Privacy Policy
This Privacy Policy explains how Fornax Ventures LLP (“we”, “us”, or “our”), which operates the Ocular platform, collects, uses, discloses, and protects information in connection with our SaaS platform (the “Service”) that provides e-commerce analytics by connecting to third-party platforms such as Shopify, Amazon (via the Selling Partner API), and Google Analytics (GA4), and other integrations. This Policy applies to information collected through our website, the Service, and related communications.
Last updated · 5 August 2026
1. Controller & Contact
Data controller: Fornax Ventures LLP
Privacy contact: dev@ocular.dev
For questions about this Policy or to exercise your rights, please contact the address above.
2. What information we collect
We collect the following categories of data to provide analytics and reporting services:
- Account & contact information — name, email, company name, billing contact, role and any credentials you provide when creating an account.
- Connected platform data — data imported from connected platforms (for example Shopify, GA4, ad platforms, payment processors). This may include store metadata, order and transaction details, product catalog, customer records, customer identifiers (email, customer ID), shipping & billing addresses, refunds, coupons, subscription statuses, event-level analytics and event parameters provided by GA4. We only access scopes you authorize.
- Usage & technical data — logs, IP address, device and browser information, cookies and similar tracking data, and Service usage metrics.
- Aggregated & derived data — aggregated, de-identified, or derived analytics we produce from the data you provide (e.g., cohort definitions, revenue attribution summaries).
- Payment & billing data — billing name, billing address, payment method metadata processed via our payment processor (we do not store full card numbers).
3. How we collect data
- You provide account and billing info when signing up.
- You connect third-party services (Shopify, GA4, advertising platforms) via OAuth or API keys — we import the data necessary to provide analytics.
- We collect usage data automatically when you use the Service (logs, cookies).
4. How we use personal data
We use personal data to:
- Provide, operate, maintain, and improve the Service (including analytics, dashboards, and reporting).
- Authenticate and administer accounts and process payments.
- Communicate with you about Service updates, security notices, and billing.
- Detect and prevent fraud, abuse, and security incidents.
- Perform research and product development using aggregated/de-identified data.
- Comply with legal obligations and respond to lawful requests.
5. Connectors & third-party platforms (Shopify, GA4, etc.)
When you connect a third-party service:
- You authorize us to access data via the APIs/scopes you approve. We request the minimum scopes needed to deliver the Service.
- Connected-platform data may contain personal data about your customers (orders, emails, addresses). You remain the controller of your customers’ personal data; we act as a processor on your behalf. You must ensure you have the lawful basis or permission required to share that data with us.
- You can revoke the connection at any time via the third-party platform or our app settings; revoking may limit our ability to provide the Service.
6. Google user data
Our application connects to your Google account via Google OAuth to run the data workflow you configure: reading business data from your email and writing results to your Google Sheets. We access Google user data only to the extent needed to provide these user-facing features.
What we access:
- Gmail (read-only, gmail.readonly): we read emails that originate from supported business and commerce platforms only (e.g. Amazon, Flipkart, Meesho), restricted to a maintained allowlist of sender domains. These are used to fetch automated performance reports and retrieve sales, inventory, and revenue data delivered by email. We do not access personal correspondence, emails from non-platform senders, or any email unrelated to business reporting.
- Google Sheets / Drive: to write and upload the processed results to the spreadsheets you select.
We do not access Contacts, Calendar, or any other Google Workspace data beyond the scopes above.
How we share, transfer, or disclose it: We do not sell, rent, or share your Google user data — including email content — with any third parties for purposes other than providing the workflow you requested. The only sub-processor that handles this data is Amazon Web Services (AWS), which provides encrypted hosting and processing on our behalf; no other third party has access to your Google data or OAuth tokens. We disclose data only where required by law.
How we use it: Exclusively to execute the workflow you set up — business analytics, report generation, and syncing results to your Sheets. We do not use Google user data for advertising, profiling, or to train or improve AI/ML models, and humans do not read your email content except as required for security or to comply with law.
Protection & retention: OAuth tokens are stored encrypted (AES-256) on AWS and transmitted over TLS 1.2+, scoped to the minimum permissions required. You can disconnect at any time, which revokes tokens and stops all further access; you may request deletion of stored data at dev@ocular.dev.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. Amazon Selling Partner data & Acceptable Use Policy
When you connect your Amazon Selling Partner account, Ocular accesses Amazon data through Amazon’s Selling Partner API (SP-API) via secure OAuth, only to the extent needed to deliver the analytics and reporting you configure. Our handling of this data complies with Amazon’s Acceptable Use Policy (including Sections 4.4 and 4.5) and Amazon’s Data Protection Policy. Ocular is operated by Fornax Ventures LLP.
Acceptable Use Policy commitments:
- Section 4.4 (No data aggregation): We do not use Amazon data obtained through the Selling Partner API to aggregate data across Selling Partners’ businesses or Amazon customers to provide or sell to any parties, including competing Selling Partners.
- Section 4.5 (No insights about Amazon’s business): We do not use Amazon data to calculate insights about Amazon’s business, nor to promote or publish insights about Amazon’s business publicly or through paid services, including within the Service itself.
What we access (only when you authorize it via Amazon’s OAuth flow):
- Seller account metrics and performance data.
- Product listings and catalog details.
- Orders, inventory, and pricing information.
- Brand Analytics reports (for example Search Terms, Market Basket, Repeat Purchase) where your API role and authorization permit.
We request the minimum access needed to deliver the features and reports you set up.
How we share it: We do not sell or rent Amazon Information, and we never share it with outside parties for marketing, advertising, or resale. We share it only with the sub-processors that host and process it on our behalf (Amazon Web Services), with Amazon’s Selling Partner API as required to run the workflow you authorized, and with regulatory authorities where required by law.
Protection: Amazon Information is encrypted in transit (TLS 1.2+) and at rest (AES-256), protected by token-based authentication and role-based access controls, and continuously logged and monitored. We maintain a formal Incident Response Plan; any security incident involving Amazon Information will be promptly reported to Amazon at security@amazon.com.
Your control: You can revoke Ocular’s access to your Amazon data at any time from Amazon Seller Central, which stops all further access. You may request deletion of stored Amazon data by contacting dev@ocular.dev.
8. Data retention & deletion
- We retain your account and connected data for as long as your account is active or as needed to provide the Service.
- After account termination or prolonged inactivity, we will retain backup copies for a limited period for fraud prevention, legal compliance, or legitimate business needs.
- You may request deletion of your account and associated data by contacting dev@ocular.dev. We will remove personal data unless retention is required by law or necessary for legitimate business purposes; if we cannot delete certain information we will notify you.
9. Your rights and access
If you would like access to, correction of, or deletion of your personal data that we hold, or to request a copy of your data in a portable format, contact dev@ocular.dev. We may require verification of identity before fulfilling requests.
10. Security
We implement industry-standard technical and organizational measures to protect personal data, including:
- Encryption in transit (SSL/TLS) and encryption at rest where feasible.
- Access controls, role-based permissions, and logging.
- Regular backups and incident response procedures.
- Security reviews and audits.
11. International data transfers
Your data may be processed or stored in countries other than where you or your customers reside. We take reasonable measures to protect data when transferred internationally and will use appropriate safeguards where required.
12. Cookies & tracking
We and our partners use cookies, local storage and similar technologies for functionality, analytics, and advertising. These are set automatically when you visit the site so we can measure and improve it. You can control, block or clear cookies through your browser settings.
13. Data Processing Agreement (DPA)
We will enter into a Data Processing Agreement upon request for enterprise customers. The DPA will specify subprocessors, security obligations, data subject request procedures, and transfer safeguards. The DPA is available upon request and is incorporated into our Terms of Service for customers who sign it.
14. Law enforcement & legal compliance
We may disclose data to law enforcement, courts, or regulators where required by law or necessary to protect our rights, property, or safety, or the rights and safety of others.
15. Marketing & communications
We may contact you with product updates, marketing materials, and service announcements if you have consented or where permitted by law. You can opt out of marketing emails by following the unsubscribe link in those messages or by contacting dev@ocular.dev.
16. Changes to this policy
We may update this Policy from time to time. Material changes will be notified via our Service or by email with the revised effective date.
17. How to contact us
Privacy contact: dev@ocular.dev
If we are unable to resolve your complaint, you may have the right to raise concerns with local authorities as applicable.