1. Introduction
Asteri Technologies LLC, doing business as Asteri ("Asteri," "we," "our," or "us"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service management platform, including our integrations with third-party services such as Meta (Facebook and Instagram), Google services, Stripe, and communication providers.
This policy applies to all users of the Asteri platform, including service business owners and their team members ("Business Users") and customers who book services through the platform ("End Customers").
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Name
- Organization/business name
- Password (securely hashed — we never store plaintext passwords)
2.2 Booking & Customer Information
When End Customers book a service, we collect:
- Name, email address, and phone number
- Service address
- Service selections and preferences
- Special instructions or notes
This information is collected on behalf of the Service Provider and is shared with them to fulfill your booking.
2.3 Payment Information
Payment processing is handled entirely by Stripe, Inc. Your card number, expiration date, and CVC are transmitted directly to Stripe and are never stored on Asteri’s servers. We receive only:
- A confirmation that the payment succeeded or failed
- The last four digits of the card (for display purposes)
- The card brand (e.g., Visa, Mastercard)
- Transaction amounts and timestamps
2.4 Google Business Profile Data
When a Business User connects their Google Business Profile, with their explicit consent, we access and store:
- Business Locations: Name, address, phone number, website, business hours
- Reviews: Customer reviews, star ratings, reviewer display names, and your responses
- Posts: Business updates, offers, and events you create through our platform
- Performance Insights: Search views, map views, website clicks, direction requests, phone calls
- OAuth Tokens: Encrypted access and refresh tokens to maintain your connection
2.5 Former Gmail Integration
Asteri no longer offers a Gmail mailbox integration and does not request permission to read Gmail messages or send mail through a connected Gmail account. Google Sign-In does not grant access to your mailbox.
Business records and customer-linked attachments previously imported from Gmail may remain subject to the retention and deletion rules in Section 6. Removing the integration does not automatically delete those existing organization records.
2.6 Google Calendar Data
When an authorized Business User connects Google Calendar, we access the connected account email, calendar list, and event information including event titles, descriptions, locations, attendees, organizers, availability, and start and end times. We use this data to select calendars, synchronize availability, prevent scheduling conflicts, and create, update, or remove Asteri-related events according to the organization’s settings.
2.7 Google Drive Data
Asteri requests the limited Google Drive permission that applies only to files and folders a user creates with Asteri or explicitly opens or selects for use with Asteri. We access file and folder names, identifiers, types, sizes, links, modification times, and file content when needed to complete a user-requested browse, upload, download, folder-creation, link, or deletion action. File bytes may pass through Asteri to complete the requested transfer; Asteri does not copy a user’s entire Google Drive.
2.8 Google Ads and Data Manager Data
When an authorized Business User connects Google Ads, we access the connected account email; accessible Google Ads customer accounts; campaign, ad-group, keyword, spend, performance, and conversion-action information; and Data Manager partner-link status when partner onboarding is used. We use this information to report marketing performance, associate leads and revenue with campaigns, configure and verify conversion actions, and upload user-authorized conversion or event data.
2.9 Meta (Facebook and Instagram) Platform Data
When a Business User connects a Facebook Page, Instagram professional account, or Meta Ads account, with their explicit consent, Asteri may access and store:
- Meta user, Business Manager, Facebook Page, Instagram professional account, ad account, Pixel, and lead-form identifiers and display names
- Facebook Page messages, posts, comments, sender names, and profile pictures needed for the Communications inbox and authorized replies or moderation
- Instagram Direct messages and professional-account profile or media information needed for the Communications inbox and authorized feed publishing
- Meta Ads campaigns, ads, spend, performance insights, conversion events, and lead form submissions used for attribution, reporting, authorized Pixel/conversion tracking, and CRM lead creation
- Granted permissions and encrypted OAuth access tokens needed to maintain the connection
Asteri uses this data only to provide the Meta integration features selected by the Business User. We do not sell Meta Platform Data, use it to build advertising profiles for third parties, or share it with unrelated organizations.
2.10 Communications Data
When Business Users use our communication features, we process:
- SMS messages: Sent and received via Telnyx on behalf of the Business User
- Emails: Sent via Resend on behalf of the Business User (appointment confirmations, invoices, review requests, etc.)
2.11 Log & Device Data
When you access the platform, we automatically collect:
- IP address
- Browser type and version
- Device type and operating system
- Pages visited and time spent on each page
- Referring URL
- Date and time of access
2.12 Location & Vehicle Data
When a Business User enables mobile location features (such as field-technician tracking, time-clock geofencing, dispatch, or route optimization) or connects a vehicle telemetry device, we collect:
- Precise GPS coordinates (latitude and longitude)
- Speed, heading, location accuracy, altitude, and timestamps
- Device battery level and charging status during an active tracking feature
- Trip history (start/stop points, route taken)
- For connected vehicles: telemetry such as ignition status, odometer, and device identifiers, received via our integration partner Flespi
Asteri collects mobile location for the single primary purpose of active technician dispatch and job tracking. Collection requires both workspace eligibility and the technician's own consent. It can start only while the technician is clocked in or assigned to an active appointment and, with OS background permission, can continue while the app is closed or not in use. Collection stops after clock-out when no active appointment remains, after the active appointment ends, after consent withdrawal, sign-out, organization switching, OS permission revocation, or a workspace tracking disablement. Detailed breadcrumbs are normally retained for 90 days and then deleted; a configured retention period may range from 30 to 730 days. Limited session summaries may remain with payroll, billing, safety, or dispute records under the applicable record-retention period. Declining location does not prevent access to non-location features, but live dispatch, customer ETAs, active job tracking, and location-based arrival verification will be unavailable.
2.13 Mobile App Operations & Notifications
The production mobile app uses Expo and EAS services for app delivery, updates, startup-performance monitoring, and bounded operational events. Those services may process the app and project identifiers, app/build/update versions, device model, operating-system version, language, persistent installation and session identifiers, startup timing, and narrowly scoped event fields. Asteri disables Expo Observe's navigation integration, so resolved screen URLs and route or query parameters are not exported.
If you enable notifications or mobile calling, Apple Push Notification service, Firebase Cloud Messaging, Expo notification tooling, and Telnyx may process app, device, push, or VoIP registration tokens plus delivery and call-notification metadata. These identifiers are used to deliver requested notifications and incoming business calls, maintain registration security, and troubleshoot delivery. They are not used by Asteri for advertising.
The mobile app asks for device permissions only for the feature you are using, and each permission can be declined or turned off later in your device settings:microphone for in-app business calls, voice notes, and AI voice prompts or transcription (audio for AI features is routed to the AI providers described in Section 8); camera and photo library for job photos, inspection media, document scans, and barcode scans, which are stored with your workspace files and, only when you choose an AI feature, sent to an AI provider for analysis; Bluetooth solely to route call audio to a headset or car system; Face ID or fingerprintto unlock the app on your device, which never leaves the device; and location as described in Section 2.12.
Business calls may create call metadata, voicemail recordings, voicemail transcripts, and call summaries for the organization's records. Call recordings are made only when the organization enables recording and the applicable consent is obtained, and they follow the retention and deletion rules in Section 6. When an organization enables an AI receptionist, ElevenLabs processes call audio, transcripts, caller details and the workspace information needed to answer or act on the request. New receptionist agents are configured to record calls and use a 10-day provider retention setting. This is not a promise that every copy is erased after 10 days: organization records, backups and legal retention follow their own rules. On Android, map screens use the Google Maps SDK. When used, it collects device and request metadata, IP address, a Maps-specific identifier and crash information. Map interactions may also be collected. These diagnostics do not depend on enabling background location. If you enable the My Location layer, your device location may also be processed.
2.14 Marketing Performance and Benchmark Data
When a Business User connects advertising or marketing integrations, or uses Asteri’s marketing analytics tools, we may process campaign, ad account, spend, lead, booking, and attributed revenue metrics. We use this information to show your own marketing performance and, unless you opt out, to create aggregate peer benchmark snapshots.
Benchmark snapshots are designed to protect business confidentiality. We do not expose customer records, click identifiers, ad-account identifiers, raw organization totals, or named businesses in peer benchmarks. We only show percentile ranges for cohorts that meet Asteri’s minimum qualification rules, including a minimum cohort size of 10 qualified businesses and a minimum monthly ad-spend threshold.
Organization owners and authorized administrators can opt out of contributing to future aggregate benchmark snapshots, or hide benchmark comparisons in their own workspace, from Marketing Settings.
2.15 What We Do NOT Collect
- Full credit or debit card numbers (handled by Stripe)
- Social Security numbers or government-issued ID numbers
- Personal information of reviewers beyond their public display name
- Google account data outside the services and permissions you explicitly authorize
- Google Contacts or Google People data; Asteri does not request a Google Contacts permission
- Biometric identifiers (facial geometry, fingerprints, voiceprints)
3. How We Use Your Information
We use the collected information to:
- Provide, operate, and maintain the platform and its features
- Process bookings and facilitate communication between Business Users and End Customers
- Process payments through Stripe on behalf of Service Providers
- Send transactional communications (confirmations, reminders, invoices)
- Display your business locations and performance metrics in our dashboard
- Enable you to view and respond to customer reviews
- Synchronize selected Google Calendars, avoid scheduling conflicts, and manage Asteri-related events
- Complete user-requested Google Drive file and folder operations on items authorized for use with Asteri
- Import Google Ads performance and upload user-authorized conversion or event data through Google Ads or Data Manager
- Generate AI-powered suggestions (review responses, floor inspection analysis, proposal and estimate drafting, smart chat replies, marketing copy generation)
- Receive and investigate in-app reports about AI-generated responses, including the selected concern category, optional details, model information when available, and a limited, sanitized response snapshot or secure internal reference
- Provide dispatch, routing, time-and-attendance, and vehicle-history features using device or vehicle location data, for Business Users who enable those features
- Provide analytics and insights about your business performance
- Create privacy-preserving aggregate marketing benchmarks that help Business Users understand how their marketing performance compares with qualified peer cohorts
- Measure product usage and improve the Service through first-party product analytics (such as which steps of the booking flow customers complete or abandon). These events are recorded by Asteri directly and are not shared with third-party advertising or marketing companies
- Monitor errors, crashes, and performance through our error-monitoring provider (Sentry), to keep the Service reliable
- Detect and prevent fraud, abuse, and security threats
- Comply with legal obligations
4. Data Storage and Security
4.1 Encryption
All OAuth tokens are encrypted using AES-256-GCM encryption before being stored. Tokens are never stored in plaintext. All data in transit is encrypted using TLS 1.2 or higher.
4.2 Access Control
Your data is isolated at the organization level by application-layer access controls enforced on every API request. Only authenticated users within your organization, and with the appropriate role-based permissions, can access your data.
4.3 Infrastructure
Our data is hosted on secure cloud infrastructure with industry-standard security measures, including encryption at rest and in transit. File uploads are stored on Cloudflare R2 with access-controlled URLs.
4.4 PCI Compliance
Asteri does not process, store, or transmit cardholder data. All payment card processing is handled by Stripe, which is certified as a PCI Level 1 Service Provider.
5. Data Sharing
We do NOT:
- Sell your data to third parties
- Share your organization-level business data with other organizations on the platform, except as aggregate or de-identified benchmark statistics described below
- Use your data for advertising purposes
- Transfer your data to third parties for their marketing purposes
For purposes of the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), we do not “sell” or “share” your personal information as those terms are defined in Cal. Civ. Code § 1798.140.
We do not use Google Workspace data from Gmail, Google Calendar, or Google Drive for advertising, ad targeting, creditworthiness, lending, or aggregate marketing benchmarks. We do not transfer Google Workspace data to advertising platforms.
Mobile information and SMS opt-in consent are not shared with third parties or affiliates for marketing or promotional purposes. We share this information only with service providers that help deliver and support the messages you request.
We share data with the following categories of service providers:
- Service Providers you book with: Your booking details and contact information to fulfill your appointment
- Payment processor (Stripe): Transaction data necessary to process payments and prevent fraud
- Communication providers (Telnyx, Resend): Phone numbers and email addresses necessary to deliver SMS, voice calls, and email
- Mobile delivery and reliability providers (Expo/EAS, Apple, Google/Firebase): App/build/update identifiers, device and operating-system metadata, persistent installation/session identifiers, push or VoIP tokens, startup metrics, bounded operational events, and delivery metadata needed to ship, update, secure, monitor, and notify the mobile app. Asteri disables Expo Observe's resolved-URL and route-parameter integration.
- AI routing and model providers: When you use AI features (Smart Chat, Floor Inspector, proposal and estimate generation, review-response suggestions, marketing studio drafting), the content you submit to those features—including customer names, addresses, service descriptions, photos, and chat messages—is transmitted over an encrypted connection through Vercel AI Gateway to a routed model provider. Depending on the feature and current routing, that provider may be OpenAI, DeepSeek, Google, or Z.ai. Embedding requests also use the configured AI routing service. For supported text, tool, structured-output and embedding requests, Asteri requests provider zero data retention through AI Gateway. This does not cover every AI feature: speech transcription and Grok image generation follow their applicable provider retention policies. Asteri may still retain saved chats, documents and results under this policy. Zero data retention does not delete those application records. We do not anonymize or pseudonymize content before transmission. These providers process submitted content under their applicable business-service terms, privacy notices, and retention controls. See Vercel’s Privacy Policy, OpenAI’s Privacy Policy, DeepSeek’s Privacy Policy, and Google’s Privacy Policy. We may add or change AI providers and will update this Section and Section 8 when that changes. Before the mobile app opens an AI feature, it asks each signed-in Business User to allow this third-party processing for the active workspace. You may decline and keep using non-AI features, allow it later, or withdraw permission in Privacy & Data. Withdrawal stops new AI requests from that user in that workspace; it does not automatically delete completed AI results or records retained for safety, audit, legal, or compliance purposes.
- AI safety reports: Authenticated Business Users can report a generated response entirely inside Asteri. We use the report to investigate harmful, hateful, sexual, deceptive, privacy-sensitive, or unsafe business output. The report does not change the underlying customer record or execute an AI action. We minimize copied customer information, redact common contact and sensitive-number patterns from stored response snapshots, and normally remove those snapshots after 180 days. Limited report, assignment, resolution, and audit records may be retained longer for safety, legal, and compliance purposes.
- Vehicle telemetry provider (Flespi): For Business Users who enable vehicle tracking, device identifiers and GPS telemetry are exchanged with Flespi to deliver fleet features
- File storage (Cloudflare R2): Files, photos, and documents you upload are stored on Cloudflare R2 with access-controlled URLs
- Legal compliance: When required by law, subpoena, or court order, or to protect the rights, property, or safety of Asteri, our users, or the public
- Business transfer: In connection with a merger, acquisition, financing, reorganization, or sale of assets
5.1 Aggregate Marketing Benchmarks
Asteri may use Business User marketing performance data to produce aggregate or de-identified benchmark statistics, such as median cost per lead or peer percentile ranges by service vertical and monthly ad-spend band. These statistics are generated as precomputed snapshots and are not designed to identify any individual customer, team member, ad click, ad account, or named business.
We suppress benchmark rows unless the cohort meets our minimum privacy thresholds. We also show only coarse sample-size labels, such as “10+ businesses,” instead of exact contributor counts. If you turn off benchmark contribution, your organization is excluded from future benchmark snapshots. Previously generated aggregate statistics may remain if they no longer identify your organization.
6. Data Retention and Deletion
6.1 Active Accounts
While your account is active, we retain your data to provide our services. Booking and payment records are retained for at least 7 years for tax and legal compliance purposes.
6.2 Google Business Profile Disconnection
Disconnecting Google Business Profile removes the stored OAuth connection and stops future synchronization. Previously imported reviews, posts, performance insights, business location data, and review-request history may remain as organization business records until an authorized user deletes the related data, the organization account is deleted, or a verified deletion request is completed.
6.3 Other Google Integration Disconnection
The former Gmail integration is no longer available. Previously imported message records and customer-linked attachments may remain as organization business records until an authorized user deletes the related data, the organization account is deleted, or a verified deletion request is completed. You can revoke any earlier Gmail grant through your Google Account connections.
Disconnecting Google Calendar removes its OAuth connection, synchronization mappings, and cached busy-time data and stops future synchronization. Disconnecting Google Drive deletes the stored connection but does not delete files from Google Drive. Disconnecting Google Ads or Data Manager attempts to revoke the Google grant, deletes stored OAuth tokens and connection configuration, and stops future imports and uploads; previously imported campaign and conversion records may remain as organization business records until account deletion or a verified deletion request.
6.4 Meta Platform Data Disconnection and Deletion
To disconnect Meta and stop Asteri’s access:
- Sign in to Asteri.
- For Facebook or Instagram, open Settings > Integrations and select Disconnect for the connected account. For Meta Ads, open Marketing > Settings and disconnect Meta Ads.
- You may also revoke Asteri from Facebook’s Business Integrations settings.
Disconnecting deletes Asteri’s stored OAuth token and connection configuration and stops future Meta data collection. Historical business records, such as messages, published-post history, leads, and campaign reporting already imported into the organization’s workspace, remain subject to the organization’s normal retention settings.
To request deletion of stored Meta Platform Data, email privacy@getasteri.com from the email address associated with your Asteri account and include your organization name and the connected Facebook, Instagram, or Meta Ads account. After verifying authority and scope, we delete or de-identify applicable Meta Platform Data that is not subject to legal, security, fraud-prevention, financial-compliance, or backup-retention requirements. Completion time depends on the request and those constraints.
6.5 Account Deletion
Canceling a paid subscription does not delete the account or its data. You can request deletion in the mobile app under Settings > Privacy & Data or from our public Delete Account page. The public page works without installing the app and supports a verified email request or an authenticated handoff. You do not need to telephone or email support.
A verified request enters a 7-day grace period. You can cancel from the same mobile or web deletion screen until processing begins. We expect final completion within 30 days and send a completion confirmation. Deactivation, signing out, or uninstalling Asteri is not account deletion.
Personal-account deletion removes the Asteri login, linked authentication methods, passkeys, MFA secrets, sessions and refresh credentials, push and VoIP tokens, remembered devices, preferences, user-only notifications, and every organization membership. Sign in with Apple authorization is revoked where applicable. Shared organizations and records belonging to other workspace members are not silently deleted. A sole organization owner must transfer ownership or deliberately use the approved organization-closure path first.
We delete or anonymize personal identifiers in accordance with the approved data map. We preserve only narrowly required tax and financial records, fraud-prevention and security evidence, dispute or legal-hold records, payroll and employment records, and shared-workspace history. Processing of retained records is restricted to the legal, financial, security, employment, or dispute purpose for the applicable retention period.
6.6 Benchmark Opt-Out Retention
If you opt out of contributing to aggregate marketing benchmarks, we stop using your organization’s marketing performance data in future benchmark snapshot generation. Historical aggregate or de-identified snapshots may remain in the Service when they cannot reasonably be used to identify your organization or any person.
6.7 End Customer Data
End Customer data is retained by the Business User’s organization, which is the data controller. End Customers who wish to have their data deleted should contact the Service Provider directly using the contact information on their booking confirmation.
Backstop: If a Service Provider does not respond to a deletion request, the End Customer may contact us at privacy@getasteri.com with a copy of the original request. After verifying authority and scope, we delete or de-identify the End Customer’s personal data that is not subject to legal, security, fraud-prevention, financial-compliance, dispute, or backup-retention requirements. Completion time depends on the request and those constraints.
7. Your Rights
You have the right to:
- Access: Request a copy of all data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data (subject to legal retention requirements)
- Portability: Request a copy of your data in a portable, machine-readable format
- Disconnect: Remove any third-party integration at any time from Settings
- Revoke: Revoke Asteri's access to Google directly through your Google Account settings
- Opt-out: Opt out of non-essential communications at any time
To delete an Asteri account, use the self-service deletion page. For other rights or privacy questions, contact privacy@getasteri.com. We will respond within the applicable legal period.
8. Third-Party Services
Our platform integrates with the following third-party services:
- Stripe: Payment processing. Stripe Privacy Policy
- Google APIs: Optional Google Sign-In, Calendar, Drive, Business Profile, Google Ads, and Data Manager integrations, plus Firebase Cloud Messaging for Android push delivery. Google Privacy Policy
- Expo / EAS: Mobile app build and update delivery, startup-performance monitoring, bounded operational events, and optional push-notification routing. Asteri does not enable Expo Observe's route URL or route-parameter integration. Expo Privacy Policy
- Apple platform services: Sign in with Apple, APNs/PushKit delivery, WeatherKit, Apple Pay, and Tap to Pay platform services where enabled. Apple may process the Apple account identifier and relay email the user chooses to share, device or push-registration identifiers, weather request location, and payment authorization or eligibility signals under Apple's policies. Asteri does not receive full Apple Pay card credentials. Apple Privacy Policy
- Meta Platforms (Facebook, Instagram, and Marketing API): Business messaging, Page and Instagram publishing, lead retrieval, advertising management, and campaign reporting. Meta Privacy Policy
- Telnyx: SMS messaging and voice calling. Telnyx Privacy Policy
- ElevenLabs: AI receptionist calls. When this feature is used, ElevenLabs receives phone numbers, call audio, transcripts, and the workspace information needed to handle the call. Provider recording and retention settings are described in Section 2.13. ElevenLabs Privacy Policy
- Resend: Email delivery. Resend Privacy Policy
- Cloudflare R2: File storage. Cloudflare Privacy Policy
- Vercel AI Gateway and routed model providers: AI inference for Smart Chat, Floor Inspector, proposal and estimate generation, review-response suggestions, marketing studio drafting, embeddings, and other AI features. Current routing may use OpenAI, DeepSeek, Google, or Z.ai models. Address lookup may use Radar, and backend services may run on Fly.io. Our Sub-Processors page lists the data handled by each provider. See Vercel Privacy Policy, OpenAI Privacy Policy, DeepSeek Privacy Policy, and Google Privacy Policy
- Flespi: Vehicle telemetry for fleet and routing features, for Business Users who enable vehicle tracking. Flespi Privacy Policy
- Sentry: Application error and performance monitoring. Sentry receives error stack traces and a sample of performance traces from the platform. We do not enable session replay and our Sentry configuration is set to omit personally identifying request data by default. Sentry Privacy Policy
9. Cookies and Tracking
We use essential cookies to maintain your session and preferences. We do not use third-party tracking or advertising cookies. For full details, see our Cookie Policy.
10. Children's Privacy
Asteri is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.
11. Our Role as Data Processor
When Service Providers use the Asteri platform to collect and manage End Customer data, the Service Provider is the "data controller" and Asteri acts as a "data processor" on their behalf.
- The Service Provider determines why and how End Customer data is collected and used
- Asteri processes this data only as necessary to provide the platform’s features
- End Customers with questions about how their data is used should contact the Service Provider directly
- Service Providers are responsible for ensuring they have a lawful basis to collect and process their customers’ data
12. California Consumer Privacy Act (CCPA)
If you are a California resident, you have additional rights under the CCPA:
- Right to Know: Request disclosure of what personal information we have collected about you
- Right to Delete: Request deletion of your personal information, subject to legal exceptions
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out of Sale: We do not sell your personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
To exercise your CCPA rights, contact us at privacy@getasteri.com. We will respond within 45 days.
13. European Economic Area & United Kingdom (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR):
- Lawful Basis: We process your data based on contractual necessity (to provide the Service), legitimate interests (to improve the platform and prevent fraud), and your consent (where explicitly given)
- Right to Restriction: Request that we restrict processing of your personal data under certain conditions
- Right to Object: Object to processing of your personal data based on our legitimate interests
- Benchmark Opt-Out: Business Users can turn off contribution to future aggregate marketing benchmarks from Marketing Settings
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format
- Right to Lodge a Complaint: File a complaint with your local supervisory authority (data protection authority)
- Automated Decision-Making: Our AI-powered features (review response suggestions, floor inspection analysis, proposal generation) produce recommendations only. No solely automated decisions with legal or similarly significant effects are made without human review and approval
For GDPR-related inquiries, contact us at privacy@getasteri.com. We will respond within 30 days.
EU / UK Representative (GDPR Art. 27 & UK GDPR)
Asteri is a US-based controller. We are in the process of engaging an EU and UK representative under GDPR Art. 27 / UK GDPR Art. 27. Until that representative is appointed and listed here, EEA and UK data subjects may exercise all GDPR rights directly with us at privacy@getasteri.com or in writing to our address listed in Section 19. Once the representative is appointed, their name and contact details will appear here.
14. Do Not Track Signals
We do not currently respond to DNT browser signals. However, we do not use third-party tracking or advertising cookies.
15. Security Breach Notification
In the event of a data breach that affects your personal information, we will:
- Notify affected users via email within 72 hours of confirming the breach
- Provide details about what information was affected and what steps we are taking
- Notify relevant regulatory authorities as required by applicable law
- Offer guidance on steps you can take to protect yourself
16. International Data Transfers & Hosting Locations
Our services are hosted in the United States. If you access the platform from outside the United States, your data will be transferred to and processed in the United States.
Where your data is stored
- Application database (PlanetScale Postgres): US-East (N. Virginia). Multi-region EU residency is available on request for Enterprise customers.
- File storage (Cloudflare R2): US default region with global edge cache. Region restriction available on request.
- Real-time queue + cache (Redis): US-East.
- Email delivery (Resend): US.
- SMS and voice gateway (Telnyx): US.
- Vehicle telemetry (Flespi / Gurtam): European Union (Lithuania).
- Error monitoring (Sentry): US, with PII scrubbing before transmission.
- Application hosting (Vercel): US primary region, global edge for static assets only (no customer data persisted at the edge).
- Mobile delivery and telemetry (Expo/EAS, Apple, and Google/Firebase): provider infrastructure may operate globally; device, update, notification, and performance data is processed under the applicable provider terms and transfer safeguards.
Where personal data is transferred outside the EEA, UK, or Switzerland we rely on Standard Contractual Clauses (SCC 2021/914), the UK International Data Transfer Addendum, the EU-U.S. Data Privacy Framework where the sub-processor is certified, or your explicit consent.
17. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes (for example, new categories of data collected, new sub-processors that process your personal information, or new purposes of processing), we will post the revised Policy with an updated “Last updated” date, provide a short summary of what changed, and notify registered Business Users by email at least 30 days’ in advance of the change taking effect. For non-material changes (clarifications, typos, formatting), the revised Policy takes effect when posted.
18. Sub-processor Changes
The current list of sub-processors that process personal information on our behalf is in Section 8. We may engage new sub-processors as we add features or change vendors. We will update Section 8 when we make material changes to that list and treat the change as a material change under Section 17.
19. Contact Us
If you have questions about this Privacy Policy, please contact us at:
Email: privacy@getasteri.com
Address: 4503 Forge Road, Perry Hall, MD 21128
20. Google API Services User Data Policy
Asteri's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
Google user data is used only to provide or improve the user-facing integration the user selected. It is not sold, used for personalized advertising, transferred for advertising purposes, or used to train generalized artificial intelligence or machine-learning models. Human access is limited to actions the user requests, security and abuse investigation, legal obligations, or support performed with the user’s consent.
A service-by-service description of the permissions, use, and disconnection behavior is available on our Google Integrations and Data Use page.