Legal
Privacy Policy
Effective date: August 11, 2026
Who we are
OMEC Smart Card Inc. (“OMEC”, “we”, “us” or “our”) operates this website at https://omecus.com. We manufacture smart cards, RFID products and related credentials at 8293 Dow Cir, Strongsville, Ohio 44136, United States. We are the controller of the personal information described in this policy. For any privacy question or request, contact legal@omecus.com or write to us at the address above.
Scope of this policy
This policy covers your use of this website and the handling of inquiries you submit through it, including by email follow-up. It does not cover data we process while manufacturing products for customers (such as personalization data), which is governed by the written agreement for that program, and it does not cover third-party websites we link to.
Information we collect
Information you provide. When you submit our contact form we collect your name, company, work email address, your message, whether you requested a catalog, and program details such as application, technology, material and volume requirements. The fields marked required are needed to answer your inquiry; if you do not provide them, we cannot process it.
Technical and security information. Like most websites, our infrastructure processes your IP address, browser type and version (user agent) and standard request headers, which can indicate your approximate country or region. We use this information for security, rate limiting and troubleshooting, and our web server keeps standard access logs for a limited period.
Anti-spam signals. The contact form uses Cloudflare Turnstile to distinguish people from bots. Cloudflare processes signals including your IP address, TLS fingerprint, user agent, and the site key and origin of the page (see Cloudflare’s Turnstile privacy addendum). The form also sets a signed session cookie recording when you opened it, and our rate limiter briefly holds your IP address (for about 15 minutes) and your email address (for about one hour) in server memory to block abusive repeat submissions.
Inquiry records. Accepted inquiries are stored as lead records together with a unique identifier, the time of submission, and the version of our website terms in force when you submitted.
Preferences kept on your device. Your theme choice (light/dark/auto) is stored in your browser’s local storage and never sent to us.
What we do not collect. We do not use advertising trackers or third-party analytics, and fonts and other page assets are served from our own infrastructure rather than third-party services.
How we use your information and our legal bases
Where the EU or UK General Data Protection Regulation applies, our legal basis for each purpose is noted below.
- Responding to your inquiry - answering your message, sending a confirmation email, providing a catalog if requested, and following up on your program requirements (taking steps at your request prior to a contract, Article 6(1)(b), and our legitimate interest in managing business relationships, Article 6(1)(f)).
- Security and abuse prevention - bot verification, rate limiting and server logging (our legitimate interest in protecting the site and the contact form, Article 6(1)(f)).
- Legal compliance - keeping records and responding to lawful requests where required (Article 6(1)(c)).
We do not sell or rent your information, we do not use it for advertising, and we do not use it for automated decision-making or profiling that produces legal or similarly significant effects.
Who receives your information
We share personal information only with the service providers that run this site and its email flows:
- DigitalOcean hosts our application and stores our inquiry records on servers in the United States.
- Cloudflare provides the Turnstile anti-bot verification described above. Cloudflare acts as our processor when verifying submissions and as an independent controller when it uses signals to improve the Turnstile service.
- SMTP2GO delivers your confirmation email and our internal sales notification, both of which contain your inquiry details. Per SMTP2GO’s privacy policy, email headers are retained for a default period of 35 days and sampled content may be stored for compliance review.
We may also disclose information where required by law or legal process, to protect our legal rights, or to a successor in a merger, acquisition or sale of assets (in which case this policy continues to apply to the transferred information).
Cookies, local storage and tracking
- omec_contact_dwell - a signed first-party session cookie set when you open the contact form, used only for spam prevention. It expires after 30 minutes.
- theme - your display preference, kept in local storage on your device only.
- Cloudflare Turnstile may set its own cookies or use browser storage while verifying a submission, under Cloudflare’s privacy policy.
We do not engage in cross-site tracking, targeted advertising, or the sale or sharing of personal information, so there is no such activity for a “Do Not Track” or Global Privacy Control signal to opt out of on this site.
How long we keep it
- Inquiry and lead records - kept while relevant to your inquiry and any resulting business relationship, and reviewed periodically. We delete them on verified request unless we must keep them to meet a legal, accounting or reporting obligation.
- Email copies - confirmation and sales notification emails are retained in our mailboxes under our ordinary business-records practices, and by SMTP2GO as described above.
- Rate-limit records - held in server memory for at most about one hour.
- Form session cookie - expires after 30 minutes.
- Server access logs - retained for a limited period for security and troubleshooting, then discarded.
Data security
We use reasonable administrative and technical safeguards designed to protect the information you submit, including transport encryption (HTTPS) and access limited to personnel who need it to respond to your inquiry. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Your privacy rights
Depending on where you live, you may have the right to know what personal information we hold about you, to receive a copy of it in a portable format, to have it corrected or deleted, to restrict or object to our processing of it (including processing based on legitimate interests), and to withdraw any consent you have given, without affecting processing that happened before withdrawal.
To exercise any right, email legal@omecus.com. You may use an authorized agent, in which case we may ask for proof of authorization. We may need to verify your identity, for example by confirming control of the email address you used, before acting on a request. We will respond within the period required by applicable law. Legal exceptions may allow or require us to decline part of a request; if we do, we will explain why, and you may appeal by replying to our response with “Appeal” in the subject line. We will never discriminate against you for exercising a privacy right.
If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local supervisory authority or the UK Information Commissioner’s Office. We would appreciate the chance to address your concern first.
International data transfers
We are based in the United States, and information you submit through this site is provided directly to us and processed and stored in the United States, where data protection laws may differ from those in your jurisdiction. Where our service providers process EEA or UK personal data, they do so under data processing agreements that incorporate appropriate safeguards such as standard contractual clauses; contact legal@omecus.com for more information about these safeguards. Given the occasional, low-risk nature of our processing of EEA and UK personal data, we have not appointed a representative in those jurisdictions; you can always reach us directly.
Children's privacy
This site is a business-to-business resource intended for professional audiences. It is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has submitted information to us, contact legal@omecus.com and we will delete it.
Changes to this policy
If this policy changes, the updated version will be posted on this page with a new effective date, and changes apply from that date forward. If a change materially affects information we already hold about you, we will take reasonable steps to notify you directly, such as by email. Prior versions are retained and available on request.
Contact us
For privacy questions, requests or complaints, email legal@omecus.com or write to OMEC Smart Card Inc., 8293 Dow Cir, Strongsville, Ohio 44136, United States.