Privacy Policy
Last updated: September 9, 2026
This Privacy Policy describes how Oryon Data Intelligence Corp. ("Oryon", "we", "our") collects, uses, discloses, retains and protects personal information and business data in connection with the use of the website https://oryondata.com and all services, software, applications and platforms operated by Oryon.
Oryon provides a software platform that enables organizations to centralize, visualize and analyze their business, marketing, sales and operational data to support decision-making. In the course of its activities, Oryon processes certain information necessary to deliver its services and is committed to doing so in compliance with applicable privacy laws.
This Policy is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA), the Act to modernize legislative provisions as regards the protection of personal information (Quebec Law 25), and any other applicable data protection legislation.
Use of Oryon's website, platform or services implies acceptance of this Privacy Policy.
In the course of providing its services, Oryon may collect certain information that directly or indirectly identifies a person or organization. This may include the user's name, professional email address, phone number, organization name, login credentials, account settings and subscription management information. Oryon also automatically collects certain technical information when the website or platform is used, including IP address, browser type and version, device and operating system information, referring pages, pages viewed, timestamps and server log data, which are used for security, diagnostics and measurement of service usage.
When a user chooses to connect third-party platforms to Oryon, certain business data may also be processed to deliver the requested services. Depending on the permissions granted by the client, this data may include information related to advertising campaigns, marketing spend, revenue, performance metrics, visibility statistics, aggregated sales data and certain metrics from CRM or financial platforms. Oryon does not collect clients' personal contact lists, the content of their emails, or any other data not necessary to perform the requested services.
When a user connects a Google account, Oryon accesses Google user data through the Google Analytics Admin API, the Google Analytics Data API, the Google Ads API, the Google Search Console API and the Google Slides API, using the scopes https://www.googleapis.com/auth/analytics.readonly, https://www.googleapis.com/auth/adwords, https://www.googleapis.com/auth/webmasters.readonly and https://www.googleapis.com/auth/drive.file. From Google Analytics, Oryon reads the list of GA4 properties the user can access and daily aggregate metrics such as sessions, active users, page views, engaged sessions, engagement time and key events. From Google Ads, Oryon reads the list of accessible customer accounts and daily campaign totals for impressions, clicks and cost. From Google Search Console, where the user grants that permission, Oryon reads the list of properties the user owns and daily search statistics by date and by page, namely clicks, impressions, click-through rate and average position. Access to Google Analytics, Google Ads and Google Search Console is strictly read-only: Oryon never creates, edits or deletes anything in those accounts. The drive.file scope is the sole exception: where a user asks Oryon to export a report to Google Slides, Oryon uses it to create that presentation in the user's own Google Drive and to write the report content into it. That scope grants access solely to files created by Oryon; it does not permit Oryon to read, modify or delete any other file in the user's Drive. Oryon does not access Gmail, Google Contacts, or any Google service other than those named above.
Google user data is used solely to provide the features the user has requested, namely to display dashboards, key performance indicators, trend charts, comparisons and reports within that user's own Oryon workspace and, where the user expressly requests it, to create a report presentation in that user's own Google Drive. It is not used for any other purpose, and it is not shared with other Oryon customers.
Oryon's use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Oryon does not use Google user data to serve or target advertising; does not sell or transfer it to data brokers, information resellers, or for credit assessment or lending purposes; does not use it to develop, train, fine-tune or improve generalized or personalized artificial intelligence or machine learning models; and does not transfer it to third parties except as necessary to provide or improve the user-facing features the user requested, to comply with applicable law, or as part of a merger or acquisition following the user's prior consent. For the avoidance of doubt, the provisions of this Policy permitting the use of aggregated or anonymized data to improve Oryon's services, algorithms and analytical models do not apply to Google user data.
Where a user requests an analysis, recommendation, summary or report, the connected data used to produce it, which may include Google user data, is transmitted to Oryon's artificial intelligence sub-processor solely to generate that output for that user. Oryon uses the OpenAI API under terms providing that submitted data is not used to train OpenAI models. Google user data is never used to train, fine-tune or otherwise improve any artificial intelligence or machine learning model, whether generalized or personalized.
A user may disconnect a Google account at any time from the Connections page of the Oryon platform, which immediately and permanently deletes the stored Google OAuth credentials from Oryon's systems and stops any further retrieval of Google user data. A user may also revoke Oryon's access directly through their Google Account at https://myaccount.google.com/permissions. Metrics already retrieved from Google APIs are retained in the user's workspace so that the source can be reconnected without loss of history; they are permanently deleted when the user deletes the workspace or the account, in any case within thirty (30) days, and may be deleted at any time on request to privacy@oryondata.com.
When a user connects a Facebook Page, an Instagram professional account or a Meta advertising account, Oryon accesses Meta Platform Data through the Instagram API with Instagram Login, the Facebook Pages API and the Meta Marketing API. The permissions requested are instagram_business_basic and instagram_business_manage_insights for Instagram; pages_show_list, pages_read_engagement, read_insights and business_management for Facebook Pages; and ads_read for advertising reporting. From an Instagram professional account, Oryon reads the account's follower count, its daily reach and profile views, and, for each post, the publication date, media type, caption, permalink, thumbnail, likes, comments, shares, saves, total interactions and reach. From a Facebook Page, Oryon reads the list of Pages the user manages, the Page's follower count, its daily views, profile views and page actions, and, for each post, the publication date, reactions, comments and shares. From a Meta advertising account, Oryon reads daily campaign totals for spend, impressions, clicks, reach, click-through rate, cost per thousand impressions, cost per click and conversion actions. This access is read-only: Oryon never publishes, edits or deletes anything on a user's Facebook Page, Instagram account or advertising account, and does not access Facebook or Instagram messages, direct messages, friend lists or contact lists.
Meta Platform Data is used solely to provide the features the user has requested, namely to display dashboards, key performance indicators, trend charts, comparisons and reports within that user's own Oryon workspace. It is not used for any other purpose, it is not shared with other Oryon customers, and it is not used to serve or target advertising.
Oryon's use of Meta Platform Data adheres to the Meta Platform Terms and Developer Policies. Oryon does not sell or transfer Meta Platform Data to data brokers or information resellers, does not use it for credit assessment or lending purposes, and does not use it to develop, train, fine-tune or improve generalized or personalized artificial intelligence or machine learning models. Where a user requests an analysis, recommendation, summary or report, the connected data used to produce it may include Meta Platform Data and is transmitted to Oryon's artificial intelligence sub-processor solely to generate that output for that user, under terms providing that submitted data is not used to train models. For the avoidance of doubt, the provisions of this Policy permitting the use of aggregated or anonymized data to improve Oryon's services, algorithms and analytical models do not apply to Meta Platform Data.
A user may disconnect a Facebook, Instagram or Meta advertising connection at any time from the Connections page of the Oryon platform, which immediately and permanently deletes the stored Meta access token and the connection record from Oryon's systems and stops any further retrieval of Meta Platform Data. A user may also revoke Oryon's access directly from Facebook, under Settings & privacy → Settings → Apps and websites. Metrics already retrieved from Meta APIs are retained in the user's workspace so that the source can be reconnected without loss of history; they are permanently deleted when the user deletes the workspace or the account, in any case within thirty (30) days, and may be deleted at any time on request to privacy@oryondata.com. Step-by-step deletion instructions are available at https://www.oryondata.com/legal/data-deletion.
When a user connects a Shopify store, Oryon accesses that store's data through the Shopify Admin API. The permission requested is read_orders. For each order, Oryon reads its creation date and total amount; for each refund, its date and amount. These values are aggregated into daily totals — order count, gross sales, refunds and net revenue — before being stored: no record specific to an individual order or to a store customer is retained. Oryon does not read or store the names, email addresses, phone numbers, or shipping or billing addresses of the store's customers, nor the line items of their orders. This access is read-only: Oryon never creates, modifies or deletes anything in a user's store.
Shopify data is used solely to provide the features the user has requested, namely to display dashboards, key performance indicators, trend charts, comparisons and reports within that user's Oryon workspace. It is not used for any other purpose, is not shared with other Oryon clients, and is not used to deliver or target advertising.
Oryon's use of Shopify data adheres to Shopify's applicable developer terms and to Shopify's requirements for protected customer data. Oryon does not sell or transfer this data to data brokers or information resellers, does not use it for credit or lending assessment purposes, and does not use it to develop, train, fine-tune or improve generalized or personalized artificial intelligence or machine learning models. Where a user requests an analysis, recommendation, summary or report, the daily totals described above may be transmitted to Oryon's artificial intelligence subprocessor solely to generate that output for that user, under terms providing that submitted data is not used to train models.
A user may disconnect a Shopify store at any time from the Connections page of the Oryon platform, which deletes the Shopify access token and the connection record held in Oryon's systems and ends any further retrieval of data. Uninstalling the Oryon app from the store's admin has the same effect. Where Shopify transmits a redaction request for a store, Oryon deletes the daily totals and the connection record associated with that store. Because Oryon retains no information specific to a store customer, an access or deletion request concerning an individual customer corresponds to no data held by Oryon. Daily totals already obtained are otherwise retained in the user's workspace so that the source can be reconnected without loss of history; they are permanently deleted when the user deletes the workspace or the account, in all cases within thirty (30) days, and may be deleted at any time on request to privacy@oryondata.com. Detailed deletion instructions are available at https://www.oryondata.com/legal/data-deletion.
Data imported, synchronized or connected to the platform remains at all times the exclusive property of the client. Oryon Data Intelligence Corp. acquires no ownership, commercial licence or right of reuse over its clients' data, except to the extent strictly necessary to perform the subscribed services and the normal operation of the platform.
The information collected is used to create and manage user accounts, deliver services, produce customized dashboards, analyses and reports, improve platform features, ensure system security, respond to support requests, and communicate with users regarding their subscription or service updates.
Oryon may also send commercial communications, newsletters, product updates or educational content where permitted by applicable law or with the user's consent. The user may withdraw consent or unsubscribe from such communications at any time.
Certain analysis and recommendation services rely on artificial intelligence technologies provided by OpenAI. Data transmitted to these services is processed in accordance with OpenAI's applicable privacy and security policies. As of the date of this Policy, data processed by the OpenAI API is not used to train AI models and is generally retained for a maximum of thirty (30) days for abuse monitoring and security purposes before deletion.
Oryon provides analysis and decision-support tools that rely in part on artificial intelligence and user-connected data. Recommendations generated by the platform do not constitute professional human advice or a guarantee of performance or future results. Any decision made based on the analyses provided remains the sole responsibility of the user.
In delivering its services, Oryon may engage technology, hosting, cloud, analytics or payment providers. These include Google Cloud Platform, which hosts the Oryon platform and its databases; Cloudflare, which provides network and content delivery services for the platform; Vercel, which hosts the Oryon website; OpenAI, which provides the artificial intelligence services described in this Policy; and Stripe, which processes payments. Certain processing may take place in Canada or the United States depending on the infrastructure used.
Oryon implements reasonable security measures consistent with industry practices to protect personal information and business data against loss, theft, unauthorized access, disclosure, alteration or destruction. These measures include encryption of data at rest and in transit, use of secure protocols, multi-factor authentication where available, access logging and monitoring controls adapted to the nature of the data processed.
Oryon acknowledges the confidential nature of data transmitted or connected by its clients. Subject to applicable legal obligations and sub-processors necessary to deliver the services, Oryon undertakes not to disclose, sell, rent or commercially exploit its clients' data to third parties without their prior consent.
Oryon may, however, use aggregated, anonymized data that does not directly or indirectly identify a user or organization to improve its services, algorithms, analytical models, performance indicators and platform. Under no circumstances will such aggregated data identify a particular client or disclose confidential information belonging to that client. This does not apply to Google user data or to Meta Platform Data, which are excluded from any such use as described above.
Personal information and business data are retained only for as long as necessary to fulfill the purposes for which they were collected or to satisfy applicable legal, regulatory or contractual requirements. Subject to such obligations, client data is deleted within a maximum of thirty (30) days following account closure or termination.
Users have the rights recognized under applicable law, including the right to access their personal information, request its correction, withdraw consent where applicable, and request the deletion of certain information, subject to Oryon's legal obligations.
The website and platform may use cookies, analytics technologies and similar tools to ensure their proper functioning, measure service usage, improve the user experience and enhance system security.
Oryon reserves the right to modify this Privacy Policy at any time to reflect changes in its activities, technologies or legal obligations. Any updated version will be published on the website and will take effect upon posting.
For any questions regarding this Privacy Policy, the protection of personal information or the exercise of your rights, including requests to access or delete your data, please contact: Privacy Officer — Élody Sanchis, Co-founder, Oryon Data Intelligence Corp., Canada — privacy@oryondata.com. General enquiries: hello@oryondata.com.
By using the services of Oryon Data Intelligence Corp., you acknowledge that you have read this Privacy Policy and agree to the terms described herein.