Skip to content

Legal / Version 2 / Effective 2026-07-01

Privacy Notice

This Privacy Notice explains what personal information Five Star Solutions handles, why we handle it, how we share it, how long we keep it, and how to exercise privacy rights. It applies to our website, app, customer accounts, support, marketing, and operator platform.

Who we are

Five Star Solutions builds and operates AI operators for business customers. For customer data processed inside an operator workflow, the customer is usually the controller and we act as processor. For account, website, support, security, billing, and marketing data we collect directly, we act as controller.

What we handle

We may handle account details such as name, work email, phone number, company, role, sign-in events, and organization membership. We handle customer tool data when a customer connects a system and configures an operator to read or write it. We also handle operator conversations, workflow inputs, run results, generated artifacts, approvals, usage/cost records, support messages, and security/audit metadata.

What we never keep

We do not use product passwords, so there is no product password to store or reset. We do not intentionally store customer OAuth tokens for connected SaaS tools in our application database. Connector tokens stay in the connector provider's vault where possible, and our database stores the connection reference and metadata. Secrets we do store for custom tools are encrypted and kept out of logs.

Why we handle your data

We handle personal information to provide the service, authenticate users, isolate tenants, run operators, connect tools, maintain approvals and audit records, secure the platform, troubleshoot issues, bill customers, meet legal obligations, and communicate about the service. We do not sell personal information. We do not use customer data to train third-party foundation models.

Who else touches it

We use subprocessors to host the app, run AI/document processing, store data, run scheduled tasks, deliver sign-in flows, and connect customer tools. The Subprocessors page lists the platform providers and explains which providers are active, planned, customer-directed, or gated for PHI. PHI workloads are not activated until the required customer and subprocessor BAA path is complete.

Retention

We keep different records for different periods. Run steps are generally kept about 90 days, pending approvals about seven days after expiry, agent memory about 180 days by default, usage/cost records about two years, artifacts according to customer contract defaults, and audit records longer for security and regulated-record evidence. Some data may be retained where law, contract, security, accounting, or audit duties require it.

Your rights

Depending on where you live and how your data entered the service, you may ask to access, correct, delete, export, restrict, or object to processing of personal information. For data controlled by one of our customers, we may route the request to that customer and help them respond. The Data Rights page explains how to ask. Email justin@5starsolutions.co to start.