Sandbox draft · No live sales
Privacy notice
Draft Privacy Notice · Acknowledged with paid-beta-v3 · Updated 1 September 2026
This draft outlines data used by the current OSYLLO private beta. It is not ready for external onboarding: the operator's legal identity, address, lawful bases, and retention schedule must be completed before personal data is collected from external beta users.
Current boundary
OSYLLO does not store full payment-card details. Stripe handles sandbox test-payment entry. Do not enter real card or bank details in the sandbox.
1. Data categories
- Account data: email address, Supabase user identifier, account confirmation and security events.
- Support correspondence: the sender's email address, message content, and related replies when someone chooses to contact OSYLLO support.
- Session and security data: authentication tokens in the user's browser, IP address, request metadata, and security logs processed to protect the service.
- Product data: bounded user preferences and service-use events required to provide and troubleshoot the beta.
- Acceptance records: the account identifier, accepted document version, acceptance context, and server-recorded acceptance time needed to prove which paid-beta terms were accepted.
- Sandbox billing data: selected test package, Stripe sandbox customer, Checkout Session, payment or subscription identifiers, status, access period, and signed webhook event identifiers. Raw webhook bodies and full card details are not stored in the OSYLLO billing tables.
2. Why data is used
Data is used to create and secure accounts, record required terms acceptance, verify Product access, operate the beta, prevent abuse, diagnose failures, test one-time payment and subscription lifecycles, respond to lawful requests, and improve reliability. User-controlled profile metadata is not used to grant roles, Founder status, discounts, or Product access.
3. Service providers
The current technical flow uses Supabase for authentication and database services, Cloudflare for hosting, network security and access controls, Google Workspace for support email, and Stripe for sandbox billing. Each provider may process technical data under its own terms and privacy documentation.
4. Sharing
The current private-beta design does not include selling account data. Before external beta onboarding, the completed notice must confirm the operator's actual practices and explain any disclosure to service providers, professional advisers, or authorities.
5. Retention and deletion
Authentication, security, Product, support-correspondence, and sandbox billing records are kept only as needed for the beta, responding to inquiries, fraud prevention, troubleshooting, and legal obligations. A category-by-category retention schedule must be published before external beta onboarding.
6. Privacy rights
Depending on location, users may have rights to access, correct, delete, restrict, or export personal data and to object or complain to a regulator. The final notice will identify the responsible operator and any jurisdiction-specific process for exercising those rights or making a complaint.
7. Privacy contact
Privacy questions and requests can be sent to [email protected]. The final notice must still identify the responsible legal operator before external beta onboarding.