Privacy Policy
Last updated September 14, 2026
This policy explains what Operax () collects when a business uses the service, what happens to it, who else processes it, how long we keep it and what you can ask us to do with it. It is written for the businesses that use Operax; the people they market to are covered in section 3.
1. Who this covers
Operax is a business-to-business service. Our customers are the businesses that create an account, and the users are the people they invite. A customer decides which of its own systems to connect and which of its customers’ data flows through Operax; for that data the customer is the controller and Operaxprocesses it on the customer’s instructions. Where this policy says you, it means a customer or one of its users.
2. What we collect
Account data. Your name, work email, password (stored as a salted hash, never in the clear), role, two-step-verification secret and backup codes, theme and notification preferences, and the invitations you send.
Business profile. What you tell us about the business — name, locations, services, service area, technicians, capacity, hours, brand kit (logos, colours, taglines) — and what the AI infers from it into the business model and its knowledge memory.
Connected-platform data. When you connect Google Ads, Meta Ads, Google Business Profile, CallRail, Twilio, an email provider or a revenue source, we store the OAuth tokens or API credentials needed to act on your behalf and pull the data those platforms expose: campaigns, ad groups, ads, keywords, spend and performance metrics, business-profile posts and reviews, call logs and SMS logs, and revenue figures. Credentials are encrypted at rest with Fernet (symmetric authenticated encryption) using a key held outside the database, and are decrypted only at the moment a connector uses them.
Leads, calls and appointments. The people who contact your business through the channels you connect: name, phone number, email, message, source and attribution touches, lead status and value; call records including caller number, duration, outcome and — where your call-tracking provider records them — call recordings and transcripts; and appointments with their address and time. You are responsible for any notice your callers are owed about recording.
Usage and audit data. Every decision the AI proposes, its reasoning, who approved or rejected it and when, every action executed and its result, credit consumption, sign-ins and security events, and technical logs (IP address, browser, request identifiers) kept for security and debugging.
Billing data. Your plan, subscription status, invoices and credit purchases. Card details are entered on and stored by Stripe; we hold only Stripe’s identifiers and the last four digits Stripe shows us.
3. Your customers’ data
Operax processes information about the people who contact or are marketed to by your business (leads, callers, review authors, message recipients) only to run the Service for you: to attribute and follow up leads, to draft replies and messages you or your autonomy settings approve, and to report results. Every outbound message carries an unsubscribe route, and an opt-out is recorded as a suppression that the Service will not message again. If one of your customers asks you about their data, we will help you answer.
4. How AI processing works
The AI agents that propose and carry out work are large language models run by third-party providers. To do a task, Operax assembles a prompt from the relevant slice of your data — for example a review and your brand voice to draft a reply, or campaign metrics and your guardrails to propose a budget change — and sends it to the provider over an encrypted API connection. The providers we use are Anthropic and OpenAI. Under their API terms, data sent this way is not used to train their models. Prompts and responses may be retained by a provider briefly for abuse monitoring under its own policy. Operax decides which provider and model handle each kind of task and may change that routing at any time; the routing is managed by Operax and is not shown in the console.
AI outputs are proposals and drafts. The console records who or what approved each action, so there is always an audit trail from a change on a platform back to the decision and the data it was based on.
5. Sub-processors
The third parties that process data on our behalf, and why:
- Stripe — payments, subscriptions, invoices and the billing portal.
- Anthropic and OpenAI — the AI models described in section 4.
- Google (Google Ads, Google Business Profile, and Google sign-in where offered) and Meta (Meta Ads) — the platforms you connect; data flows both ways under the access you grant.
- Twilio — sending and receiving SMS on the numbers you connect.
- CallRail — call tracking, recordings and transcripts, when you connect it.
- Mailgun — delivering the emails the Service sends (verification, invitations, notifications, and email campaigns you run).
- DataForSEO — keyword, ranking, backlink and competitor research; receives search terms and domains, not personal data.
- OpenWeather — local weather used to time demand forecasts; receives a location, not personal data.
- Our hosting provider — the servers, database and file storage the Service runs on.
We will update this list before adding a sub-processor that would handle your customers’ personal data, and will notify account owners by email or in the console.
6. How long we keep data
Account and business data, performance metrics, decisions and audit records are kept for as long as your account is active; there is no per-plan retention period. Call recordings and transcripts follow your call-tracking provider’s retention. Disconnecting a platform revokes our credential for it, and removing a user deactivates that user’s sign-in. When you ask us to delete your account (section 8), we delete its data, except for invoices and records we must keep for legal or accounting reasons.
7. Security
All traffic to Operax and to every sub-processor is encrypted in transit (TLS). Platform credentials are encrypted at rest as described in section 2, and database volumes are encrypted at rest. Access inside the product is role-based, with purchases and destructive settings limited to the account owner and admins; every mutation is written to an audit trail with who did it and when. Users can turn on two-step verification, and sign-in is rate-limited and locks after repeated failures. Our own staff access production data only to operate the Service or at your request, and that access is logged. No system is perfectly secure; if we learn of a breach affecting your data we will tell you without undue delay.
8. Your rights and choices
You can see and change most account and business data in the console. To export everything we hold for your account, to delete your account and its data, or to ask what we hold, email the support address shown in your account from the account owner’s address; we answer within 30 days. You can disconnect any platform at any time from the Integrations page, which also revokes our credential for it. Depending on where you are, you may also have rights to correct or restrict processing and to complain to a data-protection authority; we will not treat you differently for exercising them.
9. Cookies and local storage
The console does not use tracking cookies and does not load third-party analytics or advertising trackers. It keeps your session tokens (JWTs) in the browser’s localStorage so you stay signed in, together with your theme, selected business and sidebar preference. Signing out clears the tokens; you can also clear them by clearing site data. Public pages the Service hosts for your business (landing pages, review-request links, unsubscribe pages) set no cookies of their own.
10. Email from us
We send transactional email you cannot opt out of while you have an account: verification, password resets, invitations, security alerts, billing notices and the notifications you enabled. We may also send product news; every such email has an unsubscribe link, and you can opt out in Settings.
11. Children
Operax is not directed at anyone under 18 and we do not knowingly collect their data. If you believe a minor has created an account, tell us and we will remove it.
12. International transfers
Your data is stored with our hosting provider and processed by the sub-processors above, some of which operate in countries other than yours. Where a transfer needs a legal safeguard, we rely on the sub-processor’s standard contractual clauses or an equivalent mechanism. Ask us if you need a copy of the terms that apply.
13. Changes to this policy
We will update this policy when the Service changes in a way that affects it. Material changes are announced to account owners by email or in the console before they take effect. The date at the top is the current version.
14. Contact
Privacy questions and requests go to the support address shown in your account. The operator’s legal name and postal address are shown on your invoices.