Legal
Privacy Policy
Effective date: July 29, 2026 · Version: 2026-07-29
This Policy explains how Osrilo handles account, business, customer, worker, device, billing, and usage information. Businesses using Osrilo also have their own privacy responsibilities for the customer and worker information they enter.
1. Scope and roles
This Privacy Policy applies to Osrilo’s website, application, support, and Osrilo-powered estimate and invoice pages. It does not replace a contractor’s own privacy notice.
For account, subscription, security, support, and platform-operation information, Osrilo determines how the information is used. For customer, job, employee, estimate, invoice, photo, and similar workspace information, the business using Osrilo generally decides what is entered and why. Customers and workers should contact that business first about its records.
2. Information we collect
Account and business information
Name, email address, authentication identifiers, business name, contact details, workspace memberships, role, permissions, plan, and setup choices.
Workspace content
Customers, addresses, phone numbers, emails, jobs, schedule entries, estimates, invoices, payments, notes, photos, files, assignments, time entries, labor rates, costs, reports, and other information submitted by authorized users.
Billing and payment information
Subscription status, Stripe customer and subscription identifiers, connected-account status, invoice payment amount and status, payment method type, receipt details, refunds, disputes, and transaction identifiers. Stripe—not Osrilo—collects and stores full card numbers and bank-account credentials.
Technical and usage information
Device and browser type, pages and features used, approximate timestamps, authentication and security events, error information, diagnostics, IP-derived security information when provided by infrastructure services, and cookie or local-storage identifiers.
Support and bug reports
Messages sent to support, bug descriptions, selected diagnostic details, and follow-up history. Osrilo’s bug-report tool is designed to exclude passwords, card numbers, customer notes, and document contents.
3. Sources of information
- You, when you create an account, configure a workspace, contact support, or use a feature.
- Other authorized members of a business workspace.
- Customers who view, accept, decline, or pay an Osrilo-powered document.
- Stripe and other service providers that confirm billing, payment, identity, delivery, security, or system status.
- Automatically from the application, browser, device, and infrastructure logs.
4. How we use information
- Provide, secure, maintain, troubleshoot, and improve Osrilo.
- Create and authenticate accounts and enforce permissions.
- Store and display business records and perform requested workflows.
- Process subscription billing and help businesses accept customer invoice payments.
- Send verification, security, billing, document, schedule, payment, and support communications.
- Calculate usage, storage, balances, time, revenue, cost, and profitability information.
- Detect fraud, abuse, duplicate payments, security threats, and violations.
- Comply with law, enforce agreements, resolve disputes, and protect users and the public.
- Create aggregated or de-identified information that does not reasonably identify a person.
5. Stripe and payment information
Osrilo uses Stripe for software subscriptions and contractor customer payments. Stripe receives payment details directly through Stripe-hosted pages. Osrilo receives limited transaction information needed to confirm the payment, update balances, prevent duplicates, provide receipts, handle refunds or disputes, and diagnose failures.
Customer invoice payments are made to the contractor or business shown on the invoice. That business is responsible for its refund decisions and customer relationship. See Stripe’s privacy information on Stripe’s website for details about Stripe’s processing.
7. Business-controlled customer and worker data
Businesses decide which customers, workers, jobs, photos, documents, and communications they place in Osrilo. They are responsible for providing required privacy notices, respecting access and deletion requests, obtaining communication and workplace consents, and using data lawfully.
If you are a customer or worker seeking access, correction, or deletion of records held in a contractor’s workspace, contact that contractor first. Osrilo may assist the business when appropriate and legally permitted.
9. Data retention
We keep information as long as reasonably necessary to provide the Service, maintain business and payment records, comply with law, resolve disputes, prevent fraud, enforce agreements, and maintain backups. Retention varies by data type and account status.
Deleted information may remain temporarily in backups, logs, payment records, audit history, or fraud-prevention systems. Temporary test workspaces are designed for automatic cleanup, but security and diagnostic records may be retained when necessary.
10. Security
We use administrative, technical, and organizational safeguards intended to protect information, including authenticated access, role-based permissions, server-side enforcement, encrypted network connections, payment-provider tokenization, and audit or diagnostic controls. No system is completely secure, and we cannot guarantee that unauthorized access will never occur.
Do not send passwords, full card numbers, bank credentials, or government identification through bug reports, notes, or ordinary support email.
11. Your choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or information about disclosure of personal data. These rights may have exceptions for payment records, security, legal claims, business records, and other lawful purposes.
- Account owners can update many profile and business details inside Osrilo.
- Users can manage workspace data according to their permissions.
- Subscription renewal can be cancelled through Manage Billing.
- You may contact support@osrilo.com with a privacy request.
We may verify identity and authority before completing a request. If the request concerns a contractor’s workspace data, we may direct you to that business.
12. Children’s privacy
Osrilo is business software and is not directed to children under 13. We do not knowingly create accounts for children under 13. If you believe a child provided personal information improperly, contact us.
13. Processing location
Osrilo is operated in the United States. Information may be processed and stored in the United States and other locations where our service providers operate, subject to their safeguards and applicable law.
14. Changes to this Policy
We may update this Privacy Policy as Osrilo, applicable law, or our providers change. The current version and effective date will be posted here. We will provide reasonable notice of material changes when appropriate.
15. Contact
Privacy questions and requests may be sent to support@osrilo.com.