Privacy Policy

1. INTRODUCTION AND SCOPE

Onix Performance, LLC, a limited liability company doing business as Rynuu

(“Rynuu,” “Company,” “we,” “us,” or “our”) is committed to protecting the

privacy of its users (“User,” “you,” or “your”). This Privacy Policy (the

“Policy”) describes how Rynuu collects, uses, stores, shares, and protects

personal information in connection with the Rynuu platform, mobile

application, and related services (collectively, the “Services”).

By accessing or using the Services, you acknowledge that you have read,

understood, and agree to be bound by this Privacy Policy. If you do not agree

to this Policy, you must discontinue access to and use of the Services

immediately.

2. INFORMATION WE COLLECT

2.1 Information Provided by Users. The Company collects personal

information that Users voluntarily provide when registering for or using the

Services. Such information includes, without limitation: full name; email

address; password (stored in encrypted form); profile information; and any

other information Users choose to submit through the Services.2.2 Payment Information. Payment transactions are processed by Stripe,

Inc. (“Stripe”), a third-party payment processor. Rynuu does not collect or

store full payment card numbers, card verification values (CVV), or other

sensitive cardholder data. When you submit payment information through the

Services, that information is transmitted directly to and stored by Stripe in

accordance with Stripe’s own Privacy Policy, available at

https://stripe.com/privacy. Rynuu may receive and store limited transaction

metadata from Stripe—including but not limited to the last four digits of a

payment card, card brand, billing address, and transaction confirmation

identifiers—solely for billing reconciliation, customer support, and fraud

prevention purposes.

2.3 Automatically Collected Information. When Users access or use the

Services, the Company may automatically collect certain technical and usage

information, including but not limited to: device identifiers; Internet Protocol

(IP) address; browser type and version; operating system; pages visited and

features accessed; time spent on pages; clickstream data; and other usage

analytics generated through interaction with the Services.

2.4 Location Information. The Company may collect approximate location

information derived from a User’s IP address. Where a User has granted

explicit permission through their mobile device settings, the Company may

also collect precise geolocation data. Users may withdraw location

permissions at any time through their device settings.

2.5 Communications. The Company may collect messages, feedback,

support requests, and other content submitted by Users through the

Services, including communications directed to the Company’s support

channels.

2.6 Information from Third-Party Sources. The Company may receive

information about Users from third-party services integrated with theServices, such as social login providers, analytics providers, and Stripe. Such

information is subject to the privacy policies of the respective third parties.

Users are encouraged to review those policies independently.

3. HOW WE USE YOUR INFORMATION

The Company uses the personal information it collects for the following

purposes:

3.1 To provide, operate, maintain, secure, and improve the Services;

3.2 To process payment transactions via Stripe and to send related

information, including transaction confirmations, invoices, and payment

receipts;

3.3 To communicate with Users regarding account activity, service updates,

security alerts, and technical support;

3.4 To send promotional and marketing communications where the User has

provided consent or where otherwise permitted by applicable law, and to

provide Users with the ability to opt out of such communications;

3.5 To personalize the User experience and to deliver relevant content and

features;

3.6 To monitor and analyze usage patterns, trends, and Service performance

for the purpose of improving and developing the Services;

3.7 To detect, investigate, prevent, and respond to fraudulent activity, abuse,

security incidents, and other potentially harmful or unlawful conduct; and

3.8 To comply with applicable legal obligations, regulatory requirements,

and lawful governmental requests.4. PAYMENT PROCESSING BY STRIPE

4.1 Rynuu uses Stripe, Inc. as its exclusive third-party payment processor for

all financial transactions conducted through the Services. Stripe is a Payment

Card Industry Data Security Standard (PCI-DSS) compliant payment

platform. By submitting payment information through the Services, you

authorize Rynuu to transmit that information to Stripe for processing

purposes in accordance with this Policy.

4.2 Your payment data is governed by Stripe’s Privacy Policy and Terms of

Service. Rynuu encourages all Users to review Stripe’s policies, available at

https://stripe.com/privacy, prior to submitting any payment information

through the Services.

4.3 Rynuu is not responsible for the privacy or security practices of Stripe.

Any disputes, questions, or concerns regarding payment data held by Stripe

should be directed to Stripe directly. Rynuu bears no liability for Stripe’s

handling of User payment data.

4.4 Stripe may independently collect information about Users in connection

with processing payment transactions. Such collection by Stripe is subject to

Stripe’s own terms and privacy practices and is outside of Rynuu’s control.

5. SHARING OF INFORMATION

5.1 Service Providers. The Company may share personal information with

third-party vendors and service providers engaged to perform services on the

Company’s behalf, including but not limited to Stripe for payment processing,

cloud hosting providers, analytics providers, and email delivery services.

Such vendors are bound by contractual confidentiality obligations and areprohibited from using personal information for any purpose other than

providing the contracted services.

5.2 Business Transfers. In connection with a merger, acquisition,

reorganization, dissolution, or sale of all or a portion of the Company’s assets,

personal information held by the Company may be among the assets

transferred. The Company will notify Users of any such transfer by posting a

prominent notice on the Services or by sending notice to the email address

associated with a User’s account.

5.3 Legal Compliance and Protection. The Company may disclose

personal information when required to do so by law, court order, or

governmental authority, or where the Company determines in good faith that

such disclosure is reasonably necessary to protect the rights, property, or

safety of the Company, its Users, or the public.

5.4 With User Consent. The Company may share personal information for

any other purpose disclosed to the User at or prior to the time of collection, or

with the User’s prior express consent.

6. DATA RETENTION

The Company retains personal information for as long as is reasonably

necessary to fulfill the purposes described in this Policy, unless a longer

retention period is required or permitted by applicable law. Upon receipt of a

valid account deletion request, the Company will delete or anonymize the

User’s personal data within a commercially reasonable time, except to the

extent that retention of such data is required by applicable law, regulation, or

legal process. Transaction records and payment metadata associated with

Stripe-processed payments may be retained for the period required under

applicable financial regulations and tax laws.

7. SECURITY

The Company employs industry-standard technical, administrative, and

physical safeguards designed to protect personal information against

unauthorized access, disclosure, alteration, loss, or destruction. Payment

data is protected via Stripe’s PCI-DSS compliant infrastructure.

Notwithstanding the foregoing, no method of transmission over the Internet

or electronic storage is completely secure. The Company cannot guarantee

the absolute security of any personal information and makes no warranty,

express or implied, to that effect. Users are responsible for maintaining the

confidentiality of their account credentials.

8. COOKIES AND TRACKING TECHNOLOGIES

Rynuu uses cookies, web beacons, pixels, and similar tracking technologies to

enhance the functionality of the Services, to analyze usage patterns, and to

deliver relevant content. Users may control cookie preferences through the

settings of their web browser; however, disabling cookies may impair or limit

certain features and functionality of the Services. The Company may engage

third-party analytics and advertising technology providers that operate under

their own respective privacy policies and terms of service. Users are

encouraged to consult those providers’ policies for additional information.

9. CHILDREN’S PRIVACY

The Services are not directed to individuals under the age of thirteen (13), or

such higher age of digital consent as may be applicable in the User’s

jurisdiction. The Company does not knowingly collect, solicit, or retain

personal information from minors below such applicable age. If the Company

becomes aware that personal information has been collected from a minorwithout appropriate parental or guardian consent, the Company will take

prompt steps to delete such information. Parents or guardians who believe

that a minor has submitted personal information to the Company should

contact us immediately at admin@rynuu.com.

10. INTERNATIONAL DATA TRANSFERS

Personal information collected by the Company may be transferred to, stored

in, and processed in countries other than the User’s country of residence,

including the United States, which may not provide the same level of data

protection as the laws of the User’s home jurisdiction. The Company takes

appropriate measures designed to ensure that such cross-border transfers of

personal information are conducted in compliance with applicable data

protection laws, including through the use of contractual safeguards or other

lawful transfer mechanisms where required.

11. USER RIGHTS

Depending on the laws of the jurisdiction in which a User resides, the User

may have certain rights with respect to their personal information. Such

rights may include the following:

11.1 Right of Access. The right to request access to and receive a copy of

the personal information the Company holds about the User.

11.2 Right to Rectification. The right to request correction or update of

personal information that is inaccurate, incomplete, or outdated.

11.3 Right to Erasure. The right to request deletion of personal

information, subject to applicable legal retention requirements and other

lawful grounds for continued processing.

11.4 Right to Object or Restrict Processing. The right to object to, or

request restriction of, certain processing activities involving the User’s

personal information.

11.5 Right to Data Portability. The right to receive personal information

in a structured, commonly used, and machine-readable format, and to

transmit such information to another controller, where technically feasible

and required by applicable law.

11.6 Right to Withdraw Consent. Where the processing of personal

information is based on the User’s consent, the right to withdraw such

consent at any time without affecting the lawfulness of processing carried out

prior to withdrawal.

To exercise any of the foregoing rights, Users should submit a written request

to the Company at admin@rynuu.com. The Company will respond to all

verified requests within the timeframe required by applicable law. The

Company reserves the right to verify the identity of any individual submitting

a rights request prior to acting on such request.

12. GOVERNING LAW

This Privacy Policy shall be governed by and construed in accordance with the

laws of the Commonwealth of Virginia without regard to

its conflict of law provisions. Any disputes arising out of or relating to this

Privacy Policy shall be subject to the exclusive jurisdiction of the state and

federal courts located in the Commonwealth of Virginia, and the

parties consent to personal jurisdiction in such courts.

13. CHANGES TO THIS POLICY

The Company reserves the right to modify or update this Privacy Policy at any

time in its sole discretion. In the event of a material change to this Policy, the

Company will provide advance notice to Users by posting a prominent notice

on the Services or by sending written notice to the email address associated

with the User’s account, no fewer than thirty (30) days prior to the effective

date of the change. The updated Policy will indicate the revised effective date

at the top of the document. Continued use of the Services following the

effective date of any updated Policy shall constitute the User’s acceptance of

the revised terms. Users who do not agree to a material change should

discontinue use of the Services prior to the effective date of such change.

14. CONTACT INFORMATION

For all privacy-related inquiries, requests, or concerns, Users may contact

the Company using the information set forth below:

Onix Performance, LLC d/b/a Rynuu

9480 Main St #1082

Fairfax, VA 22031

United States

Email: admin@rynuu.com

The Company will make reasonable efforts to respond to all privacy-related

inquiries in a timely manner and in accordance with applicable law.

Attorney Review Notice — Privileged & Confidential Draft

This document has been prepared for attorney review prior to publication and does not

constitute legal advice. All bracketed placeholders must be completed by qualified legal

counsel prior to publication or distribution. The following areas are identified as priority

review items:(i) Governing Law Jurisdiction — Counsel should confirm the appropriate state

law designation at Section 12 and ensure consistency with the Company’s formation

state and operational nexus.

(ii) Age of Digital Consent — Section 9 references age 13 as the baseline

threshold consistent with COPPA. Counsel should confirm whether any applicable

jurisdiction (e.g., EU/EEA under GDPR Article 8, UK, or U.S. state law) imposes a higher

minimum age and revise accordingly.

(iii) International Data Transfer Mechanisms — Section 10 addresses

cross-border transfers in general terms. If the Company processes personal data of

EU/EEA, UK, or Swiss residents, counsel should assess whether Standard Contractual

Clauses, a Data Processing Agreement, or other lawful transfer mechanism is required

and supplement this Policy accordingly.

(iv) Stripe Data Processing Relationship — Sections 2.2 and 4 address

Stripe as a third-party payment processor. Counsel should confirm whether Stripe is

properly characterized as a processor or controller in all applicable jurisdictions, and

whether a separate Data Processing Addendum with Stripe is required under GDPR or

other applicable law.