This Privacy Policy explains how Offermesh Network, doing business as Randomness As a Service ("Company," "we," "us," or "our"), collects, uses, shares, retains, and otherwise processes personal data when you visit our website, join our waitlist, create or use an account, interact with our dashboard or APIs, subscribe to a paid plan, contact us, or otherwise use our services (collectively, the "Service").
This policy is intended to provide the transparency typically required by privacy laws such as the GDPR/UK GDPR transparency rules and U.S. state privacy laws, but it is still a draft and must be finalized against the actual production vendor stack and launch flows.
If you do not agree with this Privacy Policy, do not use the Service.
1. Scope
This Privacy Policy applies to personal data we process as a controller in connection with:
- our public marketing site;
- the prelaunch waitlist or access-request flow;
- customer accounts, authentication, and email verification;
- the dashboard, API access management, and usage reporting;
- subscriptions, billing support, invoices, and payment-method flows;
- customer support, operational support, and administrative actions; and
- security monitoring, fraud prevention, logging, and compliance operations.
This policy does not apply to:
- third-party sites, apps, or services that we do not control;
- data processed by third-party payment providers under their own privacy notices;
- anonymized information that cannot reasonably identify you; or
- employer-controlled environments where your organization, rather than us, acts as the primary controller for certain internal data.
2. Who We Are
The controller responsible for your personal data is:
Offermesh NetworkKyrenia, Mersin 10, Turkey[email protected][email protected]
- Data protection officer or privacy lead:
[DPO OR PRIVACY CONTACT, IF APPLICABLE] - EU/UK representative:
[EU/UK REPRESENTATIVE, IF APPLICABLE]
3. Personal Data We Collect
The personal data we collect depends on how you interact with the Service.
3.1 Information you provide directly
Depending on the feature you use, we may collect:
- email address;
- name or display name;
- account credentials or password-related records;
- company or organization information, if you provide it;
- plan selection, subscription preferences, and billing contact details;
- support messages, feedback, and other communications you send us;
- account-deletion requests, privacy requests, and support follow-up information;
- API key labels, environment labels, and other account configuration data;
- any other information you choose to submit through forms, support channels, or account settings.
3.2 Waitlist and access-request information
For the current prelaunch site, we collect:
- your email address when you request access; and
- limited anti-abuse data needed to protect the waitlist endpoint, such as a hashed fingerprint derived from IP address and user-agent data for rate limiting.
The current waitlist flow is intended for access and product-update communications related to launch readiness, not for a generic marketing newsletter sequence.
3.3 Account, authentication, and verification information
When accounts are available, we may collect:
- account identifiers;
- login and authentication records;
- session identifiers and session-expiry data;
- email-verification records;
- password reset or verification-token records;
- account-security events and login history;
- role or access-control data, including whether an account has customer or admin privileges.
3.4 Subscription and billing information
If you start a trial or subscribe, we may collect or receive:
- selected plan and billing cadence;
- subscription status and entitlement status;
- trial qualification status;
- invoice and receipt metadata;
- billing history;
- payment status, refund status, chargeback status, and grace-period status;
- partial payment-method details provided by processors, such as card brand, last four digits, expiration month/year, and billing country, if the processor makes those available to us.
We generally expect payment card data itself to be collected and stored by the relevant payment processor rather than by us.
3.5 API, usage, and operational information
When you use the dashboard or API, we may collect:
- API key metadata, including key names, environment labels, last-used timestamps, and status;
- request metadata such as timestamps, request IDs, account identifiers, and machine-readable error codes;
- usage summaries, token-consumption records, and generator-type aggregates;
- balance, entitlement, renewal, and billing-state information;
- operational logs and abuse-monitoring data;
- rate-limit, fraud-prevention, and security-monitoring signals.
The product is designed so customer-facing dashboard history is aggregated and time-limited. Raw customer-facing request logs are not part of the planned v1 customer experience.
3.6 Device, network, and diagnostic information
When you access the Service, we may automatically collect technical data such as:
- IP address;
- browser and device characteristics;
- operating system;
- network and connection information;
- timestamps;
- referral URLs;
- error logs, performance logs, and diagnostic events;
- server-side security and abuse-detection signals.
3.7 Information we receive from third parties
We may receive personal data from:
- billing and subscription-management providers, including RevenueCat and underlying payment processors;
- email and transactional-message providers;
- hosting, database, and infrastructure providers;
- fraud-prevention, abuse-detection, and security vendors;
- customer support systems or communication tools;
- your organization or another authorized user, if they create an account or manage access on your behalf.
If we later enable additional sign-in providers or third-party integrations, we will update this policy accordingly.
4. Sources of Personal Data
We collect personal data:
- directly from you when you complete forms, create an account, configure the Service, subscribe, contact us, or use the API or dashboard;
- automatically from your browser, device, or application when you access the Service;
- from our service providers in connection with billing, email delivery, infrastructure, fraud prevention, support, and security; and
- from other authorized users or organizations connected to your use of the Service, where applicable.
5. How We Use Personal Data
We use personal data to operate a subscription-based developer product. In particular, we may use personal data to:
- provide the website, waitlist, dashboard, API, and account features;
- create and manage accounts;
- verify email addresses and secure login flows;
- issue, manage, rotate, revoke, and monitor API keys;
- meter usage, enforce token entitlements, and show balance or usage visibility;
- administer free trials, subscriptions, renewals, plan switches, invoices, refunds, and billing-problem states;
- provide customer support and respond to product, billing, legal, and privacy requests;
- send transactional messages such as verification emails, trial-ending notices, payment-failed notices, receipts, cancellation confirmations, refund confirmations, and API-key regeneration notices;
- protect the Service, including rate limiting, spam prevention, fraud detection, abuse prevention, and incident response;
- troubleshoot bugs, diagnose outages, improve reliability, and maintain security;
- comply with legal obligations, enforce our Terms of Service, protect rights and safety, and maintain audit records;
- perform internal reporting, reconciliation, and operational analysis; and
- communicate with you about access, onboarding, product availability, and service changes.
Where permitted by law, we may also use limited contact information for narrow product-related communications, such as launch-access updates or service notices. If consent is required for a message type, we will rely on consent and give you an appropriate way to withdraw it.
6. Lawful Bases for Processing
If GDPR, UK GDPR, or similar laws apply, we generally rely on one or more of the following legal bases:
| Purpose | Typical categories | Legal basis |
|---|---|---|
| Provide accounts, dashboard, API access, subscriptions, invoices, and support | account data, usage data, billing data, communications | performance of a contract or steps taken at your request before entering a contract |
| Verify accounts, secure the platform, prevent fraud, rate limit, investigate abuse, and maintain logs | login data, IP address, device data, security events, request metadata | legitimate interests in operating a secure and reliable service; in some cases legal obligation |
| Send required service communications such as email verification, receipts, refund notices, and security notices | contact details, account status, billing metadata | performance of a contract; legal obligation; legitimate interests in administering the service |
| Maintain financial, tax, accounting, audit, and compliance records | billing records, invoices, payment status, support and audit records | legal obligation; legitimate interests in recordkeeping and dispute handling |
| Respond to privacy requests, complaints, deletion requests, and legal demands | identity and verification data, support records, request history | legal obligation; legitimate interests in compliance and defense of claims |
| Prelaunch waitlist and access-request processing | email address, limited anti-abuse data | consent where required; otherwise legitimate interests in controlled launch access and abuse prevention |
When we rely on legitimate interests, those interests generally include running a secure, reliable, fraud-resistant, commercially workable developer platform; enforcing our rules; measuring usage; and protecting the Service, our users, and the public from misuse.
7. Cookies and Similar Technologies
We may use cookies, session tokens, local storage, and similar technologies to:
- keep you signed in;
- maintain session integrity;
- protect against fraud and abuse;
- remember basic preferences;
- support security controls such as CSRF prevention; and
- operate essential site and product functionality.
As of the current repository state, we do not see advertising SDKs or third-party behavioral-ad targeting tools wired into the public site. If optional analytics, personalization, advertising, or cross-site tracking technologies are added later, this policy and any required consent flow must be updated before they are deployed.
You can usually control cookies through your browser settings. Blocking strictly necessary cookies may prevent parts of the Service from working.
As of the effective date, we do not sell personal information and we do not share personal information for cross-context behavioral advertising.
We may disclose personal data to the following categories of recipients:
- hosting, database, cloud, and infrastructure providers;
- billing, subscription-management, invoicing, and payment providers;
- email delivery and transactional-messaging providers;
- authentication, identity, and account-security providers;
- customer support, ticketing, and communications providers;
- analytics, logging, monitoring, and security vendors, if and when used;
- professional advisers such as lawyers, auditors, insurers, and accountants;
- law enforcement, regulators, courts, or other third parties where required by law or necessary to protect rights, safety, or the Service;
- potential buyers, investors, lenders, or successor entities in connection with a merger, financing, acquisition, reorganization, or sale of assets; and
- internal personnel and administrators who need access to perform support, security, billing, or operational duties.
We may also disclose information at your direction or with your consent.
9. International Transfers
We and our service providers may process personal data in the United States and other countries where we or our vendors operate.
If applicable law restricts cross-border transfers, we will rely on an approved transfer mechanism, such as:
- an adequacy decision;
- standard contractual clauses or equivalent contractual safeguards; or
- another lawful transfer mechanism recognized by applicable law.
If you want more information about applicable transfer safeguards, contact [email protected].
10. Data Retention
We retain personal data for as long as reasonably necessary for the purposes described in this policy, including to operate the Service, maintain security, comply with law, resolve disputes, and enforce our agreements.
Where the current business requirements define a specific launch retention window, we expect the following baseline rules:
- request logs: up to 30 days;
- customer usage history: up to 30 days;
- API key metadata: up to 60 days;
- billing records: up to 60 days for customer-facing visibility, while underlying legally required business records may be retained longer where required;
- admin audit logs: up to 180 days;
- deleted accounts: anonymized after 30 days rather than immediately hard-deleted.
For the prelaunch waitlist, we retain your email for as long as reasonably necessary to manage access requests, send relevant launch or access-related communications, prevent abuse, maintain suppression records, or comply with law, unless you ask us to delete it earlier and no exception applies.
Retention can be longer where needed for:
- fraud prevention or abuse investigations;
- chargebacks, refunds, and billing disputes;
- legal claims or regulatory obligations;
- security incident response;
- backup integrity, disaster recovery, or auditability.
Because the detailed field-level anonymization matrix is still an open business/legal work item, final deletion and anonymization behavior must be reviewed again before publication.
11. Data Security
We use administrative, technical, and organizational measures designed to protect personal data appropriate to the nature of the Service and the risks involved. These measures may include access controls, credential protection, hashing or tokenization where appropriate, environment-level controls, logging, abuse prevention, and monitoring.
No security measure is perfect, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and API keys and for using the Service in a secure manner.
12. Your Rights and Choices
Depending on where you live and subject to applicable law, you may have the right to:
- know whether we process your personal data;
- access personal data we hold about you;
- correct inaccurate personal data;
- delete personal data;
- restrict or object to certain processing;
- receive a portable copy of certain data;
- withdraw consent where processing is based on consent;
- opt out of certain disclosures or uses where applicable law provides that right; and
- complain to a supervisory authority or privacy regulator.
To exercise a privacy right, contact us at [email protected] or use any designated privacy-request method we make available. We may need to verify your identity before fulfilling a request. Verification requirements may depend on the sensitivity of the request and the relationship you have with us.
We may deny or limit a request where permitted by law, including where we cannot verify your identity, the request concerns data exempt from disclosure, or retention is required for legal, security, billing, or operational reasons.
13. GDPR / UK GDPR Supplemental Information
If GDPR or UK GDPR applies to our processing of your personal data:
- you have the rights described in Section 12 to the extent available under applicable law;
- you may lodge a complaint with the supervisory authority in your habitual residence, workplace, or place of the alleged infringement;
- we are required to provide clear information about our identity, purposes, lawful bases, recipients, retention periods, transfers, and rights; and
- where we obtain personal data from a source other than you, we will provide the additional source-related transparency required by applicable law.
We do not currently intend to use solely automated decision-making that produces legal or similarly significant effects in the privacy-law sense. We do, however, use automated tooling for security, spam prevention, rate limiting, fraud detection, and service integrity, which may temporarily block or delay some actions.
14. U.S. State Privacy Rights, Including California
Depending on your state of residence and the applicability thresholds of the relevant law, you may have rights such as the right to know, access, correct, delete, obtain portability, opt out of sale or targeted-advertising-related sharing, appeal certain denials, and receive non-discriminatory treatment for exercising your rights.
As of the effective date of this draft:
- we do not sell personal information for money;
- we do not share personal information for cross-context behavioral advertising;
- we do not knowingly use or disclose sensitive personal information to infer characteristics about you; and
- we do not currently provide public advertising trackers on the marketing site for cross-site behavioral profiling.
If you are a California resident, you may have rights under the California Consumer Privacy Act, as amended, including rights to know, correct, delete, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive equal treatment for exercising your rights, subject to the law's scope and exceptions.
California online tracking disclosures
California law also requires certain online privacy disclosures. As of the effective date:
- we do not currently respond differently to browser "Do Not Track" signals because there is no universally adopted standard for responding to them and because we do not currently engage in cross-site behavioral advertising or sale/share flows that would cause a different response on the public site;
- we do not knowingly allow third-party advertising networks to collect personal data on our public marketing site across different websites for their own behavioral advertising purposes; and
- if our practices later change in a way that requires opt-out handling under applicable law, we will update this policy and process applicable opt-out preference signals, such as Global Privacy Control, as required.
15. Communications Preferences
You can opt out of non-essential email communications by using the unsubscribe mechanism in the message or by contacting [email protected] or [email protected].
You cannot opt out of service-critical communications such as:
- account verification emails;
- password reset or security notices;
- billing notices;
- subscription status changes;
- receipts and refund confirmations; and
- important policy or service updates where notice is required.
16. Third-Party Services and Links
The Service may contain links to third-party websites, documentation, payment pages, or support tools. We are not responsible for those third parties' privacy practices. Review their privacy notices before providing data directly to them.
17. Children's Privacy
The Service is not directed to children, and our Terms of Service require users to be at least 18 years old.
We do not knowingly collect personal data from children under 13, and we do not intentionally design the Service for children. If you believe a child has provided personal data to us, contact [email protected] and we will review and address the report.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the Service, our processing practices, legal requirements, or vendor stack.
If we make a material change, we will post the updated policy and update the effective date. Where required by law, we will also provide additional notice, such as by email or in-product notice.
19. Contact Us
If you have questions, complaints, or privacy requests, contact:
Offermesh NetworkKyrenia, Mersin 10, Turkey[email protected][email protected]
If you are not satisfied with our response, you may have the right to complain to a relevant supervisory authority, state regulator, or attorney general, depending on where you live.