OxyPages

Privacy Policy

Last Updated: 2 September 2026


Summary

This is the short version. The full policy below is what governs.


1. Who we are and what this policy covers

OxyPages (https://oxypages.com) is a static-site hosting service operated by Ditra Point, a business established in Malaysia. In this policy "OxyPages", "we", "us" and "our" mean Ditra Point. "You" and "your" mean the person who holds an OxyPages account or who visits oxypages.com or app.oxypages.com.

Ditra Point is the data controller of the personal data described in this policy: we decide why and how it is processed and we are responsible for it. Our contact for every privacy matter, including requests to exercise your rights, is support@oxypages.com.

This policy applies to:

This policy does not apply to the personal data of people who visit websites hosted on OxyPages, submit forms on those websites or are counted by their analytics. For that data we act as a processor on behalf of the site owner. Section 3 explains the distinction and section 10 is addressed to those visitors.

This policy should be read together with our Terms of Service. Where we process personal data as your processor, our Data Processing Agreement governs; it is available on request from support@oxypages.com.

2. Definitions

TermMeaning
Personal dataAny information relating to an identified or identifiable living person. Laws in some places call this "personal information"; the meaning here is the same.
AccountYour registered OxyPages account, whether free or paid.
Customer ContentThe HTML, ZIP archives, files, assets and settings you upload to or create in OxyPages to build a Hosted Site, including anything produced with the AI code editor.
Hosted SiteA website served by OxyPages on a subdomain of myoxypages.com or on a custom domain you connect.
VisitorA person who visits a Hosted Site, submits a form on it or is counted by its analytics.
ControllerThe party that decides why and how personal data is processed.
ProcessorA party that processes personal data on the controller's documented instructions.
Sub-processorA third-party service provider we use to deliver the Service and that processes personal data on our behalf.
ServiceEverything OxyPages provides, as described in the Terms of Service.
Data protection lawThe privacy and data-protection laws that apply to you or to us, wherever you are. Section 21 gives additional information for residents of particular places.

3. When we are your processor, not the controller

When you use OxyPages to host a website, collect form submissions or measure Visitors, the personal data involved belongs to the relationship between you and your Visitors. For that data:

The remainder of this policy concerns the personal data for which we are the controller: your Account, billing, support, affiliate and domain data, your use of our own websites and dashboard, and the limited data we collect from Visitors for our own security purposes (described in section 10).

4. Personal data we collect

We collect only the categories below. We do not collect sensitive personal data (such as health, religious, biometric or precise location data) and we ask you not to send it to us. We do not buy data about you and we do not receive data about you from data brokers, advertising networks or social media platforms.

The "Basis" column states why the law allows us to process each category: because it is necessary for our contract with you; because a law obliges us; because we have a legitimate interest that does not override your rights; or because you consented.

CategoryWhat it includesSourceWhy we collect itBasis
Account identityName, email address, password (stored only as a salted hash), account creation date, plan and status, and the timezone your browser reports (detected automatically and stored so that dates and usage periods are shown in your local time; you can change it in your profile)You; your browserTo create and secure your Account, identify you when you sign in and show times correctlyContract
Google Sign-In dataYour name and email address, received in a Google ID token when you choose to sign in with GoogleGoogle, at your requestTo create or sign you in to your Account without a passwordContract
Two-factor authentication dataThe shared secret for your authenticator app (TOTP), stored encrypted, and whether two-factor authentication is enabledYouTo verify a second factor when you sign inContract; legitimate interest in account security
Bot-check signalsCloudflare Turnstile issues a short-lived token on our sign-up, sign-in and password-reset forms; Cloudflare receives your IP address and browser characteristics to decide whether the request is automatedYour browser, via CloudflareTo keep automated abuse off our authentication formsLegitimate interest in security
Customer ContentHTML, ZIP archives, files, assets, site settings and custom-domain configuration, and any personal data you choose to include in themYouTo host and serve your Hosted SitesContract
AI editor promptsThe instructions you type into the AI code editor, the files in scope for that request, and the output returnedYouTo fulfil the editing request you madeContract
Payment and transaction recordsStripe customer ID; card brand, last four digits and expiry date; plan, amounts, currency, dates, invoices, receipts, refund and failed-payment historyYou (via Stripe) and StripeTo take payment, renew your plan automatically, issue receipts, handle failed payments and keep the records tax law requiresContract; legal obligation
Domain registrant detailsRegistrant name, organisation (if any), postal address, email address and telephone number, and the domain(s) registeredYouTo register the domain in your name as ICANN and the registry require, and to manage renewals and transfersContract; legal obligation (ICANN and registry policy)
Affiliate dataYour payout email address, the referral code and links assigned to you, the Accounts attributed to your referrals, commissions earned and payments madeYou; our systemsTo attribute referrals and pay youContract
Referral attributionThe affiliate or share-link reference stored in the ox_ref cookie when you arrive at oxypages.com from a referral or share link, and the referring Account your sign-up was attributed toYour browserTo credit the person who referred youLegitimate interest in operating the affiliate programme
Unclaimed Links dataThe content published anonymously and a salted hash of the publisher's IP addressThe publisher; your browserTo serve the temporary link and to rate-limit anonymous publishingLegitimate interest in preventing abuse
Support and abuse correspondenceSupport tickets you open, your messages, our replies and any files you attach to a ticket (stored in a private storage bucket accessible only to you and our support staff); abuse reports about a Hosted Site, including the URL reported, the reason given and any contact details the reporter providesYou; the reporterTo answer you, investigate reports and keep a record of what was decidedContract; legitimate interest in responding to reports and enforcing our Terms
Leave-A-Message enquiriesThe name, email address and message you submit through the "Leave A Message" widget on oxypages.com, which anyone can use without an Account. Your message is delivered to our support inbox and, as an alert, to our staff messaging channel (section 15)YouTo receive and answer your enquiryLegitimate interest in answering enquiries; steps taken at your request
Product usage telemetryPages viewed and features clicked inside the dashboard, tied to your signed-in AccountYour use of the dashboardTo understand which features are used, fix problems and improve the productLegitimate interest in improving the Service
Error logsTechnical details of a failure in our systems: the request that failed, the error message, a timestamp and the Account or session it relates toOur systemsTo diagnose and fix faultsLegitimate interest in running a reliable Service
Request and security logsStandard request metadata recorded by our API servers and edge network: IP address, user agent, requested URL, timestamp and response statusYour browser or API clientSecurity, rate limiting, abuse investigation and debuggingLegitimate interest in security
Moderation recordsResults of automated content checks and any manual review of your Hosted Sites, notices sent to you and actions takenOur systems; our staffTo keep illegal and harmful content off the Service and to detect repeat abuseLegitimate interest; legal obligation
Email delivery recordsRecords of the emails we sent you and whether they were deliveredOur systems (via Resend)To prove that required notices were sent and to troubleshoot deliveryContract; legitimate interest

Information we receive from third parties. The only information about you that we receive from others is: your name and email address from Google when you use Google Sign-In; payment outcomes from Stripe; domain status from Dynadot and the registry; the results of Google Safe Browsing lookups on URLs you publish; and the contents of abuse reports that third parties send us about your Hosted Sites.

Information about other people. If you enter another person's details, for example as a domain registrant contact or in Customer Content, you are responsible for having the right to do so.

What you must provide. Your name, email address and a password (or Google Sign-In) are required to open an Account; without them we cannot provide the Service. Payment details are required for paid plans. Registrant contact details are required to register a domain. A payout email is required to receive affiliate commissions. Everything else is optional, and not providing it does not affect the rest of the Service.

5. How we use personal data and why

We use personal data for the purposes below and for no others.

PurposeData usedBasis
Creating, securing and administering your AccountAccount identity, Google Sign-In data, two-factor data, bot-check signalsContract; legitimate interest in security
Hosting and serving your Hosted Sites, custom domains and formsCustomer Content, request logsContract
Providing the AI code editorAI editor prompts and files in scopeContract
Taking payment, auto-renewing your plan, issuing receipts and following up failed paymentsPayment and transaction recordsContract
Keeping accounting and tax recordsPayment and transaction recordsLegal obligation
Registering, renewing and transferring domains in your nameDomain registrant detailsContract; legal obligation
Operating the affiliate programme and paying commissionsAffiliate data, referral attributionContract; legitimate interest
Serving Unclaimed Links and rate-limiting anonymous publishingUnclaimed Links dataLegitimate interest
Answering support requests, Leave-A-Message enquiries and abuse reportsSupport and abuse correspondence, Leave-A-Message enquiries, Account identityContract; legitimate interest
Detecting and preventing fraud, abuse, phishing, malware and other illegal or harmful contentModeration records, request and security logs, Customer ContentLegitimate interest; legal obligation
Sending the service emails described in section 14Account identity, email delivery recordsContract; legal obligation
Understanding how the dashboard is used and improving the ServiceProduct usage telemetry, error logsLegitimate interest
Establishing, exercising or defending legal claims and complying with law, court orders and regulatorsAny category, as relevantLegal obligation; legitimate interest

Legitimate interests. Where we rely on a legitimate interest we have considered whether it is outweighed by your interests, rights and freedoms and concluded that it is not, because the processing is limited, expected and low-risk. You may object to any processing based on legitimate interests (section 19).

No secondary uses. We do not use personal data for advertising, for profiling for marketing purposes, for sale or rental to third parties, or to build models about you. We do not use Customer Content, prompts, form submissions or any other personal data to train artificial intelligence models, and our AI provider is contractually limited to processing your request.

6. Signing in: Google Sign-In, two-factor authentication and bot checks

Email and password. Your password is stored only as a salted hash. We cannot read it and we will never ask you for it.

Google Sign-In. If you choose "Sign in with Google", we use Google Identity Services loaded on our own origin. Google authenticates you and returns an ID token to us containing your name and email address. We use those two fields to create or match your Account. We do not receive your Google password, contacts, calendar, files or any other Google data, and we do not request access to any Google API beyond sign-in. Google's own privacy policy governs what Google collects when you use its sign-in; you can review or remove the connection in your Google Account's security settings.

Two-factor authentication (TOTP). If you enable two-factor authentication we store the shared secret needed to verify codes from your authenticator app. We store it encrypted and use it only for verification.

Cloudflare Turnstile. Our sign-up, sign-in and password-reset forms are protected by Cloudflare Turnstile. Turnstile runs in your browser and sends signals about the request (including your IP address and browser characteristics) to Cloudflare, which returns a token that we verify. We do not receive the underlying signals. Cloudflare processes them under its own privacy policy and as our sub-processor.

7. Payments, saved cards and auto-renewal

Payments are processed by Stripe. When you pay, you enter your card details on a Stripe-hosted page or in Stripe's secure payment elements; the full card number and security code go directly to Stripe and never touch our servers.

We store:

Auto-renewal. Paid plans and domain registrations renew automatically using your saved card unless you cancel before the renewal date. We send a reminder before renewal and a receipt after each charge. If a charge fails we will email you so that you can update your card (section 14).

Stripe acts as an independent controller for the card data it holds and for its own fraud-prevention processing, and as our processor for the rest. Stripe may set cookies on its payment pages for fraud prevention. Stripe's privacy policy is at https://stripe.com/privacy.

8. Domain registration

When you register a domain through OxyPages, you are the registrant: the domain is registered in your name, not ours. Our registrar is Dynadot, LLC (United States).

To register a domain, ICANN and the relevant registry require the registrant's name, postal address, email address and telephone number. We pass those details to Dynadot, which passes them to the registry. Dynadot and the registry process them under their own policies and under ICANN's Registrar Accreditation Agreement, which requires the registrar to keep registration records for at least two years after the registration ends.

Public WHOIS and RDAP. Registration data may be published in the public WHOIS or RDAP directory to the extent ICANN or the registry requires. Where the registrar offers WHOIS privacy or redaction for your domain, we enable it by default.

Verification emails. ICANN requires the registrar to verify the registrant's email address. You may receive verification emails from Dynadot directly; failing to respond can suspend the domain.

Retention. Domain registration records are kept for as long as ICANN and the registry require, even after your Account is closed (section 17).

9. AI code editor, content moderation and automated decisions

AI code editor. When you use the AI editor, your prompt and the files in scope are sent to our AI provider, Moonshot AI, to generate the result. The provider processes the request on our behalf and is contractually restricted to that purpose. Your prompts and content are not used to train the provider's models or ours. Do not include personal data in prompts unless you need to.

Automated content moderation. To keep phishing, malware and other illegal or harmful content off the Service, published content is checked automatically by:

Content flagged by these checks is reviewed by a member of our team before any decision to suspend an Account or remove a site. An automated check may temporarily restrict serving of a page pending that review, for example where Safe Browsing reports a URL as malicious. We record the result of checks and reviews (section 4, "Moderation records") so that we can recognise repeat abuse.

Automated decisions. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Any suspension, termination or removal decision is taken or reviewed by a person. If you believe a moderation action was wrong, email support@oxypages.com; a person will review it, and you may put your point of view and contest the decision.

Manual review. Our staff may view Customer Content when investigating an abuse report, a moderation flag, a support ticket you have opened, or a security incident. We do not browse Customer Content otherwise.

10. Visitors to sites hosted on OxyPages

This section is written for Visitors. If you are reading this because you visited a website hosted on OxyPages, the owner of that website is the controller of your personal data and their privacy notice governs. This section explains what OxyPages does with Visitor data on the owner's behalf and how to exercise your rights.

Serving the site. To deliver the page you requested, our edge network (Cloudflare) receives the standard data any web request carries: your IP address, the URL requested, your browser's user-agent string and referrer. This is used to serve the response, protect the site from attack and produce the analytics described next.

Analytics: no cookies, no scripts, no raw IP addresses. Visitor analytics are counted at the edge when the page is served. No analytics script runs in your browser and no cookie or other identifier is set. Your IP address is hashed together with a secret salt that rotates every day; the hash is used only to estimate unique visitors within that day and the raw IP address is never written to storage. What the site owner sees are monthly aggregates: page views, bytes served, paths, countries, referrers, and device, operating system and browser families. Nothing in those aggregates identifies you.

Forms. If you submit a form on a Hosted Site, the data you enter is stored in the site owner's OxyPages Account and, if the owner has enabled notifications, emailed to the owner. We store submissions for the owner and act only on the owner's instructions. We do not read, use or share form submissions for any purpose of our own.

Password-protected sites. If a Hosted Site is password-protected, entering the password sets a cookie in your browser so that you do not have to enter it on every page. The cookie is strictly necessary to provide the protected site and contains no personal data.

Do Not Track and Global Privacy Control. Because no tracking takes place on Hosted Sites, there is nothing for a Do Not Track or Global Privacy Control signal to switch off. We honour them by design.

Our own limited use. Independently of the site owner, we use request metadata for the security, abuse-prevention and moderation purposes in section 5, for which we are the controller. This is limited to what is needed to keep the Service safe.

Exercising your rights. To access, correct or delete personal data you gave to a Hosted Site, contact the site's owner; the contact details should be in their privacy notice or on the site. If you cannot reach the owner, email support@oxypages.com with the site address and we will forward your request to the owner and assist them in responding. Where the law requires us to act directly, we will.

Affiliate programme. If you join the affiliate programme we collect your payout email address and keep records of the referral links assigned to you, the Accounts attributed to your referrals, commissions earned and payments made. Commission records are transaction records and are retained as tax law requires.

Referral attribution. When someone arrives at oxypages.com through an affiliate link (a URL containing a "?r=" parameter) or a share link, we set a first-party cookie named ox_ref containing only the referral reference. It lasts 60 days. If that person opens an Account within 60 days, the referral is attributed to the referrer. The cookie is set only on oxypages.com, is not shared with any third party and is not used for any other purpose. Anyone can delete it in their browser settings; doing so simply removes the attribution.

What affiliates see. Affiliates see aggregate statistics and their commission balance. We do not disclose the name or email address of referred customers to the affiliate.

Share and clone links. If you generate a share link for a Hosted Site, anyone with the link can view the site and, where you allow it, clone it into their own Account. Anything in the shared site, including any personal data you put in it, is visible to anyone who has the link. Sign-ups made through a share link are attributed to you in the same way as affiliate referrals.

Unclaimed Links. Unclaimed Links let anyone publish a page without an Account. The page lives for 30 minutes and is then deleted unless it is claimed into an Account. We do not ask for any personal data to publish an Unclaimed Link. We store a salted hash of the publisher's IP address solely to limit how many links one address can create; the raw IP address is not stored, and the hash cannot be turned back into it. Content published as an Unclaimed Link is subject to the same moderation checks as any other Hosted Site.

12. API keys, the MCP server and developer data

Every plan can create API keys and connect the OxyPages MCP server to compatible tools. An API key is a credential tied to your Account. Requests made with your key, including requests the MCP server makes on your behalf, are treated as made by you and are logged in the same way as dashboard requests (section 4, "Request and security logs"). We record which key made a request so that you can see and revoke keys.

Keep keys secret. Anyone who has your key can act as you. You can revoke a key at any time from the dashboard. If you believe a key has been exposed, revoke it immediately and email support@oxypages.com.

Your MCP client. When you use the MCP server through a third-party AI assistant or agent, the data our API returns (including your Customer Content and site settings) is passed to that assistant and its provider. That provider's terms and privacy policy govern what it does with the data; we do not control it and this policy does not cover it.

13. Cookies, Do Not Track and Global Privacy Control

We use only the cookies below. All of them are first-party. We set no analytics, advertising or cross-site tracking cookies, and we do not embed third-party trackers, pixels or social media widgets. Because there are no optional cookies to consent to, we do not show a cookie banner.

CookieSet onPurposeLifetimeType
Authentication and session cookiesapp.oxypages.comKeep you signed in and protect against cross-site request forgerySession, or until you sign outStrictly necessary
ox_refoxypages.comAttribute a sign-up to the affiliate or share link that referred it (section 11); set only when you arrive through such a link60 daysReferral attribution
Password-gate cookiePassword-protected Hosted SitesRemember that you entered the site passwordSessionStrictly necessary (set as processor for the site owner)
Stripe cookiesStripe payment pages and elementsFraud prevention during checkoutSet and governed by StripeStrictly necessary for payment
Cloudflare security cookiesOur sites and Hosted Sites, where Cloudflare's bot protection requires themDistinguish legitimate traffic from attacksSet and governed by CloudflareStrictly necessary

Local storage. The dashboard may store interface preferences (such as theme) in your browser's local storage. That data stays on your device.

Managing cookies. You can block or delete cookies in your browser settings. Blocking the authentication cookie will prevent you from signing in; deleting ox_ref removes referral attribution and nothing else.

Marketing-site analytics. If we measure traffic to oxypages.com, we do so with the same cookieless, edge-counted method described in section 10. No analytics cookie or third-party analytics script is used.

Do Not Track and Global Privacy Control. We honour both signals by design. We do not sell or share personal data, run targeted advertising or track you across sites, so there is nothing further for these signals to switch off. Where a law treats a Global Privacy Control signal as an opt-out request, we treat it as honoured.

14. Emails we send

We send email only from noreply@oxypages.com, delivered by Resend. We send:

EmailTriggerBasis
Account and authentication emails: email verification, password reset, sign-in and security alertsYour actions or a security eventContract; security
Welcome emailOpening an AccountContract
Receipts and invoicesA successful paymentContract; legal obligation
Renewal reminders and failed-payment noticesAn upcoming renewal or a failed chargeContract; legal obligation to disclose auto-renewal
Form notificationsA Visitor submits a form on your Hosted Site, if you enabled notificationsContract (we act as your processor)
Support repliesWe reply to a support ticket you opened or a message you leftContract; legitimate interest
Moderation noticesA moderation check or review affects your Hosted SiteContract; legitimate interest
Domain noticesRegistration, renewal, transfer or verification eventsContract; legal obligation
Legal and policy noticesMaterial changes to this policy or the Terms; legal requirementsLegal obligation; contract

These are service emails; they are necessary to operate your Account and cannot be unsubscribed from while the Account is open, except that you may switch off form notifications in your dashboard.

Marketing email. We do not currently send marketing or promotional email. If we introduce a newsletter or product announcements, we will ask for your consent first where the law requires it, every such email will contain an unsubscribe link, and opting out will never affect the service emails above.

Resend processes the recipient address, message content and delivery events as our sub-processor.

15. Who we share personal data with

We do not sell personal data, and we do not share it for advertising. We disclose personal data only to the parties and in the circumstances below.

15.1 Sub-processors

The following service providers process personal data on our behalf under written contracts that limit their use of the data to providing their service to us, require confidentiality and appropriate security, and (where required) include the transfer safeguards in section 16.

ProviderLocation of processingWhat it does for usPersonal data it processes
Supabase, Inc.India (Mumbai region)Database, authentication and private file storageAccount identity, two-factor data, affiliate and referral data, support tickets, messages and attachments, abuse records, telemetry, moderation records, form submissions and Customer Content metadata
Render Services, Inc.SingaporeAPI application serversAll data passing through our API, request and error logs
Cloudflare, Inc.Global edge networkCDN and DNS, edge hosting and Workers, KV and R2 object storage, Analytics Engine, Workers AI, Turnstile bot protectionCustomer Content and site assets, Unclaimed Links content and IP hashes, request logs, hashed Visitor analytics, Turnstile signals
Vercel, Inc.GlobalHosting of oxypages.com and the dashboard web applicationRequest logs for those sites
Stripe, Inc.United States and globalPayment processing, saved cards, invoicingName, email, card details (held by Stripe only), transaction records
Resend, Inc.United StatesTransactional email deliveryEmail address, name, message content, delivery events
Dynadot, LLCUnited StatesDomain registrarDomain registrant details
Moonshot AIChinaAI code editor and AI content classifierAI editor prompts and files in scope; content submitted for classification
Google LLCUnited States and globalGoogle Sign-In (Identity Services); Google Safe BrowsingSign-in: name, email address and token data; Safe Browsing: the URLs we look up
TelegramGlobalInstant alerts to our staff about new support tickets, Leave-A-Message enquiries and similar operational eventsThe alert content: your name, email address and the message or event details

We will update this table when a sub-processor changes. For sub-processors that process Visitor data on your behalf, we will notify you in advance so that you can object under the Data Processing Agreement.

15.2 Other disclosures

We may also disclose personal data:

Aggregated data. We may share aggregated statistics that do not identify anyone, such as the number of sites hosted.

Our websites and Hosted Sites may link to websites and services we do not operate, including sites built by our customers. We are not responsible for their privacy practices, and this policy does not apply to them. Read the privacy notice of any site you visit.

16. International transfers

We are based in Malaysia and our sub-processors operate in the countries listed in section 15, including India, Singapore, the United States and, through global edge networks, other countries. Personal data will therefore be transferred to and stored in countries other than the one you live in, and some of those countries may have data-protection laws that differ from your own.

Wherever we transfer personal data, we protect it as this policy describes. Where the law of the country the data comes from requires a safeguard for the transfer, we use one: a contract with the recipient incorporating standard contractual clauses approved for that purpose, the recipient's certification under a recognised transfer framework, or, where no other mechanism is available, a legally recognised exception such as necessity for performing our contract with you. We also assess the laws of the destination country where the law requires us to and add further protections where needed.

You may ask for a copy of the safeguards we rely on by emailing support@oxypages.com; we may redact commercial terms. Section 21 gives additional information for residents of particular places.

17. How long we keep personal data

We keep personal data only as long as needed for the purposes in section 5, or as long as the law requires. The periods below are our standard retention periods.

DataRetention
Account identity, two-factor data, telemetry, preferencesFor the life of your Account. When you close your Account we anonymise the authentication record: your email address is replaced with a placeholder and personal identifiers are scrubbed, so the record no longer identifies you.
Customer Content (sites, files, settings) and form submissionsUntil you delete them. After your Account is closed or terminated, retained for 90 days so that the closure can be reversed, then permanently deleted.
Free Accounts with no sign-in for 12 monthsMay be treated as dormant and reclaimed, including deletion of Hosted Sites and release of the subdomain, after notice to your email address.
Payment and transaction records, invoices, affiliate commission recordsRetained after Account closure for as long as tax and accounting law requires (seven years under the law that applies to us).
Stripe customer ID and saved-card summary (brand, last four, expiry)Until you remove the card or close your Account; the underlying card is deleted at Stripe at the same time.
Domain registrant details and registration recordsFor as long as the domain is registered through us, and thereafter for as long as ICANN and the registry require (at least two years after the registration ends).
Referral attribution cookie (ox_ref)60 days
Unclaimed Links content30 minutes, unless claimed into an Account
Unclaimed Links IP hashOnly for the rate-limiting window, then deleted
Hosted-site analytics: daily IP hashNever stored beyond the daily count; the salt rotates every day, after which the hash cannot be recomputed
Hosted-site analytics: monthly aggregates24 months
Request, security and error logs12 months
Support tickets, messages and attachments, Leave-A-Message enquiries and abuse reports24 months after the ticket or enquiry is closed
Moderation records24 months, so that repeat abuse can be recognised
Email delivery records12 months

Backups. Backups expire on their own cycle, normally within 35 days. Data deleted from live systems remains in backups until then; we do not restore it except to recover from a failure, and if a backup is restored we re-apply deletions.

Legal holds. We may keep specific data longer where it is needed for a complaint, dispute, investigation or legal claim, or where the law requires it.

18. Security and data breach notification

Security measures. We take technical and organisational measures appropriate to the risk, including:

No method of transmission or storage is completely secure. You are responsible for keeping your password and API keys confidential and for the security of the devices you use. If you believe your Account has been compromised, change your password, revoke your keys and email support@oxypages.com immediately.

Data breach notification. If we become aware of a personal data breach affecting data we control, we will:

Where a breach affects Visitor data we process on your behalf, we will notify you as controller without undue delay so that you can meet your own obligations, as set out in the Data Processing Agreement.

19. Your rights and how to exercise them

Wherever you live, we give you the following rights over the personal data we hold about you. Some of them are guaranteed by the data protection law of your country; we extend all of them to everyone.

How to exercise them. Email support@oxypages.com from the address on your Account, or use the dashboard tools. We may ask you to confirm your identity, usually by responding from your Account email or signing in; we will not ask for more than is needed to verify you, and we will use verification information only for that purpose. You may authorise someone to act for you; we may ask for proof of the authorisation and, where the law permits, confirm with you directly.

Timing and cost. We respond without undue delay and in any event within 30 days, or within any shorter period your local law requires. If a request is complex we may take longer where the law allows, and we will tell you within the first 30 days. We do not charge for requests unless they are manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline, and we will tell you why.

No discrimination. We will not deny you the Service, charge you a different price or provide a different level of service because you exercised a right.

Refusals and appeals. If we cannot comply with a request in full, we will tell you why. If you disagree with our response you may ask us to reconsider by replying to it; a different person will review the decision and answer within the time the applicable law allows. You may also complain to your data-protection authority.

Requests about Hosted Sites. If your request concerns data you gave to a Hosted Site, section 10 applies.

20. Children

The Service is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18, and you may not open an Account if you are under 18. If we learn that we have collected personal data from a person under 18 we will close the Account and delete the data. If you believe someone under 18 has given us personal data, email support@oxypages.com.

If you are a site owner, you are responsible for ensuring that any Hosted Site directed at children complies with the laws that apply to it.

21. Additional information for residents of particular places

The core of this policy applies to everyone. This section adds only what the law of certain places requires us to say, or requires us to say in a particular way. Where this section and the rest of the policy differ, this section prevails for residents of the place concerned.

21.1 Malaysia

This policy, including this subsection, is the written notice required by section 7 of the Personal Data Protection Act 2010 (as amended). Each element the Act requires is addressed as follows: the personal data being processed and its description (section 4); the purposes (section 5); the source (section 4, "Information we receive from third parties"); your right to request access to and correction of your personal data and how to contact us (section 19 and section 23); the classes of third parties to whom the data is disclosed (section 15); the choices and means you have to limit processing (section 19, and the optional features described in sections 6 to 12); whether supplying the data is obligatory or voluntary and the consequences of not supplying it (section 4, "What you must provide").

A Bahasa Malaysia version of this notice is available on request.

Data controller. Ditra Point, Malaysia. Contact: support@oxypages.com.

Access and correction requests. We respond to data access and data correction requests within 21 days. We do not charge the prescribed fee.

Data protection officer. We have not appointed a data protection officer. We keep this under review against the appointment thresholds in the Act and will appoint one, and update this notice, if and when the law requires.

Transfers outside Malaysia. We transfer personal data outside Malaysia only as section 129 of the Act permits: to places whose law is substantially similar to the Act or that otherwise ensure adequate protection, where the transfer is necessary to perform our contract with you, with your consent, or under another condition the Act allows. Section 16 describes the safeguards.

Complaints. You may complain to the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi), https://www.pdp.gov.my.

21.2 European Economic Area, United Kingdom and Switzerland

Controller and representative. Ditra Point, Malaysia, is the controller. We are subject to the GDPR and the UK GDPR because we offer the Service to people in the EEA and the UK. We have not appointed a representative in the EEA or the UK under Article 27 of the GDPR or UK GDPR at this time. Contact us directly at support@oxypages.com.

Legal bases. The "Basis" column in sections 4 and 5 identifies the lawful basis for each processing activity: performance of a contract (Article 6(1)(b)); compliance with a legal obligation (Article 6(1)(c)); our legitimate interests (Article 6(1)(f)), namely security, abuse prevention, product improvement, operating the affiliate programme and defending legal claims; and consent (Article 6(1)(a)) where we ask for it. We do not process special-category data.

Your rights. The rights in section 19 correspond to Articles 15 to 22 of the GDPR and UK GDPR. We respond within one month, extendable by two months for complex requests with notice. Where we rely on legitimate interests you may object on grounds relating to your particular situation, and we will stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms or the processing is needed for legal claims.

International transfers. Malaysia, India, Singapore and China are not the subject of an adequacy decision; the United States is covered only for organisations certified under the EU-U.S. Data Privacy Framework (and its UK Extension and Swiss equivalent). For transfers to countries without adequacy we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum or the UK International Data Transfer Agreement for UK data, and the Swiss adaptations for Swiss data), the recipient's Data Privacy Framework certification where applicable, and, where neither is available, the derogation for transfers necessary for the performance of our contract with you.

Cookies. The authentication and password-gate cookies in section 13 are strictly necessary and exempt from consent. The ox_ref cookie is set only when you arrive through a referral link, holds only a referral reference and is never used to track you.

Complaints. You have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work or the place of an alleged infringement. In the UK, the Information Commissioner's Office, https://ico.org.uk. In the EEA, the list of authorities is at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en. In Switzerland, the Federal Data Protection and Information Commissioner, https://www.edoeb.admin.ch.

21.3 California and other US states

This subsection provides the disclosures the California Consumer Privacy Act (as amended by the California Privacy Rights Act) requires. It also applies, with the adjustments noted, to residents of other US states with comprehensive privacy laws, to the extent those laws apply to us.

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA, and we have not done so in the preceding 12 months. We do not engage in targeted advertising or in profiling in furtherance of decisions that produce legal or similarly significant effects. We have no actual knowledge that we sell or share the personal information of anyone under 16.

Categories of personal information collected in the preceding 12 months.

CCPA categoryCollectedWhat we collectSourcesBusiness purposeDisclosed to (for a business purpose)
A. IdentifiersYesName, email address, Account ID, IP address in request logs, Stripe customer ID, domain registrant detailsYou; your device; Google (sign-in)Providing the Service, security, payments, domain registrationService providers in section 15; registrar and registries
B. Customer records (Cal. Civ. Code 1798.80(e))YesName, postal address and telephone number (domain registrants only), card brand, last four and expiryYouPayments, domain registrationStripe, Dynadot, registries
C. Protected classificationsNo
D. Commercial informationYesPlans purchased, transactions, invoices, affiliate commissionsYou; StripeProviding the Service, accountingStripe; Supabase
E. Biometric informationNo
F. Internet or network activityYesDashboard pages viewed and features clicked; request, security and error logs; API usageYour use of the ServiceImproving the Service, security, debuggingSupabase, Render, Cloudflare, Vercel
G. Geolocation dataNoWe do not collect precise geolocation. Country-level location is derived from IP address only in Hosted-Site analytics, which we process as a service provider for the site owner
H. Audio, visual or similarNo
I. Professional or employment informationNo
J. Education informationNo
K. InferencesNo
L. Sensitive personal informationYes, one itemAccount log-in credentials (password hash, two-factor secret)YouAuthenticating you only; this use does not trigger the right to limitSupabase

We also collect the content you upload (Customer Content, AI prompts, support messages and attachments), which may contain personal information in any category you choose to include. Each category is retained for the periods in section 17. The categories of third parties to whom we disclose personal information for a business purpose are service providers and contractors (database, hosting, edge network, payments, email, AI, sign-in and safety services), the domain registrar and registries, professional advisers, and government authorities where required. Sections 4, 5 and 17 together constitute our notice at collection.

Your rights. The right to know, the right to delete, the right to correct, and the right to non-discrimination, as described in section 19. The right to opt out of sale or sharing and the right to limit use of sensitive personal information do not arise because we do not sell or share personal information and we use sensitive personal information only for purposes that do not trigger the right to limit; we nonetheless treat a Global Privacy Control signal as a valid opt-out request.

How to exercise them. Email support@oxypages.com. We are an online-only business and email is our designated request method. We verify requests by matching the information you provide with what we hold, normally by confirming from your Account email address; we will not require you to create an Account to make a request. An authorised agent may submit a request on your behalf; we may require proof of written authorisation and may confirm the request with you directly. We respond within 45 days, extendable once by a further 45 days with notice.

Appeals (other states). If you are a resident of a state whose law provides an appeal right and we decline your request, you may appeal by replying to our decision. We will respond in writing within the time your state's law allows with the reasons for our decision. If we deny your appeal you may contact your state Attorney General.

Shine the Light (Cal. Civ. Code 1798.83). We do not disclose personal information to third parties for their direct marketing purposes.

22. Changes to this policy

We will post any changes to this policy on this page and update the "Last updated" date. If a change is material, meaning it reduces your rights, adds a category of personal data, adds a purpose, or adds a sub-processor that processes Visitor data, we will email the address on your Account at least 30 days before the change takes effect, unless the change is required sooner by law. Continuing to use the Service after a change takes effect means the updated policy applies to you; if you do not agree, close your Account before then.

Previous versions are available on request.

23. Governing law and contact

This policy is governed by the laws of Malaysia. Nothing in it removes rights you have under mandatory data-protection law in the country where you live, which apply in addition.

Ditra Point (operating OxyPages) Malaysia Malaysia (postal address available on request)

Privacy questions, requests to exercise your rights, complaints, Data Processing Agreement requests and security reports: support@oxypages.com

We have not appointed a data protection officer or a representative in the EEA or the UK. Every privacy matter should be sent to the address above and will be handled by the person responsible for data protection at Ditra Point.