Skip to content
Oh Dear

Privacy Policy

Last updated: January 19th, 2026
This privacy policy explains how Oh Dear collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (GDPR) and Belgian data protection law.

1. Data Controller

The data controller responsible for your personal data is:
Immutable VOF
Hemelshoek 277
2590, Berlaar, Belgium
VAT number: BE 0699.594.682
Email: privacy@ohdear.app

2. What Personal Data We Collect

We collect and process the following categories of personal data:

How we know which campaign brought you here

You're probably running a content blocker. Good. Here's exactly what happens when you land on our site from one of our campaigns, so you can decide for yourself.

If you click a link we've tagged, say from a newsletter or a post on Reddit, that link carries a campaign name in the URL. We remember that name so that if you go on to create an account, we know which of our efforts was worth the money. That's the whole purpose. It tells us where to spend our marketing budget, nothing more.

What we don't do, and this is the important part:

What we store is the campaign name from the link, the domain that referred you (just the domain, never the full URL, and never anything that isn't a plain hostname), and which page you landed on. That's it. If you never create an account, none of it is ever attached to a person, and it's discarded after 30 days.

One thing we want to be straight about, because you'd spot it in your dev tools anyway: clicking a tagged link does start a session, which means a first-party session cookie. It's the same functional cookie you'd get from logging in, it holds a random identifier and the campaign name, and nobody but us can read it. It's not an advertising cookie and it's never shared. Arriving from someone else's site without one of our tags doesn't start a session at all.

If you arrive any other way, by typing our address, from a search result, or from a link someone shared, we store nothing at all and start no session.

Yes, you can block it

The script that does this is called marketing-campaign.js. We named it that on purpose, because hiding it behind an innocent filename to sneak past your blocker would be a lousy thing to do to you. Block it, and the site works exactly as before. Nothing breaks, no nag, no degraded experience. We simply record your signup as "direct" and carry on. We'd rather lose the data than play games with you.

For general traffic statistics we use Fathom Analytics, which is cookieless and GDPR compliant. We don't use Google Analytics, and we never will.

3. Legal Basis for Processing

We process your personal data based on the following legal grounds:

4. How We Use Your Data

We use your personal data to:

5. Data Sharing and Third Parties

We may share your personal data with:

We ensure adequate protection through Data Processing Agreements (DPAs) with all third-party processors. All our subprocessors are SOC 2 or ISO 27001 certified. Your primary data stays in the EU - stored in Belgium with Combell, an ISO 27001 certified hosting provider.

Subprocessors

Complete list of third-party processors and their certifications

View List

6. International Data Transfers

Some of our service providers may be located outside the European Economic Area (EEA). When transferring data internationally, we ensure adequate protection through:

7. Data Retention

We retain your personal data only as long as necessary:

8. Your Rights Under GDPR

As a data subject, you have the following rights:

Right of Access

You can request access to your personal data and information about how we process it.

Right to Rectification

You can request correction of inaccurate or incomplete personal data.

Right to Erasure ("Right to be Forgotten")

You can request deletion of your personal data when it's no longer necessary or you withdraw consent.

Right to Restrict Processing

You can request limitation of processing in certain circumstances.

Right to Data Portability

You can request your data in a structured, machine-readable format to transfer to another service.

Right to Object

You can object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Where processing is based on consent, you can withdraw it at any time.

9. Exercising Your Rights

To exercise any of your rights, please contact us at privacy@ohdear.app or use our contact form. We will respond within one month of receiving your request.

You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit/Autorité de protection des données) if you believe we have not handled your personal data properly.

9a. Your Data, Your Control

We believe you should always have control over your data:

10. Security Measures

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

Security

How we protect your data and earn your trust

Read More

11. Data Breach Notification

In case of a personal data breach that poses a high risk to your rights and freedoms, we will notify you within 72 hours of becoming aware of the breach, as required by GDPR.

To date, Oh Dear has never experienced a data breach requiring notification.

12. Cookies and Tracking

We do not use tracking cookies. We do use cookies for technical purposes such as session management.

13. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes by email or through our service. The current version is always available on our website.

14. Contact Us

If you have any questions about this privacy policy or our data practices, please contact us:

15. Data Processing Agreement

For customers who process personal data through our services, we provide a GDPR-compliant Data Processing Agreement.

Data Processing Agreement

GDPR-compliant DPA with EU Standard Contractual Clauses

Read DPA