Openn.it logo

Legal

Privacy Policy

How Openn.it collects, uses, and protects personal data - with notices for GDPR, DPDPA, CCPA, and other international frameworks.

Last updated: 7 June 2025

1. Introduction

Openn.it ("Openn.it", "we", "us", or "our") operates the openn.it link-in-bio and creator operations platform. This Privacy Policy describes how we collect, use, disclose, and protect personal information when you use our website, dashboard, public bio pages, APIs, and related services (collectively, the "Services").

We are committed to compliance with applicable data protection laws including the EU/UK General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act 2023 (DPDPA), the California Consumer Privacy Act as amended by CPRA (CCPA/CPRA), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Singapore's Personal Data Protection Act (PDPA), Australia's Privacy Act 1988, the UAE Personal Data Protection Law, and other laws in jurisdictions where Indian companies lawfully trade and serve customers.

2. Data controller & contact

For most processing activities, Openn.it is the data controller. For agency or enterprise clients processing end-user data on behalf of their customers, Openn.it may act as a data processor - a Data Processing Agreement (DPA) is available on request.

  • Privacy inquiries: privacy@openn.it
  • General support: support@openn.it
  • Data Protection Officer (where applicable): dpo@openn.it

3. Information we collect

3.1 Account & profile data

Name, email address, username, password hash, profile photo, billing details, plan tier, and preferences you provide when registering or updating your account.

3.2 Content & usage data

Bio page content, links, templates, form submissions, shop listings, social compose drafts, inbox messages (when Meta accounts are connected), analytics events, API usage logs, and support communications.

3.3 Visitor & analytics data

When visitors view public bio pages or click short links we may collect IP address (often truncated or hashed), device type, browser, referrer URL, approximate geography, timestamps, scroll depth, and engagement metrics. Form field values submitted on bio pages are stored for account holders' analytics.

3.4 Payment data

Subscription and wallet transactions are processed by Razorpay and other payment partners. We receive transaction IDs and billing status - not full card numbers.

3.5 Cookies & similar technologies

See our Cookie Policy for details on cookies, local storage, and consent mechanisms.

5. How we use information

  • Provide, operate, and maintain the Services
  • Authenticate users and secure accounts
  • Process subscriptions, wallet payouts, and billing
  • Deliver bio analytics, link tracking, and inbox features
  • Send service announcements, security alerts, and support responses
  • Improve templates, performance, and user experience
  • Detect abuse, spam, malware links, and policy violations
  • Comply with legal requests and enforce our Terms

We do not sell personal information as defined under CCPA/CPRA.

6. Sharing & subprocessors

We share data only as needed:

  • Service providers: cloud hosting, email delivery, payment processing (Razorpay), analytics, customer support tools - bound by confidentiality and data processing terms.
  • Meta Platforms: when you connect Instagram/Facebook for inbox and compose features, subject to Meta's terms.
  • Your integrations: webhook URLs and API endpoints you configure receive events you trigger.
  • Legal: when required by law, court order, or to protect rights and safety.
  • Business transfers: in connection with merger, acquisition, or asset sale, with notice where required.

International transfers from India, the EEA, UK, or other regions use appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or contractual commitments required under DPDPA and GDPR.

7. Data retention

We retain personal data while your account is active and for a reasonable period thereafter for backup, dispute resolution, and legal compliance. Analytics aggregates may be retained longer in de-identified form. You may request deletion subject to exceptions (e.g. unpaid invoices, legal holds).

8. Security

We implement technical and organisational measures including TLS encryption in transit, access controls, hashed credentials, monitoring, and regular reviews. No method of transmission over the Internet is 100% secure; please use strong passwords and enable available security features.

9. Your privacy rights

9.1 All users

Access, correct, or delete account data via Settings or by emailing privacy@openn.it.

9.2 EEA & UK (GDPR)

Rights include access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Lodge complaints with your supervisory authority.

9.3 India (DPDPA)

Data principals may access, correct, erase, and nominate representatives. Grievances: dpo@openn.it. Consent may be withdrawn for processing based on consent. Significant data fiduciaries' obligations apply as we scale.

9.4 California (CCPA/CPRA)

Right to know, delete, correct, and opt out of sale/sharing (we do not sell). Non-discrimination for exercising rights.

9.5 Canada (PIPEDA), Singapore (PDPA), Australia, UAE

Residents may request access and correction. We respond within timelines prescribed by local law.

10. Children

Services are not directed to children under 16 (or higher age where local law requires). We do not knowingly collect data from children. Contact us to request deletion if you believe a child has provided data.

11. Changes to this policy

We may update this Privacy Policy. Material changes will be notified via email or in-app notice. Continued use after the effective date constitutes acceptance where permitted by law.

12. Contact

Questions or rights requests: privacy@openn.it · support@openn.it · openn.it/contact