Skip to content

Sign in to OraFarmer

Use a trusted identity provider. We never store your password.

By signing in you agree to our Terms and Privacy Policy.

Legal

Privacy Policy

Last updated: April 20, 2026

This policy explains what personal data OraFarmer ("we") collects, why, and how we handle it. It applies to our websites, software, subscriptions, hardware purchases, and support. By using any of these services you accept this policy.

1. Who we are

OraFarmer is the data controller for information we collect through our services. Contact: [email protected].

2. Information we collect

We collect only what we need to operate, bill, and improve the services:

  • Account data: email, display name, and avatar — supplied when you sign in with Google; Google account identifier; last login timestamp and IP.
  • Subscription data: plan, status, renewal date, and a reference to your Stripe customer/subscription records. We do not store payment-card numbers; Stripe holds those.
  • Billing and shipping data: for hardware orders — name, shipping address, tax identifiers where required, order history, and invoice records.
  • Product telemetry: crash reports, performance metrics, feature usage counts, app version, operating system, and a generated device identifier. Telemetry is reported in aggregate and does not include the contents of your device screens, macros, or the accounts you automate.
  • Support correspondence: any data you voluntarily share when contacting us — including screenshots, logs, and attachments you upload. Do not share information you do not want us to process.
  • Server and security logs: IP address, request metadata, user-agent, and timestamps — retained for fraud prevention, abuse detection, and legal compliance.

3. Why we process it (legal bases)

  • To provide and maintain the services you requested — contractual necessity.
  • To process payments, issue invoices, and enforce tax law — legal obligation.
  • To detect fraud, abuse, and protect our services and other users — legitimate interest.
  • To send product updates, policy changes, and transactional messages to paying customers — legitimate interest.
  • For marketing emails beyond transactional needs — only with your opt-in consent, withdrawable any time.

4. Subprocessors and data transfers

We share the minimum necessary data with the following subprocessors in order to operate the services. Each is contractually bound to use the data only for the stated purpose and to maintain industry-standard security:

  • Stripe Payments Europe / Stripe Inc. — payment processing, subscription lifecycle.
  • Google LLC — authentication (OAuth), identity verification, and website analytics (Google Analytics 4).
  • Cloudflare, Inc. — DNS, CDN, DDoS protection.
  • Resend (by Resend, Inc.) — transactional email delivery.
  • Our hosting provider — server infrastructure for our websites and APIs.

Data may be transferred to and processed in the United States or other countries where our subprocessors operate. Transfers from the EU or UK rely on Standard Contractual Clauses or equivalent safeguards.

5. How long we keep it

We retain personal data only as long as necessary for the purpose it was collected. Typical retention windows:

  • Active account data — for the life of the account, plus up to 12 months after deletion for backup rotation.
  • Billing records, invoices, and tax data — retained for at least 7 years as required by tax and accounting law.
  • Security and audit logs — retained up to 24 months for fraud prevention and legal defense.
  • Aggregated / de-identified analytics — may be retained indefinitely.

Deletion requests do not override these retention obligations where we have a legal basis to keep the data.

6. What we do NOT do

  • We do not sell your personal information.
  • We do not share personal information with advertisers.
  • We do not access the contents of your device screens, macros, or workflow data.
  • We do not access your credentials for third-party platforms (Meta, TikTok, etc.).

7. Your rights

Depending on your jurisdiction (EEA, UK, California, others) you may have the right to: access, correct, delete, object to processing, restrict processing, or port your data. To exercise any right, email [email protected] with sufficient information for us to verify your identity. We will respond within 30 days (or the period required by applicable law).

You may also lodge a complaint with your local data-protection authority; we appreciate the chance to resolve concerns directly first.

8. Security

We use industry-standard safeguards — TLS for data in transit, encryption for data at rest, access controls, secure development practices, and regular updates. No system is perfectly secure; we cannot guarantee the absolute security of transmitted or stored data and are not liable for breaches that occur despite commercially reasonable measures.

9. Cookies and tracking

Our websites use essential cookies for authentication, cart state, and security (such as the Stripe checkout and Google OAuth flows). We also use Google Analytics 4 to understand how the site is used; it sets analytics cookies and collects usage data such as pages viewed and approximate location. We do not use third-party advertising cookies.

10. Children

Our services are not directed to anyone under 18. We do not knowingly collect data from children. If you believe we have, email [email protected] and we will delete it.

11. Changes

We may update this policy. Material changes will be announced by email or a notice on this page. Continued use of the services after the effective date indicates acceptance.

Contact

[email protected]