Privacy Policy
OnSyra, operated by Lansky Center Solutions Inc. Version 1.0 · Effective [DATE] · DRAFT — requires counsel review
This policy says what we actually collect and why. Where a practice is uncomfortable — location tracking, identity documents — it is stated plainly rather than buried.
1. What we collect
You give us
| Data | Why | Who sees it |
|---|---|---|
| Name, email, phone | Account, notifications | You, LCS |
| Date of birth | Identity verification, age eligibility | LCS, verification provider |
| Government ID document | Legal identity verification | LCS operations only |
| Taxpayer ID (SSN/EIN) | Tax reporting. Full value stored encrypted; most staff see only the last four digits, and access to the full number is limited, logged and requires a reason. (Pending counsel review.) | LCS finance |
| Bank / payout details | Paying you | LCS finance, payment provider |
| Home or base address | Matching work to your area | LCS; city only is shown publicly |
| Skills, certifications, résumé | Matching and Client selection | Public profile, except the résumé file |
| Business registration documents | Verifying a business | LCS operations |
Generated by using the platform
| Data | Why | Notes |
|---|---|---|
| Location at check-in and check-out | Proving attendance at the site | Shared with that engagement's Client |
| Location during an active job | Live arrival tracking | Only while a job is in progress. Stops at check-out. |
| Work photos, notes, signatures | Evidence of completed work | Shared with the engagement's parties |
| Messages | Communication on an engagement | The parties, and LCS if a dispute is raised |
| Time logs | Hours worked and billed | The parties |
| Ratings and reviews | Marketplace trust | Public |
| Device, browser, IP address | Security, fraud prevention, abuse investigation | LCS |
| Sign-in events | Account security | You, LCS security |
From others
Identity verification and sanctions-screening results, background check results where required for a role, and payment status from our payment providers.
2. Why we are allowed to (legal bases)
- Contract — running your account, matching work, paying you
- Legal obligation — identity verification, sanctions screening, tax reporting, record retention
- Legitimate interests — fraud prevention, platform security, service improvement
- Consent — marketing, and device location in the browser. Both can be withdrawn.
3. Location, specifically
Because it is the most intrusive thing we collect:
- We ask the browser for location. You can refuse, and the platform still works.
- Continuous tracking happens only while you are on an active job, and stops at check-out.
- We do not track you between jobs, off shift, or when the app is closed.
- Location is shared only with the Client of that engagement, never the marketplace.
- The public map shows work and coverage at city level, never a precise address.
4. Who we share with
Engagement counterparties — the Client and Provider on a job see each other's relevant details and the work evidence. Exact site addresses are released only on award acceptance.
Service providers working on our behalf, under contract, listed in
subprocessors.md: identity verification, sanctions screening, payment
processing, email delivery, hosting, error monitoring.
Authorities where legally required. Where we are permitted to tell you, we will.
A successor in a merger or acquisition, under the same commitments.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
5. How long we keep it
Set out in data-retention-schedule.md. Summary: account records for 7 years
after closure (tax and AML obligations), identity verification records for
5 years, financial records for 7 years, work evidence for 3 years,
location data for 12 months, messages for 3 years.
Some of this is longer than we would choose. It is driven by AML and tax retention rules, not preference.
6. Your rights
Wherever you are, you can access, correct, delete, export (machine-readable), object to processing based on legitimate interests, and withdraw consent.
Deletion has limits we will be honest about. We cannot delete records we are legally required to keep — transaction records, identity verification, tax documents. We can delete your profile, close your account, and stop all non-required processing. We will tell you exactly what is retained and why.
California (CCPA/CPRA) — the above rights, plus the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined.
EU/UK (GDPR) — the above rights, plus the right to lodge a complaint with your supervisory authority.
Canada (PIPEDA) — the above rights, plus complaint to the Privacy Commissioner.
Exercise any of these at privacy@onsyra.com. We respond within 30 days.
We will verify your identity before acting — that check protects you.
7. Automated decisions
Two things on the platform are automated:
- Match scoring ranks work orders and technicians by skills, distance, ratings and reliability. It influences visibility, not eligibility — it does not decide who may work.
- Sanctions screening can automatically suspend payouts on a possible match.
Any adverse automated outcome can be reviewed by a person on request. For screening matches, a human reviews before any decision becomes permanent.
8. Security
Encryption in transit (TLS) and at rest for sensitive fields; identity documents and payout details are never served publicly — every file is delivered only after an authorisation check. Two-factor authentication is available to everyone and mandatory for staff. Access is least-privilege and logged. Backups are encrypted, verified, and tested.
If a breach affects you, we follow incident-response-plan.md and notify you
and the regulators within the periods the law requires.
9. International transfers
Data is processed in the United States. Transfers from the EU/UK rely on [MECHANISM — counsel to confirm: Standard Contractual Clauses or equivalent].
10. Children
The platform is not for anyone under 18. We do not knowingly collect their data and will delete it if we learn we have.
11. Changes
Material changes are notified 30 days in advance by email and in the platform.
Contact: privacy@onsyra.com · Data protection contact: [NAME — to be appointed]