PRIVACY POLICY

Obsidian Roadside & Recovery LLC

Effective Date: September 3, 2026
Last Updated: September 3, 2026

Obsidian Roadside & Recovery LLC (“Obsidian,” “we,” “us,” or “our”) respects the privacy of our customers, service providers, drivers, technicians, business partners, website visitors, application users, and other individuals who interact with our services.

This Privacy Policy explains how Obsidian collects, uses, processes, discloses, retains, and protects personal information when individuals interact with our websites, mobile applications, web applications, provider and driver systems, customer portals, communications services, dispatch technology, marketplaces, APIs, and related products and services.

We designed this Privacy Policy to address our current technology platform as well as reasonably anticipated functionality across Obsidian’s customer, provider, driver, enterprise, dispatch, and administrative systems.


1. WHO WE ARE

Obsidian Roadside & Recovery LLC operates a technology-enabled automotive service, roadside assistance, dispatch, provider-network, marketplace, and communications platform.

The Obsidian platform may allow customers and organizations to request, coordinate, monitor, manage, or pay for automotive-related services and may allow independent service providers and their personnel to receive and manage service opportunities.

Depending on the service, Obsidian may facilitate connections with independent businesses or professionals including:

  • roadside assistance providers;

  • towing companies;

  • automotive repair facilities;

  • collision repair facilities;

  • mobile mechanics;

  • technicians;

  • drivers;

  • transportation providers; and

  • other automotive service providers.

Unless expressly stated otherwise in a written agreement, third-party service providers operate independently from Obsidian.


2. SCOPE OF THIS PRIVACY POLICY

This Privacy Policy applies to personal information collected through or in connection with:

  • ObsidianRoadside.com;

  • other websites operated by Obsidian;

  • the Obsidian customer mobile application;

  • Obsidian provider applications;

  • Obsidian driver applications;

  • customer portals;

  • provider portals;

  • enterprise and fleet portals;

  • administrative systems;

  • dispatch and service-management systems;

  • public provider directories or marketplaces;

  • mobile and web applications;

  • APIs;

  • telephone communications;

  • SMS and MMS communications;

  • email;

  • in-app messaging;

  • push notifications;

  • online forms;

  • account registration;

  • provider onboarding;

  • customer support;

  • service requests;

  • service fulfillment;

  • claims and incident reporting; and

  • other online or offline interactions with Obsidian.

Some third-party services accessible through the Platform may maintain separate privacy policies governing information they independently collect.


3. CATEGORIES OF INFORMATION WE MAY COLLECT

The information Obsidian collects depends upon how an individual interacts with the Platform.

A. Identification and Contact Information

We may collect:

  • first and last name;

  • telephone number;

  • email address;

  • mailing address;

  • billing address;

  • business address;

  • company or organization name;

  • job title;

  • account username;

  • customer or provider identification numbers;

  • profile information; and

  • other contact information voluntarily provided to us.


B. Account and Authentication Information

When an account is created or accessed, we may collect or process:

  • account identifiers;

  • usernames;

  • passwords in securely protected or hashed form;

  • authentication credentials;

  • authentication tokens;

  • login history;

  • account security information;

  • multifactor authentication information;

  • verification codes;

  • device identifiers associated with account access; and

  • account recovery information.

Obsidian does not intend to store account passwords in readable plaintext form.


C. Vehicle Information

We may collect information about a vehicle involved in a service request, including:

  • year;

  • make;

  • model;

  • trim;

  • color;

  • license plate number;

  • vehicle identification number where reasonably necessary;

  • vehicle type;

  • vehicle condition;

  • mileage;

  • mechanical information;

  • damage information; and

  • other vehicle-related information necessary to provide or coordinate a service.


D. Service and Dispatch Information

When a service is requested, accepted, performed, monitored, or completed, we may collect:

  • requested service type;

  • service location;

  • destination;

  • pickup location;

  • service notes;

  • dispatch records;

  • provider assignments;

  • driver assignments;

  • estimated arrival times;

  • actual arrival times;

  • service timestamps;

  • status changes;

  • service history;

  • completion information;

  • customer instructions;

  • provider notes;

  • incident information;

  • claim information;

  • signatures;

  • photographs;

  • receipts; and

  • other records associated with the service.


4. LOCATION INFORMATION

Location information is an important component of certain Obsidian services.

Depending on the user’s role and device permissions, we may collect approximate or precise location information.

Customer Location

Customer location information may be used to:

  • identify the location of a disabled or stranded vehicle;

  • identify available providers;

  • determine distance;

  • calculate estimated arrival times;

  • coordinate service;

  • provide navigation information;

  • display provider progress; and

  • improve service accuracy.

Where reasonably practicable, customers may also be able to manually enter a location instead of providing device location information.

Provider and Driver Location

For service providers and drivers, location information may be used to:

  • determine provider or driver availability;

  • identify nearby service opportunities;

  • coordinate dispatch;

  • route drivers;

  • calculate distance;

  • calculate estimated arrival times;

  • show job progress;

  • verify arrival;

  • document service activity;

  • support operational safety;

  • prevent fraud;

  • investigate disputes; and

  • improve dispatch operations.

Background Location

Provider or driver applications may request permission to access location while the application is running in the background when background access is reasonably necessary for:

  • active dispatch;

  • navigation;

  • job-status monitoring;

  • estimated arrival calculations;

  • provider availability;

  • active service coordination;

  • fraud prevention; or

  • safety-related functionality.

Where operating-system rules require permission, the application will request the applicable device permission before collecting protected location information.

Users may manage device-level location permissions through their device settings.

Disabling location permissions may reduce or prevent certain Platform functionality.


5. CAMERA, PHOTOS, AND MEDIA

With applicable device permission, Obsidian applications may use a device camera or allow images to be selected from a device.

Images may be used to:

  • document vehicle condition;

  • document pre-service or post-service condition;

  • document damage;

  • verify job completion;

  • document roadside conditions;

  • provide customer support;

  • submit receipts;

  • submit identification or business documents;

  • submit insurance documentation;

  • maintain provider profiles; or

  • support other features initiated by the user.

Obsidian does not intend to access a user’s camera or photo library for purposes unrelated to disclosed Platform functionality.


6. PROVIDER AND DRIVER INFORMATION

Providers, drivers, technicians, and other service professionals may provide additional business and professional information.

Depending on the relationship, this may include:

  • business name;

  • business address;

  • business telephone number;

  • business email;

  • ownership or authorized representative information;

  • service areas;

  • services offered;

  • rates;

  • availability;

  • driver information;

  • vehicle and equipment information;

  • driver’s license information where applicable;

  • permits;

  • professional licenses;

  • insurance information;

  • certificates of insurance;

  • tax documentation such as Form W-9;

  • payment or banking information;

  • qualifications;

  • training information;

  • onboarding documents;

  • service history;

  • acceptance and rejection activity;

  • dispatch performance;

  • response times;

  • customer reviews;

  • ratings;

  • complaints;

  • incidents;

  • claims;

  • compliance status; and

  • other information reasonably required to administer the provider relationship.

Separate contractual terms may also govern provider and driver information.


7. PAYMENT AND TRANSACTION INFORMATION

When payments are made through the Platform, payment information may be processed by a third-party payment processor.

Obsidian may receive information such as:

  • transaction amount;

  • payment status;

  • payment method type;

  • transaction identifier;

  • billing information;

  • refund information;

  • dispute information;

  • limited payment-card information, such as card brand and last four digits; and

  • other information necessary to administer the transaction.

Where payment-card data is handled directly by a third-party payment processor, Obsidian generally does not need to receive or store the complete payment-card number.


8. COMMUNICATION INFORMATION

Obsidian may collect or maintain records of communications involving the Platform, including:

  • SMS messages;

  • MMS messages;

  • telephone communications;

  • email;

  • in-app messages;

  • push-notification interactions;

  • customer-support communications;

  • dispatch communications;

  • provider communications; and

  • associated communications metadata.

Communications may be retained when reasonably necessary for operational purposes, service documentation, security, customer support, quality assurance, claims, dispute resolution, fraud prevention, or legal compliance.

Where required by applicable law, notice or consent will be provided before telephone calls or other communications are recorded, transcribed, or analyzed.


9. DEVICE, APPLICATION, AND TECHNICAL INFORMATION

When users access our websites or applications, we may automatically collect technical information including:

  • IP address;

  • browser type;

  • operating system;

  • device type;

  • application version;

  • device identifiers;

  • session identifiers;

  • language preferences;

  • login timestamps;

  • application interaction information;

  • crash information;

  • performance information;

  • security logs;

  • diagnostic information; and

  • other technical information reasonably necessary to operate and secure the Platform.


10. COOKIES AND SIMILAR TECHNOLOGIES

Our websites and web applications may use cookies, local storage, pixels, session technologies, or similar technologies to:

  • authenticate users;

  • maintain sessions;

  • remember settings;

  • prevent fraud;

  • protect accounts;

  • maintain security;

  • diagnose problems;

  • measure system performance; and

  • understand how our Platform is used.

Where applicable law requires consent for optional technologies, appropriate consent mechanisms may be provided.


11. HOW WE USE PERSONAL INFORMATION

Obsidian may use personal information for the following purposes.

Providing and Coordinating Services

We may use information to:

  • receive service requests;

  • identify service locations;

  • identify available providers;

  • coordinate dispatch;

  • assign providers or drivers;

  • calculate estimated arrival times;

  • facilitate navigation;

  • communicate job status;

  • coordinate appointments;

  • obtain quotations;

  • document services;

  • facilitate completion of services; and

  • provide customer support.

Operating the Platform

We may use information to:

  • establish accounts;

  • authenticate users;

  • maintain user profiles;

  • administer customer accounts;

  • administer provider accounts;

  • operate mobile applications;

  • operate websites;

  • provide marketplace functionality;

  • process transactions;

  • maintain service records; and

  • operate administrative systems.

Communications

We may communicate through:

  • telephone calls;

  • SMS;

  • MMS;

  • email;

  • push notifications;

  • in-app messaging; and

  • Platform notifications.

Depending on the circumstances and applicable consent requirements, communications may relate to:

  • service requests;

  • provider assignments;

  • estimated arrival times;

  • technician or driver status;

  • appointment reminders;

  • customer support;

  • account activity;

  • security;

  • authentication;

  • payments;

  • claims;

  • provider operations;

  • application functionality; and

  • other operational matters.

Marketing communications are subject to separate legal requirements and applicable consent or opt-out mechanisms.

Providing contact information does not, by itself, constitute consent to every form of marketing communication.


12. SMS AND MMS PRIVACY

Obsidian may use SMS or MMS for conversational, informational, transactional, customer-care, account, security, and service-related communications.

Examples may include:

  • service confirmations;

  • dispatch updates;

  • provider assignment information;

  • provider arrival information;

  • estimated arrival updates;

  • appointment reminders;

  • service-status notifications;

  • customer-support communications;

  • account notifications;

  • payment-related notifications;

  • verification codes;

  • security alerts; and

  • other communications relating to a requested service or account.

Where applicable consent is required, Obsidian will seek the appropriate consent before sending applicable messages.

Message frequency may vary based upon user activity and services requested.

Message and data rates may apply.

Recipients may reply STOP to applicable messages to request that future SMS communications of that type stop.

Recipients may reply HELP for assistance.

An opt-out confirmation may be sent after a STOP request.

Consent to receive promotional SMS messages is not a condition of purchasing goods or services.

SMS Consent and Mobile Opt-In Information

No mobile opt-in or text message consent will be shared with third parties or affiliates for marketing or promotional purposes.

Obsidian may provide information to telecommunications carriers, communications-platform providers, or other service vendors solely as reasonably necessary to transmit, route, deliver, secure, administer, or support communications requested or authorized by the user.

Mobile opt-in information will not be sold.

Where appropriate, Obsidian may maintain records showing:

  • the telephone number;

  • date and time consent was obtained;

  • method through which consent was obtained;

  • consent language or consent version;

  • source of the consent;

  • opt-in status;

  • opt-out status; and

  • date and time of an opt-out.


13. MULTI-CHANNEL COMMUNICATIONS

Obsidian operates a multi-channel communications platform.

A service or support interaction initiated through one communication channel may continue through another communication channel when reasonably necessary and legally permitted.

For example, a service request initiated in an application may result in:

  • an in-app message;

  • a push notification;

  • an email;

  • a telephone call; or

  • an SMS message where the applicable consent or legal basis exists.

Users may manage applicable communication preferences through account settings, device settings, unsubscribe links, SMS opt-out commands, or customer support.

Certain transactional, safety, authentication, or account-security communications may be necessary to operate an active account or fulfill a requested service.


14. HOW WE DISCLOSE PERSONAL INFORMATION

Obsidian may disclose personal information when reasonably necessary to operate the Platform or fulfill a requested service.

A. Service Providers, Drivers, and Automotive Businesses

Information necessary to fulfill a request may be provided to a provider, driver, technician, towing company, repair facility, or other service professional.

Depending on the service, this may include:

  • customer name;

  • telephone number;

  • service location;

  • destination;

  • vehicle information;

  • requested service;

  • relevant service notes;

  • photographs; and

  • other information reasonably necessary to perform the service.

B. Enterprise, Fleet, Insurer, or Contracting Organizations

If a service is arranged, sponsored, administered, or paid for by an employer, fleet, insurer, motor club, enterprise customer, or other organization, Obsidian may provide that organization information reasonably necessary to:

  • administer the service;

  • document completion;

  • administer payment;

  • address claims;

  • meet contractual requirements; or

  • manage the business relationship.

C. Technology and Operational Service Providers

Obsidian may engage vendors that provide services such as:

  • cloud infrastructure;

  • database hosting;

  • communications;

  • SMS and voice delivery;

  • email delivery;

  • payment processing;

  • mapping;

  • geolocation;

  • navigation;

  • authentication;

  • cybersecurity;

  • analytics;

  • application monitoring;

  • customer support;

  • file storage;

  • document management;

  • artificial intelligence functionality;

  • push notifications; and

  • other technical infrastructure.

These vendors may process information only as reasonably necessary to provide services to Obsidian and subject to applicable contractual, platform, privacy, and security requirements.

Current or anticipated technology providers may include services supplied by companies such as Google, RingCentral, Stripe, cloud and database infrastructure providers, email providers, mapping providers, and other technology vendors.

Third-party technology integrated into an application may collect or process information consistent with its role in providing Platform functionality.


15. THIRD-PARTY SDKs, APIs, AND INTEGRATIONS

Obsidian applications may use software development kits, APIs, libraries, or integrations supplied by third parties.

We evaluate third-party integrations based upon the functionality they provide and the information reasonably necessary for that functionality.

Where a third party processes personal information on our behalf, we expect the third party to provide protections consistent with applicable privacy and security requirements.

Users may also intentionally connect to or interact with independent third-party services.

Information independently collected by those services may be governed by their own privacy policies.


16. ARTIFICIAL INTELLIGENCE AND AUTOMATED SYSTEMS

Obsidian may use automated technologies, algorithms, artificial intelligence, machine learning, or decision-support systems to assist with Platform operations.

These technologies may assist with functions such as:

  • identifying appropriate providers;

  • dispatch recommendations;

  • estimating arrival times;

  • identifying service risks;

  • detecting suspected fraud or abuse;

  • analyzing system performance;

  • routing communications;

  • summarizing operational information;

  • assisting customer-support personnel;

  • categorizing service information; and

  • improving Platform functionality.

Automated recommendations may be used to support human decision-making and Platform operations.

Obsidian does not intend to use artificial intelligence to make legally significant decisions about consumers solely through automated processing unless such use is permitted by applicable law and appropriate disclosures or rights are provided.

Information submitted to third-party AI services, where used, will be limited to information reasonably necessary for the applicable functionality and subject to applicable vendor safeguards.


17. SERVICE PHOTOS, DAMAGE CLAIMS, AND INCIDENT RECORDS

Information relating to an accident, vehicle condition, property damage, complaint, incident, or insurance claim may be retained and disclosed where reasonably necessary to:

  • investigate the matter;

  • document vehicle condition;

  • resolve a dispute;

  • communicate with a provider;

  • communicate with an insurer;

  • respond to legal claims;

  • prevent fraud; or

  • satisfy contractual or legal obligations.

Such information may include photographs, service records, location records, timestamps, messages, statements, estimates, invoices, and related documentation.


18. LEGAL, SAFETY, AND SECURITY DISCLOSURES

We may disclose information if we reasonably believe disclosure is necessary to:

  • comply with applicable law;

  • respond to valid legal process;

  • respond to lawful governmental requests;

  • protect a person’s health or safety;

  • investigate suspected fraud;

  • investigate criminal activity;

  • protect property;

  • enforce agreements;

  • investigate misuse of the Platform;

  • defend legal claims; or

  • protect the rights and security of Obsidian, our users, providers, or others.


19. BUSINESS TRANSACTIONS

Personal information may be transferred as part of a:

  • merger;

  • acquisition;

  • financing;

  • restructuring;

  • reorganization;

  • sale of assets;

  • sale of a business unit;

  • bankruptcy proceeding; or

  • similar corporate transaction.

Any successor that receives personal information will remain subject to applicable privacy obligations concerning that information.


20. WE DO NOT SELL MOBILE OPT-IN INFORMATION

Obsidian does not sell mobile telephone numbers, SMS consent records, or SMS opt-in information.

No mobile opt-in or text message consent information will be provided to third parties or affiliates for their marketing or promotional purposes.


21. SALE OR SHARING OF PERSONAL INFORMATION

Obsidian does not currently sell personal information for monetary consideration.

Obsidian does not currently use personal information for cross-context behavioral advertising as that term is defined under California privacy law.

If our practices materially change, we will update our disclosures and provide legally required rights or opt-out mechanisms before engaging in applicable activities.


22. DATA SECURITY

Obsidian uses administrative, technical, and organizational safeguards designed to protect personal information.

Safeguards may include:

  • encryption in transit;

  • encryption at rest where appropriate;

  • authentication controls;

  • role-based access controls;

  • credential protection;

  • access logging;

  • system monitoring;

  • security testing;

  • database access controls;

  • vendor-management procedures;

  • secure cloud infrastructure;

  • account verification; and

  • incident-response procedures.

No electronic system, internet transmission, or storage environment can guarantee absolute security.

Users are responsible for protecting their login credentials and should promptly contact Obsidian if unauthorized account activity is suspected.


23. DATA RETENTION

Obsidian retains information only for as long as reasonably necessary for the purposes for which it was collected and for legitimate operational, security, contractual, accounting, insurance, dispute-resolution, and legal purposes.

Retention periods vary based upon the category of information and circumstances.

Factors considered when determining retention include:

  • whether the account remains active;

  • whether information is necessary to provide services;

  • applicable limitation periods;

  • tax or accounting requirements;

  • insurance requirements;

  • pending claims;

  • chargebacks;

  • payment disputes;

  • fraud prevention;

  • cybersecurity;

  • contractual obligations;

  • regulatory requirements; and

  • pending litigation or governmental requests.

Examples may include:

Account Information

Maintained while an account is active and thereafter for the period reasonably necessary to complete deletion, address legal obligations, prevent fraud, resolve disputes, or maintain required business records.

Service and Transaction Records

May be retained after service completion when reasonably necessary for accounting, customer support, claims, insurance, fraud prevention, contractual obligations, or legal compliance.

Location and Dispatch Records

Retained only for the period reasonably necessary to support service operations, documentation, safety, fraud prevention, analytics, dispute resolution, or legal requirements.

Photographs and Service Documentation

May be retained with the associated service record where needed to document completion, vehicle condition, claims, incidents, disputes, or other legitimate purposes.

SMS Consent Records

Consent and opt-out records may be retained for compliance, audit, and dispute-resolution purposes even after marketing or messaging consent has been withdrawn.

Provider Compliance Records

Licenses, insurance information, tax documents, contracts, and related records may be retained for legally required periods or for the period reasonably necessary to administer or defend the provider relationship.

Security Logs

Security and access records may be retained for a period reasonably necessary to detect abuse, investigate incidents, secure the Platform, and comply with legal requirements.

When information is no longer reasonably necessary, Obsidian may delete, destroy, anonymize, aggregate, or de-identify the information consistent with applicable law.


24. ACCOUNT AND DATA DELETION

Users may request deletion of eligible Obsidian accounts and associated personal information.

Obsidian intends to provide account-deletion functionality:

  • through the applicable customer mobile application;

  • through applicable provider or driver applications; and

  • through a publicly accessible web-based account-deletion method.

When a valid account-deletion request is completed, Obsidian will delete or de-identify personal information associated with the account except information that Obsidian is legally permitted or required to retain.

Information may be retained where reasonably necessary for:

  • legal compliance;

  • transaction records;

  • tax requirements;

  • accounting obligations;

  • fraud prevention;

  • security;

  • chargebacks;

  • disputes;

  • insurance claims;

  • damage claims;

  • provider contractual obligations;

  • litigation;

  • governmental requests; or

  • establishment or defense of legal rights.

Temporary account deactivation or suspension is not treated as permanent account deletion.

Information retained after account deletion will not be used for unrelated purposes.


25. MOBILE APPLICATION PRIVACY

Obsidian mobile applications may request permissions necessary to provide particular features.

Depending upon the application and functionality, permissions may include:

  • approximate location;

  • precise location;

  • background location;

  • camera access;

  • photo or media access;

  • notifications;

  • microphone access if voice functionality requires it;

  • file access where necessary;

  • Bluetooth or nearby-device functionality if such functionality is introduced; and

  • other permissions reasonably related to Platform features.

Obsidian intends to request protected device permissions only when reasonably related to user-facing functionality.

Users can generally manage operating-system permissions through their device settings.


26. GOOGLE PLAY PRIVACY

For applications distributed through Google Play, Obsidian intends to maintain disclosures consistent with applicable Google Play User Data and Data Safety requirements.

Our Google Play disclosures are intended to accurately reflect:

  • personal information collected;

  • sensitive information collected;

  • information shared;

  • purposes of collection;

  • security practices;

  • data deletion practices; and

  • the behavior of third-party libraries, SDKs, or integrations used in the applicable application.

The Privacy Policy will be made available through a publicly accessible webpage and through an appropriate location within applicable mobile applications.

For applications permitting account creation, Obsidian intends to provide both an in-app account-deletion mechanism and an external web-based account-deletion mechanism.


27. APPLE APP STORE PRIVACY

For applications distributed through Apple’s App Store, Obsidian intends to maintain App Privacy disclosures consistent with actual application practices.

Applicable applications will provide access to this Privacy Policy from within the application.

Where an application allows users to create an account, Obsidian intends to provide a readily accessible method for initiating account deletion from within the application.

Protected device permissions will be requested in accordance with applicable operating-system requirements.


28. USER PRIVACY CHOICES

Depending on the user’s relationship with Obsidian and applicable law, users may be able to:

  • access certain account information;

  • update account information;

  • correct inaccurate information;

  • request deletion;

  • change communication preferences;

  • withdraw certain consents;

  • opt out of SMS communications;

  • unsubscribe from marketing email;

  • disable push notifications;

  • change location permissions;

  • change camera or photo permissions; and

  • exercise applicable statutory privacy rights.

Device permissions can generally be modified through the user’s operating-system settings.

Withdrawal of a permission may affect functionality that depends upon that permission.


29. CALIFORNIA PRIVACY RIGHTS

Residents of California may have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), when the statute applies to Obsidian or to the applicable processing activity.

Applicable rights may include:

  • the right to know what categories of personal information are collected;

  • the right to know the sources of personal information;

  • the right to know the purposes for collecting or using personal information;

  • the right to know categories of recipients;

  • the right to access specific pieces of personal information;

  • the right to request deletion, subject to exceptions;

  • the right to request correction of inaccurate information;

  • the right to opt out of certain sales or sharing of personal information;

  • the right to limit certain uses or disclosures of sensitive personal information where applicable; and

  • the right to exercise applicable privacy rights without unlawful discrimination.

Obsidian does not currently sell personal information or share personal information for cross-context behavioral advertising as described above.

Where legally required, Obsidian will recognize applicable opt-out preference signals such as Global Privacy Control.

Privacy requests may require identity verification.

An authorized agent may submit a request when permitted by applicable law and appropriate authority can be verified.


30. NOTICE AT COLLECTION

At or before applicable points of collection, Obsidian may provide a shorter Notice at Collection describing:

  • categories of information being collected;

  • purposes for which the information is used; and

  • a link to this Privacy Policy.

Additional just-in-time disclosures may be presented before collecting particularly sensitive information or requesting protected device permissions.

Such shorter notices supplement this Privacy Policy and do not replace it.


31. SENSITIVE PERSONAL INFORMATION

Depending upon the services used, Obsidian may process information that may qualify as sensitive personal information under applicable law, including:

  • precise geolocation;

  • login credentials;

  • financial information;

  • government identification information provided by providers or drivers;

  • certain account-security information; and

  • other legally protected information.

Obsidian uses sensitive personal information for purposes reasonably necessary to provide services, protect accounts, conduct transactions, administer provider relationships, maintain security, prevent fraud, comply with law, or perform other legally permitted purposes.


32. CHILDREN’S PRIVACY

Obsidian’s Platform is not directed to children under 13.

Obsidian does not knowingly seek to collect personal information directly from children under 13 without legally required authorization.

If we become aware that information was collected from a child in violation of applicable law, we will take reasonable steps to delete the information.


33. PRIVACY OF PROVIDER EMPLOYEES AND PERSONNEL

Businesses participating in the Obsidian provider network may create accounts for, submit information relating to, or authorize access by drivers, technicians, dispatchers, or other personnel.

The provider is responsible for ensuring that it has authority to provide applicable personnel information to Obsidian.

Obsidian may process this information to:

  • administer provider accounts;

  • manage access;

  • coordinate services;

  • administer dispatch;

  • maintain compliance records;

  • manage safety;

  • investigate incidents; and

  • operate provider-related functionality.


34. SECURITY INCIDENTS

Obsidian maintains processes intended to identify, investigate, contain, remediate, and document suspected security incidents.

If a security incident involving personal information requires notification under applicable law, Obsidian will provide legally required notice to affected individuals, regulators, or other parties.


35. INTERNATIONAL PROCESSING

Obsidian primarily operates services for users in the United States.

Personal information may be processed or stored in the United States or in other locations in which our technology or service providers operate.

Where legally required, appropriate safeguards will be used for international transfers of personal information.


36. THIRD-PARTY LINKS

The Platform may contain links to independent websites, applications, or services.

Obsidian is not responsible for the privacy practices of independent third-party services.

Users should review applicable third-party privacy policies before providing information directly to those parties.


37. CHANGES TO THIS PRIVACY POLICY

Obsidian may modify this Privacy Policy from time to time to reflect:

  • changes in law;

  • regulatory requirements;

  • Platform functionality;

  • business operations;

  • technology;

  • security practices; or

  • information practices.

The “Last Updated” date will be revised when this Privacy Policy changes.

Where required by law, additional notice or consent may be provided before a material change takes effect.


38. CONTACTING OBSIDIAN ABOUT PRIVACY

Questions, concerns, or privacy requests may be directed to:

Obsidian Roadside & Recovery LLC

Website:
https://obsidianroadside.com

Telephone:
(888) 676-6908

Privacy Email:
Support@obsidianroadside.com

Mailing Address:
2370 Waterloo Road, Stockton CA 95205

Account Deletion:
https://obsidianroadside.com/account-deletion

Privacy Requests:
https://obsidianroadside.com/privacy-request

Requests may require reasonable identity verification before personal information is disclosed, corrected, or deleted.


39. ACKNOWLEDGMENT

By accessing or using the Obsidian Platform, users acknowledge that personal information may be processed as described in this Privacy Policy.

Where applicable law requires affirmative consent for a particular processing activity, permission, or communication method, acknowledgment of this Privacy Policy does not replace that separate consent.


END OF PRIVACY POLICY