SECTION 802 · BY OVNEL
SECTION 802 Privacy Policy
Effective and last updated: October 2, 2026
Privacy version: 2026-10-02
Yuta Asano, trading as A-Ovnel (the “Operator”), establishes this Policy for information handled through SECTION 802, its Chrome extension, related websites, email, and associated services.
Cross-page run observations and retention
A cross-page run handles its start, observed route, endpoint and checklist answers in one tab where the user explicitly starts recording. Separately from start-page rules, a checklist can allow up to 10 additional exact origins (scheme, host and port). The starting origin is always included; the scope, checklist and workspace are fixed at start. Same-origin navigation and reload retain the run. Moving to another origin pauses it, even on an allowed site: click the extension icon again, review the destination preview and explicitly resume. URLs before start, while paused, after completion, outside scope and in other tabs are not observed. Returning to an allowed site does not automatically resume. Registering a site does not itself grant browser access.
The start screen shows the URL to record and allowed sites. Record URL paths is selected by default and retains ordinary paths. Uncheck it to record only origins for the run's start, route and endpoint. Credentials (userinfo), query strings and fragments (hashes) are removed before extension session storage and transmission, and the server validates them again. Obvious email or authentication paths reduce to the origin, but names, customer IDs and unrecognized secrets can remain; complete anonymization is not guaranteed. Pause before visiting a page you do not want recorded. Inspect observations and the submission review; before the first send, you can remove all paths from start, route and endpoint together. After a send attempt, the retry payload is fixed and this change is unavailable. Close/pause retains answers; cancel discards an unfinished draft and does not undo previously submitted history.
The run's route and answers are sent only when the user chooses Send in the completion review, to the signed-in SECTION 802 API for the workspace fixed at start. That workspace's history access applies, including the user and authorized administrators. The start and observed route are stored separately from normal history, hidden after 30 days and deleted by scheduled cleanup. Endpoints and answers use normal retention: 365 days on Personal and 730 days on Team/Enterprise. Observations are limited to 200 and may omit overflow, brief transitions, redirects or paused periods; they are not a complete browsing audit log. Page titles, body text, page form contents, click sequences and images are not collected. Unfinished drafts use extension session storage and are removed on completion, cancellation or logout. Browser/extension restart recovery and exact-time deletion during suspension are not guaranteed. Work-page routes and Run identifiers are not sent to GA4/GTM.
1. Scope
This Policy applies to registration, use, inquiries, payments, team invitations, referrals, and related processing. Linked third-party services apply their own policies.
2. Controller
The controller is Yuta Asano, trading as A-Ovnel, and is located in Japan. Where lawful to omit a street address or telephone number, it will be disclosed without delay upon a verified request through the designated contact channel.
3. Information collected
We may process account details; authentication, session, extension-login and security events; workspace, membership, role, invitation and sharing data; checklist definitions, page rules, target URLs, answers, run history and snapshots; subscription, seat, billing and Stripe identifiers; referral and Credit data; onboarding progress; inquiry details; page paths, Service interactions and usage, approximate region, device, browser, session, access, request and error information; cookies and local storage required to provide the Service; and cookies or other online identifiers used for analytics.
4. Purposes
We use information to provide and secure the Service, authenticate users, manage accounts and teams, operate checklists and history, process contracts, billing, payments, refunds and seats, provide trials and referrals, send operational notices, answer inquiries, prevent abuse, investigate incidents, understand Service usage, improve navigation, content and features, analyze trends in onboarding and checklist execution, improve quality, preserve evidence, exercise rights, and comply with law.
5. Third-party information entered by users
Users must secure any authority, consent, or other lawful basis required before entering another person's information.
6. Providers and processors
We use Cloudflare for delivery, protection, Workers, Static Assets, D1, and Turnstile; Resend for authentication and operational email; Stripe for payments, billing, and Customer Portal; and Google LLC for tag management through Google Tag Manager and usage analytics through Google Analytics. Stripe handles card numbers and security codes; we generally do not store them directly.
7. Analytics, cookies, and external transmission
We use Google Tag Manager and Google Analytics, provided by Google LLC, to understand and improve use of the Service.
Google Analytics may transmit or process page paths; Service interaction and usage information; browser, device, session, and other technical information; cookies or other online identifiers; and approximate region. Technical information such as an IP address may also be transmitted from a browser to and processed by Google. SECTION 802's implementation limits page information to the origin and pathname and excludes the query string and URL hash.
We design our Google Analytics payloads not to send names, email addresses, telephone numbers, street addresses, company or organization names, user IDs, workspace, checklist, or Check Run IDs or names, checklist items, answers, notes or other business content, free text, form content, API bodies, raw errors, URL query strings or hashes, authentication codes, magic links, invitation or referral codes, Stripe identifiers or Checkout URLs, Google Ads identifiers, or data for advertising personalization.
We use this information to understand Service usage, improve navigation, content and features, analyze trends in onboarding and checklist execution, and improve quality. We do not use it for ad serving, remarketing, Google Signals, or advertising personalization.
Information sent to Google LLC is handled under Google's terms, Privacy Policy, and related policies. See https://policies.google.com/technologies/partner-sites?hl=en for information about Google's handling.
Users can control cookies through their browser settings and can use the Google Analytics opt-out browser add-on described at https://support.google.com/analytics/answer/181881?hl=en. Restricting cookies may affect authentication or other cookies required to provide the Service.
8. International processing
Providers may process information outside Japan. We take measures required by applicable law.
9. Third-party disclosure
We do not disclose personal data without consent except where permitted by law, required for processing, involved in business succession, or otherwise lawful.
10. Retention
Run history is normally kept for 365 days on Personal and 730 days on Team and Enterprise. Certain authentication attempts, completed invitations, and sent operational messages are normally kept for 30 days; certain processed payment-integration logs for 90 days. Information may be kept longer where required for law, accounting, disputes, or security.
11. Account deletion
Deletion normally has a 30-day grace period and may be deferred for unresolved billing or Team-owner duties. Personal data is deleted. Shared Team business records may be retained after identifiers are removed or replaced.
12. Security
We use appropriate access control, credential hashing, transport protection, role management, minimized logging, security monitoring, and provider management. Login codes, extension login codes, login tokens, and secrets are not designed to be stored in plaintext logs.
13. Incidents
We investigate, contain, report, and notify affected persons about leaks or similar incidents as required by applicable law.
14. Access, correction, and restriction
Requests under applicable data-protection law are accepted through the designated contact channel, subject to identity verification and lawful exceptions.
15. Statistics
Non-identifying statistical information may be used for quality improvement and other lawful purposes.
16. Changes
Material changes will be announced by a reasonable method, and consent will be obtained where required by law.
17. Contact
Contact A-Ovnel / SECTION 802 through the designated form at https://ovnel.com/#contact.
