Privacy Policy
Last Updated: 2 September 2026
Summary
This is the short version. The full policy below is what governs.
- Who we are. OxyPages is operated by Ditra Point, a business established in Malaysia ("OxyPages", "we", "us"). We are the data controller for your account, billing, support and your use of our own websites and dashboard.
- What we collect. Only what we need to run your account, host your sites, take payment, register domains you order, pay affiliates, answer your support and contact messages and stop abuse. The full list is in section 4. We do not collect anything not listed there.
- What we do not do. We do not sell personal data. We do not run advertising. We do not track you across other websites. We do not use your content to train AI models.
- Your visitors. When we host your site, store your form submissions or count your visitors, you are the controller and we are your processor. Your privacy notice applies to your visitors, not this one. Our visitor analytics set no cookies, run no scripts and never store a raw IP address.
- Payments. Stripe holds your card. We keep only a Stripe customer ID and the card brand, last four digits and expiry so that auto-renewal can work.
- Cookies. Sign-in cookies on app.oxypages.com, a 60-day affiliate referral cookie on oxypages.com if you arrive through a referral link, and a password cookie on password-protected hosted sites. No analytics or advertising cookies.
- Your rights. Wherever you live, you can access, correct, delete and export your data, object to or restrict how we use it, withdraw consent and complain to your local authority. Email support@oxypages.com. A self-serve JSON export is available in your dashboard.
- Age. You must be 18 or over.
1. Who we are and what this policy covers
OxyPages (https://oxypages.com) is a static-site hosting service operated by Ditra Point, a business established in Malaysia. In this policy "OxyPages", "we", "us" and "our" mean Ditra Point. "You" and "your" mean the person who holds an OxyPages account or who visits oxypages.com or app.oxypages.com.
Ditra Point is the data controller of the personal data described in this policy: we decide why and how it is processed and we are responsible for it. Our contact for every privacy matter, including requests to exercise your rights, is support@oxypages.com.
This policy applies to:
- the marketing site at oxypages.com;
- the dashboard and application at app.oxypages.com, our API and our MCP server;
- your account, billing, support and affiliate relationship with us;
- the "Unclaimed Links" anonymous publishing feature;
- emails we send you.
This policy does not apply to the personal data of people who visit websites hosted on OxyPages, submit forms on those websites or are counted by their analytics. For that data we act as a processor on behalf of the site owner. Section 3 explains the distinction and section 10 is addressed to those visitors.
This policy should be read together with our Terms of Service. Where we process personal data as your processor, our Data Processing Agreement governs; it is available on request from support@oxypages.com.
2. Definitions
| Term | Meaning |
|---|---|
| Personal data | Any information relating to an identified or identifiable living person. Laws in some places call this "personal information"; the meaning here is the same. |
| Account | Your registered OxyPages account, whether free or paid. |
| Customer Content | The HTML, ZIP archives, files, assets and settings you upload to or create in OxyPages to build a Hosted Site, including anything produced with the AI code editor. |
| Hosted Site | A website served by OxyPages on a subdomain of myoxypages.com or on a custom domain you connect. |
| Visitor | A person who visits a Hosted Site, submits a form on it or is counted by its analytics. |
| Controller | The party that decides why and how personal data is processed. |
| Processor | A party that processes personal data on the controller's documented instructions. |
| Sub-processor | A third-party service provider we use to deliver the Service and that processes personal data on our behalf. |
| Service | Everything OxyPages provides, as described in the Terms of Service. |
| Data protection law | The privacy and data-protection laws that apply to you or to us, wherever you are. Section 21 gives additional information for residents of particular places. |
3. When we are your processor, not the controller
When you use OxyPages to host a website, collect form submissions or measure Visitors, the personal data involved belongs to the relationship between you and your Visitors. For that data:
- You are the controller. You decide what your site collects, what your forms ask for and why.
- We are your processor. We process Visitor data only to serve your site, store and deliver your form submissions, produce your analytics, keep the Service secure and comply with law. We follow the instructions set out in the Terms of Service and the Data Processing Agreement.
- Your privacy notice applies to your Visitors. You are responsible for having one that is accurate for what your site does, for obtaining any consent your site needs and for answering your Visitors' requests about their data. We will help you do so (section 10).
- Our sub-processors are listed in section 15. We will give you notice before we add or replace a sub-processor that processes Visitor data.
The remainder of this policy concerns the personal data for which we are the controller: your Account, billing, support, affiliate and domain data, your use of our own websites and dashboard, and the limited data we collect from Visitors for our own security purposes (described in section 10).
4. Personal data we collect
We collect only the categories below. We do not collect sensitive personal data (such as health, religious, biometric or precise location data) and we ask you not to send it to us. We do not buy data about you and we do not receive data about you from data brokers, advertising networks or social media platforms.
The "Basis" column states why the law allows us to process each category: because it is necessary for our contract with you; because a law obliges us; because we have a legitimate interest that does not override your rights; or because you consented.
| Category | What it includes | Source | Why we collect it | Basis |
|---|---|---|---|---|
| Account identity | Name, email address, password (stored only as a salted hash), account creation date, plan and status, and the timezone your browser reports (detected automatically and stored so that dates and usage periods are shown in your local time; you can change it in your profile) | You; your browser | To create and secure your Account, identify you when you sign in and show times correctly | Contract |
| Google Sign-In data | Your name and email address, received in a Google ID token when you choose to sign in with Google | Google, at your request | To create or sign you in to your Account without a password | Contract |
| Two-factor authentication data | The shared secret for your authenticator app (TOTP), stored encrypted, and whether two-factor authentication is enabled | You | To verify a second factor when you sign in | Contract; legitimate interest in account security |
| Bot-check signals | Cloudflare Turnstile issues a short-lived token on our sign-up, sign-in and password-reset forms; Cloudflare receives your IP address and browser characteristics to decide whether the request is automated | Your browser, via Cloudflare | To keep automated abuse off our authentication forms | Legitimate interest in security |
| Customer Content | HTML, ZIP archives, files, assets, site settings and custom-domain configuration, and any personal data you choose to include in them | You | To host and serve your Hosted Sites | Contract |
| AI editor prompts | The instructions you type into the AI code editor, the files in scope for that request, and the output returned | You | To fulfil the editing request you made | Contract |
| Payment and transaction records | Stripe customer ID; card brand, last four digits and expiry date; plan, amounts, currency, dates, invoices, receipts, refund and failed-payment history | You (via Stripe) and Stripe | To take payment, renew your plan automatically, issue receipts, handle failed payments and keep the records tax law requires | Contract; legal obligation |
| Domain registrant details | Registrant name, organisation (if any), postal address, email address and telephone number, and the domain(s) registered | You | To register the domain in your name as ICANN and the registry require, and to manage renewals and transfers | Contract; legal obligation (ICANN and registry policy) |
| Affiliate data | Your payout email address, the referral code and links assigned to you, the Accounts attributed to your referrals, commissions earned and payments made | You; our systems | To attribute referrals and pay you | Contract |
| Referral attribution | The affiliate or share-link reference stored in the ox_ref cookie when you arrive at oxypages.com from a referral or share link, and the referring Account your sign-up was attributed to | Your browser | To credit the person who referred you | Legitimate interest in operating the affiliate programme |
| Unclaimed Links data | The content published anonymously and a salted hash of the publisher's IP address | The publisher; your browser | To serve the temporary link and to rate-limit anonymous publishing | Legitimate interest in preventing abuse |
| Support and abuse correspondence | Support tickets you open, your messages, our replies and any files you attach to a ticket (stored in a private storage bucket accessible only to you and our support staff); abuse reports about a Hosted Site, including the URL reported, the reason given and any contact details the reporter provides | You; the reporter | To answer you, investigate reports and keep a record of what was decided | Contract; legitimate interest in responding to reports and enforcing our Terms |
| Leave-A-Message enquiries | The name, email address and message you submit through the "Leave A Message" widget on oxypages.com, which anyone can use without an Account. Your message is delivered to our support inbox and, as an alert, to our staff messaging channel (section 15) | You | To receive and answer your enquiry | Legitimate interest in answering enquiries; steps taken at your request |
| Product usage telemetry | Pages viewed and features clicked inside the dashboard, tied to your signed-in Account | Your use of the dashboard | To understand which features are used, fix problems and improve the product | Legitimate interest in improving the Service |
| Error logs | Technical details of a failure in our systems: the request that failed, the error message, a timestamp and the Account or session it relates to | Our systems | To diagnose and fix faults | Legitimate interest in running a reliable Service |
| Request and security logs | Standard request metadata recorded by our API servers and edge network: IP address, user agent, requested URL, timestamp and response status | Your browser or API client | Security, rate limiting, abuse investigation and debugging | Legitimate interest in security |
| Moderation records | Results of automated content checks and any manual review of your Hosted Sites, notices sent to you and actions taken | Our systems; our staff | To keep illegal and harmful content off the Service and to detect repeat abuse | Legitimate interest; legal obligation |
| Email delivery records | Records of the emails we sent you and whether they were delivered | Our systems (via Resend) | To prove that required notices were sent and to troubleshoot delivery | Contract; legitimate interest |
Information we receive from third parties. The only information about you that we receive from others is: your name and email address from Google when you use Google Sign-In; payment outcomes from Stripe; domain status from Dynadot and the registry; the results of Google Safe Browsing lookups on URLs you publish; and the contents of abuse reports that third parties send us about your Hosted Sites.
Information about other people. If you enter another person's details, for example as a domain registrant contact or in Customer Content, you are responsible for having the right to do so.
What you must provide. Your name, email address and a password (or Google Sign-In) are required to open an Account; without them we cannot provide the Service. Payment details are required for paid plans. Registrant contact details are required to register a domain. A payout email is required to receive affiliate commissions. Everything else is optional, and not providing it does not affect the rest of the Service.
5. How we use personal data and why
We use personal data for the purposes below and for no others.
| Purpose | Data used | Basis |
|---|---|---|
| Creating, securing and administering your Account | Account identity, Google Sign-In data, two-factor data, bot-check signals | Contract; legitimate interest in security |
| Hosting and serving your Hosted Sites, custom domains and forms | Customer Content, request logs | Contract |
| Providing the AI code editor | AI editor prompts and files in scope | Contract |
| Taking payment, auto-renewing your plan, issuing receipts and following up failed payments | Payment and transaction records | Contract |
| Keeping accounting and tax records | Payment and transaction records | Legal obligation |
| Registering, renewing and transferring domains in your name | Domain registrant details | Contract; legal obligation |
| Operating the affiliate programme and paying commissions | Affiliate data, referral attribution | Contract; legitimate interest |
| Serving Unclaimed Links and rate-limiting anonymous publishing | Unclaimed Links data | Legitimate interest |
| Answering support requests, Leave-A-Message enquiries and abuse reports | Support and abuse correspondence, Leave-A-Message enquiries, Account identity | Contract; legitimate interest |
| Detecting and preventing fraud, abuse, phishing, malware and other illegal or harmful content | Moderation records, request and security logs, Customer Content | Legitimate interest; legal obligation |
| Sending the service emails described in section 14 | Account identity, email delivery records | Contract; legal obligation |
| Understanding how the dashboard is used and improving the Service | Product usage telemetry, error logs | Legitimate interest |
| Establishing, exercising or defending legal claims and complying with law, court orders and regulators | Any category, as relevant | Legal obligation; legitimate interest |
Legitimate interests. Where we rely on a legitimate interest we have considered whether it is outweighed by your interests, rights and freedoms and concluded that it is not, because the processing is limited, expected and low-risk. You may object to any processing based on legitimate interests (section 19).
No secondary uses. We do not use personal data for advertising, for profiling for marketing purposes, for sale or rental to third parties, or to build models about you. We do not use Customer Content, prompts, form submissions or any other personal data to train artificial intelligence models, and our AI provider is contractually limited to processing your request.
6. Signing in: Google Sign-In, two-factor authentication and bot checks
Email and password. Your password is stored only as a salted hash. We cannot read it and we will never ask you for it.
Google Sign-In. If you choose "Sign in with Google", we use Google Identity Services loaded on our own origin. Google authenticates you and returns an ID token to us containing your name and email address. We use those two fields to create or match your Account. We do not receive your Google password, contacts, calendar, files or any other Google data, and we do not request access to any Google API beyond sign-in. Google's own privacy policy governs what Google collects when you use its sign-in; you can review or remove the connection in your Google Account's security settings.
Two-factor authentication (TOTP). If you enable two-factor authentication we store the shared secret needed to verify codes from your authenticator app. We store it encrypted and use it only for verification.
Cloudflare Turnstile. Our sign-up, sign-in and password-reset forms are protected by Cloudflare Turnstile. Turnstile runs in your browser and sends signals about the request (including your IP address and browser characteristics) to Cloudflare, which returns a token that we verify. We do not receive the underlying signals. Cloudflare processes them under its own privacy policy and as our sub-processor.
7. Payments, saved cards and auto-renewal
Payments are processed by Stripe. When you pay, you enter your card details on a Stripe-hosted page or in Stripe's secure payment elements; the full card number and security code go directly to Stripe and never touch our servers.
We store:
- your Stripe customer ID;
- the brand, last four digits and expiry date of your saved card, so that we can show you which card is on file and renew your plan automatically;
- your transaction history, invoices and receipts.
Auto-renewal. Paid plans and domain registrations renew automatically using your saved card unless you cancel before the renewal date. We send a reminder before renewal and a receipt after each charge. If a charge fails we will email you so that you can update your card (section 14).
Stripe acts as an independent controller for the card data it holds and for its own fraud-prevention processing, and as our processor for the rest. Stripe may set cookies on its payment pages for fraud prevention. Stripe's privacy policy is at https://stripe.com/privacy.
8. Domain registration
When you register a domain through OxyPages, you are the registrant: the domain is registered in your name, not ours. Our registrar is Dynadot, LLC (United States).
To register a domain, ICANN and the relevant registry require the registrant's name, postal address, email address and telephone number. We pass those details to Dynadot, which passes them to the registry. Dynadot and the registry process them under their own policies and under ICANN's Registrar Accreditation Agreement, which requires the registrar to keep registration records for at least two years after the registration ends.
Public WHOIS and RDAP. Registration data may be published in the public WHOIS or RDAP directory to the extent ICANN or the registry requires. Where the registrar offers WHOIS privacy or redaction for your domain, we enable it by default.
Verification emails. ICANN requires the registrar to verify the registrant's email address. You may receive verification emails from Dynadot directly; failing to respond can suspend the domain.
Retention. Domain registration records are kept for as long as ICANN and the registry require, even after your Account is closed (section 17).
9. AI code editor, content moderation and automated decisions
AI code editor. When you use the AI editor, your prompt and the files in scope are sent to our AI provider, Moonshot AI, to generate the result. The provider processes the request on our behalf and is contractually restricted to that purpose. Your prompts and content are not used to train the provider's models or ours. Do not include personal data in prompts unless you need to.
Automated content moderation. To keep phishing, malware and other illegal or harmful content off the Service, published content is checked automatically by:
- Google Safe Browsing lookups on the URLs you publish;
- our own phishing heuristics;
- an AI classifier operated through Moonshot AI, which receives the content to be classified and returns a classification.
Content flagged by these checks is reviewed by a member of our team before any decision to suspend an Account or remove a site. An automated check may temporarily restrict serving of a page pending that review, for example where Safe Browsing reports a URL as malicious. We record the result of checks and reviews (section 4, "Moderation records") so that we can recognise repeat abuse.
Automated decisions. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Any suspension, termination or removal decision is taken or reviewed by a person. If you believe a moderation action was wrong, email support@oxypages.com; a person will review it, and you may put your point of view and contest the decision.
Manual review. Our staff may view Customer Content when investigating an abuse report, a moderation flag, a support ticket you have opened, or a security incident. We do not browse Customer Content otherwise.
10. Visitors to sites hosted on OxyPages
This section is written for Visitors. If you are reading this because you visited a website hosted on OxyPages, the owner of that website is the controller of your personal data and their privacy notice governs. This section explains what OxyPages does with Visitor data on the owner's behalf and how to exercise your rights.
Serving the site. To deliver the page you requested, our edge network (Cloudflare) receives the standard data any web request carries: your IP address, the URL requested, your browser's user-agent string and referrer. This is used to serve the response, protect the site from attack and produce the analytics described next.
Analytics: no cookies, no scripts, no raw IP addresses. Visitor analytics are counted at the edge when the page is served. No analytics script runs in your browser and no cookie or other identifier is set. Your IP address is hashed together with a secret salt that rotates every day; the hash is used only to estimate unique visitors within that day and the raw IP address is never written to storage. What the site owner sees are monthly aggregates: page views, bytes served, paths, countries, referrers, and device, operating system and browser families. Nothing in those aggregates identifies you.
Forms. If you submit a form on a Hosted Site, the data you enter is stored in the site owner's OxyPages Account and, if the owner has enabled notifications, emailed to the owner. We store submissions for the owner and act only on the owner's instructions. We do not read, use or share form submissions for any purpose of our own.
Password-protected sites. If a Hosted Site is password-protected, entering the password sets a cookie in your browser so that you do not have to enter it on every page. The cookie is strictly necessary to provide the protected site and contains no personal data.
Do Not Track and Global Privacy Control. Because no tracking takes place on Hosted Sites, there is nothing for a Do Not Track or Global Privacy Control signal to switch off. We honour them by design.
Our own limited use. Independently of the site owner, we use request metadata for the security, abuse-prevention and moderation purposes in section 5, for which we are the controller. This is limited to what is needed to keep the Service safe.
Exercising your rights. To access, correct or delete personal data you gave to a Hosted Site, contact the site's owner; the contact details should be in their privacy notice or on the site. If you cannot reach the owner, email support@oxypages.com with the site address and we will forward your request to the owner and assist them in responding. Where the law requires us to act directly, we will.
11. Affiliate programme, share links and Unclaimed Links
Affiliate programme. If you join the affiliate programme we collect your payout email address and keep records of the referral links assigned to you, the Accounts attributed to your referrals, commissions earned and payments made. Commission records are transaction records and are retained as tax law requires.
Referral attribution. When someone arrives at oxypages.com through an affiliate link (a URL containing a "?r=" parameter) or a share link, we set a first-party cookie named ox_ref containing only the referral reference. It lasts 60 days. If that person opens an Account within 60 days, the referral is attributed to the referrer. The cookie is set only on oxypages.com, is not shared with any third party and is not used for any other purpose. Anyone can delete it in their browser settings; doing so simply removes the attribution.
What affiliates see. Affiliates see aggregate statistics and their commission balance. We do not disclose the name or email address of referred customers to the affiliate.
Share and clone links. If you generate a share link for a Hosted Site, anyone with the link can view the site and, where you allow it, clone it into their own Account. Anything in the shared site, including any personal data you put in it, is visible to anyone who has the link. Sign-ups made through a share link are attributed to you in the same way as affiliate referrals.
Unclaimed Links. Unclaimed Links let anyone publish a page without an Account. The page lives for 30 minutes and is then deleted unless it is claimed into an Account. We do not ask for any personal data to publish an Unclaimed Link. We store a salted hash of the publisher's IP address solely to limit how many links one address can create; the raw IP address is not stored, and the hash cannot be turned back into it. Content published as an Unclaimed Link is subject to the same moderation checks as any other Hosted Site.
12. API keys, the MCP server and developer data
Every plan can create API keys and connect the OxyPages MCP server to compatible tools. An API key is a credential tied to your Account. Requests made with your key, including requests the MCP server makes on your behalf, are treated as made by you and are logged in the same way as dashboard requests (section 4, "Request and security logs"). We record which key made a request so that you can see and revoke keys.
Keep keys secret. Anyone who has your key can act as you. You can revoke a key at any time from the dashboard. If you believe a key has been exposed, revoke it immediately and email support@oxypages.com.
Your MCP client. When you use the MCP server through a third-party AI assistant or agent, the data our API returns (including your Customer Content and site settings) is passed to that assistant and its provider. That provider's terms and privacy policy govern what it does with the data; we do not control it and this policy does not cover it.
13. Cookies, Do Not Track and Global Privacy Control
We use only the cookies below. All of them are first-party. We set no analytics, advertising or cross-site tracking cookies, and we do not embed third-party trackers, pixels or social media widgets. Because there are no optional cookies to consent to, we do not show a cookie banner.
| Cookie | Set on | Purpose | Lifetime | Type |
|---|---|---|---|---|
| Authentication and session cookies | app.oxypages.com | Keep you signed in and protect against cross-site request forgery | Session, or until you sign out | Strictly necessary |
| ox_ref | oxypages.com | Attribute a sign-up to the affiliate or share link that referred it (section 11); set only when you arrive through such a link | 60 days | Referral attribution |
| Password-gate cookie | Password-protected Hosted Sites | Remember that you entered the site password | Session | Strictly necessary (set as processor for the site owner) |
| Stripe cookies | Stripe payment pages and elements | Fraud prevention during checkout | Set and governed by Stripe | Strictly necessary for payment |
| Cloudflare security cookies | Our sites and Hosted Sites, where Cloudflare's bot protection requires them | Distinguish legitimate traffic from attacks | Set and governed by Cloudflare | Strictly necessary |
Local storage. The dashboard may store interface preferences (such as theme) in your browser's local storage. That data stays on your device.
Managing cookies. You can block or delete cookies in your browser settings. Blocking the authentication cookie will prevent you from signing in; deleting ox_ref removes referral attribution and nothing else.
Marketing-site analytics. If we measure traffic to oxypages.com, we do so with the same cookieless, edge-counted method described in section 10. No analytics cookie or third-party analytics script is used.
Do Not Track and Global Privacy Control. We honour both signals by design. We do not sell or share personal data, run targeted advertising or track you across sites, so there is nothing further for these signals to switch off. Where a law treats a Global Privacy Control signal as an opt-out request, we treat it as honoured.
14. Emails we send
We send email only from noreply@oxypages.com, delivered by Resend. We send:
| Trigger | Basis | |
|---|---|---|
| Account and authentication emails: email verification, password reset, sign-in and security alerts | Your actions or a security event | Contract; security |
| Welcome email | Opening an Account | Contract |
| Receipts and invoices | A successful payment | Contract; legal obligation |
| Renewal reminders and failed-payment notices | An upcoming renewal or a failed charge | Contract; legal obligation to disclose auto-renewal |
| Form notifications | A Visitor submits a form on your Hosted Site, if you enabled notifications | Contract (we act as your processor) |
| Support replies | We reply to a support ticket you opened or a message you left | Contract; legitimate interest |
| Moderation notices | A moderation check or review affects your Hosted Site | Contract; legitimate interest |
| Domain notices | Registration, renewal, transfer or verification events | Contract; legal obligation |
| Legal and policy notices | Material changes to this policy or the Terms; legal requirements | Legal obligation; contract |
These are service emails; they are necessary to operate your Account and cannot be unsubscribed from while the Account is open, except that you may switch off form notifications in your dashboard.
Marketing email. We do not currently send marketing or promotional email. If we introduce a newsletter or product announcements, we will ask for your consent first where the law requires it, every such email will contain an unsubscribe link, and opting out will never affect the service emails above.
Resend processes the recipient address, message content and delivery events as our sub-processor.
15. Who we share personal data with
We do not sell personal data, and we do not share it for advertising. We disclose personal data only to the parties and in the circumstances below.
15.1 Sub-processors
The following service providers process personal data on our behalf under written contracts that limit their use of the data to providing their service to us, require confidentiality and appropriate security, and (where required) include the transfer safeguards in section 16.
| Provider | Location of processing | What it does for us | Personal data it processes |
|---|---|---|---|
| Supabase, Inc. | India (Mumbai region) | Database, authentication and private file storage | Account identity, two-factor data, affiliate and referral data, support tickets, messages and attachments, abuse records, telemetry, moderation records, form submissions and Customer Content metadata |
| Render Services, Inc. | Singapore | API application servers | All data passing through our API, request and error logs |
| Cloudflare, Inc. | Global edge network | CDN and DNS, edge hosting and Workers, KV and R2 object storage, Analytics Engine, Workers AI, Turnstile bot protection | Customer Content and site assets, Unclaimed Links content and IP hashes, request logs, hashed Visitor analytics, Turnstile signals |
| Vercel, Inc. | Global | Hosting of oxypages.com and the dashboard web application | Request logs for those sites |
| Stripe, Inc. | United States and global | Payment processing, saved cards, invoicing | Name, email, card details (held by Stripe only), transaction records |
| Resend, Inc. | United States | Transactional email delivery | Email address, name, message content, delivery events |
| Dynadot, LLC | United States | Domain registrar | Domain registrant details |
| Moonshot AI | China | AI code editor and AI content classifier | AI editor prompts and files in scope; content submitted for classification |
| Google LLC | United States and global | Google Sign-In (Identity Services); Google Safe Browsing | Sign-in: name, email address and token data; Safe Browsing: the URLs we look up |
| Telegram | Global | Instant alerts to our staff about new support tickets, Leave-A-Message enquiries and similar operational events | The alert content: your name, email address and the message or event details |
We will update this table when a sub-processor changes. For sub-processors that process Visitor data on your behalf, we will notify you in advance so that you can object under the Data Processing Agreement.
15.2 Other disclosures
We may also disclose personal data:
- To domain registries and ICANN, as section 8 describes.
- To comply with law. Where required by a law, regulation, court order, subpoena or lawful request from a public authority that has jurisdiction over us. Where we are permitted to, we will tell you before disclosing.
- To protect people and the Service. Where we reasonably believe disclosure is necessary to investigate or prevent fraud, abuse, security incidents or threats to anyone's safety, or to enforce our Terms.
- To exercise or defend legal claims, including to our professional advisers.
- In a business transfer. If Ditra Point is involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be transferred to the successor under the same protections as this policy. We will notify you before your personal data becomes subject to a different privacy policy.
- At your direction, for example when you ask us to share a site with someone or connect a third-party tool.
Aggregated data. We may share aggregated statistics that do not identify anyone, such as the number of sites hosted.
15.3 Links to other websites and services
Our websites and Hosted Sites may link to websites and services we do not operate, including sites built by our customers. We are not responsible for their privacy practices, and this policy does not apply to them. Read the privacy notice of any site you visit.
16. International transfers
We are based in Malaysia and our sub-processors operate in the countries listed in section 15, including India, Singapore, the United States and, through global edge networks, other countries. Personal data will therefore be transferred to and stored in countries other than the one you live in, and some of those countries may have data-protection laws that differ from your own.
Wherever we transfer personal data, we protect it as this policy describes. Where the law of the country the data comes from requires a safeguard for the transfer, we use one: a contract with the recipient incorporating standard contractual clauses approved for that purpose, the recipient's certification under a recognised transfer framework, or, where no other mechanism is available, a legally recognised exception such as necessity for performing our contract with you. We also assess the laws of the destination country where the law requires us to and add further protections where needed.
You may ask for a copy of the safeguards we rely on by emailing support@oxypages.com; we may redact commercial terms. Section 21 gives additional information for residents of particular places.
17. How long we keep personal data
We keep personal data only as long as needed for the purposes in section 5, or as long as the law requires. The periods below are our standard retention periods.
| Data | Retention |
|---|---|
| Account identity, two-factor data, telemetry, preferences | For the life of your Account. When you close your Account we anonymise the authentication record: your email address is replaced with a placeholder and personal identifiers are scrubbed, so the record no longer identifies you. |
| Customer Content (sites, files, settings) and form submissions | Until you delete them. After your Account is closed or terminated, retained for 90 days so that the closure can be reversed, then permanently deleted. |
| Free Accounts with no sign-in for 12 months | May be treated as dormant and reclaimed, including deletion of Hosted Sites and release of the subdomain, after notice to your email address. |
| Payment and transaction records, invoices, affiliate commission records | Retained after Account closure for as long as tax and accounting law requires (seven years under the law that applies to us). |
| Stripe customer ID and saved-card summary (brand, last four, expiry) | Until you remove the card or close your Account; the underlying card is deleted at Stripe at the same time. |
| Domain registrant details and registration records | For as long as the domain is registered through us, and thereafter for as long as ICANN and the registry require (at least two years after the registration ends). |
| Referral attribution cookie (ox_ref) | 60 days |
| Unclaimed Links content | 30 minutes, unless claimed into an Account |
| Unclaimed Links IP hash | Only for the rate-limiting window, then deleted |
| Hosted-site analytics: daily IP hash | Never stored beyond the daily count; the salt rotates every day, after which the hash cannot be recomputed |
| Hosted-site analytics: monthly aggregates | 24 months |
| Request, security and error logs | 12 months |
| Support tickets, messages and attachments, Leave-A-Message enquiries and abuse reports | 24 months after the ticket or enquiry is closed |
| Moderation records | 24 months, so that repeat abuse can be recognised |
| Email delivery records | 12 months |
Backups. Backups expire on their own cycle, normally within 35 days. Data deleted from live systems remains in backups until then; we do not restore it except to recover from a failure, and if a backup is restored we re-apply deletions.
Legal holds. We may keep specific data longer where it is needed for a complaint, dispute, investigation or legal claim, or where the law requires it.
18. Security and data breach notification
Security measures. We take technical and organisational measures appropriate to the risk, including:
- encryption of all traffic in transit (TLS) and encryption of stored data at our providers;
- passwords stored only as salted hashes, and two-factor authentication available to every Account;
- two-factor authentication required for administrative access to our systems;
- row-level security in our database so that one customer's data is not reachable from another's Account;
- hashing of Visitor IP addresses at the edge with a daily-rotating salt, so raw addresses are never stored;
- API keys that can be revoked at any time, and rate limiting on authentication and publishing endpoints;
- automated content scanning to keep malicious content off our infrastructure;
- access to production systems limited to the people who need it, and sub-processors bound by contract to equivalent protections.
No method of transmission or storage is completely secure. You are responsible for keeping your password and API keys confidential and for the security of the devices you use. If you believe your Account has been compromised, change your password, revoke your keys and email support@oxypages.com immediately.
Data breach notification. If we become aware of a personal data breach affecting data we control, we will:
- notify the data-protection authority that has jurisdiction over us, and any other authority the law requires, within the period the law sets (72 hours where that is the requirement);
- notify you without undue delay where the breach is likely to cause you significant harm or a high risk to your rights, describing what happened, the likely consequences and what we are doing about it;
- comply with any other breach-notification law that applies to you.
Where a breach affects Visitor data we process on your behalf, we will notify you as controller without undue delay so that you can meet your own obligations, as set out in the Data Processing Agreement.
19. Your rights and how to exercise them
Wherever you live, we give you the following rights over the personal data we hold about you. Some of them are guaranteed by the data protection law of your country; we extend all of them to everyone.
- Access. Ask what personal data we hold about you and receive a copy.
- Correction. Have inaccurate or incomplete data corrected. You can edit most Account data yourself in the dashboard.
- Deletion. Have your personal data deleted. You can close your Account yourself in the dashboard; section 17 explains what happens next and what we must retain.
- Export and portability. A self-serve JSON export of your Account data is available in the dashboard, and you may ask us for a copy in a machine-readable format or, where feasible, for it to be transmitted to another provider.
- Objection. Object to processing based on our legitimate interests, and to any direct marketing.
- Restriction. Ask us to restrict processing while a dispute about accuracy or lawfulness is resolved.
- Withdraw consent. Where we rely on consent, withdraw it at any time without affecting processing that already took place.
- Human review of automated decisions. Not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you (section 9).
- Complain. Complain to the data-protection authority in the country where you live or where you believe a breach occurred. We would appreciate the chance to resolve your concern first.
How to exercise them. Email support@oxypages.com from the address on your Account, or use the dashboard tools. We may ask you to confirm your identity, usually by responding from your Account email or signing in; we will not ask for more than is needed to verify you, and we will use verification information only for that purpose. You may authorise someone to act for you; we may ask for proof of the authorisation and, where the law permits, confirm with you directly.
Timing and cost. We respond without undue delay and in any event within 30 days, or within any shorter period your local law requires. If a request is complex we may take longer where the law allows, and we will tell you within the first 30 days. We do not charge for requests unless they are manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline, and we will tell you why.
No discrimination. We will not deny you the Service, charge you a different price or provide a different level of service because you exercised a right.
Refusals and appeals. If we cannot comply with a request in full, we will tell you why. If you disagree with our response you may ask us to reconsider by replying to it; a different person will review the decision and answer within the time the applicable law allows. You may also complain to your data-protection authority.
Requests about Hosted Sites. If your request concerns data you gave to a Hosted Site, section 10 applies.
20. Children
The Service is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18, and you may not open an Account if you are under 18. If we learn that we have collected personal data from a person under 18 we will close the Account and delete the data. If you believe someone under 18 has given us personal data, email support@oxypages.com.
If you are a site owner, you are responsible for ensuring that any Hosted Site directed at children complies with the laws that apply to it.
21. Additional information for residents of particular places
The core of this policy applies to everyone. This section adds only what the law of certain places requires us to say, or requires us to say in a particular way. Where this section and the rest of the policy differ, this section prevails for residents of the place concerned.
21.1 Malaysia
This policy, including this subsection, is the written notice required by section 7 of the Personal Data Protection Act 2010 (as amended). Each element the Act requires is addressed as follows: the personal data being processed and its description (section 4); the purposes (section 5); the source (section 4, "Information we receive from third parties"); your right to request access to and correction of your personal data and how to contact us (section 19 and section 23); the classes of third parties to whom the data is disclosed (section 15); the choices and means you have to limit processing (section 19, and the optional features described in sections 6 to 12); whether supplying the data is obligatory or voluntary and the consequences of not supplying it (section 4, "What you must provide").
A Bahasa Malaysia version of this notice is available on request.
Data controller. Ditra Point, Malaysia. Contact: support@oxypages.com.
Access and correction requests. We respond to data access and data correction requests within 21 days. We do not charge the prescribed fee.
Data protection officer. We have not appointed a data protection officer. We keep this under review against the appointment thresholds in the Act and will appoint one, and update this notice, if and when the law requires.
Transfers outside Malaysia. We transfer personal data outside Malaysia only as section 129 of the Act permits: to places whose law is substantially similar to the Act or that otherwise ensure adequate protection, where the transfer is necessary to perform our contract with you, with your consent, or under another condition the Act allows. Section 16 describes the safeguards.
Complaints. You may complain to the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi), https://www.pdp.gov.my.
21.2 European Economic Area, United Kingdom and Switzerland
Controller and representative. Ditra Point, Malaysia, is the controller. We are subject to the GDPR and the UK GDPR because we offer the Service to people in the EEA and the UK. We have not appointed a representative in the EEA or the UK under Article 27 of the GDPR or UK GDPR at this time. Contact us directly at support@oxypages.com.
Legal bases. The "Basis" column in sections 4 and 5 identifies the lawful basis for each processing activity: performance of a contract (Article 6(1)(b)); compliance with a legal obligation (Article 6(1)(c)); our legitimate interests (Article 6(1)(f)), namely security, abuse prevention, product improvement, operating the affiliate programme and defending legal claims; and consent (Article 6(1)(a)) where we ask for it. We do not process special-category data.
Your rights. The rights in section 19 correspond to Articles 15 to 22 of the GDPR and UK GDPR. We respond within one month, extendable by two months for complex requests with notice. Where we rely on legitimate interests you may object on grounds relating to your particular situation, and we will stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms or the processing is needed for legal claims.
International transfers. Malaysia, India, Singapore and China are not the subject of an adequacy decision; the United States is covered only for organisations certified under the EU-U.S. Data Privacy Framework (and its UK Extension and Swiss equivalent). For transfers to countries without adequacy we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum or the UK International Data Transfer Agreement for UK data, and the Swiss adaptations for Swiss data), the recipient's Data Privacy Framework certification where applicable, and, where neither is available, the derogation for transfers necessary for the performance of our contract with you.
Cookies. The authentication and password-gate cookies in section 13 are strictly necessary and exempt from consent. The ox_ref cookie is set only when you arrive through a referral link, holds only a referral reference and is never used to track you.
Complaints. You have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work or the place of an alleged infringement. In the UK, the Information Commissioner's Office, https://ico.org.uk. In the EEA, the list of authorities is at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en. In Switzerland, the Federal Data Protection and Information Commissioner, https://www.edoeb.admin.ch.
21.3 California and other US states
This subsection provides the disclosures the California Consumer Privacy Act (as amended by the California Privacy Rights Act) requires. It also applies, with the adjustments noted, to residents of other US states with comprehensive privacy laws, to the extent those laws apply to us.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA, and we have not done so in the preceding 12 months. We do not engage in targeted advertising or in profiling in furtherance of decisions that produce legal or similarly significant effects. We have no actual knowledge that we sell or share the personal information of anyone under 16.
Categories of personal information collected in the preceding 12 months.
| CCPA category | Collected | What we collect | Sources | Business purpose | Disclosed to (for a business purpose) |
|---|---|---|---|---|---|
| A. Identifiers | Yes | Name, email address, Account ID, IP address in request logs, Stripe customer ID, domain registrant details | You; your device; Google (sign-in) | Providing the Service, security, payments, domain registration | Service providers in section 15; registrar and registries |
| B. Customer records (Cal. Civ. Code 1798.80(e)) | Yes | Name, postal address and telephone number (domain registrants only), card brand, last four and expiry | You | Payments, domain registration | Stripe, Dynadot, registries |
| C. Protected classifications | No | ||||
| D. Commercial information | Yes | Plans purchased, transactions, invoices, affiliate commissions | You; Stripe | Providing the Service, accounting | Stripe; Supabase |
| E. Biometric information | No | ||||
| F. Internet or network activity | Yes | Dashboard pages viewed and features clicked; request, security and error logs; API usage | Your use of the Service | Improving the Service, security, debugging | Supabase, Render, Cloudflare, Vercel |
| G. Geolocation data | No | We do not collect precise geolocation. Country-level location is derived from IP address only in Hosted-Site analytics, which we process as a service provider for the site owner | |||
| H. Audio, visual or similar | No | ||||
| I. Professional or employment information | No | ||||
| J. Education information | No | ||||
| K. Inferences | No | ||||
| L. Sensitive personal information | Yes, one item | Account log-in credentials (password hash, two-factor secret) | You | Authenticating you only; this use does not trigger the right to limit | Supabase |
We also collect the content you upload (Customer Content, AI prompts, support messages and attachments), which may contain personal information in any category you choose to include. Each category is retained for the periods in section 17. The categories of third parties to whom we disclose personal information for a business purpose are service providers and contractors (database, hosting, edge network, payments, email, AI, sign-in and safety services), the domain registrar and registries, professional advisers, and government authorities where required. Sections 4, 5 and 17 together constitute our notice at collection.
Your rights. The right to know, the right to delete, the right to correct, and the right to non-discrimination, as described in section 19. The right to opt out of sale or sharing and the right to limit use of sensitive personal information do not arise because we do not sell or share personal information and we use sensitive personal information only for purposes that do not trigger the right to limit; we nonetheless treat a Global Privacy Control signal as a valid opt-out request.
How to exercise them. Email support@oxypages.com. We are an online-only business and email is our designated request method. We verify requests by matching the information you provide with what we hold, normally by confirming from your Account email address; we will not require you to create an Account to make a request. An authorised agent may submit a request on your behalf; we may require proof of written authorisation and may confirm the request with you directly. We respond within 45 days, extendable once by a further 45 days with notice.
Appeals (other states). If you are a resident of a state whose law provides an appeal right and we decline your request, you may appeal by replying to our decision. We will respond in writing within the time your state's law allows with the reasons for our decision. If we deny your appeal you may contact your state Attorney General.
Shine the Light (Cal. Civ. Code 1798.83). We do not disclose personal information to third parties for their direct marketing purposes.
22. Changes to this policy
We will post any changes to this policy on this page and update the "Last updated" date. If a change is material, meaning it reduces your rights, adds a category of personal data, adds a purpose, or adds a sub-processor that processes Visitor data, we will email the address on your Account at least 30 days before the change takes effect, unless the change is required sooner by law. Continuing to use the Service after a change takes effect means the updated policy applies to you; if you do not agree, close your Account before then.
Previous versions are available on request.
23. Governing law and contact
This policy is governed by the laws of Malaysia. Nothing in it removes rights you have under mandatory data-protection law in the country where you live, which apply in addition.
Ditra Point (operating OxyPages) Malaysia Malaysia (postal address available on request)
Privacy questions, requests to exercise your rights, complaints, Data Processing Agreement requests and security reports: support@oxypages.com
We have not appointed a data protection officer or a representative in the EEA or the UK. Every privacy matter should be sent to the address above and will be handled by the person responsible for data protection at Ditra Point.