Short version: We collect your domain, email, and basic usage data to power the Service. We don't sell your personal information. You can request deletion at any time.
Ollo Technologies Inc ("we," "us," or "our") operates ollo.build (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use the Service.
1. Information We Collect
Information you provide directly:
- Domain name — The business domain you submit for analysis
- Email address — When you sign up, join the waitlist, or contact us
- Business information — Company name, industry, and other details you voluntarily provide
- Payment information — Processed securely through Stripe; we do not store full card numbers
Information collected automatically:
- Usage data — Pages visited, features used, scan history, and interaction events
- Device and browser data — Browser type, operating system, screen resolution, referring URL
- IP address — Stored in hashed/anonymized form for analytics and abuse prevention
- Cookies and similar technologies — See Section 5 below
Domain scan data:
- When you submit a domain, we fetch publicly accessible content from that domain (meta tags, headings, social links, technology stack indicators) to generate your AI agent recommendations
- We do not access password-protected areas or any non-public content
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Service
- Generate AI agent recommendations tailored to your business
- Send transactional emails (scan results, account notifications)
- Send product updates and promotional communications (with your consent, unsubscribable at any time)
- Prevent fraud and abuse
- Comply with legal obligations
- Analyze aggregate usage patterns to improve our algorithms and product
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area, United Kingdom, or Switzerland, we process your personal data on the following legal bases:
- Contract performance — Processing necessary to provide the Service you requested
- Legitimate interests — Analytics, fraud prevention, and product improvement
- Consent — Marketing communications and non-essential cookies (you may withdraw consent at any time)
- Legal obligation — Compliance with applicable laws
4. Information Sharing and Disclosure
We do not sell your personal information. We may share your information with:
- Service providers — Third-party vendors who assist us in operating the Service (hosting, analytics, email delivery, payment processing) under confidentiality obligations
- Business transfers — In connection with a merger, acquisition, or sale of assets, with notice to you
- Legal requirements — If required by law, court order, or to protect the rights and safety of our users or others
- With your consent — For any other purpose with your explicit consent
5. Cookies and Tracking Technologies
We use the following cookies and tracking technologies:
Essential cookies: Required for the Service to function. Cannot be disabled.
Analytics — Google Analytics (GA4):
- We use Google Analytics 4 (property ID: G-GNJX0NQ8R9) to understand how visitors interact with the Service
- Data collected includes page views, session duration, and interaction events
- IP addresses are anonymized before being sent to Google
- You can opt out via the Google Analytics Opt-out Browser Add-on
- Google's privacy policy: policies.google.com/privacy
Advertising — Meta Pixel:
- We use the Meta Pixel to measure ad campaign effectiveness and retarget website visitors on Meta platforms (Facebook, Instagram)
- The Pixel fires on page load (PageView), waitlist signups (Lead), and deposit payments (Purchase)
- You can opt out via Facebook Ad Preferences or the Digital Advertising Alliance opt-out
- Meta's data policy: facebook.com/privacy/policy
Session/functional cookies: Used to remember your preferences and scan history within a session. These expire when you close your browser.
6. Third-Party Services
The Service uses the following third-party services that may process your data:
- Render (hosting infrastructure) — render.com/privacy
- Neon / PostgreSQL (database) — neon.tech/privacy
- Stripe (payment processing) — stripe.com/privacy
- OpenAI / Anthropic (AI analysis) — Your domain content may be sent to AI providers for processing. We use these under business agreements that restrict data use
- Google Analytics — See Section 5
- Meta Pixel — See Section 5
7. Data Retention
We retain your information for as long as necessary to provide the Service and comply with our legal obligations:
- Account data — Retained while your account is active, plus 90 days after deletion request
- Scan results — Retained for 12 months to enable you to revisit past recommendations
- Usage analytics — Aggregated data retained indefinitely; individual event data retained for 24 months
- Payment records — Retained for 7 years as required by tax and accounting law
8. Data Security
We implement industry-standard security measures including:
- TLS/HTTPS encryption for all data in transit
- AES-256-GCM encryption for sensitive stored data
- Hashed storage of IP addresses (no raw IPs stored)
- Regular security reviews and limited access controls
No method of transmission over the Internet is 100% secure. We cannot guarantee absolute security but are committed to protecting your information using commercially reasonable means.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access — Request a copy of the personal data we hold about you
- Correction — Request correction of inaccurate or incomplete data
- Deletion — Request deletion of your personal data ("right to be forgotten")
- Portability — Request your data in a portable, machine-readable format
- Objection — Object to processing based on legitimate interests
- Restriction — Request restriction of processing in certain circumstances
- Withdraw consent — Withdraw previously given consent for marketing or non-essential cookies
To exercise any of these rights, email us at privacy@ollo.build. We will respond within 30 days.
10. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
11. International Data Transfers
We are based in the United States. If you access the Service from outside the US, your information may be transferred to and processed in the US or other countries where our service providers operate. We ensure appropriate safeguards are in place for such transfers (including Standard Contractual Clauses where required).
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to know what personal information we collect, use, disclose, or sell
- Right to delete personal information
- Right to opt out of sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising your rights
To submit a CCPA request, email privacy@ollo.build with "CCPA Request" in the subject line.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the revised policy on this page and updating the "Last updated" date. For material changes, we will provide additional notice (such as email notification).
Your continued use of the Service after changes constitutes acceptance of the revised policy.
14. Contact Us
For any privacy-related questions, requests, or concerns, please contact us:
- Email: privacy@ollo.build
- Website: ollo.build
We aim to respond to all privacy inquiries within 30 days.