Legal Agreement

Privacy Policy

Last updated: July 09, 2026. This policy outlines how OptiDrive collects, processes, and stores data.

1. Introduction and Scope

OptiDrive ("we", "us", or "our") respects your privacy and is committed to protecting your personal data and uploaded media assets. This Privacy Policy explains how we collect, process, share, and protect your information when you register for an account, access our dashboard, or utilize our global image optimization APIs and content delivery networks (CDN).

2. Information We Collect

We collect several types of information to provide high-performance asset delivery services: • Account Credentials: Name, email address, password hashes, and profile avatars. • Billing & Payment Data: Payment methods and subscription histories processed securely via Stripe. We do not store full credit card details on our servers. • Media Files & Assets: Images, vectors, and other files uploaded to our cloud buckets. For "Bring Your Own Storage" (BYOS) accounts, we do not store master assets but temporarily cache processed assets. • Technical Metadata: File sizes, mime-types, optimization rates, original file names, image dimensions, and URL paths. • API & Client Logs: Request IP addresses, HTTP headers, request paths, API keys used, bandwidth consumption, and response statuses.

3. Legal Basis for Processing (GDPR/CCPA)

If you reside in the European Economic Area (EEA) or California, our processing of your data is grounded on: (a) Performance of a contract to deliver our optimization services; (b) Compliance with legal obligations (e.g. tax laws); and (c) Our legitimate business interests, including service security, prevention of API key abuse, and performance analytics.

4. Data Retention and Deletion Policy

We adhere to strict data minimization guidelines: • Account Data: Maintained as long as your account remains active. Upon workspace deletion, account details are purged within 30 days. • Master Media Files: Retained until you trigger a deletion via our API or Dashboard. Once deleted, files are immediately scheduled for permanent erasure from physical cloud buckets within 24 hours. • Edge CDN Cache: Optimized copies cached at global edge locations expire based on your cache headers or can be purged instantly using the Cache Purge API. • Access Logs: Security and performance logs are rotated and deleted automatically after 90 days.

5. Security of Your Credentials & Data

We implement industry-standard security protocols to protect your workspace settings and credentials. All traffic to our API gateways and control panels is encrypted using TLS (HTTPS). S3 storage credentials (access keys, secrets) for BYOS configurations are encrypted at rest using AES-256 algorithms. Developer API keys are stored in hashed formats to prevent unauthorized read access.

6. Sharing & Third-Party Processors

We do not sell, rent, or trade your personal data or uploaded media assets. We only share information with trusted sub-processors necessary to run the platform: • Infrastructure Providers: Cloud hosting and object storage providers (e.g., AWS, Neon, Vercel). • Payment Gateways: Stripe, for billing and processing subscriptions. • Communication Tools: Email delivery servers (e.g., Resend, Nodemailer) for system warnings and transaction updates.

7. Your Rights and Choices

Depending on your location, you hold legal rights regarding your information: the right to access the personal data we hold about you, request corrections, request deletion, limit processing, or request a portable copy of your account profile. To exercise these rights, please contact our support desk at troutundefined5894@gmail.com.