Privacy Policy

Last updated: February 2, 2026

This policy explains what data OD collects, why we collect it, how it is protected, and the control you have over it. Plain language, no dark patterns.

  1. 1. Information We Collect

    Account information: your name, email address, password (stored hashed, never in plain text), phone number if you provide it, and your agency profile details such as agency name, city, niche and goals.

    Business data you enter: clients, leads, tasks, content, proposals, contracts, invoices, expenses, time logs and notes. This is your data — we store it so the product works.

    Usage data: pages visited, features used, and error diagnostics, used to keep the product stable and to improve it.

    Technical data: IP address, browser type, device type and timestamps, collected automatically when you use the service.

    Integration data: when you connect a third-party account (for example Google, Meta or Stripe), we store the connection tokens and only the data needed to power the feature you enabled.

  2. 2. How We Use Your Information

    To provide and operate the platform, including authentication, storing your agency data, and running the features you use.

    To process subscription payments and manage your billing.

    To send transactional messages: trial reminders, receipts, password resets and important service notices.

    To provide support when you contact us.

    To improve the product through aggregated, de-identified usage analysis.

    We do not sell your personal data, and we do not use your client data to train AI models.

  3. 3. Payment Information

    Payments are processed by Stripe. Card numbers, CVC codes and full billing details are collected and stored by Stripe — they never touch our servers and we cannot see them.

    We store only a customer reference, your plan, subscription status and billing period so we know what access to grant.

    Stripe's handling of your data is governed by Stripe's own privacy policy.

  4. 4. Data Storage and Security

    Application data is stored in a managed Postgres database with row-level security so that each account can only read and write its own records.

    All traffic between your browser and our servers is encrypted with TLS (HTTPS). Data is encrypted at rest by our hosting provider.

    Access to production systems is restricted to personnel who need it to operate the service.

    No system is perfectly secure. If a breach affects your data we will notify you and, where required, the relevant supervisory authority without undue delay.

  5. 5. Data Sharing

    We share data only with service providers that make the product function: our hosting and database provider, Stripe for payments, email delivery providers for transactional email, AI providers for the content features you invoke, and Google for prospecting and maps features.

    These providers act as processors on our instructions and are not permitted to use your data for their own purposes.

    We may disclose data if legally required by valid legal process, or to protect our rights, users, or the public.

    If Ona Digital is involved in a merger or acquisition, your data may transfer as part of that transaction; you will be notified beforehand.

  6. 6. Cookies and Similar Technologies

    We use strictly necessary cookies and local storage to keep you signed in, remember interface preferences, and secure the session.

    We use limited analytics to understand aggregate product usage. We do not run third-party advertising trackers.

    You can clear or block cookies in your browser, but sign-in will not work without the essential ones.

  7. 7. Data Retention

    We keep your account data while your account is active and for a reasonable period afterwards so you can reactivate without losing work.

    You can request permanent deletion at any time by emailing support@onadigital.org; we will delete your data within 30 days except where retention is legally required (for example financial records).

  8. 8. Your Rights

    Depending on where you live — including under the GDPR in the EEA/UK and the CCPA in California — you have the right to access, correct, export, restrict processing of, and delete your personal data, and to object to certain processing.

    You also have the right to withdraw consent where processing is based on consent, and to lodge a complaint with your local data protection authority.

    Most of these actions can be performed directly in Settings. For anything else, email support@onadigital.org and we will respond within 30 days.

    We will never discriminate against you for exercising these rights.

  9. 9. International Transfers

    Our infrastructure is operated in the United States. If you access OD from outside the US, your data is transferred to and processed there under appropriate safeguards, including standard contractual clauses where required.

  10. 10. Children's Privacy

    OD is a business tool intended for adults. It is not directed at anyone under 18, and we do not knowingly collect personal information from children.

    If we learn that we have collected data from someone under 18, we will delete it. Contact support@onadigital.org if you believe this has happened.

  11. 11. Changes to This Policy

    We may update this policy as the product and the law change. The "last updated" date above always reflects the current version.

    Material changes will be announced by email or in-app notice before they take effect.

  12. 12. Contact Us

    Privacy questions, data requests, or complaints: email support@onadigital.org. We respond within two business days and complete formal data requests within 30 days.