Privacy Policy

Version 2026-08-26 · Effective August 26, 2026

This Privacy Policy explains how OID Guard collects, uses, discloses, and retains personal information through its public website, demo and plan-enrollment forms, account-confirmation process, OID Guard workspaces, support, and related services. It applies to website visitors, prospective customers, Customer Owners and Managers, and Authorized Users.

Information we collect

Information you provide

We collect information you provide when you request a demo, select a plan, confirm an email address, create or administer an account, accept a workspace invitation, contact support, or otherwise use the Service. This may include your name, work email, phone number, company name and size, role or title, business address, compliance priorities, team information, account credentials, communications, and plan-selection details.

Customer Content

Customers and Authorized Users may submit supplier and operation information, NOP Operation IDs, certified-item details, ingredients, products, SKUs, purchasing mappings, notes, assignments, decisions, evidence records, uploaded files, and other business information needed for their compliance workflow.

Subscription and transaction information

For paid plans, we receive information about the selected plan, transaction status, subscription status, billing contact, payment-method type and last digits, and related payment events. Stripe processes complete card and bank-payment details through its payment interface; OID Guard does not collect complete card numbers through its signup form.

Usage, device, and security information

When you visit the website or use the Service, OID Guard and its providers may process IP address, browser and device information, operating system, requested pages and features, referring page, timestamps, session identifiers, authentication events, diagnostic information, and security logs.

Public-source information

OID Guard retrieves publicly available Organic Integrity Database information, including operation and certified-item records. Customers may connect that public information to their internal supplier and product context.

Where information comes from

We obtain information directly from you; from the Customer organization that creates a workspace or invites you; automatically from browsers, devices, and Service activity; from service providers such as hosting, email, security, and payment providers; and from public sources used to provide monitoring.

How we use information

OID Guard uses information to:

Customer organizations and workspace users

The Customer organization controls its workspace and decides what Customer Content to submit, which users to invite, what permissions to grant, and how its team uses the Service. Customer Owners and Managers may access and manage information associated with their Authorized Users and workspace.

For personal information contained in Customer Content, OID Guard generally processes information to provide the Service on the Customer’s instructions. If your request concerns information controlled by your employer or another Customer organization, contact that organization first. OID Guard will assist the Customer as required by applicable law and its agreement with OID Guard.

How information is disclosed

OID Guard may disclose information:

OID Guard does not sell personal information and does not share personal information for cross-context behavioral advertising.

Service providers

Providers may process personal information only for the services they supply to OID Guard or as otherwise permitted by their agreements and applicable law. Current provider categories include infrastructure and hosting, database and storage, email delivery, payment processing, security, diagnostics, and professional support. Stripe’s handling of payment information is also governed by Stripe’s own privacy terms presented through its services.

Cookies and similar technologies

OID Guard may use necessary cookies and similar technologies to maintain sessions, authenticate users, remember preferences, balance traffic, prevent abuse, and protect the Service. On the production website, OID Guard uses Google Tag Manager to deploy Google Analytics. Google Analytics may use cookies or similar technologies and process information such as requested pages, referring pages, timestamps, approximate location derived from IP address, and browser or device information. OID Guard uses this information to understand website traffic, evaluate engagement, troubleshoot performance, and improve the website and Service. OID Guard does not use Google Analytics for cross-context behavioral advertising. Learn more about how Google uses information from sites that use its services.

Communications

OID Guard sends transactional communications needed to confirm enrollment, administer accounts, process payments, provide security notices, and operate the Service. We may also respond to requests or send information about OID Guard when you ask for a demo or product information. You may opt out of nonessential promotional email using the instructions in the message, but account, billing, security, and legal notices will still be sent when necessary.

Data retention

OID Guard retains information for the period reasonably necessary for the purposes described in this policy, including providing the Service, maintaining security and business records, processing transactions, resolving disputes, enforcing agreements, and complying with law.

Published evidence-retention limits describe how long monitoring history is available within a plan; they do not necessarily determine retention of account, subscription, security, support, backup, consent, or legally required records. When information is no longer needed, OID Guard will delete, de-identify, or securely dispose of it according to applicable processes and backup cycles.

Security

OID Guard uses reasonable administrative, technical, and organizational measures designed to protect personal information, including access controls and safeguards appropriate to the nature of the information processed. No system can be guaranteed completely secure. Users should protect account credentials and promptly report suspected unauthorized access to [email protected].

Your choices and privacy requests

You may update certain account information through the Service or through your Customer Owner or Manager. Depending on your location and applicable law, you may have rights to request access to, correction of, deletion of, or information about personal information OID Guard holds, and to appeal a response to a privacy request.

Submit a request to [email protected]. Include enough information for us to understand the request. OID Guard may verify your identity and authority before responding. Authorized agents may submit requests where applicable law permits. OID Guard will not discriminate against a person for exercising an applicable privacy right.

Because OID Guard does not sell personal information or use it for cross-context behavioral advertising, browser-based opt-out preference signals do not currently change website behavior.

Children’s privacy

The website and Service are intended for business users who are at least 18 years old and are not directed to children. OID Guard does not knowingly collect personal information from children through account enrollment. If you believe a child has provided personal information, contact us so we can evaluate and address it.

Changes to this policy

OID Guard may update this Privacy Policy when its website, Service, providers, or applicable requirements change. The version and effective date above identify the current policy. OID Guard will provide additional notice when a material change requires it.

Contact

For questions or privacy requests, contact [email protected].