Privacy Policy
Effective date: September 9, 2026
1. Information We Collect
OptedOut360 may store account details, verified email addresses, company/workspace relationships, application identifiers, communication preferences, consent records, suppression records, login and audit information, uploaded files, and technical metadata needed to operate the service.
2. Communication Preferences and Consent
We store global, application-level and category-level communication choices, together with history showing when and how preferences changed. Important consent records are retained as history rather than simply overwritten.
3. Email Addresses and Identity Matching
Verified email addresses and email hashes may be used to associate the same person across participating applications while reducing unnecessary duplicate contact records.
4. Application Integrations
Connected applications may send secure server-to-server requests asking whether an optional communication is permitted. OptedOut360 may return an allowed or suppressed decision and a reason. Preference and suppression information may be shared with those applications only as needed to enforce the user's choices and operate the integration.
5. Cookies and Sessions
Session cookies may be used for secure login, CSRF protection, account continuity and other essential service functions.
6. Security
The application is designed to use password hashing, prepared database statements, role-based access, session protection, secure tokens, file validation, HTTPS, audit logging and server-side credential protection.
7. Data Retention
Preference, suppression, consent and audit records may be retained for operational, security, dispute-resolution and compliance-oriented purposes. Retention periods should be configured by the organization according to its obligations.
8. Data Deletion
Users may request account deletion through supported account tools. Some limited records may need to be retained where necessary to preserve a valid suppression request, security history, transaction history, or legal obligation.
9. Third-Party Services
The platform may use services such as SMTP providers and, when enabled, Stripe. Third-party services process information under their own terms and privacy practices.
10. User Rights
Depending on location and applicable law, users may have rights to access, correct, delete, export, or limit certain processing of personal information. OptedOut360 provides tools intended to support these requests.
11. Compliance-Oriented Design
The system is designed to support communication-management concepts associated with CAN-SPAM, GDPR consent and withdrawal, CCPA/CPRA preference concepts, and general email marketing practices. This does not constitute legal advice or automatic legal compliance.
12. Changes
This policy may be updated and versioned by authorized administrators. Changes should include an effective date and appropriate notice when required.
13. Contact
Questions may be submitted through the Support page or the contact method configured by the System Administrator.
Return to Main Page