Side Quest Energy LLC d/b/a optzi!

Privacy Policy

Last Updated: July 25, 2026 | Effective July 25, 2026

Side Quest Energy LLC d/b/a optzi! ("Optzi", "we", "us"), a Virginia limited liability company, operates the optzi! consent-management service. This Privacy Policy describes how we handle personal data of our customers and their team members (for which Optzi is the controller) and how we process end-user consent data on behalf of our customers (for which the customer is the controller and Optzi is the processor; see the Data Processing Addendum). Contact: support@useoptzi.com.

1. Scope

This policy covers (a) personal data of our customers and their team members (for which Optzi is the controller) and (b) how we handle end-user consent data that our customers' websites collect (for which the customer is the controller and Optzi is the processor; see the Data Processing Addendum).

2. Customer Data We Collect and Why

Do not submit passwords, API keys, payment-card information, or personal data from website visitors through support chat.

3. End-User Data We Process for Customers (as Processor)

When our customer deploys the widget, it records consent interactions of that customer's website visitors: a consent identifier, the consent and notice versions shown, the visitor's choices, and a timestamp. This supports the customer's obligation to demonstrate consent. Optzi also stores, for consent events, a country and region code derived at the network edge (we do not store the raw end-user IP), the visitor's Global Privacy Control signal where the browser sends one, and an impression identifier that links the event to the banner impression. We process this data only on the customer's documented instructions (see the Data Processing Addendum). For this data the customer is the controller, and the visitor should consult that customer's privacy policy.

4. Diagnostic Telemetry from the Widget

To keep the consent tool working reliably, the widget sends a small, storage-less diagnostic beacon when it encounters an internal error: the error stage (an enum), the error class name, a "failed open" flag, the site's embed key, the widget version, coarse configuration flags, and the visitor's country only (derived at the network edge). It never sends the error message, stack trace, page URL, page content, cookies, local storage, or any visitor identifier, and it sets no storage on the device. Lawful basis: legitimate interest (operating a reliable, compliant tool). The beacon still transmits an IP at the network layer, which is why we disclose it here; we do not store the raw IP. Retention: 90 days. The beacon is deliberately designed to be storage-less and first-party with a closed allowlist of fields and no third-party SDK.

5. Sub-Processors and Service Providers

We use: Supabase (database hosting, EU region), Vercel (application hosting), Cloudflare (edge content-delivery network and key-value storage), Clerk (authentication), Stripe (billing), Trigger.dev (background scan jobs), and Featurebase (in-app help and customer-support messaging). Clerk and Stripe process only Optzi's own account, identity, and billing data as Optzi's service providers and do not process Customer Personal Data (end-user consent records). Featurebase ordinarily processes Optzi account identity and support correspondence as our service provider. If a customer chooses to include Customer Personal Data in a support message or attachment, we treat Featurebase as a sub-processor for that limited support flow. Featurebase is used for support, not advertising. Optzi does not load a third-party analytics or error-tracking SDK through the consent widget on customer websites. A current sub-processor list is maintained in the dashboard or available upon request.

6. International Transfers

Our primary database is hosted in the European Union. Where personal data is transferred outside the EEA, UK, or Switzerland (for example, to US-based sub-processors for edge services, authentication, or billing), we rely on Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Modules 2 and/or 3 as applicable), the UK International Data Transfer Addendum, and any Swiss addendum, as completed for Optzi's data flows. Completed modules and addenda are available upon request from support@useoptzi.com.

7. Retention

We retain customer account data for the life of the account. We retain end-user consent records for the life of the customer account (the customer's proof-of-consent), widget diagnostic telemetry for 90 days, and scan results for 90 days. Support conversations and attachments are retained while needed to support the account. When we approve a valid deletion request, we remove the applicable information from Featurebase's active workspace using its supported deletion tools. Under Featurebase's published retention terms, customer content may be retained for the agreement term, deletion from active systems after termination may take up to 90 days, and encrypted backup copies may remain until overwritten for up to 365 days. On account termination we return and/or delete consent records within 30 days of the customer's instruction, after first providing a complete export, except where law requires retention; absent an instruction within 30 days after termination, we may delete after giving at least 14 days' prior notice. We retain our own minimised business records that contain no end-user personal data (billing-state ledgers, administrative-action logs, webhook-idempotency records, and our proof-of-erasure log) for up to 7 years for tax/accounting and to establish or defend legal claims. These numbers are enforced in our code where the data is held in Optzi-controlled systems; external support-data requests follow our documented provider process.

8. Your Rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection. Customers and their team members can exercise rights, including access to or deletion of applicable Featurebase support data, via support@useoptzi.com. End users should contact the website operator (our customer), who is the controller; we will assist that operator as their processor.

9. California Privacy Rights

If the CCPA/CPRA applies, California consumers may have the right to know/access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and not be discriminated against for exercising those rights. We collect the categories of personal information described in sections 2 to 4 from you, your account, our service providers, and network-level operation of the service. We use them for account creation, authentication, billing, support, service operation, security, diagnostics, legal compliance, and accounting. We disclose personal information for business purposes to the service providers listed in section 5. Optzi does not sell or share personal information as those terms are defined by the CCPA/CPRA, does not use or disclose sensitive personal information for purposes requiring a right to limit, and does not knowingly sell or share personal information of consumers under 16. You may exercise California rights at support@useoptzi.com; where we act only as processor/service provider for a customer, we will assist that customer rather than respond as the controller/business.

10. Security

We apply technical and organisational measures appropriate to the risk (GDPR Art. 32), including tenant isolation enforced in application code, encrypted transport, and least-privilege database access.

11. Cookies on Our Own Properties

The Optzi dashboard uses cookies strictly necessary for authentication and does not load third-party analytics or advertising. Featurebase Messenger loads only after an authenticated user chooses to open Help. It may then use browser storage needed to identify the support session and preserve conversation continuity; that storage is used for support, not advertising.

12. Storage the Widget Places on a Visitor's Device

On a website that uses Optzi, the consent widget keeps two first-party items in the visitor's own browser. Both are strictly necessary to provide the consent function the website has chosen to use, and neither is used for tracking, profiling, or advertising:

These items are first-party storage set in the context of the website the visitor is using. Optzi loads no third-party storage or SDK on that website.

13. Changes and Contact

We will notify material changes by email and/or dashboard notice. Contact support@useoptzi.com.

Side Quest Energy LLC d/b/a optzi! • Virginia, USA • support@useoptzi.com