OSTRO / LEGAL
Privacy Policy
How personal information is used, shared, protected, and retained throughout your Ostro journey.
Who we are and what this policy covers
Ostro is operated by SP STUDIOZ (OPC) PRIVATE LIMITED, a company incorporated in India, with Corporate Identification Number (CIN) U72900PN2022OPC213485. References to “Ostro”, “we”, “us”, and “our” mean that company.
Company address171, Behind ZP School, Ukhali (Kh), Harangul, Gangakhed,
Parbhani, Maharashtra, India — 431514.
This Privacy Policy explains how we handle personal information in connection with the Ostro website, enquiries, onboarding, and the payment workflows we provide. It applies to individuals, business representatives, beneficial owners, and other people whose information is involved in those activities.
For processing whose purposes and means we determine, we act as the controller or corresponding responsible entity under the applicable privacy law. Licensed financial partners may have independent responsibilities for their own verification, payment processing, conversion, custody where applicable, settlement, and legal obligations. Their applicable privacy notices explain that processing. A provider does not act only on our instructions merely because its service is accessible through Ostro.
A notice shown when particular information is requested may provide more detail about the collecting organisation, purpose, recipients, and choices. This policy does not replace that notice or any consent required by law. Privacy questions and requests can be sent to privacy@tryostro.com.
Information you provide
The information required depends on the service, your role, and the checks applicable to your location and payment route. Relevant categories include:
- Contact and workspace information: your name, email address, contact details, country, business or professional role, registration information, and communications about your workspace.
- Identity and business verification: details needed to verify you or your business, which may include date of birth, residential or operating address, identification details and documents, incorporation records, beneficial ownership, and authority to act.
- Payment information: payer and beneficiary details, bank-account identifiers, available receiving details, wallet addresses and selected networks, amounts, currencies or assets, references, instructions, transaction status, and records of returns or disputes.
- Supporting records: contracts, invoices, source-of-funds or payment-purpose information, and documents reasonably required for compliance review.
- Enquiries and preferences: the topic and content of a support or pricing request, preferred routes, and any choices or permissions you communicate.
Some verification steps may be performed directly by a partner. Information Ostro receives from that step depends on the arrangement and may consist of a status or verification result rather than the underlying document. If a verification flow requires a photograph, liveness check, or biometric processing, the collecting provider must explain that activity and obtain any required consent before collection.
Do not send passwords, authentication codes, seed phrases, private keys, identity documents, or sensitive financial records through the public contact form. Use the verification channel provided during onboarding for required verification material.
Information from other sources
We may receive information relevant to your requested service from a business representative you authorise, a payer or recipient involved in a payment, licensed financial partners, verification providers, banks, or other institutions processing an instruction.
Verification and compliance reviews may also use official company registers, sanctions lists, public records, and other lawful sources relevant to identity, ownership, eligibility, or financial-crime risk. We use this information for the relevant check, investigation, or payment workflow.
If you provide another person’s information, have a lawful reason to do so, give them appropriate privacy information, and provide only what is needed. Do not claim to consent on someone else’s behalf without authority.
Website requests and contact forms
When you request a web page, the systems delivering it receive technical information such as an IP address, request time, page address, and browser information. Hosting and security services may record this information to deliver pages, diagnose failures, and detect abuse. Technical request records are distinct from advertising tracking.
The public Ostro pages do not load analytics, advertising pixels, or live-chat widgets. Fonts and brand images are served with the website. Search, filters, and currency previews operate in your browser without sending your selections to an analytics service. A quote enquiry may place your selected route in the contact page’s address so the form can display it.
Our contact form asks for your name, email address, topic, and message. When you submit it, those fields are sent to Formspree, Inc. to handle the submission and deliver it to us. Formspree also receives technical request information. Merely opening or typing into our contact form does not submit your message to Formspree.
Formspree’s Privacy Policy describes its processing. It identifies processing in the United States and other places where it operates. If you prefer, use the email addresses on our Contact page; email delivery also involves email-service providers. See our Cookie Policy for device-storage information.
Why we use personal information
- Respond to you: use contact details and enquiry content to answer questions, prepare a requested quote, investigate a support issue, and communicate a response.
- Establish and manage the relationship: use registration and representative information to identify the customer, manage access, maintain accurate records, and communicate about the service.
- Verify eligibility: use identity, business, location, ownership, and supporting information for onboarding, KYC and sanctions screening, country checks, and compliance escalation.
- Carry out payment workflows: use instructions, destination details, transaction information, and relevant supporting records to coordinate the requested activity with licensed financial partners and show payment status.
- Prevent and investigate misuse: use relevant access, payment, and verification records to detect fraud, resolve errors, investigate unauthorised activity, and protect users and systems.
- Meet legal and recordkeeping obligations: retain required evidence, respond to lawful requests, handle complaints, and establish, exercise, or defend legal claims.
We limit processing to information relevant to the stated purpose. We will provide further information and obtain any necessary permission before using information for a materially different, incompatible purpose.
Legal grounds and consent
We process information on a basis permitted by the law that applies to the particular activity. Where consent is required, including for relevant sensitive-information processing, it must be obtained through an appropriate request. Viewing this policy or accepting the Terms of Service is not blanket consent to every use of your information.
Where the EU or UK GDPR applies, the relevant grounds may include steps you request before a contract or performance of that contract; legal obligations recognised by the applicable privacy law; and legitimate interests in responding to business enquiries, maintaining security, preventing fraud, and resolving claims, subject to balancing your rights. Consent is used for processing that requires it. A separate applicable condition is also required where the law gives particular information additional protection.
You can decline to provide optional information and can withdraw consent by contacting privacy@tryostro.com. We will explain the consequences for an affected service. If information is necessary for verification, a requested payment, or a legal obligation, we may be unable to start or continue that activity without it.
Withdrawal does not invalidate earlier lawful processing or require deletion of information that has a separate, valid retention basis. We will not treat withdrawal as permission to substitute an incompatible processing purpose.
Who receives information
Information is disclosed only where relevant to the purpose, permitted by law, and subject to the responsibilities applicable to the recipient. Recipient categories include:
- Licensed financial partners and payment participants: for verification, screening, payment processing, conversion, custody where applicable, settlement, reconciliation, returns, and investigations.
- Service providers: hosting, security, communication, contact-form, verification, and operational providers used for the relevant service. Formspree is the provider used by this website’s contact form.
- Payers and recipients: receiving instructions or transaction information needed for the payment relationship. Sharing payment instructions is not permission to disclose unrelated identity documents.
- Professional advisers and authorities: where needed for legal advice, accounts, audit, a lawful request, fraud prevention, or a legal claim.
- A successor to the business: where necessary for a lawful reorganisation or transfer, subject to appropriate confidentiality, applicable notice requirements, and continuing protection of personal information.
When a provider processes information on our behalf, its use must be limited by appropriate instructions and safeguards. A financial partner with independent legal duties may decide how it processes and retains information for those duties. We can help identify the relevant recipient for a particular request, subject to lawful restrictions on disclosure.
This policy does not authorise selling your identity, payment, or enquiry records to advertisers or disclosing them for unrelated third-party advertising.
International processing
Ostro is operated from India. Cross-border services may involve recipients or systems in other countries, depending on the selected route and provider. Contact-form processing by Formspree involves the United States, as described in its privacy information.
The laws governing information in another country may differ from those where you live. A transfer must have a lawful basis and satisfy applicable restrictions and safeguards. Where a particular protection level, contractual safeguard, consent, or other transfer condition is required, that requirement must be met before the transfer.
Using a cross-border payment service does not amount to unrestricted consent to transfer your information anywhere. Contact privacy@tryostro.com for information about the recipients, destinations, and safeguards relevant to your activity, subject to protection of confidential or legally restricted information.
How long information is retained
Retention depends on the record, the reason it was collected, applicable legal requirements, and whether a dispute or investigation remains open. We use the following criteria:
- Enquiries and support: the time needed to respond, complete relevant follow-up, document the outcome, and address a related complaint or claim.
- Registration and verification: the duration of the relationship and any further period required for applicable identity, financial-crime, or other legal records. An unsuccessful application may still require limited records where there is a lawful compliance or fraud-prevention reason.
- Payment and accounting records: the period needed to reconcile the activity and comply with applicable accounting, tax, transaction, dispute, and recordkeeping requirements.
- Technical and security records: the period reasonably needed to operate and protect the relevant system, investigate an incident, and comply with any specific legal retention requirement.
- Permission and privacy-request records: the period needed to document choices, fulfil requests, and demonstrate compliance with the obligations that apply.
We will delete information or make it irreversibly anonymous when it is no longer needed for a lawful purpose. Information retained for a specific legal reason must be limited to that purpose and access appropriately restricted. Backup copies, where held, remain protected until removed through the applicable backup cycle.
Closing your workspace does not automatically erase records that must lawfully be retained. Financial partners may have different statutory retention duties. You may ask us which criteria apply to your records and why a particular record remains necessary.
Security and incident handling
We are responsible for applying reasonable technical and organisational safeguards appropriate to the information and risks involved. Access to personal information must be limited to people and providers who need it for an authorised purpose, with appropriate confidentiality and handling requirements.
No service can promise absolute security. Protect your account and devices, check receiving and payout instructions carefully, and report suspected compromise to security@tryostro.com. Do not include passwords or wallet secrets in a report.
Where we become aware of a personal-information incident, we will investigate, take appropriate containment and remedial steps, and notify affected people and authorities when and as required by applicable law.
Your choices and privacy rights
Depending on the law that applies, its commencement, and the circumstances, you may be entitled to ask for information about processing, access or a copy, correction, deletion, restriction, portability, an objection to particular processing, withdrawal of consent, or another remedy provided by law.
You can send a request to privacy@tryostro.com or use the privacy contact form. Describe the request and the service involved. We may ask for proportionate information to verify identity or authority before disclosing or changing a record. We will explain any applicable exception or lawful limitation.
Requests will be handled within the applicable legal timeframe. Information needed for a valid legal obligation, unresolved dispute, or another recognised exception may not be immediately erasable. The rights of other people and restrictions on compliance information may also affect what can be disclosed.
Where a partner independently controls the information, its own privacy procedure may be relevant. We will help direct your request where appropriate. Exercising a privacy right does not itself waive your contractual or statutory remedies.
Screening and review of decisions
Verification, sanctions screening, and fraud checks may use information matching and other automated checks. A result may lead to additional questions or affect whether a payment or service can proceed.
If information appears incorrect or you want to challenge a result, contact support or the privacy contact. We will consider relevant corrections and arrange the review required by applicable law. Any right to information about a decision, human intervention, or an explanation remains subject to the legal rules and any lawful restriction on disclosing security or compliance information.
Verification and payment decisions may involve Ostro and a financial partner. A review concerning a partner’s independent decision may need to be handled through that partner’s applicable process.
Stablecoin transactions and public networks
If you choose an available stablecoin payout, wallet addresses, transaction amounts, transaction identifiers, and other network information may be recorded on a public blockchain. Other people may be able to view that information and link it with information from other sources.
Ostro does not control a public blockchain and may be unable to alter or erase its transaction history. That technical limitation does not remove our responsibilities for personal information in systems we control. Do not place unnecessary personal information in transaction references or other public network fields.
Children and other people’s information
Ostro payment services are intended for adults who meet the eligibility requirements in our Terms of Service. They are not offered to people under 18. Do not register for a child or use a child’s identity to obtain payment access.
If you believe a child’s information has been provided improperly, contact the privacy address so we can assess the situation and take appropriate action, subject to any necessary safeguarding or legal retention obligation.
A business using Ostro must handle information about its representatives, owners, payers, and other contacts lawfully. Providing this policy does not replace the business’s own privacy responsibilities.
Communications and optional uses
We use the contact details you provide to respond to requests and communicate about your relationship with Ostro, including verification, payment issues, material service changes, and security. These service communications are distinct from optional promotional messages.
A contact enquiry does not automatically subscribe you to unrelated marketing. If optional marketing or device-tracking features are introduced, they must have the notices, choices, and permissions required by applicable law. You can object to direct marketing or withdraw a related consent through the privacy contact or an available unsubscribe mechanism.
Additional app-specific privacy or storage information must be provided for features not described by the public website’s cookie inventory. Read any notice shown when signing in, verifying identity, or selecting a partner service.
Complaints and contact
For privacy requests and grievances, contact privacy@tryostro.com, or write to SP STUDIOZ (OPC) PRIVATE LIMITED at the company address in section 1, marked “Privacy request”. For payment and account support, use support@tryostro.com. If a privacy concern remains unresolved, you may also contact legal@tryostro.com.
We will review the information, request clarification where needed, and communicate the outcome or relevant next steps. Where the Indian sensitive-personal-data rules require redress of a grievance within one month, that requirement applies; we will also comply with any other applicable statutory deadline.
You may approach a competent data-protection authority, consumer body, or court where the law provides that remedy, subject to its applicable procedure. This policy does not restrict those rights, claim that every regional law applies to every user, or bring a statutory right into effect before its legal commencement.
Changes to this policy
We will update this policy when the relevant services, providers, processing purposes, or legal requirements change. The date at the top identifies the latest version. Material changes will be communicated through an appropriate notice where required.
An update does not retrospectively authorise incompatible processing or replace any consent that must be obtained. This policy explains privacy practices and responsibilities; it is not a waiver of your rights or a substitute for the Terms of Service.