Osta LLC Privacy Policy California Residents
Effective Date: August 7, 2025
Last Reviewed on: August 7, 2025
This California Privacy Policy describes how Osta LLC and its subsidiaries, affiliates, and related entities (collectively, "Osta," "Company," "we," or "us") collect and process personal information about our consumers who reside in California. The California Consumer Privacy Act ("CCPA") requires us to provide our California consumers with a privacy policy that contains a comprehensive description of our online and offline practices regarding our collection, use, sale, sharing, and retention of their personal information, along with a description of the rights they have regarding their personal information. This Privacy Policy provides the information the CCPA requires, together with other useful information regarding our collection and use of personal information. Any terms defined in the CCPA have the same meaning when used in this policy.
This Privacy Policy does not apply to our collection and use of personal information in an employment capacity. Employees, job applicants, contractors, interns, or other workers seeking more information our employment-related personal information policies and practices should see our employee privacy notice on the company intranet at: [EMPLOYEE PRIVACY POLICY URL].]
This Privacy Policy does not apply to our collection and use of personal information from residents outside of California. Consumers residing in other locations should see our general privacy notice at: [GENERAL PRIVACY POLICY URL].
Personal Information Collected
We collect and use information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household ("personal information"). Personal information does not include:
Publicly available information, including from government records, through widely distributed media, or that the consumer made publicly available without restricting it to a specific audience.
Lawfully obtained, truthful information that is a matter of public concern.
De-identified or aggregated consumer information.
Personal Information Categories Chart
The chart below identifies which categories of personal information we collected from our consumers within the last 12 months and the expected retention period.
Category | Examples of Data Collected | Collected | Retention Period | |
---|---|---|---|---|
A. Identifiers | Name, email, phone number, account ID, IP address | Yes | Duration of account + 2 years (for accounting/legal hold) | |
B. California Customer Records | Name, address, telephone, payment token/last 4 digits (excluding SSN/driver’s license) | Yes (subset) | Transactions: 7 years (tax/audit)Profile fields: Account life + 2 years | |
C. Protected Class Information | Race, religion, etc. | No | — | |
D. Commercial Information | Service requests, quotes, invoices, purchase history | Yes | 7 years (for accounting, warranty, or dispute resolution) | |
E. Biometric Information | Facial recognition, voiceprints | No | — | |
F. Network Activity | App interactions, screens viewed, crash logs | Yes | 24 months (for analytics purposes) | |
G. Geolocation Data | GPS-based location for routing or proximity verification | Yes | 24 months (for operations and fraud prevention) | |
H. Sensory Data | Audio, video, image recordings | Yes (images/video only) | Job-related media: 4 years (per California contract statute)Support uploads: 24 months | |
I. Professional or Employment Data | Job history, performance evaluations | No (in consumer context) | — | |
J. Non-public Education Information | Student records | No | — | |
K. Inferences | Profile-based preferences or abilities | No (no profiling beyond essentials) | — | |
L. Sensitive Personal Information | Refer to Sensitive Personal Information (SPI) table | Yes (limited) | Refer to SPI table |
Sensitive Personal Information Categories Chart
Sensitive personal information is a subtype of personal information consisting of the specific information categories listed in the chart below. Importantly, the CCPA only treats this information as sensitive personal information when we collect or use it to infer characteristics about a consumer. The chart below identifies which sensitive personal information categories, if any, we have collected from consumers to infer characteristics about them in the last 12 months.
Sensitive Personal Information Category | Collected to Infer Characteristics? | Retention Period |
---|---|---|
L.1 Government identifiers (SSN, DL, passport) | No / Not collected | — |
L.2 Account access credentials (username + password) | No | Account life + 2 years after closure |
L.3 Precise geolocation | No | 24 months |
L.4 Racial/ethnic origin | No / Not collected | — |
L.5 Citizenship/immigration status | No / Not collected | — |
L.6 Religious/philosophical beliefs | No / Not collected | — |
L.7 Union membership | No / Not collected | — |
L.8 Mail/email/text contents not directed to company | No | — |
L.9 Genetic data | No / Not collected | — |
L.10 Neural data | No / Not collected | — |
L.11 Unique biometric identifiers | No / Not collected | — |
L.12 Health information | No / Not collected | — |
L.13 Sex life/sexual orientation | No / Not collected | — |
Sources of Personal Information
We obtain the categories of personal information listed above from the following categories of sources:
Directly from you, such as from the forms or other information you provide to the Company.
Indirectly from you, such as from your interactions with the Company's websites, mobile applications, reward program participation, customer service programs, mobile app service bookings, or app measurement features.
From our service providers, such as customer service support providers, data analytics providers, and payment processor and mapping/geolocation providers
Other customers, such as from referral programs.
Inferences generated by the Company's or our service providers' computer systems.
How We Use Personal Information
Personal Information Collection, Use, and Disclosure Purposes
We may use and disclose the personal information we collect to advance the Company's business and commercial purposes, specifically to:
Develop, offer, and provide you with our products and services, including on-site home services.
Meet our obligations and enforce our rights arising from any contracts with you, including for billing or collections, or to comply with legal requirements.
Fulfill the purposes for which you provided your personal information or that were described to you at collection, and as the CCPA otherwise permits.
Improve our products or services, marketing, or customer relationships and experiences.
Notify you about changes to our products or services.
Administer our systems and conduct internal operations, including for troubleshooting, data analysis, testing, research, statistical, and survey purposes.
Protect our Company, employees, or operations.
Manage your consumer relationship with us, including for:
online account creation, maintenance, and security;
reaching you, when needed, about your account; and
scheduling, technician dispatch, and job anti-circumvention using proximity checks.
Perform data analytics and benchmarking
Administer and maintain the Company's systems and operations, including for safety purposes.
Engage in corporate transactions requiring review of consumer records, such as for evaluating potential Company mergers and acquisitions.
Comply with all applicable laws and regulations.
Exercise or defend the legal rights of the Company and its employees, and affiliates, customers, contractors, and agents.
Respond to law enforcement requests and as required by applicable law or court order.
Sensitive Personal Information Use and Disclosure Purposes
We may use or disclose sensitive personal information for the following statutorily approved reasons (Permitted SPI Purposes):
Performing actions that are necessary for our consumer relationship and that an average consumer in a relationship with us would reasonably expect.
Preventing, detecting, and investigating security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted personal information.
Defending against and prosecuting those responsible for malicious, deceptive, fraudulent, or illegal actions directed at the Company.
Ensuring physical safety.
Short-term, transient use, such as non-personalized advertising shown as part of your current interactions with us, where we do not:
disclose the sensitive personal information to another third party; or
use it to build a profile about you or otherwise alter your experience outside your current interaction with the Company.
Services performed for the Company, including maintaining or servicing accounts, processing or fulfilling transactions, verifying consumer information, processing payments, or providing financing, analytic services, storage, or similar services for the Company.
Activities required to:
verify or maintain the quality or safety of a product, service, or device that we own, manufacture, had manufactured, or control; or
improve, upgrade, or enhance the service or device that we own, manufacture, had manufactured, or controlled.
Collecting or processing sensitive personal information that we do not use for the purpose of inferring characteristics about a consumer.
We do not use or disclose sensitive personal information for purposes other than the Permitted SPI Purposes.
Additional Categories or Other Purposes
We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice. If required by law, we will also seek your consent before using your personal information for a new or unrelated purpose.
We may collect, process, and disclose aggregated or deidentified consumer information for any purpose, without restriction. When we collect, process, or disclose aggregated or deidentified consumer information, we will maintain and use it in deidentified form and will not to attempt to re-identify the information, except to determine whether our deidentification processes satisfies any applicable legal requirements.
Disclosing, Selling, or Sharing Personal Information
Business Purpose Disclosures
We may disclose the personal information we collect, including sensitive personal information, to third parties for the business purposes described in the Personal Information Collection, Use, and Disclosure Purposes section and in the table below, such as to engage third parties to support our business functions. For example, we may disclose your address to our service technician to complete your booking
We only make these business purpose disclosures under written contracts that describe the purposes, require the recipient to keep the personal information confidential, prohibit using the disclosed information for any purpose except performing the contract, and meet the CCPA's other contract requirements for engaging service providers or contractors.
The chart below identifies the categories of entities to whom we have disclosed our consumers' personal information for a business purpose over the preceding 12 months, along with the personal information categories disclosed and the disclosure's business purposes.
Business Purposes Disclosure Recipient Category, Personal Information Category, and Purposes Chart
Category of Disclosure Recipients | Personal Information Categories Disclosed | Sensitive Personal Information Categories Disclosed | Business Purpose Disclosures |
---|---|---|---|
Field Service and Dispatch Providers (formerly “Order Fulfillment and Shipping”) | A. IdentifiersB. California Customer RecordsD. Commercial informationG. Geolocation data | L.3 Precise geolocation | To schedule and complete on-site services you book with us, including dispatch, routing, and arrival verification. |
Customer Service Support Providers | A. IdentifiersB. California Customer RecordsD. Commercial InformationF. Network Activity | None | To support customers using our products and services, including account management and troubleshooting. |
Payment Processors | A. IdentifiersB. California Customer RecordsD. Commercial Information | None | To process payments and prevent fraud. |
Analytics and Crash Reporting Providers | F. Network Activity | None | To improve app performance, stability, and user experience. |
Maps/Location Services Providers | G. Geolocation data | L.3 Precise geolocation | To provide routing, arrival estimates, and anti-circumvention proximity checks. |
Selling or Sharing Personal Information
We do not sell your personal information to third parties and have not sold it in the preceding 12 months. We do not share your personal information with third parties for cross-context behavioral advertising purposes and have not shared your personal information in the preceding 12 months.
Your Rights and Choices
If you are a California resident, the CCPA grants you the following rights regarding your personal information:
Right to Know and Data Portability Requests
You have the right to request that we disclose certain information to you about our collection and use of your personal information (the "right to know"), including the specific pieces of personal information we have collected about you (a "data portability request"). Our response will cover the 12-month period preceding the request, although we will honor requests to cover a longer period that do not extend past January 1, 2022, unless doing so would be impossible or involves disproportionate effort. You may make exercise your right to know twice within in any 12-month period. Once we receive your request and confirm your identity (see How to Exercise Your Rights), we will disclose to you:
The categories of:
personal information we collected about you; and
sources from which we collected your personal information.
The business or commercial purpose for collecting your personal information and, if applicable, selling or sharing your personal information.
If applicable, the categories of persons, including third parties, to whom we disclosed your personal information, including separate disclosures identifying the categories of your personal information that we:
disclosed for a business purpose to each category of persons; and
sold or shared to each category of third parties.
When your right to know submission includes a data portability request, a copy of your personal information subject to any permitted redactions.
For more on exercising this right, see Exercising the Rights to Know, Delete, or Correct.
Right to Delete and Right to Correct
You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions and limitations (the "right to delete"). Once we receive your request and confirm your identity, we will delete your personal information from our systems unless an exception allows us to retain it. We will also notify our service providers to take appropriate action.
You also have the right to request correction of personal information we maintain about you that you believe is inaccurate (the "right to correct"). We may require you to provide documentation, if needed, to confirm your identity and support your claim that the information is inaccurate. Unless an exception applies, we will correct personal information that our review determines is inaccurate and notify our service provider to take appropriate action.
For more on exercising these rights, see Exercising the Rights to Know, Delete, or Correct.
Right to Limit Sensitive Personal Information Use and Disclosure to Permitted SPI Purposes
As we do not use or disclose sensitive personal information beyond the CCPA's Permitted SPI Purposes, we do not currently provide this consumer right.
Personal Information Sales or Sharing Opt-Out and Opt-In Rights
You have the right to request that businesses stop your personal information at any time (the "right to opt-out"), including through a user-enabled opt-out preference signal. Similarly, the CCPA prohibits businesses from selling or sharing the personal information of consumers it actually knows are under 16 years old without first obtaining consent from consumers who are between 13 and 15 years old or the consumer's parent or guardian for consumers under age 13 (the "right to opt-in")
As we do not sell or share consumers' personal data, we do not currently provide these consumer rights.
Right to Non-Discrimination
You have the right not to be discriminated or retaliated against for exercising any of your privacy rights under the CCPA.
How to Exercise Your Rights
Exercising the Rights to Know, Delete, or Correct
To exercise the right to know, data portability, delete, or correct described above, please submit a verifiable request to us by emailing us at privacy@osta.ai
Please describe your request with sufficient detail so we can properly understand, evaluate, and respond to it. You or your authorized agent may only submit a request to know, including for data portability, twice within a 12-month period.
Exercising the Right to Limit or Opt-Out
You can submit your request to limit or opt-out through emailing us at privacy@osta.ai
You can also submit your request to opt-out of personal information sales and sharing through an opt-out preference signal.
Verification Process and Authorized Agents
Only you, or someone legally authorized to act on your behalf, may make a request to know, delete, or correct related to your personal information. To designate an authorized agent, send a signed authorization and a copy of the agent’s government-issued ID to privacy@osta.ai.
We may request specific information from you or your authorized representative to confirm your or their identity before we can process your right to know, delete, or correct your personal information. We verify requests by matching two or three data points, depending on the sensitivity of the information requested.
We will only use personal information provided in the request to verify the requestor’s identity or authority to make the request.
We consider requests made through your password-protected account with our company sufficiently verified when the request relates to personal information associated with that specific account. You do not need to create an account with us to submit a request to know, correct, or delete.
For requests to limit or opt-out, we ask for the information necessary to complete the request, which may include, for example, the consumer’s name, email address, or account username.
Responding to Your Requests to Know, Delete, or Correct
We will confirm receipt of your request within ten business days. If you do not receive confirmation within the ten-day timeframe, please contact privacy@osta.ai.
We endeavor to substantively respond to a verifiable request within 45 days of its receipt. If we require more time (up to another 45 days), we will inform you of the reason and extension period in writing. We will deliver our written response to your verified email address. Our substantive response will tell you whether or not we have complied with your request. If we cannot comply with your request in whole or in part, we will explain the reason, subject to any legal or regulatory restrictions. Applicable law may allow or require us to refuse to provide you with access to some or all of the personal information that we hold about you, or we may have destroyed, deleted, or made your personal information anonymous in compliance with our record retention policies and obligations.
Any disclosures we provide will cover information for the 12-month period preceding the request's receipt date. We will consider requests to provide a longer disclosure period that do not extend past January 1, 2022, unless providing the longer timeframe would be impossible or involves disproportionate effort.
For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance, specifically CSV or JSON via secure email link.
We do not charge a fee to process or respond to your verifiable request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Response and Timing on Rights to Limit or Opt‑Out
In response to your request to limit or opt‑out, we will process your request as soon as feasibly possible, but no later than 15 business days from the date we receive the request. You do not need to create an account with us to exercise your limitation and opt‑out rights. We will only use personal information provided from your request to comply with the request.
Once you make a request to limit or opt‑out, we will wait at least 12 months before asking you to reauthorize the use or disclosure of your sensitive personal information for purposes other than the Permitted SPI Purposes. However, you may change your mind and opt back in at any time by emailing us at privacy@osta.ai.
Privacy Policy Changes
We reserve the right to update this Privacy Policy at any time, as we continue to develop our compliance program in response to legal developments of the CCPA. If we make any material changes to this Privacy Policy, we will update the policy's effective date and post the updated policy on our website.
Contact Information
If you have any questions or comments about this policy, the ways in which we collect and use your information described here, [or] your choices and rights regarding such use[, or wish to exercise your rights under California law,] please do not hesitate to contact us at:
Email: privacy@osta.ai
If you need to access this Privacy Policy in an alternative format due to a disability, please contact privacy@osta.ai.