1.Scope and our role
This policy covers personal information handled by PavlEx Incorporated in connection with Oplix, Oplix Go, our websites, and our support and billing operations.
Two different roles
- Account information — we decide how it is used. When you create an account, subscribe, contact support, or visit our website, we act as the business responsible for that information and this policy governs it directly.
- Customer business data — our customer decides how it is used. The records an organization keeps in Oplix — its customers, contacts, vendors, orders, deliveries, and personnel records — are controlled by that organization. We process them on its instructions to provide the service. If you are an employee of, or a business contact of, an organization that uses Oplix, direct your privacy requests to that organization; we will refer such requests to them.
This policy does not apply to third-party products you connect to Oplix, such as QuickBooks, or to the practices of the organizations that use Oplix.
2.Information we collect
Information you give us
| Category | Examples | Why we have it |
|---|---|---|
| Account and profile | Name, work email address, password (stored only as a salted hash), job role, organization name, organization membership and permissions | To create and secure accounts and to determine what each user may access |
| Billing | Billing contact, billing address, subscription plan, invoices and payment history, and a payment-method token | To sell and administer subscriptions. Card numbers go directly to our payment processor — we never receive or store them |
| Support and communications | Support requests, email correspondence, and any information you choose to include | To answer questions and resolve problems |
| Customer business data | Your customer and vendor contacts, orders, deliveries, routes, inventory, ledger entries, sales-rep assignments and commissions | To provide the service to the organization that entered it |
Information collected automatically
- Device and connection data — IP address, browser or device type, operating system, app version, language, and time zone.
- Usage data — pages and screens viewed, actions taken in the product, feature usage, and timestamps.
- Security and audit data — sign-in events, session activity, device registrations for the mobile app, and administrative actions recorded in the activity log.
- Diagnostics — error reports and crash traces, including the state of the application when an error occurred.
We do not collect precise geolocation, and we do not use device advertising identifiers.
3.The Oplix Go mobile app
Oplix Go is designed to work without a network connection, which means it stores business data on the device.
- On-device cache.The app keeps an encrypted local database containing only the records the signed-in user's organization and role are entitled to — for example, a sales rep receives their assigned customers and a limited recent window of orders, not the organization's full customer list or history.
- Credentials.Access tokens are stored in the operating system's secure storage (iOS Keychain or Android Keystore), never in plain app storage.
- Device identifiers. The app registers a device identifier with us so an administrator can see which devices hold company data and revoke a lost or stolen one. We use it for security and for remote wipe — not for advertising or tracking.
- Purging. Signing out, switching organizations, uninstalling the app, or being revoked by an administrator purges the local database and stored credentials.
- Permissions. The app requests only the permissions its features need — network access, and, if you enable app lock, biometric or device-passcode authentication (which is verified by the operating system; we never receive your biometric data).
4.How we use information
- To provide, operate, maintain, and synchronize the service, including the offline mobile experience.
- To authenticate users, enforce roles and permissions, and keep organizations' data isolated from one another.
- To process subscriptions, invoice, and collect payment.
- To provide support and respond to your requests.
- To monitor reliability and security, investigate errors and abuse, and prevent fraud.
- To improve and develop our products, including through aggregated and de-identified analysis that does not identify you.
- To send service and transactional messages — verification, invitations, password resets, notifications, billing, security, and material changes to our terms.
- To send product and marketing email to business contacts who have opted in or who we have an existing business relationship with; you can unsubscribe at any time.
- To comply with law and to establish, exercise, or defend legal claims.
We do not use personal information to train third-party generative artificial intelligence models, and we do not make automated decisions about individuals that produce legal or similarly significant effects on them.
6.How we disclose information
- Within your organization. Information in Oplix is visible to other users of your organization according to the roles and permissions its administrators configure.
- Service providers. To the vendors listed in Section 7, which process information on our behalf under contracts that restrict them to that purpose.
- Integrations you enable.When your organization connects a third-party product such as QuickBooks, we exchange the relevant data with it at your direction. That product's provider then handles the data under its own policies.
- Legal and safety. When we believe disclosure is required by law, legal process, or a governmental request, or is necessary to protect the rights, property, or safety of PavlEx Incorporated, our customers, or the public, or to enforce our terms. Where we are legally permitted, we will notify the affected customer first.
- Corporate transactions. In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to the acquirer continuing to handle the information consistently with this policy.
- With your direction or consent. Any other disclosure you ask us to make.
7.Service providers and sub-processors
The following categories of vendor may process information on our behalf. We maintain this list publicly so customers can review it before and during a subscription.
| Provider | Purpose | Data handled | Location |
|---|---|---|---|
| Amazon Web Services | Application hosting, database hosting, and document/image object storage | All hosted account and business data | United States |
| Stripe, Inc. | Subscription billing and payment processing for Oplix subscriptions | Billing contact and payment method data (card data goes directly to Stripe) | United States |
| Resend / transactional email provider | Transactional email (verification, invitations, password reset, notifications) | Recipient name, email address, message contents | United States |
| Functional Software, Inc. (Sentry) | Application error and crash diagnostics | Error traces, app version, device/browser metadata, user and organization identifiers | United States |
| Intuit Inc. (QuickBooks) | Accounting synchronization — only if the customer enables the integration | Customers, vendors, invoices, payments, and ledger records selected for sync | United States |
| Apple Inc. / Google LLC | Mobile app distribution and push delivery for Oplix Go | Store account and device delivery metadata only; no business data | United States |
We may add or replace providers as the service evolves. Material changes to this list will be reflected here. Write to admin@oplix.us to ask for advance notice of changes.
8.We do not sell or share your information
We do not disclose personal information to data brokers, advertising networks, or analytics companies that combine it with data from other sources.
9.How long we keep information
- Customer business data is kept for as long as the organization's subscription is active. After termination or expiration we retain it for approximately 30 days so the organization can request an export, after which we may permanently delete it.
- Account and profile information is kept while the account is active and for a reasonable period afterwards to handle reactivation, disputes, and security investigations.
- Billing and tax records are kept for the period required by law, typically seven years.
- Security, audit, and sign-in logs are kept for a limited period appropriate to investigating incidents.
- Diagnostic and error data is kept on a short rolling window and is not used to build profiles of individuals.
- Data cached on a mobile device covers only a rolling recent window and is purged on sign-out, organization switch, uninstall, or administrator revocation.
Copies may persist in routine encrypted backups for a limited period after deletion from live systems, and are deleted on our normal backup cycle. We may retain information longer where required by law or reasonably necessary to establish, exercise, or defend legal claims.
10.How we protect information
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit, encryption of data cached on mobile devices, isolation between customer organizations, role-based access control, least- privilege access for our personnel, logging of administrative activity, and regular review of our security posture.
Much of an organization's security depends on choices its own administrators make. See the security responsibilities described in our Terms of Service. If you believe your account or a device has been compromised, contact us immediately at admin@oplix.us.
11.Your privacy choices and rights
Depending on where you live, you may have the right to:
- Know what personal information we have collected about you, the sources, the purposes, and the categories of recipients.
- Access or receive a copy of your personal information, in a portable format where required.
- Correct inaccurate personal information.
- Delete personal information, subject to legal and contractual exceptions.
- Opt out of the sale or sharing of personal information and of targeted advertising — which we do not do in any case.
- Limit the use of sensitive personal information — which we do not collect for such purposes.
- Not be discriminated against for exercising a privacy right.
- Appeal a decision we make about your request, where state law provides for an appeal.
To make a request, email admin@oplix.us from the address associated with your account and describe what you are asking for. We will verify your identity before acting, and we will respond within the period required by applicable law. An authorized agent may submit a request on your behalf with proof of authorization.
If your request concerns business records held in Oplix by an organization you work for or do business with, that organization is responsible for responding. We will forward your request to them and assist them in responding.
You can opt out of marketing email at any time using the unsubscribe link or by writing to us. We will still send transactional and service messages about your account.
12.Account and data deletion
Step-by-step instructions for deleting a user account, deleting data cached on a mobile device, and deleting an entire organization's data are on our support page. In short:
- A user account can be deactivated by your organization's administrator, or deleted by writing to admin@oplix.us from the account's email address.
- Data cached on a mobile device is purged by signing out of the app, uninstalling it, or having an administrator revoke the device.
- An organization's account and business records can be deleted at the request of an authorized administrator. Export what you need first — deletion is irreversible.
We may retain records we are required to keep by law, such as billing and tax records, and information reasonably necessary to resolve disputes, prevent fraud, and enforce our agreements.
13.Notice for California residents
This section supplements the rest of this policy for California residents, under the California Consumer Privacy Act as amended.
Categories collected in the last 12 months
| Statutory category | Collected | Business purpose |
|---|---|---|
| Identifiers (name, email, IP address, account and device identifiers) | Yes | Provide and secure the service, support, billing |
| Customer records (billing contact and address, payment history) | Yes | Subscription administration and billing |
| Commercial information (subscription plan, transactions with us) | Yes | Subscription administration |
| Internet or network activity (product usage, error and diagnostic data) | Yes | Reliability, security, product improvement |
| Professional or employment information (job role, organization, permissions) | Yes | Access control within a customer's organization |
| Geolocation (precise) | No | — |
| Biometric information | No | Biometric app unlock is verified by the device operating system; we never receive biometric data |
| Sensitive personal information | No | We do not collect sensitive personal information for the purpose of inferring characteristics |
| Inferences / profiles | No | — |
Sources, disclosures, and retention
We collect this information from you, from the organization that created your account, automatically from your use of the service, and from our payment processor. We disclose it for business purposes to the service providers listed in Section 7. We retain it for the periods described in Section 9. We do not sell personal information and do not share it for cross-context behavioral advertising.
Exercising your rights
Submit requests to know, delete, correct, or appeal by emailing admin@oplix.us. We will not discriminate against you for exercising these rights. Note that much of the information in Oplix is collected in a business-to-business context and may be held by our customer as the responsible business rather than by us.
14.Children
Oplix is business software intended for use by adults acting on behalf of an organization. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact admin@oplix.us and we will delete it.
15.Users outside the United States
We operate in the United States and our service providers process information there. If you access the service from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, where privacy laws may differ from those in your country. Oplix is offered for use in the United States market and is not marketed to individuals in the European Economic Area, the United Kingdom, or Switzerland.
16.Changes to this policy
We may update this policy as the product and the law change. The "Effective" date at the top of this page shows when the current version took effect. If a change is material, we will notify account administrators by email or through the service before it takes effect. Continued use after the effective date means you accept the updated policy.
17.Contact us
PavlEx Incorporated — Oplix
PavlEx Incorporated, attention: Legal — admin@oplix.us
Questions, privacy requests, and legal notices: admin@oplix.us.