Last updated: 30 March 2026
This Privacy Policy explains how Ostly (“we”, “us”, “our”) collects, uses, stores, and protects your personal information when you use Ostly at ostly.co (“Service”). We are committed to handling your data responsibly and in compliance with applicable privacy laws, including the Protection of Personal Information Act 4 of 2013 (POPIA) and, where applicable, the General Data Protection Regulation (GDPR).
By using the Service, you agree to the practices described in this policy. If you do not agree, please do not use the Service.
The responsible party (under POPIA) and data controller (under GDPR) is Ostly, operated from South Africa. You can reach us at hello@ostly.io for any privacy-related matters.
| Purpose | Information used | Lawful basis |
|---|---|---|
| Provide and operate the Service | Account info, content you create | Contract performance |
| Process payments and manage subscriptions | Email, Paddle customer ID, subscription status | Contract performance |
| Send transactional emails (receipts, password resets, trial reminders) | Email address | Contract performance |
| Improve the Service | Usage data, error data | Legitimate interest |
| Detect and prevent abuse or fraud | Account info, technical data | Legitimate interest |
| Comply with legal obligations | As required by applicable law | Legal obligation |
We do not sell your personal information. We do not use your content to train AI models. We do not send marketing emails unless you have explicitly opted in.
We share data only with the third-party service providers necessary to operate the Service. These are:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database hosting and user authentication | United States (AWS) |
| Vercel | Application hosting and deployment | United States / global edge |
| Paddle | Payment processing and subscription management | United Kingdom / United States |
| Sentry | Error tracking and crash reporting | United States |
We do not share your data with any other third parties except where required by law or to protect the rights and safety of users.
We are based in South Africa. Our service providers operate primarily in the United States and United Kingdom. By using the Service, you acknowledge that your information may be transferred to and processed in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) to protect your data during these transfers.
We retain your personal information for as long as your account is active or as needed to provide the Service. If you close your account:
Depending on where you are located, you may have the following rights regarding your personal information:
To exercise any of these rights, email us at hello@ostly.io. We will respond within 30 days. We may ask you to verify your identity before processing your request.
If you are in South Africa, you have the right to lodge a complaint with the Information Regulator of South Africa. If you are in the EU or UK, you have the right to complain to your local supervisory authority.
We use industry-standard security measures to protect your personal information, including encrypted connections (HTTPS/TLS), Row Level Security in our database so users can only access their own data, and access controls limiting who within our organisation can access user data. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
In the event of a personal data breach, we will notify affected users and the relevant supervisory authority as required by applicable law.
The Service uses a small number of essential cookies required for authentication and session management. We do not use advertising or tracking cookies. We do not use third-party analytics cookies (such as Google Analytics).
You can disable cookies in your browser settings, but doing so may prevent the Service from functioning correctly.
The Service is not directed at children under 18 and we do not knowingly collect personal information from anyone under 18. If we become aware that we have collected data from a minor, we will delete it promptly. If you believe a minor has provided us with their data, please contact us at hello@ostly.io.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a notice in the Service at least 14 days before the changes take effect. The “last updated” date at the top of this page reflects the most recent version.
For any questions, requests, or concerns about this Privacy Policy or how we handle your data, please contact us: