Legal
Privacy Policy
Last updated: May 9, 2026
1. Introduction
Cozy Holdings Corp. ("Company", "we", "us", or "our"), a corporation registered in British Columbia, Canada, operates the Vesta OS platform, accessible at vestaos.ai and associated subdomains (the "Service").
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this policy carefully. By using the Service, you consent to the practices described in this policy.
2. Information We Collect
Account and profile information: Name, email address, phone number, company name, and role when you register for an account.
Property and operational data: Listing details, booking records, guest communication content, pricing data, cleaning and maintenance records, vendor information, and financial settlement data you enter or generate through the Service.
Usage data: IP address, browser type, device identifiers, pages visited, features used, and timestamps of interactions with the Service.
Payment information: Payment processing is handled by Stripe, Inc. We do not store full credit card numbers. Stripe's privacy policy governs the handling of your payment card data.
Communications: Any correspondence you send us, including support requests and feedback.
3. How We Use Your Information
- To provide, operate, and maintain the Service
- To process transactions and send related information
- To train and improve our AI models using aggregated, anonymized operational data
- To send administrative information, such as updates, security alerts, and support messages
- To respond to your comments and questions
- To monitor and analyze usage patterns and trends
- To detect, prevent, and address fraud and abuse
- To comply with legal obligations
4. Data Storage and Transfer
Your data is stored on servers operated by Google Cloud Platform, located in Hong Kong (asia-east2 region). By using the Service, you acknowledge and consent to the storage of your data in Hong Kong.
As a Canadian company, we are subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable British Columbia privacy legislation. We maintain appropriate safeguards to protect personal information during any cross-border transfers.
5. Data Sharing and Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
- Service providers: Third-party vendors who assist in operating the Service, including Google Cloud (infrastructure), Stripe (payments), and Resend (transactional email). These providers are contractually bound to protect your data.
- OTA platform integrations: When you connect Airbnb, Booking.com, Ctrip, or other channels, data is exchanged with those platforms pursuant to your authorization and their terms of service.
- Legal requirements: We may disclose information if required by law, court order, or governmental authority.
- Business transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred subject to appropriate confidentiality protections.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Operational data (booking records, guest communications, task records) is retained for a minimum of 7 years for accounting and legal compliance purposes.
You may request deletion of your account and associated personal data by contacting us at privacy@vestaos.ai. Note that some data may be retained in anonymized, aggregated form for AI model improvement.
7. Your Rights Under PIPEDA
Under PIPEDA and applicable provincial privacy laws, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Withdraw consent to collection or use of your information (subject to legal and contractual restrictions)
- File a complaint with the Office of the Privacy Commissioner of Canada
To exercise these rights, contact our Privacy Officer at privacy@vestaos.ai.
8. Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, access controls, and regular security audits. However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
9. Cookies and Tracking
We use cookies and similar tracking technologies to operate the Service, remember your preferences, and analyze usage. You may configure your browser to refuse cookies, but some features of the Service may not function properly.
10. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected information from a minor, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
12. Contact Us
For privacy-related inquiries:
Cozy Holdings Corp.
Privacy Officer
Email: privacy@vestaos.ai
Website: vestaos.ai
