Legal & Trust
Legal

Privacy Policy

Learn how StorageFlo.io collects, uses, shares, retains, and protects personal information for operators, users, renters, and website visitors.

EffectiveApril 25, 2026·v1.0·Last updatedApril 25, 2026
USCAEUUKAU

1. Overview and scope

This Privacy Policy ("Policy") explains how South Star Holdings LLC, operating the StorageFlo platform, collects, uses, shares, and protects personal information. It applies to everyone who interacts with StorageFlo: operators who subscribe to the Service, their employees and authorized users, and the end-users (tenants) whose data flows through the operator's booking widget.

This Policy covers StorageFlo in two distinct capacities: as a Controller for direct relationships with operators, and as a Processor for tenant personal information handled at the operator's direction. Section 2 explains this distinction in detail.

This Policy does not apply to third-party websites or services that operators or tenants may link to from StorageFlo. Those parties have their own privacy practices.

By using the Service, you acknowledge this Policy. Operators accepting our Terms of Service also accept the data processing terms set out in the DPA.

2. Who we are

South Star Holdings LLC is a Delaware limited liability company. Our registered address is [REGISTERED ADDRESS PENDING INCORPORATION]. We operate the StorageFlo platform at storageflo.io.

As a Controller, we process operator account information, billing data, and platform telemetry for our own business purposes. The lawful bases for that processing are set out in Section 5.

As a Processor, we process tenant personal information strictly as instructed by the operator. We do not independently determine the purpose or means of that processing. The full terms governing our processor role, including data subject request handling and security obligations, are in the DPA.

For the remainder of this Policy, "Personal Information" means any information that identifies or could reasonably identify a natural person.

3. What we collect

We collect Personal Information in the categories described below.

3.1. Account and contact data

When an operator creates an account, we collect:

  • Operator name and email address.
  • Job title, role, and company name.
  • Business address, phone number, and website.
  • Account credentials (stored in hashed form).

We also collect similar information for each Authorized User the operator adds to its account.

3.2. Billing data

For paid subscriptions, we collect:

  • Billing name and address.
  • Tax identification numbers where required.
  • Payment-method tokens provided by our payment processors (Stripe, Inc. and Square, Inc.).

We do not store full payment card numbers (PANs), card verification values (CVVs), or magnetic stripe data on StorageFlo infrastructure. Payment card details pass directly to and are stored by the applicable processor.

3.3. Telemetry and usage data

When operators or their users interact with the Platform, we automatically collect:

  • IP address and approximate geographic location.
  • Browser type, operating system, and device identifiers.
  • Pages visited, features used, and action timestamps.
  • Error reports, performance metrics, and diagnostic logs.

This data is linked to operator accounts for support, security, and product improvement purposes.

3.4. Customer-provided content

Operators upload and maintain:

  • Facility details, unit listings, and availability calendars.
  • Lease templates, move-in checklists, and communication templates.
  • Documents, notes, and configurations created within the Platform.

This content may incidentally contain Personal Information about the operator's staff or tenants. The operator is responsible for the lawfulness of any such content.

3.5. Tenant personal information (processed on operator's behalf)

When a tenant interacts with an operator's booking widget, the following information is collected on the operator's behalf:

  • Name, email address, and phone number.
  • Move-in date, unit selection, and lease terms.
  • Payment metadata (transaction IDs, amounts, timestamps) provided by the payment processor.
  • Communications between the tenant and the operator routed through the Platform.

We collect and process this information only as instructed by the operator. The operator's privacy policy governs the operator's relationship with the tenant.

4. How we collect it

We collect Personal Information in the following ways:

  • Directly from you. When you register, complete a form, contact support, or interact with the Platform.
  • Automatically. Through our servers, logs, cookies, and similar tracking technologies when you use the Service. See Section 11 for details.
  • From operators. When an operator configures an integration, invites users, or uploads content that includes Personal Information.
  • From integration partners. When an operator connects an Integrated System such as SiteLink, storEDGE, or Yardi Breeze, data flows to and from that system under the operator's direction.
  • From payment processors. Stripe and Square provide payment metadata and event notifications that we record on behalf of the operator.

5. Lawful bases for processing

For Personal Information we process as a Controller, we rely on the following lawful bases under GDPR Article 6 and equivalent provisions in applicable law:

Processing purposeLawful basis
Creating and managing operator accountsContract performance (Art. 6(1)(b))
Processing subscription payments and issuing invoicesContract performance (Art. 6(1)(b))
Operating and improving the PlatformLegitimate interest (Art. 6(1)(f))
Sending product updates and service communicationsContract performance or legitimate interest (Art. 6(1)(b)/(f))
Sending marketing communications (optional)Consent (Art. 6(1)(a))
Fraud detection and platform securityLegitimate interest (Art. 6(1)(f))
Compliance with legal obligations (tax, audit, law enforcement)Legal obligation (Art. 6(1)(c))

For Personal Information we process as a Processor (tenant data on the operator's behalf), the lawful basis is determined by the operator as Controller. The operator is responsible for identifying and documenting the applicable basis.

6. How we use your information

As a Controller, we use the Personal Information we collect to:

  • Create, maintain, and secure operator accounts.
  • Process subscription payments, issue invoices, and manage billing.
  • Provide customer support and respond to inquiries.
  • Monitor, diagnose, and improve the performance and reliability of the Platform.
  • Detect and prevent fraud, abuse, and security incidents.
  • Send transactional communications related to the Service (billing confirmations, security alerts, service updates).
  • Send optional marketing or product-update emails where you have provided consent or where we have a legitimate interest and you have not opted out.
  • Comply with applicable laws, court orders, and regulatory requirements.
  • Generate anonymized, aggregated analytics to improve the Service.

We do not sell your Personal Information. We do not use it to serve third-party advertising.

As a Processor, we use tenant Personal Information only as directed by the operator. We do not use tenant data for our own independent purposes.

7. Sharing and disclosure

We share Personal Information in the following circumstances.

Subprocessors. We engage third-party subprocessors to help deliver the Service. Those subprocessors are bound by data processing agreements that impose confidentiality and security obligations at least as protective as this Policy. A current list is maintained at Subprocessors. Key subprocessors include:

  • Google Cloud Platform and Firebase (hosting, database, storage, authentication).
  • Stripe, Inc. (payment processing).
  • Square, Inc. (payment processing).

Integration partners. When an operator enables an integration with SiteLink, storEDGE, Yardi Breeze, or another Integrated System, data flows to that partner under the operator's direction. Integration partners act under the operator's authority, not ours. They are not our subprocessors in that context.

Service providers. We may share Personal Information with vendors who provide ancillary services such as email delivery, analytics, error monitoring, and customer support tooling. Those vendors are bound by contractual confidentiality obligations.

Business transfers. If South Star Holdings LLC undergoes a merger, acquisition, or sale of all or substantially all of its assets, Personal Information may be transferred to the acquiring entity. We will provide notice before such a transfer takes effect.

Legal and regulatory disclosure. We may disclose Personal Information when we believe disclosure is required by applicable law, regulation, legal process, or governmental request. We will provide notice to the affected party where legally permitted and where doing so is not precluded by the nature of the request.

With your consent. We may share Personal Information for any other purpose with your explicit consent.

We do not sell, rent, or trade Personal Information to third parties for their own marketing purposes.

8. International data transfers

StorageFlo is operated from the United States. Personal Information may be transferred to, stored in, and processed in the United States or other countries where our subprocessors operate.

European Economic Area and United Kingdom. For transfers of Personal Information from the EEA and UK to countries not recognized as providing an adequate level of protection, we rely on:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission. For transfers where we are Controller, we use Module 2 (controller-to-processor). For transfers where the operator is Controller and we are Processor, we use Module 3 (processor-to-processor), incorporated into the DPA.
  • The UK International Data Transfer Addendum (IDTA) to the EU SCCs, for transfers from the United Kingdom.

Switzerland. For transfers from Switzerland, we apply the Swiss Federal Act on Data Protection (nFADP) equivalents to the SCCs where required.

Adequacy decisions. Where the European Commission or UK Information Commissioner's Office has issued an adequacy decision for the destination country, we rely on that decision.

Details of the transfer mechanisms applicable to specific subprocessors are set out in the DPA. You may request a copy of the applicable SCCs by emailing [email protected].

9. Data retention

We retain Personal Information for as long as necessary to fulfill the purposes described in this Policy, subject to longer retention required by law.

Specific retention periods:

  • Operator account data. Retained for the duration of the subscription and for 90 days after account closure, to allow for data export. After that period, we delete or anonymize the data, except where law requires longer retention.
  • Billing records. Retained for seven years to satisfy tax and financial recordkeeping requirements.
  • Telemetry and log data. Retained for 90 days in operational logs, and up to 24 months in aggregated or de-identified analytics.
  • Tenant personal information. Retained as instructed by the operator. Operators may configure retention periods within the Platform. Upon termination of the operator's account, we follow the process described in the DPA.
  • Support communications. Retained for three years after the conversation closes.

When retention periods expire, we securely delete or anonymize the data using industry-standard methods.

10. Your rights, by jurisdiction

Depending on where you are located, you may have the following rights with respect to your Personal Information. We describe those rights by jurisdiction below.

10.1. European Economic Area and United Kingdom (GDPR / UK GDPR)

If you are located in the EEA or UK, you have the following rights under the General Data Protection Regulation (GDPR) or UK GDPR:

  • Right of access (Art. 15). You may request a copy of the Personal Information we hold about you and information about how we process it.
  • Right to rectification (Art. 16). You may request correction of inaccurate or incomplete Personal Information.
  • Right to erasure (Art. 17). You may request deletion of your Personal Information where the processing is no longer necessary, you have withdrawn consent, or you have objected to processing that has no overriding legitimate ground.
  • Right to restriction of processing (Art. 18). You may request that we limit our processing of your Personal Information in certain circumstances.
  • Right to data portability (Art. 20). You may request a structured, machine-readable copy of Personal Information you provided to us, where processing is based on consent or contract.
  • Right to object (Art. 21). You may object to processing based on legitimate interest or for direct marketing purposes. We will cease that processing unless we can demonstrate compelling legitimate grounds.
  • Rights related to automated decision-making (Art. 22). You have the right not to be subject to decisions based solely on automated processing where those decisions produce legal or similarly significant effects.

You also have the right to lodge a complaint with a supervisory authority in your country of residence or establishment.

10.2. California (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to know. You may request disclosure of the categories and specific pieces of Personal Information we collect about you, and the categories of sources, business purposes, and third parties with whom we share it.
  • Right to delete. You may request deletion of Personal Information we hold about you, subject to certain exceptions.
  • Right to correct. You may request correction of inaccurate Personal Information.
  • Right to opt out of sale or sharing. We do not sell or share Personal Information for cross-context behavioral advertising. If that practice changes, we will provide a "Do Not Sell or Share My Personal Information" link at storageflo.io/privacy-choices.
  • Right to limit use of sensitive personal information. You may request that we limit our use of sensitive Personal Information to the purposes permitted by the CPRA.
  • Right to non-discrimination. We will not discriminate against you for exercising any of these rights.

Categories of Personal Information we have collected in the preceding 12 months are described in Section 3. We have not sold Personal Information to third parties for their own purposes.

10.3. Canada (PIPEDA)

If you are located in Canada, you have the following rights under the Personal Information Protection and Electronic Documents Act (PIPEDA):

  • Right of access. You may request access to the Personal Information we hold about you and information about how it has been used or disclosed.
  • Right to correction. You may request correction of inaccurate or incomplete Personal Information.
  • Right to withdraw consent. Where processing is based on consent, you may withdraw consent at any time, subject to legal and contractual restrictions. Withdrawal of consent may affect our ability to provide certain services.

10.4. Australia (Privacy Act / APPs)

If you are located in Australia, you have the following rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs):

  • Right of access. You may request access to the Personal Information we hold about you.
  • Right to correction. You may request that we correct Personal Information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
  • Right to complain. You may make a complaint to the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs.

10.5. How to exercise your rights

To exercise any of the rights described above, email us at [email protected].

We will respond within 30 days of receiving your request, or within any shorter period required by applicable law. Requests are free of charge unless they are manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline the request.

We may ask you to verify your identity before processing your request. This is to protect your Personal Information from unauthorized disclosure.

If you are a tenant whose Personal Information was collected by an operator through the booking widget, please direct your request to the operator in the first instance. The operator is the Controller for that data and is responsible for responding to your request. We will assist the operator as described in the DPA.

11. Cookies and similar technologies

StorageFlo uses cookies and similar technologies to operate the Platform, remember preferences, maintain sessions, and analyze usage.

A full explanation of the types of cookies we use, their purposes, their lifetimes, and your choices is provided in our Cookie Policy. That policy also explains how to manage your cookie preferences.

The booking widget deployed on operator websites may set cookies on behalf of the operator. The operator's cookie policy governs the widget's cookie behavior on their domain.

12. Children's privacy

The StorageFlo Service is directed to businesses, not to individuals under the age of 18. We do not knowingly collect Personal Information from children under 18.

If we become aware that we have inadvertently collected Personal Information from a child under 18, we will delete it promptly. If you believe we may have collected such information, please contact us at [email protected].

13. Security

We apply industry-standard technical and organizational measures to protect Personal Information against unauthorized access, disclosure, alteration, and destruction. A description of our security practices is published at /security.

Measures include encryption of data in transit and at rest, access controls, audit logging, vulnerability management, and incident response procedures.

No method of transmission or storage is 100% secure. We cannot guarantee absolute security. We encourage operators to review our security documentation and to maintain their own risk management practices.

If you discover a potential security vulnerability, please report it to [email protected] before disclosing it publicly. We follow responsible disclosure practices.

14. Changes to this policy

We may update this Policy from time to time. For changes that materially affect how we collect, use, or share Personal Information, we will provide at least 30 days advance notice. We will deliver that notice by email to the address on the operator's account, by in-product notification, or both.

The updated Policy will take effect on the date stated in the notice. Continued use of the Service after that date constitutes acceptance of the updated Policy.

For minor or non-material changes, such as typographical corrections, clarification of existing practices, or updates required by law that do not reduce protections, we may update the Policy with shorter or no notice.

The current version of this Policy is always available at storageflo.io/legal/privacy. The version number and effective date appear in the frontmatter of the document.

15. Contact

For questions about this Policy or to exercise your privacy rights, contact us:

Mailing address:

South Star Holdings LLC [REGISTERED ADDRESS PENDING INCORPORATION]

EU representative. Our designated EU representative is [EU REPRESENTATIVE PENDING APPOINTMENT]. EU residents may contact the EU representative directly for matters related to the GDPR.

UK representative. Our designated UK representative is [UK REPRESENTATIVE PENDING APPOINTMENT]. UK residents may contact the UK representative directly for matters related to the UK GDPR.

Data Protection Officer. Our designated DPO contact is [DPO PENDING APPOINTMENT]. DPO appointment is required under the GDPR only when an organization's processing meets certain thresholds (for example, large-scale processing of special categories of data, or systematic monitoring of data subjects). If South Star Holdings LLC has not yet reached those thresholds, the [DPO PENDING APPOINTMENT] placeholder will be updated when a DPO is formally appointed.

Ready to evaluate?

Review the terms, then start the setup.

Once the operational, privacy, and payment boundaries make sense for your team, you can start shaping the booking path for your facility.

Clear policiesDefined boundariesOperator control