Privacy policy

Last updated July 1, 2026

This Privacy Policy explains what personal data Patna, Inc., a Delaware corporation and wholly owned subsidiary of OpenCrate ("Patna," "we," "us"), collects, why we collect it, how we use and share it, how long we keep it, and the choices and rights you have. It applies to visitors to our websites, users of the Patna marketplace and communications tools, and individuals whose data is submitted to us by Brands or Partners. We collect the minimum information reasonably necessary to run campaigns, attribute Outcomes, settle payouts, prevent fraud, meet our legal obligations, and keep the marketplace safe. We do not sell personal data as that term is defined under U.S. state privacy laws, and we do not share personal data for cross-context behavioral advertising.

1. Data we collect

Account data: name, email address, hashed password, authentication method, workspace membership, role, and preferences.

Identity and verification data: where required by law or risk policy, government-issued identifiers, tax identifiers (W-9, W-8BEN, VAT/GST numbers), and information collected for sanctions and adverse-media screening.

Business data: for Brands, company name, registered address, billing address, tax ID, banking or card details (tokenized and held by our payment processors), Campaigns, creative assets, and conversion events; for Partners, promotional channels, referral codes, tracking links, and payout account details.

Usage and device data: pages viewed, features used, IP address, approximate location derived from IP, device type, operating system, browser type, session identifiers, referrers, and error diagnostics.

Communications data: emails, SMS, calls, and messages sent through Patna-provisioned inboxes, phone numbers, or (where a Brand's Campaign requires it) LinkedIn verification tools. Content is retained to enable dispute resolution, fraud review, safety, and legal compliance.

Cookies and similar technologies: strictly necessary cookies, session cookies, and, subject to consent where required, analytics cookies. We do not use third-party advertising cookies. Consent can be updated at any time through your browser settings and, where required, our cookie banner.

2. How we use data

We use personal data to operate the Platform, verify Outcomes, calculate Payouts and Platform Commissions, provide the communications tools, secure the service, prevent and investigate fraud and abuse, respond to disputes, communicate with you, comply with our legal and tax obligations, and improve our products.

We do not use Partner or Brand communications data to train third-party generative AI models. We do not sell personal data. We do not share personal data for cross-context behavioral advertising.

3. Legal bases (EEA/UK)

For individuals in the European Economic Area, the United Kingdom, and Switzerland, we process personal data on the following legal bases: performance of a contract (to provide the Platform you or your organization requested); our legitimate interests (to secure the Platform, prevent and investigate fraud, defend legal claims, and improve our service, balanced against your rights); consent (for optional marketing communications and any non-essential cookies, which you may withdraw at any time); and compliance with legal obligations (including tax, accounting, and anti-money-laundering rules).

4. Sharing

Between counterparties: Brands and Partners see the information reasonably necessary to work together on a given Campaign, including profile information, communications, and Outcome records.

Service providers and sub-processors: hosting, database, payment processing, telecommunications, email deliverability, analytics, error monitoring, customer support, identity verification, and screening vendors, each bound by written contract and permitted to use personal data only on our instructions.

Corporate transactions: in connection with a merger, acquisition, reorganization, financing, or sale of assets, subject to appropriate confidentiality protections.

Legal and safety: to comply with lawful requests, protect our rights and property, enforce our terms, defend legal claims, and investigate suspected fraud, security incidents, or abuse.

With your consent or at your direction, including when you connect a third-party integration.

5. International transfers

Patna is U.S.-based, with team members and sub-processors located across multiple regions. Personal data may be transferred to and processed in the United States and other jurisdictions that may have different data-protection standards than your home jurisdiction. Where required, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and appropriate supplementary technical and organizational measures.

6. Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law. Account and financial records are retained for the life of the account plus seven (7) years to meet tax, audit, and anti-fraud obligations. Conversion logs, communications records, and dispute evidence are retained for at least twenty-four (24) months. On deletion, personal data may remain in encrypted backups for a limited additional period before being overwritten.

7. Your rights

Depending on where you live, you may have the right to request access to, correction of, deletion of, portability of, or restriction of processing of your personal data, to object to certain processing, to opt out of certain uses, and to lodge a complaint with your local data-protection authority. Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, and other U.S. states with comprehensive privacy laws have additional rights, including the right to appeal a denial. To exercise your rights, use the controls in Settings → Privacy or email privacy@onpatna.com. We respond within the timeframe required by applicable law, typically within thirty (30) to forty-five (45) days.

8. Security

We use industry-standard safeguards including encryption in transit and at rest, role-based access controls, single sign-on and multi-factor authentication for staff, least-privilege access, continuous monitoring, and periodic reviews. No system is perfectly secure. If you believe your account or data has been compromised, report it immediately to security@onpatna.com.

9. Children

The Platform is not directed to, and we do not knowingly collect personal data from, anyone under the age of eighteen (18). If you believe a minor has provided us data, contact privacy@onpatna.com and we will take steps to delete it.

10. Changes

We may update this Policy from time to time. Material changes will be notified in-app or by email at least fifteen (15) days before they take effect, or such shorter period as is reasonably necessary for legal or security reasons. The "Last updated" date at the top reflects the most recent revision.

11. Contact

Privacy inquiries and rights requests: privacy@onpatna.com. Mailing address: Patna, Inc., 1209 N Orange Street, Wilmington, DE 19801, USA.