Legal
Privacy Policy
Last updated: March 2026
1. Introduction
Oryx Data Systems, Inc. ("Oryx DTR," "we," "our," or "us") operates OryxDTR.com and the Oryx DTR direct-to-retail platform (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, store, and safeguard information from two categories of individuals:
- Website Visitors - individuals who browse OryxDTR.com without a platform account.
- Platform Users - manufacturer and dealer accounts that connect to the Oryx DTR platform, including via Shopify or other integrated ecommerce platforms.
Please read this Privacy Policy carefully. By accessing or using the Services, you acknowledge that you have read, understood, and agree to be bound by this policy.
2. Information We Collect
2.1 Website Visitors
When you visit OryxDTR.com, we may automatically collect:
- IP address and approximate geographic location
- Browser type, version, and device identifiers
- Pages visited, time on site, and referring URLs
- Contact form submissions (name, email, company, message)
2.2 Platform Users - Manufacturers
When a manufacturer account is created and the platform is in use, we collect and process:
- Account Data: Business name, contact name, email address, phone number, billing address, and payment method tokens (we do not store raw card numbers).
- Catalog Data: Product listings, SKUs, pricing tiers, dealer-specific pricing rules, and inventory levels you publish through the platform.
- Order Data: Order records, line items, fulfillment status, tracking numbers, and shipping destinations associated with dealer orders.
- Financial Data: Settlement records, ACH transaction identifiers, gross and net amounts, fee breakdowns, and payment timing data.
- Usage Analytics: Platform activity logs including login timestamps, API call history, and feature utilization metrics used to improve service performance.
- Integration Credentials: OAuth tokens or API keys issued by connected third-party platforms that authorize Oryx DTR to act on your behalf. These are stored encrypted and scoped to the minimum permissions required.
2.3 Platform Users - Dealers
When a dealer account is created or connected through the platform, we collect and process:
- Account Data: Business name, contact name, email address, license information where applicable, billing address, and payment method tokens.
- Order Data: Orders placed through the Oryx portal or via dropship integrations, including SKUs, quantities, shipping addresses, and order status.
- Storefront Data: When a dealer connects a third-party ecommerce platform, we receive product catalog data, order events, and customer-facing inventory levels necessary to operate the dropship integration. We do not collect end-consumer personal data from dealer storefronts except as strictly necessary to fulfill individual dropship orders.
- Usage Analytics: Platform activity logs, order search history, and session data.
2.4 Third-Party Platform Integrations
If you connect Oryx DTR to a third-party ecommerce platform, we receive access via that platform's OAuth authorization flow. The data we access is limited to the scopes you authorize during the connection process and may include:
- Products, variants, and inventory levels
- Orders and fulfillment events
- Store metadata (shop name, domain, currency, timezone)
We do not access end-consumer personal data from connected platforms except where a customer's shipping address is required to fulfill a specific dropship order, and only for that purpose.
3. How We Use Your Information
We use the information we collect to:
- Provision, operate, and maintain the platform and its features
- Process and route orders, manage fulfillment workflows, and settle transactions via ACH
- Authenticate users and enforce access controls
- Generate invoices, statements, and financial reporting for your account
- Send transactional communications (order confirmations, settlement notifications, access PINs)
- Send marketing and product update communications (you may opt out at any time)
- Monitor service performance, investigate incidents, and maintain audit logs
- Comply with applicable legal obligations and respond to lawful requests
- Enforce our Terms of Service and protect the rights and safety of our users
4. Data Storage and Infrastructure Security
Oryx DTR is designed and operated in alignment with SOC 2 Type II security principles, including the Trust Services Criteria for Security, Availability, and Confidentiality. Our infrastructure controls include:
- Encryption in Transit: All data transmitted between users and the platform is encrypted using TLS 1.2 or higher. API communications are enforced over HTTPS exclusively.
- Encryption at Rest: All stored data - including platform databases, backups, and file storage - is encrypted at rest using AES-256 or equivalent industry-standard algorithms.
- Access Controls: Access to production systems and customer data is restricted to authorized personnel on a need-to-know basis. Role-based access controls (RBAC) are enforced, and all privileged access is logged and auditable.
- Authentication: Internal systems require multi-factor authentication (MFA). User-facing platform access enforces secure session management and one-time PIN verification for sensitive features.
- Audit Logging: All significant data access, modification, and deletion events are logged with timestamps and user identifiers. Logs are retained for a minimum of 12 months.
- Vulnerability Management: We conduct regular dependency audits, static analysis scans, and periodic security reviews. Critical vulnerabilities are remediated on a defined SLA.
- Incident Response: We maintain a formal incident response plan. In the event of a data breach affecting your account, we will notify affected users within 72 hours of confirmed discovery, as required by applicable law.
- Subprocessors: Third-party service providers who process data on our behalf (including payment processors, cloud infrastructure providers, and email delivery services) are contractually required to maintain equivalent security standards and are reviewed prior to onboarding.
5. Data Retention
We retain personal information and platform data for as long as your account is active and for a defined period thereafter to satisfy legal, accounting, and dispute resolution requirements. Specific retention windows include:
- Active account data: Retained for the duration of the account relationship.
- Financial transaction records: Retained for a minimum of 7 years to comply with tax, accounting, and regulatory obligations.
- Order and fulfillment records: Retained for 5 years after the order date.
- Audit and access logs: Retained for a minimum of 12 months.
- Marketing contact data: Retained until you opt out or request deletion, after which it is removed within 30 days.
- After account closure: Non-financial personal data is deleted or anonymized within 90 days of account termination, except where retention is required by law.
6. Third-Party Platform Integrations - GDPR Compliance and Disconnection
Where Oryx DTR integrates with third-party ecommerce or commerce platforms, we comply with applicable data protection requirements imposed by those platforms and by law. Specifically:
- Customer Data Requests: When an end-consumer submits a data access request through a connected platform, we will compile and provide all personal data we hold in connection with that individual within 30 days.
- Customer Data Erasure: When an end-consumer requests erasure through a connected platform, we will delete or anonymize all personal data associated with that individual from our systems within 30 days, except where retention is required to satisfy a legal obligation (e.g., tax records tied to a completed transaction).
- Account or Integration Removal: When a merchant disconnects or uninstalls a platform integration, we initiate a 48-hour grace period during which the connection may be restored without data loss. After that period, we permanently delete all data associated with the disconnected integration - including OAuth tokens, platform-sourced product data, and storefront records - except for financial transaction records that must be retained under applicable law.
Disconnecting a third-party platform integration immediately invalidates all associated access credentials and ceases any further data access to that platform.
7. Information Sharing and Disclosure
We do not sell your personal information. We may share information in the following limited circumstances:
- Between Platform Participants: Order, catalog, and fulfillment data is shared between manufacturers and dealers as necessary to operate the platform (e.g., a dealer's shipping address is shared with the manufacturer fulfilling their order).
- Service Providers (Subprocessors): We engage third-party providers for infrastructure hosting, payment processing, email delivery, and analytics. These providers are bound by data processing agreements and may not use your data for their own purposes.
- Payment Processors: Financial data necessary to execute ACH settlements is shared with our banking and payment processing partners under appropriate data sharing agreements.
- Business Transfers: In connection with a merger, acquisition, or sale of substantially all assets, your data may be transferred to the successor entity, who will be bound by this Privacy Policy.
- Legal Compliance: We may disclose information when required by law, subpoena, court order, or to protect the rights, property, or safety of Oryx DTR, our users, or the public.
- With Your Consent: We may share information for other purposes with your explicit consent.
8. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal information. We honor these rights for all users regardless of location:
- Right to Access: You may request a copy of all personal data we hold about you.
- Right to Correction: You may request correction of inaccurate or incomplete information.
- Right to Deletion: You may request deletion of your personal data. We will fulfill deletion requests within 30 days, subject to legal retention obligations. Financial records required for tax or regulatory compliance cannot be deleted before their required retention period expires.
- Right to Data Portability: You may request your data in a structured, machine-readable format (JSON or CSV).
- Right to Restrict Processing: You may request that we limit processing of your data in certain circumstances.
- Right to Object: You may object to processing of your data for marketing purposes at any time.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
To exercise any of these rights, contact us at privacy@oryxdtr.com. We will respond within 30 days. We may require identity verification before processing sensitive requests.
If you are a resident of the European Economic Area (EEA) or United Kingdom, you have additional rights under the GDPR/UK GDPR, including the right to lodge a complaint with a supervisory authority. California residents have additional rights under the CCPA/CPRA.
9. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to operate the website, analyze usage, and support marketing. Specifically:
- Strictly Necessary Cookies: Required for core site functionality (e.g., session authentication). Cannot be disabled.
- Analytics Cookies: Used to understand how visitors interact with the site (e.g., Google Analytics, Microsoft Clarity). These are activated only with your consent.
- Marketing Cookies: Used to measure the effectiveness of marketing campaigns. These are activated only with your consent.
You can manage your cookie preferences at any time using the cookie preference center on this site.
10. Children's Privacy
The Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that we have inadvertently collected information from a child under 18, we will delete it promptly.
11. 10DLC Compliance and Privacy
11.1 Collection of Personal Information
We collect personal information from users when:
- You voluntarily provide it to us when using our website or services.
- You submit your phone number to receive messages via 10DLC.
11.2 Use of Personal Information
We use the personal information you provide for the following purposes:
- To provide the requested services.
- To send you messages via 10DLC as per your request.
- To comply with legal obligations.
- To improve our services and user experience.
11.3 Privacy and 10DLC
As a 10DLC service provider, we adhere to the following principles:
- Privacy policies and terms and conditions are displayed next to the phone number entry fields.
- Privacy policies explicitly state that end user information is protected and not shared or sold to third parties for marketing, lead generation, or analytics purposes.
- The opt-in and opt-out procedures for 10DLC traffic are clearly outlined in both the call-to-action (CTA) and the Terms and Conditions. Opt-in and opt-out occur via the 10DLC number, and short code opt-out routes are not used.
11.4 Opting Out
You can opt out of receiving messages by texting STOP to the 10DLC number associated with our service. If you need assistance or have questions, text HELP for help.
11.5 Disclosure of Personal Information
We do not share or sell end-user information to third parties or affiliates for any marketing, lead generation, or analytics purposes.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify platform users of material changes by email and by posting an updated policy with a revised "Last updated" date. Your continued use of the Services after the effective date of any update constitutes acceptance of the revised policy.
13. Contact Us
For privacy-related inquiries, requests, or complaints, please contact us at:
Oryx Data Systems, Inc.
Privacy Contact: privacy@oryxdtr.com
General Contact: info@oryxdtr.com
Website: OryxDTR.com