Privacy Policy
Effective and last updated: September 3, 2026
The operator and data controller's legal identity, address, registration details, and representative information are TBD before production launch. They will be published before real-money public service begins. Privacy requests may currently be sent to support@opennextai.com.
1. Scope
This Policy explains how OpenNext AI handles personal information when you browse the directory, follow an outbound link, submit or manage a product, purchase Sponsored placement, report content, contact support, or use the admin service. Third-party product websites and payment-provider pages have their own privacy practices.
2. Information we collect
- Product and submission data: product URL, name, descriptions, category, logo, preview image, submitted website metadata, review status, and ownership history.
- Contact and verification data: Owner, payer, reporter, and support email addresses; Magic Link records; verification timestamps; and correspondence you send.
- Order data: internal order identifiers, amount, currency, terms version, provider checkout and payment identifiers, payment/refund/dispute status, and timestamps.
- Usage and click signals: requested product, time, a pseudonymous visitor identifier, a rotating IP-derived hash, referring host, user-agent bot signals, and valid or suspected-click totals.
- Security and operations data: admin actions, audit reasons, webhook event data, rate-limit signals, diagnostic information, and server or hosting logs.
Our application does not store raw payment-card numbers. Payment providers may collect billing name, address, tax information, card or bank details, device data, and fraud signals under their own policies.
3. How we use information
- Operate organic listings, Sponsored ranking, checkout, refunds, and product management.
- Verify ownership, prevent email enumeration, secure Magic Links, and resolve disputes.
- Measure valid outbound engagement and filter duplicate or automated traffic.
- Review products and reports, enforce the Terms, prevent fraud, and preserve payment and administrative audit records.
- Respond to support, privacy, legal, and safety requests.
- Maintain, debug, secure, and improve the service and comply with applicable law.
4. Legal bases
Where a legal basis is required, we process information as necessary to perform a contract or take requested pre-contract steps; for legitimate interests such as operating, securing, measuring, and improving the service; to comply with legal obligations; and with consent where required. You may withdraw consent without affecting earlier lawful processing.
5. Email and account security
Email addresses are encrypted at rest and separately transformed with a keyed, irreversible hash for matching. Magic Link tokens are stored as hashes, expire after 30 minutes, and are single-use. Responses to Magic Link requests are designed not to disclose whether an email matches a product.
Local-development email capture is not used in production. Production transactional emails are intended to be delivered through Resend or a replacement email provider. We do not send marketing email unless a separate lawful opt-in is implemented.
6. Click measurement
Outbound visits pass through an OpenNext AI redirect so that we can count engagement. We do not retain raw IP addresses in the application database. We generate pseudonymous hashes and apply short-window visitor deduplication and basic bot detection. Counts are estimates and may exclude suspected automation or repeated clicks.
7. Cookies and local storage
The service may use strictly necessary cookies or browser storage for security, administrator sessions, request integrity, and click deduplication. We do not currently operate third-party behavioral advertising cookies. If analytics or non-essential cookies are introduced, this Policy and any required consent controls will be updated before use.
8. How we share information
We may share the minimum necessary information with infrastructure and service providers that process data for us, including hosting, PostgreSQL database, email, security, monitoring, and payment services. Dodo Payments or another payment provider may act as payment processor or Merchant of Record and receive order amount, currency, payer email, internal order reference, and product description.
We may also disclose information when required by law; to protect rights, safety, and service integrity; in connection with a genuine business reorganization subject to appropriate safeguards; or at your direction. We do not sell personal information or share it for cross-context behavioral advertising.
9. Public information
Approved product names, descriptions, categories, images, domains, Sponsored status, rank, effective weekly amount, and filtered click count are public. Owner and payer emails, payment-provider identifiers, visitor hashes, and internal audit data are not intended for public display.
10. Retention
We retain information only while reasonably necessary for the purposes described here, including operating active and historical listings, resolving disputes, preventing abuse, maintaining security records, and meeting accounting, tax, payment, and legal obligations. Payment and immutable ledger records may be retained for the period required by applicable law and provider obligations. Removal of a public listing does not require deletion of transaction or audit records.
Because production jurisdiction and provider contracts are not yet finalized, a detailed production retention schedule is TBD before launch. We will publish it after legal and operational review. You may request deletion now, subject to security, legal, fraud-prevention, and recordkeeping exceptions.
11. International processing
OpenNext AI is intended for a global audience, and providers may process information in countries other than yours. Before production launch, we will identify production providers and implement transfer mechanisms required by applicable law. Different countries may provide different levels of data protection.
12. Security
We use measures including encryption, keyed hashing, one-time expiring links, access controls, signed webhook verification, transaction locking, event idempotency, rate limiting, security headers, and audit logging. No system is completely secure, and we cannot guarantee absolute protection.
13. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing; receive portable data; withdraw consent; and complain to a supervisory authority. We may need to verify your identity and authority before responding. Authorized agents may be required to provide proof of authority.
Send requests to support@opennextai.com with the subject “Privacy request.” Mandatory rights and response periods under applicable law remain unaffected.
14. Children
OpenNext AI is not directed to children under 16, and we do not knowingly collect their personal information. Contact us if you believe a child has provided information so we can investigate and take appropriate action.
15. Changes and contact
We may update this Policy as the service, providers, or laws change. Material changes will be identified by a new effective date and any notice required by law. For questions or complaints, use the Contact page or email support@opennextai.com.