Privacy Policy

Last updated: 8 July 2025

1. Information We Collect

CategoryExamplesPurpose
Account DataName, email address, Google OAuth IDCreate & secure your account, deliver Service
Payment DataLimited billing details (tokenized card, ZIP) handled by StripeProcess subscriptions & invoices
Usage LogsIP address, request headers, endpoint called, query string (address looked-up), timestamps, quota usageProvide core functionality, rate-limit abuse, analytics
Cookies / Local StorageAuth session cookie, CSRF token, preference flagsKeep you signed in, remember settings

We do not intentionally collect sensitive personal data (race, health, etc.).

2. How We Use Your Information

  1. Provide & improve the Service (run look-ups, maintain infrastructure, debug).
  2. Communicate with you (service announcements, invoices, support).
  3. Billing & fraud prevention via Stripe and anti-abuse tooling.
  4. Product analytics (aggregate metrics to understand feature adoption).
  5. Legal compliance (respond to lawful requests, enforce Terms).

We do not sell or rent your personal information.

3. Legal Bases (GDPR)

BasisWhen applied
ContractTo deliver the Service you request (e.g., API look-ups).
Legitimate InterestsSecurity, service analytics, preventing fraud.
ConsentMarketing emails (opt-in, unsubscribe anytime).
Legal ObligationAccounting & tax record-keeping.

4. How We Share Information

RecipientReason
Infrastructure Providers (Vercel, AWS, Supabase/Postgres)Host servers & databases
Payment Processor (Stripe)Manage subscriptions, refunds
Analytics (Plausible, self-hosted)Privacy-friendly usage metrics
Law enforcement or regulatorsOnly when legally required

All vendors are bound by agreements that protect your data.

5. Data Retention

  • Account data — while your account is active + 12 months.
  • Payment records — 7 years (tax laws).
  • Server logs — 30 days, unless we investigate abuse.
  • Lookup queries — anonymised and aggregated after 90 days.

You may delete your account anytime via the Dashboard or by emailing privacy@oz-mcp.com; we’ll erase identifying data within 30 days except where legal obligations require otherwise.

6. Security

We use HTTPS, encrypted databases, least-privilege IAM roles, and audit logging. No method is 100 % secure, but we work hard to protect your data.

7. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or port your personal data. Send requests to privacy@oz-mcp.com. We’ll respond within 30 days.

8. International Transfers

We host the Service in the United States. If you access from outside the U.S., you consent to transferring your data to U.S. servers.

9. Children

OZ-MCP is not directed to children under 16. We do not knowingly collect data from them.

10. Changes

We may update this policy. We’ll post the revision date and, for material changes, email account holders at least 7 days before it takes effect.

11. Contact Us

Agiato LLC

548 Market St, PMB 12345

San Francisco, CA 94104

privacy@oz-mcp.com