Privacy policy
Last updated 22 August 2026
This explains what Choi Ming Lei collects when you use Ostiara, why, and what you can ask us to do about it. It is written in ordinary language on purpose.
1. Who is responsible
Choi Ming Lei, based in Malaysia, decides how the information described here is handled. Questions and requests go to support@ostiara.com.
2. What we collect
Three kinds of thing, and nothing else.
- Your account. Your name, email address, password (held by our sign-in provider, not by us), your company or business name, and your role within it.
- What you put here. The website files you upload and the files you store, plus records of what was published when, and by whom. If a website you publish collects information from your own customers, that information is yours. We store it for you and do not use it.
- Records of use. How many people opened your websites and how much data was served, so we can show you visitor numbers and what your sites cost to run. This comes from server logs. We do not place advertising or tracking cookies on your visitors, and we do not build profiles of them.
3. Why we hold it
To run the service you asked for. That means publishing your websites, storing your files, showing you who changed what, and telling you what your account costs. We also use your email address to send you things about your own account, such as a password reset or a warning that something failed. We do not sell it, rent it, or use it for anyone else's advertising.
4. Who else touches it
Amazon Web Services, which provides the storage, databases and computers this service runs on, and which sends our account emails. AWS processes it on our instructions and does not use it for its own purposes. We do not share your data with anyone else. If that ever changes, for example when payments are switched on and a payment processor is involved, this page will say so before it happens.
5. Where it is stored
In Amazon Web Services' Singapore region. We do not copy it to other regions. Storage and database contents are encrypted at rest.
6. How long we keep it
- Account details and published websites. For as long as your account exists.
- Earlier copies of a file. 90 days after they are replaced, so an accidental overwrite can be undone.
- An uploaded website file that has not been published. 7 days.
- A link you shared outside your company. Until it expires, at most 7 days. We keep only a fingerprint of it, never the link.
- Records of who changed what. For as long as your account exists, because their purpose is to be able to answer that question later.
If you ask us to close your account, we delete your websites, your files and your account details. There is no button for this yet, so please email us and we will confirm when it is done.
7. What you can ask for
Under Malaysia's Personal Data Protection Act you may ask to see the personal data we hold about you, ask us to correct it if it is wrong, ask us to stop using it in a particular way, or withdraw a consent you previously gave. Write to support@ostiara.com and we will answer within 21 days.
If your employer's account holds your details because you are a team member, we will point your request at them where the data is theirs to correct, but we will always tell you what we hold.
8. Sign-in and browser storage
When you sign in, your browser keeps a sign-in token so you are not asked for your password on every page. That is the only thing we store in your browser, it is removed when you sign out, and it is not used to track you anywhere else.
9. Changes
If this policy changes we will update the date at the top, and where a change affects what we do with data we already hold, we will email account owners rather than rely on you re-reading the page.
See also the terms of service and the security page.