Privacy Policy
This page covers what we collect when you visit oneirly.com, send us a form, pay us, or hire us, and what you can ask us to do about it.
The short version: we collect what we need to answer you and do the work. We don't run analytics or ad tracking on this site. We don't sell your information, and anyone can ask us to see, correct or delete it.
Who we are
Oneirly Digital Marketing LLC is a Wyoming limited liability company and the controller of the personal information described here.
Oneirly Digital Marketing LLC
30 N Gould St, STE R
Sheridan, WY 82801, USA
admin@oneirly.com
+1 (475) 652-1487
The Sheridan address is our registered agent's address. Legal notices and company mail go there, but it isn't an office you can visit. The fastest way to reach us about privacy is email: put "Privacy" in the subject line.
"We", "us" and "Oneirly" on this page mean Oneirly Digital Marketing LLC.
What we collect
Forms on this site
Free audit request (/free-audit/): your name, work email, company name and website. You also pick what describes your business, what you want to fix first, and, if you like, your monthly ad spend range, the ad platforms you use, a preferred contact window and a note. Your phone number is optional.
Contact form (/contact/): your name, email, reason for writing and message. Company and phone number are optional. Before sending, you confirm: "By sending this form, you agree that Oneirly Digital Marketing LLC will use the details you provide to respond to your inquiry, as described in our Privacy Policy. We don't sell your information."
When you submit either form, our server checks it and emails it to us. The website doesn't keep a copy in a database.
Phone calls and texts
If you give us a phone number on either form, a consent box appears. It says:
"By submitting this request, you agree that Oneirly Digital Marketing LLC may contact you by email, phone, or text at the number provided — including by autodialer or pre-recorded message — about your request and our services. Message and data rates may apply. Consent isn't a condition of purchase. Reply STOP to opt out of texts, or email admin@oneirly.com. See our Privacy Policy for how we handle your information."
You don't have to give a phone number to use either form or to buy from us. You can withdraw this consent at any time by replying STOP to a text, telling us on a call, or emailing admin@oneirly.com. We keep a do-not-call and do-not-text list so a withdrawn number stays withdrawn. We don't call or text numbers from bought lists.
Paying us
Card payments. Fixed-price audits and setups are paid through Stripe's hosted checkout. Before you're sent to Stripe, the pay panel asks for your email, business name and website, and your confirmation that you've read the Refund & Cancellation Policy. On the Ads Account Audit page it may also take a promo code, your confirmation that this is your business's first paid engagement with us, and the number of extra ad accounts. Our server passes those details to Stripe to set up the checkout.
You enter your card details on Stripe's page, not ours. We never see or store your full card number. Stripe tells us the amount, the item, the payment status and the contact details you gave, along with limited card information such as the brand and last four digits. Stripe uses your information under its own privacy policy, as an independent controller for its own purposes such as fraud prevention.
Invoice requests. If you choose "Request an invoice instead", the same fields go to our server, which emails the request to us and a copy to you. We then send an invoice by email. Monthly retainer invoices work the same way: you pay by bank transfer, ACH or card through a Stripe-hosted invoice link. We keep the payer name, amount and reference that come with each payment.
We don't store cards for automatic monthly charges.
The fee calculator
The calculator at /calculator/ runs entirely in your browser. The platforms, spend and services you enter aren't sent to us or anyone else, and they aren't saved. Close the page and they're gone.
If you click through to the free audit form, the link carries only a fixed spend range and the platforms you ticked (for example spend=3000-10000), so the form can pre-select them. It never carries the number you typed. Nothing reaches us unless you then send the form.
Email, calls and working together
If you email or call us, we get your contact details and whatever you tell us. If we meet on a video call, the invitation names the platform, and that platform's own privacy policy applies to the call. We don't record calls unless everyone agrees first.
Once you're a client, we also hold your proposal and Statement of Work (SOW), contact details for the people we work with, invoices and payment records, and the business information you share so we can do the work.
The promo popup
If you close the discount popup, your browser stores a small note (the key on_promo in local storage) so the popup doesn't show again for 30 days. It holds the date you closed it and nothing else. It stays on your device; we never receive it. Details are in the Cookie Policy.
Technical information and logs
Like any website, this one receives your IP address, browser type, the page requested and the time when you visit. The access and error logs our site keeps are deleted within 24 hours.
To stop spam, the forms keep a scrambled (hashed) form of your IP address so one address can't send dozens of submissions. That is deleted within 24 hours too. The forms also contain a hidden field that catches bots; it holds nothing about you.
Our web host may keep its own short-term infrastructure and security logs under its own policies.
What we don't do
There's no Google Analytics, Meta Pixel, LinkedIn Insight Tag, heatmap, session recording or any other analytics or advertising tracker on oneirly.com. Fonts, images and scripts are served from our own server, so visiting a page doesn't send your details to other companies.
If that changes, we'll update this policy and add a cookie consent banner before any such script loads.
Why we use it
We use your information to reply to you, prepare a proposal, deliver the work you buy, send and collect invoices, keep records the law requires, and protect the site from abuse. We don't sell it, rent it, or share it for cross-context behavioral advertising.
If you're in the EU or UK, these are our legal bases:
| What | Legal basis |
|---|---|
| Answering forms, emails and calls; proposals | Steps you ask for before a contract, or our legitimate interest in replying to business inquiries |
| Delivering paid work, invoicing, payments | Performance of a contract |
| Tax and accounting records | Legal obligation |
| Spam prevention, rate limiting, server logs | Legitimate interest in keeping the site secure |
| Calls and texts to the number you give | Consent, which you can withdraw at any time |
Emails we send you
We email you to answer what you asked, to deliver work and to send invoices. We don't run a newsletter or mailing list. If we ever send you a marketing email, it will say who it's from, include our postal address, and have a working unsubscribe link that we honor within 10 business days.
If you're in Canada, we follow Canada's Anti-Spam Legislation (CASL): we only send commercial emails with your express consent, or where the law allows implied consent (for example, within 6 months of your inquiry or 2 years of a purchase), and every one carries an unsubscribe option.
Who we share it with
We share personal information only with the companies that help us run the business, and only as much as each one needs:
- Stripe, for card payments and Stripe-hosted invoice links.
- Our web host, which runs the server the site and forms live on.
- Our email provider, which carries form submissions and our correspondence.
- The invoicing tool we use, to create and send invoices.
- Professional advisers such as our accountant or lawyer, under a duty of confidentiality, when we need their help.
We may also disclose information if the law requires it, to protect our rights in a dispute, or to a buyer if the business is ever sold, in which case this policy keeps applying to your information.
When we work inside your accounts
When you hire us, you give us access to your ad accounts, analytics, Google Business Profile, CRM, e-commerce platform or email tool. Those hold personal information about your customers. For that data, you're the controller and we're your processor (a "service provider" under US state laws). We use it only to do the work in your SOW and on your written instructions, never for our own purposes or for other clients.
For any engagement that touches your customers' personal information, we sign a Data Processing Addendum (DPA) with you. It covers confidentiality, security, our sub-processors, help with your customers' requests and data breaches, and deleting or returning data when the engagement ends. We send it with your SOW. If you're one of our client's customers and want to use your rights, please contact the business you dealt with; we'll help them answer you.
We ask for user or manager access, never your passwords, and we remove our access when the engagement ends.
Where your information is processed
We're a US company, and we process information in the United States.
If you're outside the US, US privacy law may give you different protections from the law where you live. When you send us information directly through a form or email, it's transferred to the US so we can answer you. For client engagements involving personal data from the EU or UK, our DPA includes the European Commission's Standard Contractual Clauses and the UK Addendum to them. Stripe describes its own transfer safeguards in its privacy policy.
How long we keep it
| Information | How long |
|---|---|
| Free audit requests, contact forms, emails and invoice requests that don't become paid work | 24 months after our last contact |
| Client records: SOWs, invoices, payment records, correspondence | 7 years after the engagement ends, for tax and accounting |
| Access to your ad accounts and other tools | Removed when the engagement ends, or sooner if you ask |
| Server access and error logs | Deleted within 24 hours |
| Hashed IP addresses used for rate limiting | Deleted within 24 hours |
The on_promo note in your browser | Ignored and deleted after 30 days; you can clear it any time |
Stripe keeps payment records under its own retention rules.
Security
The whole site runs over HTTPS. Only Oneirly can read form submissions and client records. In client accounts we use the lowest level of access the work needs, and we never ask for passwords. No system is perfectly secure, so if a breach affects your information, we'll tell you and any regulator as the law requires.
Your rights
Whatever the law in your state or country says, anyone can ask us to:
- tell you what personal information we hold about you and send you a copy,
- correct anything that's wrong,
- delete it, unless we have to keep it (for example, invoices for tax purposes),
- stop calling or texting you.
To ask, email admin@oneirly.com with "Privacy" in the subject. We may need to confirm it's you, usually by replying from the email address we already have. You can use an authorized agent; we'll ask for proof that they act for you. We'll answer within 30 days. If the law lets us take longer and we need to, we'll tell you why within those 30 days. We won't charge you or treat you differently for asking.
If we turn down a request, we'll explain why. You can appeal by replying to that email with "Appeal" in the subject, and we'll give you a written decision within 45 days.
US state privacy laws
California's CCPA/CPRA and the comprehensive privacy laws in other states generally apply to businesses above certain size thresholds: for example, more than $25 million in annual revenue, handling the personal information of 100,000 or more consumers or households a year, or making half or more of their revenue from selling or sharing personal information. We likely don't meet them. We offer the rights above to everyone anyway.
We don't sell personal information, share it for cross-context behavioral advertising, or use it for profiling that has legal or similarly significant effects. Because of that, there's nothing to opt out of, but we still treat a Global Privacy Control signal as an opt-out request. We don't collect sensitive personal information on this site, and we ask clients not to send it unless the work needs it.
Your rights under the GDPR and UK GDPR
If you're in the European Economic Area or the United Kingdom, you also have the right to restrict or object to how we use your information, to get it in a portable format, and to withdraw consent at any time (this doesn't affect anything we did before). You can complain to your local data protection authority or, in the UK, to the Information Commissioner's Office. We'd appreciate the chance to sort it out with you first.
Canada
If you're in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) gives you the right to access and correct your information and to withdraw consent. Use the same email address. If you're not satisfied, you can contact the Office of the Privacy Commissioner of Canada.
Children
oneirly.com is for businesses. It isn't directed at children, and we don't knowingly collect information from anyone under 13 (or under 16 in the EU and UK). If you think a child has sent us information, email us and we'll delete it.
Changes to this policy
When we change this policy, we'll update the date at the top. If a change affects how we use information we already hold, we'll tell the people affected by email before it takes effect.
Contact
Email admin@oneirly.com (subject "Privacy"), call +1 (475) 652-1487, or write to Oneirly Digital Marketing LLC, 30 N Gould St, STE R, Sheridan, WY 82801, USA.