Privacy Policy
How Oeave handles your data
This policy explains what we collect, why we collect it, how we use it, and the choices you have. It applies to the Oeave web application, the renderer script, and all related services operated by Bjørn Fjellstad Indahl (enkeltpersonforetak registered in Norway).
Effective date: February 16, 2026
1. Information we collect
1a. Account data
- Email address and hashed password (via Convex Auth).
- Account creation date and trial start date.
1b. Billing data
Payments are processed by Paddle, which acts as our Merchant of Record. Paddle collects your payment method, card details, and billing address directly. We receive and store only: Paddle customer ID, subscription ID, plan name, subscription status, and next billing date. We never store full card numbers.
1c. Content you upload
- Fibers: images, 3D models, text blocks, documents, and other content pieces you add.
- Project metadata: product name, price, description, and images.
- Threads: layout arrangements of Fibers.
1d. Automatically collected data
- IP address, browser type, device information, pages visited.
- Cloudflare Turnstile token used for bot protection during login and signup.
- Google Analytics and Meta Pixel data (only if you have given consent).
1e. Renderer analytics (merchant shoppers)
When a merchant embeds the Oeave renderer on their site and a shopper has given consent, the renderer may collect session-level signals: session ID, Thread views, dwell time, interaction signals, and funnel depth. This data is sent to the merchant’s configured analytics endpoint only if consent has been given. If no endpoint is configured, signals stay local to the browser and are used only to guide the experience.
2. How we use your information
- Provide, maintain, and improve the Oeave service.
- Process payments and manage subscriptions via Paddle.
- Send transactional emails (verification, password reset).
- Prevent fraud and abuse (Cloudflare Turnstile).
- Generate analytics reports for merchants on higher-tier plans.
- Understand how the product is used so we can improve it (analytics, only with consent).
We do not sell your data to third parties.
3. Legal bases for processing (GDPR)
- Contract: account creation, billing, and service delivery.
- Legitimate interest: security, fraud prevention, and product improvement.
- Consent: analytics cookies, marketing pixels, and renderer shopper analytics.
4. Data sharing & sub-processors
We share data only with the following trusted service providers, solely to operate the Oeave service:
| Provider | Purpose | Data shared |
|---|---|---|
| Convex | Database & backend | Account, content, subscription data |
| Paddle | Payment processing (MoR) | Email, billing address, payment method |
| Cloudflare | CDN, Turnstile bot protection | IP address, Turnstile token |
| Google Analytics | Website analytics | Usage data (with consent) |
| Meta (Pixel) | Marketing attribution | Browsing events (with consent) |
5. Marketing & retargeting
With your consent, we use cookies and tracking pixels (such as Meta Pixel) to deliver relevant advertisements on other platforms. You can opt out at any time using the cookie settings above. Denying consent prevents retargeting pixels from loading.
6. Data retention
- Account data: retained while your account is active. Deleted within 30 days of an account deletion request.
- Uploaded content: deleted when you delete a project or your account. A 30-day export window is provided after account cancellation.
- Billing records: retained as required by Norwegian tax and accounting law (Bokføringsloven, typically 5 years).
- Analytics data: aggregated data retained indefinitely; identifiable data purged after 26 months.
7. Your rights
Under the GDPR (and the Norwegian Personal Data Act), you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Eraseyour data (“right to be forgotten”).
- Port your data to another service.
- Restrict or object to processing.
- Withdraw consent for analytics and marketing at any time.
To exercise any of these rights, email us at privacy@oeave.com. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).
8. International data transfers
Some of our sub-processors (e.g. Convex, Cloudflare) may process data outside the European Economic Area. Where this occurs, we rely on Standard Contractual Clauses or equivalent safeguards approved by the European Commission.
9. Children’s privacy
Oeave is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a minor has provided us with data, please contact us and we will delete it promptly.
10. Changes to this policy
We may update this policy as the service evolves. The effective date at the top of this page shows when changes were last made. We encourage you to review this page periodically.
11. Contact
For any privacy-related questions, contact us at privacy@oeave.com.
Read our Terms of Service.
For data questions, reach us at privacy@oeave.com.