← All documents

Open Storage Platform (OSP) Privacy Policy

Version: 0.7.1 Beta Draft Effective: [EFFECTIVE DATE] Organization: btec LLC Contact: b@btec.me


Plain-Language Summary

What this means for you:

  • We collect the bare minimum needed to run the service: your email, name, and account details.
  • Your customer data (tenant records, leases, financials) is *your data*. We process it only to provide the service.
  • We do not sell data. We don't run ad trackers. We don't monetize your information.
  • We haven't done formal GDPR, CCPA, or HIPAA certifications yet — this is beta. Be aware of that if you handle regulated data.
  • You control your instance. You control who accesses it. You're responsible for your own data-handling practices.
  • If something's unclear, email b@btec.me.

1. Who We Are

btec LLC ("b-tec," "we," "us") provides the Open Storage Platform (OSP), a source-available storage management platform. This Privacy Policy explains how we handle information when you use OSP.

This policy applies to:

  • The OSP hosted beta service
  • The osp.b-tec.org website and login portal
  • The osp.your.site website and login portal
  • Communications between you and b-tec

It does not apply to self-hosted OSP instances you run on your own infrastructure. On those instances, you are the data controller.

2. Important Distinction: Controller vs. Processor

We wear two hats depending on the data:

RoleWhat it coversWho's responsible
Data ControllerYour account information (email, name, billing contact), website analyticsb-tec
Data ProcessorCustomer Data stored inside your OSP instanceb-tec processes on your behalf; you are the controller

For Customer Data (everything inside your instance — tenants, leases, financials, facility data), you determine what data is collected, who can access it, and how long it's kept. We provide the platform. See the Data Processing Addendum for the formal terms.

3. What Data We Collect

3.1 Account Data (We Are Controller)

When you sign up for OSP, we collect:

  • Email address — required for login and account recovery
  • Name / display name — for account identification
  • Account creation date — for audit and support purposes
  • Billing contact information — for invoicing/ billing
  • Support communications — emails, messages, and any info you share with us for support

3.2 Customer Data (You Are Controller)

Inside your OSP instance, the platform stores whatever data you choose to put in it. This typically includes:

  • Tenant personally identifiable information (PII) — names, contact details, identification documents
  • Lease and rental records — agreements, terms, payment histories
  • Financial records — payment transactions, ledgers, invoices
  • Facility operational data — unit configurations, maintenance records, access logs
  • Audit logs — automatically generated records of actions taken within your instance

We do not access, review, or use Customer Data except:

  • As necessary to provide technical support (with your permission)
  • As required by law
  • As described in our Security Overview

3.3 Automatically Collected Data

When you interact with OSP's web interface:

  • Session data — login timestamps, IP addresses, browser metadata (standard web server logs)
  • Performance and error logs — to debug issues and keep the service running
  • No advertising trackers, no cookies for marketing, no fingerprinting.

4. How We Use Data

Account Data

  • To authenticate you and provide access to OSP
  • To communicate with you about the service (updates, maintenance, billing)
  • To provide customer support
  • To improve OSP based on aggregated, anonymized usage patterns

Customer Data

  • Solely to provide the OSP service as directed by you
  • Solely on infrastructure you or we provision for your instance

5. Data Sharing & Subprocessors

5.1 We Do Not Sell Data

We do not sell, rent, or trade Account Data or Customer Data to third parties. We do not use Customer Data for advertising or marketing.

5.2 Subprocessors

To run OSP, we rely on modern infrastructure providers. These are listed in the Data Processing Addendum. Key ones:

  • Vercel — hosting and edge functions
  • Neon — PostgreSQL database hosting
  • Stripe — payment processing (connected to *your* Stripe account, not ours)
  • Resend — transactional email delivery
  • Inngest — background job processing

5.3 Legal Disclosure

We may disclose data if required by valid legal process. We will notify you before disclosure unless prohibited by law.

6. Data Retention

Account Data

We retain your account information as long as your account is active. Upon termination, we delete Account Data within 90 days unless required otherwise by law.

Customer Data

You control retention of Customer Data. Upon termination, we provide a full database export and then delete instance data within 90 days of termination, unless you instruct otherwise.

7. Your Rights

Depending on where you are, you may have rights under laws like GDPR or CCPA. Because this is a beta service, we have not yet completed formal compliance certification. However, we commit to:

  • Providing you a copy of your Account Data on request
  • Correcting inaccurate Account Data
  • Deleting your Account Data on request (subject to legal obligations)
  • Exporting your Customer Data at any time through the platform

To exercise these rights, email b@btec.me.

8. No GDPR / CCPA / HIPAA Certifications (Yet)

OSP is beta software. We have not completed:

  • Formal GDPR compliance assessment or Data Protection Impact Assessment
  • CCPA compliance verification
  • HIPAA Business Associate Agreement (BAA) readiness
  • SOC 2 audit
  • PCI DSS assessment (payment processing is handled through your own Stripe account)

If you handle regulated data (health records, EU personal data, California consumer data), you should consult your own counsel before using OSP in beta. We intend to address these frameworks as OSP matures toward general availability.

9. Security

We take security seriously. See the Security Overview for the full picture. Highlights:

  • HTTPS/TLS everywhere
  • Row-Level Security (RLS) at the database level
  • Bcrypt password hashing (never stored in plaintext)
  • Session-based authentication with 7-day tokens
  • Append-only audit log for all changes
  • Idempotency enforcement on financial operations

10. International Transfers

b-tec's data is hosted in Illinois and Ohio regions.

11. Changes to This Policy

We will notify active customers of material changes via email at least 14 days before they take effect. Continued use after changes constitutes acceptance.

12. Contact

btec LLC Email: b@btec.me Bourbonnais, Illinois

Questions? b@btec.me