1. Introduction
Openn.it ("Openn.it", "we", "us", or "our") operates the openn.it link-in-bio and creator operations platform. This Privacy Policy describes how we collect, use, disclose, and protect personal information when you use our website, dashboard, public bio pages, APIs, and related services (collectively, the "Services").
We are committed to compliance with applicable data protection laws including the EU/UK General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act 2023 (DPDPA), the California Consumer Privacy Act as amended by CPRA (CCPA/CPRA), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Singapore's Personal Data Protection Act (PDPA), Australia's Privacy Act 1988, the UAE Personal Data Protection Law, and other laws in jurisdictions where Indian companies lawfully trade and serve customers.
2. Data controller & contact
For most processing activities, Openn.it is the data controller. For agency or enterprise clients processing end-user data on behalf of their customers, Openn.it may act as a data processor - a Data Processing Agreement (DPA) is available on request.
- Privacy inquiries: privacy@openn.it
- General support: support@openn.it
- Data Protection Officer (where applicable): dpo@openn.it
3. Information we collect
3.1 Account & profile data
Name, email address, username, password hash, profile photo, billing details, plan tier, and preferences you provide when registering or updating your account.
3.2 Content & usage data
Bio page content, links, templates, form submissions, shop listings, social compose drafts, inbox messages (when Meta accounts are connected), analytics events, API usage logs, and support communications.
3.3 Visitor & analytics data
When visitors view public bio pages or click short links we may collect IP address (often truncated or hashed), device type, browser, referrer URL, approximate geography, timestamps, scroll depth, and engagement metrics. Form field values submitted on bio pages are stored for account holders' analytics.
3.4 Payment data
Subscription and wallet transactions are processed by Razorpay and other payment partners. We receive transaction IDs and billing status - not full card numbers.
3.5 Cookies & similar technologies
See our Cookie Policy for details on cookies, local storage, and consent mechanisms.
4. Legal bases for processing (GDPR/UK GDPR)
Where GDPR applies, we rely on:
- Contract: to provide Services you request.
- Legitimate interests: security, fraud prevention, product improvement, and aggregated analytics - balanced against your rights.
- Consent: marketing emails, non-essential cookies, and optional integrations where required.
- Legal obligation: tax, accounting, and regulatory compliance.
5. How we use information
- Provide, operate, and maintain the Services
- Authenticate users and secure accounts
- Process subscriptions, wallet payouts, and billing
- Deliver bio analytics, link tracking, and inbox features
- Send service announcements, security alerts, and support responses
- Improve templates, performance, and user experience
- Detect abuse, spam, malware links, and policy violations
- Comply with legal requests and enforce our Terms
We do not sell personal information as defined under CCPA/CPRA.
7. Data retention
We retain personal data while your account is active and for a reasonable period thereafter for backup, dispute resolution, and legal compliance. Analytics aggregates may be retained longer in de-identified form. You may request deletion subject to exceptions (e.g. unpaid invoices, legal holds).
8. Security
We implement technical and organisational measures including TLS encryption in transit, access controls, hashed credentials, monitoring, and regular reviews. No method of transmission over the Internet is 100% secure; please use strong passwords and enable available security features.
9. Your privacy rights
9.1 All users
Access, correct, or delete account data via Settings or by emailing privacy@openn.it.
9.2 EEA & UK (GDPR)
Rights include access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Lodge complaints with your supervisory authority.
9.3 India (DPDPA)
Data principals may access, correct, erase, and nominate representatives. Grievances: dpo@openn.it. Consent may be withdrawn for processing based on consent. Significant data fiduciaries' obligations apply as we scale.
9.4 California (CCPA/CPRA)
Right to know, delete, correct, and opt out of sale/sharing (we do not sell). Non-discrimination for exercising rights.
9.5 Canada (PIPEDA), Singapore (PDPA), Australia, UAE
Residents may request access and correction. We respond within timelines prescribed by local law.
10. Children
Services are not directed to children under 16 (or higher age where local law requires). We do not knowingly collect data from children. Contact us to request deletion if you believe a child has provided data.
11. Changes to this policy
We may update this Privacy Policy. Material changes will be notified via email or in-app notice. Continued use after the effective date constitutes acceptance where permitted by law.
12. Contact
Questions or rights requests: privacy@openn.it · support@openn.it · openn.it/contact