Centralized Communication Preference Management

Privacy Policy

Effective date: September 9, 2026

1. Information We Collect

OptedOut360 may store account details, verified email addresses, company/workspace relationships, application identifiers, communication preferences, consent records, suppression records, login and audit information, uploaded files, and technical metadata needed to operate the service.

2. Communication Preferences and Consent

We store global, application-level and category-level communication choices, together with history showing when and how preferences changed. Important consent records are retained as history rather than simply overwritten.

3. Email Addresses and Identity Matching

Verified email addresses and email hashes may be used to associate the same person across participating applications while reducing unnecessary duplicate contact records.

4. Application Integrations

Connected applications may send secure server-to-server requests asking whether an optional communication is permitted. OptedOut360 may return an allowed or suppressed decision and a reason. Preference and suppression information may be shared with those applications only as needed to enforce the user's choices and operate the integration.

5. Cookies and Sessions

Session cookies may be used for secure login, CSRF protection, account continuity and other essential service functions.

6. Security

The application is designed to use password hashing, prepared database statements, role-based access, session protection, secure tokens, file validation, HTTPS, audit logging and server-side credential protection.

7. Data Retention

Preference, suppression, consent and audit records may be retained for operational, security, dispute-resolution and compliance-oriented purposes. Retention periods should be configured by the organization according to its obligations.

8. Data Deletion

Users may request account deletion through supported account tools. Some limited records may need to be retained where necessary to preserve a valid suppression request, security history, transaction history, or legal obligation.

9. Third-Party Services

The platform may use services such as SMTP providers and, when enabled, Stripe. Third-party services process information under their own terms and privacy practices.

10. User Rights

Depending on location and applicable law, users may have rights to access, correct, delete, export, or limit certain processing of personal information. OptedOut360 provides tools intended to support these requests.

11. Compliance-Oriented Design

The system is designed to support communication-management concepts associated with CAN-SPAM, GDPR consent and withdrawal, CCPA/CPRA preference concepts, and general email marketing practices. This does not constitute legal advice or automatic legal compliance.

12. Changes

This policy may be updated and versioned by authorized administrators. Changes should include an effective date and appropriate notice when required.

13. Contact

Questions may be submitted through the Support page or the contact method configured by the System Administrator.

Return to Previous Page