Privacy Policy
Oforro LLC ("Oforro," "we," "us," or "our") respects your privacy. This Privacy Policy explains what information we collect through the Oforro mobile application and website (the "Platform"), how we use and share it, and the choices and rights you have. This Policy applies to Consumers and Providers alike unless otherwise noted, and is incorporated by reference into our Terms and Conditions and Provider Agreement.
1. Information We Collect
1.1 Information You Provide Directly
- Account information: name, email address, phone number, password, profile photo, and (for Providers) business name, license/certification details, and government-issued ID submitted for verification.
- Booking information: service requests, Offers, messages exchanged with other users, appointment details, and photos related to a Service, which may include information about allergies, sensitivities, or treatment history you choose to disclose in connection with a booking.
- Payment information: billing details processed by our payment processor, PayPal/Braintree. Oforro does not directly store your full card number; Braintree handles and secures that data under its own PCI-compliant systems.
- Reviews and ratings you submit about a completed Service.
- Communications you send us, such as support requests.
1.2 Information Collected Automatically
- Location data: with your permission, we collect precise or approximate location to match Consumers with nearby Providers and to enable service delivery. You can disable location access in your device settings, though this may limit core functionality.
- Device and usage data: IP address, device identifiers, operating system, app version, crash logs, and how you interact with the Platform.
- Cookies and similar technologies: used on our website and, where applicable, in-app, to remember preferences, keep you logged in, and understand usage patterns.
1.3 Biometric Information
As part of Provider identity verification, we may collect a selfie or short video and use automated facial-matching technology to confirm it corresponds to your government-issued ID ("Biometric Information"). We collect Biometric Information only from Providers as part of onboarding and periodic re-verification, and only with your consent. Biometric Information is used solely for identity verification and fraud prevention, is encrypted in storage, is shared only with our identity-verification vendor for that purpose, and is retained only for as long as necessary to verify your identity and comply with our recordkeeping obligations, after which it is deleted in accordance with our retention schedule. We do not use Biometric Information for any other purpose, including general facial recognition or advertising.
1.4 Information From Third Parties
- Background check and license verification results from our verification vendor (for Providers), as described further in Section 3.6.
- Payment and transaction status information from Braintree.
- Information from analytics and crash-reporting providers.
2. How We Use Your Information
- To operate the Platform, including matching Consumers with Providers and processing bookings;
- To process payments and disbursements through Braintree;
- To verify Provider identity, licensing, and (where required) insurance;
- To calculate Oforro Scores and display reviews;
- To send transactional communications (booking confirmations, receipts, safety notices) and, with your consent, marketing communications;
- To detect, investigate, and prevent fraud, abuse, and violations of our Terms;
- To provide customer support;
- To improve, personalize, and develop new features for the Platform, including through the automated and AI-assisted systems described in Section 3.7;
- To comply with legal obligations, including tax and recordkeeping requirements.
3. How We Share Your Information
3.1 Between Consumers and Providers
To facilitate a booking, we share limited information between the Consumer and Provider involved in a transaction — for example, first name, profile photo, general location, messages, and booking details. Providers involved in high-risk service categories may also have their license/insurance verification status (but not underlying documents) shown to Consumers.
3.2 Service Providers and Vendors
We share information with vendors who perform services on our behalf, including payment processing (Braintree), cloud hosting, identity/background-check verification, analytics, customer support tooling, and SMS/push notification delivery. These vendors are contractually restricted from using your information for any purpose other than providing services to Oforro.
3.3 Legal and Safety
We may disclose information if required by law, subpoena, or legal process, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Oforro, our users, or the public.
3.4 Business Transfers
If Oforro is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction, subject to standard confidentiality protections.
3.5 What We Do Not Do
We do not sell your personal information to third parties for their own marketing purposes, and we do not share your full payment card details with Providers.
3.6 Background Checks and the Fair Credit Reporting Act
If you apply to become a Provider, Oforro may obtain a background check report about you from a third-party consumer reporting agency ("CRA") for the purpose of evaluating your eligibility to join the Platform. Before doing so, we will provide you a separate disclosure and obtain your written authorization as required by the federal Fair Credit Reporting Act ("FCRA") and applicable state law. If information in a background check report may result in an adverse action (such as denial or removal from the Platform), we will provide you with a copy of the report and a summary of your rights under the FCRA before the adverse action is finalized, and an opportunity to dispute inaccurate information directly with the CRA.
3.7 AI and Automated Systems
Oforro uses automated systems, including artificial intelligence and machine learning, to match Consumers and Providers, detect fraud and policy violations, generate price or offer recommendations, analyze uploaded photos for moderation and categorization, and improve search and ranking. These systems process the categories of information described in Section 1. Output from these systems is used to operate and improve the Platform and does not make final legal or similarly significant decisions about you without the ability for you to seek human review through support@oforro.com.
4. Cookies and Tracking Technologies
We use cookies and similar technologies on our website to keep you signed in, remember preferences, and understand aggregate usage. You can control cookies through your browser settings; disabling them may affect site functionality. Our mobile app may use comparable device-level identifiers and SDKs from analytics and crash-reporting vendors.
5. Data Retention
We retain personal information for as long as your account is active and as needed to provide the Service, comply with legal and tax obligations (including Florida sales tax and recordkeeping requirements), resolve disputes, and enforce our agreements. Biometric Information is subject to the shorter retention period described in Section 1.3. When information is no longer needed, we delete or anonymize it, except where retention is required by law.
6. Data Security
We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit, access controls, and reliance on PCI-compliant payment processing through Braintree. No system is completely secure, and we cannot guarantee absolute security of your information.
7. Data Breach Notification
If we discover a breach of security that compromises your unencrypted personal information, we will notify affected individuals and, where required, applicable regulators in accordance with the Florida Information Protection Act and other applicable law, generally without unreasonable delay and, absent a legal exception, within the timeframe required by applicable statute.
8. Your Rights and Choices
- Access and correction: you can review and update most account information directly in the app.
- Deletion: you may request deletion of your account and associated personal information by contacting us, subject to legal retention requirements (e.g., financial records).
- Marketing opt-out: you can opt out of promotional emails and push notifications in your account settings or via the unsubscribe link in emails. You cannot opt out of transactional messages necessary to the Service.
- Location permissions: you can disable location sharing in your device settings at any time.
- Biometric opt-out: Providers who do not wish to complete facial-matching verification may contact us to discuss alternative verification methods, where available; note that verification is a condition of Provider approval under the Provider Agreement.
- Do Not Track: our systems do not currently respond to browser "Do Not Track" signals.
8.1 Florida Residents
The Florida Digital Bill of Rights (FDBR) grants certain rights — including access, correction, deletion, and opt-out of targeted advertising or sale — to consumers of businesses that meet specific size and revenue thresholds. If and when Oforro meets those thresholds, we will honor applicable FDBR rights; in the meantime, we extend the access, correction, and deletion choices described above to all users as a matter of practice.
8.2 Other State Residents
If you are a resident of a state with a comprehensive privacy law, you may have similar rights to access, correct, delete, or limit the use of your personal information. You may exercise these rights by contacting us at the address below; we will respond in accordance with applicable law.
9. Children's Privacy
The Platform is not directed to, and may not be used by, anyone under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from someone under 18, we will delete it promptly. If you believe a minor has provided us information, contact us at support@oforro.com.
10. International Users
The Platform is intended for use within the United States, currently launching in Miami, Florida. If you access the Platform from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your home country.
11. Third-Party Links and Services
The Platform may contain links to third-party websites or services, including our payment processor Braintree. This Policy does not apply to those third parties, and we encourage you to review their privacy policies separately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Platform or by email before the changes take effect. The "Last Updated" date at the top of this Policy reflects the most recent revision.
13. Contact Us
If you have questions, requests, or complaints about this Privacy Policy or our data practices, contact us at:
Oforro LLC 2700 N. Miami Avenue, Unit 701, Miami, FL 33127 Email: support@oforro.com
This document is a draft template prepared for informational purposes and does not constitute legal advice. Please have it reviewed by a licensed Florida attorney before publishing or relying on it.
Appendix: Open Questions for Legal Counsel
The following questions are provided to help counsel finalize this Policy for launch:
- Does the Biometric Information section (1.3) satisfy notice-and-consent requirements in every state Oforro may operate in, including states with dedicated biometric privacy statutes?
- Is the FCRA disclosure/authorization process described in Section 3.6 sufficient, or does Oforro need a separate standalone FCRA disclosure form outside this Policy?
- Does the Data Breach Notification section (Section 7) correctly state Florida's notification timeline and any additional state-specific requirements Oforro should anticipate?
- Should Oforro adopt a formal biometric data retention/destruction schedule as a standalone internal policy, separate from this public-facing Policy?
- Once Oforro's size/revenue could trigger FDBR thresholds, what additional mechanisms (e.g., a "Do Not Sell/Share" link) should be added?
- Should this Policy include a formal Data Processing Addendum or subprocessor list for transparency?
- Is the AI/automated-systems disclosure in Section 3.7 sufficient given Florida and emerging state AI-transparency requirements?
- Should Oforro adopt a separate, standalone Cookie Policy for the website, or is Section 4 sufficient at current scale?
This document is a draft template prepared for informational purposes and does not constitute legal advice. It is pending review by a licensed Florida attorney before final publication.