C
OCCEAN
Contact
Legal

Privacy Policy

Privacy is not a feature — it's the foundation of the Executive Operating System. This policy explains what we collect, how we use it, and the rights you have.

Last updated · March 12, 2026Version · 3.4Reading time · 14 min read

1. Information We Collect

We collect only what is necessary to operate OCCEAN and to help Commerce Brain™ make better executive decisions for your business.

  • Account information — name, email, role, organization, authentication metadata.
  • Business metrics — revenue, profit, cash, inventory, marketing spend, and other KPIs you connect.
  • Commerce data — products, orders, customers (pseudonymized), fulfillment, and returns via connected platforms such as Shopify.
  • Analytics — aggregated performance from ad networks and analytics tools you connect.
  • Cookies — see our Cookie Policy.
  • Device information — browser, OS, IP address, session logs used for security and diagnostics.
  • Payment information — handled by our PCI-DSS Level 1 payment processor; we never store full card numbers.

2. How We Use Information

  • Operate and secure the Service.
  • Generate executive recommendations and Commerce Brain™ output tailored to your business.
  • Send transactional emails, product updates, and (with consent) marketing.
  • Detect fraud, abuse, and security incidents.
  • Meet legal and regulatory obligations.

3. AI Processing

Decision Memory™

Your Decision Memory (private layer) — the private context that trains Commerce Brain™ for your business — is isolated per organization, encrypted at rest, and never mixed with Decision Memory (anonymous layer).

Anonymous, aggregated patterns may improve the platform for everyone. We never sell your data and we never use identifiable business data to train third-party foundation models.

4. Data Retention

  • Active data is retained for the life of your subscription.
  • Backups are retained for 35 days.
  • Upon account deletion, personal and business data is purged within 30 days, except where retention is legally required (e.g. tax records for 7 years).

5. Third-party Services

We use trusted subprocessors to operate the Service, including cloud hosting, payment processing, error tracking, and AI model providers. Subprocessors are contractually bound to comparable privacy and security terms.

A live list is available on request at privacy@occean.com.

6. Your Rights

Depending on your jurisdiction (including GDPR and CCPA), you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate personal data.
  • Delete your account and associated personal data.
  • Export your data in a portable, machine-readable format.
  • Object to or restrict certain processing.
  • Withdraw consent at any time.

Exercise any of these from your profile or by emailing privacy@occean.com.

7. Security

We encrypt data in transit (TLS 1.3) and at rest (AES-256), enforce role-based access, log every privileged action, and run continuous vulnerability scans. See our Security & AI Transparency page for details.

8. Children's Privacy

OCCEAN is not directed to children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided personal data, contact us and we will delete it.

9. International Transfers

OCCEAN is operated from the United States. If you access the Service from outside the U.S., your data may be transferred to and processed in the U.S. under Standard Contractual Clauses or equivalent safeguards.

10. Contact

Data Protection Officer

OCCEAN, Inc. — 2261 Market Street, San Francisco, CA 94114, USA

privacy@occean.com