Privacy Policy
1. Controller
The data controller is Foighne Ventures Limited, Dublin, Ireland (company no. 738028), trading as Opsidion. Privacy contact: [email protected].
2. What we process and why
| Data | Purpose | Lawful basis (Art. 6 GDPR) |
|---|---|---|
| Stripe account data read via OAuth with your authorization: account profile (name, country, business website, account email, verification status), charges, disputes, refunds, Radar signals (including IP geolocation of reviewed payments) | Generating the report you purchased | Performance of a contract (6(1)(b)) |
| Your email address (prefilled from your Stripe profile or entered by you) | Delivering your report as a PDF when you request it | Performance of a contract (6(1)(b)) |
| Payment records (Stripe account ID, checkout/payment identifiers, amount, time) | Granting access to purchased reports, processing refunds, accounting | Contract (6(1)(b)); legal obligation (6(1)(c)) for tax records |
| Session data (a signed random session ID cookie, your OAuth access token stored server-side) | Keeping you signed in securely | Contract (6(1)(b)); legitimate interests (6(1)(f)) in service security |
| Technical logs (timestamps, request outcomes, errors) | Security, abuse prevention, debugging | Legitimate interests (6(1)(f)) |
Product usage (a sequence of short codes for the pages you viewed and the
buttons you pressed, e.g. P1,B3,P2, attached to your session) | Understanding how the product is actually used and where it fails people | Legitimate interests (6(1)(f)) |
Google Analytics data (a randomly generated device identifier stored in the
_ga cookie, pages viewed, approximate location derived from a truncated
IP address, device and browser type, and the site that referred you) | Measuring how people find us and which pages lead to a purchase | Legitimate interests (6(1)(f)); on by default, and you can opt out at any time |
Your Stripe data may include personal data of your customers (e.g. card country, dispute details). We process it solely to produce your report, immediately and transiently. See retention below.
3. Cookies & your choice
Two cookies are strictly necessary and are always set: the signed session cookie that keeps you logged in, and a small cookie recording the analytics choice you made so we don't ask again. Neither is optional, because the service cannot work without the first and the second exists only to honour your answer.
Beyond those we use Google Analytics 4 to understand how people find Opsidion and which pages lead to a purchase. It is on by default. You can turn it off by choosing Accept necessary only on the notice we show you, or at any later time through the Cookie settings link in the footer of any page, on this site or in the app. When you turn it off we stop sending Google any identifier for you and delete the Google Analytics cookies already in your browser. Nothing in the product is withheld or degraded either way.
Your choice is remembered for 180 days, after which we ask again. You can also block or delete these cookies in your browser at any time.
Analytics is never allowed to see your Stripe data, your reports, or anything you type. It sees pages and events only.
4. What we do NOT do
- No advertising cookies and no ad targeting. Google Analytics is configured with advertising features and ad personalisation switched off, so nothing here is used to follow you around the web or build an advertising profile.
- We do measure how our own product is used (the usage row above), but it is tied to the session cookie you already have. We set no additional identifier, store nothing extra in your browser, and the record is a list of numbered codes, never the text you typed, your Stripe data, or your screen. This is separate from Google Analytics and runs whatever you choose above.
- We never sell or share personal data for marketing.
- We never receive or store your card number; payment is handled by Stripe Checkout.
- Reports do not produce legal effects by automated means. They are informational analyses that you choose how to act on (no Art. 22 automated decision-making).
5. Retention
- Report data: reports are generated on demand from Stripe's API and returned to you; the underlying Stripe data is not retained after generation. PDF copies exist only in the download/email we send you.
- Sessions & OAuth tokens: deleted after 7 days of inactivity, on disconnect, or immediately when you revoke access in Stripe.
- Payment records: kept 6 years as required by Irish tax law.
- Logs: kept up to 90 days.
- Product usage: kept up to 90 days, then deleted.
- Google Analytics: event data is retained by Google for 14 months from
your last visit. The
_gacookie expires 2 years after it is set, and is deleted as soon as you opt out. Your choice itself is remembered for 180 days.
6. Recipients & processors
We use a small number of processors under Art. 28 agreements: Stripe (payments and the API you authorize), our hosting provider, our email delivery provider (only when you request an emailed report), and Google Ireland Limited for Google Analytics (unless you have opted out). We disclose data if legally required.
7. International transfers
Stripe, Inc. is a US company; transfers to it rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses. Google Analytics data is collected by Google Ireland Limited and may be transferred to Google LLC in the US under the EU–US Data Privacy Framework and Standard Contractual Clauses; IP addresses are truncated before storage. Where any other processor is outside the EEA, we use SCCs or an adequacy decision.
8. Your rights
Under GDPR you may request access, rectification, erasure, restriction, portability, and and object to processing based on legitimate interests, which for analytics you can do at any time via Cookie settings (objecting does not affect processing already carried out). Write to [email protected]; we respond within one month. You may also lodge a complaint with the Irish supervisory authority: the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28 (dataprotection.ie), or your local EU supervisory authority.
9. Security
OAuth tokens are held server-side only (never in your browser), session cookies are signed and HttpOnly, access is payment-gated per account, and we operate least-privilege read-only use of your Stripe data. Report a security concern to [email protected].
10. Changes
We'll post any changes here with a new effective date. Material changes will be flagged in the app.