The short version. Ostrich App Inc. runs member communications for credit unions. We collect very little about visitors to this website. The credit union member data we handle isn't ours, we process it on behalf of the credit union that gave it to us, under their instructions, and we don't sell it, rent it, or use it to advertise to anyone.
1. Who we are
Ostrich App Inc. ("Ostrich," "we," "us") is a Delaware corporation providing managed member communications services to credit unions.
This policy explains what we do with personal information collected through getostrich.com, through our sales and client relationships, and through the member communications we operate on behalf of credit union clients.
Contact: info@getostrich.com
2. Two different roles
This distinction matters, because different rules apply to each.
When we act for ourselves. For visitors to this website, prospective clients, and the people we deal with at client credit unions, we decide what information is collected and why. In GDPR terms we are the controller; under US state privacy laws we are the business.
When we act for a credit union. When a credit union engages us, they provide member information so we can send communications on their behalf. That data belongs to the credit union. We handle it only on their documented instructions, and we do not use it for our own purposes. In GDPR terms we are a processor; under US state privacy laws we are a service provider.
If you are a credit union member and want to know how your information is used, the credit union's own privacy notice governs. Requests about your data should go to your credit union, and we will support them in responding.
3. Information we collect
Website visitors
- Usage and device information collected automatically: IP address, browser type, operating system, referring page, pages viewed, and time on page.
- Session activity, including mouse movement, scrolling, and clicks, captured through session-recording and heatmap tools. See section 4.
- Information you give us when you book a call or email us: your name, email address, credit union, role, and whatever you choose to put in the message.
Prospective and current client contacts
- Name, job title, business email, business phone, and credit union.
- Records of our correspondence, meetings, and calls.
- Billing and contract administration details.
Credit union member data (processed for our clients)
To operate a client's member communications, the credit union provides us with member information, typically by export. This usually includes name, email address, and membership or relationship indicators such as whether someone joined through indirect lending.
We do not connect to a credit union's core banking system. We do not receive account numbers, balances, transaction histories, Social Security numbers, or credit data, and we do not ask for them. The scope of data for each engagement is set in that client's agreement.
4. Cookies, analytics, and session recording
This website uses the following. We are naming them specifically because generic disclosure isn't useful to anyone.
| Tool | What it does | Cookies |
|---|---|---|
| Google Analytics 4 | Traffic volume, traffic sources, which pages are read, and which calls-to-action are clicked. | Yes |
| Microsoft Clarity | Records browsing sessions and builds heatmaps. This captures mouse movement, scrolling, and clicks so we can see where pages confuse people. Clarity applies automatic masking to text entered into form fields. | Yes |
| Cloudflare Web Analytics | Page views and performance measurement. | No, cookieless |
We call out session recording explicitly because most policies bury it. If you would rather not be recorded, you can block these tools with a browser extension or by disabling cookies in your browser settings. Nothing on this site stops working if you do.
We do not run advertising on this website, we do not use advertising cookies, and we do not participate in ad networks or retargeting.
[DECISION NEEDED: GA4 and Clarity both set cookies. A consent banner is currently not implemented. Counsel should advise whether one is required given the visitor mix.]
5. How we use information
Information we hold as a controller is used to:
- Operate, secure, and improve this website
- Respond to enquiries and schedule calls
- Provide, administer, and support our services
- Send business communications to prospective and current clients
- Handle billing and keep proper records
- Meet legal, tax, and regulatory obligations
- Detect and prevent fraud, abuse, and security incidents
Member data we process for a credit union is used only to deliver that credit union's program: sending their member communications, operating their onboarding sequences, running their branded financial wellness site, and producing their engagement reporting. Nothing else. We do not use one client's member data to benefit another client, to train models, or to build our own marketing lists.
6. We do not sell your information
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act and comparable state laws. We have never done so.
7. Who we share information with
We share information with service providers who help us operate, each bound by contract to protect it and use it only for the services they provide to us:
- Cloudflare, Inc. Website and microsite hosting, content delivery, security, and cookieless traffic analytics.
- Google LLC. Google Workspace for email, documents, and file storage, and Google Analytics 4 for website measurement.
- Microsoft Corporation. Microsoft 365 for business productivity and storage, and Microsoft Clarity for website session analytics.
- Notion Labs, Inc. Internal documentation and project records.
- Anthropic PBC. Enterprise Claude, used to assist with drafting member communications content. Our agreement provides that our data is not used to train models.
- Email service providers. Delivery of client member communications. The specific platform varies by client, and where the account is held in the credit union's own name that provider is the credit union's processor rather than our subprocessor.
- Scheduling and business software. Call booking, billing, and internal operations.
We keep this list current and will provide it, with processing locations, on request during vendor review.
On artificial intelligence specifically. Credit union compliance teams increasingly ask whether member data is processed by AI tools. Where we use AI assistance to draft content, we do so under enterprise agreements that prohibit use of our data for model training. We do not upload member lists or personally identifiable member data into general-purpose AI tools.
We may also disclose information where required by law, to enforce our agreements, or in connection with a merger or acquisition. If we are ever compelled to disclose client member data, we will notify the client unless legally prohibited.
8. How long we keep information
- Website analytics, retained per the tool's default retention window, then deleted or aggregated.
- Enquiries and prospect records. Kept while there is an active business relationship or prospect, and deleted 24 months after the last meaningful contact.
- Client records, kept for the term of the agreement plus any period required for legal, tax, or audit purposes.
- Member data processed for a client, kept only as long as needed to deliver that client's program. On termination it is returned or deleted at the client's direction, per their agreement.
- Compliance review records, the auditable review trail we maintain for member communications is retained for three years so clients can evidence their review process across multiple examination cycles.
9. Security
We maintain administrative, technical, and physical safeguards appropriate to the information we handle, including access controls, encryption in transit, and limiting access to personnel who need it.
Our decision not to integrate with client core banking systems is itself a security posture: it means we never hold account numbers, balances, or transaction data, so a compromise of our systems could not expose them.
No system is perfectly secure. If a breach affecting personal information occurs, we will notify affected parties and, where we act as a processor, the relevant credit union without undue delay and as required by law and by contract.
10. Your privacy rights
Depending on where you live, you may have the right to:
- Know and access, what personal information we hold about you and how we use it
- Correct, inaccurate or incomplete information
- Delete, your personal information, subject to legal exceptions
- Portability, receive your information in a portable format
- Opt out, of sale or sharing for targeted advertising. We do neither.
- Non-discrimination. We will not treat you differently for exercising these rights
- Restrict or object to processing, and withdraw consent, where those rights apply to you
To exercise any of these, email info@getostrich.com. We will verify your identity before acting and respond within the timeframe the applicable law requires, generally 45 days under US state laws and one month under GDPR.
If you are a credit union member, direct your request to your credit union. They control that data; we act on their instructions and will assist them promptly.
11. Children
Our services are sold to credit unions and are not directed to children. We do not knowingly collect personal information from children under 13 through this website. If you believe a child has provided us information, contact info@getostrich.com and we will delete it.
Member communications we send on behalf of a credit union go to that credit union's membership, which may include minors who are members. In that case the credit union is the controller and its own policies and consents apply.
12. The former Ostrich consumer app
Ostrich previously operated a direct-to-consumer financial wellness mobile app. That app has been discontinued and is no longer available.
The personal data collected through that app has been deleted. We do not retain accounts, profiles, or personal information from former consumer app users, and there is nothing for a former user to request deletion of. If you have a question about it, contact info@getostrich.com.
13. International users
We operate in the United States and information we collect is processed there. We do not target our services outside the United States. If you access this website from elsewhere, you understand your information will be processed in the US, where privacy laws may differ from your own.
14. Changes to this policy
We may update this policy. When we do, we will change the "last updated" date above and post the revised version here. For material changes affecting client member data, we will notify affected clients directly.
15. Contact us
Questions, requests, or concerns about this policy or your information:
Ostrich App Inc.
130 Inverness Plaza, No. 305
Birmingham, Alabama 35242
info@getostrich.com