Last updated: August 7, 2026
OCDevel LLC ("OCDevel," "we," "us") operates ocdevel.com and the cookieless analytics tool used on this site. This notice explains how we collect, use, and share information for visitors to ocdevel.com, for account holders using our on-site tools, and for customers and end users of the OCDevel Analytics script. When a customer installs the script on their own site, that customer is the controller for their visitors; we act as their processor and follow their instructions.
sessionStorage (resets when the browser session ends), plus event properties for affiliate/CTA clicks and, on authenticated tool pages, the subscription tier and price associated with an event. On the first page view in a session we also collect referrer domain (the site you arrived from, reduced to its domain), UTM campaign tags, a five-bucket viewport size bin (xs/sm/md/lg/xl, never exact pixel dimensions), device class, browser family, OS family, and the visitor's country as reported by a CloudFront edge header. We do not collect city, region, timezone, browser or OS version numbers, or any per-visitor identifier. On ocdevel.com we also record: an impression event when an affiliate link is displayed, carrying the same link identifier its click event carries; a warn: event family around the buy-warning interstitial; and a compare: event family on the spec-comparison surface. Custom event properties are filtered for obvious PII keys; referrer domains may occasionally reveal the site you came from. We do not store raw IPs in analytics tables, and session IDs do not persist across sessions. CloudFront/API Gateway headers (including IP/user agent) appear in access and transit logs, and in the S3 error bucket that holds events our pipeline could not process, to ensure delivery and support debugging — see Retention for how long each is kept.Legal bases (EU/UK): contract (when you create an account or use the service), legitimate interests (site analytics, security, product improvement, communicating with existing users), and consent where required (e.g., optional marketing or if future ad/analytics cookies are introduced). When you use our analytics script on your own site, you are the controller for your visitors and should disclose that lawful basis to them; we process data on your instructions and collect only the attributes in the basket you selected for that site.
sessionStorage plus an opt-out flag in localStorage; we do not set tracking cookies for our own analytics or use persistent identifiers across browser sessions. Writing that tab-scoped session key, and reading UTM tags from the URL, are both operations the ePrivacy Directive's Article 5(3) reaches. Our own tool classifies this configuration as exemption-resting, and we use that word deliberately: we do not claim ocdevel.com is banner-free by construction. It rests on the audience-measurement exemptions that several national regulators apply to first-party analytics, subject to their conditions. The tool also offers a zero-footprint configuration, which retains neither the session key nor the campaign tags — the tracker still writes the same tab-scoped sessionStorage id, it is simply discarded on arrival — and this site does not use it.localStorage to keep you signed in. On pages with checkout entry points, Stripe.js sets its own fraud-prevention cookies (__stripe_mid, __stripe_sid); these are functional/security cookies, not advertising trackers.?notrack=1 (or setting localStorage.setItem('notrack','true')). Remove that key to re-enable tracking. You can also block requests to https://events.ocdevel.com or disable JavaScript.We do not sell personal data or share it for cross-context behavioral advertising. We may disclose information if required by law, to protect rights, or during a business transaction.
Data is encrypted in transit and at rest within our providers, and access is limited to operational needs. Our analytics stores no per-visitor identifier at all. Custom event properties are filtered for obvious PII keys. No method is 100% secure; please use strong, unique credentials and contact us if you suspect an issue.
We primarily use U.S.-based infrastructure and service providers. Data may be transferred to other countries where our providers (AWS, Stripe, Google, etc.) operate. We rely on their transfer safeguards (e.g., standard contractual clauses) where applicable.
Depending on your location, you may have rights to access, correct, delete, or receive a copy of your data, and to object or restrict certain processing. You can:
For California residents: we do not sell or share personal information for cross-context behavioral advertising. You may request to know, delete, or correct personal information and to limit sensitive data use (we do not collect sensitive categories for our analytics).
Our services are not directed to children under 16. If you believe a child provided us information, contact us and we will delete it.
We may update this policy to reflect product or legal changes. We will revise the "Last updated" date and, if changes are significant, provide additional notice.
For questions or requests, email tylerrenelle@gmail.com.