Legal
Privacy Notice
Effective September 14, 2026
1. Who we are and what this notice covers
This Privacy Notice explains how Croft Crafts, LLC ("Croft Crafts," "we," "us," or "our") collects, uses, discloses, retains, and protects information in connection with OpportunityOps Social Outreach, including its public website, authenticated business workspaces, campaign tools, connected-service integrations, billing features, support channels, and related services (collectively, the "Service"). It also explains choices available to account holders and other individuals whose personal information we process.
2. Business workspaces and customer-controlled data
OpportunityOps is designed primarily for business users. A customer workspace may contain information about the customer's business, personnel, clients, prospects, audiences, or other people. For account administration, billing, security, support, and operation of the Service, we determine why and how certain information is processed. For Customer Content that a business customer submits and directs us to process, publish, or transmit, we generally process that information to provide the requested Service functions on the customer's instructions. If you are an individual whose information was placed in OpportunityOps by one of our business customers, that customer may be the appropriate first contact for a request concerning its Customer Content.
3. Categories of information we process
Depending on how the Service is used, we may process the following categories:
- Account and identity information: name, business or organization name, email address, user ID, role, workspace membership, email-verification state, and authentication-related records.
- Workspace and Customer Content: campaign briefs, prompts, objectives, audiences, offers, calls to action, destination URLs, drafts, approved versions, schedules, uploaded images or video, source files, brand instructions, notes, and other content submitted to or generated through the Service.
- Connected-service information: platform type, external account identifiers or names, connection state, granted permissions, publishing status, revocation state, and provider credentials or authorization tokens needed to maintain an authorized connection.
- AI and generation information: prompts, campaign context, selected options, source media, generated text or media, provider request information, and technical records needed to complete, validate, or troubleshoot a requested generation.
- Publishing and evidence information: approval records, publishing jobs, provider responses, external post or delivery identifiers, result status, timestamps, diagnostics, and evidence needed to show what was requested and what happened.
- Billing information: billing email, Stripe customer and subscription identifiers, plan or price identifier, subscription status, trial and billing-period dates, invoice identifiers, payment status, and cancellation state. Complete payment-card credentials are collected and processed by Stripe and are not intended to be stored by OpportunityOps.
- Device, session, and technical information: authentication cookies or session data, browser or device information made available in ordinary web requests, IP-derived security information, request identifiers, application logs, error records, and diagnostics used to operate and protect the Service.
- Communications and support information: messages, support requests, billing questions, security reports, and other communications you send to us.
4. Where information comes from
We receive information directly from you and other authorized workspace users; automatically from your use of the Service and its security or session mechanisms; from connected social networks and other services you authorize; from payment, authentication, hosting, storage, AI, email, and infrastructure providers that support the Service; and from public or customer-directed sources when a feature is expressly used to retrieve or analyze that information.
5. How we use information
We use information as reasonably necessary to:
- create, verify, authenticate, and administer accounts and workspaces;
- provide campaign creation, generation, transformation, review, approval, publishing, scheduling, evidence, export, and account-management functions requested by customers;
- connect to authorized third-party accounts and perform authorized actions;
- process subscriptions, billing status, invoices, cancellations, and account entitlements;
- preserve customer work, workflow state, approvals, and delivery evidence;
- detect, prevent, investigate, and respond to fraud, abuse, security events, unauthorized access, duplicate actions, and operational failures;
- troubleshoot, maintain, test, secure, and improve the Service and its reliability;
- provide customer support and respond to privacy, security, billing, and legal requests;
- comply with law, enforce our agreements, establish or defend legal claims, and protect customers, third parties, and the Service.
6. Artificial-intelligence processing
When you choose an AI feature, OpportunityOps may send the campaign information, prompt, instructions, selected settings, and source text or media reasonably needed to fulfill that request to an AI service provider. Current managed generation functions include provider-backed text and image generation. The Service may also support a customer-provided API credential, in which case the requested generation is submitted using that customer-authorized provider relationship.
OpportunityOps does not use Customer Content to train an OpportunityOps general-purpose foundation model. Third-party AI providers process information under their own contractual, privacy, security, abuse-prevention, and retention rules. Where a provider supports a non-storage or reduced-retention request for a function, we may configure the integration to use it, but we do not promise that a provider retains no operational, safety, or legally required records. Do not submit regulated or highly sensitive information to an AI feature unless the feature is expressly designed for it and you are authorized to do so.
7. Connected platforms and publishing
When you connect a social network or other external service, OpportunityOps may store connection metadata and protected authorization material needed to maintain the connection and perform actions you request. When you approve or instruct a publication, we transmit the approved content and required metadata to the selected provider. That provider then processes the information under its own terms and privacy practices. Disconnecting or deleting OpportunityOps does not necessarily delete content, analytics, messages, or account records already held by the third-party provider. Provider-held information must be managed through that provider's controls where OpportunityOps cannot control it.
8. Payments and Stripe
Stripe processes checkout, payment methods, recurring subscription charges, invoices, receipts, and the customer billing portal. OpportunityOps receives and stores billing-state information needed to administer access, such as Stripe customer and subscription identifiers, billing email, plan or price identifier, payment status, invoice identifier, trial dates, billing-period dates, and cancellation state. OpportunityOps is not intended to receive or store complete payment-card numbers or card security codes.
9. Cookies, browser storage, and similar technology
The Service uses cookies and similar browser storage that are reasonably necessary for authentication, session continuity, security, preferences, registration continuity, and application functionality. For example, authenticated sessions use provider-backed session cookies, and limited same-browser registration state may be stored temporarily to help complete account setup. OpportunityOps does not currently use third-party advertising cookies to build cross-site behavioral advertising profiles. Browser or provider settings may allow you to control some storage, but disabling essential storage can prevent authentication or other Service functions from working.
10. When we disclose information
We may disclose information in the following circumstances:
- Service providers and processors: to vendors that provide hosting, infrastructure, authentication, database, storage, payment, AI, email, security, monitoring, or related technical services, subject to the role they perform for us.
- Connected services: to social networks, AI providers, and other destinations or services you authorize us to use for a requested action.
- Workspace users: to authorized users of the same workspace when needed for collaboration, administration, review, publishing, or account management.
- Legal, safety, and security: when we reasonably believe disclosure is necessary to comply with law or valid legal process, protect rights or safety, investigate abuse or fraud, enforce agreements, or defend legal claims.
- Business transactions: in connection with a financing, merger, acquisition, reorganization, bankruptcy, or sale of all or part of the relevant business or assets, subject to applicable confidentiality and legal requirements.
- With your direction or consent: when you ask us to disclose information or otherwise authorize the disclosure.
11. Sale of personal information and targeted advertising
OpportunityOps does not sell personal information for money and is not designed to use personal information for third-party cross-context behavioral advertising. We do not treat the customer-directed transmission of content to a connected platform, or the use of a processor to provide the Service, as a sale of personal information by OpportunityOps. If our practices materially change in a way that creates an opt-out or consent right under applicable law, we will update this notice and provide the required choice before applying that change where the law requires it.
12. Data retention
We retain information for as long as reasonably necessary for the purposes described in this notice, including maintaining an active workspace, preserving customer work and publishing evidence, administering subscriptions, securing the Service, resolving failures or disputes, and meeting legal obligations. Retention varies by record type. When an account is deleted, the deletion workflow is designed to erase applicable workspace records and stored customer files and to remove unshared authentication accounts, while preserving only limited material that is reasonably necessary to complete or prove deletion, prevent fraud, protect security, resolve disputes, or satisfy law. Temporary deletion-verification records are subject to retention controls and scheduled purging. Third parties may retain information independently under their own policies.
13. Security
We use administrative and technical measures intended to protect information against unauthorized access, use, alteration, or disclosure. These include authenticated workspace access, authorization checks, restricted service credentials, protected storage for provider credentials, private storage for applicable customer media, validation controls, operational logging, and deletion controls. Provider access tokens, API keys, and other secrets are excluded from ordinary customer exports. No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your account or information has been compromised, contact us promptly.
14. Your account tools and privacy choices
Account holders can correct certain account or workspace information through the Service, manage connected accounts, manage subscription billing through Stripe, and use supported owner tools to export or delete the account. Workspace owners may download a structured account export containing supported account, workspace, campaign, publishing, and connection information. The export intentionally excludes provider access tokens, API keys, encrypted credentials, minimal deletion-verification material, and third-party data that OpportunityOps does not store.
You may also request access, correction, deletion, or another privacy action by contacting us at the address below. We may verify your identity and authority before acting. Depending on where you live and whether an applicable privacy law covers our processing, you may have additional rights such as confirmation of processing, access, correction, deletion, portability, or the right to opt out of certain sale, sharing, targeted-advertising, or profiling practices. Statutory rights and exceptions vary, and some privacy laws apply only when specified thresholds are met. We will not unlawfully discriminate against you for exercising an applicable privacy right. If applicable law gives you a right to appeal our response, you may appeal by replying to the response or contacting us again with the subject "Privacy Appeal."
15. Permanent account deletion
The workspace owner may initiate permanent account deletion through supported account tools. The deletion workflow is designed to address applicable workspace records, stored customer files, billing-customer cleanup, stored provider credentials, and unshared authentication accounts. A deletion may temporarily remain pending if an external or internal cleanup step cannot safely complete and must be retried. OpportunityOps may preserve a minimal deletion-verification record until its retention period expires. Deletion from OpportunityOps does not erase copies already published to or independently retained by connected platforms or other third parties.
16. International processing
OpportunityOps is operated from the United States. If you access the Service from another country, information may be transferred to and processed in the United States or other jurisdictions where our service providers operate. Those jurisdictions may have different data-protection laws from your location. Where applicable law requires a particular transfer mechanism or safeguard, we will use a legally recognized mechanism appropriate to the processing.
17. Children
The Service is intended for business users who are at least 18 years old and is not directed to children. We do not knowingly create OpportunityOps accounts for children under 18. Customers should not intentionally submit children's personal information unless they are legally authorized to do so and the Service feature is appropriate for that processing. If you believe a child's information has been submitted improperly, contact us so we can review the request.
18. Changes to this notice
We may update this Privacy Notice as the Service, providers, law, or our data practices change. The effective date above identifies the current version. We will post updated terms here and provide additional notice or obtain consent when applicable law requires it for a material change. A revised notice does not retroactively authorize a materially different use of previously collected information when the law requires new consent.
19. Contact and privacy requests
Questions, security reports, or privacy requests may be sent to support@opportunityops.net. Please include enough information for us to understand the request, but do not send passwords, full payment-card numbers, API keys, or other account secrets by email.