Privacy Policy
Last updated: August 4, 2026
1. Overview
This Privacy Policy explains how Camorna, LLC, a Delaware limited liability company ("Camorna," "we," "us," or "our"), collects, uses, discloses, and protects personal information when you use camorna.com, Camorna applications, and Camorna's advertising, measurement, commerce, customer-workflow, and AI features (the "Services").
Camorna is designed for businesses and their authorized team members. It is not intended for personal, family, or household use. Camorna currently offers and supports the Services only for businesses, stores, users, and advertising operations in the United States.
2. Our Role
Camorna acts as a controller, or "business" under some U.S. state laws, when we decide why and how to process information for account administration, billing, security, product analytics, support, and our legal obligations.
Camorna generally acts as a processor or service provider when we process a customer's lead, shopper, website-event, campaign, commerce, and connected-platform data only to provide the Services under that customer's instructions. The customer is responsible for its own notices, consents, legal bases, and instructions to Camorna.
If you are an individual whose information was submitted by a Camorna customer, contact that customer first. We will assist the customer with a verified request as required by law.
3. Information We Collect
3.1 Account, organization, and store information
Name, business name, email address, phone number, country or region, role, team membership, workspace settings, authentication and verification records, account status, subscription status, store name, website URL, commerce platform, business category, logo, and contact details. We store password hashes, not plaintext passwords.
3.2 Login, device, and security information
Device label and type, browser, operating system, authentication method and strength, login and last-active times, approximate country, region, or city, IP address, user agent, request metadata, and security events. Session records use hashed or HMAC-protected identifiers where designed and do not store plaintext passwords or bearer tokens.
3.3 Website, lead, commerce, and conversion information
Page views, referring URLs, campaign parameters and click IDs, product and collection views, searches, cart activity, checkout and purchase events, refunds, form interactions, click-to-call events, consent signals, timestamps, first-party session or visitor identifiers, device and browser context, and hashed contact identifiers.
Laxsar hashes raw shopper email address, phone number, and name in the browser and discards the raw values before transmitting the event envelope. Shopify and Wix order-event handlers also hash customer email address and phone number at ingestion and are designed not to store, log, or forward the raw values. A customer's separate lead or CRM workflow may process names, contact details, messages, notes, source labels, CRM status, and communication history outside these event streams.
Laxsar may collect precision-reduced geolocation only when the visitor has granted Camorna consent and browser permission is already granted. The SDK does not trigger a geolocation prompt and rounds coordinates to four decimal places.
3.4 Advertising and connected-App information
Connected account identity; account and resource IDs and names; Pages; advertiser and manager accounts; pixels or datasets; product catalogs; campaigns; ad groups or ad sets; ads and creatives; audiences and targeting; conversion actions; budgets, spend, and performance; and provider approval, rejection, and delivery status. We also record selected resources and requested actions such as creating, editing, pausing, enabling, or reading a campaign.
3.5 Campaign, creative, and business content
Goals, budgets, targeting choices, keywords, negative keywords, locations, audiences, headlines, descriptions, destination URLs, images, video, product information, brand assets, drafts, approvals, edits, versions, and provider responses. If you ask Camorna to inspect a public website, we may retrieve public page text, images, metadata, and crawl results to prepare recommendations or creative content.
3.6 AI information
Prompts, instructions, feedback, generated content, recommendations, workflow state, approvals, and the minimum business, campaign, website, creative, or performance context needed for an enabled AI feature.
3.7 Payment and support information
Stripe processes payment-card details. Camorna receives a tokenized payment reference and limited billing metadata such as card brand, last four digits, expiration date, subscription, invoice, and payment status. Camorna does not store full card numbers. If you contact us, we collect messages, attachments, contact information, diagnostic details, and request trace IDs needed to respond.
| Data point | How Camorna uses it | How Camorna secures it | How to revoke or delete it |
|---|---|---|---|
| Payment-card details | Stripe collects and processes the card information needed to complete a customer-authorized payment. | Camorna uses Stripe-hosted or tokenized payment processing and does not store full card numbers or card security codes. | Update or remove a payment method through the billing flow. Stripe may retain payment records under its legal, fraud-prevention, and financial-services obligations. |
| Payment token, card brand, last four digits, expiration, invoice, subscription, and payment status | Shows billing status, manages subscription access, reconciles invoices, and supports payment issues. | Billing access is restricted to authorized organization users and service roles. Payment references are used instead of full card data. | Cancel the subscription, remove the payment method where available, close the account, or submit a verified deletion request. Required tax, accounting, dispute, and fraud records may be retained. |
4. Sources and Uses
We receive information directly from account users and Camorna customers; from a customer's website, store, forms, servers, CRM, or installed tracking; from connected Apps and advertising platforms at the user's direction; automatically from browsers, devices, and service logs; from public websites a customer asks Camorna to analyze; and from service providers involved in authentication, billing, communications, hosting, security, analytics, and AI inference.
We use information to:
- create, verify, administer, and secure accounts and organizations; - operate store onboarding, first-party measurement, commerce sync, lead workflows, and reporting; - discover provider resources and create, edit, pause, enable, publish, measure, or troubleshoot advertising as directed by an authorized user; - generate drafts, creative content, targeting suggestions, summaries, and optimization recommendations; - process payments, provide support, send operational notices, and maintain service availability; - detect fraud, abuse, credential compromise, policy violations, and technical failures; - maintain audit trails, enforce agreements, and comply with legal obligations; and - improve reliability and usability using aggregated or appropriately de-identified data.
We do not use connected-platform data to build unrelated advertising products, sell data broker lists, or advertise Camorna to another customer's shoppers.
5. Connected Apps
Connecting an App is optional. The authorization and setup flow identifies the provider and requested permissions. Camorna uses connected data only to provide the customer-facing features the user selects and actions the user requests or approves.
Disconnecting an App stops new provider API access. Uninstalling removes its active Camorna credential, setup configuration, selected resources, and Camorna-held connected-App data within 48 hours. Legally required billing, security, privacy-request, fraud-prevention, tax, dispute, and legal-hold records and rotating backups follow the exceptions in Section 13.
Ads, campaigns, audiences, and other records already held by a provider remain with that provider until the user removes them there or Camorna performs an explicitly requested and supported provider action.
6. Google
Depending on the features authorized, Camorna may access:
- Google account identity, including name, email address, and profile information used to identify the connected account; - Google Ads manager and customer accounts, account names and IDs, currency and time zone, campaigns, ad groups, ads, creatives, keywords, audiences, budgets, conversion actions, policy status, performance, and reporting; - Merchant Center product and catalog information; and - YouTube upload capability when the user chooses a video-creative feature.
Camorna uses this information to show eligible accounts, display and measure advertising, create or edit campaign resources, upload selected creative, and troubleshoot provider responses. Provider writes occur only after an authorized user starts or confirms the corresponding workflow.
Camorna's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy. We do not sell Google user data or use it for unrelated advertising. If a visible user-requested AI feature needs connected Google campaign or performance data, Camorna sends only the fields needed for that result and does not send raw audience-member data.
| Data point | How Camorna uses it | How Camorna secures it | How to revoke or delete it |
|---|---|---|---|
| Google account identity | Shows which Google account authorized Camorna and helps the user review or reconnect the correct connection. | Received over Google OAuth and TLS. Tokens are kept in protected credential storage; identity is scoped to the authorized Camorna account and organization. | Disconnect Google in Settings > Apps or revoke Camorna in Google Account permissions. Uninstall deletes Camorna-held App data within 48 hours, subject to Section 13 exceptions. |
| Google Ads manager and customer accounts | Lists accessible accounts, full account IDs, account names, currency, time zone, and manager relationships so the user can select the account Camorna may operate. | Account and organization authorization is checked before discovery or selection. Credentials remain server-side and are not returned to the browser. | Deselect or change the account in the Google setup flow, disconnect Google, or uninstall the App. Uninstall deletes Camorna-held selections and account metadata within 48 hours. |
| Campaigns, ad groups, ads, creatives, keywords, audiences, and budgets | Displays existing advertising and performs user-requested creation, editing, pausing, enabling, and reporting. | Provider writes require an authorized workflow action. Camorna records the requested action and provider response, validates account ownership, and uses encrypted transport. | Delete or edit provider-side advertising in Google Ads. Disconnect stops new Camorna API actions; uninstall deletes Camorna-held copies within 48 hours but does not delete Google-side records. |
| Conversions, policy status, spend, and performance | Builds reporting, attribution, rejection guidance, optimization suggestions, and user-requested AI recommendations. | Access is limited by Camorna organization and selected Google Ads account. AI requests are minimized and exclude raw audience-member data. | Disconnect stops new reads. Uninstall deletes Camorna-held App-specific reports and provider-derived data within 48 hours, subject to legal and backup exceptions. |
| Merchant Center products and YouTube uploads | Uses product data for catalog-backed advertising and uploads a selected video only when the user starts that creative workflow. | Uses Google-authorized API scopes, server-side credentials, TLS, resource validation, and an audited user action before an upload. | Disconnect or revoke the Google grant to stop access. Remove uploaded media or products in Google. Uninstall deletes Camorna-held App data within 48 hours. |
7. Meta
Depending on the permissions and features authorized, Camorna may access Meta account and business identity, Pages, ad accounts, campaigns, ad sets, ads, creatives, leads, pixels or datasets, Custom Audiences, delivery and policy status, permissions, and performance.
Camorna uses this information to let users select a Page, ad account, and dataset; create and manage campaigns and creatives; display reporting and rejection reasons; and deliver requested measurement or audience features. At a customer's instruction, Camorna may send event data and normalized, hashed contact identifiers to Meta through Conversions API or Custom Audiences for matching, measurement, attribution, and audience delivery.
Customers must have the rights, permissions, and lawful basis to send that information, honor applicable opt-outs, and not send prohibited sensitive information or data about children. Meta processes received information under its own Meta Business Tools Terms and Customer List Custom Audiences Terms.
| Data point | How Camorna uses it | How Camorna secures it | How to revoke or delete it |
|---|---|---|---|
| Meta identity and Business account | Identifies the person and business that authorized Camorna and discovers eligible business assets. | Received through Meta OAuth over TLS. Access tokens remain in protected server-side credential storage and are scoped to the authorized Camorna organization. | Disconnect Meta in Settings > Apps or remove Camorna in Meta Business integrations. Uninstall deletes Camorna-held App data within 48 hours. |
| Pages and ad accounts | Lets the user choose the Page identity and ad account used for campaign creation, delivery, and reporting. | Camorna verifies organization access and persists only the selected resource identifiers and display details needed for setup. | Change the selection in the Meta setup flow, disconnect, or uninstall. Provider-side assets remain in Meta; Camorna-held selections are deleted within 48 hours after uninstall. |
| Campaigns, ad sets, ads, creatives, budgets, and status | Shows existing advertising and performs user-requested creation, versioning, editing, pausing, enabling, and reporting. | Writes require an authorized workflow action. Camorna validates the selected ad account, uses TLS, and records provider outcomes without exposing access tokens. | Edit or delete provider-side resources in Meta. Disconnect stops new Camorna actions; uninstall deletes Camorna-held copies within 48 hours. |
| Pixels, datasets, events, and conversion status | Configures measurement, sends customer-authorized conversion events, verifies delivery, and reports attribution readiness. | Camorna validates event structure and consent signals. Raw prohibited fields are rejected, and supported contact identifiers are normalized and hashed before provider delivery. | Disable the event destination or disconnect Meta to stop new delivery. Uninstall deletes Camorna-held App-specific event and dataset data within 48 hours. |
| Leads | Imports or displays leads only when the customer enables the Meta lead workflow. | Lead access is restricted by organization roles and the authorized Meta Page or account. Credentials never appear in the lead payload returned to the browser. | Disable lead sync, disconnect Meta, or submit a verified deletion request. Uninstall deletes Camorna-held Meta App data within 48 hours, subject to required records. |
| Custom Audiences and hashed contact identifiers | Creates or updates a customer-requested audience for matching and campaign delivery. | Identifiers are normalized and hashed before transfer. Camorna requires customer authority and is designed to block prohibited sensitive or child data. | Remove the audience or members in Meta, disable the destination, or disconnect. Uninstall deletes Camorna-held audience source data within 48 hours but does not automatically remove Meta-side audiences. |
8. TikTok
Camorna may access TikTok advertiser accounts, campaigns, ad groups, ads, creatives, pixels, audiences, targeting, budgets, delivery and policy status, and performance. Camorna uses this information to show eligible advertiser resources; create, edit, pause, publish, and measure advertising at the user's direction; and display provider responses.
When a customer enables TikTok event or audience delivery, Camorna may send allowed event data and hashed identifiers for measurement, attribution, or audience matching. The customer is responsible for the required website or app notice, consent, suppression, and lawful use.
| Data point | How Camorna uses it | How Camorna secures it | How to revoke or delete it |
|---|---|---|---|
| TikTok identity and advertiser accounts | Identifies the authorized connection and lists advertiser accounts the user can select. | OAuth credentials remain in protected server-side storage. Account discovery and selection require Camorna account and organization authorization. | Disconnect TikTok in Settings > Apps or revoke the authorization in TikTok. Uninstall deletes Camorna-held connection data within 48 hours. |
| Campaigns, ad groups, ads, creatives, targeting, and budgets | Displays existing resources and performs user-requested creation, editing, pausing, publishing, and reporting. | Writes require an authorized workflow action, selected advertiser validation, TLS, and provider-response auditing. | Edit or delete resources in TikTok. Disconnect stops new Camorna actions; uninstall deletes Camorna-held copies within 48 hours without deleting TikTok-side records. |
| Pixels, events, and hashed identifiers | Measures outcomes, attributes conversions, and supports customer-enabled event delivery. | Camorna validates event payloads and consent context and hashes supported contact identifiers before provider delivery. | Disable the TikTok destination or disconnect to stop new delivery. Uninstall deletes Camorna-held App-specific event data within 48 hours. |
| Audiences, delivery status, policy status, and performance | Supports audience selection, reporting, rejection guidance, and optimization recommendations. | Data is scoped to the selected advertiser and authorized organization. AI inputs are minimized to fields needed for the visible requested result. | Remove provider-side audiences in TikTok. Disconnect stops new reads; uninstall deletes Camorna-held provider-derived data within 48 hours. |
9. Shopify
When a merchant installs the Camorna Shopify App, Camorna receives the shop's myshopify.com domain, shop and installation identifiers, an offline authorization token, and the data allowed by the merchant-approved scopes. The current App requests access to products, orders, customer events, and web pixel installation.
Camorna uses Shopify data to sync products and recent order history for catalog, attribution, and reporting; receive order and refund webhooks; install a web pixel that can receive product and collection views, searches, add-to-cart activity, checkout steps, and completed purchases; and associate the merchant's store with its Camorna organization.
Order and event data may include order and product identifiers, item details, amount, currency, timestamps, and customer email address or phone number. Camorna hashes customer email address and phone number at ingestion and is designed not to retain or forward those values in raw form.
Camorna verifies Shopify webhook signatures and processes Shopify's required customers/data_request, customers/redact, and shop/redact topics through a durable privacy pipeline: a verified request is recorded before it is acknowledged, and deletion or export then runs across Camorna's attribution records, analytics warehouse, and raw event archive, with deadline tracking and alerting against Shopify's 30-day requirement. Data-request exports are assembled into private, access-controlled storage. Uninstalling the App starts the same shop-scoped erasure immediately — Camorna does not wait for Shopify's later shop/redact delivery to begin. Bounded, hashed-only records of each privacy request are retained as compliance evidence under Section 13.
| Data point | How Camorna uses it | How Camorna secures it | How to revoke or delete it |
|---|---|---|---|
| Shop domain, shop ID, and installation ID | Binds the Shopify shop to the correct Camorna organization and routes installation, sync, and privacy events. | Domains are validated, installation records are organization-scoped, and webhook signatures are verified before payload processing. | Uninstall the Camorna App in Shopify or Camorna. Active setup and App-owned data are deleted within 48 hours, subject to Section 13 exceptions. |
| Offline Shopify authorization token and granted scopes | Allows server-side product/order sync, webhook management, and Web Pixel installation while the App is installed. | The token stays in protected credential storage, is never returned to the browser, and is used only for the installed shop over TLS. | Uninstalling or revoking the Shopify App invalidates provider access. Camorna removes the stored token as part of uninstall and completes App-data deletion within 48 hours. |
| Products and catalog data | Builds the store catalog, product reporting, and product-backed campaign recommendations and creative. | Access is read-only under read_products, scoped to the installed shop, and protected by Camorna organization authorization. | Disconnect or uninstall to stop sync. Uninstall deletes Camorna-held Shopify product data within 48 hours; source products remain in Shopify. |
| Orders, line items, amounts, currency, and refunds | Provides recent-order backfill, revenue attribution, conversion reporting, and refund adjustment. | Access is scoped to the installed shop. Signed webhooks and authenticated API calls are validated before bounded processing. | Uninstall stops new sync and deletes Camorna-held Shopify order/refund App data within 48 hours, subject to billing, legal, security, and backup exceptions. |
| Web Pixel customer events | Measures product views, collection views, searches, cart activity, checkout steps, and completed purchases. | Shopify controls pixel execution and consent context. Camorna validates event contracts and uses bounded first-party identifiers. | Disable or remove the pixel/App to stop new events. Uninstall deletes Camorna-held Shopify event data within 48 hours. |
| Customer email address and phone number | Creates a stable hashed match key for attribution and customer-authorized conversion delivery. | Values are normalized and SHA-256 hashed at ingestion; handlers are designed not to store, log, or forward the raw values. | A verified customers/redact request deletes the corresponding Camorna-held data. Shop uninstall also places App-owned data under the 48-hour deletion commitment. |
| Shopify privacy webhook identifiers | Locates the shop, customer, orders, and request involved in customers/data_request, customers/redact, or shop/redact. | Camorna verifies the Shopify HMAC before parsing and retains bounded audit evidence without retaining deleted content. | Handled through Shopify's privacy-request process. Legally required request evidence may be retained under Section 13. |
10. Wix
When a site owner installs or connects the Camorna Wix App, Camorna receives an App instance identifier and site/store binding information. Camorna uses Wix client credentials to provision an embedded first-party collection script and does not store a per-site Wix refresh token in the current implementation.
Camorna may receive signed Wix webhooks for order creation or updates, payment-status changes, purchases, and refunds. These events may include site, order, product, item, amount, currency, and timestamp data, plus customer email address or phone number. Camorna hashes customer email address and phone number at ingestion and is designed not to store, log, or forward the raw values.
Disconnecting removes Camorna's embedded script and active local setup. Uninstalling the App in Wix remains a Wix site-owner action. Wix users' and site visitors' information is used only to provide the installed Camorna feature, not to build Camorna's own contact database or sell it.
| Data point | How Camorna uses it | How Camorna secures it | How to revoke or delete it |
|---|---|---|---|
| Wix App instance ID and site/store binding | Binds the Wix installation to the correct Camorna organization and routes setup and webhook events. | Camorna verifies signed Wix requests and stores the binding under organization authorization. The instance ID is not used for advertising identity. | Disconnect in Camorna to remove active local setup, and uninstall the App in Wix. Camorna-held App data is deleted within 48 hours after uninstall completes. |
| Wix client-credential access | Mints short-lived provider access needed to provision or remove Camorna's embedded collection script. | App credentials remain server-side in secret storage. The current implementation does not retain a per-site Wix refresh token. | Disconnect removes the embedded script and active setup. Uninstalling in Wix ends the installation; rotate App credentials if compromised. |
| Embedded script and first-party events | Collects customer-configured website and commerce activity for live reporting, attribution, and conversion measurement. | Script provisioning is bound to the verified site instance. Laxsar consent and event-validation controls apply to collected events. | Disconnect removes the script to stop new collection. Uninstall deletes Camorna-held Wix App event data within 48 hours. |
| Orders, items, amounts, currency, payments, and refunds | Builds revenue attribution, purchase reporting, and refund adjustments. | Wix webhook JWT signatures are verified before processing. Events are scoped to the bound site and handled with bounded payload processing. | Disconnect or uninstall stops new processing. Uninstall deletes Camorna-held Wix order and payment App data within 48 hours, subject to Section 13 exceptions. |
| Customer email address and phone number | Creates a hashed match key for attribution and customer-authorized conversion delivery. | Values are normalized and SHA-256 hashed at ingestion; handlers are designed not to store, log, or forward the raw values. | Disconnect or uninstall places the associated Wix App data under the 48-hour deletion commitment. A verified privacy request may be submitted to privacy@camorna.com. |
11. Website Tracking, WooCommerce, CRM, and Communications
A customer may install the Laxsar tag directly or through a supported website or commerce plugin, including WooCommerce. Camorna uses the resulting first-party events to show live activity, attribute campaign results, build reports, and send customer-authorized conversions to a connected ad platform. The store controls where the tag is installed and the consent signals passed to it.
The Camorna WordPress plugin integrates with WordPress's built-in Erase Personal Data tool. When a site owner runs an erasure for a shopper, the plugin forwards a signed deletion request to Camorna carrying only a hashed email identifier — never the raw address — and records the erasure as fulfilled only after Camorna has durably accepted it. The deletion then runs through the same privacy pipeline as Shopify requests, removing matching hashed-identifier data from Camorna's attribution records and analytics warehouse and blocking archive replay.
If a customer connects a CRM or communications provider, such as Salesforce, HubSpot, Zoho, an email provider, SMS, or WhatsApp, Camorna exchanges only the lead, contact, status, message, and workflow information needed for the selected sync or communication. The customer controls the connection and is responsible for lawful contact, message consent, opt-out handling, and the provider's own terms.
| Data point | How Camorna uses it | How Camorna secures it | How to revoke or delete it |
|---|---|---|---|
| Consent state and first-party visitor/session ID | Determines whether collection may occur and groups related first-party events for live activity and attribution. | Identifiers are pseudonymous, bounded, first-party, and separated by store. An explicit DENIED state drops events, purges the queue, removes durable identifiers, and severs in-memory identity. | Set consent to DENIED or remove the tag/plugin to stop collection and purge the local queue and identifiers. Submit a verified deletion request for Camorna-held history. |
| Page, product, collection, search, cart, checkout, purchase, and refund events | Shows live store activity, attributes campaign outcomes, creates reports, and sends customer-authorized conversions. | Events pass a versioned validation contract, reject prohibited sensitive fields, use bounded payloads, and are scoped to the store and organization. | Disable tracking or remove the tag/plugin to stop new events. Raw event envelopes expire after 30 days on an infrastructure-enforced schedule; verified deletion requests cover associated retained data. |
| Referrer, campaign parameters, and advertising click IDs | Connects visits and conversions to the campaign or channel that produced them. | Values are validated and scoped to first-party event processing. They are not used to create Camorna's own cross-customer advertising profile. | Disable tracking or consent to stop new collection. Submit a verified deletion request for retained attribution data. |
| Shopper name, email address, and phone number | Produces hashed identifiers used for attribution, deduplication, and customer-authorized conversion matching. | Raw values are normalized and SHA-256 hashed in the browser before the event envelope is sent, then discarded. | Set consent to DENIED to purge queued local identity. Submit a verified deletion request to remove associated Camorna-held hashed data. |
| Precision-reduced geolocation | Supports customer-enabled local measurement when both Camorna consent and existing browser permission are present. | The SDK does not trigger a permission prompt and rounds coordinates to four decimal places before use. | Do not grant browser location permission, revoke it in the browser, or deny Camorna consent. Submit a verified deletion request for retained location data. |
| Data point | How Camorna uses it | How Camorna secures it | How to revoke or delete it |
|---|---|---|---|
| Provider authorization and account/resource IDs | Connects the selected CRM, email, SMS, or messaging workspace and routes sync actions. | OAuth or provider credentials remain server-side in protected storage and are scoped to the authorized Camorna organization. | Disconnect or revoke the provider authorization. Uninstall deletes Camorna-held App connection data within 48 hours. |
| Lead and contact details | Creates or updates customer-requested lead records, syncs CRM status, and supports follow-up workflows. | Role and organization authorization restrict access. Camorna sends only fields required for the selected sync and does not sell contact lists. | Delete the lead in the controlling system, disable sync, disconnect, or submit a verified deletion request. Provider-side copies follow that provider's controls. |
| Messages, notes, source, status, and communication history | Shows workflow context, records customer-authorized outreach, and prevents duplicate or conflicting follow-up. | Access is role-scoped, message delivery uses authenticated provider APIs, and operational logs are designed not to contain provider secrets. | Disable the workflow or disconnect to stop new messages. Delete records in Camorna and the provider as applicable or submit a verified request. |
| Consent, suppression, and opt-out status | Prevents messages to people who opted out and records the customer's communication instructions. | Suppression state is treated as an operational control and must not be removed merely to resume marketing. | Recipients can use the provider's opt-out mechanism. Customers must honor opt-outs; retained suppression evidence may remain to prevent future unlawful contact. |
12. OpenAI, ChatGPT, and AI Features
Camorna uses OpenAI API services for enabled text, vision, planning, embedding, and image-generation features. Camorna may send prompts and the minimum business, website, product, campaign, creative, and performance context needed to produce the output requested by the user.
OpenAI states that API data is not used to train its models unless the API customer opts in. Under OpenAI's default controls, abuse-monitoring logs may be retained for up to 30 days, subject to safety and legal exceptions, and some API features may retain application state as described in OpenAI's API data controls: https://developers.openai.com/api/docs/guides/your-data.
Camorna does not currently offer a verified public ChatGPT OAuth connection. A Camorna preview or workflow labeled for a ChatGPT advertising experience is not a statement that OpenAI has approved, endorsed, or published a general advertising API. Any future ChatGPT App or MCP integration will identify the requested context and require confirmation before an external write or destructive action.
AI outputs are drafts and may be inaccurate. Users must review material outputs and approve advertising actions before publication. Camorna does not use identifiable customer content to train a general-purpose model and does not permit a model provider to do so unless the customer separately and affirmatively chooses that use.
| Data point | How Camorna uses it | How Camorna secures it | How to revoke or delete it |
|---|---|---|---|
| Prompts and user instructions | Generates the requested campaign plan, copy, summary, recommendation, analysis, or image. | Camorna sends only the prompt and context needed for the visible feature over TLS. Secrets, payment data, and raw audience-member data are not intended AI inputs. | Delete the related draft/workflow or submit a verified deletion request. OpenAI default abuse-monitoring logs may remain for up to 30 days under its controls and legal exceptions. |
| Business, website, product, and brand context | Grounds outputs in the customer's actual offering, tone, destination, products, and brand assets. | Context is scoped to the authorized organization and minimized for the selected AI operation. Public-site crawl content is treated as customer workspace data after retrieval. | Remove the source asset or store, delete the related workflow, or submit a verified deletion request. Disconnecting an originating App applies its 48-hour deletion commitment. |
| Campaign, creative, and performance context | Produces platform-aware ad drafts, optimization guidance, summaries, and rejection corrections. | Camorna sends only fields needed for the requested result and excludes provider access tokens and raw audience-member data. Provider writes remain a separate authorized action. | Delete the draft or campaign copy in Camorna or uninstall the originating App. Camorna-held App-specific context is deleted within 48 hours after uninstall. |
| Images and visual inputs | Supports user-requested image analysis, creative generation, or refinement. | Uploads use authenticated encrypted transport and are scoped to the requested workflow. Users should not submit prohibited sensitive or unlicensed content. | Delete the creative/workflow or submit a verified deletion request. Provider-side transient or abuse-monitoring retention follows OpenAI's data controls. |
| Generated outputs, feedback, approvals, and action status | Displays drafts, supports version review, records user approval, and maintains an audit trail for any later provider action. | Outputs are organization-scoped and do not authorize an external write by themselves. Camorna does not use identifiable customer content to train a general-purpose model. | Delete the workflow or output, close the account, or submit a verified deletion request, subject to security, legal, and audit exceptions. |
13. Retention, Disconnect, Uninstall, and Deletion
We retain information only for as long as needed to provide the Services, maintain customer-directed history, secure the platform, meet tax and accounting obligations, resolve disputes, and comply with law.
- OAuth tokens and App credentials are retained while the connection is active and deleted from active credential storage when disconnect, uninstall, provider revocation, or account deletion completes. - Active credentials, setup, selected resources, provider-derived connection data, and associated Camorna-held App data are deleted within 48 hours after uninstall completes. - Raw event envelopes (Laxsar, Shopify, and commerce webhooks) expire after 30 days. This expiry is enforced at the infrastructure level — analytics-warehouse partitions and archived raw event objects expire automatically — not only by application policy. - Derived analytics, attribution, lead, commerce, workflow, campaign, creative, provider-response, and AI workflow information is retained for the customer-configured or account-history period and then deleted or de-identified, except App-specific data covered by the 48-hour uninstall commitment, and subject to legal and security exceptions. - Login, audit, and security information is retained for the active session or for the period reasonably needed to detect, investigate, and document abuse or unauthorized access. - Billing, tax, privacy-request, and dispute records are retained for the period required by law or reasonably needed to document compliance. - Deleted information may remain inaccessible in rotating, encrypted backups until those backups expire and is not restored to active use except for disaster recovery. If Camorna restores from a backup, completed deletion requests are re-applied to the restored data before it returns to service, so a restore does not resurrect erased information.
The 48-hour commitment does not require deletion of records Camorna must retain by law or for security, privacy-request evidence, fraud prevention, billing, tax, disputes, or legal holds. Disconnecting or uninstalling does not automatically delete ads or information held by the provider.
14. How We Disclose Information
We disclose information only as needed to:
- service providers and subprocessors for cloud hosting and storage, databases, communications, payment processing, analytics, security, support, and AI inference; - connected Apps selected by the user, including Google, Meta, TikTok, Shopify, Wix, CRM, commerce, and communications services; - the customer's authorized users according to organization roles and permissions; - legal and safety recipients when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or establish or defend legal claims; and - transaction participants in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and notice obligations.
We do not sell personal information for money or use it for Camorna's own cross-context behavioral advertising. A business customer may direct Camorna to send that customer's event or audience data to a connected advertising platform for the customer's advertising. The customer is responsible for any notice and opt-out duty that applies to that advertising.
15. Cookies and Local Storage
We use browser storage for sign-in, security, preferences, consent, pseudonymous first-party identifiers, and a bounded event-delivery queue. An explicit DENIED Laxsar consent state drops events before queue or network transmission, purges queued events, removes durable Laxsar identifiers, and severs in-memory identity. Customers are responsible for configuring legally required consent before non-essential collection.
Our Google Analytics configuration denies advertising storage, ad-user-data storage, and ad personalization. You can change non-essential choices through Cookie preferences.
| Data point | How Camorna uses it | How Camorna secures it | How to revoke or delete it |
|---|---|---|---|
| Consent and analytics-storage choice | Determines whether non-essential product analytics may load and records the user's preference. | Advertising storage, ad-user-data storage, and ad personalization are configured as denied. The preference is stored as a bounded browser setting. | Change Cookie preferences or clear site storage. Denying analytics stops new non-essential analytics collection. |
| Page, route, device, browser, and product-usage events | Measures application reliability, navigation, feature adoption, and performance so Camorna can improve the Service. | Camorna configures analytics without advertising personalization and avoids sending provider credentials, raw lead content, or full payment-card data. | Deny Analytics in Cookie preferences to stop future events. Submit a verified deletion request for Camorna-controlled linked analytics data where applicable. |
16. Security
We use safeguards designed to protect information, including TLS in transit, cryptographic protection for stored credentials and selected sensitive identifiers, role-based access controls, account and organization authorization checks, secret management, signature and request validation, rate limiting, logging, monitoring, and bounded caches.
No system is completely secure. Contact security@camorna.com if you believe information or an account has been compromised.
17. Your Choices and Privacy Rights
Depending on your U.S. state of residence, you may have the right to know, access, correct, or delete personal information; receive a portable copy; object to or restrict certain processing; withdraw consent; opt out of sale, sharing, targeted advertising, or certain profiling; limit certain uses of sensitive personal information; and appeal a denied request.
Email privacy@camorna.com to submit a request. We may verify your identity and authority before acting. An authorized agent may submit a request where allowed by law, but we may require proof of authorization. We will respond within the period required by applicable law.
Deletion and export requests that arrive through a platform channel — Shopify's privacy webhooks or the WordPress Erase Personal Data tool — are recorded durably before they are acknowledged and processed through the same pipeline, with internal deadline tracking ahead of each platform's required response window.
You can also revoke a login session in account security settings; disconnect or uninstall an App in Settings > Apps; change non-essential choices through Cookie preferences; and opt out of marketing messages using the instructions in the message.
If we deny a request, appeal by emailing privacy@camorna.com with the subject "Privacy Appeal."
18. U.S. State Privacy Notice
During the preceding 12 months, Camorna may have collected identifiers; customer records; commercial and transaction information; internet or network activity; approximate or consented precision-reduced location; professional or employment-related information; audio, visual, or creative content; account credentials; and inferences generated to provide recommendations.
We do not knowingly sell personal information or use it for Camorna's own cross-context behavioral advertising, and we do not knowingly sell or share personal information of people under 18. We use sensitive information only for permitted purposes such as authentication, account security, and providing a requested service unless we provide a separate notice and choice.
Camorna will not discriminate against a person for exercising an applicable privacy right.
19. United States Service Area
Camorna currently offers and supports the Services only in the United States. Some service providers may process information outside the state where a user or customer is located.
Before Camorna accepts customers, stores, users, or advertising operations in a non-U.S. market, we will review the market's legal and privacy requirements, update this Policy and product controls, and provide any required notice or consent.
20. Children
The Services are for businesses and are not directed to children or minors. Camorna does not knowingly create accounts for children under 13 or knowingly collect their personal information directly through the Services. Customers must not use Camorna to target children unlawfully or send child data to connected advertising tools.
21. Changes to This Policy
We will post changes here and update the effective date. If a change materially expands how we use connected-platform or personal information, we will provide additional notice and obtain consent where required before applying the new use.
22. Contact Us
Camorna, LLC 325 E. Grand River Ave., Suite 300, East Lansing, Michigan 48823, United States Phone: +1 (260) 517-0002
Privacy requests: privacy@camorna.com Support: support@camorna.com Security: security@camorna.com