the changes.
Customize Catalog
Enhance personalization by incorporating a custom landing page. When recipients receive the reward code, they will first encounter this landing page before being directed to the storefront for redemption.
Customize Catalog
Customize the email subject and content to align with your campaign goals.
* You can also edit the logo by clicking on "Edit Logo" and uploading a new logo.
* You can also edit the logo by clicking on "Edit Logo" and uploading a new logo.
* Xoxoday Plum allows for editing or removing the banner. Click on "**Edit/Remove Banner**" and follow the steps.
* Click on "Edit Message" to make changes to the message.
* Click on "Edit Message" to make changes to the message.
* **Configure Message Details** Toggle the recipient's name on or off and choose from our library of greetings (or create a custom one). Define your message by entering a title and body text, then adjust the content alignment to your preference.
Once all configurations are complete, click "**Create**" to launch your Reward Code Campaign. Once all configurations are complete, click "**Create**" to launch your Reward Code Campaign.
Congratulations! You have successfully created a Reward Code Campaign. For any feedback or questions reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). Congratulations! You have successfully created a Reward Code Campaign. For any feedback or questions reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Create Reward Link Campaign
Source: https://help-plum.xoxoday.com/campaigns/create-a-reward-link-campaign
Learn how to create a reward link campaign in Plum so you can distribute reward links to a large group of recipients in bulk.
*Learn to create campaigns with Reward Links tailored to your audience's preferences.*
***
## Creating a Reward Link Campaign
Step-by-step guide to creating Reward Link Campaign:
Navigate to **Settings > Campaign, select the tab Reward Link and click "Create Reward Link Campaign**".
Choose a descriptive and memorable name for your campaign so that it is easy to identify later. Consider including the campaign objective or target audience in the name.
Tailor the reward amount and country selection based on your target audience's preferences. You can choose either gift cards or merchandise as the reward type. Click "**Customise"** to adjust the amount and currency.
Carefully select vouchers that align with your audience's interests and preferences.
**Pro tip**
Consider offering a variety of options to cater to diverse tastes and maximize redemption rates.
Customize your email and SMS campaigns to resonate with your audience by using personalization tokens to address recipients by name and segmenting your messaging based on demographics or past interactions.
**Pro tip**
You can customize communication at the time of sending reward links as well. Learn more here: [Customize Reward Communication](/send-rewards/reward-links/reward-link-customize-reward-communication)
Always preview your campaign setup before finalizing it. Check for any errors or inconsistencies in the content and ensure that the campaign flows smoothly from start to finish. Once previewed, click **"Create**" to proceed.
***
Feedback or Questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Manage Campaigns
Source: https://help-plum.xoxoday.com/campaigns/duplicate-or-disable-a-campaign
See how to duplicate an existing reward campaign to reuse its settings, or disable a campaign that is no longer needed in Plum.
The Campaign Duplication feature helps you save time by creating new campaigns based on existing ones. Whether you're working with Reward Codes or Reward Links, you can duplicate any campaign in just a few clicks.
***
## What is Campaign Duplication?
Instead of starting from scratch every time you want to run a similar campaign, you can **duplicate** an existing one. This copies all the settings and configurations of the original campaign, allowing you to make only the necessary changes.
## Where to Find This Feature
You can access the duplication feature from the Campaigns section under **Settings**.
***
## How to Duplicate a Campaign
Choose between:
* **Reward Codes Campaigns**
* Reward Links Campaigns
Each campaign is listed with a **three-dot menu (⋮)** on the right. Click on the three dots to open more options.
Click **"Duplicate Campaign"** from the menu.
* Default name: `Copy of #"Original Campaign Name"}`
* You can rename it or keep the default.
Click "Customize Your Communications" to proceed. Customize the email template as needed, then click **"Create"**.
### What Gets Duplicated?
When you duplicate a campaign, the following elements are copied:
* Campaign settings
* Rules and configurations
* Templates and assets (if applicable)
The new campaign is created in a **draft/inactive** state so you can review and activate it when ready.
### Tips and Best Practices
* Use duplication to run recurring campaigns with similar setups.
* Rename duplicated campaigns clearly to avoid confusion.
* Review and adjust expiry dates, reward quantities, and other variables before activating.
***
## Disable a Campaign
Go to Campaigns and click on the Reward Code or Reward Link tab.
Click the **three-dot menu (⋮)** next to it.
In the confirmation pop-up, click **Yes, Disable**.
Done — the campaign is now paused.
***
For any queries or feedback, reach out to [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Admin and Business
Source: https://help-plum.xoxoday.com/faq/security-compliance/adminbusiness
Find answers to frequently asked questions about Plum's administrative controls and business continuity practices.
*Access Admin and Business security policy documents.*
[Open document](https://drive.google.com/file/d/1LyE7ogFTxdbUiaSLBOYaMbFxsvXbuI3v/view)
[Open document](https://drive.google.com/file/d/1jNgN1Rc9hMM8xcVPcB6Rd32NKHqvHdyo/view?usp=sharing)
[Open document](https://drive.google.com/file/d/10sWqTxSQqSdfdPi4q4lwIjHtoJhrn5UQ/view?usp=sharing)
[Open document](https://drive.google.com/file/d/16c7bYIdwy8ei58QnYydnA5qT07UD_meb/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1WJL_C6MLX9PCDfTisFUokTzoLK5qdoiw/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1ZDDnbuxb8X39t39QP-riP2wwQjl9crhc/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1NjQR15_VDeHqKB1OHHBFOIv_1n3igI48/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1xr3hhkLmYu6c5tpR8aG3iF2NyQ2ormZa/view?usp=sharing)
# Application, Dev and Security
Source: https://help-plum.xoxoday.com/faq/security-compliance/application-dev-and-security
Find answers to frequently asked questions about Plum's application development lifecycle and secure coding practices.
***
## Infrastructure & Compliance
We take steps to securely develop and test against security threats to ensure the safety of our customer data. We maintain a Secure Development Lifecycle, in which training our developers and performing design and code reviews takes a primary role. In addition, Xoxoday employs third-party security experts to perform detailed penetration tests on different applications. In addition to the security components provided by our top-level cloud providers AWS, Xoxoday maintains its own dedicated controls by following the industry best practices. These controls cover DDoS attacks, DB protection and a dedicated web application firewall, as well as network firewall fine-grained rules configured using the highest industry standards.
We provide Software as a Service (SaaS).
SaaS.
Admins can control the application and will have access to alerts and security events.
Xoxoday application is an API-driven digital rewards platform that automates rewards, incentives and gifting. The storefront has a global catalogue of 20,000+ options with 5,000+ experiences, 2,000+ gift cards and 10,000+ perks. The platform offers reward distribution modes like sending bulk vouchers via emails and generation of bulk voucher codes.
No. We are cloud hosted only.
We will share this as an attachment upon request.
Cloud hosted, microservice-based, highly scalable, High Availability.
NA — We are cloud hosted.
NA — We are cloud hosted. Users need to have internet access.
Yes. The solution is available as part of SAP SuccessFactors solution on web, as well as the SuccessFactors native mobile app for both iOS and Android.
It's accessible in a mobile browser and can be accessed via an Android or iOS device.
Our applications are compatible with desktops, tablets, and mobiles. No additional components are required.
Our applications are compatible with desktops, tablets, and mobiles. No additional components are required.
AWS / Kubernetes — React — Node/GraphQL — MySQL/MongoDB.
We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js and MongoDB technology.
Yes. We are using the latest language frameworks like MySQL, JavaScript, Node.js and MongoDB.
Yes. These are approved during the code review process wherein the reviewer checks the utility and security of the libraries.
We have deployed our application on AWS Cloud virtual platform. The backup data center is in Singapore.
The data centers are hosted completely in isolation so that access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load. Each instance (EC2) under a fortified VPC network is a conglomeration of Docker Container Web Services and APIs and application layer running on top. Amazon CloudWatch is implemented to enable monitoring. The data is encrypted using 256-encryption-based SSL certificate. Xoxoday plans a quarterly VAPT-based security audit.
Plum by Xoxoday is a cloud-based SaaS platform hosted on VPC infrastructure of AWS. The data centers are hosted in complete isolation. The architecture allows adding more location-specific data centers for latency and data security. Load balancers allow auto-scaling. Each EC2 instance under fortified VPC network is a conglomeration of Docker Container Web Services and APIs. Amazon CloudWatch is implemented for monitoring. Data is encrypted using TLS 1.3 in transit and AES-256 at rest.
***
## Backup, Recovery & Business Continuity
Data backups are done daily and in a secured way in AWS.
We use AWS Virtual platform cloud. We have created an Amazon CloudWatch alarm that monitors Amazon EC2 instances and automatically recovers them if impaired. EBS Snapshot functionality allows us to capture and restore virtual machine images at any time.
Yes, the infrastructure environment solution includes software/provider independent restore and recovery capabilities.
Yes. Data backups are automated and done daily in a secured way on AWS. We test the backup or redundancy mechanisms at least annually.
Our RTO and RPO is 60 minutes.
Yes. Data backups are done daily and in a secured way in AWS.
Data backups are done on a daily basis and in a secured way on AWS.
We take automated backups on a regular basis.
Yes. We take a backup of all data before making any major changes to hardware and software.
We have implemented the Backup Recovery Procedure.
We have Business Continuity Policy and Business Continuity Management Procedure in place, tested periodically. Our policies are reviewed and audited annually. We test the BCP every 12 months, reviewed as part of internal and external audits.
Yes. Data backups are done on a daily basis in a secured way in AWS.
Yes. It is tested annually.
Yes. All data backup is encrypted.
Yes. It can be recovered.
We have implemented the Business Continuity Management Policy and test the BCM plan annually. The BCM policy is attached for reference.
We have implemented policies and procedures with regard to DR. Since we have deployed our application on AWS cloud, they provide DR services.
The application network architecture diagram is attached upon request.
***
## Application Development & SDLC
We have an SDLC Policy as per ISMS requirements and follow General Coding Practice. We conduct data validation on a trusted system, use cryptographic functions to protect secrets, and perform code reviews, vulnerability assessments, and penetration testing. We follow a blue-green deployment strategy that introduces new changes without downtime and provides rollback capability.
Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates.
We have implemented the SDLC Procedure and standards of quality are met for all software development.
We have not outsourced software development activities. Our code reviews and analysis run through stringent automated technologies as well as manual source code overviews to cover any security loopholes prior to the production phase.
Yes. All debugging and test code elements are removed from released software versions.
Yes. We use an automated source code analysis tool.
We are proactively embedding privacy into the design and operation of IT systems, networked infrastructure, and business practices.
We focus on security while producing software. SDLC procedures are attached for reference.
Yes. All environments are separate.
No. We do not use production data in test environments.
Yes. Both are kept separate.
Yes.
Any applications and software are implemented after security testing by our IT team. All logs are monitored. We maintain an approved software/application register, audited during internal and external audits. Users are disallowed from installing software on their workstations.
Yes. We have static code analysis.
We have an SDLC Policy per ISMS requirements and follow General Coding Practice including data validation on a trusted system, cryptographic functions to protect secrets, and least privilege — restricting users to only the functionality, data, and system information required for their tasks.
More than 50% of our production code is covered by automated tests.
We do not use staging for building artifacts.
We conduct application security testing with the help of industry-approved third-party vendors every six months. Any observations found are addressed by our team. The primary objective is to identify and eliminate problems that could lead to a breach of confidentiality, availability, or integrity of Xoxoday data resources.
Yes. Our code reviews run through stringent automated technologies and manual source code overviews. Vulnerability scanning gives deep insight for quick identification of non-compliant systems. Xoxoday also employs third-party security experts to perform VAPT.
Yes. Code reviews and analysis run through stringent automated technologies as well as manual source code review. Multiple security checks including code reviews, web vulnerability reviews, and advanced security tests are performed in every build.
Yes. Code is reviewed both internally and externally. We engage third-party vendors for security testing every six months.
All software development procedures are supervised and monitored by Xoxoday to include: security requirements, independent security review of the environment, code reviews, quality monitoring, evaluation, and acceptance criteria for information systems.
Our QA department reviews and tests our code base. Dedicated application security engineers identify, test, and triage security vulnerabilities. We also conduct code reviews and VAPT with the help of a third-party vendor. VAPT Certificate is attached.
Yes. This is part of the code review process wherein the reviewer checks the utility and security of the 3rd party library.
Compliant. The application is developed based on secure coding guidelines and code reviews are conducted per compliance requirements.
Compliant.
Compliant. Yes, we follow all technical guidelines for development that come under the Open Web Application Security Project.
Compliant. We have implemented DLP techniques and there are no possibilities of data leakage or loss.
Compliant. The application uses HTTPS.
Compliant. We use strict HTTP transport security.
We cannot impose file upload frequency restrictions. However, the application has technical and organizational measures to prevent attacks through WAF, log monitoring, AWS GuardDuty, Amazon CloudWatch, IDS/IPS, etc.
***
## Access Control & Authentication
We have a role-based access system to make sure that only authorized individuals have access to the required information.
We don't provide multi-factor authentication as a default. As of now, there's OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
No, we don't provide multi-factor authentication as a default. As of now, there's OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
It can be configured with Active Directory.
Access to data and systems is based on the principles of least privilege. All information systems and data are classified and segregated to support role-based access requirements. We use MFA, Firewall, VPN, Active Directory, etc. for maximum security.
The password needs to be a minimum of 8 characters long and contain at least one capital letter, special characters among '# \$ % \* &' and 1 digit. These are reviewed monthly.
We store passwords hashed. We have SHA-512 hash with unique salt for every password.
We store passwords hashed. We have SHA-512 hash with unique salt for every password.
Yes. Our password requirements comply with all factors to ensure strong passwords: minimum length, special characters, capitalized letters, and alpha-numeric combinations. Passwords are stored after encryption.
Yes.
Yes.
The solution does not allow login using credentials that have not been used. Admins can create and delete user accounts.
It's a SaaS solution. Users can log in from multiple locations.
No. Users need to login with user ID and password. However, we have integrations with Zoho CRM, HubSpot, DarwinBox, SurveyMonkey, Freshdesk, etc.
Since it's a SaaS product, session timeout can be set with the help of Active Directory. For example — 15 min or 20 mins as per requirements.
The account will get automatically locked after 5 unsuccessful login attempts.
Users will get a reset password link and can unlock their account through that.
User accounts will be created by the admin and linked with the email ID of the users. Please refer to the admin guide: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1)
Yes.
Yes. Two-factor authentication is enabled. MFA devices like Google Authenticator are available for OTP/Codes/Passwords.
Yes.
We have procedures for Roles, Responsibilities & Authorities at Xoxoday. Per the access control policy, access to data is provided only to authorized and appropriate individuals.
Password policy: Must contain at least 8 characters, numbers and letters, uppercase (A-Z), lowercase (a-z), digits (0-9), and non-alphabetic characters (e.g., !, \$, #, %). Password must be changed every 90 days. Passwords are shared through secure, encrypted channels.
Yes. Policies and procedures enforce two-factor authentication for privileged account management while accessing tenant data/systems. An IAM solution manages user access through role-based access profiles based on the need-to-know principle and segregation of duties.
By default, Xoxoday will not have access to service data. Access control is managed by the admin from the customer end. If we require access for troubleshooting, we request temporary access, and the customer decides. Access to our production environment is allowed only via the Xoxoday corporate network to authorized individuals.
Please refer to the admin guide on SSO Logins: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started)
Yes. Access has been restricted and monitored for security reasons.
Yes. We have complexity and length requirements for passwords.
We review user access on a periodical basis, validated during internal and external audits.
***
## Network Security & Firewall
Yes. We have captured this information in our architecture and data flow diagrams.
Yes, we have a firewall.
Yes, we have the network architecture diagram.
Yes, we have configured secure internet access.
Yes, we have configured these.
Yes. We have IDS and IPS implemented and receive alerts for unauthorised network access.
Yes. It's reviewed on a monthly basis.
Yes.
Yes.
Yes. All are configured according to security standards as part of the build process.
We have implemented IDS/IPS to facilitate timely detection, investigation by root cause analysis, and response to incidents.
Wireless access is allowed and handled with high-quality routers, password protection and restriction on internet usage.
Yes. We have installed firewalls for maximum security and configured them to restrict unauthorised traffic.
All data is collected only through the Xoxoday Platform.
We use a Web Application Firewall (WAF).
We harden the operating systems and restrict access to all ports, applications, and software, monitored on a regular basis.
We have implemented policies and mechanisms to protect the wireless network environment. We use a cloud-hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and linked with SSO/Active Directory.
Yes. It's logically and physically segregated. We have deployed our application on AWS Cloud platform.
We do not provide external access.
We have implemented IDS/IPS, Endpoint security, Firewall, DLP, Antispoofing, VPN, Active Directory and other security solutions for maximum security.
Yes. With multiple layered firewalls configured with deny-all mode allowing only specific rules required for business, network traffic is regulated. We have implemented intrusion detection and prevention system tools for timely detection and investigation.
With multiple layered firewalls in deny-all mode, network traffic is regulated. We use tools that analyze various traffic patterns and correlate network events. Early warning signals trigger alerts to our team. We are equipped to detect and mitigate threats, DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
Yes. As part of WAF, rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats.
All our network components and computers are password protected to ensure compliance with integrity, availability, and confidentiality principles of Information Security.
Yes.
We have Network Access Control and Security Procedure in place. Network resources must be on a need-to-know basis and authorizations must be obtained from appropriate authorities. Networks are logically or physically divided based on the criticality of the information stored.
We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and data encryption. We conduct code reviews and VAPT annually with a third-party vendor. We are equipped to detect and mitigate DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
We use Cloudflare Web Application Firewall (WAF) and IDS/IPS for maximum security.
Yes. We have implemented the Web Application Firewall (WAF).
We have a web application firewall, IDS/IPS, SQL injection protection. We use Cloudflare for the same.
Yes. Our network communication is encrypted with highly restricted protocols to ensure maximum security. We use TLS 1.2 encryption for data in transit.
We use HTTPS and our network communication is encrypted with highly restricted protocols to ensure maximum security.
We do not provide support for IP address range restriction. Our restrictions/security are based on our OAuth process and do not restrict to specific IPs.
***
## Logging, Monitoring & Audit
Yes. We monitor the logs. Application and infrastructure logs are centrally collected and backed up in a secure manner for internal development and audit-related concerns.
Yes. We maintain the records.
Yes. Since we record Services and Server logs at the level of virtual machine, and Audit and Access logs at the level of AWS, all these are covered.
Monthly.
Yes. Only authorised individuals can do this.
Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We provide logs to the customer on a need and approval basis.
We maintain logs and monitor for security and audit purposes.
Yes. System clocks of all relevant information processing systems are synchronized to facilitate tracing and reconstitution of activity timelines.
Yes.
We maintain logs for at least 180 days. Only the CTO and Production Head will have access to these logs. There will be no modification to these logs.
Only authorised individuals have access to the security logs — e.g., CTO, DevOps Head, Production Head.
At least 180 days.
Yes. Only authorised individuals have access.
Yes. We have a SIEM in place for monitoring and maintaining logs over security incidents from various components.
Yes, SIEM has been implemented. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts in case of contingency. Audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions.
We have implemented the Security Operations Center to monitor, prevent, detect, investigate, and respond to cyber threats around the clock.
Cyber security incidents are analyzed with network intrusion detection (IDS) tools. The incident response team is immediately notified for counter-actions and defense mechanisms. We have a Security incident management process to classify and handle incidents and security breaches.
Yes.
No. Logs are automatically audited but are not integrated with tenant's security ops. In case the tenant requests logs, they can be shared when asked by the clients.
No. We do not have such a service. The key admin actions are present in the application reports. Our support team can help with a deep dive into a specific incident with the help of audit logs.
Yes. Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
All infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. The audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions.
Yes. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts if needed.
We monitor logs on a regular basis. Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
We use a cloud-hosted VPN with strict access controls. We have implemented intrusion detection tools for timely detection and investigation. File integrity and network intrusion detection (IDS) tools are implemented. We also have Endpoint security software for all computers.
We perform internal and external audits annually. We also conduct security assessments and testing like VAPT every six months. We communicate these assessment results to clients on a yearly basis.
Yes. We conduct audits on our Information Security Management System. The last audit date was 16th June 2021.
Yes.
Yes. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty threat detection service that continuously monitors for malicious activity and unauthorised behaviour. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails.
We have an intrusion detection/monitoring application that alerts on unauthorized access. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails.
Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
Yes. All audit logs are monitored as a best practice.
Yes. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
Yes. Our event management systems merge the data sources to maintain a log data within the SIEM. This helps in proper analysis and driving out alerts if needed in case of contingency.
At Xoxoday, the following are recorded in audit logs: 1. Infrastructure logs — collected using AWS Audit Trail. 2. Application related logs — collected in our Elastic Search server and retained in long-term cloud storage.
***
## Data Protection & Encryption
Yes. We can freeze data from a specific time without freezing other data if needed.
We have a data loss prevention solution in place and data will not be lost.
Personal data will be processed only for rewards and redemption purposes.
Yes. We can provide the data flow diagram.
We use technologies like DLP, Data encryption, access control, and log monitoring.
All data is collected only through the Xoxoday Platform.
Yes. The data is segregated with a client-specific key for proper handling and representation. Physical segregation is done for production and non-production environments.
We use a split key mechanism to ensure that every client's key is unique. It's generated automatically from our end.
We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and encrypted data. We conduct code reviews per compliance requirements and VAPT annually with a third-party vendor. We are equipped to detect and mitigate threats, DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
Yes. We do testing before deploying in the production environment.
All data is collected only through the Xoxoday Platform.
We do not transfer any data externally. However, we have implemented encryption, VPN, Firewall, IDS/IPS, and monitoring systems.
We have disabled all ports and users do not have access to USB, CD-ROM, Disks, tapes, or Hard drives. All data including backups has been encrypted. We use TLS 1.2 for data in transit and AES-256 for data at rest.
All customer data including backup data is stored on AWS virtual platform cloud and does not store anything locally. We use TLS 1.2 for data in transit and AES-256 for data at rest. We have also implemented the Media handling procedure.
Yes.
Our web application, email records, and endpoints are sealed with data loss prevention techniques. We have the capability to respond immediately.
We logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data.
All security mechanisms and policies are established to prevent data leaks in transit as well as at rest. Exhaustive VAPT has been conducted along with business logic testing based on the OWASP framework, which incorporates 120+ test cases.
No. We use logical data isolation with the help of company-specific encryption keys.
Yes. We have implemented Data Loss Prevention techniques on AWS.
We have implemented data loss prevention techniques to make sure that the data is not lost permanently.
It's a part of our data loss prevention techniques.
Our web assets, email records, and endpoints are sealed with data loss prevention techniques even when the endpoint is disconnected from the corporate network.
Each tenant's data is uniquely encrypted using a client-specific key. We use AES-256 bit encryption for data at rest. Our network communication is encrypted with highly restricted protocols. The cryptographic keys, including data encryption and SSL certificates, are managed by Xoxoday for optimal security.
We use a split key mechanism to ensure that every client's key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS.
We use a split key mechanism to ensure that every client's key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS.
We use logical data isolation with the help of company-specific encryption keys.
Password can be reset by employees. We do not send the password in plain text. We use TLS 1.2 for data in transit and AES-256 for data at rest.
We store passwords hashed. We have SHA-512 hash with unique salt for every password.
Only our product engineering team members have access as per their job functions and role-based logical access. We do not provide access to any third parties and all development and testing is done by internal employees.
Yes. We use TLS 1.2 for data in transit and AES-256 for data at rest. All data including backups is encrypted.
Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
Yes. Per our policies and procedures, we ensure secure disposal and removal of data from every storage media. The data cannot be recovered by any computer forensic means. We assure secure data disposal when storage is decommissioned or when the contract comes to an end.
The only user data stored within the system is personal information — names, emails, and contact numbers. This data is not put to any use by Xoxoday and resides within the system. The data can be deleted upon the tenant's request.
We have implemented the Data Retention and Disposal Policy.
We retain logs for a minimum of 180 days and in accordance with the Company's records retention guidelines. We do not process any e-PHI.
***
## Patch Management
We update patches on a routine basis.
We update patches on a routine basis for servers as well.
We test patches before implementation in the production environment.
Patches are updated regularly.
Security patches are rated as Critical, High, Medium, and Low.
Critical patches will be deployed immediately. High patches will be deployed within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached.
Yes. We update patches periodically for our operating systems, software, servers, and network infrastructure.
Yes. We test the patches on the testing environment and deploy to production upon validation.
Yes. Security patches are regularly monitored and applied to the network security devices. All critical patches will be deployed immediately.
We update patches periodically. See Patch Management Procedure attached.
Yes. We regularly update our instance and make sure we follow security best practices. There is a process in place for regularly updating the servers and monitoring for latest updates across the entire stack.
We have implemented the Patch Management Procedure.
We follow the Change Management process to implement the compensatory control.
We follow the Change Management process.
Patches are updated on time.
Critical patches will be deployed immediately. High patches within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached.
Yes. We test patches before deploying in the production environment.
***
## Change Management
We have implemented the Change Management Procedure. All IT changes take place as per the Change Management Procedure.
Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates.
Yes. Change management procedures are attached. We are compliant.
Yes. We have implemented the change management procedures, and this applies to all Xoxoday assets, infrastructure, processes, software, and third-party activities. The procedure also applies to employees, vendors, and all other individuals who have access to, or are responsible for Xoxoday information processing facilities.
Yes. Our production team and QA team test all new releases or changes made to the existing product.
Yes. We will notify the customer if there are any major changes.
Yes. Our customer support team will communicate.
***
## Antivirus & Endpoint Security
We have installed antivirus on all workstations and servers.
Yes. We have the controls in place. We have blocked connecting Hard disk, USB, CD-ROM, etc. to computers and all devices are centrally managed.
We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty that continuously monitors for malicious activity and unauthorised behaviour. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory.
We use endpoint security for prevention.
We have an alerting system in place and we perform scanning immediately to reduce the risk.
We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc.
We maintain up-to-date endpoint security to safeguard from attack scripts, viruses, worms, Trojan horses, backdoors, and malicious active content.
We are using Linux operating systems and following security best practices. We are monitoring using Prometheus/Grafana.
We have installed endpoint security in servers and PCs of all our employees as per compliance requirements.
Yes. We update patches periodically and ensure that all endpoints have the latest available security-related patches.
We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory.
***
## SSO, Authentication & Integration
Yes. Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. Please refer to our list of integrations: [https://xoxoday.gitbook.io/plum/developer-resources/integrations](https://xoxoday.gitbook.io/plum/developer-resources/integrations)
Yes. The application has robust authentication methods. We have integrated SAML 2.0 with SAP SuccessFactors and also support OAuth 2.0 for seamless authentication.
API Documentation: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis)
Please click here to know more about API integration: [https://www.empuls.io/integrations](https://www.empuls.io/integrations)
The application enables user account management through API-based integration with the customer's HR management system. These APIs are used to access employee data to ensure users' accounts are created, updated, and disabled securely.
Please click here for API Documentation: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis)
We have implemented WAF, IDS/IPS, and Amazon GuardDuty for maximum security. OAuth 2.0 is used to authorize all API requests. We also conduct code reviews to make sure that the APIs are secure.
Yes. It supports SSO.
Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go.
Application Integrations: [https://www.application.io/integrations?tab=tab-collaborations](https://www.application.io/integrations?tab=tab-collaborations)
It's a web and mobile application.
Our partnerships ensure existing customer-based SSO capability for all users. Our identity federation standards include SAML 2.0, SPML, WS-Federation, and more as means of authenticating and authorizing users with airtight security protocol. Please visit: xoxoday.com/integrations
Yes. The application has robust authentication methods. We have integrated SAML 2.0 with SAP SuccessFactors and support OAuth 2.0 and Azure AD for seamless authentication.
We have an option to integrate with SSO and HRMS. For more info, please visit the link: [https://www.application.io/integrations](https://www.application.io/integrations)
Two standard reports are available for admins on SuccessFactors at the program level — Budget and Spot Award Nomination. Using People Analytics, customers can create their own reports and dashboards combining Spot Awards data from Recognition with data from across SuccessFactors. Admins can also access similar data via a Xoxoday logon.
Yes. Customers can extract data from SuccessFactors via Integration Center and integrate it with other third parties.
Somewhat. We have a Spot Award Approved event available via Intelligent Service Center on SuccessFactors which customers can use to build custom extensions.
User provisioning for SAP SuccessFactors — Reward and Recognition is handled the same way as the rest of SuccessFactors. For employees redeeming points via Xoxoday, user provisioning is done on the fly at the time of redeeming the awards.
***
## Third Party & Vendor Management
We make sure that they have adequate controls in place and meet the security standard.
We are managing the platform end to end.
Yes. Incident reporting obligations are passed on to all 3rd parties as well. All contracts and agreements are reviewed by the Legal Department.
We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
***
## Service, Support & Upgrades
It will be the responsibility of Xoxoday.
The process for upgrades is automated using Continuous Integration and Deployment. Since our services are delivered via the web, upgrades and updates are seamless and usually do not involve any actions from end-users.
Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
The process for upgrades is automated using CI/CD. We try to release product hotfixes once every week and major features once every month.
The process for upgrades is automated using CI/CD. Upgrades and updates are seamless. We try to release hotfixes once every week and major features once every month.
Product updates and feature enhancements are done periodically by the application team. These updates are available to all customers by default. The customer need not do anything from their end to update the product version as the application is hosted on AWS Cloud.
The time of support ranges between two to forty-eight hours. This depends on the level of service and the gravity of incidents.
We have Email Support and an application help center for helping users.
We will be providing training for the admin and the end user and also provide extensive support through our customer support team.
Yes. We have an Information security team and group of people with responsibility for security within the organization.
Yes. We fix the issues found at no cost. We understand that consumer data protection is a high priority. We have implemented a Bug Bounty Program and encourage the reporting of security issues. If any outsiders or customers report security-related issues, we fix them free of cost.
We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js, and MongoDB technology.
See the application high-level diagram of CI/CD attached.
See the following policies attached — Infrastructure Change Control Procedure, Patch Management Procedure, Information System Acquisition Development and Maintenance Procedure, SDLC Procedure, Threat and Vulnerability Management.
Please click here for more details: [https://help.empuls.io/](https://help.empuls.io/)
Payments are redirected to PayU gateway or PayPal websites to complete purchases securely. We are also implementing PCI DSS compliance controls and will provide the certification as soon as possible.
Approximately 2 weeks.
No installation. We are an out-of-the-box SaaS solution.
No recommendations as such. The application is a SaaS product supported by a comprehensive web application that can be accessed via desktop and mobile browsers on all compatible devices, including Android and iOS.
We have a multi-layered network architecture with role-based access control. All confidential/PII data is encrypted at rest with a split key mechanism to ensure that every client's key is unique. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.
Yes.
Yes.
Yes. We have deployed our application on AWS Virtual platform cloud. We use WAF, IDS/IPS, AWS Audit Trail, Amazon GuardDuty, etc.
Yes. Segregation is done for production and non-production environments.
The production center location will be Bangalore.
***
## Compliance Statements
Xoxoday would act as liaison partner between customer and merchants. We process the budgets which are approved by the customer. Xoxoday application is a SaaS Product.
The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests logs, they can be shared when asked by the clients.
It's a multi-tenant system. We use logical data isolation with the help of company-specific encryption keys and it is isolated from other customers' data.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. We provide these logs on a need and approval basis for forensic investigation. We can freeze data from a specific time without freezing other data if needed.
We are compliant. We have implemented the password management policy and follow the concept of least privilege. Only a limited number of approved users have privileged access. All access will be provided on a need and approval basis. We maintain a ticketing system to make sure that the appropriate process is followed.
We have implemented the Password Management Policy for maximum security of data.
We are compliant. The password will be changed every 90 days.
These are integrated with security operations/SIEM solutions.
We have a secure log-on process and are compliant with these requirements.
We have a secure log-off process and are compliant with these requirements.
Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
We review architecture diagrams and data flow diagrams on a periodical basis. This is also validated during our internal and external independent audits.
We logically segregate the tenant's data, and it is segregated with a client-specific key for proper handling and security reasons.
We do not use any unsecured protocols.
All critical applications are reviewed and tested before deployment.
We have a separate test and production environment.
We monitor systems and network utilization.
We have implemented file integrity (host) and network intrusion detection (IDS) tools to help facilitate timely detection and investigation.
We make sure that we follow industry best practices, the PDCA cycle, and standards in order to safeguard the Information Security System.
All critical patches are applied rapidly.
We are a multi-tenant SaaS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis.
Yes. All critical patches will be deployed immediately. We ensure that our infrastructure is always using up-to-date systems.
We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data.
Compliant. We have deployed our application and database on separate servers.
Since the application is a SaaS Platform, this would not be applicable.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
Yes. We logically segregate the tenant's data and the application.
WAF and rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks.
Once the user logs out from the application, all pages, forms, and pop-ups will get closed.
We maintain logs and monitor on a regular basis for security reasons.
Compliant. We have resources to meet these requirements.
***
## Infrastructure & Compliance
We take steps to securely develop and test against security threats to ensure the safety of our customer data. We maintain a Secure Development Lifecycle, in which training our developers and performing design and code reviews takes a primary role. In addition, Xoxoday employs third-party security experts to perform detailed penetration tests on different applications. In addition to the security components provided by our top-level cloud providers AWS, Xoxoday maintains its own dedicated controls by following the industry best practices. These controls cover DDoS attacks, DB protection and a dedicated web application firewall, as well as network firewall fine-grained rules configured using the highest industry standards.
We provide Software as a Service (SaaS).
SaaS.
Admins can control the application and will have access to alerts and security events.
Xoxoday application is an API-driven digital rewards platform that automates rewards, incentives and gifting. The storefront has a global catalogue of 20,000+ options with 5,000+ experiences, 2,000+ gift cards and 10,000+ perks. The platform offers reward distribution modes like sending bulk vouchers via emails and generation of bulk voucher codes.
No. We are cloud hosted only.
We will share this as an attachment upon request.
Cloud hosted, microservice-based, highly scalable, High Availability.
NA — We are cloud hosted.
NA — We are cloud hosted. Users need to have internet access.
Yes. The solution is available as part of SAP SuccessFactors solution on web, as well as the SuccessFactors native mobile app for both iOS and Android.
It's accessible in a mobile browser and can be accessed via an Android or iOS device.
Our applications are compatible with desktops, tablets, and mobiles. No additional components are required.
Our applications are compatible with desktops, tablets, and mobiles. No additional components are required.
AWS / Kubernetes — React — Node/GraphQL — MySQL/MongoDB.
We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js and MongoDB technology.
Yes. We are using the latest language frameworks like MySQL, JavaScript, Node.js and MongoDB.
Yes. These are approved during the code review process wherein the reviewer checks the utility and security of the libraries.
We have deployed our application on AWS Cloud virtual platform. The backup data center is in Singapore.
The data centers are hosted completely in isolation so that access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load. Each instance (EC2) under a fortified VPC network is a conglomeration of Docker Container Web Services and APIs and application layer running on top. Amazon CloudWatch is implemented to enable monitoring. The data is encrypted using 256-encryption-based SSL certificate. Xoxoday plans a quarterly VAPT-based security audit.
Plum by Xoxoday is a cloud-based SaaS platform hosted on VPC infrastructure of AWS. The data centers are hosted in complete isolation. The architecture allows adding more location-specific data centers for latency and data security. Load balancers allow auto-scaling. Each EC2 instance under fortified VPC network is a conglomeration of Docker Container Web Services and APIs. Amazon CloudWatch is implemented for monitoring. Data is encrypted using TLS 1.3 in transit and AES-256 at rest.
***
## Backup, Recovery & Business Continuity
Data backups are done daily and in a secured way in AWS.
We use AWS Virtual platform cloud. We have created an Amazon CloudWatch alarm that monitors Amazon EC2 instances and automatically recovers them if impaired. EBS Snapshot functionality allows us to capture and restore virtual machine images at any time.
Yes, the infrastructure environment solution includes software/provider independent restore and recovery capabilities.
Yes. Data backups are automated and done daily in a secured way on AWS. We test the backup or redundancy mechanisms at least annually.
Our RTO and RPO is 60 minutes.
Yes. Data backups are done daily and in a secured way in AWS.
Data backups are done on a daily basis and in a secured way on AWS.
We take automated backups on a regular basis.
Yes. We take a backup of all data before making any major changes to hardware and software.
We have implemented the Backup Recovery Procedure.
We have Business Continuity Policy and Business Continuity Management Procedure in place, tested periodically. Our policies are reviewed and audited annually. We test the BCP every 12 months, reviewed as part of internal and external audits.
Yes. Data backups are done on a daily basis in a secured way in AWS.
Yes. It is tested annually.
Yes. All data backup is encrypted.
Yes. It can be recovered.
We have implemented the Business Continuity Management Policy and test the BCM plan annually. The BCM policy is attached for reference.
We have implemented policies and procedures with regard to DR. Since we have deployed our application on AWS cloud, they provide DR services.
The application network architecture diagram is attached upon request.
***
## Application Development & SDLC
We have an SDLC Policy as per ISMS requirements and follow General Coding Practice. We conduct data validation on a trusted system, use cryptographic functions to protect secrets, and perform code reviews, vulnerability assessments, and penetration testing. We follow a blue-green deployment strategy that introduces new changes without downtime and provides rollback capability.
Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates.
We have implemented the SDLC Procedure and standards of quality are met for all software development.
We have not outsourced software development activities. Our code reviews and analysis run through stringent automated technologies as well as manual source code overviews to cover any security loopholes prior to the production phase.
Yes. All debugging and test code elements are removed from released software versions.
Yes. We use an automated source code analysis tool.
We are proactively embedding privacy into the design and operation of IT systems, networked infrastructure, and business practices.
We focus on security while producing software. SDLC procedures are attached for reference.
Yes. All environments are separate.
No. We do not use production data in test environments.
Yes. Both are kept separate.
Yes.
Any applications and software are implemented after security testing by our IT team. All logs are monitored. We maintain an approved software/application register, audited during internal and external audits. Users are disallowed from installing software on their workstations.
Yes. We have static code analysis.
We have an SDLC Policy per ISMS requirements and follow General Coding Practice including data validation on a trusted system, cryptographic functions to protect secrets, and least privilege — restricting users to only the functionality, data, and system information required for their tasks.
More than 50% of our production code is covered by automated tests.
We do not use staging for building artifacts.
We conduct application security testing with the help of industry-approved third-party vendors every six months. Any observations found are addressed by our team. The primary objective is to identify and eliminate problems that could lead to a breach of confidentiality, availability, or integrity of Xoxoday data resources.
Yes. Our code reviews run through stringent automated technologies and manual source code overviews. Vulnerability scanning gives deep insight for quick identification of non-compliant systems. Xoxoday also employs third-party security experts to perform VAPT.
Yes. Code reviews and analysis run through stringent automated technologies as well as manual source code review. Multiple security checks including code reviews, web vulnerability reviews, and advanced security tests are performed in every build.
Yes. Code is reviewed both internally and externally. We engage third-party vendors for security testing every six months.
All software development procedures are supervised and monitored by Xoxoday to include: security requirements, independent security review of the environment, code reviews, quality monitoring, evaluation, and acceptance criteria for information systems.
Our QA department reviews and tests our code base. Dedicated application security engineers identify, test, and triage security vulnerabilities. We also conduct code reviews and VAPT with the help of a third-party vendor. VAPT Certificate is attached.
Yes. This is part of the code review process wherein the reviewer checks the utility and security of the 3rd party library.
Compliant. The application is developed based on secure coding guidelines and code reviews are conducted per compliance requirements.
Compliant.
Compliant. Yes, we follow all technical guidelines for development that come under the Open Web Application Security Project.
Compliant. We have implemented DLP techniques and there are no possibilities of data leakage or loss.
Compliant. The application uses HTTPS.
Compliant. We use strict HTTP transport security.
We cannot impose file upload frequency restrictions. However, the application has technical and organizational measures to prevent attacks through WAF, log monitoring, AWS GuardDuty, Amazon CloudWatch, IDS/IPS, etc.
***
## Access Control & Authentication
We have a role-based access system to make sure that only authorized individuals have access to the required information.
We don't provide multi-factor authentication as a default. As of now, there's OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
No, we don't provide multi-factor authentication as a default. As of now, there's OAuth 2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
It can be configured with Active Directory.
Access to data and systems is based on the principles of least privilege. All information systems and data are classified and segregated to support role-based access requirements. We use MFA, Firewall, VPN, Active Directory, etc. for maximum security.
The password needs to be a minimum of 8 characters long and contain at least one capital letter, special characters among '# \$ % \* &' and 1 digit. These are reviewed monthly.
We store passwords hashed. We have SHA-512 hash with unique salt for every password.
We store passwords hashed. We have SHA-512 hash with unique salt for every password.
Yes. Our password requirements comply with all factors to ensure strong passwords: minimum length, special characters, capitalized letters, and alpha-numeric combinations. Passwords are stored after encryption.
Yes.
Yes.
The solution does not allow login using credentials that have not been used. Admins can create and delete user accounts.
It's a SaaS solution. Users can log in from multiple locations.
No. Users need to login with user ID and password. However, we have integrations with Zoho CRM, HubSpot, DarwinBox, SurveyMonkey, Freshdesk, etc.
Since it's a SaaS product, session timeout can be set with the help of Active Directory. For example — 15 min or 20 mins as per requirements.
The account will get automatically locked after 5 unsuccessful login attempts.
Users will get a reset password link and can unlock their account through that.
User accounts will be created by the admin and linked with the email ID of the users. Please refer to the admin guide: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1)
Yes.
Yes. Two-factor authentication is enabled. MFA devices like Google Authenticator are available for OTP/Codes/Passwords.
Yes.
We have procedures for Roles, Responsibilities & Authorities at Xoxoday. Per the access control policy, access to data is provided only to authorized and appropriate individuals.
Password policy: Must contain at least 8 characters, numbers and letters, uppercase (A-Z), lowercase (a-z), digits (0-9), and non-alphabetic characters (e.g., !, \$, #, %). Password must be changed every 90 days. Passwords are shared through secure, encrypted channels.
Yes. Policies and procedures enforce two-factor authentication for privileged account management while accessing tenant data/systems. An IAM solution manages user access through role-based access profiles based on the need-to-know principle and segregation of duties.
By default, Xoxoday will not have access to service data. Access control is managed by the admin from the customer end. If we require access for troubleshooting, we request temporary access, and the customer decides. Access to our production environment is allowed only via the Xoxoday corporate network to authorized individuals.
Please refer to the admin guide on SSO Logins: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started)
Yes. Access has been restricted and monitored for security reasons.
Yes. We have complexity and length requirements for passwords.
We review user access on a periodical basis, validated during internal and external audits.
***
## Network Security & Firewall
Yes. We have captured this information in our architecture and data flow diagrams.
Yes, we have a firewall.
Yes, we have the network architecture diagram.
Yes, we have configured secure internet access.
Yes, we have configured these.
Yes. We have IDS and IPS implemented and receive alerts for unauthorised network access.
Yes. It's reviewed on a monthly basis.
Yes.
Yes.
Yes. All are configured according to security standards as part of the build process.
We have implemented IDS/IPS to facilitate timely detection, investigation by root cause analysis, and response to incidents.
Wireless access is allowed and handled with high-quality routers, password protection and restriction on internet usage.
Yes. We have installed firewalls for maximum security and configured them to restrict unauthorised traffic.
All data is collected only through the Xoxoday Platform.
We use a Web Application Firewall (WAF).
We harden the operating systems and restrict access to all ports, applications, and software, monitored on a regular basis.
We have implemented policies and mechanisms to protect the wireless network environment. We use a cloud-hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and linked with SSO/Active Directory.
Yes. It's logically and physically segregated. We have deployed our application on AWS Cloud platform.
We do not provide external access.
We have implemented IDS/IPS, Endpoint security, Firewall, DLP, Antispoofing, VPN, Active Directory and other security solutions for maximum security.
Yes. With multiple layered firewalls configured with deny-all mode allowing only specific rules required for business, network traffic is regulated. We have implemented intrusion detection and prevention system tools for timely detection and investigation.
With multiple layered firewalls in deny-all mode, network traffic is regulated. We use tools that analyze various traffic patterns and correlate network events. Early warning signals trigger alerts to our team. We are equipped to detect and mitigate threats, DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
Yes. As part of WAF, rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats.
All our network components and computers are password protected to ensure compliance with integrity, availability, and confidentiality principles of Information Security.
Yes.
We have Network Access Control and Security Procedure in place. Network resources must be on a need-to-know basis and authorizations must be obtained from appropriate authorities. Networks are logically or physically divided based on the criticality of the information stored.
We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and data encryption. We conduct code reviews and VAPT annually with a third-party vendor. We are equipped to detect and mitigate DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
We use Cloudflare Web Application Firewall (WAF) and IDS/IPS for maximum security.
Yes. We have implemented the Web Application Firewall (WAF).
We have a web application firewall, IDS/IPS, SQL injection protection. We use Cloudflare for the same.
Yes. Our network communication is encrypted with highly restricted protocols to ensure maximum security. We use TLS 1.2 encryption for data in transit.
We use HTTPS and our network communication is encrypted with highly restricted protocols to ensure maximum security.
We do not provide support for IP address range restriction. Our restrictions/security are based on our OAuth process and do not restrict to specific IPs.
***
## Logging, Monitoring & Audit
Yes. We monitor the logs. Application and infrastructure logs are centrally collected and backed up in a secure manner for internal development and audit-related concerns.
Yes. We maintain the records.
Yes. Since we record Services and Server logs at the level of virtual machine, and Audit and Access logs at the level of AWS, all these are covered.
Monthly.
Yes. Only authorised individuals can do this.
Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We provide logs to the customer on a need and approval basis.
We maintain logs and monitor for security and audit purposes.
Yes. System clocks of all relevant information processing systems are synchronized to facilitate tracing and reconstitution of activity timelines.
Yes.
We maintain logs for at least 180 days. Only the CTO and Production Head will have access to these logs. There will be no modification to these logs.
Only authorised individuals have access to the security logs — e.g., CTO, DevOps Head, Production Head.
At least 180 days.
Yes. Only authorised individuals have access.
Yes. We have a SIEM in place for monitoring and maintaining logs over security incidents from various components.
Yes, SIEM has been implemented. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts in case of contingency. Audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions.
We have implemented the Security Operations Center to monitor, prevent, detect, investigate, and respond to cyber threats around the clock.
Cyber security incidents are analyzed with network intrusion detection (IDS) tools. The incident response team is immediately notified for counter-actions and defense mechanisms. We have a Security incident management process to classify and handle incidents and security breaches.
Yes.
No. Logs are automatically audited but are not integrated with tenant's security ops. In case the tenant requests logs, they can be shared when asked by the clients.
No. We do not have such a service. The key admin actions are present in the application reports. Our support team can help with a deep dive into a specific incident with the help of audit logs.
Yes. Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
All infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. The audit logs are reviewed and recorded automatically. These logs are integrated with security operations/SIEM solutions.
Yes. Our event management systems merge data sources to maintain log data within the SIEM. This helps in proper analysis and driving out alerts if needed.
We monitor logs on a regular basis. Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
We use a cloud-hosted VPN with strict access controls. We have implemented intrusion detection tools for timely detection and investigation. File integrity and network intrusion detection (IDS) tools are implemented. We also have Endpoint security software for all computers.
We perform internal and external audits annually. We also conduct security assessments and testing like VAPT every six months. We communicate these assessment results to clients on a yearly basis.
Yes. We conduct audits on our Information Security Management System. The last audit date was 16th June 2021.
Yes.
Yes. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty threat detection service that continuously monitors for malicious activity and unauthorised behaviour. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails.
We have an intrusion detection/monitoring application that alerts on unauthorized access. We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails.
Infrastructure logs are collected using AWS Audit Trail. Application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
Yes. All audit logs are monitored as a best practice.
Yes. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage.
Yes. Our event management systems merge the data sources to maintain a log data within the SIEM. This helps in proper analysis and driving out alerts if needed in case of contingency.
At Xoxoday, the following are recorded in audit logs: 1. Infrastructure logs — collected using AWS Audit Trail. 2. Application related logs — collected in our Elastic Search server and retained in long-term cloud storage.
***
## Data Protection & Encryption
Yes. We can freeze data from a specific time without freezing other data if needed.
We have a data loss prevention solution in place and data will not be lost.
Personal data will be processed only for rewards and redemption purposes.
Yes. We can provide the data flow diagram.
We use technologies like DLP, Data encryption, access control, and log monitoring.
All data is collected only through the Xoxoday Platform.
Yes. The data is segregated with a client-specific key for proper handling and representation. Physical segregation is done for production and non-production environments.
We use a split key mechanism to ensure that every client's key is unique. It's generated automatically from our end.
We have WAF, IDS/IPS, AWS GuardDuty, Cloudflare, and encrypted data. We conduct code reviews per compliance requirements and VAPT annually with a third-party vendor. We are equipped to detect and mitigate threats, DDoS attacks, session hijacks, login spoofs, or any other data extraction strategies.
Yes. We do testing before deploying in the production environment.
All data is collected only through the Xoxoday Platform.
We do not transfer any data externally. However, we have implemented encryption, VPN, Firewall, IDS/IPS, and monitoring systems.
We have disabled all ports and users do not have access to USB, CD-ROM, Disks, tapes, or Hard drives. All data including backups has been encrypted. We use TLS 1.2 for data in transit and AES-256 for data at rest.
All customer data including backup data is stored on AWS virtual platform cloud and does not store anything locally. We use TLS 1.2 for data in transit and AES-256 for data at rest. We have also implemented the Media handling procedure.
Yes.
Our web application, email records, and endpoints are sealed with data loss prevention techniques. We have the capability to respond immediately.
We logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data.
All security mechanisms and policies are established to prevent data leaks in transit as well as at rest. Exhaustive VAPT has been conducted along with business logic testing based on the OWASP framework, which incorporates 120+ test cases.
No. We use logical data isolation with the help of company-specific encryption keys.
Yes. We have implemented Data Loss Prevention techniques on AWS.
We have implemented data loss prevention techniques to make sure that the data is not lost permanently.
It's a part of our data loss prevention techniques.
Our web assets, email records, and endpoints are sealed with data loss prevention techniques even when the endpoint is disconnected from the corporate network.
Each tenant's data is uniquely encrypted using a client-specific key. We use AES-256 bit encryption for data at rest. Our network communication is encrypted with highly restricted protocols. The cryptographic keys, including data encryption and SSL certificates, are managed by Xoxoday for optimal security.
We use a split key mechanism to ensure that every client's key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS.
We use a split key mechanism to ensure that every client's key is unique. We perform annual key rotation. Keys are generated using KMS service whenever needed. We store keys in KMS.
We use logical data isolation with the help of company-specific encryption keys.
Password can be reset by employees. We do not send the password in plain text. We use TLS 1.2 for data in transit and AES-256 for data at rest.
We store passwords hashed. We have SHA-512 hash with unique salt for every password.
Only our product engineering team members have access as per their job functions and role-based logical access. We do not provide access to any third parties and all development and testing is done by internal employees.
Yes. We use TLS 1.2 for data in transit and AES-256 for data at rest. All data including backups is encrypted.
Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
Yes. Per our policies and procedures, we ensure secure disposal and removal of data from every storage media. The data cannot be recovered by any computer forensic means. We assure secure data disposal when storage is decommissioned or when the contract comes to an end.
The only user data stored within the system is personal information — names, emails, and contact numbers. This data is not put to any use by Xoxoday and resides within the system. The data can be deleted upon the tenant's request.
We have implemented the Data Retention and Disposal Policy.
We retain logs for a minimum of 180 days and in accordance with the Company's records retention guidelines. We do not process any e-PHI.
***
## Patch Management
We update patches on a routine basis.
We update patches on a routine basis for servers as well.
We test patches before implementation in the production environment.
Patches are updated regularly.
Security patches are rated as Critical, High, Medium, and Low.
Critical patches will be deployed immediately. High patches will be deployed within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached.
Yes. We update patches periodically for our operating systems, software, servers, and network infrastructure.
Yes. We test the patches on the testing environment and deploy to production upon validation.
Yes. Security patches are regularly monitored and applied to the network security devices. All critical patches will be deployed immediately.
We update patches periodically. See Patch Management Procedure attached.
Yes. We regularly update our instance and make sure we follow security best practices. There is a process in place for regularly updating the servers and monitoring for latest updates across the entire stack.
We have implemented the Patch Management Procedure.
We follow the Change Management process to implement the compensatory control.
We follow the Change Management process.
Patches are updated on time.
Critical patches will be deployed immediately. High patches within 5 days. Medium patches within 15 days. Low within 25 days. Patch Management Procedure is attached.
Yes. We test patches before deploying in the production environment.
***
## Change Management
We have implemented the Change Management Procedure. All IT changes take place as per the Change Management Procedure.
Yes. Changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates.
Yes. Change management procedures are attached. We are compliant.
Yes. We have implemented the change management procedures, and this applies to all Xoxoday assets, infrastructure, processes, software, and third-party activities. The procedure also applies to employees, vendors, and all other individuals who have access to, or are responsible for Xoxoday information processing facilities.
Yes. Our production team and QA team test all new releases or changes made to the existing product.
Yes. We will notify the customer if there are any major changes.
Yes. Our customer support team will communicate.
***
## Antivirus & Endpoint Security
We have installed antivirus on all workstations and servers.
Yes. We have the controls in place. We have blocked connecting Hard disk, USB, CD-ROM, etc. to computers and all devices are centrally managed.
We use Bitdefender Endpoint security software to prevent malware and protect data. Additionally, we have AWS GuardDuty that continuously monitors for malicious activity and unauthorised behaviour. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory.
We use endpoint security for prevention.
We have an alerting system in place and we perform scanning immediately to reduce the risk.
We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc.
We maintain up-to-date endpoint security to safeguard from attack scripts, viruses, worms, Trojan horses, backdoors, and malicious active content.
We are using Linux operating systems and following security best practices. We are monitoring using Prometheus/Grafana.
We have installed endpoint security in servers and PCs of all our employees as per compliance requirements.
Yes. We update patches periodically and ensure that all endpoints have the latest available security-related patches.
We have all required security controls for protecting endpoints — VPN, Firewall, IDS/IPS, Anti-Virus software, Audit log monitoring, Active Directory, etc. We use a cloud-hosted VPN with strict access controls linked with SSO/Active Directory.
***
## SSO, Authentication & Integration
Yes. Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. Please refer to our list of integrations: [https://xoxoday.gitbook.io/plum/developer-resources/integrations](https://xoxoday.gitbook.io/plum/developer-resources/integrations)
Yes. The application has robust authentication methods. We have integrated SAML 2.0 with SAP SuccessFactors and also support OAuth 2.0 for seamless authentication.
API Documentation: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis)
Please click here to know more about API integration: [https://www.empuls.io/integrations](https://www.empuls.io/integrations)
The application enables user account management through API-based integration with the customer's HR management system. These APIs are used to access employee data to ensure users' accounts are created, updated, and disabled securely.
Please click here for API Documentation: [https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis)
We have implemented WAF, IDS/IPS, and Amazon GuardDuty for maximum security. OAuth 2.0 is used to authorize all API requests. We also conduct code reviews to make sure that the APIs are secure.
Yes. It supports SSO.
Our partnerships with a wide array of integration partners ensure existing customer-based SSO capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go.
Application Integrations: [https://www.application.io/integrations?tab=tab-collaborations](https://www.application.io/integrations?tab=tab-collaborations)
It's a web and mobile application.
Our partnerships ensure existing customer-based SSO capability for all users. Our identity federation standards include SAML 2.0, SPML, WS-Federation, and more as means of authenticating and authorizing users with airtight security protocol. Please visit: xoxoday.com/integrations
Yes. The application has robust authentication methods. We have integrated SAML 2.0 with SAP SuccessFactors and support OAuth 2.0 and Azure AD for seamless authentication.
We have an option to integrate with SSO and HRMS. For more info, please visit the link: [https://www.application.io/integrations](https://www.application.io/integrations)
Two standard reports are available for admins on SuccessFactors at the program level — Budget and Spot Award Nomination. Using People Analytics, customers can create their own reports and dashboards combining Spot Awards data from Recognition with data from across SuccessFactors. Admins can also access similar data via a Xoxoday logon.
Yes. Customers can extract data from SuccessFactors via Integration Center and integrate it with other third parties.
Somewhat. We have a Spot Award Approved event available via Intelligent Service Center on SuccessFactors which customers can use to build custom extensions.
User provisioning for SAP SuccessFactors — Reward and Recognition is handled the same way as the rest of SuccessFactors. For employees redeeming points via Xoxoday, user provisioning is done on the fly at the time of redeeming the awards.
***
## Third Party & Vendor Management
We make sure that they have adequate controls in place and meet the security standard.
We are managing the platform end to end.
Yes. Incident reporting obligations are passed on to all 3rd parties as well. All contracts and agreements are reviewed by the Legal Department.
We use Amazon CloudWatch and Grafana which monitor instances and alert us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
***
## Service, Support & Upgrades
It will be the responsibility of Xoxoday.
The process for upgrades is automated using Continuous Integration and Deployment. Since our services are delivered via the web, upgrades and updates are seamless and usually do not involve any actions from end-users.
Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
The process for upgrades is automated using CI/CD. We try to release product hotfixes once every week and major features once every month.
The process for upgrades is automated using CI/CD. Upgrades and updates are seamless. We try to release hotfixes once every week and major features once every month.
Product updates and feature enhancements are done periodically by the application team. These updates are available to all customers by default. The customer need not do anything from their end to update the product version as the application is hosted on AWS Cloud.
The time of support ranges between two to forty-eight hours. This depends on the level of service and the gravity of incidents.
We have Email Support and an application help center for helping users.
We will be providing training for the admin and the end user and also provide extensive support through our customer support team.
Yes. We have an Information security team and group of people with responsibility for security within the organization.
Yes. We fix the issues found at no cost. We understand that consumer data protection is a high priority. We have implemented a Bug Bounty Program and encourage the reporting of security issues. If any outsiders or customers report security-related issues, we fix them free of cost.
We have deployed our application on Amazon Web Services (AWS) cloud platform. We are using MySQL, Salt stack, Node.js, and MongoDB technology.
See the application high-level diagram of CI/CD attached.
See the following policies attached — Infrastructure Change Control Procedure, Patch Management Procedure, Information System Acquisition Development and Maintenance Procedure, SDLC Procedure, Threat and Vulnerability Management.
Please click here for more details: [https://help.empuls.io/](https://help.empuls.io/)
Payments are redirected to PayU gateway or PayPal websites to complete purchases securely. We are also implementing PCI DSS compliance controls and will provide the certification as soon as possible.
Approximately 2 weeks.
No installation. We are an out-of-the-box SaaS solution.
No recommendations as such. The application is a SaaS product supported by a comprehensive web application that can be accessed via desktop and mobile browsers on all compatible devices, including Android and iOS.
We have a multi-layered network architecture with role-based access control. All confidential/PII data is encrypted at rest with a split key mechanism to ensure that every client's key is unique. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.
Yes.
Yes.
Yes. We have deployed our application on AWS Virtual platform cloud. We use WAF, IDS/IPS, AWS Audit Trail, Amazon GuardDuty, etc.
Yes. Segregation is done for production and non-production environments.
The production center location will be Bangalore.
***
## Compliance Statements
Xoxoday would act as liaison partner between customer and merchants. We process the budgets which are approved by the customer. Xoxoday application is a SaaS Product.
The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests logs, they can be shared when asked by the clients.
It's a multi-tenant system. We use logical data isolation with the help of company-specific encryption keys and it is isolated from other customers' data.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. We provide these logs on a need and approval basis for forensic investigation. We can freeze data from a specific time without freezing other data if needed.
We are compliant. We have implemented the password management policy and follow the concept of least privilege. Only a limited number of approved users have privileged access. All access will be provided on a need and approval basis. We maintain a ticketing system to make sure that the appropriate process is followed.
We have implemented the Password Management Policy for maximum security of data.
We are compliant. The password will be changed every 90 days.
These are integrated with security operations/SIEM solutions.
We have a secure log-on process and are compliant with these requirements.
We have a secure log-off process and are compliant with these requirements.
Audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
We review architecture diagrams and data flow diagrams on a periodical basis. This is also validated during our internal and external independent audits.
We logically segregate the tenant's data, and it is segregated with a client-specific key for proper handling and security reasons.
We do not use any unsecured protocols.
All critical applications are reviewed and tested before deployment.
We have a separate test and production environment.
We monitor systems and network utilization.
We have implemented file integrity (host) and network intrusion detection (IDS) tools to help facilitate timely detection and investigation.
We make sure that we follow industry best practices, the PDCA cycle, and standards in order to safeguard the Information Security System.
All critical patches are applied rapidly.
We are a multi-tenant SaaS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis.
Yes. All critical patches will be deployed immediately. We ensure that our infrastructure is always using up-to-date systems.
We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data.
Compliant. We have deployed our application and database on separate servers.
Since the application is a SaaS Platform, this would not be applicable.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile application related logs are collected in our Elastic Search server and retained in long-term cloud storage. Administrative logs are part of the Cloud Dashboard and are regularly reviewed.
Yes. We logically segregate the tenant's data and the application.
WAF and rate limiters are installed to block multiple requests from specific IPs to prevent DDoS-type attacks.
Once the user logs out from the application, all pages, forms, and pop-ups will get closed.
We maintain logs and monitor on a regular basis for security reasons.
Compliant. We have resources to meet these requirements.
# DPDP Act
Source: https://help-plum.xoxoday.com/faq/security-compliance/certifications/dpdp-act
Learn about Plum's compliance with India's Digital Personal Data Protection (DPDP) Act and how it safeguards personal data.
*Learn more about Digital Personal Data Protection Act, 2023*
The Digital Personal Data Protection (DPDP) Act, 2023 governs the processing of digital personal data in India, emphasizing user consent, purpose limitation, and data accuracy. Enacted in August 2023 with rules effective from 2025, it applies to both online and offline data, protecting individual rights while allowing certain exceptions for the state.
The Digital Personal Data Protection Act, 2023 (DPDP Act) helps by protecting individuals' personal data and ensuring it is processed lawfully, transparently, and for specific purposes. It strengthens citizens' rights over their data while imposing clear obligations on organizations to prevent misuse and data breaches. This promotes trust, accountability, and responsible digital governance in India.
The complete assessment report can be shared through a proper Trust Center portal that provides controlled access and undergoes an NDA process before granting visibility.
Under the Digital Personal Data Protection Act, 2023, clients must clearly understand their role as Data Fiduciaries, while we act as a Data Processor supporting compliance. Only necessary personal data should be collected, processed for lawful purposes, and protected with reasonable security safeguards. Teams must ensure mechanisms exist to handle data principal rights (access, correction, erasure) and follow proper breach notification procedures. All responsibilities, security commitments, and data handling terms should be clearly defined in contracts.
Feedback or Questions? Write to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Certifications and Compliance
Source: https://help-plum.xoxoday.com/faq/security-compliance/certifications/others-documents
Access additional compliance certifications and supporting documentation available for Plum beyond the core certifications.
[Open document](https://drive.google.com/file/d/10gHjDefPzKBB3EC1BPHZ4SbqpcluKLjw/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1LyE7ogFTxdbUiaSLBOYaMbFxsvXbuI3v/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1gIJySTLQSSWGoeF3P8ukvr3xZhMGGePY/view?usp=sharing)
[Open document](https://drive.google.com/file/d/161zus2TDtFeoIshMKAdKe8FDDGf_aaq0/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view?usp=sharing)
[Open document](https://drive.google.com/file/d/16ICZUl9dbFC-PGHaU2jj49rzs0jzi_-S/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1dWf4on16eN2MebO7fNDFMuUJDp0CR1hW/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1K1zwc6qEjgYu4I8qYJcxBuPgsiPgtLnP/view?usp=sharing)
# Cloud Security
Source: https://help-plum.xoxoday.com/faq/security-compliance/cloud-security
Find answers to frequently asked questions about the cloud security infrastructure and safeguards protecting the Plum platform.
We have deployed our application on AWS Virtual platform cloud - Singapore and USA region.
Data Security Architecture designed using an industry standard and best practices. We are adhered to CSA, ISO 27001, SOC 2 TSP. We have deployed our application on AWS Virtual platform cloud - Singapore region. The cloud infrastructure providers have high levels of physical and network security and hosting provider vendor diversity.
All our customer data is stored on AWS Virtual platform cloud. And we collect the data only throguh our application platform. We do not store any customers data locally.
File integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation.
AWS CloudTrail helps to detect changes to the build/configuration of the virtual machine
Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands.
We use Web application firewall (WAF) and pfSense firewall for security reasons. 1. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. 2. pfSense helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules
We isolate our machines, network and storage with respect to the AWS Standards in order to keep it safe and secure.
We use Web application firewall (WAF) and pfSense firewall for security reasons.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
Yes. We monitor the compliance programs of AWS As we have stored the data on their cloud.
No. Currently, all the data is stored on AWS VPC - Singapore region.
Yes, we inform the customer on the data storage location.
We are CSA STAR Level 1 compliant. Please click here to know more - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday)
We use OWASP Software Assurance Maturity Model
Since we have deployed our application on AWS Cloud its not applicable for us.
Since we have deployed our application on AWS Cloud its not applicable for us. We provide certifite of destruction of data once the data is purged/deleted from all the places upon request from the customer.
We have deployed our product on AWS Cloud virtual platform. AWS provides physical security to the data center as a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/)
We have implemented IDS/IPS to facilitate timely detection, investigation by root cause analysis and response to incidents
Data backups are done on daily basis and in a secured way on AWS
Data backups are done on daily basis and in a secured way on AWS - Singapore
Data backups are done on daily basis and in a secured way on AWS. This has been tested on regular basis.
Applies to all.
We have deployed our application on AWS cloud virtual platform and the data is stored on it. Only approved users will have an access and We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory.
We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it's a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/)
Yes. We have deployed our application on AWS cloud virtual platform for maximum security.
Yes. Its deployed on AWS cloud virtual platform.
The application is deployed on AWS cloud virtual platform. We maintain the register for hardwares, softwares, physical assets etc as per the Asset management policy. All the inventories are reviewed and updated on monthly basis. We have tagged the owners for all the assets alloted by the organization. Atatched the asset management policy.
Our application is deployed on AWS cloud virtual platform. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
We use AWS Platform for storing the data. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records.
Yes
We have deployed our application on AWS Cloud platform.As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks.
Yes. We comply with this.
We monitor the user activities and spread awareness about data storage, access, sharing etc. All the custoer data is stored on AWS cloud. We are not storing any information on the computers.
Data backups are done daily and in a secured way in AWS
Yes. We have implemented the Backup Recovery Procedure
Yes. Data backups are done daily and in a secured way in AWS
We do not use the backup. We only take the backup on AWS and its stored on AWS platform itself.
Its hosted on AWS
BCP and DR facilities has been provided by AWS. We do not have any other data centers
Since we are hosting our application on AWS, they are providing us a service for backup, BCP and DR for seamless customer experience.
Since we are hosting our application on AWS, they are providing us a service for backup, BCP and DR for seamless customer experience.
Amazon web service (AWS)
AWS Virtual platform cloud And AWS MSK
99.00%
Yes. Xoxoday or AWS does not share the data.
We have deployed the application on AWS and we have the controls in place to destruction upon request or post the retention timeframe. Since we are GDPR compliant we provide this option to our end users.
We have deployed the application on AWS Singpore.
Data backup and retrieval happens on AWS platform.
We use Public cloud for hosting
we have an intrusion detection/monitoring application that alerts on unauthorized access.
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails.
We have deployed the application on cloud and have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour.
Its provided by AWS, it's a part of AWS service.
Please click here for more details about AWS Compliance Programs - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
It will be hosted on AWS singapore
Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
Data backups are done on daily basis and in a secured way in AWS. We monitor the same.
We collect, store and process Name, email ID and Phone numbers and it will be stored on AWS cloud and will be deleted upon termination of the contract.
AWS Singapore
[Xoxoday application is a SaaS product deployed on AWS Virtual platform cloud. Please click to know more about application - https://xoxoday.gitbook.io/application/](https://xoxoday.gitbook.io/plum/)
We have deployed our application on AWS virtual platform cloud and do not store any data outside cloud for security reasons. All the customer data is encrypted for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest
Yes. We have the backup for power supply and computer systems can be used without any interruption. We have applied the lightning protection metallic rods for the buidling for protection of premises.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. All the workstations are part of the Active directory. User accounts get locked after 15 minutes of inactivity. The accounts will get locked after the predetermined unauthorised attempts for security reasons.
Yes, our web assets, email records, and end-points are sealed with data loss prevention techniques. All the customer data will be stored on only AWS virtual platform cloud. We do not store it offline for security reasons. AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. The data is stored in our secure database and is transit scrambled for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. logs are automatically audited, but are not integrated with tenant's security operations. In case the tenant requests for logs, they can share when asked by the clients.
Attached the Infrastructure Change Control Procedure
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests for logs, they can shared when asked for by the clients.
The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests for logs, they can shared when asked for by the clients.
The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests for logs, they can shared when asked for by the clients.
We retain the logs for at least 180 days.
AWS is one of the critical third party for us as we have deployed our application on AWS VPC. AWS is ISO 27001 and SOC 2 certified organization and compliant with the business continnuity requirements.
Xoxoday application application has deployed on AWS Cloud virtual platform for securtity reasons and imlemented the business continuity plan. Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Business day will be considered as 24\*7 and will be available for 365 days in a year for the customer support services to be provided to the Client
The data will be stored on AWS Virtual platform cloud – Singapore region.
The personal data will be uploaded on application application for rewards and recognition purposes and will be stored on AWS virtual platform cloud.
We have deployed our application on AWS Virtual platform cloud. We do not have physical access to the location where the personal data is stored.
We have deployed our application on AWS Virtual platform cloud. We have the physical access controls in place. For ex – Access cards, Biometric machines, ID cards, CCTV etc..
The personal information will be collected through application platform and stored on AWS virtual platform cloud – Singapore region.
We have only one data center and deployed our application of AWS virtual platform cloud. By Default, Xoxoday will not have access to Service Data (customer's account/application and the associated data processed as part of using our services). The access control to the accounts (who can access the application instance) is managed by the admin from the customer end.
We use Public cloud for hosting (AWS Singapore)
AWS Virtual Platform Cloud - Singapore region.
We have deployed our application on AWS Virtual platform cloud and Xoxoday is GDPR certified. We have implemented the policies and procedures as per the ISMS and GDPR and implemented across the organization. We collect only three PIIs on our platform such as - Name, email ID and phone number. Xoxodau GDPR - [https://www.xoxoday.com/gdpr](https://www.xoxoday.com/gdpr) Xoxoday Privacy - [https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/privacy-policy)
Yes. We have deployed our product on AWS virtual platform cloud.
The data backups are done on AWS Virtual platform cloud on regular basis and implemeted the Data loss prevention techniques. We have all the capabilities to recover the data or restore. Data is available for restore within a few minutes of a backup job completing on the daily schedule. Attached the Backup Recovery Procedure
AWS is responsible for providing physical security to the data center as we have deployed our application on AWS. AWS provides physical data center access only to approved employees. All employees who need data center access must first apply for access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. Requests are reviewed and approved by authorized personnel, and access is revoked after the requested time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Third-party access is requested by approved AWS employees, who must apply for third-party access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. These requests are approved by authorized personnel, and access is revoked after request time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Anyone granted visitor badge access must present identification when arriving on site and are signed in and escorted by authorized staff.
We have deployed our application on AWS Virtual platform cloud. Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. We make these logs available upon tenents request.
We make these logs available upon tenents request
The logs are collected using the AWS Audit Trail and application related logs are collected in our Elastic Search server.
AWS Cloud virtual platform.
Its on AWS cloud virtual platform.
We have deployed our product on AWS Cloud virtual platform.
We do not connect to the customer network. Since it's a SaaS prodcut and deployed on cloud virtual platform only authorised individual have an access to the our production environment on need and approval basis.
We have implemented the security measures to manage the risks introduced during the use of Organization's information assets used for managing Personally Identifiable Information. Attached the Personally Identifiable Information (PII) Policy.
We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it's a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/)
We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it's a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/)
We have deployed our application on AWS Virtual platform cloud. We use Web application firewall, IDs/IDs, AWS Audit trail, Amazon guard duty etc..
Yes. Data backups are done on daily basis in a secured way in AWS
Yes.
Yes.
Its on AWS Cloud virtual platform Cloud.
Yes
The data will be stored on AWS cloud virtual platform Singapore. Since we are a multi tenant system, we have common infrastructure for all clients.But All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment.
We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates.
We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates.
We have deployed our application on AWS cloud virtual platform.
We have deployed our application on AWS cloud virtual platform.
Data storage location will be AWS Singapore.
Data backups are done on daily and in a secured way in AWS. Attached the Backup Recovery Procedure.
We have deployed our application on AWS Virtual platform cloud - Singapore and we operate from our corporate office located in Bangalore, India.
We have deployed our application on AWS Virtual platform cloud - Singapore region and all the data will be stored there. All the end users from various parts in the world can access the platform. We inform the customer if we need to change the data center location.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. pfSense generation firewall helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules We also have implemented the IDS/IPS and Amazon guard duty which continuously monitors our AWS accounts and workloads for malicious activity and delivers detailed security findings for visibility and remediation.
We have implemented the data backup policy and attached the same. The data backups are done daily in a secured way in AWS and tested on weekly basis.These backup process are automated and does not require any mannual effort. Since we are SAAS product, we maintain backup and restore all the customer data by ourselves. We use AES 256 encryption for data at rest. All the backups are stored on Cloud and does not store any data off-cloud.
NA. We have deployed our application on AWS Virtual platform cloud.
We have deployed our application on AWS Virtual Platform cloud. application is a cloud based application. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
We have tools that analyze various traffic patterns and correlate network events. We have configured early warning signals that trigger alerts to our team based on event patterns and strict thresholds. We are equipped to detect and mitigate Threats, DDOS attacks, session hijack, login spoofs or any other data extraction strategies AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. The data is stored in our secure database and is transit scrambled for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest. We also conduct periodical Vulnerability assessment and penetration testing and fixes the vulnerabilities identified in order to eliminate the risk.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. We use a synchronized time-service protocol (e.g., NTP) to ensure all systems have a common time reference
Yes, systems must be configured to log all successful and unsuccessful login attempts by accounts with privileged access. These authentication logs must be retained for a minimum of 180 days and in accordance with the Company's records retention guidelines.
We use logical data isolation with the help of company specific encryption keys and its solated from other customers data. Yes, audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
The data backups are done daily in a secured way on AWS and tested on a weekly basis. These backup processes are automated and do not require any manual effort. Since the data backup is automated and happening on a daily basis the data backup will get replaced every day and restored, if necessary/required.
Yes, AWS is certified under the EU-US Privacy Shield. [https://www.privacyshield.gov/participant?id=a2zt0000000TOWQAA4](https://www.privacyshield.gov/participant?id=a2zt0000000TOWQAA4)
All the data will be stored on AWS cloud virtual platform cloud - Singapore region.
All user activities are logged in the audit trail.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks
We use Web application firewall, IDs/Ips, AWS Audit trail, Amazon guard duty etc..
We have a dedicated non-production environment which is in a different AWS account and allows us to segregate data from the production environment.
We have implemented the Backup Recovery Procedure to protect the organization information asset from the damages that may be caused due to failure of hardware system, corruption of software etc..
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. The event logs are stored in a bucket wherein nobody can access them without an approval from the high authorities i.e. the Chief Technical Officer. In case the tenant requests for logs, that can be shared.
At present, application application has been deployed on AWS Virtual platform cloud.
[This is not feasible. AWS is compliant to the Singapore Data Privacy Regulations. https://aws.amazon.com/compliance/singapore-data-privacy/](https://aws.amazon.com/compliance/singapore-data-privacy/)
All the data will be stored on AWS Singapore
All the data will be collected only through our application and stored on AWS cloud platform and its situated in Singapore.
All the data will be stored on AWS Singapore
We are cloud security alliance level 1 compliant. We would be happy to help NSE for checking the integrity and security of the cloud computing services and compliance to applicable policies and regulations.
We agreee. We comply with CSA STAR Level 1 compliance requirements.
We comply with this. We have deployed our application on AWS to ensure maximum security of data.
We agree. We combine enterprise-class security features with comprehensive audits of our applications, systems, and networks to ensure customer and business data is always protected. And our customers rest easy knowing their information is safe, their interactions are secure, and their businesses are protected. We do conduct internal and external audits and ensure that required remidiations are implemented.
The data is hosted on Amazon Web Services (AWS) For accurate latency, the data center is selected as Singapore region for Asia specific data and Oregon for US specific data which are defined as data centers.
The Xoxoday platform operates on the cloud, which means there are no removable storage devices in question. We have Media protection procedure to handle the locally stored data. We complied with the compliance requirements.
We do not take any data directly. The data will be provided through our platform or application and its hosted on Amazon Web Services (AWS)
We rely on AWS Cloud for Uptime mesurement.
Yes. We have deployed our application on AWS cloud platform
Yes. Please visit here for more details about AWS Cloud Security - [https://aws.amazon.com/security/](https://aws.amazon.com/security/)
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails We have implemented IDS/IPS Firewall. Our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting.
We predominantly work on cloud-based infrastructure from Amazon Web Services which provide backup and restore services to build scalable, durable, and secure data-protection solutions Please refer to AWS site for more details: [https://aws.amazon.com/backup-restore/](https://aws.amazon.com/backup-restore/)
It will be stored on AWS, and It will be encrypted (AES 256-bit encryption)
Yes. We have implemented IDS/IPS Firewall. Our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting.
The only user data that will stored within the system is employee personal information - names, emails and contact numbers. Infrastructure logs are collected using AWS Audit Trail
Please visit for more details - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/)
Our application is deployed on AWS cloud platform.
We are Compliant. We have implemented the data backup policy. We do take backup of the all the users and securely stored. All our application users data back up including password will happen through AWS cloud virtual platform.
We have controls in place. We have implemented the firewall and IDS/IPS for detection and prevention of security.
During the testing phase we make sure that we are meeting all the security requesrements and validate the same before the deployment.
All the data will be stored on AWS cloud and encrypted with Client specific keys. We do not transfer data to any external drives or media devices.
We monitor these logs periodically
Backup data is stored on AWS cloud for maximum security.
We test the backup on a periodical basis to make sure that we follow the availability and integrity principles.
We have documented our Data backup procedures.
We monitor the logs as per the compliance requirements.
We are compliant.
All the logs are recorded in the system.
We always make sure that componentory controls in place if monitoring is not feasible.
We have deployed our application on AWS cluod virtual platform
It's a part of cloud security services
It's a part of cloud security services
Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
The data is only stored on our application and its deployed on AWS Cloud. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records
We have deployed our application on Amaon web services (AWS) cloud platform. We are using MySQL, Salt stack, Nodejs and MongoDB technology. LDAP, SAML2, Normal username-password
We are a SAAS solution. We are cloud hosted.
We are a SAAS Solution and have all the capabilities to supoprt huge number of users.
Data center services are provided by AWS
Data backups are done daily and in a secured way in AWS
No. Application is deployed on AWS Cloud.
We have both horizontal and Vertical Scaling
We have auto scaling and self healing.
We use a variety of tools and plugins integrated with Prometheus & Cloudwatch along with health checks for facilitating our uptime/service availability
AWS Cloud virtual platform
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails
Yes. We have deployed our application on AWS virtual platform cloud. And we have the process in place to handle or manage any contingent events or circumstances. We have implemented the Business continuity management and tested annually to validate the effectiveness of the controls. Attached the Business continuity management plan.
We have an Admin/Facility department who is responsible and manage the Physical security and we have provided the access cards to all the employees and visitors and installed biometric machines at all the entry and exit areas. We have also installed the CCTV cameras in our building and will be monitored 24\*7 for maximum security. AWS Data centre physical security – We have deployed our application product on AWS virtual platform cloud. Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff utilizing video surveillance, intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication a minimum of two times to access data center floors. All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff. AWS only provides data center access and information to employees and contractors who have a legitimate business need for such privileges. When an employee no longer has a business need for these privileges, access is immediately revoked, even if they continue to be an employee of Amazon or Amazon Web Services. All physical access to data centers by AWS employees is logged and audited routinely.
PII will be entered through application and stored it on AWS cloud virtual platform. We store Name, email ID and phone number of the users.
Reports can be generated by the admins through the application. If there are any additional support needed, our customer support team would be able to help and guide on generating report.
The data will be stored on AWS Cloud and we do not share or transfer the data
Xoxoday is CSA STAR LEVEL 1 Compliant. Please click here to download CAIQ - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday/services/nreach-online-services-pvt-ltd-xoxoday/](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday/services/nreach-online-services-pvt-ltd-xoxoday/)
We have deployed our application on AWS Virtual platform cloud – Singapore region.
Not Applicable. We have not outsourced.
We have deployed our application on AWS Cloud virtual platform for maximum security. The data center is hosted completely in isolation so that the access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load experienced by application. We have implemented Amazon Cloud watch to enable monitoring of the functioning of the application. The data is encrypted using 256-encryption based SSL certificate. To manage security of data we conduct a quarterly VAPT based security audit of application.
Yes, all the mechanisms related to security are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools.
We have implemented the Patch management procedures. Critical patches will be deployed immediately High patches will get deployed within 5 days Medium Patches will get deployed within 15-day Low will get deployed in 25 days.
Yes. Since it's a SAAS Product we do not charge any additional cost.
We have a team of 15+ who works for improving our solution security. We conduct periodical Vulnerability assessment and Penetration testing with the help of the Authorized third-party vendors and Fix the observations found during the testing in order to mitigate the risk. Our team is based out of Bangalore location.
Yes. Our SAAS solution has been deployed on AWS cloud virtual platform.
Its SAAS Product and implemented the security controls in order to provide secure services and make sure that the customer data is protected.
We have deployed our application on AWS Cloud platform for maximum security. The data will be provided through our platform or application and its hosted-on Amazon Web Services (AWS) Our solution is very easy to use with convenient security features.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team, and it's linked with the SSO/Active Directory
We have deployed our application on AWS Cloud virtual platform. AWS is met all the data center compliance requirements.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory We have implemented intrusion detection tools, we ensure timely detection and investigation in a prompt manner. File integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation. We also have Endpoint security software for all the computers for Protection from exploits, malicious web downloads and softwares, Application and device control etc.
We have deployed the application application on AWS Cloud platform.
The data center is in the Singapore region
We have deployed our application on AWS cloud virtual platform. but, We have not outsourced any of services and third party will not have access to FINCARE data.
Yes. We monitor their compliance, security standards, certifications and Audit Etc.
[We have deployed our application on AWS cloud virtual platform. AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
All the data will be provided through the application and it will be stored on AWS cloud virtual platform. We use Cloudflare web application firewall for maximum security. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. Attached the application data flow diagram
We have the security controls in place. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory. Attached the Network Access Control and Security Procedure.
Yes. we have installed Bitdefender end point security in all the devices for maximum security and have controls on Anti-Virus / Malicious Software throgh End point security. We have also enabled Network Threat Prevention, Advanced Threat Defense, Web Attack Prevention, Multi-Layer Ransomware Protection. Attached the sample screenshot of Bitdefender end point security.
The application is deployed on AWS Virtual platform cloud - Singapore region.
application application is deployed on AWS virtual platform cloud and storgae and scaling up would not be a challenge.
Data backups are automated and done daily and in a secured way on AWS. The data at rest in encrypted only authorised individuals (CT0/Production head) will have access to protect the confidentiality, integrity, and availability of the information. These data backups are reviewed on weekly basis and has been validated during the internal and external audits.
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed.
Yes, audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed.
We have deployed our applicaiton on AWS Virtual platform cloud. We do not use any unauthorised applications accross the organization as per the Information security policy.
At Xoxoday the test environment and production environment has been seperated. We have dedicated non-production environment which is in different AWS account and allowing us to segregate data of production environment.
we use Cloudflare Web application firewall (WAF), AWS Guard Duty threat detection service, Amazon CloudWatch, IDS/IPS etc.. for maximum security of data.
Compliant. We do not allow un-trusted and un-validated inputs and attacker cannot insert malicious data and false entries into the logs.
We do not share the source code. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase.
At Xoxday the source code is restricted to only the authorised individuals
Yes. Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands.
We have deployed our application on AWS Cloud virtual platform and all the data is stored on AWS. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client's key is unique. We use TLS1.3 encryption while data in transit and AES256 while data at rest.
we use Amazon Web Services (AWS) as our Communication service provider. We review the adequate security governance periodicall to make sure that they are also complied with all the Security and Privacy compliance requirements.
We are the Data processor. application is GDPR compliant. At Xoxoday, we ensure that the data is gathered, stored, and handled with respect to individual rights.
The audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
At Xoxoday Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
The backup is automated and happen on AWS on regular basis.
We have deployed our application on AWS Virtual platform cloud - Singapore region.
The application and database server are hardened.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
We have deployed our application on AWS Virtual platform cloud - Singapore region. All the application data is stored there on AWS - Singapore.
We use third party to provide necessary services to the organization on need and approval basis. For ex – Background verification vendor, VA/PT authorised third party vendor, Eternal Auditors, AWS Virtual platform cloud service providers, Google workspace etc
We predominantly work on cloud-based infrastructure - Amazon Web Services which provides the Backup and Restore services to build scalable, durable, and secure data-protection solutions. No limits.
Data backups are done daily and in a secured way in AWS. And Our team review the same on regular basis.
Data backups are done on daily basis and in a secured way in AWS. We have the mechanism in place to delete the data upon termination of the contract upon customer request. In addition to safeguarding the rights of data subjects under the GDPR, we have implemented the Data Retention and Disposal Policy ensuring that excessive amounts of data are not retained by us.
We have deployed our application on AWS Virtual platform cloud and they provide these services.
We have deployed our application on AWS Virtual platform cloud - Singapore and USA region.
Data Security Architecture designed using an industry standard and best practices. We are adhered to CSA, ISO 27001, SOC 2 TSP. We have deployed our application on AWS Virtual platform cloud - Singapore region. The cloud infrastructure providers have high levels of physical and network security and hosting provider vendor diversity.
All our customer data is stored on AWS Virtual platform cloud. And we collect the data only throguh our application platform. We do not store any customers data locally.
File integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation.
AWS CloudTrail helps to detect changes to the build/configuration of the virtual machine
Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands.
We use Web application firewall (WAF) and pfSense firewall for security reasons. 1. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. 2. pfSense helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules
We isolate our machines, network and storage with respect to the AWS Standards in order to keep it safe and secure.
We use Web application firewall (WAF) and pfSense firewall for security reasons.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
Yes. We monitor the compliance programs of AWS As we have stored the data on their cloud.
No. Currently, all the data is stored on AWS VPC - Singapore region.
Yes, we inform the customer on the data storage location.
We are CSA STAR Level 1 compliant. Please click here to know more - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday)
We use OWASP Software Assurance Maturity Model
Since we have deployed our application on AWS Cloud its not applicable for us.
Since we have deployed our application on AWS Cloud its not applicable for us. We provide certifite of destruction of data once the data is purged/deleted from all the places upon request from the customer.
We have deployed our product on AWS Cloud virtual platform. AWS provides physical security to the data center as a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/)
We have implemented IDS/IPS to facilitate timely detection, investigation by root cause analysis and response to incidents
Data backups are done on daily basis and in a secured way on AWS
Data backups are done on daily basis and in a secured way on AWS - Singapore
Data backups are done on daily basis and in a secured way on AWS. This has been tested on regular basis.
Applies to all.
We have deployed our application on AWS cloud virtual platform and the data is stored on it. Only approved users will have an access and We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory.
We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it's a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/)
Yes. We have deployed our application on AWS cloud virtual platform for maximum security.
Yes. Its deployed on AWS cloud virtual platform.
The application is deployed on AWS cloud virtual platform. We maintain the register for hardwares, softwares, physical assets etc as per the Asset management policy. All the inventories are reviewed and updated on monthly basis. We have tagged the owners for all the assets alloted by the organization. Atatched the asset management policy.
Our application is deployed on AWS cloud virtual platform. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
We use AWS Platform for storing the data. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records.
Yes
We have deployed our application on AWS Cloud platform.As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks.
Yes. We comply with this.
We monitor the user activities and spread awareness about data storage, access, sharing etc. All the custoer data is stored on AWS cloud. We are not storing any information on the computers.
Data backups are done daily and in a secured way in AWS
Yes. We have implemented the Backup Recovery Procedure
Yes. Data backups are done daily and in a secured way in AWS
We do not use the backup. We only take the backup on AWS and its stored on AWS platform itself.
Its hosted on AWS
BCP and DR facilities has been provided by AWS. We do not have any other data centers
Since we are hosting our application on AWS, they are providing us a service for backup, BCP and DR for seamless customer experience.
Since we are hosting our application on AWS, they are providing us a service for backup, BCP and DR for seamless customer experience.
Amazon web service (AWS)
AWS Virtual platform cloud And AWS MSK
99.00%
Yes. Xoxoday or AWS does not share the data.
We have deployed the application on AWS and we have the controls in place to destruction upon request or post the retention timeframe. Since we are GDPR compliant we provide this option to our end users.
We have deployed the application on AWS Singpore.
Data backup and retrieval happens on AWS platform.
We use Public cloud for hosting
we have an intrusion detection/monitoring application that alerts on unauthorized access.
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails.
We have deployed the application on cloud and have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour.
Its provided by AWS, it's a part of AWS service.
Please click here for more details about AWS Compliance Programs - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
It will be hosted on AWS singapore
Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
Data backups are done on daily basis and in a secured way in AWS. We monitor the same.
We collect, store and process Name, email ID and Phone numbers and it will be stored on AWS cloud and will be deleted upon termination of the contract.
AWS Singapore
[Xoxoday application is a SaaS product deployed on AWS Virtual platform cloud. Please click to know more about application - https://xoxoday.gitbook.io/application/](https://xoxoday.gitbook.io/plum/)
We have deployed our application on AWS virtual platform cloud and do not store any data outside cloud for security reasons. All the customer data is encrypted for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest
Yes. We have the backup for power supply and computer systems can be used without any interruption. We have applied the lightning protection metallic rods for the buidling for protection of premises.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. All the workstations are part of the Active directory. User accounts get locked after 15 minutes of inactivity. The accounts will get locked after the predetermined unauthorised attempts for security reasons.
Yes, our web assets, email records, and end-points are sealed with data loss prevention techniques. All the customer data will be stored on only AWS virtual platform cloud. We do not store it offline for security reasons. AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. The data is stored in our secure database and is transit scrambled for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. logs are automatically audited, but are not integrated with tenant's security operations. In case the tenant requests for logs, they can share when asked by the clients.
Attached the Infrastructure Change Control Procedure
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests for logs, they can shared when asked for by the clients.
The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests for logs, they can shared when asked for by the clients.
The logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests for logs, they can shared when asked for by the clients.
We retain the logs for at least 180 days.
AWS is one of the critical third party for us as we have deployed our application on AWS VPC. AWS is ISO 27001 and SOC 2 certified organization and compliant with the business continnuity requirements.
Xoxoday application application has deployed on AWS Cloud virtual platform for securtity reasons and imlemented the business continuity plan. Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Business day will be considered as 24\*7 and will be available for 365 days in a year for the customer support services to be provided to the Client
The data will be stored on AWS Virtual platform cloud – Singapore region.
The personal data will be uploaded on application application for rewards and recognition purposes and will be stored on AWS virtual platform cloud.
We have deployed our application on AWS Virtual platform cloud. We do not have physical access to the location where the personal data is stored.
We have deployed our application on AWS Virtual platform cloud. We have the physical access controls in place. For ex – Access cards, Biometric machines, ID cards, CCTV etc..
The personal information will be collected through application platform and stored on AWS virtual platform cloud – Singapore region.
We have only one data center and deployed our application of AWS virtual platform cloud. By Default, Xoxoday will not have access to Service Data (customer's account/application and the associated data processed as part of using our services). The access control to the accounts (who can access the application instance) is managed by the admin from the customer end.
We use Public cloud for hosting (AWS Singapore)
AWS Virtual Platform Cloud - Singapore region.
We have deployed our application on AWS Virtual platform cloud and Xoxoday is GDPR certified. We have implemented the policies and procedures as per the ISMS and GDPR and implemented across the organization. We collect only three PIIs on our platform such as - Name, email ID and phone number. Xoxodau GDPR - [https://www.xoxoday.com/gdpr](https://www.xoxoday.com/gdpr) Xoxoday Privacy - [https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/privacy-policy)
Yes. We have deployed our product on AWS virtual platform cloud.
The data backups are done on AWS Virtual platform cloud on regular basis and implemeted the Data loss prevention techniques. We have all the capabilities to recover the data or restore. Data is available for restore within a few minutes of a backup job completing on the daily schedule. Attached the Backup Recovery Procedure
AWS is responsible for providing physical security to the data center as we have deployed our application on AWS. AWS provides physical data center access only to approved employees. All employees who need data center access must first apply for access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. Requests are reviewed and approved by authorized personnel, and access is revoked after the requested time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Third-party access is requested by approved AWS employees, who must apply for third-party access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. These requests are approved by authorized personnel, and access is revoked after request time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Anyone granted visitor badge access must present identification when arriving on site and are signed in and escorted by authorized staff.
We have deployed our application on AWS Virtual platform cloud. Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. We make these logs available upon tenents request.
We make these logs available upon tenents request
The logs are collected using the AWS Audit Trail and application related logs are collected in our Elastic Search server.
AWS Cloud virtual platform.
Its on AWS cloud virtual platform.
We have deployed our product on AWS Cloud virtual platform.
We do not connect to the customer network. Since it's a SaaS prodcut and deployed on cloud virtual platform only authorised individual have an access to the our production environment on need and approval basis.
We have implemented the security measures to manage the risks introduced during the use of Organization's information assets used for managing Personally Identifiable Information. Attached the Personally Identifiable Information (PII) Policy.
We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it's a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/)
We have deployed our application on AWS cloud virtual platform. AWS provides physical security to the data center and it's a part of our subscription. AWS physical security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/)
We have deployed our application on AWS Virtual platform cloud. We use Web application firewall, IDs/IDs, AWS Audit trail, Amazon guard duty etc..
Yes. Data backups are done on daily basis in a secured way in AWS
Yes.
Yes.
Its on AWS Cloud virtual platform Cloud.
Yes
The data will be stored on AWS cloud virtual platform Singapore. Since we are a multi tenant system, we have common infrastructure for all clients.But All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment.
We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates.
We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates.
We have deployed our application on AWS cloud virtual platform.
We have deployed our application on AWS cloud virtual platform.
Data storage location will be AWS Singapore.
Data backups are done on daily and in a secured way in AWS. Attached the Backup Recovery Procedure.
We have deployed our application on AWS Virtual platform cloud - Singapore and we operate from our corporate office located in Bangalore, India.
We have deployed our application on AWS Virtual platform cloud - Singapore region and all the data will be stored there. All the end users from various parts in the world can access the platform. We inform the customer if we need to change the data center location.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. pfSense generation firewall helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules We also have implemented the IDS/IPS and Amazon guard duty which continuously monitors our AWS accounts and workloads for malicious activity and delivers detailed security findings for visibility and remediation.
We have implemented the data backup policy and attached the same. The data backups are done daily in a secured way in AWS and tested on weekly basis.These backup process are automated and does not require any mannual effort. Since we are SAAS product, we maintain backup and restore all the customer data by ourselves. We use AES 256 encryption for data at rest. All the backups are stored on Cloud and does not store any data off-cloud.
NA. We have deployed our application on AWS Virtual platform cloud.
We have deployed our application on AWS Virtual Platform cloud. application is a cloud based application. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
We have tools that analyze various traffic patterns and correlate network events. We have configured early warning signals that trigger alerts to our team based on event patterns and strict thresholds. We are equipped to detect and mitigate Threats, DDOS attacks, session hijack, login spoofs or any other data extraction strategies AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. The data is stored in our secure database and is transit scrambled for maximum security. We use TLS1.3 encryption while data in transit and AES256 while data at rest. We also conduct periodical Vulnerability assessment and penetration testing and fixes the vulnerabilities identified in order to eliminate the risk.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. We use a synchronized time-service protocol (e.g., NTP) to ensure all systems have a common time reference
Yes, systems must be configured to log all successful and unsuccessful login attempts by accounts with privileged access. These authentication logs must be retained for a minimum of 180 days and in accordance with the Company's records retention guidelines.
We use logical data isolation with the help of company specific encryption keys and its solated from other customers data. Yes, audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
The data backups are done daily in a secured way on AWS and tested on a weekly basis. These backup processes are automated and do not require any manual effort. Since the data backup is automated and happening on a daily basis the data backup will get replaced every day and restored, if necessary/required.
Yes, AWS is certified under the EU-US Privacy Shield. [https://www.privacyshield.gov/participant?id=a2zt0000000TOWQAA4](https://www.privacyshield.gov/participant?id=a2zt0000000TOWQAA4)
All the data will be stored on AWS cloud virtual platform cloud - Singapore region.
All user activities are logged in the audit trail.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks
We use Web application firewall, IDs/Ips, AWS Audit trail, Amazon guard duty etc..
We have a dedicated non-production environment which is in a different AWS account and allows us to segregate data from the production environment.
We have implemented the Backup Recovery Procedure to protect the organization information asset from the damages that may be caused due to failure of hardware system, corruption of software etc..
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long term cloud storage. The event logs are stored in a bucket wherein nobody can access them without an approval from the high authorities i.e. the Chief Technical Officer. In case the tenant requests for logs, that can be shared.
At present, application application has been deployed on AWS Virtual platform cloud.
[This is not feasible. AWS is compliant to the Singapore Data Privacy Regulations. https://aws.amazon.com/compliance/singapore-data-privacy/](https://aws.amazon.com/compliance/singapore-data-privacy/)
All the data will be stored on AWS Singapore
All the data will be collected only through our application and stored on AWS cloud platform and its situated in Singapore.
All the data will be stored on AWS Singapore
We are cloud security alliance level 1 compliant. We would be happy to help NSE for checking the integrity and security of the cloud computing services and compliance to applicable policies and regulations.
We agreee. We comply with CSA STAR Level 1 compliance requirements.
We comply with this. We have deployed our application on AWS to ensure maximum security of data.
We agree. We combine enterprise-class security features with comprehensive audits of our applications, systems, and networks to ensure customer and business data is always protected. And our customers rest easy knowing their information is safe, their interactions are secure, and their businesses are protected. We do conduct internal and external audits and ensure that required remidiations are implemented.
The data is hosted on Amazon Web Services (AWS) For accurate latency, the data center is selected as Singapore region for Asia specific data and Oregon for US specific data which are defined as data centers.
The Xoxoday platform operates on the cloud, which means there are no removable storage devices in question. We have Media protection procedure to handle the locally stored data. We complied with the compliance requirements.
We do not take any data directly. The data will be provided through our platform or application and its hosted on Amazon Web Services (AWS)
We rely on AWS Cloud for Uptime mesurement.
Yes. We have deployed our application on AWS cloud platform
Yes. Please visit here for more details about AWS Cloud Security - [https://aws.amazon.com/security/](https://aws.amazon.com/security/)
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails We have implemented IDS/IPS Firewall. Our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting.
We predominantly work on cloud-based infrastructure from Amazon Web Services which provide backup and restore services to build scalable, durable, and secure data-protection solutions Please refer to AWS site for more details: [https://aws.amazon.com/backup-restore/](https://aws.amazon.com/backup-restore/)
It will be stored on AWS, and It will be encrypted (AES 256-bit encryption)
Yes. We have implemented IDS/IPS Firewall. Our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting.
The only user data that will stored within the system is employee personal information - names, emails and contact numbers. Infrastructure logs are collected using AWS Audit Trail
Please visit for more details - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/)
Our application is deployed on AWS cloud platform.
We are Compliant. We have implemented the data backup policy. We do take backup of the all the users and securely stored. All our application users data back up including password will happen through AWS cloud virtual platform.
We have controls in place. We have implemented the firewall and IDS/IPS for detection and prevention of security.
During the testing phase we make sure that we are meeting all the security requesrements and validate the same before the deployment.
All the data will be stored on AWS cloud and encrypted with Client specific keys. We do not transfer data to any external drives or media devices.
We monitor these logs periodically
Backup data is stored on AWS cloud for maximum security.
We test the backup on a periodical basis to make sure that we follow the availability and integrity principles.
We have documented our Data backup procedures.
We monitor the logs as per the compliance requirements.
We are compliant.
All the logs are recorded in the system.
We always make sure that componentory controls in place if monitoring is not feasible.
We have deployed our application on AWS cluod virtual platform
It's a part of cloud security services
It's a part of cloud security services
Data backups are done daily and in a secured way in AWS. The customer data cannot be lost permanently. We also have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
The data is only stored on our application and its deployed on AWS Cloud. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records
We have deployed our application on Amaon web services (AWS) cloud platform. We are using MySQL, Salt stack, Nodejs and MongoDB technology. LDAP, SAML2, Normal username-password
We are a SAAS solution. We are cloud hosted.
We are a SAAS Solution and have all the capabilities to supoprt huge number of users.
Data center services are provided by AWS
Data backups are done daily and in a secured way in AWS
No. Application is deployed on AWS Cloud.
We have both horizontal and Vertical Scaling
We have auto scaling and self healing.
We use a variety of tools and plugins integrated with Prometheus & Cloudwatch along with health checks for facilitating our uptime/service availability
AWS Cloud virtual platform
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails
Yes. We have deployed our application on AWS virtual platform cloud. And we have the process in place to handle or manage any contingent events or circumstances. We have implemented the Business continuity management and tested annually to validate the effectiveness of the controls. Attached the Business continuity management plan.
We have an Admin/Facility department who is responsible and manage the Physical security and we have provided the access cards to all the employees and visitors and installed biometric machines at all the entry and exit areas. We have also installed the CCTV cameras in our building and will be monitored 24\*7 for maximum security. AWS Data centre physical security – We have deployed our application product on AWS virtual platform cloud. Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff utilizing video surveillance, intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication a minimum of two times to access data center floors. All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff. AWS only provides data center access and information to employees and contractors who have a legitimate business need for such privileges. When an employee no longer has a business need for these privileges, access is immediately revoked, even if they continue to be an employee of Amazon or Amazon Web Services. All physical access to data centers by AWS employees is logged and audited routinely.
PII will be entered through application and stored it on AWS cloud virtual platform. We store Name, email ID and phone number of the users.
Reports can be generated by the admins through the application. If there are any additional support needed, our customer support team would be able to help and guide on generating report.
The data will be stored on AWS Cloud and we do not share or transfer the data
Xoxoday is CSA STAR LEVEL 1 Compliant. Please click here to download CAIQ - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday/services/nreach-online-services-pvt-ltd-xoxoday/](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday/services/nreach-online-services-pvt-ltd-xoxoday/)
We have deployed our application on AWS Virtual platform cloud – Singapore region.
Not Applicable. We have not outsourced.
We have deployed our application on AWS Cloud virtual platform for maximum security. The data center is hosted completely in isolation so that the access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load experienced by application. We have implemented Amazon Cloud watch to enable monitoring of the functioning of the application. The data is encrypted using 256-encryption based SSL certificate. To manage security of data we conduct a quarterly VAPT based security audit of application.
Yes, all the mechanisms related to security are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools.
We have implemented the Patch management procedures. Critical patches will be deployed immediately High patches will get deployed within 5 days Medium Patches will get deployed within 15-day Low will get deployed in 25 days.
Yes. Since it's a SAAS Product we do not charge any additional cost.
We have a team of 15+ who works for improving our solution security. We conduct periodical Vulnerability assessment and Penetration testing with the help of the Authorized third-party vendors and Fix the observations found during the testing in order to mitigate the risk. Our team is based out of Bangalore location.
Yes. Our SAAS solution has been deployed on AWS cloud virtual platform.
Its SAAS Product and implemented the security controls in order to provide secure services and make sure that the customer data is protected.
We have deployed our application on AWS Cloud platform for maximum security. The data will be provided through our platform or application and its hosted-on Amazon Web Services (AWS) Our solution is very easy to use with convenient security features.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team, and it's linked with the SSO/Active Directory
We have deployed our application on AWS Cloud virtual platform. AWS is met all the data center compliance requirements.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory We have implemented intrusion detection tools, we ensure timely detection and investigation in a prompt manner. File integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation. We also have Endpoint security software for all the computers for Protection from exploits, malicious web downloads and softwares, Application and device control etc.
We have deployed the application application on AWS Cloud platform.
The data center is in the Singapore region
We have deployed our application on AWS cloud virtual platform. but, We have not outsourced any of services and third party will not have access to FINCARE data.
Yes. We monitor their compliance, security standards, certifications and Audit Etc.
[We have deployed our application on AWS cloud virtual platform. AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
All the data will be provided through the application and it will be stored on AWS cloud virtual platform. We use Cloudflare web application firewall for maximum security. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. Attached the application data flow diagram
We have the security controls in place. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory. Attached the Network Access Control and Security Procedure.
Yes. we have installed Bitdefender end point security in all the devices for maximum security and have controls on Anti-Virus / Malicious Software throgh End point security. We have also enabled Network Threat Prevention, Advanced Threat Defense, Web Attack Prevention, Multi-Layer Ransomware Protection. Attached the sample screenshot of Bitdefender end point security.
The application is deployed on AWS Virtual platform cloud - Singapore region.
application application is deployed on AWS virtual platform cloud and storgae and scaling up would not be a challenge.
Data backups are automated and done daily and in a secured way on AWS. The data at rest in encrypted only authorised individuals (CT0/Production head) will have access to protect the confidentiality, integrity, and availability of the information. These data backups are reviewed on weekly basis and has been validated during the internal and external audits.
We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed.
Yes, audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage. Administrative logs are part of Cloud Dashboard and are regularly reviewed.
We have deployed our applicaiton on AWS Virtual platform cloud. We do not use any unauthorised applications accross the organization as per the Information security policy.
At Xoxoday the test environment and production environment has been seperated. We have dedicated non-production environment which is in different AWS account and allowing us to segregate data of production environment.
we use Cloudflare Web application firewall (WAF), AWS Guard Duty threat detection service, Amazon CloudWatch, IDS/IPS etc.. for maximum security of data.
Compliant. We do not allow un-trusted and un-validated inputs and attacker cannot insert malicious data and false entries into the logs.
We do not share the source code. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase.
At Xoxday the source code is restricted to only the authorised individuals
Yes. Our solution is using state of the art Cloud Native infrastructure technologies along with microservices architecture allows us to scale our operations as per the demands.
We have deployed our application on AWS Cloud virtual platform and all the data is stored on AWS. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client's key is unique. We use TLS1.3 encryption while data in transit and AES256 while data at rest.
we use Amazon Web Services (AWS) as our Communication service provider. We review the adequate security governance periodicall to make sure that they are also complied with all the Security and Privacy compliance requirements.
We are the Data processor. application is GDPR compliant. At Xoxoday, we ensure that the data is gathered, stored, and handled with respect to individual rights.
The audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
At Xoxoday Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
The backup is automated and happen on AWS on regular basis.
We have deployed our application on AWS Virtual platform cloud - Singapore region.
The application and database server are hardened.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
We have deployed our application on AWS Virtual platform cloud - Singapore region. All the application data is stored there on AWS - Singapore.
We use third party to provide necessary services to the organization on need and approval basis. For ex – Background verification vendor, VA/PT authorised third party vendor, Eternal Auditors, AWS Virtual platform cloud service providers, Google workspace etc
We predominantly work on cloud-based infrastructure - Amazon Web Services which provides the Backup and Restore services to build scalable, durable, and secure data-protection solutions. No limits.
Data backups are done daily and in a secured way in AWS. And Our team review the same on regular basis.
Data backups are done on daily basis and in a secured way in AWS. We have the mechanism in place to delete the data upon termination of the contract upon customer request. In addition to safeguarding the rights of data subjects under the GDPR, we have implemented the Data Retention and Disposal Policy ensuring that excessive amounts of data are not retained by us.
We have deployed our application on AWS Virtual platform cloud and they provide these services.
# Cloud Security Alliance
Source: https://help-plum.xoxoday.com/faq/security-compliance/cloud-security-alliance
Find answers to frequently asked questions about Plum's Cloud Security Alliance (CSA) compliance and cloud security posture.
## Application & Interface Security
Applications and programming interfaces (APIs) shall be designed, developed, deployed, and tested in accordance with leading industry standards (e.g., OWASP for web applications) and adhere to applicable legal, statutory, or regulatory compliance obligations.
Yes, we ensure the same as part of our code review, static code analysis and Web Application Firewall.
Prior to granting customers access to data, assets, and information systems, identified security, contractual, and regulatory requirements for customer access shall be addressed.
Yes, we provide API access only to vendors and systems authorized by the customer.
Data input and output integrity routines (i.e., reconciliation and edit checks) shall be implemented for application interfaces and databases to prevent manual or systematic processing errors, corruption of data, or misuse.
Yes, we follow multi layer application architecture to isolate database access
Policies and procedures shall be established and maintained in support of data security to include (confidentiality, integrity and availability) across multiple system interfaces, jurisdictions and business functions to prevent improper disclosure, alteration, or destruction.
Complied with the requirement - We have Information security policy in place and working effectively
***
## Audit Assurance & Compliance
Audit plans shall be developed and maintained to address business process disruptions. Auditing plans shall focus on reviewing the effectiveness of the implementation of security operations. All audit activities must be agreed upon prior to executing any audits.
Complied with the requirement - We are conducting the Internal and External Audit as per the requirement and focus on the evaluation of the effectiveness security controls
Independent reviews and assessments shall be performed at least annually to ensure that the organization addresses nonconformities of established policies, standards, procedures, and compliance obligations.
Complied with the requirement - reviews and assessments has been performed annually.
Organizations shall create and maintain a control framework which captures standards, regulatory, legal, and statutory requirements relevant for their business needs. The control framework shall be reviewed at least annually to ensure changes that could affect the business processes are reflected.
We are complied with the requirement - Information security team is reviewing the requirements at least annually to ensure changes that could affect the business processes are reflected.
***
## Business Continuity Management & Operational Resilience
A consistent unified framework for business continuity planning and plan development shall be established, documented and adopted to ensure all business continuity plans are consistent in addressing priorities for testing, maintenance, and information security requirements. Requirements for business continuity plans include the following: • Defined purpose and scope, aligned with relevant dependencies • Accessible to and understood by those who will use them • Owned by a named person(s) who is responsible for their review, update, and approval • Defined lines of communication, roles, and responsibilities • Detailed recovery procedures, manual work-around, and reference information • Method for plan invocation
We are complied with the requirement -We have Business continuity plan and procedure which is approved by the Management and tested annually once as per the compliance requirements.
Business continuity and security incident response plans shall be subject to testing at planned intervals or upon significant organizational or environmental changes. Incident response plans shall involve impacted customers (tenant) and other business relationships that represent critical intra-supply chain business process dependencies.
We are complied with the requirement -We have Business continuity plan and procedure which is approved by the Management and tested annually once as per the compliance requirements.
Datacenter utilities services and environmental conditions (e.g., water, power, temperature and humidity controls, telecommunications,and internet connectivity) shall be secured, monitored, maintained, and tested for continual effectiveness at planned intervals to ensure protection from unauthorized interception or damage, and designed with automated fail-over or other redundancies in the event of planned or unplanned disruptions.
Yes, we use Amazon Web Services (AWS) as our CSP, and they provide the same.
Information system documentation (e.g., administrator and user guides, and architecture diagrams) shall be made available to authorized personnel to ensure the following: • Configuring, installing, and operating the information system • Effectively using the system's security features
Yes, we have such documentation
Physical protection against damage from natural causes and disasters, as well as deliberate attacks, including fire, flood, atmospheric electrical discharge, solar induced geomagnetic storm, wind, earthquake, tsunami, explosion, nuclear accident, volcanic activity, biological hazard, civil unrest, mudslide, tectonic activity, and other forms of natural or man-made disaster shall be anticipated, designed, and have countermeasures applied.
We are complied with the requirement . We have Physical and Environmental Security Procedure in place and effectively working
To reduce the risks from environmental threats, hazards, and opportunities for unauthorized access, equipment shall be kept away from locations subject to high probability environmental risks and supplemented by redundant equipment located at a reasonable distance.
We are complied with the requirement
Policies and procedures shall be established, and supporting business processes and technical measures implemented, for equipment maintenance ensuring continuity and availability of operations and support personnel.
Yes. We follow this and complied with the requirement
Protection measures shall be put into place to react to natural and man-made threats based upon a geographically-specific Business Impact Assessment
We are complied with the requirement . We have Physical and Environmental Security Procedure in place and effectively working
There shall be a defined and documented method for determining the impact of any disruption to the organization (cloud provider, cloud consumer) that must incorporate the following: • Identify critical products and services • Identify all dependencies, including processes, applications, business partners, and third party service providers • Understand threats to critical products and services • Determine impacts resulting from planned or unplanned disruptions and how these vary over time • Establish the maximum tolerable period for disruption • Establish priorities for recovery • Establish recovery time objectives for resumption of critical products and services within their maximum tolerable period of disruption • Estimate the resources required for resumption
We are complied with the requirement as per the Business continuity plan and procedure.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, for appropriate IT governance and service management to ensure appropriate planning, delivery and support of the organization's IT capabilities supporting business functions, workforce, and/or customers based on industry acceptable standards (i.e., ITIL v4 and COBIT 5). Additionally, policies and procedures shall include defined roles and responsibilities supported by regular workforce training.
Yes. We have the policies and procedures in place for approproate IT Governance and service management.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, for defining and adhering to the retention period of any critical asset as per established policies and procedures, as well as applicable legal, statutory, or regulatory compliance obligations. Backup and recovery measures shall be incorporated as part of business continuity planning and tested accordingly for effectiveness.
We are complied with the requirement. We have data protection policy.
***
## Change Control & Configuration Management
Policies and procedures shall be established, and supporting business processes and technical measures implemented, to ensure the development and/or acquisition of new data, physical or virtual applications, infrastructure network and systems components, or any corporate, operations and/or datacenter facilities have been pre-authorized by the organization's business leadership or other accountable business role or function.
We are complied with the requirement
External business partners shall adhere to the same policies and procedures for change management, release, and testing as internal developers within the organization (e.g. ITIL service management processes).
Yes, we comply
Organization shall follow a defined quality change control and testing process (e.g. ITIL Service Management) with established baselines, testing, and release standards that focus on system availability, confidentiality, and integrity of systems and services.
Yes, we comply
Policies and procedures shall be established, and supporting business processes and technical measures implemented, to restrict the installation of unauthorized software on organizationally-owned or managed user end-point devices (e.g., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components.
We are complied with the requirement - We have installed End point security in users devices.
Policies and procedures shall be established for managing the risks associated with applying changes to: • business-critical or customer (tenant)-impacting (physical and virtual) applications and system-system interface (API) designs and configurations • infrastructure network and systems components Technical measures shall be implemented to provide assurance that all changes directly correspond to a registered change request, business-critical or customer (tenant) , and/or authorization by, the customer (tenant) as per agreement (SLA) prior to deployment.
Yes, we follow such a CM process.
***
## Data Security & Information Lifecycle Management
Data and objects containing data shall be assigned a classification by the data owner based on data type, value, sensitivity, and criticality to the organization.
Yes, We comply
Policies and procedures shall be established to inventory, document, and maintain data flows for data that is resident (permanently or temporarily) within the service's applications and infrastructure network and systems. In particular, providers shall ensure that data that is subject to geographic residency requirements not be migrated beyond its defined bounds.
Yes, We comply
Data related to electronic commerce (e-commerce) that traverses public networks shall be appropriately classified and protected from fraudulent activity, unauthorized disclosure, or modification in such a manner to prevent contract dispute and compromise of data.
Yes, We comply
Policies and procedures shall be established for the labeling, handling, and security of data and objects which contain data. Mechanisms for label inheritance shall be implemented for objects that act as aggregate containers for data.
We are complied with the requirements with regards to data handling/Labeling/clasification
Production data shall not be replicated or used in non-production environments.
Yes, We dont use LIVE data in any other environment.
All data shall be designated with stewardship, with assigned responsibilities defined, documented, and communicated.
Yes, We comply
Any use of customer data in non-production environments requires explicit, documented approval from all customers whose data is affected, and must comply with all legal and regulatory requirements for scrubbing of sensitive data elements.
Yes, We comply
***
## Datacenter Security
Assets must be classified in terms of business criticality, service-level expectations, and operational continuity requirements. A complete inventory of business-critical assets located at all sites and/or geographical locations and their usage over time shall be maintained and updated regularly, and assigned ownership by defined roles and responsibilities.
Yes, We comply
Physical security perimeters (e.g., fences, walls, barriers, guards, gates, electronic surveillance, physical authentication mechanisms, reception desks, and security patrols) shall be implemented to safeguard sensitive data and information systems.
Yes, We comply. Our CSP(AWS) provides the same.
Automated equipment identification shall be used as a method of connection authentication. Location-aware technologies may be used to validate connection authentication integrity based on known equipment location.
Yes, We comply. Our CSP(AWS) provides the same.
Authorization must be obtained prior to relocation or transfer of hardware, software, or data to an offsite premises.
We are complied - As per the Information security policy and Media protection procedure.
Policies and procedures shall be established for the secure disposal of equipment (by asset type) used outside the organization's premises. This shall include a wiping solution or destruction process that renders recovery of information impossible. The erasure shall consist of a full overwrite of the drive to ensure that the erased drive is released to inventory for reuse and deployment, or securely stored until it can be destroyed.
We are complied. We have Asset Management Procedure
Policies and procedures shall be established, and supporting business processes implemented, for maintaining a safe and secure working environment in offices, rooms, facilities, and secure areas storing sensitive information.
We are complied. Physical and Environmental Security Procedure
Ingress and egress to secure areas shall be constrained and monitored by physical access control mechanisms to ensure that only authorized personnel are allowed access.
We are complied. We have Physical and Environmental Security Procedure
Ingress and egress points such as service areas and other points where unauthorized personnel may enter the premises shall be monitored, controlled and, if possible, isolated from data storage and processing facilities to prevent unauthorized data corruption, compromise, and loss.
We are complied. We have Physical and Environmental Security Procedure and we are monitoring the office building via CCTV cameras.
Physical access to information assets and functions by users and support personnel shall be restricted.
We are complied. We have Physical and Environmental Security Procedure in place and provided the access card to the users to restrict the specific areas.
***
## Encryption & Key Management
Keys must have identifiable owners (binding keys to identities) and there shall be key management policies.
Yes, We comply.
Policies and procedures shall be established for the management of cryptographic keys in the service's cryptosystem (e.g., lifecycle management from key generation to revocation and replacement, public key infrastructure, cryptographic protocol design and algorithms used, access controls in place for secure key generation, and exchange and storage including segregation of keys used for encrypted data or sessions). Upon request, provider shall inform the customer (tenant) of changes within the cryptosystem, especially if the customer (tenant) data is used as part of the service, and/or the customer (tenant) has some shared responsibility over implementation of the control.
Yes, We comply.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, for the use of encryption protocols for protection of sensitive data in storage (e.g., file servers, databases, and end-user workstations), data in use (memory), and data in transmission (e.g., system interfaces, over public networks, and electronic messaging) as per applicable legal, statutory, and regulatory compliance obligations.
Yes, We comply.
Platform and data-appropriate encryption (e.g., AES-256) in open/validated formats and standard algorithms shall be required. Keys shall not be stored in the cloud (i.e. at the cloud provider in question), but maintained by the cloud consumer or trusted key management provider. Key management and key usage shall be separated duties.
Yes, we use AES256 for data at rest.
***
## Governance and Risk Management
Baseline security requirements shall be established for developed or acquired, organizationally-owned or managed, physical or virtual, applications and infrastructure system and network components that comply with applicable legal, statutory and regulatory compliance obligations. Deviations from standard baseline configurations must be authorized following change management policies and procedures prior to deployment, provisioning, or use. Compliance with security baseline requirements must be reassessed at least annually unless an alternate frequency has been established and authorized based on business need.
We are complied with this - We have Compliance Procedure in place and reviewed by the management annually
Risk assessments associated with data governance requirements shall be conducted at planned intervals and shall consider the following: • Awareness of where sensitive data is stored and transmitted across applications, databases, servers, and network infrastructure • Compliance with defined retention periods and end-of-life disposal requirements • Data classification and protection from unauthorized use, access, loss, destruction, and falsification
We are complied - We have Risk Management Procedure and Data classification policy to protect unauthorized use, access, loss, destruction, and falsification
Managers are responsible for maintaining awareness of, and complying with, security policies, procedures, and standards that are relevant to their area of responsibility.
We are complied - we provied information security awareness training to all the employees annually once we per the ISMS requirements.
An Information Security Management Program (ISMP) shall be developed, documented, approved, and implemented that includes administrative, technical, and physical safeguards to protect assets and data from loss, misuse, unauthorized access, disclosure, alteration, and destruction. The security program shall include, but not be limited to, the following areas insofar as they relate to the characteristics of the business: • Risk management • Security policy • Organization of information security • Asset management • Human resources security • Physical and environmental security • Communications and operations management • Access control • Information systems acquisition, development, and maintenance
We are complied with the requirements - We have Information security management framework consisted of all the required policies and procedures. For ex - Risk management • Security policy • Organization of information security • Asset management • Human resources security • Physical and environmental security • Communications and operations management • Access control policy etc....
Executive and line management shall take formal action to support information security through clearly-documented direction and commitment, and shall ensure the action has been assigned.
We are complied - The management is reviewing the performance if the Information Security department and taking necessing actions and providing the recommondation on a timely basis. And all the ISMS policies has been reviewed and approved by the management yearly once as per the requirements.
Information security policies and procedures shall be established and made readily available for review by all impacted personnel and external business relationships. Information security policies must be authorized by the organization's business leadership (or other accountable business role or function) and supported by a strategic business plan and an information security management program inclusive of defined information security roles and responsibilities for business leadership.
We are complied. We have all the required ISMS policies and procedures in place.
A formal disciplinary or sanction policy shall be established for employees who have violated security policies and procedures. Employees shall be made aware of what action might be taken in the event of a violation, and disciplinary measures must be stated in the policies and procedures.
We have Desciplinary policy in place and created an awareness among employees regarding voilation of the polciies via ISMS training.
Risk assessment results shall include updates to security policies, procedures, standards, and controls to ensure that they remain relevant and effective.
We have Risk Management Procedure as per the requirement. We are complied.
The organization's business leadership (or other accountable business role or function) shall review the information security policy at planned intervals or as a result of changes to the organization to ensure its continuing alignment with the security strategy, effectiveness, accuracy, relevance, and applicability to legal, statutory, or regulatory compliance obligations.
We are complied with the requirements - The management is reviewing the performance if the Information Security department and taking necessing actions and providing the recommondation on a timely basis.
Aligned with the enterprise-wide framework, formal risk assessments shall be performed at least annually or at planned intervals, (and in conjunction with any changes to information systems) to determine the likelihood and impact of all identified risks using qualitative and quantitative methods. The likelihood and impact associated with inherent and residual risk shall be determined independently, considering all risk categories (e.g., audit results, threat and vulnerability analysis, and regulatory compliance).
We are conducting Risk assessment at least once in a year as per the ISMS requirements.
Risks shall be mitigated to an acceptable level. Acceptance levels based on risk criteria shall be established and documented in accordance with reasonable resolution time frames and stakeholder approval.
Risk criteria has been established as per the Risk management procedure and consuct risk assessment once in a year as per the compliance requirements.
***
## Human Resources
Upon termination of workforce personnel and/or expiration of external business relationships, all organizationally-owned assets shall be returned within an established period.
We are complied as a part of offboarding procedure.
Pursuant to local laws, regulations, ethics, and contractual constraints, all employment candidates, contractors, and third parties shall be subject to background verification proportional to the data classification to be accessed, the business requirements, and acceptable risk.
We conduct background verification as per the compliance requirements and kept all the required data.
Employment agreements shall incorporate provisions and/or terms for adherence to established information governance and security policies and must be signed by newly hired or on-boarded workforce personnel (e.g., full or part-time employee or contingent staff) prior to granting workforce personnel user access to corporate facilities, resources, and assets.
We are complied with it. Also all the employees have signed for the Non disclosure agreements.
Roles and responsibilities for performing employment termination or change in employment procedures shall be assigned, documented, and communicated.
We are complied - Roles, Responsibilities & Authorities has been defined and communicated to the respective individials.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, to manage business risks associated with permitting mobile device access to corporate resources and may require the implementation of higher assurance compensating controls and acceptable-use policies and procedures (e.g., mandated security training, stronger identity, entitlement and access controls, and device monitoring).
We are complied - We have mobile device management polciy.
Requirements for non-disclosure or confidentiality agreements reflecting the organization's needs for the protection of data and operational details shall be identified, documented, and reviewed at planned intervals.
We have non-disclosure or confidentiality agreements and signed by all the employees and external parties.
Roles and responsibilities of contractors, employees, and third-party users shall be documented as they relate to information assets and security.
We are complied - Roles, Responsibilities & Authorities has been defined and communicated to the respective individials.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, for defining allowances and conditions for permitting usage of organizationally-owned or managed user end-point devices (e.g., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components. Additionally, defining allowances and conditions to permit usage of personal mobile devices and associated applications with access to corporate resources (i.e., BYOD) shall be considered and incorporated as appropriate.
We are complied with the requirement - We have controls in place through policies and procedure.
A security awareness training program shall be established for all contractors, third-party users, and employees of the organization and mandated when appropriate. All individuals with access to organizational data shall receive appropriate awareness training and regular updates in organizational procedures, processes, and policies relating to their professional function relative to the organization.
we are complied - We provide Information security awareness traning to all the employees and contractors, third-party users.
All personnel shall be made aware of their roles and responsibilities for: • Maintaining awareness and compliance with established policies and procedures and applicable legal, statutory, or regulatory compliance obligations. • Maintaining a safe and secure working environment
We are complied - We have Roles, Responsibilities & Authorities policy in place as per the compliance requirements.
Policies and procedures shall be established to require that unattended workspaces do not have openly visible (e.g., on a desktop) sensitive documents and user computing sessions are disabled after an established period of inactivity.
we are complied - we have an access control policy and IT Team have implemented accounts lockout policy to safeguard the sestive documents and personal information.
***
## Identity & Access Management
Access to, and use of, audit tools that interact with the organization's information systems shall be appropriately segmented and restricted to prevent compromise and misuse of log data.
Yes, We comply.
User access policies and procedures shall be established, and supporting business processes and technical measures implemented, for ensuring appropriate identity, entitlement, and access management for all internal corporate and customer (tenant) users with access to data and organizationally-owned or managed (physical and virtual) application interfaces and infrastructure network and systems components. These policies, procedures, processes, and measures must incorporate the following: • Procedures and supporting roles and responsibilities for provisioning and de-provisioning user account entitlements following the rule of least privilege based on job function • Business case considerations for higher levels of assurance and multi-factor authentication secrets • Access segmentation to sessions and data in multi-tenant architectures by any third party • Identity trust verification and service-to-service application (API) and information processing interoperability (e.g., SSO and federation) • Account credential lifecycle management from instantiation through revocation • Authentication, authorization, and accounting (AAA) rules for access to data and sessions • Adherence to applicable legal, statutory, or regulatory compliance requirements
We are complied - Access control policy and Information security policies has been established as per the requirements. We provide an accesss to the data only to an authorised individial.
User access to diagnostic and configuration ports shall be restricted to authorized individuals and applications.
Complied with the requirements though End point security installation.
Policies and procedures shall be established to store and manage identity information about every person who accesses IT infrastructure and to determine their level of access. Policies shall also be developed to control access to network resources based on user identity.
We are complied - We have policies and procedure in place to store and manage identity information.
User access policies and procedures shall be established, and supporting business processes and technical measures implemented, for restricting user access as per defined segregation of duties to address business risks associated with a user-role conflict of interest.
We are complied - We have policies and procedure in place to have control on access of data. We provide access only to an authorised individials.
Access to the organization's own developed applications, program, or object source code, or any other form of intellectual property (IP), and use of proprietary software shall be appropriately restricted following the rule of least privilege based on job function as per established user access policies and procedures.
We have role based access system to make sure that only the authorised individual have an access to the required information.
The identification, assessment, and prioritization of risks posed by business processes requiring third-party access to the organization's information systems and data shall be followed by coordinated application of resources to minimize, monitor, and measure likelihood and impact of unauthorized or inappropriate access. Compensating controls derived from the risk analysis shall be implemented prior to provisioning access.
Yes, We comply.
Policies and procedures are established for permissible storage and access of identities used for authentication to ensure identities are only accessible based on rules of least privilege and replication limitation only to users explicitly defined as business necessary.
We have role based access system to make sure that only the authorised individual have an access to the required information.
Provisioning user access (e.g., employees, contractors, customers (tenants), business partners and/or supplier relationships) to data and organizationally-owned or managed (physical and virtual) applications, infrastructure systems, and network components shall be authorized by the organization's management prior to access being granted and appropriately restricted as per established policies and procedures. Upon request, provider shall inform customer (tenant) of this user access, especially if customer (tenant) data is used as part the service and/or customer (tenant) has some shared responsibility over implementation of control.
We have role based access system to make sure that only the authorised individual have an access to the required information.
User access shall be authorized and revalidated for entitlement appropriateness, at planned intervals, by the organization's business leadership or other accountable business role or function supported by evidence to demonstrate the organization is adhering to the rule of least privilege based on job function. For identified access violations, remediation must follow established user access policies and procedures.
We have role based access system through access control policy to make sure that only the authorised individual have an access to the required information.
Timely de-provisioning (revocation or modification) of user access to data and organizationally-owned or managed (physical and virtual) applications, infrastructure systems, and network components, shall be implemented as per established policies and procedures and based on user's change in status (e.g., termination of employment or other business relationship, job change or transfer). Upon request, provider shall inform customer (tenant) of these changes, especially if customer (tenant) data is used as part the service and/or customer (tenant) has some shared responsibility over implementation of control.
We have change management policy and Infrastructure Change Control Procedure to comply with this requirements.
Internal corporate or customer (tenant) user account credentials shall be restricted as per the following, ensuring appropriate identity, entitlement, and access management and in accordance with established policies and procedures: • Identity trust verification and service-to-service application (API) and information processing interoperability (e.g., SSO and Federation) • Account credential lifecycle management from instantiation through revocation • Account credential and/or identity store minimization or re-use when feasible • Adherence to industry acceptable and/or regulatory compliant authentication, authorization, and accounting (AAA) rules (e.g., strong/multi-factor, expireable, non-shared authentication secrets)
Yes, We comply.
Utility programs capable of potentially overriding system, object, network, virtual machine, and application controls shall be restricted.
Yes, We comply.
***
## Infrastructure & Virtualization Security
Higher levels of assurance are required for protection, retention, and lifecyle management of audit logs, adhering to applicable legal, statutory or regulatory compliance obligations and providing unique user access accountability to detect potentially suspicious network behaviors and/or file integrity anomalies, and to support forensic investigative capabilities in the event of a security breach.
Yes, We comply.
The provider shall ensure the integrity of all virtual machine images at all times. Any changes made to virtual machine images must be logged and an alert raised regardless of their running state (e.g. dormant, off, or running). The results of a change or move of an image and the subsequent validation of the image's integrity must be immediately available to customers through electronic methods (e.g. portals or alerts).
Yes, We comply.
A reliable and mutually agreed upon external time source shall be used to synchronize the system clocks of all relevant information processing systems to facilitate tracing and reconstitution of activity timelines.
Yes, We comply.
The availability, quality, and adequate capacity and resources shall be planned, prepared, and measured to deliver the required system performance in accordance with legal, statutory, and regulatory compliance obligations. Projections of future capacity requirements shall be made to mitigate the risk of system overload.
Yes, We comply.
Implementers shall ensure that the security vulnerability assessment tools or services accommodate the virtualization technologies used (e.g. virtualization aware).
Yes, We comply.
Network environments and virtual instances shall be designed and configured to restrict and monitor traffic between trusted and untrusted connections. These configurations shall be reviewed at least annually, and supported by a documented justification for use for all allowed services, protocols, and ports, and by compensating controls.
Yes, We comply.
Each operating system shall be hardened to provide only necessary ports, protocols, and services to meet business needs and have in place supporting technical controls such as: antivirus, file integrity monitoring, and logging as part of their baseline operating build standard or template.
Yes, We comply.
Production and non-production environments shall be separated to prevent unauthorized access or changes to information assets. Separation of the environments may include: stateful inspection firewalls, domain/realm authentication sources, and clear segregation of duties for personnel accessing these environments as part of their job duties.
Yes, We comply.
Multi-tenant organizationally-owned or managed (physical and virtual) applications, and infrastructure system and network components, shall be designed, developed, deployed and configured such that provider and customer (tenant) user access is appropriately segmented from other tenant users, based on the following considerations: • Established policies and procedures • Isolation of business critical assets and/or sensitive user data, and sessions that mandate stronger internal controls and high levels of assurance • Compliance with legal, statutory and regulatory compliance obligations
Yes, We comply.
Secured and encrypted communication channels shall be used when migrating physical servers, applications, or data to virtualized servers and, where possible, shall use a network segregated from production-level networks for such migrations.
Yes, We comply.
Access to all hypervisor management functions or administrative consoles for systems hosting virtualized systems shall be restricted to personnel based upon the principle of least privilege and supported through technical controls (e.g., two-factor authentication, audit trails, IP address filtering, firewalls, and TLS encapsulated communications to the administrative consoles).
Yes, We comply.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, to protect wireless network environments, including the following: • Perimeter firewalls implemented and configured to restrict unauthorized traffic • Security settings enabled with strong encryption for authentication and transmission, replacing vendor default settings (e.g., encryption keys, passwords, and SNMP community strings) • User access to wireless network devices restricted to authorized personnel • The capability to detect the presence of unauthorized (rogue) wireless network devices for a timely disconnect from the network
Yes, We comply.
Network architecture diagrams shall clearly identify high-risk environments and data flows that may have legal compliance impacts. Technical measures shall be implemented and shall apply defense-in-depth techniques (e.g., deep packet analysis, traffic throttling, and black-holing) for detection and timely response to network-based attacks associated with anomalous ingress or egress traffic patterns (e.g., MAC spoofing and ARP poisoning attacks) and/or distributed denial-of-service (DDoS) attacks.
Yes, We comply.
***
## Interoperability & Portability
The provider shall use open and published APIs to ensure support for interoperability between components and to facilitate migrating applications.
Yes, We comply.
All structured and unstructured data shall be available to the customer and provided to them upon request in an industry-standard format (e.g., .doc, .xls, .pdf, logs, and flat files)
Yes, We comply.
Policies, procedures, and mutually-agreed upon provisions and/or terms shall be established to satisfy customer (tenant) requirements for service-to-service application (API) and information processing interoperability, and portability for application development and information exchange, usage, and integrity persistence.
Yes, We comply.
The provider shall use secure (e.g., non-clear text and authenticated) standardized network protocols for the import and export of data and to manage the service, and shall make available a document to consumers (tenants) detailing the relevant interoperability and portability standards that are involved.
Yes, We comply.
The provider shall use an industry-recognized virtualization platform and standard virtualization formats (e.g., OVF) to help ensure interoperability, and shall have documented custom changes made to any hypervisor in use and all solution-specific virtualization hooks available for customer review.
Yes, We comply.
***
## Mobile Security
Anti-malware awareness training, specific to mobile devices, shall be included in the provider's information security awareness training.
We are complied with this - We provide information security awareness training
A documented list of approved application stores has been defined as acceptable for mobile devices accessing or storing provider managed data.
We are complied with it by having Mobile device Management Policy
The company shall have a documented policy prohibiting the installation of non-approved applications or approved applications not obtained through a pre-identified application store.
We are complied with Mobile device Management Policy
The BYOD policy and supporting awareness training clearly states the approved applications, application stores, and application extensions and plugins that may be used for BYOD usage.
We are complied with it - We have BYOD policy and conducted the awareness training as per the requirements.
The provider shall have a documented mobile device policy that includes a documented definition for mobile devices and the acceptable usage and requirements for all mobile devices. The provider shall post and communicate the policy and requirements through the company's security awareness and training program.
We are complied with it by having Mobile device Management Policy
All cloud-based services used by the company's mobile devices or BYOD shall be pre-approved for usage and the storage of company business data.
We have Mobile device policy and BYOD Policies in place and given the proper guidelines for usage as per the requirements.
The company shall have a documented application validation process to test for mobile device, operating system, and application compatibility issues.
Yes, We comply.
The BYOD policy shall define the device and eligibility requirements to allow for BYOD usage.
We are complied with requirements - We have well defined BYOD policy in place.
An inventory of all mobile devices used to store and access company data shall be kept and maintained. All changes to the status of these devices (i.e., operating system and patch levels, lost or decommissioned status, and to whom the device is assigned or approved for usage (BYOD)) will be included for each device in the inventory.
We are complied with the requrements.
A centralized, mobile device management solution shall be deployed to all mobile devices permitted to store, transmit, or process customer data.
We do not have a centralized mobile device management solution but having control via Google workspace admin console on the Mobile devices.
The mobile device policy shall require the use of encryption either for the entire device or for data identified as sensitive on all mobile devices and shall be enforced through technology controls.
We are complied with the requrements.
The mobile device policy shall prohibit the circumvention of built-in security controls on mobile devices (e.g. jailbreaking or rooting) and shall enforce the prohibition through detective and preventative controls on the device or through a centralized device management system (e.g. mobile device management).
We are complied with the requrements.
The BYOD policy includes clarifying language for the expectation of privacy, requirements for litigation, e-discovery, and legal holds. The BYOD policy shall clearly state the expectations regarding the loss of non-company data in the case a wipe of the device is required.
We are complied with the requrements.
BYOD and/or company-owned devices are configured to require an automatic lockout screen, and the requirement shall be enforced through technical controls.
We are complied with the requrements.
Changes to mobile device operating systems, patch levels, and/or applications shall be managed through the company's change management processes.
We are complied with the requrements.
Password policies, applicable to mobile devices, shall be documented and enforced through technical controls on all company devices or devices approved for BYOD usage, and shall prohibit the changing of password/PIN lengths and authentication requirements.
We are complied with the requrements.
The mobile device policy shall require the BYOD user to perform backups of data, prohibit the usage of unapproved application stores, and require the use of anti-malware software (where supported).
We are complied with the requrements.
All mobile devices permitted for use through the company BYOD program or a company-assigned mobile device shall allow for remote wipe by the company's corporate IT or shall have all company-provided data wiped by the company's corporate IT.
We are complied with the requrements.
Mobile devices connecting to corporate networks, or storing and accessing company information, shall allow for remote software version/patch validation. All mobile devices shall have the latest available security-related patches installed upon general release by the device manufacturer or carrier and authorized IT personnel shall be able to perform these updates remotely.
We are complied with the requrements. We have defined in the policy that Devices must be kept up to date with manufacturer or network provided patches.
The BYOD policy shall clarify the systems and servers allowed for use or access on a BYOD-enabled device.
We are complied with the requrements.
***
## Security Incident Management, E-Discovery & Cloud Forensics
Points of contact for applicable regulation authorities, national and local law enforcement, and other legal jurisdictional authorities shall be maintained and regularly updated (e.g., change in impacted-scope and/or a change in any compliance obligation) to ensure direct compliance liaisons have been established and to be prepared for a forensic investigation requiring rapid engagement with law enforcement.
We are complied with the requrements.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, to triage security-related events and ensure timely and thorough incident management, as per established IT service management policies and procedures.
We are complied with the requrements. We also have incident management plan in place and taken care by Information security team.
Workforce personnel and external business relationships shall be informed of their responsibilities and, if required, shall consent and/or contractually agree to report all information security events in a timely manner. Information security events shall be reported through predefined communications channels in a timely manner adhering to applicable legal, statutory, or regulatory compliance obligations.
We are complied with it - We have an conyratcs and SLA/MSA and all the external parties have signed the NDA as well.
Proper forensic procedures, including chain of custody, are required for the presentation of evidence to support potential legal action subject to the relevant jurisdiction after an information security incident. Upon notification, customers and/or other external business partners impacted by a security breach shall be given the opportunity to participate as is legally permissible in the forensic investigation.
Yes, We comply.
Mechanisms shall be put in place to monitor and quantify the types, volumes, and costs of information security incidents.
We have Security Incident Management plan and communicated to all the employees.
***
## Supply Chain Management, Transparency and Accountability
Providers shall inspect, account for, and work with their cloud supply-chain partners to correct data quality errors and associated risks. Providers shall design and implement controls to mitigate and contain data security risks through proper separation of duties, role-based access, and least-privilege access for all personnel within their supply chain.
Yes, We comply.
The provider shall make security incident information available to all affected customers and providers periodically through electronic methods (e.g. portals).
Yes, We comply.
Business-critical or customer (tenant) impacting (physical and virtual) application and system-system interface (API) designs and configurations, and infrastructure network and systems components, shall be designed, developed, and deployed in accordance with mutually agreed-upon service and capacity-level expectations, as well as IT governance and service management policies and procedures.
Yes, We comply.
The provider shall perform annual internal assessments of conformance to, and effectiveness of, its policies, procedures, and supporting measures and metrics.
We perform annual internal assessments of conformance to, and effectiveness of, its policies, procedures, and supporting measures and metrics.
Supply chain agreements (e.g., SLAs) between providers and customers (tenants) shall incorporate at least the following mutually-agreed upon provisions and/or terms: • Scope of business relationship and services offered • Information security requirements, provider and customer (tenant) primary points of contact for the duration of the business relationship • Notification and/or pre-authorization of any changes controlled by the provider with customer (tenant) impacts • Timely notification of a security incident (or confirmed breach) to all customers (tenants) and other business relationships impacted • Assessment and independent verification of compliance with agreement provisions and/or terms • Expiration of the business relationship and treatment of customer (tenant) data impacted • Customer (tenant) service-to-service application (API) and data interoperability and portability requirements
We are complied with it - We have an conyratcs and SLA/MSA and all the external parties have signed the NDA as well.
Providers shall review the risk management and governance processes of their partners so that practices are consistent and aligned to account for risks inherited from other members of that partner's cloud supply chain.
We have Risk Management Procedures in place.
Policies and procedures shall be implemented to ensure the consistent review of service agreements (e.g., SLAs) between providers and customers (tenants) across the relevant supply chain (upstream/downstream). Reviews shall performed at least annually and identity non-conformance to established agreements. The reviews should result in actions to address service-level conflicts or inconsistencies resulting from disparate supplier relationships.
We review the SLA/MSA and NDA with external parties annually.
Providers shall assure reasonable information security across their information supply chain by performing an annual review. The review shall include all partners/third party-providers upon which their information supply chain depends on.
We review the SLA/MSA and NDA with external parties annually.
Third-party service providers shall demonstrate compliance with information security and confidentiality, access control, service definitions, and delivery level agreements included in third-party contracts. Third-party reports, records, and services shall undergo audit and review at least annually to govern and maintain compliance with the service delivery agreements.
We have ISMS framework including all the required polcieis and procedures as per the compliance requirements.
***
## Threat and Vulnerability Management
Policies and procedures shall be established, and supporting business processes and technical measures implemented, to prevent the execution of malware on organizationally-owned or managed user end-point devices (i.e., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components.
We conduct Vulnerability assessment and Penetration testing on a timely interval and have controls on Anti-Virus / Malicious Software throgh End point security.
Policies and procedures shall be established, and supporting processes and technical measures implemented, for timely detection of vulnerabilities within organizationally-owned or managed applications, infrastructure network and system components (e.g. network vulnerability assessment, penetration testing) to ensure the efficiency of implemented security controls. A risk-based model for prioritizing remediation of identified vulnerabilities shall be used. Changes shall be managed through a change management process for all vendor-supplied patches, configuration changes, or changes to the organization's internally developed software. Upon request, the provider informs customer (tenant) of policies and procedures and identfied weaknesses especially if customer (tenant) data is used as part the service and/or customer (tenant) has some shared responsibility over implementation of control.
We conduct Vulnerability assessment and Penetration testing on a timely interval and have controls on Anti-Virus / Malicious Software throgh End point security.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, to prevent the execution of unauthorized mobile code, defined as software transferred between systems over a trusted or untrusted network and executed on a local system without explicit installation or execution by the recipient, on organizationally-owned or managed user end-point devices (e.g., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components.
We have Threat and Vulnerabilities Management procedure and we conduct Vulnerability assessment and Penetration testing through an athorised vendor.
## Application & Interface Security
Applications and programming interfaces (APIs) shall be designed, developed, deployed, and tested in accordance with leading industry standards (e.g., OWASP for web applications) and adhere to applicable legal, statutory, or regulatory compliance obligations.
Yes, we ensure the same as part of our code review, static code analysis and Web Application Firewall.
Prior to granting customers access to data, assets, and information systems, identified security, contractual, and regulatory requirements for customer access shall be addressed.
Yes, we provide API access only to vendors and systems authorized by the customer.
Data input and output integrity routines (i.e., reconciliation and edit checks) shall be implemented for application interfaces and databases to prevent manual or systematic processing errors, corruption of data, or misuse.
Yes, we follow multi layer application architecture to isolate database access
Policies and procedures shall be established and maintained in support of data security to include (confidentiality, integrity and availability) across multiple system interfaces, jurisdictions and business functions to prevent improper disclosure, alteration, or destruction.
Complied with the requirement - We have Information security policy in place and working effectively
***
## Audit Assurance & Compliance
Audit plans shall be developed and maintained to address business process disruptions. Auditing plans shall focus on reviewing the effectiveness of the implementation of security operations. All audit activities must be agreed upon prior to executing any audits.
Complied with the requirement - We are conducting the Internal and External Audit as per the requirement and focus on the evaluation of the effectiveness security controls
Independent reviews and assessments shall be performed at least annually to ensure that the organization addresses nonconformities of established policies, standards, procedures, and compliance obligations.
Complied with the requirement - reviews and assessments has been performed annually.
Organizations shall create and maintain a control framework which captures standards, regulatory, legal, and statutory requirements relevant for their business needs. The control framework shall be reviewed at least annually to ensure changes that could affect the business processes are reflected.
We are complied with the requirement - Information security team is reviewing the requirements at least annually to ensure changes that could affect the business processes are reflected.
***
## Business Continuity Management & Operational Resilience
A consistent unified framework for business continuity planning and plan development shall be established, documented and adopted to ensure all business continuity plans are consistent in addressing priorities for testing, maintenance, and information security requirements. Requirements for business continuity plans include the following: • Defined purpose and scope, aligned with relevant dependencies • Accessible to and understood by those who will use them • Owned by a named person(s) who is responsible for their review, update, and approval • Defined lines of communication, roles, and responsibilities • Detailed recovery procedures, manual work-around, and reference information • Method for plan invocation
We are complied with the requirement -We have Business continuity plan and procedure which is approved by the Management and tested annually once as per the compliance requirements.
Business continuity and security incident response plans shall be subject to testing at planned intervals or upon significant organizational or environmental changes. Incident response plans shall involve impacted customers (tenant) and other business relationships that represent critical intra-supply chain business process dependencies.
We are complied with the requirement -We have Business continuity plan and procedure which is approved by the Management and tested annually once as per the compliance requirements.
Datacenter utilities services and environmental conditions (e.g., water, power, temperature and humidity controls, telecommunications,and internet connectivity) shall be secured, monitored, maintained, and tested for continual effectiveness at planned intervals to ensure protection from unauthorized interception or damage, and designed with automated fail-over or other redundancies in the event of planned or unplanned disruptions.
Yes, we use Amazon Web Services (AWS) as our CSP, and they provide the same.
Information system documentation (e.g., administrator and user guides, and architecture diagrams) shall be made available to authorized personnel to ensure the following: • Configuring, installing, and operating the information system • Effectively using the system's security features
Yes, we have such documentation
Physical protection against damage from natural causes and disasters, as well as deliberate attacks, including fire, flood, atmospheric electrical discharge, solar induced geomagnetic storm, wind, earthquake, tsunami, explosion, nuclear accident, volcanic activity, biological hazard, civil unrest, mudslide, tectonic activity, and other forms of natural or man-made disaster shall be anticipated, designed, and have countermeasures applied.
We are complied with the requirement . We have Physical and Environmental Security Procedure in place and effectively working
To reduce the risks from environmental threats, hazards, and opportunities for unauthorized access, equipment shall be kept away from locations subject to high probability environmental risks and supplemented by redundant equipment located at a reasonable distance.
We are complied with the requirement
Policies and procedures shall be established, and supporting business processes and technical measures implemented, for equipment maintenance ensuring continuity and availability of operations and support personnel.
Yes. We follow this and complied with the requirement
Protection measures shall be put into place to react to natural and man-made threats based upon a geographically-specific Business Impact Assessment
We are complied with the requirement . We have Physical and Environmental Security Procedure in place and effectively working
There shall be a defined and documented method for determining the impact of any disruption to the organization (cloud provider, cloud consumer) that must incorporate the following: • Identify critical products and services • Identify all dependencies, including processes, applications, business partners, and third party service providers • Understand threats to critical products and services • Determine impacts resulting from planned or unplanned disruptions and how these vary over time • Establish the maximum tolerable period for disruption • Establish priorities for recovery • Establish recovery time objectives for resumption of critical products and services within their maximum tolerable period of disruption • Estimate the resources required for resumption
We are complied with the requirement as per the Business continuity plan and procedure.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, for appropriate IT governance and service management to ensure appropriate planning, delivery and support of the organization's IT capabilities supporting business functions, workforce, and/or customers based on industry acceptable standards (i.e., ITIL v4 and COBIT 5). Additionally, policies and procedures shall include defined roles and responsibilities supported by regular workforce training.
Yes. We have the policies and procedures in place for approproate IT Governance and service management.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, for defining and adhering to the retention period of any critical asset as per established policies and procedures, as well as applicable legal, statutory, or regulatory compliance obligations. Backup and recovery measures shall be incorporated as part of business continuity planning and tested accordingly for effectiveness.
We are complied with the requirement. We have data protection policy.
***
## Change Control & Configuration Management
Policies and procedures shall be established, and supporting business processes and technical measures implemented, to ensure the development and/or acquisition of new data, physical or virtual applications, infrastructure network and systems components, or any corporate, operations and/or datacenter facilities have been pre-authorized by the organization's business leadership or other accountable business role or function.
We are complied with the requirement
External business partners shall adhere to the same policies and procedures for change management, release, and testing as internal developers within the organization (e.g. ITIL service management processes).
Yes, we comply
Organization shall follow a defined quality change control and testing process (e.g. ITIL Service Management) with established baselines, testing, and release standards that focus on system availability, confidentiality, and integrity of systems and services.
Yes, we comply
Policies and procedures shall be established, and supporting business processes and technical measures implemented, to restrict the installation of unauthorized software on organizationally-owned or managed user end-point devices (e.g., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components.
We are complied with the requirement - We have installed End point security in users devices.
Policies and procedures shall be established for managing the risks associated with applying changes to: • business-critical or customer (tenant)-impacting (physical and virtual) applications and system-system interface (API) designs and configurations • infrastructure network and systems components Technical measures shall be implemented to provide assurance that all changes directly correspond to a registered change request, business-critical or customer (tenant) , and/or authorization by, the customer (tenant) as per agreement (SLA) prior to deployment.
Yes, we follow such a CM process.
***
## Data Security & Information Lifecycle Management
Data and objects containing data shall be assigned a classification by the data owner based on data type, value, sensitivity, and criticality to the organization.
Yes, We comply
Policies and procedures shall be established to inventory, document, and maintain data flows for data that is resident (permanently or temporarily) within the service's applications and infrastructure network and systems. In particular, providers shall ensure that data that is subject to geographic residency requirements not be migrated beyond its defined bounds.
Yes, We comply
Data related to electronic commerce (e-commerce) that traverses public networks shall be appropriately classified and protected from fraudulent activity, unauthorized disclosure, or modification in such a manner to prevent contract dispute and compromise of data.
Yes, We comply
Policies and procedures shall be established for the labeling, handling, and security of data and objects which contain data. Mechanisms for label inheritance shall be implemented for objects that act as aggregate containers for data.
We are complied with the requirements with regards to data handling/Labeling/clasification
Production data shall not be replicated or used in non-production environments.
Yes, We dont use LIVE data in any other environment.
All data shall be designated with stewardship, with assigned responsibilities defined, documented, and communicated.
Yes, We comply
Any use of customer data in non-production environments requires explicit, documented approval from all customers whose data is affected, and must comply with all legal and regulatory requirements for scrubbing of sensitive data elements.
Yes, We comply
***
## Datacenter Security
Assets must be classified in terms of business criticality, service-level expectations, and operational continuity requirements. A complete inventory of business-critical assets located at all sites and/or geographical locations and their usage over time shall be maintained and updated regularly, and assigned ownership by defined roles and responsibilities.
Yes, We comply
Physical security perimeters (e.g., fences, walls, barriers, guards, gates, electronic surveillance, physical authentication mechanisms, reception desks, and security patrols) shall be implemented to safeguard sensitive data and information systems.
Yes, We comply. Our CSP(AWS) provides the same.
Automated equipment identification shall be used as a method of connection authentication. Location-aware technologies may be used to validate connection authentication integrity based on known equipment location.
Yes, We comply. Our CSP(AWS) provides the same.
Authorization must be obtained prior to relocation or transfer of hardware, software, or data to an offsite premises.
We are complied - As per the Information security policy and Media protection procedure.
Policies and procedures shall be established for the secure disposal of equipment (by asset type) used outside the organization's premises. This shall include a wiping solution or destruction process that renders recovery of information impossible. The erasure shall consist of a full overwrite of the drive to ensure that the erased drive is released to inventory for reuse and deployment, or securely stored until it can be destroyed.
We are complied. We have Asset Management Procedure
Policies and procedures shall be established, and supporting business processes implemented, for maintaining a safe and secure working environment in offices, rooms, facilities, and secure areas storing sensitive information.
We are complied. Physical and Environmental Security Procedure
Ingress and egress to secure areas shall be constrained and monitored by physical access control mechanisms to ensure that only authorized personnel are allowed access.
We are complied. We have Physical and Environmental Security Procedure
Ingress and egress points such as service areas and other points where unauthorized personnel may enter the premises shall be monitored, controlled and, if possible, isolated from data storage and processing facilities to prevent unauthorized data corruption, compromise, and loss.
We are complied. We have Physical and Environmental Security Procedure and we are monitoring the office building via CCTV cameras.
Physical access to information assets and functions by users and support personnel shall be restricted.
We are complied. We have Physical and Environmental Security Procedure in place and provided the access card to the users to restrict the specific areas.
***
## Encryption & Key Management
Keys must have identifiable owners (binding keys to identities) and there shall be key management policies.
Yes, We comply.
Policies and procedures shall be established for the management of cryptographic keys in the service's cryptosystem (e.g., lifecycle management from key generation to revocation and replacement, public key infrastructure, cryptographic protocol design and algorithms used, access controls in place for secure key generation, and exchange and storage including segregation of keys used for encrypted data or sessions). Upon request, provider shall inform the customer (tenant) of changes within the cryptosystem, especially if the customer (tenant) data is used as part of the service, and/or the customer (tenant) has some shared responsibility over implementation of the control.
Yes, We comply.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, for the use of encryption protocols for protection of sensitive data in storage (e.g., file servers, databases, and end-user workstations), data in use (memory), and data in transmission (e.g., system interfaces, over public networks, and electronic messaging) as per applicable legal, statutory, and regulatory compliance obligations.
Yes, We comply.
Platform and data-appropriate encryption (e.g., AES-256) in open/validated formats and standard algorithms shall be required. Keys shall not be stored in the cloud (i.e. at the cloud provider in question), but maintained by the cloud consumer or trusted key management provider. Key management and key usage shall be separated duties.
Yes, we use AES256 for data at rest.
***
## Governance and Risk Management
Baseline security requirements shall be established for developed or acquired, organizationally-owned or managed, physical or virtual, applications and infrastructure system and network components that comply with applicable legal, statutory and regulatory compliance obligations. Deviations from standard baseline configurations must be authorized following change management policies and procedures prior to deployment, provisioning, or use. Compliance with security baseline requirements must be reassessed at least annually unless an alternate frequency has been established and authorized based on business need.
We are complied with this - We have Compliance Procedure in place and reviewed by the management annually
Risk assessments associated with data governance requirements shall be conducted at planned intervals and shall consider the following: • Awareness of where sensitive data is stored and transmitted across applications, databases, servers, and network infrastructure • Compliance with defined retention periods and end-of-life disposal requirements • Data classification and protection from unauthorized use, access, loss, destruction, and falsification
We are complied - We have Risk Management Procedure and Data classification policy to protect unauthorized use, access, loss, destruction, and falsification
Managers are responsible for maintaining awareness of, and complying with, security policies, procedures, and standards that are relevant to their area of responsibility.
We are complied - we provied information security awareness training to all the employees annually once we per the ISMS requirements.
An Information Security Management Program (ISMP) shall be developed, documented, approved, and implemented that includes administrative, technical, and physical safeguards to protect assets and data from loss, misuse, unauthorized access, disclosure, alteration, and destruction. The security program shall include, but not be limited to, the following areas insofar as they relate to the characteristics of the business: • Risk management • Security policy • Organization of information security • Asset management • Human resources security • Physical and environmental security • Communications and operations management • Access control • Information systems acquisition, development, and maintenance
We are complied with the requirements - We have Information security management framework consisted of all the required policies and procedures. For ex - Risk management • Security policy • Organization of information security • Asset management • Human resources security • Physical and environmental security • Communications and operations management • Access control policy etc....
Executive and line management shall take formal action to support information security through clearly-documented direction and commitment, and shall ensure the action has been assigned.
We are complied - The management is reviewing the performance if the Information Security department and taking necessing actions and providing the recommondation on a timely basis. And all the ISMS policies has been reviewed and approved by the management yearly once as per the requirements.
Information security policies and procedures shall be established and made readily available for review by all impacted personnel and external business relationships. Information security policies must be authorized by the organization's business leadership (or other accountable business role or function) and supported by a strategic business plan and an information security management program inclusive of defined information security roles and responsibilities for business leadership.
We are complied. We have all the required ISMS policies and procedures in place.
A formal disciplinary or sanction policy shall be established for employees who have violated security policies and procedures. Employees shall be made aware of what action might be taken in the event of a violation, and disciplinary measures must be stated in the policies and procedures.
We have Desciplinary policy in place and created an awareness among employees regarding voilation of the polciies via ISMS training.
Risk assessment results shall include updates to security policies, procedures, standards, and controls to ensure that they remain relevant and effective.
We have Risk Management Procedure as per the requirement. We are complied.
The organization's business leadership (or other accountable business role or function) shall review the information security policy at planned intervals or as a result of changes to the organization to ensure its continuing alignment with the security strategy, effectiveness, accuracy, relevance, and applicability to legal, statutory, or regulatory compliance obligations.
We are complied with the requirements - The management is reviewing the performance if the Information Security department and taking necessing actions and providing the recommondation on a timely basis.
Aligned with the enterprise-wide framework, formal risk assessments shall be performed at least annually or at planned intervals, (and in conjunction with any changes to information systems) to determine the likelihood and impact of all identified risks using qualitative and quantitative methods. The likelihood and impact associated with inherent and residual risk shall be determined independently, considering all risk categories (e.g., audit results, threat and vulnerability analysis, and regulatory compliance).
We are conducting Risk assessment at least once in a year as per the ISMS requirements.
Risks shall be mitigated to an acceptable level. Acceptance levels based on risk criteria shall be established and documented in accordance with reasonable resolution time frames and stakeholder approval.
Risk criteria has been established as per the Risk management procedure and consuct risk assessment once in a year as per the compliance requirements.
***
## Human Resources
Upon termination of workforce personnel and/or expiration of external business relationships, all organizationally-owned assets shall be returned within an established period.
We are complied as a part of offboarding procedure.
Pursuant to local laws, regulations, ethics, and contractual constraints, all employment candidates, contractors, and third parties shall be subject to background verification proportional to the data classification to be accessed, the business requirements, and acceptable risk.
We conduct background verification as per the compliance requirements and kept all the required data.
Employment agreements shall incorporate provisions and/or terms for adherence to established information governance and security policies and must be signed by newly hired or on-boarded workforce personnel (e.g., full or part-time employee or contingent staff) prior to granting workforce personnel user access to corporate facilities, resources, and assets.
We are complied with it. Also all the employees have signed for the Non disclosure agreements.
Roles and responsibilities for performing employment termination or change in employment procedures shall be assigned, documented, and communicated.
We are complied - Roles, Responsibilities & Authorities has been defined and communicated to the respective individials.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, to manage business risks associated with permitting mobile device access to corporate resources and may require the implementation of higher assurance compensating controls and acceptable-use policies and procedures (e.g., mandated security training, stronger identity, entitlement and access controls, and device monitoring).
We are complied - We have mobile device management polciy.
Requirements for non-disclosure or confidentiality agreements reflecting the organization's needs for the protection of data and operational details shall be identified, documented, and reviewed at planned intervals.
We have non-disclosure or confidentiality agreements and signed by all the employees and external parties.
Roles and responsibilities of contractors, employees, and third-party users shall be documented as they relate to information assets and security.
We are complied - Roles, Responsibilities & Authorities has been defined and communicated to the respective individials.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, for defining allowances and conditions for permitting usage of organizationally-owned or managed user end-point devices (e.g., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components. Additionally, defining allowances and conditions to permit usage of personal mobile devices and associated applications with access to corporate resources (i.e., BYOD) shall be considered and incorporated as appropriate.
We are complied with the requirement - We have controls in place through policies and procedure.
A security awareness training program shall be established for all contractors, third-party users, and employees of the organization and mandated when appropriate. All individuals with access to organizational data shall receive appropriate awareness training and regular updates in organizational procedures, processes, and policies relating to their professional function relative to the organization.
we are complied - We provide Information security awareness traning to all the employees and contractors, third-party users.
All personnel shall be made aware of their roles and responsibilities for: • Maintaining awareness and compliance with established policies and procedures and applicable legal, statutory, or regulatory compliance obligations. • Maintaining a safe and secure working environment
We are complied - We have Roles, Responsibilities & Authorities policy in place as per the compliance requirements.
Policies and procedures shall be established to require that unattended workspaces do not have openly visible (e.g., on a desktop) sensitive documents and user computing sessions are disabled after an established period of inactivity.
we are complied - we have an access control policy and IT Team have implemented accounts lockout policy to safeguard the sestive documents and personal information.
***
## Identity & Access Management
Access to, and use of, audit tools that interact with the organization's information systems shall be appropriately segmented and restricted to prevent compromise and misuse of log data.
Yes, We comply.
User access policies and procedures shall be established, and supporting business processes and technical measures implemented, for ensuring appropriate identity, entitlement, and access management for all internal corporate and customer (tenant) users with access to data and organizationally-owned or managed (physical and virtual) application interfaces and infrastructure network and systems components. These policies, procedures, processes, and measures must incorporate the following: • Procedures and supporting roles and responsibilities for provisioning and de-provisioning user account entitlements following the rule of least privilege based on job function • Business case considerations for higher levels of assurance and multi-factor authentication secrets • Access segmentation to sessions and data in multi-tenant architectures by any third party • Identity trust verification and service-to-service application (API) and information processing interoperability (e.g., SSO and federation) • Account credential lifecycle management from instantiation through revocation • Authentication, authorization, and accounting (AAA) rules for access to data and sessions • Adherence to applicable legal, statutory, or regulatory compliance requirements
We are complied - Access control policy and Information security policies has been established as per the requirements. We provide an accesss to the data only to an authorised individial.
User access to diagnostic and configuration ports shall be restricted to authorized individuals and applications.
Complied with the requirements though End point security installation.
Policies and procedures shall be established to store and manage identity information about every person who accesses IT infrastructure and to determine their level of access. Policies shall also be developed to control access to network resources based on user identity.
We are complied - We have policies and procedure in place to store and manage identity information.
User access policies and procedures shall be established, and supporting business processes and technical measures implemented, for restricting user access as per defined segregation of duties to address business risks associated with a user-role conflict of interest.
We are complied - We have policies and procedure in place to have control on access of data. We provide access only to an authorised individials.
Access to the organization's own developed applications, program, or object source code, or any other form of intellectual property (IP), and use of proprietary software shall be appropriately restricted following the rule of least privilege based on job function as per established user access policies and procedures.
We have role based access system to make sure that only the authorised individual have an access to the required information.
The identification, assessment, and prioritization of risks posed by business processes requiring third-party access to the organization's information systems and data shall be followed by coordinated application of resources to minimize, monitor, and measure likelihood and impact of unauthorized or inappropriate access. Compensating controls derived from the risk analysis shall be implemented prior to provisioning access.
Yes, We comply.
Policies and procedures are established for permissible storage and access of identities used for authentication to ensure identities are only accessible based on rules of least privilege and replication limitation only to users explicitly defined as business necessary.
We have role based access system to make sure that only the authorised individual have an access to the required information.
Provisioning user access (e.g., employees, contractors, customers (tenants), business partners and/or supplier relationships) to data and organizationally-owned or managed (physical and virtual) applications, infrastructure systems, and network components shall be authorized by the organization's management prior to access being granted and appropriately restricted as per established policies and procedures. Upon request, provider shall inform customer (tenant) of this user access, especially if customer (tenant) data is used as part the service and/or customer (tenant) has some shared responsibility over implementation of control.
We have role based access system to make sure that only the authorised individual have an access to the required information.
User access shall be authorized and revalidated for entitlement appropriateness, at planned intervals, by the organization's business leadership or other accountable business role or function supported by evidence to demonstrate the organization is adhering to the rule of least privilege based on job function. For identified access violations, remediation must follow established user access policies and procedures.
We have role based access system through access control policy to make sure that only the authorised individual have an access to the required information.
Timely de-provisioning (revocation or modification) of user access to data and organizationally-owned or managed (physical and virtual) applications, infrastructure systems, and network components, shall be implemented as per established policies and procedures and based on user's change in status (e.g., termination of employment or other business relationship, job change or transfer). Upon request, provider shall inform customer (tenant) of these changes, especially if customer (tenant) data is used as part the service and/or customer (tenant) has some shared responsibility over implementation of control.
We have change management policy and Infrastructure Change Control Procedure to comply with this requirements.
Internal corporate or customer (tenant) user account credentials shall be restricted as per the following, ensuring appropriate identity, entitlement, and access management and in accordance with established policies and procedures: • Identity trust verification and service-to-service application (API) and information processing interoperability (e.g., SSO and Federation) • Account credential lifecycle management from instantiation through revocation • Account credential and/or identity store minimization or re-use when feasible • Adherence to industry acceptable and/or regulatory compliant authentication, authorization, and accounting (AAA) rules (e.g., strong/multi-factor, expireable, non-shared authentication secrets)
Yes, We comply.
Utility programs capable of potentially overriding system, object, network, virtual machine, and application controls shall be restricted.
Yes, We comply.
***
## Infrastructure & Virtualization Security
Higher levels of assurance are required for protection, retention, and lifecyle management of audit logs, adhering to applicable legal, statutory or regulatory compliance obligations and providing unique user access accountability to detect potentially suspicious network behaviors and/or file integrity anomalies, and to support forensic investigative capabilities in the event of a security breach.
Yes, We comply.
The provider shall ensure the integrity of all virtual machine images at all times. Any changes made to virtual machine images must be logged and an alert raised regardless of their running state (e.g. dormant, off, or running). The results of a change or move of an image and the subsequent validation of the image's integrity must be immediately available to customers through electronic methods (e.g. portals or alerts).
Yes, We comply.
A reliable and mutually agreed upon external time source shall be used to synchronize the system clocks of all relevant information processing systems to facilitate tracing and reconstitution of activity timelines.
Yes, We comply.
The availability, quality, and adequate capacity and resources shall be planned, prepared, and measured to deliver the required system performance in accordance with legal, statutory, and regulatory compliance obligations. Projections of future capacity requirements shall be made to mitigate the risk of system overload.
Yes, We comply.
Implementers shall ensure that the security vulnerability assessment tools or services accommodate the virtualization technologies used (e.g. virtualization aware).
Yes, We comply.
Network environments and virtual instances shall be designed and configured to restrict and monitor traffic between trusted and untrusted connections. These configurations shall be reviewed at least annually, and supported by a documented justification for use for all allowed services, protocols, and ports, and by compensating controls.
Yes, We comply.
Each operating system shall be hardened to provide only necessary ports, protocols, and services to meet business needs and have in place supporting technical controls such as: antivirus, file integrity monitoring, and logging as part of their baseline operating build standard or template.
Yes, We comply.
Production and non-production environments shall be separated to prevent unauthorized access or changes to information assets. Separation of the environments may include: stateful inspection firewalls, domain/realm authentication sources, and clear segregation of duties for personnel accessing these environments as part of their job duties.
Yes, We comply.
Multi-tenant organizationally-owned or managed (physical and virtual) applications, and infrastructure system and network components, shall be designed, developed, deployed and configured such that provider and customer (tenant) user access is appropriately segmented from other tenant users, based on the following considerations: • Established policies and procedures • Isolation of business critical assets and/or sensitive user data, and sessions that mandate stronger internal controls and high levels of assurance • Compliance with legal, statutory and regulatory compliance obligations
Yes, We comply.
Secured and encrypted communication channels shall be used when migrating physical servers, applications, or data to virtualized servers and, where possible, shall use a network segregated from production-level networks for such migrations.
Yes, We comply.
Access to all hypervisor management functions or administrative consoles for systems hosting virtualized systems shall be restricted to personnel based upon the principle of least privilege and supported through technical controls (e.g., two-factor authentication, audit trails, IP address filtering, firewalls, and TLS encapsulated communications to the administrative consoles).
Yes, We comply.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, to protect wireless network environments, including the following: • Perimeter firewalls implemented and configured to restrict unauthorized traffic • Security settings enabled with strong encryption for authentication and transmission, replacing vendor default settings (e.g., encryption keys, passwords, and SNMP community strings) • User access to wireless network devices restricted to authorized personnel • The capability to detect the presence of unauthorized (rogue) wireless network devices for a timely disconnect from the network
Yes, We comply.
Network architecture diagrams shall clearly identify high-risk environments and data flows that may have legal compliance impacts. Technical measures shall be implemented and shall apply defense-in-depth techniques (e.g., deep packet analysis, traffic throttling, and black-holing) for detection and timely response to network-based attacks associated with anomalous ingress or egress traffic patterns (e.g., MAC spoofing and ARP poisoning attacks) and/or distributed denial-of-service (DDoS) attacks.
Yes, We comply.
***
## Interoperability & Portability
The provider shall use open and published APIs to ensure support for interoperability between components and to facilitate migrating applications.
Yes, We comply.
All structured and unstructured data shall be available to the customer and provided to them upon request in an industry-standard format (e.g., .doc, .xls, .pdf, logs, and flat files)
Yes, We comply.
Policies, procedures, and mutually-agreed upon provisions and/or terms shall be established to satisfy customer (tenant) requirements for service-to-service application (API) and information processing interoperability, and portability for application development and information exchange, usage, and integrity persistence.
Yes, We comply.
The provider shall use secure (e.g., non-clear text and authenticated) standardized network protocols for the import and export of data and to manage the service, and shall make available a document to consumers (tenants) detailing the relevant interoperability and portability standards that are involved.
Yes, We comply.
The provider shall use an industry-recognized virtualization platform and standard virtualization formats (e.g., OVF) to help ensure interoperability, and shall have documented custom changes made to any hypervisor in use and all solution-specific virtualization hooks available for customer review.
Yes, We comply.
***
## Mobile Security
Anti-malware awareness training, specific to mobile devices, shall be included in the provider's information security awareness training.
We are complied with this - We provide information security awareness training
A documented list of approved application stores has been defined as acceptable for mobile devices accessing or storing provider managed data.
We are complied with it by having Mobile device Management Policy
The company shall have a documented policy prohibiting the installation of non-approved applications or approved applications not obtained through a pre-identified application store.
We are complied with Mobile device Management Policy
The BYOD policy and supporting awareness training clearly states the approved applications, application stores, and application extensions and plugins that may be used for BYOD usage.
We are complied with it - We have BYOD policy and conducted the awareness training as per the requirements.
The provider shall have a documented mobile device policy that includes a documented definition for mobile devices and the acceptable usage and requirements for all mobile devices. The provider shall post and communicate the policy and requirements through the company's security awareness and training program.
We are complied with it by having Mobile device Management Policy
All cloud-based services used by the company's mobile devices or BYOD shall be pre-approved for usage and the storage of company business data.
We have Mobile device policy and BYOD Policies in place and given the proper guidelines for usage as per the requirements.
The company shall have a documented application validation process to test for mobile device, operating system, and application compatibility issues.
Yes, We comply.
The BYOD policy shall define the device and eligibility requirements to allow for BYOD usage.
We are complied with requirements - We have well defined BYOD policy in place.
An inventory of all mobile devices used to store and access company data shall be kept and maintained. All changes to the status of these devices (i.e., operating system and patch levels, lost or decommissioned status, and to whom the device is assigned or approved for usage (BYOD)) will be included for each device in the inventory.
We are complied with the requrements.
A centralized, mobile device management solution shall be deployed to all mobile devices permitted to store, transmit, or process customer data.
We do not have a centralized mobile device management solution but having control via Google workspace admin console on the Mobile devices.
The mobile device policy shall require the use of encryption either for the entire device or for data identified as sensitive on all mobile devices and shall be enforced through technology controls.
We are complied with the requrements.
The mobile device policy shall prohibit the circumvention of built-in security controls on mobile devices (e.g. jailbreaking or rooting) and shall enforce the prohibition through detective and preventative controls on the device or through a centralized device management system (e.g. mobile device management).
We are complied with the requrements.
The BYOD policy includes clarifying language for the expectation of privacy, requirements for litigation, e-discovery, and legal holds. The BYOD policy shall clearly state the expectations regarding the loss of non-company data in the case a wipe of the device is required.
We are complied with the requrements.
BYOD and/or company-owned devices are configured to require an automatic lockout screen, and the requirement shall be enforced through technical controls.
We are complied with the requrements.
Changes to mobile device operating systems, patch levels, and/or applications shall be managed through the company's change management processes.
We are complied with the requrements.
Password policies, applicable to mobile devices, shall be documented and enforced through technical controls on all company devices or devices approved for BYOD usage, and shall prohibit the changing of password/PIN lengths and authentication requirements.
We are complied with the requrements.
The mobile device policy shall require the BYOD user to perform backups of data, prohibit the usage of unapproved application stores, and require the use of anti-malware software (where supported).
We are complied with the requrements.
All mobile devices permitted for use through the company BYOD program or a company-assigned mobile device shall allow for remote wipe by the company's corporate IT or shall have all company-provided data wiped by the company's corporate IT.
We are complied with the requrements.
Mobile devices connecting to corporate networks, or storing and accessing company information, shall allow for remote software version/patch validation. All mobile devices shall have the latest available security-related patches installed upon general release by the device manufacturer or carrier and authorized IT personnel shall be able to perform these updates remotely.
We are complied with the requrements. We have defined in the policy that Devices must be kept up to date with manufacturer or network provided patches.
The BYOD policy shall clarify the systems and servers allowed for use or access on a BYOD-enabled device.
We are complied with the requrements.
***
## Security Incident Management, E-Discovery & Cloud Forensics
Points of contact for applicable regulation authorities, national and local law enforcement, and other legal jurisdictional authorities shall be maintained and regularly updated (e.g., change in impacted-scope and/or a change in any compliance obligation) to ensure direct compliance liaisons have been established and to be prepared for a forensic investigation requiring rapid engagement with law enforcement.
We are complied with the requrements.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, to triage security-related events and ensure timely and thorough incident management, as per established IT service management policies and procedures.
We are complied with the requrements. We also have incident management plan in place and taken care by Information security team.
Workforce personnel and external business relationships shall be informed of their responsibilities and, if required, shall consent and/or contractually agree to report all information security events in a timely manner. Information security events shall be reported through predefined communications channels in a timely manner adhering to applicable legal, statutory, or regulatory compliance obligations.
We are complied with it - We have an conyratcs and SLA/MSA and all the external parties have signed the NDA as well.
Proper forensic procedures, including chain of custody, are required for the presentation of evidence to support potential legal action subject to the relevant jurisdiction after an information security incident. Upon notification, customers and/or other external business partners impacted by a security breach shall be given the opportunity to participate as is legally permissible in the forensic investigation.
Yes, We comply.
Mechanisms shall be put in place to monitor and quantify the types, volumes, and costs of information security incidents.
We have Security Incident Management plan and communicated to all the employees.
***
## Supply Chain Management, Transparency and Accountability
Providers shall inspect, account for, and work with their cloud supply-chain partners to correct data quality errors and associated risks. Providers shall design and implement controls to mitigate and contain data security risks through proper separation of duties, role-based access, and least-privilege access for all personnel within their supply chain.
Yes, We comply.
The provider shall make security incident information available to all affected customers and providers periodically through electronic methods (e.g. portals).
Yes, We comply.
Business-critical or customer (tenant) impacting (physical and virtual) application and system-system interface (API) designs and configurations, and infrastructure network and systems components, shall be designed, developed, and deployed in accordance with mutually agreed-upon service and capacity-level expectations, as well as IT governance and service management policies and procedures.
Yes, We comply.
The provider shall perform annual internal assessments of conformance to, and effectiveness of, its policies, procedures, and supporting measures and metrics.
We perform annual internal assessments of conformance to, and effectiveness of, its policies, procedures, and supporting measures and metrics.
Supply chain agreements (e.g., SLAs) between providers and customers (tenants) shall incorporate at least the following mutually-agreed upon provisions and/or terms: • Scope of business relationship and services offered • Information security requirements, provider and customer (tenant) primary points of contact for the duration of the business relationship • Notification and/or pre-authorization of any changes controlled by the provider with customer (tenant) impacts • Timely notification of a security incident (or confirmed breach) to all customers (tenants) and other business relationships impacted • Assessment and independent verification of compliance with agreement provisions and/or terms • Expiration of the business relationship and treatment of customer (tenant) data impacted • Customer (tenant) service-to-service application (API) and data interoperability and portability requirements
We are complied with it - We have an conyratcs and SLA/MSA and all the external parties have signed the NDA as well.
Providers shall review the risk management and governance processes of their partners so that practices are consistent and aligned to account for risks inherited from other members of that partner's cloud supply chain.
We have Risk Management Procedures in place.
Policies and procedures shall be implemented to ensure the consistent review of service agreements (e.g., SLAs) between providers and customers (tenants) across the relevant supply chain (upstream/downstream). Reviews shall performed at least annually and identity non-conformance to established agreements. The reviews should result in actions to address service-level conflicts or inconsistencies resulting from disparate supplier relationships.
We review the SLA/MSA and NDA with external parties annually.
Providers shall assure reasonable information security across their information supply chain by performing an annual review. The review shall include all partners/third party-providers upon which their information supply chain depends on.
We review the SLA/MSA and NDA with external parties annually.
Third-party service providers shall demonstrate compliance with information security and confidentiality, access control, service definitions, and delivery level agreements included in third-party contracts. Third-party reports, records, and services shall undergo audit and review at least annually to govern and maintain compliance with the service delivery agreements.
We have ISMS framework including all the required polcieis and procedures as per the compliance requirements.
***
## Threat and Vulnerability Management
Policies and procedures shall be established, and supporting business processes and technical measures implemented, to prevent the execution of malware on organizationally-owned or managed user end-point devices (i.e., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components.
We conduct Vulnerability assessment and Penetration testing on a timely interval and have controls on Anti-Virus / Malicious Software throgh End point security.
Policies and procedures shall be established, and supporting processes and technical measures implemented, for timely detection of vulnerabilities within organizationally-owned or managed applications, infrastructure network and system components (e.g. network vulnerability assessment, penetration testing) to ensure the efficiency of implemented security controls. A risk-based model for prioritizing remediation of identified vulnerabilities shall be used. Changes shall be managed through a change management process for all vendor-supplied patches, configuration changes, or changes to the organization's internally developed software. Upon request, the provider informs customer (tenant) of policies and procedures and identfied weaknesses especially if customer (tenant) data is used as part the service and/or customer (tenant) has some shared responsibility over implementation of control.
We conduct Vulnerability assessment and Penetration testing on a timely interval and have controls on Anti-Virus / Malicious Software throgh End point security.
Policies and procedures shall be established, and supporting business processes and technical measures implemented, to prevent the execution of unauthorized mobile code, defined as software transferred between systems over a trusted or untrusted network and executed on a local system without explicit installation or execution by the recipient, on organizationally-owned or managed user end-point devices (e.g., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components.
We have Threat and Vulnerabilities Management procedure and we conduct Vulnerability assessment and Penetration testing through an athorised vendor.
# Cryptography and Encryption
Source: https://help-plum.xoxoday.com/faq/security-compliance/cryptography-and-encryption
Find answers to frequently asked questions about the cryptography and encryption standards Plum uses to protect customer data.
Yes, we use AES 256-bit encryption. All the network communication for network communication is encrypted with the industry standards. Note - Please provide supporting documentation defining encryption standards and technologies.
All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment.
Yes, the data is segregated with a client-specific key for proper handling and representation.
Yes, there's a native encryption capability when it comes to sensitive data fields. As each field is equally intricate, there are no limits to such fields.
User IDs and passwords must transmit through stringent checks in an encrypted format that complies with the current Technical Security Baseline Standards.
The passwords are stored after encryption for maximum security of data.
"Yes, our policies and procedures are established as per implemented mechanisms for secure disposal and removal of data from every storage media. By this, it rests assured that the data can't be recovered by any computer forensic means. We assure secure data disposal when storage is decommissioned or when the contract comes to an end."
Please refer "Do you support secure deletion of data?" for an explanation. As for the procedure, here's the protocol that we follow:
* Storage Period would be as per regulatory conditions.
* Personal data can be deleted based on a formal written request, with justification.
* Xoxoday would delete the data within 30 days of receiving the request.
No, users must use certificates from Xoxoday. They are benchmarked as per the best industry standards to ensure complete encryption of data.
No, open encryption has proven to show cracks and bruises and that's why we only equip data traversing public networks with industrial standards to ensure protection from fraud, unauthorized disclosure, modification, or compromise of data.
Yes, personal data is to be transmitted using firmly approved encrypted systems and in no way is it to be transmitted via email.
Yes, the hardened images are secure from any malicious leak or unauthorized access. These hardened images do not contain any authentication credentials.
Yes, our network communication is encrypted with highly restricted protocols to ensure maximum security.
No, the cryptographic keys, including data encryption and SSL certificates are managed by Xoxoday for optimal security of sensitive data.
We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security
Yes. We have implemented the Information Classification Policy
We use a split key mechanism to ensure that every client's key is unique. • We perform annual key rotation. • Keys are generated using KMS service whenever needed. • We store keys in KMS.
Attached the Encryption policy Name of the folder - EN01 Encryption policy
Every client's key is unique.
Yes. Our tech team manages this.
We have encrypted the data while in transit and at rest.We use TLS1.2 encryption for Data at transit and AES256 Data at rest.
We store keys in KMS.
Yes. Backup data is also encrypted.
The data in transit will be always be encrypted.
Yes. We use google workspace and all the conversations are TLS encrypted.
Passwords are encrypted all the time.
We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256.
Backup, passwords are protected. We use encryption.
We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data. our network environment is designed and configured to restrict any communication and connection between the tenant's environment.
We have a multi-layered network architecture with role-based access control. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client's key is unique. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.
We use TLS1.2 encryption for Data in transit and AES256 for Data at rest.
We use TLS1.3 encryption for Data at transit
We logically segregate the tenant's data, and it is segregated with a client-specific key for proper handling and security reasons. We use TLS1.3 encryption while data in transit and AES256 while data at rest
Yes, our logic to physically separate tenant systems is made possible by assigning each tenant's data a client-specific key that is uniquely encrypted for maximum security.
We use TLS1.3 encryption while data in transit and AES256 while data at rest
We use logical data isolation with the help of company specific encryption keys. All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment.
We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
By default the users will not have access to our customer information or PII. These PII or Sensitive information will be visible only to authorized users and only to the extent needed to perform activities. We do not share or transfer any of the customer data with any other parties. We do not provide access to the PII/SPII to any personnel who do not need the access and implemented the role based access control mechanism.
We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client's key is unique. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest
Data backups are done on daily basis and in a secured way on AWS. This has been tested on regular basis.
We use TLS1.2 encryption for Data in transit and AES256 for Data at rest.
Yes. The data at rest encrypted in the cloud.
We use AES256 while data at rest. Attached the evidence.
We use TLS1.3 encryption while data in transit and AES256 while data at rest
Each tenant data is uniquely encrypted using client specific key. We use AES 256 bit encryption for data at rest to ensure maximum security measures.
our network communication is encrypted with highly restricted protocols to ensure maximum security. the cryptographic keys, including data encryption and SSL certificates are managed by Xoxoday for optimal security of sensitive data. The passwords are also stored after encryption for maximum security of data
Yes. All the data at rest is encrypted using AES-256-bit standards and all the data in transit encryption is HTTPS with TLS 1.2
we logically segregate the tenant's data and the application.Each tenant data is uniquely encrypted using client specific key. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
We are compliant with EU GDPR and CPRA (California Privacy Rights Act)
We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks.
In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behavior.
Our network environment is designed and configured to restrict any communication and connection between the tenant's environment and our corporate network.
We use logical data isolation with the help of company-specific encryption keys. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
We are EU GDPR Compliant and CPRA Certified.
The data isolated between customers. We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256
The data is stored on AWS and The IDs and passwords are stored after encryption for maximum security of data
We also conduct Network layer vulnerability and applicatioin layer vulnerability scan. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256
Yes. Data is encrypted.
Each tenant data is uniquely encrypted using client specific key
Yes. We provide importance to user's privacy. We use AES 256-bit encryption.
We have a multi-layered network architecture with role-based access control. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client's key is unique. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.
Since we are SAAS product, we maintain backup and restore all the customer data by ourselves. We use AES 256 encryption for data at rest. We have a multi AZ deployment with periodic backup for our DR.
We use logical data isolation with the help of company specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256
Yes, our network communication is encrypted with highly restricted protocols to ensure maximum security.
We use AES 256 bit encryption for data at rest to ensure maximum security measures.
Yes. The data anonymization implemented. We have enabled security settings with strong encryption for authentication and transmission. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest
Our employees only have access to the data that is necessary for the completion of the business activity which they are involved in. We have role based access system to make sure that only the authorised individual have an access to the required information.
We review the role provisioning, deprovisioning, and recertification on a periodical basis and also audited by the external auditor. Our IT Team Review an access controls and approve as per the procedure. Any changes in the access levels of the users will be as per the role based logical access.
We encrypt our secretes and store them in a private respository and servers.
All the network communication for network communication is encrypted to industry standards. We use logical data isolation with the help of company specific encryption keys. Data in non-production environment is not updated with the production data. We generate separate test data at transit - TLS1.2 encryption, Data at rest - AES256
Yes
We do very limited modification or changes wherever necessary.
We have implemented the Encryption policy. We have defined generation, storage, archival, retrieval, distribution, retirement and destruction of keys. Attached the Encryption policy.
All information are classified as Restricted and encrypted.
The data is segregated with a client-specific key for proper handling and representation.
All the data including the account credentials, Backup data are encrypted in transit and at rest.
All the the customer data stored on our application also be encrypted for maximum security.
We have implemented the security controls. We use TLS1.3 encryption for Data at transit and AES256 Data at rest for maximum security.We store password hashed. We have SHA512 hash with unique salt for every password
We make sure that we follow the Industry best practices and security standard to make sure that we secure the information asset.
Backup is encrypted and stored on cloud.
We use logical data isolation with the help of company specific encryption keys
We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256. We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data. our network environment is designed and configured to restrict any communication and connection between the tenant's environment.
Yes.
We comply with all the applicable new laws and regulations. We also have a service provider who helps us with regards to Information security, compliance and certifications etc.. We have identified the upcoming CPRA and implemented the controls and achieved the CPRA Attestation with the help of the external auditor.
Attached the CPRA Attestation report.
Yes. The communications are secure. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.
We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. We store password hashed. We have HA512 hash with unique salt for every password
Yes. We use encrypted channel
Yes
We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. We store password hashed. We have HA512 hash with unique salt for every password
Each tenant data is uniquely encrypted using a client specific key. All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment Corporate data cannot be accessed by other clients of the service provider
Data is encrypted during transmission, at rest (database and storage), and at backup We use TLS1.2 encryption for Data in transit and AES256 for Data at rest.
We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access. Attached the Encryption Policy.
We have the ability to logically segment or encrypt customer data. our network environment is designed and configured to restrict any communication and connection between the tenant's environment and our corporate network.our logic to physically separate tenant systems is made possible by assigning each tenant's data a client-specific key that is uniquely encrypted for maximum security.
We do field level encryption for PII and user generated content. This encryption has a unique encryption key for each client. In addition we also do disk level encryption for the entire stored data.
We have implements cryptographic mechanisms to prevent unauthorized disclosure and modification of information at rest.
We use AES 256 bit encryption for data at rest to ensure maximum security measures.
Attached the encryption policy.
Sensitive data is encrypted and not stored in logs. Compliant.
Cryptographic keys are protected. Compliant.
The cryptographic keys, including data encryption and SSL certificates, are managed by Xoxoday for optimal security of sensitive data. Each tenant's data is uniquely encrypted using client specific key.
NA. We do not store any other Sensitive personal information.
The PII(name, email ID, phone#) are encrypted. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
The application and system backup data is encrypted
We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
The back up data is encrypted and only authorised individuals will have access. Test data and backup data is seperated from the production servers.
There is no integration with Infosys services/systems. The network Architecture diagram has been shared to show the TLS communication.
Yes, we use AES 256-bit encryption. All the network communication for network communication is encrypted with the industry standards
All data volume is encrypted with AES 256-bit encryption to prevent any external snooping or unauthorized access in the multi-tenant environment
We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
All the PII Are encrypted.
# Data Management
Source: https://help-plum.xoxoday.com/faq/security-compliance/data-management
Find answers to frequently asked questions about Plum's data management practices, including retention and lifecycle policies.
Yes, the payment card data is masked and encrypted to ensure that the access only lies in the hands of authorized individuals.
We use AES 256-bit encryption for data at rest for securing digital identities.
The only user data stored within the system is their personal information - names, emails and contact numbers. This data is not put to any use by Xoxoday and resides within the system. The data can be deleted upon the tenant's request.
Your data is completely secure. Third parties have no access to the given data.
Yes, as stated above, your data is completely encrypted and secure, hence no critical information shall be revealed to the third parties.
No. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records.
Yes, our web assets, email records, and end-points are sealed with data loss prevention techniques.
Yes, our technicalities are built in tandem with the customer data retention policies.
No, we only rely on our ironclad infrastructure to ensure maximum security of data.
The Xoxoday platform operates on the cloud, which means there are no removable storage devices in question.
Our data cleansing process goes through an organized purge. Once the data is purged, it's purged from all places.
There are user roles available for privileged and authorized members, access to which is provided via oAuth-2.0.
Identities of users are verified on the events they access any resources.
A support ticket has to be raised to the customer support team, after which the de-provisioning of privileged credentials will be taken care of in the back-end.
The accounts with highest privilege are authenticated and managed via oAuth-2.0, which can be used to implement secure access to confidential data.
No, roles of high privilege are allocated to a chosen few so that it doesn't break the segregation of duties.
In case of an emergency, tenants can raise a request to the customer support personnel or the key account manager. The privileged access shall be given from the back-end promptly.
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
Yes, mutual authentication exists for strong authentication via AES 256-bit encryption.
* Infrastructure logs are collected using AWS Audit Trail
* Application-relatedlogs are collected in our Elastic Search server and retained in long-term cloud storage.
No. Since we are a multi-tenant system, our logs contain information of all the tenants. We cannot isolate a single customer's information from our logs.
Administrative logs are part of Cloud Dashboard and are regularly reviewed.
Yes, we have multiple internet service providers for uninterrupted coverage and maximum uptime.
There are gateways in place to defer DDoS attacks.
No, historical data cannot be provided due to its confidentiality.
We don't face any downtime and keep our service uninterrupted even in the events of upgrades and patches.
Yes, in case there's a need for a forensic investigation, we can accommodate time and make it happen.
Yes. We comply with this requirement, we follow multi-layer application architecture to isolate database access.
Yes. We follow a defined quality change control and testing as per the Organization's policies and procedures.
Yes. We follow a data classification policy and access control policy to provide access to the individuals based on data type, value, sensitivity, and criticality to the organization.
Yes, We comply with this requirement. All data has been designated with stewardship, with assigned responsibilities defined, documented, and communicated as per the compliance requirements.
Yes. We make sure that we follow access control policy and data protection policy to make sure that only authorized individual has access to the required data. And we have controls such as antivirus, file integrity monitoring, and log monitoring as per the compliance requirements.
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role based access requirements. Furthermore, while defining job roles and designing access roles, privileges leading to conflicts of interests are to be avoided. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events.
We have implemented the Role based access control machanism.
Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. We have implemented the Media protection procedure and Data retension & Disposal policy to make sure that we dispose the data securely.
Yes. All are separate.
We do not use.
We not disclose or share any of the clients data.
They do not have access.
Yes. Segregation is done.
Yes, we have implemented the physical security and only authorised individual can have access. We have also deployed security guards for maximum security.
At least 180 days
Yes, we do not allow any personal storgae devices.
Yes, we will delete the data upon termination of the contract of request of the end users.
The data will be entered by the end users and will be deleted upon the termination of the contract.
Upon termination of the contract we confirm the data deletion.
We securely dispose the data upon termination of the contract and confirm you within a specified period of timeline.
We have implemented the Data Retention and Disposal Policy. Attached the document. We do not store customer information in any equipments, all the information will be stored on AWS Cloud virtual platform. We make sure that all the any data stored in any electronic devices are deleted before disposing of the equipments.
NO
The secure deletion standard like DoD 5220.22-M ECE is being followed and we provide a certificate that the data was properly sanitized from all computing resources and portable storage media
We have implemented the data loss prevention techniques to make sure that the data is not lost permanently.
It's a part of our data loss prevention techniques
our web assets, email records, and end-points are sealed with data loss prevention techniques even when the endpoint is disconnected from corporate network
Since we are into SAAS business we purge the data upon termination of the contracts or request by the customer.
As per the compliance requirements we will delete the data upon a request from the customer. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
We do not use any of our customer data for testing.
We collect only the name and email from the customer as a mandatory PII and these data stored on AWS - Singapore region. We always transparently inform the customer about the data storage location.
No.We do not use our customer data for any of these purposes.
We adhere to Data Retention and Disposal Policy and make sure that the personal information of the data subject will be deleted upon requests or termination of the contract.
We have implemented the Data Loss Prevention techniques and Backup of data will be taken on regular basis automatically on AWS Platform. The data backup is also encrypted and there are no possibilities of loosing the data stored.
The data can be deleted upon the tenant's request or termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
The data can be deleted upon the tenant's request or termination of the contract.
We conduct the code review and get the necessary approvals from authorised personnel before releasing the new versions or developments.
This is part of the code review process wherein the reviewer checks the utility and security of the 3rd party library.
NA. We do not store any Health information or PHI.
7Years. But we delete the data upon customer request as per the GDPR.
The employees Name, Email ID, DOB, designation will be involved. And other information posted on the groups will be involved.
Cardholder data is not involved.
Yes, our web assets, email records, and end-points are sealed with data loss prevention techniques.
We can delete the customer data upon their request or after the termination of the contract. Our data cleansing process goes through an organized purge. Once the data is purged, it's purged from all places
We do not use any data from our production environment for testing purposes.
Our testing and production environment is on a different account. Its logically segregated for maximum security.
We do not use any data from our production environment for testing purposes.
We treat this as sensitive and confidential
We securely delete the data upon termination of the contract
Our data cleaning process goes through an organized purge.
We will delete the data upon termination of the contract and confirm you. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
our web application, email records, and end-points are sealed with data loss prevention techniques. We have the capability to do it immediately.
our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC). All software development procedures are supervised and monitored by Xoxoday so that they include: • security requirements • independent security review of the environment by a certified individual • code reviews Quality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients' reference.
We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. We use logical data isolation with the help of company specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system.
Upon request or termincation of the contract we delete the data and confirm.
Since we are a SaaS solution, PII is collected through our application and stored on AWS virtual platform cloud. We do not provide access to anybody except an authorised individual of our product teams.
we logically segregate the tenant's data and the application.Each tenant data is uniquely encrypted using client specific key. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
NA. We do not handles the card holder data.
Yes. OTP will get generate before making the payment.
We have the Data security Controls in place. We have established the Data Management System and Information Security Management system to ensure that the data is managed during the conduct of business in a safe and secure manner in delivering the business values to the interested parties. Nreach Online Services Pvt ltd, respects the individual right to their personal information and is committed to use minimum personal data with transparency, accuracy & protection of confidentiality, integrity, availability, privacy, authenticity & trustworthiness, nonrepudiation, accountability and auditability of the data received, stored, processed and destroyed for business purposes. Atatched the Xoxoday GDPR Data Security Policy
We do not transfer any data to any external parties.
We are equipped to detect and mitigate Threats, DDOS attacks, session hijack, login spoofs or any other data extraction strategies.
We deleted the data upon termination of the contract or if received the request from the customers/users. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
NA. We do not process any PHI.
NA. We do not process any PHI.
We do not share or disclose any PII to the third parties. We do not store PHI.
Not application. All the data enters via our application.
We do not process any PHI. We process the PII(name, email ID, phone#) and all are encrypted. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. Attached the Network architecture diagram and data flow.
We will be deleting the data securely as per the Data retension and data disposal policy Yes, our policies and procedures are established as per implemented mechanisms for secure disposal and removal of data from every storage media. By this, it rests assured that the data can't be recovered by any computer forensic means. We assure secure data disposal when storage is decommissioned or when the contract comes to an end."
Yes, we follow all the technical guidelines for development of our code and applications that come under the Open Web Application Security Project.
We collect the data only through our application.
There have been no incidences of security breaches resulting in the failure of core systems. We are equipped to detect and mitigate Advanced Persistent Threats or DDOS. We use AWS Cloud watch for monitoring the configuration and infrastructure changes. This will identify several types of denial of service (DoS) attacks
The data can be deleted upon the tenant's request or termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
NA. We do not transmit data from one location to another.
Our web assets, email records, and endpoints are sealed with data loss prevention techniques.
We delete the customer data upon termination of the contract or request from the data subject.
Yes. We confirm once the data is securely deleted from all the sources. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
We delete the customer data upon termination of the contract or on request of the data subject.
# Data Security
Source: https://help-plum.xoxoday.com/faq/security-compliance/data-security
Find answers to frequently asked questions about the technical safeguards Plum uses to keep customer data secure.
[Open document](https://drive.google.com/file/d/1W5QQnsnixFirx-xjZ1KRhPOA7Bi3cMRf/view)
[Open document](https://drive.google.com/file/d/1okA7QhhKPHrrO_eSUrGd19yHhqpZRnOI/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1zsggds3GYgDOAMOE-bBT2vX1EH5R9E4A/view)
[Open document](https://drive.google.com/file/d/1W5QQnsnixFirx-xjZ1KRhPOA7Bi3cMRf/view)
[Open document](https://drive.google.com/file/d/1zyr_8lViSEbl3YlClOJFe4BmqJgdO_hU/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1S4C7STlV8n9xUKaNOY__hEMerLQbkqus/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1AUHfaBYe5lLXsbyRzP4mLMHh4LNsFY2e/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1KaECkPolkGh10EHfIpkUgntHn7-eK2X1/view?usp=sharing)
# Finance Compliance
Source: https://help-plum.xoxoday.com/faq/security-compliance/finance-compliance
Find answers to frequently asked questions about Plum's finance compliance practices and internal financial controls.
[Open document](https://drive.google.com/file/d/1BdeOUJl-14jww0Dkm3uLHtnLRjKIYlag/view?usp=sharing)
# Governance, Risk and Data Compliance
Source: https://help-plum.xoxoday.com/faq/security-compliance/governance-risk-data-compliance
Find answers to frequently asked questions about Plum's governance, risk management, and data compliance practices.
Yes, there are established policies and procedures for labeling, handling, storing, transmitting, retention/disposal, and security of TCCC data and objects which contain data, per the TCCC Information Classification Standard and Protection Measures.
Yes, there are established policies and procedures for label inheritance of TCCC data and objects which contain data, per the TCCC Information Classification Standard and Protection Measures. Mechanisms for label inheritance shall be implemented for objects that act as aggregate containers for data.
Yes, we adhere to the retention policy that the tenant sends out for optimal collaboration and smooth user experience with Xoxoday's products and services.
Your data is of the utmost importance. All the security mechanisms and policies are established and implemented in such ways that data leak can be prevented, in transit as well as at rest.
Yes, the policy, process, and procedure is implemented to ensure proper segregation of duties. These can be asked for and delivered upon tenants' requests. In the event of user-role conflict of interest, technical controls shall be implemented to mitigate risk (if any) from unauthorized/unintentional modification/misuse of organizations' information assets.
Yes, our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC). All software development procedures are supervised and monitored by Xoxoday so that they include:
* security requirements
* independent security review of the environment by a certified individual
* code reviewsQuality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients' reference.
Yes, our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase.
Yes, an independent security review is conducted by certified professionals to look for any security vulnerabilities in order to solve them before deploying to production.
Yes, our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC) security standard.
Yes, changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates and modifications. Any change in roles, rights, or responsibilities shall be documented for a seamless experience.
We have a consistent and unified framework for business continuity planning, disaster recovery, plan development. All the appropriate communications shall be established, documented, and adopted to ensure consistency in business continuity. This includes protection against natural and man-made disasters (e.g. fire, flood, earthquake, war, volcanic activity, biological hazard, civil unrest, mudslide, tectonic activity, utility services outages, etc.).
Our hosting options are limited to Xoxoday's jurisdiction and are backed by prominent business continuity plans. Hence, we don't find the need to provide geographically diverse hosting options.
The capability to transfer infrastructure service failover to other providers is not provided to the clients.
Business continuity plans shall be subject to test at least annually or upon significant organizational or environmental changes to ensure continuing effectiveness.
Along with an aligned enterprise-wide framework, we perform independent reviews through industry professionals along with formal risk assessments. These are done at least annually or at planned intervals to determine the likelihood and impact of all identified risks. With qualitative/quantitative methods ensuring our compliances with policies, procedures, and standards, we stick to the best standards.
Yes, our stringent checks and tests are conducted annually to keep up the cloud service infrastructure hygiene as per the industrial standards.
Annual audits are processed both internally and externally. The audit results can be sent over to tenants upon request.
Yes, the tenants can request for penetration results and get the reports from our end.
No, we do not process your payment card data for any reason other than billing purposes.
Yes, we are compliant with the Indian IT Act of 2000.
There is no such process available from our end.
We will terminate the contract as per rules and statutes. Meanwhile your data will be stored with us and won't be given back to you. However, if the tenant wants the data to be erased, it can be done so upon request.
Yes, we store data that's required for seamless rewarding and recognition. We conduct regular audits to ensure safety of data like employees' names, emails, employee numbers, etc. are used for verification and rewarding purposes.
Xoxoday's information and cyber-security team keeps a watchful eye on all potential sources of threats and areas of compromise when it comes to information security.
Roles are systematically defined for information security measures to tactfully align all operations, preventing any security breaches.
Employees must agree with the acceptable usage policy of peripherals and devices to prevent malicious activities from the inside and out.
Our environment has all the capabilities to be SOC-2 Type-II compliant but the certification is yet to come through. It shall be updated soon.
No, our environment is not CSA-certified.
Xoxoday keeps track of all security requirements with respect to legislations, statutes, and contracts. They are documented in all steps.
We have our own procedure for control of documents and records that ensures compliance related to intellectual property rights and use of proprietary software.
Our record management criteria checks all boxes of legislative, regulatory, contractual and business requirements.
With different metrics tracking cyber-security measures, Xoxoday keeps the effectiveness in check with regular monitoring.
Xoxoday's Human Resource operation procedure takes all measures of employee confidentiality into consideration.
Yes, Xoxoday performs a thorough background check on every employee before they get onboard. The Non Disclosure Agreement ensures that the information is secure even after the contract is terminated.
Yes, our Xoxoday Store vouchers are procured from third-party vendors. These vouchers are shared with the tenants in order to be showcased to users of Xoxoday platform.
No, the third parties and vendors we deal with our confidential to Xoxoday. Hence, this list cannot be shared.
Yes, there's a third-party security policy present to safeguard the interests of Xoxoday's tenants as well as the end users.
Yes, our third party security policy deems it clear to comply with security obligations and we monitor their compliance regularly.
Yes, we have a detailed risk management procedure in place to address situational issues like change of services being provided to tenants.
No, our customer requests are addressed by the Xoxoday customer support team for maximum efficiency.
Yes, Xoxoday's brand protection caters to any malicious interruptions and fallacies as they are addressed in prompt time.
Yes, with media platforms being the biggest pedestal for information sharing, we keep an eye out for any brand protection issues.
Yes, in the event of a rapid spike/slump in network traffic or host activity, Xoxoday analyzes the traffic to detect and prevent unauthorized or erratic behavior.
Yes, in order to ensure airtight security of data, we have a mandatory and sessional privacy training and awareness module.
The Cloud Security Alliance (CSA) is the world's leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment.
Yes, Please visit the link to view the registry - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday)
Important features of CSA STAR LEVL – 1 are listed below
* Operating in a low-risk environment
* Wanting to offer increased transparency around the security controls they have in place.
* Looking for a cost-effective way to improve trust and transparency.
Yes, we ensure the same as part of our code review, static code analysis, and Web Application Firewall.
Yes, We comply with these requirements. Our Cloud Security Platform, (CSP) Amazon Web Services (AWS) provides these securities to our data centers.
Production data shall not be replicated or used in non-production environments. We do not use LIVE data in any other environment. We comply with the requirement.
We take prior authorization from the concerned authority as per the Media protection procedure before relocation or transfer of hardware, software, or data to an offsite premises.
As per Mobile Security Compatibility compliance requirements we have a documented application validation process to test for mobile device, operating system, and application compatibility issues.
The California Privacy Rights Act (CPRA) is a state-wide data privacy bill that amends and expands the existing California Consumer Privacy Act (CCPA). The CPRA works as an addendum to the CCPA, strengthening data privacy rights for California residents, tightening business regulations, and establishing the California Privacy Protection Agency (CPPA) as lead enforcer and supervisor.
Yes. We are compliant with CPRA, and Our solution will continue to offer full compliance with the new and updated data privacy regime.
Yes. We support our consumers to exercise their rights as per the CPRA.
Yes. We have implemented all the privacy controls and audited the same with the help of external Auditors.
Yes. Please reach out to our sales representative/Xoxoday POC to have access to the CPRA report.
No. We do not collect any data from any users across the globe who are not 18 years old.
Yes. The data subject can authorize an agent (an "Authorized Agent") to exercise their rights. To do this, the data subject must provide your Authorized Agent with written permission to do, and we may request a copy of this written permission from your Authorized Agent when they make a request to exercise the rights.
You may submit a Valid Request by emailing [cs@xoxoday.com](mailto:cs@xoxoday.com).
No. We will not sell, rent, or share Personal Data with third parties outside of our company. But Personal Data may be provided where we are required to do so by any privacy laws.
SOC 2 compliance is part of the AICPA Service Organization Control reporting platform. The goal of SOC 2 is to evaluate organization security and internal controls around security, availability, processing integrity, confidentiality, and privacy.
SOC 2 Compliances are developed by the American Institute of CPAs (AICPA), it defines criteria for managing customer data based on five "trust service principles"—security, availability, processing integrity, confidentiality, and privacy.
Yes. Xoxoday is SOC 2 certified organization. We have implemented all the required SOC 2 controls and got them Audited with the help of Certified Public Accountants (CPA).
Amazon Web Services (AWS) has achieved SOC 1, SOC 2, and SOC 3 reports. These reports detail the AWS controls environment and implemented controls for AICPA Trust Services Criteria (TSC) and can be leveraged as part of a cloud customer security program. AWS SOC-covered cloud services are audited periodically against the SOC reporting framework.
You may reach out to our sales representative/Xoxoday POC to have access to the SOC 2 report.
Laika Compliance LLC performs the SOC 2 audit for Xoxoday.
The SOC 2 Type I report is valid for one year following the date the report was issued.
Yes. SOC 2 is an internationally recognized standard. The SOC 2 report and certification involve an independent audit by a third party.
Yes. We do conduct the SOC 2 Audit on an annual basis.
The Auditor has validated and tested all the applicable SOC 2 controls as per the compliance requirements.
We do not process (Collect/Store) Protected Health Information (PHI).
Yes. Xoxoday is compliant with Health Insurance Portability and Accountability Act (HIPAA).
Yes. Please reach out to our sales representative/Xoxoday POC to have access to the HIPAA Audit report.
Yes. We have implemented the Data Subject Access Rights Procedure to make sure that all the data subjects will have the opportunities to exercise their rights as per the privacy laws.
The secure deletion standard like DoD 5220.22-M ECE is being followed and we provide a certificate that the data was properly sanitized from all computing resources and portable storage media.
Yes. Xoxoday is GDPR Compliant. We have implemented the Data Subject Access Rights Procedure as per the GDPR and made all the data subject rights available as per the data protection laws. This procedure sets out the key features regarding handling or responding to requests for access to personal data made by data subjects, their representatives or other interested parties.
Yes. We validate the compliance requirements of the Sub-processor and obtain the Compliance certificates and audit reports such as – ISO 27001:2013, SOC 2 Type II, ISO 27017, ISO 27701, ISO 27018, Cloud Security Alliance Controls, etc.
We conduct the independent Audits for - ISO 27001:2013, SOC 2 Type I, CPRA/CCPA, HIPAA, VA/PT Assessments.
Xoxoday maintains a disaster recovery program to ensure services remain available or are easily recoverable in the case of a disaster. Customers can stay up-to-date on availability issues through a publicly available status website covering scheduled maintenance and service incident history. The BCP and DR Plans are tested and reviewed every year. The Xoxoday BCP and DR plans are reviewed and audited as part of ISO 27001 standards and SOC 2 Type II covering availability as one of the trust service principles.
Users are not having admin access to their computer machines and only IT Support admins can install or uninstall the softwares.
CTOs and Production heads are responsible for safeguarding the customers data. Only authorised individual will have access to the production environment.
We delete the customer data upon request/termination of the contract and confirm the secure deletion. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
We clasify the Information assets into Confidential, Restricted , Internal and Public etc..
We maintain the records of all our assets.
we logically segregate the tenant's data, and it is segregated with a client-specific key for proper handling and security reasons.
We have restricted the ports for all the users as per Xoxoday IT Policy
The password needs to be minimum 8 characters long and should contain at least one capital letter, special characters among '# \$ % \* &' and 1 digit Maximum Password Age – 45 days Minimum Password Age – 1 day Computer machines will lockout in 15 mins from the time it became inactive.
Yes. Only authorised individual have access.
We use best practices and industry standards to achieve compliance with industry-accepted general security and privacy frameworks. We use enterprise-class security features and conduct comprehensive audits of our applications, systems, and networks to protect customer and business data. Our customers rest easy knowing their information is safe, their interactions are secure, and their businesses are protected. Please click here to know about Xoxoday Security framework - [https://www.xoxoday.com/security](https://www.xoxoday.com/security)
We are compliant. We monitor the system performance.
Yes. We maintain current architecture diagrams that include data flows between security domains/zones
All operating systems are hardened as per Xoxoday hardening guidelines.
We are compliant. We have deployed our applications on AWS Virtual platform cloud.
Please click here for SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view)
Appropriate roles and responsibilities have been defined and documented. Finance, Leagl, Admin, Infosec departments are active part of it.
Since its SaaS platform is not applicable.
Yes. we conduct the testing on frequent basis to comply with the requirements.
Yes. Its compliant with ISO 27001 and SOC 2 trust service principles.
Yes. We mitigate all the risk identified.
We inform the customer if there is any incidents as per the security and privacy laws.
Yes. We do conduct an internal Audit.
Yes. Privacy and security is a part of the Master Service agreements.
Xoxoday is compliant with GDPR, HIPAA, CCPA/CPRA privacy laws. And we inform the customer if there is any data breaches as per the compliance requirements.
Yes. We provide report on SLA.
We do conduct an External Audit with the help of the independent auditor.
Yes. we conduct the assessment on annual basis.
AWS is a sub-processor as we are storing data on AWS VPC. And they are AWS SOC 2, ISO 27001, ISO 27017 and ISO 27018 certified We monitor the compliances of sub-processor on frequent basis.
We continuosly train employees on privacy and security.
Yes. We have member in our organisation with dedicated information security duties. Xoxoday's primary security focus is to safeguard our customers or users data. This is the reason that Xoxoday has invested in the appropriate resources and controls to protect and service our customers.
All our employees are having the unique log in IDs.
We have installed the firewall for maximum securty and configured to restrict unauthorized traffic
All are configured according to security standards as part of the build process
Its part of our Internal and external Audits and validated by the indeendent auditors.
We have implemented the access control policy and access will be provided only upon need and approval basis. Attached the access control policy.
We have track of the changes. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
We have installed Smoke detectors and Fire extinguishers for physical security.
security incidents reviewed to capture the root cause.
We are SOC 2 compliant and we have engaged Laika Compliance LLC, an independent assessor firm, to conduct a SOC 2 Type 1 and SOC 2 Type 2 examination for the Xoxoday Platform against the Security and Confidentiality Trust Services Categories.
Attached the ISO 27001:2013 certificate.
We provide Software as a Service.(SAAS). We are ISO 27001 certified and GDPR compliant. Attached the document.
We are ISO 27001 certified and GDPR compliant. Attached the document.
Since it's a SaaS prodcut and deployed on cloud virtual platform only authorised individual have an access to the our production environment on need and approval basis.
We inform the client to revoke access.
We use Google workspace and have secure mode of sharing the data.
We can manage all the enpoints centrally.
We have implemented the security measures to manage the risks introduced during the use of Organization's information assets used for managing Personally Identifiable Information.
We have a formal risk assessment process and conduct the risk assessment annually.
All the contractors/vendors have signed the NDA and contracts All the necessary clauses has been included in the agreements with regards to Confidentiality, liabilities, termination etc
Yes. We do conduct the Risk Assessment every year.
Yes. We have implemented the Data security and Information clasification policy. Attached the same.
Yes. They have signed for the agreements.
We have a biometric systems and access cards. only authorised individual can have access.
We have deployed Sensors for fire detection and fire extinguishers to detect and protect from the fire.
Yes, we will notify
Yes. Our Customer support team will notify.
Yes. We create an email accounts only after the approval from reporting managers.
We have not outsourced and does not create any email ids
Yes. IT Team is responsible.
Yes. We have a Email Security Policy and attached the same
Yes, we have implemented the security controls for email with the help of Google workspace and installed the end point security for all the laptops of the employees. All the incoming and outgoing attachments are scanned.
Yes.
Yes, We have implemented the Acceptable Usage Policy and have restricted for usage and access to internet.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. Since our application is deployed on AWS cloud we will ensure the best uptime in the insudtry.
Yes. All the changes takes place as per the change management policy implemented.
Yes. We have software register and only approved and licensed softwares will be used.
Yes, all are up to date.
Yes, we have capacity planning and monitor the hard disk space, RAM, CPU etc.
All the employees laptop is secured with Bitdefender end point security software
Yes
Yes. Taken into consideration
Annually
Yes. Attached the same.
We do consider all of these, addition to that we also validate the controls in place with regards to cloud security, BCP, Uptime etc. AWS is ISO 27001, SOC 2 Type II certified and complied with CSA start level 2. Please click here for more details about AWS Compliance Programs - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
Yes. We have an agreement.
We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications.
Xoxoday and AWS both are ISO 27001:2013 certified and implemented the change management procedure. We ensure that we follow the policies and procedures with regards to any changes to be made.
Yes. AWS is ISO 27017, ISO 27001:2013, ISO 2018, SOC 2 certified.
Yes. Attached the AWS ISO 27001 certificate
Yes. Tested our BCP plan
We ensure that we maintain confidentiality, integrity, availability and privacy of data collected, processes, stored through implementing policies and procedures. And we do conduct the internal and external Audits periodically to make sure that all the controls are working effeectively.
Yes
Yes
Since we have logically segregated the data and ISO 27001 certified and GDPR compliant we do not disclose or provide any of the the customer data.
Yes. Audited by the independent Auditor and all the aspects of Privacy, information security, BCP, DR, Production, VAPT has been validated.
NO
Production Site - No.17, Bhagyalakshmi Square, 2nd Floor, Sector 3, HSR Layout, Bangalore -560102 We have deployed our application on AWS Singapore. Since we have deployed our application on AWS cloud they only provide DR Services.
No other location
We provide our application to the customer. We have 230+ employees. 100+ employees are involved in the production/devolopment and we have a sepearate team for IT Support and Information security. We have provided separate computers to each employees. Altogether we are having around 250 computer machines. Our application is deployed on AWS cloud virtual platform.
We are ISO27001;2013 certified and GDPR compliant.Attached the ISO 27001:2013 certificate. We are SOC 2 compliant and in the last phase of final Audit. Attached the engagement letter that we have with our external Auditors.
Xoxoday is ISO 27001:2013 certified, GDPR compliant and SOC 2 type I certified organization and have all the required technical and organizational controls in place and auditred during the internal and external audits.
We are ISO 27001 Certified organization. We make sure that all the required records are maintained and compliant with the requirements.
Attached the Security Incident Reporting & Response Procedure and Incident Management Procedure
We have implemented the Information classification Policy to protect against unauthorised access, disclosure, modification, or other misuse. All our assets are labelled as per the requirement.
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provide a centralized control to administer, monitor and review all critical access. We have a role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates.
We have the Fire alarams, Smoke detectors, UPS, Temperature controler, Air conditioner, etc.. for protecting against the environmental hazards.
Yes, all our - both full-time and on-contract are bound by an agreement of non-disclosure and a confidentiality agreement as a condition of employment to protect the customers and tenant's information.
We use the CCTV cameras to monitor the building on a 24\_7\_365 basis. All the enterances, exit, restricted areas are under surveilance for security reasons.
Yes. We have the Information security team.
We are compliant
In accordance with Data Protection Laws, we make available to Controller on request in a timely manner such information as is necessary to demonstrate compliance by Processor with its obligations under Data Protection Laws. Upon Controller's written request and subject to the confidentiality obligations set forth in the Agreement, we will make available to Controller a copy of Nreach the most recent third-party audits or certifications, as applicable. We do not agree for the Surprise audits.
We have the Buiness continuity and Disaster Recovery Plan in place. These controls has been tested at least annually as per the compliacne requirements. Attached the policies for your referrence.
We have the Crisis management is in place. Attache the same. We have provided an option to work from home/remotely due to this pandamic with necessary infrastructure and security. Business continuity plan has been tested on annual basis and audited during the internal and external audits. Atatched the business continuity policy and plan.
Generic IDs are not used
[Please click here for SLA - https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view)
We have the ability to delete the data upon request by the data subject or termination of the contract. Attached the data retension and disposal policy.
We have implemented the Business continuity policy and we have the ability to resume our operation from potential threats, Pandemic, flood, fire, earthquake etc. Due this pandemic/WFH situation, VPN access has been enabled with 2FA For such authorized individuals, for ensuring business continuity. We have the required controls in place for working from home or remotely due to this pandemic situation.
Its a part of our Business continuity plan and IT Support Head, HR Head, CTO, Infosec Head will be involved in the preparedness activities.
We have provided WFH option to all the employees to get protected from COVID 19.
We have provided WFH option to all the employees to get protected from COVID 19.
We test the Business continuity plan on annual basis. It was tested in the month of Aug 2021 for the last time.
It has been well defined in the in the Business continuity policy and plans. Attached the same for your referrence.
We inform our customer on any crisis and if that is effecting on our customers.
Xoxoday is a data processor.
NO. We obtain consent before such activities from the customer.
We have the DPA and appropriate controls in place – We are compliant.
ISO 27001;2013, SOC 2 Type I Certified and GDPR compliant.
YES. We have implemented the Business continuity plans and tested them annually.
No. But we are in the process of getting the insurance from the Insurance company.
We conduct the internal and External audits on a periodical basis as per the compliance requirements and obtain Audit reports and certifications. We provide the same with the customers.
NO. We are not subjected to any actions as such.
application by Xoxoday, the RnR platform is a cloud-based SaaS platform hosted on VPC infrastructure of AWS. The data centers are hosted completely in isolation so that the access is limited and controlled. Each instance (EC2 Instance) under fortified VPC network is further conglomeration of Docker Container Web Services and APIs and application layer running on top of it. This helps in managing various aspects and features of application without affecting the functioning of each other and achieving a modular architecture to work as plug and play model. Amazon Cloud Watch is implemented to enable monitoring of the functioning of the application. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, and the data has been encrypted for security reasons. Attached the Architecture diagram.
Xoxoday is ISO 27001:2013 certified and GDPR compliant.
Xoxoday is ISO 27001:2013 certified and GDPR compliant. And we follow ISO 27001, NIST, CSA standards and best practices. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, Coudflare and the data has been encrypted for security reasons. We conduct code reviews as per the compliance requirements. We also conduct the Vulnerability assessment and penetration testing on annual basis with the help of the third party authorised vendor. Attached the latest VAPT certificate and ISO 27001 certificate.
Attached the ISO 27001:2013 certificate and 1st Year Surveilance audit report. We did not have any non-confirmities.
We are compliant with the data privacy and security requirements. We are having the controls in place with regards to Cyber security, Risk management, crisis management, business continuity, Network security, application security etc. Attached the Business continuity management and Cyber Crisis Management Plan, incident management procedures, SDLC etc.
Attached the Business continuity plan and procedure. We test the BCP controls on annual basis as per the compliance requirements and it has been auditted during the internal and external audits.
Xoxoday is ISO 27001:2013 certified, CSA START Level 1 and GDPR compliant. And we follow ISO 27001, NIST, CSA standards and best practices. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, Coudflare and the data has been encrypted for security reasons. We conduct code reviews as per the compliance requirements. We also conduct the Vulnerability assessment and penetration testing on annual basis with the help of the third party authorised vendor. Attached the below policies and procedures - 1. Encryption Policy 2. Password Management Policy 3. IT Policy 4. Information Classification Policy 5. Threat and Vulnerability Management 6. Cyber Crisis Management Plan 7. Backup Recovery Procedure 8. Access Control Procedure 9. Incident Management Procedure 10. Change Management Procedure
Data centers are designed to anticipate and tolerate failure while maintaining service levels. In case of failure, automated processes move traffic away from the affected area. These are tested on annual basis. AWS is also ISO 27001, ISO 27017, ISO 27701, ISO 27018, SOC 2 compliant organizatin. Please click here for more details - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) Please click here to know more about AWS security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/) Please click here to know more about Xoxoday Service level agreement - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view)
Please click here to know more about Xoxoday Service level agreement - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view)
Please click here to know more about data governance - [https://www.xoxoday.com/gdpr](https://www.xoxoday.com/gdpr)
Attached the Risk Management Procedure
We have plan for having the cyber insurance. - In progress.
Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. We have implemented the Information security policy and Disciplinary policy.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
Please click here to know more about the Application SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view?usp=sharing](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view?usp=sharing)
We review and get an approval from the management on annual basis as per the compliance requirements.
We have installed End point security on all the computers and monitored and updated on regular basis.
Yes. Our tenants can report the Bugs and security vulnerabilities to [cs@xoxoday.com](mailto:cs@xoxoday.com) We also have Bug Bounty Program at Xoxoday and please click here to know more about - [https://www.xoxoday.com/bug-bounty](https://www.xoxoday.com/bug-bounty)
Since application is a SaaS platform and deployed on AWS virtual platform cloud
NA. We have the full time employees.
We conduct the review and update the policies, procedures etc..and take an approval from the management on annual basis as per the compliance requirements. We also communicate all the policies and procesures to all the employees, contractors through HRMS platform.
We do not allow to access the infrastructure hosting.
All the information security policy and standards been approved by senior management.
We have installed the antivirus on all the workstations and servers.
Customer data security is an essential part of our product, processes, and team culture. Our facilities, processes and systems are reliable, robust, and tested by reputed quality control and data security organizations. We continuously look for opportunities to make improvements in the dynamic technology landscape and give you a highly secure, scalable system to provide a great experience. Attached the GDPR - Data security policy.
We have installed Bidefender endpoint security and restricted the access of external hard drives, USB etc to have restriction on data transfer. we use file integrity and network intrusion detection (IDS) tools to help facilitate timely detection, investigation by root cause analysis, and response to incidents
We do not use.
Annually
We have conducted the BCP test on 6th Aug 2021. Attached the Business continuity policy.
We have installed Smoke detectors and Fire extinguishers for physical security.
Attached the incident management procedure. All our policies are reveiwed annuaaly and approved by the top level management.
security incidents reviewed to capture the root cause.
Attached the Security Incident Reporting and Response Procedure
Classification of Incidents are done. Attached the Incident Management Procedure
No Security breaches till date.
We are SOC 2 compliant and we have engaged Laika Compliance LLC, an independent assessor firm, to conduct a SOC 2 Type 1 and SOC 2 Type 2 examination for the Xoxoday Platform against the Security and Confidentiality Trust Services Categories. Attached the engagement letter.
Attached the ISO 27001:2013 certificate.
We make sure that they have adequate controls in place and meet the security standard.
We are ISO 27001 certified and GDPR compliant. Attached the document.
We review these to make sure the all the controls in place.
We provide access only upon need and approval basis.
We use Google workspace and have secure mode of sharing the data.
We can manage all the enpoints centrally.
Attached the Risk Management Procedure
We have a formal risk assessment process and conduct the risk assessment annually.
All the contractors/vendors have signed the NDA and contracts All the necessary clauses has been included in the agreements with regards to Confidentiality, liabilities, termination etc
The SaaS solution is deployed on Public cloud.
Yes
Yes. We are using Bitdefender endpoint security.
Yes. We use for security reasons
Our employees will not have access by default. The data will be accessed only upon need an approval basis. The access is controlled through the AWS Identity and Access Management system that also enforces two-factor authentication
We collect only 3 types of the personal Information such as Name, email ID, phone#. , personal data is to be transmitted using firmly approved encrypted systems. We have implemented the role based acccess control to make sure that the acccess has been granted to only authorised individual.
Yes.
Yes. We inform the client about any security incidents.
Yes. Attached Incident management policy and SLA
Yes
Yes
We are compliant.
Yes, We are ISO 27001:2013 certified. Attached the certificate.
We are SOC 2 Type 1 compliant. The audit has been completed and auditor is working on the Draft audit report. We will be able to share once the report is finalized.
NA. But AWS Virtual platform cloud is ISO 27017 and 27018 certified and attached the report.
NA. We do not handles the card holder data.
the customer will be using the application product and all the information will be entered only through our application.
The data sharing between vendor and the customer will take place only through application product. There will be no manual data sharing or transfer.
PII will be entered through application and stored it on AWS cloud virtual platform. We store Name, email ID and phone number of the users.
We do not have any sub-contractors. We have deployed our application on AWS Virtual platform cloud. And AWS is ISO 27001, SOC 2, ISO 27017, ISO 27018, ISO 27701, CSA Compliant etc..
We have deployed our application on AWS Virtual Platform cloud. application is a cloud based application. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client's key is unique We do not decrypt the data until and unless if there any specific request from the customer.
Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week ("Agreed Hours of Service"). Uptime is measured based on the monthly average of availability, rounded down to the nearest minute. Please click here to know about Xoxoday SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) Xoxoday has a formal Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) defined and implemented to enable people and process support during any crisis or business interruptions. The BCP and DR Plan is tested and reviewed on a yearly basis as per the compliance requirements. The BCP and DR plan of Xoxoday is reviewed and audited as part of ISO 27001 standards and SOC 2 Audits by the independent auditor. Attached the Business Continuity Plans (BCP) and Disaster Recovery Plan (DRP) documents.
Since it's a SaaS platform, there are no process as such.
Attached the below mentioned coompliance certifications - Attached the Audit reports. 1. ISO 27001 certificate 3. VAPT Certificates 4. VAPT Audit reports 5. SOC 2 Audit reports. 6. GDPR Data Privacy Impact assessment report 7. California Privacy Rights Act (CPRA) attestation report. 8. CSA STAR LEVEL 1 compliant - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) We conduct these audit on annual basis and we will share it upon request.
We always provide our best service to resolve security incidents / outages. Attached the Service Level Agreement (SLA)
Xoxoday is committed to ensuring the integrity, confidentiality, availability, and security of its physical and information assets and maintaining privacy when serving the customers and organization's needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially. Xoxoday will implement procedures and controls at all levels to protect the confidentiality and integrity of information stored and processed on its systems and ensure that information is available only to authorized individuals as and when required. Please click here to know more about Xoxoday Security - [https://www.xoxoday.com/security](https://www.xoxoday.com/security)
We have deployed our application on AWS Virtual platform cloud - Singapore region. We are GDPR compliant. And we have an agreement and Standard contractual clauses (SCC) as per GDPR Compliance requirements.
NO
NO
No. There were no Personal Data Breaches.
Xoxoday is committed to ensuring the integrity, confidentiality, availability, and security of its physical and information assets and maintaining privacy when serving the customers and organization's needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially. Xoxoday will implement procedures and controls at all levels to protect the confidentiality and integrity of information stored and processed on its systems and ensure that information is available only to authorized individuals as and when required. Attached the below documents - 1. ISO 27001 Certificate 2. SOC 2 Audit report. 3. California Privacy Rights Act (CPRA) attestation report. 4. VAPT Certificates 5. GDPR DPIA Assessment report. 6. CSA START LEVEL 1 Compliant - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) the customer can request the Xoxoday POC for these reports and we will provide the latest Audit reports upon request.
We are storing all the customer data on AWS Virtual platform cloud – Singapore region and consider AWS as a Sub-Processor as per EU GDPR. AWS is ISO 27001, SOC 2, ISO 27017, ISO 27018, CSA STAR, ISO 27701 certified organization. Please click here to know about AWS Compliance offerings - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
Scope and functionalities are the part of the agreement.
Please click here for SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) We do not offer any credits/ penalties.
We have implemented all the technical and organisational measures to ensure the integrity, confidentiality, availability, and security of its physical and information assets and maintain privacy when serving the customers and organization's needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially.
[ISO 27001 certificate VAPT Certificate SOC 2 Audit reports. California Privacy Rights Act (CPRA) attestation report. CSA STAR LEVEL 1 compliant - https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday We have shared these certifications and Audit reports.](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday)
We do not process the data for other purposes than the one specified in the contract,
We do not share the data with third parties. But we store it on AWS Virtual platform cloud and we consider AWS as a Sub-processor. We do not disclose any of our customers personal information to any third parties. We reserve the right to disclose PI if required by law or if we reasonably believe that use or disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with a law, court order, or legal process. We reject any non-legally binding requests for disclosure.
We process only the Name, phone# and Email ID as mandatory information.
We process the information as per the terms of use - [https://www.xoxoday.com/terms-of-use](https://www.xoxoday.com/terms-of-use)
We are storing all the customer data on AWS Virtual platform cloud and we operate or provide services from Bangalore, India.
We inform the customer of any changes in regards to changes in sub-processors.
Xoxoday Terms & conditions - [https://www.xoxoday.com/terms-of-use](https://www.xoxoday.com/terms-of-use)
Yes, the cloud provider does have a right to suspend services for specific reasons; more detailed in Section 3.3 of the Master Services Agreement. Section 3.3(a) read along with Section 2 of the MSA
The Contract is subject to the laws of India. For disputes arising under this contract, courts of Delhi has an exclusive jurisdiction. Arbitration & Conciliation Act, 1996
We conduct the periodical Risk assessment. and it has been audited during the internal and external audits.
We also provide SLA performance report to the customer on need basis.
we have the capability to respond to security alerts, and report security vulnerabilities and information security incidents within 24 hours of discovering them
[We also have Bug Bounty program - https://www.xoxoday.com/bug-bounty](https://www.xoxoday.com/bug-bounty)
We train our employees on their role and responsibilities and also comminicate before joining the organizatin
application is an all-in-one employee engagement and motivation platform that offers Rewards & Recognition, Pulse Surveys, 1-on-1 Feedback, Social Intranet and People Analytics in one powerful solution.
Information security department is responsible for security initiatives and the Head of the Information security reports to the Board of Director of the company.
The policies and procedures have been created, reviewed and approved by the Top level management of the company.
The information security policies have been uploaded on KEKA HRMS Application and communicated to all the employees. Attached the screenshot for your reference.
Attached the Risk Management Procedure.
Attached the internal audit report.
Your data is of the utmost importance. All the security mechanisms and policies are established and implemented in such ways that data leak can be prevented, in transit as well as at rest.
We have installed Bitdefender endpoint security in all the endpoints. Bitdefender is based on a layered next-gen endpoint protection platform with the industry's best prevention, detection and blocking capabilities, using proven machine learning techniques, behavioural analysis and continuous monitoring of running processes.
We have the capability to wipe out the data remotely for all endpoints including BYOD devices.
Attached the ISO 27001:2013 certificate and Statement of applicability.
We provide tpliance certifications upon request.
We use the Software Development Life Cycle (SDLC) process. It is aligned with ISO 27001;2013 and SOC 2 frameworks.
During the development and testing security related requirements are specially considered.
We have SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user.
We can also provide uptime status on a need basis.
We have proper forensic procedures for data collection and analysis for incident responses
Yes, in case specific incidents arise for particular tenants, our logging and monitoring framework allows isolation of incidents.
Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Uptime is measured based on the monthly average of availability.
We do not offer any penalty.
Attached the SLA
Attached the below documents - 1. ISO 27001:2013 certificate 2. VA/PT Certificate 3. VA/PT Executive report 4. application Architecture Diagram 5. We have deployed our aplication on AWS Virtual platform Cloud and attached AWS Compliance certificates - ISO 27001, ISO 27017 & ISO 27018. 5. application SLA
Customer Support is available on all working days (Mon - Fri) between 3.30 AM GMT to 1:30 PM GMT.
Xoxoday is – ISO 27001:2013 certified CPRA (California Privacy Rights Act) EU GDPR Compliant CSA STAR LEVEL 1 Compliant – Click here Vulnerability Assessment and Penetration Testing (VAPT) Attached these above certificates and Reports.
The backups are automated and taken on a daily basis. We delete the data upon receiving the request from the customer/end users/termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
We have an ELK setup in place to ensure data monitoring in the most optimal manner. The audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
As per the SDLC Policy we follow several distinct stages, including planning, design, building, testing, code review, deployment and maintenance etc. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase.
It would depend on the criticality of the investigation and the type of service subscribed. Our team will be able to provide the ETA as soon as they receive the request from you and start acting immediately.
Yes. You can check this information from the user management option available for Admin console.
You can reach out to us with the help of the help center or can write an email to customer support team
Yes. We maintain and record the Audit logs and complying with various compliance requirements.
Yes. You may reach out to our support team anytime for requesting these records and they would be able to help you out on this requirement.
It would depend on the criticality of the investigation and the type of service subscribed. Our team will be able to provide the ETA as soon as they receive the request from you and start acting immediately.
Yes. We deployed our application on AWS and AWS provides the data backup service as well.
Yes. We are ISO 27001:2013 certified and GDPR Compliant.
We have implemented the risk assessment procedure and conduct the risk assessment annually as per the compliance requirements.Risk assessment is used to identify the risks encountered by the information-processing facilities (or individual system components). The aim is to estimate the impact and probability of a threat occurrence. The risk assessment procedure is having Risk, Likelihood and Impact. The risk ranking is done based on the Residual Risk Rating such as High, medium and low. Attached the Risk Management Procedure for your reference.
Risk Management Procedure has been used to validate the security compliance of AWS. AWS Compliance certifications and attestations are assessed by a third-party independent auditor and result in a certification, audit report, or attestation of compliance. AWS is ISO 27001, SOC 2 Type II certified and complied with CSA start level 2. Please click here for more details about AWS Compliance Programs - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
Yes. We can use the risk assessment framework adopted by NSE for cloud service risk assessment.. Please provide the same.
We comply with this requirement. The risk assessment procedure has defined the Risk Acceptance Criteria, Benefits, Components, Impact Rating, Risk Treatment, Risk Acceptance etc and all the controls identified in our risk assessment as per the industrial standard like ISO, SOC2, NIST, GDPR etc.
Sure. We are ISO 27001;2013 and GDPR compliant. We have policies and procedures in place with all the required compliance controls.
We comply with this requirement. We conduct annual audit by the independent auditors to test the controls in place with regards to Information Security management system(ISMS) and also for testing the service organization controls(SOC)covering the principles of Security, Availability, Confidentiality, and Privacy. AWS is also SOC 2 certified.
Sure. Attached the ISO certificate and we are in the Audit process for SOC 2. we will provide the same once the audit is completed.
We are ISO 27001;2013 certified, GDPR compliant and in the process of SOC 2 audit. We make sure that our customer data is safe and secure and meet all the compliance requirements and industry best practices. Xoxoday has built the Information Security Management System (ISMS) which includes the respective policies to be followed in a diligent, consistent, and impartial manner.
Our legal team would review and agree the terms and conditions.
We agree. NSE can review.
Our legal team would review and agree the terms and conditions.
We will inform NSE if there is any breach.
The data isolated between customers. We use logical data isolation with the help of company specific encryption keys.We use TLS1.2 encryption for Data in transit and AES256 for Data at rest
We agree. We have implemented the data breach notification procedure.
We agree. We will notify NSE.
We agree.Currently, we do not have any plans as such.
All the data will be stored on AWS cloud We have the disposal policy in place and implemented mechanisms for secure disposal and removal of data.
We agree. We will delete the data upon termination of the contract or request and confirm. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
We have implemented Asset Management Procedure in place and maintain all the records of IT Assets like, hardware, software, licenses, accessories etc.
We review and update the inventory as per the Asset management policy.
The database server, application server or storage devices hosting NSE's data & information is not made available publicly. We isolate our machines, network and storage with respect to the AWS Standards in order to keep it safe and secure
Yes, one can write to us at our 24\*7 support team at [cs@xoxoday.com](mailto:cs@xoxoday.com)
We help the clinets in setting up from both admin and end user side, and traiing is also provided on how application can be used for hasslefree awards distribution
We provide trainging over internet , if possible we provide telephonic assistance also.
Yes we provide "on demand training" , this incur no additional cost to the company
We have a 24\*7 available support team, once a ticket is generated , It is assigned to one of the cs team executive and we intent to solve the issue within next 24hrs.
Xoxoday employees and third party would have an access. We provide acess on case to case basis as per the Information security and access control policy. We also have role based access system to meet the compliance requirements of the data security . The data is hosted on Amazon Web Services (AWS)
We do conduct employees and contractors background verification as per the compliance requirements before onboarding process. We will onboard them only after passing the background verification. We are ISO 27001:2013 certified organization.
We conduct periodical review of the access provided and make the necessary chages as per the Role based access management and access control policy. We also conduct Internal and external audits in a timely manner.
Our Information security compliance policies and procedures are established and implemented to enforce two-factor authentication
We are ISO 27001:2013 certified organization The User access are monitored and recorded internally as per the compliance requirement and Access Control Procedures.
Yes we have implemented intrusion detection tools, we ensure timely detection and investigation in a prompt manner.
Yes. file integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation.
Yes. Implemented SIEM
Yes. All the controls are audited annually.
Yes, We will share the Data protection policy. Access control policy and Information security policies
Size of the team is 5 and all are having 5+ years of experience
personal data is stored are registered databases that comply to all necessary inputs of a standard inventory repository and its transit scrambled for maximum security.
We use AWS Platform for storing the data. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records.
As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system.
No. Planned downtime will not be calculated uptime
No. Planned downtime will not count against the SLA
We have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
We test it annually once as per the compliance requirements.
Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
We have Business Continuity Policy and Business Continuity Management Procedure in place and tested periodically. And also our Policies has been reviwed and Audited annually.
Yes. We have implemented IDS/IPS, Firewall and our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting
Yes. We have procedures in place to support Government
We have the clauses for suppporting local government and law enforcement requesting customer data in data protection policy. We will share the copy of it.
We have deployed our application on Amaon web services (AWS) AWS is designed to help us build secure, high-performing, resilient, and efficient infrastructure for our applications. AWS is also ISO 27001:2013 and SOC 2 type II Certified and provide all applicable security to the data center.
Yes. We have industry approved vendor called Appknox for Vulnerability assessment anf Penetration Testing. Appknox performs Static, Dynamic, API, and as well as Behavioral Analysis. And they helps to detect and address security vulnerabilities.
We collect only personal information through our application. We collect name, email ID and mobile numbers.
Yes. We have capabilities to anonymize data. By Anonymization users are able to make use of sensitive information without having access to the identifiable data items. And its used within a secure environment with employee access on a need to know basis.
No. we do not have it in hard copy
Yes. We conduct vendor Risk assessment and also external Auditor validate the critical vendor documentations during the annual and Internal Audit.
Yes. We have Information Security Program
Yes. We review Information Security Policies every year.
Yes. We have Information security risk management program
Yes. Our management is supportive and evaluate, Recommend and take action on security risks
Yes, we have Information security team and the Infosec head is reporting to Chief Operating Officer of Xoxoday.
Yes
Yes. Please visit here for more details - [https://www.xoxoday.com/bug-bounty](https://www.xoxoday.com/bug-bounty)
Yes. All the endpoint laptops that connect directly to production networks centrally managed
All the employees laptop is secured with Bitdefender end point security software. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory.
No. sensitive or private data never reside on endpoint devices. This is enforced throgh access control policy.
We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour.
Yes. Our incient response plan is tested every year as per the ISMS requirements.
We follow SDLC policy during the design phase of devolopment. See SDLC procedure attached
We have SDLC procedure and Information System Acquisition Development and Maintenance Procedure. Devolopers are trained on the Secure Coding Practices as soon as they joined our organization
We conduct vendor risk assessment and collect all the required security policies, procedures, VAPT reports, ISO 27001, SOC 2 reports. And also our internal and exteranal auditors validate the security controls of our crtical vendors during the Audit.
NO
NA. We do not have custom-built software
Yes
Internal Audit has been conducted by the inhouse Infosec and ISMS Lead Auditor. All the projects, business processes and ISMS controls has been included in the scope and opportunity of improvements has been communicated to all the respective teams with the remideiation plan. And the frequency of the Internal audit is annually.
We have the external Auditor for ISMS Audit. All the projects, business processes and ISMS controls has been included in the scope and opportunity of improvements has been communicated to all the respective teams with the remideiation plan. And the frequency of the external audit is annually.
See ISOIEC 270012013 Certificate and Internal Audit report attached.
NA. We do not use for own purposes
Yes
Yes. All the employees and third party service providers are required to sign Confidentiality Agreements to protect customer information as per ISMS compliance requirements.
We have dedicated IT Team and Admin team who looks after the hardware security and, we have implemented the security controls as per the ISO 27001:2013 and SOC 2 Compliance requirements. We are hosting our application on AWS, and they are providing physical security to our data centre. We have Asset Management Procedure in place to identify, classify, label, and handle the Information and Information assets according to their criticality and sensitivity. We have Media protection procedure to handle the locally stored data as per the Information security compliance requirements.
As per the Physical and Environmental Security policy we have security guards and CCTV Camera's to safeguard the office building and also to provide an access to the building only for the authorized individuals. We also have Media protection policy which also defines on how to handle the Paper documents as per the compliance requirements. Physical documents are handled with at most care and followed the policies and procedures of an organisation to make sure that the data is protected.
We have Physical and Environmental Security policy and Vendor management guidelines in place and working effectively. We have implemented controls on Physical entry, Securing offices, rooms, facilities, Working in secure areas, Delivery and Loading areas etc. Only the authorised individuals will get an access upon verification. And we also conduct periodical verification of the effectiveness of these controls periodically through internal and external Audit. We provide access to the outsiders or suppliers on approval and escorting mechanism of vendor management guidelines by issuing the access cards.
All our assets are classified, labelled, and maintained in the register by our IT Team. Access granted only to, authorized individuals. We have locked environment for our hardware's which would store the data. We also have implemented the Media protection procedure to protect the data which are stored physically.
Yes. Backups are stored in a safe place. We have backup Recovery Procedure and implemented the controls to protect the organization information asset from the damages that may be caused due to failure of hardware system, corruption of software, breaches leading to data destruction and or not being able to retrieve and use. We predominantly work on cloud-based infrastructure and the teams may consider adoption of Amazon Web Services which provides the Backup and Restore services to build scalable, durable and secure data-protection solutions. AWS claims the following benefits and the teams may evaluate the benefits to the respective context that may lead to realize the following outcomes: 1. Data Type and Durability 2. Flexibility and Scalability 3. Security and Compliance The following AWS based offering for the following use cases offered by AWS may be considered based on the contractual needs of the subject under consideration: 1. Hybrid Cloud Backup 2. Data Lifecycle Management 3. Tape Replacement 4. Global Data Resiliency 5. Data Backup 6. Archive & Compliance
We are ISO 27001:2013 certified and GDPR compliant organization. We have Information security policy and Data security policies in place with regards to data protection. We make sure that the below principle of data security has been followed as per the compliance requirements. 1. Fairness and lawfulness When personal data processed by us, we make sure that the individual rights of the data subjects must be protected. We will ensure that the personal data is collected and processed in a legal and fair manner. 2. Confidentiality - Restriction to a specific purpose We make sure that the any processing of personal data should be lawful, fair, and transparent. Personal data will be processed only for the purpose that was defined before the data was collected. Subsequent changes to the purpose are only possible to a limited extent and require substantiation. 3. Transparency We make sure that we maintain the transparency with regards to the data collected, stored and disposed. We also provide rights to data subjects as per the GDPR compliance requirements. For ex - Right to Rectification, Right to Portability and Right to be Forgotten. 4. Integrity and data security Personal data is subjected to the data secrecy. We have controls on confidentiality, Integrity and data security. We follow secured suitable organizational and technical measures to make sure that the data is protected from an unauthorized access, illegal processing or distribution, as well as accidental loss, modification or destruction etc. Sensitive data - We do Inform involved parties about how we will process their data Inform involved parties about who has access to their information Have provisions in cases of lost, corrupted, or compromised data Allow involved parties to request that we modify, erase, reduce or correct data contained in our databases. Sensitive data - We do not Communicated informally. Stored for more than a specified amount of time. Distribute to any party other than the ones agreed upon by the data's owner (exempting legitimate requests from law enforcement authorities. In addition to ways of handling the data the company has direct obligations towards people to whom the data belongs.
We have controls in place to protect the information or to maintain privacy. We conduct Data Privacy impact assessment and Audits periodically as per the compliance requirements. We have Personally Identifiable Information Policy, Data Security policy, Data Subject Access Rights Procedure, Data Retention and Disposal Policy as per GDPR compliance.
We conduct periodic vendor risk assessment. Information security documents are validated by theiInternal and external auditors during the assessments.
Yes.
We have an access control policy. The policy is attached for reference. Only authorised employees will have access to the data.
Yes. Xoxoday is ISO/IEC 27001:2013 certified organization. See certificate attached.
Yes. We have a well-defined policy for roles and responsibilities. We have communicated each employee about their responsibilities across the organization. We do maintain appropriate contracts with relevant authorities and ensure that applicable regulations are complied with
Yes. We provide these rights to the data subject as per GDPR
Yes. We conduct internal and external audits and all the applicable controls have been validated as per the compliance requirements.
Yes
We have a media handling procedure. See attached for reference.
No. We do not transfer the data outside our organization.
Yes. See Infrastructure Change Control Procedure attached.
Yes.
Security inceidents will be reported by our Information security team or customer support team within 48 hours.
We have implemented physical security controls as per the compliance requirements. We have CCTV, access cards, security guards for monitoring and only authorised individual have access.
Segregation is done for production and non-production or Testing environments. We maintain the test accounts seperately and delete or terminate the accounts immediately once the testing is completed. Only Admins have an access to create these tests accounts on need and approval basis.
We have implemented the Roles and Resposibilities policy and defined the Duties of all the system users and segragated based on the defined roles. Only authorised individual will have an access to the Information system on need and approval basis.
We maintain these records for Audit purposes.
We have controls in place to monitor the user access system. We have implemented Role based access management system through access control policy. Our application also supports Role based access control system to make sure that only authorised individual will have an access to the Information system on need and approval basis.
We maintain these records for Audit purposes.
We are Compliant. We monitor these controls on a periodical basis and also during the internal and external Audits. Successful and failed login attempts will be logged, we use privileged accounts are used only for system administration activities,we remove default credentials and use the new credentials for all our systems.
We use Multifactor authentication menthods to make sure that only authenticated individual have an access to the Information system wherever strong authentication is required. We use Biomentric verification and access cards methods for physical security purposes.
We have these controls in place. We have a restriction for Physical access, monitor these access periodically and validate to make sure that only the authorised individual have an access.
The credentilas has been comminocated via secured mode to make sure that confidentiality is maintained.
We are Compliant.These controls are audited during the internal and external Audits.
We are Compliant.Only authorised individual will have an access.
We are cothe customerant. We maintain the records of Audit logs.
We have restricted the access of external harddrives, USB etc for all the systems through Active directory and End point security.
We have the security controls in place. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network.
We have implemented the asset management procedure to identify, classify, label and handle the Information and Information assets according to their criticality and sensitivity.
We have labeled the aseets in order to identify and make sure that the access control permissions are maintained.
we have implemented intrusion detection and prevention tools, we ensure timely detection and investigation in a prompt manner.
These are integrated with security operations/SIEM solutions.
We take an approval from the concerned authority before procuring the equipment or routing connections and test the same before installing it.
All the network devices are securely configured and we always make sure that we monitor the same on regular basis and take appropriate action on any detections.
We use vendor supplied softwares without any changes wherever feasible, if all the security controls are in place.
We consider these factors before making these changes to the softwares.
Yes, we test the changes made on testing environment before moving it to a production environment.
Only authorised individual have an acces to the approved information assets.
we are compliant. We document or have a track of all the changes made to protect the information system.
We are compliant and have these controls in place.
We have the appropriate clauses in the agreements wherever necessary.
We provide guidance for using our products appropriately and take all the possible benefits.
We have the controls in place. All the Critical patches will be deployed immediately
We inform our customers on the vulnerabilities wherever is required from the compliance perspective.
Our product is free from dormant malicious programmes
We test the systems before deploying into operational environment.
We have implemented the System Devolopment Life Cycle procedures and all the testing of new features are documented.
We conduct security assessments before accepting the products and take appropriate approval to make sure that all the security requirements are met.
All the test results are documented.
We record these in the Risk register and documented before purchasing the product.
We make sure that these are met before acquiring and products.
The customer responsible staff can confirm upon validation of the security requirements.
All the design and implemetation has been documented. We conduct the security Risk assessment in order to identify and mitigate the risks.
We have kept Testing and production environment seperately. We do not use any data from our production environment for testing purposes.
All our contracts or agreeements are having appropriate clauses with regards to security compliance, privacy, Audit requirements etc.
we use only licensed softwares or assets
We are compliant. We maintain these records for Audit purposes.
We have not outsourced.
Attached the Information Security Manual. It prescribes the policies that govern the management and administration of the Information Security Management System (ISMS) for application.It specifies the scope and the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving the information security controls.
We have not subcontracted or outsourced any of services with regards to the product.
We have documented the Transfer of Information and it's a part of our Information security policy
We do not transfer the data. But if its necessary it will be done only upon the approval of the management.
We have documented the Transfer of Information and it's a part of our Information security policy
We do not transfer the data. But we follow these compliance requirements if there are any data transfers. We have implemented the Information security and Data security policies in order to make sure that we secure our organizational and customers information.
We maintain these records for Audit purposes.
We monitor and audit the logs.
We are complied. We have controls in place to make sure that Information system is protected.
We conduct the Risk assessment to identify and mitigate the risks involved.
We use Google workspace as email solution and adequate security features has been enabled to make sure that Information system is protected.
We do not connect.NA
We make sure that all the controls and compensatory controls are in place in order to protect against the Security threats.
We have implemeted the risk management procedure and defined the Risk Treatment, Risk Treatment, Risk Mitigation, and Risk transfer etc
We have implemeted the risk management procedure and defined the Risk Treatment, Risk Treatment, Risk Mitigation, and Risk transfer etc We implement the Compensating security controls wherever measures cannot be applied due to technical or operational infeasibility.
We maintain these records for Audit purposes.
It's a part of our Internal and external Audits.
We make sure that these controls are in place and security has not been degraded below the accepted level. We also validate these controls during our internal and external Audits.
We have implemented the role based access system and change management policy in order to make sure that we provide an access to an individual only upon need and approval basis. All the changes has been tracked and maintained the records for audit purposes.
We have a up to date records of all the assets used.
We make sure that we follow the Industry best practices and security standard to make sure that we secure the information asset.
We make sure that we follow the existing security controls and implement the compensatory controls to make sure that the information system is secure.
We have implemented the control.
We conduct the Risk assessment to identify and mitigate the risks involved.
Compliant.We review and validate these controls on a periodical basis and These are part of an Internal and external Audits.
Compliant.We review and validate these controls on a periodical basis.
We maintain these records for Audit purposes.
We have the required security controls in place.
We do not use outdated computer hardware, software, technology, services or practices
We upgrade the systems make sure that do not use outdated computer hardware, software, technology, services or practices
We have installed the end point security software on all the computers and servers to keep the computer and personal information protected.
We have installed the end point security software on all the computers and servers to keep the computer and personal information protected.
We are compliant.
We have enabled these features.
We have installed end point security softwares to safeguard from attack scripts, viruses, worms, Trojan horses, backdoors and malicious active content. We also conduct periodical scanning in order to make sure that all the information assets are safe. These are centrally managed and have control on all the end points.
It is available on need to know basis
We make sure the Vulnerability assessment has been conducted for our products as per the compliance requirements.
We are compliant.
the customer Sensitive information will not be exposed to the general public.
We document and maintain all the security issues.
We are complaint.
We are compliant. We have clasified, labeled our assets and periodically monitored. All the logs and realtime trafic is monitored.
Implemented. We are compliant.
These are all part of CSP agreement.
We have these controls in place as a part of our Business continuity plan.
We have these controls in place as a part of our Business continuity plan. It has been tested periodically and part of our internal and external Audit.
We have conducted the risk assessment as per the industrial standard.
Agreed. We will sign the NDA
SLA can be documented and agreed by the both the party.
Only authorised individual have an acces to the approved information assets.
We allow our customer to audit but atlease 30 days prior notice with the scope of the audit needs to be communicated
Its documented as per the Risk management procedure.
We have all the details in SLA
We can make our audit reports available
We maintain appropriate reports and records, to monitor and measure the compliance with the security requirements.
We make sure that we follow the risk management procedure and take these factors into consideration.
We have these in place and tested annually.
We have these in place and tested annually.
Our BCP/DR plan supports this.
We review these on annual basis
We have cmmunicated to all the internal and external parties.
It's a part of Business continuity documents and attached the same for your reference.
The BCP Test and lessons learned has been documented.
It's a part of BCP documents and we review and update when changes takes place.
These are part of internal and external audits
We have implemented the Corrective Action Procedure.
We have implemented the Corrective Action Procedure. We review rhe corrective action taken.
We conduc the security assessments by the Internal and external auditors
We share the data with our Internal and external auditors
We make sure the Assessments and Audits will be conducted and reported independently.
All the Sensitive information shall be handled as per Policies and procedures implemented.
We have defined it in our compliance policy and Corrective Action Procedure
We allow our customer to audit or assess but atlease 30 days prior notice with the scope of the audit needs to be communicated
We continuously monitor and improve Information security framework to make sure that we safegurd the Information and all the controls are in place.
We make sure that we brings these improvements to Information security systems from the incidents reported and audit observations etc
We have implemented the corrective action plan procedure and review the policies and procedures on annual basis.
It can be included in the agreement and our legal team will review and confirm
Statement of work will have a details of product/service to be provided
We can include the service levels in the agreement. We are not currently having an options for service credits/liquidated damages, if SLA are not met.
We make sure that we have all the controls in place.
We will do this as part of the agreement
We are a multi tenant SAAS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis.
Attached the BCP/DR documents
We end point security in place
We allow our customer to audit, but atlease 30 days prior notice with the scope of the audit needs to be communicated
We have deployed our application on Amazon web services (AWS) Virtual platform cloud. AWS provides data center security to our application. AWS is ISO 27001;2013, ISO 27017, ISO 27018, SOC 2 certified organization. Xoxoday is also ISO 27001:2013 and GDPR compliant organization. Only the authorised individual have an access as per Access control policy. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access. Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
Since our services are delivered via. Web, the upgrades and updates to the services are seamless and usually do not involve any actions from the end-users. We try to release our product hotfixes once every week & major features once every month.
Yes. Annually once.
Yes. We are ISO 27001:2013 and GDPR Compliant. We are also compliant with SOC 2 type 1 and on the last phase of Audit. We will share the report once we have it from the Auditor. Attached the ISO 27001 certificate and engagement letter that we have for SOC 2 Audit.
We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory
All the employees initially inform the IT Support team through ticketing systemb the Infosec manager and Final level will be DPO and the management.
The time of support ranges depends on the level of service. RTO and RPO is - 6 mins
our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC). All software development procedures are supervised and monitored by Xoxoday so that they include: security requirements independent security review of the environment by a certified individual code reviews Quality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients' reference.
The data centers are hosted completely in isolation so that the access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load experienced by application. Each instance (EC2 Instance) under fortified VPC network is further conglomeration of Docker Container Web Services and APIs and application layer running on top of it. This helps in managing various aspects and features of application without affecting the functioning of each other and achieving a modular architecture to work as plug and play model. Amazon Cloud Watch is implemented to enable monitoring of the functioning of the application. The data is encrypted using 256-encryption based SSL certificate. To manage security of data Xoxoday plans a quarterly VAPT based security audit of application.
We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. We use logical data isolation with the help of company specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system.
We comply with Information security compliance - ISO 27001;2013, SOC 2 and GDPR
Our product is ISO 27001 and GDPR compliant and have the features.
We have health checks along with Self healing mechanisms in place
99.99%
We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256. We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data. our network environment is designed and configured to restrict any communication and connection between the tenant's environment.
Yes. We have the controls in place. We have blocked connecting Hard disk, USB, CD ROM etc to computers and all the devices are centrally managed.
The data is only stored on our application and its deployed on AWS Cloud. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records
We are a SAAS solution. We are cloud hosted.
We use a variety of tools and plugins integrated with Prometheus & Cloudwatch along with health checks for facilitating our uptime/service availability
Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
active-passive
Yes. we have implemented the cookies policy
Yes, we have the access controls
Yes
Yes, we have the access controls
Yes. Users can updated their information
Xoxoday - application platform has been integrated with Darwinbox with the objective of creating a reward system for employees. Organizations that are using DarwinBox will not only be able to automate their HR processes but can also reward employees to keep them motivated and engaged. Xoxoday application offers a unified rewarding platform that helps organizations build a winning organizational culture through reward and recognition programs that have a global catalog consisting of products and experiences from more than 700+ brands. Please click here to know more - [https://xoxoday.gitbook.io/application/developer-resources/integrations/darwinbox-+-application](https://xoxoday.gitbook.io/application/developer-resources/integrations/darwinbox-+-application)
Yes. Xoxoday's primary security focus is to safeguard our customers or users' data. This is the reason that Xoxoday has invested in the appropriate resources and controls to protect and service our customers. We have an Infosec Manager who is responsible for Information security and reports to the Board of Directors of the company. All the job descriptions, role and responsibilities has been documented as per the compliance requirements.
Xoxoday has developed a comprehensive set of security policies covering a range of topics. These policies are shared with and made available to all employees and contractors with access to Xoxoday information assets. Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. We spread awareness about the Information security among the employees through posters in public areas, emails, training and orientations etc..
Yes. All new hires are required to sign Non-Disclosure and Confidentiality agreements. The Employee expressly agrees that he/she shall not use Confidential Information provided by the Company in the development or delivery or for personal gain from providing any products or services for his/her own account or for the account of any third party. The NDA signed will be valid till the termination from an employement.
Yes, We have implemented the process for termination from an employement. Once the employee is terminated all the access will be revoked, IDs are disabled, assets are returned and recorded as a part of the exit clearance. We have implemented the access control procedure and all the access will be revoked upon termination or transfer of an emplyees as per the compliance requirements.
Anti-Virus is deployed in all systems and servers for protection against virus and malware. We use Bitdefender end point security for protecting the systems from virus and this has been updated on daily basis and centrally managed.
1. Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com) to raise a ticket, if you happen to notice any potential security issue whilst meeting all the required criteria in our policy. 2. The validation of the reported issue in terms of severity & authenticity will be done by our security team in around 90 days. 3. Post validation, steps will be taken to fix the security issues in accordance with our security policies. 4. The owner of the ticket will be informed once the issue is resolved. Security Severity has been categorized as High, Medium and Low. Once the reported vulnerability is closed we will conform the same.
Reports can be generated by the admins through the application. If there are any additional support needed, our customer support team would be able to help and guide on generating report.
We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates.
[Please click here to know more about API Documentation - https://xoxoday.gitbook.io/application/user-guide/for-admins-1/xoxo-links/xoxo-link-apis https://xoxoday.gitbook.io/application/developer-resources/storefront-integration/api-endpoints](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis)
We have implemented the Web application firewall, IDs/IPs and amazon guard duty etc for maximum security. OAuth2 is used to authorize all API requests. We also conduct code review to make sure that the APIs are secure.
Yes. Our employees are having required education and certifications to perform the job.
We do conduct Internal and external Audit very year
Yes, It's a part og our ISMS training. Attached the training calender as an advace.
Xoxoday is compliant with - ISO 27001:2013, CPRA (California Privacy Rights Act), SOC 2 Type I, CSA STAR Level 1 and GDPR(General Data Protection Regulation). Attached the below mentioned documents. 1. Xoxoday ISOIEC 270012013 Certificate 2. Xoxoday SOC 2 Type 1 Report 2021 3. Xoxoday VAPT Certificate (Conducted by 3rd party vendor) 4. Xoxoday application VAPT Report (Conducted by 3rd party vendor) 5. Xoxoday CPRA Attestation Report 6. CSA STAR LEVEL 1 Compliant - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday)
We have deployed our application on AWS Virtual platform cloud. The AWS Compliance Program helps to understand the robust controls in place at AWS to maintain security and compliance in the cloud. Attached the below compliance certificates and Audit reports – 1. Amazon Web Services ISO 27001 Certificate 2. AWS ISO 27017\_certification 3. AWS ISO 27018\_certification 4. AWS SOC 2 Report 5. AWS SOC 2 Type I Privacy Report 6. AWS CSA STAR Certificate
Yes. We follow ISO 27001:2013, SOC-2 and GDPR We are ISO 27001:2013 certified and GDPR Compliant.
Yes. We are ISO 27001:2013 certified and GDPR Compliant. We are also complied with Cloud Security Alliance (CSA) STAR level 1.
Its SAAS Solution and available 24\*7
It's a web application. And it can be presented over the calls like MS Teams, Zoom, Google meet etc.
Yes. We have an integration with other applications and provide secure communications.
Yes
Yes. Files will be transferred securely.
Yes.
The solutions integrated with other solutions like Zoho CRM, HubSpot, Darwin box, SurveyMonkey, Freshdesk etc
NA. It's a SAAS Solution and does not require.
The data will be in our control. And AWS Cloud provide service for deploying our application. AWS is also ISO 27001 and SOC 2 certified organization and adhered to the data governance.
It's a part of our Risk assessment and we validate the compliance requirements of AWS cloud virtual platform annually.
We have implemented all the required Infosec Policies and procedures as per ISO 27001:2013, GDPR and SOC-2
We perform Internal Audit and external Audits annually. We also conduct Security assessments and testing like Vulnerability assessment and Penetration testing every six months. Yes. We communicate these assessment results to clients on a yearly basis.
We have the arrangements in place. Storage Period would be as per regulatory conditions. Personal data can be deleted based on a formal written request. Xoxoday would delete the data within 30 days of receiving the request. We will delete the data of the customers upon the termination of the contract and Our data cleansing process goes through an organized purge. Once the data is purged, it's purged from all places
We have implemented all the SOC controls and in the last phase of Audit. We would be able to provide SOC 2 Type I report in next 2-3 weeks
We have BCP/DR Policy as per the Infosec compliance requirements and we conduct the BCP test annually. See Business Continuity Management Procedure attached.
See attached Incident Management Procedure attached
Yes. An independent security third party audit been completed by "TUV NORD". The last last day of Audit was 29th June 2021
We have establised the Information security management systemIt specifies the scope and the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving the information security management system (ISMS) at Xoxoday. Xoxoday is committed to ensure Integrity, Confidentiality, Availability and Security of its Physical and Information Assets and also maintaining privacy for serving the needs of the customers and organization while meeting appropriate legal, statutory and regulatory requirements. Attached the Information Security Management System Manual.
We have the Data security Controls in place. We have implemented IDS/IPS, Firewall and our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting. We have Cloudflare web application firewall for maximum security of data. We have implemented the role based access control system to make sure that the data os available only to an authorised individual. Nreach Online Services Pvt ltd, respects the individual right to their personal information and is committed to use minimum personal data with transparency, accuracy & protection of confidentiality, integrity, availability, privacy, authenticity & trustworthiness, nonrepudiation, accountability and auditability of the data received, stored, processed and destroyed for business purposes. Atatched the Xoxoday GDPR Data Security Policy
We are compliant. We collect the data only throigh our application. We have role based access system to make sure that only the authorised individual have an access to the required information All the devices and emails are having adequate security controls. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory for more security. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.We have SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user.We also have Implemented least privilege; restrict users to only the functionality, data and system information that is required to perform their tasks.
Yes. We have Implemented the SPF/ DKIM/ DMARC effectively.
We are compliant. We have implemented the Password Management Policy We store password hashed. We have SHA512 hash with unique salt for every password. The password needs to be minimum 8 characters long and should contain at least one capital letter, special characters among '# \$ % \* &' and 1 digit. Maximum Password Age is 45 days. User IDs and passwords transmit through stringent checks in an encrypted format that complies with the current Technical Security Baseline Standards. All the user can set their own password from the very first login attempt. Passwords once used cannot be reused with the password history technique in order to disallow the reuse of old passwords.
[AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
We inform Fincare if these regulatory authories agreed to inform.
Yes. 30 days prior notice and scope of the Audit needs to communicated.
We are a multi tenant SAAS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis.
Its a SAAS product and we use We use TLS1.2 encryption for Data in transit and AES256 for Data at rest.
Yes
Yes
[We store data on AWS Singapore.AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
We do not own the data centers. We deploy our application on AWS cloud virtual platform.
[We store data on AWS Singapore.AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
Attached the ISO27001:2013 certificate. We do not collect and store any Payment card details. PCI DSS is not applicable for us.
We inform the client if there is any changes of the design that impacts security posture of the system.
We take steps to securely develop and test against security threats to ensure the safety of our customer data. We maintain a Secure development Lifecycle, in which training our developers and performing design and code reviews takes a primary role. In addition, Xoxoday employs third-party security experts to perform detailed penetration tests on different applications. application is ISO 27001, GDPR, CPRA/CCPA, CSA STAR certified.
Our technical team maintains these records.
We consuct the code review as per the compliance requirements and maintain the code repository. Attached the SDLC Proedures.
Compliant.
Since application is a SaaS Platform this would be not applicable.
Since application is a SaaS Platform this would be not applicable.
Since application is a SaaS Platform this would be not applicable.
We are compliant with the requiremenrts.
We do not transfer manually. NA And we use Google workspace for emailing solution.
cryptographic keys are protected. Compliant.
We do not store any PHI. The PII(name, email ID, phone#) are encrypted. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
We store only the PII(name, email ID, phone#) and does not store/process PHI & PCI. We are compliant with ISO 27001, CCPA/CPRA, EU GDPR, CSA etc. Attached these compliance certificates/audit reports.
Yes, all the mechanisms related to security and policies are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools.
The information used for authentication is securely stored and transmitted. We store password hashed. We have SHA512 hash with unique salt for every password
Not applicable since application is a SaaS platform.
At Xoxoday we use Google workspace and activated the MDM features. application also has iOS and Androind mobile applications.
This feature can be configured with the help of the MDM Solution that the customer use.
At Xoxoday we use Google workspace and activated the MDM features.
Compliant. We have segreated the roles and assign the responsibilities to our employees.
Since its a Cloud hosted SaaS platform deploying of the application on cloud and server scannings are under the scope of Xoxoday.
We use Web application firewall (WAF) and pfSense firewall for security reasons. 1. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. 2. pfSense helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules.
At xoxoday we monitor and maintain the logs. The Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
At Xoxoday we have implemented the Active directory and the system will get locked if its inactive for more than 15 mins and re-autentication would require.
We have the process in place for standardized approach to structured exception and error handling across all layers.
At Xoxoday the validation has been done during the development and testing and we are compliant with the requirements.
At Xoxoday Security and compliance requirements are considered during the development stage and we are ISO 27001, CPRA, CSA STAR level 1, GDPR compliant.
We have implemented the controls to monitor the application and safegurd from the attacks. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails.
Since application is SaaS Platform it would be not applicable.
We have implemented the Software Development Life Cycle (SDLC) procedure and attached the same for your reference. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing. We remidiate or fixes the issues identified during the VA/PT assessment and make sure that the application is free from the vulnerabilities.
Since it's a SaaS platform and deployed on AWS cloud virtual platform Singapore region. All the data will be stored on AWS VPC.
Xoxoday is ISO 27001:2013 certified. An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organisation's information risk management processes with the aim of keeping information secure. With ISO's robust information security management system (ISMS) in place, you gain the additional reassurance that a full spectrum of security best practices is implemented across the organization Our Goal is to protect three aspects of information - Confidentiality: only the authorized persons have the right to access information. Integrity: only the authorized persons can change the information. Availability: the information must be accessible to authorized persons whenever it is needed.
We have implemented the Access control policy to control the upload, download, viewing and modification
AV Scans takes place every week and users also can scan it whenever they can scan the machine. We have prescheduled the scanning once in a week.
We are using linux operating system which is inherently secure along with security practices like web application firewall etc We make sure that the customer data is well segregated and compartmantalized
No Breaches taken place.
We are having Robust Information security compliance framework and we are ISO 27001:2013 and GDPR complied. We follow all the applicable infosec compliance requirements to comply with the regulations
We conduct the Risk assessment and compliance review on annual basis as per the compliance requirements.
Yes. All the compliance and audit findings has been mitigated.
All the vulnerabilities identified during the assessment has been fixed.
We use Bitdefender end point security and installed on servers and development machines.
Its updated on regular basis.
Our roles and job duties are segregated through role-based access to ensure maximum security. Access to data and systems are based on the principles of least privilege for access. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events.
Its restricted and not available to the public.
We follow the best practices ans servers are hardened for security reasons.
We have implemented the Identity access management (IAM) and follow the Access control policy.
At Xoxoday we follow the password policy.
We have deployed our application on AWS Virtual platform cloud - Singapore region.
RTO and RPO is 60 Minutes.
We have implemented the Incident Management Procedure and attached the same for your reference.
Since application is a SaaS product and the customer can use the product and services as soon as subscribed for application product usage. the customer will have the legal rights to use the Product.
We do not change the terms frequently. We will provide 30 days' notice period for any changes of terms.
We notify Client in case of any unauthorized disclosure of or breach of any confidentiality obligation of Xoxoday with respect to Confidential Information, data or information of Client and Xoxoday shall take all necessary and required steps and measures to mitigate such unauthorized disclosure or breach and shall co-operate with Client , at Xoxoday 's cost, to mitigate or control the loss or liability arising out of such disclosure or breach and to retrieve such data or information.
Yes. have an active SLA in place that identifies minimum performance of the Product.
We have the SLA in place. application endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Uptime is measured based on the monthly average of availability.
We would be able to provide a report on need basis.
No penalties are associated with SLA.
We monitor the service continuously and make sure that the product and service is available to use all the time. We have a documented Business Continuity and Disaster Recovery Plan defined and implemented to enable people and process support during any crisis or business interruptions.
Since our services are delivered via. Web, the upgrades and updates to the services are seamless and usually do not involve any actions from the end-users.
Yes.
Our architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows. If there is any major activity and the service will be unavailable, the Maintenance hours were communicated well in advance at least 3-4 day by application.
Termination clause will be the part of Master Service agreement and both the parties can review and agree during entering into an agreement.
Since it's a SaaS product, this is not applicable.
Termination clause will be the part of Master Service agreement and both the parties can review and agree before entering into an agreement.
Yes. changes to the production environment or development are documented, tested, and approved prior to implementation or any new releases. We conduct internal reviews and audited by the external auditors for our security standard certification. We conduct periodical Vulnerability assessment and Penetration Testing from the Industry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications.
the customer data will stored on AWS virtual platform cloud Singapore. There is no impact on security.
At Xoxoday we have implemented the Cyber Crisis Management Plan to provide and support capability for reporting and responding to cyber security incidents, to eliminate or minimize impacts of such incidents
No.
We monitor the logs on regular basis with regards to network, file and server, and security system. To provide more information, the infrastructure logs are collected using AWS Audit Trail and Application related logs are collected in our Elastic Search server and retained in long term cloud storage.
No. Since we are a multi-tenant system, our logs contain information of all the tenants. We cannot isolate a single customer's information from our logs.
At Xoxoday the Audit logs reviewed on a regular basis for security events. audit logs are set up, reviewed by our Technical team and logs are recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
We are GDPR Compliant. Our information security team and Customer support team will inform the POC of Client via email communication with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions.
Yes. We have implemented the incident response plan and it complies with industry standards ISO 27001:2013, SOC-2, GDPR.
We are ISO 27001:2013 certified and attached the certificate.
Yes, there are established policies and procedures for label inheritance of TCCC data and objects which contain data, per the TCCC Information Classification Standard and Protection Measures. Mechanisms for label inheritance shall be implemented for objects that act as aggregate containers for data.
Yes, we adhere to the retention policy that the tenant sends out for optimal collaboration and smooth user experience with Xoxoday's products and services.
Your data is of the utmost importance. All the security mechanisms and policies are established and implemented in such ways that data leak can be prevented, in transit as well as at rest.
Yes, the policy, process, and procedure is implemented to ensure proper segregation of duties. These can be asked for and delivered upon tenants' requests. In the event of user-role conflict of interest, technical controls shall be implemented to mitigate risk (if any) from unauthorized/unintentional modification/misuse of organizations' information assets.
Yes, our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC). All software development procedures are supervised and monitored by Xoxoday so that they include:
* security requirements
* independent security review of the environment by a certified individual
* code reviewsQuality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients' reference.
Yes, our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase.
Yes, an independent security review is conducted by certified professionals to look for any security vulnerabilities in order to solve them before deploying to production.
Yes, our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC) security standard.
Yes, changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates and modifications. Any change in roles, rights, or responsibilities shall be documented for a seamless experience.
We have a consistent and unified framework for business continuity planning, disaster recovery, plan development. All the appropriate communications shall be established, documented, and adopted to ensure consistency in business continuity. This includes protection against natural and man-made disasters (e.g. fire, flood, earthquake, war, volcanic activity, biological hazard, civil unrest, mudslide, tectonic activity, utility services outages, etc.).
Our hosting options are limited to Xoxoday's jurisdiction and are backed by prominent business continuity plans. Hence, we don't find the need to provide geographically diverse hosting options.
The capability to transfer infrastructure service failover to other providers is not provided to the clients.
Business continuity plans shall be subject to test at least annually or upon significant organizational or environmental changes to ensure continuing effectiveness.
Along with an aligned enterprise-wide framework, we perform independent reviews through industry professionals along with formal risk assessments. These are done at least annually or at planned intervals to determine the likelihood and impact of all identified risks. With qualitative/quantitative methods ensuring our compliances with policies, procedures, and standards, we stick to the best standards.
Yes, our stringent checks and tests are conducted annually to keep up the cloud service infrastructure hygiene as per the industrial standards.
Annual audits are processed both internally and externally. The audit results can be sent over to tenants upon request.
Yes, the tenants can request for penetration results and get the reports from our end.
No, we do not process your payment card data for any reason other than billing purposes.
Yes, we are compliant with the Indian IT Act of 2000.
There is no such process available from our end.
We will terminate the contract as per rules and statutes. Meanwhile your data will be stored with us and won't be given back to you. However, if the tenant wants the data to be erased, it can be done so upon request.
Yes, we store data that's required for seamless rewarding and recognition. We conduct regular audits to ensure safety of data like employees' names, emails, employee numbers, etc. are used for verification and rewarding purposes.
Xoxoday's information and cyber-security team keeps a watchful eye on all potential sources of threats and areas of compromise when it comes to information security.
Roles are systematically defined for information security measures to tactfully align all operations, preventing any security breaches.
Employees must agree with the acceptable usage policy of peripherals and devices to prevent malicious activities from the inside and out.
Our environment has all the capabilities to be SOC-2 Type-II compliant but the certification is yet to come through. It shall be updated soon.
No, our environment is not CSA-certified.
Xoxoday keeps track of all security requirements with respect to legislations, statutes, and contracts. They are documented in all steps.
We have our own procedure for control of documents and records that ensures compliance related to intellectual property rights and use of proprietary software.
Our record management criteria checks all boxes of legislative, regulatory, contractual and business requirements.
With different metrics tracking cyber-security measures, Xoxoday keeps the effectiveness in check with regular monitoring.
Xoxoday's Human Resource operation procedure takes all measures of employee confidentiality into consideration.
Yes, Xoxoday performs a thorough background check on every employee before they get onboard. The Non Disclosure Agreement ensures that the information is secure even after the contract is terminated.
Yes, our Xoxoday Store vouchers are procured from third-party vendors. These vouchers are shared with the tenants in order to be showcased to users of Xoxoday platform.
No, the third parties and vendors we deal with our confidential to Xoxoday. Hence, this list cannot be shared.
Yes, there's a third-party security policy present to safeguard the interests of Xoxoday's tenants as well as the end users.
Yes, our third party security policy deems it clear to comply with security obligations and we monitor their compliance regularly.
Yes, we have a detailed risk management procedure in place to address situational issues like change of services being provided to tenants.
No, our customer requests are addressed by the Xoxoday customer support team for maximum efficiency.
Yes, Xoxoday's brand protection caters to any malicious interruptions and fallacies as they are addressed in prompt time.
Yes, with media platforms being the biggest pedestal for information sharing, we keep an eye out for any brand protection issues.
Yes, in the event of a rapid spike/slump in network traffic or host activity, Xoxoday analyzes the traffic to detect and prevent unauthorized or erratic behavior.
Yes, in order to ensure airtight security of data, we have a mandatory and sessional privacy training and awareness module.
The Cloud Security Alliance (CSA) is the world's leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment.
Yes, Please visit the link to view the registry - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday)
Important features of CSA STAR LEVL – 1 are listed below
* Operating in a low-risk environment
* Wanting to offer increased transparency around the security controls they have in place.
* Looking for a cost-effective way to improve trust and transparency.
Yes, we ensure the same as part of our code review, static code analysis, and Web Application Firewall.
Yes, We comply with these requirements. Our Cloud Security Platform, (CSP) Amazon Web Services (AWS) provides these securities to our data centers.
Production data shall not be replicated or used in non-production environments. We do not use LIVE data in any other environment. We comply with the requirement.
We take prior authorization from the concerned authority as per the Media protection procedure before relocation or transfer of hardware, software, or data to an offsite premises.
As per Mobile Security Compatibility compliance requirements we have a documented application validation process to test for mobile device, operating system, and application compatibility issues.
The California Privacy Rights Act (CPRA) is a state-wide data privacy bill that amends and expands the existing California Consumer Privacy Act (CCPA). The CPRA works as an addendum to the CCPA, strengthening data privacy rights for California residents, tightening business regulations, and establishing the California Privacy Protection Agency (CPPA) as lead enforcer and supervisor.
Yes. We are compliant with CPRA, and Our solution will continue to offer full compliance with the new and updated data privacy regime.
Yes. We support our consumers to exercise their rights as per the CPRA.
Yes. We have implemented all the privacy controls and audited the same with the help of external Auditors.
Yes. Please reach out to our sales representative/Xoxoday POC to have access to the CPRA report.
No. We do not collect any data from any users across the globe who are not 18 years old.
Yes. The data subject can authorize an agent (an "Authorized Agent") to exercise their rights. To do this, the data subject must provide your Authorized Agent with written permission to do, and we may request a copy of this written permission from your Authorized Agent when they make a request to exercise the rights.
You may submit a Valid Request by emailing [cs@xoxoday.com](mailto:cs@xoxoday.com).
No. We will not sell, rent, or share Personal Data with third parties outside of our company. But Personal Data may be provided where we are required to do so by any privacy laws.
SOC 2 compliance is part of the AICPA Service Organization Control reporting platform. The goal of SOC 2 is to evaluate organization security and internal controls around security, availability, processing integrity, confidentiality, and privacy.
SOC 2 Compliances are developed by the American Institute of CPAs (AICPA), it defines criteria for managing customer data based on five "trust service principles"—security, availability, processing integrity, confidentiality, and privacy.
Yes. Xoxoday is SOC 2 certified organization. We have implemented all the required SOC 2 controls and got them Audited with the help of Certified Public Accountants (CPA).
Amazon Web Services (AWS) has achieved SOC 1, SOC 2, and SOC 3 reports. These reports detail the AWS controls environment and implemented controls for AICPA Trust Services Criteria (TSC) and can be leveraged as part of a cloud customer security program. AWS SOC-covered cloud services are audited periodically against the SOC reporting framework.
You may reach out to our sales representative/Xoxoday POC to have access to the SOC 2 report.
Laika Compliance LLC performs the SOC 2 audit for Xoxoday.
The SOC 2 Type I report is valid for one year following the date the report was issued.
Yes. SOC 2 is an internationally recognized standard. The SOC 2 report and certification involve an independent audit by a third party.
Yes. We do conduct the SOC 2 Audit on an annual basis.
The Auditor has validated and tested all the applicable SOC 2 controls as per the compliance requirements.
We do not process (Collect/Store) Protected Health Information (PHI).
Yes. Xoxoday is compliant with Health Insurance Portability and Accountability Act (HIPAA).
Yes. Please reach out to our sales representative/Xoxoday POC to have access to the HIPAA Audit report.
Yes. We have implemented the Data Subject Access Rights Procedure to make sure that all the data subjects will have the opportunities to exercise their rights as per the privacy laws.
The secure deletion standard like DoD 5220.22-M ECE is being followed and we provide a certificate that the data was properly sanitized from all computing resources and portable storage media.
Yes. Xoxoday is GDPR Compliant. We have implemented the Data Subject Access Rights Procedure as per the GDPR and made all the data subject rights available as per the data protection laws. This procedure sets out the key features regarding handling or responding to requests for access to personal data made by data subjects, their representatives or other interested parties.
Yes. We validate the compliance requirements of the Sub-processor and obtain the Compliance certificates and audit reports such as – ISO 27001:2013, SOC 2 Type II, ISO 27017, ISO 27701, ISO 27018, Cloud Security Alliance Controls, etc.
We conduct the independent Audits for - ISO 27001:2013, SOC 2 Type I, CPRA/CCPA, HIPAA, VA/PT Assessments.
Xoxoday maintains a disaster recovery program to ensure services remain available or are easily recoverable in the case of a disaster. Customers can stay up-to-date on availability issues through a publicly available status website covering scheduled maintenance and service incident history. The BCP and DR Plans are tested and reviewed every year. The Xoxoday BCP and DR plans are reviewed and audited as part of ISO 27001 standards and SOC 2 Type II covering availability as one of the trust service principles.
Users are not having admin access to their computer machines and only IT Support admins can install or uninstall the softwares.
CTOs and Production heads are responsible for safeguarding the customers data. Only authorised individual will have access to the production environment.
We delete the customer data upon request/termination of the contract and confirm the secure deletion. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
We clasify the Information assets into Confidential, Restricted , Internal and Public etc..
We maintain the records of all our assets.
we logically segregate the tenant's data, and it is segregated with a client-specific key for proper handling and security reasons.
We have restricted the ports for all the users as per Xoxoday IT Policy
The password needs to be minimum 8 characters long and should contain at least one capital letter, special characters among '# \$ % \* &' and 1 digit Maximum Password Age – 45 days Minimum Password Age – 1 day Computer machines will lockout in 15 mins from the time it became inactive.
Yes. Only authorised individual have access.
We use best practices and industry standards to achieve compliance with industry-accepted general security and privacy frameworks. We use enterprise-class security features and conduct comprehensive audits of our applications, systems, and networks to protect customer and business data. Our customers rest easy knowing their information is safe, their interactions are secure, and their businesses are protected. Please click here to know about Xoxoday Security framework - [https://www.xoxoday.com/security](https://www.xoxoday.com/security)
We are compliant. We monitor the system performance.
Yes. We maintain current architecture diagrams that include data flows between security domains/zones
All operating systems are hardened as per Xoxoday hardening guidelines.
We are compliant. We have deployed our applications on AWS Virtual platform cloud.
Please click here for SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view)
Appropriate roles and responsibilities have been defined and documented. Finance, Leagl, Admin, Infosec departments are active part of it.
Since its SaaS platform is not applicable.
Yes. we conduct the testing on frequent basis to comply with the requirements.
Yes. Its compliant with ISO 27001 and SOC 2 trust service principles.
Yes. We mitigate all the risk identified.
We inform the customer if there is any incidents as per the security and privacy laws.
Yes. We do conduct an internal Audit.
Yes. Privacy and security is a part of the Master Service agreements.
Xoxoday is compliant with GDPR, HIPAA, CCPA/CPRA privacy laws. And we inform the customer if there is any data breaches as per the compliance requirements.
Yes. We provide report on SLA.
We do conduct an External Audit with the help of the independent auditor.
Yes. we conduct the assessment on annual basis.
AWS is a sub-processor as we are storing data on AWS VPC. And they are AWS SOC 2, ISO 27001, ISO 27017 and ISO 27018 certified We monitor the compliances of sub-processor on frequent basis.
We continuosly train employees on privacy and security.
Yes. We have member in our organisation with dedicated information security duties. Xoxoday's primary security focus is to safeguard our customers or users data. This is the reason that Xoxoday has invested in the appropriate resources and controls to protect and service our customers.
All our employees are having the unique log in IDs.
We have installed the firewall for maximum securty and configured to restrict unauthorized traffic
All are configured according to security standards as part of the build process
Its part of our Internal and external Audits and validated by the indeendent auditors.
We have implemented the access control policy and access will be provided only upon need and approval basis. Attached the access control policy.
We have track of the changes. Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
We have installed Smoke detectors and Fire extinguishers for physical security.
security incidents reviewed to capture the root cause.
We are SOC 2 compliant and we have engaged Laika Compliance LLC, an independent assessor firm, to conduct a SOC 2 Type 1 and SOC 2 Type 2 examination for the Xoxoday Platform against the Security and Confidentiality Trust Services Categories.
Attached the ISO 27001:2013 certificate.
We provide Software as a Service.(SAAS). We are ISO 27001 certified and GDPR compliant. Attached the document.
We are ISO 27001 certified and GDPR compliant. Attached the document.
Since it's a SaaS prodcut and deployed on cloud virtual platform only authorised individual have an access to the our production environment on need and approval basis.
We inform the client to revoke access.
We use Google workspace and have secure mode of sharing the data.
We can manage all the enpoints centrally.
We have implemented the security measures to manage the risks introduced during the use of Organization's information assets used for managing Personally Identifiable Information.
We have a formal risk assessment process and conduct the risk assessment annually.
All the contractors/vendors have signed the NDA and contracts All the necessary clauses has been included in the agreements with regards to Confidentiality, liabilities, termination etc
Yes. We do conduct the Risk Assessment every year.
Yes. We have implemented the Data security and Information clasification policy. Attached the same.
Yes. They have signed for the agreements.
We have a biometric systems and access cards. only authorised individual can have access.
We have deployed Sensors for fire detection and fire extinguishers to detect and protect from the fire.
Yes, we will notify
Yes. Our Customer support team will notify.
Yes. We create an email accounts only after the approval from reporting managers.
We have not outsourced and does not create any email ids
Yes. IT Team is responsible.
Yes. We have a Email Security Policy and attached the same
Yes, we have implemented the security controls for email with the help of Google workspace and installed the end point security for all the laptops of the employees. All the incoming and outgoing attachments are scanned.
Yes.
Yes, We have implemented the Acceptable Usage Policy and have restricted for usage and access to internet.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. Since our application is deployed on AWS cloud we will ensure the best uptime in the insudtry.
Yes. All the changes takes place as per the change management policy implemented.
Yes. We have software register and only approved and licensed softwares will be used.
Yes, all are up to date.
Yes, we have capacity planning and monitor the hard disk space, RAM, CPU etc.
All the employees laptop is secured with Bitdefender end point security software
Yes
Yes. Taken into consideration
Annually
Yes. Attached the same.
We do consider all of these, addition to that we also validate the controls in place with regards to cloud security, BCP, Uptime etc. AWS is ISO 27001, SOC 2 Type II certified and complied with CSA start level 2. Please click here for more details about AWS Compliance Programs - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
Yes. We have an agreement.
We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications.
Xoxoday and AWS both are ISO 27001:2013 certified and implemented the change management procedure. We ensure that we follow the policies and procedures with regards to any changes to be made.
Yes. AWS is ISO 27017, ISO 27001:2013, ISO 2018, SOC 2 certified.
Yes. Attached the AWS ISO 27001 certificate
Yes. Tested our BCP plan
We ensure that we maintain confidentiality, integrity, availability and privacy of data collected, processes, stored through implementing policies and procedures. And we do conduct the internal and external Audits periodically to make sure that all the controls are working effeectively.
Yes
Yes
Since we have logically segregated the data and ISO 27001 certified and GDPR compliant we do not disclose or provide any of the the customer data.
Yes. Audited by the independent Auditor and all the aspects of Privacy, information security, BCP, DR, Production, VAPT has been validated.
NO
Production Site - No.17, Bhagyalakshmi Square, 2nd Floor, Sector 3, HSR Layout, Bangalore -560102 We have deployed our application on AWS Singapore. Since we have deployed our application on AWS cloud they only provide DR Services.
No other location
We provide our application to the customer. We have 230+ employees. 100+ employees are involved in the production/devolopment and we have a sepearate team for IT Support and Information security. We have provided separate computers to each employees. Altogether we are having around 250 computer machines. Our application is deployed on AWS cloud virtual platform.
We are ISO27001;2013 certified and GDPR compliant.Attached the ISO 27001:2013 certificate. We are SOC 2 compliant and in the last phase of final Audit. Attached the engagement letter that we have with our external Auditors.
Xoxoday is ISO 27001:2013 certified, GDPR compliant and SOC 2 type I certified organization and have all the required technical and organizational controls in place and auditred during the internal and external audits.
We are ISO 27001 Certified organization. We make sure that all the required records are maintained and compliant with the requirements.
Attached the Security Incident Reporting & Response Procedure and Incident Management Procedure
We have implemented the Information classification Policy to protect against unauthorised access, disclosure, modification, or other misuse. All our assets are labelled as per the requirement.
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provide a centralized control to administer, monitor and review all critical access. We have a role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates.
We have the Fire alarams, Smoke detectors, UPS, Temperature controler, Air conditioner, etc.. for protecting against the environmental hazards.
Yes, all our - both full-time and on-contract are bound by an agreement of non-disclosure and a confidentiality agreement as a condition of employment to protect the customers and tenant's information.
We use the CCTV cameras to monitor the building on a 24\_7\_365 basis. All the enterances, exit, restricted areas are under surveilance for security reasons.
Yes. We have the Information security team.
We are compliant
In accordance with Data Protection Laws, we make available to Controller on request in a timely manner such information as is necessary to demonstrate compliance by Processor with its obligations under Data Protection Laws. Upon Controller's written request and subject to the confidentiality obligations set forth in the Agreement, we will make available to Controller a copy of Nreach the most recent third-party audits or certifications, as applicable. We do not agree for the Surprise audits.
We have the Buiness continuity and Disaster Recovery Plan in place. These controls has been tested at least annually as per the compliacne requirements. Attached the policies for your referrence.
We have the Crisis management is in place. Attache the same. We have provided an option to work from home/remotely due to this pandamic with necessary infrastructure and security. Business continuity plan has been tested on annual basis and audited during the internal and external audits. Atatched the business continuity policy and plan.
Generic IDs are not used
[Please click here for SLA - https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view)
We have the ability to delete the data upon request by the data subject or termination of the contract. Attached the data retension and disposal policy.
We have implemented the Business continuity policy and we have the ability to resume our operation from potential threats, Pandemic, flood, fire, earthquake etc. Due this pandemic/WFH situation, VPN access has been enabled with 2FA For such authorized individuals, for ensuring business continuity. We have the required controls in place for working from home or remotely due to this pandemic situation.
Its a part of our Business continuity plan and IT Support Head, HR Head, CTO, Infosec Head will be involved in the preparedness activities.
We have provided WFH option to all the employees to get protected from COVID 19.
We have provided WFH option to all the employees to get protected from COVID 19.
We test the Business continuity plan on annual basis. It was tested in the month of Aug 2021 for the last time.
It has been well defined in the in the Business continuity policy and plans. Attached the same for your referrence.
We inform our customer on any crisis and if that is effecting on our customers.
Xoxoday is a data processor.
NO. We obtain consent before such activities from the customer.
We have the DPA and appropriate controls in place – We are compliant.
ISO 27001;2013, SOC 2 Type I Certified and GDPR compliant.
YES. We have implemented the Business continuity plans and tested them annually.
No. But we are in the process of getting the insurance from the Insurance company.
We conduct the internal and External audits on a periodical basis as per the compliance requirements and obtain Audit reports and certifications. We provide the same with the customers.
NO. We are not subjected to any actions as such.
application by Xoxoday, the RnR platform is a cloud-based SaaS platform hosted on VPC infrastructure of AWS. The data centers are hosted completely in isolation so that the access is limited and controlled. Each instance (EC2 Instance) under fortified VPC network is further conglomeration of Docker Container Web Services and APIs and application layer running on top of it. This helps in managing various aspects and features of application without affecting the functioning of each other and achieving a modular architecture to work as plug and play model. Amazon Cloud Watch is implemented to enable monitoring of the functioning of the application. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, and the data has been encrypted for security reasons. Attached the Architecture diagram.
Xoxoday is ISO 27001:2013 certified and GDPR compliant.
Xoxoday is ISO 27001:2013 certified and GDPR compliant. And we follow ISO 27001, NIST, CSA standards and best practices. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, Coudflare and the data has been encrypted for security reasons. We conduct code reviews as per the compliance requirements. We also conduct the Vulnerability assessment and penetration testing on annual basis with the help of the third party authorised vendor. Attached the latest VAPT certificate and ISO 27001 certificate.
Attached the ISO 27001:2013 certificate and 1st Year Surveilance audit report. We did not have any non-confirmities.
We are compliant with the data privacy and security requirements. We are having the controls in place with regards to Cyber security, Risk management, crisis management, business continuity, Network security, application security etc. Attached the Business continuity management and Cyber Crisis Management Plan, incident management procedures, SDLC etc.
Attached the Business continuity plan and procedure. We test the BCP controls on annual basis as per the compliance requirements and it has been auditted during the internal and external audits.
Xoxoday is ISO 27001:2013 certified, CSA START Level 1 and GDPR compliant. And we follow ISO 27001, NIST, CSA standards and best practices. We have Web application firewall (WAF), IDS/IPS, AWS Guardduty, Coudflare and the data has been encrypted for security reasons. We conduct code reviews as per the compliance requirements. We also conduct the Vulnerability assessment and penetration testing on annual basis with the help of the third party authorised vendor. Attached the below policies and procedures - 1. Encryption Policy 2. Password Management Policy 3. IT Policy 4. Information Classification Policy 5. Threat and Vulnerability Management 6. Cyber Crisis Management Plan 7. Backup Recovery Procedure 8. Access Control Procedure 9. Incident Management Procedure 10. Change Management Procedure
Data centers are designed to anticipate and tolerate failure while maintaining service levels. In case of failure, automated processes move traffic away from the affected area. These are tested on annual basis. AWS is also ISO 27001, ISO 27017, ISO 27701, ISO 27018, SOC 2 compliant organizatin. Please click here for more details - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/) Please click here to know more about AWS security - [https://aws.amazon.com/compliance/data-center/controls/](https://aws.amazon.com/compliance/data-center/controls/) Please click here to know more about Xoxoday Service level agreement - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view)
Please click here to know more about Xoxoday Service level agreement - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view)
Please click here to know more about data governance - [https://www.xoxoday.com/gdpr](https://www.xoxoday.com/gdpr)
Attached the Risk Management Procedure
We have plan for having the cyber insurance. - In progress.
Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. We have implemented the Information security policy and Disciplinary policy.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
Please click here to know more about the Application SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view?usp=sharing](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view?usp=sharing)
We review and get an approval from the management on annual basis as per the compliance requirements.
We have installed End point security on all the computers and monitored and updated on regular basis.
Yes. Our tenants can report the Bugs and security vulnerabilities to [cs@xoxoday.com](mailto:cs@xoxoday.com) We also have Bug Bounty Program at Xoxoday and please click here to know more about - [https://www.xoxoday.com/bug-bounty](https://www.xoxoday.com/bug-bounty)
Since application is a SaaS platform and deployed on AWS virtual platform cloud
NA. We have the full time employees.
We conduct the review and update the policies, procedures etc..and take an approval from the management on annual basis as per the compliance requirements. We also communicate all the policies and procesures to all the employees, contractors through HRMS platform.
We do not allow to access the infrastructure hosting.
All the information security policy and standards been approved by senior management.
We have installed the antivirus on all the workstations and servers.
Customer data security is an essential part of our product, processes, and team culture. Our facilities, processes and systems are reliable, robust, and tested by reputed quality control and data security organizations. We continuously look for opportunities to make improvements in the dynamic technology landscape and give you a highly secure, scalable system to provide a great experience. Attached the GDPR - Data security policy.
We have installed Bidefender endpoint security and restricted the access of external hard drives, USB etc to have restriction on data transfer. we use file integrity and network intrusion detection (IDS) tools to help facilitate timely detection, investigation by root cause analysis, and response to incidents
We do not use.
Annually
We have conducted the BCP test on 6th Aug 2021. Attached the Business continuity policy.
We have installed Smoke detectors and Fire extinguishers for physical security.
Attached the incident management procedure. All our policies are reveiwed annuaaly and approved by the top level management.
security incidents reviewed to capture the root cause.
Attached the Security Incident Reporting and Response Procedure
Classification of Incidents are done. Attached the Incident Management Procedure
No Security breaches till date.
We are SOC 2 compliant and we have engaged Laika Compliance LLC, an independent assessor firm, to conduct a SOC 2 Type 1 and SOC 2 Type 2 examination for the Xoxoday Platform against the Security and Confidentiality Trust Services Categories. Attached the engagement letter.
Attached the ISO 27001:2013 certificate.
We make sure that they have adequate controls in place and meet the security standard.
We are ISO 27001 certified and GDPR compliant. Attached the document.
We review these to make sure the all the controls in place.
We provide access only upon need and approval basis.
We use Google workspace and have secure mode of sharing the data.
We can manage all the enpoints centrally.
Attached the Risk Management Procedure
We have a formal risk assessment process and conduct the risk assessment annually.
All the contractors/vendors have signed the NDA and contracts All the necessary clauses has been included in the agreements with regards to Confidentiality, liabilities, termination etc
The SaaS solution is deployed on Public cloud.
Yes
Yes. We are using Bitdefender endpoint security.
Yes. We use for security reasons
Our employees will not have access by default. The data will be accessed only upon need an approval basis. The access is controlled through the AWS Identity and Access Management system that also enforces two-factor authentication
We collect only 3 types of the personal Information such as Name, email ID, phone#. , personal data is to be transmitted using firmly approved encrypted systems. We have implemented the role based acccess control to make sure that the acccess has been granted to only authorised individual.
Yes.
Yes. We inform the client about any security incidents.
Yes. Attached Incident management policy and SLA
Yes
Yes
We are compliant.
Yes, We are ISO 27001:2013 certified. Attached the certificate.
We are SOC 2 Type 1 compliant. The audit has been completed and auditor is working on the Draft audit report. We will be able to share once the report is finalized.
NA. But AWS Virtual platform cloud is ISO 27017 and 27018 certified and attached the report.
NA. We do not handles the card holder data.
the customer will be using the application product and all the information will be entered only through our application.
The data sharing between vendor and the customer will take place only through application product. There will be no manual data sharing or transfer.
PII will be entered through application and stored it on AWS cloud virtual platform. We store Name, email ID and phone number of the users.
We do not have any sub-contractors. We have deployed our application on AWS Virtual platform cloud. And AWS is ISO 27001, SOC 2, ISO 27017, ISO 27018, ISO 27701, CSA Compliant etc..
We have deployed our application on AWS Virtual Platform cloud. application is a cloud based application. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. All the confidential/PI data are encrypted at rest and in transit with a split key mechanism to ensure that every client's key is unique We do not decrypt the data until and unless if there any specific request from the customer.
Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week ("Agreed Hours of Service"). Uptime is measured based on the monthly average of availability, rounded down to the nearest minute. Please click here to know about Xoxoday SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) Xoxoday has a formal Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) defined and implemented to enable people and process support during any crisis or business interruptions. The BCP and DR Plan is tested and reviewed on a yearly basis as per the compliance requirements. The BCP and DR plan of Xoxoday is reviewed and audited as part of ISO 27001 standards and SOC 2 Audits by the independent auditor. Attached the Business Continuity Plans (BCP) and Disaster Recovery Plan (DRP) documents.
Since it's a SaaS platform, there are no process as such.
Attached the below mentioned coompliance certifications - Attached the Audit reports. 1. ISO 27001 certificate 3. VAPT Certificates 4. VAPT Audit reports 5. SOC 2 Audit reports. 6. GDPR Data Privacy Impact assessment report 7. California Privacy Rights Act (CPRA) attestation report. 8. CSA STAR LEVEL 1 compliant - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) We conduct these audit on annual basis and we will share it upon request.
We always provide our best service to resolve security incidents / outages. Attached the Service Level Agreement (SLA)
Xoxoday is committed to ensuring the integrity, confidentiality, availability, and security of its physical and information assets and maintaining privacy when serving the customers and organization's needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially. Xoxoday will implement procedures and controls at all levels to protect the confidentiality and integrity of information stored and processed on its systems and ensure that information is available only to authorized individuals as and when required. Please click here to know more about Xoxoday Security - [https://www.xoxoday.com/security](https://www.xoxoday.com/security)
We have deployed our application on AWS Virtual platform cloud - Singapore region. We are GDPR compliant. And we have an agreement and Standard contractual clauses (SCC) as per GDPR Compliance requirements.
NO
NO
No. There were no Personal Data Breaches.
Xoxoday is committed to ensuring the integrity, confidentiality, availability, and security of its physical and information assets and maintaining privacy when serving the customers and organization's needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially. Xoxoday will implement procedures and controls at all levels to protect the confidentiality and integrity of information stored and processed on its systems and ensure that information is available only to authorized individuals as and when required. Attached the below documents - 1. ISO 27001 Certificate 2. SOC 2 Audit report. 3. California Privacy Rights Act (CPRA) attestation report. 4. VAPT Certificates 5. GDPR DPIA Assessment report. 6. CSA START LEVEL 1 Compliant - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday) the customer can request the Xoxoday POC for these reports and we will provide the latest Audit reports upon request.
We are storing all the customer data on AWS Virtual platform cloud – Singapore region and consider AWS as a Sub-Processor as per EU GDPR. AWS is ISO 27001, SOC 2, ISO 27017, ISO 27018, CSA STAR, ISO 27701 certified organization. Please click here to know about AWS Compliance offerings - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
Scope and functionalities are the part of the agreement.
Please click here for SLA - [https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view](https://drive.google.com/file/d/1LatFZLoRzeRlQf4mEemzL8XsO71YGahk/view) We do not offer any credits/ penalties.
We have implemented all the technical and organisational measures to ensure the integrity, confidentiality, availability, and security of its physical and information assets and maintain privacy when serving the customers and organization's needs while meeting appropriate legal, statutory, and regulatory requirements. To provide adequate protection for information assets, Xoxoday has built the Information Security Management System (ISMS), enabling everyone to follow these policies diligently, consistently, and impartially.
[ISO 27001 certificate VAPT Certificate SOC 2 Audit reports. California Privacy Rights Act (CPRA) attestation report. CSA STAR LEVEL 1 compliant - https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday We have shared these certifications and Audit reports.](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday)
We do not process the data for other purposes than the one specified in the contract,
We do not share the data with third parties. But we store it on AWS Virtual platform cloud and we consider AWS as a Sub-processor. We do not disclose any of our customers personal information to any third parties. We reserve the right to disclose PI if required by law or if we reasonably believe that use or disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with a law, court order, or legal process. We reject any non-legally binding requests for disclosure.
We process only the Name, phone# and Email ID as mandatory information.
We process the information as per the terms of use - [https://www.xoxoday.com/terms-of-use](https://www.xoxoday.com/terms-of-use)
We are storing all the customer data on AWS Virtual platform cloud and we operate or provide services from Bangalore, India.
We inform the customer of any changes in regards to changes in sub-processors.
Xoxoday Terms & conditions - [https://www.xoxoday.com/terms-of-use](https://www.xoxoday.com/terms-of-use)
Yes, the cloud provider does have a right to suspend services for specific reasons; more detailed in Section 3.3 of the Master Services Agreement. Section 3.3(a) read along with Section 2 of the MSA
The Contract is subject to the laws of India. For disputes arising under this contract, courts of Delhi has an exclusive jurisdiction. Arbitration & Conciliation Act, 1996
We conduct the periodical Risk assessment. and it has been audited during the internal and external audits.
We also provide SLA performance report to the customer on need basis.
we have the capability to respond to security alerts, and report security vulnerabilities and information security incidents within 24 hours of discovering them
[We also have Bug Bounty program - https://www.xoxoday.com/bug-bounty](https://www.xoxoday.com/bug-bounty)
We train our employees on their role and responsibilities and also comminicate before joining the organizatin
application is an all-in-one employee engagement and motivation platform that offers Rewards & Recognition, Pulse Surveys, 1-on-1 Feedback, Social Intranet and People Analytics in one powerful solution.
Information security department is responsible for security initiatives and the Head of the Information security reports to the Board of Director of the company.
The policies and procedures have been created, reviewed and approved by the Top level management of the company.
The information security policies have been uploaded on KEKA HRMS Application and communicated to all the employees. Attached the screenshot for your reference.
Attached the Risk Management Procedure.
Attached the internal audit report.
Your data is of the utmost importance. All the security mechanisms and policies are established and implemented in such ways that data leak can be prevented, in transit as well as at rest.
We have installed Bitdefender endpoint security in all the endpoints. Bitdefender is based on a layered next-gen endpoint protection platform with the industry's best prevention, detection and blocking capabilities, using proven machine learning techniques, behavioural analysis and continuous monitoring of running processes.
We have the capability to wipe out the data remotely for all endpoints including BYOD devices.
Attached the ISO 27001:2013 certificate and Statement of applicability.
We provide tpliance certifications upon request.
We use the Software Development Life Cycle (SDLC) process. It is aligned with ISO 27001;2013 and SOC 2 frameworks.
During the development and testing security related requirements are specially considered.
We have SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user.
We can also provide uptime status on a need basis.
We have proper forensic procedures for data collection and analysis for incident responses
Yes, in case specific incidents arise for particular tenants, our logging and monitoring framework allows isolation of incidents.
Xoxoday endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Uptime is measured based on the monthly average of availability.
We do not offer any penalty.
Attached the SLA
Attached the below documents - 1. ISO 27001:2013 certificate 2. VA/PT Certificate 3. VA/PT Executive report 4. application Architecture Diagram 5. We have deployed our aplication on AWS Virtual platform Cloud and attached AWS Compliance certificates - ISO 27001, ISO 27017 & ISO 27018. 5. application SLA
Customer Support is available on all working days (Mon - Fri) between 3.30 AM GMT to 1:30 PM GMT.
Xoxoday is – ISO 27001:2013 certified CPRA (California Privacy Rights Act) EU GDPR Compliant CSA STAR LEVEL 1 Compliant – Click here Vulnerability Assessment and Penetration Testing (VAPT) Attached these above certificates and Reports.
The backups are automated and taken on a daily basis. We delete the data upon receiving the request from the customer/end users/termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
We have an ELK setup in place to ensure data monitoring in the most optimal manner. The audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
As per the SDLC Policy we follow several distinct stages, including planning, design, building, testing, code review, deployment and maintenance etc. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase.
It would depend on the criticality of the investigation and the type of service subscribed. Our team will be able to provide the ETA as soon as they receive the request from you and start acting immediately.
Yes. You can check this information from the user management option available for Admin console.
You can reach out to us with the help of the help center or can write an email to customer support team
Yes. We maintain and record the Audit logs and complying with various compliance requirements.
Yes. You may reach out to our support team anytime for requesting these records and they would be able to help you out on this requirement.
It would depend on the criticality of the investigation and the type of service subscribed. Our team will be able to provide the ETA as soon as they receive the request from you and start acting immediately.
Yes. We deployed our application on AWS and AWS provides the data backup service as well.
Yes. We are ISO 27001:2013 certified and GDPR Compliant.
We have implemented the risk assessment procedure and conduct the risk assessment annually as per the compliance requirements.Risk assessment is used to identify the risks encountered by the information-processing facilities (or individual system components). The aim is to estimate the impact and probability of a threat occurrence. The risk assessment procedure is having Risk, Likelihood and Impact. The risk ranking is done based on the Residual Risk Rating such as High, medium and low. Attached the Risk Management Procedure for your reference.
Risk Management Procedure has been used to validate the security compliance of AWS. AWS Compliance certifications and attestations are assessed by a third-party independent auditor and result in a certification, audit report, or attestation of compliance. AWS is ISO 27001, SOC 2 Type II certified and complied with CSA start level 2. Please click here for more details about AWS Compliance Programs - [https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
Yes. We can use the risk assessment framework adopted by NSE for cloud service risk assessment.. Please provide the same.
We comply with this requirement. The risk assessment procedure has defined the Risk Acceptance Criteria, Benefits, Components, Impact Rating, Risk Treatment, Risk Acceptance etc and all the controls identified in our risk assessment as per the industrial standard like ISO, SOC2, NIST, GDPR etc.
Sure. We are ISO 27001;2013 and GDPR compliant. We have policies and procedures in place with all the required compliance controls.
We comply with this requirement. We conduct annual audit by the independent auditors to test the controls in place with regards to Information Security management system(ISMS) and also for testing the service organization controls(SOC)covering the principles of Security, Availability, Confidentiality, and Privacy. AWS is also SOC 2 certified.
Sure. Attached the ISO certificate and we are in the Audit process for SOC 2. we will provide the same once the audit is completed.
We are ISO 27001;2013 certified, GDPR compliant and in the process of SOC 2 audit. We make sure that our customer data is safe and secure and meet all the compliance requirements and industry best practices. Xoxoday has built the Information Security Management System (ISMS) which includes the respective policies to be followed in a diligent, consistent, and impartial manner.
Our legal team would review and agree the terms and conditions.
We agree. NSE can review.
Our legal team would review and agree the terms and conditions.
We will inform NSE if there is any breach.
The data isolated between customers. We use logical data isolation with the help of company specific encryption keys.We use TLS1.2 encryption for Data in transit and AES256 for Data at rest
We agree. We have implemented the data breach notification procedure.
We agree. We will notify NSE.
We agree.Currently, we do not have any plans as such.
All the data will be stored on AWS cloud We have the disposal policy in place and implemented mechanisms for secure disposal and removal of data.
We agree. We will delete the data upon termination of the contract or request and confirm. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
We have implemented Asset Management Procedure in place and maintain all the records of IT Assets like, hardware, software, licenses, accessories etc.
We review and update the inventory as per the Asset management policy.
The database server, application server or storage devices hosting NSE's data & information is not made available publicly. We isolate our machines, network and storage with respect to the AWS Standards in order to keep it safe and secure
Yes, one can write to us at our 24\*7 support team at [cs@xoxoday.com](mailto:cs@xoxoday.com)
We help the clinets in setting up from both admin and end user side, and traiing is also provided on how application can be used for hasslefree awards distribution
We provide trainging over internet , if possible we provide telephonic assistance also.
Yes we provide "on demand training" , this incur no additional cost to the company
We have a 24\*7 available support team, once a ticket is generated , It is assigned to one of the cs team executive and we intent to solve the issue within next 24hrs.
Xoxoday employees and third party would have an access. We provide acess on case to case basis as per the Information security and access control policy. We also have role based access system to meet the compliance requirements of the data security . The data is hosted on Amazon Web Services (AWS)
We do conduct employees and contractors background verification as per the compliance requirements before onboarding process. We will onboard them only after passing the background verification. We are ISO 27001:2013 certified organization.
We conduct periodical review of the access provided and make the necessary chages as per the Role based access management and access control policy. We also conduct Internal and external audits in a timely manner.
Our Information security compliance policies and procedures are established and implemented to enforce two-factor authentication
We are ISO 27001:2013 certified organization The User access are monitored and recorded internally as per the compliance requirement and Access Control Procedures.
Yes we have implemented intrusion detection tools, we ensure timely detection and investigation in a prompt manner.
Yes. file integrity (host) and network intrusion detection (IDS) tools implemented to help facilitate timely detection, investigation.
Yes. Implemented SIEM
Yes. All the controls are audited annually.
Yes, We will share the Data protection policy. Access control policy and Information security policies
Size of the team is 5 and all are having 5+ years of experience
personal data is stored are registered databases that comply to all necessary inputs of a standard inventory repository and its transit scrambled for maximum security.
We use AWS Platform for storing the data. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records.
As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system.
No. Planned downtime will not be calculated uptime
No. Planned downtime will not count against the SLA
We have Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working.
We test it annually once as per the compliance requirements.
Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
We have Business Continuity Policy and Business Continuity Management Procedure in place and tested periodically. And also our Policies has been reviwed and Audited annually.
Yes. We have implemented IDS/IPS, Firewall and our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting
Yes. We have procedures in place to support Government
We have the clauses for suppporting local government and law enforcement requesting customer data in data protection policy. We will share the copy of it.
We have deployed our application on Amaon web services (AWS) AWS is designed to help us build secure, high-performing, resilient, and efficient infrastructure for our applications. AWS is also ISO 27001:2013 and SOC 2 type II Certified and provide all applicable security to the data center.
Yes. We have industry approved vendor called Appknox for Vulnerability assessment anf Penetration Testing. Appknox performs Static, Dynamic, API, and as well as Behavioral Analysis. And they helps to detect and address security vulnerabilities.
We collect only personal information through our application. We collect name, email ID and mobile numbers.
Yes. We have capabilities to anonymize data. By Anonymization users are able to make use of sensitive information without having access to the identifiable data items. And its used within a secure environment with employee access on a need to know basis.
No. we do not have it in hard copy
Yes. We conduct vendor Risk assessment and also external Auditor validate the critical vendor documentations during the annual and Internal Audit.
Yes. We have Information Security Program
Yes. We review Information Security Policies every year.
Yes. We have Information security risk management program
Yes. Our management is supportive and evaluate, Recommend and take action on security risks
Yes, we have Information security team and the Infosec head is reporting to Chief Operating Officer of Xoxoday.
Yes
Yes. Please visit here for more details - [https://www.xoxoday.com/bug-bounty](https://www.xoxoday.com/bug-bounty)
Yes. All the endpoint laptops that connect directly to production networks centrally managed
All the employees laptop is secured with Bitdefender end point security software. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory.
No. sensitive or private data never reside on endpoint devices. This is enforced throgh access control policy.
We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour.
Yes. Our incient response plan is tested every year as per the ISMS requirements.
We follow SDLC policy during the design phase of devolopment. See SDLC procedure attached
We have SDLC procedure and Information System Acquisition Development and Maintenance Procedure. Devolopers are trained on the Secure Coding Practices as soon as they joined our organization
We conduct vendor risk assessment and collect all the required security policies, procedures, VAPT reports, ISO 27001, SOC 2 reports. And also our internal and exteranal auditors validate the security controls of our crtical vendors during the Audit.
NO
NA. We do not have custom-built software
Yes
Internal Audit has been conducted by the inhouse Infosec and ISMS Lead Auditor. All the projects, business processes and ISMS controls has been included in the scope and opportunity of improvements has been communicated to all the respective teams with the remideiation plan. And the frequency of the Internal audit is annually.
We have the external Auditor for ISMS Audit. All the projects, business processes and ISMS controls has been included in the scope and opportunity of improvements has been communicated to all the respective teams with the remideiation plan. And the frequency of the external audit is annually.
See ISOIEC 270012013 Certificate and Internal Audit report attached.
NA. We do not use for own purposes
Yes
Yes. All the employees and third party service providers are required to sign Confidentiality Agreements to protect customer information as per ISMS compliance requirements.
We have dedicated IT Team and Admin team who looks after the hardware security and, we have implemented the security controls as per the ISO 27001:2013 and SOC 2 Compliance requirements. We are hosting our application on AWS, and they are providing physical security to our data centre. We have Asset Management Procedure in place to identify, classify, label, and handle the Information and Information assets according to their criticality and sensitivity. We have Media protection procedure to handle the locally stored data as per the Information security compliance requirements.
As per the Physical and Environmental Security policy we have security guards and CCTV Camera's to safeguard the office building and also to provide an access to the building only for the authorized individuals. We also have Media protection policy which also defines on how to handle the Paper documents as per the compliance requirements. Physical documents are handled with at most care and followed the policies and procedures of an organisation to make sure that the data is protected.
We have Physical and Environmental Security policy and Vendor management guidelines in place and working effectively. We have implemented controls on Physical entry, Securing offices, rooms, facilities, Working in secure areas, Delivery and Loading areas etc. Only the authorised individuals will get an access upon verification. And we also conduct periodical verification of the effectiveness of these controls periodically through internal and external Audit. We provide access to the outsiders or suppliers on approval and escorting mechanism of vendor management guidelines by issuing the access cards.
All our assets are classified, labelled, and maintained in the register by our IT Team. Access granted only to, authorized individuals. We have locked environment for our hardware's which would store the data. We also have implemented the Media protection procedure to protect the data which are stored physically.
Yes. Backups are stored in a safe place. We have backup Recovery Procedure and implemented the controls to protect the organization information asset from the damages that may be caused due to failure of hardware system, corruption of software, breaches leading to data destruction and or not being able to retrieve and use. We predominantly work on cloud-based infrastructure and the teams may consider adoption of Amazon Web Services which provides the Backup and Restore services to build scalable, durable and secure data-protection solutions. AWS claims the following benefits and the teams may evaluate the benefits to the respective context that may lead to realize the following outcomes: 1. Data Type and Durability 2. Flexibility and Scalability 3. Security and Compliance The following AWS based offering for the following use cases offered by AWS may be considered based on the contractual needs of the subject under consideration: 1. Hybrid Cloud Backup 2. Data Lifecycle Management 3. Tape Replacement 4. Global Data Resiliency 5. Data Backup 6. Archive & Compliance
We are ISO 27001:2013 certified and GDPR compliant organization. We have Information security policy and Data security policies in place with regards to data protection. We make sure that the below principle of data security has been followed as per the compliance requirements. 1. Fairness and lawfulness When personal data processed by us, we make sure that the individual rights of the data subjects must be protected. We will ensure that the personal data is collected and processed in a legal and fair manner. 2. Confidentiality - Restriction to a specific purpose We make sure that the any processing of personal data should be lawful, fair, and transparent. Personal data will be processed only for the purpose that was defined before the data was collected. Subsequent changes to the purpose are only possible to a limited extent and require substantiation. 3. Transparency We make sure that we maintain the transparency with regards to the data collected, stored and disposed. We also provide rights to data subjects as per the GDPR compliance requirements. For ex - Right to Rectification, Right to Portability and Right to be Forgotten. 4. Integrity and data security Personal data is subjected to the data secrecy. We have controls on confidentiality, Integrity and data security. We follow secured suitable organizational and technical measures to make sure that the data is protected from an unauthorized access, illegal processing or distribution, as well as accidental loss, modification or destruction etc. Sensitive data - We do Inform involved parties about how we will process their data Inform involved parties about who has access to their information Have provisions in cases of lost, corrupted, or compromised data Allow involved parties to request that we modify, erase, reduce or correct data contained in our databases. Sensitive data - We do not Communicated informally. Stored for more than a specified amount of time. Distribute to any party other than the ones agreed upon by the data's owner (exempting legitimate requests from law enforcement authorities. In addition to ways of handling the data the company has direct obligations towards people to whom the data belongs.
We have controls in place to protect the information or to maintain privacy. We conduct Data Privacy impact assessment and Audits periodically as per the compliance requirements. We have Personally Identifiable Information Policy, Data Security policy, Data Subject Access Rights Procedure, Data Retention and Disposal Policy as per GDPR compliance.
We conduct periodic vendor risk assessment. Information security documents are validated by theiInternal and external auditors during the assessments.
Yes.
We have an access control policy. The policy is attached for reference. Only authorised employees will have access to the data.
Yes. Xoxoday is ISO/IEC 27001:2013 certified organization. See certificate attached.
Yes. We have a well-defined policy for roles and responsibilities. We have communicated each employee about their responsibilities across the organization. We do maintain appropriate contracts with relevant authorities and ensure that applicable regulations are complied with
Yes. We provide these rights to the data subject as per GDPR
Yes. We conduct internal and external audits and all the applicable controls have been validated as per the compliance requirements.
Yes
We have a media handling procedure. See attached for reference.
No. We do not transfer the data outside our organization.
Yes. See Infrastructure Change Control Procedure attached.
Yes.
Security inceidents will be reported by our Information security team or customer support team within 48 hours.
We have implemented physical security controls as per the compliance requirements. We have CCTV, access cards, security guards for monitoring and only authorised individual have access.
Segregation is done for production and non-production or Testing environments. We maintain the test accounts seperately and delete or terminate the accounts immediately once the testing is completed. Only Admins have an access to create these tests accounts on need and approval basis.
We have implemented the Roles and Resposibilities policy and defined the Duties of all the system users and segragated based on the defined roles. Only authorised individual will have an access to the Information system on need and approval basis.
We maintain these records for Audit purposes.
We have controls in place to monitor the user access system. We have implemented Role based access management system through access control policy. Our application also supports Role based access control system to make sure that only authorised individual will have an access to the Information system on need and approval basis.
We maintain these records for Audit purposes.
We are Compliant. We monitor these controls on a periodical basis and also during the internal and external Audits. Successful and failed login attempts will be logged, we use privileged accounts are used only for system administration activities,we remove default credentials and use the new credentials for all our systems.
We use Multifactor authentication menthods to make sure that only authenticated individual have an access to the Information system wherever strong authentication is required. We use Biomentric verification and access cards methods for physical security purposes.
We have these controls in place. We have a restriction for Physical access, monitor these access periodically and validate to make sure that only the authorised individual have an access.
The credentilas has been comminocated via secured mode to make sure that confidentiality is maintained.
We are Compliant.These controls are audited during the internal and external Audits.
We are Compliant.Only authorised individual will have an access.
We are cothe customerant. We maintain the records of Audit logs.
We have restricted the access of external harddrives, USB etc for all the systems through Active directory and End point security.
We have the security controls in place. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network.
We have implemented the asset management procedure to identify, classify, label and handle the Information and Information assets according to their criticality and sensitivity.
We have labeled the aseets in order to identify and make sure that the access control permissions are maintained.
we have implemented intrusion detection and prevention tools, we ensure timely detection and investigation in a prompt manner.
These are integrated with security operations/SIEM solutions.
We take an approval from the concerned authority before procuring the equipment or routing connections and test the same before installing it.
All the network devices are securely configured and we always make sure that we monitor the same on regular basis and take appropriate action on any detections.
We use vendor supplied softwares without any changes wherever feasible, if all the security controls are in place.
We consider these factors before making these changes to the softwares.
Yes, we test the changes made on testing environment before moving it to a production environment.
Only authorised individual have an acces to the approved information assets.
we are compliant. We document or have a track of all the changes made to protect the information system.
We are compliant and have these controls in place.
We have the appropriate clauses in the agreements wherever necessary.
We provide guidance for using our products appropriately and take all the possible benefits.
We have the controls in place. All the Critical patches will be deployed immediately
We inform our customers on the vulnerabilities wherever is required from the compliance perspective.
Our product is free from dormant malicious programmes
We test the systems before deploying into operational environment.
We have implemented the System Devolopment Life Cycle procedures and all the testing of new features are documented.
We conduct security assessments before accepting the products and take appropriate approval to make sure that all the security requirements are met.
All the test results are documented.
We record these in the Risk register and documented before purchasing the product.
We make sure that these are met before acquiring and products.
The customer responsible staff can confirm upon validation of the security requirements.
All the design and implemetation has been documented. We conduct the security Risk assessment in order to identify and mitigate the risks.
We have kept Testing and production environment seperately. We do not use any data from our production environment for testing purposes.
All our contracts or agreeements are having appropriate clauses with regards to security compliance, privacy, Audit requirements etc.
we use only licensed softwares or assets
We are compliant. We maintain these records for Audit purposes.
We have not outsourced.
Attached the Information Security Manual. It prescribes the policies that govern the management and administration of the Information Security Management System (ISMS) for application.It specifies the scope and the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving the information security controls.
We have not subcontracted or outsourced any of services with regards to the product.
We have documented the Transfer of Information and it's a part of our Information security policy
We do not transfer the data. But if its necessary it will be done only upon the approval of the management.
We have documented the Transfer of Information and it's a part of our Information security policy
We do not transfer the data. But we follow these compliance requirements if there are any data transfers. We have implemented the Information security and Data security policies in order to make sure that we secure our organizational and customers information.
We maintain these records for Audit purposes.
We monitor and audit the logs.
We are complied. We have controls in place to make sure that Information system is protected.
We conduct the Risk assessment to identify and mitigate the risks involved.
We use Google workspace as email solution and adequate security features has been enabled to make sure that Information system is protected.
We do not connect.NA
We make sure that all the controls and compensatory controls are in place in order to protect against the Security threats.
We have implemeted the risk management procedure and defined the Risk Treatment, Risk Treatment, Risk Mitigation, and Risk transfer etc
We have implemeted the risk management procedure and defined the Risk Treatment, Risk Treatment, Risk Mitigation, and Risk transfer etc We implement the Compensating security controls wherever measures cannot be applied due to technical or operational infeasibility.
We maintain these records for Audit purposes.
It's a part of our Internal and external Audits.
We make sure that these controls are in place and security has not been degraded below the accepted level. We also validate these controls during our internal and external Audits.
We have implemented the role based access system and change management policy in order to make sure that we provide an access to an individual only upon need and approval basis. All the changes has been tracked and maintained the records for audit purposes.
We have a up to date records of all the assets used.
We make sure that we follow the Industry best practices and security standard to make sure that we secure the information asset.
We make sure that we follow the existing security controls and implement the compensatory controls to make sure that the information system is secure.
We have implemented the control.
We conduct the Risk assessment to identify and mitigate the risks involved.
Compliant.We review and validate these controls on a periodical basis and These are part of an Internal and external Audits.
Compliant.We review and validate these controls on a periodical basis.
We maintain these records for Audit purposes.
We have the required security controls in place.
We do not use outdated computer hardware, software, technology, services or practices
We upgrade the systems make sure that do not use outdated computer hardware, software, technology, services or practices
We have installed the end point security software on all the computers and servers to keep the computer and personal information protected.
We have installed the end point security software on all the computers and servers to keep the computer and personal information protected.
We are compliant.
We have enabled these features.
We have installed end point security softwares to safeguard from attack scripts, viruses, worms, Trojan horses, backdoors and malicious active content. We also conduct periodical scanning in order to make sure that all the information assets are safe. These are centrally managed and have control on all the end points.
It is available on need to know basis
We make sure the Vulnerability assessment has been conducted for our products as per the compliance requirements.
We are compliant.
the customer Sensitive information will not be exposed to the general public.
We document and maintain all the security issues.
We are complaint.
We are compliant. We have clasified, labeled our assets and periodically monitored. All the logs and realtime trafic is monitored.
Implemented. We are compliant.
These are all part of CSP agreement.
We have these controls in place as a part of our Business continuity plan.
We have these controls in place as a part of our Business continuity plan. It has been tested periodically and part of our internal and external Audit.
We have conducted the risk assessment as per the industrial standard.
Agreed. We will sign the NDA
SLA can be documented and agreed by the both the party.
Only authorised individual have an acces to the approved information assets.
We allow our customer to audit but atlease 30 days prior notice with the scope of the audit needs to be communicated
Its documented as per the Risk management procedure.
We have all the details in SLA
We can make our audit reports available
We maintain appropriate reports and records, to monitor and measure the compliance with the security requirements.
We make sure that we follow the risk management procedure and take these factors into consideration.
We have these in place and tested annually.
We have these in place and tested annually.
Our BCP/DR plan supports this.
We review these on annual basis
We have cmmunicated to all the internal and external parties.
It's a part of Business continuity documents and attached the same for your reference.
The BCP Test and lessons learned has been documented.
It's a part of BCP documents and we review and update when changes takes place.
These are part of internal and external audits
We have implemented the Corrective Action Procedure.
We have implemented the Corrective Action Procedure. We review rhe corrective action taken.
We conduc the security assessments by the Internal and external auditors
We share the data with our Internal and external auditors
We make sure the Assessments and Audits will be conducted and reported independently.
All the Sensitive information shall be handled as per Policies and procedures implemented.
We have defined it in our compliance policy and Corrective Action Procedure
We allow our customer to audit or assess but atlease 30 days prior notice with the scope of the audit needs to be communicated
We continuously monitor and improve Information security framework to make sure that we safegurd the Information and all the controls are in place.
We make sure that we brings these improvements to Information security systems from the incidents reported and audit observations etc
We have implemented the corrective action plan procedure and review the policies and procedures on annual basis.
It can be included in the agreement and our legal team will review and confirm
Statement of work will have a details of product/service to be provided
We can include the service levels in the agreement. We are not currently having an options for service credits/liquidated damages, if SLA are not met.
We make sure that we have all the controls in place.
We will do this as part of the agreement
We are a multi tenant SAAS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis.
Attached the BCP/DR documents
We end point security in place
We allow our customer to audit, but atlease 30 days prior notice with the scope of the audit needs to be communicated
We have deployed our application on Amazon web services (AWS) Virtual platform cloud. AWS provides data center security to our application. AWS is ISO 27001;2013, ISO 27017, ISO 27018, SOC 2 certified organization. Xoxoday is also ISO 27001:2013 and GDPR compliant organization. Only the authorised individual have an access as per Access control policy. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access. Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
Since our services are delivered via. Web, the upgrades and updates to the services are seamless and usually do not involve any actions from the end-users. We try to release our product hotfixes once every week & major features once every month.
Yes. Annually once.
Yes. We are ISO 27001:2013 and GDPR Compliant. We are also compliant with SOC 2 type 1 and on the last phase of Audit. We will share the report once we have it from the Auditor. Attached the ISO 27001 certificate and engagement letter that we have for SOC 2 Audit.
We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory
All the employees initially inform the IT Support team through ticketing systemb the Infosec manager and Final level will be DPO and the management.
The time of support ranges depends on the level of service. RTO and RPO is - 6 mins
our products comply with all the industrial benchmarks and standards when it comes to the Software Development Life-cycle (SDLC). All software development procedures are supervised and monitored by Xoxoday so that they include: security requirements independent security review of the environment by a certified individual code reviews Quality monitoring, evaluation, and acceptance criteria for information systems, upgrades, and new versions shall be established and documented for the clients' reference.
The data centers are hosted completely in isolation so that the access is limited and controlled. Load balancer allows shifting incremental load and can auto scale based on data load experienced by application. Each instance (EC2 Instance) under fortified VPC network is further conglomeration of Docker Container Web Services and APIs and application layer running on top of it. This helps in managing various aspects and features of application without affecting the functioning of each other and achieving a modular architecture to work as plug and play model. Amazon Cloud Watch is implemented to enable monitoring of the functioning of the application. The data is encrypted using 256-encryption based SSL certificate. To manage security of data Xoxoday plans a quarterly VAPT based security audit of application.
We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. We use logical data isolation with the help of company specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system.
We comply with Information security compliance - ISO 27001;2013, SOC 2 and GDPR
Our product is ISO 27001 and GDPR compliant and have the features.
We have health checks along with Self healing mechanisms in place
99.99%
We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256. We have the ability to logically segment or encrypt customer data such that data may be produced for a single tenant only, without inadvertently accessing another tenant's data. our network environment is designed and configured to restrict any communication and connection between the tenant's environment.
Yes. We have the controls in place. We have blocked connecting Hard disk, USB, CD ROM etc to computers and all the devices are centrally managed.
The data is only stored on our application and its deployed on AWS Cloud. Our data is stored in secured databases and there is no window to alter any data without it being logged into the system records
We are a SAAS solution. We are cloud hosted.
We use a variety of tools and plugins integrated with Prometheus & Cloudwatch along with health checks for facilitating our uptime/service availability
Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
active-passive
Yes. we have implemented the cookies policy
Yes, we have the access controls
Yes
Yes, we have the access controls
Yes. Users can updated their information
Xoxoday - application platform has been integrated with Darwinbox with the objective of creating a reward system for employees. Organizations that are using DarwinBox will not only be able to automate their HR processes but can also reward employees to keep them motivated and engaged. Xoxoday application offers a unified rewarding platform that helps organizations build a winning organizational culture through reward and recognition programs that have a global catalog consisting of products and experiences from more than 700+ brands. Please click here to know more - [https://xoxoday.gitbook.io/application/developer-resources/integrations/darwinbox-+-application](https://xoxoday.gitbook.io/application/developer-resources/integrations/darwinbox-+-application)
Yes. Xoxoday's primary security focus is to safeguard our customers or users' data. This is the reason that Xoxoday has invested in the appropriate resources and controls to protect and service our customers. We have an Infosec Manager who is responsible for Information security and reports to the Board of Directors of the company. All the job descriptions, role and responsibilities has been documented as per the compliance requirements.
Xoxoday has developed a comprehensive set of security policies covering a range of topics. These policies are shared with and made available to all employees and contractors with access to Xoxoday information assets. Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. We spread awareness about the Information security among the employees through posters in public areas, emails, training and orientations etc..
Yes. All new hires are required to sign Non-Disclosure and Confidentiality agreements. The Employee expressly agrees that he/she shall not use Confidential Information provided by the Company in the development or delivery or for personal gain from providing any products or services for his/her own account or for the account of any third party. The NDA signed will be valid till the termination from an employement.
Yes, We have implemented the process for termination from an employement. Once the employee is terminated all the access will be revoked, IDs are disabled, assets are returned and recorded as a part of the exit clearance. We have implemented the access control procedure and all the access will be revoked upon termination or transfer of an emplyees as per the compliance requirements.
Anti-Virus is deployed in all systems and servers for protection against virus and malware. We use Bitdefender end point security for protecting the systems from virus and this has been updated on daily basis and centrally managed.
1. Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com) to raise a ticket, if you happen to notice any potential security issue whilst meeting all the required criteria in our policy. 2. The validation of the reported issue in terms of severity & authenticity will be done by our security team in around 90 days. 3. Post validation, steps will be taken to fix the security issues in accordance with our security policies. 4. The owner of the ticket will be informed once the issue is resolved. Security Severity has been categorized as High, Medium and Low. Once the reported vulnerability is closed we will conform the same.
Reports can be generated by the admins through the application. If there are any additional support needed, our customer support team would be able to help and guide on generating report.
We do not use any in-house devoloped applications. We have deployed our application on AWS cloud virtual platform. And AWS is SOC 2, ISO 27001, ISO 27017 and ISO 27701 certified organization. Shared the certificates.
[Please click here to know more about API Documentation - https://xoxoday.gitbook.io/application/user-guide/for-admins-1/xoxo-links/xoxo-link-apis https://xoxoday.gitbook.io/application/developer-resources/storefront-integration/api-endpoints](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/xoxo-links/xoxo-link-apis)
We have implemented the Web application firewall, IDs/IPs and amazon guard duty etc for maximum security. OAuth2 is used to authorize all API requests. We also conduct code review to make sure that the APIs are secure.
Yes. Our employees are having required education and certifications to perform the job.
We do conduct Internal and external Audit very year
Yes, It's a part og our ISMS training. Attached the training calender as an advace.
Xoxoday is compliant with - ISO 27001:2013, CPRA (California Privacy Rights Act), SOC 2 Type I, CSA STAR Level 1 and GDPR(General Data Protection Regulation). Attached the below mentioned documents. 1. Xoxoday ISOIEC 270012013 Certificate 2. Xoxoday SOC 2 Type 1 Report 2021 3. Xoxoday VAPT Certificate (Conducted by 3rd party vendor) 4. Xoxoday application VAPT Report (Conducted by 3rd party vendor) 5. Xoxoday CPRA Attestation Report 6. CSA STAR LEVEL 1 Compliant - [https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday](https://cloudsecurityalliance.org/star/registry/nreach-online-services-pvt-ltd-xoxoday)
We have deployed our application on AWS Virtual platform cloud. The AWS Compliance Program helps to understand the robust controls in place at AWS to maintain security and compliance in the cloud. Attached the below compliance certificates and Audit reports – 1. Amazon Web Services ISO 27001 Certificate 2. AWS ISO 27017\_certification 3. AWS ISO 27018\_certification 4. AWS SOC 2 Report 5. AWS SOC 2 Type I Privacy Report 6. AWS CSA STAR Certificate
Yes. We follow ISO 27001:2013, SOC-2 and GDPR We are ISO 27001:2013 certified and GDPR Compliant.
Yes. We are ISO 27001:2013 certified and GDPR Compliant. We are also complied with Cloud Security Alliance (CSA) STAR level 1.
Its SAAS Solution and available 24\*7
It's a web application. And it can be presented over the calls like MS Teams, Zoom, Google meet etc.
Yes. We have an integration with other applications and provide secure communications.
Yes
Yes. Files will be transferred securely.
Yes.
The solutions integrated with other solutions like Zoho CRM, HubSpot, Darwin box, SurveyMonkey, Freshdesk etc
NA. It's a SAAS Solution and does not require.
The data will be in our control. And AWS Cloud provide service for deploying our application. AWS is also ISO 27001 and SOC 2 certified organization and adhered to the data governance.
It's a part of our Risk assessment and we validate the compliance requirements of AWS cloud virtual platform annually.
We have implemented all the required Infosec Policies and procedures as per ISO 27001:2013, GDPR and SOC-2
We perform Internal Audit and external Audits annually. We also conduct Security assessments and testing like Vulnerability assessment and Penetration testing every six months. Yes. We communicate these assessment results to clients on a yearly basis.
We have the arrangements in place. Storage Period would be as per regulatory conditions. Personal data can be deleted based on a formal written request. Xoxoday would delete the data within 30 days of receiving the request. We will delete the data of the customers upon the termination of the contract and Our data cleansing process goes through an organized purge. Once the data is purged, it's purged from all places
We have implemented all the SOC controls and in the last phase of Audit. We would be able to provide SOC 2 Type I report in next 2-3 weeks
We have BCP/DR Policy as per the Infosec compliance requirements and we conduct the BCP test annually. See Business Continuity Management Procedure attached.
See attached Incident Management Procedure attached
Yes. An independent security third party audit been completed by "TUV NORD". The last last day of Audit was 29th June 2021
We have establised the Information security management systemIt specifies the scope and the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving the information security management system (ISMS) at Xoxoday. Xoxoday is committed to ensure Integrity, Confidentiality, Availability and Security of its Physical and Information Assets and also maintaining privacy for serving the needs of the customers and organization while meeting appropriate legal, statutory and regulatory requirements. Attached the Information Security Management System Manual.
We have the Data security Controls in place. We have implemented IDS/IPS, Firewall and our security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting. We have Cloudflare web application firewall for maximum security of data. We have implemented the role based access control system to make sure that the data os available only to an authorised individual. Nreach Online Services Pvt ltd, respects the individual right to their personal information and is committed to use minimum personal data with transparency, accuracy & protection of confidentiality, integrity, availability, privacy, authenticity & trustworthiness, nonrepudiation, accountability and auditability of the data received, stored, processed and destroyed for business purposes. Atatched the Xoxoday GDPR Data Security Policy
We are compliant. We collect the data only throigh our application. We have role based access system to make sure that only the authorised individual have an access to the required information All the devices and emails are having adequate security controls. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory for more security. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.We have SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user.We also have Implemented least privilege; restrict users to only the functionality, data and system information that is required to perform their tasks.
Yes. We have Implemented the SPF/ DKIM/ DMARC effectively.
We are compliant. We have implemented the Password Management Policy We store password hashed. We have SHA512 hash with unique salt for every password. The password needs to be minimum 8 characters long and should contain at least one capital letter, special characters among '# \$ % \* &' and 1 digit. Maximum Password Age is 45 days. User IDs and passwords transmit through stringent checks in an encrypted format that complies with the current Technical Security Baseline Standards. All the user can set their own password from the very first login attempt. Passwords once used cannot be reused with the password history technique in order to disallow the reuse of old passwords.
[AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
We inform Fincare if these regulatory authories agreed to inform.
Yes. 30 days prior notice and scope of the Audit needs to communicated.
We are a multi tenant SAAS system and all our logs will contain data of all customers. We will have our own log monitoring and security analysis.
Its a SAAS product and we use We use TLS1.2 encryption for Data in transit and AES256 for Data at rest.
Yes
Yes
[We store data on AWS Singapore.AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
We do not own the data centers. We deploy our application on AWS cloud virtual platform.
[We store data on AWS Singapore.AWS is ISO 27001, ISO 27017, ISO 27701, SOC 2, PCI DSS Level 1 certified organization. Please click here for more information about AWS Audit and certification - https://aws.amazon.com/compliance/programs/](https://aws.amazon.com/compliance/programs/)
Attached the ISO27001:2013 certificate. We do not collect and store any Payment card details. PCI DSS is not applicable for us.
We inform the client if there is any changes of the design that impacts security posture of the system.
We take steps to securely develop and test against security threats to ensure the safety of our customer data. We maintain a Secure development Lifecycle, in which training our developers and performing design and code reviews takes a primary role. In addition, Xoxoday employs third-party security experts to perform detailed penetration tests on different applications. application is ISO 27001, GDPR, CPRA/CCPA, CSA STAR certified.
Our technical team maintains these records.
We consuct the code review as per the compliance requirements and maintain the code repository. Attached the SDLC Proedures.
Compliant.
Since application is a SaaS Platform this would be not applicable.
Since application is a SaaS Platform this would be not applicable.
Since application is a SaaS Platform this would be not applicable.
We are compliant with the requiremenrts.
We do not transfer manually. NA And we use Google workspace for emailing solution.
cryptographic keys are protected. Compliant.
We do not store any PHI. The PII(name, email ID, phone#) are encrypted. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security.
We store only the PII(name, email ID, phone#) and does not store/process PHI & PCI. We are compliant with ISO 27001, CCPA/CPRA, EU GDPR, CSA etc. Attached these compliance certificates/audit reports.
Yes, all the mechanisms related to security and policies are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools.
The information used for authentication is securely stored and transmitted. We store password hashed. We have SHA512 hash with unique salt for every password
Not applicable since application is a SaaS platform.
At Xoxoday we use Google workspace and activated the MDM features. application also has iOS and Androind mobile applications.
This feature can be configured with the help of the MDM Solution that the customer use.
At Xoxoday we use Google workspace and activated the MDM features.
Compliant. We have segreated the roles and assign the responsibilities to our employees.
Since its a Cloud hosted SaaS platform deploying of the application on cloud and server scannings are under the scope of Xoxoday.
We use Web application firewall (WAF) and pfSense firewall for security reasons. 1. The Cloudflare Web Application Firewall (Cloudflare WAF) checks incoming web requests and filters undesired traffic based on the set of rules. 2. pfSense helps to monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on a defined set of security rules.
At xoxoday we monitor and maintain the logs. The Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long term cloud storage.
At Xoxoday we have implemented the Active directory and the system will get locked if its inactive for more than 15 mins and re-autentication would require.
We have the process in place for standardized approach to structured exception and error handling across all layers.
At Xoxoday the validation has been done during the development and testing and we are compliant with the requirements.
At Xoxoday Security and compliance requirements are considered during the development stage and we are ISO 27001, CPRA, CSA STAR level 1, GDPR compliant.
We have implemented the controls to monitor the application and safegurd from the attacks. We use Amazon CloudWatch and Grafana polemique which allows us to monitor instances and alerts us through emails.
Since application is SaaS Platform it would be not applicable.
We have implemented the Software Development Life Cycle (SDLC) procedure and attached the same for your reference. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing. We remidiate or fixes the issues identified during the VA/PT assessment and make sure that the application is free from the vulnerabilities.
Since it's a SaaS platform and deployed on AWS cloud virtual platform Singapore region. All the data will be stored on AWS VPC.
Xoxoday is ISO 27001:2013 certified. An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organisation's information risk management processes with the aim of keeping information secure. With ISO's robust information security management system (ISMS) in place, you gain the additional reassurance that a full spectrum of security best practices is implemented across the organization Our Goal is to protect three aspects of information - Confidentiality: only the authorized persons have the right to access information. Integrity: only the authorized persons can change the information. Availability: the information must be accessible to authorized persons whenever it is needed.
We have implemented the Access control policy to control the upload, download, viewing and modification
AV Scans takes place every week and users also can scan it whenever they can scan the machine. We have prescheduled the scanning once in a week.
We are using linux operating system which is inherently secure along with security practices like web application firewall etc We make sure that the customer data is well segregated and compartmantalized
No Breaches taken place.
We are having Robust Information security compliance framework and we are ISO 27001:2013 and GDPR complied. We follow all the applicable infosec compliance requirements to comply with the regulations
We conduct the Risk assessment and compliance review on annual basis as per the compliance requirements.
Yes. All the compliance and audit findings has been mitigated.
All the vulnerabilities identified during the assessment has been fixed.
We use Bitdefender end point security and installed on servers and development machines.
Its updated on regular basis.
Our roles and job duties are segregated through role-based access to ensure maximum security. Access to data and systems are based on the principles of least privilege for access. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events.
Its restricted and not available to the public.
We follow the best practices ans servers are hardened for security reasons.
We have implemented the Identity access management (IAM) and follow the Access control policy.
At Xoxoday we follow the password policy.
We have deployed our application on AWS Virtual platform cloud - Singapore region.
RTO and RPO is 60 Minutes.
We have implemented the Incident Management Procedure and attached the same for your reference.
Since application is a SaaS product and the customer can use the product and services as soon as subscribed for application product usage. the customer will have the legal rights to use the Product.
We do not change the terms frequently. We will provide 30 days' notice period for any changes of terms.
We notify Client in case of any unauthorized disclosure of or breach of any confidentiality obligation of Xoxoday with respect to Confidential Information, data or information of Client and Xoxoday shall take all necessary and required steps and measures to mitigate such unauthorized disclosure or breach and shall co-operate with Client , at Xoxoday 's cost, to mitigate or control the loss or liability arising out of such disclosure or breach and to retrieve such data or information.
Yes. have an active SLA in place that identifies minimum performance of the Product.
We have the SLA in place. application endeavours to provide 99.9% Uptime each month 24 hours a day 7 days a week. Uptime is measured based on the monthly average of availability.
We would be able to provide a report on need basis.
No penalties are associated with SLA.
We monitor the service continuously and make sure that the product and service is available to use all the time. We have a documented Business Continuity and Disaster Recovery Plan defined and implemented to enable people and process support during any crisis or business interruptions.
Since our services are delivered via. Web, the upgrades and updates to the services are seamless and usually do not involve any actions from the end-users.
Yes.
Our architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows. If there is any major activity and the service will be unavailable, the Maintenance hours were communicated well in advance at least 3-4 day by application.
Termination clause will be the part of Master Service agreement and both the parties can review and agree during entering into an agreement.
Since it's a SaaS product, this is not applicable.
Termination clause will be the part of Master Service agreement and both the parties can review and agree before entering into an agreement.
Yes. changes to the production environment or development are documented, tested, and approved prior to implementation or any new releases. We conduct internal reviews and audited by the external auditors for our security standard certification. We conduct periodical Vulnerability assessment and Penetration Testing from the Industry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications.
the customer data will stored on AWS virtual platform cloud Singapore. There is no impact on security.
At Xoxoday we have implemented the Cyber Crisis Management Plan to provide and support capability for reporting and responding to cyber security incidents, to eliminate or minimize impacts of such incidents
No.
We monitor the logs on regular basis with regards to network, file and server, and security system. To provide more information, the infrastructure logs are collected using AWS Audit Trail and Application related logs are collected in our Elastic Search server and retained in long term cloud storage.
No. Since we are a multi-tenant system, our logs contain information of all the tenants. We cannot isolate a single customer's information from our logs.
At Xoxoday the Audit logs reviewed on a regular basis for security events. audit logs are set up, reviewed by our Technical team and logs are recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
We are GDPR Compliant. Our information security team and Customer support team will inform the POC of Client via email communication with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions.
Yes. We have implemented the incident response plan and it complies with industry standards ISO 27001:2013, SOC-2, GDPR.
We are ISO 27001:2013 certified and attached the certificate.
# HR Compliance
Source: https://help-plum.xoxoday.com/faq/security-compliance/hr-compliance
Find answers to frequently asked questions about Plum's HR compliance practices and internal employment-related policies.
Each employee undergoes a process of background verification. We hire reputed external agencies to perform this check on our behalf. We do this to verify their criminal records, previous employment records, if any, and educational background. Until this check is performed, the employee is not assigned tasks that may pose risks to users. There will be exception and it applies to all the employees, contractors, vendors, and others who may have access to your systems.
Yes, we conduct background verification of all the employees
Yes. We conduct Background verification criminal history checks for all candidates for employment, contractors and third party vendors
Yes. We have the procedure for exit clearance and we will remove all the access provided and take all the assets back from the employees.
We do conduct employees and contractors background verification as per the compliance requirements
As a part of onboarding process all the employees are mandated to sign a non-disclosure agreement
As part of the employee on-boarding process, all new joinees are provided with awareness training on information security and privacy requirements at Freshworks. Annually a refresher training is conducted for all the employees. In addition, on a need basis, role-based information security and data privacy training are provided to different teams.
The disciplinary process has been documented and communicated to the employees. As a part of on boarding process we also have taken Information security declaration form from all the employees and made it mandatory. All the employees are aware that in case of any breach the desciplinary action will be taken against them,
User registration and de-registration process is a part of Onboarding and Offboarding.
We have provided WFH option to all our employees and also we follow hygiene practices at work and educating employees on the importance controlling infections at work by adopting correct hygiene practices
We have taken a approriate measures and stopped travelling due to an outbreak. All the employees are working from home and issued guidelines to get protected from the current situation.
We are compliant.
We are compliant.
YES. We conduct the mandatory background verification.
Each employee undergoes a process of background verification. We hire reputed external agencies to perform this check on our behalf. We do this to verify their criminal records, previous employment records if any, and educational background. Until this check is performed, the employee is not assigned tasks that may pose risks to users. All new hires are required to sign Non-Disclosure and Confidentiality agreements. The Employee expressly agrees that he/she shall not use Confidential Information provided by the Company in the development or delivery or for personal gain from providing any products or services for his/her own account or for the account of any third party.
Yes. We conduct the background verification of all our employees.
We performs background checks for all the employees in accordance with law. The background check includes criminal, education, and employment verification etc.
We conduct ISMS training for all the employees. The frequency of the training will be annually.
Yes. We conduct the background verification of all the employees.
We provide mandatory security and awareness training to all our employees and spread awareness about the information security accrross the organization.
Yes. Our employees are having required education and certifications to perform the job.
Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. All our engineers and other employees who suports application service are having appropriate education and skillset to perform the job.Each employee undergoes a process of background verification. We hire reputed external agencies to perform this check on our behalf. We do this to verify their criminal records, previous employment records, if any, and educational background. Until this check is performed, the employee is not assigned tasks that may pose risks to users.
Yes
Yes. All the employees and third party service providers are required to sign Confidentiality Agreements to protect customer information as per ISMS compliance requirements.
We conduct Background verification of the vendors before onboarding. We have implemented Supplier Management Procedure, and this is applicable to all suppliers delivering various products and services with respect to delivery functions and support functions including Finance, Legal, Human Resources, IT Infrastructure. We are having contracts or agreements and non-disclosure agreements with all our suppliers Xoxoday monitors supplier services and compliance requirements and review each supplier annually with respect to the services delivered by the supplier. The review frequency could be changed based on the criticality of the services provided. Validation of suppliers related documentations are also part of our internal and external Audits.
It's a part of our recruitment process. Attached the Background Verification Procedure
Each employee undergoes a process of background verification. We hire reputed external agencies to perform this check on our behalf. We do this to verify their criminal records, previous employment records if any, and educational background. Until this check is performed, the employee is not assigned tasks that may pose risks to users.
Yes. We have a Recruitment policy.
Yes. We conduct background verification of all the employees before onboarding.
Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles. We also conduct the annual training for all the employees thereafter.
Yes. We have communicated to all the employees and conducting periodical Awareness training to spread awareness and the employees are well aware of Incident reporting system.
# Identity and Access Management
Source: https://help-plum.xoxoday.com/faq/security-compliance/identity-and-access-management
Find answers to frequently asked questions about Plum's identity and access management practices and internal security controls.
Yes, our policies and procedures are established and implemented to enforce two-factor authentication for privileged account management/authentication while accessing tenant data/systems.
Yes, systems must be configured to log all successful and unsuccessful login attempts by accounts with privileged access. These authentication logs must be retained for a minimum of 180 days and in accordance with the Company's records retention guidelines.
Yes, users can re-authenticate a change in credentials and we comply to any attempted change in authentication information.
No, we do not present login notices to users before they log in as the users are redirected through SAP SuccessFactors.
Yes, there is a protocol in place to ensure that no information beyond an unsuccessful login attempt goes through prior to a successful login.
Yes, our partnerships with a wide array of integration partners ensure existing customer based Single Sign On (SSO) capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. Please refer to our list of integrations to know more.
Yes, our identity federation standards include SAML 2.0, SPML, WS-Federation and more as means of authenticating and authorizing users with airtight security protocol.
We isolate our machines, network and storage with respect to the AWS Standards in order to keep it safe and secure.
No, tenants are only allowed to use our secure protocols and procedures to prevent cracks and folds in data handling.
Yes, we do support our clients' and tenants' access review policies.
Our password setting requirements comply with all factors to ensure that strong passwords are created. Passwords should be of a minimum length and contain special characters, capitalized letters, and alpha-numeric combinations.
No, customers/tenants must comply with Xoxoday's account lockout and password polices that have been incorporated for maximum security.
No, the user can set their own password from the very first login attempt.
No. As Xoxoday's products use single sign on (SSO), the users can login via their suite email and credentials.
Yes, audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
Yes, to ensure the maximum safety and authority of data in right hands, the physical and logical adult log access of users can only be accessed by authorized personnel.
No, logs are automatically audited, but are not integrated with tenant's security ops. In case the tenant requests for logs, they can shared when asked for by the clients.
Yes, regular audit logs are stored with Xoxoday and retained for future references.
The event logs are stores in a bucket wherein nobody can access them without an approval from the high authorities i.e. the Chief Technical Officer.
Yes, all the mechanisms related to security and policies are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools.
Please refer to: "Threat & Vulnerabilities Management Procedures".
Yes, in case specific incidents arise for particular tenants, our logging and monitoring framework allows isolation of incidents.
Yes, there are measures to limit the access of tenant's data from non-authorized devices. Please refer to "Access Control Procedures".
No. In case the accounts are deactivated or dormant, they would still be in the Xoxoday's domain. The admin would have to manually reach out and disable the accounts that they wish to declare dormant or inactive.
Yes. Passwords once used cannot be reused with the password history technique in order to disallow the reuse of old passwords. Please refer to "Password Management Policy".
Yes, with access control limit, super admins and admins can give out access to authorized individuals as per requests raised by them in order to handle their platform as well as the personal data accordingly.
Yes, the role of "admin" and "super admin" holds the high regards and these roles can process the personal data of users as per their choice with the access control limit capability.
Yes, personal data is stored are registered databases that comply to all necessary inputs of a standard inventory repository.
Yes, all the given credentials are safely stored in a TCCC-approved centralized system in order to securely process the personal data.
Yes, our roles and job duties are segregated through role-based access to ensure maximum security of tenants' databases.
Yes, in case an incident occurs with respect to inappropriate access of data, we shall share the reports.
Yes, we do support measures to enforce strong multifactor authentication when it comes to accessing highly restricted data.
No, the data can be accessed by Xoxoday's authorized personnel to serve you better with maximum security.
We have AWS Identity and Access Management (IAM). Access to data and systems is based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provide centralized control to administer, monitor, and review all critical access events.
AWS is responsible for providing physical security to the data center as we have deployed our application on AWS. AWS provides physical data center access only to approved employees. All employees who need data center access must first apply for access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access and are time-bound. Requests are reviewed and approved by authorized personnel, and access is revoked after the requested time expires. Once granted admittance, individuals are restricted to areas specified in their permissions. Third-party access - Third-party access is requested by approved AWS employees, who must apply for third-party access and provide a valid business justification. These requests are granted based on the principle of least privilege, where requests must specify to which layer of the data center the individual needs access, and are time-bound. These requests are approved by authorized personnel, and access is revoked after request time expires.
Yes, we have implemented the process for termination from employment. Once the employee is terminated all the access will be revoked, IDs are disabled, assets are returned and recorded as a part of the exit clearance. We have implemented the access control procedure and all the access will be revoked upon termination or transfer of an employee as per the compliance requirements.
Yes. We use a cloud-hosted VPN with strict access controls to allow our employees to access the official network.
Yes, We have implemented the security operations center to monitor, prevent, detect, investigate, and respond to cyber threats around the clock.
We have AWS Identity and Access Management (IAM). Access to data and systems is based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. Furthermore, while defining job roles and designing access roles, privileges leading to conflicts of interests are to be avoided. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events.
our identity federation standards include SAML 2.0, SPML, WS-Federation and more as means of authenticating and authorizing users with airtight security protocol
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network.
Wireless access is allowed and handled with high quality routers, password protection and restriction on internet usage etc.
All our employees are having a unique email IDs and we have implemented the role based access control. Our product team will create an account for the admin users and the password can be changed immediately.
Yes, we have the exit procedure and all the access provided to an employee will be removed or deleted.
Yes. We review the access provided every month and the SPOC will be our system administrator.
Yes. We have defined the number of unsuccessful attempts. After 3 unsuccessful logins the account will get locked.
Yes, we have the different levels of access. For Ex - Admin, users.
Yes. Every 90 days
We will get an email for resetting the password. Once we click on it it will take us to a different window and provide an option to change or reset the password.
We use only internet connection through wifi and only after the approval process IT Team will provide an access.
Yes. We have all these controls. We have restricted access to shared folders, USB or external drives, Internet access and privileges access.
Yes. We have a track of all these information and we will remove the access once the empoyee left the organization.
Yes, we have different level of access like Admin and users and its configured in a secured manner.
It's an application and it supports SSO and Active directory. Time our period that we configure in SSO/AD would apply.
Yes. We have segregated the areas. We have implemented the controls for having the access only to an authorised individuals for production area.
Yes, we have the controls.
Yes. We have segregated the users.
Sharing device is not allowed. All the permisson needs to be taken from the IT Team. Not provided these access to the employees.
We have different levels of users and only upon approval and need basis will get access.
At Xoxoday for all the critical applications the 2FA has been enabled.
only Xoxoday authorised individual will have an access
All the computer machines are restricted with Access to CDs, USB or any other hard drives. We do not grant access for security reasons.
The secured areas are restricted and does not have access with electronic devices or mobiles. These areas are physically locked and periodically reviewed as a part of internal and external audits. Also these restricted area are secured with CCTV cameras and monitored 24\*7 for security reasons.
We have implemented the access control procedure and we revoke the access rights of the employees when not needed or termination from the employment. Access granted and revoked will be reviewed regularly and validated during the internal and external audits.
Access to the systems are based on the principles of least privilege for access. All the users have restrictions on installing and uninstalling the application/softwares, they are not provided with Admin access. Admin access will be with the the IT support head and will not be available for the normal users.
We remove the access immediately after termination of an employees as a part of exit procedures. We inform the BSLI incase of any involuntary termination of an employee working on client account within a reasonable timeframe
We have implemented the role based access control policy. We regularly monitor the user access controls and make neccessary reconciliation for security reasons.
Our employees are provided access for corporate emails. But we have restricted for accessing other email service provider, sending the PII on emails, sending an email to personal email Ids etc for maximum security.
All our employees are not provided with access to the client data. Only authorised individual will have access on need and approval basis. The approvers are either the Product Heads or CTO. Content Filtering Solution in place for cotrolled access to Internet and all the logs are monitored.
We have the documented procedure in place for user access management. Attached the Access Control Procedure. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need to know basis and support segregation of duties. Access to data and systems are based on the principles of least privilege for access and need to know basis. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. Only authorised individual will have access on need and approval basis. The approvers are either the Product Heads or CTO.
We provide option of work from home/remotely to our employees. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory.
All the computer machines are restricted with Access to CDs, USB or any other hard drives. We do not grant access for security reasons. We have Changed default credentials and turned off services that are not needed. MFA has been enabled to make sure that only authorised individuals have access. We have implemented Cloudflare web application firewall, IDS, Guard Duty etc in order to prevent DDOS-type attacks. (Attached the evidence of Cloudflare web application firewall, IDS, VA/PT reports, guard Duty etc) We have implemented the role-based access control system and Only authorized users have access to the servers. logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long-term cloud storage. mechanisms are implemented to detect, address, and stabilize vulnerabilities We also have implemented the backup plan. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. Data backups are done daily and in a secured way in AWS.
All the systems are secured with Bitdefender end point security, VPN, Active directory, Firewall etc for maximum security.
All the sensitive areas are restricted and authorized personnel only can have access. Our facility is having Biometric access system and all the logs are maintained and periodically reviewed. We also have visitors management guidelines and All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff.
AWS Identity and Access Management (IAM) enables us to manage access to AWS services and resources securely
we don't provide multi-factor authentication. As of now, there's oAuth2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
We have 3 types of roles - User, Admin and Super Admin. Based on the roles and responsibility these access can be provided on need and and approval basis.
[Manage accounts - Manage Super Admin/Admins - https://xoxoday.gitbook.io/application/user-guide/for-admins-1/getting-started/settings/manage-super-admin-admins#can-the-super-admin-disable-his-her-own-account-if-no-how-is-the-scenario-of-the-exit-of-a-super-admin-handled](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started/settings/manage-super-admin-admins#can-the-super-admin-disable-his-her-own-account-if-no-how-is-the-scenario-of-the-exit-of-a-super-admin-handled)
Xoxoday application platform collects PII like Name, email ID and Phone number of the employees those who will be using this platform. Xoxoday is ISO 27001:2013 certified, GDPR compliant and SOC 2 type I certified organization and have all the required technical and organizational controls in place and auditred during the internal and external audits. We have implemented the role-based access control system and Only authorized users have access to the servers. We use Amazon IAM for Identity access management. logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our ElasticSearch server and retained in the long-term cloud storage. mechanisms are implemented to detect, address, and stabilize vulnerabilities We also have implemented the backup plan. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. Data backups are done daily and in a secured way in AWS.
Our network is protected through the use of key cloud security services, integration with our Cloudflare edge protection networks, regular audits, and network intelligence technologies, which monitor and/or block known malicious traffic and network attacks. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a Vulnerability assessment and penetration testing.
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role based access requirements. Furthermore, while defining job roles and designing access roles, privileges leading to conflicts of interests are to be avoided. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access. We conduct the access control review on frequent basis and revoke all the access provided for exit employees.
We have unique user IDs for all and does not use generic user IDs.Access to data and systems are based on the principles of least privilege for access. We conduct the access control review on frequent basis and revoke all the access provided for exit employees. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need to know basis and support segregation of duties. Privileges relating to Administration of user access privileges and role configurations are different from the authorized approver that approves access requests. The approvers are either the Product Heads or respective function Heads are their authorized delegates. Attached the Access control procedure.
An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need to know basis and support segregation of duties.
All our employees are having the unique log in IDs.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network.
We provide application web application.
Admins can control the application and will have an access to alerts and security events.
We inform the the customer to revoke access.
We have the alerting system in place and we perfom the scaning immediately in order to reduce the risk.
They do not have access.
Yes. We have role-based access system through access control policy to make sure that only the authorised individual has access to the required information. All the Access to data and systems are based on the principles of least privilege for access. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates.
Yes, We have the necessary controls in place in order to protec the information according to the data classification. For ex - Identity access management (IAM)
Yes. We have a SIEM in pance for monitoring and maintaining logs over security incidents from various components.
[Please click here to know more about admin acceess, Login, SSO Logins - https://xoxoday.gitbook.io/application/user-guide/for-admins-1/getting-started](https://xoxoday.gitbook.io/plum/user-guide/for-admins-1/getting-started)
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access. We have role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles
Only authorised individual would access on need and approval basis. We also use SSO.
All our employees are using official email IDs
We have implemented Role based Access control policy and only authorised individual will have access upon need and approval basis.
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role based access requirements. Furthermore, while defining job roles and designing access roles, privileges leading to conflicts of interests are to be avoided. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and it's linked with the SSO/Active Directory.
We monitor and review these privileged access provided and do the necessary reconciliation as per the Access control policy implemented.
1. Xoxoday application has a rich set of integrations with HRMS, HRIS, CRM, Survey, Marketing automation, SSO, SAML tools like SAP SuccessFactors, Zoho People, Darwin Box, Hubspot, Freshworks, Zapier, Hubspot, Type Form, Survey Monkey, Survey Gizmo, SAML 2.0, etc 2. SSO SSO Redirection - The client has to generate temporary token for SSO and redirect the user to Xoxoday with this temporary token. Please click here - [https://xoxoday.gitbook.io/application/developer-resources/storefront-integration/api-endpoints/sso-redirection#sso-token-from-company-session](https://xoxoday.gitbook.io/application/developer-resources/storefront-integration/api-endpoints/sso-redirection#sso-token-from-company-session)
Access to our production environment is allowed only via Xoxoday corporate network and access is allowed only to authorized individuals of the infrastructure and engineering team. Given the pandemic/WFH situation, VPN access has been enabled with 2FA For such authorized individuals, for ensuring business continuity. All our admins accounts has been sealed with MFA. and also we use AWS IAM for managing privileged identities.
We revoke the access once the tasks is performed or terminated from the organization as per the access control policy and part of the HR Exit clearance. Yes. access revocation process synchronized throughout all the systems. Attached the Access control policy.
We have implemented the Role-Based Access Control (RBAC) An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need to know basis and support segregation of duties. Privileges relating to Administration of user access privileges and role configurations are different from the authorized approver that approves access requests. The approvers are either the Product Heads or respective function Heads are their authorized delegates. We review the access rights on monthly basis. Attached the access control policy.
We have implemented the incident management procedure and attached the same. We communicate with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions.
We use logical data isolation with the help of company specific encryption keys. We have encrypted the data while in transit and at rest. We use TLS1.2 encryption for Data at transit and AES256 Data at rest for maximum security. The incidents in other tenants would have no effect on the customer's services.
We are adhered to ISO 27001:2013, GDPR, CPRA, SOC 2, CSA STAR and VA/PT - Shared these certifications and Audit reports. We have implemented the Access control policy and shared the same for your reference. All our admins' accounts have been sealed with MFA. and also, we use AWS IAM for managing privileged identities. All our Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in the long-term cloud storage. The audit logs are reviewed and recorded on a regular basis automatically. These logs are integrated with security operations/SIEM solutions.
application support many SSO options such as - Google workspace. Azure AD, OKTA SSO, Onelogin, Ping Identity, Centrify etc..
There are four access roles: Super Admin, General Admin, Manager and Employee. Manage the level of access for each role through the access controls page
application is a web application and also supports Android and iOS apps. application is supported by a comprehensive web application that can be accessed via desktop and mobile browsers on all compatible devices. For ex -Google chrome, Internet explorer, Microsoft edge etc..
The access control mechanism like RBAC is built in the application. We have a Super Admin, Admin, and user's account.
Please click here to know more about SSO integration - [https://www.application.io/integrations](https://www.application.io/integrations) It supports Azure AD, Google workspace, Okta SSO, One login, Ping identity SSO, Centrify etc..
Its supports Azure AD integration.
No. it does not. Once SSO is enabled, the users are not presented with any password options.
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provide a centralized control to administer, monitor and review all critical access. We have a role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team, and it's linked with the SSO/Active Directory In addition to that we also use Encryption, Firewall, Bitdefender end point security etc.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team, and it's linked with the SSO/Active Directory
We have implemented the Web application firewall, IDs/IPs and amazon guard duty etc for maximum security. OAuth2 is used to authorize all API requests. We also conduct code review to make sure that the APIs are secure.
Yes. application supports SSO like Okta SSO, Onelogin SSO, Ping Identity SSO, Centrify etc.. Please click here to know more about application SSO - [https://www.application.io/integrations?tab=tab-sso](https://www.application.io/integrations?tab=tab-sso)
Our identity federation standards include SAML 2.0, SPML, WS-Federation
It Supports MS Azure active directory.
No.
We store password hashed. We have SHA512 hash with unique salt for every password
No. 2FA is not required for logging into the application. We only support SSO with the help of SAML2.0 protocol.
Yes. It supports SSO and OKTA Integration
Yes. The account owner will receive an email notification and all the activities are logged.
The account owner will receive an email notification and immediately and user can act on it.
We have enabled password reset process. It identifies from the domain name of the email ID. We can Change the password of the application account by navigate to Setting in the Quick Access menu.
2FA is not supported.
Yes. We have defined accessibility features, role-based permissions, access control and can Manage user access to various account functionality based on organizational needs.
When SSO (via SAML2.0) is enabled login via password will be technically prohibited
Yes. Users can provide complex password to make sure that the account is secure.
Yes. We have enabled Multi factor authentication. Our application also support multi factor authentication.
We have implemented the access control policy to make sure that only the authorised individual have an access to the data. You may suggest if anything needs to be added as per NSE access control policy.
Super admin have complete control of the platform and can configure everything.
We have the controls in place. As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks.
We have controls in place to monitor the user access system. We have implemented Role based access management system through access control policy. We also conduct internal review, Audit and external Audit from the third party auditors to make sure that we are complying with the requirements.
Yes, our identity federation standards include SAML 2.0, SPML, WS-Federation and more as means of authenticating and authorizing users with airtight security protocol.
We use Freshdesk and Jira for Authorizing access.
We have role based access system to make sure that only the authorised individual have an access to the required information. We also have Access Control Procedure as per the compliance requirements.
Yes. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory.
Yes. We have enabled MFA for maximum security
Yes
Yes. We have access control policy and change manangement policy in place. Our IT team periodically review the access granted to all the users and take necessary actions. Revocation of access and Asset submission is part of our exit procedure upon termination from the employment.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory.
We use AES 256-bit encryption for data at rest for securing digital identities
We store password hashed. We have SHA512 hash with unique salt for every password
The cryptographic keys, including data encryption and SSL certificates are managed by Xoxoday for optimal security of sensitive data. Each tenant data is uniquely encrypted using client specific key. We use AES 256 bit encryption for data at rest to ensure maximum security measures.
Yes
Yes
Yes
Yes
API Keys are stored in high availability ephemeral storage and not in any disc.
Yes
Yes
Yes. We follow role-based access system. We have implemented an access control policy and it will restrict access of the authorised individuals only.
At least 8 characters
45 days
5 attempts
Yes
Infrastructure logs are collected using the AWS Audit Trail, meanwhile the application related logs are collected in our Elastic Search server and retained in long-term cloud storage
All users have benn assigned a unique user account. We have implemeted the Access control Policy and all the system components, network files, sensitive data will be accessed my the unique user accounts.
All users have benn assigned a unique user account. And will not be reused by other people in the future.
Admins will have a Centralised directory and can manage the users. For ex - Creation and deletion of the users.
We are Compliant. We have implemented the Network Access Control and Security Procedure. We are diligently controlling access to computer resources, enforcing policies, Firewall, Switches etc
We review the access controls on periodical basis and make sure that only authorised individual will have an access to the Information system. We grant privileges only upon the need and approval basis as per the access control policy.
We review the access controls on periodical basis and make sure that only authorised individual will have an access to the Information system
We have the monitoring system in place. Unauthorised access or attempts will be detected and prevented
We have implemented the role based access control system. Only approved users will have an access to the Business application.
We have controls in place to monitor the user access system. We have implemented Role based access management system through access control policy.
We are compliant. Only authorised individual have an acces.
We are compliant
We use 2FA wherever is required to safeguard the information system.
We grant an access to the vendor whenever is necessary on approval basis and access will be revoked upon the tasks completion.
We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory for more security.
We have granted the logical access to the third parties upon approval and Agreement in place.
We have disabled all the access for security purposes. The access will be provided only on need and approval basis for a specific period of time.
We are compliant. We have role based access system to make sure that only the authorised individual have an access to the required information All the devices and emails are having adequate security controls. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.We have SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user.We also have Implemented least privilege; restrict users to only the functionality, data and system information that is required to perform their tasks.
We have installed the firewalls to monitor and control the incoming and outgoing network traffic based on predetermined security rules. It helps us to establishes a barrier between a trusted network and an untrusted network. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network. This VPN is managed by our IT team and is linked with the SSO/Active Directory for more security.
we can provide limited access to different vendors or systems.
We are compliant. We use a cloud hosted VPN with strict access controls to allow our employees to access the official network.
We have implemented the Network Access Control and Security Procedure. Network services are provided in house. We maintain the records for the service levels and reviewed during the internal and external Audits.
We always make sure that components are configured to the most restrictive mode.
We provide access to our employees to only required amount of functionalities for any software applications.We uninstall the softwares or disable the features wherever is not required.
We have disabled all the access for security purposes.
We review these access frequently.
We are compliant.
We are compliant. Physical access to equipment has been restricted to only necessary and authorised personnel
We are compliant.
Only authorised individual have an acces to the approved information assets.
We provide access to authorised individual on approval basis
Our application doesn't have a 2FA for admin functions.
We have role based access system to make sure that only the authorised individual have an access to the required information.
Yes. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest.
As per the access control policy our application controls the access of an unauthorised individual through diference levels of users like Admin, super admin and users.
Yes. We are complied. We have the access control policy and password policies.
We have access control polic and only the authorosed individual have an access to the PII on need and approval basis. We also review these access granted on monthly basis.
We have access control system in place and only the authorised individual have an access. Attached the procedure for your reference.
application supports SSO.
our identity federation standards include SAML 2.0, SPML, WS-Federation,Google SSO Login and more as means of authenticating and authorizing users with airtight security protocol
The application have robust authentication methods. We are integrated SAML 2.0 with SAP SuccessFactors, we also support OAuth 2.0 for seamless authentication.
Yes -SSO
Yes. We also fix the issues identified and conduct the test once again for confirmation of fixes.
Our partnerships with a wide array of integration partners ensure existing customer based Single Sign On (SSO) capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go.
Yes. We have physical access controls in place and only authorised individuals will have access. We have provided the access cards to all the employees and installed biometric machines at all the entry and exit areas. We have also installed the CCTV cameras in our building and will be monitored 24\*7 for maximum security.
We have implemented the access control policy and only authorised individual will have access to the systems/application. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need to know basis and support segregation of duties Access to the production environment is restricted to a limited set of authorized users based on their job responsibilities. Users from the development and testing or QA teams do not have access to the production environment. Access to migrate changes is limited to designated and authorized individuals. Access to the production environment is approved by the Product Owner and the systems of the authorized users are registered and authenticated during login. The access is controlled through the AWS Identity and Access Management system that also enforces two-factor authentication.
Yes. The list of users who have admin access have been maintained through AD, IAM, HRMS etc..and reviewed periodically and during the internal and external audits.
Mobile devices are not allowed for production use.
Yes. All the sensitive information has been encrypted. All the data at rest also has been encrypted for maximum security.
Yes. All the software installation restricted for desktops, laptops and servers. Users does not have permission to install any software or make any changes.
Yes. Access to source application code restricted. Application code has been stored in the code repository and have access only to the authorised individuals. We have implemented SDLC Policy as per ISMS requirements and we follow General Coding Practice. For example - We Conduct data validation on a trusted system, All cryptographic functions used to protect secrets from the application user. We also have Implemented least privilege; restrict users to only the functionality, data and system information that is required to perform their tasks we follow all the technical guidelines for development of our code and applications that come under the Open Web Application Security Project.
Yes. All our users uses unique IDs. There are no shared accounts.
Yes. We have implemented the access control policy and we review the use accounts on frequent basis for both admin and normal users.
Only authorised individual would access on need and approval basis. We also use SSO.
All our employees are using official email IDs
We have implemented Role based Access control policy and only authorised individual will have access upon need and approval basis.
Yes. We have role-based access system through access control policy to make sure that only the authorised individual has access to the required information. All the Access to data and systems are based on the principles of least privilege for access. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates.
Our employees will not have access by default. The data will be accessed only upon need an approval basis. The access is controlled through the AWS Identity and Access Management system that also enforces two-factor authentication
Yes.
No, we don't provide multi-factor authentication. As of now, there's oAuth2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
Yes, We have the necessary controls in place in order to protec the information according to the data classification. For ex - Identity access management (IAM)
Yes.
Yes.
We have implemented the physical access control and logical access control to protect the personal data. We have security guards, CCTV cameras, access cards etc for monitoring purposes. We use logical data isolation with the help of company specific encryption keys. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256
Only authorised individual will have an access.
Yes. The administrator has the privileged access and can add or terminate the users. Admins have complete control of the platform and can configure the addition and deletion of the users through the admin console.
Yes. application comes with a full set of integration with various platforms like AD.
No. We do not use 3rd party application framework
It's a SAAS Solution and can login in the multiple system by using the Single user ID/Password.
Yes, there is a protocol in place to ensure that no information beyond an unsuccessful login attempt goes through prior to a successful login.
Yes. We have this mechanism.
Yes. solution disable the User ID automatically if the unsuccessful attempts exceeds the maximum of trial
Yes
Yes.
Its not shown in the screen or sent via email.
Password will be reset upon the email confirmation through password reset link. Once we click on the reset my password.it will redirected to the platform and ask us to Set a new password for our account.
Password will be reset upon the email confirmation through password reset link. Once we click on the reset my password.it will redirected to the platform and ask us to Set a new password for our account
We have enabled the role-based access system to provide an access to only authorized individuals.
Yes. It can be managed centrally.
The platform will get locked out as configured in AD or SSO ect
No. Its linked with the Email IDs
Yes. We can set up an account with the help of unique email IDs
Yes
It supports Email and Mobile phone Authentication.
JSON-based token is available for maximum security direct-email logins.
We have implemented the role-based access system to make sure that only the authorized individual have access to the required information.
We have more than 100 employees for the application product including support functions. Few important positions those who are involved in Infosec and IT Security Functions Chief Operating Officer Vice president - application DevOps Head - application Product Head - application Infosec Manager IT Head
We have Access Control Procedure and role based access system to make sure that only the authorised individual has access to the required information.
application collaborated with the tools like MS Teams, Slack and HRMS tools like Gusto, Keka, SAP Successfactor, BambooHr, Ramco HRMS, people strong, Zohopeople and darwinbox. Users can also login via G Suite, Azure AD, Okta SSO, One login SSO, Ping identity SSO and Centrify.
We have 4 user access roles - Super admin, General Admin, Manager and Employee.
application collaborated with the tools like MS Teams, Slack and HRMS tools like Gusto, Keka, SAP Successfactor, BambooHr, Ramco HRMS, people strong, Zohopeople and darwinbox. Users can also login via G Suite, Azure AD, Okta SSO, One login SSO, Ping identity SSO and Centrify.
Yes. we have the Physical security controls in place. Attached the Physical and Environmental Security Procedure. All the Fincare data will be stored on AWS Cloud virtual platform and will not store anything locally. The purpose of this procedure is to prevent unauthorized physical access, damage, interference, theft or compromise to assets owned or controlled by Nreach Online Services Private Limited.
Yes. We have the Access control policy to make sure that the data os available only to an authorised individual.. Attached the Access control policy.
Yes.
Attached the Access control policy
No.. it does not. Once SSO is enabled, the users are not presented with any password options.
Super Admin (CTO) and Devops team are the custodians of the key.
[application supports Single Sign-On (SSO). Please click here to know more - https://www.application.io/integrations?tab=tab-sso](https://www.empuls.io/integrations?tab=tab-sso)
Since empluls is SaaS platform this can be configured with the help of the Active directory so that the users who are inactive for more than 15 mins can re-login.
Yes. Account can be created, disabled and password can be reset.
Password is masked during the entry. We store password hashed. We have SHA512 hash with unique salt for every password.
[application has four different user access levels, namely Super Admin, General Admin, Manager, User. Please click here to know more - https://help.application.io/platform-management/platform-settings/access-controls](https://help.empuls.io/platform-management/platform-settings/access-controls)
[application has four different user access levels, namely Super Admin, General Admin, Manager, User. Please click here to know more - https://help.application.io/platform-management/platform-settings/access-controls Xoxoday is ISO 27001:2013, GDPR, CCPA/CPRA and CSA STAR Level 1 compliant organization. We take appropriate consent for collecting the PII (Name, Email ID, Phone#) as per the privacy laws. Xoxoday GDPR - https://www.xoxoday.com/gdpr Xoxoday Privacy - https://www.xoxoday.com/privacy-policy](https://help.empuls.io/platform-management/platform-settings/access-controls)
Since empluls is SaaS platform this can be configured with the help of the Active directory.
Yes. This can be configured and users can reset the password.
Admins will have a centralised controls on the platform and will have access for creation/deletion of the users as per the requirements. Please click here to know more - [https://help.application.io/platform-management/platform-settings/access-controls](https://help.application.io/platform-management/platform-settings/access-controls)
Admins will have a centralised controls on the platform and will have access for creation/deletion of the users as per the requirements. Please click here to know more - [https://help.application.io/platform-management/platform-settings/access-controls](https://help.application.io/platform-management/platform-settings/access-controls)
application has four different user access levels, namely Super Admin, General Admin, Manager, User. Please click here to know more - [https://help.application.io/platform-management/platform-settings/access-controls](https://help.application.io/platform-management/platform-settings/access-controls) Application can be used only by the authorised individuals.
We have implemented the oAuth2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
At Xoxoday, the access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role based access requirements. A strong identification and authentication system(AWS IAM) and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events.
Yes the application have robust authentication methods. The users can re-authenticate a change in credentials and we comply to any attempted change in authentication information. our identity federation standards include SAML 2.0, SPML, WS-Federation and more as means of authenticating and authorizing users with airtight security protocol.
At Xoxoday we review the access controls on frequent basis.
We remove/revoke the access of the users upon termination or the access is not required and maintain these records for Audit purposes.
At Xoxoday we review the access controls on frequent basis. Compliant. Attached the Access control policy.
Yes. The customer will have control on the Application as they will be having the Super admin access.
Yes. The users can access the mobile application only upon successful login.
We provide remote support using the client remote access tools.
[application has four different user access levels, namely Super Admin, General Admin, Manager, User. Please click here to know more - https://help.application.io/platform-management/platform-settings/access-controls](https://help.empuls.io/platform-management/platform-settings/access-controls)
We have implemented the Role based access control machanism. Attached the Access control policy. We have the controls in place on who access the information and what level of access needs to be provided etc..
At Xoxoday we have implemented the Identity access management and all the applications are authenticated before login.
We conduct the code review and get an approval from the CTO before releasing any new versions or updates.
At Xoxoday we have implemented the Identity access management and all the applications are authenticated before login.
Compliant. Only authorised individuals can have access to the application with the help of the valid credentials.
No. Its not accessed via direct internet connection. Access to our production environment is allowed only via our corporate network and access is allowed only to authorized individuals. We use a cloud hosted VPN with strict access controls. VPN access has been enabled with 2FA For such authorized individuals.
We have Role-based access control (RBAC) system and make sure that only the autorized individual have an access to the data. And we review these access provisoining regularly and deactive the users access as per the change management policy.
No. We do not use generic IDs to access data
application application has four different user access levels, namely Super Admin, General Admin, Manager, User.
Super Admins are the default admins of application. They are also the Group Admins of Townhall. Super Admins can view what access permissions are available to various user access levels using Access Control settings. Super Admins can also delegate access for various features and tasks to General Admin, Manager & User. Within Xoxoday, Access to data and systems are based on the principles of least privilege for access. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access events.
We have implimeneted the Access Control policy and follow the role based access control system. And all the access has been reviewed and make the necessary adjustments. The roles and access rights are reviewed during the internal and external Audits as well.
Our partnerships with a wide array of integration partners ensure existing customer based Single Sign On (SSO) capability for all users to seamlessly use Xoxoday's products. With an easy DIY setup, your SSO solution would be plugged in and ready to go. our identity federation standards include SAML 2.0
At Xoxoday we have enabled MFA for all the critical roles and privilege accounts for maximum security.
At Xoxoday user accounts will lockout after 5 unsuccessful failure login attempts.
At Xoxoday all the users enforced to change the password for every 90 days.
We store password hashed. We have SHA512 hash with unique salt for every password.
We have implemented the Identity access management and follow the Access control policy.
At Xoxoday we follow the password policy.
We have implemented the Identity access management and follow the Access control policy.
At Xoxoday we follow the password policy. Attached the same for your reference.
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access.
We have role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. The approvers are either the Product Heads or respective function Heads are their authorized delegates.
We logically segregate the the customer environment from other clients, each customer is uniquely identified by a tenant ID. It is segregated with a client-specific key for proper handling and security reasons. The application is engineered and verified to ensure that it always fetches data only for the logged-in tenant. Per this design, no customer has access to another customer's data.
An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. Privileges relating to Administration of user access privileges and role configurations are different from the authorized approver that approves access requests. The approvers are either the Product Heads or respective function Heads are their authorized delegates. Developers do not have access to the production environment. Access to the production environment is restricted to a limited set of authorized users based on their job responsibilities
Within Xoxoday Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. Furthermore, while defining job roles and designing access roles, privileges leading to conflicts of interests are to be avoided. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access. We use Active directory and SSO for authentication purposes.
[No, we don't provide multi-factor authentication. As of now, there's oAuth2.0 and SAML-based tokens Please click here to know more about Single Sign-On - https://www.application.io/integrations?tab=tab-sso](https://www.empuls.io/integrations?tab=tab-sso)
Within Xoxoday Access to data and systems are based on the principles of least privilege for access. Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles of need-to-know basis and support segregation of duties. Privileges relating to Administration of user access privileges and role configurations are different from the authorized approver that approves access requests. The approvers are either the department heads or the management.
At Xoxoday only authorised personnel from our technical team will have access. For Ex – CTO/production head, Devops Lead etc.. The event logs are stores in a bucket wherein nobody can access them without an approval from the high authorities i.e. the Chief Technical Officer.
# Information Security
Source: https://help-plum.xoxoday.com/faq/security-compliance/information-security
Find answers to frequently asked questions about the information security practices and standards Plum follows.
[Open document](https://drive.google.com/file/d/1l23BTr1RStFZq_QmF-5V2vpS06cBJnHb/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1oww6vB7PxwXGafO33h0jG-T1VlD0Wm8q/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1WxUI_BnLLbeNzQHtWgkgLFqzhuZxIwax/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1P_7-nKbRI8AIWUgm66Q9aUsYr83nN85r/view?usp=sharing)
[Open document](https://drive.google.com/file/d/10UXddHd9CxaCO6OLyqEM5PC1iGS2vFEz/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1bRjJvB4gDqvkp-WY_NlwTNL35K-Y6_YS/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1LQsURIqAmb8waKgI5DJac2D5hUVDNjua/view?usp=sharing)
[Open document](https://drive.google.com/file/d/10JIrklIh9EzHWYQYLUvw-oDoTd3THwY2/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1PpWRocTmV2CKzZPvVf-9b60qi0Pe3Gx3/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1pzfi-zYodRujjPR5RzktjqyE4LME2jT_/view?usp=sharing)
[Open document](https://drive.google.com/file/d/18qj9Cu55TuMileF7ppUJTNqfklabZFAX/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1FLNuR6I5uy3DHyuH6joR6v5KvlP-_aI-/view?usp=sharing)
[Open document](https://drive.google.com/file/d/17eIpv1sBhYTS8mqLPlf1OuZYAkvGmBxo/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1BgY8w7K2gaxg2zlVcYaIc32VbdclBuCz/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1ajHzFdqttTek0APJhj9Z5bWr9QS6q6N_/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1d25BY9fxNhLUb6GmoDtrQ8WDPYtRf3Lh/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1ZFnMWlz_RtvrbYQbXxnQV4N7HNmT-MKn/view?usp=sharing)
[Open document](https://drive.google.com/drive/u/0/folders/1q1hVwUQ0fEYzFZFXMatHn3UIeIOXM7tU/)
[Open document](https://drive.google.com/file/d/1n02SoROiB1L3V27dFGd4G1vszZneoAr0/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1OZcypu7cVjHjwVFLnI5XY9zYKqjklMcq/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1FlyOOf8Nf6_eNgXFnnII8KZzyzVarCmc/view?usp=sharing)
[Open document](https://drive.google.com/file/d/1FSl84TJ1kd-LWSQgs62609I5Xwz9KSyj/view?usp=sharing)
# Others
Source: https://help-plum.xoxoday.com/faq/security-compliance/others
Find answers to additional security and compliance questions about the Plum platform that aren't covered elsewhere in this FAQ.
Plum is GDPR compliant. At Xoxoday, we ensure that the data is gathered, stored, and handled with respect to individual rights. We have raised awareness among our employees and other stakeholders on how to handle the data appropriately. Our employees understand the importance of GDPR and information security.
Xoxoday has an information security policy that is published and communicated to all suppliers and employees (including contractors and other relevant external parties).
Xoxoday has ensured that the Information security policies have established the direction of the organization and align to best leading practices (e.g., ISO-27001, ISO-22307, CoBIT), regulatory, federal/state, and international laws where applicable.
Yes, at Xoxoday, we have a formal disciplinary or sanction policy established for employees who have violated security policies and controls. Employees are made aware of what action might be taken in the event of a violation and stated as such in the policies and controls. A detailed disciplinary process and policy are also in place.
At Xoxoday, we use JIRA for Project Management, and abiding by the Information security policy is mandatory and has been followed in all the projects.
Every code change is reviewed by the tech lead or architect responsible for the project.
During the review process, the reviewer is responsible for identifying possible security issues.
Yes, Xoxoday has a Mobile device policy. At Xoxoday, the mobile device policy takes into account the risks of working with mobile devices in unprotected environments and the controls to be implemented for preventing data transmitted/stored in the mobile device, and much more.
Yes at Xoxoday, we do have an 'Information Security Policy' in place.
Information Classification is included in the organization's processes, and be consistent and coherent across the organization. Results of classification indicate the value of assets depending on their sensitivity and criticality to the organization, e.g. in terms of confidentiality, integrity, and availability. Results of classification are updated in accordance with changes in their value, sensitivity, and criticality through their life-cycle.
Formal procedures for the secure disposal of media are also established to minimize the risk of confidential information leakage to unauthorized persons. The procedures for the secure disposal of media containing confidential information are proportional to the sensitivity of that information.
Yes, we do have an 'Information Security Policy' in place and formal procedures for the secure disposal of media are established to minimize the risk of confidential information leakage to unauthorized persons. The procedures for the secure disposal of media containing confidential information are proportional to the sensitivity of that information.
Our application has role-based access controls and the menu's screens are made accessible accordingly.
AES 256 bit encryption for PI data. SHA256 with unique salt for Hashing passwords.
Yes, Xoxoday does have tested Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP), the data would be stored at AWS Singapore.
During security audit/VAPT review, these incidents are identified.
Yes, this process is widely communicated to all the employees and stakeholders.
Yes, on Xoxoday, we do conduct Quarterly VAPT.
Yes, at Xoxoday, we perform quarterly VAPT and have static code analysis via SonarQube
Policies, procedures, and standards have been established and maintained to protect information and physical media in transit, and are referenced in such transfer agreements.
Also, there is a clause on securing business information and protection of confidential information in the NDA's signed by the external parties.
As part of the ISO audit, IS Systems audit is also covered and yes the audit process ensures business disruption is minimized.
We have a quarterly VAPT performed on the entire application by a third-party security auditor.
At Xoxoday, we ensure that the data is gathered, stored, and handled with respect to individual rights. We have raised awareness among our employees and other stakeholders on how to handle the data appropriately. Our employees understand the importance of GDPR and information security. Our controls are placed based on the data protection impact assessment (DIPA). All personal data is encrypted on Xoxoday.
We take data and security very seriously. We are ISO 27001, GDPR, and SOC compliant. More details about our [security](https://www.xoxoday.com/security) and [privacy policy](https://www.xoxoday.com/privacy-policy) in the links aforementioned. You can also know more about our compliance [**here**](/faqs/security-compliance/privacy-and-security).
We may use the information we collect from you when you register, make a purchase, sign up for our newsletter, respond to a survey or marketing communication, surf the website, or use certain other site features in the following ways:
* To personalize your experience and to allow us to deliver the type of content and product offerings in which you are most interested.
* To improve our website in order to better serve you.
* To allow us to better service you in responding to your customer service requests.
* To ask for ratings and reviews of services or products.
* To follow up with them after correspondence (live chat, email, or phone inquiries).
We take data and security very seriously. We are ISO 27001, GDPR and SOC compliant. More details about our [security](https://www.xoxoday.com/security) and [privacy policy](https://www.xoxoday.com/privacy-policy) are [here](/faqs/security-compliance/privacy-and-security).
We ensure that ensure production data shall not be replicated or used in non-production environments. Physical segregation is done for production and non-production environments.
Yes. We are compliant with CPRA (California Privacy Rights Act), GDPR (General Data Protection Regulation) and HIPAA (Health Insurance Portability and Accountability Act)
Implemented the data security Policy and Data Subject Access Rights Procedure.
In accordance with Data Protection Laws, we make available to Controller on request in a timely manner such information as is necessary to demonstrate compliance by Processor with its obligations under Data Protection Laws. Upon Controller's written request and subject to the confidentiality obligations set forth in the Agreement, we will make available to Controller a copy of Nreach the most recent third-party audits or certifications, as applicable.
Privacy Policy - [https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/privacy-policy) Attached the - Data Protection Policy, Data Security policy, Data Subject Access Rights Procedure, Data Breach Notification Procedure.
Attached the data security Policy and Data Subject Access Rights Procedure. Please visit here for Privacy policy - [https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/privacy-policy)
Yes. Please visit - [https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/privacy-policy)
Yes, the policy, process, and procedure is implemented to ensure proper segregation of duties. our roles and job duties are segregated through role-based access to ensure maximum security of tenants' databases
Attached the Xoxoday Privacy Policy. Please click here for the external privacy statement - [https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/privacy-policy).
Yes. We do maintain the records as per the Data privacy compliance requirements.
Yes. we maintain the list as per the Privacy laws and review it. We provide access only to authorised individual as per Role based access and access control policy.
Yes. we follow the privacy gidelines when collecting, storing, or processing Personal Data via electronic, audio, visual or print media. We are complied with this requirements.
We have review and monitor machanism to make sure that only the authorised individual have an access and the objectives of the privacy commitments are met.
Yes. we provide them a Information security and Privacy training. The frequency of the training is once in a year or as soon as they onboarded.
Yes. We have applicable data privacy clauses in the contracts.
We continuosly monitor the efficiency and effectiveness of implemented security controls frequently during the internal and external audits.
# Policies & Procedures
Source: https://help-plum.xoxoday.com/faq/security-compliance/policies-procedures
Find answers to frequently asked questions about the internal security policies and procedures that govern Plum's operations.
We have the disciplinary process in place for Non-compliance with Information security Policy and we have communicated and made aware of the consequences for non-compliance.
We have the employee termination process in place.
We have implemented the information security policy and Hardening Guidelines.
We have implemented the Data Retention and Disposal Policy and attached the same for your referrence. • Storage Period would be as per regulatory conditions. • Personal data can be deleted based on a formal written request, with justification. • Xoxoday would delete the data within 30 days of receiving the request.
All our Privacy and security policies are reviewed every year and approved by the management.
At Xoxoday we have developed a Risk Management Framework as part of the Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2013 standard and SOC II attestation. The information security team assesses security risks annually and on an ongoing basis when major changes occur or when industry changes occur.
Yes. We have implemented the Data Encryption policy
Yes. We have the policies and procesures in place as per the compliane requirements.
Yes. classification inclusive of all media types.
Yes. we have implemented the Media handling procedures.
We follow Xoxoday media handling procedure.
Yes. It's a part of Media handling procedure and Information security policy implemented.
Yes. we have implemented the Data Retention and Disposal Policy.
Yes. We have a written Information security policy.
These policies are reviewed anually or whenever changes made to it and approved by the management as per the compliance requirements.
Yes. We have implemented the Password Management Policy
All the information security policy and standards been approved by senior management.
Yes. Xoxoday is ISO 27001:2013, SOC 2, CCPA/CPRA, HIPAA, CSA START, GDPR certified organization.
We have implemented the access control policy and access will be provided only upon need and approval basis. Attached the access control policy.
We focus on the security while producting the softwares.
It's a part of our system devolopment life cycle.
We have implemented the BYOD policy and all our employees follow the Xoxoday Information security and IT Policies.
Yes. we have implemented the access control policy.
We have implemented the Risk Management Procedure
Yes. Its approved by the management and communicated to all the employees.
Yes. Aattached the Information security policy, Roles and responsibilities policies.
Yes. All the policies have been reviewed at regular intervals.
Yes. We have implemented the role based access control mechanism and only authorised individual will get access.
Yes, we have the policies and procedures in place and we will notify the customer if there is any changes took place in terms of security and privacy.
Yes. We have a Change Management process and approved by the management.
Yes. We have implemented the change management procedure.
Yes. We implemented the the change management procedure.
Yes. We have implemented the Data clasification policy.
Yes. We have the data retension and disposal policy. We will have the data till you use our platform and will be deleted upon termnination of the contracts and will confirm.
1 year
Yes. We have implemented data security policy and have controls in place to monitor the processing of personal information. Since we have deployed our application of AWS cloud only authorised individual have an access.
Yes. We have the incident management response team and roles and responsibilities has been clearly defined. As per our policies and procedure we condut Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions.
Yes. We have communicated on this to a concerned parties.
Yes, we segregated the duties.
Yes, our policies and procedures are established and implemented to enforce two-factor authentication for privileged account management/authentication while accessing tenant data/systems.
We have segregated the teams according to their roles and responsibilites.
We have the SDLC Procedure and attached the same for your reference. We have defined rules and guidelines for secure development of software and systems.
Yes. We have implemented the media protection procedure.
Yes. We have BCP policy and procedures in place and test it every year.
At Xoxoday we have implemented the password management policy. Attached the same for your referrence. We have deployed password security controls accross the organization for maximum security.
Attached the Change Management Procedure. All the chnages to production environment is recorded and followed the change management procedure.
We have implemented the Asset classification policy. Attached the policy for your referrence.
We have the policies in place and audited during the internal and external audits. We have the policies with regards to Access control, Ceyptography, Anti virus protection, Back up and recovery etc..
Yes. We have implemented the Acceptable Usage Policy
Yes. We have implemented Clear Screen and Clear Desk Policy
All the information security policies has been reviewed annually or upon any changes to the policies. All the management review and approvals has been recorded.
Attached the Business continuity documents.
Data backups are done daily and in a secured way in AWS. Attached the Backup Recovery Procedure.
Attache the Information Security Policy and Data Security policy.
Attached the policies with regards to - IT, Virtual Private Network, Threat and vulnerabilities, Virus management, patch management, access control, logging and monitoring etc.
Attached the below mentioned policies - 1. Cloud Computing Security Policy 2. Encryption Policy 3. Password Management Policy 4. Threat and Vulnerability Management 5. Infrastructure Change Control Procedure 6. Virtual Private Network Policy 7. Information Classification Policy 8. Cyber Crisis Management Plan 9. Network Access Control and Security Procedure 10. Information System Acquisition Development and Maintenance Procedure
The policy, process, and procedure is implemented to ensure proper segregation of duties.
Attached the Roles Responsibilities\_Authorities Policy.
Yes, all the mechanisms related to security and policies are implemented to facilitate timely decision and investigation by root-cause analysis. These incidences are analyzed with network intrusion detection (IDS) tools.
We have implemented the change management procedure. Attached the Change Management Procedure
Attached the Security Incident Reporting \_ Response Procedure
Yes. We have a written Information security policy. Attached the same for your reference.
These policies are reviewed anually or whenever changes made to it and approved by the management as per the compliance requirements.
We have implemented the change management Procedure. All the IT changes takes place as per the Change management procedure. Attached the same for your reference.
Attached the IT policy. We also have communicated these to all the employees to spread awareness among them.
We have implemented the access control policy and access will be provided only upon need and approval basis. Attached the access control policy.
Attached the Business continuity policy.
Attached the Business continuity plan
It's a part of our system devolopment life cycle. Attached the policy.
Attached the Change management process.
Attached the Supplier Management Procedure
We have implemented the BYOD policy. Attached the same for your reference.
Attached the Change management process.
Please find attached Data Protection Policy and Data Retention and Disposal Policy
Data privay and Data protection is a part of our Infoarmation security awareness training.
Yes. Attached the Information Classification Policy
We have Business Continuity Policy and Business Continuity Management Procedure in place and tested periodically. And also, our Policies has been reviewed and Audited annually. Attached the Business continuity policy, plan and procedures. We have test the BCP every 12 months and this has been reviewed as a part of Internal and external Audits.
Attached the Information security Policy
Attached the business continuity documents.
Attached the Information Security Policy and Risk Management Procedure
Yes, We have implemented the change management procedure and atatched the same for your referrence. The changes to the production environment are documented, tested, and approved prior to implementation. Production software and hardware changes may include applications, systems, databases, and network devices requiring patches, service packs, and other updates and modifications.
1. We have implimented the systems development life cycle (SDLC) and atatched the same for your referrence. 2. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase. 3. We also conduct vulnerability and penetration testing and fix the identified observations. 4. Upon passing all the security and quality checks the new version of the product will be released.
Xoxoday has a formal Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) defined and implemented to enable people and process support during any crisis or business interruptions. The BCP and DR Plan is tested and reviewed on a yearly basis as per the compliance requirements.
We provide applicable compliance Policies/Procedures, Audit/attestation reports, certifications etc.. on need basis.
Attached the Change Management Procedure
Attached the Security Incident Reporting & Response Procedure.
We have Business Continuity Policy and Business Continuity Management Procedure in place and tested periodically. And also, our Policies have been reviewed and Audited annually. Attached the Business continuity policy, plan and procedures. We have tested the BCP every 12 months and this has been reviewed as a part of Internal and external Audits.
As per the compliance requirement and Business continuity policy we test the BCP plan every 12 months or upon significant organizational or environmental changes.
We conduct the BCP/DR Test on an annual basis as per the compliance requirements and audited during the internal and external audits. Our RTO & RPO is 60 minutes, Attached to the BCP/DR Policy.
Data backups are done daily and in a secured way in AWS. We also do test to comply with the business continuity plan.
Yes. We have Business continuity plan.
We communicate as per the BCP or the agreements or contracts
Yes. We have Media handling procedure.
Sure. We will provide the same.
Yes
We adhere to all the policies and procedures of the organization.
Yes. We have disciplinary policy
Yes. See Acceptable Use Policy attached.
We adhere to all the policies and procedures of the organization.
Yes. We have disciplinary policy
We are ISO 27001:2013 and GDPR Compliant organization. We have policies and procedures in place to comply with all the requirements and working effectively. We have Information security policy, Mobile Device Management Policy, Encryption Policy, Password Management Policy, Risk Management Procedure, Email Security Policy, Access control policy etc as per the compliance requirements. We also have implemented end point security in all our computers and servers to make sure that the data stored are safe, secure, and Protecting against non-human sources of risks.
Yes. We have a well-defined policy for roles and responsibilities. We have communicated each employee about their responsibilities across the organization. We do maintain appropriate contracts with relevant authorities and ensure that applicable regulations are complied with
Yes.
We have an access control policy. The policy is attached for reference. Only authorised employees will have access to the data.
Authorised Xoxoday employees only will have access controlled per the relevant policies attached
Yes
Yes
We store password hashed. We have SHA512 hash with unique salt for every password
We have implemented the Password Management Policy. Only verified or authorised users can reset the password. No one can reset the password on behalf of somebody. We also follow the best practices for Password Protection and incorporated the same in the Password Management Policy.
All the changes takes place as per the change management procedure.
We have implemented the SDLC policy and made applicable to all the development and maintenance services, architecture, software and systems that are part of the Information Security Management System.
Implemeted the asset management policy
We are compliant. Attached the SDLC procedure. We folow General Coding Practice, test the information security features, Vulnerability scanning, Penetration Testing etc and mitigate all the risks identified.
We have implemented the Media protection procedures in order to make surer that the data is protected if we store it in any external drives.
We have implemented the Media protection procedures in order to make surer that the data is protected.
We have asset management policy and Media protection procedure to track the customer maintain the records.
It's a part of of Asset management policy.
We have implemented the change management procedure
We have implemented the change management procedure
Capacity management has been well defined in our IT Policy
It's a part of our change management and IT Policy.
We have Implemented the Physical security Policy and allowed access to only an authorised individual.
We have protected all the area as per the physical security Policy and allowed access to only an authorised individual.
We have implemented the Security Incident Reporting & Response Procedure
Attached the application Change management procedure
Our RPO/RTO is 6 mins. Attached the Business continuity documents
The BCP Test and lessons learned has been documented.
We have implemented the Incident Management Procedure and attached the same for your reference
Its part of our Incident Management Procedure
We report the incidents
Attached our Incident management procedure.
Yes. We have Policies and procedures in place. Our application also support for adding and removing users.
We have implemented policies and procedure with regards to DR. Since we have deployed our application on AWS cloud they only provide DR Services.
Yes. We have Policies and procedures in place. Our application also support for adding and removing users.
Yes. We have an Information Classification Policy and attached the same for your referrence. Information classification policy is primarily concerned with the management of information to ensure that sensitive information is handled well with respect to the threat it poses to an organization. It also demonstrates how gathered data is being used and structured within an organization to allow authorized personnel to get the right pieces of information at the right time, while also ensuring that only those who are authorized can view or access information. Sensitive data has been categorised as Confidential, Restricted, Internal, Public etc..
Yes. We have implemented the Acceptable Usage Policy and attached the same for your referrence. The policy outline the usage of Email, Computer Resources, Internet, Clean Desk and Clean Screen, Punitive actions, General guidelines etc.. We have a formal processess in place for security policies review and approval by the top level management as per the compliance requirements.
Yes. Xoxoday has developed a Risk Management Framework as part of the Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2013 standard and SOC II compliance. The information security team assesses security risks annually and on an ongoing basis when major changes occur or when industry changes occur. Xoxoday Risk management process includes Risk Treatment, Mitigating Actions, Action Owners, Action Due Dates, Risk Acceptance, Risk Mitigation, Risk Avoiding, Risk Transfer, exceptins etc.. We also conduct the Risk assessment on annual basis and this has been audited as a part of an internal and external Audits.
Yes. Attached the Physical and Environmental Security Procedure.
Yes. All the repair/modification or installation will be as per the change management procedure upon appropriate approvals. Whenever there is a requirement for additions or changes impacting security of the site, approval shall be taken from the site, Physical Security team prior to implementation. Attached the Physical and Environmental Security Procedure
Yes. Data backups are done daily and in a secured way in AWS. All the data backup will be stored on AWS virtual platform cloud. We also have implemented the Business Continuity Policy and Business Continuity Management Procedure in place and effectivly working. Out DR/BCP plans are reviewed and approved by the management and tested on annual basis as per the compliance requirements. DR/BCP controls are validated during the internal and external audits.
We have Data Retention and Disposal Policy. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
Data backups are done on daily and in a secured way in AWS. Attached the Backup Recovery Procedure.
Yes
Access to data and systems are based on the principles of least privilege for access. Accordingly, all information systems and data are classified and further segregated to support role-based access requirements. A strong identification and authentication system and logging systems are deployed and provides a centralized control to administer, monitor and review all critical access. We have role-based access system through access control policy to make sure that only the authorised individual has access to the required information. An Identity and Access Management (IAM) solution has been defined to manage user access through role-based access profiles that support the implementation of accesses based on the principles
Attached the Information security Policy
Yes. we have implemented the Business Continuity Plan to ensure that the data is managed during the conduct of business in a safe and secure manner in delivering the business values to the interested parties. Attached the BCP/DR policies and procedures.
Yes. we have Acceptable usage policy to outline the acceptable use of Information Security at Xoxoday.This policy applies to all employees – part time or full time, temporary or permanent, service providers with in-house engineers or consultants, contractors, and other workers at Xoxoday, including all personnel affiliated with third parties. This policy applies to all Information Security that is owned or leased by Xoxoday. Attached the Acceptable Usage Policy
Attached the Security Incident Reporting & Response Procedure and ncident Management Procedure
We adhered to the change management procedure and all the changes to the production systems will be upon review and approval of Chief Technology Officer (CTO) Attached change management procedures.
We have implemented the change management policy and all the changes to the platform takes palce as per the compliance process.
At Xoxoday we have a documented Business Continuity and Disaster Recovery Plan defined and implemented to enable people and process support during any crisis or business interruptions. Appropriate roles and responsibilities have been defined and documented as part of the BC plan. At Xoxoday the BCP and DR Plan is tested and reviewed on a yearly basis. The BCP and DR plan of Xoxoday is reviewed and audited as part of internal and external audits.
We have implemente the Software Development Life Cycle (SDLC) procedures and attached the same for your reference. We have controls on external file sharing.
Sure. We will provide our Incident Management Procedure
Attached the Cyber Crisis Management Plan
We adhered to the change management procedure and all the changes to the production systems will be upon review and approval of Chief Technology Officer (CTO)
Attached the data classificaiton policy.
Yes. A formal Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) defined and implemented to enable people and process support during any crisis or business interruptions.
Yes. At Xoxoday we have implemented the Physical and Environmental Security Procedure. Physical entries have been restricted based on the role of the personnel within the organization. The restriction will be enforced using electronic locks with access through access cards and biometric machines. Third-party Access - The entrance premise of Xoxoday has been manned by security guards on a 24-hour basis. The guards shall verify all the visitors and direct them to the reception and provide temporary access cards. At the reception, the concerned employee shall be intimated, and he/she will escort the visitor on premises always. CCTVs has been placed at strategic points inside the facility Reception lobby, Entry and exit doors of the Xoxoday office, Entry and exit to parking areas, delivery, and dispatch areas etc. and monitored 24x7x365.
Our information security team and Customer support team will inform the POC of Client via email communication with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions
Attached the Incident Management Procedure
We have implemented the Business Continuity Policy and Business Continuity Management Procedure and BCP controls has been tested annually as per the compliance requirements and reviewed during the internal and external audits.
We have implemented the Identity access management and follow the Access control policy.
# Privacy Compliance
Source: https://help-plum.xoxoday.com/faq/security-compliance/privacy-compliance
Find answers to frequently asked questions about Plum's privacy compliance practices and how customer data is protected.
## GDPR
We have implemented all the technical and organisational measures (TOM)
Yes. we have implemented the Data Subject Access Rights Procedure
Yes. The Data Processing Agreements is in place.
Yes. The Data Processing Agreements is in place.
Yes. we conduct the Data Privacy Impact Assessments on annual basis and there are no high risk involved in handling the PII
formal data breach notification process is in place.
Customer data security is an essential part of our product, processes, and team culture. Our facilities, processes and systems are reliable, robust, and tested by reputed quality control and data security organizations. We continuously look for opportunities to make improvements in the dynamic technology landscape and give you a highly secure, scalable system to provide a great experience. We have implemented many technical controls to safeguard the customer data. For example - Cloudflare Web application firewall (WAF), AWS Guard Duty threat detection services, Amazon CloudWatch, IDS/IPS etc.
We are GDPR compliant. Implemented the Data security and Personally Identifiable Information Policy
We have implemented the Data Subject Access Rights Procedure.
In accordance with Data Protection Laws, we make available to Controller on request in a timely manner such information as is necessary to demonstrate compliance by Processor with its obligations under Data Protection Laws. Upon Controller's written request and subject to the confidentiality obligations set forth in the Agreement, we will make available to Controller a copy of Nreach the most recent third-party audits or certifications, as applicable. We do not agree for the Surprise audits.
Yes. It's a part of the agreement.
We have implemented the GDPR Xoxoday is the data processor.
Xoxoday is GDPR Compliant. We have implemented the Data Subject Access Rights Procedure as per the GDPR and make all the data subject rights available as per the data protection laws. This procedure sets out the key features regarding handling or responding to requests for access to personal data made by data subjects, their representatives or other interested parties.
We validate the compliance requirements of the Sub-processor and obtain the Compliance certificates and audit reports such as – ISO 27001:2013, SOC 2 Type II, ISO 27017, ISO 27701, ISO 27018, Cloud Security Alliance Controls etc..
We have implemented the Data Subject Access Rights Procedure to make sure that all the data subjects will have the opportunities to exercise their rights as per the privacy laws. Attached the Xoxoday Data Subject Access Rights Procedure.
We provide Software as a Service.(SAAS). We are ISO 27001 certified and GDPR compliant. Attached the document.
We are GDPR compliant. And atatched the Data security and Personally Identifiable Information Policy
Attached the Data Subject Access Rights Procedure. Please visit here for Privacy policy - [https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/privacy-policy)
We are GDPR Complaint and respect the data subjet access rights. We erase or delete the data upon request of the data subject or on the request of the customer upon termination of the contract. We have Data Retention and Disposal Policy. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. Attached the Data Retention and Disposal Policy.
We have Data Retention and Disposal Policy. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
Xoxoday is Compliant with EU GDPR.
We are compliant with GDPR. We inform the customer within 48 hours, if there are any data breach as per the compliance requirements.
At Xoxoday we have appointed the DPO. Please click here to know more about Xoxoday GDPR - [https://www.xoxoday.com/gdpr](https://www.xoxoday.com/gdpr)
Over 2 millions of customers across the globe trust us with their data security. We back ourselves up with robust data security and privacy practices that form an integral part of our product engineering and service delivery principles. Our comprehensive GDPR program is supported by key privacy principles -- Accountability, Privacy by Design and Default, Data Minimization, Subject Access Rights, among others. Technology and operations related to the business are subject to regular sensitization programs. Please click here to know more about Xoxoday GDPR - [https://www.xoxoday.com/gdpr](https://www.xoxoday.com/gdpr)
We have implemented the Data Subject Access Rights procedure (DSAR) 1. Personal data can be deleted based on a formal written request, with justification. 2. Xoxoday would delete the data within 30 days of receiving the request Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. Attahed the Data Subject Access Rights procedure (DSAR)
Xoxoday is GDPR Compliant and shared the Data Protection Impact Assessment (DPIA) We are not required to submit the report to the Data Protection authority.
Xoxoday is compliant with GDPR
We offer EU Standard Contractual Clauses.
We support end users to Exercise their Rights as per the GDPR compliance requirements.
We are compliant with GDPR. We inform the customer within 48 hours, if there are any data breaches as per the compliance requirements.
In accordance with Data Protection Laws, we make necessary documents, Audit reports and certifications available to Controllers on request in a timely manner such information as is necessary to demonstrate compliance by Processor with its obligations under Data Protection Laws. Upon Controller's written request and subject to the confidentiality obligations set forth in the Agreement, Xoxoday will make available to Controller a copy of Nreach then most recent third-party audits or certifications, as applicable.
We adhere to Data Retention and Disposal Policy and make sure that the personal information of the data subject will be deleted upon requests or termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
We offer standard contractual clauses (SCC) or binding corporate rules to regulate transfers of data to non-adequate third countries.
We adhere to Data Retention and Disposal Policy and make sure that the personal information of the data subject will be deleted upon requests or termination of the contract. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
Attached the GDPR Data Protection Policy and Data Security Policy
[GDPR compliance - https://www.xoxoday.com/gdpr Privacy policy - https://www.xoxoday.com/privacy-policy](https://www.xoxoday.com/gdpr)
[Link - https://www.xoxoday.com/gdpr Note - if you are using Xoxoday products and have agreed to our terms of service, you do not need to sign an additional Data Processing Addendum.](https://www.xoxoday.com/gdpr)
AWS - We have deployed our application on AWS Virtual platform cloud. And AWS is GDPR, ISO 27001, SOC 2 certified organization.
We collect names, email IDs and Phone numbers. These are the mandatory information required to use the application platform.
Yes. We are GDPR Compliant
The application is deployed on AWS virtual platform cloud. We are a data processor as per GDPR and all the information is collected only throgh our application. We use TLS1.2 encryption for Data in transit and AES256 for Data at rest. Additionally, we have an intrusion detection/monitoring application that alerts on unauthorized access.
Notify data controllers within 48 hours of the breach or within stipulated time as agreed with the data controller
Yes
Yes
Yes
Yes. We have appointed DPO
No. The EU-U.S. Privacy Shield Framework is no longer a valid mechanism to comply with EU data protection requirements when transferring personal data from the European Union to the United States. Please visit here for more details - [https://www.privacyshield.gov/Program-Overview](https://www.privacyshield.gov/Program-Overview)
See Security Incident Reporting & Response Procedure attached We are GDPR Compliant. Our information security team and Customer support team will inform the POC of the customer via email communication with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions.
Yes. We have formally defined criteria for notifying a client during an incident that might impact the security of their data or systems. We notify within 72 hours as per EU-GDPR
Data Protection Training and Awareness – Indicate what awareness-raising controls are carried out with regards to colleagues We conduct Information security and Data protection awareness training as soon as new employees joined the organization and annually once for the old employees. The training material includes the below concepts – Information Security Objective How to handle and protect PII What is ISO 27001:2013 Confidentiality, Integrity, Availability and Privacy. Business and cyber security PDCA – Continual improvement General guidelines for security Visitor management Security guidelines Guidelines while using Xoxoday provided devices Password guidelines Email related guidelines Social media related guidelines Phishing attack and its types Information storage related guidelines Incident Management Business continuity management
We have implemented Security Incident Reporting & Response Procedure and tested annually. We also have Data Breach Notification Procedure as per the GDPR compliance requirements. We will share the supporting documents with regards to data breach notification and Incident management procedures.
Yes. We provide these rights to the data subject as per GDPR
We inform our customer in 48 hours if in case any security breaches as per the GDPR regulation.
We have implemented policies and procedures as per ISMS and GDPR requirements. We also conduct periodical Internal and external Audit by the third party Auditor. We have deployed our application on Cloud Virtual platform for maximum security. We use Bitdefender End point security software to prevent from malware and protect the data. In addition to that we also have AWS Guard Duty threat detection service that continuously monitors for malicious activity and unauthorized behaviour. We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications. We use logical data isolation with the help of company specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256 As per the Information security policy and Data protection policy only the authorised individual have an access to the data through internal approving and ticketing system.
Yes. Attached the data retension and disposal policy.
Yes. we are GDPR compliant. We have procedure in place to provide services to data subject.
We do not share the PII with any third parties.
We are GDPR Complaint and respect the data subjet access rights. We erase or delete the data upon request of the data subject or on the request of the customer upon termination of the contract. We have Data Retention and Disposal Policy. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places. Attached the Data Retention and Disposal Policy.
We restrict the processing of data as per the contract signed.
We are GDPR compliant. we have implemented the Data Breach Notification Procedure. Our information security team and Customer support team will inform the customer via email communication with Preliminary Incident Synopsis and Root Cause Analysis report (RCA) including the details of Business Impact, Issue Description, Root Cause, and Corrective Actions.
We have provided the features to withdraw consent or exercise the right for the end users. Attached the Data subject access rights procedures
Yes. We collect the data through our application application. As per the GDPR we are the data processor.
No. Since it's a SAAS product we are having EU customers who are using our application application.
Employees.
No. We collect the data through this application and store it. We do not use or transfer or share the PII
Yes. Its posted on our website and they can exercise their rights as per the law.
Yes. We do take consent from the data subjects.
We Dispose the data Upon the expiry of the data retention as per the agreements, or when the data subject exercises their right to have their personal data erased, the personal data shall be deleted.
We do not use personal information for Marketing or Advertisement.
NA. We do not use personal information for Marketing or Advertisement.
No. But we have deployed our application on AWS cloud virtual platform for maximum security.
we are the data processor.
We are GDPR compliant.
Yes. We are GDPR Compliant and we have a data retention and disposal policy. We assure secure data disposal when storage is decommissioned or when the contract comes to an end. We also provide rights to the users to request for data deletion. GDPR Policy - [https://www.xoxoday.com/gdpr](https://www.xoxoday.com/gdpr)
We will be deleting the customer data upon termination of the contracts.
Our data cleansing process goes through an organized purge. Once the data is purged, it's purged from all places or completely wiped out.
We are GDPR Compliant. And we would be notifying Nova Professional Services of an incident or data breach within 72 hours. We will make sure that we will be fully informed of incident response and investigation.
We are ISo 27001;2013 certified and GDPR compliant. We also conduct internal review, Audit and external Audit from the third party auditors to make sure that we are complying with the requirements.
we Notify data controllers within 48 hours of the breach or within stipulated time as agreed with the data controller throgh email.
Yes. We provide service to the data subject as per the GDP Compliance requirements. They can rectify, erase or restrict processing of their personal data.
Xooxday is GDPR Compliant. We collect the data which are only required. We collect the PII - Name, Email ID and Phone/
## CCPA/CPRA
We are compliant with EU GDPR and CPRA (California Privacy Rights Act)
We are EU GDPR Compliant and CPRA Certified.
Yes. We comply with all the applicable new laws and regulations. We also have a service provider who helps us with regards to Information security, compliance and certifications etc.. We have identified the upcoming CPRA and implemented the controls and achieved the CPRA Attestation with the help of the external auditor..
# Security Operations
Source: https://help-plum.xoxoday.com/faq/security-compliance/security-operations
Find answers to frequently asked questions about Plum's security operations, monitoring, and incident response practices.
Our security systems are airtight and so far we haven't suffered any security breaches.
Yes, we have a repository of security incident information if needed for all the affected customers. This information can be accessed electronically.
We have an ELK setup in place to ensure data monitoring in the most optimal manner.
No, content monitoring and filtration is not done to detect inappropriate data flows.
Yes, only the authorized personnel are allowed in points of ingress and egress in order to isolate access of data storage and process.
Data backups are done daily and in a secured way in AWS
No, the backup and retention of data lies in the hands of Xoxoday. Data is stored in the event that a future need arises for looking into the database.
Yes, the data is stored in our secure database and is transit scrambled for maximum security.
Our tenants' data is excruciatingly confidential and is never used for testing or staging purposes.
Yes, we promptly notify the KO-CIRT for immediate counter-actions and defense mechanisms in case of confirmed security incidents.
Yes, please go through our "Information Security Management System Manual" for a complete understanding.
Our ISMP is annually reviewed and updated if required.
Please go through the links below to access our policies:
Information Security Policy Privacy Policy
Privacy Policy
Yes, it's crucial for our providers to adhere with the Information Security & Privacy Policy of the organization.
Yes, we follow all the technical guidelines for development of our code and applications that come under the Open Web Application Security Project.
Yes, we remediate and address all requirements with respect to security, contracts, and regulative purposes for customer access to data and information systems.
No, we don't provide multi-factor authentication. As of now, there's oAuth2.0 and SAML-based tokens. JSON-based token is available for maximum security direct-email logins.
Yes, Xoxoday's architecture goes through constant upliftment and experiences no downtime during upgrades and maintenance windows.
Yes, our event management systems merge the data sources to maintain a log data within the SIEM. This helps in proper analysis and driving out alerts if need be in case of contingency.
Yes, our documented security incident response plan logs, monitors, and collects relevant security event data for the purpose of investigation.
Yes, information security incidents, if any, shall be quantified in type, volume, and impact of such incidents.
Yes, systems must be configured to log all successful and unsuccessful login attempts by accounts with privileged access. These authentication logs must be retained for a minimum of 180 days and in accordance with the Company's records retention guidelines.
Yes, with host and network intrusion detection tools, we ensure timely detection and investigation in a prompt manner.
No, all of Xoxoday's servers are with Amazon Web Services, Singapore and that is where the outbound traffic is routed through.
Cyber threats, if any, are managed internally by the tech team.
Yes we have a regular audit on threats for applicability and exposure to our environment.
Yes we update your cyber security program based on proactive or reactive threat intelligence feeds
Xoxoday's holistic presence keeps our tech team updated with the latest news from multiple sources when it comes to any technological developments or threats.
Yes, physical segregation is done for production and non-production environments.
# Security Operations & Technical Capabilities and Support
Source: https://help-plum.xoxoday.com/faq/security-compliance/security-operations-technical-capabilities-and-support
Find answers to frequently asked questions about the technical capabilities and support behind Plum's security operations.
Yes, we have proper forensic procedures in place that includes chain-of-custody management processes and controls.
As part of Web Application Firewall (WAF), rate limiters are installed to block multiple requests from specific IPs in order to prevent DDOS-type attacks. These are powered by intelligent daemons that detect other identifiers like URLs accessed or other client properties to automatically blacklist possible threats either temporarily or permanently.
Yes, in our cloud audit program, we analyze and address all the requirements put forth by the tenant to ensure maximum satisfaction.
Yes, we have proper forensic procedures for data collection and analysis for incident responses.
Yes, we can freeze data from a specific time without freezing other data if need be.
Yes. Tenant data is enforced and attested in case it comes to light in legal subpoenas.
The Xoxoday Platform is developed on microservices architecture because the independent applications and deployed on the AWS virtual platform cloud.
No, our product is supported by a comprehensive web application that can be accessed via desktop and mobile browsers on all compatible devices.
Our platform can be white-listed to match the look and feel of the tenant's platform. The emails are also customizable for a personal touch.
Reports with respect to rewarding and beyond can be accessed through the platform.
The customization is done on the platform level, manually by the super admin.
Yes, Xoxoday Plum comes with a full set of integration with various platforms for enriched utility and maximum output from the platform.
Yes, Xoxoday Plum comes with a full set of integration with various platforms for enriched utility and maximum output from the platform.
No, we keep it with one data center for maximum safety, privacy, and security of database of our tenants.
Reports and analysis can be extracted from the platform. These reports give detailed insights with respect to what's being the reward and recognition input and output throughout the concerned period.
In case reports are needed apart from the predefined ones, they can be shared with the tenants in a spreadsheet.
Xoxoday's customer support team is available at all times to address any queries and support with respect to advisory and technical operations.
Each tenant data is uniquely encrypted using client specific key. We use AES 256 bit encryption for data at rest to ensure maximum security measures.
Yes, hardware security modules are used to protect these keys, and the key access lies with the Chief Technical Office.
We use the Key Management Service by AWS to manage all the keys. In the event that keys get compromised, they can be recovered through the Key Management Service.
Yes, in the event of service interruption, the prior notification will count for downtime.
The time of support ranges between six to forty-eight hours. This depends on the level of service and the gravity of incidents.
No, there is no penalty clause attached in the event of a performance failure.
We are a SAAS company hence we do not have in built APIs, we maintain quarterly/yearly audit logs. No we do not integrate with the above third party tools
We maintain the logging of applications and alerts by ourselves. We cannot be integrated with the bank system, According to our company policy we do not share the logs with any third party.
Yes the application have robust authentication methods. We are integrated SAML 2.0 with SAP SuccessFactors, we also support OAuth 2.0 for seamless authentication.
Yes we do report pen test and SOC findings
Our applications are compatible with desktops, tablets and Mobiles, No additional components are required.
Since we are SAAS product, we maintain backup and restore all the customer data by ourselves. We use AES 256 encryption for data at rest. We have a multi AZ deployment with periodic backup for our DR. DR is active-active.
We use logical data isolation with the help of company-specific encryption keys. Data in non production environment is not updated with the production data. We generate separate test data Data at transit - TLS1.2 encryption, Data at rest - AES256
We are a SAAS solution, and hosting is handled by us. No instances needed from the client. We use Public cloud for hosting (AWS Singapore)
6 Hours RTO and 6 Hours RPO, Yes upon request we can share latest DR strategy test results.
No there aren't any FLASH component installed in our web app.
This solution doesn't require any such API integration. The solution is seamlessly integrated with the SAP SuccessFactors solution already.
We only have 2 roles. Super admin and user. Super admin have complete control of the platform and can configure everything. SCB Admin staff will become the super admins.
Xoxoday will not be sharing logs with SCB as we have multi-tenant information in the logs. If there is a significant downtime or disruption of service, we will provide an alert notification to SCB
Web Content Accessibility Guidelines (WCAG) defines how to make Web content more accessible to people with disabilities. Accessibility involves a wide range of disabilities, including visual, auditory, physical, speech, cognitive, language, learning, and neurological disabilities.
Yes. We always give our best to make sure that our applications are developed as per WCAG guidelines and helping differently-abled people across the globe.
Yes. We ensure that people with disabilities can use our websites and applications without any difficulties. Our website and products are having very simple options with very good visibility of the content.
Yes. We always consider the WCAG guidelines for helping differently-abled people.
Yes. We periodically review and do all the necessary changes to our website and applications as per the guidelines.
# Solution Development
Source: https://help-plum.xoxoday.com/faq/security-compliance/solution-development
Find answers to frequently asked questions about the secure solution development lifecycle Plum follows for its products.
Yes, our network environment is designed and configured to restrict any communication and connection between the tenant's environment and our corporate network.
Yes, our logic to physically separate tenant systems is made possible by assigning each tenant's data a client-specific key that is uniquely encrypted for maximum security.
Yes, all the resources that are needed for the configuration, installation, and operation of information systems are made available to the authorized personnel for their perusal.
No, we have a holistic computing environment which uses logical methods of isolation to keep the tenant's data secure.
Yes, we logically segregate the tenant's data and the application.
Yes, physical segregation is done for production and non-production environments.
As per the SDLC process, we have defined General Coding Practice and some salient points are -
* We use parameterized queries.
* All PI data need will be encrypted
* All our communications will be over secure channels only and many more.
No. All the deployments will take place only upon QA Process.
Backups are automated and tested/reviewed on a weekly basis. Recovery process has been tested during the annual BCP test to make sure that implemented controls are working effectively. All the customer data backup has been stored on AWS/MS Azure Virtual platform cloud and all the data at rest has been encrypted.
Information security and Technology Team will be responsible for evaluating the incident and appropriately initiating the escalation process and holds the overall responsibility to monitor the activity and facilitate any action. If the problem requires further investigation, IT will assign the ticket to the appropriate Support Groups and escalate it CTO.
We use a split key mechanism to ensure that every client's key is unique.
* We perform annual key rotations.
* Keys are generated using the KMS service whenever needed.
* We store keys in KMS.
We have implemented the systems development life cycle (SDLC) Procedure. Our code reviews and analysis run through stringent eyes of automated technologies as well as manual source code overview to cover any security loopholes prior to the production phase. We also conduct vulnerability and penetration testing and fix the identified observations. Upon passing all the security and quality checks the new version of the product will be released.
# Tax Compliance
Source: https://help-plum.xoxoday.com/faq/security-compliance/tax-compliance
Find answers to frequently asked questions about Plum's tax compliance practices and the documentation it maintains.
Disclaimer: This is for informative purposes only and should not be construed as professional, financial, or legal advice. The information does not constitute or form part of, and should not be construed as, a direct indication from the designated countries' tax authorities. For updated information, please visit the official tax website of your country's government/tax authority.
## USA
In the United States, every person is allowed a tax-free benefit of up to \$25 per year. This is valid for every employee irrespective of the federal, local, or state laws.
A Federal Income Tax (22%) + Social Security (7.65%) + Local/State Tax (if applicable) is applied on the amount above \$25.
The employer can either record a high value of benefits and withhold the tax, or trim it from the amount being given to the employee.
The Internal Revenue Service USA
## UK
In the United Kingdom, an amount of £50 goes tax-free in the name of small benefits for every person through the year.
If the amount goes over the exemption limit or is issued as a voucher exchangeable for cash, it will be taxed on the employee's end under "Other Earnings".
There are certain exemptions, the list of which can be checked out here ([https://www.gov.uk/hmrc-internal-manuals/national-insurance-manual/nim02416](https://www.gov.uk/hmrc-internal-manuals/national-insurance-manual/nim02416)). Trivial benefits are non-taxable, provided that:
* it costs the employer £50 or less to provide
* it isn't cash or a cash voucher
* it isn't a reward for employees' work or performance
* it isn't in terms of their contract
[https://www.gov.uk/expenses-and-benefits-trivial-benefits](https://www.gov.uk/expenses-and-benefits-trivial-benefits)
## Ireland
The Irish tax authorities exempt a handsome total of €500 per person through the year in the name of small benefits.
If the SBE limits are crossed, the taxation would be according to the rules and regulations of the Irish tax authority.
The amount is only deemed to be tax-free in case it is gifted in terms of vouchers and benefits. Long Service Awards are not taxable at all as much as €50 per every year of service.
The Revenue Commissioners, Ireland>> [https://www.revenue.ie/en/employing-people/benefit-in-kind-for-employers/other-benefits/service-and-performance-schemes-and-awards.aspx](https://www.revenue.ie/en/employing-people/benefit-in-kind-for-employers/other-benefits/service-and-performance-schemes-and-awards.aspx)
## India
Gifts up to Rs. 5,000 in the aggregate per financial year would be tax-exempt in the hands of the employees.
The excess value of gifts over and above Rs. 5000/- would be taxed as a perquisite in the hands of the employees.
The Gift value is added to the CTC (Cost to the Company) of the employee for calculation of Income-tax.
Income Tax
## Poland
In Poland, any purchase of gifts that ZFŚS aka the National Revenue Administration of Poland finances is tax-free.
The amount would be wholesomely taxed. Purchase gifts partly from the ZFŚS and partly from current assets won't make it tax-free—no matter how much the amount is.
This fund houses a separate bank account for every worker and has an employee's and employer's contribution to it. The ZFŚS is allocated to leisure, healthcare, entertainment, sports, recreation along with other expenses. Any purchase of gifts that ZFŚS finance is tax-free.
GOV.PL>>[https://www.gov.pl/web/national-revenue-administration/about-us](https://www.gov.pl/web/national-revenue-administration/about-us)
## France
In France, an exemption of €169 is given for every person through the year, provided that it's spent on activities other than food and fuel.
Provided that the amount goes about the SBE limit, it shall be fully taxed under the French Tax statutes.
When the gifts are given for an event that marks a significant milestone, e.g. wedding, birth, retirement, Mother's Day, or Father's Day, etc. If the gift voucher given for the event (s)mentioned above, one can not redeem it for food or fuel (the voucher's value should still be €169 per event and calendar year). Cultural events that promote the country's colors and traditions are also exempted.
The Ministry of Economy & Finance>> [https://www.impots.gouv.fr/portail/](https://www.impots.gouv.fr/portail/)
## Netherlands
With an amount of €2207 for every employee through the year, the Dutch authorities have a generic gift tax statute for all its citizens.
The Dutch tax authority identifies tax slabs on gifts according to the value of donations. For donations ranging between €0 to €126,723, the tax rate is 30% on the gift value. Meanwhile, for donations with a value that goes above €126.723, the tax rate is 40% on the gift value.
In a general sense, there's no separate clause for the Dutch corporations signifying the gift tax rules for employees, so we are going to focus on what it says altogether.
The Dutch Tax Authority>> [https://www.belastingdienst.nl/wps/wcm/connect/en/individuals/individuals](https://www.belastingdienst.nl/wps/wcm/connect/en/individuals/individuals)
## Norway
NOK1000 - that is the maximum an employee can get per year while being exempted from any kind of taxation under the small benefits exemption.
All gifts to employees over this amount and without special occasions and taxable.
All gifts to employees over this amount and without special occasions and taxable. In the case of long service rewards,gifts up to NOK8,000 in value can be given for long service in the business.The first reward for long service opens up after 20 years of service, and after that in every 10 years. Gifts up to NOK4,000 can be given in case when the recipient gets married, reaches the age of fifty (and ten years thereafter), and when the recipient retires. The same amount of reward unlocks when the business reaches a jubilee landmark, i.e. 25 years, 50 years, and soon. It's a condition that to get tax exemptions, the gifts must be non-cash. Gift vouchers are acceptable.
The Ministry of Economy & Finance>> [https://www.impots.gouv.fr/portail/](https://www.impots.gouv.fr/portail/)
## Spain
Spanish Tax Authorities give a relaxation of up to €299 for every gift through the year per employee.
There are certain benefits besides it, like meal vouchers worth up to €11 per day, nursery vouchers, public transport vouchers within certain limits, medical insurance premiums up to a maximum annual amount of EUR500 per family member covered, etc. that are exempted from tax.
Agencia Tributaria>> [https://www.agenciatributaria.es/AEAT.internet/en\_gb/Inicio.shtml](https://www.agenciatributaria.es/AEAT.internet/en_gb/Inicio.shtml)
## Germany
The EStG states a total of \$44 for every emplpoyee per month that can go tax free.
All gifts to employees over this amount and without special occasions and taxable.
As per Section 8, (para two; clause 11) of the German Income Tax Act (EStG), tax and social security contributions are exempted up to € 44 a month. Section 19.6 (para one) of the German Income Tax Law (LStR) exempt from tax and social security contributions up to€60 for special personal occasions.
BZSt>> [https://www.bzst.de/EN/Home/home\_node.html](https://www.bzst.de/EN/Home/home_node.html)
## Denmark
With an amount of DKK1100 for every employee for a year, the Danish tax authorities has a threshold for gift vouchers and other non-cash gifts.
The gifts going beyond this limit are taxable to the given slabs.
Skattestyrelsen, the Danish tax authority signifies that gift vouchers and other non-cash gifts aren't taxable up to DKK1,100 in case they are unrelated to the employees' jobs. Benefits related to employees' jobs have a more relaxed threshold, and they are tax-exempt until their value exceeds DKK5,600.
SKAT.DK>> [https://skat.dk/skat.aspx?oid=2244343](https://skat.dk/skat.aspx?oid=2244343)
## Singapore
No corporate gift tax is charged on presents worth under the value of SGD200.
As for the values exceeding SGD200, it would only be taxed in case of a single gift value surpassing the limit. However, multiple gifts can given under the value of SGD200 without being taxed.
If the nature of benefit or gift is that of bereavement, i.e. on the occasion of loss, then it's exempted from any tax. Such gifts are never taxable, even if their value exceeds S\$200. Do note that the above rules apply to cash and non-cash gifts.
[https://www.iras.gov.sg/IRASHome/Businesses/Employers/Tax-Treatment-of-Employee-Remuneration/Gifts/](https://www.iras.gov.sg/IRASHome/Businesses/Employers/Tax-Treatment-of-Employee-Remuneration/Gifts/)
## Malaysia
Normally, gift vouchers are not taxable in the hands of the employee unless they are of a recurring nature and are provided in circumstances where the employee expects such gifts as part of his remuneration.
In case the Gift Vouchers are part of the remuneration, it will be taxed at the hand of the employee.
The small benefit exemptions aren't applicable, however, on long service or festivities. The value of gift vouchers would be taxed on the recipient's gross income.
[http://www.hasil.gov.my/index.php?bt\_lgv=2](http://www.hasil.gov.my/index.php?bt_lgv=2)
## Philippines
Any gifts below P5000 are exempted from taxation.
These gifts, however, are advisable to be crossed only on special occasions and festivities. Any gift above P5000 would be considered as a fringe benefit and will be taxed.
[https://www.bir.gov.ph/](https://www.bir.gov.ph/)
# Training and Awareness
Source: https://help-plum.xoxoday.com/faq/security-compliance/training-and-awareness
Find answers to frequently asked questions about the security training and awareness programs Plum runs for its employees.
Yes, our personnel - both full-time and on-contract are bound by an agreement of non-disclosure and a confidentiality agreement as a condition of employment to protect the customers and tenant's information.
Yes, all the employees and personnel pass through induction and job training, along with contractors and third-party users for their share of information security controls.
Yes, all personnel are well-trained with awareness programs annually.
We conduct the Infosec Awareness training as soon as employee joined the organization and on annual basis. Each employee, when inducted, signs a confidentiality agreement and acceptable use policy, after which they undergo training in information security, privacy, and compliance. Furthermore, we evaluate their understanding through tests and quizzes to determine which topics they need further training in. We provide training on specific aspects of security that they may require based on their roles.
We conduct ISMS training for all the employees.
Attached the IT policy. We also have communicated these to all the employees to spread awareness among them.
We conduct ISMS training for all the employees. The frequency of the training will be annually.
Data privay and Data protection is a part of our Infoarmation security awareness training.
Yes. We conduct ISMS training for newly joined employees and existing employees.
Yes. We do conduct security awareness training for all the employees as soon as they joined the organization and also annually as per the ISMS requirements.
We conduct annual ISMS training for all the employees as per the compliance requirements
We provide mandatory security and awareness training to all our employees and spread awareness about the information security accrross the organization.
Yes. We conduct Infosec awareness training as soon as the new employees join the organization and annually once for all the existing employees.
Yes. We have eduated all our employees throgh training on Data privacy compliance. The Production or devolopment team always make sure that the new devolopments made will be complied with the data privacy requirements. We also educate our Production or devolopment on the recent updates throgh necessary trainings.
# Vulnerability and Threat Management
Source: https://help-plum.xoxoday.com/faq/security-compliance/vulnerability-and-threat-management
Find answers to frequently asked questions about Plum's vulnerability scanning and threat management practices.
Yes, policies and procedures are established and mechanisms are implemented to detect, address, and stabilize vulnerabilities in a timeframe that matches the Security Patch Management Standards.
Yes, Xoxoday's products are supported by leading anti-malware programs. These are connected with our cloud service offerings and are a part of all our systems.
Yes, we perform periodic scans of operating systems and databases along with server applications for vulnerability and configuration compliance. This is done by using suitable vulnerability management tools as per the industry standards.
Yes, we ensure that there is no breach in network layers with vulnerability scans as per the industrial standards.
Yes, to check the hygiene of application layer, our vulnerability scans are done as prescribed by the industrial standard.
Yes, tenants can request for vulnerability scan reports.
Yes, in order to detect any unauthorized changes in the data or system configuration, we have a procedure in place for host/file integrity monitoring.
No, our periodic vulnerability scans are conducted just the right number of times to ensure the prominence of security measures and protection of the operating system layer.
No, our periodic vulnerability scans are conducted just the right number of times to ensure prominence of security measures and protection of the database layer.
No, our periodic vulnerability scans are conducted just the right number of times to ensure the prominence of security measures and protection of the application layer.
Yes, vulnerability scans and penetration tests are conducted periodically by third parties and external services to test our security measures.
Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com) to raise a ticket, if you happen to notice any potential security issue whilst meeting all the required criteria in our policy. The validation of the reported issue in terms of severity & authenticity will be done by our security team in around 90 days. Post validation, steps will be taken to fix the security issues in accordance with our security policies. The owner of the ticket will be informed once the issue is resolved.
Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing.
We have fixed all the issues identified during the VAPT Audit and rescanned it once again to make sure that all the vulnerabilities are remideiated. Post confirmation of these fixes we got the final VAPT Certificate for our product.
Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing.
60 days.
We conduct the VA/PT on annual basis as per the compliance requirements. Manual and third party tools are used for this assessment.
Yes. We have the capabilities to patch the vulnerabilities.
We conduct VAPT on annual basis.
we follow all the technical guidelines for development of our code and applications that come under the Open Web Application Security Project. And also we conduct VAPT Assessment for our application and remidiate the findings
we perform periodic scans of operating systems and databases along with server applications for vulnerability and configuration compliance. This is done by using suitable vulnerability management tools as per the industry standards.
our periodic vulnerability scans are conducted just the right number of times to ensure prominence of security measures and protection of the database layer.
We have implemented the Threat and Vulnerability Management procedures. We close the identified vulnerabilities or fixes the issues.
We conduct code reviews, VA-PT assessments, Log monitoring, Incident reportings etc and these controls are monitored and reviewed during the internal and external parties.
Attached the latest VAPT Certificate.
Attached the letest VAPT Certificate.
Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing. Attached the Threat and Vulnerability Management and Patch Management Procedure.
We conduct the Vulnerability assessment and penetration testing for maximum security.
We conduct on yearly basis as per the compliance requirements.
Attached the Threat and Vulnerability Management Policy.
Yes. As part of every build, the third-party libraries are scanned for security vulnerability.
Our software will be free from all the vulnerabilities.
Attached the independent third party performed a Penetration Test report.
We conduct the periodical vulnerability and penetration testing as per the compliance requirements which includes Static, Dynamic, API, Manual etc..
We perform the VA/PT on an annual basis as per the compliance requirements. Attached the VA/PT report and certificate.
We do conduct Vulnerability and Penetration testing from the Authorized vendor.
We comply with the requirements. We also conduct periodical Vulnerability assessment and penetration testing with the help of the authorised third party vendor.
We conduct internal review and audited by the exteranal auditors for our security standard certification and VAPT assessment
We conduct periodical Vulnerability assessment and Penetration Testing from the Inductry approved authorized vendor to make sure that all the vulnerabilities are closed and having secured applications.
Exhaustive Vulnerability Assessment and Penetration Testing has been conducted along with business logic testing based on OWASP framework which incorporates 120+ test cases like Access Controls, Authentication and Session Management, Cross-site Request Forgery, Cross-site Scripting, Cryptography and Insecure Storage, Data Validation, Information Leakage and Error Handling, Malicious Execution etc.
We have conducted Vulnerability assessment and penetration testing with the help of Industry approved third party vendor. We conduct VAPT for every six months. During the testing, if any observations found by the auditor our team will work on those Audit observations and fix the issues.
See Threat and Vulnerabilities Management procedure attached. Periodic scans has been performed on all network assets deployed on Xoxoday by the third party vendor.
The critical vulnerabilities are fixed immediately within a span of 5 days.
We have the third party vendor called Appknox for scanning the vulnerabilities. They use Appknox tool(Mannual and Automated) for vulnerability management
See Threat and Vulnerabilities Management procedure attached. Periodic scans has been performed for application and the identified observation has been fixed by our engineering team.
We have the third party vendor called Appknox for scanning the vulnerabilities. They use Appknox tool(Mannual and Automated) for vulnerability management
We have Access control policy, and we follow Role based access system and review the access provided periodically to eliminate the risk and make sure that only the Authorised individual have access to avoid risk. We have implemented the controls with regards to avoiding source of Risk and to make sure that we prevent an unauthorised access of the data. We have implemented end point security in all the computers and servers to prevent the unauthorised access. We have Patch Management Procedure and Logging and Monitoring Procedure in place as per the compliance requirements. We also conduct periodical Vulnerability and penetration testing for identifying the source of risk and implement controls for mitigating the risk.
Yes. We update the patched and conduct the vulnerability assessment and penetration testing and remidiate the risks identified.
We have implemented the Incident Management Procedure and VAPT Audit periodically. Attached the latest VAPT Certificate.
We have implemented the Threat and Vulnerabilities Management procedures is to proactively expose security flaws and correct them before a malicious attacker can leverage the same weaknesses and cause irrecoverable damages.
We have implemented the Threat and Vulnerabilities Management procedures. We conduc the Vulnerabilities assessment and fixes the issue identified during the assessments.
We conduct the Vulnerability assessment for our application during the testing and prior to deployment.
We conduct Vulnerability assessment and penetration testing during the testing and before deployment. And we make sure that all the issues has been fixed and mitigated security vulnerabilities.
We conduct Vulnerability assessment and penetration testing for our application in order to make sure that issues has been fixed and mitigated security vulnerabilities.
We conduct Vulnerability assessment and Penetration testing in order to make sure that we identify the vulnerabilities and fixes the issue or mitigate the risk involved.
We have deployed our application on AWS cluod virtual platform and hardened in order to secure a system by reducing its surface of vulnerability.
We continuously monitor the Vulnerabilities and fixes the issue on a periodical basis. We also update the patches regularly to eliminate the security risk.
We make sure that we identify the vulnerabilities and fixes the issues in order to make sure that Information system is secure and free from vulnerabilities.
We conduct periodical vulnerability and penetration testing and fixes the issue identified and make sure that all the risk associated with these vulnerabilities are identified.
We have implemented the Threat and Vulnerability Management to identify and eliminate problems that could lead to a breach of confidentiality, availability, or the integrity of application data resources and to ensure adequate protection of client data. The treatment of vulnerabilities consists of the definition and implementation of controls and measures to eliminate vulnerabilities
We have implemented the Threat and Vulnerability Management to identify and eliminate problems that could lead to a breach of confidentiality, availability, or the integrity of application data resources and to ensure adequate protection of client data.
Vulnerabilities will be categorized as Critical, High, Medium, Low and Information. We remidiate all the vulnerabilities identified.
We have implemented the Threat and Vulnerability Management to identify and eliminate problems that could lead to a breach of confidentiality, availability, or the integrity of application data resources and to ensure adequate protection of client data.
We monitor the vulnerabilities identified and remidiate it.
We follow this as a part of Threat and Vulnerabilities Management procedure.
We do not share the vulnerabilities to any unauthorised individual.
We conduct Vulnerability assessment and penetration testing periodically and we can make this available for the customer on need to knoe basis.
We inform on our potential vulnerabilities and non-compliance issues aand make sure that we mitifate these issues
We conduct Penetration testing with the help of industry approved thord party vendor
Yes. We conduct third party Vulnerability assessment. Attached the certificate for your reference.
Yes. We also fix the issues identified and conduct the test once again for confirmation of fixes.
We will delete the data upon termination of the contract and confirm you. Our data cleaning process goes through an organized purge. Once the data is purged, it's purged from all places.
Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a Vulnerability assessment and penetration testing. We conduct the VA/PT on annual basis and Attached the latest certificate. Security patches are rated as Critical, High, Medium and Low. Critical patches will be deployed immediately High patches will get deployed within 5 days Medium Patches will get deployed within 15 day Low will get deployed in 25 days.
Attached the Threat and Vulnerabilities Management program.
Attached the latest VAPT Certificate
Attached the VA/PT Executive report and Certificate issued upon remediation of all the vulnerabilities identified during the third party assessment.
VA/PT has been consucted with the help of the third party VAPT auditor. The name of the vendor is Appknox. We conduct VPAT for every six months and shared the latest VAPT Certificate.
Attached the Infrastructure Architecture diagram where all the security components are included. Attached the VAPT certificate and Cloud Computing Security Policy
Attached the Executive summary of VAPT report
Yes. As part of every build, the third party libraries are scanned for security vulnerability.
Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing.
We are compliant with this requirements. Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing as per the compliance requirements.
Vulnerability scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems. In addition to our extensive internal scanning and testing program, Xoxoday employs third-party security experts to perform a vulnerability assessment and penetration testing. Attached the VAPT Certificate and executive report. All the vulnerabilities has been fixed.
We conduct the VAPT Assessment with the help of the authorised vendor and compliant with the requirement.
We conduct Vulnerability assessment and penetration testing from the Authorised vendor, and the identified Vulnerabilities will be closed in a timely manner. The treatment of vulnerabilities consists of the definition and implementation of controls and measures to eliminate vulnerabilities (e.g. applying a patch to the affect system) or to prevent the vulnerabilities from being exploited (e.g. deactivating a service or disallowing a firewall connection). Vulnerabilities will be categorized as Critical, High, Medium, Low and Information. We inform the Infosys Immediatly if any critical Vulnerability to be reported.
All are fixed and there are no open Vulnerabilities.
The testing is conducted and vulnerabilities has been mitigated before any releases.
We conduct Vulnerability assessment and Penetration testing as per the compliance requirements. The date of the most recent certificate is 01st March, 2021. Attached the vulnerability assessments/penetration tests report.
# Account Settings
Source: https://help-plum.xoxoday.com/faqs/for-admins/account-management-faqs
Find answers to frequently asked questions about managing your Plum account settings, admin users, and wallet balance.
*Get answers to questions on account management, user management, gift cards, the storefront, and gifting programs on Xoxoday Plum.*
## User Management
Yes. The Xoxoday customer rewards platform enables the management of multi-departmental reward programs. Admins can create department-specific configurations such as goals, budgets, roles, and performance metrics. Each team can independently manage its reward programs while leveraging shared platform features like real-time reports and budget tracking.
Yes, the Xoxoday customer rewards platform includes a robust admin portal that enables authorized personnel to access on-demand, real-time reports. These reports can be viewed, customized, and downloaded instantly, supporting a wide range of audit, compliance, and operational tracking requirements. Features such as filtered views, saved report templates, and exportable formats (e.g., CSV, XLSX) enhance data accessibility for ongoing program optimization and transparency.
Yes, the system offers complete activity logging with time-stamping capabilities for all user actions. Each transaction is tied to an individual user profile, enabling auditability, compliance tracking, and robust administrative control. This is essential for financial transparency and operational accountability.
Yes. All Xoxoday solutions maintain precise timestamping and user-level activity tracking for accountability and compliance:
* **Global rewards marketplace and payout platform** — Tracks reward issuance, catalog changes, and redemption approvals in real time.
* **Employee engagement and recognition platform** — Logs recognition events, budget updates, and survey deployments with exact timestamps.
* **Sales commission and incentive management system** — Records commission plan changes, payout processing, and performance updates with user attribution.
* **Customer loyalty management solution** — Captures member enrolments, points accruals, and redemption events with user and time logs.
* **Merchant-funded offers and promotion engine** — Tracks merchant offer activations, validations, and campaign edits with full audit trails.
## Gift cards
Yes, the Xoxoday gift card marketplace supports role-based distribution, allowing designated administrators to send gift cards to recipients regardless of who initially placed the order. Once the cards are delivered via secure links to the recipient's email, they can be activated and redeemed independently. This flexibility supports decentralized reward distribution within large organizations.
## Storefront: a global reward marketplace
Yes, the Xoxoday rewards catalog includes access to a worldwide network of airport lounges. Users can redeem their points to enjoy premium airport lounge experiences, which include Wi-Fi, refreshments, relaxation areas, and other business traveler amenities.
The Xoxoday gift card marketplace includes intuitive search and filter functionalities that empower customers to browse by category, product type, point eligibility, and preferences. This streamlined navigation enhances the overall user experience, helping users find exactly what they're looking for across a diverse range of digital and physical reward options. The AI copilot further helps customers with insightful product recommendations and queries.
Travel insurance is generally included in the booking you make via our partners. We also provide an option to choose an insurance from our options while booking.
Yes, the Xoxoday reward marketplace includes premium experiences such as hotel loyalty memberships (e.g., IHG, Hilton Honors, Radisson Rewards) and global subscription services such as Netflix, Spotify, and Amazon Prime. Availability may vary by region, and we continue to expand our catalog based on geographic feasibility. Clients will be notified when new options become available in their local reward environment.
These benefits are generally handled directly by airlines to ensure personalized service. However, the platform provides an option to redeem on airmiles to upgrade your bookings.
At present, complimentary baggage check-in benefits are not available in the Xoxoday gift card marketplace. Airlines often handle such privileges directly to maintain control over customer service standards.
The Xoxoday rewards, incentives, and payout platform provides access to one of the world's most comprehensive closed-loop gift card networks via its AI-powered global rewards marketplace. These merchant-specific cards are redeemable exclusively with the issuing brand, making them ideal for targeted reward experiences.
**Availability of closed-loop gift cards** — Clients benefit from:
* 10,000+ brand-specific gift card options
* Coverage in 100+ countries
* 30+ major reward categories to meet diverse user needs
**Top closed-loop gift card categories:**
* Retail & shopping (e.g., Amazon, Walmart, Flipkart)
* Dining & food delivery (e.g., Starbucks, Uber Eats, Swiggy)
* Travel & hospitality (e.g., Airbnb, Booking.com)
* Entertainment & gaming (e.g., Netflix, Spotify, Xbox, Steam)
* Fashion & lifestyle (e.g., Nike, H\&M, Sephora)
* Digital subscriptions & utilities (e.g., Google Play, Apple, mobile top-ups)
* Charity & donations (1000+ nonprofit options)
* Financial products (e.g., Visa/Mastercard prepaid cards)
**Custom catalog additions** — Clients can request new closed-loop gift card partners during onboarding or later via customer support. The Xoxoday team evaluates requests based on:
* Regional demand and popularity
* Brand integration and compliance
* Procurement and fulfillment feasibility
If approved, new partners can be added to the client's private catalog or made available platform-wide based on relevance and viability.
The Xoxoday rewards marketplace offers both digital and physical gift cards to meet the diverse needs of businesses and recipients globally.
**Card types offered:**- **Digital gift cards** — Delivered instantly via email, SMS, or WhatsApp; ideal for scalable campaigns.
* **Physical gift cards**— Available in bulk or individually; suitable for events or regions with limited digital adoption.**Catalog scale and customization:**
* Access to 10M+ reward options across 30+ categories in 100+ countries.
* No upper limits on the number or type of brands; supports 50,000+ daily transactions.
* Businesses can customize catalogs by geography, audience segment, redemption value, or campaign purpose.
**Popular global brands included:**
* Amazon, Walmart, Target, Kroger
* 21,000+ other trusted global and local brands, regularly updated for relevance and seasonal promotions.
This extensive offering ensures global scale, personalization, and seamless reward delivery.
The platform can support premium experiences like invite-only memberships and private events. These are offered based on client demand, subject to third-party approvals and potential additional costs, enabling high-value, exclusive loyalty and recognition programs.
Yes, the Xoxoday rewards, incentives, and payout platform provides an online catalog accessible to departments for ordering gift cards. Workflow approval can be configured to ensure that requests follow internal governance policies. The catalog includes the same comprehensive closed-loop gift card options, covering 30+ categories in 100+ countries, and supports custom partner additions as needed.
The Xoxoday reward marketplace supports a comprehensive range of redemption categories to suit diverse business needs:
* Digital vouchers such as gift cards across retail, dining, travel, wellness, and more
* Prepaid digital cards from major card issuers, available across geographies
* Digital services including subscriptions, mobile top-ups, and digital utilities
* Branded merchandise spanning electronics, fashion, lifestyle products, and more
* OEM products such as accessories, gadgets, and device-related tools
All these categories are part of the standard catalog offering in the Xoxoday gift card marketplace, covering 30+ categories in 100+ countries.
The Xoxoday reward marketplace features a fully integrated digital rewards catalog, offering a wide portfolio of multi-brand vouchers. End users can redeem rewards from a curated selection of e-vouchers and gift cards across 30+ categories, including travel, food, lifestyle, and more. This comprehensive and user-friendly interface ensures an intuitive redemption journey. Explore the catalog: [stores.xoxoday.com/marketplace/rewards-api-catalogue](https://stores.xoxoday.com/marketplace/rewards-api-catalogue).
Yes, the Xoxoday gift card marketplace includes a built-in currency conversion feature. Loyalty points and payments are automatically converted to the user's local currency based on real-time exchange rates, ensuring seamless global reward fulfillment and user convenience.
Yes, users can filter rewards by merchant, product type, keywords, location, price, and popularity. They can also mark favorites and view results based on those preferences, making catalog navigation simple and efficient.
We differentiate through the breadth, flexibility, and global scale of our digital reward infrastructure. Key points include:
* 1M+ reward options across 100+ countries
* Multiple delivery modes: email, SMS, API, and storefront
* Customizable storefronts and branded experiences
* Multi-lingual, multi-currency rewards catalog
* Data privacy and regional deployment
* Value for money and low total cost of ownership
* Dedicated enterprise support with SLAs
Xoxoday rewards marketplace supports a wide array of global airline loyalty programs for airmiles and airpoints.
Yes. The Xoxoday customer rewards platform supports custom vendor onboarding and partner management. The platform allows you to add products from your vendors.
## Gifting program
Yes, the Xoxoday customer incentive software allows you to configure redemption limits at the customer group level. This includes setting maximum redemption thresholds per transaction or restricting access based on the user's loyalty tier. These rules can be aligned with your broader loyalty program strategy.
For feedback or questions, reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Campaigns
Source: https://help-plum.xoxoday.com/faqs/for-admins/campaigns-faqs
Find answers to frequently asked questions about creating, editing, and managing your reward campaigns in Plum.
*Get quick answers to questions on running campaigns on Xoxoday Plum.*
## Dashboard
Yes. The Xoxoday reward payout platform includes a centralized dashboard for administrators to oversee all active and past campaigns.
* Provides real-time status updates: issued, redeemed, pending, or failed gift cards
* Offers recipient-level insights and program-wide analytics
* Streamlines campaign management and simplifies tracking of usage, performance, and budget compliance across initiatives
## Gifting Program
Yes. The Xoxoday customer incentive software supports end-to-end execution of marketing campaigns and promotions tied to gift cards.
* Distribute both digital and physical cards via the gift card marketplace
* Personalize campaigns and automate reward delivery
* Track redemptions through a real-time analytics dashboard
* Send reminders or nudges to users to boost engagement
The Xoxoday reward marketplace allows businesses to create and manage custom catalogs linked to specific customer groups.
* Eligibility can be based on location, loyalty tier, or account type
* Ensures only qualified users can access certain rewards
* Supports targeted reward delivery through the customer rewards platform
Xoxoday customer incentive software powers referral programs by automatically rewarding users for successful referrals.
* Built-in referral tracking and reward automation
* Rewards can include points, gift cards, or bonus credits
* Supports both B2B and B2C audiences
* Drives customer acquisition and loyalty through meaningful incentives
Yes, the Xoxoday gifting platform supports a wide range of digital reward use cases, including gifting for employees and students, processing reimbursements, managing athletic stipends, and mileage-related rewards.
It also accommodates similar custom remuneration projects through its robust configuration options and integrations. These features are adaptable to academic, administrative, and research environments, making the platform highly versatile for university-wide use.
Our admin portal provides a self-service platform for distributing rewards, allowing administrators to log in and send rewards either in bulk or individually. Bulk uploads support lists of up to 10,000 recipients in a single file. Administrators can download cards in bulk to their email address through the portal or via API.
## Reporting
Yes, the customer rewards platform includes gamification tools like leaderboards that rank participants based on performance, points earned, or other defined KPIs. These visual metrics help foster healthy competition and increased participation. Leaderboards can be segmented by region, team, or cohort and are particularly effective in sales, channel partner, and customer engagement programs. Combined with rewards from the Xoxoday gift card marketplace, this feature maximizes user motivation.
## Dashboard
Yes. The Xoxoday reward payout platform includes a centralized dashboard for administrators to oversee all active and past campaigns.
* Provides real-time status updates: issued, redeemed, pending, or failed gift cards
* Offers recipient-level insights and program-wide analytics
* Streamlines campaign management and simplifies tracking of usage, performance, and budget compliance across initiatives
## Gifting Program
Yes. The Xoxoday customer incentive software supports end-to-end execution of marketing campaigns and promotions tied to gift cards.
* Distribute both digital and physical cards via the gift card marketplace
* Personalize campaigns and automate reward delivery
* Track redemptions through a real-time analytics dashboard
* Send reminders or nudges to users to boost engagement
The Xoxoday reward marketplace allows businesses to create and manage custom catalogs linked to specific customer groups.
* Eligibility can be based on location, loyalty tier, or account type
* Ensures only qualified users can access certain rewards
* Supports targeted reward delivery through the customer rewards platform
Xoxoday customer incentive software powers referral programs by automatically rewarding users for successful referrals.
* Built-in referral tracking and reward automation
* Rewards can include points, gift cards, or bonus credits
* Supports both B2B and B2C audiences
* Drives customer acquisition and loyalty through meaningful incentives
Yes, the Xoxoday gifting platform supports a wide range of digital reward use cases, including gifting for employees and students, processing reimbursements, managing athletic stipends, and mileage-related rewards.
It also accommodates similar custom remuneration projects through its robust configuration options and integrations. These features are adaptable to academic, administrative, and research environments, making the platform highly versatile for university-wide use.
Our admin portal provides a self-service platform for distributing rewards, allowing administrators to log in and send rewards either in bulk or individually. Bulk uploads support lists of up to 10,000 recipients in a single file. Administrators can download cards in bulk to their email address through the portal or via API.
## Reporting
Yes, the customer rewards platform includes gamification tools like leaderboards that rank participants based on performance, points earned, or other defined KPIs. These visual metrics help foster healthy competition and increased participation. Leaderboards can be segmented by region, team, or cohort and are particularly effective in sales, channel partner, and customer engagement programs. Combined with rewards from the Xoxoday gift card marketplace, this feature maximizes user motivation.
## Gamificationamification
The Xoxoday customer incentive software includes gamification tools that turn passive users into active participants, fostering deeper engagement and loyalty.
* Interactive challenges, themed campaigns, and behavioral triggers (e.g., service milestones, driving habits)
* Custom digital badges, points-based rewards, and seasonal quests
* Leaderboards, milestone-based unlocks, and social sharing features
* Campaign refresh mechanisms aligned with monthly or seasonal themes
* Gamification analytics to track participation rates, app dwell time, badge completion, and social influence
These features create a dynamic, experience-driven loyalty environment beyond simple transactional engagement.
The Xoxoday customer incentive software includes gamification tools that turn passive users into active participants, fostering deeper engagement and loyalty.
* Interactive challenges, themed campaigns, and behavioral triggers (e.g., service milestones, driving habits)
* Custom digital badges, points-based rewards, and seasonal quests
* Leaderboards, milestone-based unlocks, and social sharing features
* Campaign refresh mechanisms aligned with monthly or seasonal themes
* Gamification analytics to track participation rates, app dwell time, badge completion, and social influence
These features create a dynamic, experience-driven loyalty environment beyond simple transactional engagement.
# Customize Communication
Source: https://help-plum.xoxoday.com/faqs/for-admins/customize-reward-communication
Find answers to common questions on customizing the reward communication, such as emails and messages, sent to recipients through Plum.
*Get quick answers to questions on customizing reward communication on Plum.*
## Communication
The communication module, part of the Xoxoday reward payout platform, enables seamless and timely multi-channel messaging to keep users informed and engaged. It supports both promotional and transactional messaging formats and integrates across:
* **Email:** for personalized promotions, surveys, and transactional updates
* **SMS:** for brief, time-sensitive communications like reminders or confirmations
* **Messaging apps (e.g., WhatsApp):** for interactive campaigns, push notifications, and engagement flows
This omnichannel communication framework ensures consistent brand messaging, improves open rates, and supports personalized customer journeys triggered by real-time behavior or events.
Yes, the Xoxoday reward payout platform allows organizations to customize gift cards with their company logo, brand colors, and messaging. This branding enhances recipient experience and reinforces your identity. Customization may incur additional fees and lead times, depending on the complexity and scale of the request.
Yes, through the Xoxoday customer incentive software, you can easily personalize messages that accompany gift card deliveries via email, SMS, or other supported formats. These custom messages allow for tailored communication that aligns with campaign goals or occasions.
The Xoxoday reward payout platform supports automated, data-driven communication workflows to deliver tailored messages via email, SMS, and in-app notifications. Messages can be personalized based on user milestones, available rewards, expiring points, or seasonal offers. This helps create a consistent engagement loop, keeping users informed and motivated throughout their rewards journey. These communications can be white-labeled and aligned with your brand voice.
The Xoxoday platform includes a multi-channel engagement suite to deliver personalized, timely, and consistent messaging throughout the customer lifecycle.
**Communication Tools Across Channels**
* Email: Transactional and promotional emails with customizable templates
* SMS & WhatsApp: Time-sensitive updates with rich media support
* Push Notifications: In-app or mobile prompts for real-time updates
* In-App Messaging: Banners and widgets for contextual nudges
* Social Integrations: Export lists for targeted ad campaigns on platforms like Facebook
**Campaign Management & Personalization**
* Automation workflows (e.g., welcome journeys, tier milestone celebrations)
* Dynamic personalization with member data such as points, names, or personalized offers
* Multi-language support for local engagement
**Marketing Support Services**
* Assistance with campaign planning, creative design, loyalty calendar management, and promotions
* End-to-end catalog updates and merchant partnership management
**Integration with Marketing Tech Stack**
* Loyalty triggers (e.g., birthdays, tier upgrades) synced with CRM, email, or SMS tools via APIs or native integrations
* Enables unified, omnichannel member experiences
**Use Case Examples**
* Onboarding journeys (Day 0/7/14)
* Tier achievements – Automated rewards and congratulations
* Birthday campaigns – Personalized monthly promotions
* Reactivation – Limited-time incentives for dormant users
* Partner offers – Geo-targeted promotional messages
By combining technology and marketing expertise, the platform ensures communications are relevant, measurable, and high-performing.
Yes. With our Custom Branding feature, you can tailor the user experience by applying your company's colors, fonts, and logos across all emails, landing pages, and the marketplace. You can customize every aspect of your reward emails, including subject lines, sender names, salutations, logos, sending domains, and banner images. Additionally, you can create unique landing pages for your rewards by personalizing content, logos, and banner images.
# Getting started
Source: https://help-plum.xoxoday.com/faqs/for-admins/getting-started-for-admins-faqs
Find answers to frequently asked questions about getting started with Plum as an admin, from setup to your first reward.
*Get quick answers to questions on Plum*
## Set up process
The steps are as followed:
**Step 1:** Initial Consultation: Detailed requirement gathering covering incentive types, program goals, and regional scope.
**Step 2:** Contract Finalization: Commercial agreement, compliance verification, and account security approvals.
**Step 3:** Admin Account Creation: Creation of the primary admin account with defined roles and permissions.
**Step 4:** Platform Configuration: Customization of reward catalogs, branding, languages, currencies, payout modes, and taxation rules.
**Step 5:** Regional Enablement: Activation of services across 55+ countries in all major continents:
* North America – United States, Canada
* South America – Brazil, Argentina, Chile
* Europe – United Kingdom, Germany, France, Spain, Italy, Netherlands, etc.
* Asia – India, Singapore, UAE, Japan, China, Indonesia, etc.
* Africa – South Africa, Nigeria, Kenya
* Oceania – Australia, New Zealand
**Step 6:** Integration & Testing: API, SSO, and payment gateway setup with sandbox testing.
**Step 7:** Go-Live: Platform launch, assignment of the Relationship Manager, and user onboarding.
This process ensures full operational readiness, security compliance, and localization for each target market.
## Security Requirement
Yes. Every client is assigned a dedicated Relationship Manager (RM) or Customer Success Manager (CSM) to ensure smooth implementation, adoption, and ongoing support. The RM acts as the primary point of contact for escalations, program reviews, and best-practice recommendations.
## Implementation & Roll out
Xoxoday follows a structured, customer-centric implementation methodology across all its Platforms to ensure seamless program rollout and long-term success. The approach is collaborative, phased, and designed to minimize disruption while maximizing adoption.
* **Pre-Implementation:** This stage involves foundational readiness checks such as reviewing the Statement of Work (SOW), obtaining required InfoSec clearance, finalizing the Master Services Agreement (MSA), establishing payment and subscription terms, and transitioning ownership from the sales team to the implementation team.
* **Requirements Gathering & Discovery:** At this stage, we work closely with client stakeholders to capture program goals, success metrics, and specific requirements. This includes understanding user segments, reward policies, technical dependencies, and branding preferences to form the blueprint of the engagement program.
* **Planning & Configuration:** A joint launch team is established, and timelines are finalized. The platform is configured based on business rules, policies, and workflows. This includes integration with critical enterprise systems such as HRIS, SSO, ERP, CRM, and communication tools.
* **Customization & Integration:** The platform is customized with client-specific branding, logos, color palettes, and program elements to ensure a consistent user experience. Technical integrations are validated to enable smooth data flows and reward automation across channels.
* **Testing & Validation:** Before launch, rigorous user acceptance testing (UAT) is conducted to ensure the platform is functioning as expected. This includes testing user journeys, redemption workflows, system integrations, and reporting dashboards.
* **Launch & Change Management:** A formal go-live is executed with supporting communication and engagement strategies. Training materials, FAQs, and guides are provided to drive user adoption and ensure all stakeholders are aligned for a smooth rollout.
* **Post-Deployment Support & Success Reviews:** Following launch, clients receive dedicated support through account managers and customer success teams. Regular reviews, monthly, quarterly, and annual, are conducted to monitor adoption, measure KPIs, and align with evolving business needs. Continuous feedback loops and proactive recommendations ensure that the program remains effective and delivers ROI.
By following this phased methodology, Xoxoday ensures that each customer engagement rewards program is launched smoothly, tailored to business requirements, and continually optimized for success.
## Gifting Program
The Xoxoday customer rewards platform offers multiple levers to optimize spend and improve operational ease:
* Volume & tiered discounts – Benefit from pricing advantages when purchasing at scale.
* Digital-first rewards – Reduce costs tied to packaging, logistics, and physical distribution.
* Bulk ordering & automation – Use self-serve bulk issuance, API integrations, and wallet-based payments for faster, low-touch reward distribution.
* Customizable reporting – Configure custom fields, generate real-time insights, and track redemptions and spend for greater visibility and accountability.
Together, these features streamline workflows, improve delivery speed, and maximize ROI on your rewards program.
Yes, a consumer reward platform can deliver highly personalized reward experiences by using rule-based automation or machine learning models. It can track user activity, preferences, transaction history, and frequency of engagement to curate personalized reward recommendations. Through the Xoxoday solution, administrators can display curated catalog options that resonate with user profiles—resulting in higher redemption satisfaction and stronger program engagement.
## Gifting Catalog
The Xoxoday reward marketplace supports a broad range of reward capabilities beyond traditional gift cards, including:
* Distribution of gift cards to employees, students, or research participants
* Reimbursements and expense allowances
* Support for athletic stipends and fringe benefits
* Management of mileage or lifestyle reimbursements
* Custom remuneration workflows tailored to organizational needs
Designed as a holistic consumer reward platform, Xoxoday can handle diverse use cases across engagement, recognition, and financial compensation.
## Customer Service
While a toll-free number is available for platform support during standard business hours, all core functions such as deactivating gift cards, verifying their status, and reissuing them can be seamlessly handled via the self-service admin panel on the Xoxoday reward payout platform. The dashboard displays delivery status, recipient engagement (email/SMS), and options to cancel or resend rewards.
## Invoice
The Xoxoday reward payout platform provides flexible and transparent invoicing options tailored to organizational needs. Invoices are typically generated during wallet top-ups initiated by the business.
Once payment is processed, the wallet balance is instantly updated, and confirmation is shared with the finance team. Itemized invoices, listing transaction details such as quantity, unit costs, reward type, and applicable service fees, can be provided in accordance with pre-approved invoice templates or customized formats preferred by the organization. This ensures detailed financial visibility and simplifies reconciliation.
The Xoxoday customer rewards platform can support invoice generation and email delivery to customers upon successful redemption or transaction. These invoices can include detailed transaction information such as date, time, itemized rewards, payment method, and custom narration if scoped appropriately.
However, the exact implementation is subject to further technical scoping, customer-specific integration requirements, and platform configuration. For financial institutions like banks, integration via API and secure email delivery mechanisms can be explored.
## Financial
Yes, Xoxoday applies a 5% transaction fee on reward redemptions. For example, if a user redeems 100 points for a $100 reward, the organization will be billed $105. This fee supports operational costs including reward processing, delivery logistics, and catalog management. There are no hidden fees for catalog access or customization.
Yes, the Xoxoday reward payout platform is designed to distinguish between compensation and reimbursement payments, as well as between human subject rewards and general-purpose payouts such as employee recognition or athletic stipends. This segmentation enhances financial accuracy and supports compliance with tax and privacy policies across different stakeholder groups.
## Record Creation
Yes. The Xoxoday reward payout platform supports milestone-based and task-driven payment scheduling. This allows program administrators to automate variable compensation based on criteria such as study phase completion, participant tenure, or activity type. The platform is built to accommodate custom payment logic and workflows aligned with research objectives.
## Wallet management
The Xoxoday gift card solution operates on a prepaid wallet model. Organizations can fund their wallet in advance and issue gift cards to recipients based on required denominations.
The system deducts the card value from the wallet at the time of issuance, ensuring transparency and control. This flexible funding mechanism supports real-time transactions and can scale according to fluctuating reward needs. You get a notification when the wallet balance hits a low threshold.
## Payments
Xoxoday supports a wide array of payout methods tailored to global needs:
* UPI and equivalent
* Digital wallets like PayPal, Venmo, Zelle (region-specific)
* Reloadable gift cards (Visa, Mastercard, etc.)
* Direct debit card payouts, and
* Bank transfers where supported.
These options are part of Xoxoday's multi-country reward catalog. Full details are available at [https://stores.xoxoday.com/marketplace/home](https://stores.xoxoday.com/marketplace/home).
Yes. Every transaction processed through the Xoxoday reward payout platform is automatically logged with a precise timestamp and payment amount. This ensures full visibility into the financial flow of rewards, facilitating transparent audits and program accountability.
Yes. The platform includes real-time tracking capabilities that capture and display the delivery and redemption status of each reward or payment card. This includes information such as whether the card has been delivered, activated, or redeemed, ensuring payment verification and fraud prevention.
## Process
Xoxoday follows a structured, transparent, and industry-aligned process for handling software enhancement requests across all its Platforms. This ensures client feedback is systematically captured, prioritized, and aligned with the long-term product roadmap.
* **Submission of Requests:** Enhancement requests can be submitted through the Customer Success Manager (CSM), the support portal, or via account management channels. Each request is logged with details such as business impact, use case, urgency, and expected outcomes.
* **Review & Prioritization:** Requests are validated by product teams before being assessed by the Chief Product Officer. Evaluation is based on customer impact, technical feasibility, security implications, and alignment with the product vision.
* **Roadmap Planning & Transparency:** Approved requests are incorporated into the product roadmap, with expected timelines communicated back to the customer. Xoxoday emphasizes roadmap transparency, enabling clients to plan adoption in advance.
* **Development & Release:** Enhancements are built using agile methodology and CI/CD (continuous integration/continuous deployment) for faster, incremental releases. Each update undergoes rigorous QA testing before deployment, with customers informed via release notes, newsletters, and business reviews.
* **Feedback & Iteration:** Post-release, feedback is actively collected to ensure enhancements deliver intended outcomes. This feedback loop ensures continuous refinement and innovation in our product suite.
Through this structured approach, combining customer co-creation, agile execution, transparent communication, and impact-driven prioritization, Xoxoday ensures enhancement requests are handled effectively, driving long-term customer success and innovation across all Platforms.
Xoxoday has robust capabilities to address enhancement, change, and customization requests across all its platforms. Our approach balances agility with governance, ensuring business needs are met while maintaining platform stability, scalability, and compliance.
* **Structured Intake & Assessment:** Requests can be submitted through Customer Success Managers (CSMs), the support portal, or account teams. Each request is assessed for business impact, urgency, and technical feasibility.
* **Customization Flexibility:** Platforms are modular and API-first, enabling configuration of workflows, branding, catalog rules, and integrations without heavy development. For unique needs, custom modules, connectors, and extensions can be built while ensuring compatibility with future releases.
* **Enhancement & Change Management:** Enhancement requests are reviewed by the Product Management team and prioritized for inclusion in the product roadmap. Changes are delivered using Agile and CI/CD practices, enabling faster iterations and frequent incremental improvements. All updates undergo QA, regression testing, and InfoSec review before deployment.
* **Transparency & Communication:** Clients are kept informed through release notes, success reviews, and roadmap discussions. Dedicated CSMs ensure requests are tracked, communicated, and followed up on until resolution.
* **Post-Implementation Support:** Once changes or customizations are deployed, user feedback is gathered and performance is monitored through analytics and KPIs. Feedback loops enable continuous refinement to maximize business value.
By combining flexible configuration options, structured change management, agile delivery, and transparent communication, Xoxoday ensures enhancement and customization requests are handled efficiently.
Xoxoday follows a well-defined Change Management Methodology across all its Platforms to ensure changes are implemented securely, efficiently, and with minimal disruption to customer operations.
* **Change Request & Impact Assessment:** Change requests are initiated via the support portal, CSMs, or account management. Each request undergoes an impact assessment covering business value, security, compliance, dependencies, and potential risks.
* **Planning & Prioritization:** Approved requests are slotted into release cycles or sprint backlogs, depending on urgency. Prioritization is based on business impact, customer need, technical feasibility, and roadmap alignment. Transparent communication of planned changes ensures clients can anticipate timelines and prepare internal stakeholders.
* **Development & Testing:** Changes are developed following Agile methodology and CI/CD practices, enabling incremental, high-quality releases. Rigorous unit testing, regression testing, InfoSec checks, and UAT (User Acceptance Testing) are conducted before deployment.
* **Deployment & Rollout:** Deployment follows a staged rollout approach (sandbox → staging → production), ensuring validation at every level. Automated monitoring is in place to detect anomalies, with rollback procedures available in case of unexpected issues.
* **Post-Implementation Review & Continuous Feedback:** After rollout, customer feedback and performance metrics are captured to confirm change effectiveness. Release notes and communication updates are shared proactively with customers. Continuous improvement is embedded, ensuring learnings from each change cycle inform future updates.
By combining structured intake, agile development, staged rollouts, rigorous testing, and transparent communication, Xoxoday ensures system changes are implemented seamlessly.
Yes, the Xoxoday reward platform guarantees 99.9% uptime and delivers high throughput performance across modules. All new releases undergo rigorous performance benchmarking and regression testing before rollout to ensure system stability and reliability.
The Xoxoday gift card solution provides a comprehensive admin dashboard with built-in audit and tracking features. Universities can monitor discount structures in real-time, filter data by category, and export detailed reports in formats like Excel and CSV. The reporting module supports advanced filtering by product type, recipient, time range, or department, offering full visibility into pricing accuracy. This ensures that all transactions are verifiable and align with contractual terms.
## Incentive Program
Xoxoday streamlines the end-to-end incentive lifecycle through its global reward marketplace. Incentives are sourced from a curated network of brand partners, offering 10M+ options across 100+ countries. IPA files containing recipient details can be processed in bulk via CSV upload or API integrations. Once validated, incentives are delivered instantly through SMS, email, or WhatsApp. Returned or failed deliveries are flagged for retries or admin review. If recipients report any issues (like malfunction or redemption failures), Xoxoday's dedicated support and SLA-backed ticketing system resolves them swiftly, ensuring a seamless experience.
The Xoxoday gift card solution offers robust admin capabilities for managing provider incentive programs. Program admins are responsible for wallet recharges and can distribute rewards through Xoxo Points, Xoxo Codes, Xoxo Links, or branded gift cards. The system supports multi-admin access—ideal for distributed teams across geographies.
To ensure smooth operations, admins are provided with detailed training kits, documentation, and access to a dedicated Customer Success Manager (CSM) who acts as the single point of contact for all ongoing support and strategic guidance.
More on administrative features can be found here: [User Management](/account-administration/user-management/user-management)
## Points based system
The Xoxoday customer incentive software allows seamless panelist data management and point allocation. Clients can upload panelist information directly through the self-service dashboard. Incentive rules and allocation can be configured manually or automated using rule-based logic for recurring bi-annual reward cycles.
# Integrations
Source: https://help-plum.xoxoday.com/faqs/for-admins/integration-faqs
Find answers to frequently asked questions about integrating Plum with your CRM, HR, and survey tools and platforms.
*Get quick answers to questions relating to integration*
Yes, the Xoxoday customer rewards platform supports robust API integrations with platforms like Salesforce, PunchOut, ERP, and Point-of-Sale systems. Custom API connections can also be developed to meet specific system requirements, including those of platforms like Vivint or NRG.
Businesses using the Xoxoday reward marketplace can access the full product catalog via secure APIs. These APIs allow for custom configurations and selective catalog displays. While catalog access is API-driven, onboarding new vendors is managed through the backend to ensure quality control, compliance, and proper integration with the platform.
Yes. Xoxoday's API suite supports real-time data retrieval on product inventory, pricing updates, and time-sensitive promotional offers. This ensures customers always view the latest catalog information, enhancing trust and driving higher engagement across the Xoxoday gift card solution.
The Xoxoday customer incentive software supports real-time synchronization of product inventory and redemption configurations. Businesses can manage digital vouchers, merchandise stock, and availability statuses seamlessly, ensuring accurate catalog experiences for all users.
The Xoxoday reward marketplace can be seamlessly integrated with any existing loyalty management system to support both points redemption and earnings. For redemptions, the platform facilitates real-time access to user point balances, updates, and redemptions via APIs.
For point earnings, transactional data can be securely shared with the loyalty engine, enabling it to allocate reward points based on purchases made through the marketplace. This integration empowers businesses to deliver a cohesive loyalty experience across all user touchpoints.
Yes, the Xoxoday gift card marketplace supports cross-vertical use cases by sharing detailed transaction data via APIs. This data can be utilized by a central loyalty engine to accumulate and manage points from purchases made across different verticals such as telecom, fintech, and travel. The system is flexible and API-first, allowing easy integration with diverse business models.
Yes, the Xoxoday customer rewards platform offers partners and vendors access to a dedicated admin portal. Through this portal, partners can manage their product catalogs, update pricing, configure shipping or digital delivery options, and handle fulfillment processes. This self-service capability enables better autonomy and faster go-to-market execution for suppliers while maintaining full visibility and control within the marketplace ecosystem.
# Reward Code
Source: https://help-plum.xoxoday.com/faqs/for-admins/reward-code-faqs
Find answers to frequently asked questions about sending, customizing, and managing your reward codes in Plum.
*Get quick answers to questions relating to Reward Code*
## Delivery
We have rarely seen incidents on our platform where the delivery of e-vouchers and incorrect codes for redemption are sent to the end users.
However, if such incidents occur, Xoxoday offers 24/7 email and chat support ([cs@xoxoday.com](mailto:cs@xoxoday.com)) for all users of the platform. We'll also share a proper escalation matrix with you. Your account manager and customer success teams will also work with you closely to address any issues.
For prepaid cards such as Visa or Mastercard, the customer incentive software does not support fund withdrawal once issued. However, for Xoxo reward codes, the funds can be retracted for unused gift cards if you are on the "redemption based plan".
## Reporting
The Xoxoday reward payout platform provides a robust self-service analytics and admin dashboard that empowers internal teams with real-time insights and actionable metrics. Features include:
* Automated daily, weekly, monthly, and quarterly reports
* Reward analytics: total vs. unique redemptions, preferred reward categories
* Communication analytics: campaign open and click-through rates across email, SMS, and other channels
* Segmentation tools: filters by geography, behavior, reward usage tiers, service touchpoints
* Customer satisfaction indicators: Net Promoter Score (NPS), Sales Satisfaction Index (SSI), and Customer Satisfaction Index (CSI)
This data-driven dashboard helps teams fine-tune campaign performance, increase redemptions, and deliver targeted experiences.
## Security Requirement
The platform prioritizes security in reward distribution. In case of frauds, the system can cancel the reward orders. The system can also block reward codes which are not misused. If the fraud happens on a 3rd party service, we'll have to check with the 3rd party to check possibilities.
# Reward Points
Source: https://help-plum.xoxoday.com/faqs/for-admins/reward-points-faqs
Find answers to frequently asked questions about sending, tracking, and managing your reward points balance in Plum.
*Get quick answers to questions relating to Reward Points*
## Points Redemption
The Xoxoday incentive management platform supports automated file processing through APIs for real-time or scheduled transfers of points data from CRM tools such as Salesforce to external programs. This allows for a fully integrated and automated rewards experience across systems.
Absolutely. The Xoxoday customer rewards platform includes automated workflows that credit points back to the member's account when a redemption request is rejected by the external partner. This ensures accurate balances and a transparent user experience.
Yes, once a redemption request is accepted, the Xoxoday reward marketplace automatically deducts the corresponding number of points from the member's balance. This ensures real-time updates and alignment between the redemption activity and point balances.
Yes, the Xoxoday consumer reward platform offers configurable redemption denominations for airline loyalty programs or any reward category. This enables clients to define specific point tiers for redemptions, supporting both user flexibility and budget control.
## Rewards Redemption
Reward values on Xoxoday's platform are fully configurable to align with your program's budget and objectives. During program design, you can set a preferred point-to-currency ratio.
Many clients choose a simple 1:1 ratio (1 point = \$1.00) for transparency, though other ratios like 1:2 can also be applied. Points are not marked up, and there's no breakage in the pay-on-redemption model. The catalog value always matches the points spent, ensuring full transparency and cost-efficient reward distribution.
## Points Redemption - Invoice Credit
Yes, the Xoxoday reward payout platform allows full control over redemption rules. Program administrators can set both minimum and maximum limits for how members convert reward points into credits or benefits.
When members choose to redeem their points as invoice credit, the equivalent credit amount is automatically applied to their next billing cycle. This credit appears as a line item on the upcoming invoice, providing full transparency and ease of tracking. The Xoxoday customer rewards platform supports such redemption workflows through customizable automation rules and flexible reward configurations.
Yes. As part of the redemption workflow on the Xoxoday reward payout platform, members instantly receive an email confirmation once their point redemption is complete. This notification includes the details of the credit applied, the number of points redeemed, and confirmation of the amount that will be adjusted on their next invoice. This real-time communication enhances user trust and ensures a seamless post-redemption experience.
Yes. The Xoxoday reward marketplace allows administrators to set up bonus credit promotions linked to specific redemption thresholds. For example, you can configure a rule where users receive an additional \$5 reward when redeeming 5,000 points. These promotions can be tailored for time-limited campaigns, member tiers, or seasonal offers, helping businesses drive engagement and encourage more redemptions.
Yes, invoice credits can be configured to apply to the pre-tax amount, depending on the specific integration setup. The Xoxoday reward payout platform can accommodate this requirement through customized billing workflows. For greater flexibility, financial rules such as credit application logic can be defined during the onboarding phase to ensure compliance with local taxation and accounting standards.
Yes. The Xoxoday customer incentive software lets administrators define rules so invoice credits apply only to selected product categories. Using configurable reward logic and advanced rule-based segmentation, businesses can restrict credits to specific SKUs or catalog sections—such as electronics, apparel, or seasonal merchandise—helping optimize budget allocation and maximize reward spend efficiency.
## Points Redemption - Travel Credit
Yes, the Xoxoday reward payout platform supports secure overnight batch file transfers for points-based reward programs. This allows seamless integration with partner systems and ensures efficient processing of bulk transactions.
Yes, the Xoxoday rewards platform supports hand-back file processing to confirm or reject points redemption requests. This feature helps maintain transactional accuracy, reconciliation, and audit readiness in partner-integrated workflows.
The Xoxoday incentive management software can automatically credit points back to a member's rewards account when a redemption or reward request is rejected. This ensures data accuracy, improves the user experience, and maintains the integrity of the reward points balance.
Yes, with the Xoxoday customer incentive platform, approved points requests are automatically deducted from the member's rewards balance. This deduction process is secure and traceable, ensuring compliance and transparency within your points management program.
The Xoxoday reward payout platform provides robust reporting features that can be configured to deliver monthly reports on all points-related activities—such as requested, approved, and rejected redemptions. These reports support audit-readiness, transparency, and informed decision-making.
Yes, the Xoxoday customer rewards platform supports robust API integrations to enable automatic file processing of points requests. This ensures a seamless and scalable exchange of data between client systems and the reward infrastructure.
## Gifting Program
The Xoxoday rewards platform enables users to participate in various games & contests such as surveys, feedback campaigns, or milestone-based actions to earn points. Submissions are automatically tracked within the platform, and corresponding points are added in real time. The gamification can be chosen by the client.
# Send Gift Cards
Source: https://help-plum.xoxoday.com/faqs/for-admins/send-gift-cards-faqs
Find answers to frequently asked questions about sending digital gift cards to recipients through the Plum platform.
*Get quick answers to questions on sending gift cards on Plum*
## Customer Service
The Xoxoday reward payout platform deems an order successful only when all quality checks are met:
* Correct voucher, denomination, or merchandise is fulfilled
* Branded collateral or cover letter (where required) follows approved format and tone
* One printed cover letter is included per package, where applicable
* Shipping is completed to the exact address provided by the organization
If deliveries are incorrect or products damaged, issues are treated as P2 priority with a 4-hour response time and 24-hour resolution window.
The Xoxoday customer rewards platform ensures end-to-end order traceability with strong logistics protocols.
* Valid Proof of Delivery (POD) is provided for disputed or undelivered orders
* If POD is unavailable, a replacement is issued at no extra cost
* Issues are prioritized as:
* P1: Time-sensitive cases like undelivered items or critical errors
* P2: Moderately urgent issues such as incorrect names, vouchers, or denominations
* Response time is 4 business hours for both categories, with resolution expected within 8 hours for P1 and 24 hours for P2
## Gift Card
Yes, all gift cards issued through the Xoxoday gift card solution come with a defined expiration period. The duration varies by card type or issuing brand and is communicated upfront at the time of issuance, ensuring recipients have ample time to redeem their rewards.
Xoxoday's rewards, incentives, and payout platform enables flexible global reward distribution, including Visa and Mastercard gift cards across 100+ countries.
* Visa & Mastercard digital gift cards: No activation fees when issued digitally via the Xoxoday marketplace, ensuring cost efficiency at scale.
* Other branded or physical cards: For cards such as American Express, Discover, or physical card formats, activation fees may apply. These fees are determined by the issuing bank and regional regulations, not by Xoxoday.
All applicable charges are displayed transparently on the platform when selecting reward types, so businesses have full clarity before issuing. Alongside this, Xoxoday offers real-time tracking, multi-currency support, and a self-serve dashboard to manage issuance, activation, cancellation, and re-delivery.
Yes. The Xoxoday reward marketplace's admin interface allows authorized users to:
* Deactivate issued gift cards
* Track usage and redemption status
* Verify remaining balances
This centralized control ensures transparency and oversight for large-scale rewards distribution.
Vouchers delivered through the Xoxoday reward payout platform typically offer flexible validity, including 12 months or longer. While validity is governed by individual brand partners, most vouchers offer ample redemption windows to ensure a satisfying end-user experience.
* Digital rewards: Delivered instantly via email, WhatsApp, or SMS
* Physical rewards: Delivered within 2 to 7 days, depending on the delivery location
All digital gift cards from the Xoxoday reward marketplace are delivered instantly via email or SMS, ensuring real-time fulfillment with no delays. This makes the solution ideal for time-sensitive campaigns such as on-the-spot rewards, contests, or service recovery gestures.
Yes, the Xoxoday gift card solution manages end-to-end fulfillment for physical gift cards, including printing, packaging, and delivery. Orders can be shipped across the 100+ countries with reliable logistics support. This turnkey offering simplifies the physical reward process while maintaining branding and quality standards.
For prepaid cards such as Visa or Mastercard, the customer incentive software does not support fund withdrawal once issued. However, for Xoxo reward codes, the funds can be retracted for unused gift cards if you are on the "redemption based plan".
Yes, the Xoxoday gift card solution enables administrators to generate gift cards without assigning them to a specific individual at the time of issue. These unassigned cards are delivered via email in bulk to the designated admin in secure format.
These cards can be sent in inactive format and can be activated on demand securely. This approach is particularly useful for open campaigns, event-based rewards, or when the final recipient is yet to be determined.
The Xoxoday rewards, incentives, and payout platform offers global delivery of physical rewards across 100+ countries with standard and expedited shipping options.
* Coverage: Rewards shipped to North America, Europe, APAC, MENA, and LATAM
* Reward types: Prepaid Visa/Mastercard gift cards, branded merchandise, swag, and corporate gifting bundles
* Tracking: Most shipments are trackable via integrated courier partners
**Standard Shipping**
* Carriers: Local postal services (USPS, Royal Mail, Canada Post, India Post, etc.)
* Delivery times:
* North America & Europe: 3–7 business days
* APAC & Middle East: 5–10 business days
* LATAM & Africa: 7–14 business days (varies by region)
* Cost: Included in base fulfillment charges for most reward categories
**Expedited Shipping**
* Carriers: FedEx, DHL, UPS, Aramex (region-based)
* Delivery times:
* Major metros (US, UK, EU, India): Next-day or 2-day delivery
* Remote/international: 3–5 business days
* Cost: Additional, based on volume, country, and weight
**Security & SLA**
* Tamper-proof packaging for prepaid and branded cards
* Delivery confirmation and audit trail via the platform
* Insurance for high-value shipments (available on request)
## Points Redemption
Yes, the Xoxoday gift card marketplace adheres to merchant-specific denomination constraints. Each brand or merchant in the platform defines their available gift card values, and these denominations are clearly displayed during the selection process to ensure transparency and accuracy for end-users.
Yes, the Xoxoday reward marketplace supports full configurability of reward point costs by gift card brand, denomination, and delivery mode (digital or physical). This allows program administrators to tailor the redemption logic to business rules, regional pricing, or marketing objectives, ensuring flexibility and cost control.
## Distribution
The Xoxoday customer rewards platform offers omnichannel gift card distribution, enabling delivery via email, SMS, WhatsApp, and in-app notifications. For those preferring tangible rewards, physical gift cards are available and can be shipped directly to recipients. This multichannel approach ensures a seamless and tailored reward delivery experience across digital and physical touchpoints.
Admins can send rewards directly to individual email addresses or mobile numbers. This flexibility is ideal for targeted recognition, milestone achievements, or just-in-time incentive distribution.
The Xoxoday reward payout platform provides bulk distribution capabilities via both the self-service portal, Spreadsheets and API integrations. Admins can upload a list of recipients and distribute rewards in bulk, or use the API to get these rewards.
These links remain accessible until activated by the recipients. There's no restriction on the number of orders per day, making it easy to run large-scale reward campaigns across departments, regions, or audience segments.
Yes, the Xoxoday reward payout platform supports both open-loop and closed-loop gift cards. Open-loop cards (such as prepaid Visa and Mastercard) can be used universally, while closed-loop cards are redeemable at specific retail or service brands. This dual offering ensures flexibility in consumer reward experiences across different geographies.
## Gifting Program
The Xoxoday rewards, incentives, and payout platform offers a gift card program that stands out for its scale, flexibility, and global coverage. Designed to meet the needs of modern enterprises, it empowers businesses with a seamless, secure, and highly customizable way to reward employees, customers, partners, or research participants.
Here's how the program differentiates itself:
* **Global gift card catalog with unmatched scale:** Our platform offers access to over 10 million reward choices across 30+ categories, with a strong emphasis on gift cards. It includes 10,000+ brand gift cards — such as Amazon, Walmart, Starbucks, and Visa/Mastercard — available in 100+ countries with support for 55+ currencies and 50+ languages.
* **Dual-mode delivery: physical & digital:** The gift card program supports both physical and electronic delivery, ensuring users can choose the mode that best suits their location and preference.
* **Real-time reward delivery & status tracking:** Gift cards can be sent instantly via email, SMS, or WhatsApp, with access to a self-service admin dashboard to track delivery and redemption status in real time. Bulk issuance is also supported for up to 10,000 recipients at once.
* **Custom branding and localization:** Businesses can fully customize gift card emails, landing pages, and catalogs with brand logos, messages, and localization settings (language, currency, etc.) to ensure a white-labeled, personalized gifting experience.
* **Transparent pricing with pay-on-redemption model:** Unlike many providers, Xoxoday uses a transparent pricing structure with no markups on gift card value or shipping, and offers pay-on-redemption billing for point-based programs, minimizing breakage and optimizing spend efficiency.
* **Fraud prevention and redemption controls:** Admins can set expiration periods, block specific gift cards, enable approval workflows, and use maker-checker models for high-value distributions. Built-in fraud detection further secures transactions.
* **Dedicated account management and global support:** Clients receive a dedicated account manager, access to 24/7 customer support, and optional onboarding and integration assistance. This ensures smooth implementation, timely issue resolution, and scalable program management.
These capabilities collectively make the Xoxoday gift card program a highly secure, flexible, and globally scalable rewards solution trusted by over 5000+ businesses, including Fortune 500 enterprises and leading research institutions.
Absolutely. The Xoxoday gift card solution is designed for flexible ordering to suit varied use cases. Administrators can issue single cards for individual rewards or execute bulk distributions to thousands of recipients in one go. Cards can be activated and sent instantly via email, SMS, or custom links. This dual-mode ordering capability supports dynamic reward campaigns, whether for a one-off recognition or a large-scale loyalty or engagement program.
There are no minimum or maximum order limits. Organizations can issue a single reward or run bulk campaigns for thousands of recipients. The platform is designed to scale seamlessly without constraints.
No fixed dollar limit exists.
* Gift card denominations are selected within brand-specific ranges displayed during order setup
* Virtual prepaid cards support custom denominations (e.g., \$1, ₹2500, £52)
* Reward Codes can hold up to 50,000 points each, with up to 15 codes applicable per transaction within the total balance
Yes, the incentive software provides full flexibility to load digital prepaid cards in custom denominations as per your requirements. This helps tailor the value of each reward to specific user actions, performance tiers, or campaign milestones.
Yes. The platform supports personalized gifting:
* Custom messages and delivery scheduling for occasions like birthdays or holidays
* Delivery via email, SMS, WhatsApp, or other social channels
* Recipient selection from contact directories
* Confirmation notifications for senders and email receipts summarizing the transaction
* Functionality is configurable based on integration and implementation requirements
The Xoxoday gift card marketplace supports global shipping of physical vouchers. Cards can be sent to a designated location as per project instructions, including consolidated delivery to client-appointed audit hubs. There are no additional costs to participants for receiving these rewards.
Yes, the gift cards can be uploaded in Apple or Google wallet for easy tracking.
The Xoxoday gift card solution maintains a transparent pricing model. There are no hidden fees related to card issuance, inactivity, or reporting. Clients only pay for what is redeemed, with no markup on gift card value or hidden service costs.
Yes, the Xoxoday gift card solution offers a real-time dashboard that allows administrators to track every stage of gift card activity. This includes issuance status, redemption history, balance checks, delivery confirmations, and user-level usage insights. The platform ensures transparency and accountability by updating these records dynamically as transactions occur.
Yes, the Xoxoday gift card solution enables users to seamlessly share rewards, e-gift cards, and merchandise links with others. These can be sent through multiple digital channels such as WhatsApp, text message, email, or social platforms, directly from the integrated app experience. This functionality enhances social gifting and engagement and can be embedded within any app ecosystem via API or SDK integration.
## Refunds and Returns
The Xoxoday gift card solution supports cancellations and refund processing for cancelled or unfulfilled orders. The refunds go to the original payment method which can be reward points or reward codes or credit card/bank through payment gateway.
While the Xoxoday gift card solution does not offer guaranteed upfront discounts based solely on expected breakage, organizations can benefit from its pay-on-redemption pricing model, where costs are incurred only for claimed gift cards. Additionally, volume-based pricing tiers and program-specific commercial models may be available depending on usage scale and scope.
The treatment of breakage depends on the type of card issued.
* For prepaid Visa or Mastercard-type gift cards, unused funds are not recoverable.
* For gift cards, the breakage is handled as per the terms of the brand and the country. For unused balances, the terms of the brand define the usage.
Through the Xoxoday gift card solution's admin dashboard, authorized personnel can:
* Cancel issued rewards
* Resend gift cards when needed
If the gift card hasn't been accessed or used, the order can usually be reversed, ensuring a smooth and secure process for administrators managing both bulk and individual reward programs.
# Cancellation/Refund
Source: https://help-plum.xoxoday.com/faqs/for-end-users/cancellation-refund
Find answers to frequently asked questions about cancellations and refunds for rewards received through the Plum platform.
*FAQ's on cancellation and refunds.*
You cannot cancel an experience after booking confirmation is received from Xoxoday. Any modification in the booking will be at the service provider's discretion. Please drop a mail to [cs@xoxoday.com](mailto:cs@xoxoday.com) for any rescheduling/canceling changes. You can also [raise a ticket](https://www.xoxoday.com/support#raise_a_ticket) or Whatsapp us at **+91 8061915050**.
Cancellation charges are dependent on the cancellation policy of the experience. It is mentioned while booking the experience.
You would be able to change the experience before a confirmation is received. Currently, this feature isn't available online. Please contact at [cs@xoxoday.com](mailto:cs@xoxoday.com) to help you guide through the process. You can also [raise a ticket](https://www.xoxoday.com/support#raise_a_ticket) or Whatsapp us at +91 8061915050.
But once you receive the confirmation of your booking, any modifications will be at the service provider's discretion.
Yes, the amount will be refunded to your account without any cancellations, if the experience is not available.
# Create Support Ticket
Source: https://help-plum.xoxoday.com/faqs/for-end-users/create-support-ticket
Learn how to create a support ticket as an end user on Plum if you run into any issue with a reward you've received.
*How to create customer support ticket for a quick resolution of your query*
At Xoxoday, we strive to deliver a superior experience to all our users at all times.
However, we understand that at times, the users may be left with unanswered questions or are simply not sure about what to do next. The Plum customer support team is available to resolve all such queries and issues that the customers are facing.
## How to Create a Customer Support Ticket?
1. Navigate to the in-app resource centre.
Empuls Resource Center
2. Go to Home --> Raise A Support Ticket.
Raise A ticket
3. Fill out the form on the new tickets creation page and submit.
Ticket Creation Form
Users can also simply drop an email to [support@empuls.io](mailto:support@empuls.io) with the details of their query/issue for a swift resolution.
# Delivery related Issues
Source: https://help-plum.xoxoday.com/faqs/for-end-users/delivery-related-issues
Find answers to frequently asked questions about delivery-related issues for rewards sent through the Plum platform.
*Get answers to Delivery FAQ's*
Please [raise a ticket](https://www.xoxoday.com/support#raise_a_ticket) or send a mail to [cs@xoxoday.com](mailto:cs@xoxoday.com) or Whatsapp us at +91 080 61915050. We will check and get back to you on the same.
Please [raise a ticket](https://www.xoxoday.com/support#raise_a_ticket) or send a mail to [cs@xoxoday.com](mailto:cs@xoxoday.com) or Whatsapp us at +91 8061915050. We will update you in the next 4 business hours.
Yes, you may coordinate with the delivery executive at the time of delivery and arrange an alternate person to collect the Gift Box on your behalf.
You may provide any address to deliver the gift box, be it residential or otherwise.
Once the Gift Box is dispatched from our end, you will be notified with the tracking details on your official mail ID to track the shipment further.
# Getting started
Source: https://help-plum.xoxoday.com/faqs/for-end-users/getting-started-for-end-users-faqs
Find answers to frequently asked questions about getting started as an end user redeeming rewards on the Plum platform.
*FAQ's for End Users*
The Storefront ([https://stores.xoxoday.com/companyname/](https://stores.xoxoday.com/companyname/)) is accessible in a mobile browser and can be accessed via an Android or an iOS device.
For first-time users, please follow the steps below:
Go to "stores.xoxoday.com/\[companyname]," click on the login page, and enter your email and password.
You will receive an OTP to verify and be successfully signed up.
The user has to visit stores.xoxoday.com to redeem the code. Users can redeem the code through guest checkout. You don't have to log in or sign up. [Read more](/getting-started/for-end-users/how-to-redeem/reward-code) here.
After logging in to the store, your reward points balance will be shown at the top right corner of the page or under "Xoxo Points" in the profile icon. Choose any gift vouchers or any product from 30+ categories. During checkout, the user will be able to see the points balance and will be asked if he wants to use the points for the order payment. After checking the same, your points can be used for checkout. [Read more](/getting-started/for-end-users/how-to-redeem/redeem-reward-points) here.
When you get the email about the reward, click "Redeem Now." You'll be taken to a page listing all of your vouchers. Read more here.
No, you cannot redeem Giift points/vouchers for cash.
To use your Mastercard/Visa cards, you can pay the excess amount during checkout by selecting the option to pay via "Credit Card" and choosing the card of your choice.
For Reward Codes and Rewards links, the user need not log into Plum. Checkout is available for guest login.
We generally respond to customer inquiries within 8 business hours. Our customer support timings are as follows:
Monday to Friday (9:00 am to 9 pm)\*
Saturday to Sunday (9:30 am to 6.30 pm)\*
Note: All times are in IST.
For queries please raise a ticket at [cs@xoxoday.com](mailto:cs@xoxoday.com) or Whatsapp us at +91 080 61915050.
You can check the order status under your Profile. Click on the profile icon and select "Orders." Then, navigate to "Your Orders" to view a list of your orders.
Order Status is mentioned right next to the order. (Delivered/Pending).
If your order status is pending, please check the Delivery TAT of the Gift voucher mentioned in T\&C of the Brand.
Note: The order history can only be checked if the user is registered in Plum and has placed the order by logging into the account and not guest check out.
* Go to [https://stores.xoxoday.com/](https://stores.xoxoday.com/)
* Now, click on the "Login" button that is present in the top right corner of the page.
* Enter your company email address that is associated with Plum.
* Now, click on "Verify Email".
* Now, enter the password and click on "Login"
* After logging in to the Plum Storefront, click on the "Profile" button.
* You can edit information from the "Basic Information" section in the dashboard.
* Now, change the mobile number in the "Phone" section by clicking on "Edit Information".
* Now, click "Confirm"
* You will receive an OTP. Please enter the OTP on the screen.
* Congratulations, you have successfully changed your mobile number in the storefront.
After logging in to the Plum Storefront, you can see your reward points on top-right corner.
Yes, we allow multi-lingual support in 10 different languages for the convenience of our end users.
Kindly check if the number provided is correct this might happen due to network issues, please retry after some time. If you still face issues, raise a ticket in the help section at the top right corner. You can also email us at [cs@xoxoday.com](mailto:cs@xoxoday.com) or WhatsApp us at +91 080 61915050.
Yes, they come with validity, the validity of the offer is limited and subject to change.
Conversion rates are the conversion amount of the points that you have received. For example: 1 Point = 1 INR.
Yes, "Couple" in this case denotes any two people who can visit and enjoy the experience.
Yes, they are identical.
You may redeem the experience and gift the same to your family & friends but the booking name has to be provided so that we can inform the service provider in whose name it has to be booked.
No, once the booking is confirmed it cannot be canceled or swapped.
The Reward points are usually rewarded from your Company and the same cannot be added manually by an individual.
Please drop us an email at [cs@xoxoday.com](mailto:cs@xoxoday.com) with the existing mail ID and the reason for the change of mail ID. We will validate the details and update you on the request.
Kindly check your spam folder if the reset link is delivered. You can click on reset password after 15 min to check if you are receiving the reset link. If you still have not received the reset link, write to [cs@xoxoday.com](mailto:cs@xoxoday.com) to help you with the query.
No, Plum doesn't support cash on delivery right now.
In Plum, you pay the price that is mentioned on the checkout page. There are no hidden charges present.
To check the validity of xoxo points, please write to [cs@xoxoday.com](mailto:cs@xoxoday.com).
Information like date of procurement, amount, quantity can be seen in the history reports on the Plum Admin platform.
Yes, we allow custom changes to the company logo. The following steps can be followed to do the same. Settings >> Platform Preference >> Storefront >> Click on company logo >> Upload new image >> Click on upload.
Phone support is available for administrators in case of order placement or redemption issues on a case-by-case basis. Placing orders by phone is possible through some custom configurations.
The Xoxoday consumer reward platform provides complete support to track events like reward issuance and expiration. These data points can be leveraged by client-owned communication systems to trigger timely user notifications. This setup allows for seamless integration while maintaining flexibility in how end-user communication is managed.
Yes, the redemption process within the Xoxoday reward solution can be configured to require two-factor authentication (2FA). Codes can be sent via SMS or email to the registered mobile number or email ID of the designated primary or secondary account holder, ensuring secure and compliant redemption processes.
# Gift Box Queries
Source: https://help-plum.xoxoday.com/faqs/for-end-users/gift-box-queries
Find answers to frequently asked questions about gift box orders and other related queries for Plum end users.
No, you do not have to create a new account on Xoxoday. You can log in to your enterprise account, and click to visit the e-store option and select Experiences and Activities you will be redirected to stores.Xoxoday.com and you can proceed to choose and book the experience.
Once the Gift Box is dispatched from our end, you will be notified with the tracking details on your official mail ID to track the shipment further.
You may receive either a Xoxo voucher in the Gift Box or Xoxo points to your Email ID.
The gift box will be dispatched and delivered to you on or before the anniversary date. In case, the employee updates the address after the anniversary date or near the anniversary date, the gift box will be dispatched within 7-8 working days.
In case of any queries, you will have to write to [cs@xoxoday.com](mailto:cs@xoxoday.com) with your Employee ID/Official Mail ID. You can also [raise a ticket](https://www.xoxoday.com/support#raise_a_ticket) or Whatsapp us at +91 080 61915050. We will revert to you with the updates on Gift Box Delivery.
# Gift Vouchers
Source: https://help-plum.xoxoday.com/faqs/for-end-users/gift-vouchers-faqs
Find answers to frequently asked questions about redeeming the gift vouchers you've received through the Plum platform.
*Get answers to commonly asked questions on Gift Vouchers*
* E-gift vouchers are gift vouchers (Ex: Flipkart, Myntra, Lifestyle, etc.,) available on Xoxoday.
* You can use Xoxo points to redeem the e-gift vouchers.
* Each brand has a different way of redeeming itself. We suggest you go through the "Terms & Conditions" and "How to Use" sections for that particular brand that you wish to redeem and then use your XoxoPoints accordingly.
* The order will be delivered to your mail ID instantly. Please check your spam box/junk/promotional/updates folders just in case.
* We make it a point to deliver the vouchers instantly, however, if there is a delay from the vendor's side, it might take up to 24 to 48 hours.
* If you are still unable to find the voucher, please write to [cs@xoxoday.com](mailto:cs@xoxoday.com) or click on "[Raise a ticket](https://www.xoxoday.com/support#raise_a_ticket)" on the header of this page. You can also WhatsApp us at +91 080 61915050.
* Every gift voucher has a specific validity and specific time of delivery. You will be able to find the validity of the voucher and the T\&C of the voucher at the time of purchase. Please note that the validity of the voucher cannot be extended and the vouchers cannot be canceled after delivery to the recipient.
* The reward email will have the redirecting link to the brand website if its online, you can use the instruction to redeem the voucher.
* Every gift voucher has a specific validity and specific time of delivery. You will be able to find the validity of the voucher and the T\&C of the voucher at the time of purchase. Please note that the validity of the voucher cannot be extended and the vouchers cannot be canceled after delivery to the recipient.
Please write to [cs@xoxoday.com](mailto:cs@xoxoday.com) with your official email id and company details. Xoxoday will send you a copy of the voucher code. You can also WhatsApp us at +91 8061915050 or raise a help ticket from the header of this page.
* Please check the order status, if the delivered voucher details will be available in your inbox, spam, or Junk folder.
* If pending - Please check the **Terms and conditions** for delivery turnaround time.
* If you are still struggling to resolve this, please raise a ticket or send a mail to [cs@xoxoday.com](mailto:cs@xoxoday.com) or Whatsapp us at +91 080 61915050.
Please drop us an email to [cs@xoxoday.com](mailto:cs@xoxoday.com) with the Order ID & alternate mail ID marking your official mail ID in CC. We will validate the details and re-send them to your alternate mail ID.
You can also raise a ticket or Whatsapp us at +91 080 61915050.
Please raise a ticket or send a mail to [cs@xoxoday.com](mailto:cs@xoxoday.com) or Whatsapp us at +91 8061915050. We will ensure that this is resolved.
Yes, every gift voucher has a specific validity, please check the T\&C while placing the order.
No physical vouchers are sent for any gift vouchers. These are the e-vouchers that are sent only to your provided email ID.
Most of the vouchers are delivered instantly. There are a few vouchers with the defined TAT (Turn Around Time) and it is mentioned on our website under T\&C. This will help you to know the delivery TAT.
Please raise a ticket or send a mail to [cs@xoxoday.com](mailto:cs@xoxoday.com) or Whatsapp us at +91 8061915050. We will update you in the next 24 hours.
Currently, we do not support the feature to add xoxo code to your account and use it during the time of checkout. This is something our team is currently working on and will be getting this feature live soon.
Yes, xoxo points and xoxo codes are usually valid for one year. You can view all such necessary details in the terms and condition section on the specific gift voucher page.
# Performance and Reliability
Source: https://help-plum.xoxoday.com/faqs/for-end-users/performance-and-reliability
Find answers to frequently asked questions about Plum's platform performance and reliability from an end user's view.
*Get quick answers to questions on Performance and Reliability.*
Yes. Xoxoday is engineered for scalability and reliability, ensuring smooth performance even during peak events like promotions, campaigns, or seasonal reward cycles. The platform currently supports 10,000+ transactions per minute and uses auto-scaling infrastructure to handle sudden surges without affecting user experience.
**How Xoxoday Manages Seasonal Spikes**
* **Scalable Architecture:** Built on containerized microservices, async messaging, and caching so each component can scale independently. Stateless services scale horizontally behind AWS Application Load Balancers. Kafka-backed queues absorb "flash-sale" traffic, while Redis caching avoids database hot spots.
* **High Availability & Reliability:** Active-active deployments across availability zones ensure continuity. Datastores run with replication, hourly snapshots, and disaster recovery (RTO/RPO of 120 minutes). Target uptime of 99.99%.
* **Performance Under Load:** Search & audit handled by managed Elasticsearch; reporting & analytics run on Redshift—keeping transactions fast. WAF and Cloudflare bot protection secure the perimeter against promo-related bot traffic.
* **Modern Scaling Practices:** Kubernetes-ready microservices with HPA/VPA pod autoscaling, cluster autoscaler, and safe rollout strategies (blue-green, canary). Rate-limiting, back-pressure, circuit breakers, and exponential backoff prevent overloads during sudden spikes.
* **Operational Playbook for Peak Events:** Capacity planning and load testing ahead of campaigns. Pre-scaling hot services and pre-warming caches. Partitioned messaging and tuned concurrency to maximize throughput. Real-time observability with APM and alerting (PagerDuty) for proactive autoscaling.
The Xoxoday reward payout platform is designed to scale with institutional needs, supporting high-volume reward distribution and automation. Through the self-service admin portal, administrators can upload reward recipient lists in bulk (up to 10,000 records in a single file) or send individual rewards. Automation capabilities include API-triggered sends, scheduling for time-based rewards, and rule-based workflows. Bulk delivery options via email, SMS, or shareable reward links streamline processes, making it ideal for recurring programs, cohort-based campaigns, or seasonal events.
## Reporting
The Xoxoday reward payout platform is designed to scale effortlessly with growing organizations. As a cloud-hosted, enterprise-grade solution, it can handle expanding user bases and higher transaction volumes without impacting performance. The platform supports a global rewards store that can be customized to meet organizational needs, and the catalog team ensures fast onboarding of new products and categories across geographies.
While adding new features or integrating with additional tools may require project-based implementation, core functions such as user onboarding, catalog scaling, and reward fulfillment operate autonomously and are built for enterprise-scale performance.
The customer incentive software is designed to support flexible event tracking mechanisms. To ensure accurate export of event data to your enterprise data warehouse, our team would need further clarity on event taxonomy, expected data granularity, and data warehouse integration requirements. Xoxoday can work with your IT/data teams to configure a compliant event capture and delivery workflow based on custom needs.
## Integration
Yes, transactions initiated through the Xoxoday reward marketplace can be configured to emit loyalty-related events. During the transaction creation process, you can pass an internal reference ID, which can then be included in the event payload and shared with existing or future loyalty systems. This enables a seamless connection between reward actions and loyalty event tracking, enhancing program integration.
## Reward Transaction
Yes, the Xoxoday reward payout platform supports automatic logging of all reward transactions into the appropriate ledgers. Each transaction is mapped based on its type—such as wallet recharges, redemptions, or refunds—and reflected accurately in the system. If required, the platform can be configured to reflect transactions across multiple ledgers depending on financial structure or reconciliation needs.
Absolutely. The Xoxoday customer incentive software offers a unified ledger view that includes all transaction types—redemptions, refunds, wallet top-ups—making reconciliation seamless. Admins can download these reports directly from the dashboard or retrieve them via API. This structure aligns with conventional MIS and reconciliation workflows, ensuring integration with existing financial protocols.
# SMS and WhatsApp Message Pricing
Source: https://help-plum.xoxoday.com/faqs/for-end-users/sms-and-whatsapp-message-pricing
Find answers to frequently asked questions about SMS and WhatsApp message pricing for reward notifications sent via Plum.
\*This document provides an overview of the per-message cost incurred by Xoxoday for sending SMS and WhatsApp notifications related to rewards delivery.
The cost varies by country and channel, as outlined below.\*
## SMS Cost (per message)
| **Country** | **Per SMS unit cost (USD)** | **Average Cost per message (USD)** |
| -------------------- | --------------------------- | ---------------------------------- |
| India | \$0.0015 | \$0.0030 |
| United States | \$0.0037 | \$0.0088 |
| Canada | \$0.0037 | \$0.0097 |
| South Africa | \$0.0229 | \$0.0481 |
| Maldives | \$0.0488 | \$0.0488 |
| Turkey | \$0.0270 | \$0.0514 |
| Thailand | \$0.0246 | \$0.0532 |
| Qatar | \$0.0477 | \$0.0562 |
| Denmark | \$0.0424 | \$0.0635 |
| Bahrain | \$0.0234 | \$0.0642 |
| United Kingdom | \$0.0288 | \$0.0658 |
| Guatemala | \$0.0455 | \$0.0683 |
| Australia | \$0.0298 | \$0.0835 |
| Brazil | \$0.0303 | \$0.0835 |
| South Korea | \$0.0325 | \$0.0858 |
| Poland | \$0.0381 | \$0.0890 |
| Puerto Rico | \$0.0418 | \$0.0977 |
| Singapore | \$0.0353 | \$0.1012 |
| Czech Republic | \$0.0548 | \$0.1048 |
| Saudi Arabia | \$0.0553 | \$0.1112 |
| Malta | \$0.0562 | \$0.1123 |
| Costa Rica | \$0.0418 | \$0.1228 |
| Kenya | \$0.0562 | \$0.1246 |
| China | \$0.0230 | \$0.1257 |
| Taiwan | \$0.0427 | \$0.1262 |
| Mexico | \$0.0442 | \$0.1298 |
| Portugal | \$0.0446 | \$0.1308 |
| Croatia | \$0.0513 | \$0.1367 |
| Greece | \$0.0548 | \$0.1385 |
| Ukraine | \$0.1249 | \$0.1400 |
| Sweden | \$0.0557 | \$0.1452 |
| Morocco | \$0.0565 | \$0.1471 |
| United Arab Emirates | \$0.0596 | \$0.1525 |
| Hong Kong | \$0.0539 | \$0.1540 |
| Italy | \$0.0603 | \$0.1632 |
| Slovakia | \$0.0556 | \$0.1668 |
| Finland | \$0.0708 | \$0.1680 |
| Japan | \$0.0696 | \$0.1696 |
| Switzerland | \$0.0585 | \$0.1708 |
| Argentina | \$0.0606 | \$0.1769 |
| Austria | \$0.0692 | \$0.1792 |
| Ireland | \$0.0640 | \$0.1803 |
| Romania | \$0.0625 | \$0.1811 |
| Spain | \$0.0637 | \$0.1834 |
| France | \$0.0659 | \$0.1841 |
| Bolivia | \$0.0640 | \$0.1851 |
| Netherlands | \$0.0845 | \$0.2127 |
| Malaysia | \$0.0778 | \$0.2142 |
| Belgium | \$0.0881 | \$0.2246 |
| New Zealand | \$0.0881 | \$0.2307 |
| Kuwait | \$0.0814 | \$0.2442 |
| Lebanon | \$0.0814 | \$0.2442 |
| Germany | \$0.0904 | \$0.2514 |
| Israel | \$0.0947 | \$0.2539 |
| Pakistan | \$0.1559 | \$0.2560 |
| Hungary | \$0.0873 | \$0.2600 |
| Bulgaria | \$0.1158 | \$0.2702 |
| Nepal | \$0.1133 | \$0.2833 |
| Mauritius | \$0.1302 | \$0.2864 |
| Oman | \$0.0955 | \$0.2864 |
| Egypt | \$0.1040 | \$0.3021 |
| Myanmar | \$0.1009 | \$0.3027 |
| Vietnam | \$0.1102 | \$0.3202 |
| Sri Lanka | \$0.1795 | \$0.3508 |
| Jordan | \$0.1337 | \$0.3674 |
| Philippines | \$0.1328 | \$0.3941 |
| Bangladesh | \$0.1729 | \$0.4593 |
| Indonesia | \$0.2490 | \$0.5452 |
**Notes:**
* SMS costs represent the **per-unit cost** and Average cost per message charged to Xoxoday.
* These rates may vary slightly depending on carrier and message length.
## WhatsApp cost (per message)
| **Country** | **WhatsApp Cost USD** |
| -------------------- | --------------------- |
| India | \$0.0020 |
| United States | \$0.0116 |
| Canada | \$0.0116 |
| South Africa | \$0.0068 |
| Maldives | \$0.0350 |
| Turkey | \$0.0075 |
| Thailand | \$0.0350 |
| Qatar | \$0.0151 |
| Denmark | \$0.0312 |
| Bahrain | \$0.0151 |
| United Kingdom | \$0.0296 |
| Guatemala | \$0.0365 |
| Australia | \$0.0350 |
| Brazil | \$0.0261 |
| South Korea | \$0.0350 |
| Poland | \$0.0457 |
| Puerto Rico | \$0.0365 |
| Singapore | \$0.0350 |
| Czech Republic | \$0.0457 |
| Saudi Arabia | \$0.0100 |
| Malta | \$0.0312 |
| Costa Rica | \$0.0365 |
| Kenya | \$0.0123 |
| China | \$0.0350 |
| Taiwan | \$0.0350 |
| Mexico | \$0.0200 |
| Portugal | \$0.0312 |
| Croatia | \$0.0457 |
| Greece | \$0.0312 |
| Ukraine | \$0.0457 |
| Sweden | \$0.0312 |
| Morocco | \$0.0123 |
| United Arab Emirates | \$0.0134 |
| Hong Kong | \$0.0350 |
| Italy | \$0.0311 |
| Slovakia | \$0.0457 |
| Finland | \$0.0312 |
| Japan | \$0.0350 |
| Switzerland | \$0.0312 |
| Argentina | \$0.0303 |
| Austria | \$0.0312 |
| Ireland | \$0.0312 |
| Romania | \$0.0457 |
| Spain | \$0.0283 |
| France | \$0.0564 |
| Bolivia | \$0.0365 |
| Netherlands | \$0.0587 |
| Malaysia | \$0.0120 |
| Belgium | \$0.0312 |
| New Zealand | \$0.0350 |
| Kuwait | \$0.0151 |
| Lebanon | \$0.0151 |
| Germany | \$0.0627 |
| Israel | \$0.0143 |
| Pakistan | \$0.0051 |
| Hungary | \$0.0457 |
| Bulgaria | \$0.0457 |
| Nepal | \$0.0350 |
| Mauritius | \$0.0123 |
| Oman | \$0.0151 |
| Egypt | \$0.0050 |
| Myanmar | \$0.0350 |
| Vietnam | \$0.0350 |
| Sri Lanka | \$0.0350 |
| Jordan | \$0.0151 |
| Philippines | \$0.0350 |
| Bangladesh | \$0.0350 |
| Indonesia | \$0.0249 |
**Notes:**
* WhatsApp cost is **per session message**, billed based on conversation category (utility, marketing, authentication).
* Prices are calculated based on Meta's Business API rates and Xoxoday's provider markup.
* The cost reflects **average per-message delivery** charges.
# For Merchants
Source: https://help-plum.xoxoday.com/faqs/offer-management/faqs-offer-management-for-merchants
Find answers to frequently asked questions about using Plum's Offers Management portal as a registered merchant.
*Get quick answers to questions on Merchant platform*
## Getting Started
The Xoxoday offer management solution is an end-to-end digital platform that allows banks, payment providers, and reward platforms to launch, manage, and track merchant-funded offers seamlessly — all in one place. Designed for scalability and speed, it enables businesses to deliver personalised, data-driven promotions to their customers without operational complexity. Built with enterprise-grade architecture, the platform simplifies offer creation, automates validation, and improves customer engagement through real-time analytics and omnichannel distribution.
Key highlights of the Xoxoday offer management solution include:
* **Comprehensive offer creation:** Merchants can create digital offers, vouchers, and discounts across categories like fixed-value, percentage-based, and product-specific promotions.
* **Omnichannel distribution:** Publish and share offers across websites, apps, emails, SMS, and social media with personalised URLs and QR codes.
* **Merchant & customer management:** Simplifies onboarding, approval workflows, and redemptions with secure role-based access and store-level PIN validation.
* **Smart analytics & reporting:** Access real-time dashboards to monitor redemptions, customer behaviour, and campaign ROI to make data-driven decisions.
* **Flexible deployment:** Available as a white-labelled, mobile-responsive solution supporting multi-language and multi-currency environments across 175+ countries.
* **Global scalability & security:** With 250+ integrations and enterprise-grade privacy settings, it guarantees seamless compatibility and compliance across diverse markets. Overall, the Xoxoday offer management solution streamlines how organisations deliver and measure promotional campaigns — reducing go-to-market time from weeks to minutes while driving higher engagement, conversions, and customer loyalty.
## Campaign & Offer Management
Yes, administrators can create test cohorts of users who receive the campaign offers before the public launch. This allows thorough validation of configurations, rules, and notifications. The pre-live testing environment helps ensure that everything functions smoothly once the campaign goes live, all within the Xoxoday platform for merchant funded offers.
Yes, the platform provides robust support for dynamic, event-based notifications. Campaign managers can personalize messages using variables like user name, voucher code, or expiry date. These messages can be sent via SMS, push notifications, or in-app alerts for events like reward claim confirmations, upcoming voucher expirations, or system-level updates. This ensures real-time, relevant communication tailored to each user through Xoxoday's merchant campaign management software.
Yes. The platform for merchant funded offers by Xoxoday allows users to fund one or multiple campaigns at the same time. Users can allocate funds to each campaign individually based on their preferences and specify the amount for each.
Yes. The merchant payout automation software by Xoxoday provides wallet debit APIs that allow users to initiate fund withdrawals to a nominated bank account. All debit transactions are recorded in the wallet for reconciliation and transparency.
Yes. Message template creation is supported, allowing campaign owners to standardize communications. However, prioritizing the delivery queue of messages is not currently available as a built-in feature. If required, this functionality can be developed through custom configuration on the Xoxoday platform for merchant funded offers.
Yes. The solution for merchant offer creation by Xoxoday enables businesses to apply pricing models such as subscription, time-based, or usage-based at the campaign or contract level. Once pricing definitions and dependencies are finalized, the system will be configured to support these billing structures.
Yes. The platform for merchant funded offers by Xoxoday allows users to build highly customized campaigns. Features include defining campaign periods, setting up recurring schedules (e.g., every day or every few hours), restricting access to exclusive customer segments, targeting specific SKUs or branches, and enabling task-based offer logic.
Yes. Grouping campaigns to assign multiple prizes with different claim limits and eligibility rules is supported.
Merchants can fully customize their offer templates to align with their brand's visual identity and campaign objectives. The platform enables selection from diverse coupon styles and layouts, allowing businesses to integrate their logo, brand colors, and messaging. It supports multiple offer types — such as fixed-value discounts, percentage-based offers, product-specific promotions, and free-format vouchers — ensuring every campaign looks and feels unique. These configurations can be adjusted instantly from the admin dashboard for greater creative flexibility.
The Xoxoday solution enables seamless omnichannel campaign distribution through websites, mobile apps, email, SMS, and social media. With just a few clicks, merchants can launch live campaigns and share personalized URLs or QR codes generated automatically by the system. These features make it easy for customers to discover, claim, and redeem offers both online and in-store, driving engagement and accelerating campaign visibility.
The Xoxoday merchant-funded offers platform allows businesses to share promotions directly with their existing customer base and publish them across partner ecosystems to reach new audiences. Once published, offers begin generating high-quality, engaged traffic within hours. With proven mechanics that enhance conversion rates, merchants can leverage audience segmentation and targeting capabilities to maximize visibility and customer acquisition at scale.
## Gift Voucher & Promo Codes
The Xoxoday platform for merchant funded offers supports a wide range of use cases for digital gift voucher creation and management. These include:
* Creating electronic gift cards for marketplaces and campaigns
* Uploading existing gift card voucher codes for use in promotions
* Digitalizing physical gift cards or vouchers
* Creating new digital gift cards based on inputs from previously issued ones
* Configuring flexible validity periods, including rounding validity to month-end
* Generating gift voucher codes and integrating with SMS/Email gateways to communicate these codes to customers
* Enabling self-upload of voucher code lists
* System-generated gift vouchers with preset denominations and code stock
* Distributing vouchers via a white-labeled marketplace
* Customizing marketplace selections and defining discounts
* Sending vouchers via email campaigns
* Defining campaign details and customer segments using customer data from retailers
The Xoxoday merchant reward program software facilitates bulk generation of gift voucher codes with user-defined denominations, code quantities, and downloadable reports. Additional capabilities include:
* Blocking and unblocking gift voucher codes
* Extending gift voucher validity
* Viewing and editing gift card configurations
* Downloading the list of voucher codes
* Publishing or unpublishing gift cards directly within the platform
Yes, the platform allows users to distribute vouchers in multiple ways: as single items, in bulk batches, or automatically triggered by specific events. This flexibility enables targeted and timely engagement across different customer segments using Xoxoday merchant campaign management software.
Yes, the Xoxoday platform for merchant reward programs supports both static and dynamic promo code configurations. Campaign creators can issue common codes for mass distribution or auto-generate unique, single-use codes. Promo codes can be configured to offer fixed discounts, percentage discounts, or product/SKU-specific offers. Additionally, users can apply these codes across specific stores, merchants, or audience groups with customized redemption rules.
The software for merchant reward programs enables merchants to list and sell vouchers from various categories directly on a digital rewards marketplace. Merchants gain access to a wide customer base and can promote their offerings through targeted campaigns. The solution also supports localized redemption, omnichannel voucher delivery, and real-time performance tracking, making it a scalable tool for merchant acquisition and engagement.
The solution for merchant offer creation includes a robust inventory management module. Merchants can efficiently organize vouchers by categories (e.g., food, fashion), voucher types (e.g., digital, physical), and industries. This structured view enhances visibility and control, allowing merchants to optimize voucher availability and marketing efforts.
Yes, the merchant payout automation software provides end-to-end order management capabilities. Merchants can track every stage of an order—whether it's pending, cancelled, or completed—through a centralized dashboard. This helps streamline operations, reduce manual overhead, and improve customer satisfaction through timely order handling.
The software for merchant campaigns offers advanced analytics tools that let merchants monitor transaction orders in real time. They can access key metrics such as sales volume, redemption rates, and campaign performance. This enables data-driven decisions, proactive stock adjustments, and strategic optimization of voucher promotions.
## Customer Engagement & Loyalty
The platform includes built-in customer engagement and loyalty tools to help merchants retain and grow their customer base. These include reward points, cashback campaigns, personalized offer targeting, referral programs, and automated notifications to keep customers engaged at every touchpoint. Merchants can also run segmented campaigns and track performance in real time to optimize retention strategies.
## Merchant Onboarding & Management
Yes, internal teams can easily onboard merchants by granting them access through the admin console. The system supports role-based access control, allowing internal users to define merchant permissions, assign contract terms, and manage activation workflows seamlessly.
Yes. The Xoxoday solution for merchant offer creation enables businesses to build and manage a vast merchant ecosystem across verticals such as:
* Travel, retail, wellness, healthcare, dining, and lifestyle
* Dynamic onboarding of merchants and partners
* Configurable discount structures tailored to different segments
* Customer access to exclusive benefits and reward privileges
This multi-segment approach enhances customer engagement and drives brand affinity while ensuring compliance with data privacy and security protocols.
## Financial & Wallet Management
Yes. The platform for merchant funded offers by Xoxoday supports both prefunded and postpaid charging models at the campaign or contract level. Users can define the applicable charging method, and the invoicing and settlement process will be configured accordingly.
Yes. The platform offers automated invoice generation and settlement capabilities. Users can view campaign-level billing details, download invoices, and settle payments through integrated payment gateways or wallet balances.
The Xoxoday wallet solution for merchant campaigns integrates with prefunding and invoicing systems to support multi-bank funding.
Merchants can:
* Nominate local, digital, or international banks to fund end-customer wallets.
* Use third-party payment gateway integration to manage prefunding workflows.
Yes. Through its third-party payment gateway integration, Xoxoday enables users to directly fund a customer wallet using their nominated bank account. This ensures seamless wallet top-ups while maintaining complete traceability and security across all funding actions.
## Reports and Analytics
The Xoxoday solution provides advanced reporting and analytics tools that deliver deep insights into campaign performance and return on investment. Merchants can monitor key metrics such as clicks, views, redemptions, and customer interactions in real time. The platform highlights friction points across the customer journey, enabling data-driven optimizations for higher engagement and better conversion rates. Additionally, dynamic dashboards and exportable reports make it easy to evaluate offer success and fine-tune future campaigns.
# For Admins
Source: https://help-plum.xoxoday.com/faqs/offer-management/offer-management-for-admins-faqs
Find answers to frequently asked questions about managing Plum's Offers Management portal as an account admin.
*Get quick answers to questions on Loopr Admin platform*
## Overview
The Xoxoday offer management solution is a comprehensive platform that helps businesses design, manage, and optimize their merchant-funded reward and offer programs. It supports a wide range of campaign types — from transactional incentives to behavioral rewards — ensuring flexibility and scalability.
Key capabilities include:
* **Flexible offer creation:** Design diverse reward programs aligned with your business objectives.
* **Behavioral targeting:** Encourage specific customer actions through personalized, data-driven offers.
* **Advanced analytics:** Gain full visibility into KPIs, ROI, and customer engagement metrics.
* **Continuous optimization:** Identify performance trends and make real-time adjustments to enhance outcomes.
* **Scalable infrastructure:** Manage multiple campaigns, merchants, and customer segments seamlessly across geographies.
## Campaign & Platform Management
Yes, Xoxoday's merchant offer automation platform supports role-based access control, including a Maker role. Users with this role can:
* Create and configure new campaigns
* Define budgets and allocate funds
* Generate and assign promo codes
All Maker actions require approval from an assigned Approver role before execution.
Yes, users can fully customize error messages specific to each campaign. This includes setting messaging for different failure scenarios such as invalid promo codes, expired offers, or redemption issues. Personalized error handling improves clarity and user experience across campaigns managed through Xoxoday merchant offer automation software.
Yes. The platform provides a Super Admin role with full access and control over all modules, user roles, campaigns, and configurations within the account.
Yes. User access can be restricted or customized based on company or group affiliation, ensuring proper governance and data visibility control.
The platform stands out for its end-to-end campaign and offer management capabilities, real-time reporting, seamless merchant onboarding, multi-segment support, automated communication, and advanced rule configuration. It enables businesses to build, scale, and optimize their offer ecosystem efficiently while ensuring compliance and data security.
Yes, Xoxoday's merchant campaign management software enables operations teams to:
* View voucher and promo code status
* Perform batch voucher recovery and extend expiry dates
* Generate additional promo codes for ongoing campaigns
* Create test codes for UAT or internal QA purposes
## Integration
The Xoxoday merchant-funded offers platform enables smooth integration between brands, merchants, and partner ecosystems, making it simple to publish and manage offers across multiple touchpoints.
Integration highlights:
* **Unified merchant portal:** Merchants can easily connect with brands to share discounts, promotions, and exclusive deals.
* **Automated publishing:** Offers appear instantly across connected digital storefronts or marketplaces, expanding merchant visibility.
* **SME enablement:** Simplifies onboarding for small and medium businesses, helping them reach customers more efficiently.
* **Seamless synchronization:** All offers remain up to date across channels, ensuring a consistent customer experience.
* **Enhanced reach:** Strengthens partnerships and boosts engagement through collaborative reward ecosystems.
## Reports
Xoxoday's platform for merchant funded offers provides users with the ability to view, generate, and export both transaction-level and summary reports through the Reports module.
The system supports:
* **Disbursement Reports:** Track the issuance of vouchers across customers.
* **Usage Reports:** Monitor redemptions, claim trends, and offer performance in real time.
* **Error Logs:** View logs such as failed shares, offer expiration, and redemption failures.
* **Filtering & Drill-Down:** Apply filters like date range, campaign, or store-level views for granular insights.
* **Export Options:** Reports can be downloaded in CSV or Excel formats for offline analysis or external integration.
# For End Users
Source: https://help-plum.xoxoday.com/faqs/offer-management/offer-management-for-customers-faqs
Find answers to frequently asked questions about browsing and redeeming offers as a customer on the Plum platform.
*Get quick answers for commonly asked questions on Loopr customer portal*
Yes, the platform supports multi-voucher payments, enabling customers to combine multiple vouchers in a single transaction. They can also redeem the entire transaction amount using vouchers alone, providing a seamless and flexible payment experience powered by Xoxoday's merchant payout automation software.
The platform for merchant funded offers provides users with an intuitive marketplace dashboard. Through this unified interface, users can browse all available vouchers, search specific vouchers by name or category, and access essential details like denominations, redemption instructions, and expiry dates. Users can also review their purchase history and monitor voucher delivery status, ensuring full transparency and control over their transactions.
# Privacy and Security
Source: https://help-plum.xoxoday.com/faqs/security-compliance/privacy-and-security
Find answers to frequently asked questions about Plum's privacy and security practices for protecting user data.
*Get quick answers to your questions relating to Privacy and Security on Xoxoday Plum.*
## Data
The Xoxoday rewards, incentives, and payout platform ensures secure, compliant, and globally accessible data hosting infrastructure through Amazon Web Services (AWS).
Key aspects of data storage include:
* **Primary Data Centers in the United States:** All customer data is stored on AWS cloud infrastructure, with primary hosting facilities located within the United States.
* **High Availability and Redundancy:** The platform leverages AWS's geographically distributed data centers to ensure business continuity, high availability, and disaster recovery.
* **ISO 27001 and SOC 2 Compliance:** All hosting infrastructure complies with globally recognized data protection and security standards.
* **Data Encryption:** Customer data is encrypted both in transit (via TLS 1.2) and at rest (via AES-256 encryption), ensuring maximum security.
* **Optional Regional Hosting:** For enterprise clients, data can also be hosted in other jurisdictions such as Singapore or the European Union, based on compliance and data residency requirements.
This architecture ensures that customer data is protected by rigorous physical, administrative, and technical safeguards as outlined by AWS.
Learn more: [https://aws.amazon.com/trust-center/data-center/our-controls/](https://aws.amazon.com/trust-center/data-center/our-controls/)
## Data, Policy and Privacy
Xoxoday follows a comprehensive, enterprise-grade information security framework to fully protect customer and end-user data.
Core data security practices:
* **Certifications:** ISO 27001, SOC 2 Type II, GDPR-compliant
* **Encryption:** AES-256 for data at rest; TLS 1.2+ for data in transit
* **Access Management:** Role-based access control (RBAC), Multi-factor authentication (MFA), Least privilege principle, Regular access reviews and logs
* **Cloud Infrastructure:** Hosted on AWS with VPC isolation and auto-scaling; Monitored using real-time security event tracking and anomaly detection
* **Data Retention & Deletion:** Aligned with client contracts, GDPR, and PIPL retention requirements
* **Audits & Testing:** Periodic internal audits, Annual third-party vulnerability assessments, Penetration testing and risk remediation workflows
* **Incident Management:** Structured incident response plan with SLA-bound notification and containment steps
* Ensures high availability, confidentiality, and integrity of data across all geographies and client use cases
All proprietary rights, including customizations built within the Xoxoday gift card marketplace or customer incentive software framework, remain with the platform provider. Clients may use these customizations as part of their subscription but do not acquire ownership of the platform's source code or IP.
The Xoxoday customer rewards platform keeps comprehensive logs of all payments, user actions, and redemptions, ensuring audit readiness, transparency, and compliance. Authorized administrators can access these records anytime via the reporting dashboard.
Xoxoday's privacy notice is publicly accessible via its official website and outlines its full commitment to data privacy and user rights.
Privacy notice includes:
* The types of personal data collected across services.
* Purposes for data processing (e.g., reward fulfillment, communication, analytics).
* Legal basis under GDPR, CCPA, and other applicable frameworks.
* User rights and instructions for submitting access or deletion requests.
* Contact details for privacy and data protection queries.
The privacy policy can be accessed on [https://www.xoxoday.com/security](https://www.xoxoday.com/security)
## AI Data Security
Yes, the Xoxoday rewards, incentives, and payout platform is designed with enterprise-grade data governance and compliance frameworks that support the removal or de-identification of sensitive data from AI models and systems, upon valid customer requests. Below is a breakdown by product.
* **Xoxoday Rewards, Incentives, and Payout Platform:** Data deletion upon request: The platform supports data subject rights under regulations like GDPR and CCPA, including the right to erasure ("right to be forgotten"), which applies to both structured and unstructured data—including inputs processed by AI systems. Model behavior isolation: LLM-based AI features do not persist user-specific training data beyond a session scope. Multi-tenant architecture ensures each client's data is logically segregated with encryption keys per tenant.
* **Employee Engagement Platform:** PII sanitization via content moderation: Em's AI scans and blocks the ingestion of personally identifiable information before it's processed by internal models. Consent-based AI processing allows user or admin-led revocation of processed data. Data control APIs allow admins to raise requests to remove engagement logs and user-generated content used in AI training.
* **Sales Incentives Platform:** Custom dashboards and reports built through natural language queries do not permanently train AI models on client data. These are temporarily cached and can be purged or redacted based on user role or admin request.
* **Loyalty Platform:** All customer data used in AI-driven segmentation or CLTV prediction models can be excluded or deleted upon request, thanks to configurable segmentation rules and data access policies.
* **Merchant Offer Platform:** AI modules that use personalization logic operate within secure, tenant-specific boundaries. Sensitive user or partner data involved in offer targeting can be excluded or wiped via admin-level operations or customer success support.
Xoxoday uses user input data to enhance feature performance and personalization, not to train generalized or foundational AI models.
* **Purpose:** Data is leveraged for smart recommendations, sentiment analysis, predictive analytics, and engagement insights.
* **Patterns used:** Recognition activity, reward redemptions, and survey feedback inform contextual outputs.
* **Personalization focus:** Inputs are applied to improve user-specific experiences within the platform.
* **Examples:** Skill mapping from recognition messages, reward suggestions based on behavior, and predictive trends for retention and engagement.
Yes. The platform provides real-time analytics and reporting with detailed user activity logs.
* AI Co-pilot tracks active users, pending nominations, award givers/receivers, budget utilization, and engagement reports
* Logs are time-bound and actionable, helping admins monitor AI usage over time
* Supports auditability and transparency, with timestamped logs available for compliance needs
Yes. Xoxoday's AI solutions follow responsible AI practices aligned with the NIST AI Risk Management Framework.
* Safety checks are built into AI features for content moderation, fraud detection, and decision transparency
* Technical safeguards include anomaly detection, rule-based overrides, and configurable escalation protocols
* Procedural controls allow workflows to be flagged, paused, or escalated for manual oversight
* AI outputs are designed for explainability, ensuring interpretability and auditability
Yes. The Xoxoday rewards, incentives, and payout platform is capable of processing Protected Health Information (PHI) in compliance with the Health Insurance Portability and Accountability Act (HIPAA) when required by the client's use case. The platform's design, infrastructure, and operational processes incorporate the necessary safeguards to protect sensitive healthcare data. This includes:
* **HIPAA compliance framework** – implemented controls and processes aligned with HIPAA's Privacy, Security, and Breach Notification Rules.
* **Data encryption** – PHI is encrypted both in transit (using TLS protocols) and at rest (using AES-256 encryption) to prevent unauthorized access.
* **Access control measures** – role-based access controls (RBAC) and multi-factor authentication (MFA) restrict PHI access to authorized personnel only.
* **Audit logging and monitoring** – comprehensive logging of system access, data interactions, and administrative actions for accountability and traceability.
* **Secure hosting environment** – cloud infrastructure hosted on ISO 27001 and SOC 2 Type 2 certified data centers with strong physical and network security controls.
* **Data segregation** – multi-tenant architecture with logical separation of client data, ensuring PHI is isolated and protected from other tenants.
* **Incident response protocols** – documented procedures to identify, contain, and report any potential data breaches in compliance with HIPAA requirements.
* **Business Associate Agreement (BAA)** – available for clients in the healthcare sector who require contractual assurance of HIPAA compliance.
## System Requirement
The system is designed to comply with all regulatory recordkeeping and reporting standards applicable to vendors in the rewards and incentive space. It incorporates robust mechanisms to ensure accurate documentation, timely reporting, and data traceability. Whether it's audit trails, transaction logs, or compliance records, the platform maintains structured data practices that fulfill regulatory obligations. If there are specific regulatory needs, the customer incentive software team is open to customizing workflows or discussing tailored solutions.
The platform upholds high standards of data confidentiality and privacy for research participants. It utilizes end-to-end encryption, RBAC, anonymization techniques, and audit logs to ensure all sensitive data, including that of human subjects, is secured and de-identified where required. By applying secure design principles and adhering to data protection frameworks, the solution guarantees compliance with confidentiality requirements for human research data.
The platform is not required to comply with PCI-DSS standards, as it does not collect, store, or process sensitive payment card data. Instead, all reward transactions are securely managed through the Xoxoday reward payout platform using industry-standard encryption and compliance protocols to ensure safety and integrity.
Yes, Xoxoday is built for scalability and is capable of handling large user bases and high transaction volumes. The system currently supports over 10,000 transactions per minute and includes auto-scaling infrastructure to handle demand surges during promotions, campaigns, or seasonal reward cycles.
Xoxoday's Platforms are engineered for horizontal scale and seasonal spikes in traffic. The core architecture uses containerized microservices, async messaging, and caching so components can scale independently and absorb spikes without blocking user flows. High-availability is built in with active-active deployment across availability zones, fronted by an AWS Application Load Balancer, plus managed Kafka, Redis, and Elasticsearch to decouple workloads and keep latency low during traffic surges. Datastores run with replication, snapshots, and DR, and the estate is continuously watched via APM/monitoring with PagerDuty alerts; target uptime is 99.99% with RTO/RPO of 120 minutes.
How we handle Seasonal Spikes in Traffic:
* Stateless services scale out behind the ALB; critical data is cached to avoid database hot spots.
* Kafka-backed queues smooth "flash-sale" style traffic; consumers scale horizontally to drain backlogs.
* Search & audit workloads are offloaded to managed Elasticsearch; analytics run on Redshift so reporting never competes with transactions.
* WAF/Bot protection (Cloudflare) shields the perimeter, important during promos when bot traffic rises.
**Kubernetes & modern scaling practices:** Our microservices are containerized and orchestrator-ready; for K8s-based deployments we apply industry patterns such as HPA/VPA for pod autoscaling, cluster autoscaler, Pod Disruption Budgets, readiness/liveness probes, and rolling/canary or blue-green rollouts. We also employ rate-limiting, back-pressure, circuit breakers, and exponential backoff to prevent thundering-herd effects.
**Operational playbook for peak events:** Capacity planning & load tests ahead of campaigns; pre-scaling hot services and pre-warming caches. Messaging partitioning & consumer concurrency tuning to raise throughput without impacting latency. Read replicas/replication on primary databases; hourly snapshots and cross-AZ DR safeguard data while allowing scale. Real-time observability with APM + alerting to spot hotspots early and autoscale safely.
## Legal
The Xoxoday gift card solution can support high-value physical Visa cards, but denomination limits vary by issuing partner and region. We recommend confirming availability and legal compliance during onboarding for denominations exceeding \$1,000.
## Security and Compliance
Xoxoday recognizes the importance of compliance in operating across multiple states, countries, and regulatory jurisdictions. Our approach combines governance, continuous monitoring, and proactive adaptation to ensure our Platforms remain compliant for all customers and users, regardless of their location.
* **Dedicated Compliance & Legal Teams:** We have specialized compliance, data privacy, and legal teams who continuously monitor state, federal, and international regulations affecting employment, data privacy, rewards, taxation, and payments. Regulations such as GDPR, CCPA/CPRA, HIPAA (where applicable), SOC 2, and ISO 27001 are embedded into our global frameworks.
* **Regulatory Intelligence & Partnerships:** Xoxoday leverages partnerships with audit firms, legal advisors, and compliance consultants in different geographies to stay ahead of state-specific regulatory updates. We subscribe to regulatory intelligence feeds and compliance monitoring services that track multi-state taxation, digital rewards governance, data residency, and employment-related laws.
* **Product Flexibility for Multi-State Needs:** Our Platforms allow localization of program rules, including tax handling, redemption catalogs, accrual structures, payout modes, and communication templates, ensuring adaptability to state or region-specific mandates. For payments and financial products, we integrate with licensed payment partners who are compliant with state money movement and tax reporting laws.
* **Global Best Practices in Data Privacy and Security Compliance:** We adopt Privacy by Design and Security by Default principles across all products. Frequent third-party audits, penetration testing, and certification renewals validate compliance against changing standards. Our multi-region hosting options (e.g., USA, Singapore, EU) ensure adherence to data residency and sovereignty requirements.
* **Customer Communication & Assurance:** Any regulatory changes impacting product usage are communicated through release notes, compliance updates, and customer success reviews. Clients benefit from configurable compliance controls such as audit trails, retention policies, and access management to meet their own internal governance needs.
By combining dedicated compliance governance, expert partnerships, flexible platform configurations, and global data privacy and security best practices, Xoxoday ensures that multi-state and multi-location users are supported in a compliant, secure, and future-ready manner.
## Security Requirement
Yes. The platform securely manages confidential and sensitive business data as part of its operations.
Data types handled include:
* Employee and customer PII (names, emails, contact details)
* Transaction and redemption history
* Financial identifiers for payouts and prepaid cards
Security and compliance measures include:
* Enterprise-grade encryption for data at rest and in transit
* Role-based access control (RBAC)
* Secure API integrations with audit logs
* Compliance with GDPR and relevant local data privacy laws
* Regular third-party audits to prevent unauthorized access and mitigate risks
## Technical Requirement
No. All Xoxoday solutions are cloud-based and accessible via secure HTTPS connections, without requiring clients to host virtual appliances or modify firewall rules.
* Global rewards marketplace & payout platform: Fully cloud-hosted, with optional on-premise deployment available for highly regulated environments.
* Employee engagement & recognition platform: Delivered as SaaS, accessible via browsers and mobile apps with no additional network configuration.
* Sales commission & incentive management system: Cloud-native, integrating securely with CRM and HRMS platforms via APIs.
* Customer loyalty management solution: Entirely online, eliminating the need for local hosting or infrastructure.
* Merchant-funded offers & promotion engine: Cloud-based with secure API access for seamless partner integrations.
Yes, but only as required to deliver contracted services, with strict role-based access controls and full GDPR compliance.
* Global rewards marketplace & payout platform: Uses recipient names, emails, and transaction data solely to process and deliver rewards.
* Employee engagement & recognition platform: Stores and processes employee identifiers, email addresses, and engagement activity to support recognition and surveys.
* Sales commission & incentive management system: Handles sales team identifiers, performance metrics, and payout details to calculate and distribute incentives.
* Customer loyalty management solution: Manages loyalty member data including profiles, points balances, and redemption history.
* Merchant-funded offers & promotion engine: Maintains merchant details, customer segment data, and redemption records for campaign management.
Yes. All Xoxoday solutions operate under a corporate-level Business Continuity Plan owned by senior management and tested annually.
* Global rewards marketplace and payout platform: Includes continuity procedures for reward delivery, catalog access, and payment processing.
* Employee engagement and recognition platform: Ensures uninterrupted engagement, recognition, and survey operations during disruptions.
* Sales commission and incentive management system: Maintains continuous access to commission tracking, incentive calculations, and reporting.
* Customer loyalty management solution: Keeps loyalty enrolment, accrual, and redemption systems available in crisis scenarios.
* Merchant-funded offers and promotion engine: Provides continuity for merchant offer creation, validation, and redemption tracking during outages.
Yes. Xoxoday has a corporate Disaster Recovery Plan owned by the Information Security team and tested regularly to meet RTO/RPO objectives.
* Global rewards marketplace and payout platform: Covers restoration of transaction processing, catalog services, and payment integrations.
* Employee engagement and recognition platform: Ensures rapid recovery of recognition data, engagement analytics, and survey records.
* Sales commission and incentive management system: Restores commission plans, sales performance data, and payout schedules promptly after incidents.
* Customer loyalty management solution: Recovers loyalty member accounts, points balances, and redemption records with minimal downtime.
* Merchant-funded offers and promotion engine: Brings back merchant campaign data, offer rules, and redemption history in line with recovery targets.
## Record Creation
Yes. The Xoxoday gift card solution maintains detailed records of credit card issuance, including information on both issuers and recipients. These records are encrypted and accessible only by authorized personnel, ensuring complete confidentiality of participant data while supporting compliance and audit requirements.
Yes, the Xoxoday customer rewards platform enables administrators to flag studies or projects as exempt from collecting personally identifiable information (PII), such as names or SSNs. These exemption flags are configurable based on user roles, allowing secure, role-specific access while ensuring compliance with research privacy protocols and institutional review board (IRB) requirements.
The Xoxoday reward payout platform supports the secure upload and attachment of IRS Form W-9 during the input of subject information. This ensures streamlined compliance with U.S. tax documentation requirements, particularly for human subject payments that require IRS reporting, such as 1099 filings.
Yes, the Xoxoday survey rewards platform includes geo-tagging capabilities that allow administrators to classify and flag studies based on their geographic scope. This supports accurate reporting, compliance, and operational tracking for global studies conducted outside the U.S.
The platform is designed to support selective externalization of back-office functions via APIs. Transaction data necessary for reporting and reconciliation can be programmatically accessed using secure APIs provided by the Xoxoday reward payout platform.
Yes. Xoxoday supports on-premise deployments and can host the reward portal within the client's internal network. This deployment option ensures full control over infrastructure, data governance, and security settings. Our implementation team will work closely with your IT and security stakeholders to align with existing policies and protocols, while ensuring seamless integration and compliance throughout the deployment process.
Yes. Xoxoday plays a direct role in mission-critical engagement and incentive workflows for enterprises, SMBs, and global organizations:
* Powers customer loyalty programs, employee recognition programs, sales and channel incentives, and instant payout delivery, all of which are essential for business continuity.
* Delivers time-sensitive reward redemptions for events like sales milestones, festive gifting, employee anniversaries, and customer retention campaigns.
* Supports multi-region and multi-currency operations, ensuring that global incentive programs remain uninterrupted.
* Operates on high-availability infrastructure with redundancy, minimizing downtime risk.
* Without Xoxoday, businesses would face disruptions in engagement programs, potentially leading to reduced retention, sales performance, and customer satisfaction.
No. Xoxoday does not process, store, or transmit credit card information. It operates as a digital rewards and incentives engine and does not serve as a payment gateway or financial processing tool.
## Xoxolink
Xoxoday adheres to all major global regulatory standards. It maintains comprehensive audit trails, logs, and exportable reports for every transaction. Custom reports can be scheduled or generated on-demand to support compliance with tax, financial, or internal audit policies.
# Account Verification
Source: https://help-plum.xoxoday.com/getting-started/for-admins/account-verification/account-verification-overview
*In this article, you'll see the information you need to complete the KYB verification step to kick start rewarding journey with Xoxoday.* *Everything you need to complete the KYB verification step and kick start your rewarding journey with Xoxoday.* *Everything you need to complete the KYB verification step and kick start your rewarding journey with Xoxoday.*
## What is Account Verification?
Xoxoday, as a Fintech company, verifies businesses and gift card usage to comply with regulations. Plum's account verification ensures we understand your business and intended use case to provide tailored assistance.
***
## Verification Process
Provide the necessary business details via the Plum Admin Panel.
Our compliance team reviews your submission within **2 working days** and may request additional information if needed.
Once all details are gathered, the compliance team classifies your use case.
Upon use case determination, the catalog team maps available products for immediate redemption.
Expect an acknowledgement email within **2 hours** of submission. Any additional information needed will be requested via email.
***
## Use Case Classification
Once verified, your account is classified into one of the following use cases, which determines the catalog products available to you:
* **Regular Business** — Can procure vouchers from the catalog, excluding Amazon and Open Loop cards. Contact your Account Executive or [cs@xoxoday.com](mailto:cs@xoxoday.com) to request access to these cards.
* **Resellers (B2B & B2C)** — Can purchase closed-loop cards, except for brands explicitly prohibiting resellers and Amazon/Open-Loop cards.
* **Crypto** — Can only procure closed-loop cards and brands that permit crypto use cases.
***
## Escalation Matrix
For anything related to account verification, reach out through the appropriate level:
| Level | Designation | Email |
| ------- | --------------------- | ------------------------------------------------- |
| Level 1 | Customer Success Team | [cs@xoxoday.com](mailto:cs@xoxoday.com) |
| Level 2 | Implementation Lead | [damodar@xoxoday.com](mailto:damodar@xoxoday.com) |
| Level 3 | Customer Success Head | [kailash@xoxoday.com](mailto:kailash@xoxoday.com) |
***
# Submitting Brand KYC
Source: https://help-plum.xoxoday.com/getting-started/for-admins/account-verification/submitting-brand-kyc-amazon-india-and-mastercard
Some brands and reward options require additional **KYC** or **KYB (Know Your Business)** verification before you can issue rewards through Plum.
The verification required depends on the reward you want to issue:
| Verification | Applicable rewards |
| :------------------------------------------- | :------------------------------------------------------------------------------- |
| **Amazon India Brand KYC** | Amazon India gift cards |
| **Amazon Global Brand KYC** | Amazon gift cards in applicable international markets |
| **Prepaid Instruments & Digital Wallet KYB** | Visa/Mastercard prepaid instruments, PayPal, Venmo, and other applicable rewards |
## Access the Verification Form
1. Sign in to your **Plum Admin Portal**.
2. Go to **Admins**.
3. Click the **Settings** icon.
4. Select **Verifications**.
5. Select the verification applicable to the reward you want to issue.
Before you begin, make sure you have the required company information and supporting documents ready.
***
# Amazon India Brand KYC
Amazon requires additional information about your organisation and reward programme for **security and compliance purposes** before you can issue Amazon India gift cards.
### Information required
You will need to provide:
* **Registered Email ID** – Email address registered with your Plum account.
* **Company Legal Name** – Registered legal name of your organisation.
* **Business Category** – Select the category that best describes your organisation.
* **Reward Use Case** – Select how you plan to use the Amazon gift cards.
* **Annual Reward Spend** – Estimated annual amount you plan to spend on rewards.
* **Reward Programme Description and Goals** – Briefly explain what the programme is, who it is intended for, and its objective.
### Documents required
| Requirement | Accepted document |
| :---------------------------------- | :---------------------------------------------------------- |
| **Business Establishment Document** | Company Incorporation/Registration Certificate |
| **Company ID Document** | GST Registration Certificate or PAN Card |
| **Business Address Proof** | Telephone Bill, Electricity Bill, or Water Bill |
| **Company Declaration** | Declaration on company letterhead using the sample provided |
### Complete the verification
Enter the required information, upload the supporting documents, and click **Submit**.
Make sure that:
* The company name matches your official registration documents.
* All uploaded documents are valid and legible.
* The information in the form is consistent with the supporting documents.
* The declaration is prepared using the required format.
**Additional requirements for consumer and marketing use cases**
If you plan to use Amazon gift cards for **consumer incentives or marketing campaigns**, you may also need to submit your marketing collateral.
Make sure the collateral follows Amazon's applicable guidelines before submitting it for review.
You will also need to prepare an **undertaking document on your company letterhead** using the sample undertaking provided as part of the verification process.
***
# Amazon Global Brand KYC
Amazon Global KYC requires additional information about your organisation and reward program before you can issue Amazon gift cards in applicable international markets.
### Information required
You will need to provide:
* **Registered Email ID**
* **Company Legal Name**
* **Countries where you plan to distribute rewards**
* **Business Category**
* **Company Website**
* **Annual Reward Spend** in USD
* **Applicable Business Activities**
* **Reward Programme Description and Goals**
* **Programme Start Date**
* **Reward Use Case**
You may also be asked whether the Amazon gift cards will be distributed **exclusively within the US**.
### Complete the verification
Enter the required information and review your responses before clicking **Submit**.
Make sure the company and programme information provided in the form is accurate and consistent with your organisation's details.
***
# Prepaid Instruments and Digital Wallet KYB
KYB verification is required for certain **Visa/Mastercard prepaid instruments** and **digital wallet rewards such as PayPal and Venmo**.
The information submitted through the form may be shared with the relevant card issuers and reward partners for review and approval.
### Information required
You will need to provide details about both your organisation and the person submitting the form:
* **Registered Email ID**
* **Name**
* **Designation/Title**
* **Organisation Legal Name**
* **Company Brand Name**
* **Number of Employees**
* **Type of Business**
* **Tax ID** – TAX, VAT, EIN, GST, or other applicable tax identification number
* **Official Website URL**
* **Country of Business Formation**
* **Date of Business Formation**
* **Lawsuits or Regulatory Actions** – Indicate whether the company is currently or has previously been subject to any lawsuits or regulatory actions.
### Complete the verification
1. Enter the required user and business information.
2. Click **Next** to proceed through the form.
3. Complete all remaining sections.
4. Review the information you have provided.
5. Click **Apply for Verification**.
Ensure that all information submitted is complete and accurate. The information may be shared with the respective card issuers and partners as part of the approval process.
***
# What happens after you submit the form?
Once you submit the verification form, the relevant brand or issuing partner reviews the information and documents provided.
The typical timelines are:
* **Amazon India Brand KYC:** 3–4 business days
* **Prepaid Instruments and Digital Wallet KYB:** 2–4 business days
* **Amazon Global Brand KYC:** The timeline may vary depending on the market and programme details.
The verification may take longer if additional information or documents are required.
Once your verification is approved, the applicable reward options will become available for issuance through Plum.
## Need Help?
If you need assistance with the verification process, contact [**cs@xoxoday.com**](mailto:cs@xoxoday.com) or reach out to your designated SPOC.
# Submitting Verification Detail
Source: https://help-plum.xoxoday.com/getting-started/for-admins/account-verification/submitting-verification-details
*In this article, you'll see the information you need to complete the KYB verification step to kick start rewarding journey with Xoxoday!*
## Steps and some pre-requisites
Start by logging in to the [Admin Dashboard](https://stores.xoxoday.com/marketplace/login)
Here are some of the things you'll need to keep handy:
Details of the company as follows:
| Requirement | Details |
| :---------------------- | :--------------------------------------------------------------------------------------------------------------------------- |
| **Basic Admin Details** | Name, Email address, and a valid Phone number (you'll receive an OTP here). |
| **Company Details** | Registered Business Name, Country of Registration, Registered Identification number (Example: GST, TAX ID, EIN, or DUNS etc) |
| **Company Address** | Company's registered address. |
KYB details must be completed before funds can be added or rewards can be sent.
***
## Step-by-step guide
Alternatively, for select geographies, we can fetch company details based on the name input. This feature is currently supported only for customers in India.
***
## What to expect next
Expect an acknowledgement email within 2 hours. Our compliance team will then verify your details for account approval. Any additional information needed will be requested via email.
# Updating Billing Address
Source: https://help-plum.xoxoday.com/getting-started/for-admins/changing-billing-address-during-wallet-recharge
This article explains how administrators can **add or update the billing address while adding funds to a client's Plum wallet**. The billing address selected during the transaction is used on the **Proforma Invoice** and **Invoice PDF** generated for the wallet recharge.
# Manage Billing Addresses
The Account Page allows you to view, add, update, or remove billing addresses associated with your Plum account.
To access the billing address settings, navigate to **Settings > Account & Billing Address** and click **Change**.
## Add a Billing Address
To add a new billing address:
1. Navigate to **Settings > Account & Billing Address**.
2. Click **Change**.
3. Click **Add New**.
4. Enter the required billing address details:
* **GST/Identification Number:** Mandatory for India and optional for other countries.
* **Country, State, and City**
* **Billing Address**
5. Click **Save**.
The new billing address is added to your account.
***
## Edit a Billing Address
To update an existing billing address:
1. Navigate to **Settings > Account >Billing Address**.
2. Click on Change
3. Select the billing address you want to update.
4. Click the **Edit** icon.
5. Update the required details:
* **GST/Identification Number:** Mandatory for India and optional for other countries.
* **Country, State, and City**
* **Billing Address**
6. Click **Update**.
The updated billing address is saved to your account.
***
## Remove a Billing Address
To remove an existing billing address:
1. Select the billing address you want to remove.
2. Click the **Remove/Delete** icon.
3. Confirm the deletion.
The selected billing address is removed from your account.
## Update an Existing Billing Address
You can update or add a billing address while adding funds to your Plum wallet. The selected billing address is used on the invoice generated for the transaction.
To update the billing address while adding funds:
1. Navigate to **Payments > Wallet Balance** in the Plum Admin Dashboard.
2. Click **View Funds**.
3. On the **Add Funds to Wallet** screen, locate the **Billing Details** section.
4. Click **Change**.
5. Update the required billing details:
* **Billing Address**
* **GST/Identification Number:** Mandatory for India and optional for other countries.
* **Country, State, and City**
* **Client POC, Email, and Phone:** These details are auto-filled based on the Admin's information.
6. Click **Update** and proceed.
The selected billing address is included on the invoice generated for the transaction.
## Add a New Billing Address
You can also add a new billing address while adding funds to the wallet.
To add a new billing address:
1. On the **Add Funds to Wallet** screen, navigate to the **Billing Details** section.
2. Click **Add New**.
3. Enter the required billing details:
* **GST/Identification Number:** Mandatory for India and optional for other countries.
* **Country, State, and City**
* **Billing Address**
* **Client POC, Email, and Phone:** These details are auto-filled based on the Admin's information.
4. Click **Save**.
The new billing address is saved and becomes available for selection when adding funds to the wallet.
Feedback or Questions: Reach out to [**cs@xoxoday.com**](mailto:cs@xoxoday.com)
# Signing Up
Source: https://help-plum.xoxoday.com/getting-started/for-admins/signing-up
*Follow the step-by-step instructions to create your Xoxoday business account.*
We have enhanced the sign-up flow to improve usability and engagement, ensuring a seamless experience. This guide will walk you through the process.
## Prerequisites
Before starting, ensure you have the following information ready:
* **Full Name**
* **Company Name**
* **Business Email Address**
* **Password**
* Business Email Address
* Password
| Requirement | Details |
| -------------------------- | -------------------------------------- |
| **Full Name** | Your first and last name |
| **Company Name** | Your organization's name |
| **Business Email Address** | A valid company email (not personal) |
| **Password** | Min. 8 characters including one number |
***
## Creating Your Account
Open your browser and navigate to [https://stores.xoxoday.com/admin/signup](https://stores.xoxoday.com/admin/signup).
Enter your **Full Name** and **Business Email Address**, then submit the information to proceed.
Check your inbox for an OTP sent to your registered email. Enter the OTP on the sign-up page to validate your email address.
Create a strong password (at least 8 characters, including one numeric digit) and confirm it to complete this step.
Specify the number of employees in your organization.
***
Need help? Contact our support team at [**cs@xoxoday.com**](mailto:cs@xoxoday.com)
# Funding the Account
Source: https://help-plum.xoxoday.com/getting-started/for-admins/wallet-management/funding-the-account
To get started with Plum, you need to add funds to your **Company Wallet**. The available wallet balance is used to fund rewards sent through your Plum account.
Once the payment is made, kindly **share the payment receipt** via email. After verification by our Finance team, the funds will be credited to your Xoxoday wallet within **2–3 business days**.
You can view the status in the reports section. It might take a couple of minutes to show up on the dashboard.
Feedback or Questions: Reach out to [**cs@xoxoday.com**](mailto:cs@xoxoday.com)
# Payment Methods
Source: https://help-plum.xoxoday.com/getting-started/for-admins/wallet-management/payment-methods
*Learn about different ways to fund your Plum account.*
Plum supports multiple ways for you to fund your account. Below is a list of a few, please select as applicable:
***
## 1. Online Payment Methods
Online Payment Methods using Credit Card & Debit Card.
### Fund addition for INR Accounts
Online options available - UPI, Credit/Debit Card, Net banking, e-Wallets and more.
***
## 2. Pay Offline
### Create an Invoice
An invoice (or pre-payment invoice) is a great way if you want to get your finance team involved in making the payment. Here's how to do this:
Input the desired amount in your base currency click "Create Invoice" to proceed.
Enter the Purchase Order Number (Optional) and Purchase Order Date using the calendar icon.
The selected date is stored in the system and displayed clearly on the invoice template, giving finance and procurement teams the visibility they need for smooth tracking and reporting.
That's it! The invoice will be sent to your email address.
After the payment is made, share the details with [ar@xoxoday.com](mailto:ar@xoxoday.com). The finance team will verify the details, and after the verification, the funds will be credited to your account.
**Pro tip**
* You can optionally enter a PO number at the time of generating the invoice.
* You can view the status in the reports section. It might take a couple of minutes to show up on the dashboard.
***
Feedback or Questions: Reach out to [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Wallet Management
Source: https://help-plum.xoxoday.com/getting-started/for-admins/wallet-management/wallet-management-overview
Super Admins can manage the organization's pre-funded Plum wallet. You can add funds to the wallet and use the available balance to send rewards.
## Base Currency
The **Base Currency** is the currency in which your organisation's wallet, funds, and transactions are maintained.
The Base Currency is selected by the **Super Admin** when the account is created and is used as the default currency for activities such as adding funds and redeeming rewards.
To view your account's Base Currency:
1. Navigate to **Settings**.
2. Select **Account**.
3. View the configured **Base Currency**.
Plum supports major currencies, allowing Super Admins to select the appropriate currency for their organization when creating a business account.
## Pre-funded Wallet
Plum uses a **pre-funded wallet** to process rewards. You must add funds to the wallet before you can send rewards.
Super Admins can add other Admins to help manage the Plum account and send rewards.
## Add Funds to the Wallet
To add funds to your Plum wallet:
1. Sign in to your **Plum Admin Dashboard**.
2. Navigate to **Payments** from the left navigation menu
3. Click **Add Funds to Wallet**.
4. Enter the amount you want to add in your **Base Currency**.
5. Complete the payment using the designed payment method.
Once the payment is successfully completed, the funds are added to the company wallet.
## Payment Methods
Plum supports multiple payment methods for adding funds to your wallet.
Check out this article to learn all payment methods [Payment Methods.](/getting-started/for-admins/wallet-management/payment-methods)
# Redeem Reward Link
Source: https://help-plum.xoxoday.com/getting-started/for-end-users/how-to-redeem/redeem-reward-link
Learn how to redeem a reward link you've received as an end user on Plum, from opening the link to claiming your reward.
Learn how to redeem a Reward Link as an end user.
Click "**Redeem Now**" when you get the email about the reward. You'll be taken to a page where all of your vouchers are listed.
On click of '**Redeem Now**', you will see a landing page. Here, you can view your reward value and the link validity.
Pick the brand you like the most. Click on **Send OTP.**
Enter your information, either your email address or phone number, if asked to get vouchers. You'll be asked to enter the OTP for verification purposes.
You can also choose other gift cards by clicking on the cross. This will take you back to the previous page so you can use another gift card.
Once you have the code, you can copy it or click the "**Send me a copy**" button to send it to your email or phone number.
***
## HRMS such as Darwinbox, Here is how you can redeem
**Here are the steps to redeem:**
Under "**My Access**", click the "**Recognition**" tile.
Within the "**Recognition Overview**", you check your accumulated reward points balance.
Click **"Redeem".**
You will now be redirected to the Plum Storefront via single sign-on. You can check your points balance in the top right corner of the page.
Choose any experience, gift vouchers, etc, from categories based on location.Click on "**Add to cart**" on the selected option. Please read the item's Terms and Conditions, Validity, and Description before proceeding.
After adding all the items to the cart, click on the cart icon to proceed with the purchase. Verify your items and click on "**Proceed to Checkout**".
***
## If you are using SAP® SuccessFactors or a custom platform, here is how you can redeem
Under the **"Home"** tab, click the **"Compensation"** module.
You can check your accumulated reward points under "**My Team**".
Now, click **"Redeem"**; with a single sign-on, you will be redirected to the Plum Storefront.
Choose any experience, gift vouchers, etc, from 30+ categories based on location.
Click on **"Add to cart"** on the selected option.
Please read the item's Terms and Conditions, Validity, and Description before proceeding.
After adding all the items to the cart, click on the cart icon to proceed with the purchase. Verify your items and click on **"Proceed to Checkout".**
***
## How to redeem Mastercard/Virtual Visa Card using Reward Code/Reward Points
**To redeem your Mastercard/Virtual Visa Card, follow these steps below:**
*
Visit [**https://stores.xoxoday.com/**](https://stores.xoxoday.com/).
Select the Product of your choice and choose the "**Guest Checkout**" option on the landing page.
Enter a valid email ID to proceed as a guest user.
You can successfully place an order by choosing the Guest Checkout option.
Mention your name, email, dialling code, and phone number. Before continuing with the purchase, an OTP will be sent to the mobile number provided.
Select the option to use available reward points for the purchase.
If you have a gift card, add the gift card code and click on **"Apply"**.
You can also pay the excess amount by selecting the option to pay via "Credit Card" and choosing the card of your choice.
Click "**Pay Now**" to continue with the selected payment mode.
# Redeem Reward Points
Source: https://help-plum.xoxoday.com/getting-started/for-end-users/how-to-redeem/redeem-reward-points
Learn how to redeem the reward points you've received as an end user on Plum, from browsing options to confirming your choice.
*Learn how to redeem Reward Points as an end user.*
Upon registration, you will receive mail from Xoxoday to set up your account as shown below.
***
Your reward points balance is shown at the top right corner of the page.
Choose any gift vouchers, etc, from the different categories shown.
Click on "**Add to cart**" on the selected brand.
Once you add the product to your card, "Add to cart" button will show the "**Go to Cart**" option making the journey simple. You can click on the "**Go to Cart**" button.
You can also "**Go to cart**" by clicking on the cart icon in the top right corner beside the profile.
Please read the Terms and Conditions, Validity, and Description of the item before proceeding.
Click on "**Checkout Now**" to move to the check-out page.
Enter your name, email, dialing code, and phone number. An OTP will also be sent to the mobile number provided before continuing with the purchase.
The user will be able to see the reward point balance and ask if he wants to use the points for the order payment.
# Redeem Reward Code
Source: https://help-plum.xoxoday.com/getting-started/for-end-users/how-to-redeem/reward-code
Learn how to redeem a reward code you've received as an end user on Plum, step by step from entry to confirmation.
*Learn how to redeem your reward code on the Plum Marketplace.*
The user has to visit [stores.xoxoday.com](https://stores.xoxoday.com/) to redeem the code.
Users can redeem reward codes through Guest Checkout. You don't have to log in or sign up.
**Things to Remember:**
* Reward code can be used within the validity period only.
* Partial redemptions for Reward codes are allowed and can be used until the code balance is exhausted.
* You can choose multiple codes (**Up to 10 reward codes in a single transaction**) to order as long as the amount does not exceed your code Balance.
***
## Redeeming Reward Codes
On receiving the reward email, click on "**Redeem Now**" as shown below. You will be redirected to our marketplace to consume the code.
Choose any gift vouchers or search your favorite brand from 30+ categories and 21,000+ branded options and click "**Add to Cart**".
Visit the cart or click on "**Go to Cart**" and click on "**Checkout Now**".
Under the Payment Details Card, select '**Click here**' and paste your Reward Code.
You can paste code in the input text field. You can apply up to 10 valid codes against a single order. Once done, click '**Proceed**' to move ahead.
Enter your **name, email, dialling code, and phone number.** An OTP will also be sent to the mobile number provided before continuing with the purchase.
Enter your contact details and click 'Proceed' to check out. You will get an OTP for confirmation in the email.
* You can also pay the excess amount with credit/debit cards or net banking.
* You'll receive an order delivery email with the necessary details.
***
We regret that the reward code cannot be exchanged for cash. If you face a code error, kindly share a screenshot of the code and the error with us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Sign Up
Source: https://help-plum.xoxoday.com/getting-started/for-end-users/signing-up-logging-in
Learn how to sign up and log in as an end user on Plum so you can view and redeem the rewards you've received.
*How to Login/Signup to the Storefront?*
***
## Sign up to Plum Storefront
Go to [https://stores.xoxoday.com/](https://stores.xoxoday.com/)companyname.
Login using your registered email address and password.
You have successfully signed up for Xoxoday Plum.
**Note:** Users with a valid Reward Code do not need login credentials. During checkout, they can continue as a guest and redeem the code directly.
* For Signing up, select the signup option from the accounts dropdown.
Provide necessary information such as name, email address, country etc to proceed with the signup process.
Congratulations! You have successfully signed up for Xoxoday Plum.
**Note:** Users with a valid Reward Code need not have login credentials. During checkout, they can continue as guest users and redeem the Reward Code.
***
## Forgot your password?
Visit [https://stores.xoxoday.com/vouchers](https://stores.xoxoday.com/nreachtech/vouchers/)
Enter your registered email ID and click "**Forgot password**".
A reset password link is sent to the email ID provided. Click on the link and set a password.
You will now be able to log into the portal with a new password.
**Note:** Any users with a valid Reward Code need not have login credentials. During the checkout, continue as a guest user and redeem the Reward Code.
***
## Logging in for the first time
First-time users, please follow the steps below:
Go to [stores.xoxoday.com](https://stores.xoxoday.com/)/companyname, click on the login page and select sign up and this opens the Sign-up form as below.
Enter the required information, such as your "Name", "Email ID", "Country Code for Phone Number", and "Password". You will receive an OTP to verify and you will be successfully signed up.
***
Feedback or Questions: Reach out to [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Overview
Source: https://help-plum.xoxoday.com/getting-started/overview
Get an overview of Plum, Xoxoday's rewards platform, and learn how admins send gift cards, reward links, codes, and points.
Welcome to Xoxoday Plum's Help Center — here you'll find comprehensive guides and documentation to help you get started with Plum as quickly as possible. You can also find self-help guides, tips, and tricks. Let's jump right in.
# Account Set up
First things first — below is a collection of articles that will help you get up and running in no time and get you acquainted with Xoxoday Plum's features in an instant!
Here is a collection of articles that will get you started with your Xoxoday plum account:
# Account Verification
As part of regulatory requirements, customers need to complete a quick verification step as part of the KYB requirements for bands.
## KYB Verification
Head over to this article [Submitting Verification Details](/getting-started/for-admins/account-verification/submitting-verification-details) to know everything about the KYB verification steps.
# Add Funds
Xoxoday Plum works on a pre-funded wallet that gives you total control over your spending and budget for all your rewards.
## Wallet Management
Xoxoday operates on a pre-funded wallet. Head over to [Recharge & Wallet Management](/getting-started/for-admins/wallet-management/wallet-management-overview) to know everything about managing your Xoxoday wallet.
# Rewards
Distribute rewards and incentives the way you want seamlessly and quickly. First things first, let's start with different modes of reward in Xoxoday Plum.
## Modes of Reward
Plum lets you reward anyone, anywhere, in your own special way as a Code, a Link or as a Point. [Click here](/send-rewards/reward-modes/reward-modes-types-overview) to learn all about it.
## Reward Code
Reward Code provides a fast and secure method to send unique reward codes to participants. Learn more here [Reward Code](/send-rewards/reward-code/reward-code-overview)
## Reward Link
A unique reward link that can be sent to each recipient and provide a one-click redemption experience. [Reward Link](/send-rewards/reward-links/reward-link-overview)
## Reward Point
Reward points can be accumulated, and used for redemption from our extensive rewards catalog. Learn more here: [Reward Points](/send-rewards/reward-points/reward-points-overview)
## Brand Vouchers
Instantly send brand gift cards directly to recipients' inboxes. There are over 8,000 top global brands from Amazon to Walmart and everything in between! Learn more here [Brand Vouchers](/getting-started/for-end-users/gift-vouchers-faqs)
If you want to learn more about which mode fits best for you, [check out this article](/send-rewards/reward-modes/comparison-of-when-to-use-what).
# Send Reward
## Send Reward Links
* [Send Reward Links: to a Few](/send-rewards/reward-links/send-reward-links-send-individually)
* [Send Reward Links: to Many](/send-rewards/reward-links/send-reward-links-bulk-upload)
* [Send Reward Links: to Self](/send-rewards/reward-links/send-reward-links-to-self)
## Send Reward Code
* [Send Reward Code: to Many](/send-rewards/reward-code/send-reward-code-bulk-upload)
* [Send Reward Code: to a Few](/send-rewards/reward-code/send-reward-code-individually)
## Reward Points
* [Reward Points](/send-rewards/reward-points/reward-points-overview)
# Campaigns
Xoxoday Plum enables super admins and admins to create and manage bespoke campaigns, enriching the rewarding experience for end-users by offering customizable storefronts and personalized rewards, thereby boosting engagement and driving outcomes.
Click here: [Overview: Campaigns](/campaigns/campaigns-overview)
# Plug-n-Play Native Integration
Plum Apps enables seamless integration with leading SaaS platforms in marketing automation, CRMs, customer engagement tools, HR software, collaboration platforms, and more. This integration streamlines workflows and enriches Plum with contextual information, providing a comprehensive perspective on your mutual growth.
## List of Most Popular Integration
* [HubSpot](/integrations/hubspot/hubspot-overview)
* [Salesforce](/integrations/salesforce/salesforce-overview)
* [Zoho CRM](/integrations/zoho-crm/zoho-crm-overview)
* [ActiveCampaign](/integrations/activecampaign/activecampaign-overview)
* [SAP SuccessFactors](/integrations/sap-successfactors/sap-successfactor-overview)
* [Darwinbox](/integrations/darwinbox/darwinbox-overview)
* [Zoho People](/integrations/zoho-people)
* [Qualtrics](/integrations/qualtrics/using-qualtrics-workflow-extension-to-send-rewards)
* [SurveyMonkey](/integrations/surveymonkey/public-survey-automation)
* [Typeform](/integrations/typeform/typeform)
# For Developers
Xoxoday’s developer platform is a core part of our mission to empower organizations to bake in rich rewarding experiences inside their application(s) and blitzkrieg growth and revenue. Unlock seamless rewards distribution and redemption within your application using our extensive library of API integrations. Developer Documentation is here: [Overview](https://developers.xoxoday.com/reference/api-reference-documentation)
## Rewards API
Add rewards to your application with seamless integration to our rewards catalog, featuring over 8,000 gift cards from top brands. Check out the documentation. [About Rewards API](https://developers.xoxoday.com/reference/about-rewards-api)
## Integrate Marketplace
Transform your reward points redemption process instantly with our plug-and-play global rewards catalog integration, delivering an exhilarating experience to your users within minutes. Check out the documentation [About Marketplace Integration](https://developers.xoxoday.com/reference/about-marketplace-integration)
## Reward Link API
Programmatically send unique reward links to recipients from within your application, redeemable against a curated catalog. Check out the documentation [About Reward Link APIs](https://developers.xoxoday.com/reference/about-xoxolink-apis)
# Plum Help Center
Source: https://help-plum.xoxoday.com/home
Guides and walkthroughs for Plum — sending rewards, campaigns, the reward marketplace, wallets and payments, reports, offers management, and integrations.
Plum Help Center
Plum is Xoxoday's rewards, incentives and payouts infrastructure. Send gift cards, prepaid cards, experiences and cash-outs to employees, customers and channel partners across 100+ countries.
# ActiveCampaign: Overview
Source: https://help-plum.xoxoday.com/integrations/activecampaign/activecampaign-overview
Get an overview of the Plum-ActiveCampaign integration and how it automates rewards triggered by marketing automation events.
*This article will guide you through integrating ActiveCampaign with Xoxoday Plum and setting up your first automation.*
## Here is how the Xoxoday ActiveCampaign Integration works?
Follow the below steps to create ActiveCampaign Reward Automation in Plum. Creation of automation in ActiveCampaign to connect Xoxoday plum.
## Pre-requisite
The App should be installed to be used as an action.
## Steps to Connect Rewards on ActiveCampaign with Plum
Xoxoday Plum can simply be integrated into ActiveCampaign by following the steps below:
You (the admin) can log in to ActiveCampaign and set up Xoxoday automation in either of the two ways.
## Method 1
* Sign in to **ActiveCampaign with** your credentials.
* Under the **"Automations" tab, click on "Create an Automation**"
* Choose "**Xoxoday Plum" from the "Actions**" tab to set up the workflow.
* Click on the account to which you would like to set up the automation.
## Method 2:
* Under the "**Automations**" tab
* Click on "Create a new automation" and click on the\*\*"+"\*\* button to add your first action and choose Xoxoday Plum from the options below:
## Creation of Reward Automation on Plum
* Next, sign in to Plum using [https://www.xoxoday.com/](https://www.xoxoday.com/)
* Once signed up to Plum, add funds to your account.
* Now go to Campaign on the sidebar, and click on Create New to create a reward campaign.
* Define the Reward Amount, Select rewards from the catalog, customize your email and click on Proceed.
* Now go to "Manage Integrations" and select ActiveCampaign Integration.
* Click on "Create New Automation" give your reward automation a name and select the type of trigger manual or automated.
* Finally, click on launch.
* To view Reward automation statistics, open the reward automation from the dashboard.
## Disconnecting Xoxoday Plum from ActiveCampaign
* Go to "Apps" on ActiveCampaign, Select Connected Apps
2\. Select "Xoxoday Plum" and Select the account you wish to disconnect
3. Click on "Disconnect":
## Integrate Your ActiveCampaign with Plum and witness amazing results!
Positively impact your audience’s journey and get that prospect which ultimately becomes a sale. Integrate your ActiveCampaign with Xoxoday Plum and see the difference with positive results. With dedicated account managers, full-time support to admins as well as end-users, and ISO, GDPR, and SOC compliance, Xoxoday Plum is as safe as it gets.
For any questions or feedback reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Creating Automation
Source: https://help-plum.xoxoday.com/integrations/activecampaign/creating-automation
Learn how to create a reward automation inside ActiveCampaign using Plum, so contacts are rewarded automatically at the right moment.
*This page will help you in creating your first automation with Xoxoday's ActiveCampaign Integration*
## Steps to Connect & Automate Rewards on ActiveCampaign with Plum
\*\*Step 1:\*\*Connect your Xoxoday & active campaign account.**Step 2:** Login/Signup to your Xoxoday account.
Step 3:\*\* Click on ActiveCampaign Integration under Manage Integration and select "Connect" to sync ActiveCampaign with Xoxoday.
Login to your ActiveCampaign account and connect with Xoxoday Plum as shown in previous article.
Create a Reward Campaign as shown in ::Xoxo-link::
## Create Reward Automation
Step 1: Click on '**Create New Automation**' in ActiveCampaign Dashboard.\*\*
Step 2: Name your automation and click on 'Save and Proceed'.\*\* \*\*
## Set your Reward
Here you can select the Campaign which holds the type of rewards and brands you want to use for this automation. You can set reward expiry and select the Approval type as manual or automatic. In Advanced Settings, you can set start and end date of automations and many more customisations.\*\*
Now, click on "Save and Launch" \*\*to move to next step.
Now, Click '**Yes, Launch'** button to launch automation.
### Automation created Successfully
**Link to the Xoxoday Plum recipe:**
Send Gift to New Client [https://www.activecampaign.com/marketplace/recipe/send-gift-card-to-new-client](https://www.activecampaign.com/marketplace/recipe/send-gift-card-to-new-client)
## Based on the triggers, rewards can be:
* Sent automatically without restrictions, which will be automatically distributed based on a customized time range and the maximum count of rewards, or
* Subjected to manual approval by admins.
* Now that the reward triggers are set, head back to the ActiveCampaign dashboard and click on ‘Create an Automation’. The template can be created from scratch or a readymade template aka ‘Recipe\*\*’ can be put to use.
* Next up, you ‘**Add a New Trigger**’ on the workflow builder, which is made easy with the recipe templates that come with their own sets of triggers.
* Once this is done, you can **‘Add a New Action**’ by clicking on CX Apps and selecting Reward through Xoxoday Plum. In case the [Xoxoday Plum Rewards App](https://www.activecampaign.com/apps/xoxoday-plum-integration) hasn’t been installed, it can be done at this very step.
* Remember the Automation we configured in Step 5? When the configured automation list appears, select your particular automation, and activate it with ‘Active’. Before activation, a quick review can be done with ‘View Contacts’. Refer to the above GIF for a better outlook.
* Bravo! Your ActiveCampaign Reward Automation is all set to be launched.
**Some points to note**
* While setting up the reward automation, the denomination will be in the same currency as the one selected in your Billing Details.
* You will have all access to the dashboard features of the Reward Automation and can deactivate the reward automation at any stage.
* On the condition that someone on the recipients’ list matches the criteria on ActiveCampaign automation, he/she automatically receives the reward delivered to his inbox in the form of Reward Codes.
As for your audience, check **how one can redeem the Xoxo Codes** on Marketplace.
# Zapier Integration
Source: https://help-plum.xoxoday.com/integrations/connect-plum-to-thousands-of-apps-using-zapier
Learn how to connect Plum to thousands of apps using Zapier, letting you trigger reward sends from almost any tool you use.
*Connect Xoxoday Plum to thousands of apps for various use-cases*
Below are some of the many Apps and their Use-Cases with templatized triggers that can be connected to Xoxoday Plum to send rewards, via Zapier:
## HRMS Tools
## 1. BambooHR
By connecting BambooHR with Xoxoday Plum, rewards can be sent to newly joined employees on successful onboarding completion.
Step 1: Select BambooHR as the Trigger application, the Trigger, in this case, is\*\*“When a new employee is added to BambooHR”. First, log in to your BambooHR account and Test trigger to Find data.\*\*
**Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new employees on BambooHR.
**Step 3:** After DIY set-up, log in as a registered user of Xoxoday Plum.
Step 4: Click\*\*'Continue\*\*' and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email.
**Step 5: Test and Review or Continue.**
**Congrats! Your Zap is ready.**
As a result of this integration, when a new employee is added to BambooHR, he/she receives Xoxoday Plum’s customized Gift Card via email.
**2. Namely**
By connecting Namely with Xoxoday Plum, rewards can be sent to new employees on successful onboarding completion.
Step 1: Select Namely as the Trigger application, the Trigger, in this case, is\*\*“When a new employee is added to Namely”\*\*. First, log into your Namely account and Test the trigger to Find data.
**Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new employees on Namely.
**Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum.
**Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use case of the Action you have set. Double-check everything. For example, the "Recipient Email" field is important if the gift card(s) need to be sent to the user via email.
**Step 5:** Test and Review or Continue.
As a result of this integration, when a new employee is added on Namely, he/she receives Xoxoday Plum’s customized Gift Card via email.
**3. Beekeeper**
By connecting Beekeeper with Xoxoday Plum, rewards can be sent for an employee’s personal milestones (birthdays, wedding anniversary celebration, etc.) as well as professional milestones (for work anniversaries, superior performance, employee referrals, achieving targets, participation in events conducted, etc.).
**Step 1:** Select Beekeeper as the Trigger application, the Trigger, in this case, is \*“an employee celebrating an anniversary on a particular day”. First, log into your Beekeeper account and Test the trigger to Find data.
**Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new employees on Beekeeper.
**Step 3:** After DIY set-up or login as a registered user of Xoxoday Plum.
**Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email.
**Step 5:** Test and Review or Continue.
**Congrats! Your Zap is ready.**
As a result of this integration, the day on which an employee celebrates his/her anniversary on Beekeeper, he/she receives Xoxoday Plum’s customized Gift Card via email.
## Survey tools & Forms
**1.Survey Monkey**
**2. Survey Sparrow**
By connecting SurveySparrow with Xoxoday Plum, rewards can be sent to a respondent on completion of any given survey.
Step 1: Select SurveySparrow as the Trigger application, the Trigger, in this case, is\*\*“when a user completes a survey”\*\*. First, log into your SurveySparrow account and Test the trigger to Find data.
**Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new responses to a survey on SurveySparrow.
**Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum.
**Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email.
**Step 5:** Test and Review or Continue.
**Congrats! Your Zap is ready.**
As a result of this integration, whenever a new response is submitted by a user on SurveySparrow, the user receives Xoxoday Plum’s customized Gift Card via email.
**3. SurveyGizmo**
By connecting SurveyGizmo with Xoxoday Plum, rewards can be sent to a respondent on completion of any given survey.
Step 1: Select SurveyGizmo as the Trigger application, the Trigger, in this case, is\*\*“when a user completes a survey”\*\*. First, log into your SurveyGizmo account and Test the trigger to Find data.
**Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new responses to a survey on SurveyGizmo.
**Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum.
**Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email.
**Step 5:** Test and Review or Continue.
**Congrats! Your Zap is ready.**
As a result of this integration, whenever a new response is submitted by a user on SurveyGizmo, the user receives Xoxoday Plum’s customized Gift Card via email.
**4. TypeForm**
By connecting TypeForm with Xoxoday Plum, rewards can be sent to new entries on TypeForm.
Step 1: Select TypeForm as the Trigger application, the Trigger, in this case, is\*\*“when a new entry is made”\*\*. First, log into your TypeForm account and Test the trigger to Find data.
**Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new entries on TypeForm.
**Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum.
**Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the "Recipient Email" field is important if the gift card(s) need to be sent to the user via email.
**Step 5:** Test and Review or Continue.
**Congrats! Your Zap is ready.**
As a result of this integration, whenever a new entry is made on TypeForm, the user receives Xoxoday Plum’s customized Gift Card via email.
**5. Qualtrics**
By connecting Qualtrics with Xoxoday Plum, rewards can be sent to new entries on Qualtrics.
**Step 1:** Select Qualtrics as the Trigger application, the Trigger, in this case, is “when a new response is added to the survey”. First, log in to your Qualtrics account and Test the trigger to Find data.
**Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new responses to a survey on Qualtrics.
**Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum.
**Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email.
**Step 5:** Test and Review or Continue.
**Congrats! Your Zap is ready.**
As a result of this integration, whenever a new response is submitted by a user on a Qualtrics survey, the user receives Xoxoday Plum’s customized Gift Card via email.
## Sales and Marketing Enablement, CRM
**1.** \*\*[Salesforce CRM](/integrations/connect-plum-to-thousands-of-apps-using-zapier)****
**2. Zoho CRM**
By connecting Zoho with Xoxoday Plum, rewards can be sent to new leads/prospects added on Zoho.
Step 1: Select Zoho as the Trigger application, the Trigger, in this case, is\*\*“when a new lead(a record) is added”\*\*. First, log in to your Zoho account and Test the trigger to Find data.
**Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to a new lead added on Zoho.
**Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum.
**Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email.
**Step 5:** Test and Review or Continue.
**Congrats! Your Zap is ready.**
As a result of this integration, whenever a new lead is added to Zoho, the user receives Xoxoday Plum’s customized Gift Card via email.
**3. Freshsales CRM**
By connecting Freshsales with Xoxoday Plum, rewards can be sent to new leads/prospects added on Freshsales.
Step 1: Select Freshsales as the Trigger application, the Trigger, in this case, is\*\*“when a new lead(a record) is added”\*\*. First, log into your Freshsales account and Test the trigger to Find data.
**Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to a new lead added on Freshsales.
**Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum.
**Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email.
**Step 5:** Test and Review or Continue.
**Congrats! Your Zap is ready.**
As a result of this integration, whenever a new lead is added to Freshsales, the user receives Xoxoday Plum’s customized Gift Card via email.
**4. Hubspot Marketing Automation**- By connecting HubSpot with Xoxoday Plum, rewards can be sent to **new form submissions** on HubSpot.
* By connecting HubSpot with Xoxoday Plum, rewards can be sent to \***new deals added** on HubSpot.
Step 1: Select HubSpot as the Trigger application, the Trigger, in this case, is\*\*“when a new deal is added”\*\*. First, log into your HubSpot account and Test the trigger to Find data.
**Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to a new deal added on HubSpot.
**Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum.
**Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Doublecheck everything. For example, the "Recipient Email" field is important if the gift card(s) need to be sent to the user via email.
**Step 5:** Test and Review or Continue.
**Congrats! Your Zap is ready.**
As a result of this integration, whenever a new deal is added to HubSpot, the user receives Xoxoday Plum’s customized Gift Card via email.
### 5. Mailchimp Email Newsletter
By connecting Mailchimp with **Xoxoday Plum**, rewards can be sent to every new subscriber of Mailchimp’s email newsletter.
Step 1: Select Mailchimp as the Trigger application, the Trigger, in this case, is\*\*“new subscriber of the newsletter”\*\*. First, log in to your Mailchimp account and Test the trigger to Find data.
**Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to a new subscriber on Mailchimp.
**Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum.
**Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the "Recipient Email" field is important if the gift card(s) need to be sent to the user via email.
**Step 5:** Test and Review or Continue.
**Congrats! Your Zap is ready.**
As a result of this integration, whenever a new subscriber is added to Mailchimp, the user receives Xoxoday Plum’s customized Gift Card via email.
**6. Google Sheets**
By connecting GoogleSheet with Xoxoday Plum, rewards can be sent to every new user row(prospect lead) added to the Google spreadsheet.
Step 1: Select GoogleSheet as the Trigger application, the Trigger, in this case, is\*\*“new row added to spreadsheet”\*\*. First, log into your Google account and Test the trigger to Find data.
**Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to a new row on Google Sheet.
**Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum.
**Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email.
**Step 5:** Test and Review or Continue.
**Congrats! Your Zap is ready.**
As a result of this integration, whenever a new spreadsheet row is added to GoogleSheet, the user receives Xoxoday Plum’s customized Gift Card via email.
## Webinar Tools
**1. Go to Webinar**
By connecting GoToWebinar with Xoxoday Plum, rewards can be sent to every new webinar attendee.
Step 1: Select GoToWebinar as the Trigger application, the Trigger, in this case, is\*\*“new webinar attendee”. First, log in to your GoToWebinar account and Test the trigger to Find data.
**Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to a new attendee of a webinar in GoToWebinar.
**Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum.
**Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the "Recipient Email" field is important if the gift card(s) need to be sent to the user via email.
**Step 5:** Test and Review or Continue.
**Congrats! Your Zap is ready.**
As a result of this integration, every new webinar attendee in GoToWebinar receives Xoxoday Plum’s customized Gift Card via email.
2. Zoom \*\*By connecting Zoom with **Xoxoday Plum**, rewards can be sent to every new registrant.
Step 1: Select Zoom as the Trigger application, the Trigger, in this case, is\*\*“new registrant in Zoom”. First, log in to your Zoom account and Test the trigger to Find data.
**Step 2:** Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to new registrants in Zoom.
**Step 3:** After DIY set-up or log in as a registered user of Xoxoday Plum.
**Step 4:** Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the "Recipient Email" field is important if the gift card(s) need to be sent to the user via email.
**Step 5:** Test and Review or Continue.
**Congrats! Your Zap is ready.** As a result of this integration, every new registrant in Zoom receives Xoxoday Plum’s customized Gift Card via email.
## What Next? : Quick Zap Creation
The use cases mentioned in the above section are a few of the many popular Zap templates that already exist to connect applications like **Salesforce, HubSpot, SurveyMonkey, GoToWebinar, Mailchimp, etc. to Xoxoday Plum**. Using these pre-created templates will help you automate the workflow and get it up and running in no time.
For more information about building your first **Xoxoday → Zapier integration**, [Contact us](https://www.xoxoday.com/contact-us).
# Darwinbox: Overview
Source: https://help-plum.xoxoday.com/integrations/darwinbox/darwinbox-overview
Learn how the Plum-Darwinbox integration works, connecting your HRMS to Plum so employee rewards can be triggered and disbursed automatically.
*Learn all about integration of Darwinbox with Xoxoday Plum.*
## Overview
Xoxoday integrates with DarwinBox, one of the leading HRMS automation platforms for modern businesses. This integration enables organizations using DarwinBox to not only streamline and automate HR workflows, but also seamlessly reward employees to keep them motivated, engaged, and appreciated.
With Xoxoday Plum, companies can build a culture of recognition through a unified rewards platform offering a global catalog of products and experiences — helping teams feel valued and inspired to do their best work.
## Points Redemption procedure
* Log in to your DarwinBox account.
* \*\*Darwinbox + Xoxoday Integration \*\*Click on the **Recognition** tile.
* Click **Redeem**, get redirected to [stores.xoxoday.com](https://docs.xoxoday.com/docs/stores.xoxoday.com), and get auto logged in via SSO.
* Users will be automatically logged in to [Xoxoday plum stores](https://docs.xoxoday.com/docs/stores.xoxoday.com) (Catalog front).
* Users can redeem their points in plum on a variety of experiences and vouchers.
* Select your Country & Click on **Gift Vouchers, experiences**, or other classification of your choice.
* Select the listed Brand Voucher or any other option.
* Select the Denomination and Quantity and then Add to the Cart.
* Under the payment option, click on Use available xxx points for this order and place the order. You may use a debit/credit card to augment points in case it is insufficient.
* You can also view the integration video here:
* You can view the interactive demo using this [***Link***](https://reward-path-showcase.lovable.app)
# Guide to Configure End-points
Source: https://help-plum.xoxoday.com/integrations/darwinbox/guide-to-configure-end-points
Follow this step-by-step guide to configure the Darwinbox API endpoints needed to connect your HRMS with Plum for reward automation.
*Learn about the configuration on Darwinbox.*
Step 1: Initiate the process by logging in to the Xoxoday Admin dashboard using the provided link:\*\*stores.xoxoday.com.\*\*Step 2: Navigate to the "**Integrations" section and select "Darwinbox**".
**Step 3:** Proceed to Configure the Darwinbox settings.
Step 4: Fill in the necessary fields, namely **Username, Password, Datasetkey, and Redirect URL**. You should have received these specific details from the Darwinbox team.
Step 5:\*\* Update the Endpoint URL and API Key for the following subsequent endpoints:
* Fetch Point Balance API
* Update Point Balance API Endpoint
* Fetch Employee Master API
Step 6: After completing the previous step, click "**Verify and Proceed"**. Afterwards, please notify to your implementation manager from Xoxoday, so that we can inform the Darwinbox team to activate the redemption button on your behalf.
Step 7:\*\* Upon the successful completion of this configuration, feel free to arrange a call with us to facilitate an onboarding session. During this session, we will guide you through both the end user journey and the admin dashboard.
# Forsta (Decipher) Integration
Source: https://help-plum.xoxoday.com/integrations/forsta-decipher-integration
Get an overview of the Plum integration with Forsta Decipher and how it automates reward distribution to survey respondents.
*Learn more about Forsta and Xoxoday Plum Integration.*
# Overview
Boost survey response rates and gather meaningful insights with instant rewards! Xoxoday Plum, integrated with Forsta, automates digital rewards, letting you engage respondents effortlessly. Create reward automation campaigns to send rewards instantly, eliminating manual gift-code management for a seamless experience.
## Highlights of the Integration
Once the integration between the two platforms is enabled, you no longer have to juggle between spreadsheets to track or manage reward campaigns, or manually procure and distribute rewards.
Xoxoday Plum not only simplifies the rewarding process but also brings a host of value additions to the integration. Here are some of the key highlights:
* **Automated Rewards on Completion of Survey** The integration allows you to set up Reward automation Campaigns on Xoxoday Plum and send out rewards to respondents who complete the survey. Not just that, the survey respondents can choose gifts, perks, and experiences of their choice from Xoxoday’s extensive global catalog.You can also restrict the number of rewards sent out based on criteria like - campaign time range, Maximum Reward count, etc.
* Built-in Approval Workflows
Integration with Xoxoday allows you to have complete control over whom among your respondents to send the rewards to. The built-in approval system lets you review and approve respondents individually or in bulk. This ensures that there are no repeat claims that take place.
* **Customised Communication Templates**
Survey rewards can be sent to respondents through customized email templates that represent your organizational DNA - with your own logo, messaging, and images. This ensures they are instantly recognised and don't get lost in their inbox.
* **Dedicated Redemption Support**
Our API integrations ensure that the redemption process is seamless and non-intrusive for your users. Furthermore, we also offer global support for all your user queries during redemption.
## How does the Integration Work?
Follow the step-by-step guide to set up the integration between Xoxoday Plum and Forsta, and create & run reward campaigns.
## STEP 1: Connect to Decipher
Go to Integrations and Search for **Forsta (Decipher).** \*\*
Click on ‘Connect\*\*’
Enter the API Key provided by Forsta (Decipher) account to authenticate and connect your account.
Once the Authentication is done, you are now successfully connected to Xoxoday.
This authentication allows Xoxoday to fetch the Survey Projects on Frosta and set Reward Automation to send rewards.
Setting up Reward Automation
Reward Automation defines Reward Campaigns and provides additional settings to the reward processing.
Click on ‘Create new Automation
Here, Name the Automation and Select the Survey from the Frosta account for which you want to send rewards to respondents.
In the next steps, Select the Reward Campaign you already set up, which defines the reward denomination, catalog, and reward email.
You can set:
* Expiry of Automation: Define the end date of automation.
* Approval type:
Automatic: Automatically send rewards as soon as the survey is submitted by the respondent.
* Manual: This will capture the respondents and you can choose whom they send reward by simply choosing to Approve or Reject button.
Click on ‘Save and Launch’ to start reward Automation.
Once created, Copy the reward claim page link and paste it into Redirect URL of your Survey.
# Complete Wellness with Fitterfly
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/complete-wellness-with-fitterfly
Learn how the Plum-Fitterfly integration gives employees access to Complete Wellness programs as part of your rewards and benefits catalogue.
*Learn about integrating Wellness with Fitterfly*
## About Fitterfly
Fitterfly is a health-tech startup specializing in digital therapeutics (DTx) for metabolic health. Fitterfly combines personalized coaching with advanced technology to help individuals manage and reverse chronic conditions.
Fitterfly's programs are clinically validated and have shown significant improvements in health outcomes, including reductions in HbA1c levels, weight loss, and enhanced physical fitness.
## Key Benefits
* **For HRs**
Holistic Employee Wellness Empower your workforce with personalized digital health programs that address diabetes, weight, and lifestyle management — promoting overall well-being.
* Improved Productivity & Engagement Healthier employees are more focused, energetic, and motivated, leading to better workplace performance.
* Preventive Health Insights Gain access to anonymized wellness data and trends to identify potential health risks and plan proactive interventions.
* Scalable, Digital Implementation Easily integrate Fitterfly’s digital platform across teams, ensuring smooth access without logistical challenges.
* For Employees
Personalized Health Coaching Get digital programs tailored to your unique needs — from managing diabetes to maintaining a healthy weight and lifestyle.
* Continuous Progress Tracking Monitor your health metrics and track improvements with smart digital tools and real-time insights.
* Expert Support at Your Fingertips Access guidance from certified coaches, nutritionists, and wellness professionals anytime, anywhere.
* Sustainable Lifestyle Habits Adopt small, consistent changes that help build long-term health, energy, and confidence.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Comprehensive Flexibility & Mobility Wellness with STRETCHIT
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/comprehensive-flexibility-mobility-wellness-with-stretchit
See how the Plum-StretchIt integration lets you offer employees flexibility and mobility wellness programs through your rewards catalogue.
*Learn all about integrating STRETCHIT*
## About STRETCHIT
STRETCHIT is a digital flexibility and mobility training platform designed to improve movement, posture, and overall physical well-being. The platform provides structured stretching programs guided by expert coaches to help users reduce muscle stiffness, prevent injuries, and improve flexibility over time.
Through the STRETCHIT mobile app, users gain access to personalized stretching routines, guided mobility sessions, and progressive training programs tailored to different fitness levels and health goals. The platform focuses on improving mobility, reducing musculoskeletal discomfort, and supporting healthier movement habits for people with sedentary or desk-based lifestyles.
## Why connect with STRETCHIT
Integrating STRETCHIT enables organizations to support employee well-being by addressing mobility, posture, and physical strain caused by long working hours and sedentary routines. This integration helps companies introduce structured flexibility programs that encourage movement, reduce workplace discomfort, and improve overall employee wellness.
## Key Benefits
**For Leaders and HR**- Improved workplace wellness Structured flexibility programs help address common workplace issues such as back pain, muscle stiffness, and poor posture.
* Preventive health support Regular stretching routines can help reduce the risk of musculoskeletal issues and support long-term physical well-being.
* Employee engagement Interactive wellness programs encourage employees to stay active and maintain healthier daily routines.
* Seamless program access Employees can easily access flexibility training sessions through the platform.
For Employees
* Guided stretching programs Access professionally designed flexibility routines tailored to different skill levels.
* Improved mobility and posture Programs designed to help relieve tension from long sitting hours and improve body alignment.
* Convenient training sessions Short and effective sessions that can be performed anytime through the STRETCHIT mobile app.
* Progressive flexibility training Structured programs that help employees gradually improve flexibility and range of motion.
## How Employees Can Use STRETCHIT
* Guided Stretching Sessions
Employees can follow structured stretching routines led by professional trainers that target flexibility, mobility, and posture improvement.
* **Mobility Training Programs**
Users can participate in progressive mobility programs designed to improve joint health and muscle flexibility.
* **Workplace-Friendly Routines**
Short routines designed specifically for people who spend long hours sitting or working at a desk.
* **Progress Tracking**
Employees can track their flexibility progress and stay consistent with guided sessions through the STRETCHIT mobile app.
* **Corporate Wellness Programs**
Organizations can introduce flexibility and mobility training programs to support employee health, reduce physical strain, and promote active lifestyles.
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Comprehensive Home Healthcare Made Easy with Portea
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/comprehensive-home-healthcare-made-easy-with-portea
Learn how the Plum-Portea integration brings comprehensive home healthcare benefits to employees directly through your rewards program.
*Learn more about integration with Portea*
## About Portea
Portea is a trusted home healthcare company, delivering doctor consultations, physiotherapy, nursing, lab tests, and chronic care management right at patients’ doorsteps. Operating across 60+ cities with 4,000+ clinicians, Portea brings hospital-quality healthcare to homes—reducing hospital visits and ensuring continuous care with convenience for healthier, happier employees and families.
## Why Connect Portea with Xoxoday Plum
Integrating Portea helps organizations provide employees and their families with easy access to home healthcare services. Employees can book medical visits, physiotherapy, or lab tests at home, while business leaders can promote preventive health, reduce absenteeism, and support employees’ holistic wellbeing—especially for aging family members or those recovering from illness.
## Key Benefits
**For Employers**- \*\*End-to-end health support Offer home-based medical and nursing care as part of employee benefits.
* Reduce absenteeism Enable faster recovery and continuity of work through at-home care.
* Inclusive wellness Extend benefits to employees’ families and dependents.
* Stronger wellbeing culture Promote preventive and post-hospitalization care programs.
For Employees
* **Convenient Home Healthcare** \*\* Access professional medical care, nursing, and wellness services from the comfort of home—saving time and ensuring continuous care.
* Trusted Support for Family Health\*\* \*\* Receive reliable and compassionate healthcare solutions for yourself and your loved ones, including specialized elder care services.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Comprehensive Wellness with HealthiFy
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/comprehensive-wellness-with-healthify
See how the Plum-Healthify integration lets you deliver comprehensive employee wellness programs as part of your rewards and benefits offering.
*Learn how to integrate Xoxoday with HealthiFy*
## About HealthiFy
HealthiFy is a global digital health and wellness platform offering AI-led nutrition, fitness, and wellness solutions. Combining advanced analytics with human expertise, it helps users build healthy habits through data-driven insights and coaching support.
## Why Integrate with HealthiFy
The integration enables HR teams to deliver a unified, science-backed wellness experience for employees. Through this integration, employees can access wellness programs, monitor progress, and receive expert guidance—all within their corporate wellness ecosystem.
## Key Benefits
* **For Employers/ HR Leaders**
Comprehensive wellness ecosystem Offer employees AI-powered health tracking, expert coaching, and engagement tools in one platform.
* Seamless integration Embed HealthiFy’s programs directly into the platform for unified wellness delivery.
* Data insights & engagement Track participation, engagement, and overall wellness trends across teams.
* Preventive health impact Encourage early health awareness and reduce long-term healthcare costs.
* ## For Employees
Personalised wellness journey Receive customized plans for diet, exercise, and mindfulness.
* Continuous support Access guidance from professional health coaches and AI-driven insights.
* Sustainable habit formation Build long-term healthy routines through consistent nudges and motivation.
* Engaging digital experience Use the HealthiFy app to log meals, track progress, and celebrate milestones.
## How Employees Can Redeem Points Using HealthiFy
* Enroll in the Program Employees can sign up through the Xoxoday platform and get a personalized wellness assessment.
* Set Health Goals Define goals—such as fitness, nutrition, or mindfulness—and receive tailored plans.
* Track Daily Progress Use the Healthify app to log meals, workouts, and hydration.
* Get Expert Support Interact with nutritionists and fitness coaches for customized advice.
* Stay Motivated Participate in wellness challenges, leaderboards, and team activities for engagement.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Comprehensive Wellness with Humm Care
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/comprehensive-wellness-with-humm-care
Learn how the Plum-Humm Care integration supports employee wellness with comprehensive care benefits available through your rewards catalogue.
*Learn more about integration with Humm Care*
## About Humm Care
Humm Care provides comprehensive, inclusive healthcare solutions focused on women’s health, family care, and eldercare. Through expert consultations and personalized programs, it supports employees across fertility, pregnancy, postpartum, and caregiving journeys.
Why Connect with Humm Care Integrating Humm Care offers employees holistic wellness support across life stages while enabling HR teams to track engagement and well-being, fostering a healthier, more supported workforce.
## Key Benefits
* For HRs
Enhanced Employee Well-being Support employees through life’s most important phases with structured maternal and childcare programs that promote physical and emotional health.
* Improved Retention & Loyalty Provide meaningful benefits that help new and expecting parents feel supported, reducing turnover and increasing long-term engagement.
* Inclusive Wellness Offering Create a family-friendly workplace by extending wellness initiatives beyond traditional healthcare to include maternal and child development support.
* Seamless Program Integration Easily enable Humm Care’s services through Xoxoday’s platform, ensuring convenient access for employees across locations.
* For Employees
\*\*Work-Life Balance Support Access flexible, family-centered care options that help balance personal wellness and professional responsibilities with ease.
* Emotional and Mental Well-being Benefit from empathetic care programs and resources that promote mental resilience and reduce stress during major life transitions.
* Reliable Expert Network Connect with trusted healthcare professionals, counselors, and specialists for guidance whenever needed.
* Empowered Health Awareness Gain knowledge and confidence to make informed health and lifestyle choices for yourself and your family.
## How Employees Can Use Humm Care
Humm Care provides comprehensive support programs for maternal health, prenatal care, and child development\*\*, helping parents and expecting parents navigate every stage with expert guidance and confidence.
* Maternal Health Support Access tailored health programs that support physical and emotional well-being throughout pregnancy and postpartum recovery.
* Prenatal Care Programs Receive personalised care plans, consultations, and resources to ensure a safe and well-supported prenatal experience.
* Child Development Support Get expert advice and developmental guidance to monitor and enhance your child’s early milestones and well-being.
* Easy Digital Access Connect with healthcare professionals, access educational content, and manage your journey conveniently through Humm Care’s digital platform.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Comprehensive Wellness with Unlock.fit
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/comprehensive-wellness-with-unlockfit
See how the Plum-UnlockFit integration enables comprehensive employee wellness benefits as part of your organization's rewards catalogue.
*Learn how to integrate Unlock.Fit with Xoxoday*
## About Unlock.fit
Unlock.fit is a cutting-edge wellness platform that leverages genetic insights to deliver personalized nutrition and fitness plans. By analyzing over 700,000 gene markers, Unlock.fit provides users with tailored recommendations that align with their unique genetic makeup. Their services include DNA testing, blood analysis, personalized diet plans, exercise routines, and expert consultations, all accessible through a user-friendly mobile app.
## Why this integration
Integrating Unlock.fit enables HR teams to offer employees a holistic wellness program that combines genetic insights with personalized nutrition and fitness plans. This integration supports preventive healthcare, enhances employee engagement, and promotes a culture of health and well-being within the organization.
## Key Benefits
* For Organization/ HR Leaders Comprehensive wellness supportDNA and blood-based analysis to tailor nutrition and fitness plans.
* Data-driven insights
Access to anonymized wellness reports to monitor employee health trends.
* Employee engagement
Personalized wellness programs that foster a healthier, more productive workforce.
* Seamless integration
Easy deployment and management through the platform.
* For Employees
Personalized wellness plans Tailored nutrition and fitness recommendations based on genetic and health data.
* Expert guidance:
Access to certified nutritionists and fitness coaches for ongoing support.
* Convenient access
Wellness programs available anytime, anywhere through the Unlock.fit app.
* Holistic health approach
Programs designed to address individual health goals and challenges.
## How Employees Can Use Unlock.fit
* DNA & Blood Testing Employees can collect saliva and blood samples using provided kits, which are then analyzed to provide insights into their genetic and health profiles.
* Personalized Wellness Plans Based on test results, employees receive customized diet and exercise plans designed to optimize their health and performance.
* Expert Consultations Access to certified nutritionists and fitness coaches for personalized guidance and support.
* Progress Tracking Monitor health metrics and track progress through the Unlock.fit mobile app, ensuring continuous improvement and engagement.
* Corporate Wellness Programs Organizations can implement DNA-based wellness programs, like CorpGene, to enhance employee health and productivity on a larger scale.
## Co-Sponsor & Deliver Unlock.fit Benefits at Scale
Employers can roll out Unlock.fit’s personalized wellness programs across their organization, ensuring every employee has access to tailored health solutions. By this integration, companies can streamline wellness initiatives, track engagement, and foster a culture of health and well-being.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Dental Care with Clove Dental
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/dental-care-with-clove-dental
Learn how the Plum-Clove Dental integration lets you offer employees dental care benefits directly through your rewards and benefits program.
*Learn more about integration with Clove Dental with Xoxoday*
## About Clove Dental
Clove Dental is India's largest dental chain with 600+ multi-specialty clinics, 1200+ expert dentists, and presence across 27 cities. Their Corporate Dental Health Programme addresses stress-related oral health issues through preventive education, assessments, and accessible healthcare delivery, helping organizations reduce dental-related absenteeism and healthcare costs.
## Why Connect Clove Dental
Employees gain easy access to dental checkups, treatments, and emergency care at convenient locations, while HR can promote wellness, reduce absenteeism, and demonstrate care through accessible health benefits.
## Key Benefits
* **For Organizations**
All-in-one platform: rewards + comprehensive dental wellness
* Nationwide coverage: 600+ clinics across 27 cities for easy employee access
* Reduced absenteeism: Preventive care addresses dental issues before they escalate
* Simplified administration: Centralized booking and benefit delivery at scale
* **For Employees**
Convenient access: Walk-in appointments at 600+ clinics near home or office
* Weekend availability: All clinics open on Saturdays and Sundays
* Comprehensive care: From routine checkups to complex procedures
* Expert treatment: 1200+ qualified dentists including specialists
* Flexible payments: Cash, card, and digital payment options
## How Employees Can Use Clove Dental
* **Preventive Care**
Routine dental checkups, cleanings, and oral health assessments to catch issues early and maintain healthy gums and teeth.
* **Restorative Treatments**
Comprehensive solutions like root canal therapy, crowns, dentures, and dental implants to restore function and comfort.
* **Orthodontics & Alignment**
Consultations and treatments for braces, clear aligners, and bite correction to achieve proper teeth alignment.
* **Cosmetic Dentistry**
Teeth whitening, veneers, and smile enhancement procedures to boost confidence and appearance.
* **Surgical & Emergency Care**
Safe wisdom tooth extractions, emergency dental treatments for pain or injury, and immediate care for infections or trauma.
* **Corporate Dental Wellness**
On-site dental camps, awareness sessions, and educational programs to promote preventive oral health at the workplace.
## Co-Sponsor Health Benefits with Ease
Xoxoday allows organizations to co-sponsor wellness benefits like Clove Dental at reduced costs, making it simple to invest in employee well-being without exceeding budget constraints.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Digital Healthcare for Employees with Practo
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/digital-healthcare-for-employees-with-practo
See how the Plum-Practo integration gives employees access to digital healthcare consultations as part of your organization's benefits catalogue.
*Learn more about integration with Practo*
## About Practo
Practo is a digital healthcare platform that connects employees with doctors across 25+ specialties for both online and in-person consultations. It offers a complete healthcare ecosystem including medicine delivery, diagnostic tests, dental care, and preventive health checkups. Through one easy-to-use app, Practo ensures employees can access trusted medical care anytime, anywhere.
## Why Connect with Practo?
Integrating with Practo enables organizations to extend reliable, round-the-clock healthcare support to their workforce. Employees can easily access medical consultations, book diagnostic tests, or schedule health checkups from their devices. For HR, it simplifies benefit distribution, strengthens employee wellbeing, and reduces absenteeism through preventive care.
## Key Benefits
## For Business Leaders/HR
* Seamless healthcare integration Offer employees convenient access to medical services directly through Xoxoday platform.
* Preventive wellness programs Encourage regular checkups and early diagnosis to maintain workforce health.
* Improved productivity Reduce sick leaves and boost employee morale by providing easy access to care.
## For Employees
* All-in-one medical access Connect with doctors, book tests, or get medicines—all through a single app.
* Choice and convenience Select from 25+ specialties and access care online or at clinics near you.
* Trusted quality care Consult certified doctors and specialists, ensuring reliable treatment and guidance.
## How Employees Can Use Practo
* Health Checkup Book comprehensive preventive health packages and diagnostic tests online with quick scheduling and trusted results.
* Teleconsultation Consult general physicians or specialists online for quick, reliable, and secure medical advice—without leaving home.
* OPD Care Access affordable outpatient care packages for routine checkups and specialized medical consultations.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Employee Wellness Sessions with 1to1 help
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/employee-wellness-sessions-with-1to1-help
Learn how the Plum-1to1Help integration lets employees book wellness sessions through your rewards and benefits catalogue.
*Learn all about integration with 1to1help*
## About 1to1help
1to1Help is a holistic employee well-being platform offering personalized counselling and expert-led support. It helps employees manage stress, mental health, and personal challenges, while enabling organizations to build a healthier, productive, and emotionally resilient workforce.
## Why Integrate with 1to1help?
Integration with 1to1help brings well-being and recognition together on one platform. Employees get the mental health support they need, while HR teams can drive engagement and rewards alongside holistic wellness programs.
## Key Benefits
For Organizations/Business Leaders/HR Leaders
* Manage recognition and well-being from a centralized platform
* Provide easy access to counselling services
* Boost engagement with automated rewards and recognition
For Employees
* Confidential, one-on-one counselling sessions
* Direct access to well-being resources within Empuls
* Work in a supportive, mental health-friendly environment
## How Employees Can Use 1to1help
1to1Help gives employees a confidential and convenient way to address personal and professional challenges.
* Manage Stress & Anxiety
Get guidance on coping with work stress, deadlines, or anxiety
* Learn practical techniques to reduce tension and stay focused
* Maintain Work-Life Balance
Receive support in balancing professional responsibilities with personal commitments.
* Tips for managing time, prioritizing tasks, and avoiding burnout.
* Career Guidance & Performance Coaching
Improve productivity, focus, and overall performance.
* Explore career decisions, goal-setting, and professional development opportunities.
* Relationship & Family Support
Guidance on managing interpersonal challenges, family stress, or parenting concerns.
* Learn strategies to resolve conflicts and improve communication.
* Emotional & Mental Health Support
Discuss feelings of burnout, low motivation, or emotional distress in a safe space.
* Receive practical advice from trained counsellors.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Employee Wellness Support with Samvedna Care
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/employee-wellness-support-with-samvedna-care
See how the Plum-Samvedna Care integration supports employee wellness by making counselling and care services available through your benefits catalogue.
*Learn more about integrating Samvedna Care*
## About Samvedna Care
Samvedna Care supports employee emotional wellbeing with counseling, individual and group therapy, and eldercare. Expert counsellors reduce stress, build resilience, and address work-life challenges, fostering a culture that prioritises mental health, awareness, and employee satisfaction.
## Why Connect Samvedna Care
Xoxoday Plum and Samvedna Care combine engagement and wellbeing—giving employees easy access to online counselling, psychiatrist consultations, eldercare and dementia support, while helping HR promote workplace mental health, drive participation, and improve overall well‑being and productivity.
## Benefits
* **For Employers**
One platform for counseling, therapy, and eldercare support.
* Fosters a mental-health-first culture.
* Boosts satisfaction with expert care.
* Frees HR to focus on programs.
* **For Employees**
Easy access
* Individual or group therapy options.
* Eldercare guidance for better balance.
* A workplace that prioritizes well-being.
## How Employees Can Use Samvedna Care
* Access to Counseling Book one-on-one sessions easily with experienced counselors for stress management, emotional support, or personal issues.
* Mental Health Assessments Take confidential self-assessments to evaluate their mental health and get personalized recommendations.
* Elder Care Support Avail guidance and support for employees managing eldercare responsibilities, reducing stress and improving focus at work.
* Workshops & Training Participate in mental wellness workshops and training sessions to build emotional resilience and improve overall well-being.
* Confidentiality Completely confidential interactions allowing employees to feel safe and supported when seeking help.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Empower Employee Mental Wellness with Your DOST
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/empower-employee-mental-wellness-with-your-dost
Learn how the Plum-YourDOST integration empowers employee mental wellness by making counselling support available through your rewards catalogue.
*Learn more about integrating Xoxoday with Your DOST.*
## About Your DOST
Your DOST provides confidential mental health support through one-on-one counseling, self-help tools, and workshops. Its clinically validated approach builds emotional resilience and long-term wellbeing for employees.
## Why this integration
This integration brings mental health and employee engagement together on one platform. Employees can access confidential counseling and self-care tools directly through Xoxoday, while HR teams can foster an open, stigma-free culture of emotional wellness — leading to improved morale, reduced burnout, and stronger team connections.
## Key benefits
**For business leaders and HR**- **Enhance employee wellbeing** — Address emotional and mental health proactively.
* **Boost productivity** — Support mental clarity, focus, and motivation at work.
* **Reduce attrition** — Help employees manage burnout and stress effectively.
* **Measure impact**— Access anonymized wellness insights to guide HR initiatives.**For employees**- **24/7 availability** — Access emotional support anytime, anywhere.
* **Diverse expertise** — Reach professional counsellors specializing in stress, anxiety, relationships, career issues, and more.
* **Personal growth** — Access life coaching for confidence, performance, and leadership skills.
* **Completely private** — All sessions are 100% confidential and secure.
## How employees can use Your DOST
* **Connect with a counselor** — Book one-on-one online sessions with licensed psychologists or life coaches.
* **Instant chat support** — Get immediate help through real-time chat with emotional wellness experts.
* **Video or audio therapy** — Choose flexible formats for therapy sessions based on comfort and need.
* **Self-help tools** — Access personalized assessments, progress tracking, and self-guided exercises.
* **Confidentiality and security** — All data and sessions are encrypted and anonymized to protect employee privacy.
## Deliver Your DOST benefits at scale
Integrating Your DOST with Xoxoday unites mental health and engagement in one place — enabling easy access to mental health counselling while helping HR nurture a stigma-free culture of wellbeing.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Empower Employee Wellbeing with TruWorth Wellness
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/empower-employee-wellbeing-with-truworth-wellness
See how the Plum-Truworth Wellness integration empowers employee wellbeing with health programs available through your benefits catalogue.
*Learn more about integrating TruWorth with Xoxoday*
## About TruWorth Wellness
TruWorth Wellness is a leading digital corporate wellness platform helping organizations enhance employee health through analytics, preventive care, and expert coaching—creating happier, healthier, and more productive workplaces at scale.
## Why Connect with TruWorth Wellness
Integrating TruWorth Wellness enables organizations to deliver data-driven wellness programs, monitor engagement, and give employees easy access to health assessments, fitness challenges, and expert consultations—all in one platform.
## Key Benefits
* **For Business Leaders/HR**
**Holistic Wellness Engagement:** Combine engagement activities with customized wellness journeys.
* **Actionable Insights:** Use analytics and dashboards to measure program impact and participation.
* **Enhanced Productivity:** Promote preventive health to reduce absenteeism and improve morale.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Empower Women’s Wellness Journeys with Newmi Care
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/empower-womens-wellness-journeys-with-newmi-care
Learn how the Plum-Newmi Care integration supports women's wellness journeys by making specialised care available through your rewards catalogue.
*Learn more about Newmi Care integration*
## About Newmi Care
Newmi Care is India’s first comprehensive women’s wellness ecosystem that supports women across every stage of life—menstruation, fertility, pregnancy, motherhood, and menopause. The platform brings together expert consultations, curated wellness programs, and a marketplace of trusted health and lifestyle products designed exclusively for women’s physical, mental, and emotional wellbeing.
## Key Benefits
* **For Employers**
**Inclusive wellness initiative:** Promote women’s health and wellbeing through tailored programs.
* **Effortless rollout:** Deliver healthcare, counselling, and lifestyle benefits via Empuls.
* **Engagement & retention:** Build a culture of care and inclusivity through holistic wellness support.
* **For Employees**
**End-to-end wellness support:** Access programs for fertility, pregnancy, parenting, and beyond.
* **Expert consultations:** Book gynecologists, nutritionists, and therapists anytime.
* Curated marketplace:Explore and shop trusted women’s health and wellness products.**How Employees Can Use Newmi** Care
* Book Wellness Services Employees can use the Newmi Care platform to schedule consultations, join fitness or nutrition programs, and access specialized women’s health services—directly through Empuls.
* Explore the Newmi Care Store Discover products across maternity, hygiene, and self-care categories tailored to women’s unique needs.
## Co-Sponsor & Deliver Newmi Care at Scale
Integrate Newmi Care across your organization through Empuls to drive holistic women’s wellness initiatives. Celebrate inclusivity, support every stage of women’s health, and make wellbeing a core part of your workplace culture.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Fast Diagnostic Testing with Orange Health
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/fast-diagnostic-testing-with-orange-health
See how the Plum-Orange Health integration gives employees access to fast diagnostic testing as part of your organization's benefits catalogue.
*Learn more about integrating Orange Health*
## About Orange Health
Orange Health is a modern diagnostics platform that delivers lab tests at home in just 60 minutes, combining speed, accuracy, and convenience. With NABL-accredited labs and expert phlebotomists, Orange Health makes preventive and diagnostic testing simple, seamless, and trusted for individuals and families.
## Why Connect with Orange Health
Adding Orange Health empowers employees to take charge of their health with quick, at-home diagnostics. It eliminates the need to visit labs or wait for appointments — ensuring health checks fit easily into employees’ schedules while maintaining the highest testing standards.
## Key Benefits
**For HR/ Leaders**- **Wellbeing made easy:** Offer employees instant access to at-home lab testing.
* **Low admin lift:** Partner-managed logistics, communication, and report delivery.
* Reliable network:Backed by NABL-accredited labs for accurate, professional results.**For Employees**- **At-home testing:** Book tests online and get samples collected at home in 60 minutes.
* **Quick results:** Receive verified reports digitally within 6–8 hours.
* **Trusted care:** Enjoy hospital-grade accuracy, hygiene, and service quality.
## How Employees Can Use Orange Health
Access Orange Health to book preventive or diagnostic lab tests. Choose your preferred time slot, have samples collected at home, and receive certified reports directly on your phone or email — all within hours
.
## Co-Sponsor & Deliver Orange Health at Scale
Employers can make Orange Health available across teams to promote preventive healthcare and early detection. It’s a powerful way to strengthen employee wellbeing through fast, reliable, and accessible diagnostics.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Holistic Employee Wellness with YogiFi
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/holistic-employee-wellness-with-yogifi
Learn how the Plum-YogiFi integration delivers holistic employee wellness benefits, including guided yoga and fitness, through your rewards catalogue.
*Learn more about integrating with YogiFi*
## About YogiFi
YogiFi is an innovative AI-powered yoga solution that integrates intelligent sensor technology to offer personalized, real-time posture feedback during yoga sessions. This intelligent yoga mat helps users enhance their practice by providing accurate corrections, ensuring a more effective and therapeutic yoga experience.
## Why Connect with YogiFi?
Integrating YogiFi allows HR teams and business leaders to promote physical wellness through personalized yoga programs. Employees can access real-time posture feedback and therapeutic yoga sessions, fostering a healthier workforce. HR leaders can track engagement, encourage holistic wellness, and reduce stress-related absenteeism, all while promoting a culture of wellness within the organization.
## Key Benefits
* For Business Leaders/ HR Leaders AI-driven wellness supportPersonalized yoga sessions that correct posture and enhance practice.
* Data-driven insights
Monitor engagement and track wellness metrics across your organization.
* Employee retention boost
Improve morale and productivity through tailored wellness initiatives.
* Simplified program delivery
Easily integrate YogiFi’s digital yoga programs across the workforce.
* For Employees
Real-time posture feedback Improve your yoga practice with AI-powered corrections.
* Therapeutic yoga sessions
Enjoy stress relief and mental clarity anytime, anywhere.
* Accessible wellness
Yoga sessions that fit into any schedule and require no prior experience.
* Interactive learning
Engage with personalized sessions that adapt to your skill level.
## How Employees Can Use YogiFi
* Personalized Yoga Classes Employees can participate in yoga sessions tailored to their unique needs, with real-time feedback that helps improve posture and enhances the practice.
* Therapeutic Sessions Enjoy instant stress relief and therapeutic benefits with sessions designed to promote mental clarity and physical wellness.
* Anywhere, Anytime Access With YogiFi, employees can practice yoga from the comfort of their home, office, or while traveling, ensuring wellness is always within reach.
* Posture Correction YogiFi’s AI-driven sensor technology provides accurate posture corrections during yoga sessions, helping employees maintain proper alignment and avoid strain.
* Engagement & Tracking HR leaders can monitor employee engagement with the program, track wellness progress, and ensure that every employee has access to the resources they need for a healthier lifestyle.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Holistic Fitness & Wellness with Cult.fit
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/holistic-fitness-wellness-with-cultfit
See how the Plum-cult.fit integration offers employees holistic fitness and wellness benefits directly through your rewards and benefits catalogue.
*Learn all about integrating Xoxoday with Cult.fit*
## About Cult.fit
Cult.fit is India's largest integrated fitness and wellness platform with 200+ cult centers, 8,000+ partner gyms, and presence across 25+ cities. Their corporate wellness program combines fitness, nutrition, sports, and engagement activities to help organizations improve employee health, boost productivity, and create a culture of wellness through flexible access to workouts, expert guidance, and company-wide challenges.
## Why this integration
This integration combines employee recognition with comprehensive fitness and wellness. Employees get flexible access to workouts, sports, nutrition, and wellness programs, while HR can drive engagement through wellness, track analytics, and demonstrate commitment to employee wellbeing.
## Key Benefits
* **For HR**
All-in-one platform Enhance the rewards and recognition ecosystem with easy access to fitness
* Drive engagement Improve engagement with fitness challenges and transformation contests
* Flexible offerings Avail the services at the center, at-home, and sports options for diverse workforce
* For Employees
Multiple workout options Easy access to 200+ cult centers + 8,000+ partner gyms nationwide
* Flexible scheduling Avail the services from the center, at-home workouts
* Expert guidance: Take guidance from the best of trainers, nutritionists, and wellness coaches
* Convenience Book classes, track progress, and workout anytime through the cult app
## How Employees Can Use Cult.fit
* Gym Access Across India Get a 12-month gym membership with options like Cult Elite, Fitternity OnePass (includes OnePass & Cult HOME), or Fitso/Cultpass PLAY — giving you flexibility to choose how and where you work out.
* Train Your Way Enjoy access to top gyms, fitness studios, and Cult centers nationwide. Choose in-person workouts or home-based sessions through the Cult platform (as per your selected pass).
* Dietician Consultations Opt for 3, 6, or 8 consultation sessions with certified dieticians to receive personalized nutrition guidance and maintain healthy habits.
* All-in-One Fitness Solution Combine expert-led workouts and professional nutrition support to stay active, motivated, and balanced throughout the year.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Integrated Health & Wellness Solutions with MediBuddy
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/integrated-health-wellness-solutions-with-medibuddy
Learn how the Plum-MediBuddy integration provides employees with integrated health and wellness solutions through your rewards catalogue.
*Learn all about integrating Xoxoday with MediBuddy*
## About MediBuddy
MediBuddy is a leading digital healthcare platform offering comprehensive medical services, including online consultations, lab tests, medicine delivery, mental health support, and preventive care. With a trusted nationwide network, it makes quality healthcare accessible, affordable, and convenient for individuals and organizations alike.
## Why this integration
Integrating MediBuddy with Xoxoday allows organizations to promote preventive care, reduce absenteeism, and improve employee wellness through on-demand digital healthcare. Employees gain instant access to qualified doctors and essential medical services, while HR leaders can track health engagement, drive wellness initiatives, and create a healthier, more productive workplace.
## Key Benefits
* **For Employers/HR Leaders**
Comprehensive wellness coverage Integrate physical and mental health services into employee benefits.
* Reduce medical claims Encourage preventive care through early diagnosis and regular check-ups.
* Boost productivity Support employees’ health to minimize downtime and stress-related issues.
* Data insights Monitor utilization trends and wellness participation securely.
* For Employees
Convenient Access to Healthcare Employees can easily book health checkups, consultations, and diagnostic tests online, making healthcare accessible and hassle-free.
* Affordable and Reliable Medical Support With cost-effective OPD and teleconsultation options, employees receive dependable medical care and advice without leaving home.
## How Employees Can Use MediBuddy
* Book Health Checkups Schedule comprehensive preventive health checkups and diagnostic tests easily through MediBuddy for reliable results.
* Access OPD Packages Choose affordable outpatient consultation packages for routine health checkups and specialized medical care.
* Connect via Teleconsultation Consult with doctors online conveniently from home through MediBuddy’s teleconsultation feature.
* Manage Healthcare Digitally Use the MediBuddy platform to book services, access reports, and track appointments in one place.
## Co-Sponsor & Deliver Medibuddy Benefits at Scale
Employers can implement MediBuddy Corporate Health Programs to offer doctor access, preventive care, and comprehensive medical services to their teams. By digitizing healthcare delivery, organizations can ensure their employees stay healthy, engaged, and supported—both physically and mentally.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Master O
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/master-o
See how the Plum-Master-O integration connects gamified learning and training outcomes to rewards, letting you incentivise employee skill-building.
*Learn all about integration with Master O*
## About Master-O
Master-O is a gamified microlearning platform delivering bite-sized training to sales and support teams—boosting knowledge, engagement, and performance.
## Why Connect Master-O with Empuls
Blend recognition with continuous, snackable learning—easy to launch, fun to complete, and proven to reinforce skills.
## Key Benefits
### For HR
* High engagement: Game mechanics keep learners active.
* Faster rollout: Micro modules fit busy schedules.
* Skills tracking: Monitor progress and outcomes.
### For Employees
* Short, impactful lessons: Learn in minutes, retain more.
* Practice through play: Quizzes and challenges reinforce skills.
* Sales & support focus: Directly tied to daily workflows.
## How Employees Can Use Master-O
* Interactive Microlearning: Consume bite-sized lessons designed for quick retention.
* Game-Based Assessments Reinforce learning with gamified quizzes and challenges.
* Sales Enablement Use microlearning tools to strengthen sales techniques and customer engagement skills.
* Spaced Learning Workflows Follow structured workflows that reinforce concepts over time.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Personalized Nutrition and Weightloss with Fitelo
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/personalized-nutrition-and-weightloss-with-fitelo
Learn how the Plum-Fitelo integration offers employees personalized nutrition and weight-loss coaching programs through your benefits catalogue.
*Learn more about integrating Fitelo*
## About Fitelo
Fitelo is India's personalized nutrition and wellness platform with 500+ doctors, nutritionists, and lifestyle experts, serving 25,000+ users across 55+ countries. Their evidence-based approach addresses weight management, disease management, and lifestyle transformation through customized diet plans based on individual body types, medical conditions, and preferences—helping organizations reduce lifestyle-related absenteeism and healthcare costs.
## Why Connect Fitelo with Xoxoday Plum
Integrating Fitelo with Xoxoday Plum combines employee engagement with personalized nutrition and wellness. Employees gain access to expert-led diet plans, health coaching, and disease management support, while HR can promote preventive health, track wellness outcomes, and build a culture of sustainable wellbeing.
## Key Benefits
## For Employers
* **All-in-one platform:** Execute employee engagement and personalized nutrition and wellness
* **Reduce healthcare costs:** Address lifestyle diseases before they escalate
* **Boost productivity:** Healthier employees with improved energy and focus
* **Measurable outcomes:** Gain visibility into engagement levels, health scores, and program outcomes with real-time reports.
## For Employees
* **Personalized plans:** Diet plans tailored to body type, lifestyle, and medical conditions
* **Expert guidance:** 500+ nutritionists, doctors, and wellness coaches
* **Holistic approach:** Nutrition, fitness, and habit coaching
* **Long-term results:** Sustainable lifestyle changes, not quick fixes
For set up or usage assistance, reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Preventive Health Checkups with Healthians
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/preventive-health-checkups-with-healthians
See how the Plum-Healthians integration gives employees access to preventive health checkups as part of your organization's rewards catalogue.
*Learn all about integration with Healthians*
## About Healthians
Healthians is India’s leading health test at-home service offering a wide range of diagnostic tests, full body check-ups, and preventive health packages. With certified labs, trained phlebotomists, and accurate reports delivered digitally, Healthians makes preventive healthcare simple, affordable, and accessible right at your doorstep.
## Why Connect with Healthians
Integrating Healthians with Xoxoday brings preventive healthcare into your recognition and engagement ecosystem. Employees can book convenient at-home tests and receive digital reports, while HR can promote participation in checkups, support wellbeing initiatives, and signal a strong commitment to employee health.
## Key Benefits
* **For Business Leaders/HR**
Promote Employee Health and Productivity Encourage preventive checkups to reduce sick days and build a healthier, more productive workforce.
* Boost Employee Satisfaction and Retention Improving employee satisfaction, loyalty, and retention with at-home health services.
## How Employees Can Use Healthians
* Book At-Home Sample Collection Choose the required diagnostic test or check-up and schedule a doorstep visit at a convenient time.
* Quality & Safety Benefit from certified labs and trained phlebotomists for a reliable testing experience.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Preventive Health Checkups with Thyrocare
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/preventive-health-checkups-with-thyrocare
Learn how the Plum-Thyrocare integration offers employees preventive health checkups directly through your organization's benefits catalogue.
*Learn more about integration with Thyrocare*
## About Thyrocare
Thyrocare is one of India’s leading diagnostic and preventive healthcare service providers, offering a wide range of pathology and wellness tests through a trusted, technology-driven network. With a focus on accuracy, affordability, and convenience, Thyrocare ensures early detection and proactive health management for employees and their families.
## Why Connect with Thyrocare
Adding Thyrocare supports employee wellbeing by making preventive health checkups easy to access and affordable. With nationwide coverage, at-home sample collection, and digital reports, Thyrocare ensures a smooth and reliable health testing experience for every employee.
## Key Benefits
**For HR**- **Employee wellbeing:** Promote preventive health with reliable and accessible diagnostics.
* Nationwide reach:Enable employees to access health checkups anywhere in India.**For Employees**- **Convenient testing:** Get samples collected from home or office.
* **Accurate results:** Benefit from advanced lab automation and quality processes.
* **Comprehensive packages:** Choose from a wide range of health and wellness tests.
## How Employees Can Use Thyrocare
Access Thyrocare to book preventive health checkups or specific diagnostic tests. Schedule at-home sample collection, receive updates digitally, and get reports directly through secure online access.
## Co-Sponsor & Deliver Thyrocare at Scale
Employers can roll out Thyrocare health packages across teams to build a culture of wellbeing and preventive care. Enable hassle-free access to health services that keep employees proactive and productive.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Seamless OPD Coverage for Employees with OPDSure
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/seamless-opd-coverage-for-employees-with-opdsure
See how the Plum-OPDsure integration provides employees with seamless outpatient (OPD) coverage as part of your rewards and benefits program.
*Learn more about integration with OPDSure*
## About OPDSure
OPDSure is a healthcare platform that focuses on outpatient care, covering essential medical expenses such as doctor consultations, pharmacy costs, diagnostic tests, and preventive health checkups. It helps individuals and families manage the high proportion of healthcare spending that comes from routine outpatient needs, while promoting regular health monitoring and preventive care.
## Why Connect OPDSure
Connecting OPDSure allows organizations to provide employees with structured support for everyday healthcare needs. Employees gain access to consultations, medicines, diagnostics, and checkups under a unified healthcare benefit, encouraging timely medical attention and contributing to overall well-being at work.
## Key Benefits for Employees
* Offer Comprehensive and Manageable OPD Benefits Enable employees to access a wide range of outpatient services while managing everything effortlessly through seamless integration.
* Gain Actionable, Data-Driven Insights Track utilization, engagement, and wellness trends to understand employee health behavior and enhance benefits strategies effectively.
## How Employees Can Use OPDSure
* Access Routine Consultations Easily Employees can book convenient outpatient consultations for regular health checkups and everyday medical needs.
* Get Specialized Care When Required Avail packages for specialized consultations, helping employees seek expert advice for specific health concerns.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Unlock Employee Wellness with Fitpass
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/unlock-employee-wellness-with-fitpass
Learn how the Plum-Fitpass integration unlocks employee wellness benefits, including gym and fitness access, through your rewards catalogue.
*Learn more about Fitpass integration*
## About Fitpass
Fitpass is India’s largest fitness and wellness network offering flexible access to 7,500+ gyms, studios, and fitness centers across 40+ cities. It empowers users with an integrated fitness ecosystem that includes AI-powered fitness tracking, personalized nutrition guidance, and corporate wellness programs designed to enhance employee health, reduce sedentary habits, and improve workplace productivity.
## Why Connect Fitpass with Xoxoday Plum
Integrating Fitpass helps organizations deliver holistic employee wellness experiences. Employees gain instant access to personalized fitness routines, gym memberships, and expert coaching, while organizations can promote healthy lifestyles, measure engagement, and enhance retention through data-driven wellness insights.
## Key Benefits
* **For Employers**
Unified wellness platform Combine engagement, rewards, and physical wellbeing.
* Reduce absenteeism Encourage consistent fitness to improve employee health.
* Data-backed insights Track participation and wellness outcomes.
* Attract and retain talent Offer modern wellness benefits employees love.
* For Employees
Personalized Fitness Options Employees can select flexible subscription plans tailored to their lifestyle and fitness preferences.
* Smart Wellness Integration
Each plan enhances the fitness experience with connected tools to monitor progress and stay active.
Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com) to get started with the integration.
# Wellbeing Reimagined with Fitterfly
Source: https://help-plum.xoxoday.com/integrations/health-and-wellness/wellbeing-reimagined-with-fitterfly
See how the Plum-Fitterfly integration reimagines employee wellbeing with structured wellness programs available through your rewards catalogue.
*Learn more about integration with Fitterfly*
## About Fitterfly
Fitterfly is a health-tech startup specializing in digital therapeutics (DTx) for metabolic health. Fitterfly combines personalized coaching with advanced technology to help individuals manage and reverse chronic conditions. The programs include:
* Fitterfly Diabetes Prime A 6–12 month program designed to prevent, manage, or reverse type 2 diabetes and prediabetes.
* Fitterfly Weight Loss A 3–6 month program focused on sustainable weight loss and maintenance.
* Fitterfly FitHeart A program aimed at improving heart health through lifestyle modifications.
Fitterfly's programs are clinically validated and have shown significant improvements in health outcomes, including reductions in HbA1c levels, weight loss, and enhanced physical fitness.
## Why Connect with Fitterfly
This integration empowers HR leaders to offer employees data-driven, personalized care plans backed by science. With real-time progress tracking and expert support, it enhances engagement, well-being, and overall organizational productivity.
## Key Benefits
* **For Employers/HR Leaders**
AI-driven health solutions Provide employees with personalized metabolic health plans based on real-time data.
* Seamless integration Easily incorporate Fitterfly's programs into existing wellness initiatives through the platform.
* Data-driven insights Monitor employee health metrics and track program engagement to assess effectiveness.
* Cost-effective Reduce healthcare expenses by addressing the root causes of chronic conditions and promoting preventive care.
* For Employees
Personalized care Receive tailored recommendations for nutrition, activity, sleep, and stress management.
* Continuous support Access a dedicated care team of health coaches and medical professionals.
* Sustainable health improvements Achieve long-term health goals, such as weight loss and medication reduction, through evidence-based interventions.
* User-friendly technology Utilize the Fitterfly app to track progress and stay connected with your care team.
## How Employees Can Use Fitterfly
* Enroll in the Program Employees can sign up for Fitterfly's program through the platform, providing basic health information to personalize their care plan.
* Wearable Sensors Upon enrollment, employees receive wearable sensors that continuously monitor key health metrics, feeding data into their digital twin.
* Personalized Recommendations The Fitterfly app provides daily guidance on nutrition, activity, sleep, and stress management based on the individual's unique metabolic profile.
* Regular Check-ins Employees have access to regular consultations with health coaches and medical professionals to discuss progress and adjust their care plan as needed.
* Track Progress Through the Fitterfly app, employees can monitor their health metrics, set goals, and celebrate milestones, fostering motivation and sustained engagement.
## Co-Sponsor & Deliver Fitterfly Benefits at Scale
Enable employees to access Fitterfly’s personalized metabolic health programs organization-wide. Through this integration, employers can easily launch wellness initiatives, monitor participation, and foster a healthier workplace culture.
## Support
For setup or usage assistance, contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# 1-Many Link for Xoxolink’s Reward Automation
Source: https://help-plum.xoxoday.com/integrations/hubspot/1-many-link-for-xoxolinks-reward-automation
Learn how to automate one-to-many reward distribution in HubSpot using Xoxoday reward links, so an entire segment can be rewarded in one action.
*1 - many Xoxolink feature helps in enabling real-time rewarding and CTA hyperlinking for sending emails to the masses.*
This feature is specially designed for sales and marketing teams using Xoxoday plum integrated with HubSpot.
1-many automation can be created from Xoxoday’s dashboard and the link generated can be copied and pasted to your marketing emails in HubSpot.
Feature Specification: Only the ones who are part of the contact list in HubSpot will be eligible to redeem their rewards, anyone apart from that will not have access.
## Pre-requisites
* As an admin, You should have already connected the Xoxoday with [HubSpot](/integrations/hubspot/hubspot-overview).
## Steps to create a 1-many campaign:
**Step 1:** The admin creates the Xoxolink [campaign](/getting-started/overview).
Step 2: The admin creates Automation for HubSpot — and selects ‘1-many reward link’. Accepts the Information message and tick that you understood the guidelines. Click '**Continue'.**
Step 3: Select 'Campaign' Upon selecting Campaign, set the Expiry date, select Approval type as Manual or Automatic as per your preferences. You can also add **Additional settings** on 1. Start and End Date of Automation 2. Maximum number of Rewards to sent - Upon reaching max limit, the Automation will be completed. \*Repeat Rewarding is disabled.
**Step 4:** Upon creating a 1-many link for the automation — a link is generated to trigger rewards for that automation which users can ‘copy’ and use inside HubSpot emails.
Pro Tip: Don't forget to copy the link( as shown in the above image), as you will have to hyperlink it to your email’s CTA on HubSpot.
**Step 5:** Adding the link inside HubSpot for launching Emails:
**Step 6:** Now you are good to go!! You can now send rewards to all of your contact lists in one go.
## Steps to Redeem a 1-Many campaign
Below are the steps to redeem your rewards:
**Step 1:** From your reward email Click the CTA to go about redeeming.
**Step 2:** Below screen will open for you to redeem the reward:
Step 3:Once Authenticated, you will receive a redemption email for selecting your desirable reward.**Step 4:** Select the Reward you wish to avail yourself:
During the Redemption journey —
* End user inputs email address say [xyz@gmail.com](mailto:xyz@gmail.com)
* **If** the email address is present in the HubSpot contacts, we proceed to send the reward
* **Else**, we show an error message saying ‘Unable to validate. Please contact the sender of the email for further assistance ‘
# Email based Reward Automation
Source: https://help-plum.xoxoday.com/integrations/hubspot/email-based-reward-automation
See how to automate reward sends that are triggered by HubSpot email actions, using the Plum-HubSpot integration to reward engaged contacts.
*Learn how to automate rewards for email recipients.*
Now you can reward your prospects, contacts, and leads directly via email marketing campaigns (without any workflow-based triggers in HubSpot). Just select the contact 'List' from HubSpot.
In a few simple clicks, you can set up a reward automation campaign in Plum and use the reward-enriched contacts to send emails with your own template from HubSpot. Not just that, the email recipient (contacts, prospects, or leads) can choose gift cards of their choice from Xoxoday’s extensive global catalog.
You can also restrict the number of rewards sent out based on criteria like - campaign time range, Maximum Reward count as well as repeated rewards, etc.
## Follow the step to step guide to make your first rewarding automation for email recipients.
Skip Section 1 if you have already integrated Xoxoday Plum with HubSpot
# Section I: Sync up your HubSpot with Plum
Step 1: \*\*Connect your Xoxoday plum to HubSpot.\*\*
## Step 2: Go to App Marketplace and search for Xoxoday plum.
Now, click on the app marketplace by clicking on the shop icon on the right top corner of your dashboard.
## Step 3: Click on the Install app
Search for Xoxoday Plum in the app marketplace, and click on the “Install” button.
## Step 4: Signup or Sign In on Plum
If you are new to Xoxoday Plum, click on the “**Signup” button. You can learn how to set up a Plum account [here](https://xoxoday.gitbook.io/plum/for-admins-1/getting-started). It's recommended that you use the email registered with HubSpot to signup with Plum as well.If you are an existing user, use your Xoxoday credentials to log in to the admin dashboard.**
**Congrats, you have successfully installed the application.**
# Section II: Create Reward Automation in Plum
## Step 1: Setting up the Reward Automation.
Once the Xoxoday Plum Rewards App is downloaded, follow the steps given below and hook Xoxoday Plum up to your Hubspot CRM.
These are for the Admins operating the HubSpot CRM dashboard.
Please ensure that you follow the steps on the dashboard to create the reward automation and recharge your account.
Step 2: Choose to Automate your first reward
Once you choose ‘automate your first reward’ from the dashboard you will be shown a pop-up with the option to choose a type of reward automation. You need to choose “email-based reward automation” Existing Plum admins can go to their HubSpot integration and click on ‘create new automation’ and they will also be presented with the same automation selection pop-up.
## Step 3: Enter Reward Automation Name and Choose Contact list
On the automation first step enter the reward automation name which you will be using during the email template creation to embed the reward link in HubSpot. Choose the contact list from HubSpot which will be fetched to enrich the contacts with reward links.
Once selected, you can click on "Save & Proceed" to proceed to move to the next steps:
## Step 4: Create or select the Xoxolink campaign
As a first-time user, you have to create a Xoxolink campaign from where the rewards will actually flow.
Perform the following actions to set up your Xoxolink campaign: Enter Campaign Name, Set Link expiry date, Select the country and denomination as per your choice. For existing users, you can select the existing Xoxolink campaign or choose to create a new one.
## Step 5: Let the contact enrichment complete on plum.
Once you launch the reward automation, then you will be redirected to the reward report page where you could see how the contact enrichment is progressing. (The time taken to complete the enrichment is relative to the number of contacts you have in the contact list). Once the enrichment is complete, follow the below-mentioned steps in HubSpot to generate and send emails with a reward link embedded into them.
# HubSpot Integration
Source: https://help-plum.xoxoday.com/integrations/hubspot/hubspot-overview
Get an overview of the Plum-HubSpot integration, including how it connects your CRM workflows to automated reward disbursal for contacts.
*Learn more about Xoxoday Plum and Hubspot integration*
## Overview
The HubSpot ↔ Xoxoday Plum integration enables you to automate the way you send rewards, incentives, and branded gifts to your customers, prospects, and partners directly from HubSpot. Whether you want to reward a single contact when they convert, or send rewards at scale after an event, the integration makes the process seamless, branded, and trackable.
**Typical use cases include:**
* Sending welcome kits to new customers during onboarding.
* Rewarding attendees of webinars and events.
* Driving survey completions with incentives.
* Encouraging referrals and advocacy programs.
* Nudging trial users to upgrade to paid plans.
* Re-engaging dormant leads or inactive users.
* Recognizing partners, affiliates, and advocates.
## Key Features
* **Seamless HubSpot integration**: Trigger rewards directly from workflows, contact lists, or emails.
* **White-labeled experience**: Customize reward emails and landing pages with your branding.
* **Flexible catalogues**: Choose from Xoxoday’s global catalogue or curate your own campaigns with selected items.
* **Vast reward catalogue & automated fulfillment**: Choose from thousands of options including global gift cards and merchandise. Whether you curate branded swags or send digital gift cards, Plum handles delivery, redemption, and order tracking end-to-end.
* **Multiple automation options**: Choose the flow that fits your use case — Workflow-based, Email-based, 1-Many Reward Links, or 1-1 Widget.
* **Reporting & analytics**: Track rewards sent, claimed, and delivered directly within HubSpot and Plum.
## How to integrate HubSpot with Xoxoday?
Discover how to integrate Xoxoday Plum with HubSpot to automate and personalize reward campaigns. This video walks you through connecting both platforms, mapping contact data, and triggering rewards directly from your HubSpot workflows.
## Ways to Send Rewards via HubSpot
* ### Workflow-Based Reward Automation
What it is:Automate rewards triggered by HubSpot workflows (e.g., when a contact’s lifecycle stage changes to Customer).Best for:Targeted, event-driven rewarding.**Use cases:**
* Welcome gift when a lead converts into a paying customer.
* Send a thank-you gift when a deal is marked Closed Won.
* Celebrate customer milestones (renewals, anniversaries, or usage achievements).
**How it works:** HubSpot workflow → triggers Plum automation → Plum sends reward email → contact redeems via landing page → fulfillment handled automatically.
See detailed setup guide: [Workflow-Based Reward Automation.](https://help.plum.xoxoday.com/en/articles/11483885-workflow-based-reward-automation)
* ### Email-Based Reward Automation
What it is:Send rewards to an entire HubSpot contact list in bulk.Best for:Rewarding segmented groups of contacts without building a new workflow.**Use cases:**
* Reward all contacts who completed a survey in the last month.
* Send incentives to webinar attendees pulled into a HubSpot static list.
* Deliver a gift to a segment like “Top 100 engaged customers.”
**How it works:** Plum enriches the HubSpot list with unique reward links → you design an email in HubSpot → insert Plum token → each recipient gets their own secure reward link.
See detailed setup guide: [Email-Based Reward Automation.](https://help.plum.xoxoday.com/en/articles/9403738-email-based-reward-automation)
* ### 1-Many Reward Link
What it is:Generate one reusable reward claim link and embed it into HubSpot emails.Best for:Mass campaigns where the same CTA goes to many recipients.**Use cases:**
* Add a reward CTA in an NPS survey follow-up email.
* Incentivize signups by including a reward link in a marketing newsletter.
* Reward all webinar registrants at once with a single campaign.
**How it works:** Plum creates a 1-Many URL → you add it to a HubSpot marketing email (as a CTA) → when contacts click, Plum validates their identity and allows them to redeem.
See detailed setup guide: [1-Many Reward Link Automation.](https://help.plum.xoxoday.com/en/articles/10225649-1-many-link-for-xoxolink-s-reward-automation)
* ### 1-1 Rewards via Widget
What it is:Send a reward manually to a single contact directly from their HubSpot profile.Best for:High-touch, personal gestures.**Use cases:**
* Send a thank-you to a VIP client after a meeting.
* Appreciate a partner for closing a big referral deal.
* Resolve a support issue with a goodwill gift to the affected customer.
**How it works:** From the HubSpot contact profile → open the Xoxoday Plum widget → select a campaign → send reward instantly.
See detailed setup guide: [Send 1-1 Reward via Widget.](https://help.plum.xoxoday.com/en/articles/9398889-send-1-1-reward-via-xoxoday-widget)
## Reporting & Tracking
* **In HubSpot**: Use reward-specific properties to track which contacts have received or claimed rewards. Add these to your HubSpot dashboards for reporting.
* **In Plum**: Use the automation dashboard to track triggered rewards, redemptions, and order status.
This dual visibility ensures your marketing, sales, and customer success teams can measure ROI and manage budgets effectively.
## Getting Started
* Connect your HubSpot account with Plum from the Integrations section in Plum.
* Choose the automation type that fits your use case.
* Create and customize campaigns with your chosen rewards and branding.
* Test with a sample contact or list before rolling out.
Next: Explore the [detailed setup guides for each automation type](https://help.plum.xoxoday.com/en/collections/9503710-hubspot) to configure your first campaign.
Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com) for any questions or feedback.
# Report Dashboard in HubSpot
Source: https://help-plum.xoxoday.com/integrations/hubspot/report-dashboard-in-hubspot
Learn how to track reward automation performance from a dedicated dashboard embedded directly inside your HubSpot account.
*All about tracking your Xoxoday Reward Campaigns in Hubspot*
There are a few ways that you can currently track and measure the impact of Xoxoday Rewards campaign efforts and their influence on your deals.
**At a personal level, for each contact,** you can see the outcome of your Xoxoday campaigns in the activity timeline.
\#For example, below you can see that this person has been sent a gift 'Coffee On Us' campaign and they have claimed it. These are populated as custom events and will update when a status changes:
You can also use **lists** to group contacts who have responded to a Xoxoday campaign in the same way (example: Sent, Claimed, etc) by using the details within the event to the group i.e. by campaign name, status, etc.
For more holistic rewarding activity reporting specifically **relating to deal influence**, there are a few options that you could call upon, using workflows.
# Here’s How to Set Up RoI Reporting
**Step 1:** Creating custom contact properties for Xoxoday reward activity touch points
* Add Xoxoday campaign/touches to a contact custom field —
This will allow you to see the last Xoxoday campaign associated to a contact, related to deals (open and closed).
## - ## Requirements
2 custom fields/properties on a contact:
* 1 single line text field, name this Xoxoday Reward Campaign Status
* 1 boolean field, name this **Xoxoday Touch**
**Step 2:** Create a workflow to update these fields
Our recommended workflow would be to update the 2 custom fields set out above when a Xoxoday reward is redeemed. The Xoxoday campaign Status field should be populated with the campaign Statusas it exists within Xoxoday. The Xoxoday Touch field will be populated with 'True'.These workflows should be set up per campaign, and it would look something like this:
Once your workflow is switched on, anyone who redeems your particular campaign will have those fields populated as a result.
You can also add additional contact properties and workflows to add more granularity to your Xoxoday reward campaign reporting if you like.
Now you can build a 'contacts and deals' report to see the influence of Xoxoday campaigns on open and closed deals.
**For open opportunities:**
Select Create Custom Report> cross-object and select contacts and deals.
Configure Bar Chart
Let us know if you're reporting in other ways by sending us email at [plum.product@giift.com](mailto:plum.product@giift.com).
We will update our documentation once HubSpot release attribution for custom events
# Send 1-1 reward via Xoxoday Widget
Source: https://help-plum.xoxoday.com/integrations/hubspot/send-1-1-reward-via-xoxoday-widget
See how to send individual one-to-one rewards from within HubSpot using the embedded Xoxoday widget, without leaving your CRM.
*Learn how to send a personalized 1-1 reward.*
Xoxoday Plum Rewards widget feature helps a sales rep to send 1-1 personalized emails for building a better relationship with their clients.
\*\*This helps by allowing teams to reward a single contact with a personalized email and select a campaign. Every contact can be rewarded with a different campaign depending on various variables.
Feature Specification: \*\*Only the ones who are part of the contact list in HubSpot will be eligible to redeem their rewards, anyone apart from that will not have access.
# Sending 1-1 rewards using Xoxoday Plum Widget
**Prerequisites**
**As an admin, You should have already connected the Xoxoday with HubSpot. If not check this article.**
**HubSpot users who need access to 1-1 rewards widget should be added as a user in Xoxoday Plum with Admin or Super admin access as required.**
## Steps to send 1-1 Rewards
## Step 1: Open Xoxoday 1-1 Rewards Widget
* Open the detail page of the contact to whom you want to send rewards in HubSpot.
* Find Xoxoday Card on the left panel and click ‘Send Rewards’,\*\* then Xoxoday’s 1-1 widget opens.
Now, There are two ways to send 1:1 Rewards
### Through a Reward Link
This features generates a unique reward link. This link can be embedded in your custom emails to send rewards.
## Step 2: Select Campaign
Select your Campaign from the dropdown menu.
## Step 3: Reward Link Generated
Voila! a unique Reward Link is generated for the Contact. This link can be sent to contact through any medium. We suggest you include this link in your custom emails\*\*.\*\*
## Reward Email via Plum
This feature will send a custom email from the selected Campaign to the Contact.
## Step 2: Select Campaign
From the Dropdown option, select your preferred Campaign.
## Step 3: Reward Email Sent
Voila! The Reward email is sent.
Check Reward History
* Reward History shows the rewards sent through ‘Rewards by Plum Email’ and ‘Reward Link’.
* Only Super-admins will be able to view the global list of Rewards sent by the team.
# Workflow based Reward Automation
Source: https://help-plum.xoxoday.com/integrations/hubspot/workflow-based-reward-automation
Learn how to automate rewards using HubSpot workflows connected to Plum's reward automation engine, triggered by contact or deal properties.
Follow the step-by-step guide to set up the integration between Xoxoday Plum and HubSpot.
## Step 1: Log in to your HubSpot account using your credentials.
Now, click on the app marketplace by clicking on the shop icon on the right top corner of your dashboard.
## Step 2: Click on the Install app
Search for Xoxoday Plum in the app marketplace, and click on the “Install” button.
## Step 3: Signup or Sign In on Plum(if you already do not have a plum account)
If you are new to Xoxoday Plum, click on the “Signup” button. It's recommended that you use the email registered with HubSpot to signup with Plum as well.
If you are an existing user, use your Xoxoday credentials to log in to the admin dashboard.
**Congrats, you have successfully installed the application.**
## Step 4: Click on the 'Add Funds' option on the Menu bar to Recharge your Plum
Account for the Reward automation campaign.
## Step 6: Recharging the account
* Click on Add Funds and Proceed with the Payment.
* Click [here](/getting-started/for-admins/wallet-management/funding-the-account) to know more on how to recharge your account.
The recharged amount will now be reflected in your Xoxoday Wallet.
## Step 7: Once you have enough funds in your Xoxoday account, click on the
HubSpot extension to Create a new Reward automation campaign.
## Step 8: Creating a New Automation.
Click on the “Create New” button to start a new Reward Automation.
* Select the **Workflow-based reward automation** as shown below:
* Now, Name the Automation.
## Step 9: Campaign Selection and Email Customization.
You will now be prompted to “Choose your Campaign” to customize your HubSpot Reward Automation. You can also customize your reward email [here](/send-rewards/reward-links/reward-link-customize-reward-communication).
Further to this, before launching your reward automation, you can also change reward trigger settings to either automatically send rewards, or have an approval process to manually approve rewards.
You can also set up a reward distribution logic based on a Custom time range or Maximum Reward count.
Now, click on the **Save & Launch** button to activate the HubSpot Reward automation.
## Step 10: Workflow Creation in HubSpot.
Now, on your HubSpot Account, Under the “Automation” tab, under workflows, click “Create Workflow”. Start a reward automation campaign by clicking on “Start from Scratch”.
You can choose to make a “Contact-based workflow” or a “Company-based workflow” or a “Deal-based workflow”.
Now, name the workflow and click “Next”.
## Step 11: Set-up the reward trigger.
Now, set an enrollment trigger. You can choose to set up the trigger when a lead becomes a new customer. Now, apply the filter and save it.
## Step 12: Select the action upon successful criteria match.
Insert Xoxoday Plum as the action application to automatically send rewards whenever a lead is converted into a customer.
Select from the “reward automation” that you have created a while back for HubSpot and click “Save”.
## Step 13: Select the campaign drop the plum dropdown.
Check your campaign parameters like enrollment, timing, etc., and turn on the workflow.
Congratulations, You have successfully triggered a reward workflow from HubSpot.
# Integrations Overview
Source: https://help-plum.xoxoday.com/integrations/integration-overview
Get an overview of all the integrations available in Plum, covering CRM, HR, survey, and automation platforms you can connect.
*Xoxoday Plum works seamlessly with all the tools you already use! Learn how to leverage integrations to automate rewarding.*
## Plug-n-Play Native Integration
Plum Apps enables seamless integration with leading SaaS platforms in marketing automation, CRMs, customer engagement tools, HR software, collaboration platforms, and more. This integration streamlines workflows and enriches Plum with contextual information, providing a comprehensive perspective on your mutual growth.
### List of Most Popular Integration
* HubSpot
* Salesforce
* Zoho CRM
* ActiveCampaign
* SAP Successfactors
* Darwinbox
* Zoho People
* Qualtrics Using Qualtrics Workflow Extension to Send Rewards
* SurveyMonkey Public Survey Rewarding
* Typeform
#### Here are some of the many PnP integration platform supports. Partial list
### Pro tip
If you don't see an integration list, just reach out to [cs@](mailto:cs@giift.com)xoxoday.com or [plum.product@](mailto:plum.product@giift.com)xoxoday.com
## Customer Experience & Survey Tools
Marketing Automation and CRM tools
## HRMS and People tools
Feedback or Questions: Reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Integrations Report
Source: https://help-plum.xoxoday.com/integrations/integrations-report
Learn how to view the integrations report in Plum to track reward automation activity generated through connected apps.
*Learn all about the Integration Report on your Plum Dashboard.*
## Integration Report
The Integration report offers valuable insights into the integration of Xooday Plum with external systems or platforms. Users can monitor integration status, data synchronization, and troubleshoot any integration-related issues.
## Integration Reports
You can check out the reports for each of the integration in the specific article. Check it out here: [All Integration at a Glance](/integrations/integration-overview).
# Other Integrations
Source: https://help-plum.xoxoday.com/integrations/other-integrations
Explore additional Plum integrations beyond the core CRM, survey, and HR platforms covered elsewhere in this help center.
*Explore the complete range of integrations available on Xoxoday Plum to streamline your rewards, incentives, and engagement programs effortlessly.*
In addition to the existing integrations aforementioned, Plum by Xoxoday offers myriad integrations for marketers, HR teams, support teams, etc. Do check the entire set of integrations **[here](https://www.xoxoday.com/plum-integrations).**
# Anonymous Survey Rewarding
Source: https://help-plum.xoxoday.com/integrations/qualtrics/anonymous-survey-rewarding
See how to automatically reward anonymous survey respondents using the Plum-Qualtrics integration, without collecting identifying details.
*Learn about reward automation for anonymous survey on Qualtrics*
# Introduction
Now you can reward survey respondents anonymously via Xoxoday Plum. In a few simple clicks, you can set up a reward automation campaign in Plum and then attach the reward claim page at the end of your survey to enable quick and instant rewarding of respondents.
Not just that, the survey respondents can choose gift cards of their choice from Xoxoday’s extensive global catalog.
You can also restrict the number of rewards sent out based on criteria like - Campaign Time Range, Maximum Reward count as well as repeated rewarding, etc.
# Getting Started
## Create Reward Automation in Plum
\*\*Step 1:Go to your plum admin account by login in via xoxoday.com or if you are new create a plum admin account by clicking on a try for FREE.**For login go to [https://stores.xoxoday.com/](https://stores.xoxoday.com/) and login with your email and password**
For Signup go to [https://www.xoxoday.com/](https://www.xoxoday.com/) and click on TRY FOR FREE
Step 2: Connect your Qualtrics Account to Xoxoday Plum.
Once you land into your Plum Admin Dashboard, click 'Manage Integrations' option on the left panel, search for Qualtrics and click '**connect'** \*\*
Step 3: Authentication of Qualtrics account
After clicking on the connect option, confirm if you want to proceed with the integration post which you will have to authenticate your Qualtircs account - simply login into your Qualtrics account for the final connection to establish.\*\*
Step 4: Create a new Reward automation campaign for an anonymous survey.
Once the account is authenticated, you will be redirected to the Qualtrics automation page on the Plum Dashboard.
Click **“Create New”** and choose Anonymous to create anonymous survey.
Select a survey for which you want the respondent to be rewarded using **'Select a Survey'** which is intended for anonymous survey responses). You will be able to see the active campaign surveys in the dropdown.
## Step 5: Select the Campaign
Select a Campaign that specifies the rewards you want to send to anonyomous survey respondents.
Step 6: Trigger Setting
**Auto approval: The system will automate the reward once the trigger is met**
* Distribute rewards for a custom time range: You can define the time range till when you want the rewards to be sent
* Max rewards count: Select the number of rewards you want to trigger through this campaign
* Allow repeat rewarding: Same respondent can be rewarded multiple times for filling out the surveys again.
**Manual Approval: Approval to send the rewards to respondents.**
You will be shown all the respondents on the dashboard and you can manually approve them.
Step 7: Save and Launch Automation
Click **'Save and Launch'**.
## **Embed the Reward claim page at the end of your survey**
Once you have successfully created your reward automation and recharged your wallet as well. Then you need to complete the remaining steps in Qualtrics in order to enable anonymous rewarding after survey completion.
Follow the step-by-step guide below :
**Step 1: Open your recently created reward automation** \*\*
Go to your recently created reward automation under integration in Plum admin. Click on the latest automation in the colored tile.
Step 2: Click on ‘ Follow next steps of Automation’ and copy the reward claim page link
Follow the screenshot below and copy the reward claim page link. This link will be embedded at the end of the survey under your Qualtrics account\*\*.\*\* \*\*
Step 3: Now go to your Qualtrics account
Log in to your Qualtrics account and find and open the survey which you have used to create anonymous reward automation in the Plum Admin.\*\*
Step 4: Setup the end of Survey flow
Choose the survey flow option from the left menu, click on +Add a New Element Here and choose End of Survey option.\*\*
Step 5: Add the reward claim page link
Once you click **'End of the survey', click 'Customize' option. Highlight the ‘Override survey option**’ and then choose the third option ‘Redirect to a URL’. Paste the reward claim page link you copied from the reward automation in Plum admin. After completing all steps press OK and Apply all changes.\*\*
Then go back and publish your survey after saving the changes.
Rewards delivered to your respondent anonymously Once any of your respondents fill in your survey and click on complete/submit, they will be automatically redirected to the reward claim page as shown below. For any respondent to claim a reward they have to enter their email ID and submit. The respondents will receive an email with the reward link from which they can redeem the voucher of their choice.
# Public Survey Rewarding
Source: https://help-plum.xoxoday.com/integrations/qualtrics/public-survey-rewarding
Learn how to automatically reward respondents of public surveys through the Plum-Qualtrics integration as soon as they complete a response.
*Learn about setting up integrations, creating and running reward campaigns.*
Follow the step-by-step guide to set up the integration between Xoxoday and Qualtrics, and create & run reward campaigns.
You can find Xoxoday plum on the Qualtrics [marketplace](https://www.qualtrics.com/marketplace/xoxoday-plum-integration/), one can click on the "Get Started" button and fill in the basic information as **First Name, Last Name, company name, etc.**
The Xoxoday team will reach out to you to get you started with the integration.
## Step 1: Account creation and Password Reset
**Once you get confirmation about the account creation, you can visit the URL [stores@xoxoday.com](https://stores.xoxoday.com/marketplace/) and go to the "login option**" and reset the password using the forget password option.
Once the password is reset, you can log in to your account and click on the profile option on the top right beside the "cart" option and select the "**switch to Admin"** option from the drop-down.
## Step 2: Connect your Qualtrics Account to Xoxoday plum.
Once you land into your Plum Admin Dashboard, click **"Manage Integrations**" option on the left panel, search for Qualtrics and click\*\*"Connect"\*\*
## Step 3: Authentication of Qualtrics account
* **Click Connect**: After selecting the "Connect" option, you will be prompted to confirm if you want to proceed with the integration.
* **Authenticate Qualtrics Account**: To finalize the connection, log in to your Qualtrics account when prompted. Once authenticated, the integration will be successfully established.
## Step 4: Create a new Reward Automation Campaign.
Once the account is authenticated, you will be redirected to the Qualtrics automation page on the Plum Dashboard.
Click “Create New” to start a new Reward Campaign. Select "Public" **and click**"Continue"\*\*.
## Step 5: Select the Survey for Campaign
* **Choose a Survey**: Use the\*\*"Select a Survey"\*\* dropdown to pick the survey for which you want respondents to be rewarded.
* **View Active Campaigns**: The dropdown will display all active campaign surveys. Select the appropriate survey to proceed.
## Step 6.1: Set How to Collect Email Addresses
In this step, you will be required to select between the two case
* Please provide your email address to send a reward: Select this if you already have any sample questions collecting the email id of the respondent in the survey.
* Create a question with "email" as input field: Select this if you already do not have any question collecting the email id of the respondent in the survey.
## Step 6.2: Select a Campaign
Select the Campaign which states the denomination and brands of rewardsApproval of the reward delivered can be done in two way:
* Auto Approval
* The system will automatically distribute rewards once the trigger conditions are met.
* **Options under Auto Approval**:
**Distribute Rewards for a Custom Time Range**: Define a specific time range during which rewards should be sent.
* **Max Rewards Count**: Set the maximum number of rewards to be distributed through this campaign.
* **Allow Repeat Rewarding**: Enable this option to allow the same respondent to be rewarded multiple times for filling out the survey again.**2. Manual Approval**
* Rewards will only be sent after manual approval.
* All respondents will be displayed on the dashboard, allowing you to manually approve rewards for distribution.
Now 'Save and Launch'.
Your Qualtrics - Xoxo Plum automation is all set to go!
# Qualtrics: Overview
Source: https://help-plum.xoxoday.com/integrations/qualtrics/qualtrics-overview
Get an overview of the Plum-Qualtrics integration and how it automates respondent reward distribution based on survey completion.
*Learn more about Qualtrics and Xoxoday Plum integration.*
## Overview
Once the integration between the two platforms is enabled, you no longer have to juggle between spreadsheets to track or manage reward campaigns or manually procure and distribute rewards. Xoxoday Plum not only simplifies the rewards process but also adds significant value to the integration. Here are some of the key highlights:
## Automated Rewards on Completion of Survey
The integration allows you to set up Reward automation Campaigns on Xoxoday Plum and send out rewards to respondents who complete the survey. Not just that, the survey respondents can choose gifts, perks, and experiences of their choice from Xoxoday’s extensive global catalog. You can also restrict the number of rewards sent out based on criteria like - campaign time range, Maximum Reward count, etc.
## Built-in Approval Workflows
Integration with Xoxoday lets you control who among your respondents receives rewards. The built-in approval system lets you review and approve respondents individually or in bulk. This ensures that no repeat claims occur.
## Customized Communication Templates
Survey rewards can be sent to respondents through customized email templates to represent your organizational DNA - with your own logo, messaging, and images so they are instantly recognized and don’t get lost in their inbox.
## Extensive Global Catalogue
Xoxoday’s storefront offers an extensive global catalog of 5000+ experiences, 3000+ gift vouchers, and 12000+ perks for your users to choose from. Plum also offers a wide range of reward distribution modes like sending bulk vouchers via emails, SMS, WhatsApp, generation of bulk voucher codes, and distribution through APIs.
## Dedicated Redemption Support
Our API integrations ensure that the redemption process is seamless and non-intrusive for your users. Further to this, we also offer global support for all your user queries during redemption.
## Prerequisite: Adding API Endpoint Access in your Qualtrics account.
**Step 1:** Log in to your Qualtrics account.
Step 2: Select "**Admin**" from the top dropdown.\*\*
Step 3: **Select**"User"\*\*from the header.\*\*
Step 4:\*\* Click on the email id of the user, and a pop-up will appear, where you can tick the Access API as shown below:
Note: The User account must have access to Access API. Some roles who have this access are Brand Administrator, Account Manager, etc.
For any questions or feedback reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Using Qualtrics Workflow Extension to Send Rewards
Source: https://help-plum.xoxoday.com/integrations/qualtrics/using-qualtrics-workflow-extension-to-send-rewards
Learn how to send rewards automatically using the Qualtrics workflow extension connected to Plum, triggered by specific survey events.
First, you'll need to connect Qualtrics and Xoxoday accounts to be able to create a 'Task' inside your Qualtircs Workflow. Follow the steps outlined below:
## Step 1: Find Xoxoday extension
Find Xoxoday Extension from your Qualtrics account. To do this, go to 'Admin' and over to the 'Extensions\*\*' tab. Click on the Xoxoday extension (listed) and follow the steps to connect:
* Click '**Connect Account'** to add a Xoxoday Account.
Connect Account
* Now, login to your Xoxoday account and click **'Allow'** access.
Allow Permissions
# Creating a Qualtrics Workflow
Now, from your Qualtircs account, create a Qualtrics workflow by clicking '**Workflow'** from the main menu (options drop-down):
Create a Workflow in Qualtrics
* Select the 'Survey Response' and choose the survey project you want to send reward (upon completion).
* Click Start by an 'Event' for the Workflow.
* Select '**Newly created Resonse' and 'Response via APIs**'(if applicable). See the below image.
Select Response triggers for your survey as applicable
* Now, click '+' icon to add an action '**Task'** (see below)
Select 'Task' for setting up a Xoxoday Reward action
\*\*Now, select 'Xoxoday' from the available extensions (see below) and select the Xoxoday account.
# Configuring Xoxoday Reward Settings
Here you can configure Xoxoday reward settings for your action task in the workflow. This is a one-time setup and takes just a couple of mins, steps below:
* Select the reward campaign (pulled from your Xoxoday account).
* Approval Required? Select 'Yes\*\*' if you want to manually approve rewards, else, select 'No' to automatically send rewards out,
* Set the **Reward Expiry period** from the drop-down,
You can setup Additional Settings as follows for your Reward Automation:
* Set date range — the period during which this reward automation should be active.
* Maximum Reward count — Define the maximum number of times a reward can be sent for this survey completion.
* Repeat Rewarding — Turn the toggle ON if you want to enable the same email address to be rewarded multiple times.
That's it. Click 'Save' button and then proceed to 'Next' by clicking the 'Next' button.
Map the Survey question corresponding to the Email address
\*\*Here, map the survey question where you're collecting the email address from the recipient — this email address will be used to deliver their Xoxoday reward.
* Select 'Survey Question\*\*' from the main drop-down.
* Then, select the specific question which collects the email address.
* See below.
That's it. You've successfully configured Xoxoday Rewards with Qualtircs Extensions.
# Overview
Source: https://help-plum.xoxoday.com/integrations/salesforce-loyalty-cloud/salesforce-loyalty-cloud
Get an overview of the Plum integration with Salesforce Loyalty Cloud and how it powers automated, loyalty-driven customer rewards.
*Integrate Salesforce Loyalty Cloud with Xoxoday to offer seamless reward redemptions.*
This integration enables loyalty members to redeem loyalty points effortlessly through Xoxoday’s marketplace using SSO or SAML authentication.
# Salesforce Loyalty Cloud Integration
With **Xoxoday’s Salesforce Loyalty Cloud Integration, you can seamlessly redirect your loyalty members from member portal (via Salesforce experience cloud or your own mobile app) to Xoxoday’s global marketplace (storefront) for reward redemption. This integration ensures a frictionless experience by supporting SSO (Single Sign-On) or SAML-based authentication**, allowing loyalty members to log in effortlessly to Xoxoday’s hosted storefront.
## Why integrate Salesforce Loyalty Cloud with Xoxoday?
Leverage Salesforce Loyalty Points Use Salesforce Loyalty Cloud’s points engine to allocate loyalty points while allowing loyalty members to redeem them seamlessly through **Xoxoday’s reward catalog**.
**Seamless Authentication** **Enable SSO or SAML-based authentication**, providing secure and hassle-free access to Xoxoday’s storefront for redemptions.
Once loyalty members enter the storefront, Xoxoday’s system will consume your **Salesforce endpoints** to:
* **Fetch accrued loyalty points** from Salesforce
* **Post back the spent points** after redemption
***
## Salesforce Loyalty Cloud API Endpoints Consumed by Xoxoday
## FetchPointsAPI
Xoxoday consumes this API to fetch an employee’s available **Salesforce Loyalty points** for redemption.
* Method:GET **Sample Data**
**Required?**
**Description**
userId
jsmth23
Unique **Salesforce Loyalty Cloud user ID**, passed during the SSO session. Xoxoday uses this to fetch loyalty points.
availableAmount
8925.15
Available **loyalty points** accrued by the user, ready for redemption.
***
## Security & Authentication
## Xoxoday requests originate from the following IP addresses:
## Staging
* 50.112.248.135
* 54.184.56.156
* 52.24.158.163
* 34.217.113.26
* 54.185.176.191
## Production
* 52.76.120.90
* 52.74.39.101
* 52.221.42.47
* 46.137.196.217
## Xoxoday requests originate from these domains:
## Staging
* [https://stagingstores.xoxoday.com](https://stagingstores.xoxoday.com/)
* [https://stagingaccount.xoxoday.com](https://stagingaccount.xoxoday.com/)
* [https://staging.plum.gift](https://staging.plum.gift/)
## Production
* [https://stores.xoxoday.com](https://stores.xoxoday.com/)
* [https://accounts.xoxoday.com](https://accounts.xoxoday.com/)
* [https://app.xoxoday.com](https://app.xoxoday.com/)
* [https://plum.gift](https://plum.gift/)
***
This integration ensures a smooth and secure experience for **Salesforce Loyalty Cloud loyalty members, enabling them to redeem their loyalty points effortlessly via Xoxoday’s storefront**.
# Salesforce Loyalty Onboarding Guide for Xoxoday Plum
Source: https://help-plum.xoxoday.com/integrations/salesforce-loyalty-cloud/salesforce-loyalty-onboarding-guide-for-xoxoday-plum
Follow this onboarding guide to connect Xoxoday Plum with Salesforce Loyalty Cloud and set up automated loyalty reward disbursal.
This guide outlines the steps required to integrate Xoxoday Plum with **Salesforce Loyalty Cloud. By completing this onboarding process, customers can seamlessly connect their Salesforce Loyalty account** with Xoxoday to enable automated rewards and incentives.
***
## Step 1: Logging into Salesforce Loyalty Cloud
* Open a web browser and navigate to your **Salesforce Loyalty Cloud login page**.
* Enter your **username and password, then click Login**.
* Ensure that you have the necessary **admin permissions** to install external apps.
***
## Step 2: Installing the Xoxoday App Package in Salesforce
* Navigate to Salesforce AppExchange and search for the **Xoxoday Plum Integration Package**, or use the link below:[Xoxoday Plum, Version 1.5](https://login.salesforce.com/packaging/installPackage.apexp?p0=04tJ3000000kaLr)
* Choose the Salesforce environment (Production or **Sandbox**) where you want to install the package.
* Follow the **on-screen prompts** to complete the installation.
* Once installed, ensure that all **necessary permissions** are granted for the app to function properly.
##
## Step 3: Connecting Salesforce Loyalty Cloud with Xoxoday Plum
## 3.1. Logging into Xoxoday Plum
* Open a new browser tab and navigate to **Xoxoday Plum**.
* Enter your **Xoxoday login credentials** and sign in.
## 3.2. Navigating to the Integration Page
* Once logged in, go to the Integration page from the **Xoxoday dashboard**.
* Locate the **Salesforce Loyalty** card in the list of available integrations.
## 3.3. Initiating the Connection
* Click the Connect button on the **Salesforce Loyalty integration card**.
* You will be redirected to the **Salesforce login page**.
## 3.4. Logging into Salesforce Loyalty
* Enter your Salesforce Loyalty credentials and click **Login**.
* After successful authentication, you will be prompted to **approve permissions**.
## 3.5. Approving Permissions
* Review the list of permissions required for Xoxoday to function within **Salesforce Loyalty**.
* Click **Allow** to grant access.
##
## Final Steps & Confirmation
* Once the connection is **approved, you will be redirected back to Xoxoday Plum**.
* A **confirmation message** will indicate that the integration has been successfully established.
* The Salesforce Loyalty Integration Card on Xoxoday will now show a **Connected** status.
This completes the Salesforce Loyalty & Xoxoday Plum integration. Your users can now seamlessly redeem **loyalty rewards** using Xoxoday’s marketplace.
## Standard Workflow for Salesforce Loyalty Cloud Integration
# Create a Flow and Add Trigger Rewards
Source: https://help-plum.xoxoday.com/integrations/salesforce/create-a-flow-and-add-trigger-rewards
Learn how to build a Salesforce Flow and add trigger-based rewards, so points or gift cards are sent automatically when conditions are met.
*Learn how to create a flow in Salesforce.*
# Creating a Flow in Salesforce for Xoxoday Plum Reward Automation
Before you get into creating your flows, you need to Create a Campaign and automation in Xoxoday Plum, Add the Xoxoday Refresh widget, and refresh it, to have all your old and new automation synced in.
Step 0: Once you have added the widget, click\*\*"Refresh".**Step 1: On the homepage, Go to Navbar->Select Setup and Click**"Setup"**Step 2: On the Setup Dashboard, Search for "Flows" under Process Automation and Click**"New Flow".**Step 3: Now select the template type and Configure the Start Trigger Settings, Under Object: Select Lead/Contact and Click**"done".\*\* \*\*
Step 4: **Now next step would be to add a new element: from options select**"Create records".\*\* \*\*
Step 5: Edit the Create Records settings and under object look for "XoxodayRewardFlowAutomations" and then Click "Done".\*\* (refer to above image)
Step 6: Now add another element and Select "\*\*Get Records".\*\*Step 7: Edit the Get Records settings and under object look for "XoxodayRewardFlowAutomations" Once done, "Filter XoxodayRewardFlowAutomations Records" has to be updated. - In fields select "id" - In Values look for "Record (single) variables" ->Select your Xoxoday automation->Select "ID".
Step 8: **Now the element that has to be added is "Action":** Add element->Select Action->Uncategorised-> Action name: Xoxoday Plum Reward API.
**Step 9:** Update Input fields as per your flow (refer below image)
Step 10: Now "Save" your flow and **Activate** it.
# Getting Started - Xoxoday Plum and Salesforce Integration
Source: https://help-plum.xoxoday.com/integrations/salesforce/getting-started-xoxoday-plum-and-salesforce-integration
Get started with the Xoxoday Plum and Salesforce integration, covering setup basics and how automated reward distribution works.
*Learn about integrating Xoxoday Plum and Salesforce*
# Creating a Reward Link Campaign
\*\*Step 1: Login/Signup \*\*to your Xoxoday account [here](https://stores.xoxoday.com/admin/signup).\*\*
Step 2: **On the Admin Dashboard, navigate to **Settings > Campaigns**, Select Reward Link Campaign, and click**"Create New".
Step 3:\*\* Choose a Name
Choose a descriptive and memorable name for your campaign to easily identify it later. Consider including the campaign objective or target audience in the name.
Step 4: Customize your Catalogue as per the Country, Denomination of the Campaign, and Select your Vouchers. Once done click\*\*"Save and Close".\*\* \*\*
Step 5:\*\* Personalized Communication
Customize your email and SMS campaigns to resonate with your audience. Use personalization tokens to address recipients by name and segment your messaging based on demographics or past interactions.
Learn more here: [Customize Reward Communication](/send-rewards/reward-links/reward-link-customize-reward-communication)
Step 6: Click\*\*"Preview"\*\* and now you can edit the redemption page background.
Step 7: Click "**Update Campaign"** and you are good to go!
# Integrating Xoxoday Plum and Salesforce
Step 1: Click on Salesforce Integration under Manage Integration and select "**Connect"** to sync Salesforce with Xoxoday Plum.
Once you click on the "Connect" button, you will be taken to the salesforce page to finish connecting both Platforms. Refer to the below link for the Steps.
[Getting Started and Setting up Salesforce Integration](/integrations/salesforce/salesforce-overview)
# Redemption Journey for your Recipients
Source: https://help-plum.xoxoday.com/integrations/salesforce/redemption-journey-for-your-recipients
See the full reward redemption journey your recipients experience after receiving a reward through the Plum-Salesforce integration.
**Once you have sent rewards to your users, the reward mail lands up in their Mailbox. If you have not sent the reward yet refer to:**
[Sending 1-1 Reward](/integrations/salesforce/send-1-1-reward)
[Steps to create a Flow and add a Trigger](/integrations/salesforce/create-a-flow-and-add-trigger-rewards)
## Steps to Redeem a Reward
**Step 1:** Check your mail for the reward email:
Step 2:Click on "Redeem now".**Step 3:** This will open the Campaign Catalogue for you to select your voucher.
**Step 4:** Select the Voucher of your preference and Click "Collect Voucher"
**Step 5:** This will give you a unique code to redeem at the partner store/website.
# Salesforce Integration
Source: https://help-plum.xoxoday.com/integrations/salesforce/salesforce-overview
Get an overview of the Plum-Salesforce integration and how it connects CRM workflows to automated reward disbursal for your contacts.
*Learn more about Salesforce integration with Xoxoday Plum*
## Introduction to Salesforce Integration with Plum
Plum's Salesforce integration empowers you to capture, engage and motivate your Clients/Contacts by inculcating personalized rewards, incentives, gift cards, etc. The seamless integration between the two platforms allows you to analyze and track details like the number of campaigns running, the number of gift coupons sent, etc. from either platform, without having to juggle between the two.
## Benefits of the integration
* This integration helps sales and marketing teams send rewards to Leads and Contacts directly from Salesforce.
* A seamless experience for the admins and end-users.
* Simple 4-step rewarding process: - Install the app - Choose the campaign - Send reward link - Track rewards sent
## Salesforce+Plum Integration for Marketing Teams:
* Account-based marketing (ABM)
* Demand Generation
## Salesforce+Plum Integration for Sales Teams:
* Re-engage cold leads
* Book more meetings
* Boost customer referrals
## Security and Compliance
Xoxoday platform meets the highest certification standards to help reduce compliance burdens for your business and keep payouts safe.
* Encryption of sensitive data
* HTTPS and HSTS for secure connections
* Vulnerability disclosure and reward program
Write to us at [cs@xoxoday.com](mailto:cs@xoxoday.com) for any questions or feedback.
# Send 1-1 reward
Source: https://help-plum.xoxoday.com/integrations/salesforce/send-1-1-reward
Learn how to send an individual one-to-one reward directly from Salesforce using the Plum integration, without switching tools.
*Learn how to send rewards using Salesforce and Xoxoday Plum.*
# Select, Customize and Send a Reward
**Prerequisites**
Salesforce CRM users who need access to 1-1 rewards widget should be added as a user in Xoxoday Plum with Admin or Super admin access as required.
Once the Xoxoday Reward Widget is added to your lead's dashboard, follow the steps given below to send rewards to your prospects.
Step 1: On the Leads/Contacts Page, Under Xoxoday refresh automation widget-> Click\*\*"Refresh".**Step 2.1: Under the Xoxoday reward widget, Select Name, Email, Campaign, Reward Amount and Click**"Next".\*\* \*\*
Step 2.2: If you have not already created a Campaign, Select "Create a Campaign"\*\* in the widget. or Create one from [here](https://stores.xoxoday.com/admin/campaign/).
## Getting Started with Xoxoday Plum
Step 3: **Customize the Email template, Select the banner most relevant to your campaign type and then Click** "Send Reward".
Congratulations! On sending your first 1-1 Reward.
# Setting up Salesforce Integration
Source: https://help-plum.xoxoday.com/integrations/salesforce/setting-up-salesforce-integration
Follow this step-by-step guide to setting up the Plum-Salesforce integration so your team can automate reward distribution from CRM records.
*Learn how to set up Salesforce Integration.*
# Steps to Install Salesforce Integration
Step 1: Sign in to Salesforce using your credentials:\*\*
Step 2. **Go to Apps-> AppExchange marketplace-> Search Xoxoday Plum and Click on**"Get it now!**": This will install plum on your salesforce.**//App once published, add an image
There are three options for installing your app:
* Install for Admins only
* Install for all users
* Install for Specific Users
This helps you in giving this app to required people and restricts everybody else.
**Congrats, you have successfully installed the application.**
# Steps to Authenticate and Connect
Before you start sending any rewards your connection to Xoxoday Plum AppExchange integration has to be authenticated with your specific callout end-points URL and authentication settings, this helps Salesforce to make callouts to Xoxoday's remote system.
Step 1: In the home section: Go to Setup->Users->select users->Auth settings for external -> Named Credential.
Step 2: Under **Authentication-> Select Authenticator Provider->Click Edit->Under Authentication Protocol select Auth2.0.**
Step 3: Now under Authentication Provider-> Click on the search option and look for **"XOXODay\_AuthProvider" and then Click "Save".**
\*\*
Step 4: \*\*Once Saved, It will take you to connect Salesforce with Xoxoday Plum. Click "Allow". If everything looks good, then you'll be taken back to Salesforce.\*\*
Congrats, you have successfully authenticated.
# Adding 1-1 Widget
\*\*Once the installation is done and you have finished the authentication, now you can access widgets by Xoxoday Plum to send your rewards.
Step 1:\*\* On the Salesforce homepage-> Select either Leads or Contacts-> Select a Lead (to whomsoever you wish to send a reward)
Step 2: From the **Navbar-> Select the Setup icon->Select Edit Page**. Under Components search for\*\*"Xoxoday"-> Drag and drop "Xoxodayreward"**on page**
Step 3: \*\*Click "Save" and you have successfully added the Xoxoday reward widget.
# Adding Refresh Widget for Automation
Once the installation is done and you have finished the authentication, now you can access widgets by Xoxoday Plum to send your rewards.
**Step 1:** On the Salesforce homepage
Step 2: From the Navbar-> Select the Setup icon->Select Edit Page. Under Components search for "Xoxoday"-> Drag and drop "**XoxodayRefreshAutomations**" on page.\*\*
Step 3: \*\*Click "Save" and you have successfully added the XoxodayRefreshAutomation widget.**Congrats, On successfully adding both the Xoxoday Widgets.**
# SAP Client Registration with Xoxoday for Stores Redemption
Source: https://help-plum.xoxoday.com/integrations/sap-successfactors/sap-client-registration-with-xoxoday-for-stores-redemption
Learn how to register your SAP client with Xoxoday to enable employees to redeem their rewards through the store redemption flow.
*Learn the technical details of integrating SAP® with Xoxoday Plum.*
# Overview
\*\*Xoxoday Plum acts as a Redemption Partner for SAP SuccessFactors. Points assigned to Employees on SAP SuccessFactors can be redeemed in Plum’s Marketplace via SSO Sign-On.
Employees can choose amongst the options available in the catalog and redeem their points.
The Plum rewards application is now available on the SAP SuccessFactors and is listed in the SAP App Center.
## Key User journeys
* Point Distribution & Wallet recharge\*\* \*\*Your customers' HR Admin user sets up a wallet fund and distributes Points to employees by SAP SuccessFactors Reward Program.
* Point Balance for Employee\*\* \*\*Employees of your customers can view their Points directly within your SAP Successfactors Recognition portal.
* Reward Redemption
Employees can click on a Button enabled inside the SAP app to redeem rewards. Xoxoday
* Plum auto-identifies and authenticates via an OAuth 2.0 SSO and the Employee\_user is redirected to the Plum dashboard, where they can explore the catalog and complete their redemption.
Xoxoday Plum sends the voucher details to employees' inbox
* **Balance Update**
The client application can get the Points balance by making an API call to Xoxoday Plum.
# Redemption on Xoxoday for Points-Based Award Programs
In a points-based program, recipients receive points instead of direct compensation. The system converts the points to virtual currency that employees redeem with Xoxoday.
**Connections to Xoxoday must be enabled before a points-based award program becomes active.**
Multiple steps are required for setting up redemption options. Configuration and sign-on to partner sites are only part of the requirement.
\*\*You also create different accounts, or wallets, for the points and how the points are redeemed.
Note\*\*: Award recipients can view their reward balances through the user interface. When converting points, the system rounds amounts to 2 decimal places. For amounts halfway between, the system rounds up.
To set up the program and setup Integration with Xoxoday:
* Enable points-based settings in Manage Award Program Settings
* Establish a connection with **Xoxoday** through whom employees redeem their awards.
* Configure a Single Sign-On connection with Xoxoday and configure **API communications**.
* Set up the points-based awards program, designate the redemption partner as Xoxoday, and configure the wallet (account) used to accumulate and then redeem the points.
## Step 1: Enable Point-Based Settings
* Enable points-based setting in the **Manage Award Program Settings**.
* Visit Reward and Recognition > Manage Award Program Settings and select the checkbox ‘**Enable Points Based Programs**’
## \*\*Step 2: Establishing a Single Sign-On (SSO) Connection with Redemption Partner Xoxoday.
* After enabling the points-based program, you next set up Single Sign-On connections with the partners that will fulfill your employees' requests to redeem their points. Note that part of this process involves contacting SAP SuccessFactors Technical Support.
* To expedite the process for you, please make sure that you are guided by Customer Success Partner from Xoxoday.
Context
When working with the partner Xoxoday, your company instance is referred to as the Identity Provider (IDP). Xoxoday is referred to as the Service Provider (SP).
\*\*Configuring API Communications with XOXODAY Redemption Partner \*\*The Reward and Recognition module shares information with redemption partner XOXODAY Web sites through API calls. To enable partners to configure their systems, you need to gather some critical information and add it to the Integration setup screen in Xoxoday:\*\*
Company ID, API Key, Private Key, and Base API URL\*\*.
There are a number of steps required to retrieve the Private Key and **API Key**.
### Prerequisites
You have the role-based permission for **Manage OAuth2 Client Applications**.
### Procedure
1. Within your SAP SuccessFactors instance, go to **Admin Center Manage OAuth2 Client Applications**.\*\*
2. Select Register Client Application\*\* \*\*
3. Company will be auto-populated with CompanyID
4. Add Application Name as ‘**Xoxoday Plum**’
5. Add Description as:\*\*Rewards by Xoxoday Plum **6. Set Application URL field:** [https://www.xoxoday.com](https://www.xoxoday.com/)
Now, to **Generate Private Key**,
(i) Select **Generate X.509 Certificate**.\*\*
A new panel appears.
(ii) Enter the same value into Common Name (CN) \*\*that you entered into Application Name previously.**
(iii) Select Generate.The system returns you to the previous panel and fills in the X.509 Certificate **field.**(iv) Select Download**.
\*\*The system allows you to download the X.509 certificate once only.
(v) Open the X.509 Certificate - named certificate.pem **- and search for the string** ----BEGIN ENCRYPTED PRIVATE KEY-----
The Private key is between -----BEGIN ENCRYPTED PRIVATE KEY----- and\*\*-----END ENCRYPTED PRIVATE KEY-----\*\*
\*\*Copy the Private Key
To get the value for API Key\*\*, proceed as follows:
From the Manage OAuth2 Client Applications page, select View next to the **Application Name** you created in the previous set of steps.
* Copy the value for **API Key**.
* Note the Company ID for your SAP SuccessFactors instance. Use it for **Company ID**.
To create the Base API URL, use the Endpoint URL Patterns from the [List of SAP SuccessFactors API Servers](https://help.sap.com/docs/SAP_SUCCESSFACTORS_COMPENSATION/70b6f618048540f0847db586847bc14d/af2b8d5437494b12be88fe374eba75b6.html).\*\*To Retrieve the Security Assertion Markup Language (SAML) Metadata file \*\*for your company's instance, which you find at:**YOUR-INSTANCE-URL/idp/samlmetadata?company=YOUR-COMPANY-ID**
YOUR-INSTANCE-URL **depends on the data center where your company instance is located, and**YOUR-COMPANY-ID \*\*is the Company ID for your instance.\*\*Add the extension .xml to the SAML Metadata file.
Now, You have:
* API Key
* **Private Key**- **Base API URL**- **SAML File**
# Step 3: Setup Account in Xoxoday Plum
Proceed to: Navigate to Integrations > SAP SuccessFactors. Click on the ‘Configure\*\*’ button.\*\*
Step 1: Add API Details
Add the asked details and credentials collected from the above steps.
### Step 2: UPLOAD SAML METADATA
### Upload the SAML file generated from the above steps.
On Successful upload of SAML file
You will get:
Assertion Consumer Service URL
Logout URL Open a ticket with SAP SuccessFactors Technical Support with the following code: LOD-SF-RNR-SCR and provide Technical Support with the Assertion Consumer Service URL and **Logout URL** you gathered.
Technical Support adds the Assertion Consumer Service URL - along with the Logout URL - to its list of Authorized Service Provider Assertion Consumer Services.
Once, you have verified that Technical Support has added Assertion Consumer Service URL - and Logout URL.
Select Checkbox ‘Please Verify that URLs are added by SAP’
and proceed to the next step by clicking on the ‘**Save and Proceed**’ button
### Step 3: Test Login
# Redemption Process
\*\*Xoxoday use the SAP SuccessFactors APIs to request the following information:
* First and last name
* Email address
* Mailing address
* Phone number
* Country/Region
* Award balance
* Currency type
When an award recipient initiates a transaction with a redemption partner i.e. Xoxoday, Xoxoday sends a transaction log to SAP SuccessFactors by means of the Redemption API.
The log includes the details of the transaction.
For example, transaction ID, order and product details, user initiating the transaction, and so on. The award recipient's balance is adjusted in the Reward and Recognition award wallet.
Note\*\* There may be additional configurations or restrictions required by the redemption partner when using multiple wallets.
# SAP Successfactor: Overview
Source: https://help-plum.xoxoday.com/integrations/sap-successfactors/sap-successfactor-overview
Get an overview of the Plum-SAP SuccessFactors integration and how it automates HR-driven employee reward distribution from your HRMS.
*Learn more about SAP SuccessFactor integration with Xoxoday Plum.*
## The purpose of the association
Xoxoday Plum is an API-driven digital rewards platform offering a global catalog with over 10 million redemption options across 55+ countries, including 2,000+ digital gift cards, 10,000+ international experiences, and 10,000+ perks.
Ideally suited for SuccessFactors® users worldwide, Plum ensures effortless scalability and seamless integration. It empowers organizations of any size to streamline reward redemption, providing employees with a vast range of aspirational and meaningful rewards.
## Benefits of the integration
* ## Employee rewarding made easy
Xoxoday Plum takes care of the redemption process and delivery while helping you save on your precious time.
* ## Help employees save money
Employees are happier when they get to save on their monthly expenses by using various perks and offers on daily usage.
* ## Global catalog to choose from
Xoxoday Plum supports redemption in more than 70 countries which makes for a unified experience for your employees across locations.
* ## Dedicated Support
Xoxoday Plum goes the extra mile to make sure that the redemption process is seamless and non-intrusive. Still, in case of any queries, you can count on us.
* ## Instant Delivery
Instant delivery of vouchers/experiences via email and SMS. All the logistics challenges are taken care of by Xoxoday right from curation to delivery.
* ## Thematic experiences
Experiences that appeal to the users across demographics. Themes like ‘Family Time’ and ‘Solo Travellers’ contain specially curated experiences personalized to delight all employees.
* ## Simple checkout
Finding the right experience or brand voucher is just a search away supported by a simple checkout experience that supports SSO and guest checkout.
* ## Employee rewarding made easy
Understand the effectiveness of the program with in-depth insights on redemption patterns and feedback of employees.
## Getting Started with the Integration
Step 1: Administrator Access
* Upon enabling the Xoxoday Plum integration, a reset password link is sent to the registered company email.
* The registered email acts as the administrator account for configuration and management.
**Step 2: Initial Setup**
* Log in and update platform settings, including:
Conversion factor
* Time zone
* Company logo and themes
* Receive the SAP® SuccessFactors® Client API Configuration, which includes:
Company ID
* API Key
* Private Key
* Base API URL
* Upload IDP Metadata (one-time process) to enable Single Sign-On for employees.
**Step 3: Configuration Verification**
* Verify the setup by checking the configuration module’s status report.
**Step 4: Employee Access**
* Employees can redeem points collected in SAP® SuccessFactors®.
* Single Sign-On redirects them to Plum, where they can choose from the reward catalog to redeem points.
**Step 5: Availability**
* The Xoxoday Plum rewards app is listed on the SAP® App Center.
* Contact our rewards consultants to explore the Xoxoday-SuccessFactors® integration.
## Redemption procedure
* Log in to your SAP SF account.
* On the Home tab, click '**Compensation'.**- See your points accumulation and click\*\*'Redeem'.\*\*
* Get redirected on [stores.xoxoday.com](https://docs.xoxoday.com/docs/stores.xoxoday.com), you can see point balance sync here.
* Select your Country & click on Gift Vouchers, experiences, or any other classification of your choice.
* Select an option to checkout.
* Select the denomination, and quantity and then click **“Add to Cart”.**
* On the payments page, click on Use xoxo points and then place the order. You may use a debit/credit card to pay additional points.
Reach out to [cs@xoxoday.com](mailto:cs@xoxoday.com) for any questions or feedback.
# Survey Incentive Management with MRBuddies
Source: https://help-plum.xoxoday.com/integrations/survey-incentive-management-with-mrbuddies
See how the Plum-MrBuddies integration lets you manage and automate survey incentive distribution to respondents at scale.
*Learn more about integrating MRBuddies with Plum*
## About MRBuddies
MRBuddies (by TechBuddies) is a market research project management ERP that streamlines the entire research lifecycle—from client and project management to supplier coordination and panelist engagement. It helps organizations reduce costs, eliminate redundancies, and accelerate outcomes with integrated tools for sales, fraud detection, and engagement.
## Why Connect MRBuddies with Xoxoday Plum?
Integrating MRBuddies with Xoxoday Plum automates survey incentive distribution within a unified platform. Researchers can efficiently manage projects and instantly reward participants from Plum’s global catalog of 26,000+ options, while ensuring seamless workflows from recruitment to fraud screening.
## Key Benefits of the Integration: MRBuddies + Xoxoday Plum
* **Automated & Unified Incentive Management** \*\* Automatically trigger reward campaigns upon survey completion and manage survey invitations, tracking, and incentive distribution from a single dashboard—eliminating manual tracking or spreadsheets.
* Configurable Reward Logic & Fraud Protection\*\* \*\* Set dynamic reward rules based on completion rate, region, or project type, while MRBuddies’ FraudCop and Plum’s secure APIs ensure only verified participants receive rewards.
* Personalized & Seamless Reward Experience\*\* \*\* Deliver branded reward notifications instantly via email or WhatsApp, with access to Xoxoday’s global catalog of 26,000+ options across 5,000+ brands for richer redemption experiences.
* Real-Time Tracking & Insights\*\* \*\* Monitor reward dispatch, redemption status, and engagement metrics through integrated dashboards and analytics—enabling better visibility and ROI measurement.
* Global Reach with Local Compliance\*\* \*\* Run multi-country campaigns effortlessly with built-in currency conversion, taxation compliance, and localized redemption options.
## Benefits for Your Business
* Boost Response Rates and Data Quality Automated, fraud-proof incentives motivate genuine participation, improving survey completion rates and ensuring higher-quality, more reliable data.
* Save Time with End-to-End Automation Seamless integration between MRBuddies and Xoxoday Plum eliminates manual reward tracking, enabling instant payouts and streamlined operations for market research teams.
* Deliver Instant Gratification Globally Reward respondents, vendors, and panelists instantly across 100+ countries with Plum’s vast digital catalog—ranging from e-gift cards to travel and lifestyle experiences.
* Increase Engagement and Loyalty Personalized, flexible rewards drive sustained respondent engagement, vendor satisfaction, and stronger long-term relationships across your market research ecosystem.
* Gain Real-Time Visibility and Control Comprehensive dashboards provide insights into project performance, budget utilization, and reward redemption—empowering data-driven business decisions.
## How Xoxoday Customers Benefit
As a valued Xoxoday customer, you can now access MRBuddies’ advanced market research automation and data management solutions at exclusive rates. This collaboration helps you:
* Automate survey operations and panel management
* Reward respondents instantly through integrated Xoxoday Plum payouts
* Enhance data accuracy with real-time fraud detection
* Streamline vendor and project workflows from one unified dashboard
Together, Xoxoday and MRBuddies empower research-driven organizations to move from manual processes to intelligent, reward-linked automation—driving faster insights, higher participation, and improved ROI.
## Get Started
Discover how MRBuddies can transform your research automation journey. Contact [cs@xoxoday.com](mailto:cs@xoxoday.com) to learn more.
# Anonymous Survey Automation
Source: https://help-plum.xoxoday.com/integrations/surveymonkey/anonymous-survey-automation
Learn how to automate rewards for anonymous SurveyMonkey respondents using the Plum integration, without collecting identifying data.
*Learn all about automating rewards for anonymous surveys,*
## How does it work?
For Anonymous surveys in SurveyMonkey, Xoxoday uses the contact email of a SurveyMonkey respondent(s).
**Pre-requisites**
* Integration Setup: Ensure that Xoxoday is already connected with SurveyMonkey. If not, follow the integration guide to complete the setup.
* Campaign Creation: Verify that a campaign has been created in Xoxoday to align with your SurveyMonkey survey.
**Feature Specification:** Only the ones who are part of the Email collectors in SurveyMonkey will be eligible to redeem their rewards, anyone apart from that will not have access.
# Steps to send rewards to Anonymous surveys
## Step 1: Create Anonymous Automation
Click ‘Create New Automation’ and select the ‘Anonymous’\*\* option modal.
## \*\*Step 2: Accept Guidelines
Read the guidelines mentioned in the modal and accept it by clicking to select option ‘I understand the above guidelines’ and click ‘Continue’.
## Step 3: Setup your Automation
Select the survey of your choice and set Reward settings by setting Manual or Automatic approval. You can also set the automation start date and end date with a limit on rewards sent.\*\*
## Step 4: Save and Launch
Once automation is launched, the settings cannot be changed.\*\*
Step 5: Add Reward URL in Survey End Page
Copy the reward claim page URL >> In SurveyMonkey, select the Email Collector\*\*>> then, click 'options' and select\*\*'Survey End Page >> Select Redirect a URL >> Paste the reward URL\*\* here. Copy the given link.
## \*\*Refresh Email Collector
By Refreshing the Email Collector, our system will fetch new collectors and emails added to this survey. The new email address will be added to Eligible list for rewards. Only emails added in eligible list can receive rewards.
Go to the details page of Automation.
Select the ‘Refresh Email Collector’\*\* button.
# Public Survey Automation
Source: https://help-plum.xoxoday.com/integrations/surveymonkey/public-survey-automation
See how to automate rewards for respondents of public SurveyMonkey surveys through the Plum integration as soon as they submit.
*Learn how to send rewards to public surveys.*
## How does it work?
For Anonymous surveys in SurveyMonkey, Xoxoday uses the contact email of a SurveyMonkey respondent(s).
* **Integration Setup**: Ensure that Xoxoday is already connected with SurveyMonkey. If not, follow the integration guide to complete the setup.
* **Campaign Creation**: Verify that a campaign has been created in Xoxoday to align with your SurveyMonkey survey.
Feature Specification: Only the ones who are part of the Email collectors in SurveyMonkey will be eligible to redeem their rewards, anyone apart from that will not have access.
# Steps to send rewards to public surveys
## Step 1: Create Public Automation
Click **‘Create New Automation**’ and select the\*\*‘Public’\*\* option modal.
Step 2: Select a Survey
Select a Survey that you want to send rewards through. To collect email addresses to send rewards, please select the question in your surveying 'Choose a existing Question' where respondents will enter their email.
If you don't have a question that collects email addresses, you can add the question in survey by selecting 'Create a new Question' and add a Question.
This question will appear as the last question in survey.
## Step 3: Setup your Automation
Select the survey of your choice and set Reward settings by setting Manual or Automatic approval. You can also set the automation start date and end date with a limit on rewards sent.
## Step 4: Save and Launch
Once automation is launched, the settings cannot be changed.
# SurveyMonkey and Qualtrics Integration
Source: https://help-plum.xoxoday.com/integrations/surveymonkey/surveymonkey-overview
Get an overview of the Plum-SurveyMonkey integration and how it automates reward distribution to survey respondents.
*Learn all about integrating Survey Monkey and Xoxoday Plum*
### Introduction
Building a strong panel for your survey to collect insights that are accurate, insightful, and meaningful takes a lot of effort. But that’s definitely not the end of it. The success of the survey depends on how many of these people actually respond to the survey.
A Low response rate is one of the biggest challenges that most marketers face while conducting a survey.
So how do you encourage people to respond to your surveys? How can you improve the response rate to get better insights?
One of the most widely adopted, and not-so-secret motivator that nudges respondents to complete surveys is instant rewards, incentives, and benefits.
Xoxoday Plum, with SurveyMonkey, has integrated to empower organizations to significantly improve survey response rates by engaging the respondents with automated digital rewards and benefits.
The seamless integration between the platforms ensures a superior user experience by eliminating any kind of manual gift-code management. You can now simply create a reward automation campaign on Xoxoday Plum to automatically send rewards to all respondents who complete the survey.
## Highlights of the Integration
Once the integration between the two platforms is enabled, you no more have to juggle between spreadsheets to track or manage reward campaigns, or manually procure and distribute rewards. Xoxoday Plum not only simplifies the rewarding process, but also brings a host of value addition to the integration. Here are some of the key highlights:
## Automated Rewards on Completion of Survey
The integration allows you to set up Reward automation Campaigns on Xoxoday Plum and send out rewards respondents to complete the survey. Not just that, the survey respondents can choose gifts, perks, and experiences of their choice from Xoxoday’s extensive global catalog.
You can also restrict the number of rewards sent out based on criteria like - campaign time range, Maximum Reward count, etc.
## Built-in Approval Workflows
Integration with Xoxoday allows you to have complete control over who among your respondents to send the rewards to. The built-in approval system lets you review and approve respondents individually or in bulk. This ensures that there are no repeat claims that take place.
## Customized Communication Templates
Survey rewards can be sent to respondents through customized email templates to represent your organizational DNA - with your own logo, messaging, and images so they are instantly recognized and don’t get lost in their inbox.
## Extensive Global Catalogue
Xoxoday’s storefront offers an extensive global catalog of 5000+ experiences, 3000+ gift vouchers, and 12000+ perks for your users to choose from. Plum also offers a wide range of reward distribution modes like sending bulk vouchers via emails, SMS, WhatsApp, generation of bulk voucher codes, and distribution through APIs.
## Dedicated Redemption Support
Our API integrations ensure that the redemption process is seamless and non-intrusive for your users. Further to this, we also offer global support for all your user queries during redemption.
## How does the Integration Works?
Follow the step-by-step guide to set up the integration between Xoxoday Plum and SurveyMonkey, and create & run reward campaigns.
## Step 1: Go to SurveyMonkey App Marketplace → Search for Xoxoday Plum
## Step 2: Click on the “Install” button to connect with Xoxoday Plum.
Step 3: Now, you will be redirected to the Xoxoday app registration process
Log in/Sign-up to your Xoxoday account with admin credentials to access to Xoxoday admin dashboard.
## Step 4: Fill in the details
* Company Name: It will be used for customer communication and invoicing purposes.
* Currency: The currency selected will be used for all your transactions
* Tax ID: The company Tax ID will be used to issue the invoices for your transactions
* Password: You will be asked to create a password
## Step 5: Create Public Survey Automation
* Click 'Create New'\*\* on the Automation page.
* Select Public Surveys and click **'Continue'.**
## Step 6: Select Survey
Select the Survey from the list of SurveyMonkey surveys that you want to use to provide rewards.
In the survey, one should have a question type as email type or enter the question as email type in the campaign
## Step 7: Setup Rewards Settings
* Select a Campaign.
* Link Expiry- Select an end date when the links will expire.
* Manage Approval method: Manual or Auto.
* Click the "Customize Email" option.
* Automation Date range
* Reward Limit and
* Repeating rewards.
Step 8: Save and Launch Automation
Click 'Save and Launch' and confirm '**Yes, Launch'.**
**The Xoxoday Plum rewards application is now available on SurveyMonkey's app marketplace.** **[Get in touch](https://www.xoxoday.com/book-a-demo) with our experts to know more about how the Xoxoday-SurveyMonkey integration works**
For any feedback or questions reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Overview
Source: https://help-plum.xoxoday.com/integrations/typeform/typeform
Get an overview of the Plum-Typeform integration and how it automates reward distribution to respondents who complete your forms.
*Learn about the Xoxoday Plum integration with Typeform.*
## How the Xoxoday Plum and Typeform Integration works?
**Send personalized rewards, incentives, and gift cards to your respondents to increase the survey response rate with Xoxoday Plum**
i. Instant Gratification -Provides a sense of fulfillment for the user on completion of a particular task, leaving behind a good taste of the application or platform used.**ii. Automated workflows**- You can set up custom workflows and triggers to automate the complete process of sending, tracking, and managing rewards, incentives, gift cards, etc.**iii. Hassle-free Rewarding**- Provides a hassle-free method for organizations to reward users based on specific triggers.**iv. Approval Workflows**- Eliminate any duplicate or multiple reward claims by using Xoxoday’s robust built-in approval process. Scrutinize all claims before approving or rejecting them.**v. Extensive Global Catalogue** - Xoxoday’s storefront offers an extensive global catalog of 5000+ experiences, 3000+ gift vouchers, and 12000+ perks for your users to choose from.
No-code setup - No human intervention or technical support is needed. No code workflow set up with a step-by-step walkthrough.
## Getting started with the Xoxoday Plum ↔ Typeform Integration
Follow the step-by-step guide to set up the integration between Xoxoday Plum and Typeform.
**Step 1**
Go to [Typeform](https://admin.typeform.com/login) → Apps and Integrations→ Search for Xoxoday Plum
**Step 2**
Click on the “Xoxoday” card to connect with Xoxoday Plum.
**Step 3**
Now, you will be redirected to the Xoxoday app registration page.
**Log in/Sign-up** to your Xoxoday account with admin credentials to access the Xoxoday admin dashboard.
Step 4 Click on the **Recharge option** on the Sidebar to Recharge your Plum Account to kickstart your campaign.
Complete your KYB before doing the recharge, as you will be able to recharge only up to INR 10000 until your account is verified.
**Step 5**- Click on **Add Funds** and Proceed with the Payment.
* [Click here](/getting-started/for-admins/wallet-management/wallet-management-overview) to know more on how to recharge your account.
The recharged amount will now be reflected in your Xoxoday Wallet.
\*\*Step 6 \*\*Once you have enough funds in your Xoxoday account, click **Campaign** Tab to Create a new Reward automation campaign.
Step 7
* Now, click 'Create Reward Code/Reward Link Campaign'.
* You will now be redirected to a page where you can customize reward automation details like **Reward Amount, Reward Recurrence, Start Date, End Date, email templates to be sent, etc.**- Now, click on the\*\*"Create Campaign"\*\* button.
Step 8
* Now, go to **Typeform** Integration from the sidebar.
* Click on "**Create new"** automation
* You will now be prompted to “Select a Survey” for your Typeform Reward Automation.
* Further to this, before launching your reward automation, you can also change;
Reward trigger settings to either automatically send rewards or have an approval process to manually approve rewards.
* You can also set up a reward distribution logic based on a Custom time range or Maximum Reward count.
* Now, click on the **"Launch"** button to activate the Typeform Reward automation.
Select Survey
Step 9
Navigate through the various Reward Automations → click on any specific Reward automation to take action like changing Reward Automation status (active to inactive), track the number of rewards distributed, etc. from your Typeform integration page on Xoxoday Plum.
Talk to our expert to know more about how you can improve survey response rates by integrating with [Xoxoday Plum](https://www.xoxoday.com/book-a-demo).
For any questions or feedback contact us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Zapier + Plum
Source: https://help-plum.xoxoday.com/integrations/zapier-plum
Learn how to connect Plum with Zapier to automate reward workflows across thousands of apps without any custom code.
## SurveyMonkey + Zapier + Xoxoday Plum
Integrate SurveyMonkey with Xoxoday Plum to send a gift card to respondents on SurveyMonkey.
**Benefits of this integration**
* Saves time – Seamless and automated workflow triggered by just a few clicks.
* No human intervention or Technical support needed - No code workflow set-up with a step-by-step walkthrough.
* Ease of workflow creation improves Customer Experience.
* Provides a hassle-free method for organizations to reward and recognize people.
* Instant Rewarding/Gratification - Provides a sense of fulfillment for the user on completion of a particular task, leaving behind a good taste of the application or platform used.
**To integrate SurveyMonkey with Zapier follow the following steps:**
* Create a Zap workflow by first choosing an online app (HubSpot, Salesforce, SurveyMonkey, Slack, Google sheets, SurveySparrow, etc.) and then choose a trigger, such as ‘when a survey submission is completed by the user’. Test the trigger to Find data.
* Next, pick Xoxoday Plum as the "Action" application to send rewards in the form of e-gift cards automatically as a response to the "Trigger".
* Sign in to the Trigger App. Next, to sign into the Action App, complete the self-serve set-up of Xoxoday Plum.
Below are the steps to register:
## Signup or Sign In on Plum(if you already do not have a plum account)
If you are new to Xoxoday Plum, click on the “Signup” button. You can learn how to set up a Plum account here. It's recommended that you use the email registered with HubSpot to signup with Plum as well.\*\*
If you are an existing user, use your xoxoday credentials to log in to the admin dashboard.
Congrats, you have successfully installed the application.
## Click on the Recharge option on the Menu bar to Recharge your Plum Account for the Reward automation campaign
## **Recharging the account**
* Click on Add Funds and Proceed with the Payment.
\*\*Step 5:\*\*Now authorize your Zapier account with the Plum account for seamless data sync.**Now you are successfully registered with Xoxoday Plum.**
**Already existing customer: Sign in using your existing user ID and password.**
## Authorize your account
Now you are successfully registered with Xoxoday Plum.
* Once signed into Plum, click Continue and start Customising your reward, fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email.
* Click Continue. You may now test it for review or proceed to the next step.
* Turn on Zap to complete the workflow.
\*\*Congrats! You have successfully created the Zap.
As a result, whenever a respondent completes the selected Survey on SurveyMonkey, he will instantly receive the customized Gift Card from Xoxoday Plum!
Could this process of workflow creation get any simpler?!
# Salesforce + Zapier + Xoxoday Plum
Integrate Salesforce with Xoxoday Plum to send a gift card to new Prospects/leads added to your Salesforce account
To integrate Salesforce account with Zapier follow the following steps:
\*\*Step 1:\*\*Select Salesforce as the Trigger application, the Trigger, in this case, is “when a new lead(a record) is added”. First, log in to your Salesforce account and Test the trigger to Find data.\*\*Step 2:\*\*Next, pick Xoxoday Plum as the Action application to send rewards in the form of e-gift cards automatically as a response to the Trigger, i.e. to a new record added on Salesforce.**Step 3**: After DIY set-up or log in as a registered user of Xoxoday Plum.\*\*Step 4:\*\*Click Continue and begin Customizing the Reward. Fill up all the fields depending on the use-case of the Action you have set. Double-check everything. For example, the Recipient Email field is important if the gift card(s) need to be sent to the user via email.\*\*Step 5:\*\*Test and Review or Continue.**Congrats! Your Zap is now ready.**
As a result of this integration, whenever a new record is added to Salesforce, the user receives Xoxoday Plum’s customized Gift Card via email.
# Automation: Workflow Rules
Source: https://help-plum.xoxoday.com/integrations/zoho-crm/automation-workflow-rules
Learn how to set up automation workflow rules for sending rewards automatically in Zoho CRM using the Plum integration.
*Learn all about automating Workflow Rules*
Workflow rules allow you to perform certain automatic actions on specific records based on filter criteria. Using Workflow Automation, you can automate reward sending based on your rules.
## STEP 1: NAVIGATE TO AUTOMATION WORKFLOW RULES
Visit **Setup > Automation > Workflow Rules** for setting workflows.
## STEP 2: CREATING A REWARD WORKFLOW RULE
Click **'Create Rules'** button.
Set the Module for which you want to automate rewards. Add a name to your rule indicating the purpose of reward via name and description.\*\*
STEP 3: SET RULES FOR REWARDING
This rules rewards sales representative for winning a deal within a closing date.
STEP 4: SET PLUM REWARDS AS ACTION
Select **Instant Actions > Choose Plum Rewards** (PlumrewardsbyXoxoday).
Select the reward Automation that you created in Xoxoxday Plum.\*\*
After selecting the automation, Name your custom action.
Click on ‘Save’\*\* to save the rule.
By default, the rules are not active. Click on **‘Activate’** to start your rewarding workflow rules.
# Send 1-1 rewards
Source: https://help-plum.xoxoday.com/integrations/zoho-crm/send-1-1-rewards
See how to send an individual one-to-one reward directly from Zoho CRM using the Plum integration, without switching tools.
*Learn how to integration Zoho CRM with Xoxoday Plum*
# Integrating Zoho CRM and Plum
## STEP 1: Connect with Zoho CRM
Go to Xoxoday Plum Admin Dashboard and click 'Integrations' and search for Zoho CRM. Click **"Connect"**, and you will land on ZohoPeople’s App Marketplace.
## STEP 2: Install Xoxoday Rewards for Zoho CRM App
Click on the Install button.
On Install, accept the terms and conditions and click 'Install'.
# Sending Rewards to Leads and Contacts
## STEP 3: Select the Contact or Lead you want to send Rewards.
After the Xoxoday Plum App installation, click ‘Plum Rewards’ on the Leads and Contacts detail page.
STEP 4: Open Xoxoday Plum Rewards Widget and Select Reward Campaign
**Prerequisites**
Zoho CRM users who need access to 1-1 rewards widget should be added as a user in Xoxoday Plum with Admin or Super admin access as required.\*\*Click on the ‘Plum Rewards’ button to open our rewards Widget. Via this widget, you can select the desired reward Campaigns that you already created in Xoxoday Plum.\*\*
Click on Next
## STEP 5: Customize Reward Email
\*\*Now you can customize your reward Email. You can change the Email Subject and Message to send personalized rewards to your contact or lead.
STEP 6: Change the Email Banner
Click on Email Banner to open up available banners for different gifting occasions.
Select the desired banner and click 'Use Image'\*\*.
## \*\*STEP 7: Preview your Reward Email
Click 'Preview your email'\*\* below the banner to check how your reward email will look to your rewardee.
## STEP 8: Send Reward
Congratulations! You have sent a reward to your contact or lead. Continue sending reward emails to win more deals and manage relationships with your customers for choosing you.
# Zoho CRM Integration
Source: https://help-plum.xoxoday.com/integrations/zoho-crm/zoho-crm-overview
Get an overview of the Plum-Zoho CRM integration and how it connects CRM workflows to automated reward disbursal.
*Learn more about Zoho CRM and Xoxoday Plum integration.*
# Zoho CRM + Xoxoday
Zoho CRM is a customer relationship management (CRM) software that helps businesses of all sizes to manage their sales, marketing, and customer support processes in a centralized platform. With Xododay Plum Rewards App in Zoho CRM, rewarding has never been so easy. Include rewarding in your sales Funnel and manage relationships with customers by rewarding them for choosing you.
# Why Integrate with Zoho CRM
* **Create campaigns** Take complete control of your reward delivery process, create and personalize your reward campaign with nuances like reward type (cash, gift card, voucher, etc.), reward mode (automated/ manual), communication templates, and more.
* Send rewards to Prospects
Xoxoday Plum extends the capabilities of Zoho CRM by allowing multi-dimensional rewards to be performed from the workflow. You can generate meetings, sustain post-demo contact with the POC, and re-engage with lost prospects with tailored one-time rewards.
* **Assign workflows**
While creating workflows in Zoho CRM, set up automatic triggers to send out rewards, incentives, and gift cards to your customers. Define campaign process goals such as lead conversion, webinar registrations, etc. to set the triggers.
* **Analyze rewards**
Get a unified view of all reward-automation campaigns set up in Zoho CRM directly. Create and Navigate through various campaigns to check the active/inactive statuses and more
# Zoho People
Source: https://help-plum.xoxoday.com/integrations/zoho-people
Get an overview of the Plum integration with Zoho People and how it automates HR-driven employee reward distribution.
Effortlessly recognise, reward, and delight your employees — all without leaving Zoho People. The Xoxoday integration enables you to award points directly from an employee profile and lets employees redeem them on a curated global rewards catalogue, all in just a few clicks.
This guide walks you through everything you need to know: from setting up the integration and assigning points, to exploring the employee redemption experience.
## Overview
The Xoxoday + Zoho People integration seamlessly connects your HR platform with your rewards ecosystem. With this integration, you can:
* **Automate recognition** — Award reward points directly from Zoho People profiles.
* **Streamline redemption** — Employees redeem points from Xoxoday's global rewards catalogue without leaving Zoho People.
* **Deliver a seamless experience** — Users are logged in automatically when redeeming — no extra steps or logins required.
This helps HR and business leaders create a culture of appreciation while keeping the entire recognition journey inside the tools teams already use.
## Prerequisites
Before you get started, make sure you have:
* An active **Xoxoday Plum** account with admin access.
* Admin or HR privileges in **Zoho People**.
* Sufficient reward points or wallet balance in your Xoxoday account.
* (Optional) A list of locations or employee types for whom the program will be applicable.
***
## Step 1: Set Up Integration
### 1. Navigate to Integrations
Go to your Xoxoday Plum Admin Dashboard and click on **Integrations**.
### 2. Connect Zoho People
Find Zoho People in the integrations list and click **Connect**.
### 3. Activate in Zoho Marketplace
You'll be redirected to the Zoho People Marketplace. Click **Activate** to enable the integration.
### 4. Log in and Confirm Activation
Log in with your Zoho People credentials and accept the terms and conditions to complete activation.
***
## Step 2: Configure Integration Settings
Once activated, you can customise how the integration behaves for your organisation.
### 1. Define Applicability
Choose which locations and **employee types** are eligible to receive rewards. This ensures that only relevant users are part of your recognition program.
### 2. Save Settings
Click **Save** to finalise your preferences.
***
## Step 3: Award Points to Employees
Once setup is complete, awarding points is seamless and can be done directly from Zoho People.
### 1. Go to an Employee Profile
Navigate to the profile of the employee you want to reward.
Only administrators and **reporting managers** can award points.
### 2. Click on "Reward Points"
Here, you'll see:
* **Total available points** — your organisation's wallet balance.
* **Employee's current points** — how many they already have.
* **Points to be awarded** — how many you want to give.
* **Awarded For** — add a note or reason for recognition.
### 3. Assign Points
Click **Assign Points** to complete the process. The employee will receive the points instantly, along with an email notification.
***
## Step 4: Employee Redemption Experience
Here's what the experience looks like from an employee's perspective.
### 1. Redeem from Zoho People Home
Employees can view their available points in the Xoxoday widget on their Zoho People homepage. Clicking **Redeem Points** starts the redemption journey.
### 2. Seamless Access to Storefront
Clicking **Redeem Points** takes them directly to the Xoxoday storefront — no extra login required, thanks to a secure single sign-on (SSO) flow handled in the background.
### 3. Browse and Choose a Reward
Employees can explore a wide range of **gift cards, merchandise, experiences, and vouchers**.
### 4. Add to Cart and Checkout
Once they select a reward, they can add it to the cart, proceed to checkout, and confirm. Their reward points will be automatically applied.
***
## Frequently Asked Questions
**Who can award points?**
Only administrators and reporting managers with the required permissions can award points.
**Do employees need a separate Xoxoday account?**
No. The integration uses secure SSO, so employees are automatically signed in when redeeming points.
**What if I don't have enough points?**
Admins will be prompted to top up their points wallet before completing the award.
**Can I restrict the program to certain locations or teams?**
Yes. Applicability can be configured by location and/or employee type in the integration settings.
***
You're all set to run a seamless recognition and rewards program directly inside Zoho People — with zero manual work, zero extra logins, and maximum delight.
Want to see it in action? Check out the step-by-step walkthrough for the Zoho People integration.
# Approvals - Overview
Source: https://help-plum.xoxoday.com/offers-management/approvals/approvals-overview
Get an overview of the approvals workflow for offers submitted in Plum's Offers Management portal before they go live.
*Learn more about the Approval module*
## Accessing the Approval Page
To manage pending approvals for offers or redemptions, follow these steps:
* **Navigate to the Left Menu** — From your dashboard, locate the navigation panel on the left side of the screen.
* **Click on "Approval"** — Select Approval from the menu. This will direct you to the Approval Management page.
***
## Approval Management Page
The Approval module is built on a maker-checker workflow, ensuring all changes undergo review before going live. Any action requiring approval will appear in the task list of admins assigned the role of checker or approver.
***
## What You Can Do on the Approval Management Page:
* **View Pending Change Requests** — See a comprehensive list of changes that require review and approval.
* **Check and Approve Requests** — Review the details of each change and approve or reject them with a single click.
* **View Rejection Reasons** — For any previously rejected requests, you can view the rejection reason for better context and tracking.
* **Export Approval Logs** — Download the entire list of change requests, including their approval status, for audit or record-keeping purposes.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Managing Approvals
Source: https://help-plum.xoxoday.com/offers-management/approvals/managing-approvals
Learn how to review, approve, or reject pending offer approvals in Plum's Offers Management portal before they go live.
*Learn more about managing approvals on Loopr*
## View the List of Change Requests
On the Approval Management Page, you'll find a list of all pending change requests that require review.
Each entry in the list shows:
* The feature or function being changed
* The type of change requested
* The current status of the request (Pending, Approved, Rejected)
***
## View Details of a Change Request
To inspect a specific request:
* Click on the "View" button beside the change item.
* This opens a detailed view of the requested changes for review.
***
## Check / Approve or Reject a Change Request
To review and act on a request:
* Click "**Approver**" next to the change request.
* A detailed overlay will appear showing:
* What feature/function is being changed
* Who made the request
* Time and date of the request
* Summary of changes
* To proceed:
* Click "**Approve**" to accept the request.
* Click "**Reject**" to decline the request.

***
## View the Reason for a Rejected Request
To understand why a request was rejected:
* Click "Rejected Reason" beside the rejected change request.
* An overlay will appear displaying the rejection note or feedback.
***
## Export the rejected list of change request
* Admins can export all approval requests—including pending, approved, and rejected—by clicking the "Export Report List" button.
* This generates a downloadable report for tracking and auditing purposes.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Dashboard
Source: https://help-plum.xoxoday.com/offers-management/dashboard
Get an overview of the Offers Management dashboard, where you can track merchant offer performance at a glance.
This article outlines the key components and modules on the modules Admin Portal, helping administrators navigate the system effectively.
## Dashboard Overview
Upon successful login, the admin is presented with a Dashboard summarising key insights and statuses.
***
## 1.1 Merchant Information (Pie Chart)
* Displays a breakdown of merchants by countries
* Helps track the geographic distribution of partner merchants
***
## 1.2 Vouchers Information (Pie Chart)
* Shows a breakdown of vouchers by offer type
* Useful for understanding which types of offers are most common
***
## 1.3 Web Portals
* Offer Apps
***
## 1.4 Important Reminder Section
Stay on top of urgent or pending actions with this live summary:
* Expired Merchants – List of merchants whose validity has lapsed
* Expiring Merchants in 30 days – Merchants nearing their expiration date
* Expired Offers – Offers that are no longer active
* Expiring Offers in this year – Offers set to expire in the current year
* To Be Reviewed – Offers or merchants pending admin review or approval
***
## Platform Modules
The intuitive interface is organized into core modules that help you efficiently manage your tasks, based on your user role. Each module is accessible through the left-hand navigation menu and is tailored for a streamlined workflow.
* **Merchants: Manage merchant accounts and profiles. Admins use this module to onboard, approve, and monitor merchants.**
* Add and edit merchant details
* Track merchant activity and status
* Assign offers and stores to merchants
* **Offers: Create and manage promotional offers and discounts. Merchants and Admins can customize, schedule, and monitor offers here.**
* Create new offers with templates
* Customize branding, validity, and types
* Track active, expired, and upcoming offers
* **Customers: View and manage customer profiles, engagement, and redemption histories.**
* Access customer details and preferences
* Monitor offer redemptions and activity
* Segment customers for targeted promotions
* **Stores: Manage physical and online store locations linked to merchants and offers.**
* Add and update store information
* Link offers to specific stores for localized promotions
* Manage store operational details
* **History: Track past activities, transactions, and offer redemption logs for auditing and review.**
* View detailed logs of offer redemptions
* Monitor customer interactions over time
* Review activity history
* **Reports: Access comprehensive analytics and performance data to optimize campaigns and measure ROI.**
* Generate reports on offer performance
* Analyze customer engagement trends
* Export data for deeper insights
* **Web Portals: Configure customer-facing portals where offers are displayed and redeemed.**
* Customize portal appearance and branding
* Publish offers across portals and regions.
* Manage portal access and navigation
* **Approvals: Manage workflow approvals for offers based on the user roles – Admin, Checker and Maker.**
* Review and approve new offers
* Track approval status and history
* **Settings: Configure account, user roles, subscription, user feedback and password.**
* Manage user roles and access control
* Configure subscription and password
# Dashboard Overview
Source: https://help-plum.xoxoday.com/offers-management/for-customers/dashboard-overview
Get an overview of the customer dashboard within Plum's Offers Management portal and what customers can see there.
*This article will take you through the dashboard overview on Loopr*
Offers are organized into multiple sections to help you easily find and manage them.
***
## Favourite Offers
* This section displays all the offers marked as favourites.
* Use the filters and search icon to narrow down the list.
* Great for quick access to offers you're most interested in.
***
## Offer Wallet
* The Offer Wallet contains all the offers you've added for future redemption.
* It's divided into two subsections:
**Added Offers:** Lists all offers that you've currently added to your wallet but haven't redeemed yet.

**Redeemed Offers:** Displays a history of all offers you've already redeemed.

Use filters and the search icon here as well to quickly find what you need.
For any questions or feedback reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
Looking to drive loyalty, boost sales performance, or enhance employee engagement? [Explore Xoxoday's product suite here!](https://www.xoxoday.com/get-a-demo)
# Listing of Offers
Source: https://help-plum.xoxoday.com/offers-management/for-customers/listing-of-offers
Learn how customers browse the full listing of available offers within Plum's Offers Management customer portal.
*Learn about the different ways a offer is listed on the Loopr platform.*
**1.1 Offer in categories**
* Offer categories and subcategories can be created and managed from the admin portal.
* Category image can be uploaded to show in the portal.
* Sorting of the categories can be configured.
* The number of offers in each of categories can be shown.
* A "Near Me" category can be supported to display offers based locations.
* The location parameter (1km, 5km or 10km) can be defined from the backend.
***
**1.2 Offers in Carousels**
* Multiple carousels can be shown to display different subsets of offers, for marketing and campaign purposes
***
**1.3 Offers by Brands and Merchants**
* Offers under the same brand can be listed in the brand page
* "Top brands" can be configured in the admin portal
* Offers under the same merchant can be listed in the merchant page
***
**1.4 Search and Filter**
* Search and Filter can be always accessed in any offer listing pages and as well as the landing page
* Key words searching is supported in all offer fields, including title, brand, merchant name, description, location, terms and conditions
* Filtering is based on category and subcategory and locations
* Sorting support recency and A-Z (Z-A)
***
**1.5 Map View**
* Offers can be shown in the map based on the store locations
* Map is supported by Google Map
* An offer carousel displays all offers under the shown area
* Zooming out the map, pins will form clusters which display the number of offers in an area
* Zooming in to the clustered pin to show all offers within the area
* Clicking "Get Directions" will jump to a Google Map URL
* Display distance only if location permission is allowed
For any questions or feedback reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
Looking to drive loyalty, boost sales performance, or enhance employee engagement? [Explore Xoxoday's product suite here!](https://www.xoxoday.com/get-a-demo)
# Offer Management for Customers - Logging In
Source: https://help-plum.xoxoday.com/offers-management/for-customers/offer-management-for-customers-logging-in
Learn how customers can log in to Plum's Offers Management portal so they're able to browse and redeem available offers.
*Learn how to log in to the customer portal app*
Go to the Customer Portal using your preferred web browser.
* Enter your **registered email address and password.**
* Click on the **Sign In** button to access your account.
Once logged in, you'll land on your Dashboard.
Here, you can:
* View Recommended Offers curated just for you
* Track your recent activity
* Access personalized insights and updates
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Personalized and Trending Offers
Source: https://help-plum.xoxoday.com/offers-management/for-customers/personalized-and-trending-offers
Discover how personalized and trending offers are surfaced to customers within Plum's Offers Management portal.
*Learn about personalized and trending offers.*
This section highlights a variety of offers curated for customers, organized into different segments for easier discovery:
* **Top Picks for You:** Handpicked offers based on your preferences and activity.
* **Offers That Might Interest You:** Suggested deals tailored to your interests.
* **Offers Others Are Interested In:** Popular offers that are gaining attention from other users.
* **Trending Now:** Time-sensitive and high-demand offers are currently trending on the platform.
* **Top Brands:**
* Favourite any of the offers by clicking on the star next to the offer.
For any questions or feedback reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
Looking to drive loyalty, boost sales performance, or enhance employee engagement? [Explore Xoxoday's product suite here!](https://www.xoxoday.com/get-a-demo)
# Redemption & Validation
Source: https://help-plum.xoxoday.com/offers-management/for-customers/redemption-validation
Learn how offer redemptions are validated for customers within Plum's Offers Management portal and platform overall.
*Learn how to redeem an offer on Loopr app.*
Customers can browse and redeem a wide variety of offers available on the Loopr portal. Here's how the redemption process works:
***
## Offer Redemption
A variety of offers are available on the portal, and customers can select and redeem any offer of their choice. On the offer redemption page, three key sections are presented:
* **Offer Details:** This section displays all relevant information about the offer. Customers are encouraged to review the details before proceeding with redemption.
* **Location/Contact:** This section provides the location details of the stores offering the deal, helping customers know where to redeem it. A "Map View" button is available clicking it shows the store's location and directions for easier navigation.
* **Terms and Conditions:** This section outlines all the terms and conditions for redeeming the offer. Customers should read these carefully before proceeding with redemption.
***
Offers can be redeemed in two ways: by selecting "**Redeem Now**" for immediate use, or by choosing "**Add to Wallet**" to save the offer for future redemption.
* **Redeem Now:** When customers click this button, the offer code becomes visible. This code should be presented to the retailer to receive the discount.
For any questions or feedback reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
Looking to drive loyalty, boost sales performance, or enhance employee engagement? [Explore Xoxoday's product suite here!](https://www.xoxoday.com/get-a-demo)
# Creating and Managing Offers
Source: https://help-plum.xoxoday.com/offers-management/for-merchants/creating-and-managing-offers
Learn how merchants create and manage their offers within Plum's Offers Management portal, from setup to publishing.
*Learn all about creating offers on Loopr merchant portal*
The Offers module in the merchant portal enables admins to create, customize, and manage a wide range of promotional offers.
## Creating Offers
To create a new offer:
Click the "**Create Offer**" button.
* Discount (percentage-based)
* Fixed-value (e.g., \$10 off)
* Free-format (custom offer format)
* Product (physical or digital product)
After selecting the offer type, fill in all required fields across the following sections:
* Time Zone
* Brand Name
* Display Title
* Face Value (use drop-down menu to select)
* Offer Image
* Description
* Voucher Code Info
* Redemption Info
Once all the details are filled in, click the "**Create**" button to save the offer.
***
## Managing Offers
The Offers module in the Loopr Merchant Portal allows you to create, manage, and optimize promotional offers. Once offers are created, you can manage them using several built-in tools and actions.
### 1. Search & Filter Offers
The Loopr Merchant Portal makes it easy to find specific offers with the help of a powerful search bar and filter system.
You can apply one or more filters to narrow down your offer list based on various attributes.
### Available Filters:
* **1.1 Offer Title** — Enter keywords or the full title of the offer to search directly by name.
* **1.2 Store** — Use the drop-down menu to select a specific store associated with the offer.
* **1.3 Location** — Filter offers by their associated location using the location drop-down list.
* **1.4 Web Portals** — Select one or more web portals through which the offer is published.
* **1.5 Offer Type** — Choose from the following types:
* Discount
* Fixed Value
* Free Format
* Product
* **1.6 Status** — Filter offers based on their current status:
* Published
* Unpublished
* Publishing
* Expired
* Draft
* **Expiry Date** — Use the calendar UI to select a date or range for when the offer is set to expire.
***
## 2. Actions Available for Each Offer
For every offer listed, the following actions are available:
### 2.1 View
* Navigate to the offer and click on **View** next to the offer.
### 2.2 Edit
* Modify offer content, validity, T\&Cs, images, or any associated settings.
* Navigate to the offer and click on the **pencil icon** next to the offer.
* Edit the details and click "**Save**" to proceed.
### 2.4 Delete
* Remove an outdated or inactive offer from the platform.
* Navigate to the offer. Click on the **delete icon** next to the offer.
* A confirmation pop-up will appear. Click "**Confirm**" to permanently delete the offer.
Note: Deletion may require confirmation and cannot be undone.
### 2.5 Detail
* Navigate to the Offers Module — From the dashboard, go to Offers.
* Click on the "**Detail**" Button — Next to the offer you want to analyze, click "Detail" to open the offer performance page.
* Once inside the detail view, you'll see a complete breakdown of the offer's activity, including:
* Claimed – Number of times the offer was claimed
* Redeemed – Number of times it was successfully redeemed
* Favourited – How many users marked it as a favorite
* User Feedback – Comments or ratings submitted by users
* You can also filter this data by:
* Source (e.g., Web, App, Partner Portal)
* Customer ID
* Status (e.g., Claimed, Redeemed, Expired)
* Claimed Time (using the calendar filter)
* **Exporting the Offer Data** — To export the tracked data: Scroll to the bottom of the page. Click on the **Download icon** to export the list as a report.
### 2.6 Share
Generate a shareable link or code to distribute the offer through your desired marketing channels.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Customer Module
Source: https://help-plum.xoxoday.com/offers-management/for-merchants/customer-module
Get an overview of the customer module available to merchants within Plum's Offers Management portal and its features.
*Learn how to Create, View, and Manage Customers*
This section displays a customer list that merchants can use to send offers.
Navigate to **Customers** on the left hand of the dashboard.
***
## Search for customers
The Customers module allows merchants to search, filter, and export customer data. It also enables you to target specific users for personalized offers.
### How to Search for Customers:
* Use the search bar and filters to narrow down the customer list. You can search by:
* Customer Name
* Email Address
* Registered Mobile Number
* Redemption Date
* Birthday Start and End Date
This makes it easy to find the right customer or group of customers for communication or promotional campaigns.
***
## Adding a customer
Customers can be added in two ways: manually or through bulk upload.
**Method 1: Manually Adding**
* Click "**Add Customer**" at the top of the Customers page.
* Fill in details (name, email, mobile, birthday). Once done, Click "**Save**".
**Method 2: Upload Customers in Bulk**
* Click the "**Upload Customers**" icon.
* Upload the file. You can also download the sample template for reference.
***
## Managing Customers
In the Customers module, you can view, edit, or delete individual customer records.
**View a Customer**
* Go to the Customers page.
* Find the customer in the list and click the "View" icon next to their name.
* You'll see:
* Full customer details

* A tracking section showing offers claimed, redeemed, or favourited by the customer

**Edit a Customer**
* Click the "**Edit**" icon next to the customer name.
* Update any required details (e.g., email, phone, birthday).
* Click "**Save**" to apply changes.
**Delete a Customer**
* Click the "**Delete**" icon next to the customer name.
* A confirmation pop-up will appear.
* Click "**Confirm**" to delete the customer.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# History Module
Source: https://help-plum.xoxoday.com/offers-management/for-merchants/history-module
Learn how merchants can view a complete history of their offer activity within Plum's Offers Management portal.
*Learn all about checking history on the Merchant platform.*
The History module allows you to view a detailed record of offer activity, including claims and redemptions.
## How to Access
* From the main menu, click on "**History**" in the left-side navigation panel.
***
## What You Can Do:
Once inside the History module, you can:
**Search & Filter Offer Activity**
Use filters to refine your search results based on:
* Offer Title
* Status
* Claimed
* Redeemed

* Source
* Web Portal
* Merchant
* Stores — Select specific store(s) from the dropdown list
* Voucher Code — Add the particular voucher code
* Offer Type
* Discount
* Fixed Value
* Free Format
* Product

* Date and Time — Select the date and time using the calendar.
Use multiple filters together for more specific results.
**View History Records**
* Browse the list of activity logs showing the time, user, store, and offer details.
* Each record provides visibility into how and where an offer was claimed or redeemed.
This helps merchants track campaign performance and customer engagement across channels.
**Export History**
Click on "**Export List**" to download the list.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Overview
Source: https://help-plum.xoxoday.com/offers-management/for-merchants/offer-management-for-merchants
Get an overview of the Offers Management portal from a merchant's perspective, covering the key features available.
*Learn how to login to the merchant dashboard*
## Accessing the Merchant Portal
Follow the steps below to log in and navigate through the main dashboard of the Merchant Portal.
## Steps to Log In:
Open your browser and go to the Merchant Portal URL.
* Input your username and password
* Click "Sign In"
Upon successful login, you'll be directed to the Dashboard.
***
## Dashboard Overview
Once on the dashboard, you'll see the following key elements:
## Language & Notifications
* Language Dropdown: Located at the top right, allowing you to switch between supported languages.
* Notification Icon: Also at the top right, to view important updates and alerts.
***
## Module Access Buttons
You'll find quick-access buttons for different modules such as:
* Home
* Offers
* Customers
* Stores
* History
* Reports
* Approvals
* Settings
* Redemptions
And more, depending on your permissions.
Each module provides tools for managing specific parts of your merchant operations.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Account Settings
Source: https://help-plum.xoxoday.com/offers-management/for-merchants/settings/account-settings
Learn how merchants manage their account settings and preferences within Plum's Offers Management merchant portal.
Merchants can easily manage their personal or business account information from the Account Settings section.
## How to Access
* Go to "**Settings**" from the left-hand menu.
* Click on the "**Account**" tab from the dropdown.
***
## View Account Details
* Your account details (name, email, business info, etc.) will be displayed for review.
***
## Edit Account Information:
* Click "**Edit Account**" on the top right.
* Make the necessary changes to your personal or business details.
* Once done, click "**Submit Approval**" to save the updates.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Overview
Source: https://help-plum.xoxoday.com/offers-management/for-merchants/settings/settings
Get an overview of all the settings and configuration options available to merchants within Plum's Offers Management portal.
*Learn how to manage Settings*
The Settings module allows Admins to efficiently manage account details, subscription preferences, and password security.
It includes three key sub-sections:
1. Account
* To manage your profile information
2. Subscription
* To view and manage your subscription plan
3. Password
* To update your login credentials securely
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Subscription
Source: https://help-plum.xoxoday.com/offers-management/for-merchants/settings/subscription
Learn how merchants can view and manage their subscription plan and billing details within Plum's Offers Management portal.
The Subscription section provides visibility into all active and past subscription records tied to your budget and usage. Merchants can manage multiple packages based on their needs.
## How to Access
* Navigate to **"Settings**" from the left-hand menu.
* Click on **"Subscription"** from the dropdown.
***
## View All Subscription Records
See a list of all your active and historical subscriptions, along with their current status (active, expired, etc.)
***
## Select a Package
* At the top of the page, click on the "**Packages**" dropdown.
* Choose from the available subscription packages as per your business needs.
This helps manage budgets and optimize platform usage effectively.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Stores Module
Source: https://help-plum.xoxoday.com/offers-management/for-merchants/stores-module
Learn how merchants manage individual store locations and their details within Plum's Offers Management portal.
*Learn all about setting up, maintaining and updating store information*
This section allows you to **create, view, edit, and manage** all store-related information from one place.
## Accessing Store Management
Navigate to "Stores" from the left menu on the dashboard.
* On the Stores page, you can:
* Search for stores
* Create new stores
* Edit store details
* View store profiles
* Update store PINs

***
## Search for a Store
* Use the search bar at the top to look up a store by name.
***
## Create a New Store
* Click "Create Store" at the top left of the Stores page.
* Fill in the following fields:
* Store Name
* Address
* Email Login
* Email
* Phone Number
* Opening Hours
* Website (optional)
* Facebook (optional)

* Click "Create" to add the new store to the list.
The store will now be visible and available for offer mapping and tracking.
***
## Managing Stores
**View a Store**
* Find the store in the list.
* Click the "View" icon next to it to see full details like address, contact info, opening hours, and linked accounts.
**Edit Store Details**
* Click the "Edit" icon beside the store name.
* Update the required fields (e.g., address, phone, email).
* Click "Save" to confirm changes.
**Update Store PIN**
* Click "**Update PIN**" next to the store.
* Enter the new PIN and click "**Confirm**."
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Viewing Reports
Source: https://help-plum.xoxoday.com/offers-management/for-merchants/viewing-reports
Learn how merchants can view detailed performance reports for their offers within Plum's Offers Management portal.
*Learn to view reports on the merchant portal*
Merchants can access detailed offer performance insights through the Reports section.
## Accessing Reports
* Go to "**Reports**" from the left-hand side (LHS) menu.
***
## Overview
The report overview displays:
* Offers Claimed
* Offers Redeemed
* Redeemed vs. Claimed (with a graphical comparison chart below)
***
## Date Range Options
* Select from:
* Today
* Yesterday
* Last 7 Days
* This Month

***
## Redeemed Vs Claimed
The data for Redeemed Vs Claimed is also depicted as a graph
* Use the Available Filters — You can filter the report data by:
* Date – View by day or month using the drop down which can be either month or day.
* Offers – Filter for all offers or select specific ones
* Source – Choose between Web Portal or Merchant
* Store Name – Select a specific store from the list
Filtered data is reflected in both the numeric summary and the graphical view below for deeper analysis.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# History
Source: https://help-plum.xoxoday.com/offers-management/history
Learn how to view the history of actions taken in Plum's Offers Management portal, useful for audits and troubleshooting.
*Learn how to view, export and sort Offer History*
Follow the steps to view, export and sort offer history:
* Navigate to **History tab** on the LHS of the dashboard.
***
## To access and manage the list of offers, follow these steps:
### Access Redemption History
Click on "**History**" from the left-hand side (LHS) menu. This will take you to the Offer History page.
***
## What You Can View
On the Offer History page, you can view details for each redeemed offer, including:
* Offer Name
* Redemption Date
* Offer Type
* Voucher Code
* Web Portal
* Merchant Name
* Status
***
## Filter the History List
You can narrow down the results using the following filters:
* Web Portal
* Merchant Name
* Offer
* Voucher Code
* Customer ID
* Offer Type
* Status
* Time Range
After selecting the relevant filters, click **Search** to view filtered results.
***
## Export the Report
To download the redemption history:
* Click on the **"Export Report"** button (see below image, if applicable).
* The report will be downloaded as an Excel file.
Use the export feature for record-keeping, audits, or further analysis.
***
## Sort Listing
**To sort the list of offers:**
* Locate the column header you want to sort by (e.g., Offer Name, Date, Status).
* Click on the **up/down arrow** icon next to the column header.
* On click, the list will be sorted in ascending or descending order, based on the selected column.
* Click the arrow again to toggle between ascending and descending order.
* This helps you quickly organize data for better visibility and analysis.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Logging in
Source: https://help-plum.xoxoday.com/offers-management/logging-in
Learn how to log in to the Plum Offers Management portal, including what to do if you run into any login or access issues.
*Learn how to log in to the dashboard*
This guide provides step-by-step instructions for logging into the Offer Management modules Admin Portal as an administrator.
Open your preferred web browser and go to the **Admin login URL:** [https://stage.giift.com/giiftbox/GiiftBoxewards/admin/#/landing](https://stage.giift.com/giiftbox/GiiftBoxewards/admin/#/landing)
On the login screen, enter your **administrator credentials:**
**Email Address:** [name.admin@giift.com](mailto:name.admin@giift.com)
* Password: 123456 (example password)
Please Note: Ensure you use your actual admin credentials provided by the system administrator. The above is just a sample.
After entering your credentials, click the "**Sign In**" button to access the admin dashboard.
* Forgot Password? Use the "Forgot Password" option to reset.
* Security Tip: Never share your login credentials with unauthorized users.
* Need Help? Contact your system administrator or [cs@xoxoday.com](mailto:cs@xoxoday.com) for any issues.
Looking to drive loyalty, boost sales performance, or enhance employee engagement? [Explore Xoxoday's product suite here!](https://www.xoxoday.com/get-a-demo)
# Merchants
Source: https://help-plum.xoxoday.com/offers-management/merchants
Learn how to manage merchant records within the Plum Offers Management portal, including adding and updating merchant details.
*Learn how to create and manage merchants on Offer Management module*
This module allows Admins to efficiently onboard, manage, and organize merchants and their associated stores.
## Overview
The Merchants module empowers admins to:
* Create new merchants
* View, search, and filter existing merchants
* Edit merchant details
* Export merchant lists
* Manage merchant stores
***
## Accessing the Merchant List
Admins can access a full list of onboarded merchants from the Merchants module. Here, they can:
* Search for merchants using filters (e.g., name, country, status)
* Edit merchant details directly
* Export the complete list in CSV or Excel format
***
## Creating a New Merchant
To create a new merchant:
Click the "Create Merchant" button.
Fill in the required fields in the form:
* Merchant Name
* Country
* Contact Information
* Business Category, etc.
Click "Create" to onboard the merchant.
Once saved, the merchant will appear in the list.
***
## Managing Stores Under a Merchant
To manage stores:
Click on a merchant's name and under it under actions click on the details:
From here, you can:
* View existing stores
* Edit store information
* Update Store PINs
* Create new stores
***
## Creating a Store
* Click the "**Create Store**" button.
* Fill in the required store details:
* Store Name
* Address
* Store PIN (if applicable)
* Country/Location and more
* Click "**Save**" to add the store.
The store will now be listed under the merchant and available for further actions.
***
## Store Management Actions
In the Store Action Table, you can:
* View full store information
* Edit store details
* Update store PINs securely
Tip: Regularly update store PINs for improved security.
# Offer Management
Source: https://help-plum.xoxoday.com/offers-management/offer-management-product-tour-videos
Watch a collection of product tour videos covering the features and workflows of Plum's Offers Management portal.
Overview: Manage the entire ecosystem from a single dashboard. This walkthrough demonstrates how administrators can oversee merchant onboarding, configure platform-wide settings, and access high-level analytics to monitor program health and performance.
***
## Merchant Experience
Overview: See how merchants can self-serve and drive their own growth. This video covers the end-to-end merchant workflow, including:
* Creating Offers: Designing custom vouchers and setting redemption rules.
* Campaign Management: targeting specific customer segments and sending offers.
* Performance Tracking: Viewing claim history, redemptions, and detailed reports.
***
## Customer Experience
Overview: Understand the user journey from discovery to redemption. This demo shows how customers interact with the platform to browse available offers, claim rewards, and seamlessly redeem them at the point of sale using their digital vouchers.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Create an offer
Source: https://help-plum.xoxoday.com/offers-management/offers/create-an-offer
Learn how to create a new merchant offer in Plum's Offers Management portal, from initial setup through publishing it live.
*Learn how to create offers*
The Offers module in the admin portal enables admins to create, customize, and manage a wide range of promotional offers.
## Creating Offers
To create a new offer:
Click the "**Create Offer**" button.
* Discount (percentage-based)
* Fixed-value (e.g., \$10 off)
* Free-format (custom offer format)
* Product (physical or digital product)
After selecting the offer type, fill in all required fields across the following sections:
* Time Zone
* Brand Name
* Display Title
* Face Value (use drop-down menu to select)
* Offer Image
* Description
* Voucher Code Info
* Redemption Info
# Offers - Overview
Source: https://help-plum.xoxoday.com/offers-management/offers/offers-overview
Get an overview of how merchant offers are managed within Plum's Offers Management portal, from creation to tracking.
*The Offers module allows admins to create, search, and manage offers within the admin portal.*
## Key Capabilities on the Offers Page
## 1. Create Offers
## 2. Search & Filter Offers
## 3. Manage Offers
Once offers are listed, you can perform the following actions from the Action Table:
* **Edit:** Update any offer details
* **View:** See full offer information
* **Delete:** Remove an offer permanently
* **Details / Track Offer:** View offer performance, usage metrics, and status history
For any questions or feedback reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
Looking to drive loyalty, boost sales performance, or enhance employee engagement? [Explore Xoxoday's product suite here!](https://www.xoxoday.com/get-a-demo)
# Search and Filter Offers
Source: https://help-plum.xoxoday.com/offers-management/offers/search-and-filter-offers
Learn how to search and filter offers within Plum's Offers Management portal to quickly find the one you're looking for.
*Learn how to search and filter offers*
The Search Status Card allows you to filter and search for specific offers using the following filters:
* **Offer Name** — Enter the name of the offer you wish to search for.
* **Merchant Name** — Select from a list of merchants using the dropdown icon.
* **Areas** — Filter offers based on location.
* **Web Portals** — Choose the relevant web portal associated with the offer.
* **Offer Type** — Select the type of offer (e.g., Fixed, Percentage, etc.).
* **Status** — Filter by offer status:
* Unpublished
* Unpublishing
* Published
* Publishing
* Expired
* Draft
* **Expiry Before** — Use the calendar icon to select a date and filter offers expiring before that date.
# Password
Source: https://help-plum.xoxoday.com/offers-management/password
Learn how to reset or update your password in Plum's Offers Management portal if you're locked out or want to change it.
*Learn how to reset password*
## Password Management
Admins and users can update or reset their passwords through the Password section in the Settings module. This helps ensure secure access to the platform and maintain data integrity.
***
## To Update or Reset Your Own Password:
Click "**Password**" from the left-side menu under Settings.
* Current Password: Input your existing password
* New Password: Enter a new password
* Confirm New Password
Once all fields are filled correctly, click "**Save**" to reset your password.
Your password will be updated successfully.
***
## Admin-Initiated Password Reset
* For security purposes, Admins can reset any user's password. This ensures continued access and protects the system from unauthorized use.
Note: It's recommended to set a strong password with a mix of uppercase, lowercase, numbers, and symbols.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Reports Overview
Source: https://help-plum.xoxoday.com/offers-management/reports/reports-overview
Get an overview of the reporting features available in Plum's Offers Management portal, including what each report covers.
*Learn all about the reports module*
Loopr provides comprehensive reporting to help you track and analyze your offers and portal activity.
* Click on "**Reports**" from the left-hand side menu.
***
## On the Reports page, you can:
* **Quick Sort** — Quickly sort reports by Most Recent to see the latest activity at a glance.
* **Filter by Time Frame** — Select a specific date range to view data for that period.
* **Filter by Offer** — View detailed data for an individual offer to track performance.
* **Filter by Web Portal** — Access data for each web portal separately to monitor portal-specific engagement.
Offer Management's reporting tools empower you to make data-driven decisions and optimize your campaigns.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Viewing Reports & Insights
Source: https://help-plum.xoxoday.com/offers-management/reports/viewing-reports-insights
Learn how to view reports and performance insights in Plum's Offers Management portal to track offer effectiveness.
*Learn how to view reports and insights*
## Report Types Available
Loopr offers three key types of reports to help you track user engagement and campaign effectiveness:
* **Redeemed vs. Claimed Report** — Compare how many offers have been claimed vs. how many have been redeemed. This helps you identify which offers are being acted upon and which might need attention.
* **Anonymous Click Report** — Track clicks from users who have interacted with the offers but haven't logged in or provided identifiable details. Useful for measuring interest from new or guest users.
* **User Landing Page Report** — Understand how users are landing on your offer pages. This gives insight into traffic sources and campaign reach.
***
## Filters & Customization Options
To help you zero in on specific insights, Reports come with powerful filtering options:
### Date Filters
You can select from the following predefined time ranges:
* Today
* Yesterday
* Last 7 Days
* This Month
You can also select a custom date or specific day to analyze targeted periods.
### Filter Parameters
Further refine your data using the following filters:
* Day / Month
* Offer Name
* Source (e.g., Web Portal, Merchant, Campaign)
* Merchant Name
This flexibility allows Admins to view data based on campaign type, origin, or time period—giving a clear picture of what's working and where optimizations are needed.
***
## How to Use the Reports Section
Navigate to **Reports** from the dashboard.
Choose the type of report you want to view (**Redeemed vs. Claimed, Anonymous Clicks, or User Landing Page**).
Apply the **date range** from the top filter panel.
Use dropdown filters for Offer Name, Source, Merchant, or specific Days/Months.
View or export the data as needed. Click "**Export Report**".
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Activate a deactivated user
Source: https://help-plum.xoxoday.com/offers-management/settings/roles/activate-a-deactivated-user
Learn how to reactivate a previously deactivated user in Plum's Offers Management portal and restore their access.
*Learn how to activate a deactivated user*
Admins can bring back access for users who were previously deactivated.
## Steps to Reactivate an Existing User:
Click "**Active**" next to the user's name.
A confirmation pop-up will appear. Click "**Confirm**" to proceed.
### User Reactivated
* The user's status will change to "Active", and they will regain access to the platform.
Note: Only users with a "Disactive" status can be reactivated.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Add a new user
Source: https://help-plum.xoxoday.com/offers-management/settings/roles/add-a-new-user
Learn how to add a new user to Plum's Offers Management portal and assign them the appropriate role and access level.
*Learn how to add users & assign roles*
Easily create new user accounts and assign them appropriate roles such as Admin, Checker, or Maker to manage platform access.
Admins can add new users to the platform through the **Settings > Roles section**.
## Steps to Add a New User:
Go to the Settings module and click on Roles.
On the top right of the Roles page, click the "**Add User**" button.
A form will appear. Enter the following required information:
* **Name**: Full name of the user
* **Password**: Set a secure password for login
* **Role**: Select a role from the dropdown (e.g., Admin, Approver, Maker)
User role currently available for selection: Admin, Checker, Maker
Once all fields are filled, click "**Ok**" to create the new user account.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Deactivate existing user
Source: https://help-plum.xoxoday.com/offers-management/settings/roles/deactivate-existing-user
Learn how to deactivate an existing user in Plum's Offers Management portal without permanently deleting their account.
*Learn how to deactivate an existing user*
Admins can deactivate users who no longer need access to the platform. This helps maintain security and ensures only relevant users have active access.
## Steps to Deactivate a User:
Go to Settings > User
Locate the user with "**Active**" status in the user list.
Click the "**Disable**" button next to the user's name.
A confirmation pop-up window will appear. Click "**Confirm**" to proceed.
### User Deactivated
* The user's status will be updated to "Inactive", and they will no longer be able to log in.
Note: Only users with "Active" status can be deactivated.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Delete a user
Source: https://help-plum.xoxoday.com/offers-management/settings/roles/delete-a-user
Learn how to permanently delete a user from Plum's Offers Management portal, removing their access entirely and for good.
*Learn how to delete a user*
Admins can permanently delete a user from the system when they no longer require access or if the account is no longer needed.
## Steps to Delete a User:
Go to Settings > Roles.
Find the user you wish to delete from the user list.
Click the "**Delete**" button next to the user's name.
A confirmation pop-up will appear. Click "**Confirm**" to proceed.
## User Deleted
* The user will be permanently removed from the platform
Note: Deletion is irreversible. Only users no longer in use should be deleted.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Edit a User
Source: https://help-plum.xoxoday.com/offers-management/settings/roles/edit-a-user
Learn how to edit an existing user's details, role, and permissions in Plum's Offers Management portal settings.
*Learn how to edit a user*
Admins can edit a user by editing their status.
## Steps to Reactivate a User:
Click "**Edit**" next to the user's name.
Edit the Name and Role and click on **"Ok"**
For any questions or feedback reach out to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
Looking to drive loyalty, boost sales performance, or enhance employee engagement? [Explore Xoxoday's product suite here!](https://www.xoxoday.com/get-a-demo)
# Roles Landing Page
Source: https://help-plum.xoxoday.com/offers-management/settings/roles/roles-landing-page
Get an overview of the user roles available in Plum's Offers Management portal and what each role is permitted to access.
*Learn about the Roles Landing Page*
## Accessing Roles:
* To access the user role management page, click "Role" on the left menu
* On clicking "Role" on the left menu, directs to the user role management page
***
## For user role management page:
* View user roles and their access
* View listing of existing user
* Create new user
* Edit existing user
* Disable existing user
* Delete existing user
* Activate disabled user
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Viewing User Roles and Access Permissions
Source: https://help-plum.xoxoday.com/offers-management/settings/roles/viewing-user-roles-and-access-permissions
Learn how to view existing user roles and their associated access permissions in Plum's Offers Management portal settings.
The Roles Landing Page allows Admins to view all user roles and understand the permissions assigned to each role.
## Steps to View User Roles:
Navigate to the Settings module and select Roles from the sidebar.
On the Roles page, click the "View Roles" button.
A list of all available user roles will be displayed. For each role, you can see:
* Role Name (e.g., Admin, Approver, Maker)
* Features and Functions Accessible under that role
* Access Type (View/Edit/Approve/Reject)
This helps Admins manage platform security and assign the right level of access to each user based on their responsibilities.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Settings - Overview
Source: https://help-plum.xoxoday.com/offers-management/settings/settings-overview
Get an overview of the settings available in Plum's Offers Management portal, covering roles, feedback, and configuration.
*Learn how to manage platform configurations, users, and security preferences efficiently.*
The Settings module allows Admins to manage platform configurations, users, and security preferences efficiently.
***
## 1. Roles Landing Page
Manage user roles and permissions to control who can access and perform specific actions on the platform.
Key Actions:
* View existing roles
* Add new roles
* Assign or modify permissions for each role
* Delete or update roles
***
## 2. User Feedback Landing Page
Capture and manage user feedback to improve platform experience and functionality.
Key Actions:
* View submitted feedback from users
* Filter feedback by date, type, or status
* Mark feedback as addressed or in-progress
* Export feedback reports
***
## 3. Password Landing Page
Set up and manage password policies to ensure secure access to the platform.
Key Actions:
* Define password strength and expiry rules
* Set up multi-factor authentication options (if applicable)
* Reset user passwords
* View login history and password change logs
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Add new user feedback
Source: https://help-plum.xoxoday.com/offers-management/settings/user-feedback/add-new-user-feedback
Learn how to add new user feedback in Plum's Offers Management portal to capture and track input from your team.
*Learn how to add a new user feedback*
Admins can easily add new feedback options to better capture user insights and sentiments.
## Steps to Add a New Feedback Option:
Go to Settings > User Feedback from the left menu.
On the User Feedback Management Page, click the "**Add Feedback Content**" button.
A pop-up or overlay window will appear with input fields.
* **Input the Feedback:** Type the content of the feedback option (e.g., "Great experience", "Needs improvement").
* **Set Sorting Sequence:** Enter a number to define the order in which this option will appear in the list (e.g., 1, 2, 3...).
Once the information is entered, click "**Save**" to add the new feedback option to the system.

The new feedback option will now appear in the user feedback list.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Edit or Delete User Feedback
Source: https://help-plum.xoxoday.com/offers-management/settings/user-feedback/edit-or-delete-user-feedback
Learn how to edit the details of, or permanently delete, existing user feedback in Plum's Offers Management portal.
*Learn how to edit or delete a User feedback*
## Editing an Existing Feedback Option
To update a feedback option:
On the User Feedback Management Page, find the feedback you want to edit.
Click the "**Edit**" button beside the selected feedback.
An edit overlay window will appear, allowing you to update the feedback content. Make the necessary changes and click "**Save**" to apply the updates.
***
## Deleting a Feedback Option
To remove a feedback option permanently:
On the User Feedback Management Page, find the feedback you want to delete.
Click the "**Delete**" button next to the selected feedback option.
A confirmation pop-up may appear. Confirm to delete the feedback option.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# User Feedback - Overview
Source: https://help-plum.xoxoday.com/offers-management/settings/user-feedback/user-feedback-overview
Get an overview of the user feedback feature in Plum's Offers Management portal and how submitted feedback is used.
*Learn more about User feedback*
Admins can access and manage all user feedback options through the User Feedback section in the Settings module.
## How to Access the User Feedback Page:
* **Navigate to the Left Menu** — From the dashboard, click on "**User Feedback**" under the Settings module.
* **Open the Feedback Management Page** — Clicking on "User Feedback" will direct you to the User Feedback Management Page, where you can view and manage feedback options.
***
## What You Can Do on the User Feedback Page:
* **View Feedback Options** — See a list of all existing user feedback options currently available on the platform.
* **Edit Feedback Option** — Modify the content or category of any feedback option by clicking the "**Edit**" button.
* **Add New Feedback Option** — Click "**Add**" to create a new user feedback option. Enter the required details and save.
* **Delete Feedback Option** — Remove outdated or irrelevant feedback options by clicking "**Delete**" next to the corresponding item.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Add category or sub-category
Source: https://help-plum.xoxoday.com/offers-management/web-portal/add-category-or-sub-category
Learn how to add a new category or sub-category to a web portal in Plum, helping organize offers for customers.
*Learn how to add a category or a sub-category*
To add a new group (category/sub category):
* Go to the Web Portals tab from the left-hand side menu.
* Click on the desired web portal from the list.
* Once the selected portal loads, the categories and sub-categories will be displayed on the left panel.
* Click on the "+" icon located near the categories panel.
* This will open the Add Category/Sub-Category overlay.
Fill in the following fields in the overlay:
* Group Name
* Father Group (select parent category if it's a sub-category)
* Show Location
* Sort Order
* Group Image
Once all details are filled in, click "Save" to create the new category or sub-category.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Add Offers
Source: https://help-plum.xoxoday.com/offers-management/web-portal/add-offers
Learn how to add offers to a specific web portal within Plum's Offers Management module so they become visible to customers.
*Learn to add offers on the web portal*
Follow the steps to add offers on the web portal:
* Navigate to the Web Portals tab from the left-hand side menu.
* Click on the web portal you want to add offers to, and then click **"View"** under the selected offer.
* On the portal details page, click "**Add Offers**" located at the top right corner.
* This will open the Add Offers overlay window.
* Browse or search the list of available offers in the overlay.
* Click on the offers you want to add — selected offers will be highlighted.
* Once your selection is complete, click "**Confirm Adding**" to add the selected offers to the web portal.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Brand Management
Source: https://help-plum.xoxoday.com/offers-management/web-portal/brand-settings/brand-management
Learn how to manage brand settings for a web portal in Plum's Offers Management module, including adding and editing brands.
*Learn to manage brands on the Loopr dashboard*
Follow these steps to update or change a brand for a specific web portal:
Navigate to the Web Portal tab and select the relevant portal. Click the "**Brand**" button to open the Brand Management page.
On the specific brand you want to change, click the "**Change**" button below it. An overlay will appear showing all available brands.
You can either search for a brand or select one by simply clicking on it. Once selected, click Submit to save your changes.
The updated brand will now reflect on the selected web portal.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Brand Search
Source: https://help-plum.xoxoday.com/offers-management/web-portal/brand-settings/brand-search
Learn how to quickly search for a specific brand within Plum's Offers Management web portal settings and configuration.
*Learn how to search for a brand on the particular web portal*
Follow these steps to search and update a brand on a specific web portal:
Navigate to Web Portals > Brand.
Click on "**Change**" under the brand name you want to update.
In the search bar, type the name of the brand you're looking for.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Overview
Source: https://help-plum.xoxoday.com/offers-management/web-portal/brand-settings/brand-setting
Learn how to configure individual brand settings for a specific web portal within Plum's Offers Management module.
*Learn to manage brand setting on the Loopr platform*
Follow the steps below to manage brand visibility on a selected web portal:
Navigate to the **Web Portal** tab on the left-hand side (LHS) menu.
Click on the "**Brand**" button for the desired web portal. On click, the Brand Management Page for the selected web portal will open.
You can add up to 8 brands per web portal.
Use this section to control which brands are highlighted or featured on each portal.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Categories and sub-categories of the web portals
Source: https://help-plum.xoxoday.com/offers-management/web-portal/categories-and-sub-categories-of-the-web-portals
Learn how categories and sub-categories are structured within Plum's web portals to help customers browse offers.
*Learn how to view categories and sub offers*
The categories and sub-categories of the selected web portal are displayed on the left panel of the page.
**Click on a category or sub-category** on the left panel. The offers added under the selected category will be displayed on the right panel.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Delete offer from the selected web portal
Source: https://help-plum.xoxoday.com/offers-management/web-portal/delete-offer-from-the-selected-web-portal
Learn how to permanently delete an offer from a selected web portal in Plum's Offers Management module and settings.
*Learn how to delete an offer from the web portal*
Follow these steps to delete an offer from a selected sub-category in the web portal:
Go to **Web Portals** and select the desired portal. Navigate to the specific sub-category where the offer is listed.
Locate the offer you want to remove and click "**Remove**" next to it.
A confirmation prompt will appear asking: "Are you sure you to remove the offer?" Click "**Confirm**" to proceed.
Once confirmed, the selected offer will be permanently deleted from the sub-category.
Note: Deleted offers cannot be recovered. Please double-check before confirming.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Edit a category or sub-category
Source: https://help-plum.xoxoday.com/offers-management/web-portal/edit-a-category-or-sub-category
Learn how to edit an existing category or sub-category within a Plum web portal to keep your offers well organized.
*Learn how to edit a category or a sub-category*
Follow the steps to edit a category or a sub category on the webportal.
* Go to the Web Portals tab from the left-hand side menu.
* Select the web portal where you want to edit a category or sub-category.
* Click "View" to open the portal details page.
* Click on the desired category or sub-category from the left panel.
* Click the "Edit" (pencil) icon next to the selected item.
* This will open the Edit Category/Sub-Category overlay.
* Update the required category or sub-category information in the overlay fields.
* Click "Save" to apply and update the changes.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Publish or Unpublish offers in the selected web portal
Source: https://help-plum.xoxoday.com/offers-management/web-portal/publish-or-unpublish-offers-in-the-selected-web-portal
Learn how to publish or unpublish offers within a selected web portal in Plum, controlling what customers can see.
*Learn how to publish or unpublish offers in the selected web portal*
To manage offer visibility on your selected web portal, follow the steps below:
## Publishing Offers
Go to the Web Portals section from the admin dashboard. Select the desired web portal to view its details.
On the selected portal's page, scroll down to the Offer Cards section. Click "**Publish**" on the offer you want to make live. It will ask you to "**Confirm**" your selection.
Once you click **Publish**, the offer will be published to the selected web portal. The offer status will automatically update from "Unpublished" to "Published."
***
## Unpublishing Offers
In the Offer Cards section of the web portal, locate the published offer. Click "**Unpublish**" on the offer you want to remove.
After clicking **Unpublish**, the offer will be removed from the selected web portal. The status will change from "Published" to "Unpublished."
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Search/Filter for Offers in Web Portal
Source: https://help-plum.xoxoday.com/offers-management/web-portal/searchfilter-for-offers-in-web-portal
Learn how to search and filter offers within a Plum web portal to quickly locate the specific one you need to manage.
*Learn how to search/filter offers in the web portal*
Go to the left-hand side (LHS) menu and click on "Web Portals."
Admins can filter offers using multiple options available above the offer listing table.
## Available Filter Options:
* **Offer Name:** Enter the name of the offer in the search bar and click Search.
* Select the type of offer (e.g., Discount, Fixed Value).
* Filter offers based on their status (Active, Inactive, etc.).
* Select the merchant linked to the offer.
* **Date:** Select a specific date or a range to filter offers by date of creation or availability.
* **Area**
Click the **Search** button to view matching results.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Track the offers of the selected web portal
Source: https://help-plum.xoxoday.com/offers-management/web-portal/track-the-offers-of-the-selected-web-portal
Learn how to track the ongoing performance of offers within a selected web portal in Plum's Offers Management module.
*Learn to track offers*
Steps to track offer transactions in a Web Portal:
* Navigate to the Web Portals tab.
* In the list of offers, locate the offer you want to track.
* Click "**Detail**" next to the selected offer.
* The Track Offers Detail page will be displayed, showing a list of transactions related to that offer.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# View offer information
Source: https://help-plum.xoxoday.com/offers-management/web-portal/view-offer-information
Learn how to view detailed information about a specific offer within a Plum web portal, including its status and settings.
*View information relating to an offer on Loopr*
To view Offer Information in a Web Portal:
* Navigate to the Web Portals tab and click "View" for the desired web portal.
* In the list of offers displayed for that portal, locate the offer you want to view.
* Click "View" next to the selected offer.
* This will open the Offer Information page, where you can see all the details related to that offer.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Overview
Source: https://help-plum.xoxoday.com/offers-management/web-portal/web-portal
Get an overview of the web portal feature within Plum's Offers Management module and how offers are surfaced to customers.
*Learn how to manage the web portal*
In the left-hand menu, click on "Web Portals."
This will take you to the Web Portal Management page, where you can manage offers, categories, and visibility settings for different portals.
***
## What You Can Do on the Web Portals Page
Once you're on the Web Portals management page, you can perform the following actions:
**Manage Categories & Sub-Categories**
* Create/Edit Main Categories: Set up broad-level offer categories (e.g., Travel, Electronics).
* Create/Edit Sub-Categories: Organize offers under sub-groups for better navigation (e.g., Flights under Travel).
* Show/Hide Categories & Sub-Categories: Choose which categories or sub-categories should be visible or hidden on specific web portals.
**Manage Offers on Web Portals**
* Add/Delete Offers: Add offers to or remove offers from specific web portals as needed.
* Publish/Unpublish Offers: Control the live status of offers on your web portals.
* View Offer Details: Click on an offer to see more information, such as offer name, description, and validity.
* Track Offer Listings by Web Portal: View all offers assigned to a specific portal to keep track of what's currently being displayed.
***
**Pro Tips**
* Use filters to quickly find offers or categories you need to manage.
* Always save changes before navigating away to avoid losing updates.
* Unpublished offers will not appear on the end-user portal until published again.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Web Portals Management
Source: https://help-plum.xoxoday.com/offers-management/web-portal/web-portals-management
Get an overview of managing multiple web portals within Plum's Offers Management module from a single central place.
*Learn how to manage the Web Portal*
Go to the left-hand side (LHS) menu and click on "Web Portals."
* Select a web portal from the list.
* This will redirect you to the corresponding Web Portal Management page.
* Click on the "View" button next to the portal you want to explore.
On the portal details page, you can view:
* The categories and sub-categories of the selected web portal.
* The offers that have been added to this web portal.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Virtual PayPal International
Source: https://help-plum.xoxoday.com/prepaid-cards/virtual-paypal-international
Learn how to send and redeem virtual PayPal international prepaid cards through Plum, including where recipients can use them.
Cross-border transfer of rewards across geographies made easy with Paypal rewards.
PayPal is an online payment system that makes paying for things online and sending and receiving money safe and secure. PayPal is the faster, safer way to send and receive money or make an online payment worldwide.
Whether you’re shopping, splitting expenses, or getting paid for sales, Paypal makes it as easy as possible to spend or transfer money from your Paypal wallet for online purchases across the globe.
# Getting Started
## How to transfer money to a Paypal wallet
Steps for an admin to send money to a Paypal wallet:
**Step 1:** Log in to your Plum account
Step 2: Recharge your Plum wallet by clicking on the ‘Recharge’ option from the navigation bar and adding your desired amount.\*\*
Step 3:\*\* Click on ‘Plum Pro’ from the left panel to transfer money to your Paypal wallet
Step 4:You have the option to send money to the Paypal wallet to a few recipients or to multiple recipients in bulk.
# Sending money to a Paypal wallet to a single or a few recipients
Select the ‘Send to few’ tab and follow these steps:
* Under ‘Select a country for brand vouchers’ choose the recipients’ country from the drop-down list.
* In the ‘Add a Recipient’ section, add the full name of the recipient.
* For the next box, select ‘Paypal International’ from the drop-down menu
* Select the denomination of the voucher from the drop-down list
* Add the quantity of brand vouchers
* Add the recipient’s phone number (optional)
* Add the PO number (optional)
* Add a personalized message for the recipient
* Click ‘Add another recipient’ to add more recipients and repeat steps 1 to 8 listed above.
* Once you are done click on ‘Send Reward.’
## Send money to Paypal wallets in bulk to multiple recipients
Select the ‘Bulk Upload’ tab and follow these steps:
* To know the required format for uploading data in bulk, download a sample file by clicking on ‘CSV/XLSX template’ under ‘Add your recipients in bulk.’ You may skip this step if you already have a CSV/XLSX file with data in the required format.
* Once you’ve filled in the details correctly, click ‘Add CSV/XLSX file’ to upload and verify the data.
* Add the correct details for each column from the CSV sheet to upload the recipients’ information in bulk.
* Click on ‘Verify file’ at the bottom
* Click on ‘Yes, continue’ in the pop-up box to verify the file.
* Once you verify the file, click ‘Generate & Send’ to transfer the amount to the recipients’ wallets.
# How to Redeem?
## Here’s the step-by-step process for the recipient to redeem the reward:
Step 1: You will receive an email with the details of your Paypal amount. Click on ‘Redeem’.**Step 2:** Once you click on ‘Redeem’, you will be redirected externally to claim the reward. Now, click on ‘Redeem’ again.
Step 3:\*\*Choose your country and click on the Paypal icon below as shown in the screenshot \*\*Step 4:\*\*Now, enter your registered email address with Paypal to transfer the amount to your Paypal wallet.\*\*
Step 5:\*\* Once you initiate the transfer to your Paypal wallet, you will receive an email notifying you of the same to your registered email address and the date of the payment initiated.
Step 6:\*\* On the next screen you can track the delivery status of the money transferred to your Paypal wallet by clicking on the ‘Track Status’ button and review the transferred amount.
Step 7:\*\*Finally, you will receive a confirmation email from Paypal to your registered email address to notify you of the successful transaction.\*\*
About the Paypal card usage:
* Claim the amount transferred to your Paypal account within 1 month or it will be returned to the sender.
* Once claimed & amount added to your Paypal account, it cannot be canceled.
* Please input your name & registered PayPal account email on the page.
* Your funds should be available in your PayPal account within 1 day.
* Actual amount will be added based on the Forex exchange on a daily basis to your Paypal Account.
* Paypal amount can be used online only wherever it is applicable.
* This Paypal product can only be issued for employee rewards/channel incentives/consumer campaigns/loyalty programs.
* This Paypal product cannot be issued for Facebook advertising payments, cannot be procured for business-related payments, or any program that is not part of a reward/incentive use case.
* Paypal Terms & Conditions will be applicable- [https://www.paypal.com/us/webapps/mpp/ua/legalhub-full?locale.x=en\_US](https://www.paypal.com/us/webapps/mpp/ua/legalhub-full?locale.x=en_US)
* TAT for delivering the amount to your Paypal account is between 7-10 working days.
* For any queries & issues, please reach out [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Virtual Visa Card
Source: https://help-plum.xoxoday.com/prepaid-cards/virtual-visa-card
Learn how to send and redeem virtual Visa prepaid cards through Plum, including where and how recipients can spend them.
Cross-border transfer of rewards using Virtual Visa prepaid cards.
Visa rewards are great because they give your recipients the flexibility of using them at online stores of their choice.
Unlike regular gift cards, Visa prepaid cards cannot be used in combination with other payment methods. This means that the recipient must have enough money on the card to cover the full cost of their purchase.
The funds on a Visa prepaid card must be utilized within the validity timeline from the date of issue.
# Getting Started
## Steps for an admin to send virtual prepaid cards
Step 1: Log in to your Plum account\*\*
Step 2:\*\*Recharge your Plum wallet by clicking on the ‘Recharge’ option from the left panel and adding your desired amount.\*\*
Step 3:\*\*Click on ‘Plum Pro’ from the left panel to send Visa prepaid cards **Step 4:** You have the option to send Visa prepaid cards to a few recipients or to multiple recipients in bulk.
## Sending Visa prepaid cards to a single or a few recipients
Select the ‘Send to few’ tab and follow these steps:
* Under ‘Select a country for brand vouchers’ choose the recipients’ country from the drop-down list.
* In the ‘Add Recipients’ section, add the full name of the recipient.
* For the next box, select ‘Prepaid Virtual Visa International Card USD’ from the drop-down menu
* Select the denomination of the voucher from the drop-down list
* Add the quantity of brand vouchers
* Add the recipient’s phone number (optional)
* Add the PO number (optional)
* Add a personalized message for the recipient
* Click ‘Add another recipient’ to add more recipients and repeat steps 1 to 8 listed above.
* Once you are done click on ‘Generate & Send.’\*\*
Send Visa prepaid cards in bulk to multiple recipients
Select the ‘Bulk Upload’ tab and follow these steps:
* To know the required format for uploading data in bulk, download a sample file by clicking on ‘CSV/XLSX template’ under ‘Add your recipients in bulk.’ You may skip this step if you already have a CSV/XLSX file with data in the required format.
* Once you’ve filled in the details correctly, click ‘Add CSV/XLSX file’ to upload and verify the data.
* Add the correct details for each column from the CSV sheet to upload the recipients’ information in bulk.
* Click on ‘Verify file’ at the bottom.
* Click on ‘Yes, continue’ in the pop-up box to verify the file.
* Once you verify the file, click ‘Generate & Send’ to send prepaid cards to the recipients. The recipient receives an email with the details of their prepaid card and a link to claim the reward.
How to Redeem?
## Steps for the recipient to redeem a reward
* You will receive an email with the details of your Visa prepaid card. Click on ‘Click Here To Redeem’ to claim the reward.
* Click on ‘Redeem’ to claim the reward.
* Enter your first and last name in the box, go over the E-Sign Disclosure, Cardholder Agreement, and Privacy Policy, tick the two checkboxes to indicate your agreement, and click ‘Activate card.’
* On the next screen you can see the details of your Visa prepaid card.
* Post activation, if you’d like to opt for notifications for your Visa prepaid transactions, select either SMS or email, and add your phone number and email address to receive transaction-related messages.
* You’ll now receive a link in your email inbox to view your prepaid card and redeem it
About the Prepaid Virtual Visa International USD card usage\* (for the rest of the world)
* A Visa prepaid card gives you the flexibility to shop anywhere around the world where Visa debit cards are accepted.
* The funds on your Visa prepaid card must be accessed within 6 months from the date it was issued.
* This card cannot be redeemed in a country where there is a USA sanction.
* This card cannot be redeemed in India.
* The funds on the card cannot be cashed or transferred/added to Google Pay, Apple Pay, or any other wallet.
* This virtual visa card can only be used for online purchases where it is acceptable.
* This card cannot be redeemed in any country where there is a USA sanction.
* This card cannot be redeemed in India.
* This card can only be issued for employee rewards, channel incentives, consumer campaigns, and loyalty programs.
* This card cannot be issued for Facebook advertising payments, procured for business-related payments, or any program that is not part of a reward or incentive use case.
* This card is a one time use card and is non reloadable in nature.
* The card issuer does not charge any currency conversion costs, but in some regions, it's possible that a merchant where the card would be swiped could charge a fee if the USD Virtual Visa International card is used to make a purchase in a non-USD currency.
* Transactions with the following merchants are prohibited:
* Money transfer services business
* Firearm-related businesses
* Tobacco businesses
* Marijuana-related businesses
* Money services from non-financial institutions (including cryptocurrency)
* Securities brokers/dealers
* Dating services
* Massage parlors
* Government-owned lotteries
* Government-licensed online casinos and online gambling
* Government-licensed horse/dog racing
* Betting, including lottery tickets, casino gaming chips, off-track betting, and wagers at race tracks
This card can be redeemed in the following countries:
Albania, Algeria, American Samoa, Andorra, Angola, Anguilla, Antarctica, Antigua and Barbuda, Argentina, Armenia, Aruba, Ascension Island, Australia, Austria, Azerbaijan, Bahamas, Bahrain, Bangladesh, Barbados, Belgium, Belize, Benin, Bermuda, Bhutan, Bolivia, Botswana, Bouvet Island, Brazil, British Indian Ocean Territory, Brunei Darussalam, Bulgaria, Burkina Faso, Cambodia, Cameroon, Canada, Cape Verde, Cayman Islands, Chad, Chile, China, Christmas Island, Cocos (Keeling) Islands, Colombia, Comoros, Congo, Republic of the, Cook Islands, Costa Rica, Cote d'Ivoire, Croatia, Cyprus, Czech Republic, Denmark, Djibouti, Dominica, Dominican Republic, East Timor, Ecuador, Egypt, El Salvador, Equatorial Guinea, Eritrea, Estonia, Falkland Islands (Malvinas), Faroe Islands, Fiji, Finland, France, French Guiana, French Polynesia, French Southern Territories, Gabon, Gambia, Georgia, Germany, Ghana, Gibraltar, Greece, Greenland, Grenada, Guadeloupe, Guam, Guatemala, Guernsey, Guinea, Guinea-Bissau, Guyana, Haiti, Heard Island and McDonald Islands, Honduras, Hong Kong, Hungary, Iceland, Ireland, Isle of Man, Israel, Italy, Jamaica, Japan, Jersey, Jordan, Kazakhstan, Kenya, Kiribati, Korea, Republic of, Kuwait, Kyrgyzstan, Lao People's Democratic Republic, Latvia, Lesotho, Liberia, Liechtenstein, Lithuania, Luxembourg, Macao, Macedonia, the Former Yugoslav Republic of, Madagascar, Malawi, Maldives, Malta, Marshall Islands, Martinique, Mauritania, Mauritius, Mayotte, Mexico, Micronesia, Federated States of, Moldova, Republic of, Monaco, Mongolia, Montenegro, Montserrat, Morocco, Mozambique, Namibia, Nauru, Nepal, Netherlands, New Caledonia, New Zealand, Niger, Nigeria, Niue, Norfolk Island, Northern Mariana Islands, Norway, Oman, Palau, Palestine, State of, Paraguay, Peru, Pitcairn, Poland, Portugal, Puerto Rico, Qatar, Reunion, Romania, Rwanda, Saint Kitts and Nevis, Saint Lucia, Saint Vincent and the Grenadines, Samoa, San Marino, Sao Tome and Principe, Saudi Arabia, Senegal, Serbia, Seychelles, Sierra Leone, Singapore, Slovakia, Slovenia, Solomon Islands, South Africa, South Georgia and the South Sandwich Islands, Spain, Sri Lanka, Saint Helena, Saint Pierre and Miquelon, Suriname, Svalbard and Jan Mayen, Swaziland, Sweden, Switzerland, Taiwan, Province of China, Tajikistan, United Republic of Tanzania, Togo, Tokelau, Tonga, Trinidad and Tobago, Tunisia, Turkey, Turkmenistan, Turks and Caicos Islands, Tuvalu, United States Minor Outlying Islands, United Arab Emirates, United Kingdom, Uruguay, Uzbekistan, Holy See (Vatican City State), Vietnam, British Virgin Islands, US Virgin Islands, Wallis and Futuna, Western Sahara and Zambia.
## About the prepaid virtual Visa Card usage(for the US region only)
A Visa prepaid card gives you the flexibility to shop anywhere around the world where Visa debit cards are accepted.
* This card must be used within 6 months from the date of issuance.
* This card is only valid for online/virtual purchases.
* This card can only be issued as part of employee rewards, channel incentives, consumer campaigns, and loyalty programs.
* This card cannot be issued for Facebook advertising payments, business-related payments, or any program that is not part of a reward/ incentive use case.
* This card is a one time use card and is non reloadable in nature.
* Transactions with the following merchants are prohibited:
Money transfer services business
* Firearm-related businesses
* Outbound telemarketing
* Tobacco businesses
* Marijuana-related businesses
* Money services from non-financial institutions (including cryptocurrency)
* Securities brokers/dealers
* Dating services
* Massage parlors
* Government-owned lotteries
* Government-licensed online casinos and online gambling
* Government-licensed horse/dog racing
* Betting, including lottery tickets, casino gaming chips, off-track betting, and wagers at race tracks\*\*
* This US Visa prepaid virtual card can be added to digital wallets like Apple Pay and Google Pay.
Terms & Conditions are subject to change as advised from time to time by the card issuers.
# Plum Product Roadmap - 2026
Source: https://help-plum.xoxoday.com/product-roadmap/plum-product-roadmap-2026
See what's coming next for Plum in the 2026 product roadmap, including upcoming features and platform improvements.
*Learn about the upcoming features and improvement*
Plum is designed to provide an intuitive, effective platform for managing rewards and incentives, helping you manage them with ease.
Our roadmap reflects our ongoing commitment to innovation and continuous improvement. It highlights our commitment to delivering innovative solutions that empower businesses to drive engagement and achieve measurable results.
## View the Roadmap
[Open](https://giftxoxo.atlassian.net/jira/discovery/share/views/dba185f5-db75-4095-8c32-3fd32f5f6caf)
Thank you for taking the time to explore our roadmap. We're committed to continuously enhancing Plum to deliver a straightforward and effective rewards and incentives platform.
## Request another feature
We add features to our roadmap based on the shared customer feedback. You can share your ideas at [cs@xoxoday.com](mailto:cs@xoxoday.com).
# June 2026
Source: https://help-plum.xoxoday.com/product-updates/june-2026
Read the Plum product update for June 2026, covering new features, improvements, and fixes shipped that month.
Over the past month, we introduced new reward categories that help users unlock greater savings, along with enhancements across authentication, merchandise checkout, and reporting visibility. These updates are designed to create a smoother user experience while giving teams greater control, flexibility, and oversight in managing reward programs.
## Here's what's new:
### 01 — Login to Rewards Hub with OTP
End users and admins can now log to the platform in using OTP as a primary authentication method, alongside the existing password flow.
This is especially useful for programs operating across shared devices, frontline teams, partner networks, or geographies where SMS-based authentication is the operational norm.
The result is a faster login experience with lower friction for users and fewer password reset dependencies for support teams.
### 02 — Two-Factor Authentication for Xoxo Points users
Xoxo Points accounts now provides two-factor authentication at login, adding an extra layer of protection beyond the password.
After entering their password, users verify a one-time password (OTP) sent to their email or mobile. This ensures that a leaked password alone is not enough to access an account, significantly reducing the risk of account takeover.
### 03 — Benefit Codes — One Code, A World of Savings
Plum Rewards Hub introduces Benefit Codes — send a single code to your users and they get access to discounted gift cards and curated offers from top brands. No account creation, no onboarding, no fulfillment overhead.
Recipients unlock discounted gift cards and exclusive offers of up to 75% off across 1,000+ partner brands — spanning shopping, dining, travel, wellness, and more. The best part: savings are powered by our brand partners, so you hand out high-value benefits at near-zero cost.
***Why it matters:***
Benefit Codes give organizations a low-cost, high-value benefit that drives repeat engagement. Recipients return regularly to redeem offers across categories they care about, building the stickiness and sustained program participation that directly improves loyalty and retention metrics.
***Where it works best:***
Banks rewarding cardholders, community managers thanking members, HR teams running employee perks, and channel managers keeping partners engaged, any program where you need to deliver high-value benefits quickly, at scale.
### 04 - Custom Reports in Rewards Hub
Rewards Hub now supports the creation of role-based reports that can be shared with specific users. Super admins can define precisely which data each team is able to view, ensuring that sensitive commercial information remains restricted to authorized personnel.
A Super Admin can enable Custom Reports under Platform Preferences, create a report by selecting which columns to include (order ID, product name, delivery status, cost, margin, and so on), and shares it with chosen users.
***Where it works best:***
This capability provides controlled, role-appropriate access to data. Finance teams may be granted visibility of cost and margin columns, while customer support teams are limited to order and delivery information.
### 05 — Quantity visibility added to Reports
Reports now include a dedicated QTY column for orders involving multiple quantities of the same product.
This gives finance and operations teams clearer visibility into order-level transactions and simplifies reconciliation workflows where value alone was previously not enough.
### 06 — Payment gateway charges now visible on invoices
Payment gateway charges are now shown as a separate line item on invoices instead of being absorbed within the total amount.
This gives finance teams clearer visibility into transaction costs and reduces the manual effort required during reporting.
### 07 — Self-Rewards links now replaces file attachments
Self-Rewards distribution has moved away from Excel and CSV file attachments to secure, access-controlled reward links.
Recipients are authenticated before they can view or redeem, while operations teams get better visibility into who accessed what and when.
This improves access control, reduces the risk of unintended sharing and fraud, and creates a cleaner redemption experience for users.
### 08 — Expanded gift card coverage across Saudi Arabia and Middle East
The Xoxoday catalogue now includes deeper gift card coverage across Saudi Arabia and nearby Middle East markets.
For clients running regional reward programs, this expands access to more locally relevant brands and improves redemption relevance for users in the geography.
### 09 — Saved delivery addresses for faster merchandise checkout
Logged-in users are now able to save and reuse delivery addresses during merchandise checkout, removing the need to enter their full address details for every physical order.
Users may save up to three addresses, each with a recognisable label such as "Home" or "Office", and select a saved address with a single click at checkout.
For users who redeem physical rewards frequently, this removes repetitive address entry and makes checkout significantly faster and smoother.
### 10 — Address Locking on Merchandise Orders
Organizations can now restrict merchandise deliveries to a set of approved addresses, ensuring that physical rewards can only be shipped to locations sanctioned by the company — such as office branches or warehouses — rather than to addresses entered freely by recipients at checkout.
When redeeming a reward, the recipient is presented with a dropdown of the administrator's pre-configured addresses and selects one. The control applies only to physical merchandise; digital rewards such as vouchers are unaffected.
### 11 — Delivery status to merchandise orders
Merchandise orders now also reflect actual fulfilment progress instead of being marked delivered instantly. Users can track accurate order statuses throughout the delivery journey, creating a more transparent and reliable redemption experience.
### 12 — More control over catalogue visibility in Rewards APIs
Rewards API clients can now exclude specific products from catalogue responses using filter IDs.
This gives teams more flexibility in shaping what end users see, without needing to maintain separate exclusion lists or implement additional filtering logic on their side.
## Upcoming features: Self-serve storefront white labelling
We are introducing a self-serve brand identity experience within Plum Admin. Clients will soon be able to configure logos, brand colours, CTA styling, favicons, and storefront titles with live preview support.
The new flow will also support preview-before-publish and one-click rollback for safer brand updates.
Questions or feedback? Reach out to your Customer Success Manager or write to us at [support@xoxoday.com](mailto:support@xoxoday.com)
# August 2026
Source: https://help-plum.xoxoday.com/product-updates/june-2026-2
The last months have brought a strong set of updates to Xoxoday Plum, with a focus on giving you greater control over your storefront, making rewards more secure, expanding redemption options, and strengthening compliance capabilities.
Here's what's new:
### 01 — Self Serve Storefront Customization - Logo, Favicon & Brand Color
Admins can upload brand logo and favicon directly from the Rewards Hub, with a live preview and reset option. They can also select a brand color using a color picker or HEX code and instantly apply it across buttons, links, and highlights throughout the storefront.
Previously, admins had to raise a request with our team to make these changes. None of these controls were self-serve, so even a small brand update could mean waiting on support or engineering. All three can now be configured directly within Plum Admin.
### \*\*02 — White-Labelled Reward Points Icon \*\*
The points balance in the storefront header can now be customized with your own **points icon**.
Previously, this was a fixed Xoxoday coin icon. With this update, the points balance can now be branded alongside your logo, favicon, and storefront colors, creating a more consistent, white-labelled experience.
**03 — Extended Japan Brand Catalogue**
The **Japan brand catalogue** is now extended with wider brand options, expanding reward coverage for customers and programs operating in the Japanese market.
Customers can now **discover, order, and fulfil Japan-based brand rewards end to end**, creating a more seamless experience for program administrators and recipients.
**04 — Shop, Save & Earn with Cashback**
A new **Cashback** category is now available in the marketplace, expanding the range of products and savings opportunities available to users. It also creates a new reason for users to return to the marketplace for everyday shopping, driving repeat engagement while giving admins a new category to configure, manage, and monetize.
Once credited, **Cashback Points** can be redeemed at checkout, used independently, or combined with payment gateway transactions and product discounts. Refunds are also supported throughout the journey.
\*\*05 — Airmiles Added to the Reward API Catalogue \*\*
**Airmiles categories is** now available through the Reward API catalogue, with support across products, brands, currencies, denominations, and countries.
This expands the range of reward options available through API integrations, giving customers and partners more flexibility to offer travel rewards across markets.
**06 — Expanded Perks with Paid Options**
A new **Paid Perks** category is now available alongside Free Perks in the Marketplace Offers section.
Users can browse and purchase perks and offers using accumulated points, codes, or the payment gateway. This gives users more choice beyond free offerings, while giving businesses another way to introduce premium perks and expand their rewards proposition.
The checkout journey follows the same experience as gift vouchers, keeping the experience familiar and seamless.
\*\*07 — Reward Campaign Management for API Customers \*\*
API-rewarding customers can now customize **reward catalogue options and email communication settings directly within Rewards Hub**, giving them greater control over campaign configuration, catalogue selection, and recipient communications. This makes it easier to manage and update reward campaigns without relying on manual support or engineering assistance.
These catalogue and email settings are now consolidated under **API Settings**, creating a cleaner, more focused admin experience for API-first accounts.
**08 —End-to-end Withholding Tax Handling**
The Xoxoday Marketplace now supports **end-to-end withholding tax handling** at the point of reward redemption.
For redemptions above a configurable annual threshold, the platform can display, calculate, and deduct the applicable taxation details based on the country and client program. Tax type, rate, threshold, and recipient identifier requirements can be configured to reflect local regulations.
The platform also supports tax reporting, helping retailers, dealers, and channel partners meet applicable tax obligations while giving enterprise clients greater control and visibility over compliance across their distribution networks.
**09 — Enhanced Darwinbox Integration for Multi-Currency and Multi-Region reward programs**
We've enhanced our Darwinbox integration to support multi-currency, multi-region reward programs, enabling HR teams to run global campaigns while delivering a localized experience to every employee.
The integration now captures each employee's regional currency from Darwinbox and dynamically maps it to the appropriate catalog and point value. US employees, for instance, receive rewards in USD, while employees in India are rewarded in INR, all through a single, unified setup.
**10 — Configurable Redemption Limits across categories**
Admins can now configure **daily, weekly, and monthly redemption limits** across all categories.
This is particularly useful for **high-value reward categories**, where program owners may want to set clear limits to manage budgets, control exposure, and prevent unusually high redemption activity.
\*\*11 — Brand Filter on Merchandise Stores \*\*
A new **Brands** filter is now available on merchandise stores.
Brands are automatically populated from the catalogue and displayed alphabetically, making it easier for users to discover products from their preferred brands, especially across larger catalogues with a wide variety of products.
\*\*12 — “Buy Now” Direct Checkout \*\*
The new **Buy Now** flow lets users purchase a single product directly without going through a shared cart.
Each order remains within a single category, creating a simpler and faster checkout experience for users while reducing the fulfilment complexity that can come with mixed-category orders.
Keeping up with the new features is the first step. The next, and more important step, is to see their impact on your reward strategy in action.
# March 2026
Source: https://help-plum.xoxoday.com/product-updates/march-2026
Read the Plum product update for March 2026, covering new features, improvements, and fixes shipped that month.
Over the past month, we've added a new redemption category, built stronger spending and redemption controls for admins, and improved reporting with deeper visibility into categories, discounts, and travel transactions. Each update is built around one goal: making the reward experience easier to manage for your team and more valuable for your users.
### 01 - Let channel partners and influencers cash out points directly to a bank account
Users can now redeem their reward points to cash, via direct bank transfer, prepaid card, e-wallet or UPI through a new cashout category on the storefront.
For programs where unredeemed points and catalog relevance have been a persistent concern, particularly in channel incentives, influencer rewards, survey panels or refund credits this gives users a tangible cash-out option.
Users get real value of the rewards regardless of geography or preference. Xoxoday catalogue now supports 20+ payout options globally.
| Type | Top options |
| :------------ | :---------------------------------------------------------------- |
| Prepaid cards | Visa · Mastercard · Swype · Rewarble · Nexon |
| Wallets | PayPal · Venmo · PhonePe · GoPay · GCash · Touch n Go · ShopeePay |
| Bank transfer | *ACH, DBT* |
| Others | UPI, Push to Cards (Master/Visa) |
### 02 — Category-level spending controls
Admins can now configure daily or monthly redemption limits on specific reward categories, starting with gift cards and merchandise. Category-level spending controls are enforced on the backend, without altering the catalog experience for the user.
Here is what this means for Xoxoday Storefront integration customers:
* **Predictable budget control:** Keeps spending in check at the category level and ensures your monthly reward budget doesn't get exceeded.
* **Balanced catalog experience:** Prevents one category from getting overused while others are ignored. Popular rewards don't run out too quickly, so the catalog stays complete and consistent for all users.
* **Misuse prevention:** Limits how much can be redeemed from a category, helping prevent misuse or fraud without needing manual checks.
* **Better ongoing engagement:** Monthly limits encourage users to come back and redeem over time, instead of using all their points at once.
### 03 — Send multiple denominations in one transaction
The "Send Individually" flow now supports multiple denominations of the same brand for a single recipient in one transaction.
For teams managing high-volume gifting, seasonal rewards, sales incentives, bulk disbursements, this removes the need to create separate transactions for different value variants. Fewer steps, fewer errors, and faster fulfilment.
### 04 — Dedicated travel report
A single report now ties every hotel and flight redemption to the relevant member, including booking reference, route or hotel name, points debited, cash amount, and transaction date. Filterable by category, member, status, and date range.
For reward programs where travel is a significant part of the redemption mix, this replaces referencing across multiple reports. One audit-ready view for tracking utilization, managing budgets, and reporting program ROI to stakeholders.
### 05 — Product category column in redemption reports
Redemption reports now include a Product Category column showing whether users redeemed gift cards, merchandise, experiences, or lounge access. This is available in your dashboard as well as CSV exports.
Clients who can see category-level redemption patterns are better positioned to understand popular categories that drive engagement, retire low-performing categories, and run promotions that drive the outcomes they want.
*Available for storefront integration customers.*
### 07 — Custom support contact across communications
Clients can now choose to display a dedicated support contact across the reward marketplace and outbound communications.
When users need assistance, they now see your team's contact details instead of a generic default. This ensures they reach the right team directly, rather than navigating through incorrect channels.
## Other Improvements
### 01 — Hotel confirmation numbers delivered automatically
User can now receive their hotel confirmation number via email as soon as it is available after booking. The platform monitors each confirmed booking and triggers the notification automatically.
### 02 — Passenger name validation on travel bookings
Real-time validation on passenger name fields now flags errors before the user confirms a booking, for both domestic and international travel.
Catching these errors before the user hits confirm means fewer failed bookings.
### 03 — Discount amount tracking in reports
Discount amounts now appear as a dedicated column in reports, displayed in your account's base currency.
*Available for Rewards API customers.*
## Coming soon
* **Multi-language storefront** — Support for English, Hindi, Marathi, Malayalam, and Tamil, bringing a localised experience across regions.
* **Milestone-based lounge access** — Cardholders will be able to earn a complimentary airport lounge visit upon reaching a defined spend threshold.
* **Offer code discounts** — Unique discount codes for distribution, letting users apply savings directly at checkout on the Plum storefront.
Questions or feedback? Reach out to your Customer Success Manager or write to us at [support@xoxoday.com](mailto:support@xoxoday.com)
# Product Updates - May 24
Source: https://help-plum.xoxoday.com/product-updates/product-updates-may-24
Browse a further set of Plum product updates from May 2024, covering additional features and enhancements shipped.
In recent weeks, we’ve introduced an array of exciting features designed to enhance the user experience. These include the launch of our Points API, which empowers personalized engagement and seamless integration, automated reminder emails to ensure the success of your campaigns, and the introduction of the Payment Report API, providing detailed transaction histories. But that’s not all – we're offering you an exclusive sneak peek at the features slated for release in the coming months.
# Launch of Points API
## Feature Overview
We are thrilled to announce the launch of our latest feature, the Points API, designed to elevate customer engagement strategies to new heights. This powerful API empowers customers to enable a points engine inside their mobile and web applications, creating dynamic point-based engagement programs tailored to their specific needs, including loyalty programs, employee engagement initiatives, channel partnerships, and influencer collaborations.
## Key Functionality
* Seamless Integration: The Points API facilitates the effortless sending of points and retrieval of point balances, allowing customers to seamlessly incorporate a points engine directly into their mobile and web applications.
* Versatile Applications: With the Points API, customers can leverage its functionality across a wide range of engagement initiatives, unlocking new opportunities to connect with their audience and drive participation.
* Personalized Engagement: By incorporating point-based rewards and incentives, customers can deliver personalized experiences that resonate with their audience, fostering stronger connections and lasting relationships.
Security:To ensure enhanced security, the Points API features robust oAuth 2.0 authentication and IP address whitelisting. These measures are implemented to safeguard customer data and protect against unauthorized access, providing peace of mind for both customers and end-users.\*\*Redemption Opportunities:\*\*Points issued to end-users can be redeemed on Xoxoday's Global marketplace, offering thousands of brands across 90+ countries. This extensive marketplace makes the offering very lucrative, providing users with a diverse range of options to redeem their points and enjoy rewards that suit their preferences.**Benefits:**
* Enhanced Engagement: The Points API enables customers to engage with their audience in a more streamlined and efficient manner, driving participation and fostering stronger connections.
* Flexibility and Efficiency: Customers can now create and manage robust engagement programs with ease, thanks to the flexible and efficient capabilities of the Points API.
* Improved Customer Satisfaction: By delivering value and rewards in a personalized and seamless manner, customers can enhance customer satisfaction and loyalty, ultimately driving business growth.
Availability:The Points API feature is now available to all customers, enabling them to unlock new possibilities in customer engagement. For more information on how to get started with the Points API, please refer to the documentation or contact our support team for assistance.We are excited to see how our customers will leverage the Points API to create innovative and impactful engagement programs, and we look forward to supporting them on their journey to success.
# Reminder Email For Clients
This feature aims to send periodically reminders to all end users who have active rewards waiting to be redeemed.
It empowers clients with automated reminder emails ensuring better success rates of campaigns being run by the clients and that the rewards are redeemed by the intended recipients.
# Introducing Payment Report API
Reward API customers can now fetch the entire transaction history of an account. Transaction history data includes information on fund additions, deductions and refunds. This will help integrate with reporting tools and assist finance team during the monthly reconciliation process.
# Standardizing Order Delivery Status Events in Webhooks
Currently, Reward API customers have the option to select "Delivered" or "Cancelled" events for an order delivery. With our new update, Order Delivery Status events will be standardized. These events will be enabled by default if the Webhook Status is enabled. We will send all events related to Order Delivery Status to the Callback URL listed.
# Order Delivery Status Events to Now Include Refund Information
We have enhanced the webhook functionality by including refund information in the payload. Along with "Delivered" and "Cancelled" status events, we'll now include a 'refundStatus': 'Refunded' key in the payload. This event will be posted only when a refund is successfully added to the admin wallet.
# Notifications if Webhook Status is disabled
Admins can now get notified if the Webhook status is auto disabled if the Callback URL is not functioning, which will allow them to check the URL status and take further actions to rectify the issues. Immediate actions taken to rectify the URL will help users to receive the Order delivery status change events that they are dependent on to take actions related to order delivery in their user journey.
# Upcoming Features
## IP whitelisting via Admin Dashboard
Super admins will be able to add / update and delete the IPs from the Admin Dashboard to access the APIs and avoid the manual process.
## Merchandise via Xoxo Links
Admins will be able directly send a selection of merchandise for the users to choose from that will be delivered to the end users address.
## New improved DIY flow
The upcoming new DIY flow simplifies the process of creating an account and getting started with sending rewards. There is no separate business activation as it has been integrated as a part of the send rewards flow.
## Enhanced Email Capabilities
Admins will be able to format, add links in the messages and add a personal footer sent to the end users with the new email editing capabilities. They will also be able to set templates as default such that they do not have to make changes every time they login.
## Minimum Balance Notifications
To ensure smooth redemption of rewards, we will have automated notifications to the admins ensuring there is sufficient balance in the wallet for redemption.
## Enhancements in Reward API Reports
Super admins can now know which super admin / admin has sent the rewards. This helps the users to have visibility in their operations and reconciliation process.
## Track Order in Marketplace
Users in the marketplace will now track their orders by providing necessary information. They can view order details, check the order status, and access other relevant information.
## Enabling WhatsApp for Verification Process
We are introducing WhatsApp as a secondary channel for delivering verification OTP messages to users. This addition aims to enhance delivery rates, expand coverage across various regions, and optimize costs.
# Release April 2020
Source: https://help-plum.xoxoday.com/product-updates/release-april-2020
Read the Plum product update for April 2020, covering new features, improvements, and fixes shipped that month.
*Plum Product Enhancements: April 2020*
In the April 2020 update to our Rewards and Redemption platform, Plum focused on adding some innovative ways to distribute its extensive catalog and improving some existing features. Let's have a look at what Plum's April 2020 update has to offer.
## Simplified URL-Based Rewarding
The latest update simplifies the user's reward redemption experience on Xoxoday Plum. With this new rewarding method, the user is provided with a URL, from where s/he can choose from a defined range of rewards and claim it in a single click.
This removes the cumbersome multi-step process of checkout, making the journey from selection to reward to redemption much simpler especially on a mobile device.
**URL-based rewarding: Video guide**
The journey is seamless, and the user does not have to access any external website or system to redeem rewards. This removes the inconvenience for users of filling out a lot of information as the unique URL will have the following pre-stored information:
* Value (Mandatory)
* Catalog (Mandatory) - This will guide which brands to show
* Name of User (Optional)
* User E-mail (Optional)
* User Phone (Optional)
Upon clicking the URL, the user will be shown the brands that s/he eligible to procure. The four-step process goes like this:
* The user clicks on the unique URL
* The listed brands are displayed
* Users can take their pick and click 'Redeem'
* The brand voucher is displayed, from where the user chooses the reward and receives the code!
## Plum-Pro Updates
Now procure an extensive catalog of vouchers from different brands from a choice of interfaces:
* Web Interface for small quantities/single brand vouchers
* The Plum-Pro API for bulk purchases
* The Plum-Pro catalog can be expanded with easy integrations rather than approaching different vendors for a catalog of multiple vouchers.
* The new APIs for Plum Pro are more robust, more secure, faster response and have a backward-compatible version as well.
These result in:
* Seamless handling of errors with correct HTTP codes
* Easy migration from old APIs to new
* Improved API design and a modern tech stack
* Formidable uptime along with a faster response time
* Easy customer query resolution
* Supports future enhancements and new features
* An enhanced reports API to keep track of all requests
## Admin Journey Revamp for Xoxo Codes & Points
The Xoxo Code and Points journey have been revamped in order to make it simpler for the admin. For the user, here-to-fore mandatory steps are also minimized and the journey is now just a single page send.
Campaigns have also been streamlined. In the new journey, all the information about campaigns and the email template is pre-selected and ready. The admin only has to select new field notes for reference. In addition, personalized messages can be sent to recipients.
## Enhancements for Administrators
With the new update, it is possible for the super-admin to edit the list of admins i.e. add and/or delete another super admin.
This is crucial in cases when the responsibilities of handling the rewards change hands and the Super-Admin can add or edit the list of super admins.
Also, now it's possible to add another admin and register the same person as a user simultaneously. No need to add the person to the overall user list first and then make him/her the admin from the existing list.
Now the organization's super-admin has the power to manage admins entirely.
## Guest Checkouts
Xoxoday Plum now supports checkouts by all site visitors. Anyone can explore thousands of offers, experiences, vouchers, deals, and more on the Xoxoday Store.
Previously, Xoxo Codes or Points were required to shop from the Xoxoday Store, typically by an employee recipient. Any site visitor can browse as a "guest" and buy, on registration of an email address, with a payment method of their choice.
## The 'How to Use' Section
The users can decide on the basis of redemption procedures. The unique steps to redeem for each brand are represented individually just under the voucher listing.
To address the user's frequently asked questions and increase redemptions we display redemption steps and options for each brand just under the voucher listing.
## Globally Expanded Catalog
Our extensive catalog of 2000+ vouchers just got even better. We have added three new catalog vendor-partners (via API integrations), expanding the Xoxoday catalog to further reaches of the globe.
That's all for the Plum Product Enhancements launched in April 2020. If you have any specific questions, feel free to [contact us](https://www.xoxoday.com/company/contact-us), or [book a demo](https://www.xoxoday.com/book-a-demo). Until then, [stay safe and stay home!](https://www.xoxoday.com/)
# Release April 2023
Source: https://help-plum.xoxoday.com/product-updates/release-april-2023
Read the Plum product update for April 2023, covering new features, improvements, and fixes shipped that month.
With this release, we have added a feature in Xoxo reward links: admins can now include up to 50 brands in a campaign, giving users access to a wider selection of brands for more customized and targeted campaigns. This opens up new opportunities to showcase products and services to potential customers.
## Customize your Catalog with Xoxo Points
We've added a new feature that allows admins to customise the rewards catalog when sending Xoxo points. With Catalog Customisation, customers can create a tailored catalog of options that suit each recipient's interests and needs, taking their reward-giving experience to the next level.
## Integration with Forsta
We're excited to announce our integration with Forsta (previously Decipher) - an enterprise-grade survey tool. This integration allows Forsta users to automate survey rewards and incentives directly within their environment, based on triggers like geography and denominations. With a quick and easy setup, customers can now reward their survey respondents seamlessly, saving time and effort.
## Email domain authentication
Our latest feature simplifies the process of sending reward emails via a client's domain. Previously, clients had to raise a CS ticket to authenticate their domain, but now Super Admins can do it themselves in just three easy steps. Users can customize their Sender email from settings, giving them greater control over the reward-giving experience.
## Showing the creator of Automation
Super Admins can now identify the creators of Automations, enabling them to better monitor and manage ownership and administration of specific Automations. This increased visibility can ensure effective implementation.
## Introducing variable denomination
Variable denomination options are now available in Storefront, Plum PRO Dashboard, and Xoxo links. Admins can enter their desired denomination for certain brands and products during checkout or campaign creation, providing greater flexibility.
## Download all link options in Xoxo Links (Generate to Self)
All links across all batches can be downloaded at a single click as against downloading each batch separately from the download option under reports.
## New Sample CSV files
Previously, the sample file format in Xoxo points, codes and links were having test email addresses and was not matching the persona of HR and the rewarding use-cases. This is revamped completely in the current version which comes along with how to use the sheet instructions.
## New DIY Flow and home page with Zero States for all pages
A new flow has been made live that prominently highlights to the user to submit business verification and also allows them to navigate across all pages and features explicitly mentioning the features that require verification.
## Timestamp in Reports is now in UTC format
In Admin Reports, users will now be able to see the Order Sent & Delivered Date and time in UTC format. This will help them get data in UTC format than in IST format which was followed earlier.
## Automated the amazon global brand KYB
Now Admins can apply for a global amazon brand voucher from plum admin. The xoxoday team will take care of the approval and update with the status. This helps admins fast track the brand KYC approval process and reward quicker.
# Release April 2024
Source: https://help-plum.xoxoday.com/product-updates/release-april-2024
Read the Plum product update for April 2024, covering new features, improvements, and fixes shipped that month.
We have a ton of collective knowledge to share with you! In the past few weeks, we've added new features to our Plum platform, including new invoice download functionality, expanded japan catalog and many other improvements for the admins. But that's not all we have revealed the new features expected in the upcoming months.
## New Invoice Download Functionality
The admin dashboard now includes a convenient invoice download option. Users can directly access and download their invoices, streamlining the process and improving accessibility to essential documentation.
## Optimized Mobile Number Validation
Improvements have been made to the mobile number validation process during reward issuance. The system will now promptly notify users for corrections when entering recipient details, enabling immediate rectification. Additionally, the "Are you Sure?" prompt has been removed, redirecting administrators directly to the mobile number edit page or back button for a more efficient workflow.
## Expanded Japan Catalog
To better serve our Japanese customers, we have significantly expanded our product catalog by introducing a wider range of premium brands and offerings tailored to their preferences.
## Enhanced User Experience in Catalog Browsing
The catalog page has undergone a redesign to deliver an intuitive and user-friendly experience. Customers can now easily locate product discounts and compare pricing plans across various options, facilitating informed decision-making.
## Upcoming Features
### IP Whitelisting Made Convenient
Administrators will now have the ability to whitelist IP addresses directly from the Admin Dashboard. This feature will enable seamless access to APIs without the need for manual whitelisting processes, streamlining your workflow and enhancing operational efficiency.
### Account Setup Simplified
We understand the importance of a smooth account setup process. To facilitate this, we are streamlining the account verification flow by providing pre-filled business information details. This enhancement will save you valuable time by eliminating the need to manually enter tax numbers and other details, allowing you to complete your account setup effortlessly.
### Personalized Reward Communications
In our continuous effort to provide personalized experiences, we are introducing new customization options for reward email templates. You will now have the ability to add custom messages in the email body and include a footer at the end of the email. This feature will enable you to tailor reward communications to your specific needs, enhancing brand recognition and improving recipient engagement.
# Release August 2020
Source: https://help-plum.xoxoday.com/product-updates/release-august-2020
Read the Plum product update for August 2020, covering new features, improvements, and fixes shipped that month.
*Release Aug' 20: Digital Rewards Management Easier than Ever*
The Xoxoday Store comes up with a handful of new features in August. Along with handy admin capabilities, ease of redemption for users, digital rewards management, and global guest checkout, here's how the new features released in August look like at Xoxoday Plum.
## Manage different organizational wallets hierarchically with hierarchy capability in reward administration
Even though the multi-admin capability helped different admins of an organization manage their separate wallets with full functionalities, it was tough to track and control the organization level rewarding functions and reward administration. With the new admin hierarchy feature, a super-admin can manage separate wallets hierarchically under a common wallet - across all distribution methods.
Super admin(s) can now set thresholds for admins while they distribute points as well as send out brand vouchers. The common wallet can be recharged and admin-wise spending patterns can be tracked by the super admin. This provides a holistic view of rewarding patterns throughout the organization and helps in reward administration.
**NOTE: To know more about how to enable this feature on your existing Xoxoday Plum platform, please talk to your Account Manager or wave to us at [cs@xoxoday.com](mailto:cs@xoxoday.com). We'll be happy to run you through.**
## Multi-admins of non-hierarchical accounts can now transfer funds amongst each other
When a reward program admin leaves an organization, **they previously could not transfer their balance points to another admin**, disrupting the balance availability. With this release, program admins who are being relieved from the company can readily transfer the amount in their wallet to another admins' account. **An admin can either transfer their share of points to existing admins before leaving their roles, or they can add another admin and transfer the points** - according to what works best for them. This capability makes reward management especially the reward points management seamless for the organization. Xoxoday Plum has made employee reward management an easy task. That's the reason why it is considered one of the best employee reward management software worldwide.
[Book a demo now to talk to our experts>>](https://www.xoxoday.com/book-a-demo)
## Anyone can shop at Xoxoday Plum! the Global Guest Checkout desk is live
The Xoxoday Store is home to thousands of employee perks and benefits, experiences, vouchers, and surprises. With the new guest checkout, anyone can now check into the Xoxoday Store and shop through a wide catalog of options. In other words, **a user who does not have Xoxo codes, Xoxo points, or even a Plum user account can go ahead and purchase gift cards and experiences** that they have laid their eyes on.
Customers can browse through the Xoxoday Store, add items to cart and check out as a guest via email. With payment options safe and secure, the users can complete transactions seamlessly. In essence, customers no longer need a Xoxo Code or need to have xoxo points to purchase an item of their choice from Plum.
## First-time users, know the Store when you visit with the Redemption Walkthrough
Learn how to redeem gift cards, points, and Xoxocodes on your first visit with a short redemption walkthrough. There's a step-by-step process to understand how to redeem via gift card codes and via Xoxo points. To know more about Xoxocodes and XoxoPoints redemption, check out the given link.
In addition to that, the customers can also check the validity and balance of their Xoxo Code right from the home screen along with the link to 'How to Redeem' that will be always accessible from the Plum site header.
## Admins, keep track of the rewarding context with the Notes feature
There are countless instances of rewarding at Xoxoday Plum and keeping track of each is not possible without a brief detail from the rewarder. In the reports section, the rewarder can give a description of why they are rewarded as it helps get a clear picture of the digital rewarding activity. With that, the admins can adjudicate on the context of reward(s) and their utility.
[Start free trial today to avail the benefits of Xoxoday Plum>>](https://stores.xoxoday.com/admin/signup)
## Users can now receive Xoxocodes and Xoxopoints via SMS
To help reward program admins deliver digital rewards to even remote users, Plum has now enabled Xoxocode, Xoxopoint, and Gift voucher delivery via SMS. The end users now receive notifications via SMS when the points, codes, and gift voucher credentials are sent. This SMS includes the redemption codes and a URL to Plum stores or the respective brand catalog where the digital rewards codes and vouchers can be redeemed. This makes digital rewards program management easy.
## Users can clear all queries with FAQ Help-bot
With the new FAQ Prime assistant, users and shoppers can get all their grievances answered with the given FAQ guide. In case the problem is left unresolved, the user can switch to live chat or raise a ticket.
This solves all the user problems then and there meanwhile if the solution to the issue can't be found, it can be taken up in real-time.
## The Xoxoday Store is Optimized and Quicker than ever
Considerable improvements were made in the engine room that improved the page and image loading speed to make the Xoxoday Plum experience smoother for the end-users.
## New Additions to the Xoxoday Stores in employee perks and benefits
Last but not least we have the addition of various [employee perks and benefits](https://www.forbes.com/pictures/56b3b990e4b062f6b5994e8b/the-top-10-employee-perks/?sh=280b152c64c3).
[Explore all Perks>>](https://stores.xoxoday.com/us-marketplace-demo/vouchers?category_id=1271)
[Explore all Gift Cards Option>>](https://stores.xoxoday.com/us-marketplace-demo/vouchers?category_id=1271)
That's all for this month's new features at Xoxoday Plum. Missed the last update in features? Check it out here.
# Release August 2023
Source: https://help-plum.xoxoday.com/product-updates/release-august-2023
Read the Plum product update for August 2023, covering new features, improvements, and fixes shipped that month.
We have a ton of collective knowledge to share with you! In the past few weeks, we've added new features to our Plum platform, including inbuilt templates, integrations, recommended products and many other improvements for the admins. But that's not all we have revealed the new features expected in the upcoming months.
## A new tab for email templates
A new tab has been introduced with pre-defined templates for the admin user to pick from while sending rewards. This eases the process of sending rewards as the admin need not create email template modifications from scratch.
## 12 months historical report
Admins will now be able to see records of the last months 12 months instead of 6 months. Thus all the rewards sent that have not yet expired will be available for the users.
## Punchout Integration
Xoxoday is now fully punchout integrable with all major Procurement ERPs, allowing for a seamless rewards procurement experience like never before. Whether you use SAP Ariba, Coupa, Oracle Procurement Cloud, or any other procurement system, Xoxoday can easily incorporate it into your existing workflow.
## Option for a minimum threshold for redemption
The admins, while sending Xoxo points, will be able to set a minimum threshold for redemption such that the end users would need to accumulate points until they have more than the threshold value set in order to continue with redemption.
## Reference ids on generate to self
On xoxo link, generate to self, admins will now be able to generate links along with the reference id making it easier to identify and track a specific link across different reports.
## Stores/Marketplace Checkout Validations
For stores checkout there are validations being introduced where based on the user reward information and the payment method they would use like: Xoxo Reward Code user would be asked for additional OTP verification.
## Improvement in the Experience Catalog
Showcase only product enriched sub-categories in experience for respective countries on storefront.
## Introducing Partial delivery information in Xoxo Rewards API Reports
With partial delivery information Admins can now have information
* Delivered Quantity: This allows the users to know the number of vouchers that are delivered to the recipient.
* Pending Quantity: This allows users to know the pending quantity to be fulfilled.
* Canceled Quantity: This allows users to know the quantity that is Canceled and refund has been initiated.
**In Plum Status Page:** Now customers can now subscribe to the Status page and get notified at instances when there is a unplanned / planned downtime with Xoxoday system which involves Rewards APIs, Storefront and Admin Dashboard.
## Upcoming Features
### Reporting & Analytics For Admin
Get powerful insights and reports. Admins will soon be able to analyze their order patterns on Plum Admin dashboard.
### Auto debit Functionality
No more hassles of loading your wallet. The upcoming auto debit functionality will auto recharge your wallet when it goes down below a specified threshold value.
### Email & SMS Customisation in Xoxo Rewards API
This feature will help you send impactful campaigns and save development efforts. It will help you create and customize email templates in a jiffy.
That's all for this month's new features at Xoxoday Plum. Missed the last update in features? [Check it out here](/product-updates/release-june-2023).
# Release August 2025
Source: https://help-plum.xoxoday.com/product-updates/release-august-2025
Read the Plum product update for August 2025, covering new features, improvements, and fixes shipped that month.
*Learn all about product updates in Xoxoday Plum*
## Latest from our world of Rewarding
Here's a quick look at what's new in Xoxoday Plum this month. We've made discounts on gift cards easier to spot, introduced hotel bookings to the storefront, strengthened security with Reward code restrictions. Plus, we're working on exciting new features like cashout options, cashback products, and gamification to make rewarding more engaging and valuable.
## Here's what's new:
### 1. Gift Card Discounts on Homepage
We've made it easier for customers to spot deals immediately.
Discounts on gift cards are now displayed directly on the homepage, so users can find savings without navigating through multiple categories or checkout pages. This simple enhancement not only improves the user experience but also boosts conversions by highlighting deals at the first touchpoint.
### 2. Hotel Bookings on Storefront
Xoxoday Plum now offers a seamless travel booking experience with the new Hotels category.
Customers can search, compare, and book hotels directly on the storefront, alongside their usual rewards shopping. By combining travel and rewards in one place, this feature adds convenience for users and expands the value of the platform, making it a more comprehensive marketplace.
### 3. Reward Code Locked to One Verified User
To enhance security and prevent fraudulent redemptions, each Reward code is now locked to a single verified user after its first use.
This change ensures codes cannot be shared or reused, providing a trustworthy and seamless experience for users while giving businesses confidence that codes are used exactly as intended. By protecting both customers and the platform, this update strengthens the integrity of reward redemptions.
## Upcoming features:
### Cashout Option
Users will be able to convert their points into cash payouts giving them more freedom on how they use their rewards.
### Cashback Products
We're adding Cashback Products to the Xoxoday Marketplace! Shop from your favourite brand websites, enjoy exclusive deals, and earn cashback that can be redeemed on your next purchase, making every transaction more rewarding.
### Gamification
Admins will soon be able to launch interactive games like Spin the Wheel and Scratch & Win, seamlessly embedded into the marketplace to drive higher engagement in campaigns, loyalty programs, and giveaways.
# Release December 2020
Source: https://help-plum.xoxoday.com/product-updates/release-december-2020
Read the Plum product update for December 2020, covering new features, improvements, and fixes shipped that month.
The year concluded with a new array of updates on the Xoxoday Plum platform. As we gear up to become better in the coming year, here is the list of things that rolled out in December. Ranging from changes in the Xoxo Link-based redemption to major changes in campaign management for admins, let’s check them all out.
## Now create and distribute Xoxo Links to individual recipients directly from the Admin Portal
Sending out rewards as Xoxo Links to multiple users earlier came with a process of generating the links in batches, which you had to manually distribute from the given batch. These laborious efforts have now been reduced. With the new release, distribute Xoxo Links directly to your recipients via email or SMS from the Admin Portal along with a personal message.
This change reduces the manual work involved in rewards distribution and keeps the element of personal touch intact with a message to go with every reward you send via Xoxo Link.
## New customer? Now avail a seamless onboarding experience and get a grip of everything in Plum.
It's never too late to begin to reward and recognize the Xoxo-way, and now it's simpler than ever. New Xoxoday Plum customers can now sign up through the given instructions which would be thoroughly walked through in a welcome email. Follow all the given instructions and get started with rewarding without any manual intervention. Need our help? Get all the necessary resources and if there's anything needed in particular, simply [contact Xoxoday](/product-updates/release-december-2020) and address your query.
## Users can now get redirected to campaigns linked to their Xoxo Code(s) by checking the details
For every campaign run and batches of Xoxo Codes sent, there's a particular URL attached on which the campaign can be accessed. To fix the problem of users not being able to find the correct URL linked to the campaign, now the users can check their Xoxo Code details and get redirected to the specific campaign attached to their Xoxo Codes.
This would make the user journey simpler as they'll just need to match up to their codes and visit the URL, reducing the manual intervention from Xoxoday's end to search for the campaign URL, and reducing complaints in the admin's kitty for the very problem.
## Admins can now check the discounts and surcharges for brands while setting up campaigns.
Xoxoday Plum comes with an added fiscal advantage wherein the organization saves a sliver of cost while distributing gift vouchers through Plum. To analyze the benefits, admins can now check and identify any discounts and surcharges on brands and their vouchers. With this level of transparency, your organization would get a tangible idea of the Xoxoday Plum advantage, while the campaigns can be set up accordingly.
## Advanced protection against risk and malpractice with new Alert Rules
Xoxoday Plum is a secure haven for clients, users, and customers alike and we keep making it safer and airtight with every release. This time out, multiple alert rules have been introduced to identify the minutest risks of potential risk, suspicious activity, or any digital malpractices. From analyzing questionable user behavior to other digital breaches, the new alert rule engines will keep a stern eye out for anything out of the way.
## Now buy Prepaid Cards seamlessly with simplified procedures and OTP registration.
On buying prepaid MasterCard/Visa from Xoxoday Plum, seamlessly process your purchase and get your OTP delivered on your contact unlike before, wherein the OTP had to be delivered from Xoxoday's end. This results in a smooth journey from adding to the cart to procuring the card.
That's all for this feature release in Xoxoday Plum. Have a question? [Talk to us](https://www.xoxoday.com/book-a-demo)
# Release December 2021
Source: https://help-plum.xoxoday.com/product-updates/release-december-2021
Read the Plum product update for December 2021, covering new features, improvements, and fixes shipped that month.
This December, we have undergone a few major changes on both the plum admin side and the integration side.
We have come up with a cleaner UI for email customisation in the new update. This includes UI for editing, banner selection, etc. Admins will now be able to do bulk cancellation and resend mail confirmation in xoxo links, going forward we have standardized the email which will be used for all the communication ([notifications@xoxoday.com](mailto:notifications@xoxoday.com)).
On the integration side, we have come up with improved campaign automation, admins will now be guided throughout the process with step-by-step instructions, suggestions, and informational pop-ups flow. Admins will now be able to reactivate any existing automation created in the admin portal. Now the admin can also reactivate/deactivate any automation based on the requirement.
Here are more details about the latest update:
## Rewarding Email Improvements
In this release, we have enhanced the email templates sent with Xoxo Code and links either from the platform or integration. This includes cleaner UI for editing and selecting banner and logo, customizing the message at a campaign level, and previewing the email on both desktop and mobile. Admins can send a personalized message now, which will overwrite the default message. The email elements can now be customized while editing the campaign with this new edition. The reward communication has also been made crisp.
## Bulk Selection and cancellation in Xoxo Links
With this release, admins can select records in bulk, resend the reward details or cancel multiple rewards at a single click in Xoxo Links. Rewards details can be sent from the platform or triggered through integration and accessible under Reports > Xoxo Links. The system would also guide them through what actions are possible as shown below.
## Email domain for notifications
We have noticed non-synchronous emails, which led to confusion among admins and end-users. Events such as Low balance, product updates, welcome/setup emails got notified using [accounts@xoxoengage.com](mailto:accounts@xoxoengage.com), [notifications@xoxoday.com](mailto:notifications@xoxoday.com), [hr@xoxoday.com](mailto:hr@xoxoday.com) emails, respectively. With this release, all emails sent would be sent from [notifications@xoxoday.com](mailto:notifications@xoxoday.com) to help you get alerted systematically.
## Threshold Feature and used amount in common wallet type companies
We have introduced the ability for super admins to reset the threshold counter. They can allow admins to reward up to the threshold limit and then reset it periodically without updating the threshold every time. The super admins will also increase or decrease the threshold limit without affecting the **"used amount."**
The admins will always be able to view the threshold limit and how much they have reached in all rewarding screens, making it easier for them to plan out their rewarding.
## Newly Improved Integration Automation Setup flow
With the latest update, admins will now be guided throughout the process with step-by-step instructions, suggestions, and informational pop-ups for all the integrations such as SurveyMonkey, Hubspot, and others. There has been an improvement in the interface and the user journey experience.
## Ability to disconnect/reconnect integrations
With the current release, the admins will now be able to disconnect/reconnect any integration based on the requirement. This will assist them in connecting another account, removing an account, exiting an existing integration, etc.
## Ability to deactivate/activate integration automations
Earlier, there was no ability to reactivate any existing automation created in the admin portal. Now the admin can reactivate/deactivate any automation based on the requirement. This helps admins to use the old campaign for a new survey instead of creating a new one from start.
# Release December 2022
Source: https://help-plum.xoxoday.com/product-updates/release-december-2022
Read the Plum product update for December 2022, covering new features, improvements, and fixes shipped that month.
We're back again to share some significant feature upgrades that have happened on the 'Plum Admin' side over the weeks, and we can't wait to share about this newly revamped avatar.
The revamp project is a massive step in making our platform stand at par with the other recognised global SaaS players. This is no less than a milestone in having a common design language for all products of Xoxoday.
## Highlights of the newly upgraded 'Plum Admin':
* Enhanced UI: The dashboard is cleaner, easier, and sleeker, with an improved look and more intuitive interface.
* Easy navigation: The navigation is now standardised and much more organized to help you quickly find and accomplish tasks from the dashboard.
* Simplified UX: Sending rewards (across all modes of distribution: Code, Links, and Points) to your recipients is as easy as a single click.
* Better reward tracking: View the total number of rewards sent, redeemed, and cancelled (monthly/yearly) from the dashboard's homepage. Click on **'View reports'** to have a bird's-eye view of all the transactions done, along with other data insights.
## Payments
Our platform now integrates with 'Payoneer,' a payment processor to manage international currencies (except EURO and GBP) and help businesses to do a wallet recharge (in any currency) in real-time via credit or debit cards (VISA/MasterCard).
Clients can do a wallet recharge of up to USD 1000 per transaction.
# Release December 2024
Source: https://help-plum.xoxoday.com/product-updates/release-december-2024
Read the Plum product update for December 2024, covering new features, improvements, and fixes shipped that month.
*Latest from our world of Rewarding*
We've recently rolled out several exciting features to enhance the user experience. These include a new Perks category on the marketplace making it easier for users to access perks-based products, and an improved DIY sign-up process, streamlining registration for better efficiency and user engagement. These updates and many others are designed to create a seamless, secure, and efficient experience for admins and users.
## Here's what's new:
### 1. New "Perks" Category in Storefront
A new "Perks" category has been introduced to enhance the user experience on Plum's storefront. This exciting addition offers a curated selection of deals and discounts from popular brands, making it easier than ever to explore exclusive perks. This update simplifies navigation, giving users quick and easy access to a wide range of perks-based products.
**Key Features:**
* Dedicated "Perks" Category: Products related to perks are now grouped together for easier discovery.
* Improved Navigation: Users can quickly find and explore perks-based products with a more streamlined interface.
### 2. Improved DIY Sign-Up Flow
We've enhanced the DIY sign-up flow to improve user engagement and usability.
**Key Improvements:**
* Better User Experience: Optimized flow for smoother sign-up.
* Additional Validations: More checks are added to ensure accurate data.
* Optimized Submission: Streamlined form submission for quicker processing.
These changes aim to make the sign-up process faster and more efficient.
### 3. Introducing Perks as a New Category in Rewards API
Customers can now access the list of Perks and expand their redemption options through the existing Rewards API. To enable this feature for your account, please contact your account manager.
### 4. Email and SMS Activity in Rewards API Reports
We've added Email and SMS activity tracking to the Rewards API Reports, enabling you to monitor and analyze the communication activities related to rewards distribution.
Keeping up with the new features is the first step. Next, and more important step, is to see their impact on your reward strategy in action.
## Upcoming features:
### Flight Booking on the Marketplace
Soon, you will be able to book flights directly through the marketplace. This will allow users to find and book flights easily alongside other rewards, streamlining the travel booking process.
### Gamification on the Marketplace
We're introducing exciting gamification features like Spin the Wheel and Scratch and Win to the marketplace. Admins can customize the rewards and prizes, allowing users to redeem their points for a chance to win. This feature adds a fun, interactive layer to the reward process, making it more engaging and enjoyable for users to earn and claim rewards.
### Airmiles Point Exchange on the Marketplace
Airmiles Point Exchange is coming to the marketplace, allowing you to redeem reward points or codes for miles with major airlines worldwide. This feature will support all leading airlines and miles programs, turning rewards into travel opportunities.
### Benefits & Offer Marketplace
A new Benefit & Offer Marketplace is on its way, designed to enhance reward programs focused on user engagement. Featuring popular deals, discounted products, and gift cards, it will support purchases with or without points redemption. It is ideal for clients in FMCG, consumer, and employee domains to drive more effective reward engagement.
## Want to request a feature on Xoxoday?
Get in touch with our customer success team at [cs@giift.com](mailto:cs@giift.com)
# Release - December 2025
Source: https://help-plum.xoxoday.com/product-updates/release-december-2025
Read the Plum product update for December 2025, covering new features, improvements, and fixes shipped that month.
*Get updates on Xoxoday Plum.*
**Latest from our world of Rewarding!**
We've rolled out new updates to make your experience smoother and more versatile. This month, we are introducing enhanced administrative controls for our enterprise partners and high-capacity distribution features to scale your engagement efforts effortlessly.
## Here's what's new:
### 1. Flexible Billing Address Management
Managing multiple legal entities just got easier. You can now choose, add, edit, or remove billing addresses directly while recharging your Xoxoday Plum account. The selected address is automatically reflected in both proforma and final invoice PDFs, giving your finance team full control and eliminating manual follow-ups.
### 2. API Rate Limits for Improved Reliability
To ensure platform stability and consistent performance for all integrations, we've introduced per-client rate limits across key APIs. This prevents accidental traffic spikes and keeps response times predictable, ensuring your standard business workflows remain uninterrupted.
### 3. Issue up to 999 Gift Cards in One Go
Speed up your large-scale distributions! You can now issue up to 999 gift cards in a single action directly from the Plum admin dashboard. This is perfect for high-volume seasonal incentives and one-time payouts—no more breaking bulk sends into multiple batches.
### 4. Enhanced Rewards Points APIs
We've upgraded our Rewards Points APIs for deeper transparency.
* **Reversals:** Cancel issued points directly via API using a unique transaction ID.
* **Detail:** Responses now provide recipient-level status and accurate success/failure indicators.
* **Real-time:** Track partial outcomes and troubleshoot issues as they happen.
## Upcoming features
### Payment Gateway Support for Point-Priced Storefronts
Users will soon be able to complete purchases using an online payment gateway if their available points are insufficient, ensuring a smooth checkout experience.
### Category-Level Redemption Limits
Gain finer control over your budget by setting redemption limits on specific marketplace categories, aligning user behavior with your program goals.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Release Feb 2025
Source: https://help-plum.xoxoday.com/product-updates/release-feb-2025
Read the Plum product update for February 2025, covering new features, improvements, and fixes shipped that month.
*Latest from our world of Rewarding*
We've rolled out exciting new features to enhance your Plum experience, starting with flight booking on the Plum Storefront—making travel more rewarding than ever! Plus, enjoy a smoother currency conversion UI, accurate admin tracking for refunds, new payment notifications for Super Admins, and expanded gift voucher options in Argentina. These updates are designed to make your experience more seamless, secure, and efficient.
## Here's what's new:
### 1. Flight Booking Functionality
We're excited to announce that flight booking functionality is now live on the Plum Storefront!
With this update, users can seamlessly book flights using their reward points and codes making travel more accessible and rewarding. This enhancement expands the redemption options, offering greater flexibility and convenience for users looking to maximize their rewards.
**What's New?**
* Seamless Flight Booking – Browse and book flights effortlessly.
* Flexible Redemption – Use reward points to book flights with ease.
* Enhanced User Experience – Smooth, intuitive interface for a hassle-free booking process.
Start exploring and book your next journey today!
### 2. Dynamic Currency Conversion for Points
We've introduced an enhancement to improve currency conversion when users transfer points across regions.
* Hover Functionality: Users can now hover over their points balance to see the equivalent value in local currency.
* Real-Time Conversion: Points value updates automatically when switching regions, reflecting the latest exchange rates.
* Seamless Checkout: Users can use points based on their local currency without needing to understand the full currency conversion, streamlining the purchasing process.
**Benefit:** This ensures smoother, region-specific point redemption without confusion.
### 3. Personalize Reward Emails with Recipient Names
We've made it easier to personalize reward emails! A new "Name" field has been added when sending rewards to individual recipients or through bulk uploads in Gift Card section. This allows you to include the recipient's name in the email. The email will greet the recipient with "Hi" if no name is provided.
### 4. Payment & Wallet Notification for Super Admins
To improve visibility and ensure smooth operations, we've enhanced the payment and wallet notification system:
* Fund Addition Notification: All super admins will receive an email notification whenever funds are successfully added.
* Low Balance Notification: If the wallet balance drops below the threshold set by a super admin, an email notification will be sent to all super admins, including the account name.
This ensures that all super admins are notified promptly about fund additions and low balances, streamlining the fund allocation process.
### 5. Order Fulfilment Notifications
Previously, users could not know when their pending orders were ready for fulfilment.
**What's New?**
* Users will now receive an email notification as soon as their order is successfully fulfilled and ready for delivery.
* This update applies specifically to Storefront orders, ensuring timely communication.
**Benefit:** Better transparency, reduced uncertainty, and fewer support requests.
### 6. Expanded Reward Options in Argentina & India
We're enhancing the reward experience by introducing new redemption options in two regions:
**New Gift Card Editions in Argentina:** Users in Argentina can now access a wider selection of gift cards, making it easier to redeem rewards that suit their preferences.
**New Merchandise Category for India:** Merchandise catalogue has expanded for India stores, expanding product choices and giving users more variety when selecting rewards.
**Benefit:** These updates provide more flexibility, better accessibility, and an improved shopping experience for users in both regions.
### 7. Tag Filter for Order History API
We've added support for Tag Filtering in the orderHistory API, making it easier to manage and retrieve order data.
**What's New?**
Users can now filter and view orders based on specific tags.
This improves searchability and helps organize order history more efficiently.
**Benefit:** Saves time by streamlining order tracking and data management.
## Upcoming Features
* **Charity Category on Marketplace:** The Marketplace will add a new category for charitable donations, allowing users to support causes they care about.
* **Customize Catalog in Campaigns in Rewards API:** The Rewards API will allow you to customize the reward catalog in campaigns, offering a more personalized and tailored selection for your users.
* **Email Triggers for Merchandise Status & Tracking:** Automated emails will notify you about the status and tracking of your merchandise, keeping you updated at every step.
* **WhatsApp for Reward Messages:** Soon, you be able to send rewards via WhatsApp, providing faster and more convenient communication.
# February 2026
Source: https://help-plum.xoxoday.com/product-updates/release-feb-2026
Read the Plum product update for February 2026, covering new features, improvements, and fixes shipped that month.
*Learn about the latest updates on Xoxoday Plum*
Hi,
We've rolled out new updates to make your experience smoother and more versatile. This month, we are focusing on reducing manual errors in bulk uploads and giving you significantly more control over your reward communications and API integrations.
## Here's what's new:
### 1. Fully Customizable Email Greetings & Fields
Reward emails are the final touchpoint with your recipients, but generic templates can fail to capture your unique brand voice or professional tone.
**We Upgraded:** The email configuration settings to allow full control over greetings (switch "Hi" to "Hello," "Dear," or "Hey") and made recipient names optional for all sends.
**How it helps you:** Your reward emails will feel natural and professional, ensuring your communications are perfectly aligned with your brand voice.
### 2. Clear Denomination Visibility for Variable Gift Cards in Bulk Reward Uploads
Bulk reward uploads require high precision to ensure variable-value products are processed correctly without manual verification.
**We Upgraded:** The CSV bulk upload template to now explicitly indicate the Denomination Type and display the allowable range for variable products directly within the file.
**How it helps you:** This provides clearer instructions for your team, ensuring a much smoother, error-free upload experience and reducing manual corrections.
### 3. Expanded Denomination Range for Campaign Creation
As incentive programs scale, we recognized the need for greater flexibility when creating high-value campaigns and enterprise-level payouts.
**We Upgraded:** The platform's core limits by removing these caps and raising the maximum allowable limit to 50,000,000.
**How it helps you:** You now have total flexibility to handle high-value payouts and scale your incentive programs exactly as your business requires.
### 4. View "Discount Amount" in Gift Card Reports
To provide greater financial transparency for our Gift Card API customers, we've made it easier to instantly distinguish between discount values and final charged amounts.
**We Upgraded:** The reporting dashboard by adding a dedicated Discount Amount column, reflecting exactly how much was discounted in your account's base currency.
**How it helps you:** This makes accounting faster and more transparent by providing a clear, line-item view of your savings versus your gross expenditure. This enhancement is for our Gift Card API customers.
### 5. Passport Expiry Validation for International Travel
To ensure a seamless international travel experience, we've introduced proactive checks to help travelers stay compliant with global entry requirements.
**We Upgraded:** The system with an automatic validity check that ensures a passenger's passport is valid for at least 6 months beyond the travel date.
**How it helps you:** This prevents avoidable booking issues, ensuring a compliant and stress-free journey for your international travelers.
### 6. Consolidated Redemption Report for Banking Clients
Banking partners frequently had to manually merge data from Loyalty Programs and the Plum Marketplace, which was time-consuming and error-prone.
**We Upgraded:** Our reporting engine to merge these data streams into a single, unified report for all reward categories (excluding Flights and Hotels).
**How it helps you:** It simplifies reconciliation by allowing you to track Member IDs, points, and cash usage in one central place without manual file merging.
### 7. Email Proforma Invoices to Colleagues
Super Admins often face administrative delays when manually downloading and forwarding proforma invoices to finance teams to initiate fund transfers.
**We Upgraded:** The "Add Funds" page to allow Super Admins to email invoices directly to up to 10 colleagues within their organization's domain.
**How it helps you:** This streamlines internal finance coordination and significantly speeds up the payment and funding process.
### 8. Simplified Quantity Selection on Storefront
For users managing bulk or multi-voucher orders, we recognized that the traditional checkout flow could be further optimized to match the speed of high-volume purchasing.
**We enhanced:** The storefront UI with a clear quantity counter directly on the product page, allowing adjustments before adding to the cart.
**How it helps you:** This aligns with modern e-commerce standards, allowing users to buy in bulk with fewer clicks and a much faster checkout experience.
### 9. Powerful API Enhancements
We've upgraded our developer experience for better reliability and control:
* **Reward Points Control:** You can now cancel reward points programmatically via API and track success/failure status at an individual recipient level for easier reconciliation.
* **Mobile Top-Up Accuracy:** New endpoints allow you to fetch and validate mobile operators before placing an order, significantly reducing transaction failures.
Keeping up with the new features is the first step. The next, and more important step, is to see their impact on your reward strategy in action.
## Upcoming features
### Improved Quantity Selection on Storefronts
We're introducing a cleaner interface for the gift card category page. Users will soon be able to increase or decrease quantities seamlessly before adding items to the cart. This means fewer clicks and a faster checkout experience, especially for users purchasing in volume.
### Share Proforma Invoices Instantly
Super admins will soon be able to email proforma invoices to multiple colleagues directly from the Add Funds page. This streamlines finance coordination and speeds up payment processing by eliminating the need to download and forward files manually.
# Release February 2022
Source: https://help-plum.xoxoday.com/product-updates/release-february-2022
Read the Plum product update for February 2022, covering new features, improvements, and fixes shipped that month.
This February, we have undergone a few major changes on both the plum admin side and the integration side.
We have come up with an enhanced low balance notification, ease of sending xoxo links directly through the API. Improved email design will now enable admins to communicate more efficiently. Scroll below to learn more about these and much more.
On the integration side, we have improved Hubspot integration now Xoxoday plum passes reward automation campaign activities into Hubspot CRM via Custom events into Hubspot CRM, there is now ability with the admins to edit any existing automation created by the admin for the integration rewarding.
Here are more details about the latest update:
## Low balance notification enhancements
With this release, the low balance notification will get triggered immediately after the balance reaches the threshold balance as set by the admin. This enables the admin to immediately take action and hence reduce the probability of redemption failing or other admins not being able to reward.
We have also enabled these notifications for companies that use the 3rd party reserve fund as well - eg, accounts connecting through Darwin Box, SAP. Disperz etc.
## Xoxo Link API for directly sending links to emails
Up until now, the Generate xoxo link API ([https://xoxoday.gitbook.io/plum/developer-resources/xoxo-link-apis](https://xoxoday.gitbook.io/plum/developer-resources/xoxo-link-apis)) allowed for the user to only specify "Campaign ID" and "Links quantity" as a part of the request. The user would receive Xoxo links as a part of the response which they can further distribute.
With this release, in addition to the above, the user can also use the Generate xoxo link API to directly distribute links to the recipient email IDs and also set an expiry link for the Links generated as per their choice.
## Cleaner and Sleek email design
In this release, we have enhanced the email templates sent with Xoxo Points and Plum Pro from the platform. This includes a cleaner UI for editing and selecting banners and logos, customizing the message while sending, the inclusion of a default message for the user, and previewing the email on both desktop and mobile. Admins can send a personalized message now, which will overwrite the default message.
Improvements made in templates for first-time Xoxo Points recipients detailing the steps to login and in templates of Xoxo Codes and Plum Pro where the quantity of Xoxo codes / Brand vouchers are more than 5.
## Auto registration of new admins
A super admin while adding a new admin into the system, would not have to separately register the admin into the system now. This step has been eliminated from the user's journey and is taken care of automatically in the backend.
## Updated Payment Gateway
We have changed the international payment gateway partner from PayPal and it is now PayU as for our domestic accounts. Also, a Transaction Charge of 1.8% of the total value of recharge (as levied by PayU) will be applicable to all INR recharge transactions.
## Auto-refund of a failed recharge
If the recharge fails, until now the refund has to be manually initiated by our team, and once done, the funds will be put back into the wallet. This created a delay in the overall rewarding activity. Now the refund process in case of recharge failure has been automated which means the amount will be added back to the client's wallet as soon as the recharge fails and the client can try again to continue rewarding.
## Expiry Data Updates
With this sprint, the expiry of each individual reward will be visible under 'View details' of the record only. This will no longer be available as a separate column to filter out and the status of the rewards will be "delivered" if not "redeemed".
## Pre-Paid cards as a separate option in Xoxo Links
While creating xoxo Link campaigns, all available gift cards and prepaid cards were shown up as in the same single list. This is resulting in a readability issue in the drop-down as multiple currencies and a large list of denominations got listed out. We have now separated out the different categories of available products into "Gift Cards" "Prepaid" giving the user a clear picture to narrow down their brand's selection.
## Increased character limit of Name field
The character limit for the name field while sending rewards (Points, Codes, Links, and Plum Pro) both in single send or by bulk upload has been increased from 30 to 70 to make accommodations for longer recipient names.
Other smaller admin improvements: The PO number is now made a part of the plum pro reports. The input fields for Xoxo code have been renamed to "Value of Codes" and "No. of Codes" instead of "Denomination" and "Quantity" as this has previously led to the erroneous distribution of rewards due to confusion of the terms.
## Integrations
### Improved Hubspot Integrations
Hubspot Improvements - With this release, Xoxoday plum passes reward automation campaign activities into Hubspot CRM via Custom events into Hubspot CRM so that customers can view reward activity & status directly inside the Hubspot timeline for each rewarded contact (in Contact page) and use Xoxoday reward activity and attributes inside a workflow to segment lists, and build RoI reports within Hubspot CRM.
### Ability to edit integration automation
Earlier there was no ability to edit any existing automation created by admin for the integration rewarding. Now the admin can edit details like: end-date, reward expiry any automation based on the requirement.
### Get notified with integration automation updates
The latest update has added notifications and alerts for the integration automations as well. Now you will be notified with important updates like: when is automation ending, how many rewards remaining, reward success/failure updates etc.
## Storefront
### Newly improved gift voucher descriptions
With the latest release, we have improved the gift vouchers pages layout to provide a better rewarding experience. Clear and sleek instruction for redemption.
## Plum Rewards API
### New Pricing Structure for Reward API
Offering new pricing plans for all our rewards API clients to get better discounts on popular vouchers across the globe. Increase your horizon of rewards with xoxoday's rewards API platform to deliver more delight from our vast and existing gifting catalog.
## Upcoming Features
### Mobile number-based rewarding
We're adding mobile-based rewarding options for admins to reward users who only have a phone number and no email. This aims to offer a well-connected experience for a diverse set of end-users receiving rewards.
### New Native Integration with Medallia
Our native integration with Medallia will let you incentivize surveys using Xoxo links. You can set up reward automation campaigns and distribute rewards based on 'survey completion and feedback collection' from the Medallia CX platform itself.
### A brand new perks with discounted gift vouchers
In the next release, we're introducing a brand new vouchers catalog with inclusive deals and discounts on vouchers, popular brands' exclusive coupons, and exciting cashback.
### Qualtrics SDK extension
You can set up and manage rewards within the Qualtrics dashboard without leaving the platform. The extension SDK allows you to manage rewards and the status, such as delivery and redemption, and the data is automatically synced back to Qualtrics for easier reporting.
### On-Demand and one on one email rewarding within Hubspot
Introducing on-demand emails in Hubspot: Your sales reps can use Plum to send on-demand emails from the 'Contacts' tab, allowing them to engage with prospects without navigating between multiple applications.
### A Classic redesign for Admin and storefront platform
Plum's new look is coming soon, the UI of the admin platform and storefront is getting a redesign and will be more intuitive and accessible for you to use your favorite features.
### Consumer Promotions
We are launching gamified consumer promotions with unique rewards distributed via QR code-based solutions, Reply to SMS, and IVR-based solutions. Gamifying promotions such as Scratch and Win, Spin the Wheel, Peel to Reveal, Sweepstakes, Price Drop, Quiz contests, refer and earn and many more and due to release in the upcoming month.
# Release February 2023
Source: https://help-plum.xoxoday.com/product-updates/release-february-2023
Read the Plum product update for February 2023, covering new features, improvements, and fixes shipped that month.
Sending rewards globally on Plum is always exciting—but currency conversion issues can sometimes be a hassle. To make things simpler, we've changed the system to provide admins and recipients with the applicable exchange rates for cross-border conversions, creating transparency in the financial systems.
## How is this going to help the Customers?
This will allow customers to know the actual value being charged in their base currency, where there is an exchange rate applicable for their daily orders if any of them are transacting cross-currency products. This also helps create transparency in the Customer's audits.
## Multi-lingual reward links
With this release, we have introduced multilingual capabilities in Xoxo Links. The recipient of a Xoxo Link will be able to choose a language in which they would like to view the options presented in the Links. We have enabled this feature for a few specific customers as a BETA version.
## Improved Journey of Marketplace Redemption
We have made it easier for recipients to redeem rewards by customizing the storefront according to the reward they received. This not only speeds up redemption but also eliminates confusion.
## Changes in the Plum Pro APIs
**getVouchers API Response**
The "isPhoneNumberMandatory" field is added in the API response which shows True/False in response. This allows you to know if the product requires Phone number while placing the order.
**getOrderDetails API Response**
We have added the timestamp information in the "orderDate" field which was earlier showing only date.
* Before: `"orderDate": "2023-01-24"`
* After: `"orderDate": "2023-01-24 13:19:58"` in GMT +5:30
This allows user to know the exact time the order is placed which can be used as reference during internal audit.
## Integrate rapidly with any tool
In this release, we worked to optimize our integration architecture and have added capabilities to integrate with over 100+ leading SaaS platforms from popular CRMs, to Marketing Automation, and support ticket systems to referral platforms and everything in between!
With this new optimized architecture in the Xoxoday back-end, you can connect with any tools you already use to send rewards based on the trigger criteria that fit your imagination or your business logic. Also, as an added advantage, you can tweak and customize the nature of the integration—as long as the other tool provides us with an API for that feature!
**Tools you may be already using (to name a few):**
**CRM**
* Freshsales: Robust Yet Easy-To-Use CRM Software from the stable of FreshWorks.
* Salesforce: World's #1 CRM. The integrated platform, AI, app development, and best-in-class apps.
* HubSpot: Flexible and easy-to-use CRM and Marketing Automation tool!
* Pipedrive: Pipedrive is an easy-to-use CRM tool.
* CloseCRM: Close is the inside sales CRM for startups and SMBs.
**Marketing Automation**
* Oracle Eloqua: A best-in-class B2B marketing automation solution, Oracle Eloqua Marketing Automation offers campaign design and advanced lead scoring.
* Marketo: Marketo is Software-as-a-Service (SaaS)-based marketing automation software owned by Adobe.
* Salesforce Pardot: A full suite of B2B marketing automation tools from Salesforce.
* Constant Contact: With Constant Contact, you can create effective email marketing and other online marketing campaigns to meet your business goals
# Release February 2024
Source: https://help-plum.xoxoday.com/product-updates/release-february-2024
Read the Plum product update for February 2024, covering new features, improvements, and fixes shipped that month.
## Effortless App Navigation & Enhanced Help Access
We've polished up the look and smoothened your navigation through the app, bringing simplicity to the forefront. Our detailed Help section is now just a tap away in the Rewards section that explains more about a specific distribution mode. The right-hand panel includes a new progress stepper showing exactly which step of the journey you're on.
## Customizable Reward Email Templates
Elevate your reward emails with our newly refined email templates. Choose your favorite one and set it as your default template with ease. Each template now includes a customizable subject line, ensuring every message carries your unique touch, elevating your engagement with recipients.
## Streamlined Funding & Organized Transaction Tracking
We've enhanced the admin experience by directly integrating the "Add Funds" feature on the "Send Rewards" page, informing you of the available balance before dispatching rewards. We've also repositioned the "Transaction History" (formerly known as "Payment Reports") into the "Payments" section to align logically with the funds added to the system.
## Seamless Bank Transfer with Domestic Wire for USD account
You can now effortlessly add funds directly from the Admin Dashboard to accounts with base currency set as USD, bypassing the need for emails to the Xoxoday Finance team to add funds after initiating the bank transfers. Choose between domestic wire transfers powered by Stripe for an efficient and secure way to add funds.
## Unlock Precise Rewarding with Decimal Denominations
Admins will now have the flexibility to send rewards with lower decimal values, like $0.01, $0.1, \$0.5, etc., to their users. Ideal for gaming companies, this update supports nuanced user engagement and retention strategies by rewarding users with fractional values for in-game task completion, leveling up, and hosting events for the game community.
## Upcoming Features
### Consumer Engagement Features
Revolutionize your promotional activities with Xoxoday's engaging consumer promotion features: spin the wheel, scratch cards, and sweepstakes. These fun, interactive engagement boosters help increase participation rates and enrich user experience.
### Upgraded Email Templates for Enhanced Personalization
New email templates with advanced personalization capabilities, including a drag-and-drop email creator and content editor. Ideal for rewards announcements, celebrations, or promotions, these templates ensure your emails drive higher engagement and response rates.
### Revamped Integration Module
A streamlined integration process to offer a simple and intuitive user experience while setting up reward automation with your favorite platforms. This approach will ensure quick and seamless integration, enhancing the user experience and efficiency of reward distribution.
### Teams and Budgets
Superadmins can streamline team management by creating groups of admins and assigning dedicated reward budgets to each team. This feature enhances incentive distribution control, fostering targeted engagement and motivation within teams.
# Release January 2025
Source: https://help-plum.xoxoday.com/product-updates/release-january-2025
Read the Plum product update for January 2025, covering new features, improvements, and fixes shipped that month.
*Latest from our world of Rewarding*
We've recently introduced several new features to enhance your Plum experience. The Plum Reward API is live on Postman's Public API Network, enabling seamless discovery, testing, and integration. Product Whitelisting simplifies catalogue configuration, while our improved recommendation engine delivers tailored suggestions for UK and Indian customers. These updates and other enhancements are designed to provide a seamless, secure, and efficient experience for admins and users.
## Here's what's new:
### Plum is Live on Postman's Public API Network
The Plum Reward API is now live on Postman's Public API Network, the largest collection of public APIs globally. This makes it easier for developers to:
* Discover and explore the API's capabilities.
* Test it directly within the Postman environment.
* Access detailed documentation to get started quickly.
This launch simplifies integration and enhances the developer experience.
### Product Whitelisting
Introducing the Product Whitelisting feature! You can now configure catalogs to make specific products visible to selected accounts or marketplaces, ensuring tailored visibility while hiding them from others.
### Tailored Recommendations
* For UK Customers: Our new recommendation engine now provides UK-specific suggestions for products and gift cards, helping you discover the most relevant and popular options effortlessly.
* For Indian Customers: We've revamped our catalog to deliver enhanced merchandise recommendations tailored to the Indian market.
### Amazon Prime Fulfillment & Flexible Integrations Available on Plum
Plum now offers Amazon Prime fulfilment for all products in the US, ensuring fast, reliable delivery with no markups.
Plum provides two flexible integration options:
* Not Using Your Company Amazon Account: Plum facilitates purchases directly from Amazon, allowing you to set up a rewards program without needing your Amazon account.
* Using Your Company Amazon Account: Plum sets up the rewards program using your Amazon account with restricted access. This gives you control over your account while Plum handles the reward processing.
Both options offer no markup and ensure quick, efficient delivery for your employees' rewards.
### Enhanced Gift Voucher Catalog Across Countries
We've expanded our Gift Voucher catalogue with exciting new brands in multiple countries. Now, you can enjoy more choices and seamless redemptions.
Explore the Plum marketplace.
* New additions to GV in the Americas region - 129
* New additions to GV in the UK - 88
* New additions to GV in Europe - 84
* New additions to GV in Bangladesh - 23
Keeping up with the new features is the first step. Next, and more important step, is to see their impact on your reward strategy. Try it out
## Check out these new features
## Upcoming features:
### Customize Global Catalog for Rewards API Customers
You'll soon be able to:
* Select and deselect products directly from the Admin Dashboard.
* Instantly view updates in the Rewards API.
### Catalog Change Updates via Webhooks
You can receive real-time updates on product changes through webhooks, such as enabling/disabling status and denomination adjustments. Simply list your callback URL to stay informed.
### Flights in the Reward Marketplace
We're expanding our offerings! Flights will soon be available in the Reward Marketplace, giving your users more travel redemption options.
### Send Rewards via WhatsApp
You can send rewards directly via WhatsApp, making the gifting experience more seamless and convenient.
### Airmiles
A new Airmiles reward category is on the way, allowing users to list, send, and redeem them for travel benefits.
### Charity & Lounge Categories
Support for Charity and Lounge Categories is coming soon. This will enable users to donate to causes and enjoy premium lounge access, enhancing reward flexibility and user experience.
# Release July 2021
Source: https://help-plum.xoxoday.com/product-updates/release-july-2021
Read the Plum product update for July 2021, covering new features, improvements, and fixes shipped that month.
*July 2021: Distribute links seamlessly, multilingual storefront, + more*
This spring, we have several updates for admins and end-users.
The admin dashboard has been revamped completely to enable admins to distribute gifts seamlessly. For the end-users, the storefront is now multilingual, thus enabling non-English users to redeem rewards easily.
Here are more details about the latest update:
## For Admins
### Xoxo Links
**Update #1**
**Admins can now select gift vouchers from any country while creating Xoxo links.**
It was previously not possible for admins to select all geographies while creating a new campaign.
In the latest release, the distribution mode has been rebuilt to function in any geography and scale. The admin can now select any product from the wide variety of real-time brands we have from 100+ countries while creating a new campaign.
They would also be able to choose from an array of new denominations that were previously not available.
**Update #2**
**Admins now possess the ability to generate and send Xoxo links to self in bulk.**
It was earlier not possible for admins to generate links en masse. With the latest release, Admins will now be able to generate up to 1000 links at once. They can choose to distribute this later in the distribution mode of their choice.
Xoxoday will send the links generated to the admins in an excel format attached with an email. Admins can also track the redemption status of the batch separately.
**Update #3**
**Reward Redemption is even more delightful now, as the user interface for Xoxo links has been revamped.**
The Xoxo link redemption process has been revamped while retaining the sleekness and simplicity in the redemption process to solve distributing Xoxo links in scale.
Admins will now have white-labeling options to add their company logo on the header of the redemption link.
On the distribution side, the "Sending to few" and "Sending in bulk" options have been separated and made similar to the other modes of distribution, thus bringing more clarity while distributing links.
**Update #4**
**Admins of Common Wallet Companies can now distribute Xoxo links.**
The admins of "Common Wallet Companies" were previously unable to distribute Xoxo Links. With the latest release, the super admins and the admins of a company can view and send Xoxo links from the admin console.
**Update #5**
**Better Reporting for Reward sent using links.**
The new report section for Xoxo links includes the entire order history of the rewards distributed from the platform, details to whom the admin sent the link, redemption status at an individual link level, the campaign, and the value of a link. The section also can cancel any specific link, or resend the reward link to the recipient.
This elevates the Xoxo Link distribution experience to a whole new level and eliminates the dependency on the Plum team for manual reports.
The records can also be filtered by any of the above-mentioned parameters and downloaded in an excel format.
## For Storefront Users
**Update #6**
**Multi-Lingual Support on Plum Storefront has been enabled.**
We have now enabled localization support on the Plum Storefront for different languages and geographies. An end-user such as an employee or a consumer can now choose a preferred language and experience the complete redemption journey in the selected language.
The 12 Languages enabled in the current sprint are English, German, Polish, Hebrew, Chinese Traditional, Chinese Simplified, Portuguese, Spanish, Thai, Japanese, Italian, and French.
Xoxoday will enable this solution only on request from a Plum Admin from the dashboard.
**Update #7**
**Admins can now select and customize any brand color on the Plum Storefront.**
The admins of Plum can now customize the storefront background color from "Platform Preferences" in the admin console and choose from an array of options available or by directly putting in the color code that they want the storefront to reflect.
## Plum Pro
**Update #8**
**Ability to resend Plum Pro rewards and add 'tag /notes' in the reports section.**
The ability for admins to resend a reward confirmation email has been introduced in the "Plum Pro" mode of distribution thus eliminating the need for admins to reach out to Xoxoday to resend rewards.
Admins can now resend Plum Pro Rewards by clicking on "Reports" and then navigating to "Plum Pro History" and clicking on the action against the individual reward sent.
The 'Tag'/ 'Notes' column that allows capturing essential information about a reward has also been made visible under each reward in the reports section. This has been made available in all distribution modes.
**Update #9**
**Response changes in Plum Pro API**
In Plum Pro API, all the endpoints have been updated with new error messages so that the end-users can easily recognize & take action. We have introduced a new flag for all products which will tell about the product type.
Whether it's a real-time or non-real-time product, the user can use this flag in the API request to make a call and pull the relevant set of products.
**Other Admin Updates**
**Update #10**
**Email customization in bulk upload**
While sending brand vouchers in bulk to multiple recipients, the email sent, and the reward can now be previewed and customized in terms of the subject, content, banner image.
A personal message to the recipient can also be added while sending rewards.
**Update #11**
**DIY Journey Enabled to get Client ID, Secret ID, Access Token & Refresh Token.**
Generating Client ID/Secret ID is now easy with the DIY process. From the Plum Pro Stores Frontend, Plum Pro Admin can generate Client ID & Secret ID by clicking on "Generate Client ID," Post generating the client ID, Admins will have the option to generate "Access Token" & "Refresh Token."
Admins would have to just log in to Storefront, click on "Admin Dashboard," go to "Settings," visit "Platform Preferences," and select "Rewards API."
**Update #12**
An email notification will be sent if a product is enabled/disabled or when a denomination changes.
It was earlier very tedious for admins to track changes in the product catalog.
Plum will trigger notification emails to all super admins of Plum Pro users detailing product and denomination updates with this release.
Triggered every 24 hours, we will share the list of products and other changes in the notification email. This will keep the admins informed of any changes in the catalog on a near real-time basis.
**Update #13**
**Automated Notification for Scheduled Rewards that were canceled.**
For any scheduled reward that now gets canceled because of a low balance or threshold limit breach for an admin, the admin/super admin will get a notification detailing the rewards that have been canceled.
This will enable them to take immediate corrective action and ensure that the rewarding experience is smooth for end-users.
**Update #14**
**Admin Dashboard has been revamped.**
The admin management screens for both the "Common Wallet" and "Individual Wallet" companies have been improved, thus introducing visibility into the entire list of both super admins and admins present in an account.
A super admin can now see all the admins and their respective threshold values on a single page. They can also modify any other admin/super admin access or even delete another admin.
This feature was previously unavailable and took considerable back and forth with Plum to remove the admins from the system.
**Update #15**
**Enhancements in the Recharge Section**
Paypal has now been added as a payment gateway for base currency such as USD, Euro, and SGD.
OTP validation for recharge has been introduced, and the discount/markup at a client level will now be transparently visible to the admins and the breakup on the recharge page.
That is all for this product release! Have a question? Reach out to us [here](https://support.xoxoday.com/support/tickets/new)
To set up a demo with a Plum Specialist, please sign up [here](https://www.xoxoday.com/book-a-demo)
# Release July 2022
Source: https://help-plum.xoxoday.com/product-updates/release-july-2022
Read the Plum product update for July 2022, covering new features, improvements, and fixes shipped that month.
## New & improved product experience to send the first reward
As an admin, you will now be able to seamlessly send the first reward under a threshold capacity without undergoing the KYB submission and verification process. Once the reward is sent, the admin can do the documentation process. This enhances the overall user experience and navigation of the product.
The admin user will be able to add recipients and 'proceed to checkout to directly send rewards using a preferred mode of payment.
## Seamless wallet recharge flow for super admins in case of low balance
When the super admins are in the middle of sending rewards, they might run into a low balance in their wallet. Now they do not have to separately recharge and repeat the process of adding recipients to reward. With this release, they can continue rewarding by adding the balance amount to the same screen without adding the recipients again.
## Instant notifications of threshold updates and changes
The admin will now get a notification whenever the super admins update the threshold limit, and the amount used is reset to zero. This helps the admin keep track of changes to their reward limits and usage.
## In case of cancellation of rewards, the amount will be added back to the admin's threshold capacity
When an admin sends a reward, the reward amount gets updated under that admin's name. Now in case of cancellation of the reward as well, this amount will get appropriately updated in the individual admin's threshold capacity and used amount.
## Unsubscribe from 'catalog update notifications' directly from the email
Every time our catalog is updated, an email is sent to every admin to notify what's new with the gift catalog. However, if you don't want to receive these daily emails, you don't have to go through the hassle of reaching out to our team. You can simply unsubscribe directly from the email to discontinue.
## View the reward delivery status sent via email and SMS
See the Email and SMS delivery status for the brand vouchers you send to your gift recipients on the Plum Pro dashboard. Download them as reports to make data-driven decisions for your business every time. Navigate to 'Reports' under Plum Pro to see your email and SMS delivery status.
## Integrations
### Add a link to email CTAs to reward multiple recipients at once in HubSpot
Previously, Hubspot customers using Xoxoday Plum's mail merge could not hyperlink or add any CTA's with reward links. Also, the user had to refresh every time for dynamic lists to load and enrich new entries.
Now, the users can generate a one-to-many link and add it to their branded, rich HTML templates on Hubspot. These links support dynamic lists as well as automated drip campaigns in Hubspot. All you have to do is create the Xoxolink campaign with one-to-many automation on Hubspot. Copy-paste the generated reward link to your CTAs in the email template.
### Reward anonymous survey respondents in SurveyMonkey
Survey Monkey customers can now include reward incentives for anonymous surveys on their Platform. This is one of the most secure features available in the market, where Xoxoday validates the recipient's authenticity directly by calling SurveyMonkey APIs.
## Payments
### Integrated a new payment processor - RazorPay, to recharge your wallet
Our platform is now integrated with RazorPay, a highly secure payment processor that enables domestic clients to recharge their wallets seamlessly. Customers can now load wallets in real-time using Internet banking by paying flat (INR 20) charges instead of paying 1.7% as transaction fees.
## Reward Catalog
### Send experiential rewards to delight your gift recipients
Experiential rewards go beyond transactions to create brand advocacy. We have added 150+ 'experiences' as a separate category to our storefront, which you can book across India, Dubai, and Singapore.
# Release July 2024
Source: https://help-plum.xoxoday.com/product-updates/release-july-2024
Read the Plum product update for July 2024, covering new features, improvements, and fixes shipped that month.
In the recent weeks, we've introduced an array of exciting features designed to enhance the user experience. Among the notable additions are the multi-factor authentication, low balance notification, notifications for Scheduled rewards.
But that's not all – we're offering you an exclusive sneak peek at the features slated for the release in coming months.
## Here's what's new:
### Launch of Multi-Factor Authentication
Multi-Factor Authentication adds an extra layer of security to your account by requiring two forms of identification to log in.
* Mobile OTP: Receive a time-sensitive code via SMS
* Authenticator App: Generate a code using apps like Google Authenticator
Multi-Factor Authentication offers several crucial advantages for your Xoxoday account. By requiring two forms of identification, it significantly enhances your account's security, making it far more challenging for unauthorized users to gain access. This added layer of protection gives you peace of mind, knowing that your sensitive information is better safeguarded against potential cyber threats. MFA also provides flexibility, allowing you to choose between SMS-based OTPs or authenticator apps, catering to your personal preferences and convenience.
### Proactive Low Balance Alerts for Admins
We've implemented a new system to keep your rewarding process smooth and uninterrupted. Admins will now receive timely notifications when the account balance falls below the total value of unredeemed rewards. This preemptive measure ensures you're always prepared to fulfill pending redemptions, eliminating potential disappointments due to insufficient funds.
### Enhanced Security Measures
We've fortified our platform's security to protect your organization and reward recipients:
* Reward Distribution Safeguard: Our system now prevents rewards from being sent to disposable or temporary email addresses, ensuring your rewards reach legitimate recipients only.
* Admin Access Control: New admin accounts can only be created using verified work email addresses, maintaining the integrity of your administrative team.
* Transparency in Admin Privileges: Whenever an admin's access threshold is modified, both the admin in question and the super admin will be notified, keeping all parties informed of important changes.
### Smart Scheduling for Rewards
Planning ahead? Our new notification system for scheduled rewards has got you covered:
* Weekly Fund Forecasts: At the beginning of each week, admins will receive a notification if any scheduled rewards are at risk due to insufficient funds.
* Detailed Fund Requirements: These alerts will include specifics on the additional funds needed to ensure all scheduled rewards are distributed without a hitch.
These updates reflect our ongoing commitment to improving your Xoxoday experience, combining enhanced security, smarter notifications, and proactive management tools. We're excited for you to explore these new features and welcome your feedback!
### Enhanced Reward Code Transparency
We're excited to unveil a new feature that brings more clarity to your reward code management. When checking your reward code balance on the marketplace, you'll now have access to expanded information about each code, including:
* Redemption Status: Easily see which codes have been used
* Redeemer Details: Identify who has redeemed each code
If you're juggling several reward codes, this feature helps you keep track of each one's status. For codes you don't use immediately, you can now verify their status at any time. This update is designed to give you greater control and insight into your rewards, making the entire process more transparent and manageable.
### Introducing Get Link Status API
Users can now fetch reward link status to know if the link is redeemed or not by just passing the unique Link ID. This helps users to know the status of the link so that they can automate their operations process and user experience.
### Introducing Phone Number Support in Send Link API
* Users can now send links to the recipient's phone number by passing the phone number information in the API request.
* This allows users to send the links to their recipients via an additional channel besides email.
* User can then fetch the link Id unique to the recipient to get the redemption and delivery status of the link.
**Note:** The API information will be available in our API reference document shortly.
## Upcoming features:
### Perks Launch in Marketplace
The new category of perks and benefits is being introduced into reward marketplace. Avail amazing offers and deals of your favorite brand and the instant discount
### Improved User Experience for Mobile Marketplace
Enhacing the user experience of the mobile version of marketplace to allow users have more delightful rewarding redemption journey.
### Configurable reminder email system
Admins will be able to configure the intervals and frequency of the redemption reminder emails to be sent to the clients.
### Rewarding through WhatsApp
End users will be able to redeem their rewards using OTP delivered via Whatsapp or SMS whichever is more convenient for them.
### Email and SMS delivery status in reports
Admins will soon be able to see the exact status of the email and SMS delivery and the reason in case of failure so that it can be actioned upon appropriately.
# Release July 2025
Source: https://help-plum.xoxoday.com/product-updates/release-july-2025
Read the Plum product update for July 2025, covering new features, improvements, and fixes shipped that month.
*Learn all about the latest releases in Xoxoday Plum*
Here's a quick roundup of what's new, improved, and coming soon on Xoxoday Plum. From adding new redemption options like company swag and expanded travel rewards to giving admins more control over voucher management, we're continuing to build features that make rewarding easier, flexible, and more meaningful for your users.
## Here's what's new:
### 1. Add Company Swag to Your Marketplace
Want to let your users shop for company swag?
You can now add your own branded goodies, like T-shirts, mugs, bags, or jackets, directly to the rewards marketplace. Your team can redeem points for cool company merch!
### 2. Enhanced Shopping Experience with Redemption Filters
Shopping just got easier and more personal. Users can pick product options like color, size, or storage directly from the product page in the merchandise section.
This means less hassle and more clarity when choosing your perfect reward.
### 3. Simplify Gift Card Selection with Redemption Filters
Users can filter gift cards by how they can be redeemed, Online or In-Store (Offline). This gives them a clear idea of where they can use each card before redeeming, making the process smoother and stress-free.
It's all about helping users make faster, smarter decisions when choosing their rewards.
### 4. Enhance Voucher Control by Setting Custom Expiry Dates
Admins now have the option to set an exact expiry date for vouchers giving more control and flexibility, allowing you to align voucher validity with campaign timelines, special events, or business needs.
### 5. New APIs That Unlock More Rewarding Experiences
We're introducing three powerful APIs to help you offer more real-world, meaningful rewards, seamlessly integrated into your platform.
* Mobile Top-up API: Empower users to recharge their mobile phones instantly, anytime, across the globe. The Mobile Top-up API enables seamless prepaid and postpaid recharges across major telecom operators in multiple countries.
* Charity API: The Charity API is your gateway to enabling meaningful impact through seamless charitable giving. It empowers users to donate to verified NGOs and causes directly, making social good a part of everyday interactions. With the Charity API, you can design your own user interface while leveraging a curated catalog of global charitable organizations and initiatives.
* Lounge API: The Lounge API lets users effortlessly discover and book premium airport lounges across the globe. Whether they're business travelers, frequent flyers, or holidaymakers, elevate their journey with access to top-tier lounge experiences, complete with gourmet food, Wi-Fi, and more. Integrate the Lounge API to create a seamless lounge booking experience directly within your platform, tailored by location, airport, and travel needs.
[View API References here](https://e.customeriomail.com/e/c/eyJlbWFpbF9pZCI6ImRnVEI4UWdEQVBQME9fTDBPd0dZVUg3TndxYVN0M0FDcmYxN2VaND0iLCJocmVmIjoiaHR0cHM6Ly9kZXZlbG9wZXJzLnhveG9kYXkuY29tL3JlZmVyZW5jZT91dG1fY2FtcGFpZ249QWRtaW4lMkZTdXBlcitBZG1pbnMrLStQcm9kdWN0K1VwZGF0ZXMrLStKdWx5KzIwMjVcdTAwMjZ1dG1fY29udGVudD1Qcm9kdWN0K1VwZGF0ZXNfSnVseSsyNVx1MDAyNnV0bV9tZWRpdW09ZW1haWxfYWN0aW9uXHUwMDI2dXRtX3NvdXJjZT1jdXN0b21lci5pbyIsImludGVybmFsIjoiYzFmMTA4MjBmMmE4MDFmM2Y0M2IiLCJsaW5rX2lkIjoxNzM1fQ/3260a77a6f4e7f41eaec8a55220d8db1dac988ee58b46fef66f91c24a88c774c)
## Upcoming features:
### Hotel Booking in the Storefront
Soon, users will be able to redeem points for hotel stays directly from the marketplace. This feature will make travel rewards even more accessible and exciting.
### Lounge Access with QR Codes
Lounge vouchers will include a QR code in the delivery email, allowing users to easily enter lounges without needing an app or printed voucher.
### Cashout Option
Users will be able to convert their points into cash payouts giving them more freedom on how they use their rewards.
### Gamification in Xoxoday
We're adding gamification features to help drive more engagement. Look out for interactive elements that make rewards more exciting.
Looking to drive loyalty, boost sales performance, or enhance employee engagement? [Explore Xoxoday's product suite here.](https://e.customeriomail.com/e/c/eyJlbWFpbF9pZCI6ImRnVEI4UWdEQVBQME9fTDBPd0dZVUg3TndxYVN0M0FDcmYxN2VaND0iLCJocmVmIjoiaHR0cHM6Ly9iaXQubHkvM0g4U0hWaj91dG1fY2FtcGFpZ249QWRtaW4lMkZTdXBlcitBZG1pbnMrLStQcm9kdWN0K1VwZGF0ZXMrLStKdWx5KzIwMjVcdTAwMjZ1dG1fY29udGVudD1Qcm9kdWN0K1VwZGF0ZXNfSnVseSsyNVx1MDAyNnV0bV9tZWRpdW09ZW1haWxfYWN0aW9uXHUwMDI2dXRtX3NvdXJjZT1jdXN0b21lci5pbyIsImludGVybmFsIjoiYzFmMTA4MjBmMmE4MDFmM2Y0M2IiLCJsaW5rX2lkIjoxNzM2fQ/8abdfac11152f012fc442db627affd602a8e24328c84ba7cd325e33baed295e6)
Want to request a feature on Xoxoday Plum?
Get in touch with our customer success team at [cs@xoxoday.com](mailto:support@emplus.io?utm_campaign=Admin%2FSuper+Admins+-+Product+Updates+-+July+2025\&utm_content=Product+Updates_July+25\&utm_medium=email_action\&utm_source=customer.io)
# Release June 2020
Source: https://help-plum.xoxoday.com/product-updates/release-june-2020
Read the Plum product update for June 2020, covering new features, improvements, and fixes shipped that month.
*Plum New Features Release: June 2020*
Xoxoday Plum, our exclusive rewards platform, brings a handful of upgrades with this release. There's a new link-based API for redemption, front-end improvements, nudges on points-expiry, and bring-your-own-products feature, along with other changes. Let's go through them all.
## Generate URLs for Link-based Redemption with the API
Link-based redemption has proved to be a fruitful tool for admins to distribute vouchers through URL, which can be redeemed in just a click. However, the link-based redemption process for admins involved going to the platform and choosing vouchers from the catalog and then redeeming the links.
With the new Link-based Redemption API, all admin has to do is create campaigns once, after which they can use the API to generate links. This can be done so by sending campaign codes and the number of links to be generated, and they shall be delivered via email.
The admins won't have to visit the platform and go through the whole process of campaign creation. All it'd take is the campaign code to generate the links, making the link-based redemption process quicker than before.
## Automated Refund Process on Cancellation with PayU
Our integration with the PayU payment gateway was mentioned in May features release, and with the global payment gateway, we have automated refunds on canceled orders and purchases from Xoxoday Stores. In times before PayU Payment gateway, refunds were immaculately processed by the support team, but with automation, the process can easily be tracked via the PayU portal.
## "Can't find what you're looking for? You might also like…"
For the ones using the link-based redemption option on the Xoxoday Store, improvements have been made on the front-end wherein they can shop for suggested vouchers in their points-range in case the voucher they were looking for goes out of stock.
The suggestions come as a replacement to the error-screen which was showcased when the offered voucher wasn't available. With this fix, users can explore the given options in Xoxoday's catalog of the same or different denominations.
## Send Users a Nudge when Xoxocodes/Points are Near-Expiry
**This is a customizable feature. Please connect with [cs@xoxoday.com](mailto:cs@xoxoday.com) or your POC for details.**
The users are notified via email when their Xoxocodes and/or points are near to the date of expiry. Xoxo Codes and points are valid for one year from the date they're credited to the user's account. It's crucial to keep the users in the loop when the date of expiry comes near.
The users can check the validity of their Xoxocodes and points from the profile drop-down menu. But in order for them to make the most of it and not waste their points, nudges will be sent out.
This is a premium feature that our support team will be happy to walk you through. Please connect with your point of contact or write to us at [cs@xoxoday.com](mailto:cs@xoxoday.com) to know more.
## Admins, Reward Every User with a Personalized Wish
While rewarding users with Xoxo Codes and points, the admins can include a personalized wish for each and every one of them. This can be done via a bulk upload through CSV file or simply on the campaign screen.
Earlier, the admins could pen down a single message for sending out rewards to multiple people, but with this update, they can keep it personal with the messages. The process is simple:
* Download the template
* Input your personalized message in every user's row
* Upload the CSV file back to the campaign menu.
Another way to do it from the campaign menu is to enter every personalized message beneath the user's name and email.
## Admins can Retrieve and Resend Lost Codes to Users
With the rise in cases of lost Xoxocodes from users' ends, we've passed the front-end control to the admins so that they can retrieve and resend the codes. There were increased cases of lost emails, texts, and code numbers and now admins can assist the users from their end in sending the codes back.
The codes can only be retrieved and resent from the admin's end within 15 days of the issue. In case of further delay, feel free to approach your point of contact or [cs@xoxoday.com](mailto:cs@xoxoday.com).
In the Admin menu, go to Reports > Xoxocode. Click on Action and Resend the code to the designated user(s).
This feature is only available for organizations with a single admin, the multi-admin compatibility of this feature shall be live soon; stay tuned.
## Create Your Own Branded Store & show your SWAG!
Who doesn't love some Souvenirs, Wearables, and Gifts (SWAG) from the workplace? Now showcase your own catalog of products on the Plum storefront. With the add-your-merchandise feature, organizations can add their own merchandise, perks, benefits, SWAG, and vouchers in their storefront along with Xoxoday's catalog. All the users have to do is upload the images and a short description of what the merchandise is about and it'll be live in the catalog.
Be it a coffee with your brand ambassador, lunch at the high table or simply tees, portable chargers, pens, and notebooks, showcase it all on the Plum Storefront, and let your people take their pick.
All the orders received on the merchandise will be automated. The admin(s) will get a report of orders placed on the same day so that the orders can be managed in real-time by the organization.
## Learn how to Redeem with the Points Redemption Walkthrough
The users can go through the points redemption guide and clear any queries that they have. Find the answer to all your question in the document.
[Here's the points redemption walkthrough >>](https://docs.xoxoday.com/login?dest_url=L2RvY3MvaG93LXRvLXJlZGVlbS1wb2ludHM=)
# Release June 2023
Source: https://help-plum.xoxoday.com/product-updates/release-june-2023
Read the Plum product update for June 2023, covering new features, improvements, and fixes shipped that month.
## Reports Improvements
With this release, all reports have been changed to optimize performance. The records available in the portal have been restricted to the last six months to reduce instances of timeouts and incorrect numbers. To access records before six months, the admin has an option to send them across over to their email.
In addition to this, we have implemented a filter that will allow the admins to view 'records by 'redemption date'.
The admins of Xoxo Links will be able to view a link wise report in the 'Generate to self' tab as well.
A Reference ID has been added to each report (Payment, Xoxo Point, Xoxo Code, Xoxo Link, Plum Pro). This is to make it easy for the admin for recon and to have one unique identifier for each reward sent.
## Launched Templates
A new tab has been introduced that has pre-defined templates that the admin user can pick from while sending rewards. This eases the process of sending rewards as the admin need not create email template modifications from scratch. Each predefined template comes with an appropriate banner and personalized message that the admin can just pick and send out.
## Recommended Products
While selecting products on creating a campaign, the admin will be able to see a new section that will show recommended products to be selected in that country and for the selected denomination.
## Change in Reward Module Names
The reward modules are updated to:
* Xoxo Points -> Xoxo Reward Points
* Xoxo Code -> Xoxo Reward Code
* Xoxo Link -> Xoxo Reward Link
* Plum PRO -> Xoxo Rewards API
## Stores/Marketplace
### Introduction tag for recommended products
With this release, we have introduced a new tag called 'Recommended' on the storefront. This tag aims to assist our users in identifying and purchasing the most popular products available in our catalog.
By labeling certain products as 'Recommended,' we ensure that our users can easily discover and access the most sought-after items.
### Improved UI of Reward API catalog page with more filters and sorting
With the release, the user experience for the reward API catalog page is improved and more readable for the usage of sales team and API clients to know more about latest updated products and other details.
### Xoxo Rewards API (Previously Plum PRO)
**APIs:**
* In getVouchers API response, tatInDays for the Delayed delivery products have been changes to " 2 - 7 " of value type String from " 0 " which was of value type String. This is introduced for improved accuracy in representing turnaround time that can help build user experience accordingly.
* Added new prince ranges in the Price Filter (getFilters API) - This will help Admins/Super Admins to filter products with ranges that were not available earlier and use it based on their use case.
* Included "access\_toke\_expiry" and "refersh\_token\_expiry" information in the token API response. Now this will allow users to get the information from the API response than going to the dashboard to know the information.
**Xoxo Rewards API Dashboard**
* Order Cancellation Notification for Plum Pro customers - Now Super Admins and Admins of the account will get a consolidated list of all the canceled orders of a day to their emails.
**Webhooks**
**Webhook Payload:** deliveryStatus for delivered orders is changed from "Delivered" to "delivered". This is done to maintain sanity with the response users receive in Plum Pro APIs.
# Release June 2024
Source: https://help-plum.xoxoday.com/product-updates/release-june-2024
Read the Plum product update for June 2024, covering new features, improvements, and fixes shipped that month.
In the recent weeks, we've introduced an array of exciting features designed to enhance the user experience. Among the notable additions are the new and quick sign in, launch of direct bank transfer and RuPay prepaid cards in India, order tracking for your customers, and email template customisation for your reward campaigns.
The new and quick sign in process streamlines account access. Direct bank transfers and RuPay Prepaid cards offer a convenient payment option for your channel partners. Order tracking empowers your customers with visibility into their purchases. Email template customisation elevates reward campaign personalisation.
But that's not all – we're offering you an exclusive sneak peek at the features slated for the release in coming months.
## Here's what's new:
### Launch of Direct Bank Transfers and RuPay Prepaid cards in India
We're proud to introduce two powerful new payout methods - direct bank transfers and RuPay prepaid cards. These localized solutions are tailored to provide convenience, flexibility, and a superior channel partner experience.
Direct bank transfers eliminate delays and enhance transparency by allowing you to disburse incentives seamlessly into your partners' bank accounts for a nominal surcharge. RuPay prepaid cards, on the other hand, offer a secure digital wallet, empowering your partners with instant access to their well-deserved rewards.
### The New DIY Flow
Introducing the sleek and intuitive new DIY (Do It Yourself) Flow, designed to enhance the onboarding experience. We've minimized the information required for account creation, allowing users to breeze through the process effortlessly. But that's not all – we've also streamlined the rewarding journey, enabling users to submit business details, set a redemption URL, and add a rewarding base currency, all without disrupting the flow. Moreover, users can now explore the platform's features and functionalities, except for transactions, even before business verification.
### Delight Your Customers with Seamless Order Tracking
Elevate the shopping experience for your end customers with our new "Track Order On Storefront" feature. Empower them to stay informed throughout their purchase journey by allowing real-time order status tracking. With just an Order ID and contact details, your customers can effortlessly monitor every stage of their order, from processing to shipment to delivery, right from your storefront.
### Craft Personalised Communications
Now, you have the power to craft personalized email content that truly resonates with your audience. Go beyond templated messages and unleash your brand's unique voice by editing the email body, subject lines, adding links and more. Whether you're sharing updates, fostering customer relationships, or launching campaigns, this innovative addition allows you to infuse your distinct tone and messaging into every interaction. A dedicated custom footer allows you to reinforce your brand with every email. With complete control over creating personalised interactions that resonate with your audience, this feature elevates your brand communication to new heights.
### Gain Deeper Insights into Bulk Rewarding
Rather than relying on a simple "100% Processed" status, you can now effortlessly track and update the status of individual records within bulk operations. Gain visibility into successful disbursements and failed transactions, empowering you to take proactive measures, reduce manual efforts, and make data-driven decisions to enhance your overall rewarding experience.
### Increased Transparency in Reward Redemption
Now, when sharing reward links with your recipients, you can provide them with clear visibility into the expiration dates and validity periods. This added transparency empowers your users to plan their redemptions effectively, eliminating any confusion or missed opportunities.
## Upcoming features
### Launching Perks on Marketplace
Explore a brand-new category on our Marketplace – Perks and Benefits! Get ready to unlock exclusive deals and discounts from popular brands and products. Admins can easily configure and manage this exciting category from the admin panel, ensuring a seamless experience for users.
### Xoxocode Balance Insights
Gain deeper insights into your Xoxocode balance. Users will be able to access comprehensive information about the status of their Xoxocodes, including who redeemed them. This improved transparency provides better visibility and control over your rewards.
### Two-Factor Authentication for Admins
Super admins and admins can now enable two-factor authentication via mobile OTP or an authenticator app, adding an extra layer of security to their accounts.
### Bulk Resend for Reward API Customers
Reward API customers can now resend rewards in bulk by multi-selecting the rewards, streamlining the process for efficient reward management.
### Multiple Admin Enhancements
Get ready to embrace a wave of enhancements across the admin panel. Look forward to new low balance email notifications and customizable threshold settings, keeping you informed about your rewards balance. Additionally, enjoy streamlined notifications for scheduled rewards, ensuring you never miss an important update. We've also revamped our bulk template file management, making it easier than ever to handle large volumes of data efficiently.
# Release June 2025
Source: https://help-plum.xoxoday.com/product-updates/release-june-2025
Read the Plum product update for June 2025, covering new features, improvements, and fixes shipped that month.
# Release March 2020
Source: https://help-plum.xoxoday.com/product-updates/release-march-2020
Read the Plum product update for March 2020, covering new features, improvements, and fixes shipped that month.
The March 2020 Plum release brings with it a handful of advanced features to help organizations get the best out of the [reward platform](https://www.xoxoday.com/plum), like white labeling, better customization, readable campaign URLs, proforma invoicing, resending brand vouchers, viewing multiple items in one single order, multi admin and SMS delivery of points. Let's understand them one by one.
## Customize Plum as per your brand with White labeling
White labeling Plum as per your brand helps you:
* Building brand credibility
* Strengthening customer loyalty
* Saving time and money
Having your brand name on logins and messages that are sent to customers helps in building brand awareness, a sense of credibility, and trust with the client.
**White labeling feature in Plum**
They can also choose the name of their rewarding units (e.g. xoxopoints), email name through which rewards are sent.
It gives them the flexibility to enable/disable payment options, set the first level of support and communication.
Campaign email settings
* They can now enable SMS delivery of points and vouchers to the recipients
## Readable Campaign URLs
The admin will now be able to create a campaign with a URL that is more relevant and readable to the user. It will be of the format `https://stores.xoxoday.com//`
The objective is to make it easier for the end-user to read and also for future similar campaigns.
## Proforma Invoicing
A Plum admin will now have an option to generate the proforma invoice before they make a payment for recharges. They can submit the invoice for finance approval before making the actual payment and at any point of time access the specific transaction and complete it from the Reports section.
## Resending Brand Voucher
To give more flexibility to the end-users, Plum has the option to resend brand vouchers they purchased from their order history. This feature can come in very handy when a user loses their original voucher or order confirmation. The user can also resend the brand voucher to an alternate email - it can be their mail id, or they can use the email id of their family member or friend. All they need to do is to enter an alternate email in the box provided.
## Viewing Multiple items in a single order
Keeping up with the practice of giving more flexibility to the end-users, they can now see the details that include the delivery status of every individual voucher of a particular order. Earlier it wasn't possible as they were restricted to see the details of the entire order as a whole.
## Multiadmin (Earlier Releases)
With the new product release features, our primary focus was to make our product as flexible as possible for our clients and their end-users. With this new feature, We have added the multi-admin feature which will allow the admin to add other people as the admins of Plum Dashboard so that they can Send Xoxo Points, Xoxo codes and check reports by themselves.
It, in turn, helps in the decentralization of the reward allocation process to subordinates involved. Having shared access leads to faster transactions and more efficiency.
This is how it would work:
* The person who created the client's account in Xoxoday Plum acts as the super admin of the company.
* The super admin can add/remove other people as admin and grant them access to rewarding.
* The super admin can set up a maximum reward limit for each admin such that they cannot go beyond the threshold limit.
* The admins are permitted to send Xoxo codes, Xoxo points, and check reports.
## SMS for Xoxo points
We have simplified the process of redeeming rewards by introducing SMS for Xoxo points and vouchers. The end users can now receive xoxo points, xoxocodes and brand vouchers on their mobile numbers, along with a redemption link that will redirect them to a specific page where they can redeem their reward as shown in the above image.
The focus on this month's product release has been flexibility and simplification of Plum such that both our clients and their end-users are happy. We have introduced seven features to make our rewarding platform faster and more efficient. Hope it helps you in delighting your end-users.
# Release March 2021
Source: https://help-plum.xoxoday.com/product-updates/release-march-2021
Read the Plum product update for March 2021, covering new features, improvements, and fixes shipped that month.
This March, we have six major updates for our users. This product release is well balanced in terms of improvements to our end-user storefront and the admin rewards dashboard. We hope these improvisations will help you deliver rewards effortlessly, and deliver on your business goals.
**Here are more details about the updates:**
## Improved user experience in the admin dashboard
Concerning Xoxoday Points and Xoxoday Codes, users mentioned a clunky & cluttered-looking form that had a lot to put in before they could get started, and it sometimes made a simple process seem overwhelming.
We couldn't keep ourselves calm knowing that! We have introduced a new dialog box (shown in the image below) wherein all the information for a single user is collected, allowing to focus on the information put in, and there is room for description for each input field with an ability to edit the information at any time.
With the new update, The UI/UX for the aforementioned sections in the admin dashboard has been revamped to reduce clutter and make it easier for Reward Admins to distribute rewards.
## New Feature: Scheduling Rewards Distribution
Earlier, you might have faced some issues in terms of scheduling Xoxo Codes and Xoxo Points from the dashboard. With the new update, The scheduler functionality has been reintroduced for both bulk and single sending. It is now easier than ever to schedule rewards via Xoxo Codes and Xoxo Points. Now, you can distribute rewards for single/multiple recipients at a later date by selecting the date from the calendar. If left unchecked during the campaign, the rewards will be distributed instantly.
## It is now easier to distribute Xoxo Links en masse
As more and more users are exploring Xoxo Links, requests were pouring in for bulk uploading recipients to send out Xoxo links. With the new update, there are no more restrictions when it comes to uploading recipients in the Xoxo Links section. You can now upload the entire list of recipients using the prescribed CSV template and deliver Xoxo Links en masse. The functionality also allows you to send a personalized message for each recipient by adding the CSV file message and uploading it in the section as shown in the image below.
## Sleek and revamped look for the Storefront
For end-users who sometimes had a hard time navigating through the cart and felt the UI was a bit clunky, this update is for you. The upgraded look for the Storefront aims to provide a much better user experience for the end-user. The changes include an updated representation of the gift voucher section, landing page, a cleaner listing of categories, removal of the perks section, and simplifying the header and footer options. It is also easier for end-users to now checkout directly from the cart.
## Scheduled Rewards have a new home
If you had to navigate multiple sections in the admin dashboard to check the reports for scheduled Xoxo points and Xoxo Codes, we have made it simpler for you to view the data.
The Xoxo points and Xoxo codes that were scheduled can now be viewed in the respective reports section. This allows you to check the reports in a single destination and understand the usage patterns easily.
## Users who have integrated Plum with third-party tools can distribute rewards via links
For Plum users who have integrated with third-party platforms, now you can send rewards in the form of links embedded in the recipient email.
A preview of the email and reward redemption page with link-based redemption is shown in the image below. With the latest update, distribute rewards via link-based redemption on the platform of your choice.
That is all for this product release! Have a question? Reach out to us [here](https://support.xoxoday.com/support/tickets/new)
To set up a demo with a Plum Specialist, please sign up [here.](/product-updates/release-march-2021)
# Release March 2022
Source: https://help-plum.xoxoday.com/product-updates/release-march-2022
Read the Plum product update for March 2022, covering new features, improvements, and fixes shipped that month.
This March, we have undergone a few major changes on both the plum admin side and the store.
On the integration side, we have improved Hubspot integration now Xoxoday plum passes reward automation campaign activities into Hubspot CRM via Custom events into Hubspot CRM, there is now with the admins to edit any existing automation created by the admin for the integration rewarding.
Here are more details about the latest update:
## Mobile Only rewarding
The admins now will be able to reward only on the mobile number of the recipients without having to input a mandatory email ID. This adds a lot of flexibility while rewarding across all modes of distribution (Xoxo Points, Xoxo Codes, Xoxo Links, and Plum Pro). In the case of Xoxo Points and Xoxo Codes, the same number/email can be rewarded from multiple accounts. In case of non-delivery, the reward can be resent as well to the same mobile numbers from under reports.
## SMS Delivery Status in reports and resending to only mobile
With integration with our SMS service partner Kaleyra, we now are able to show the delivery status of individual rewards for Xoxo Points and Xoxo Codes via SMS. This brings in transparency to the entire rewarding experience and is critical for admins to understand the status of their rewards sent.
## Download high volume of records
Up until now, when the admin tries to download reports, if the number of records is high, it would take a long time to process and the download to complete. There was also a possibility of the process getting timed out due to large volumes. We have now optimized the process so that the admins do not have to wait around for the downloaded data. If the number of records is more than 10K, an email is triggered to the admin with the downloaded data attached as excel.
## Revamped Plum Pro report
It's convenient for clients to do reconciliation as:
* new fields have been added - **Discount (%), Amount charged, Quantity, Product ID, Delivered Date**
* user can filter reports by newly added fields
* Downloaded report contains numeric fields in a separate column from currency making it easier to do calculations.
## Other Improvements
Admins now have the ability to sort across reports by various columns like last redeemed date, sent date, Recipient Name etc. We also follow a consistent number system across the admin portal.
## Storefront
### Mobile login
Earlier email ID was mandatory for logging in to the storefront in order to redeem points or codes. After this release users will be able to create accounts/log in with their mobile numbers with OTP verification. This is a big step towards expanding the reach of the Xoxoday redemption audience.
## Integration
### Improved Signup Journey
The signup journey for integration was earlier long and had multiple steps. Now the integration sign-up journey is improved and made more interactive for the new clients getting onboarded from the respective integrations like HubSpot, Qaultrics, Zapier, etc.
Qualtrics SDK: In the release, developed a custom plugin to interact with the Qualtrics product using the Extension SDK. We are using 'Actions SDK' that can be part of a Qualtrics workflow, wherein a customer can easily set up a 'Reward automation' by selecting 'Xoxoday Plum Extension' workflow, within the Qualtrics UI.
This SDK release aims to bring the following advantages, XM Extension benefits to Xoxoday and our customers:
* Discoverability: Qualtrics users can discover your XM Extensions either in the Qualtrics marketplace or within XM OS itself.
* Seamless UX: XM Extensions are embedded into, making set-up and management intuitive easy, and accessible directly inside the Qualtrics environment.
* Retain customers via building more native features, rewarding solutions, and increased product usage.
# Release March 2025
Source: https://help-plum.xoxoday.com/product-updates/release-march-2025
Read the Plum product update for March 2025, covering new features, improvements, and fixes shipped that month.
*Latest from our world of Rewarding*
We've rolled out new features to enhance your Plum experience! Now, you can enjoy lounge passes on the Plum Storefront, making travel more rewarding than ever. We've also introduced easy order tracking for merchandise, so you'll always know where your orders are. Plus, our smoother, faster checkout experience ensures every transaction is effortless. And don't miss our new Salesforce authentication integration, designed to provide seamless, secure, and efficient access. These updates are all about giving you a smarter, more rewarding experience with Plum!
## Here's what's new:
### 1. Easy Order Tracking on Merchandise
It is simpler to track your merchandise orders now! A new order status has been added to keep you updated on your shipments. For select orders, you'll now receive a direct tracking link so you can easily check the real-time status of your delivery. This means quicker and more convenient shipment updates, all at your fingertips!
### 2. Salesforce Authentication Integration
We've implemented Salesforce authentication to enhance system security and streamline API communication. This feature allows the storage of access and refresh tokens and includes a mechanism to automatically refresh the access token before making Salesforce API calls. This ensures seamless, uninterrupted access to Salesforce data, enhancing overall performance and security.
### 3. Enhancing the Checkout Experience with Cross-Currency Insights
We've improved the checkout process by adding notifications for cross-currency transactions. Users with a lower point balance than needed for a specific currency will be notified to complete the remaining amount with points or alternative payment methods.
### 4. Access Airport Lounges with Ease!
Lounge Passes are now available for all major airports on the Plum marketplace. You can purchase lounge access based on your flight departure date and preferred lounge by redeeming reward points. Enjoy a comfortable and premium pre-flight experience with seamless booking—making travel more convenient and rewarding.
## Upcoming features
### Airmiles - A New Way to Redeem Rewards
Get ready for a new category on the Plum marketplace featuring popular air miles programs. Soon, you'll be able to seamlessly transfer miles by redeeming your reward points—making it easier than ever to turn your rewards into travel opportunities.
### WhatsApp for Reward Distribution
We will be adding WhatsApp as a new channel for reward distribution on Plum! Alongside Email and SMS, businesses will be able to seamlessly send rewards directly via WhatsApp.
### Charity on the Reward Marketplace
We'll introduce Charity as a new category on the Plum reward marketplace. This feature will allow users to donate their reward points to a charity of their choice.
# Release May 2020
Source: https://help-plum.xoxoday.com/product-updates/release-may-2020
Read the Plum product update for May 2020, covering all the new features, improvements, and fixes shipped that month.
*Enhance Your Rewarding Process With May 2020 Plum Release Features*
The May product update from Xoxoday Plum comes with handy upgrades to make the rewarding process seamless. With simplified user flows, new integrations, new email templates, and beyond, this Plum release offers a better user experience for both platform admins as well as end-users.
## All-new Campaign Dashboard for monitoring the rewarding process
Managing reward campaigns was previously a disconnected experience for the admins with having to navigate between different screens to view campaign details. With an intuitive redesign of the campaign dashboard, now the Plum admins can monitor the status of their reward campaigns seamlessly from a single interface. The dashboard displays the voucher redemption rates, status, and actions of every campaign that they have run.
## An Improved Campaign Creation Interface
The new Xoxoday Plum campaign creation user interface helps admin users to quickly select catalog categories. The interface provides category tags and checkboxes to easily configure reward campaigns and thus quicken the campaign creation process. This UI improvement allows admins to easily verify their campaign selection to configure it more accurately and efficiently.
## Customize The Reward Campaign Emails
With this release, Plum admins are given the option to configure the campaign email template as per their requirements. From the earlier standard email template that sent out the voucher codes to recipients, the admin can now tailor-make these emails with personalized messages and designs. This customization capability helps admins make the rewards more meaningful and personal to the recipients thus making it more effective.
## Integration With Payu Payment Gateway Made Seamless
[PayU, a global payment gateway](https://payu.in/) that provides an array of payment options is now available seamlessly during purchase to Plum end-users. PayU offers one of the industry's highest security and payment success rates, multiple payment options, and round-the-clock support. This update helps users use the robust PayU gateway to make their purchases through the payment mode of their choice.
## Integration With Webengage For Push Notifications
Xoxoday Plum integrates with WebEngage to engage the end-users better and help them stay updated on the new catalog offering. From having to scroll through a catalog of 21,000+ offerings, now the users are informed of new listings based on their interest through web and email push notifications. The integration aims to enhance the user experience of discovering a highly relevant offering for reward redemption.
## Paypal As A Payment Option Is Live
Xoxoday Plum users now have an option to pay via Paypal, one of the world's leading online payment portals for easy checkouts and fast processing. PayPal offers one-account mobility which can be used all around the globe - thus helping the users have a seamless redemption experience.
## Improved Admin Experience While Generating Xoxo Redemption Links
Xoxoday Plum admins can now create and send out rewards with link-based redemption options to recipients from a quick-to-use interface. This interface gives the user the option to quickly choose the reward campaign, recipients, and authentication methods. The link-based redemption feature helps in the easy distribution of rewards and perks, making Xoxoday Plum versatile for various rewarding use cases.
## Catalogue Expansion With New Global Offerings
Just like every new release, the Plum Storefront catalog keeps expanding to foray into new geographies and demographics. We work to constantly work towards improving our catalog offering with global vendor partnerships - to enrich the global redemption options for our end-user.
Here's a list of additions in the Xoxoday Plum catalog in the month of May:
[To make the most of these additions, access our vast Catalogue at the Xoxoday Storefront>>](https://stores.xoxoday.com/marketplace/vouchers)
To see the Plum May 2020 feature updates live, [book a demo](https://www.xoxoday.com/book-a-demo) or contact us now!
# Release May 2021
Source: https://help-plum.xoxoday.com/product-updates/release-may-2021
Read the Plum product update for May 2021, covering all the new features, improvements, and fixes shipped that month.
This May, we have several updates for admins and end-users. For admins, the entire platform has been upgraded with several UI/UX changes.
An expanded catalog and a new user interface for the Storefront users make it easier for them to redeem rewards seamlessly.
Here are more details about the new update:
## Seamlessly upload recipients en masse in the admin dashboard
Admins told us that they were not getting feedback on the status of the file uploaded or what percentage of the records were being processed.
With the latest release, the bulk upload process has been revamped, helping admins understand what went wrong with the upload. Admins can upload up to 10000 records in a single file and rectify the errors before sending the file to processing. They can also track real-time status on the percentage of successful uploads in the contact list.
The added checkpoints such as "Uploaded File Name Check," "Bulk Upload Progress," etc., will ensure that the entire process is as smooth as possible.
## Enhanced UI for admins
With this release, the entire "Settings" section has been overhauled to make it easier for admins to distribute rewards. Earlier, there were multiple sections present for admin settings, making it hard to navigate. There is now proper segregation in Platform Preferences into "Profile," "Storefront," and "Rewarding and communication."
The option to move to the Storefront and view profile details can now be accessed by clicking on the Account Name on the top right corner.
A single section now defines the platform's usage for admins and manages multiple admins in the dashboard. The default landing page and "Wallet Balance" section have also been remodeled to make it easier for the admins to view and send rewards.
## Ability to customize SMS in the "Xoxo Points" and "Xoxo Codes" section
It was earlier not possible for admins to view the SMS sent along with the reward.
The latest update lets an admin preview the SMS before it is sent to the end-users; he/she can also customize and add a personalized message to the recipient when the SMS is delivered. The admin can also tailor the message as per the campaign.
In the "Reports" section, the SMSes can be resent at any point in time. The status of the distributed rewards via SMS can be viewed by just searching for the phone number here.
## Updates under "Platform Settings"
The new update lets the super admins choose to make the overall balance of the company wallet visible/hidden to the other admins. This feature was a request from multiple enterprise clients running large reward programs, with each admin responsible for their reward budget.
A Tax ID form and the option to reconfirm the details have been introduced to enable error-free Tax ID update in the platform. It is mandatory to fill in tax ID for a recharge or rewarding transaction in the platform and is a one-time setting essential for billing purposes.
"Reset to last save" feature enables the admin users to make changes and revert if need be.
The overall organization and grouping of each setting for admins have been made more intuitive.
## Easier checkout with enhanced UI for Storefront Users
Storefront users told us that they were adding products unintentionally while checking out.
With the latest update on adding a product to the cart, the user is directed to the "Go to Cart" button making the user's overall redemption journey more conversational.
This also reduces the possibility of the user adding multiple quantities of the same product unintentionally.
## Expanded Catalog in the Storefront
With four new additional vendor integrations, Storefront users can now enjoy access to a broad catalog covering new brands and geographies.
Plum marks its presence in Canada and China with this release. Plum has also expanded its US and New Zealand presence with 100s of gift vouchers and incentives across categories.
## Xoxo Link personalization
Earlier, it wasn't possible to customize the email when the admin ran the campaign under the "Xoxo Links" section.
With the new release, the admin user can modify the Sender Name, Email, and Footer of the email to customize the campaign as per his/her needs.
That is all for this product release! Have a question? Reach out to us [here](https://support.xoxoday.com/support/tickets/new)
To set up a demo with a Plum Specialist, please sign up [here](https://www.xoxoday.com/book-a-demo)
# Release May 2022
Source: https://help-plum.xoxoday.com/product-updates/release-may-2022
Read the Plum product update for May 2022, covering all the new features, improvements, and fixes shipped that month.
This May, we have undergone a few major changes on the plum admin side.
On the integration side, we have improved Migration of our Hubspot app to granular CRM scopes, 'Preview Module' for ZohoCRM and Salesforce etc.
Here are more details about the latest update:
## Plum Admin
### Collection of user redemption details with Xoxo Links
With the new release, clients will now have the option to collect the recipient's email ID/phone number during redemption. This gives immense value to those running marketing campaigns and consumer promotions, as they can now have complete insight into who has redeemed the reward. This data is available in reports for both rewards sent directly through the platform, via integrations, or by generating many links for the admin and sending them out later.
### New Campaign Page
We have completely redesigned the campaign page by taking a completely different approach that optimizes to show precisely what brands are available and gives the user a clear indication of the country selected, the categories selected, and the number of products chosen, all on a single screen. This new campaign feature works with Xoxo Codes and Links.
### Status integration of Xoxo Link reports
The new reporting filters were added to give complete insights into the reward redemption process to the users running marketing campaigns or consumer promotions via Plum. You can view the details under Reports > Xoxo Links > Individual Link > View details.
### Unsubscribe for low balance notifications
We have added an unsubscribe notification in the emails. The link is generally visible at the bottom of the notification email. If you don't want to receive a particular notification, you can choose to unsubscribe from all the low balance notification emails.
### Editing sender's email ID
In many instances, the reward emails were going to spam or not delivered when the sender's email ID was changed. Now we have restricted the sender email ID to be [notifications@xoxoday.com](mailto:notifications@xoxoday.com) by default (for new accounts), and if it needs to be edited, the admin needs to reach out to Xoxoday.
### KYB restrictions for admins
To reduce a load of tech architecture and incidents of security issues, for all non-KYB verified accounts, we have now restricted the rewarding to a maximum of 100 recipients, five campaigns, and the addition of any other admin to the account up until the KYC is verified.
### Extensive account verification process in plum admin
In order to further optimize the KYB verification process and reduce KYB rejections, we have added new details like website domain, mobile number verification, and some other information in the verification process. Furthermore, any rejected account can not access their plum admin account.
### Other admin improvements
There have been improvements in payment report statuses, stopping the expired rewards resend and a few smaller issues.
## Integrations
### SAP Customers: Ability to set country-specific budget
Xoxoday now supports a smart multi-account architectural feature for users using SAP SuccessFactors. This feature enables the ability to:
* Manage wallets and budgets in a decentralized manner for employees in different geographies.
* Plum accounts can be created for each geography, wherein the different admins can be assigned to manage wallets and budgets independently.
* Employees can redeem vouchers from their assigned geography.
### Changes to Existing Qualtrics Flow
We have improved the Qualtrics user flow to allow public survey creation from the Plum admin account.
### Migration of our Hubspot app to granular CRM scopes
We have migrated all the legacy contact APIs to newer ones with this release.
### 'Preview Module' for ZohoCRM and Salesforce
With our native integration with Zoho CRM, we released updates to the preview page within the Zoho CRM and Salesforce CRM applications. Now the preview page gets a consistent view with what is there in the Plum admin account to maintain consistency between integration and admin accounts.
### Automation Settings
The advanced settings (like Set maximum reward count, Set automation date range, and Allow repeat rewarding) were also made available for the 'manual' approval type.
### Extra fields in storefront Integration
This feature release works for SAP (country attribute) and Workjam for EmployeeID and BadgeID. We store this information from the TPD data and display it in the redemption history report.
### StoreFront Integration
This process is now seamless, and the client's developer team will be able to generate keys from the admin dashboard. Earlier, they would have to contact CS to do so, which leads to a significantly higher lead time to integration.
### Supply-side
Amazon direct integration for the US and Canada along with KYB is live. This would lead to margin improvement for Xoxoday. This won't impact existing clients as they can procure Amazon products as usual as KYB is already done with Amazon for them, and new clients can initiate KYB via the Admin dashboard.
# Release May 2024
Source: https://help-plum.xoxoday.com/product-updates/release-may-2024
Read the Plum product update for May 2024, covering all the new features, improvements, and fixes shipped that month.
In recent weeks, we've introduced an array of exciting features designed to enhance the user experience. These include the launch of our Points API, which empowers personalized engagement and seamless integration, automated reminder emails to ensure the success of your campaigns, and the introduction of the Payment Report API, providing detailed transaction histories. But that's not all – we're offering you an exclusive sneak peek at the features slated for release in the coming months.
## Launch of Points API
### Feature Overview
We are thrilled to announce the launch of our latest feature, the Points API, designed to elevate customer engagement strategies to new heights. This powerful API empowers customers to enable a points engine inside their mobile and web applications, creating dynamic point-based engagement programs tailored to their specific needs, including loyalty programs, employee engagement initiatives, channel partnerships, and influencer collaborations.
### Key Functionality
* Seamless Integration: The Points API facilitates the effortless sending of points and retrieval of point balances, allowing customers to seamlessly incorporate a points engine directly into their mobile and web applications.
* Versatile Applications: With the Points API, customers can leverage its functionality across a wide range of engagement initiatives, unlocking new opportunities to connect with their audience and drive participation.
* Personalized Engagement: By incorporating point-based rewards and incentives, customers can deliver personalized experiences that resonate with their audience, fostering stronger connections and lasting relationships.
* Security: To ensure enhanced security, the Points API features robust oAuth 2.0 authentication and IP address whitelisting. These measures are implemented to safeguard customer data and protect against unauthorized access, providing peace of mind for both customers and end-users.
* Redemption Opportunities: Points issued to end-users can be redeemed on Xoxoday's Global marketplace, offering thousands of brands across 90+ countries. This extensive marketplace makes the offering very lucrative, providing users with a diverse range of options to redeem their points and enjoy rewards that suit their preferences.
**Benefits:**
* Enhanced Engagement: The Points API enables customers to engage with their audience in a more streamlined and efficient manner, driving participation and fostering stronger connections.
* Flexibility and Efficiency: Customers can now create and manage robust engagement programs with ease, thanks to the flexible and efficient capabilities of the Points API.
* Improved Customer Satisfaction: By delivering value and rewards in a personalized and seamless manner, customers can enhance customer satisfaction and loyalty, ultimately driving business growth.
**Availability:** The Points API feature is now available to all customers, enabling them to unlock new possibilities in customer engagement. For more information on how to get started with the Points API, please refer to the documentation or contact our support team for assistance.
We are excited to see how our customers will leverage the Points API to create innovative and impactful engagement programs, and we look forward to supporting them on their journey to success.
## Reminder Email For Clients
This feature aims to send periodically reminders to all end users who have active rewards waiting to be redeemed.
It empowers clients with automated reminder emails ensuring better success rates of campaigns being run by the clients and that the rewards are redeemed by the intended recipients.
## Introducing Payment Report API
Reward API customers can now fetch the entire transaction history of an account. Transaction history data includes information on fund additions, deductions and refunds. This will help integrate with reporting tools and assist finance team during the monthly reconciliation process.
## Standardizing Order Delivery Status Events in Webhooks
Currently, Reward API customers have the option to select "Delivered" or "Cancelled" events for an order delivery. With our new update, Order Delivery Status events will be standardized. These events will be enabled by default if the Webhook Status is enabled. We will send all events related to Order Delivery Status to the Callback URL listed.
## Order Delivery Status Events to Now Include Refund Information
We have enhanced the webhook functionality by including refund information in the payload. Along with "Delivered" and "Cancelled" status events, we'll now include a 'refundStatus': 'Refunded' key in the payload. This event will be posted only when a refund is successfully added to the admin wallet.
## Notifications if Webhook Status is disabled
Admins can now get notified if the Webhook status is auto disabled if the Callback URL is not functioning, which will allow them to check the URL status and take further actions to rectify the issues. Immediate actions taken to rectify the URL will help users to receive the Order delivery status change events that they are dependent on to take actions related to order delivery in their user journey.
## Upcoming Features
### IP whitelisting via Admin Dashboard
Super admins will be able to add / update and delete the IPs from the Admin Dashboard to access the APIs and avoid the manual process.
### Merchandise via Xoxo Links
Admins will be able directly send a selection of merchandise for the users to choose from that will be delivered to the end users address.
### New improved DIY flow
The upcoming new DIY flow simplifies the process of creating an account and getting started with sending rewards. There is no separate business activation as it has been integrated as a part of the send rewards flow.
### Enhanced Email Capabilities
Admins will be able to format, add links in the messages and add a personal footer sent to the end users with the new email editing capabilities. They will also be able to set templates as default such that they do not have to make changes every time they login.
### Minimum Balance Notifications
To ensure smooth redemption of rewards, we will have automated notifications to the admins ensuring there is sufficient balance in the wallet for redemption.
### Enhancements in Reward API Reports
Super admins can now know which super admin / admin has sent the rewards. This helps the users to have visibility in their operations and reconciliation process.
### Track Order in Marketplace
Users in the marketplace will now track their orders by providing necessary information. They can view order details, check the order status, and access other relevant information.
### Enabling WhatsApp for Verification Process
We are introducing WhatsApp as a secondary channel for delivering verification OTP messages to users. This addition aims to enhance delivery rates, expand coverage across various regions, and optimize costs.
# Release May 2025
Source: https://help-plum.xoxoday.com/product-updates/release-may-2025
Read the Plum product update for May 2025, covering all the new features, improvements, and fixes shipped that month.
*Learn about Product Updates for May 2025*
**Latest from our world of Rewarding**
Here's a quick roundup of what's new, what's improved, and what's coming soon on Xoxoday Plum. From better control over rewards to new ways of sending them, we've been building features that help you create more impactful reward experiences.
## Here's what's new:
### 1. Charity is now on the reward marketplace.
We're excited to introduce Charity as a new category on the Xoxoday Plum reward marketplace! Users can now donate their reward points to a cause they care about, supporting verified charities across different geographies.
Here's how it works:
* Choose the charity you want to support
* Decide how much you'd like to donate
* The equivalent reward points will be deducted automatically
### 2. Campaign management in Rewards API
Managing product catalogues just got easier.
Admins can manage catalogues by category and campaign without fetching the entire list using the Get Voucher API. Instead, they can retrieve updates for only the selected products included in a campaign, reducing effort, improving performance, and giving more control over the reward experience.
### 3. Tazapay payment gateway for SEA region
Smoother, localized payments are now live for Southeast Asia.
We've integrated Tazapay, a localized payment gateway for SEA users for smoother payments for Southeast Asia.
With Tazapay, users get
* Multi-wallet support
* Local currency transactions
* A frictionless redemption experience
## Upcoming features:
### Mobile top up as a marketplace category
Users will soon be able to recharge mobile numbers by selecting preferred plans and paying seamlessly using reward points.
### WhatsApp as a reward distribution channel
Alongside Email and SMS, businesses will soon be able to send rewards directly via WhatsApp.
No extra steps—just faster delivery right where your users are.
### Custom expiry dates for rewards
Admins will have the ability to set custom expiry dates for rewards.
No more fixed timelines—just more flexibility to align with your campaign.
# Release November 2021
Source: https://help-plum.xoxoday.com/product-updates/release-november-2021
Read the Plum product update for November 2021, covering new features, improvements, and fixes shipped that month.
This November, we have undergone a major revamp of the reports section on the plum admin portal.
Admins will now be able to send rewards confirmation mails and cancel rewards in bulk which saves their time and energy in doing the process one by one earlier.
Admins will now be able to filter the reports according to their own requirements which helps them understand the ROI of the reward program more efficiently.
**Here are more details about the latest update:**
## Bulk Cancellation of rewards
Now admins will be able to cancel the reward in bulk. Select all the users for whom you want to cancel the rewards and click on the Cancel reward button as shown below:
## Resend confirmation mail in bulk
Now users will be able to resend the reward email in bulk. Select all the users you want to send the confirmation mail again and click on the **Resend details** button as shown below:
## Filtering the report section according to your own requirements
* You can filter the entire report based on **recipients name, email, phone, reward sent, sent by** and other fields in the table.
* You can apply the filter and then view the specific reports according to your requirements which helps you understand the **ROI of the reward program** much better.
* The filtered report can also be downloaded and sent to super admin email id and shared internally.
# Release November 2025
Source: https://help-plum.xoxoday.com/product-updates/release-november-2025
Read the Plum product update for November 2025, covering new features, improvements, and fixes shipped that month.
*Get updates on Xoxoday Plum*
**Latest from our world of Rewarding!**
We've rolled out new updates to make your experience smoother and more versatile. This month, we are introducing high-frequency utility payments to drive user engagement, alongside specialized governance tools for our enterprise partners.
## Here's what's new:
### 1. Pay essential bills with the new Utility Category on Xoxoday Plum Pro API
The Utility category is now live! Your users can now pay essential bills such as electricity, water, gas, internet, and mobile postpaid directly using the Xoxoday Plum Pro API. With real-time bill fetch and instant payment confirmation, businesses can offer seamless monthly bill payments without adding new integrations or operational overhead. This brings a practical and high-frequency use case into your rewards ecosystem.
### 2. Strengthen governance with Maker-Checker workflow
For organizations that require stringent audit trails, we have introduced a Maker-Checker workflow on the Xoxoday Plum platform to enforce stronger governance. This workflow is currently enabled for select critical flows including User Management, Catalogue Management, and Discount Voucher Management. In these areas, any key admin action requires secondary approval. This ensures compliance, reduces risk, and prevents unauthorized or accidental changes.
This capability is currently available to select Enterprise Pilot partners and will be rolled out more broadly in upcoming phases.
### 3. Run smart promotions with Dynamic Voucher Management
Marketing teams can now independently create and run Discount Coupon Campaigns by distributing coupons to select customers or prospects. This module provides granular control over discount types, usage limits, and campaign validity. It allows marketing teams to tailor each promotion to the right audience within Xoxoday Plum. The dashboard enables teams to configure and deploy agile promotions instantly without relying on backend support for voucher creation
This feature is currently available to select Enterprise Pilot partners and will be rolled out to wider audiences in upcoming phases.
## Upcoming features
### Rate limiting for Xoxoday Plum Pro APIs
We'll be implementing rate limiting across key Xoxoday Plum Pro APIs to improve stability, prevent abuse, and ensure fair usage. This enhancement will apply client-based limits managed through MongoDB for flexibility and better performance control.
### Real-time gift card catalog updates
We'll be implementing webhooks for Xoxoday Gift Card APIs to notify customers in real time about product updates such as enable/disable status, denomination changes, and other catalog modifications.
Need help? Reach out to your support team or [cs@xoxoday.com](mailto:cs@xoxoday.com).
# Release October 2021
Source: https://help-plum.xoxoday.com/product-updates/release-october-2021
Read the Plum product update for October 2021, covering new features, improvements, and fixes shipped that month.
This Holiday Season, we have several new updates for Xoxoday admins, and most importantly for the Storefront users.
For admins, they can now easily customize messaging, classify data more easily, and get a more DIY-friendly experience.
There are also other updates including an expanded catalog and a better reward redemption experience.
## For Admins
### A New Campaign Landing Page for Xoxo Code and Xoxo Links
It was earlier not possible for admins to create a custom landing page and customize the messaging.
With the latest update, Admins will now be able to include a landing page along with their Xoxo Code or Xoxo Link rewards. End-users can redeem their rewards from the landing page directly.
This feature is also particularly useful during the festive season to offer a tailored branding experience and help administrators take control of the user experience. Admins can also choose to design the landing pages as they deem fit, and they are optimized across devices. They can also choose to remove the landing pages if need be.
### Xoxo Code Listing in Xoxo Links
We received feedback from a lot of firms asking us to include a Xoxo Code (unique reward code) whenever a reward link was sent across. This was because it was not possible for end-users in different geographies to redeem rewards with a link.
We heard you! With the latest update, admins can choose to include a Xoxo code along with every reward link sent.
This allows recipients from all geographies to redeem the Xoxo code by using our Storefront and purchase any product with the denomination and country of their choice.
### Bulk Selection and Cancellations in Xoxo Codes and Xoxo Points
With the latest release, Admins will be able to select multiple entries for Xoxo Points and Codes and take action on them together with a single click.
### Plum Pro SMS Customization
In alignment with our larger goal of letting admins customize their reward experience for the end-user, we are now letting Plum Pro users customize their SMSes that accompany rewards.
The SMSes sent along with a Plum Pro reward can now be customized to include tailored messages for the recipient. This feature is available both in single and bulk rewarding.
### Create advanced filters in the Plum Pro report section
It was earlier not possible for admins to set up advanced filters within Plum Pro to classify the products.
With the latest release, a new set of flexible filters have been introduced which allow the admins to specifically drill down to any set of data within the records listed - by date range, by product, by reward value, by the recipient, or a combination of any of these.
### Introducing email delivery status of rewards
For the first time, the admins will now be able to directly get insights on the delivery status of emails for each individual recipient.
This will enable them to take the action of resending the email or canceling the rewards based on the delivered status. This also significantly reduces the need for manual intervention by Xoxoday's team to check the email delivery status and report back to the customer that has requested it.
### Digital invoices can be downloaded from the platform
To enable admins to download the invoice directly from the platform, we have now introduced the feature to let admins download a digitally signed copy of the invoice generated after every recharge of the Xoxoday Plum wallet, either vis-a-vis the platform or through sales orders.
An immediate acknowledgment is also sent to the client whenever a recharge is done.
### New banners have been introduced across different rewards modes
Keeping in mind the upcoming festive season, a plethora of new banners have been added to the admin portal. All the banners have also been optimized to render without stretching/distortions across all browsers and devices.
### Improvements in Integration Automation Flow
The latest update has upgraded the integration flow for 3rd party integrations such as SurveyMonkey, Hubspot, and others. There has been an improvement in terms of experience and the user journey.
Admins will now be guided throughout the automation process with appropriate steps, suggestions, and informational pop-ups.
### Improvements in DIY onboarding journey
With the new release, the 3 step Xoxoday DIY admin sign-up process is made more interactive and smoother. Improvements here include auto-redirect after a step is a complete, correct balance on the dashboard, and improvements to the KYB workflow.
## API Updates
### Multiple PayTM products can now be added to the cart
We had a quantity restriction for Paytm products in storefront & API, allowing users to only purchase one quantity at a time. With the latest update, this restriction has been removed for mobile browsers as well.
### Plum Pro API: Error message for Duplicate PO is now updated
In Plum Pro API, place order endpoints update the existing error message for Duplicate PO with new meaningful errors so that developers can easily recognize what went wrong & take corrective measures.
### Plum Pro API: Introducing the ability for admins to get order history by using tags
We have introduced a new filter in Plum pro Order History API, this will allow users to filter the order data by "Tags".
### Exchange rate information can be accessed via GET VOUCHER API
Some clients wanted to get access to the information on the real time exchange rate that we use.
Hence, we have introduced a new filter in Plum Pro Get voucher API, to know the active exchange rate which Xoxoday uses for product cost calculations. These exchange rates can be used by clients to know the true cost of the product which they are going to purchase.
### Other improvements
A few other minor improvements in the API section include - handling of unknown special characters on the product description from vendor API, option to map multiple SKU for Giftery, and the ability to blacklist certain products for specific clients.
# Release October 2022
Source: https://help-plum.xoxoday.com/product-updates/release-october-2022
Read the Plum product update for October 2022, covering new features, improvements, and fixes shipped that month.
## Tracking opens for reward emails
With this feature, our Hubspot customers that use Workflow or 1-1 reward emails that are sent from Xoxoday will be able to see the 'open' events within Xoxoday and as well as inside their Hubspot's timeline for that contact. Furthermore, customers will be able to use these events inside their workflow and or list segmentation for additional 'actions' (such as triggering a follow-up, scoring, or internal notifications).
## Tracking clicks for reward emails
With this feature, our Hubspot customers that use Workflow or 1-1 reward emails that are sent from Xoxoday will be able to see the 'Clicks' events within Xoxoday and as well as inside their Hubspot's timeline for that contact. Furthermore, customers will be able to use these events inside their workflow and or list segmentation for additional 'actions' (such as triggering a follow-up, scoring, or internal notifications).
## Plum Admin
### Ability for the super admin to edit any campaigns
The Super admin will now be able to edit all the campaigns that are there in the account giving the flexibility to the super admin to be able to use any campaign even if the actual creator of the campaign is not available.
### Campaign improvements
Minor improvements in the campaign creation process has been included that gives clarity to the admin user on the brands, countries and denominations selected for the campaign.
### Xoxo link background customization
While creating a campaign admin will be able to customize the Xoxo Link to have any background color to reflect their branding needs by either picking from the options presented or by specifying the hex code. This was previously restricted to four predefined colors.
### Improvement in payment section of reports
Added reason for Deduction/Addition of Funds giving more clarity of movement of money.
### Enabled new payment processor
Enabled new payment processor for International currencies (except EURO and GBP), which would enable clients to do a wallet recharge in preferred currencies in real time via credit and debit cards (VISA/MasterCard) provided the cards are 3DS enabled.
## Catalog
### Experience Category launch
With this release we have now launched 700+ experiences across 30+ geographies across the world through direct experience vendor integrations. New experience added can be viewed [here](https://stores.xoxoday.com/marketplace/vouchers), under "Experiences" Tab.
## Plum Stores/Supply
### Amazon Merchandise launch on the Xoxoday catalog store (Only for India)
Now your end users can redeem their Xoxo points and codes on Amazon merchandise to buy products like electronics, accessories, appliances, and more. Admins can enable/disable the merchandise categories or specific products from campaigns under Plum Admin.
### Experience launch on stores marketplace
On Xoxoday stores, experiences have been re-launched with new global catalog categories. Anyone can use their Xoxo points or Xoxo codes to book experiences like adventurous sports, city tours, and many more. Admin can also manage (turn on/off) the experience category from the campaigns page in Plum Admin. In the experience section, Admin can also choose which products to show or hide.
# Release October 2023
Source: https://help-plum.xoxoday.com/product-updates/release-october-2023
Read the Plum product update for October 2023, covering new features, improvements, and fixes shipped that month.
We have a ton of collective knowledge to share with you! In the past few weeks, we've added new features to our Plum platform, including integrations, category and many other improvements for the admins. But that's not all we have revealed the new features expected in the upcoming months.
## Xoxo Reward Link Authentication
To enhance the security of Xoxo Reward Links sent from the platform, we will now send an OTP to the email ID / phone number to which the link was originally sent to, on redemption. This will ensure that only the intended recipient is able to access the reward.
This is applicable to all rewards directly sent to the recipient from the platform including the ones triggered via CRM / survey tools integration.
For Xoxo Reward Links that are "generated for self" by the admin to be distributed later, these links will not be tied to the specific email ID it is sent to, however the recipient will need to enter a phone number and verify with an OTP before redemption.
## Xoxo Reward Code Redemption options
While sending Xoxo Reward Code, now the admin can choose who can redeem the code: Either the recipient the code is sent to, any user with the same domain as the user, or anyone who has the code. This gives the admin the flexibility to choose who can redeem the rewards they send while enhancing security.
## Points-Based Marketplace
Introducing the ability to convert the reward marketplace into a points based marketplace. End users can now browse the catalog and checkout in the form of points. Businesses can set their own currency-to-points ratio, making the entire marketplace available for transactions in points. This feature is ideal for loyalty reward programs, allowing businesses to offer rewards in the form of points rather than currency. For example, if a business defines a 1:10 ratio, a product worth INR 10 on the marketplace can be purchased for 100 points.
## New Filters and Sorting in Storefront
We have added new filters and sorting options to the gift card category, enhancing the redemption experience for all storefront users. Now, users can easily filter and sort products based on their preferences.
## Enhancements to the Marketplace Interface
We've improved the overall look and feel of the marketplace to make it more user-friendly and aligned with e-commerce standards. This includes introducing new brand colors, enhancing navigation for better visibility, and more.
## Changes in getBalance API
As part of the standardization process, we have removed the "points" parameter from the getBalance API response as it was redundant and caused confusion during the integration process.
## Rewards API Report
To simplify the reconciliation process for the Finance / Business Team, we have now removed the currency symbol from the "Downloaded Report". This will help the admins to now just download the report and get a consolidated value without spending additional time in structuring the report to achieve the consolidated values.
## Invoices
All the Non-INR customers trying to make offline bank transactions for wallet recharge had to go through a manual process of reaching to request for an invoice by reaching out to the Sales POC / Finance team which would take 2 - 3 hours on average and customers had to follow up or wait during this time.
Now Customer's can generate a Proforma invoice from the Admin Dashboard by entering the value in the "Add Funds" Field.
For Customer's with base currency as Non-INR, who used to request Xoxoday Finance team to remove the company PAN and LUT number from the invoices shared, we have now removed PAN & LUT number fields from the Invoice for all the invoices that are being generated for Non-INR customers.
That's all for the Plum Product Enhancements launched in October 2023. If you have any specific questions, feel free to [contact us](https://www.xoxoday.com/company/contact-us), or [book a demo](https://www.xoxoday.com/book-a-demo).
# Release October - 2025
Source: https://help-plum.xoxoday.com/product-updates/release-october-2025
Read the Plum product update for October 2025, covering new features, improvements, and fixes shipped that month.
*Learn all about new releases on Plum*
## Latest from our world of Rewarding!
We've rolled out new updates to make your experience smoother, smarter, and more personalized. From custom storefronts and flexible redemptions to enhanced reports and secure order management, every update is designed to give you and your users more clarity, control, and engagement.
## Here's what's new:
### 1. Showcase your brand with custom categories in storefront
Make your Xoxoday Plum Storefront reflect your brand.
With the new Custom Category feature, create a dedicated section to display your own products, experiences, or vouchers exclusively for your users. Highlight your brand, run private campaigns, and deliver curated rewards, all within Xoxoday Plum's secure and scalable ecosystem.
### 2. Redeem your rewards as cash
Users can now redeem points as cash via UPI or Direct Bank Transfer (DBT) using the new Cashout Category. It makes the redemption process simple, secure, and fully integrated as users enter their details, choose an amount, and receive funds instantly.
This gives organizations flexibility to offer choice and convenience to employees, partners, and customers, while maintaining transparency and control through the Xoxoday Plum Admin Dashboard.
This feature is currently available in India and will soon be launched for users in the USA and EMEA regions.
### 3. Secure resends with OTP verification
We've added OTP verification to make resending order details more secure.
Earlier, users could request order details without confirming identity. Now, an OTP will be sent to the registered email or mobile, and it must be verified before details are resent.
If the reward was sent to both email and mobile, OTPs will go to both—and both must be verified.
### 4. Dedicated reports for perks and discounted marketplace
Admins can now access a dedicated report under Redemption Reports to track Perks and Discounted Gift Cards. View detailed, filterable, and downloadable insights, including total orders, value, savings, product name, category, discount percentage, savings amount, and redemption status.
This report makes it easy to track savings, measure engagement, and understand the impact of your perks program.
### 5. Enhanced reward-sending experience with use cases and occasions
The Send Rewards flow is now smarter and more intuitive. Admins can filter by Use Cases (HR, Sales, Marketing, and more) and Occasions (New Year, Holiday Gifting and more) to find the most relevant reward types, including Points, Codes, Links, Gift Cards, and Merchandise.
This update makes it easier to select and send the right reward at the right time, improving efficiency and relevance for every campaign.
### 6. PayPal Integration for Reward & Incentive Transfers
Users can now redeem their reward points or claim codes directly via PayPal, or businesses can transfer incentives/rewards to users' PayPal wallets through APIs.
This provides a seamless, secure, and globally recognised payout option alongside existing Xoxoday reward distribution methods.
## Upcoming features:
### Utility category via Xoxoday Plum Pro API
We'll soon be introducing a new Utility category in Xoxoday Plum Pro API, enabling users to make bill payments for electricity, water, gas, internet, and mobile postpaid directly through the API.
### Rate limiting for Xoxoday Plum Pro APIs
We'll be implementing rate limiting across key Xoxoday Plum Pro APIs to improve stability, prevent abuse, and ensure fair usage. This enhancement will apply client-based limits managed through MongoDB for flexibility and better performance control.
### Real-time gift card catalog updates
We'll be implementing webhooks for Xoxoday Gift Card APIs to notify customers in real time about product updates such as enable/disable status, denomination changes, and other catalog modifications.
# Release October/November 2024
Source: https://help-plum.xoxoday.com/product-updates/release-octobernovember-2024
Read the Plum product update for October and November 2024, covering new features, improvements, and fixes shipped.
We've recently rolled out several exciting features to improve the user experience. Key updates include a new flow for Festive Gifting, mobile OTP verification for enhanced security on Xoxo Link rewards, introducing an Intercom chatbot for accessible support, and upgrades to the Plum Marketplace with a refreshed homepage and optimized mobile interface.
These changes and many others are designed to make the experience seamless, secure, and efficient for admins and users.
## Here's what's new:
### New Flow for Gifting with Predefined Campaigns
We created a new, easy journey through Plum designed for clients looking to send festive gifts. It can be accessed right after login. The entire reward redemption journey is just a few clicks without having to select the distribution mode separately, create a campaign, craft emails, etc. All of this is predefined, including curated campaigns containing the most appropriate gifting products. All the admins needs to do is pick a gift selection and choose whom they want to send it to, and it is done.
### Mobile OTP verification for Xoxo Links Distributed via email
Customers can now add an extra layer of security by enabling OTP verification for the recipients' phone numbers when rewards are sent via email or SMS. This ensures that only the intended recipient can access the reward.
### Removed Case Sensitivity in Filters
Case sensitivity has been removed from the name, email ID, and notes fields in the report filters, making it easier for admins to find the specific records they need.
### Implementation of Chatbot In Plum Admin
Admins can use the new chatbot to get quick answers to their questions about Plum. The chatbot provides checklists for tasks like setting up an account, adding funds, sending rewards, and choosing a distribution method. Admins can also contact a team member with one click for further assistance.
### Reminder Email Enhancements
Reminder emails now include more details, like the expiry date, to encourage users to check out and redeem their rewards on time.
### Xoxo Link Order Delivery Improvements
Previously, if an order on Xoxo Link wasn't fulfilled immediately, the user had to remember to refresh the link periodically to check its delivery status. With this release, once the order is confirmed, it will be automatically delivered to the user via email or phone, even if it's in a pending state, eliminating the need to keep checking the status.
### Homepage for Marketplace
The Marketplace now has a new homepage with a better layout, making it easier to see all product categories. Users can easily browse through a variety of attractive products, improving their overall experience.
### Enhanced Interface for Mobile View of the Marketplace
The mobile version of the marketplace has been upgraded with improved pages for listings, products, and more. This update makes the redemption process smoother and convenient for mobile users, enhancing the overall experience.
### Improved Listing Pages on Web Interface
The product listing pages on the web interface have been improved to show more products in a single view, helping users make better choices and easily explore the full catalog. Filters and sorting options are now conveniently located in the top-right corner for easy navigation.
### Support to Collect Personal Information (PI) of End Users for B2C Brands
As per Indian regulations, it is now mandatory to collect personal details such as the recipient's first name, last name, phone number, and email address to process orders. This information is required to track redemptions for security purposes.
Applicable brands: B2C use cases, especially Amazon shopping and Amazon Pay vouchers.
### Bulk Resend Rewards for the Gift Card Module
Super admins can now resend rewards in bulk by selecting multiple orders from the report, saving time and eliminating the need to resend individual rewards.
### New Payment Options
We have now enabled PayPal and Mastercard prepaid cards as additional options.
Note: The Mastercard prepaid card requires additional KYB details to be enabled for your account.
## Upcoming features:
### Email and SMS Delivery Tracking
Admins will soon be able to track the delivery status of Emails and SMS with timestamps for each transaction. Resend activity will also be logged, providing full visibility to help better plan and manage reward resends.
### Wallet Recharge Alerts for Super Admins
Super admins will get instant notifications for successful wallet recharges, keeping them informed and ready to take action when needed.
### Reward API to support Airmiles and Perks
The Reward API will soon include Airmiles and Perks as redemption options, offering users more choices beyond gift cards. Admins can also process transactions via the API and track them in reports by category.
### Perks and Deals Category in Marketplace
We'll soon be launching a Perks and Deals category in our Marketplace, offering exclusive offers to enhance engagement programs and boost user participation.
### Currency Conversion Info for Stores
Users will soon see detailed currency conversion for their point balances when shopping in different regions, ensuring clear and transparent reward values across geographies.
## Want to request a feature on Xoxoday?
Get in touch with our customer success team at [cs@giift.com](mailto:cs@giift.com)
# Release September 2020
Source: https://help-plum.xoxoday.com/product-updates/release-september-2020
Read the Plum product update for September 2020, covering new features, improvements, and fixes shipped that month.
*Release Sep'20: Reward Automation, Email Templates & More*
This release of Xoxoday Plum comes with major features of scheduling reward campaigns, nudges and reminders on low balance, a brand-new customized email template, and much more. Read away.
## Admins can schedule automated rewards for a future date for timely rewarding
With Reward Automation, Admins can schedule rewards for a future date. These scheduled rewards can be managed in the "Scheduled Points/Codes" section in the Plum console. Automating a reward workflow substantially reduces the workload and ensures that the organization doesn't miss out on events and milestones. This feature makes Xoxoday Plum one of the best reward management software.
To take an example, admins can now schedule rewards for birthdays, wedding and work anniversaries, and other recurring milestones. In case there's a change in the schedules or recipients, they can choose the rewards that need to be canceled - before the date the reward was scheduled for. There's no need to keep the wallet filled from the day, rewards are scheduled, but these should be recharged before the scheduled date arrives - else the reward automatically gets canceled.
## Setting up Reward Automation
One can choose to either individually upload the list of email IDs while scheduling automated rewards or use the bulk upload option to choose recipients. The rewards can be automated for both Xoxo Points and Xoxo Codes and they will be automatically sent to the uploaded emails on the scheduled date without further work from the admin's behalf.
**Conditions**
One can schedule automated reward campaigns irrespective of the number of points in their wallet—as long as they recharge their wallets before the scheduled rewards are sent out. In cases where there's a lack of point balance and the scheduled time arrives; the rewards will automatically be canceled.
**Cancelling Scheduled Rewards**
**Admins can cancel the scheduled rewards at any time from the "Scheduled Points/Codes" section.** In case the scheduled rewards get canceled due to insufficient balance in the wallet, the admins will be notified via email. This brings us to the next feature added with this release:
## Get reminders to recharge the wallet & prevent bottlenecks in rewarding
With the new release, **Xoxoday Plum will send out notifications reminding the admins to recharge their company wallets on zero balance to ensure a seamless flow of reward redemption.** A low wallet balance severely interrupts the rewarding process - especially in cases where the rewards have already been sent out or scheduled.
The reminder notification will be sent again every three days in case the wallet isn't recharged to ensure there's no break in rewarding.
## New customized email templates gives every reward a personal touch
This month's Plum's improvisation includes customized email templates which bring about major changes in the way rewards are sent out to the users as the admins now have the full capability to communicate with their desired level of personalization. The new email even highlights the key purpose of why the reward is being given to the recipient. One can create a subject line that is relevant to their audience and add a short personal message.
The new email also hands out clear instructions for recipients as to how to use the reward, a reward description as well as terms of use, making it a handy piece of communication.
## Multi-admins of non-hierarchical accounts can now themselves add new admins, transfer funds & more
As introduced over our previous releases, Plum non-hierarchical accounts have reward wallets and distributions that are managed independently by multiple admins under the same organization.
In the previous feature's release, a non-hierarchical admin was given the capability of transferring their balance points to another from their company. **As an add-on capability, with this release, they can even in turn add and register a new admin on Xoxoday Plum.**
**For example, if an organization wants to add a new admin to take care of rewarding duties, any existing one can add them if they're registered on the organization's list.** Post addition, the current admin can even transfer their reward balance to the newly added one and they can delete their own accounts.
The operation, which was earlier taken care of from Xoxoday's end - speeds up the handover process.
## Users will only see the relevant catalog offerings for every demography for a smooth experience
To offer a definitive user experience at the Plum Stores, users will only see categories that offer options in the selected country. **Xoxoday Plum is a global platform with a unique gift catalog offering options from hundreds of countries.** For a few of these countries, our offerings are limited - while we are in pursuit of adding more catalog options.
If you have any options to suggest in your geography, feel free to talk to us at [cs@xoxoday.com](mailto:cs@xoxoday.com).
## Admins can toggle brands while setting up campaigns to avoid missing out
The new release offers a significant UI improvement in the gift catalog selection screen, making it much easier for admins to select, deselect, and view the brands chosen for a particular campaign while sending it over.
This improvement aims to help admins avoid errors during brand selection.
## End-users can check their Xoxo Code balance while checking out with an improved payment flow
When end-users check out and pay by Xoxo Codes, they can now use multiple Xoxo Codes for every transaction. Previously, however, there was no indication as to how much balance was left in every Xoxo Code before it was exhausted. **The Xoxo Codes balance can now be redeemed partially until it's fully exhausted and for every transaction, up to 10 Xoxo Codes can be used.**
With these improvements, the user will have better visibility of their Voucher and Xoxocode balances and also use multiple vouchers at one go.
## Other Storefront Improvements with this Release
With every release, Xoxoday tries to make the Plum Stores better than before for users and admins. Users can now view their Xoxo Points on the top right as soon as they log in. We have included selection highlights for the store categories. Many small and significant UI changes have been made for smoother user flows in Xoxoday Plum Store helping enrich the user experience. **Users can browse through all categories of the Xoxoday Plum catalog with the "View All" option straight from the homepage.** This helps them view the complete bouquet of offerings that the Store has to offer.
With the "How to Redeem" page, users can get all the information they need to use the Xoxoday Plum Store. With a step-by-step walkthrough guide of redemption, checkout, and Xoxo Codes, Xoxo Points, and delivery, users can get answers to all their questions here.
That's all for this features release in Xoxoday Plum. Have a question? [Talk to us.](https://www.xoxoday.com/book-a-demo)
# Release September 2021
Source: https://help-plum.xoxoday.com/product-updates/release-september-2021
Read the Plum product update for September 2021, covering new features, improvements, and fixes shipped that month.
Send anonymous rewards, change the shelf date for Xoxo Codes, and access a revamped Storefront UI.
This September, we have several new updates for Xoxoday customers and Storefront users.
For admins, the recharge flow has been completely revamped and comes with added security measures. They can also change the expiry date of Xoxo Codes depending on the use case.
For Storefront users, it is now possible to avail anonymous rewards and access a revamped Storefront.
Here are more details about the latest update:
## For Admins
### New Recharge Flow With Options Including PayPal
The earlier recharge workflow didn't include security measures such as OTP Verification and a Paypal payment gateway for international payments.
With the new release, we have completely revamped the recharge process and added multi-factor authentication to ensure that the process is safe. We have also added a Paypal payment gateway processing fee of 2% for international customers and the markup or discount % specific for that customer.
Customers will also be notified of the option of direct bank transfer on the screen itself.
In addition to these changes, a new requirement has made it mandatory for customers to submit a billing address and Tax ID for recharge above the threshold level and for any invoice generation.
### Variable Expiry Date For Xoxo Codes
A lot of customers requested the ability to change the expiry date of Xoxo Codes, especially when running time-bound campaigns.
With the latest update, customers sending Xoxo Codes as a mode of reward can now set an expiry to the Xoxo code as they choose. The options currently include one, three, six, and twelve months after the date of sending the reward.
These options are also applicable for Xoxo Codes that are scheduled to be delivered at a later date. This was previously not possible as Xoxo codes had a default expiry date of 1 year from the date of generation.
### Banner Customization
Admins had difficulties earlier when customizing the banner image of the reward emailers.
With the latest update, customizing reward emails while sending rewards has become much easier with the new banner selection screens. The admin will now be able to search for a particular banner, be it a holiday or a personal milestone, drill down into a particular category and explore several options.
They can also choose to upload their own images, which will be available with the filename in a separate folder for easier access.
### Admins Can Create/Edit Other Campaigns In The Organization
Earlier, it was not possible for different admins across the account to view, edit or access the details of each other's campaigns. This was a drawback especially when the customer was running an organization-wide campaign.
With this release, all admins will be able to view and select all campaigns available in the account. The campaigns also are completely editable in terms of allowing for product additions, product removals until redemption starts by the admin who has created the campaign.
## For End Users & Admins
### Anonymous Survey Rewarding
In the survey and market research industry, a lot of surveys are conducted in an anonymous fashion. While recipient rewards for anonymous surveys are very common, our earlier process didn't enable anonymous rewards for admins.
With the latest release, the anonymous survey rewarding feature has been introduced for Qualtrics ↔ Xoxoday integration, thus allowing an option to set up a Xoxo Link reward campaign without the need for providing any information on the survey. Admins can also set up a reward email collection landing page with basic customization.
### IP based selection of country code
The Storefront and admin dashboard has been revamped to enable IP-based selection of country code based on the feedback received from customers.
Both in Storefront checkouts as well in the admin portal, the country code will be automatically populated whenever there is a phone number entry required. This reduces the time in filling out details and faster completion of the checkout and reward setup process.
# Release September 2022
Source: https://help-plum.xoxoday.com/product-updates/release-september-2022
Read the Plum product update for September 2022, covering new features, improvements, and fixes shipped that month.
## Upload records in Bulk
With new-and-improved bulk upload capabilities, admins can save time and check the real time records as they gets processed. It's now easier than ever to upload the maximum records in a single file with fewer failures than ever before.
## Send global code in Xoxo links
The global xoxo code feature makes it quicker and easier for global companies to offer international catalog for end-users to choose from based on their local currency. You can combine the global xoxo code when sending Link-based campaigns, and end users can redeem it without worrying about conversion hassles.
## Admin Reports and Campaign improvements
A number of smaller improvements with both UI and the functionality for admin facing reports and the campaign creation page has been carried out along with the sprint that makes the admin journey smoother.
## Send direct-to-wallet rewards
Reach and engage users with the right reward at the right time by sending direct-to-wallet options in the reward catalog. Admins now have the freedom to reward how they want - with gift cards, with experiences, with direct-to-wallet options; you name it. You can now send the Paytm, and other direct-to-wallet options with Xoxo Link campaigns, which end users can then redeem after a successful verification.
## Track deeper insights with advanced reporting
For Plum PRO customers we have enabled report archival where the admins will be able to view all the records upto the last 6 months. If they wish to have data beyond 6 months, we have provided means for them to raise a request and the requested data will be sent over to their email id without any manual intervention. This is done to optimize the performance of the reports section. For non multi admin types of companies, we have also tweaked the reports to permanently address issues reported by clients on the data mismatch. We are currently showing the overall wallet balance as well to the admins accessing the reports section.
## Integrations
### Send 1 to 1 reward from HubSpot
Building the pipeline and acquiring the customers often feels like sales teams now need superhuman speed just to keep up. We are bringing one of the core HubSpot features to help drive sales growth.
Now, the HubSpot users can send the 1-to-1 rewards emails to the prospect within HubSpot. Our native HubSpot integration makes it easy for sales reps to send rewards directly from the contacts page and focus on effective conversations without any clutter getting in the way.
### Plum is available at Salesforce AppExchange
Embed rewards & incentives to your Salesforce CRM and grow your sales pipeline
* Send one-to-one rewards
* Automate rewards with triggers and workflows
* Powerful reporting and insightful analytics
## Catalog
### Stores Design Revamp
The overall layout and design of Xoxoday plum stores has been given a complete new overhaul to enhance redemption experience for all our end-users. Enhancements have been done to the mobile version, product pages and overall checkout flow.
## Payments
### New payment infrastructure for EU and UK regions
With the recent product release, we have integrated with a new and local payment processor "EMP" to ease the online payments and provide the best customer experience for EURO and GBP currencies. A new payments infrastructure enables admins to load funds into the wallet in real time using various credit/debit payment cards.
In Stores admin recharge section we introduced offline payment, which will help users to make offline payment & recharge their accounts automatically.
# Release September 2023
Source: https://help-plum.xoxoday.com/product-updates/release-september-2023
Read the Plum product update for September 2023, covering new features, improvements, and fixes shipped that month.
We have a ton of collective knowledge to share with you! In the past few weeks, we've added new features to our Plum platform, including integrations, category and many other improvements for the admins. But that's not all we have revealed the new features expected in the upcoming months.
## Xoxo Reward Code and Xoxo Reward Link verification
To make sure that the xoxo reward code is redeemed by only the intended recipients while keeping the current redemption flows just as seamless as possible, we have introduced an OTP verification sent to the recipient email ID/mobile number at checkout in the storefront.
In case of Xoxo Reward Link, for all links sent, an email ID or phone number will be collected mandatorily before the voucher can be redeemed.
## Bulk processing notification
A notification will be sent to the admin after a bulk file (for all modes: xoxo reward point, xoxo reward codes, Xoxo reward link, Xoxo rewards API) is processed, with the summary of records that are processed and the list of records that were unable to be processed, if any.
## PDF generation for Rewards API (Dashboard)
Admin users can now choose to generate a PDF form of the reward along with the email while sending brand vouchers directly from the platform.
This is highly useful when the vouchers are distributed in hand to the customer. We have built the capability for the brand voucher links to be rendered as QR codes. The user will be able to scan the QR code and quickly redeem the voucher removing all of the hassle of having to physically type it out / access the link to redeem.
Use cases like distribution of brand vouchers at the time of purchase in a retail outlet, or at an event in the actual venue can be made highly seamless with this.
## Pass Order details on Update Redemption API
Earlier, we required a lot of requirements from clients to also pass the order details that contained what products (along with other details) were redeemed. So, for that our backend is now ready to pass order data if required by the client on the Update Redemption API. So any Storefront clients who want Order data on Update Redemption API can create APIs accordingly.
Note: This is new standardization for Storefront Integration.
More details given in Integration doc: [/API-PLAYGROUND/Storefront-Integration-API/api-endpoints-1/update-redemption-api](/API-PLAYGROUND/Storefront-Integration-API/api-endpoints-1/update-redemption-api)
## New Category Launches: Lounge and Bike Voucher in India
The Marketplace has two new categories launched named lounges and bike voucher in india. Users can buy these products using reward points and codes.
Lounges are launched for India customers for cities such as Hyderabad, Chennai, Kochi, Bangalore, Mumbai and Delhi
Bike Vouchers are launched for India region and can be helpful for admins to send gifts to their employees and customers on different milestones. The brands added are TVS and Honda.
## Improvement in Admin Reports
Enhanced Payment Report & Rewards API Report that will allow users to have more transparency while reconciliation.
The Customers referring to the data in both Payment & Rewards API Report will see the data matching to their Internal reports and now can share the Admin access to their Finance team which will allow them to download the Rewards API report for reconciliation purpose without any delay.
## Invoice Generation
Admins can now request for Proforma Invoice from the Admin Dashboard and receive a digitally signed Proforma Invoice to their email.
This will help the admins to get the invoice immediately and initiate fund transfer without reaching out to the Xoxoday Finance Team, thereby reducing the time taken to get a Proforma Invoice from 3 hours to less than a minute. By this process the fund addition to the Customer wallet will be much faster.
# Release - September 2025
Source: https://help-plum.xoxoday.com/product-updates/release-september-2025
Read the Plum product update for September 2025, covering new features, improvements, and fixes shipped that month.
*Learn about the latest product updates on Xoxoday Plum*
**Latest from our world of Rewarding!**
We've introduced several updates to make your experience smoother, smarter, and more personalized. From easier invoice reconciliation and seamless order communications to customizable reward displays and branded emails, these enhancements are designed to give you and your users greater clarity, control, and engagement.
## Here's what's new:
### 1. Easier Invoice Reconciliation with PO Dates
Invoice reconciliation is now simpler and more accurate. Admins can manually select a PO date during invoice generation, ensuring alignment with the corresponding Purchase Orders. The selected date is stored in the system and displayed clearly on the invoice template, giving finance and procurement teams the visibility they need for smooth tracking and reporting.
### 2. Seamless Order Communications for Charity and Lounge
We've introduced key API improvements to make order transactions smoother and more transparent for both Charity and Lounge.
* Charity: The placeOrder API now includes an email field, ensuring that delivery emails are sent for every transaction.
* Lounge: Customers now receive delivery emails with dynamically generated QR codes, available both within the email and as PDF attachments for easy access.
These updates provide greater clarity, consistency, and convenience, enhancing the experience for both your team and your customers.
### 3. Custom Naming for Points is Here!
Admins can now personalize how points appear on the Xoxoday storefront. Whether you call them "Ace Points," "Coins," or "Credits," the platform will display your chosen terminology consistently across balances, redemption summaries, and confirmations.
This update ensures branding consistency and delivers a more engaging and familiar experience for your users.
### 4. Personalize Reward Emails with Your Brand Colors
Admins can now customize the background color of reward emails, aligning them with your brand identity. This added flexibility helps create a more engaging and visually consistent experience for recipients.
## Upcoming features:
### Cashout Option
Users will be able to convert their points into cash payouts giving them more freedom on how they use their rewards.
### Cashback Products
Users will be able to earn Reward points when they buy from partner offers, giving them rewards on every purchase.
### Reports for Discounted Marketplace
Admins will be able to view and download a dedicated report for perks and discounts, with filters and search options.
# Refer and Earn
Source: https://help-plum.xoxoday.com/referral-program/overview
Introduce a decision-maker at a new company to Xoxoday and earn cash rewards when the referral turns into a real deal — up to $10,000 per referral.
As an existing Plum customer, you can make a warm, professional introduction to a decision-maker at a company that doesn't yet use Xoxoday. Rewards are tied to real sales milestones — never to sign-ups — so a genuine introduction to the right person is all it takes to start earning.
You earn **\$100 in cash** when your referral completes a proper product demo, plus **10% of the deal's first-year value** (minimum \$250, maximum \$10,000) when they sign — up to **\$10,100 per referral**.
## How to refer
Submitting a referral takes under two minutes.
Open the referral form and submit your introduction in a couple of minutes.
When you submit, you'll receive a confirmation email and a **Referral ID** — a numeric ID (for example, `528606047984`) issued the first time you refer. If you've referred before, your existing Referral ID is reused: it identifies you as the referrer, not a single referral, so all your referrals are tracked under it. You then make the warm introduction over email, LinkedIn, or a shared meeting. The person you refer must agree to be contacted before our Sales team reaches out.
### What you need to provide
You only share what you already know — our team handles all further qualification.
* Company name
* Contact name
* Work email or LinkedIn profile
* Product of interest
* Your relationship with the contact
* Job title
* Phone number
* Notes or business context
* Preferred introduction method
## How the referral works
You submit the referral and receive a Referral ID and confirmation email.
You bridge Xoxoday and your contact. The referral moves forward once the contact agrees to connect.
The prospect sees the product in a genuine demo led by our Product or senior Sales team. Once confirmed, your **\$100** is released.
Solution design, security, procurement, and legal move ahead. No payout at this stage — we keep you updated by email.
When the MSA or first order is signed, you earn **10% of the first-year deal value** (minimum \$250, maximum \$10,000), on top of the \$100.
## What you earn
Your reward has two parts:
* **\$100** in cash for a qualified meeting (a proper demo). This is paid once the demo is confirmed and is **not** clawed back if the deal later doesn't close.
* **10% of the deal's first-year contract value** once it signs — with a **minimum of \$250** and a **maximum of \$10,000** on this portion.
Rewards are paid in cash by invoice or bank transfer. The deal must sign **within 6 months** of your submission to qualify for the 10% payout; the \$100 is yours either way.
### Worked examples
| Scenario | First-year deal size | Demo (\$100) | Signing (10%, min/max) | Total reward |
| ---------------------------- | -------------------- | ------------ | ---------------------- | ------------ |
| Mid-size deal, signs on time | \$50,000 | \$100 | \$5,000 | **\$5,100** |
| Small deal (minimum applies) | \$1,500 | \$100 | \$250 (minimum) | **\$350** |
| Large deal (maximum applies) | \$200,000 | \$100 | \$10,000 (maximum) | **\$10,100** |
| Deal signs after 6 months | \$50,000 | \$100 | \$0 (missed deadline) | **\$100** |
| Deal never closes | — | \$100 | \$0 | **\$100** |
**What counts as a "proper demo":** a genuine walkthrough of the product's core capabilities, led by our Product team or a senior Sales representative — not a casual intro or a scheduling call. Our team confirms the demo was substantive before the \$100 is released.
## Who can refer, and who you can refer
Existing Xoxoday customers who actively use the product, are in good standing, and have a genuine professional network. Typical referrers include Procurement, Finance, and Rewards leaders (Plum), HR leaders (Empuls), and Marketing, Loyalty, and CX leaders (Loyalife).
A referral qualifies only when the referred organization is:
* a **new company** — not a current Xoxoday customer on any product,
* **500+ employees**,
* **not already in an active Xoxoday opportunity**, and
* represented by an appropriate decision-maker or influencer for the product.
Existing customers, accounts already in an active opportunity, duplicate submissions, companies within your own corporate group, your own employer, self-referrals, and referrals where no genuine relationship exists.
## How your referral is tracked
You get **one Referral ID**, issued the first time you refer and reused for every referral you make afterward — it identifies you, not an individual referral. If you submit several referrals over time, they're all tracked under that same ID and distinguished by the referred company and contact. Each one progresses and pays out independently.
Every referral moves through these stages:
**Submitted → Introduction accepted → Demo completed → Proposal → Negotiation → MSA signed → Reward released**
There's no self-serve dashboard yet. You stay informed two ways:
* **Email updates** — we notify you proactively as each of your referrals advances, including at both reward milestones.
* **Support lookup** — contact Xoxoday support with your Referral ID any time to check the status of any or all of your referrals.
## Essential rules to know
* **Rewards gate on outcomes, never sign-up.** You earn \$100 on a qualified demo and 10% once the deal signs (within 6 months).
* **New companies only.** The referred company must not be a customer or already in an active opportunity.
* **First introduction wins.** If the account is already in our pipeline, or someone introduced it first, the referral doesn't qualify. A roughly 90-day lookback applies.
* **The person must opt in.** Your contact consents before Sales makes contact — this keeps it a warm introduction, not cold outreach.
* **Genuine relationships only.** No self-referrals and no referring within your own corporate group.
* **One Referral ID per referrer.** If you refer several companies, they all share your single Referral ID — each referral is still tracked, qualified, and rewarded separately.
### If your employer doesn't allow cash rewards
If your company's policy doesn't allow you to personally accept a cash referral reward, you still have options. You can:
* **decline** the reward entirely,
* **donate** the value to a charity of your choice, or
* **apply it as credit** — if your company is an existing Xoxoday customer, use it as a discount on your next SaaS renewal or as a wallet-recharge credit.
**Tell us your preference before the first payout** (at the demo milestone). This choice covers both the \$100 and the 10% payout, and it can't be changed after the first payout has been made.
***
For the complete rules, eligibility criteria, attribution, tax, and payout terms, see the [referral program terms and conditions](/referral-program/terms).
# Referral program terms and conditions
Source: https://help-plum.xoxoday.com/referral-program/terms
The complete terms of the Xoxoday customer referral program — eligibility, attribution, reward payout, taxes, fraud, and program changes.
These terms govern the Xoxoday customer referral program for existing customers of Empuls, Plum, and Loyalife. For a plain-language overview of how the program works and how to refer, see [Refer and Earn](/referral-program/overview).
**Reward in brief:** a flat **\$100** cash for a qualified meeting (proper demo), plus **10% of the deal's first-year contract value** once the MSA is signed — with a **\$250 minimum** and **\$10,000 maximum** on the 10% portion. The deal must sign within **6 months** of submission to qualify for the 10% payout; the \$100 is kept regardless. Submission alone earns nothing.
## Summary of key clauses
* **Eligibility** — the referrer must be an existing customer; the referred organization must be a new company with 500+ employees and an appropriate decision-maker.
* **Attribution** — first successful introduction wins; duplicate referrals are ineligible; a Referral ID is issued once per referrer (not per referral), reused across all of that referrer's referrals, and is non-transferable.
* **Reward and payout** — \$100 cash at the demo milestone, plus 10% of first-year deal value on signing (minimum \$250, maximum \$10,000 on this portion), paid by invoice or bank transfer. The deal must sign within 6 months of submission to qualify for the 10% payout.
* **Fraud prevention** — self-referrals, fake organizations, false contact information, repeat submissions, or attempts to bypass attribution may lead to disqualification or reward revocation.
* **Tax responsibility** — rewards may be taxable in the recipient's jurisdiction; the participant is responsible for compliance.
* **Program changes** — Xoxoday may modify, suspend, or discontinue the program at its discretion; changes do not affect rewards already earned.
## Full terms
### 1. Definitions
* **Referrer** — the existing customer contact submitting the referral.
* **Referred Company / Referred Contact** — the new-logo organization and the decision-maker introduced.
* **Referral ID** — a numeric tracking code auto-generated by HubSpot (for example, `528606047984`), issued once per referrer on their first submission — not once per referral. If the same referrer submits multiple referrals, to the same or different companies, all of them carry that referrer's single Referral ID; individual referrals are distinguished internally by the referred company and contact.
* **Milestone 1 (M1)** — completion of a proper product demo.
* **Milestone 2 (M2)** — signed MSA or first order (Closed Won).
* **Reward Amount** — the total cash reward: a flat \$100 for the qualified meeting (M1) plus 10% of the closed deal's first-year contract value (M2), with that 10% portion subject to a minimum of \$250 and a maximum of \$10,000, calculated per clause 6.
### 2. Who can join
* Must be a current, active customer contact on Empuls, Plum, or Loyalife, in good standing — no unresolved billing disputes and no active contract breach.
* Must have a genuine, pre-existing professional relationship with the Referred Contact, confirmed by a short attestation at submission.
* Xoxoday employees, contractors, and vendor staff are not eligible to participate as referrers, regardless of any personal customer relationship they may separately hold.
* Xoxoday may require proof of the referrer's employment or role at the referring company if reasonably in doubt.
* If a referrer's company policy does not permit participation in referral or incentive programs of this kind at all, the referrer should not submit a referral and may simply disregard this program. This is different from the employer-policy fallback in clause 6, which applies where participation itself is allowed but personally accepting a reward is not.
### 3. Who you can refer
A referral qualifies only if, at the time of submission, the Referred Company is:
* not a current Xoxoday customer on any product;
* 500+ employees;
* not already tracked in an active Xoxoday CRM opportunity, including any opportunity opened in the prior \~90 days (see clause 5 on attribution);
* represented by a person who genuinely holds decision-making or influencing authority for the relevant product (for example, HR leadership for Empuls, Procurement, Finance, or Rewards for Plum, and Marketing, Loyalty, or CX for Loyalife) — job-title claims may be verified.
**Not eligible under any circumstances:** existing customers on any Xoxoday product; companies with an open CRM opportunity; duplicate submissions of the same company or contact; companies within the referrer's own corporate group, parent company, or affiliate structure; the referrer's own employer; self-referrals in any form; and referrals where no genuine relationship exists between referrer and contact.
### 4. Submission requirements
* A submission must include, at minimum: company name, contact name, work email or LinkedIn profile, product of interest, and the nature of the referrer's relationship to the contact.
* A Referral ID (a numeric HubSpot record ID, for example `528606047984`) is issued once per referrer, on their first submission — not once per referral. If the same referrer submits multiple referrals over time, all of them are tracked under that same Referral ID; each individual referral is distinguished internally by the referred company and contact. The Referral ID, and every referral tracked under it, is non-transferable and cannot be reassigned to a different referrer.
* Referrers are fully responsible for the accuracy of everything submitted. Knowingly false, exaggerated, or misleading information voids the referral immediately upon discovery, at any stage — including after a reward has been paid.
* The Referred Contact must give affirmative consent to being contacted (double opt-in) before Xoxoday Sales makes any outreach. If consent is not obtained within a reasonable window, the referral is closed as inactive and does not qualify.
* The referred deal must sign (MSA or first order executed) within 6 months of the referral submission date. If it has not signed within that window, the referral no longer qualifies for the M2 (10% deal-value) payout, even if the deal eventually closes later. This 6-month clock does not affect the M1 \$100 payout, which is earned independently upon a qualified meeting per clause 6.
### 5. Attribution rules
* Attribution is first-touch: the first valid, timestamped submission for a given company is the one credited, regardless of how many other customers later submit the same company.
* A \~90-day lookback applies: if the account was already in active pipeline (via any channel) within 90 days before submission, the new referral is ineligible.
* Where the same referrer submits multiple contacts at the same company, only the first is treated as the qualifying referral for that company.
* Because a referrer's Referral ID is shared across all of that referrer's referrals (see clauses 1 and 4), attribution and reward calculation for each referral are tracked by the referred company and contact pairing, not by the Referral ID alone. A referrer with several referrals in progress sees each one progress and pay out independently under the same ID.
* Xoxoday's CRM timestamp and internal records are the sole and final source of truth for attribution disputes.
### 6. Reward amount, gating, and payout
* Reward Amount = \$100 per qualified meeting, plus 10% of the closed deal's first-year contract value. The 10% deal-value portion is subject to a minimum of \$250 and a maximum of \$10,000; the \$100 is additive and sits outside that floor and cap. Submission alone earns nothing.
* **M1 payout:** a flat \$100 is paid once a proper, qualified demo is confirmed — a genuine walkthrough of core product capabilities, led by the Product team or a senior Sales representative, logged as such in the CRM. A scheduling call or casual intro does not qualify. This \$100 is paid regardless of whether the deal size is known at this stage.
* The \$100 is not contingent on the deal ultimately closing. If the referred deal does not close, or closes after the 6-month deadline in clause 4, the referrer keeps the \$100 — it is not clawed back for that reason. (It may still be clawed back under the fraud provisions in clause 8.)
* **M2 payout:** once the MSA or first order is signed within the 6-month window, 10% of the deal's first-year contract value is paid, subject to the \$250 minimum and \$10,000 maximum on that portion. This is paid in addition to, not instead of, the M1 \$100.
* If the deal signs after the 6-month deadline, no M2 payout is made for that referral, regardless of deal size.
* Each referral tracked under a referrer's Referral ID is rewarded independently. If the same referrer has multiple qualifying referrals in progress, each earns its own M1 and M2 payout on its own timeline, subject to the annual per-referrer cap below.
* If a deal is later unwound, materially reduced, or found to have been misrepresented before or shortly after M2, Xoxoday may withhold or claw back the M2 (10%) portion and recalculate it to match the true deal value. The M1 \$100 is unaffected unless fraud is involved.
* The Reward Amount is paid in cash, by invoice or bank transfer, in the currency and manner Xoxoday's Finance team determines appropriate for the referrer's location.
* **Employer-policy fallback:** where personally accepting a cash reward would breach the referrer's employer policy, the referrer may instead decline or disregard the reward entirely; direct the value to a donation for a nominated charity; or, if the referrer is at an existing Xoxoday customer, apply the value as a discount on that company's next SaaS renewal or as a wallet-recharge credit. This choice must be declared at the M1 stage, before the M1 payout is processed, and applies to both the M1 and M2 payouts — it cannot be selected for the first time at M2 or invoked retroactively after the M1 cash payout has already been made.
* An annual cap per referrer applies (amount set by Finance and Sales Ops ahead of launch) across all referrals credited to that individual within a program year. Rewards in excess of the cap are not paid, deferred, or forfeited, at Xoxoday's discretion.
* Rewards are calculated as of the date each milestone is confirmed; no adjustment is made for later currency fluctuation.
### 7. Taxes
Rewards, and any fallback benefit under clause 6, may constitute taxable income, a benefit-in-kind, or otherwise be subject to tax or reporting obligations under the recipient's (or their employer's) local law. Xoxoday makes no representation, warranty, or guarantee as to tax treatment in any jurisdiction, does not withhold tax unless legally required to do so, and bears no liability for the recipient's or their employer's compliance. This is disclosed to referrers at submission and again at the time of reward.
### 8. Fraud, abuse, and enforcement
Xoxoday may investigate any referral or referrer at its discretion and may disqualify a referral, withhold a pending payout, or claw back a reward already paid (including recovering cash already transferred or requesting return of an equivalent-value benefit) where it reasonably believes there has been:
* a self-referral or referral within the referrer's own corporate group;
* a fabricated company, contact, or relationship;
* false, exaggerated, or materially misleading information at any stage;
* repeated, bulk, or systematic submissions designed to manufacture referral credit;
* collusion between a referrer and a contact at the Referred Company to simulate genuine interest;
* any other attempt to circumvent double opt-in, attribution, or milestone-gating rules.
Xoxoday's determination on eligibility, attribution, and suspected fraud is final and not subject to appeal beyond an internal review requested through Sales Ops. Referrers found to have committed fraud or repeated abuse may be permanently barred from future participation in this or related Xoxoday programs, and Xoxoday reserves the right to pursue recovery of any reward paid in error or bad faith.
### 9. No guarantee of outcome
Submitting a referral, or reaching any stage short of M1 or M2, creates no entitlement to engagement, a specific sales timeline, deal terms, or payout. Xoxoday's Sales and Product teams retain sole discretion over whether and how to pursue any referred opportunity, including declining to engage a Referred Contact for any legitimate business reason. Xoxoday is not liable for any referral that does not progress, regardless of the effort the referrer put into the introduction.
### 10. Data, privacy, and confidentiality
* Information submitted about a Referred Contact or Company is used solely to evaluate, route, and progress the referral, and is handled under Xoxoday's standard privacy practices and applicable law (including India's DPDP Act and, where relevant, GDPR for global referrals).
* Referrers must only submit contact information they are authorized to share, and must not submit information obtained in breach of any confidentiality obligation to a third party.
* Xoxoday will not disclose the referrer's identity to the Referred Company or Contact without the referrer's consent, except as necessary to facilitate the warm introduction itself.
* Program performance data may be shared internally for program evaluation; individual referral details are shared only with teams directly involved in qualification, sales, and reward processing.
### 11. Liability
Xoxoday's total liability to any referrer arising out of or related to this program is limited to the value of the reward that referrer would have been entitled to receive for the specific referral in question, had all conditions been met. Xoxoday is not liable for indirect, incidental, or consequential loss, including any business or reputational impact from an introduction not being pursued, delayed, or declined.
### 12. Program changes, suspension, and termination
* Xoxoday may modify, suspend, or discontinue the program, these terms, reward amounts, thresholds, milestones, or eligibility criteria at its sole discretion, with or without prior notice, and without liability to referrers for doing so.
* Changes do not retroactively affect a reward already fully earned — that is, both M1 and M2 completed — before the change takes effect.
* For a referral where only M1 (or neither milestone) has been completed at the time of a change, the terms in force at the time each milestone is actually reached apply to that milestone's payout.
* If the program is discontinued entirely, Xoxoday will honor rewards for referrals that have already reached the relevant milestone as of the discontinuation date, but is not obligated to allow new referrals to progress toward reward after that date.
### 13. Relationship to other agreements
These terms operate alongside, and do not override, any master service agreement, order form, or other contract between the referrer's employer and Xoxoday. Where there is a direct conflict specifically on a matter of referral-reward eligibility, these terms govern for purposes of this program only; all other aspects of the underlying commercial relationship remain governed by the applicable master agreement.
### 14. Governing law and disputes
Any dispute regarding this program that cannot be resolved through Sales Ops' internal review process will be handled per the governing law and dispute-resolution terms of the referrer's employer's underlying master agreement with Xoxoday. Where no such agreement exists, Indian law applies and disputes are subject to the jurisdiction of the courts in Bengaluru, Karnataka.
# Launch Templates
Source: https://help-plum.xoxoday.com/resources/introduction-to-plum-templates
Get an introduction to Plum's ready-to-use templates for reward communications, campaigns, and recipient messaging.
Introduction
Template 2 (Source File)
How to Sign up
How to Bookmark Reward storefront
Redeem Rewards \
\
How to Redeem Points
How to Redeem Codes\\
How to Redeem Links
How to Sign up
How to Bookmark Reward storefront
Redeem Rewards \
\
How to Redeem Points
How to Redeem Codes\\
How to Redeem Links
# Launch Kit
Source: https://help-plum.xoxoday.com/resources/launch-kit
Access Plum's launch kit, a set of resources to help you roll out and communicate your new reward program successfully.
*Turn employees into brand advocates. Setup and reward your employees across the lifecycle. Happy rewarding!*
## What is Plum Launch Kit for HR teams?
* This launch kit consists of video and email template resources for effectively communicating the launch of Plum within the organisation to the employees.
* The launch kit consists of multiple email templates that can be mass sent within the organisation for the announcement and adoption of Plum by Xoxoday.
* All the email templates are attached in the form of a JPG. You can choose to either download the email templates as they are and add them to your mailing tool directly. Or you can use the source file attached and customise it as per your company brand guidelines and own content.
* The artboard with brand colours and typography is also attached for reference.
* You can choose to add your company logos and implement a custom brand system to all the designs.
* Please go through the emails carefully and add the company name wherever the personalisation token is given.
## Video - How to set up your plum account?
## Video - How to redeem your rewards on the storefront?
(Meant for employee distribution)
## How to use the Plum Launch Kit effectively?
* **(Day -10 to Day 0)** - Pre-Launch templates to create the buzz within the organisation and get the employees excited about the upcoming rewards. These can be used before the launch of the platform in the first 10 days before the actual launch date.
* **(Day 1 to 5)-** The Introduction to Plum templates can be used on the actual date of launch and Plum implementation (You can choose to alter the content from source files)
* **(Day 6 to 10) -** How to sign up and bookmark emails can be sent in the coming week of the launch for employees’ education
* **(Day 11 to 15) -** How to redeem emails can be sent within the organisation to iterate on the easy process of redemption of rewards.
## Email templates
[Art-board (Colour Scheme and Typography)](https://drive.google.com/file/d/1PB-65INgYZ8pRQRMvL8ArNKZSvpmJJZi/view)
[Pre-Launch Templates](/resources/pre-launch-template)
[Introduction to Plum Templates](/resources/introduction-to-plum-templates)
[How to Sign up on Plum’s reward storefront Template](/resources/introduction-to-plum-templates)
[How to Bookmark Plum’s reward storefront for easy access Template](/resources/introduction-to-plum-templates)
[How to Redeem the Rewards on Plum’s Reward Storefront?](/resources/introduction-to-plum-templates)
# Pre-Launch Template
Source: https://help-plum.xoxoday.com/resources/pre-launch-template
Download Plum's pre-launch template to help you plan and organize the rollout of your reward program before going live.
Pre-Launch Template 1 (Source File)
Pre-Launch Template 2 (Source File)
Pre-Launch Template 3 (Source File)
Pre-Launch Template 4 (Source File)
# Airmiles
Source: https://help-plum.xoxoday.com/reward-marketplace/airmiles
The **Airmiles** category lets you convert **Xoxo Points** into airline frequent flyer miles. Miles are credited directly to your airline loyalty account, so you can redeem them with participating airline programs.
## Where Airmiles Is Used
Airmiles is commonly used for redeeming sales and channel incentive payouts, employee recognition and reward programs, loyalty program rewards, referral bonuses, and survey or research incentives — for users who prefer airline miles over gift cards or merchandise.
## Supported Airline Programs
Depending on your organization's reward catalog, you can redeem miles with participating airline loyalty programs, such as:
* Emirates Skywards
* Etihad Guest
* IndiGo BluChip
* SriLankan FlySmiles
Available airline partners may vary by program.
## Redeem Airmiles
* Open the **Airmiles** category.
* Browse available airline partners and mile denominations.
* Select your preferred airline and redemption value.
Enter your **Airline Loyalty Membership ID** for the selected airline program during checkout. Double-check this number — miles are credited directly to this account.
Review the redemption details and confirm the order. Once placed:
* The required Xoxo Points are deducted from your available balance.
* The order status changes to **Pending** while the transfer is being processed.
Airmile transfers are processed asynchronously and are not credited instantly. Processing typically takes 2–3 business days, depending on the airline partner.
Once processing is complete:
* **Successful transfers** are marked **Delivered**, and miles are credited to your airline loyalty account.
* **Failed transfers** are marked **Failed**, and the redeemed Xoxo Points are automatically refunded.
A confirmation email is sent once the redemption is complete.
## Cancellation & Refund
Refund eligibility depends on the transfer status:
* **Successful transfer** – Not refundable. Once miles are credited to your airline loyalty account, the transfer is permanent and cannot be cancelled.
* **Failed transfer** – Refunded automatically. The redeemed Xoxo Points are credited back to your balance.
* **Cancelling before processing** – Handled manually. Contact Xoxoday Plum Support to request a cancellation; self-service cancellation isn't available.
For any cancellation request, contact Xoxoday Plum Support via email, the support portal, or your organization's Slack/Teams support channel.
Airmiles cannot be redeemed without a valid airline loyalty membership account. Verify your membership ID before confirming the redemption.
# Cash Payouts
Source: https://help-plum.xoxoday.com/reward-marketplace/cash-outs
Learn how recipients can cash out their reward points for direct payouts through Plum's reward marketplace platform.
*Learn how to cash out your reward points directly to your UPI ID or bank account.*
You can cash out your reward points via UPI or Bank Transfer. Follow the steps below.
***
## How to Cash Out via UPI Transfer
Log in and view your available reward points.Under the payout option, select **UPI** as your transfer method.
Enter your UPI ID and the amount you want to cash out.
Click **Make Transfer**, review your details, then confirm the details entered
On the checkout page, confirm your **payment option** and **contact details**. Once verified, click **Transfer Now** to successfully make the transfer.
Your cashout is complete. You'll get a confirmation via **email and SMS**.
***
## How to Cash Payout via Bank Transfer
Here's how to do it via Bank Transfer.
Log in and view your available reward points. Under the payout option, select **Bank Transfer** as your transfer method.
Provide your bank account number, IFSC code, and account holder name. Also enter the amount you want to cash out
Sign in to confirm your points, then click here to initiate the transfer.
You'll see the transfer status on this screen once initiated.
# Charity
Source: https://help-plum.xoxoday.com/reward-marketplace/charity
The Charity category lets you donate your Xoxo Points to verified NGOs and charitable causes, converting reward points into real-world donations. It gives you an opportunity to support social causes directly from the Plum storefront.
Availability: Available on the Plum storefront for Xoxo Points redemptions only.
## Where Charity Is Used
Charity is commonly used for donating employee rewards to charitable causes, supporting CSR and corporate giving initiatives, allowing loyalty program members to contribute to NGOs, and giving users the option to redeem points for social impact instead of personal rewards.
## Redemption Options
Charity donations currently support only Xoxo Points. Xoxo Code, Points + Cash, and Cash Only are not supported for this category.
## Make a Donation
Open the Charity category and browse the available NGOs and causes. Each listing includes the NGO name, cause description, logo/image, and available donation denominations.
Choose the NGO you want to support. The product page displays details about the organization, the cause, and available donation amounts. Click **Donate** to continue.
Review the donation summary — NGO selected, donation amount, and Xoxo Points to be redeemed — then confirm to place the order.
Once the donation is confirmed:
* Xoxo Points are deducted from your balance.
* A donation order is created.
* A confirmation email is sent to your registered email address.
* The donation appears in your Order History.
The order may initially appear as **Pending** while it's processed by the partner NGO, before updating to **Delivered**.
## Cancellation & Refund
Refund eligibility depends on the donation status:
* **Donation successfully processed** – Not refundable. Donations can't be cancelled or refunded once processed.
* **Order remains pending** – Handled manually. Contact Xoxoday Plum Support for assistance.
* **Self-service cancellation** – Not available. Cancellation can't be done directly from the storefront.
Charity donations are irreversible once the funds have been processed by the NGO. If you experience any issues with your donation, contact Xoxoday Plum Support.
# Experiences
Source: https://help-plum.xoxoday.com/reward-marketplace/experiences
The Experiences category lets you redeem rewards for tours, attractions, adventure activities, dining, wellness, and other real-world experiences. Depending on your reward program, experiences can be booked using Xoxo Points, Xoxo Codes, Points + Cash, or Cash (if enabled).
## Where Experiences Is Used
Experiences is commonly used for redeeming employee recognition and reward payouts, sales and channel incentive programs, loyalty program rewards, and referral bonuses — for users who prefer memorable experiences over gift cards or merchandise.
## Redemption Options
Depending on your organization's reward program, experiences can be booked using:
* Xoxo Points
* Xoxo Code
* Points + Cash
* Cash (if enabled)
## Book an Experience
* Open the Experiences category.
* Select the Country and City, or browse the available categories.
* Explore experiences such as tours, attractions, adventure activities, dining, and wellness — and choose your preferred option.
Review the description, what's included, cancellation policy, additional information, price, and available dates. Select your preferred date and number of travellers before proceeding.
Provide Title, First/Last name, Email address, and Phone number. Some experiences may require additional details depending on the vendor or activity.
Review the booking summary and pay using Xoxo Points, Xoxo Code, Points + Cash, or Cash (if enabled). If the redeemable value is less than the booking amount, pay the remaining balance online.
Once payment completes:
* A booking reference is generated.
* A confirmation email is sent with the booking details.
* The booking is added to your order history.
* The redeemed Points/Code value is deducted from your balance.
Depending on the experience, your confirmation may include a booking reference, voucher, barcode, or additional access instructions.
## Cancellation & Refund
Refund eligibility depends on the experience provider's cancellation policy:
* **Cancelling before the experience date** – Depends on the provider's policy. Contact Xoxoday Plum Support to request a cancellation.
* **Experience cancelled by the provider** – Refunded. The applicable refund is processed if the provider cancels the experience.
* **No-show** – Not refundable. Refunds aren't available if you don't attend the booked experience.
* **Venue rejects the booking** – Handled manually. Contact Xoxoday Plum Support for assistance; refund eligibility depends on the reason for rejection.
* **Self-service cancellation** – Not available. Experience bookings can't be cancelled directly from the storefront.
For any cancellation request, contact Xoxoday Plum Support via email, the support portal, or your organization's Slack/Teams support channel.
# Flights
Source: https://help-plum.xoxoday.com/reward-marketplace/flights
The **Flights** category lets you book domestic and international flights directly from the Plum storefront. Choose from 150+ airlines across 100+ countries and pay using your rewards balance.
Depending on your organization's reward program, flights can be booked using **Xoxo Points**, **Xoxo Code**, **Points/Code + Cash**, or **Cash** (if enabled).
Flights is commonly used for redeeming sales and channel incentive payouts, employee milestone or performance reward payouts, loyalty program rewards in B2B2C programs, referral bonuses, and survey or research incentive payouts.
## Redemption Options
**Xoxo Points**
Redeem available Xoxo Points in your wallet to pay for flight bookings.
* If points fully cover the fare, the booking completes as **Points Only**.
* If the balance is insufficient and **Points + Cash** is enabled, you can pay the remaining amount online.
**Xoxo Code**
Redeem an Xoxo Code toward a flight booking. The code's value is applied to the fare; if it doesn't cover the full amount, pay the remaining balance online via the available payment gateway.
## How to Book a Flight
* Open the Flights category.
* Enter Origin, Destination, Travel date(s), Number of travellers, and Cabin class.
* Click **Search** to view matching flights.
Browse results and select your preferred itinerary. Fare and availability are reconfirmed before checkout.
Provide Title, First/Last name, Gender, Date of birth, Nationality, Email, and Phone number. International bookings also require passport details.
Review the booking summary and pay using Xoxo Points, Xoxo Code, Points + Cash, or Cash (if enabled). If the redeemable value is less than the total fare, pay the remaining balance online.
Once payment completes:
* A PNR is generated confirming your reservation.
* A confirmation email is sent to your registered address.
* The booking appears in your order history.
* The redeemed Points/Code value is deducted from your balance.
## Cancel a Flight Booking
Contact Xoxoday Plum Support via email, the support portal, or your organization's Slack/Teams support channel. The support team will process the cancellation and initiate any applicable refund.
## Refunds
* Xoxo Points used are credited back to your balance.
* Payment-gateway charges are refunded to the original payment method (may take a few business days).
# Hotels
Source: https://help-plum.xoxoday.com/reward-marketplace/hotels
The Hotels category lets you book hotels directly from the Plum storefront using your rewards. Choose from a wide range of properties and redeem toward domestic and international stays. Stays in 50k+ cities, across every major travel destination.
The Hotels category is available only on the Plum Storefront for users redeeming Xoxo Points or Xoxo Codes. It is not available through Xoxo Links or the Plum API.
## Where Hotels Is Used
Hotels is commonly used for redeeming employee recognition, milestone, and performance rewards, sales and channel incentive payouts, loyalty program rewards, referral bonuses, and survey or research incentives. Since hotel stays are typically a higher-value redemption, this category is especially popular among users who prefer travel experiences over gift cards or merchandise.
## Redemption Options
Depending on your organization's reward program, hotel bookings can be paid using:
* **Xoxo Points** – Redeem the full booking amount using available points.
* **Xoxo Code** – Redeem the value of an Xoxo Code toward the booking.
* **Points + Cash** – If the reward value doesn't cover the full amount, pay the remaining balance online.
* **Cash** – Pay the full booking amount online, if enabled for your organization.
## Book a Hotel
* Open the Hotels category.
* Enter Destination, Check-in/Check-out dates, Number of rooms, and Number of guests.
* Click **Search** to view available hotels, along with pricing, star ratings, and amenities.
Browse results and select your preferred property. Choose a room and review the rate plan, inclusions, and cancellation policy before proceeding.
Provide Title, First/Last name, Email address, and Phone number. If supported by the hotel, you can add special requests during checkout.
Review the booking summary and pay using Xoxo Points, Xoxo Code, Points + Cash, or Cash (if enabled). If the redeemable value is less than the total booking amount, pay the remaining balance online.
Once payment completes:
* The hotel reservation is confirmed and a booking confirmation number is generated.
* A confirmation email with the hotel details, check-in/check-out dates, and property address is sent to your registered email.
* The booking appears in your order history.
* The redeemed Points/Code value is deducted from your balance.
## Cancel a Hotel Booking
Contact Xoxoday Plum Support via email, the support portal, or your organization's Slack/Teams support channel. The support team will process the cancellation and initiate any applicable refund.
## Refunds
* Xoxo Points used for the booking are credited back to your balance.
* Payment-gateway charges are refunded to the original payment method (may take a few business days).
# Airport Lounge Access
Source: https://help-plum.xoxoday.com/reward-marketplace/lounge
The **Airport Lounge Access** category lets you redeem rewards for airport lounge passes directly from the Plum storefront. Access participating lounges at airports using Xoxo Points, Xoxo Codes, or a combination of rewards and online payment.
Airport Lounge Access is available only on the Plum Storefront for users redeeming Xoxo Points or Xoxo Codes. It is not available through Xoxo Links or the Plum API.
## Where Airport Lounge Access Is Used
Airport Lounge Access is commonly used for redeeming employee rewards and recognition, sales and channel incentive payouts, loyalty program rewards, referral bonuses, and survey or research incentives — for users who prefer lounge access over gift cards or merchandise.
## Redemption Options
Depending on your organization's reward program, lounge passes can be redeemed using:
* **Xoxo Points** – Redeem the full amount using available points.
* **Xoxo Code** – Redeem the value of an Xoxo Code toward the booking.
* **Points + Cash** – If the reward value doesn't cover the full amount, pay the remaining balance online.
* **Cash** – Pay the full amount online, if enabled for your organization.
## Book Airport Lounge Access
* Open the Airport Lounge Access category.
* Enter Airport, Terminal (if applicable), and Date/time of your visit.
* Click **Search** to view available lounges, along with amenities and redemption value.
Browse results and select your preferred option. Review amenities, operating hours, terminal location, and the number of guests allowed.
Provide Guest name, Email address, and Phone number. Some lounges may also require flight details during checkout.
Review the booking summary and pay using Xoxo Points, Xoxo Code, Points + Cash, or Cash (if enabled). If the redeemable value is less than the total amount, pay the remaining balance online.
Once payment completes:
* A booking reference or QR code is generated.
* A confirmation email is sent with the lounge details, airport, terminal, visit date/time, and the booking reference or QR code.
* The redeemed Points/Code value is deducted from your balance.
On the day of your visit, present the QR code or booking reference at the lounge reception to gain entry.
## Cancellation & Refund
Refund eligibility depends on how your booking is cancelled:
* **Cancelling before your visit** – Points are refunded, though the cancellation window depends on the lounge vendor's policy.
* **Not showing up for your booking** – Points are not refunded.
* **Lounge closed or unavailable** – A refund is triggered automatically.
* **Payment captured but booking not confirmed** – Points are automatically refunded.
For any cancellation request, contact Xoxoday Plum Support via email, the support portal, or your organization's Slack/Teams support channel.
# Merchandise
Source: https://help-plum.xoxoday.com/reward-marketplace/merchandise
The **Merchandise** category allows users to redeem rewards for physical products across categories such as electronics, home & kitchen, fashion, health & fitness, and more. Depending on the reward program, merchandise can be redeemed using **Xoxo Points**, **Xoxo Codes**, **Points + Cash**, or **Cash** (if enabled).
## Use Cases
The **Merchandise** category is commonly used for:
* Employee recognition and reward programs.
* Sales and channel incentive programs.
* Loyalty program rewards.
* Referral bonus programs.
* Redeeming Xoxo Points or Xoxo Codes for physical products instead of digital rewards.
## Redemption Options
Depending on your organization's reward program, merchandise can be redeemed using:
* **Xoxo Points**
* **Xoxo Code**
* **Points + Cash**
* **Xoxo Code + Cash**
* **Cash** (if enabled)
## Redeem Merchandise
1. Open the **Merchandise** category.
2. Browse products by category or use the search and filters to find a specific item.
3. Select the product you want to redeem.
You can filter products by category, brand, price, and other available options.
View the product information, including:
* Product description
* Specifications
* Available variants (such as size or color)
* Price
* Availability
* Estimated delivery timeline
Select the required variant, if applicable, and add the product to your cart.
Review the items in your cart and update the quantity if required.
When you're ready, click **Proceed to Checkout**.
Choose a saved delivery address or add a new one during checkout.
Some organizations may use **Address Lock**, which provides a pre-filled delivery address that cannot be edited.
Review your order summary and complete the payment using one of the available options:
* **Xoxo Points**
* **Xoxo Code**
* **Points + Cash**
* **Xoxo Code + Cash**
* **Cash** (if enabled)
If the available Xoxo Points or Xoxo Code value is less than the order amount, the remaining balance can be paid online.
After the payment is completed:
* Your order is placed successfully.
* An order confirmation screen is displayed.
* A confirmation email is sent to your registered email address.
* The redeemed **Xoxo Points** or **Xoxo Code** value is deducted from your available balance.
## Track Your Order
You can track your order from **Order History**, where you can view details such as:
* Order ID
* Product name
* Order date
* Order status
* Delivery address
* Points redeemed
Depending on the fulfillment partner, tracking information and the estimated delivery date may also be available.
Typical order statuses include:
* Order Placed
* Processing
* Shipped
* Out for Delivery
* Delivered
* Cancelled
* Refunded
## Cancellation and Refunds
| Scenario | Refund | Details |
| -------------------------------------- | ---------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| Order not yet shipped | ⚠️ Depends | Contact the Xoxoday Plum Support team to request a cancellation. Approval depends on the fulfillment stage. |
| Damaged, incorrect, or missing product | ⚠️ Manual | Contact the Xoxoday Plum Support team for assistance with a replacement or refund, as applicable. |
| Delivery failed | ✅ Yes | If the order cannot be fulfilled, the applicable refund is processed. |
| Self-service cancellation or return | ❌ No | Merchandise orders cannot be cancelled or returned directly from the storefront. Contact the Xoxoday Plum Support team for assistance. |
# Mobile Recharge
Source: https://help-plum.xoxoday.com/reward-marketplace/mobile-recharge
The **Mobile Recharge** category lets you redeem rewards for prepaid mobile recharges directly from the Plum storefront. Depending on your reward program, recharges can be completed using **Xoxo Points**, **Xoxo Codes**, **Points + Cash**, or **Cash** (if enabled).
Mobile recharges are powered by **DT One**, supporting 550+ mobile operators across 160+ countries.
## Where Mobile Recharge Is Used
Mobile Recharge is commonly used for redeeming employee rewards and recognition, sales and channel incentive payouts, loyalty program rewards, referral bonuses, and survey or research incentives — for users who prefer mobile recharges over gift cards or merchandise.
## Redemption Options
Depending on your organization's reward program, mobile recharges can be completed using:
* **Xoxo Points**
* **Xoxo Code**
* **Points + Cash**
* **Cash** (if enabled)
## Recharge a Mobile Number
* Open the **Mobile Recharge** category.
* Select the country code.
* Enter the mobile number.
* Click **Verify**.
The system automatically detects the telecom operator and region. If needed, you can manually select the operator.
Browse the available recharge plans for the selected operator. Each plan displays the recharge amount, validity, data allowance, and calling/SMS benefits. Select the plan you want to purchase.
Review the recharge details and pay using Xoxo Points, Xoxo Code, Points + Cash, or Cash (if enabled). If the redeemable value is less than the recharge amount, pay the remaining balance online.
Once payment completes:
* The recharge request is processed immediately.
* A confirmation message is displayed.
* A confirmation email or SMS is sent to your registered contact details.
* The redeemed Points/Code value is deducted from your balance.
## Cancellation & Refund
Refund eligibility depends on the recharge status:
* **Recharge successful** – Not refundable. Completed recharges cannot be cancelled or reversed.
* **Recharge failed** – Refunded automatically. The redeemed Xoxo Points are credited back to your balance.
* **Recharge sent to the wrong number** – Not refundable. Recharges cannot be reversed once processed — double-check the number before confirming.
* **Recharge stuck as pending** – Handled manually. Contact Xoxoday Plum Support if your recharge remains pending for an extended period.
For any recharge issues, contact Xoxoday Plum Support via email, the support portal, or your organization's Slack/Teams support channel.
# Play & Win
Source: https://help-plum.xoxoday.com/reward-marketplace/play-and-win
The Play & Win category lets you redeem Xoxo Points to play interactive games and win rewards. Depending on the game outcome, you can win gift vouchers, mobile recharges, or other rewards.
Available games may vary depending on your organization's reward program.
## Available Games
You may see one or more of the following games:
* **Spin the Wheel** – Spin the wheel for a chance to win a reward.
* **Roll the Dice** – Roll the dice to reveal the outcome.
* **Scratch Card** – Scratch the card to reveal whether you've won.
## How to Play
* Open the Play & Win category.
* Browse the available games.
* Review the cost to play and the rewards available.
* Click **Play Now**.
The required Xoxo Points are deducted before the game begins.
Gameplay depends on the selected game:
* **Spin the Wheel** – Spin the wheel to reveal your reward.
* **Roll the Dice** – Roll the dice to determine the outcome.
* **Scratch Card** – Scratch the card to reveal the result.
Depending on the outcome, you may win a reward, receive another free attempt (if applicable), or see a "Better Luck Next Time" message.
If you win:
1. Click **Redeem Now**.
2. Your reward is generated automatically.
3. A confirmation screen displays your reward details.
The reward is also added to your Play & Win Order History.
## View Play & Win History
All Play & Win rewards are available under the **Play & Win** tab in Order History. From here, you can view your game history, check the outcome of each game, view reward details, and play again (if the game is still available).
Play & Win rewards are shown separately from your regular reward redemption history.
## Cancellation & Refund
Refund eligibility depends on when the issue occurs:
* **Game played successfully** – Not refundable. Once a game has been played, the Xoxo Points used to enter cannot be refunded.
* **Reward claimed** – Not refundable. Claimed rewards cannot be cancelled or exchanged.
* **Technical failure before the game starts** – Refunded automatically. If the game fails to launch after points are deducted, they're refunded automatically.
* **Technical issue during gameplay** – Handled manually. Contact Xoxoday Plum Support if you experience an issue while playing.
For any gameplay issues, contact Xoxoday Plum Support via email, the support portal, or your organization's Slack/Teams support channel.
# Reward Marketplace Overview
Source: https://help-plum.xoxoday.com/reward-marketplace/reward-marketplace-overview
Get an overview of Plum's reward marketplace, where recipients redeem their points for products, vouchers, and experiences.
*Xoxoday Reward Marketplace is a prebuilt, hosted rewards storefront optimized for end-user delight.*
## Introduction to Marketplace
The Storefront is a customizable online marketplace where you can craft a distinct shopping experience for customers or employees. Utilizing white-label settings, you can adjust the appearance and branding to align with your brand identity. Our pre-built marketplace is a ready-to-use rewards storefront designed for the best user experience. Offering branded gift cards, unique experiences, fintech products, and merchandise enables effortless and secure global distribution of rewards and incentives.
Delight, acquire, engage, and retain global audiences with a host of physical and digital reward options across a diverse range of categories.
## Catalog Options
One marketplace, with many categories and options — your one-stop-shop for all your rewarding needs.
## Payouts
From mass payouts to meal or fuel card provisions, our fintech partnerships offer comprehensive solutions. Drop us a line at [cs@xoxoday.com](mailto:cs@xoxoday.com) for a tailored demo.
## Brand Giftcard
Extensive catalog of 10,000+ options from brands across 100+ countries if you already know their preferences. Drop us a line @ [cs@xoxoday.com](mailto:cs@xoxoday.com) for a tailored demo.
## Merchandise
Say goodbye to the logistical nightmare and troubles of sourcing and sending hundreds of gifts across countries. Drop us a line @ [cs@xoxoday.com](mailto:cs@xoxoday.com) for a tailored demo.
## Flights
Book domestic and international flights across 100+ countries with access to 150+ airlines including Emirates, Lufthansa, Air India, and more. Recipients can use their reward points directly or pay partially, with real-time pricing and live inventory to ensure a smooth booking experience. Drop us a line @ [cs@xoxoday.com](mailto:cs@xoxoday.com) for a tailored demo.
## Hotels
Let recipients redeem rewards for stays at 1M+ hotels across the US, UK, India, and beyond — from top luxury brands like Four Seasons, Ritz-Carlton, and Westin to everyday business travel options. Enjoy flexible booking with instant confirmation for both leisure and work trips. Drop us a line @ [cs@xoxoday.com](mailto:cs@xoxoday.com) for a tailored demo.
## Mobile Recharge
Give recipients the gift of instant connectivity. Our utility and top-up catalog allows users to recharge prepaid mobile numbers across a wide range of carriers and countries, making it one of the most practical and universally appreciated reward options. Drop us a line @ [cs@xoxoday.com](mailto:cs@xoxoday.com) for a tailored demo.
## Miles
Allow recipients to convert their reward points into airline miles, adding even more value to travel-focused reward programs. Compatible with leading frequent flyer programs, this option is especially popular with business travelers and high-performers who prefer travel perks. Drop us a line @ [cs@xoxoday.com](mailto:cs@xoxoday.com) for a tailored demo.
## Charity
Give recipients the option to do good with their rewards. Users can donate their points to a cause they care about, from global humanitarian organizations to local nonprofits. A meaningful and increasingly sought-after redemption option that reflects your organization's values. Drop us a line @ [cs@xoxoday.com](mailto:cs@xoxoday.com) for a tailored demo.
## Experience
You have the opportunity to offer an experience tailored to various interests, creating lasting memories. Drop us a line @ [cs@xoxoday.com](mailto:cs@xoxoday.com) for a tailored demo.
## Lounge
Get lounge access at major airports across the country. Drop us a line @ [cs@xoxoday.com](mailto:cs@xoxoday.com) for a tailored demo.
## Offers/Perks
Plum's storefront now features a dedicated "Perks" category, offering curated deals and discounts from top brands for seamless access to exclusive perks-based products. Drop us a line @ [cs@xoxoday.com](mailto:cs@xoxoday.com) for a tailored demo.
## For Developers
## Marketplace Integration
Transform your reward points redemption process instantly with our plug-and-play global rewards catalog integration, delivering an exhilarating experience to your users within minutes. Check out the documentation.
## Customize Storefront
### Brand Preference
Customize the storefront to make it your own with a lot of branding option. [Storefront Branding Customization](/account-settings/storefront/storefront-branding-customization)
Feedback or Questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Customize Communication
Source: https://help-plum.xoxoday.com/send-rewards/gift-cards/gift-cards-customize-reward-communication
See how to customize the reward communication, including subject lines, messages, and branding, sent alongside gift cards in Plum.
*Learn how to customize Reward Communication to recipients.*
You can use your Xoxoday's Rewards APIs to procure the voucher and front-end the communication yourself. Click here to learn more [About Rewards API](/API-PLAYGROUND/Rewards-API/giftcard-api).
***
## Customizing Email
You have the option to customise email and SMS based on your requirements.
You can customize the following elements before sending the Gift Cards.
* The subject line of the email
* Headline Message
* Banner Image
* Personal Message
* Email footer
***
## Customizing SMS
Select the tab "**Reward SMS**".
Add your message in the input field and proceed.
Feedback or Questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Send Gift Cards
Source: https://help-plum.xoxoday.com/send-rewards/gift-cards/sending-gift-cards-to-recipients
Learn how to send digital gift cards to one or more recipients using Plum, from selecting a brand to confirming delivery.
*Learn how to send brand vouchers to users from your Admin Dashboard*
## Brand Gift Card (Brand Vouchers)
Instantly send brand gift cards to recipients' inboxes. There are over 8,000 top global brands from Amazon to Walmart and everything in between!
### Best fit if you want to:
* Rapidly distribute gift cards within minutes
* Offer hassle-free redemption with specific brand gift cards, no login or registration required
* Generate a gift card for yourself, shareable via any channel
You can use your Xoxoday's Rewards APIs to procure the voucher and front-end the communication yourself. Click here to learn more [About Rewards API](https://developers.xoxoday.com/reference/about-rewards-api).
***
## Step-by-step guide to sending brand vouchers: to a few
Click on the **Gift Cards** section under the **Send Rewards** section.
On this page, enter the following information to send a voucher:
**Recipient Details**
* Email address
* Phone Number
**Voucher Details**
* Select Voucher Country
* Select Voucher Brand
* Enter a value of the brand (Note: add a value within the indicated range. This indicated range represents the brands' denomination available).
* Select the Quantity. You can add upto 999 gift cards in one go.
Lastly, click '**Add Recipient**'.
With advanced settings you can use following:
* Add a PO Number if you need
* Add a personal message in the email body for the recipient. The message that you enter here will be sent to all the recipients in the batch. Except otherwise as indicated in the .CSV file in case of bulk.
To customize SMS follow these steps:
* Select 'Reward SMS' tab and add your desired message.
Preview the details and send the Gift Voucher.
***
## Resend Gift Cards to a contact or in Bulk
Navigate to **Reports > Gift Cards.**
**Select Contacts:** Choose the contacts you want to resend the rewards.
**Resend Option:** Click the three dots next to the selected contacts, then click **'Resend'**.
**Confirm Action:** A confirmation pop-up will appear. Click **'Yes, Proceed'** to resend the rewards.
Feedback or Questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Customize Communication
Source: https://help-plum.xoxoday.com/send-rewards/reward-code/reward-code-customize-reward-communication
Learn how to customize the reward communication, including messaging and branding, sent to recipients along with reward codes in Plum.
*Learn how to customize Reward Communication to recipients.*
**Pro tip:** You can customize your Reward communication at the campaign level. These settings become the default communication template for the campaign. Further, you can customise to set a specific communication at the 'Send Reward' option, which will supersede the message in the default campaign template for that particular recipient(s).
***
## Customizing Email in a Reward Code Campaign
You have the option to customize the email either within the "Campaign" section or directly in the **"Reward Code"** section on the admin dashboard.
***
## Editing Email in Reward Code Section
To customize the email from the **"Reward Code"** section, follow these steps:
Navigate to the **Reward Code** section in the dashboard.
After configuring the campaign and uploading recipients, access the "**Email Preview**" section.
From there, you can proceed to edit the email directly.
You can customize the following elements before sending the Reward code.
* The subject line of the email
* Headline Message
* Banner Image
* Email footer
The banner can also be deleted by clicking on "**Remove Banner**".
Edit the Message. Click on "**Edit Message**" and enter the message title and body. Once done, click on "**Save**". Refer to the image below:
**Edit Background**: Click the pen icon to choose from the available colors, or enter your own using a hex code.
Edit the background text by selecting one of the available options or entering your own. Then, "**Save**" your changes.
***
## Customizing SMS
***
## Editing Email in Reward Code Section
To customize the email from the **"Reward Code"** section, follow these steps:
Navigate to the **Reward Code** section in the dashboard.
After configuring the campaign and uploading recipients, access the "**Email Preview**" section.
From there, you can proceed to edit the email directly.
You can customize the following elements before sending the Reward code.
* The subject line of the email
* Headline Message
* Banner Image
* Email footer
The banner can also be deleted by clicking on "**Remove Banner**".
Edit the Message. Click on "**Edit Message**" and enter the message title and body. Once done, click on "**Save**". Refer to the image below:
**Edit Background**: Click the pen icon to choose from the available colors, or enter your own using a hex code.
Edit the background text by selecting one of the available options or entering your own. Then, "**Save**" your changes.
***
## Customizing SMS
To customize the SMS, follow these steps:o customize the SMS, follow these steps:
Select a "**Reward SMS**".
Add your message in the input field to customize the SMS.
Select a duration from the dropdown. Options include 1 month, 12 months, or a custom timeframSelect a duration from the dropdown. Options include 1 month, 12 months, or a custom timeframe.
Questions or Feedback: Email us at [cs@xoxoday.com](mailto:cs@xoxoday.com)Questions or Feedback: Email us at [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Overview
Source: https://help-plum.xoxoday.com/send-rewards/reward-code/reward-code-overview
Get an overview of Plum reward codes, a flexible reward mode recipients can redeem themselves, and how they fit into your reward strategy.
*Learn all about Xoxoday Reward Code*
## Reward code
A reward code can used partially and in combination with other valid codes (up to 10).
Reward Code provides a fast and secure method to send unique reward codes to different participants in your ecosystem, regardless of their location.
### About
A Xoxo code is a 16 digit alpha numeric code that looks something like this: **S1H2-R3E4-D5I6-S7T8B**
Here are some of the features:
* Allows guest checkout (recipient doesn't need to log in).
* Allows partial redemption.
* Can be combined with up to 10 codes for a single checkout!
### Best fit if you want to:
* Allow easy redemption from our marketplace without account creation.
* Enable partial redemption or combining codes for larger rewards.
* Launch campaigns with unique landing pages and reward catalogs.
* Set expiry dates tailored to campaign duration and needs.
***
## Things to keep in mind
* Each Reward Code can hold up to 50,000 points, usable without campaign restrictions.
* Use up to 15 Reward Codes per transaction, applying them individually.
* Reward Codes are valid for 1 year by default.
* Send a maximum of 9,999 vouchers to one person at a time.
* Order multiple gift cards within your Reward Code Balance limit.
***
## Learn how to send Reward Code
* [Send Reward code: to Many](/send-rewards/reward-code/send-reward-code-bulk-upload)
* [Send Reward Code: to a Few](/send-rewards/reward-code/send-reward-code-individually)
Feedback or Questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Bulk Upload
Source: https://help-plum.xoxoday.com/send-rewards/reward-code/send-reward-code-bulk-upload
Learn how to send reward codes to many recipients at once using a bulk file upload in Plum, saving time on large distributions.
*Learn how to send reward codes to recipients one at a time and or many at a time.*
## Reward Code
Reward Code (reward code) provides a fast and secure method to send unique reward codes to different participants in your ecosystem, regardless of their location.
### About
A Reward code is a 16 digit alpha numeric code that looks something like this: **S1H2-R3E4-D5I6-S7T8B**
Here are some of the features:
* Allows guest checkout (recipient doesn't need to log in)
* Allows partial redemption
* Can be combined with up to 10 codes for a single checkout!
### Best fit if you want to:
* Allow easy redemption from our marketplace without account creation
* Enable partial redemption or combining codes for larger rewards
* Launch campaigns with unique landing pages and reward catalogs
* Set expiry dates tailored to campaign duration and needs
***
## Send Reward Code to many
**Pro tip:** Download the available template directly from the dashboard for your convenience.
Here are the quick steps:
Click on the "**Reward code**" section in the admin dashboard (under settings) and select and input "**Choose who can redeem**" settings.
Here are the three options to choose from and what they mean:
**Only the recipient of the code** — In this option, the recipient (and their email address) you mention at the time of sending the reward code, say [john.smith@acme.com](mailto:john.smith@acme.com) as the recipient email, only that person can use the Reward Code (to collect vouchers on that specified email address). It's best for direct sends to ensure the right person gets the reward.
**Only users with same domain as yours** — In this option, if your email is [john.doe@xyz.com](mailto:john.doe@xyz.com), only those email address on the same domain (xyz.com) can use the Reward Code. This is recommended if you're sending the codes to people who might share them.
**Any user with the code** — In this option, any user that has code can use/redeem it against your pre-funded wallet. This is the least secure of options, and to be used only when needed.
Prepare a list of recipients in the CSV format and upload it in one shot. You can download the template directly from the Admin portal (as seen below).
Set an expiry (default is 12 months or can set custom) and customize email and SMS messages as needed.
Learn more about campaigns for Reward codes. [Click here](/campaigns/create-a-reward-code-campaign) >
Feedback or Questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Send Individually
Source: https://help-plum.xoxoday.com/send-rewards/reward-code/send-reward-code-individually
See how to send a single reward code to one recipient individually in Plum, useful for one-off or personalized rewards.
*Learn how to send reward codes to recipients one at a time and or many at a time.*
## Reward code
Reward code provides a fast and secure method to send unique codes to different participants in your ecosystem, regardless of their location.
### About
A Xoxo code is a 16 digit alpha numeric code that looks something like this: **S1H2-R3E4-D5I6-S7T8B**
Here are some of the features:
* Allows guest checkout (recipient doesn't need to log in)
* Allows partial redemption
* Can be combined with up to 10 codes for a single checkout!
### Best fit if you want to:
* Allow easy redemption from our marketplace without account creation
* Enable partial redemption or combining codes for larger rewards
* Launch campaigns with unique landing pages and reward catalogs
* Set expiry dates tailored to campaign duration and needs
***
## Send Reward code to a few
Here are the quick steps to send one at a time:
Click on the "**Reward Codes**" in the admin dashboard and select input for "**Choose who can redeem**" option settings, based on your preference and requirement.
Here are the three options to choose from and what they mean:
**Only the recipient of the code** — In this option, the recipient (and their email address) you mention when sending the reward code, say [john.smith@acme.com](mailto:john.smith@acme.com), as the recipient email; only that person can use the Reward Code (to collect vouchers on that specific email address). It's best for direct sends to ensure the right person gets rewarded.
**Only users with same domain as yours** — In this option, if your email is [john.doe@xyz.com](mailto:john.doe@xyz.com), only those email address on the same domain (xyz.com) can use the Reward Code. This is recommended if you're sending the codes to people who might share them.
**Any user with the code** — In this option, any user that has code can use/redeem it against your pre-funded wallet. This is the least secure of options, and to be used only when needed.
Select the tab "**Send Individually**" and enter recipient details such as Name, Email address, and Reward Code value.
**Advanced Settings**
With advanced settings you can use following:
* Schedule the reward sends to a future time date. It will be sent out at 12 AM in the UTC.
* Add a personal message in the email body for the recipient. The message that you enter here will be sent to all the recipients in the batch. Except otherwise as indicated in the .CSV file in case of bulk.
* You can also add an internal reference note — a note to self that you'll can recall at a later time.
Set an expiry (default is 12 months or you can set custom time frame) and customize email and SMS messages as needed.
***
Feedback or Questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Customize Communication
Source: https://help-plum.xoxoday.com/send-rewards/reward-links/reward-link-customize-reward-communication
You can customize reward communication at two levels:
* **Campaign level** — Customizations apply to all sends within that campaign by default.
* **Send Reward level** — Customizations apply only to that specific send, overriding the campaign default for those recipients.
***
## Customizing Email in Reward Link Section
To customize the email from the "Reward Link" section, follow the steps:
Go to **Send Rewards > Reward Link > Additional Settings > Email and SMS**, then select the **Reward Email** tab.
Update any of the following elements:
* **Subject line** — Edit the subject line recipients will see in their inbox.
* **Banner image and logo** — Upload an image to appear at the top of the email or choose from the
**Headline message** — Click **Edit Message**, enter the message title and body, then click **Save**.
* **Background** — Click the pen icon to choose from available colours or enter a hex code. Update the background text by selecting an available option or entering your own, then click **Save**.
* **Email footer** — Add or update footer content to match your brand or campaign needs.
***
## Customize the Reward SMS
To customize the SMS, follow these steps:
Navigate to **Send Rewards > Reward Link > Additional Settings > Email and SMS**. Go to the tab "**Reward SMS**".
Enter your message in the input field to replace the default SMS content, then click **Save**.
***
**Before you send:** Preview both your email and SMS before sending Reward Links to recipients.
Feedback or Questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Overview
Source: https://help-plum.xoxoday.com/send-rewards/reward-links/reward-link-overview
Get an overview of Plum reward links, how recipients redeem them for a reward of their choice, and when to use this reward mode.
*Learn more about Reward Links — a unique link that can be sent to each recipient!*
Quickly create campaigns and distribute rewards with Xoxo Link. Share the link through any channel, allowing recipients to redeem rewards from a curated list of global brands easily.
## Reward Link is a good fit if you want to
* Provide recipients with one-click redemption without the hassle of account creation.
* Create campaigns with micro-landing pages with your hand-picked gift selections.
* Customize link expiry dates to match campaign needs.
***
## Learn how to send reward links
## Send Reward Links
* [Send Reward Links: to a Few](/send-rewards/reward-links/send-reward-links-send-individually)
* [Send Reward Links: to Many](/send-rewards/reward-links/send-reward-links-bulk-upload)
* [Send Reward Links: to Self](/send-rewards/reward-links/send-reward-links-to-self)
# Bulk Upload
Source: https://help-plum.xoxoday.com/send-rewards/reward-links/send-reward-links-bulk-upload
Learn how to send Reward Links to a large list of recipients at once using bulk CSV upload through the Plum Admin Portal.
## About Reward Link
Reward Link lets you create campaigns and deliver rewards through a single shareable link , via email, SMS, WhatsApp, or any channel you prefer. Recipients click the link and choose a gift card from a curated selection of leading global brands, with no account required.
**Reward Link works best when you want to:**
* **Keep redemption simple** — Recipients claim their reward instantly, without signing up.
* **Create a branded experience** — Build campaigns with a custom micro-landing page and hand-picked gift card options.
* **Control the timeline** — Set a custom expiry date to match your campaign window.
You'll need to create a campaign to be able to send Reward Link rewards to recipients. [Click here](https://revamptest.readme.io/docs/creating-xoxolink-campaigns) to learn how.
***
### How to Send Reward Links in Bulk
**Pro tip:** Download the available template directly from the dashboard for your convenience.
Choose the campaign you want to use from the list of available campaigns.
Pro tip: You can also edit the campaign directly from this page before proceeding.
Choose send in bulk delivery.
Review the field instructions on the page, then upload your completed CSV file using the provided template. Make sure all recipient details are filled in correctly before uploading.
Set how long the Reward Link will remain active by choosing an expiry period (**1, 2, 3, 6, 9, or 12 months** ) or pick a **Custom date** to match your campaign timeline. The default is **12 months**.
Optionally, customise the email and SMS messages that will be delivered to each recipient.
Review your upload and settings, then click **Send Reward** at the bottom of the page. Reward Links will be delivered to all recipients on your list.
***
### Need to send to a single recipient?
You can also send Reward Links one at a time using manual entry. [Learn how to send a Reward Link to an individual recipient](https://help-plum.xoxoday.com/send-rewards/reward-links/send-reward-link-individual)
Feedback or questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Send Individually
Source: https://help-plum.xoxoday.com/send-rewards/reward-links/send-reward-links-send-individually
Learn how to send Reward Links to recipients one at a time through the Plum Admin Portal.
### What is Reward Link?
Reward Link lets you create campaigns and deliver rewards through a single shareable link — via email, SMS, WhatsApp, or any channel you prefer. Recipients click the link and choose a gift card from a curated selection of leading global brands, with no account required.
**Reward Link works best when you want to:**
* **Keep redemption simple** — Recipients claim their reward instantly, without signing up.
* **Create a branded experience** — Build campaigns with a custom micro-landing page and hand-picked gift card options.
* **Control the timeline** — Set a custom expiry date to match your campaign window.
You'll need to create a campaign to be able to send rewards to recipients. [Click here](/send-rewards/reward-links/reward-link-customize-reward-communication) to learn how.
***
### How to Send a Reward Link to an Individual
Log in to the **Plum Admin Portal**. Navigate to **Send Rewards > Reward Link**. Click **Campaigns** and use the drop-down to choose the campaign you want to use.
Pro tip: You can also edit the campaign directly from this page before proceeding.
On the **Add Recipients** page, select **Select Individually**.
Provide the recipient's **name** and **email address**.
Customize the reward communication for this recipient. Add internal notes for reference.
To send the same Reward Link to additional people, select the option to add a recipient and enter their details. Repeat as needed.
Set how long the Reward Link will remain active by choosing an expiry period (**1, 2, 3, 6, 9, or 12 months)** or pick a **Custom date** to match your campaign timeline. The default is **12 months**.
Review the recipient details and communication preview, then click **Send Reward**. The Reward Link will be delivered to each recipient immediately.
***
### Need to send to multiple recipients?
Use the bulk upload option to send Reward Links to a large list at once. [Learn how to send Reward Links in bulk](https://help-plum.xoxoday.com/send-rewards/reward-links/send-reward-links-bulk-upload)
Feedback or questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Send to Self
Source: https://help-plum.xoxoday.com/send-rewards/reward-links/send-reward-links-to-self
Learn how to generate Reward Links in bulk and distribute them through your own channels via the Plum Admin Portal.
## What is Reward Link?
Reward Link lets you create campaigns and deliver rewards through a single shareable link — via email, SMS, WhatsApp, or any channel you prefer. Recipients click the link and choose a gift card from a curated selection of leading global brands, with no account required.
**Reward Link works best when you want to:**
* **Keep redemption simple** — Recipients claim their reward instantly, without signing up.
* **Create a branded experience** — Build campaigns with a custom micro-landing page and hand-picked gift card options.
* **Control the timeline** — Set a custom expiry date to match your campaign window.
You'll need to create a campaign to be able to send Reward link rewards to recipients. [Click here](/send-rewards/reward-links/reward-link-customize-reward-communication) to learn how.
***
## Send Reward Links to Self
Use this option when you want to manage recipient communication yourself, for example, through your own email, internal tools, or any channel outside the platform.
Choose the campaign you want to use from the list of available campaigns.
Pro tip: You can also edit the campaign directly from this page before proceeding.
Enter email ID and the number of Reward Links you need. Each link can be distributed to a separate recipient.
Set how long each Reward Link will remain active by choosing an expiry period ( **1, 2, 3, 6, 9, or 12 months)** or pick a **Custom date** to match your campaign timeline. The default is **12 months**.
Once you're ready, click **Send Reward** at the bottom of the page.The Reward Links will be generated and delivered to you for distribution.
***
### Other ways to send Reward Links
You can also send Reward Links directly to recipients — one at a time or in bulk.
[Learn how to send a Reward Link to an individual recipient](https://help-plum.xoxoday.com/send-rewards/reward-links/send-reward-links-send-individually) [Learn how to send Reward Links in bulk](https://help-plum.xoxoday.com/send-rewards/reward-links/send-reward-links-bulk-upload)
Feedback or questions: Email at [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Comparison Guide
Source: https://help-plum.xoxoday.com/send-rewards/reward-modes/comparison-of-when-to-use-what
Compare Plum's reward modes side by side to decide when to use gift cards, reward links, reward codes, or reward points for your use case.
*Learn about the best use-case fit for each of currency (aka Mode of rewarding). It's benefits and end-user experience.*
## Reward Code Vs Reward Points Vs Reward Link | Differences
| **Feature Name** | **What it means** | **Reward Points** | **Reward Code** | **Reward Link** | **Brand Gift Cards** |
| :------------------------------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------- | :---------------- | :-------------- | :-------------- | :------------------- |
| Email Registration (DIY/Self Serve) | Set up an account independently without any assistance from the team. | Yes | Yes | Yes | Yes |
| Campaign Creation | The ability to customize catalog, add landing page, customize templates with brand logos, etc. | No | Yes | Yes | No |
| Bulk Rewards | Option to send rewards to hundreds and thousands of recipients. | Yes | Yes | Yes | Yes |
| Individual Rewards | Sending rewards manually to recipient | Yes | Yes | Yes | Yes |
| Rewards API | It allow developers to implement seamless rewards and coupon systems into their applications giving the flexibility to execute any sort of campaigns. | Yes | Yes | Yes | Yes |
| Omnichannel Delivery (email, SMS) | Marketing communication across multiple channels like emails, SMS, WhatsApp, etc. | Yes | Yes | Yes | Yes |
| Integrations (CRM. HRMS, Survey tools) | Connects seamlessly with existing marketing automation tools, HR tools, and other productivity tools. | No | No | Yes | Yes |
| Reward Accumulation | It allows you to accumulate and redeem rewards at your convenience based on the value in the designated currency. | Yes | No | No | No |
| Custom Expiry | The ability to change the expiry date for rewards Offered expiry options are 3,6, and 9 months. It's 12 months by default. | No | Yes | Yes | No |
| Landing Page (Campaign specific) | A company branded web page that allows you to display a welcome screen, personalized message, and customize campaign as per brand requirements. | No | Yes | Yes | No |
| Distribution | The mechanism in which rewards are distributed for a reward program based to achieve desired outcomes. | API, CSV, Email | API, CSV | API, CSV | API, CSV |
## **Benefit comparison**
| **Benefits** | **What it means** | **Reward Points** | **Reward Code** | **Reward Link** | **Brand Gift Cards** |
| :------------------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------- | :---------------- | :-------------- | :-------------- | :------------------- |
| Ease of Choice | Ease to the end users in choosing rewards redemption as per their choice | Yes | Yes | Yes | No |
| Ease of Distribution | Flexibility in terms of distributing rewards which can be different based on the rewarding use-case. | Yes | Yes | Yes | Yes |
| Personalization (Branding) | The ability to add personalized messages and customize campaigns as per brand guidelines to keep it consistent. | No | Yes | Yes | No |
| Flexible Denominations | It allows for variations in the value or size of denominations in a particular currency and offers the flexibility to accommodate different transactional needs | Yes | Yes | Yes | Limited |
| Multi Currency | It offers uses to send rewards in multiple currencies. | Yes | Yes | Yes | No |
| Applicable in multiple countries | Rewards catalog across countries or geographies. | Yes | Yes | Yes | No |
| Multi-region deployment | Ability to deploy the servers in specific regions | Yes | Yes | Yes | No |
| Multi-lingual | Ability to show marketplace, emails, notifications and platform in different languages | Yes | Yes | Yes | No |
| Reward Scheduling | The ability to schedule rewards for the future date. | Yes | Yes | Yes | Yes |
| Redemption reports | It refers to records or summary of rewards redeemed by the user. | Yes | Yes | Yes | No |
| Catalog Customisation | Offers the flexibility to choose catalog options like gift cards, merchandise, charity, experiences, travel and more for the campaign. | Yes | Yes | Yes | Yes |
| Customer Support | Dedicated support team or CSM for resolving customer queries. | Yes | Yes | Yes | Limited |
| Reward Cancellation\* | The option to cancel the rewards sent within 180 days of reward sent date | Yes | Yes | Yes | No |
| Transferable | The option to transfer the reward points associated with the account to another account or user | No | Yes | Yes | No |
| Linked to Email/Mobile number | Reward associated to a particular account. | Yes | No | No | No |
| Anonymous Redemption | The ability to allow the redemption of rewards without revealing contact details such as email or phone number | No | Yes | Yes | No |
| Generation to Self | The ability to generate rewards for self which can be sent to others. | No | Yes | Yes | Yes |
## **Rewards & Redemption Categories**
| **Reward Category** | **What it means** | **Reward Points** | **Reward Code** | **Reward Link** | **Brand Gift Cards** |
| :------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------ | :---------------- | :-------------- | :-------------- | :------------------- |
| Gift Cards | Brand Vouchers or Cards that can be redeemed in online retail stores, restaurants, or any other service providers. | Yes | Yes | Yes | Yes |
| Non Profit Donations | Monetary or in-kind contributions made to non-profit organizations or initiatives that operate for the benefit of the public or a specific cause. | Yes | Yes | Yes | No |
| Prepaid Cards | Payment cards from Visa/Mastercard loaded with funds which allow users to purchase or access any service. | Yes | Yes | Yes | No |
| Experiences | Experiences that allows end-users to enjoy a wide range of activities like adventure, tours, hobbies, wellness, gourmet, arts, history etc. | Yes | Yes | Yes | No |
| Perks & Offers | Offers & discounts from popular brands in the form of coupons or cashback to the end users. | Yes | Yes | Yes | No |
Feedback or Questions: Email at [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Reward Types
Source: https://help-plum.xoxoday.com/send-rewards/reward-modes/reward-modes-types-overview
Get an overview of the reward modes available in Plum, gift cards, reward links, reward codes, and reward points, and how each one works.
*Learn about different modes of rewards and explore the best fit for your use-case, its benefits, and user experience.*
Plum is made to handle all your rewarding needs effortlessly! Whether the intended recipient is an employee, a customer, or a partner — Plum lets you reward anyone, anywhere, in your own special way.
## 1. Reward Code(s)
Reward code provides a fast and secure method to send unique reward codes to different participants in your ecosystem, regardless of their location.
Learn how to send a reward code here [Reward Code](/send-rewards/reward-code/reward-code-overview).
### About
A Reward code is a 16 digit alpha numeric code that looks something like this: **S1H2-R3E4-D5I6-S7T8B**
Here are some of the features:
* Allows guest checkout (recipient doesn't need to log in)
* Allows partial redemption
* Can be combined with up to 10 codes for a single checkout!
### Best fit if you want to:
* Allow easy redemption from our marketplace without account creation.
* Enable partial redemption or combining codes for larger rewards.
* Launch campaigns with unique landing pages and reward catalogs.
* Set expiry dates tailored to campaign duration and needs.
## 2. Reward Point(s)
Give out reward points that can be accumulated, allowing users to stack up their Reward Points for redemption from our extensive rewards catalog.
Learn how to send reward points here [Reward points.](/send-rewards/reward-points/send-reward-points-send-individually)
### Best fit if you want to:
* Instantly transfer points to the recipient’s account, automatically adding to their existing balance.
* Recipients can choose to redeem all Reward Points at once or in parts for flexibility.
* Reward points are sent to the recipient’s email or phone, accessible anytime via login.
## 3. Reward Link(s)
Quickly create campaigns and distribute rewards with Reward Link. Share the link through any channel, allowing recipients to redeem rewards from a curated list of global brands easily.
Learn how to send a reward link here [Reward Links.](/send-rewards/reward-links/send-reward-links-send-individually)
### Best fit if you want to:
* Quickly distribute rewards within minutes.
* Provide recipients with one-click redemption, no account creation needed.
* Create campaigns with unique landing pages displaying curated brand lists.
* Customize link expiry dates to match campaign needs.
## 4. Brand Gift Card (Brand Vouchers)
Instantly send brand gift cards directly to recipients' inboxes. There are over 8,000 top global brands from Amazon to Walmart and everything in between!
Learn how to send a brand gift cards here [Brand Gift Cards.](/getting-started/for-end-users/gift-vouchers-faqs)
### Best fit if you want to:
* Rapidly distribute gift cards within minutes.
* Offer hassle-free redemption with specific brand gift cards, no login or registration required.
* Generate a gift card for yourself, shareable via any channel.
Feedback or Questions - Email to [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Overview
Source: https://help-plum.xoxoday.com/send-rewards/reward-points/reward-points-overview
Get an overview of Plum reward points, how recipients accumulate a balance, and how they can redeem it in the reward marketplace.
*Learn about the concept of reward points and their use cases.*
## What are Xoxo Reward Points?
Xoxo Reward Points can be used by HR heads or CXO''s of a company to distribute rewards and incentivize their employees, stakeholders, or channel partners. Distributed points can be used by the recipients on the Plum Stores Platform.
***
## Instructions
* Xoxo Reward Points is the main unit of reward. It is at the core of all transactions. All Catalog Prices & Rewarding will be done based on these Points.
* The conversion value of points is equivalent to the base currency selected during sign-up. So if USD is selected as the base currency, 1 Point = 1 USD, and if EUR is selected as the base currency, 1 EUR = 1 Point.
* Xoxo Reward Points are instantly Transferred to a User account. The email Id of the recipient is the unique identifier.
* The reward points have an expiry of 1 year from the date of issue.
* Points are accumulated in the user account and they can redeem them in single or multiple transactions, irrespective of how the reward is received. The System takes care to consume the oldest points first to make sure points are used up optimally.
* Xoxo reward points can be created by Super Admin and Admins under the threshold set for each Admin.
* Xoxo reward points can be used by the employees, stakeholders, channel partners, etc.
Feedback or Questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Bulk Upload
Source: https://help-plum.xoxoday.com/send-rewards/reward-points/send-reward-points-bulk-upload
Learn how to send reward points to many recipients at once using a bulk file upload in Plum, saving time on large distributions.
*Learn how to send reward points to many recipients at once.*
Users must be registered on Plum to receive points; if not, they will receive a registration link to set up their account.
***
## Send Reward Points to Recipients
Navigate to **Send Rewards > Reward Points** in the main menu.
Select the **Send in Bulk** option. To efficiently reward a large group of recipients, upload the CSV file by clicking the option provided.
**Pro tip:** Download the available template directly from the dashboard for your convenience.
After uploading the file, click on **Next** to move ahead.
Customize the marketplace.
Customize the communication for email and SMS.
Once done, click on **Send Rewards.**
***
## Resend Reward Points in Bulk
Navigate to **Reports > Reward Points.**
**Select Contacts:** Choose the contacts you want to resend the rewards.
**Resend Option:** Click the three dots next to the selected contacts, then click **'Resend'.**
**Confirm Action:** A confirmation pop-up will appear. Click **'Yes, Proceed'** to resend the rewards.
Feedback or Questions: Email [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Send Individually
Source: https://help-plum.xoxoday.com/send-rewards/reward-points/send-reward-points-send-individually
See how to send reward points to a single recipient individually in Plum, useful for one-off or performance-based rewards.
*Learn how to send reward points to a few recipients at a time.*
Users must be registered on Plum to receive points; if not, they will receive a registration link to set up their account.
***
Enter the user's "**Name**," "**Email ID**," "**Number of Points**," and "**Mobile Number**."
Optionally, provide a citation explaining the purpose of the points, such as Long-time employee, Birthday, Work Anniversary, etc.
Once all user details are entered, proceed to distribute the points.
* Users must be registered on Plum to receive points; if not, they will receive a registration link.
* Points will be deducted from the existing "Company Balance"; if insufficient, you'll receive a warning to recharge or remove entries.
Click **"Send Reward"** to instantly deliver the reward to the user's account via email.
***
## Advanced Settings
Here are some advanced settings that you can use to customize your reward points.
With advanced settings you can use following:
* Schedule the reward sends to a future time date. It will be sent out at 12 AM in the UTC.
* Add a personal message in the email body for the recipient. The message that you enter here will be sent to all the recipients in the batch. Except otherwise as indicated in the .CSV file in case of bulk.
* You can also add an internal reference note — a note to self that you'll can recall at a later time.
For feedback or questions: Email to [cs@xoxoday.com](mailto:cs@xoxoday.com)
# Rewards Hub
Source: https://help-plum.xoxoday.com/walkthrough-videos/plum-product-videos
Watch a collection of Plum product walkthrough videos covering key features and common workflows in the platform.
*Learn how to get started with Xoxoday Plum with these Product Walkthrough Videos.*
## Onboarding
### Getting Started with Plum - Create Account and Verify KYB
In this step-by-step guide, learn how to create your Plum account and complete the KYB (Know Your Business) verification process. We'll walk you through the sign-up, document upload, and approval steps so you can get started with sending rewards quickly and compliantly.
***
## Settings
### How to Apply for Amazon Global Verification
Learn how to apply for Amazon Global Verification within Plum to enable seamless reward delivery using Amazon Global vouchers. This video guides you through the verification process, including document submission and brand compliance, so you can start offering Amazon rewards across supported countries.
### How to Apply for Amazon India Verification
Learn how to apply for Amazon India Verification within Plum to enable seamless reward delivery using Amazon India vouchers. This video guides you through the verification process, including document submission and brand compliance, so you can start offering Amazon rewards in India.
### How to Manage Storefront Catalog, Customise Branding and More
Learn how to manage your Plum storefront by customising the reward catalog, updating branding elements like logos and colours, and configuring settings to create a seamless, on-brand reward experience.
### How to Add and Authenticate Your Domain to Send Emails
Learn how to add and authenticate your domain in Plum to enable secure, branded email sending. This video walks you through domain setup, DNS configuration, and verification steps to ensure your emails land in inboxes with your company's name.
### How to Manage Team and Access Levels in Plum
Learn how to manage your team on Plum by adding members, assigning roles, and sharing access securely. This video covers everything you need to collaborate efficiently while maintaining control over who can view and manage different parts of your account.
### How to Set up Low Balance Alerts
Learn how to set up low balance alerts in Plum to stay informed when your account balance drops below a set threshold. This ensures uninterrupted reward distribution by helping you top up on time and avoid delays.
***
## Payments
### How to Add Funds to Wallet
Learn the simple steps to add funds to your Xoxoday Plum wallet. This video covers multiple payment options, wallet management tips, and how to ensure your account is always ready for seamless reward distribution.
### How to View & Download Transaction History
This video shows you how to easily download your transaction history in Xoxoday Plum. Learn to access detailed reports of all your wallet activities and export them for record-keeping and analysis.
***
## Campaigns
### How to Create Reward Code Campaigns
Learn how to easily create and manage Reward Code Campaigns in Xoxoday Plum. This video guides you step-by-step through setting up reward codes, customising campaign details, and distributing codes to your audience to drive engagement and incentivise actions effectively.
### How to Create Reward Link Campaigns
Discover how to create and launch Reward Link Campaigns in Xoxoday Plum. This tutorial walks you through generating personalised reward links, configuring campaign settings, and sharing links effortlessly to engage your users and boost participation.
***
## Send Rewards
### How to Send Reward Codes
Learn how to quickly and securely send reward codes to your recipients using Xoxoday Plum. This video guides you through selecting the right campaign, choosing delivery methods, and tracking the status of your sent rewards.
### How to Send Reward Points
[Open](https://app.supademo.com/demo/cm8mqb9g9000djryxm4pca47i/edit#ai) Learn how to easily send reward points to your recipients using Xoxoday Plum. This video guides you through selecting users, specifying point amounts, and completing the transfer quickly and securel
### How to Send Reward Links
Learn how to send reward links to your recipients effortlessly with Xoxoday Plum. This video shows you how to generate reward links and share them quickly via multiple channels for seamless reward distribution.
### How to Send Gift Cards
Learn how to send gift cards easily using Xoxoday Plum. This video guides you through selecting gift card options, adding recipient details, and delivering digital gift cards quickly and securely.
***
## Reports
### How to View and Download Reports
Learn how to access, view, and download detailed reports in Xoxoday Plum. This video guides you through navigating the reports dashboard, filtering data, and exporting reports for your records and analysis.
***
## Integrations
### Xoxoday Plum X Hubspot Integration
Discover how to integrate Xoxoday Plum with HubSpot to automate and personalize reward campaigns. This video walks you through connecting both platforms, mapping contact data, and triggering rewards directly from your HubSpot workflows.
### Xoxoday Plum X Typeform Integration
Learn how to integrate Xoxoday Plum with Typeform to automate reward distribution based on form responses. This video covers how to connect both platforms, set up triggers, and send rewards instantly when users complete a Typeform.
### Xoxoday Plum Salesforce Loyalty Account Walkthrough
Get a complete walkthrough of the Salesforce Loyalty Account integration with Xoxoday Plum. This video shows you how to manage loyalty points, track member activity, and deliver personalized rewards—all within your Salesforce environment.
### Xoxoday Plum X Qualtrics Integration
Learn how to integrate Xoxoday with Qualtrics to automate reward distribution based on survey responses. This video guides you through connecting both platforms, setting up response-based triggers, and sending personalized rewards to boost survey participation.
### Xoxoday Plum X Zapier Integration
Discover how to connect Xoxoday with thousands of apps using Zapier. This video walks you through setting up Zaps to automate reward workflows—triggering rewards from actions in tools like Google Forms, Slack, HubSpot, and more without writing any code.
### Xoxoday Plum X SurveyMonkey Integration
Learn how to integrate Xoxoday with SurveyMonkey to automatically send rewards based on survey responses. This video walks you through connecting both platforms, setting up triggers, and ensuring timely, personalized reward delivery to boost response rates.
### Xoxoday Plum X Zoho People Integration
Learn how to integrate Xoxoday Plum with Zoho People to seamlessly automate employee recognition and reward workflows. This video walks you through connecting both platforms, configuring eligibility and applicability settings, awarding points directly within Zoho People, and enabling employees to redeem their rewards — all without leaving their HRMS.
### Redeem Rewards inside SAP SF
Learn how to redeem your earned rewards and purchase gift cards directly within SAP to easily access your favorite perks. This video guides you through the complete redemption process, including browsing the integrated catalog and checking out with your points, so you can instantly start enjoying your benefits without ever leaving your SAP workspace.
***
## How to Redeem
### How to Redeem Reward Code
This video guides you through the quick and easy process of redeeming a reward code on Xoxoday Plum. Learn how to enter your code, browse available options, and complete your redemption in just a few clicks.
### How to Redeem Reward Points
Learn how to redeem your reward points seamlessly on Xoxoday Plum. This video walks you through checking your points balance, exploring the catalog, and using your points to claim exciting rewards.
### How to Redeem Reward Link
This video shows you how to redeem a reward received via a Xoxoday Plum reward link. Learn how to open the link, browse available reward options, and complete your redemption in a few easy steps.
***
## Plum Marketplaces
### Plum Offers Marketplace - Mobile View
Explore the Plum Offers Marketplace in this video walkthrough. Discover exclusive deals, discounts, and cashback offers from top brands—all available to you through Xoxoday Plum. Learn how to browse, access, and redeem these exciting offers in just a few clicks.
### Plum Embedded Marketplace Journey
Take a tour of the Plum Embedded Marketplace experience. This video shows how to seamlessly integrate and navigate the marketplace within your platform, offering users easy access to curated rewards and offers without leaving your app.