Privacy Policy

Last updated: August 17, 2026

Introduction

Oasbit ("we," "our," or "us") operates oasbit.com and related booking, checkout, and report pages. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit our website, submit forms, book a call, request a visibility report, subscribe to email, or purchase services.

This policy covers our marketing site and the services we sell through it (including End to End, web, apps, ads, SEO, GEO, consultation, social, white-label, and related applications we market). Separate products we operate or link to (for example myOasbit CRM, Portal, Trading Agents at trade.oasbit.com, or Render Reno at renderreno.ai) may have additional notices. Where those products collect data on their own domains, their policies also apply.

We handle personal information in line with applicable law, including Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Law 25 where it applies, the EU/UK GDPR, and US state laws such as the California Consumer Privacy Act as amended by the CPRA.

1. Who we are

Controller: Oasbit, 2967 Dundas St W #931, Toronto, ON M6P 1Z2, Canada. Privacy requests: privacy@oasbit.com. General: info@oasbit.com. Phone: +1-888-884-9891.

Privacy Officer (PIPEDA / Law 25): privacy@oasbit.com. You may also write to dpo@oasbit.com.

2. Information we collect

2.1 Information you give us

We collect what you submit on our site and in booking widgets. That typically includes:

  • Identity and contact: name, email, phone, business name, country, website URL, Google Business Profile URL.
  • Newsletter and exit-intent: email, and optionally first and last name.
  • Get Started / Growth Strategy Session: priorities, country (including a detected country from your connection when shown), whether you have a website, how soon you want to start, business type, marketing channels, budget, business description, current and target revenue, and biggest obstacle.
  • Cart and checkout: name, email, phone, business name, selected service and package. Card details are entered with Stripe; we do not store full card numbers on our servers.
  • White-label partner applications: contact details, target audience, website, volume tier, and requested services.
  • Free SEO/GEO visibility reports: name, phone, email, business name, website and/or Google Business Profile URL.
  • Booking calendars: name, email, phone, and appointment details entered in the HighLevel / LeadConnector calendar iframe.
  • Support and other messages: emails, calls, and form notes you send us.

2.2 Information collected automatically

  • Device and log data: IP address, user agent, approximate location (city/region/country from IP), browser, device type, referring URL, and pages viewed.
  • Session identifier: a session ID stored in your browser session storage for analytics event correlation.
  • Advertising and analytics events: page views, clicks, form and checkout events, and conversion events sent to Google Analytics 4, Meta (Facebook/Instagram) Pixel, OpenAI / ChatGPT Ads pixel, and Vercel Analytics.
  • Tracking parameters: we preserve query parameters such as utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, fbclid, msclkid, ttclid, li_fat_id, affiliate_id, partner_id, promo/discount/referral codes, and similar tags, and store them with your lead record when you submit a form.
  • Form and bot-protection signals: Google reCAPTCHA tokens, honeypot fields, and related bot-detection flags. reCAPTCHA may collect device and interaction data as described in Google's policies.
  • Local storage: we may store contact-form progress, tracking parameters, and similar preferences in local or session storage on your device.

2.3 Information from third parties

  • Stripe: payment status, customer identifier, billing email, and whether a checkout completed.
  • HighLevel / LeadConnector: booking confirmations and CRM contact records created from calendars and webhooks.
  • Google: Analytics, reCAPTCHA, and public Google Business / review data we display or use when you ask for a listings audit.
  • Meta and OpenAI Ads: conversion match feedback and campaign measurement (we send hashed identifiers; they may match them to their user graphs).
  • Visibility-report generation: an automated audit of the website and/or Google Business Profile you submit. The audit output (scores, findings, charts) is stored and shown on a report page.

2.4 Visibility reports

If you request a free SEO or GEO visibility report, we process your contact details and the URLs you provide in order to generate the report. We send the request to our report-generation partner (currently Cursor Automations) and store the finished report in our database, linked to your contact record. We also notify our CRM (LeadConnector) when a report is requested and when it is ready, and we may email or SMS you a link when it is complete.

Report pages live at a unique URL on oasbit.com. They are marked noindex (not listed in sitemaps or search results), but anyone with the link can view that report. Do not share the link if you want it kept private. You should only submit websites and profiles you are authorized to have audited.

3. How we use information

  • Respond to inquiries, run strategy sessions, and deliver the services you request or buy.
  • Create and update CRM records, assign account teams, and schedule calls.
  • Process payments, send receipts, and handle refunds through Stripe.
  • Generate SEO/GEO visibility reports and notify you when they are ready.
  • Send service messages (booking confirmations, report-ready notices, project updates).
  • Send marketing email or SMS where permitted (CASL / CAN-SPAM / similar), including newsletters and offers. You can unsubscribe using the link in the message or by emailing privacy@oasbit.com.
  • Measure site performance and advertising (including Google Ads, Meta Ads, and ChatGPT / OpenAI Ads) and improve conversion of our forms and checkout.
  • Prevent spam, fraud, and abuse (reCAPTCHA, honeypots, IP and device signals).
  • Comply with law, enforce our Terms, and protect our rights and users.

4. Legal bases (GDPR / UK GDPR)

Where those laws apply, we rely on:

  • Contract: delivering requested quotes, bookings, reports, builds, and paid services.
  • Legitimate interests: securing the site, measuring performance, B2B sales follow-up, and improving our services. You may object as described in Section 10.
  • Consent: newsletters, optional marketing, and non-essential advertising cookies/pixels where consent is required. You may withdraw consent at any time.
  • Legal obligation: tax, accounting, and responding to lawful requests.

5. Cookies, pixels, and similar technologies

We use cookies, pixels, local/session storage, and similar technologies. Advertising and analytics scripts currently load as part of the site (there is no separate cookie banner). You can block or delete cookies in your browser; blocking some cookies may break checkout, booking, or form protection.

5.1 What we use

  • Essential: session and security cookies needed to run the site, cart, and forms; Stripe cookies on checkout; HighLevel calendar cookies inside booking iframes; reCAPTCHA.
  • Analytics: Google Analytics 4 (measurement ID G-0XSZJBMHLT), including Google signals and ad-personalization signals; Vercel Analytics.
  • Advertising: Meta Pixel (ID 506453365007346) plus Meta Conversions API; OpenAI / ChatGPT Ads pixel plus OpenAI Conversions API. These technologies support cross-context advertising measurement and may be treated as a "sale" or "share" of personal information under California law.
  • Fonts and media: Google Fonts and similar CDNs may receive your IP address when pages load.

5.2 Server-side conversion matching

When you submit a form or complete checkout, we may send hashed identifiers (for example SHA-256 of email or phone), IP address, and user agent to Meta and OpenAI so they can measure ads. Hashed values are used for matching, not to publish your contact details in ads.

5.3 How to opt out of advertising cookies

  • Browser settings: block third-party cookies or use a tracking blocker.
  • Google: Ads Settings and GA opt-out.
  • Meta: Ad preferences.
  • Industry tools such as the Digital Advertising Alliance opt-out pages where available.
  • California / similar US state rights: email privacy@oasbit.com with the subject "Do Not Sell or Share My Personal Information." See Section 11.

6. Who we share information with

We do not sell personal information for money. We do share personal information with service providers that process it for us, and with advertising platforms as described above. Categories of recipients:

  • Hosting and storage: Vercel (website), our PostgreSQL database provider, and Vercel Blob for uploaded media such as blog images.
  • CRM, email, and SMS: HighLevel / LeadConnector (including calendar widgets on leadconnectorhq.com). They may email or text you about bookings and follow-up.
  • Payments: Stripe. See Stripe's privacy policy.
  • Analytics and ads: Google, Meta Platforms, OpenAI (ChatGPT Ads), and Vercel Analytics.
  • Security: Google reCAPTCHA.
  • Report generation: Cursor Automations (and related AI tooling) to produce visibility reports from the URLs you submit.
  • Professional advisors: accountants, lawyers, and insurers as needed.
  • White-label / partners: only when you apply as a partner or we have a contract that requires it, and only as needed to perform that relationship.
  • Legal: if required by law, to protect rights or safety, or in a merger, acquisition, or asset sale (we will require the successor to honor this policy or give you notice).

We do not sell your contact list to unrelated third parties for their independent marketing.

7. International transfers

We are based in Canada. Many processors (Vercel, Stripe, Google, Meta, OpenAI, HighLevel) store or process data in the United States and other countries. Those countries may not offer the same legal protections as your home country. Where GDPR requires it, we rely on appropriate safeguards such as the EU Standard Contractual Clauses used by those providers, plus their security and transfer documentation.

8. Retention

  • Leads and CRM records: while we have an active sales or client relationship, then as needed for follow-up and legal claims (typically up to 3 years after last meaningful contact, unless you ask us to delete and no legal hold applies).
  • Client project and contract files: for the engagement plus at least 7 years where tax or professional record-keeping requires it.
  • Payment records: at least 7 years for tax and accounting.
  • Visibility reports: stored with the related contact until deleted on request or as part of routine CRM hygiene.
  • Analytics: according to each platform's settings (Google Analytics is commonly retained for up to 26 months unless we configure otherwise).
  • Marketing lists: until you unsubscribe or we suppress the address after prolonged inactivity.

9. Security

We use HTTPS/TLS in transit, access controls on admin systems, hashed passwords for staff accounts, and provider-side encryption for databases and blobs. No method of transmission or storage is completely secure. If a breach is likely to result in a real risk of harm, we will notify affected individuals and regulators as required (including, where GDPR applies, without undue delay and generally within 72 hours of becoming aware of a notifiable incident).

10. Your rights (Canada, EU/UK, and generally)

Subject to exceptions in applicable law, you may request access, correction, deletion, a portable copy, restriction or objection to certain processing, and withdrawal of consent. Canadian residents may complain to the Office of the Privacy Commissioner of Canada (and, in Quebec, the CAI). EU/UK residents may complain to their local supervisory authority (ICO in the UK).

Email privacy@oasbit.com. We will verify the request and respond within the time required by law (generally 30 days in Canada and under GDPR; some US state laws allow up to 45 days).

11. US state privacy notices (including California)

In the last 12 months we have collected the following categories of personal information from website visitors and leads: identifiers (name, email, phone, IP, cookie/pixel IDs); commercial information (services viewed or purchased, package interest); internet/network activity (pages, clicks, session IDs, tracking parameters); coarse geolocation (from IP); professional/business information (company, role, website, marketing budget and similar form fields); and inferences used for sales and ads measurement. We do not collect Social Security numbers, driver's licenses, precise geolocation, or biometric identifiers through this website.

We disclose those categories to the service providers and advertising platforms listed in Sections 5 and 6. Under the CPRA, sending identifiers and device data to advertising networks (Meta, Google, OpenAI Ads) can be a "share" for cross-context behavioral advertising. We do not sell personal information for money and we do not sell or share personal information of consumers we actually know are under 16.

California (and similar state) rights include: know/access, delete, correct, opt out of sale/share, limit use of sensitive personal information (we do not use sensitive PI to infer characteristics beyond what is needed for the form you submitted), and non-discrimination. To opt out of sale/share, email privacy@oasbit.com with "Do Not Sell or Share My Personal Information." We will honor Global Privacy Control (GPC) signals as an opt-out of sale/share for that browser where required by law.

We do not use or disclose sensitive personal information for purposes that require a separate "Limit the Use" link beyond the form, payment, and security uses described here.

12. Children

Our site and services are for businesses and adults. They are not directed to children under 16 (or under 13 where COPPA applies). We do not knowingly collect personal information from children. If you believe a child provided information, contact privacy@oasbit.com and we will delete it.

13. Automated decision-making and profiling

We use analytics and advertising platforms to measure and retarget interest in our services. We do not make solely automated legal or similarly significant decisions about you (for example, we do not automatically refuse service without human review of paid engagements). Visibility reports are generated with automated tools; they are informational audits, not credit, employment, or insurance decisions.

14. Client work and third-party platforms

When you hire us, we may process additional business data (brand assets, analytics logins, ad accounts, CRM records, store catalogs) under our contract with you. You are responsible for having a lawful basis to give us access to those systems. We use that data only to perform the engagement, and we follow the access and deletion terms in the contract and this policy.

15. reCAPTCHA

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

16. Changes

We may update this policy. The "Last updated" date at the top will change. Material changes that affect how we use personal information already collected will be announced on this page and, where appropriate, by email. Continued use of the site after an update means you accept the revised policy except where consent is required by law.

Related documents: Terms and Conditions and Lifetime Development Warranty.

17. Contact

Privacy: privacy@oasbit.com
Privacy Officer / DPO mailbox: dpo@oasbit.com
Legal: legal@oasbit.com
Phone: +1-888-884-9891
Mail: Oasbit, 2967 Dundas St W #931, Toronto, ON M6P 1Z2, Canada

If we cannot resolve your concern, you may contact the Privacy Commissioner of Canada, the Commission d'accès à l'information du Québec (if you are in Quebec), the ICO (UK), your EU supervisory authority, or the California Attorney General / CPPA, as applicable.