OREOASIS← Home
Effective 26 July 2026

Privacy

Oreoasis is run by Kashif Shahzad, sole proprietor, trading as Oreoasis (Pakistan). This page says exactly what we hold and what we do with it. The short version: we hold very little, because the product is designed to need very little. Content is hashed in your process before it reaches us; what gets published to a public log is hashes, never payloads.

What we hold

  • Your account — email address, optional display name, and when it was created.
  • Sign-in links — a hash of the link token, the email it was sent to, and its expiry. The link is single-use, expires in 15 minutes, and requesting a new one retires the old one.
  • Your organization — name, URL slug, plan, and its signing DID.
  • API keys — a hash of the key, plus its first 12 and last 4 characters so you can recognise it in the dashboard. We cannot recover a key; we can only revoke it.
  • Your receipts — the signed envelope you send us, its position in your hash chain, and its anchoring record. You choose what goes in a receipt.
  • Verify-page visits — the referrer and browser user-agent, and the time. We do not store the visitor's IP address.
  • Billing state — which plan you're on and whether it's active. Card details go to the Merchant of Record and never reach us.
  • A session cookie — a signed cookie so you stay logged in. It carries no tracking.

We use Plausible for site analytics — cookieless, no cross-site tracking, no consent wall. An accountability product that greeted you with a tracking-cookie banner would be self-refuting.

What we don't do

  • We don't sell or rent your data. Ever.
  • We don't train models on your receipts.
  • We don't advertise, and we run no advertising trackers.
  • We don't ask for your signing key — we don't need it, and we couldn't use it if we had it.

Who's the controller

For your account data, we're the controller. For the receipt payloads you send us, you are the controller and we are your processor — we store and serve what you submitted, on your instructions. We'll sign a data-processing agreement on request; ask at founders@oreoasis.com. The trust page lists our sub-processors.

Erasure — and the honest limit

This is the question every serious buyer asks, so here is the design, not a slogan:

  • Deletable on request: your account, your email, your organization's details, and the receipt payloads we store and display. Ask and we delete them.
  • Not deletable, by design: the cryptographic hashes and the chain positions — and anything already written to a public transparency log. Rekor cannot be erased. Nobody can retract a public timestamp, and a proof that could be silently withdrawn would not be a proof.
  • Why that's safe: the anchored, publicly-published fields are personal-data-free by construction. What we anchor is a hash of a hash chain. A hash of your data is not your data, and it can't be reversed into it.
  • Your part of the bargain: don't put personal data in a receipt payload. The SDK hashes content locally so you can prove what happened without publishing who it happened to. If you paste a customer's name into a receipt summary, that is a public statement you chose to make.

After an erasure, the verify link for an affected receipt keeps working and keeps telling the truth: the proof and chain position remain checkable, and the payload display is gone.

How long we keep things

Your plan's retention window (30 days on Free, 13 months on Pro, 3 years on Team) governs how far back you can pull your own history through the API, dashboard, and exports. It does not expire the public verify link — that is permanent, on every plan, including cancelled accounts. Account records are kept while the account exists; sign-in tokens expire in minutes.

If you lose access to your email

Your account is keyed to your email address, and sign-in is passwordless — so today there is no password to reset and no second factor. If you can no longer receive mail at that address, email us and we'll ask for evidence only the account owner would have (a working API key, the billing record, receipt numbers). If we can't verify it, we won't move the account — that is the same rule that stops someone else doing it to you. Either way, every receipt you have already issued stays permanently verifiable at its public link; losing the mailbox loses the console, not the evidence.

Your rights

Wherever you live, you can ask us for a copy of what we hold, ask us to correct it, ask us to delete it (subject to the honest limit above), or object to how we use it. Email founders@oreoasis.com — one human reads that inbox, and we aim to answer within 30 days. If you're in the EU or UK and we haven't resolved it, you can complain to your local data-protection authority.

Where data lives, and breaches

Data is processed by us and by the sub-processors listed on the trust page, which can mean transfers outside your country — we rely on standard contractual clauses where they apply. If a breach ever affects your data, we'll tell affected account holders and the relevant authority within 72 hours of becoming aware, with what we know and what we've done. Report a vulnerability at /security.txt.

Related: Terms · Refunds · Abuse & takedown · Trust