Legal

Privacy Policy

This Privacy Policy explains how Overapt, Inc. (“Overapt,” “we,” “us,” or “our”) collects, uses, and shares information in connection with overapt.com and the Overapt platform (the “Service”). It is intended for business customers and website visitors.

1. Who we are

Overapt, Inc. is a company registered in the State of Texas. For privacy questions, contact admin@overapt.com.

2. Information we collect

Account and contact information

When you request access, create an account, or contact us, we may collect name, email address, company name, role, and related business contact details. The Request Access form on overapt.com requires name, business, and email, and emails that submission to admin@overapt.com via Cloudflare Email Sending. We use Cloudflare Turnstile when it is configured, or a short signed human check, to reduce automated spam. Cloudflare may process technical signals such as IP address for that verification.

Workspace and customer data

When you use the Service, we process information you and your organization submit or connect, which may include operational data, configurations, files, messages, connector metadata, activity logs, and similar business content (“Customer Data”). Customer Data is processed to provide the Service to your organization.

Usage and technical data

We may collect device and browser information, IP address, approximate location derived from IP, pages viewed, referring URLs, timestamps, and diagnostic or security logs needed to operate and secure the Service.

Cookies and similar technologies

The marketing site at overapt.com does not set cookies or use localStorage. Typefaces are served from this site, not from a third-party font host. The authenticated product may use cookies or similar technologies for authentication, preferences, and session continuity.

3. How we use information

We use information to:

We do not sell personal information. We do not use Customer Data to train public foundation models for unrelated third parties.

4. AI processing and subprocessors

To deliver intelligence features, Overapt may send task-scoped excerpts of relevant context to model providers and infrastructure vendors (for example AI model providers and hosting or gateway services). Those providers process data as our processors to provide the Service.

Overapt is designed so model providers receive limited, purpose-bound context rather than unrestricted access to your full database. Privacy and security controls in the product may redact sensitive fields and record metadata about outbound AI calls. Exact controls available to you depend on your plan and configuration.

5. How we share information

We may share information with:

Workspace administrators may access Customer Data and account information within their organization according to roles they assign.

6. Retention

We retain information for as long as needed to provide the Service, meet legal obligations, resolve disputes, and enforce agreements. Customer Data retention generally follows your workspace lifecycle and applicable agreements. You may request deletion of account or contact information by emailing admin@overapt.com, subject to legal retention requirements.

7. Security

We implement administrative, technical, and organizational measures designed to protect information, including tenant isolation controls in the product architecture. No method of transmission or storage is completely secure; you are responsible for safeguarding account credentials and configuring access appropriately.

8. Your choices and rights

Depending on your location and role, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing. Business customers typically control Customer Data in their workspace; end-user requests regarding Customer Data should first go to the Customer organization.

To exercise a privacy request related to information Overapt controls as a business, email admin@overapt.com. We may need to verify your identity and relationship to the account.

If you are a California resident, you may have additional rights under the CCPA/CPRA regarding personal information we collect in a business context. We do not sell or “share” personal information for cross-context behavioral advertising as those terms are commonly defined.

9. International transfers

We and our providers may process information in the United States and other countries where we or they operate. Where required, we use appropriate transfer mechanisms.

10. Children

The Service is for business use and is not directed to children under 16. We do not knowingly collect personal information from children.

11. Changes

We may update this Privacy Policy from time to time. The “Effective date” will change when we do. Material changes will be posted on this page. Continued use of the Service after the effective date means you acknowledge the updated Policy.

12. Official Amazon / Amazon Information

Official Amazon is in application — not live on the product today. The following applies when Official Amazon is available and you authorize it for your selling account. “Amazon Information” means information Amazon releases to Overapt for that Authorized User through Selling Partner API.

Collect

We collect the name, business, and email you send through our forms. If you later use the Overapt application, we process account identifiers and workspace content you enter. If you authorize Official Amazon, we process Amazon Information for your selling account.

Use

We use this information to operate your Overapt workspace and to answer access or support requests. We do not use Amazon Information to build products for other sellers.

Store

We store information on United States infrastructure: the marketing site and application delivery on Cloudflare, the API on Fly.io, and the database on Neon. Amazon Information, when present, stays in that organization’s workspace.

Protect

We use TLS in transit and encryption at rest. Tenant isolation is designed so one seller cannot read another seller’s Amazon Information. Access roles are Owner, Admin, and Viewer. Restricted Mode can limit who sees sensitive divisions.

Share

We share Amazon Information only with the parties listed on Data Sharing, and only to run your workspace or as required by law.

Delete

Disconnect Official Amazon in Overapt or revoke Overapt in Seller Central to stop new pulls. Send a written deletion request to admin@overapt.com. We delete or de-identify workspace Amazon Information within 30 days, except records we must keep for security or law.

Models

When the application uses a model, the model receives task-scoped excerpts for your workspace. We do not use Amazon Information to train Overapt or third-party foundation models.

13. Contact

Overapt, Inc.
State of Texas
Email: admin@overapt.com

Related: Terms of Service · Data Sharing · Security