Privacy Policy
Last updated: January 21, 2026
1. Introduction
Odyssai Systems Ltd. ("Odyssai Systems," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our websites and services.
Odyssai Systems Ltd. is a company incorporated in British Columbia, Canada, and serves as the data controller for your personal information.
This policy applies to all services operated by Odyssai Systems, including TabiWay, AssetWorthIQ, and odyssaisystems.com.
Quick Summary
- What we collect: Email, name, account data, usage analytics (with consent)
- Why: To provide our services, process payments, improve user experience
- Who we share with: Payment processors, hosting providers (not sold to third parties)
- Your rights: Access, correction, deletion, portability, withdraw consent
- Contact: privacy@odyssaisystems.com
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address, name, and password when you register
- Profile Information: Any additional information you choose to provide
- Payment Information: Billing details processed securely by our payment processor (Stripe)—we do not store credit card numbers
- Communications: Messages you send us via contact forms or email
- Service-Specific Data: Information required for specific services (e.g., travel preferences for TabiWay)
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, timestamps, and interactions (with consent)
- Device Information: Browser type, operating system, device type, screen resolution
- Log Data: IP address, access times, referring URLs
- Cookies: See Section 6 for detailed information on cookies
2.3 Information from Third Parties
- Social Login: If you sign in via Google or other OAuth providers, we receive your name and email
- Payment Processors: Transaction confirmation and billing details from Stripe
3. How We Use Your Information
We use your information for the following purposes:
- Service Delivery: Provide, operate, and maintain our services
- Account Management: Create and manage your account, authenticate users
- Payment Processing: Process transactions and send billing communications
- Communication: Respond to inquiries, send service updates and security alerts
- Personalization: Customize content and recommendations based on your preferences
- Analytics: Understand usage patterns and improve our services (with consent)
- Security: Detect, prevent, and address fraud and security issues
- Legal Compliance: Comply with legal obligations and protect our rights
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process your personal data based on the following legal grounds:
- Contract: Processing necessary to provide our services when you create an account
- Consent: For analytics cookies, marketing communications, and optional data processing—you can withdraw consent at any time
- Legitimate Interest: For fraud prevention, security, service improvement, and business operations
- Legal Obligation: When required by applicable laws or regulations
5. Data Sharing and Disclosure
We share your information with the following categories of recipients:
Service Providers
- Supabase: Authentication and database hosting (EU/US servers)
- Stripe: Payment processing
- Vercel: Website hosting and deployment
- Google Analytics: Usage analytics (with consent only)
- Anthropic (Claude AI): AI-generated content (only service preferences, not personal identity)
- Formspree: Contact form submissions
Other Disclosures
- Legal Requirements: When required by law, court order, or government request
- Protection of Rights: To protect our rights, property, or safety
- Business Transfers: In connection with a merger, acquisition, or sale of assets
We do not sell your personal information to third parties.
6. Cookies and Tracking Technologies
Essential Cookies
Required for our services to function. These include authentication session cookies. You cannot opt out of essential cookies.
Analytics Cookies
We use Google Analytics 4 to understand how users interact with our services. These cookies are only set with your consent. You can change your preferences at any time through our cookie banner or browser settings.
Local Storage
We use browser localStorage to save preferences and form progress locally on your device. This data is not transmitted to our servers.
Managing Cookies
You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of our services.
7. Data Retention
We retain your information for the following periods:
- Account Data: As long as your account is active, plus 30 days after deletion request
- Service Data: Up to 2 years after account closure, or as required for legal/business purposes
- Payment Records: 7 years for tax and accounting compliance
- Analytics Data: Anonymized after 26 months (Google Analytics default)
- Contact Inquiries: 2 years from the date of communication
8. Your Privacy Rights
Depending on your location, you may have the following rights:
For All Users
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data ("right to be forgotten")
- Withdraw Consent: Withdraw consent for analytics or marketing at any time
Additional Rights (EU/UK GDPR)
- Portability: Receive your data in a machine-readable format
- Restriction: Request restriction of processing in certain circumstances
- Object: Object to processing based on legitimate interests
- Automated Decisions: Not be subject to purely automated decision-making with legal effects
- Complaint: Lodge a complaint with your local supervisory authority
California Residents (CCPA/CPRA)
- Know: Right to know what personal information is collected
- Delete: Right to request deletion of personal information
- Opt-Out: Right to opt out of sale/sharing (we do not sell personal information)
- Non-Discrimination: Right not to be discriminated against for exercising your rights
Response Time: We respond to all data subject requests within 30 days (or 45 days for complex requests under CCPA).
To exercise your rights, contact us at privacy@odyssaisystems.com
9. International Data Transfers
Your information may be transferred to and processed in countries outside your country of residence, including Canada and the United States, where our servers and service providers are located.
For transfers from the EEA/UK, we rely on:
- Standard Contractual Clauses (SCCs): EU-approved data transfer agreements
- Data Processing Agreements: With all our service providers
- Adequacy Decisions: Where applicable (Canada has been deemed adequate by the EU for commercial transfers)
10. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption in transit (TLS/HTTPS) and at rest
- Secure authentication mechanisms
- Regular security assessments
- Access controls and logging
However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
11. Children's Privacy
Our services are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us immediately and we will delete it.
12. Do Not Track Signals
Some browsers transmit "Do Not Track" (DNT) signals. We currently do not respond to DNT signals, as there is no industry-standard interpretation. However, you can control tracking through our cookie consent mechanism.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on our website
- Updating the "Last updated" date
- Sending an email notification for significant changes (if you have an account)
Your continued use of our services after such changes indicates acceptance of the updated policy.
14. Contact Information
For privacy-related questions, to exercise your rights, or to file a complaint:
Odyssai Systems Ltd.
British Columbia, Canada
Privacy inquiries: privacy@odyssaisystems.com
General inquiries: support@odyssaisystems.com
EU/UK Supervisory Authorities
If you are in the EU/EEA or UK and are unsatisfied with how we handle your data, you have the right to lodge a complaint with your local data protection authority: