1. Who is responsible
The proposed data controller is Chakker Digital (Mohamed Chakker), reachable at privacy@oveloa.com and Grønnegata 78-88, 9008 Tromsø, Norway.
2. Data Oveloa processes
- Account data: email address, account identifier, authentication/session records and plan status.
- Property-production data: uploaded photographs, optional floor plans, room labels, chosen order, generated prompts, model settings, videos and project metadata.
- Collaboration data: Agency invitations, roles, activity, review-link recipients, reviewer names/emails, comments, timestamps and approval decisions.
- Billing data: Paddle customer/subscription/transaction identifiers, plan, invoice references, payment state, currency and summarized payout amounts. Oveloa does not store complete card details.
- Security and operations data: pseudonymous rate-limit identifiers, request metadata, generation status, provider usage, errors and support/privacy requests.
3. Why Oveloa processes data
Oveloa processes account, property-production, collaboration and subscription data as necessary to provide the service and perform its contract with you. Billing, tax and accounting records are processed to comply with legal obligations.
Security logs, fraud-prevention records, service diagnostics and limited operational analytics are processed for Oveloa's legitimate interests in protecting customers, preventing abuse, maintaining reliability and establishing or defending legal claims. Where consent is legally required, Oveloa will request it separately and you may withdraw it prospectively.
Oveloa does not currently include product analytics, advertising pixels or cross-site behavioral tracking in the application repository, and does not sell customer property media.
4. Processors and recipients
- OpenAI Sites and Cloudflare infrastructure: application hosting, edge execution, D1 structured records and R2 media storage.
- Supabase: account authentication and email-verification sessions.
- Google: optional Google sign-in selected by the user.
- Paddle: checkout, subscriptions, taxes, invoices, payment methods, refunds and payment disputes.
- BytePlus ModelArk: supplied references and deterministic instructions needed to generate requested video output.
- Transactional email: Resend for account confirmation and password recovery.
Client-selected recipients also receive only the review or delivery information exposed by the scoped link the creator shares.
5. International data transfers
Some providers or support functions may process data outside Norway or the EEA. Where this happens, Oveloa relies on an applicable adequacy decision, approved standard contractual clauses, or another lawful transfer mechanism, together with supplementary safeguards where required.
BytePlus ModelArk generation is currently configured in the Asia-Pacific region. Property references and generation instructions may therefore be processed outside the EEA when you request a generation. Contact the privacy address below for current provider and transfer information.
6. Retention and deletion
- Ordinary uploaded references: approximately 1 days.
- Accepted-generation source references used for revision: approximately 3 months.
- Generated MP4 files: approximately 7 days; history metadata may remain after the file expires.
- Review links expire on the creator’s selected schedule and may be revoked earlier.
- Account, billing, fraud-prevention and support records remain only as long as needed for service, legal, accounting, security or dispute purposes.
Use the support page to request media deletion, account deletion, access or correction. Deletion is verified before execution and may exclude records that must lawfully be retained.
7. Essential cookies and browser storage
Oveloa currently uses essential Supabase session cookies, a scoped review-access cookie when a protected recipient link is unlocked, and Paddle’s checkout/payment storage when billing is opened. These are used for requested authentication, security and payment functions.
The browser stores harmless studio draft state, recent/pending generation identifiers and temporary account-navigation data locally. It does not store provider credentials or payment-card data.
No non-essential analytics or advertising tracker is currently installed, so Oveloa does not display a cosmetic consent banner. This assessment must be repeated before adding analytics, marketing pixels or session-replay tools.
8. Your privacy rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may complain to the relevant supervisory authority. Requests can be opened from Support & data requests. Oveloa may verify identity before disclosing or deleting account information.
9. Security practices
Oveloa keeps provider credentials server-side, validates file content, restricts files and sizes, uses scoped signed URLs, server authorization, rate limits, idempotent billing/generation records, expiring review links and payment-webhook signature verification. No internet service can guarantee absolute security.
Report a suspected security issue privately to security@oveloa.com; do not include API keys, passwords or customer media in the first message.
10. Questions and changes
Privacy contact: privacy@oveloa.com. Material changes will be communicated as required before they take effect.