Privacy Policy

How Oeave handles your data

This policy explains what we collect, why we collect it, how we use it, and the choices you have. It applies to the Oeave web application, the renderer script, and all related services operated by Bjørn Fjellstad Indahl (enkeltpersonforetak registered in Norway).

Effective date: February 16, 2026

Cookies & tracking

Your preferences

We use cookies and similar technologies to keep the product secure, remember session state, and — with your consent — measure engagement. Google Analytics and Meta Pixel are loaded only after you opt in.

  • Essential: required for authentication, navigation, security, and bot protection (Cloudflare Turnstile).
  • Analytics & performance: Google Analytics and Meta Pixel to see how features perform and where to improve. Loaded only with your consent.
  • Your choice: accepting stores consent in localStorage so it persists across visits. Denying stores your choice in sessionStorage so it resets when you close the browser.

1. Information we collect

1a. Account data

  • Email address and hashed password (via Convex Auth).
  • Account creation date and trial start date.

1b. Billing data

Payments are processed by Paddle, which acts as our Merchant of Record. Paddle collects your payment method, card details, and billing address directly. We receive and store only: Paddle customer ID, subscription ID, plan name, subscription status, and next billing date. We never store full card numbers.

1c. Content you upload

  • Fibers: images, 3D models, text blocks, documents, and other content pieces you add.
  • Project metadata: product name, price, description, and images.
  • Threads: layout arrangements of Fibers.

1d. Automatically collected data

  • IP address, browser type, device information, pages visited.
  • Cloudflare Turnstile token used for bot protection during login and signup.
  • Google Analytics and Meta Pixel data (only if you have given consent).

1e. Renderer analytics (merchant shoppers)

When a merchant embeds the Oeave renderer on their site and a shopper has given consent, the renderer may collect session-level signals: session ID, Thread views, dwell time, interaction signals, and funnel depth. This data is sent to the merchant’s configured analytics endpoint only if consent has been given. If no endpoint is configured, signals stay local to the browser and are used only to guide the experience.

2. How we use your information

  • Provide, maintain, and improve the Oeave service.
  • Process payments and manage subscriptions via Paddle.
  • Send transactional emails (verification, password reset).
  • Prevent fraud and abuse (Cloudflare Turnstile).
  • Generate analytics reports for merchants on higher-tier plans.
  • Understand how the product is used so we can improve it (analytics, only with consent).

We do not sell your data to third parties.

3. Legal bases for processing (GDPR)

  • Contract: account creation, billing, and service delivery.
  • Legitimate interest: security, fraud prevention, and product improvement.
  • Consent: analytics cookies, marketing pixels, and renderer shopper analytics.

4. Data sharing & sub-processors

We share data only with the following trusted service providers, solely to operate the Oeave service:

ProviderPurposeData shared
ConvexDatabase & backendAccount, content, subscription data
PaddlePayment processing (MoR)Email, billing address, payment method
CloudflareCDN, Turnstile bot protectionIP address, Turnstile token
Google AnalyticsWebsite analyticsUsage data (with consent)
Meta (Pixel)Marketing attributionBrowsing events (with consent)

5. Marketing & retargeting

With your consent, we use cookies and tracking pixels (such as Meta Pixel) to deliver relevant advertisements on other platforms. You can opt out at any time using the cookie settings above. Denying consent prevents retargeting pixels from loading.

6. Data retention

  • Account data: retained while your account is active. Deleted within 30 days of an account deletion request.
  • Uploaded content: deleted when you delete a project or your account. A 30-day export window is provided after account cancellation.
  • Billing records: retained as required by Norwegian tax and accounting law (Bokføringsloven, typically 5 years).
  • Analytics data: aggregated data retained indefinitely; identifiable data purged after 26 months.

7. Your rights

Under the GDPR (and the Norwegian Personal Data Act), you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Eraseyour data (“right to be forgotten”).
  • Port your data to another service.
  • Restrict or object to processing.
  • Withdraw consent for analytics and marketing at any time.

To exercise any of these rights, email us at privacy@oeave.com. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).

8. International data transfers

Some of our sub-processors (e.g. Convex, Cloudflare) may process data outside the European Economic Area. Where this occurs, we rely on Standard Contractual Clauses or equivalent safeguards approved by the European Commission.

9. Children’s privacy

Oeave is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a minor has provided us with data, please contact us and we will delete it promptly.

10. Changes to this policy

We may update this policy as the service evolves. The effective date at the top of this page shows when changes were last made. We encourage you to review this page periodically.

11. Contact

For any privacy-related questions, contact us at privacy@oeave.com.

Read our Terms of Service.

For data questions, reach us at privacy@oeave.com.