Privacy Policy.
How One Stop Assist LLC collects, uses, protects and retains your information, and the rights available to you.
Last updated: 22 July 2026
1. Introduction and scope
One Stop Assist LLC (“OSA”, “we”, “us” or “our”), a Colorado limited liability company with its registered address at 1942 Broadway Street, STE 314C, Boulder, Colorado 80302, United States, is committed to protecting the privacy of every individual who visits this website, purchases a digital product, or engages our professional services. This Privacy Policy explains what information we collect, the lawful bases upon which we process it, how we store and safeguard it, with whom we share it, how long we retain it, and the rights you may exercise in relation to it. This Policy applies to all processing carried out by OSA in connection with onestopassist.com and any associated service delivery, and should be read together with our Terms and Conditions.
2. Information we collect
2.1 Information you provide directly
We collect information you voluntarily submit, including your name, email address, telephone number where supplied, business or organisation name, the content of enquiry or project brief messages, billing address, and any files, documents, credentials or materials you transmit to us for the purpose of service delivery. Where you purchase a digital product, we collect the information necessary to establish and administer your access.
2.2 Payment information
We do not collect, process or store complete payment card numbers, card verification values or full banking credentials on our own infrastructure. All payment transactions are handled by Stripe, Inc., a PCI DSS Level 1 certified payment processor. We receive only limited transaction metadata such as confirmation of payment status, the final four digits of the instrument, and the associated billing name and email. Your use of the payment facility is additionally governed by Stripe’s own privacy notice.
2.3 Information collected automatically
When you browse this website, limited technical information may be collected automatically, including IP address, browser type and version, operating system, referring page, pages viewed, and the date and time of access. This website is built as static content and does not deploy advertising trackers or third party behavioural profiling cookies. Where analytics are employed, they are configured to aggregate and minimise personal identifiers.
2.4 Third party fonts
This website loads typefaces from Google Fonts. In serving these files, Google may receive your IP address as a technical necessity of the request. We do not control and are not responsible for Google’s independent processing, which is governed by Google’s own privacy policy.
3. Lawful bases and purposes of processing
We process personal information where one or more of the following applies: performance of a contract to which you are party, including delivering purchased products, executing agreed services, and providing support; our legitimate interests in operating, securing, maintaining and improving our business, provided such interests are not overridden by your rights and freedoms; compliance with a legal obligation, including taxation, accounting and anti fraud requirements; and your consent, where you have opted in to marketing communications, which you may withdraw at any time.
Specific purposes include responding to enquiries, preparing proposals, delivering and supporting engagements, administering member area access, issuing invoices and processing payments, maintaining financial records, preventing fraud and abuse, and, where you have consented, sending occasional updates about our work and offerings.
4. Data security
We take the security of the information entrusted to us seriously and apply technical and organisational safeguards that are appropriate to the nature of the data and the risk presented. Data in transit between your browser and our infrastructure is protected by industry standard Transport Layer Security encryption. Payment data is handled exclusively by a PCI DSS Level 1 certified processor. Access to client materials within our organisation is restricted on a need to know basis, protected by strong authentication, and reviewed periodically. Personnel and contractors with access to client information are bound by confidentiality obligations.
Notwithstanding the foregoing, you acknowledge and accept that no method of electronic transmission or storage is completely secure, and that no organisation can guarantee absolute security. While we take reasonable and proportionate measures to protect your information, we cannot and do not warrant the absolute security of any information you transmit to us, and any such transmission is undertaken at your own risk. To the fullest extent permitted by applicable law, OSA accepts no liability for loss, corruption, interception, unauthorised access to or disclosure of information arising from any security incident, breach, cyber attack, third party platform compromise or unauthorised act of any party outside our direct control, save where such liability cannot lawfully be excluded. Where a breach affecting personal data occurs and applicable law requires notification, we will notify affected individuals and any competent supervisory authority within the timeframes prescribed by that law.
5. Disclosure to third parties
We do not sell, rent, trade or otherwise monetise personal information. We disclose information only in the following circumstances: to service providers and sub processors who perform functions on our behalf, including payment processing, email delivery, cloud hosting, file storage and course platform provision, each engaged under terms requiring appropriate confidentiality and security; to professional advisers such as accountants and legal counsel where reasonably necessary; to a successor entity in the event of merger, acquisition or asset sale, subject to this Policy continuing to apply; and where required by law, court order, regulatory authority, or where necessary to establish, exercise or defend legal claims, or to protect the rights, property or safety of OSA, our clients or the public.
6. International transfers
OSA operates from the United States and engages contractors and service providers located in various jurisdictions. Consequently, your information may be transferred to, stored in and processed in countries whose data protection laws differ from those of your country of residence. Where such transfers occur from jurisdictions requiring additional safeguards, we rely upon appropriate transfer mechanisms, including standard contractual clauses, and take reasonable steps to ensure your information continues to receive an adequate level of protection.
7. Retention
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, tax or reporting obligations. Enquiry correspondence not resulting in an engagement is ordinarily retained for up to twenty four (24) months. Client project records and financial documentation are ordinarily retained for a period of seven (7) years in accordance with United States record keeping expectations. Member area account records are retained for the duration of the lifetime access granted. Where retention is no longer necessary, information is securely deleted or irreversibly anonymised.
8. Your rights
Subject to applicable law and to verification of your identity, you may request access to the personal information we hold about you; request rectification of inaccurate or incomplete information; request erasure where there is no overriding lawful basis for continued retention; request restriction of processing in defined circumstances; object to processing carried out on the basis of legitimate interests; request portability of information you provided to us in a structured, commonly used, machine readable format; and withdraw consent at any time where processing is founded upon consent, without affecting the lawfulness of processing carried out prior to withdrawal.
Residents of California may additionally have rights under the California Consumer Privacy Act, including the right to know the categories of information collected and the right to request deletion. OSA does not sell personal information as that term is defined under that statute. Residents of the European Economic Area and the United Kingdom may have rights under the General Data Protection Regulation and may lodge a complaint with their local supervisory authority. To exercise any right, contact us using the details in section 11. We will respond within the period prescribed by applicable law.
9. Children
Our website, products and services are directed to adults and are not intended for individuals under the age of eighteen (18). We do not knowingly collect personal information from children. Where we become aware that information relating to a child has been collected, we will delete it promptly.
10. Changes to this Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements or business operations. The revised version will be published on this page with an updated effective date. Material changes affecting your rights will, where reasonably practicable and where we hold your contact details, be communicated to you directly. Continued use of the website following publication constitutes acceptance of the revised Policy.
11. Contact
For any question, request or complaint relating to this Privacy Policy or to the handling of your personal information, contact One Stop Assist LLC, 1942 Broadway Street, STE 314C, Boulder, Colorado 80302, United States, or email [email protected]. We aim to acknowledge all privacy enquiries within five (5) business days.