Effective date: September 17, 2026
1. Who this covers
This policy explains how Oakridge Media LLC, a Texas limited liability company ("Oakridge", "we") handles personal information in ORM OS (app.oakridge.media and its APIs). It covers three groups:
- Users — people a publisher (our "Customer") invites into its workspace: owners, managers, sales, designers, editors, writers, drivers.
- Customer contacts — advertisers, prospects, signers and other people whose details a Customer stores in its workspace or who receive a Customer's emails, upload links or agreements.
- Visitors — anyone using the public demo, the login page, or a public page such as a signing or upload link.
For Customer contacts, the Customer decides what is collected and why; Oakridge processes that data on the Customer's instructions. Questions about a Customer's use of your information should go to that Customer; we will help them respond.
2. What we collect
Users. Name, email, optional phone, title, bio and photo; role and workspace; sign-in events and network address; what you do in the app (records created, emails sent, pages viewed); API tokens you create (stored as a hash). If you connect Google, we store an encrypted refresh token and use it only for the Drive, Docs and Gmail features you turn on. If a Customer's Owner connects QuickBooks, we store encrypted tokens for that company.
Customer contacts. Whatever the Customer enters: name, company, email, phone, addresses, notes, agreements and their signatures, invoices and payment status, communications the Customer logs or imports from Gmail (sender, recipients, subject, date and a short snippet — not the message body), files uploaded through a Customer's upload link, and opt-out status for marketing emails.
Signers. When you sign an agreement electronically we record your name as typed, your choices, the time, the network address and browser reported by your connection, and the drawn signature image, and we keep a PDF of the signed document for the Customer.
Visitors. Server logs (network address, pages requested, browser); session-replay analytics through Microsoft Clarity (when enabled), which masks typed text by default; and, if you use the sample workspace, whatever you enter there — the sample workspace is shared and reset, and nothing entered there is private.
We do not collect payment card or bank account numbers. Advertisers set up payment methods through the Customer's QuickBooks invoice link, on Intuit's systems.
3. How we use it
- To run the Service: sign you in, show the right workspace and role, send the emails you or your Customer compose, create invoices in QuickBooks, build signing and upload pages, schedule follow-ups.
- To secure it: rate limiting, abuse detection, audit trails (including signer network addresses), token and session management.
- To support and improve it: diagnosing problems, understanding which features are used (Clarity, server logs), and measuring AI usage per workspace to enforce limits.
- AI features. When a User uses the assistant, copy check, business-card reader or drafting features, the relevant text or image (which may include Customer contacts' details and article text) is sent to Anthropic's API to generate a response, with a per-workspace identifier and no other account information. Under Anthropic's commercial API terms this data is not used to train models. AI never sends mail, moves money or changes records without a person confirming.
- To communicate with Customers about the Service (billing, changes, security notices).
We do not sell personal information and do not use it for advertising to you.
4. Who we share it with
Service providers that help us run ORM OS (each under a contract that limits them to our instructions): Supabase (database, authentication, file storage — hosted in the United States, AWS us-east-2), DreamHost (application hosting), SendGrid/Twilio (email delivery), Anthropic (AI features), Microsoft Clarity (analytics), Google (Maps geocoding for distribution addresses).
Services you connect (they receive data because you or your Customer chose to connect them, under their own policies): Intuit QuickBooks Online, Google Workspace, WordPress sites the Customer configures, Metricool.
Recipients of your communications. Emails, agreements and upload links go to the people the Customer addresses them to.
Legal. We may disclose information to comply with law, enforce our terms, or protect rights and safety, and in a merger or sale of the business (with notice).
5. Where it lives and how long
Data is stored with our providers in the United States (the database in AWS us-east-2). We keep Customer Data for as long as the Customer's subscription lasts and for 30 days after, then delete it from live systems; backups age out within 30 days after that. Signed agreements are kept as long as the Customer keeps them. Server and security logs are kept for 90 days. Sample-workspace data is reset nightly.
6. Security
Every workspace is isolated by row-level security in the database; connections are encrypted (TLS); third-party credentials are encrypted at rest; public links (signing, upload, unsubscribe) are unguessable, expire, and are never shown to other Customers' staff; uploads are served as downloads and scanned for type. No system is perfectly secure; if we learn of a breach affecting your information we will notify affected Customers without undue delay and, where required, regulators and individuals.
7. Your choices and rights
- Users can edit their profile, remove their photo, disconnect Google, and revoke API tokens at any time. To delete your account, ask your workspace Owner or email us.
- Customer contacts can unsubscribe from a Customer's follow-up emails with the link in each message; that stops all sequences from that Customer immediately. For access, correction or deletion of what a Customer holds about you, contact the Customer; we will support them.
- Cookies. We use only the cookies needed to keep you signed in and to remember in-app preferences, plus Clarity's analytics cookie where enabled. There are no advertising cookies.
- State privacy rights. Depending on where you live (for example Texas, California, Colorado, Virginia and others), you may have rights to access, correct, delete or port personal information, to opt out of certain processing, and not to be discriminated against for exercising them. Email legal@oakridge.media; we will verify your identity and respond within the time the law requires. Where Oakridge acts as a processor for a Customer, we will forward your request to that Customer.
- Global Privacy Control. We treat a GPC signal from your browser as an opt-out of analytics.
8. Children
ORM OS is a business tool and is not directed to children under 16. We do not knowingly collect their information.
9. Changes
We will post changes here and, for material changes, notify workspace Owners at least 30 days before they take effect.
10. Contact
Oakridge Media LLC, 7 Upper Balcones Rd, Boerne, TX 78006 · legal@oakridge.media