Privacy Policy
How OloLand collects, uses, protects, and retains information across its acquisition platform and marketing site.
Last updated: August 21, 2026
Encrypted in transit and at rest
End-to-end encryption protects your data in transit and at rest.
Access controls and audits
Strict access controls and authentication, with regular security audits and penetration testing.
Retention you control
Data is retained while your account is active or as needed to provide services; you can request deletion at any time.
1. Information We Collect
We collect information you provide directly to us, such as when you create an account, use our services, or contact us for support. This may include:
- Name and email address
- Company information
- Payment information
- Documents you upload to our platform
- When you use iOS Scout: a location or business name you submit on an explicit action, sent to Google Maps Platform / Places; and, if you Watch a result, precise coordinates, accuracy, capture time, and your authenticated user ID stored in your company's shared sourcing ledger
- Optional storefront photos you share in Scout, analyzed transiently with Google Gemini on Vertex AI and not retained after analysis
- Usage data and optional analytics when you consent
Scout's business lookup is delivered through Google Maps Platform, so your use of it is also subject to the Google Maps Platform Terms of Service, and Google's own handling of the data Scout sends it is described in the Google Privacy Policy.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process transactions and send related information
- Send technical notices and support messages
- Respond to your comments and questions
- Analyze usage patterns to improve user experience
3. Analytics and Your Choice
Optional analytics on the OloLand marketing site remain off until you select Allow analytics. If you consent, we use Google Analytics and Google Ads tags, Cloudflare Web Analytics, and PostHog to understand page visits, referring campaigns, and selected conversion actions.
Our marketing-site PostHog configuration disables autocapture, session recording, surveys, feature flags, heatmaps, exception capture, and performance capture. Behavioral events exclude form contents, uploaded documents, email addresses, phone numbers, passwords, access tokens, and raw error messages. Security tools such as Cloudflare Turnstile may still operate as essential services.
Allowing measurement does not enable personalized advertising or enhanced-conversion user data. Those Google consent signals remain denied in the marketing-site implementation.
You can decline analytics without losing access to the site and can change or withdraw your choice at any time. Withdrawal stops future collection and clears OloLand marketing attribution plus vendor analytics persistence that the site can access.
4. Connected AI Tools
You may connect OloLand to third-party AI tools such as ChatGPT, Claude, or Codex. When you invoke an OloLand tool from a connected service, OloLand receives the authenticated tool request and returns the deal information needed to answer it. Depending on the tool you choose, this can include deal names and status, financial summaries, risk findings, assumption-control status, analysis progress, or summary tiles.
The public ChatGPT plugin exposes a curated read-only subset. It does not expose raw document-search tools, write or approval actions, pricing payloads, or full document downloads. OloLand keeps server-side audit records such as the connected OAuth client, tool name, deal scope, result status, latency, and credit usage for security, compliance, and support; access tokens and document contents are not stored in those audit records.
Information returned to a connected AI service is then processed under your account, workspace, plan, settings, and data terms with that provider. Those terms may differ from OloLand's, including provider retention and model-improvement settings. Disconnecting the integration revokes refresh access; an existing access token can remain valid for up to one hour before it expires. Disconnecting does not delete copies already retained in the third-party service; use that provider's controls to manage its copies and contact OloLand separately for OloLand account-data requests.
5. Data Security
We implement industry-standard security measures to protect your data:
- End-to-end encryption for data in transit and at rest
- SOC 2 Type II program in progress
- Regular security audits and penetration testing
- Strict access controls and authentication
6. Data Retention
We retain your data for as long as your account is active or as needed to provide services. You can request deletion of your data at any time by contacting us. Account deletion unlinks Scout capture rows from your user ID and clears stored coordinates, accuracy, and location source; the capture record itself remains on the workspace until that company is deleted. Archiving a watchlist does not delete those rows. Company deletion cascades Scout captures and related ledger rows.
7. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Export your data
- Opt out of marketing communications
- Decline or withdraw optional marketing-site analytics
8. Contact Us
If you have questions about this Privacy Policy, please contact us at:
privacy@ololand.ai