Legal
Privacy Policy
Last updated: July 27, 2026
Oprenta ("Oprenta," "we," "us") provides a booking and customer-management platform for service businesses. This policy explains what information we collect, how we use it, and the choices available to you, whether you run a business on Oprenta (a "tenant"), work for one, or are a customer of one.
This is a draft policy prepared during early development, written to accurately reflect what the product actually does today. It has not been reviewed by a lawyer. Before relying on it for real customers or real payments, have it reviewed for your jurisdiction — this matters more once payment processing is live.
1. Information we collect
Account information. When you sign in, we collect your email address. If you sign in with Google or Facebook, we also receive your name and the email address associated with that account, as provided by Google or Facebook.
Business information. If you create a business on Oprenta, we store the business name, a generated identifier (slug), time zone, and currency.
Customer records entered by a business. A business using Oprenta may enter records about its own customers — names, phone numbers, email addresses, WhatsApp/Messenger identifiers, service addresses, and notes. This data belongs to the business that entered it. We process it on that business's behalf and do not use it for our own purposes.
Usage and device information. Standard technical logs (IP address, timestamps, request paths) are recorded for security and debugging.
2. How we use information
- To operate your account: authentication, sending sign-in links, and keeping your session active.
- To provide the service: storing and displaying the business, customer, service, and booking records you create.
- To send transactional communications: sign-in links, team invitations, and (where applicable) booking-related SMS notifications.
- To maintain an audit trail of account and business-critical actions (sign-ins, role changes, record edits) for security purposes.
- To keep the service secure and investigate misuse.
We do not sell personal information, and we do not use customer records entered by a business for advertising.
3. Third parties we share data with
We use the following processors to operate the service. Each has its own privacy policy governing how it handles data on our behalf:
- Google / Facebook — only if you choose to sign in with one of them, to verify your identity.
- Resend — delivers transactional emails (sign-in links, invitations).
- Semaphore — delivers SMS notifications where a business has enabled them.
- Xendit — processes payments where payment collection is enabled for a business. Card and payment details are handled directly by Xendit; Oprenta does not store full payment card numbers.
- Supabase / hosting infrastructure — the database and servers that store the data described above.
We do not share data with third parties for their own marketing purposes.
5. Data retention
We retain account and business data for as long as the account or business is active. Audit-log entries (a record of significant actions like sign-ins and role changes) are retained to support security investigations and are not deleted when a related record is edited.
6. Your rights and choices
You can review and correct most of your business's data directly within the product. For anything not yet self-service — including a full export or account/business deletion — contact us using the details below and we will action the request manually. We aim to respond within a reasonable time and will confirm once a deletion request has been completed.
If you are a customer of a business that uses Oprenta (rather than a business owner or staff member), that business is the one that controls your data — please contact them directly first. If you're unable to reach them, contact us and we will assist.
7. Data deletion instructions
To request deletion of your account, your business's data, or data collected via a third-party sign-in (Google or Facebook), email privacy@oprenta.com from the email address on the account, with the subject line "Data deletion request." Tell us whether you want your individual account deleted, or an entire business and its records deleted. We will confirm receipt and let you know once the deletion is complete.
8. Security
Passwords are not used — sign-in is via one-time links or Google/Facebook. Session tokens are stored hashed on our servers. Access to a business's data is restricted to people you've invited to that business, re-checked on every request.
9. Changes to this policy
We may update this policy as the product changes. Material changes will be reflected by updating the date at the top of this page.
10. Contact
Questions about this policy or a data request: privacy@oprenta.com or hello@oprenta.com.