Privacy Policy for onPoint Studio
Effective Date: June 3, 2025
1. Introduction
onPoint Studio OÜ ("onPoint Studio," "we," "us," or "our") operates the website onpoint.to ("Site"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have over your data.
This Policy applies to all visitors and clients of our Site and complies with the EU General Data Protection Regulation (GDPR) and, where applicable, the California Consumer Privacy Act (CCPA).
By using our Site or Services, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The data controller responsible for your personal data is:
onPoint Studio OÜ
Website: onpoint.to
Email: info@onpoint.to
Registered in Estonia, European Union
If you have any questions about how we handle your data, please contact us at the email above.
3. Information We Collect
3.1 Information You Provide Directly
We collect information you voluntarily provide when you:
• Fill out a contact form on our Site (name, email address, message content);
• Submit a Google Form linked from our Site (name, email, and any fields included in the form);
• Subscribe to our Services (name, email address, billing address, and payment information processed by Stripe);
• Communicate with us via the Crisp chat widget (name, email if provided, chat messages).
3.2 Information Collected Automatically
When you visit our Site, we and our third-party partners automatically collect certain technical and behavioral data, including:
• IP address and approximate geographic location;
• Browser type, operating system, and device information;
• Pages visited, time spent on pages, and navigation path;
• Referring URL (how you arrived at our Site);
• Cookie identifiers (see Section 6).
3.3 Payment Information
We do not collect or store your full payment card details. All payment processing is handled by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. When you subscribe, you provide your payment details directly to Stripe. We receive only a confirmation of the transaction and non-sensitive card metadata (e.g., last 4 digits, card type, expiration month/year).
4. How We Use Your Information
We use the information we collect for the following purposes:
• To provide and manage our subscription Services and deliver agreed Deliverables;
• To respond to inquiries submitted via contact forms or Crisp chat;
• To process subscription payments and manage billing through Stripe;
• To send transactional emails related to your subscription (receipts, renewal reminders, cancellation confirmations);
• To analyze Site usage and improve our content and user experience using Google Analytics 4;
• To detect and prevent fraud, abuse, or security incidents;
• To comply with applicable legal obligations.
5. Legal Basis for Processing (GDPR)
For users in the EU/EEA, we process your personal data on the following legal bases:
• Contract performance: processing necessary to provide our Services to you (billing, service delivery, client communication);
• Legitimate interests: analytics and Site improvement, fraud prevention, and security — where these interests are not overridden by your rights;
• Consent: cookies and tracking technologies where required by law (you may withdraw consent at any time via our cookie settings);
• Legal obligation: where we are required to retain or disclose data by applicable law.
6. Cookies and Tracking Technologies
6.1 What Are Cookies
Cookies are small text files stored on your device by your browser. We use cookies and similar technologies to operate our Site, analyze traffic, and provide chat functionality.
6.2 Cookies We Use
• _ga, ga* — Analytics. Used by Google Analytics 4 to collect anonymized usage statistics (pages visited, session duration, traffic source). Opt-out: google.com/settings/ads or tools.google.com/dlpage/gaoptout
• crisp-client/* — Functional. Used by Crisp live chat to maintain session state and user preferences during a chat interaction. Opt-out: disable via browser settings or block the cookie category in our consent banner.
• Preference cookie — Functional. Stores your cookie consent choice so you are not asked again on every visit. Opt-out: clear browser cookies (will reset your consent preference).
6.3 Managing Cookies
You can control cookies through your browser settings or our cookie consent banner. Note that disabling certain cookies may affect the functionality of the Site (e.g., Crisp chat may not load).
For Google Analytics specifically, you can opt out using the Google Analytics Opt-out Browser Add-on: tools.google.com/dlpage/gaoptout
7. Disclosure of Your Information
7.1 Third-Party Service Providers
We share personal data with the following third-party providers solely to operate our Site and Services:
• Stripe, Inc. (United States) — payment processing. Stripe acts as an independent data controller for payment data. Privacy policy: stripe.com/privacy
• Google LLC (United States) — Google Analytics 4 for Site analytics; Google Forms for form submissions. Data may be transferred to and processed in the US under Google's Standard Contractual Clauses. Privacy policy: policies.google.com/privacy
• Crisp IM S.A.S. (France, EU) — live chat widget. Chat data is stored on Crisp servers in the EU. Privacy policy: crisp.chat/en/privacy
We do not sell, rent, or trade your personal data to any third party for their own marketing or advertising purposes.
7.2 Legal Requirements
We may disclose your data if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to protect our rights, your safety, or the safety of others.
7.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the successor entity. We will notify you via email or a prominent notice on our Site before your data is transferred and becomes subject to a different privacy policy.
8. International Data Transfers
onPoint Studio is based in Estonia (EU). Some of our third-party providers are based in the United States (Google, Stripe). When we transfer personal data outside the EU/EEA, we ensure appropriate safeguards are in place, including:
• Standard Contractual Clauses (SCCs) approved by the European Commission;
• Adequacy decisions where applicable.
You may request details of the safeguards in place by contacting us at info@onpoint.to.
9. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this Policy:
• Client account and billing data: retained for 7 years after the end of the contractual relationship, as required by Estonian accounting law;
• Contact form and chat data: retained for up to 2 years after last interaction;
• Google Analytics data: retained for 14 months (default GA4 setting);
• Cookie consent records: retained for 1 year.
After the applicable retention period, data is securely deleted or anonymized.
10. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include:
• HTTPS encryption for all data transmitted through our Site;
• Use of PCI-DSS compliant payment processing via Stripe (we do not handle raw card data);
• Access controls limiting who within our organization can access personal data;
• Regular review of our data handling practices and security measures.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
11. Your Rights
11.1 Rights Under GDPR (EU/EEA Users)
If you are located in the EU or EEA, you have the following rights regarding your personal data:
• Right of access: request a copy of the personal data we hold about you;
• Right to rectification: request correction of inaccurate or incomplete data;
• Right to erasure: request deletion of your data, subject to legal retention obligations;
• Right to restriction: request that we limit how we process your data;
• Right to data portability: receive your data in a structured, machine-readable format;
• Right to object: object to processing based on legitimate interests;
• Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at info@onpoint.to. We will respond within 30 days.
You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at aki.ee, or the supervisory authority in your country of residence.
11.2 Rights Under CCPA (California Users)
If you are a California resident, you have the right to:
• Know what personal data we collect, use, disclose, or sell;
• Request deletion of your personal data;
• Opt out of the sale or sharing of your personal data.
We do not sell or share your personal data with third parties for their own advertising or commercial purposes. To submit a request, contact us at info@onpoint.to. We will not discriminate against you for exercising your CCPA rights.
12. Children's Privacy
Our Site and Services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at info@onpoint.to and we will delete it promptly.
13. Third-Party Links
Our Site may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies before submitting any personal data.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the Effective Date at the top of this page. We encourage you to review this Policy periodically to stay informed about how we protect your data.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data
practices, please contact us:
onPoint Studio OÜ
Website: onpoint.to
Email: info@onpoint.to
Registered in Estonia, European Union