◆ OppEngine ← Back to site
Legal Document

Privacy Policy

Nodiumtech, LLC · Effective date: March 19, 2026 · GDPR · CCPA/CPRA · LGPD · KVKK · PIPEDA compliant

Contents
  • 1. Introduction
  • 2. Data Controller
  • 3. What We Collect
  • 4. How We Use Data
  • 5. Legal Basis (GDPR)
  • 6. Data Sharing
  • 7. Cookies
  • 8. Data Retention
  • 9. Security
  • 10. Your GDPR Rights
  • 11. CCPA Rights (California)
  • 12. Global Privacy Rights
  • 13. Children's Privacy
  • 14. International Transfers
  • 15. Changes
  • 16. Contact & DPO
Plain-language summary: We collect your name, email, and payment info to run our service. We don't sell your personal data to third parties. You have the right to access, correct, or delete your data at any time.
Section 01

Introduction

This Privacy Policy describes how Nodiumtech, LLC ("Company," "we," "us," or "our"), the operator of the OppEngine platform, collects, uses, and shares information about you when you use our website and services (collectively, the "Service").

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this policy, please do not use the Service.

Section 02

Data Controller

For purposes of applicable data protection laws (including GDPR), the data controller is:

Nodiumtech, LLC

Address: 6818 Indian Falls Dr, Missouri City, TX 77489-7748, USA

Email: privacy@oppengine.io

Entity type: Texas Domestic LLC · File No. 0806118150

Section 03

What We Collect

Information You Provide

CategoryData ElementsPurpose
Account Data Full name, email address, password (hashed) Account creation and authentication
Profile Data Professional role, company name, preferences Personalized opportunity recommendations
Payment Data Billing name, last 4 digits of card, billing address, Stripe customer ID Subscription billing (processed by Stripe)
Communications Support tickets, emails sent to us Customer support
Note: We never store your full credit card number, CVV, or complete card data. All payment processing is handled by Stripe, Inc. under PCI-DSS standards.

Automatically Collected Data

CategoryData Elements
Usage Data Pages visited, features used, click events, session duration, search queries within the Service
Device & Log Data IP address, browser type, operating system, device identifiers, referrer URL
Cookies & Trackers Session tokens, analytics identifiers, preference cookies — see our Cookie Policy
Section 04

How We Use Your Data

  • Provide the Service: Create and manage your account, process payments, deliver opportunity reports and alerts
  • Personalization: Tailor opportunity recommendations based on your stated role, industry, and preferences
  • Service Improvement: Analyze usage patterns to improve features, fix bugs, and develop new capabilities
  • Communications: Send transactional emails (account confirmations, password resets, billing receipts), product updates, and — only with your consent — marketing emails
  • Security: Detect and prevent fraud, abuse, and security incidents
  • Legal compliance: Meet obligations under applicable laws, respond to lawful requests from public authorities

We do not use your personal data to train third-party AI models or sell it to data brokers.

Section 05

Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases:

Processing ActivityLegal Basis
Providing account and subscription servicesContract performance (Art. 6(1)(b) GDPR)
Processing paymentsContract performance (Art. 6(1)(b) GDPR)
Service improvement & analyticsLegitimate interests (Art. 6(1)(f) GDPR)
Marketing emailsConsent (Art. 6(1)(a) GDPR) — opt-in only
Fraud prevention & securityLegitimate interests (Art. 6(1)(f) GDPR)
Legal complianceLegal obligation (Art. 6(1)(c) GDPR)
Section 06

Data Sharing & Third Parties

We do not sell your personal data. We share data only with the following categories of third parties, under binding data processing agreements:

Third PartyPurposeLocation
Stripe, Inc.Payment processingUSA (PCI-DSS compliant)
Google LLC (Analytics)Website usage analyticsUSA (SCCs in place)
Hosting providerInfrastructure and data storageUSA
Email providerTransactional and marketing emailsUSA

We may also disclose your information if required to do so by law, court order, or governmental authority; to protect the rights, property, or safety of Nodiumtech, LLC, our users, or the public; or in connection with a merger, acquisition, or sale of assets (with notice to you).

Section 07

Cookies

We use cookies and similar tracking technologies. For full details, see our Cookie Policy. You can manage cookie preferences through our consent banner or your browser settings.

Section 08

Data Retention

Data CategoryRetention Period
Account dataDuration of account + 90 days after deletion request
Payment records7 years (financial/tax compliance)
Usage/analytics logs26 months (rolling)
Support communications3 years from last interaction
Marketing consent records5 years from consent or withdrawal

When we no longer have a legal basis to retain data, we securely delete or anonymize it.

Section 09

Security

We implement industry-standard technical and organizational measures to protect your data, including:

  • TLS/HTTPS encryption for all data in transit
  • Encrypted storage of passwords (bcrypt) — we never store plain-text passwords
  • Access controls limiting data access to authorized personnel only
  • Regular security assessments and monitoring
  • Stripe-managed PCI-DSS compliant payment processing

Despite these measures, no system is 100% secure. If you discover a security vulnerability, please report it responsibly to security@oppengine.io.

In the event of a data breach that affects your rights, we will notify you and applicable supervisory authorities within the timeframe required by law (72 hours under GDPR where applicable).

Section 10

Your GDPR Rights (EEA/UK Users)

If you are in the EEA, UK, or Switzerland, you have the following rights regarding your personal data:

RightWhat it means
AccessRequest a copy of personal data we hold about you
RectificationCorrect inaccurate or incomplete data
ErasureRequest deletion of your personal data ("right to be forgotten")
RestrictionAsk us to limit processing while disputing accuracy or objecting
PortabilityReceive your data in a machine-readable format
ObjectionObject to processing based on legitimate interests or for direct marketing
Withdraw consentWithdraw consent for marketing at any time
Lodge a complaintComplain to your local supervisory authority

To exercise any of these rights, email privacy@oppengine.io. We will respond within 30 days.

Section 11

California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: What personal information we collect, use, and disclose
  • Right to Delete: Request deletion of your personal information
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt Out: Opt out of the "sale" or "sharing" of personal information — we do not sell personal information
  • Right to Limit: Limit use of sensitive personal information
  • Non-Discrimination: We will not discriminate against you for exercising your CCPA rights

To submit a California privacy request, email privacy@oppengine.io with the subject "California Privacy Request."

Section 12

Global Privacy Rights

OppEngine serves users worldwide. In addition to GDPR and CCPA rights, we recognize and respect privacy rights under the following jurisdictions. To exercise any of these rights, contact privacy@oppengine.io.

JurisdictionLawKey Rights Recognized
🇹🇷 Turkey KVKK (Kişisel Verilerin Korunması Kanunu) Access, correction, deletion, objection, data portability. Explicit consent required for processing sensitive data.
🇧🇷 Brazil LGPD (Lei Geral de Proteção de Dados) Access, correction, anonymization, portability, deletion, opt-out of sharing, right to information on third parties.
🇨🇦 Canada PIPEDA / Quebec Law 25 Access, correction, withdrawal of consent, right to know what personal data is held and purpose of collection.
🇦🇺 Australia Privacy Act 1988 (APPs) Access and correction of personal information. We comply with the Australian Privacy Principles.
🇸🇬 / 🇹🇭 Singapore / Thailand PDPA Access, correction, withdrawal of consent, data portability (Singapore PDPA 2021 amendments).
🇯🇵 Japan APPI (Act on Protection of Personal Information) Disclosure, correction, deletion, and cessation of use of personal information.
🇰🇷 South Korea PIPA (Personal Information Protection Act) Access, correction, deletion, suspension of processing, and data portability rights.
How to exercise your rights: Regardless of your country, email privacy@oppengine.io with your full name, jurisdiction, and the specific right you want to exercise. We will respond within the timeframe required by the applicable law in your jurisdiction (typically 30 days).
Section 12

Children's Privacy

The Service is not directed to, and we do not knowingly collect personal information from, children under the age of 18. If we learn that we have inadvertently collected personal information from a child under 18, we will promptly delete it. If you believe we have collected such information, please contact us at privacy@oppengine.io.

Section 14

International Data Transfers

Nodiumtech, LLC is based in the United States. If you access the Service from outside the US, your personal data will be transferred to and processed in the United States, which may have different data protection laws than your country.

We implement the following safeguards for cross-border data transfers:

  • EEA/UK/Switzerland: EU Standard Contractual Clauses (SCCs) per EC Decision 2021/914 with our third-party processors
  • Turkey (KVKK): Adequate safeguards or explicit consent for international transfers as required by KVKK Article 9
  • Brazil (LGPD): Transfers rely on contractual clauses, user consent, or adequacy decisions as applicable
  • Canada (PIPEDA): Contractual protections ensuring comparable protection to Canadian standards
  • All other countries: We use contractual clauses, your consent, or other legally recognized transfer mechanisms
Section 15

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the "Effective date" above at least 14 days before changes take effect. Your continued use of the Service after that date constitutes acceptance of the updated policy.

Section 16

Contact & Data Protection Inquiries

Nodiumtech, LLC — Privacy Team

Email: privacy@oppengine.io

General contact: hi@oppengine.io

Mailing address: 6818 Indian Falls Dr, Missouri City, TX 77489-7748, USA

Response time: We aim to acknowledge all privacy requests within 5 business days and respond fully within 30 days.

◆ OppEngine
Home Terms of Service Privacy Policy Cookie Policy Contact

© 2026 OppEngine — Nodiumtech, LLC · Missouri City, TX 77489 · All rights reserved.