Draft — for counsel review only
This document is an engineering draft prepared for outside counsel review. It is not a substitute for legal advice and must not be relied upon until counsel and CEO sign-off are recorded under HD-18.
Last updated: 2026-04-08 · Status: DRAFT — counsel review pending
StelaHome ("we," "us," or "our") is operated by Stela Home, Inc., a Delaware corporation. We provide home repair cost intelligence, educational repair guides, and home management tools through our website at stelahome.com and related services (the "Platform"). This Privacy Policy describes how we collect, use, disclose, and protect your information when you use the Platform.
We collect information you provide directly: account registration data (name, email address, password); home property information you enter for estimates and health checks; payment information processed through Stripe (we do not store full card numbers); inspection reports and documents you upload; and feedback or support requests. We also collect information automatically: device and browser information; IP address and approximate location; pages visited, features used, and session duration; cookies and similar technologies (see our Cookie Policy).
We use your information to: provide and improve the Platform, including cost estimates, repair guides, and health checks; process transactions and send related notifications; personalize your experience and content recommendations; communicate with you about your account, updates, and (with your consent) marketing; detect, prevent, and address fraud, abuse, and security issues; comply with legal obligations. We do not sell your personal information to third parties.
We process your data based on: performance of our contract with you (providing Platform services); your consent (marketing communications, optional cookies); our legitimate interests (improving the Platform, preventing fraud, ensuring security); and compliance with legal obligations.
We share information with: payment processors (Stripe) to complete transactions; cloud infrastructure providers (AWS) for hosting and data storage; analytics providers to improve Platform performance; professional advisors (legal, accounting) as needed; law enforcement or government agencies when required by law. All third-party processors are contractually bound to protect your data. We never share your home address, financial details, or personal information with advertisers, lead generation companies, or contractors.
We implement industry-standard security measures including: TLS 1.2+ encryption for all data in transit; AES-256 / KMS field-level encryption for sensitive data at rest; HttpOnly session cookies (no JWTs stored in browser storage); regular security audits and vulnerability assessments; access controls and least-privilege principles for all systems. No system is completely secure. If we become aware of a breach affecting your personal data, we will notify you in accordance with applicable law.
We retain your account data for as long as your account is active. If you delete your account, we remove or anonymize your personal data within 30 days, except where retention is required by law. Session and usage data is retained for 24 months from last login. Payment records are retained as required for tax and accounting purposes.
Depending on your jurisdiction, you may have the right to: access the personal data we hold about you; correct inaccurate or incomplete data; delete your personal data; restrict or object to certain processing; receive your data in a portable format; withdraw consent at any time (where processing is based on consent); lodge a complaint with a supervisory authority. To exercise any of these rights, contact privacy@stelahome.com. We respond to all verified requests within 30 days.
California residents have additional rights under the CCPA, including the right to know what personal information is collected and how it is used, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your California privacy rights, contact privacy@stelahome.com.
Your data is processed in the United States. If you access the Platform from outside the United States, your information will be transferred to and processed in the United States. We rely on Standard Contractual Clauses and other appropriate safeguards for international transfers where required.
The Platform is not directed to children under 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us at privacy@stelahome.com.
Certain Platform features have additional privacy terms. The Stela Fix Privacy Addendum covers data practices specific to repair guides, AI processing, and creator content. These addenda supplement (and do not replace) this Privacy Policy.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Platform and updating the "Last Updated" date. Continued use of the Platform after changes constitutes acceptance of the revised policy.
For questions about this Privacy Policy or to exercise your privacy rights, contact us at: privacy@stelahome.com. Stela Home, Inc., New Haven, CT.