Privacy Policy
Effective: May 3, 2026·Last updated: August 7, 2026
Applicable Laws: California Consumer Privacy Act (CCPA/CPRA) • Children's Online Privacy Protection Act (COPPA) • Texas Data Privacy and Security Act (TDPSA)
This Privacy Policy applies to both Service Providers (businesses using the Hoshin Space platform) and End Users (clients of those businesses whose data is entered into the platform). Where a provision applies to only one group, it is clearly labeled.
1. Who We Are
Hoshin Space is a product of Saldana Tech LLC ("Company," "we," "us," or "our"), a Texas limited liability company. We operate a field service management platform ("Platform") that allows small service businesses to manage clients, schedule jobs, and process payments via Stripe Connect.
Data Controller Contact:
- Company: Saldana Tech LLC d/b/a Hoshin Space
- Privacy Contact: privacy@hoshinspace.com
- Mailing Address: Saldana Tech LLC — mailing address available on request to legal@hoshinspace.com
Geographic scope. The Platform is offered to U.S.-based businesses and the U.S. clients those businesses serve. Hoshin Space does not target, market to, or knowingly accept signups from data subjects in the European Union, the United Kingdom, or other jurisdictions whose data-protection regimes (GDPR, UK GDPR) impose extraterritorial obligations on non-EU controllers. If you are a resident of the EU / UK and reached the Platform, please email privacy@hoshinspace.com so we can either remove your data or, if appropriate, work with you under an applicable cross-border framework.
2. Scope of This Policy
This Privacy Policy covers personal information collected through:
- The Hoshin Space web application at hoshinspace.com and any associated subdomains.
- Transactional emails and communications sent by or through the Platform.
- Any customer-facing booking portals or payment pages powered by Hoshin Space.
- Direct interactions with our support team.
This Policy does not cover third-party websites, applications, or services linked from the Platform, including Stripe's payment portal. Please review those services' independent privacy policies.
3. Information We Collect
3.1 From Service Providers (Business Accounts)
When a business registers for and uses the Platform, we collect:
| Category | Examples |
|---|---|
| Account Information | Business name, owner name, email address, phone number, billing address. |
| Subscription & Billing | Payment method details (tokenized via Stripe), subscription plan, billing history. |
| Business Operations | Client lists, job records, service descriptions, pricing, scheduling data entered by the business. |
| Usage Data | Login timestamps, feature usage, browser type, IP address, device identifiers. |
| Communications | Support inquiries, feedback, and correspondence with Hoshin Space. |
3.2 From End Users (Clients of Service Providers)
When a Service Provider adds an End User to the Platform, or when an End User interacts with Platform-generated communications, we may collect:
| Category | Examples |
|---|---|
| Identity Information | Name, email address, service address(es). |
| Payment Information | Tokenized card data stored by Stripe (we do not store raw card numbers, CVV, or PINs). |
| Service Records | Job history, appointment notes, and recurring service configurations entered by the Service Provider. |
| Transaction Data | Payment amounts, dates, receipts associated with completed jobs. |
| Email Interactions | Whether transactional emails were opened or links were clicked (standard delivery tracking). |
3.3 Automatically Collected Information
When you access the Platform, we automatically collect:
- Log data: IP address, browser type and version, operating system, referring URLs, pages visited, and timestamps.
- Cookies and similar tracking technologies: session cookies (required for authentication) and analytics cookies (to understand Platform usage). See Section 8 for details.
- Device information: device type, screen resolution, and unique device identifiers where applicable.
3.4 Information We Do Not Collect
Hoshin Space does not collect:
- Raw payment card numbers, CVV codes, or PINs. All card data is tokenized by Stripe.
- Social Security Numbers or government-issued ID numbers.
- Precise geolocation data.
- Biometric data.
- Sensitive personal information as defined under CCPA Section 1798.140(ae) beyond what is disclosed in this Policy.
4. How We Use Your Information
We use personal information for the following business purposes:
| Category | Examples |
|---|---|
| Platform Operation | Creating accounts, authenticating users, processing bookings, and routing payments through Stripe Connect. |
| Transactional Email | Sending booking confirmations, job receipts, cancellation notices, and payment alerts. |
| Billing & Payments | Managing subscriptions, collecting platform fees, and reconciling Stripe Connect payouts. |
| Support | Responding to inquiries, diagnosing bugs, and resolving billing or service disputes. |
| Security & Fraud | Detecting unauthorized access, monitoring for fraudulent transactions, and enforcing our Terms of Service. |
| Legal Compliance | Responding to lawful requests from authorities, complying with financial regulations, and maintaining required business records. |
| Platform Improvement | Analyzing aggregated, de-identified usage data to improve features and user experience. We do not sell or share identified user data for this purpose. |
We do not use personal information for behavioral advertising, third-party data monetization, or profiling for automated decision-making that produces legal or similarly significant effects on individuals.
5. How We Share Information
5.1 With Service Providers (Subprocessors)
We share personal information with the following trusted third-party vendors who process it on our behalf. Each subprocessor is contractually bound to use data only for the purposes listed and to implement appropriate security measures.
| Subprocessor | Purpose | Categories of data shared |
|---|---|---|
| Stripe, Inc. (stripe.com/privacy) | Payment processing, Stripe Connect provider payouts, platform subscription billing. | Tokenized payment credentials, transaction amounts, billing email and name. |
| Resend Inc. (resend.com/legal/privacy-policy) | Transactional email delivery (invoices, receipts, reminders, sign-in links, account notifications). | Recipient email address, message content, delivery and bounce metadata. |
| Twilio, Inc. (twilio.com/legal/privacy) | Optional SMS appointment reminders and inbound STOP/HELP processing (Pro tier only). | Recipient phone number, message body, delivery metadata. |
| Neon, Inc. (neon.tech/privacy-policy) | Primary application database (Postgres). | All Platform data described in Section 3. |
| Vercel Inc. (vercel.com/legal/privacy-policy) | Application hosting, build / deploy infrastructure, edge request routing. | Request metadata (IP, user agent, URL), application logs. |
| Upstash, Inc. (upstash.com/static/trust/privacy.pdf) | Rate-limiting and short-lived auth counters (Redis). | IP address, email address (hashed in keys), counter values. |
| Sentry (Functional Software, Inc.) (sentry.io/privacy) | Error monitoring and performance tracing. | Server / browser error events, stack traces, request metadata; PII scrubbed at the SDK level where feasible. |
| Google LLC (Sign in with Google — policies.google.com/privacy) | OAuth identity for Service Providers and End Users who choose Google sign-in. | Profile email and name as returned by Google's OAuth API. |
| Apple Inc. (Sign in with Apple — apple.com/legal/privacy) | OAuth identity for Service Providers and End Users who choose Apple sign-in. | Profile email and name as returned by Apple's OAuth API; Apple may proxy the email through a private relay address. |
5.2 Between Service Provider and End User
A Service Provider has access to the End User data they themselves entered into the Platform. Hoshin Space does not grant one Service Provider access to another Service Provider's End User data.
5.3 Legal and Safety Disclosures
We may disclose personal information if we believe in good faith that disclosure is necessary to:
- Comply with a legal obligation, court order, or lawful government request.
- Enforce our Terms of Service or protect the rights, property, or safety of Hoshin Space, our users, or the public.
- Detect, prevent, or address fraud, security, or technical issues.
5.4 Business Transfers
In connection with a merger, acquisition, financing, or sale of all or substantially all of Hoshin Space's assets, personal information may be transferred to the acquiring entity. We will provide notice before personal information becomes subject to a materially different privacy policy.
5.5 No Sale of Personal Information
Hoshin Space does not sell personal information to third parties for monetary consideration. We do not share personal information with third parties for cross-context behavioral advertising. This applies to all users, including California residents exercising rights under CCPA.
6. California Privacy Rights (CCPA / CPRA)
This Section applies specifically to residents of California. The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides California residents with specific rights regarding their personal information.
6.1 Categories of Personal Information Collected
In the preceding 12 months, Hoshin Space has collected the following categories of personal information as defined by the CCPA:
- Identifiers: name, email address, IP address, account username.
- Commercial Information: subscription records, job and service history, transaction records.
- Internet / Electronic Network Activity: browsing activity on the Platform, login history, email interaction data.
- Financial Information (partial): tokenized payment card identifiers managed by Stripe. We do not possess full card data.
- Geolocation (limited): service addresses provided by Service Providers for End Users; not precise real-time geolocation.
6.2 California Consumer Rights
California residents have the following rights under CCPA/CPRA:
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, our business purposes for collection, and the categories of third parties with whom we share it.
- Right to Delete: You may request that we delete personal information we have collected about you, subject to certain exceptions (e.g., legal obligations, active transactions). Service Providers can start this themselves from Settings — see Section 9.1.
- Right to Correct: You may request correction of inaccurate personal information we maintain about you.
- Right to Opt Out of Sale/Sharing: We do not sell or share personal information for cross-context behavioral advertising. No opt-out is required, but you may confirm our practices by contacting us.
- Right to Limit Use of Sensitive Personal Information: To the extent we process sensitive personal information (as defined by CPRA), you may request that we limit its use to permitted purposes.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights, including by denying service, charging different prices, or providing a different level of service.
6.3 How to Submit a Request
To exercise your California privacy rights:
- Email: privacy@hoshinspace.com with subject line "CCPA Privacy Request"
- We will verify your identity before processing your request. Verification may require confirming information we already hold on file.
- We will respond within 45 days of receipt. If we need additional time (up to 90 days total), we will notify you in writing.
- You may submit a request up to two times in any 12-month period.
6.4 Authorized Agents
California residents may designate an authorized agent to submit requests on their behalf. We will require written authorization from the consumer and may verify the consumer's identity directly.
7. Children's Privacy (COPPA)
This Section addresses compliance with the Children's Online Privacy Protection Act (COPPA), which applies to the online collection of personal information from children under 13 years of age.
7.1 Platform Not Directed at Children
The Hoshin Space Platform is designed for use by business owners and adults (18+). We do not knowingly direct any features, marketing, or content to children under the age of 13.
7.2 End User Data and Minors
Service Providers may input End User data into the Platform on behalf of their clients. If a Service Provider enters personal information of an individual under 13 years of age, the following applies:
- The Service Provider is responsible for ensuring they have obtained verifiable parental consent (VPC) as required by COPPA before entering any personal information of a child under 13 into the Platform.
- Service Providers must not use the Platform to send direct marketing communications to any individual under 13.
- Service Providers are prohibited from entering information about children under 13 except where strictly necessary for the delivery of services (e.g., noting that a recurring home service is for a household including minors).
7.3 Discovery of Data from a Child Under 13
If Hoshin Space discovers or is notified that we have inadvertently collected personal information from or about a child under 13 without verifiable parental consent, we will:
- Delete such information from our systems as promptly as practicable.
- Notify the relevant Service Provider.
- Take reasonable steps to prevent re-collection.
7.4 Parental Notification
Parents or legal guardians who believe personal information of a child under 13 has been collected through the Platform without consent may contact us at privacy@hoshinspace.com to request review, correction, or deletion of that information. We will respond within 30 days.
7.5 Users Between 13 and 17
We do not knowingly create accounts for individuals under 18. If we become aware that a user under 18 has registered as a Service Provider, we will suspend the account and notify the account holder to confirm they have reached the age of majority in their jurisdiction.
8. Cookies and Tracking Technologies
8.1 What We Use
The Platform uses the following types of cookies and similar technologies:
- Strictly Necessary Cookies: Required for authentication, session management, and security. These cannot be disabled without breaking Platform functionality.
- Analytics Cookies: Used to understand how the Platform is used (page views, feature usage, error rates). Data is aggregated and pseudonymized.
- Preference Cookies: Store user-selected settings such as language or display preferences.
We do not use advertising cookies, third-party tracking pixels, or cookies that enable cross-site behavioral profiling.
8.2 Managing Cookies
You may control cookie settings through your browser. Note that disabling strictly necessary cookies will impair Platform functionality. For analytics cookies, you may opt out by adjusting browser settings or contacting us at privacy@hoshinspace.com.
9. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, including:
- Service Provider account data: Retained for the duration of the subscription plus 3 years to comply with tax and financial recordkeeping requirements.
- End User data: Retained as long as the Service Provider maintains an active account. End User data associated with a terminated Service Provider account is deleted or anonymized within 90 days of account termination, unless a longer retention period is required by law.
- Payment records: Retained for 7 years in accordance with IRS recordkeeping requirements and Stripe's compliance obligations.
- Usage and log data: Retained for 12 months, then deleted or aggregated into anonymized analytics.
- Support communications: Retained for 3 years from last contact.
Upon your request, we will delete personal information sooner, subject to legal and operational retention obligations (e.g., active disputes, regulatory audits).
9.1 Self-Service Account Deletion
Service Providers can request deletion directly from Settings without contacting us. Requesting deletion immediately suspends processing on the account — no reminders are sent, no recurring jobs are created, and no cards are charged — and starts a 30-day grace period. During that period the account's data is unchanged, remains available for export, and the request can be cancelled.
At the end of the grace period we erase the personal information associated with the account. This includes End User names, email addresses, phone numbers, service addresses, and any notes recorded about End Users or jobs, together with the Service Provider's own business contact details.
We do not erase the payment record itself. Transaction amounts, platform and processing fees, refunds, payment status, timestamps, and Stripe transaction identifiers are retained for the period stated above, in a form no longer linked to a named individual. We are unable to delete these sooner: they are the records that tax rules require us to keep, that Stripe's compliance obligations require us to keep, and that we need to respond to a chargeback or a regulatory enquiry about a transaction that has already occurred.
Deletion of Platform records does not affect records held independently by Stripe as a separate controller of payment data, or copies a Service Provider has exported.
10. Data Security
We implement commercially reasonable technical, administrative, and physical safeguards to protect personal information, including:
- Encryption in transit (TLS 1.2+) and at rest for stored data.
- Payment data tokenization via Stripe — we do not store raw card credentials.
- Role-based access controls limiting employee access to personal data on a need-to-know basis.
- Regular security reviews and dependency updates.
No method of transmission or storage is 100% secure. In the event of a data breach that requires notification under applicable law, we will notify affected individuals and regulators as required by Texas, California, and federal breach notification rules.
11. Third-Party Links and Services
The Platform may contain links to third-party websites or services (including Stripe's payment portal). Hoshin Space is not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing personal information.
12. Texas Residents — TDPSA
Texas residents have privacy rights under the Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024. These rights mirror many CCPA rights and include:
- Right to access, correct, delete, and obtain a copy of your personal data. Service Providers can download their client records, job and payment history, services, and recurring schedules as CSV files at any time from Settings, and can start a deletion request there — see Section 9.1.
- Right to opt out of the processing of personal data for targeted advertising, the sale of personal data, and profiling in furtherance of solely automated decisions that produce legal or similarly significant effects.
To exercise TDPSA rights, contact privacy@hoshinspace.com. We will respond within 45 days, with a possible 45-day extension with notice. If we decline your request, you may appeal by emailing privacy@hoshinspace.com with the subject line "TDPSA Appeal."
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Platform features. When we make material changes, we will:
- Update the "Last Updated" date at the top of this Policy.
- For Service Providers: provide at least 14 days' advance notice via email or in-Platform notification before the new policy takes effect.
- For significant changes affecting End Users: notify via transactional email where an email address is on file.
Continued use of the Platform after the effective date of a revised Policy constitutes acceptance of the updated terms.
14. Contact Us
For privacy-related questions, requests, or complaints:
- General Privacy Inquiries: privacy@hoshinspace.com
- CCPA / CPRA Requests: privacy@hoshinspace.com | Subject: "CCPA Privacy Request"
- COPPA / Parental Inquiries: privacy@hoshinspace.com | Subject: "COPPA Parental Request"
- TDPSA Requests: privacy@hoshinspace.com | Subject: "TDPSA Data Request"
- Data Breach Notification: privacy@hoshinspace.com
- Mailing Address: Saldana Tech LLC — mailing address available on request to legal@hoshinspace.com
Hoshin Space (Saldana Tech LLC) | privacy@hoshinspace.com | hoshinspace.com