Privacy Policy
Last Updated: July 8, 2026
1. Introduction
Welcome to Onyx I-management ("we," "our," "us"). Onyx I-management is a platform designed to connect Brands, Managers, and Influencers to collaborate on campaigns, track missions, and manage communications.
We are committed to protecting your privacy. This Privacy Policy details how we collect, store, transmit, use, and safeguard your personal and sensitive information when you use our mobile application and related web services. By accessing or using the Onyx I-management application, you consent to the data collection and practices described in this policy.
2. Information We Collect
To deliver a functional and personalized experience for Brands, Managers, and Influencers, we collect several categories of information.
A. Account and Profile Information
- Registration Details: When you create an account, we collect your name, email address, phone number, and password.
- Role Selection: We collect your role (Brand, Manager, or Influencer) to customize your user interface and permissions.
- Profile Data: You may provide profile pictures, bio details, social media handles, and agency affiliations.
B. Transactional and Collaboration Data
- Missions & Campaigns: Information relating to contracts, campaigns, deliverables, mission milestones, and task verification details.
- Messaging Content: Chat histories and messages transmitted through our real-time messaging services.
- Financial Info: In-app purchase history and onboarding details for Stripe payment integration.
C. Device and Usage Details
- Device Metadata: IP address, unique device identifiers, device model, operating system version, and system language.
- Log Data: Performance logs, crash reports, and app activity data (e.g., screens visited, features used).
3. Sensitive Data & Permissions Handling
The Onyx I-management app requires access to certain sensitive device features to perform essential core functions. We only access these permissions with your explicit consent.
Usage & Purpose: We request access to your device's Camera and Photo Gallery (using the image_picker library) to allow you to:
- Take or upload profile pictures for user identification.
- Upload documents for brand, manager, or influencer verification.
- Submit visual proof of completed mission deliverables (e.g., screenshots or photos of campaigns).
Secure Handling: These images and files are transmitted securely using HTTPS/SSL encryption to our private server and are stored behind firewalls. We do NOT harvest, share, or sell your photos. They are accessed strictly when you initiate an upload.
Usage & Purpose: We use Firebase Cloud Messaging to send alerts regarding contracts, mission approvals, and real-time chat messages.
Secure Handling: Your device registration token is securely transmitted and stored in our database. It is never shared with unauthorized third parties and is updated securely when registration changes.
4. How We Use Data
We process your personal and sensitive data strictly for the following purposes:
- Service Provision: To create your account, configure your dashboard, execute contracts, and enable communication between Brands, Managers, and Influencers.
- Transaction Processing: To complete financial payouts and process purchases safely through Stripe integrations.
- Notifications: To send you essential updates about mission updates, verification steps, and incoming messages.
- Safety & Verification: To verify influencer, manager, and brand credentials to maintain a trusted environment.
- Security: To detect, prevent, and debug potential security issues, fraudulent behaviors, or system crashes.
5. Secure Data Handling & Transmission
We employ state-of-the-art administrative, technical, and physical safeguards to protect all user data against unauthorized access, loss, alteration, or disclosure.
A. Encryption in Transit
All communications between the Onyx I-management mobile application and our servers are encrypted using Transport Layer Security (TLS 1.2 or 1.3) and HTTPS protocols. This prevents interception of your credentials, profile pictures, and messages by external parties.
B. Encryption at Rest
Sensitive local settings and session tokens are stored on your device using hardware-backed secure storage APIs (such as the Keychain on iOS and Keystore on Android) via the flutter_secure_storage mechanism. On our servers, databases housing user records are encrypted and protected by strict network firewalls.
C. Access Control
Access to personal user data is strictly limited to authorized personnel who require access to debug the system or perform verification checks.
7. Retention & Data Deletion Policy
We retain your personal data only for as long as is necessary to provide the services described, or to comply with our legal obligations.
How to Request Account & Data Deletion:
We respect your right to control your personal data. You can request complete deletion of your account and all associated personal information at any time:
- In-App Deletion: Go to the menu/settings section of the Onyx I-management app and select Delete Account. This will trigger our secure deletion API.
- By Support Request: You can send an email directly to contact@supponyx-sys.net with the subject line "Account Deletion Request", providing your registered email address.
Processing Time: Upon receiving a deletion request (either in-app or via email), we will delete or permanently anonymize all your registration details, messages, profile pictures, and active contract relations from our active databases within 30 days. Backups may retain anonymized records for up to 90 days before final overwrite.
8. Your Rights & Choices
Depending on your location (such as the European Economic Area or California), you may hold specific statutory rights regarding your personal information, including:
- Right of Access: You can request a summary of the personal data we hold about you.
- Right to Correction: You can update inaccurate profile details directly inside the application.
- Right to Deletion: As detailed in Section 7, you can request that we wipe your information.
- Right to Object: You can choose to withdraw consent for location or notification permissions via your operating system settings at any time.
9. Contact Information
If you have any questions, feedback, or concerns regarding this Privacy Policy or our secure data handling procedures, please contact us at:
Support Email:
contact@supponyx-sys.net