Privacy Policy
OBLYSS PRIVACY POLICY
Last Updated: August 2026
1. About this Privacy Policy
Oblyss Incorporated, a Delaware corporation, doing business as “Oblyss” and “OblyssPro” (“Oblyss,” “we,” “us,” or “our”), provides business operations software and related services for foundation repair, waterproofing, structural repair, and other specialty contractors.
This Privacy Policy explains how we collect, use, disclose, and protect personal information when you interact with websites that link to this Policy, including https://www.oblysspro.com; use the OblyssPro platform at https://app.oblysspro.com or another Oblyss application, portal, or product that links to this Policy; communicate with our sales, onboarding, or support teams; attend an event; participate in a survey or program; or otherwise interact with us. We refer to these websites, products, services, and interactions collectively as the “Services.”
This Policy is a privacy notice, not a contract requiring you to consent to every practice described. Where consent is required by law, we will request it separately. If a different privacy notice is presented for a particular product, program, or interaction, that notice applies to the information covered by it.
2. When Oblyss is a controller and when it is a processor
Oblyss acts in different roles depending on the information and the context:
- Oblyss as controller. We determine the purposes and means of processing information about our website visitors, business prospects, event participants, account administrators, support contacts, and other people who interact directly with Oblyss, except where another party controls the processing.
- Oblyss as processor or service provider. Our business customers determine why and how Oblyss processes personal information they or their authorized users submit to the platform, connect through an integration, or collect through customer-configured workflows (“Customer Data”). Oblyss processes Customer Data on the customer's instructions and under the applicable customer agreement and Data Processing Addendum.
A business or organization that subscribes to the Services is a “Customer.” A person whom a Customer authorizes to use the Services is an “Authorized User.” A person whose information appears in Customer Data - such as a Customer's prospect, client, property contact, employee, independent contractor, crew member, subcontractor, engineer, vendor, or other job contact - is a “Customer Contact.”
If you are a Customer Contact and want to exercise a privacy right concerning Customer Data, please contact the relevant Customer first. The Customer controls that data and is usually best positioned to respond. We will assist our Customers as required by law and our agreements. If there is a conflict between this Policy and a customer agreement concerning Customer Data, the customer agreement controls to the extent permitted by law.
3. Personal information we collect
The personal information we collect depends on how you interact with the Services, which features a Customer enables, your device permissions, and the information you or a Customer chooses to provide.
3.1 Information you provide directly to Oblyss
- Identity and contact information, such as name, business email address, telephone number, mailing address, company, role, and communication preferences.
- Account and authentication information, such as username, password hash, account identifiers, multi-factor authentication details, role, permissions, and account recovery information.
- Business and professional information, such as company profile, services offered, team size, operating locations, logo, license or certification information, job title, and business preferences.
- Billing and transaction information, such as subscription plan, billing contact, invoices, and payment status, and limited payment method details (such as card type and last four digits) received from our payment processor. Oblyss does not receive or store full payment card or bank account numbers.
- Communications and support information, such as messages, emails, support requests, call or meeting details, survey responses, feedback, and files you send us.
- Community, learning, and event information, such as forum posts, profile information, course activity, event registration, photographs or recordings where notice and permission are provided, and information you choose to make available to other participants.
- Marketing and research information, such as demo requests, form submissions, newsletter subscriptions, referral information, campaign engagement, and responses to industry questionnaires or research programs.
3.2 Customer Data and Customer Content
Customers and Authorized Users may submit, generate, receive, or connect information through the Services. Depending on the features used, Customer Data may include:
- Prospect, customer, and job contact details; property and jobsite addresses; lead sources; appointment and schedule data; access instructions; and communication preferences.
- Project information, such as inspection findings, repair history, measurements, moisture or drainage observations, service notes, scopes of work, estimates, proposals, change orders, material and inventory records, permits, quality-control records, and warranty information.
- Photos, videos, audio, documents, drawings, and associated metadata, including inspection images, before-and-after documentation, engineering materials, insurance claim documents, contracts, waivers, signatures, invoices, receipts, and warranty certificates.
- Workforce and operational information, such as user roles, assignments, availability, activity, performance records, job status, dispatch information, and location information when a Customer enables location-based features and the device user grants permission.
- Communications sent or received through Customer-configured workflows, including email, SMS/text messages, reminders, job updates, review requests, and, if enabled, call recordings, transcripts, and summaries.
- Financial and commercial records, such as pricing, line items, commissions, invoices, milestone billing, payment status, financing status, and accounting synchronization data. Full payment credentials may be collected directly by third-party payment or financing providers.
- Information received through Customer-selected integrations, APIs, webhooks, website forms, calendars, email accounts, accounting tools, e-signature tools, payment processors, call-tracking providers, photo or field tools, and other connected services.
Customers decide what Customer Data to submit and are responsible for providing required notices, obtaining required permissions and consents, respecting individual rights, and using the Services lawfully. Customers and Authorized Users should not submit Social Security numbers, health information, government identification, full payment credentials, or other highly sensitive information unless it is necessary, legally permitted, and supported by the applicable feature and customer agreement.
3.3 Location, device permissions, and media
Certain field, scheduling, dispatch, mapping, photo, and document features may request access to a device's location, camera, microphone, photo library, files, contacts, or calendar. We collect information from these device features only when permission is granted or an Authorized User directs the Services to access it. You may manage device permissions through your device settings, although disabling a permission may limit the related feature.
Where location features are enabled, location is used only to provide the requested feature, such as routing, dispatch, arrival, or timekeeping, and can be turned off in device settings. We do not use Customer workforce location data for advertising and do not sell it.
3.4 Information collected automatically
When you use the Services, we and our service providers may automatically collect technical and usage information, such as IP address, device and browser type, operating system, device or cookie identifiers, referring and exit pages, pages and features viewed, clicks, session dates and times, approximate location derived from IP address, language, performance data, error reports, access logs, and security events. We use cookies, software development kits, pixels, local storage, and similar technologies as described in Section 8.
3.5 Information from other sources
We may receive information from Customers and Authorized Users; integrations and connected services; payment, financing, authentication, e-signature, communications, analytics, and security providers; event organizers and referral partners; public sources and business directories; social networks when you interact with our pages; and other parties that you authorize or that may lawfully provide information to us. We may combine this information with information collected through the Services.
3.6 Sensitive personal information
Depending on enabled features and applicable law, account credentials, precise geolocation, financial account information, the contents of certain communications, and some information in insurance or other uploaded documents may be considered sensitive personal information. We process sensitive personal information only as reasonably necessary to provide and secure the requested Services, comply with law, or for another purpose permitted by law or supported by required consent. We do not use sensitive personal information to infer characteristics about a person for advertising, and we do not sell it.
4. How we use personal information
We may use personal information for the following purposes, as appropriate to the context:
- Provide, configure, operate, maintain, and administer the Services, including accounts, workflows, scheduling, dispatch, inspections, estimates, contracts, documents, invoicing, warranties, reporting, integrations, community, and learning features.
- Authenticate users; manage roles and permissions; maintain tenant separation; detect, investigate, and prevent fraud, abuse, security incidents, and technical problems; and protect the Services, Customers, users, and others.
- Process subscriptions and transactions; provide payment links; synchronize payment or accounting status; communicate about billing; and maintain business records.
- Send service, account, security, support, onboarding, appointment, job, warranty, and other transactional communications through email, telephone, SMS/text, in-app notifications, or other channels selected by a Customer or user.
- Respond to questions, requests, feedback, and support issues; provide training and onboarding; and manage our business relationships.
- Analyze how the Services are used, measure performance, troubleshoot, improve existing features, develop new features, and create aggregate or de-identified information, subject to the commitments in this Policy and our customer agreements.
- Provide AI-assisted features described in Section 5, when enabled or requested.
- Conduct industry research and benchmarking using aggregate or de-identified information as described in Section 6.
- Market Oblyss, measure campaigns, manage events and referrals, and send promotional communications where permitted by law and consistent with your choices.
- Comply with law and lawful requests; enforce agreements and policies; establish, exercise, or defend legal claims; complete audits; obtain professional advice; and protect rights, safety, property, and the integrity of the Services.
- Carry out another purpose disclosed at collection, with your consent, or at your direction.
5. Artificial intelligence and automated features
The Services may offer AI-assisted features that generate or transform content, including inspection summaries, report drafts, contract or invoice field extraction, proposal or communication drafts, lead summaries, and recommended next steps. When an Authorized User activates or requests an AI feature, Oblyss may send the prompt, selected Customer Data, uploaded content, and limited technical metadata to an AI service provider to generate the requested output.
AI output may be incomplete, inaccurate, or unsuitable for a particular purpose. Customers and Authorized Users are responsible for reviewing output before relying on it or sending it to another person. AI output is assistance, not legal, engineering, accounting, financial, employment, safety, or other professional advice. Oblyss does not use AI features to make decisions on its own that produce legal or similarly significant effects about individuals.
Oblyss's AI features are powered by third-party AI providers accessed under their commercial API terms — currently Anthropic (Claude) for text and document features (such as inspection summaries, document-to-template conversion, and proposal, SMS, and email drafting) and Retell AI for AI voice answering and call handling. Data submitted to these providers through their commercial APIs is not used to train their models. Oblyss does not use Customer Data to train general-purpose AI models, and will not use identifiable Customer Data to train a shared Oblyss model or materially expand its use for product development without clear notice and any consent or contractual permission required by law. Google user data is never sent to these AI providers or used to train any model (see Section 9.1).
Customers should not submit information to an AI feature unless they are authorized to process it and the information is necessary for the requested task. Additional AI terms or notices may apply to particular features.
6. Aggregate, de-identified, and industry research data
Oblyss may create aggregate or de-identified information that is not reasonably capable of being associated with an individual. Subject to our customer agreements and applicable law, we may use this information to understand platform performance, develop benchmarks, improve the Services, and support research concerning foundation repair and related specialty trades.
When information is treated as de-identified, Oblyss will maintain it in de-identified form, take reasonable measures designed to prevent re-identification, and not attempt to re-identify it except as permitted by law to test or validate de-identification. Public reports will not identify a Customer or individual unless the Customer or individual has authorized that identification.
Customer participation in benchmarking or industry research requires written customer opt-in or specific contractual permission. Oblyss will use only aggregate or de-identified information, apply documented minimum-cohort and suppression rules, prohibit re-identification, and not publicly disclose a company-specific benchmark without that company's permission. Oblyss does not sell Customer Data or disclose identifiable Customer Data to an industry association for its independent use unless the Customer expressly directs or authorizes the disclosure.
7. How we disclose personal information
We may disclose personal information to the following categories of recipients for the purposes described in this Policy:
- Customers and account administrators. A Customer and its authorized administrators may access, export, configure, monitor, and manage information associated with the Customer's account, including Authorized User activity and, when enabled, location and job-performance information.
- Service providers and subprocessors. Vendors that provide hosting, cloud infrastructure, data storage, security, authentication, customer support, analytics, AI processing, communications, email and SMS delivery, telephony, payment processing, e-signature, accounting synchronization, document processing, maps, error monitoring, marketing, and professional services may process information for Oblyss under appropriate restrictions. A current list of these providers appears in Section 7.2.
- Customer-selected integrations and third parties. When a Customer or Authorized User enables an integration, directs an export, or uses a third-party feature, we disclose and receive information as needed to complete that direction. The third party may process information under its own terms and privacy notice.
- Payment, financing, and e-signature providers. These providers may collect information directly from users or Customer Contacts to complete a payment, financing application, identity check, or signature process. Oblyss may receive status, identifiers, and limited transaction details.
- Business and marketing partners. We may work with referral, event, integration, or co-marketing partners. We will disclose personal information for their own marketing only when permitted by law and consistent with the notice and choices provided.
- Professional advisers. Lawyers, accountants, auditors, insurers, consultants, and other advisers may receive information when reasonably necessary to provide services or protect our business.
- Government authorities and other parties for legal or safety reasons. We may disclose information when we reasonably believe disclosure is required by law or legal process; needed to enforce our agreements or protect rights, safety, property, users, or the Services; or appropriate to investigate fraud, abuse, or security incidents.
- Parties to a business transaction. Information may be disclosed in connection with an actual or proposed financing, merger, acquisition, reorganization, sale of assets, bankruptcy, or similar transaction, subject to appropriate confidentiality and legal protections.
- Other recipients at your direction, with your consent, or as otherwise disclosed when the information is collected.
Public and shared features. Information you post in a forum, community, shared workspace, review, or other area designed to be visible to others may be seen, copied, or used by the intended audience. Customers control sharing within their accounts. Do not post information you do not want the relevant audience to access.
7.1 Our commitments concerning sale and targeted advertising
Oblyss does not sell Customer Data. Oblyss does not sell personal information for monetary consideration. We do not disclose mobile telephone opt-in data or consent records to third parties for their own marketing.
Where enabled, Oblyss may use analytics and advertising or retargeting technologies on its website, such as technologies associated with Google, Meta, or LinkedIn. These technologies may disclose identifiers and internet or electronic activity to analytics and advertising providers to measure campaigns or support targeted or cross-context behavioral advertising. Some laws may define that activity as a “sale” or “sharing.” You can manage these technologies through the cookie settings and the “Your Privacy Choices” control on our website.
7.2 Service providers and sub-processors we use
Oblyss uses the following third-party service providers and sub-processors to provide, secure, and support the Services. Each processes personal information only as needed for its function and under appropriate contractual restrictions. This list may change, and a current list is available on request.
- Railway — application hosting and infrastructure
- Anthropic (Claude) — AI text and document features
- Retell AI — AI voice answering and call handling
- Stripe — subscription billing and Customer payment processing (Stripe Connect)
- Intuit (QuickBooks Online and QuickBooks Payments) — accounting and invoicing sync and, where enabled, payment collection
- Twilio — SMS/text and telephony delivery
- Resend — transactional email delivery and tracking
- CallRail — inbound and outbound call logging
- Google (Calendar and Gmail) — calendar synchronization and send-from email (see Section 9.1)
- Microsoft (Outlook / Microsoft Graph) — calendar synchronization and send-from email
- CompanyCam — field photo capture and synchronization
- DocuSign — optional electronic signature
- ArcSite — proposal and line-item import
- Google Maps Platform — maps and satellite imagery
- Shovels and PermitStack — building-permit data
- BatchData and Lob — address data and direct-mail printing and mailing
- Google Analytics 4 and Google Ads — website analytics and advertising measurement
- Per4mance.io — commission synchronization
- Get The Referral — referral lead intake
- Salesforce — one-time data migration
- Zapier, Make, and n8n, via the Lead Ingestion API and outbound webhooks — Customer-configured automation
8. Cookies, analytics, and online advertising
We and our service providers may use cookies and similar technologies for the following purposes:
- Strictly necessary technologies that support login, security, fraud prevention, network management, load balancing, and core functionality.
- Preference technologies that remember settings, language, and choices.
- Analytics and performance technologies that help us understand use, diagnose errors, and improve the Services.
- Advertising and retargeting technologies that measure campaigns or help deliver advertising based on activity across different services or over time.
- Scheduling, chat, and session-replay technologies that support appointments, communications, support, usability, and troubleshooting.
You can control cookies through available cookie settings and your browser or device settings. Blocking some technologies may affect functionality. Where required, we request consent before using non-essential technologies and honor withdrawals of consent.
Where required by applicable law, Oblyss treats a legally valid opt-out preference signal, such as Global Privacy Control, as a request to opt out of sale, sharing, or targeted advertising for the browser or device sending the signal.
Oblyss uses a consent management tool to present cookie choices and to maintain a current list of the cookies and similar technologies used on its website. You can review the categories in use and manage your preferences at any time through the cookie settings on our website.
Some browsers offer a “Do Not Track” setting. Because there is no uniform standard for interpreting that signal, the Services do not currently respond to Do Not Track signals. This is different from an opt-out preference signal that applicable law requires us to honor.
Emails may contain pixels or similar technologies that tell us whether a message was opened or a link was selected. You can reduce some email analytics by adjusting your email settings or unsubscribing from marketing messages.
9. Third-party integrations, payments, financing, and signatures
The Services may link to or integrate with services operated by other companies, including accounting, calendar, email, e-signature, payments, financing, maps, website, communications, and field-documentation providers. A Customer or Authorized User chooses whether to enable an optional integration and determines the information exchanged through it.
Third parties may collect personal information directly and process it under their own privacy notices and agreements. Oblyss is not responsible for a third party's independent privacy practices. Review the applicable third-party terms before enabling an integration or providing information.
Payment card, bank account, financing application, identity-verification, and signature information may be collected directly by the relevant provider under its own terms. Oblyss receives only tokens, status information, and the limited details needed to provide the related feature, and does not receive or store full payment card or bank account numbers.
9.1 Google user data and Limited Use
When a Customer or Authorized User connects a Google account to the Services, Oblyss requests limited access to Google Calendar and, where the Customer enables it, the ability to send email on the user's behalf through Gmail. Oblyss uses this access only to provide the specific features the user turns on — for example, two-way calendar synchronization for appointments created in Oblyss, and sending Customer-configured messages from the connected account.
Google OAuth tokens are stored encrypted at rest and are used only to operate the connected feature. Oblyss does not sell Google user data, does not use it for advertising, and does not use it for any purpose other than providing the user-facing features the Customer enabled.
Oblyss does not transfer Google user data to, or process it with, any third-party artificial-intelligence or machine-learning provider (including Anthropic (Claude) and Retell AI), and Oblyss does not use Google user data to develop, improve, or train any artificial-intelligence or machine-learning models. Google user data is used solely to provide the connected feature to the Customer.
Limited Use. Oblyss's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
A Customer or Authorized User may disconnect a Google account at any time in the Oblyss integration settings, or by removing Oblyss's access on the Google Account permissions page at myaccount.google.com/permissions. Disconnecting stops further access and disables the connected feature.
10. Email, SMS/text, telephone, and recorded communications
Oblyss may send administrative and transactional communications about accounts, security, billing, support, trials, appointments, and the Services. These messages are necessary to provide the Services and may continue even if you opt out of marketing.
You can unsubscribe from Oblyss marketing email using the link in the message. For an Oblyss SMS program, message frequency varies and message and data rates may apply. Reply STOP to stop recurring texts and HELP for help, or contact us using Section 20. Consent to receive marketing texts is not a condition of purchase.
Customers may configure the Services to send communications to Customer Contacts. The Customer, not Oblyss, determines the recipients, content, timing, and lawful basis for those messages. Customers are responsible for obtaining and documenting any consent required by telephone, text-message, email-marketing, consumer-protection, or other laws; honoring opt-outs; and using accurate sender identification. Oblyss processes recipient information to deliver and support the Customer-directed communication.
If calls or meetings are recorded, transcribed, or summarized, Oblyss or the Customer will provide notice and obtain consent where required by law. Recording features are off by default; where a Customer enables them, the Customer is responsible for providing the notices and obtaining the consents required in the applicable jurisdictions.
11. Notice to Authorized Users and Customer workforce
If you use the Services through your employer or another organization, that Customer controls your account and may establish its own policies for use of the Services. Customer administrators may be able to create or disable your account; reset access; configure permissions; view, export, or delete account and activity information; access content you submit; monitor job status and performance; and, where location features are enabled, view location or dispatch information.
Customers are responsible for providing workforce notices, obtaining permissions or consent where required, and using workforce information consistently with employment, labor, privacy, monitoring, recording, and other applicable laws. Questions about your organization's use of your information should be directed to that organization. Oblyss will assist the Customer as required by law and contract.
12. Notice to Customer Contacts
A Customer may use Oblyss to manage information about its prospects, clients, property contacts, vendors, engineers, subcontractors, or other people connected to a job or business relationship. The Customer decides what information to collect, why to collect it, which communications to send, which integrations to use, and how long the information is needed. Oblyss processes that information to provide the Services to the Customer.
If you receive a message, estimate, contract, invoice, warranty, or other communication through Oblyss on behalf of a Customer, the communication is from or directed by that Customer unless it clearly states otherwise. Contact the Customer regarding its services, communication practices, or a privacy request involving Customer Data. You may also contact Oblyss, and we will route or assist with the request when appropriate.
13. Security
Oblyss uses administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. Safeguards are selected based on the nature of the information and the risks involved and may include access controls, authentication, tenant separation, encryption in transit and at rest, logging, backups, vendor controls, secure development practices, and incident-response procedures.
No system, storage environment, or transmission method can be guaranteed to be completely secure. Customers and users are responsible for protecting account credentials, using available security features, limiting permissions, maintaining secure devices, and notifying Oblyss promptly of suspected unauthorized activity.
14. Retention and deletion
We retain each category of personal information only for as long as reasonably necessary for the purpose for which it was collected, including to provide and secure the Services; maintain Customer accounts and records; complete transactions; comply with legal, tax, accounting, insurance, and reporting obligations; resolve disputes; enforce agreements; and establish or defend legal claims. Our retention decisions consider the amount, nature, and sensitivity of the information, the risk of harm, contractual commitments, user expectations, available deletion controls, and applicable law.
Customer Data is retained during the Customer's subscription and then returned, exported, deleted, or de-identified as provided in the customer agreement. After a subscription ends, Customer Data is generally available for export for a limited period and is then deleted from active systems, with backups expiring on a rolling cycle, unless a longer period is required by law, a legal hold, security, or fraud prevention.
We may retain de-identified information for longer where permitted by law. When information is no longer required, we take reasonable steps to delete, de-identify, or securely dispose of it.
15. International access and data transfers
Oblyss is based in the United States, and the Services are currently directed primarily to business users in the United States. Personal information may be processed in the United States and in other countries where our service providers operate. Those countries may have privacy laws different from the laws where you live.
The Services are currently marketed and sold on a nationwide U.S.-first basis. If Oblyss intentionally markets or sells the Services in Canada, the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction, we will add any required regional notice, legal bases, representative details, and transfer disclosures before that launch. Where applicable law requires a transfer mechanism or other safeguard for an international transfer, we will use an approved mechanism.
16. Your choices and privacy rights
16.1 Account and communication choices
- Account information. Authorized Users may review or update certain profile and account information through the Services or by contacting their administrator or Oblyss.
- Marketing email. Use the unsubscribe link in a marketing email. We may still send non-promotional service communications.
- SMS/text. Reply STOP to the sending number to opt out of recurring texts. Contact the Customer that initiated a Customer-directed message if the request concerns that Customer's campaign.
- Device permissions. Manage location, camera, microphone, photo, file, contacts, calendar, and notification permissions in device settings.
- Cookies. Use the cookie settings and the “Your Privacy Choices” control on our website, together with your browser settings, to manage cookies. Where applicable, a recognized opt-out preference signal will be honored.
16.2 Privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to request that Oblyss:
- Confirm whether we process your personal information and provide access to or a copy of it.
- Correct inaccurate personal information.
- Delete personal information.
- Provide personal information in a portable format.
- Explain the categories of personal information collected; sources; purposes; and categories of recipients.
- Opt you out of sale, sharing, targeted advertising, or certain profiling, where applicable.
- Limit certain uses or disclosures of sensitive personal information, where applicable.
- Provide a list of specific third parties to which personal information was disclosed, where required by law.
- Withdraw consent where processing is based on consent, without affecting processing that occurred before withdrawal.
- Appeal a decision concerning a privacy request and receive information about how to contact the appropriate regulator.
You will not be unlawfully discriminated against for exercising a privacy right. Some information is exempt, and we may retain or continue processing information as permitted by law, including where it is needed to provide a requested service, protect security, comply with law, or establish or defend legal claims.
16.3 How to submit a request
Submit a request by emailing privacy@oblysspro.com with the subject “Privacy Request.” To appeal a decision, use the subject “Privacy Request Appeal” and include the request number or denial notice.
We may take reasonable steps to verify your identity and authority based on the nature of the request and sensitivity of the information. We will use information provided for verification only for that purpose and related security or recordkeeping. An authorized agent may submit a request where permitted by law; we may require proof of authorization and may verify the request directly with you.
For a Customer Data request, identify the relevant Customer. We may refer you to that Customer because it controls the information. Oblyss will respond and provide any required appeal within applicable legal deadlines.
17. Supplemental notice for California residents
This section applies to California residents when Oblyss acts as a “business” subject to the California Consumer Privacy Act, as amended (“CCPA”). It does not apply when Oblyss processes Customer Data solely as a service provider or contractor for a Customer. Terms in quotation marks have the meanings assigned by the CCPA.
17.1 Categories collected and disclosed
Based on the Services and features used, Oblyss may have collected the following categories of personal information during the preceding 12 months. The examples are illustrative; not every item is collected about every person.
Sources. We collect these categories from you; Customers, Authorized Users, and Customer Contacts; your device or browser; integrations and service providers; payment, financing, communications, authentication, e-signature, analytics, security, and event partners; public sources and business directories; and other parties you direct or authorize.
Purposes. We use these categories to provide, operate, secure, support, bill for, analyze, and improve the Services; provide AI-assisted features; conduct permitted aggregate/de-identified research; communicate and market; maintain records; comply with law; protect rights and safety; and carry out purposes disclosed at collection or authorized by you.
Retention. We retain these categories under the criteria described in Section 14.
17.2 Sale, sharing, and sensitive personal information
Oblyss does not sell Customer Data and does not sell personal information for money. Where enabled, Oblyss may use analytics and advertising or retargeting technologies that disclose identifiers and internet or electronic activity to analytics and advertising providers. Where applicable, that disclosure may be considered “sharing” for cross-context behavioral advertising or a “sale” under some laws. You can exercise choices through the “Your Privacy Choices” control on our website.
Oblyss does not knowingly sell or share personal information of people under 16. Oblyss uses and discloses sensitive personal information only for purposes permitted without a right to limit under the CCPA, such as providing and securing requested Services, and does not use sensitive personal information to infer characteristics or for cross-context behavioral advertising.
17.3 California rights
California residents may have the rights to know, access, correct, delete, and obtain information about personal information; opt out of sale or sharing; limit certain uses or disclosures of sensitive personal information; and receive equal service and pricing without unlawful discrimination. Submit a request as described in Section 16.3. To opt out of sale or sharing, use the “Your Privacy Choices” control in our website footer. A legally valid Global Privacy Control signal will be treated as an opt-out request for the browser or device sending it where required by law.
California “Shine the Light.” We do not disclose personal information to third parties for their own direct marketing without providing the choice required by California law. California residents may contact us using Section 20 with questions about this practice.
18. Children's privacy
The Services are designed for businesses and are not directed to children under 18. We do not knowingly collect personal information directly from children under 13 or knowingly sell or share personal information of people under 16. If you believe a child provided personal information directly to Oblyss without appropriate authorization, contact us so we can investigate and take appropriate action.
A Customer may place information in Customer Data that incidentally concerns a minor, such as a property occupant or job contact. The Customer is responsible for having lawful authority to collect and use that information. Privacy requests concerning that Customer Data should be directed to the Customer.
19. Changes to this Policy
We may update this Policy to reflect changes in the Services, our practices, or applicable law. We will post the revised Policy and update the “Last Updated” date. If a change materially affects how we use personal information, we will provide additional notice or obtain consent where required by law or contract. Prior versions may be requested using the contact information below.
20. Contact us
Questions, privacy requests, or concerns may be directed to:
Oblyss Incorporated d/b/a Oblyss and OblyssPro
Attn: Privacy
Email: privacy@oblysspro.com