Legal

Privacy Policy

1. Scope

This Policy explains how OpenNext AI handles personal information when you browse the directory, follow an outbound link, submit or manage a product, purchase Sponsored placement, report content, contact support, or use the admin service. Third-party product websites and payment-provider pages have their own privacy practices.

2. Information we collect

Our application does not store raw payment-card numbers. Payment providers may collect billing name, address, tax information, card or bank details, device data, and fraud signals under their own policies.

3. How we use information

4. Legal bases

Where a legal basis is required, we process information as necessary to perform a contract or take requested pre-contract steps; for legitimate interests such as operating, securing, measuring, and improving the service; to comply with legal obligations; and with consent where required. You may withdraw consent without affecting earlier lawful processing.

5. Email and account security

Email addresses are encrypted at rest and separately transformed with a keyed, irreversible hash for matching. Magic Link tokens are stored as hashes, expire after 30 minutes, and are single-use. Responses to Magic Link requests are designed not to disclose whether an email matches a product.

Local-development email capture is not used in production. Production transactional emails are intended to be delivered through Resend or a replacement email provider. We do not send marketing email unless a separate lawful opt-in is implemented.

6. Click measurement

Outbound visits pass through an OpenNext AI redirect so that we can count engagement. We do not retain raw IP addresses in the application database. We generate pseudonymous hashes and apply short-window visitor deduplication and basic bot detection. Counts are estimates and may exclude suspected automation or repeated clicks.

7. Cookies and local storage

The service may use strictly necessary cookies or browser storage for security, administrator sessions, request integrity, and click deduplication. We do not currently operate third-party behavioral advertising cookies. If analytics or non-essential cookies are introduced, this Policy and any required consent controls will be updated before use.

8. How we share information

We may share the minimum necessary information with infrastructure and service providers that process data for us, including hosting, PostgreSQL database, email, security, monitoring, and payment services. Dodo Payments or another payment provider may act as payment processor or Merchant of Record and receive order amount, currency, payer email, internal order reference, and product description.

We may also disclose information when required by law; to protect rights, safety, and service integrity; in connection with a genuine business reorganization subject to appropriate safeguards; or at your direction. We do not sell personal information or share it for cross-context behavioral advertising.

9. Public information

Approved product names, descriptions, categories, images, domains, Sponsored status, rank, effective weekly amount, and filtered click count are public. Owner and payer emails, payment-provider identifiers, visitor hashes, and internal audit data are not intended for public display.

10. Retention

We retain information only while reasonably necessary for the purposes described here, including operating active and historical listings, resolving disputes, preventing abuse, maintaining security records, and meeting accounting, tax, payment, and legal obligations. Payment and immutable ledger records may be retained for the period required by applicable law and provider obligations. Removal of a public listing does not require deletion of transaction or audit records.

Because production jurisdiction and provider contracts are not yet finalized, a detailed production retention schedule is TBD before launch. We will publish it after legal and operational review. You may request deletion now, subject to security, legal, fraud-prevention, and recordkeeping exceptions.

11. International processing

OpenNext AI is intended for a global audience, and providers may process information in countries other than yours. Before production launch, we will identify production providers and implement transfer mechanisms required by applicable law. Different countries may provide different levels of data protection.

12. Security

We use measures including encryption, keyed hashing, one-time expiring links, access controls, signed webhook verification, transaction locking, event idempotency, rate limiting, security headers, and audit logging. No system is completely secure, and we cannot guarantee absolute protection.

13. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing; receive portable data; withdraw consent; and complain to a supervisory authority. We may need to verify your identity and authority before responding. Authorized agents may be required to provide proof of authority.

Send requests to support@opennextai.com with the subject “Privacy request.” Mandatory rights and response periods under applicable law remain unaffected.

14. Children

OpenNext AI is not directed to children under 16, and we do not knowingly collect their personal information. Contact us if you believe a child has provided information so we can investigate and take appropriate action.

15. Changes and contact

We may update this Policy as the service, providers, or laws change. Material changes will be identified by a new effective date and any notice required by law. For questions or complaints, use the Contact page or email support@opennextai.com.