Privacy Policy

1. Introduction

At Oddapy ("we," "us," or "our"), your privacy matters. This Privacy Policy explains what information we collect, how we use it, and how we protect it when you use the Oddapy application, website, and related services (the "Services").

Oddapy is owned and operated as a sole proprietorship based in Bangladesh.

By using our Services, you acknowledge that you've read and understood this Privacy Policy. This policy is an integral part of our Terms of Service.

2. Information We Collect

Information You Provide

Account Information: Name, email address, password, country, date of birth, mobile number, and optionally a profile picture.

Your Content: Everything you create, upload, or store in Oddapy — including calendar slots, bookmarks, files, documents, notes, shopping lists, and task items.

Communications: Support requests, feedback, survey responses, and any messages you send through the Services.

Payment Information: If you subscribe to premium features, our secure payment processors collect the necessary billing details (e.g., card number, billing address). We do not store your full payment information on our servers.

Preferences: Your app settings, notification preferences, and display customizations.

Information We Collect Automatically

Device Information: Device type, operating system, browser type, IP address, time zone, and unique device identifiers.

Usage Data: How you interact with the Services — features used, time spent, performance data, error logs, and navigation patterns.

Location: General location derived from your IP address or time zone. We only collect precise location data if you explicitly grant permission and it's relevant to a specific feature.

Information from Third Parties

If you connect third-party services to Oddapy (e.g., Google Calendar, cloud storage), we may receive data from those services — such as calendar events, contacts, or files — based on the permissions you grant.

3. How We Use Your Information

To provide the Services: Creating your account, delivering core functionality, processing subscriptions, and customizing your experience based on your preferences.

To communicate with you: Responding to support requests, sending service notifications (verification, security alerts, reminders, task due dates), and — where you've opted in — product updates and newsletters.

To keep things secure: Verifying identity, preventing unauthorized access and fraud, monitoring for security threats, and enforcing our Terms of Service.

To improve the Services: Generating anonymized, aggregated analytics to understand usage trends, monitor performance, test new features, and enhance service quality. This data cannot identify you or any individual user.

4. Legal Bases for Processing

If you're in the European Economic Area (EEA), United Kingdom, or a region with similar laws, we process your data based on:

Contractual Necessity: Processing required to deliver the Services you've signed up for.

Legitimate Interests: Improving and securing the Services, and analyzing how they're used — balanced against your privacy rights.

Consent: For things like marketing communications, precise location data, and non-essential cookies. You can withdraw consent at any time.

Legal Obligation: Complying with applicable laws, court orders, or regulatory requirements.

5. Cookies and Similar Technologies

We use cookies and local storage to keep the Services running smoothly and to understand how they're used.

Essential Cookies: Required for authentication, security, and remembering your settings. The Services can't function properly without these.

Analytics Cookies: Help us understand usage patterns by collecting anonymous, aggregated data. These do not profile or identify individual users.

Functionality Cookies: Remember your choices (language, display preferences) for a better experience.

You can manage cookies through your browser settings. Blocking essential cookies may affect functionality. Where applicable, you'll see a cookie banner on first visit to accept or decline non-essential cookies.

6. How We Share Your Information

We do not sell your personal information. We do not share your data with third parties for advertising or marketing purposes. We only share information in the following limited circumstances:

Service Providers

We work with trusted providers for hosting, payment processing, email delivery, and customer support. They access your data only as needed to perform their services and are contractually required to protect it.

Third-Party Integrations

If you connect a third-party service to your Oddapy account, we share data with that service as needed for the integration to work. These exchanges are governed by the third party's own privacy policy.

Legal Requirements

We may disclose your information if required by law or in response to valid legal requests such as court orders, subpoenas, or government demands.

Business Transfers

If Oddapy is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our Services before any such transfer.

With Your Consent

We may share information with third parties if you explicitly ask us to or give us permission.

7. Data Transfers and Storage

Oddapy is managed from Bangladesh, with servers and infrastructure hosted in various locations globally. Your data may be stored and processed across these locations as necessary to deliver the Services.

When transferring data internationally, we implement appropriate safeguards in line with applicable data protection laws, including standard contractual clauses and other legally approved mechanisms.

All data is stored using industry-standard encryption, both in transit and at rest.

8. Your Privacy Rights

Depending on where you live, you may have the right to:

Access and Portability: Request a copy of your personal data in a structured, machine-readable format.

Correction and Deletion: Update inaccurate information, or request that we delete your data (subject to legal exceptions). You can also delete your account through your account settings.

Restriction and Objection: Restrict or object to certain processing, including direct marketing. Where processing is based on consent, you can withdraw it at any time.

Communication Preferences: Manage notifications in your app settings, use unsubscribe links in marketing emails, or contact support.

How to Exercise Your Rights

Use the controls in your account settings, or submit a request through the support form in the app (see Oddapy Help for how to find it). We'll respond within 30 days or as required by your local law. We may need to verify your identity before processing your request.

9. Data Security

We take security seriously and use appropriate measures to protect your data, including:

  • End-to-end encryption for sensitive personal data
  • Encryption of all data in transit and at rest
  • Access controls and authentication safeguards
  • Regular security assessments

No system is 100% secure. While we work hard to protect your information, we cannot guarantee absolute security. If a data breach occurs, we will notify you as required by law.

10. Data Retention

We keep your data only as long as necessary for the purposes described in this policy.

Account Data: Retained until you delete your account. After deletion, data is removed or anonymized within 30 days, unless we're legally required to retain it.

Usage Data: Generally retained for no more than 24 months.

Backups: May contain personal data for up to 30 days after deletion from active systems, for disaster recovery purposes.

When data is no longer needed, we securely delete or anonymize it.

11. Children's Privacy

Oddapy is not intended for children under 16 (or the applicable digital consent age in your jurisdiction). We do not knowingly collect data from children. If you believe a child has provided us with personal information, contact us at privacy@oddapy.com and we will promptly remove it.

12. Region-Specific Rights

California Residents

Under the CCPA/CPRA, you have the right to know what data we collect and disclose, request deletion or correction, opt out of any sale or sharing of personal information, and limit use of sensitive data. We do not sell or share your personal information for advertising purposes. To exercise your rights, contact privacy@oddapy.com.

EEA, UK, and Similar Jurisdictions

In addition to the rights in Section 8, you may lodge a complaint with your local data protection authority and have the right not to be subject to automated decision-making that produces legal or significant effects. For data protection requests, contact privacy@oddapy.com.

Other Regions

We comply with local privacy laws wherever we operate. Contact us for jurisdiction-specific information.

13. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we'll notify you via email or a prominent in-app notice, and where required by law, seek your consent. We'll always update the "Last Updated" date at the top. Non-material changes take effect immediately upon posting.

14. Contact Us

If you have questions about this Privacy Policy or want to exercise your rights, reach out to us:

We're committed to resolving any privacy concern fairly. If you feel we haven't addressed your issue, you may have the right to lodge a complaint with the data protection authority in your country.