Owner and Data Controller: Otacta Inc.
Contact Email: admin@otacta.ai
Type of Data We Collect
Among the types of Personal Data that this Application collects, by itself or through third parties, there are:
- Trackers 
- Usage Data 
- Number of Users 
- Session Statistics 
- Full Access 
- Third-party platform data (with explicit client authorization) 
Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection.
Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using this Application.
Unless specified otherwise, all Data requested by this Application is mandatory and failure to provide this Data may make it impossible for this Application to provide its services. In cases where this Application specifically states that some Data is not mandatory, Users are free not to communicate this Data without consequences to the availability or the functioning of the Service.
Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner.
Any use of Cookies or of other tracking tools, by this Application or by the owners of third-party services used by this Application serves the purpose of providing the Service required by the User, in addition to any other purposes described in the present document and in the Cookie Policy.
Users are responsible for any third-party Personal Data obtained, published or shared through this Application.
Mode and Place of Processing the Data
Methods of Processing
The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data.
The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of this Application (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.
Place
The Data is processed at the Owner's operating offices and in any other places where the parties involved in the processing are located.
Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.
Retention Time
Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users' consent.
Detailed Information on the Processing of Personal Data
Analytics
The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.
Google LLC
Google Analytics 4
Third-Party Platform Integrations for Business Intelligence
This Application may integrate with various third-party platforms and services upon explicit client approval and authorization to provide AI-driven business analytics, insights, and decision-making support. These integrations are established solely for the purpose of delivering contracted analytics and optimization services to clients.
Google Analytics 4 Integration
Upon client approval and integration, this Application may connect to client Google Analytics 4 (GA4) accounts to access analytics data for the purpose of providing AI-driven analysis and insights for business optimization. This integration enables the Application to:
- Analyze website traffic patterns and user behavior data 
- Generate predictive insights for marketing and conversion optimization 
- Provide automated recommendations based on web analytics data 
- Create customized reports and analytics dashboards 
- Support demand forecasting and customer behavior analysis 
E-commerce Platform Integration (Shopify and Others)
Upon client approval and integration, this Application may connect to client e-commerce platforms including but not limited to Shopify, to access business data for the purpose of providing AI-driven retail intelligence and operational optimization. These integrations enable the Application to:Analyze sales data, inventory levels, and product performanceGenerate demand forecasting and inventory optimization recommendationsProvide dynamic pricing strategies and promotional insightsCreate automated business intelligence reports and dashboardsSupport operational decision-making across pricing, inventory, and marketingAnalyze customer purchase patterns and behavior
Additional Platform Integrations
The Application may integrate with other business platforms including but not limited to:Customer Relationship Management (CRM) systemsEnterprise Resource Planning (ERP) systemsPoint of Sale (POS) systemsMarketing automation platformsBusiness intelligence and analytics toolsOther e-commerce and retail management platformsAll integrations require explicit client authorization and are used exclusively for providing contracted analytics and business optimization services.
Data Security and Client Control: All third-party platform data is processed securely using industry-standard encryption and security protocols. Clients maintain full control over their platform access permissions and can revoke authorization at any time through their respective platform settings or by contacting the Owner. Data from these integrations is used solely for providing the contracted analytics and decision-making services and is not shared with unauthorized third parties.
Registration and authentication
By registering or authenticating, Users allow this Application to identify them and give them access to dedicated services.
Depending on what is described below, third parties may provide registration and authentication services. In this case, this Application will be able to access some Data, stored by these third-party services, for registration or identification purposes.
Some of the services listed below may also collect Personal Data for targeting and profiling purposes; to find out more, please refer to the description of each service.
Google LLC
- Gmail permissions to access User Data (OAuth addition) 
- Google OAuth 
Google User Data: Required Disclosures for OAuth Verification
1. What Google User Data is Accessed
Otacta requests access to Google Analytics 4 (GA4) data using the scope `https://www.googleapis.com/auth/analytics.readonly`. This access allows us to retrieve metrics such as website traffic, user engagement trends, page performance statistics, and other analytics reports. Otacta does not request or access any data from Gmail, Google Drive, Workspace APIs, or Google Photos APIs.
2. How This Data is Used
The Google Analytics data accessed is used to generate AI-powered recommendations and insights within the Otacta platform. Specifically, we use GA4 metrics to:
- Provide predictive analytics on product performance 
- Surface recommendations for pricing, inventory levels, and marketing performance 
- Eliminate the need for manual data exports by automatically syncing analytics data 
- All access is read-only and initiated by users through an explicit authorization flow. 
3. Data Sharing and Disclosure
Otacta does not share, sell, or transfer Google user data to any third party. All data retrieved via the Google Analytics API is used exclusively within Otacta to provide analytics and reporting services to the user who authorized the connection. User data may be accessed only by authorized personnel for the purpose of fulfilling Otacta’s services and is protected with strict access controls and encryption.
4. Use of AI/ML Models
Otacta’s AI and ML models analyze GA4 metrics to identify trends, anomalies, and actionable insights in e-commerce performance. These models do not interact with any Google Workspace or Photos API data. All data processing is limited to what is necessary to provide insights and operational recommendations to Otacta users based on GA4 metrics.
5. Compliance with Google’s Limited Use Policy
Otacta fully complies with Google’s Limited Use Policy. We do not use or access Google user data for any purpose other than explicitly requested by the user within Otacta’s functionality. All access is secure, limited, and consent-based. Data is not used for advertising or transferred to third parties outside the bounds of necessary infrastructure providers.
Further Information for Users in the European Union
Legal Basis of Processing
The Owner may process Personal Data relating to Users if one of the following applies:
- Users have given their consent for one or more specific purposes. 
- Provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof; 
- Processing is necessary for compliance with a legal obligation to which the Owner is subject; 
- Processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner; 
- Processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party. 
In any case, the Owner will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
The Rights of Users Based on the General Data Protection Regulation (GDPR)
Users may exercise certain rights regarding their Data processed by the Owner. In particular, Users have the right to do the following, to the extent permitted by law:Withdraw their consent at any timeObject to processing of their DataAccess their Data and obtain copiesVerify and seek rectification of their DataRestrict the processing of their DataHave their Personal Data deleted or otherwise removedReceive their Data and have it transferred to another controllerLodge a complaint with competent data protection authority
How to Exercise These Rights
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible and always within one month, providing Users with the information required by law.
Further Information for Users in the United States
This information applies to all Users who are residents in the following states: California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Nevada, Delaware, Iowa, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota and Montana.
Notice at Collection
The following categories of Personal Information have been collected or disclosed in the past 12 months:
Internet or other electronic network activity informationIdentifiers
Your Privacy Rights Under US State LawsYou may exercise certain rights regarding your Personal Information:Right to access Personal Information: the right to knowRight to correct inaccurate Personal InformationRight to request deletion of your Personal InformationRight to obtain a copy of your Personal InformationRight to opt out from the Sale of your Personal InformationRight to non-discrimination
Additional Rights for California Users
- Right to opt out of the Sharing of your Personal Information for cross-context behavioral advertising 
- Right to request to limit use or disclosure of your Sensitive Personal Information 
How to Exercise Your Privacy Rights
To exercise the rights described above, you need to submit your request to us by contacting us via the contact details provided in this document.
We will respond to your request without undue delay, but in all cases within the timeframe required by applicable law.
Additional Information About Data Collection and Processing
Legal Action
The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of this Application or the related Services.
The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.
System Logs and Maintenance
For operation and maintenance purposes, this Application and any third-party services may collect files that record interaction with this Application (System logs) or use other Personal Data (such as the IP Address) for this purpose.
Changes to This Privacy Policy
The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within this Application and/or - as far as technically and legally feasible - sending a notice to Users via any contact information available to the Owner.
It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.
Definitions and Legal References
Personal Data (or Data) / Personal Information (or Information)
Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
Sensitive Personal Information
Sensitive Personal Information means any Personal Information that is not publicly available and reveals information considered sensitive according to the applicable privacy law.
Usage Data
Information collected automatically through this Application (or third-party services employed in this Application), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.
Cookie
Cookies are Trackers consisting of small sets of data stored in the User's browser.
Tracker
Tracker indicates any technology - e.g Cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting - that enables the tracking of Users, for example by accessing or storing information on the User's device.
Full Access
Full access to the account, including permanent deletion of threads and messages.
Legal Information
This privacy statement has been prepared based on provisions of multiple legislations.
This privacy policy relates solely to this Application, if not stated otherwise within this document.