Legal
Privacy Policy
Last updated: July 2, 2026
Ocuula (“we,” “our,” or “us”) is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your information when you use our payment orchestration platform and website.
Information We Collect
Account information. When you create an account, we collect your name, email address, and organization details. This is required to provide our services.
Payment data. We process transaction amounts, recipient identifiers, and split configurations on your behalf. As a non-custodial middleware provider, we do not store full payment instrument details or credentials. All sensitive payment data is handled directly by your chosen payment processor.
Usage data. We collect anonymized analytics about platform usage, API call volumes, and error rates to improve our service. This data cannot be traced back to specific end users.
Cookies. We use essential cookies for authentication and session management. We do not use tracking cookies or third-party advertising cookies.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our payment orchestration platform
- Process and route split payment instructions
- Send transactional notifications about your account
- Respond to support requests and legal obligations
- Detect and prevent fraud or abuse of our platform
We do not sell your personal information to third parties. We do not use your data for advertising or marketing unrelated to our service.
Data Sharing
We may share your information with:
- Payment processors — to execute split instructions on your behalf. You choose which processor to connect.
- Service providers — hosted infrastructure (Convex, Cloudflare) that process data under our instructions. They cannot use your data for their own purposes.
- Legal authorities — when required by law, court order, or valid legal process.
We never share transaction-level data with third parties for their independent use.
Data Retention
We retain your data only as long as needed to provide our service or comply with legal obligations:
- Account information is kept for the life of your account plus 90 days
- Transaction logs are retained for 7 years for audit and compliance purposes
- Usage analytics are anonymized and retained indefinitely
When you delete your account, we erase your personal information within 90 days. Transaction logs required for regulatory compliance are kept in anonymized form.
Your Rights
Depending on your jurisdiction, you may have rights regarding your personal data:
- Right to access the personal data we hold about you
- Right to correct inaccurate data
- Right to delete your data (subject to legal retention requirements)
- Right to restrict or object to processing
- Right to data portability
To exercise any of these rights, contact us at privacy@ocuula.com. We respond to all requests within 30 days.
Contact Us
If you have questions about this Privacy Policy, contact us:
Email: privacy@ocuula.com
Legal: legal@ocuula.com