MomentAssist Privacy Policy

 

**Effective date:** August 1, 2026
**Last updated:** August 20, 2026

 

This Privacy Policy explains how StarlyPath, Inc., doing business as MomentAssist (“MomentAssist,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information through the MomentAssist website, Customer application, Assistant application, administrative and support services, and related features (collectively, the “Platform”).

 

This Policy applies to Customers, Assistant applicants and Assistants, website visitors, people who contact support, and other individuals whose personal information is submitted to the Platform.

 

1. Personal Information We Collect

 

The information we collect depends on how you use the Platform.

 

A. Account and identity information

 

We may collect:

 

- first and last name;
- username and display name;
- email address;
- telephone number and country code;
- password hash and authentication credentials;
- Google, Apple, Firebase, or telephone-authentication identifiers;
- profile photograph;
- address, gender, language, time zone, account role, status, and preferences; and
- acceptance of terms and privacy notices, including the accepted document
version, date and time, IP address, and device or browser user-agent string;
and
- for Assistant applicants, a work-authorization attestation, the applicable
Terms version, and the date and time of the attestation.

 

B. Assistant application and professional information

 

For Assistant applicants and Assistants, we may collect:

 

- government-issued identification;
- service levels selected and approved;
- media-capture device types and details;
- images of media-capture devices;
- media-capture and media-editing skill levels;
- video demonstrating media-editing skills;
- document expiration dates and review decisions;
- application status, document status, and eligibility information; and
- payout onboarding and verification status.

 

The current Assistant application does not request a Social Security number or
Social Security Number Card during registration or profile completion. If an
Assistant later chooses to enable withdrawals, Stripe Connect's hosted
onboarding may collect the Assistant's legal name, date of birth, address,
telephone number, government-issued identification, Social Security number,
Employer Identification Number or other taxpayer identifier, tax
classification, and bank-account information. That information is provided
directly to Stripe at the payout stage rather than through MomentAssist
registration.

 

Through the normal Stripe Connect integration, MomentAssist receives connected-
account identifiers, capability and requirements statuses, onboarding, bank,
and U.S. tax-information completion statuses, limited bank descriptors, and
transfer and payout records. MomentAssist does not receive or store the full
Social Security number, Employer Identification Number, complete bank-account
number, or tax form that an Assistant submits directly to Stripe through that
hosted flow. Legacy encrypted Social Security numbers or SSN-card documents
submitted under an earlier MomentAssist workflow are not current onboarding
requirements and remain restricted while their lawful retention or deletion is
reviewed. Assistant documents are stored as private cloud objects and made
available through short-lived authorized links. No method of storage is
completely secure.

 

C. Location and Assist information

 

We may collect:

 

- precise or approximate device location;
- latitude, longitude, and time of the latest location update;
- meeting location, final location, route, distance, and duration;
- scheduled date and time and estimated duration;
- online, availability, dispatch, arrival, and Assist status;
- selected service, quoted and final fare, payment method, tips, discounts, waiting time, and cancellation information;
- one-time Assist verification code;
- information for an Assist booked for someone else; and
- Assist history and status events.

 

The Assistant app may collect location in the background while the Assistant is online or completing an Assist. The Customer app uses location when needed to select locations, request an Assist, display maps, and track the assigned Assistant.

 

D. Media and content

 

We may collect:

 

- photos, videos, filenames, file types, sizes, metadata, upload timestamps, and storage keys;
- compressed previews, thumbnails, and ZIP download packages;
- media quality, malware, and content-moderation results;
- review, approval, rejection, resubmission, dispute, and retention status;
- profile images;
- chat messages and message-read status;
- ratings, reviews, complaints, complaint comments, and support communications; and
- any information visible or audible in submitted media.

 

Do not upload content unless you have the right and required consent to do so.

 

E. Payment, Wallet, and payout information

 

We may collect:

 

- Wallet balance, reserved funds, deposits, debits, earnings, withdrawals, and transaction history;
- payment amount, status, method, provider, transaction identifier, and settlement details;
- payment-card brand, last four digits, expiration month and year, and billing ZIP code;
- Stripe customer, payment-method, payment-intent, charge, and refund
identifiers;
- Stripe Connect account, capability, requirement, external-account,
payout-method, transfer, and payout identifiers;
- Stripe Connect onboarding, bank, U.S. tax-information, migration, transfer,
and payout statuses;
- Assistant bank name, account type, account last four digits, fees, and
withdrawal decisions;
- historical Stripe Global Payouts recipient, financial-account, payout-method,
and transaction identifiers retained for migration and reconciliation; and
- invoices, commissions, refunds, charge adjustments, and accounting records.

 

MomentAssist does not store complete payment-card numbers or CVV codes. Stripe
and supported device-wallet providers process those credentials. Stripe
Connect's hosted onboarding collects identity, bank, and U.S. tax information
directly from Assistants. MomentAssist stores only the provider identifiers,
limited descriptors, requirements, and statuses described above through its
normal integration, not the full bank credentials, Social Security number,
Employer Identification Number, or tax form submitted to Stripe.

 

F. Communications, calls, notifications, and safety

 

We may collect:

 

- in-app chat content and timestamps;
- protected-calling session and participant identifiers;
- temporary proxy numbers;
- call direction, status, start, answer and completion times, duration, and failure information;
- push-notification subscription identifiers, device tokens, delivery status, notification content, and read status;
- email delivery status;
- emergency contacts;
- SOS sender, Assist reference, time, contact information, region, status, and available coordinates; and
- complaint and dispute evidence.

 

MomentAssist does not record the audio of protected calls. Telephone carriers or voicemail services may process calls under their own practices.

 

G. Device, diagnostics, and usage information

 

We may collect:

 

- IP address;
- device type, operating system, app version, language, and time zone;
- network and permission status;
- authentication and session data;
- crash reports, diagnostics, error logs, and performance information;
- security and fraud indicators; and
- website request logs and cookies necessary for session, security, and preference functions.

 

The current Platform design does not include third-party behavioral-advertising SDKs.

 

2. How We Collect Information

 

We collect information:

 

- directly from you when you register, complete a profile, apply as an Assistant, book or perform an Assist, upload content, pay, withdraw, review, complain, or contact us;
- automatically from your device and use of the Platform;
- from another user when an Assist, message, complaint, emergency contact, or booking-for-someone-else involves you;
- from authentication, payment, Stripe Connect payout, mapping, storage,
communications, notification, fraud, moderation, and hosting providers; and
- from administrators who review applications, media, complaints, payments, and safety matters.

 

3. Why We Use Personal Information

 

We use personal information to:

 

- create, authenticate, maintain, and secure accounts;
- verify unique email addresses and telephone numbers;
- review Assistant identity, documents, skills, and service eligibility;
- display profiles, first names, ratings, service qualifications, and relevant device or skill information;
- calculate quotes, find and dispatch nearby Assistants, schedule Assists, and provide live status;
- enable chat, push notifications, email, and protected calling;
- process Wallet transactions, card or device payments, commissions, refunds,
earnings, Stripe Connect onboarding, transfers, and payouts;
- receive, store, scan, moderate, review, deliver, package, and delete media;
- administer Advanced and Premium media milestones, resubmissions, disputes, retention, and settlements;
- operate SOS, emergency-contact, complaint, and support functions;
- prevent duplicate accounts, fraud, abuse, unsafe behavior, security incidents, and unlawful activity;
- troubleshoot, analyze crashes, maintain service reliability, and improve the Platform;
- enforce our Terms and protect users, MomentAssist, and others;
- support identity, bank, and tax-information verification for Assistant
payouts and comply with law, tax reporting, accounting, sanctions, legal
process, and regulatory obligations; and
- send administrative and transactional communications.

 

Where legally required, we ask for permission before collecting precise location, photos, videos, camera access, notifications, or other device-protected data.

 

4. How We Disclose Personal Information

 

We may disclose personal information as follows.

 

A. Between Customers and Assistants

 

After assignment, we disclose information reasonably needed to complete the Assist, such as:

 

- first name, profile image, rating, and service-related qualifications;
- meeting and final locations;
- scheduled time, estimated duration, Assist status, and instructions;
- live location or arrival status where enabled;
- chat messages; and
- a temporary protected-calling number.

 

We do not display email addresses during an Assist. Protected calling is designed not to disclose the other party’s registered telephone number, and MomentAssist does not use the real number as a fallback when protected calling is unavailable.

 

B. Administrators and authorized personnel

 

Authorized MomentAssist personnel may access information to review Assistant applications, documents, media, payments, withdrawals, complaints, disputes, SOS alerts, fraud, and support requests.

 

Access should be limited to personnel who need the information for their role.

 

C. Service providers

 

Based on the current Platform architecture, providers may include:

 

- **Amazon Web Services:** private storage, signed file access, malware protection, content analysis, previews, and media processing;
- **Google and Firebase:** authentication, Firestore chat and synchronization, maps, location-related functions, messaging infrastructure, and crash reporting;
- **Apple:** Apple authentication, Apple Pay, app distribution, and device services;
- **Stripe:** cards, Apple Pay or Google Pay payment processing, Customer Wallet
funding, payment status, Stripe Connect account creation and hosted
onboarding, identity and bank verification, U.S. tax-information and tax-form
services, transfers, payouts, returns, and reconciliation;
- **OneSignal:** push-notification subscription and delivery;
- **Twilio:** temporary proxy numbers and protected voice-call routing;
- **email and hosting providers:** transactional email, infrastructure, databases, backups, logs, and security; and
- **professional advisers and vendors:** legal, accounting, auditing, security, fraud, and customer-support services.

 

These providers process information under their own terms and privacy notices as applicable.

 

D. Legal, safety, and business disclosures

 

We may disclose information:

 

- to comply with law, subpoena, court order, or valid legal process;
- to protect life, safety, rights, property, users, or the public;
- to investigate fraud, abuse, prohibited content, or security incidents;
- to enforce agreements and resolve disputes;
- to tax, banking, sanctions, or regulatory authorities where required; or
- in connection with financing, due diligence, merger, acquisition, reorganization, bankruptcy, or sale of all or part of the business, subject to appropriate safeguards.

 

5. Sale, Sharing, and Advertising

 

MomentAssist does not sell personal information for money.

 

Under the current product design, MomentAssist does not share personal information for cross-context behavioral advertising and does not use third-party advertising SDKs. We use service providers for Platform operations, not to build advertising profiles for unrelated businesses.

 

If these practices change, we will update this Policy, provide any legally required notice and choice, and honor applicable opt-out signals such as Global Privacy Control.

 

Browser “Do Not Track” signals do not have a uniform industry standard. Because the current website does not use cross-context behavioral advertising, a Do Not Track signal does not change current Platform behavior.

 

6. Sensitive Personal Information

 

MomentAssist may process sensitive personal information, including identity
documents, limited financial and payout information, account credentials,
precise geolocation, private communications, the contents of private photos and
videos, and legacy Social Security records retained from an earlier workflow.
Stripe separately processes complete bank credentials, tax identifiers, and tax
forms that an Assistant submits during Stripe Connect's hosted payout
onboarding.

 

We use sensitive personal information only as reasonably necessary to provide requested services, authenticate and secure accounts, verify Assistant eligibility, process payments and payouts, support safety and disputes, and comply with law.

 

We do not use sensitive personal information to infer unrelated characteristics about users.

 

We use automated tools to detect malware, technical quality issues, and potentially prohibited content in uploaded media. The current Platform does not use facial recognition to identify people and does not create biometric identity profiles.

 

7. Data Retention

 

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including service delivery, safety, disputes, fraud prevention, accounting, tax, legal compliance, and enforcement.

 

Current product-specific retention rules include:

 

| Information | Current retention approach |
|---|---|
| Advanced/Premium original media and previews | Generally 30 days after approval; generally 60 days where a dispute exists; longer if subject to legal hold |
| Protected-call metadata | Generally 14 days in MomentAssist systems |
| System backups | Generally 30 days under the current backup configuration |
| Profile image | Until replaced or the account is deleted |
| Current Assistant identity and service-eligibility documents | While needed for application, service eligibility, re-verification, fraud prevention, safety, or legal compliance; reviewed regularly and deleted through the account-deletion process when no longer necessary, unless retention is legally required |
| Legacy encrypted SSNs and SSN-card documents | No longer collected or required in current onboarding; retained only while a documented legal, tax, fraud-prevention, security, or legal-hold purpose applies, and otherwise scheduled for deletion after an approved retention review |
| Account identifiers | While the account is active; direct identifiers are anonymized through the account-deletion process |
| Assist, invoice, payment, Wallet, Stripe Connect or legacy Global Payouts, transfer, payout, and settlement records | Generally seven years after the relevant transaction or Assist, or longer where required for an active dispute, tax matter, legal hold, fraud investigation, or applicable law |
| Complaints, disputes, SOS, and material safety records | Generally seven years after closure of the matter, or longer for an active investigation, legal hold, or applicable law |
| In-app chat associated with an Assist | Generally two years after the Assist closes; longer where the chat is relevant to an unresolved complaint, dispute, safety matter, or legal hold |
| In-app notifications | Generally one year after creation |
| Customer-support communications | Generally three years after the support matter closes; longer where connected to an unresolved transaction, complaint, safety matter, or legal hold |
| Ordinary application and web-server logs | Generally 90 days; security, fraud, and abuse logs may be retained for up to one year or longer for an active investigation |
| Precise live-location updates | Generally 30 days after the Assist closes; meeting and final locations retained as part of Assist history may follow the seven-year Assist-record period |
| Provider-held data | According to the provider’s retention settings, contract, and legal obligations |

 

Deletion from active systems may not immediately remove information from encrypted backups, provider systems, legal holds, fraud-prevention records, or records we must retain by law.

 

We periodically review retained information and may shorten a period when the information is no longer reasonably necessary. We may retain information longer when required by law, reasonably necessary to establish or defend legal claims, needed to complete a transaction requested by the user, or subject to a documented legal or safety hold.

 

8. Security

 

We use administrative, technical, and physical safeguards designed for the
sensitivity of the information we process. Current controls include
authentication, authorization, encrypted transport, private cloud storage,
short-lived signed file links, server-side encryption for protected files,
restricted API serialization, encryption of retained legacy Social Security
numbers, payment tokenization, webhook signature validation, and deletion
workflows.

 

No system can guarantee absolute security. You are responsible for protecting your password, device, email account, telephone account, and authentication credentials.

 

If you believe your account or information has been compromised, contact us promptly at `support@momentassist.com`.

 

9. Your Choices and Controls

 

Depending on the feature and device, you may:

 

- update profile and service information;
- change your password;
- control location, camera, photo-library, background-location, and notification permissions in device settings;
- go offline as an Assistant;
- choose whether to begin Stripe Connect payout onboarding and use Stripe's
hosted experience or Express Dashboard to review or update eligible identity,
bank, tax, and payout information;
- mark notifications as read;
- delete or replace eligible profile and document files;
- download eligible Advanced or Premium media before the retention deadline;
- submit a complaint or dispute; and
- request account deletion in the app.

 

Disabling location may prevent booking, dispatch, live tracking, or Assistant online functionality. Disabling notifications may cause you to miss dispatch offers, status updates, document decisions, safety messages, payment reminders, and media deadlines.

 

An Assistant may create and use a MomentAssist account without completing Stripe
Connect payout onboarding. However, the Assistant cannot withdraw earnings until
the required Stripe account, bank-account, and U.S. tax-information steps are
complete and all other withdrawal conditions are satisfied.

 

Before deleting an account, the Platform requires active and scheduled Assists, unpaid amounts, Wallet balances, and pending withdrawals to be resolved.

 

10. U.S. State Privacy Rights

 

Depending on your state and whether the applicable law covers MomentAssist, you may have rights to:

 

- know or access the categories and specific pieces of personal information we hold;
- obtain a portable copy;
- correct inaccurate information;
- delete information, subject to legal exceptions;
- opt out of sale, sharing, or targeted advertising;
- limit certain uses of sensitive personal information;
- withdraw consent where processing depends on consent; and
- receive equal service and not be discriminated against for exercising privacy rights.

 

California residents may have rights under the California Consumer Privacy Act, as amended, including rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and non-discrimination.

 

To submit a request:

 

- use the account-deletion or profile controls in the app; or
- email `support@momentassist.com` with the subject “Privacy Request.”

 

Include your name, account email or verified telephone number, role (Customer or Assistant), state of residence, and the right you wish to exercise. Do not send a password, full Social Security number, complete payment-card number, or full bank-account number by email.

 

We will verify requests using information associated with the account. An authorized agent may submit a request where permitted by law, but we may require proof of authority and identity verification. We may deny or limit a request where an exception applies and will explain the decision where required.

 

We currently do not sell or share personal information for cross-context behavioral advertising, so there is no current sale or sharing to opt out of.

 

11. Authentication and Linked Accounts

 

If you use Google, Apple, or telephone authentication, the provider sends MomentAssist identifiers and account information needed to authenticate or create your account. Your use of that provider is also governed by its privacy terms.

 

MomentAssist links a recognized provider identity to an existing account where permitted, instead of intentionally creating duplicate accounts for the same normalized email address or verified telephone number.

 

12. Payments and Financial Information

 

Stripe processes payment credentials and Stripe Connect payout onboarding.
Apple Pay and Google Pay may transmit tokenized payment information through
Apple, Google, and Stripe.

 

Stripe Connect hosts the Assistant identity, bank, and U.S. tax-information
flow. MomentAssist stores provider identifiers, requirements and completion
statuses, and limited card or bank descriptors needed to display readiness,
initiate approved transfers and payouts, and reconcile transactions. Through
the normal integration, MomentAssist does not receive or store complete card
numbers, CVV codes, full bank-account numbers, the full Social Security number
or Employer Identification Number submitted to Stripe, or Stripe-hosted tax
forms.

 

Do not send full card or bank credentials through chat, email, complaints, reviews, or support messages.

 

13. Photos, Videos, and Information About Other People

 

Photos, videos, chats, emergency contacts, complaints, and bookings for someone else may contain personal information about people who do not have a MomentAssist account.

 

The person submitting that information is responsible for providing any required notice and obtaining any required consent. MomentAssist uses the information to provide, secure, review, support, and enforce the relevant service.

 

People appearing in media or otherwise affected may contact `support@momentassist.com`. We will evaluate requests in light of the submitter’s rights, contractual obligations, legal holds, free-expression interests, safety, and applicable law.

 

14. Children

 

The Platform is intended for adults and is not directed to children under 13. Users must be at least 18 years old to create an account or book or provide an Assist.

 

Children may appear in Customer-requested media only when a parent or legal guardian has authorized the capture and applicable venue and legal requirements are satisfied.

 

If you believe a child’s personal information was submitted without proper authorization, contact `support@momentassist.com`.

 

15. Communications

 

We send transactional email, push notifications, and in-app notices about account activity, authentication, document review, Assist requests and status, schedules, payments, media deadlines and decisions, complaints, withdrawals, safety, and support.

 

You may disable push notifications in device settings, but certain service communications may still be sent by email or displayed in the Platform. We may send legally required or essential account and security notices even if you opt out of optional communications.

 

The current Platform does not treat transactional communications as marketing subscriptions.

 

16. International Processing

 

MomentAssist is currently intended for launch in the United States. Our providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws.

 

Do not use the Platform outside supported locations unless MomentAssist has expressly made it available there.

 

17. Third-Party Links and Services

 

The Platform may link to third-party websites, app stores, maps, telephone functions, payment flows, or provider-hosted onboarding. This Policy does not govern a third party’s independent privacy practices.

 

Review the privacy notice of each third-party service you use.

 

18. Changes to This Policy

 

We may update this Policy to reflect product, provider, legal, or operational changes. We will post the revised Policy with a new “Last updated” date and provide additional notice or obtain consent when required.

 

We will not apply a material change retroactively where law requires affirmative consent.

 

19. Contact Us

 

StarlyPath, Inc. d/b/a MomentAssist
1775 Ohio Ave Unit 218
Long Beach, CA 90804-1559
United States
Privacy email: `support@momentassist.com`
Website: `https://momentassist.com`