US Privacy Notice
Colega's whole dataset is a name, a work email and a room booking. This page says that again in the vocabulary US state privacy laws use. There is no "Do Not Sell or Share" link on this site because there is no selling or sharing to stop.
The short version
- We do not sell personal information. We never have.
- We do not share personal information for cross-context behavioral advertising. There is no advertising anywhere in the product.
- We collect no sensitive personal information as California defines it — no government IDs, no precise geolocation, no health, biometric or financial data. No field for any of it exists.
- Our main Privacy Policy applies everywhere, this country included. This page adds the US-specific answers.
"Sale" and "sharing", precisely
California's CCPA uses these words in a specific way, so here is the answer in that specific way:
- A "sale" is disclosing personal information to a third party for money or other valuable consideration. Colega discloses personal information to no third parties at all — only to the three named service providers that run the service (Cloudflare, Resend, PostHog EU), under contracts that forbid them using it for anything else.
- "Sharing" means disclosing personal information for cross-context behavioral advertising. Colega has no ads, no ad partners, no trackers, no pixels — nothing to share into.
- Because neither happens, no "Do Not Sell or Share My Personal Information" link is required — and there is nothing a Global Privacy Control signal would need to switch off. Nothing is tracked to begin with.
Does the CCPA even apply to us?
Honestly: no. The CCPA covers a "business" only past one of three thresholds — roughly $26.6 million in annual revenue (as adjusted), buying/selling/sharing the personal information of 100,000+ California consumers or households, or earning half of revenue from selling or sharing personal information. Colega is orders of magnitude below all three. We answer in CCPA vocabulary anyway, because your legal team will ask — and because the answers cost us nothing when the honest answer is "we don't do any of that".
The other states
- The state privacy laws outside California — Virginia, Colorado, Connecticut, Texas and the rest — define a "consumer" as someone acting in a personal or household context, and exclude people acting in a commercial or employment context. Colega's data is exactly that excluded kind: members of a workplace building, booking rooms at work.
- Their applicability thresholds sit in the tens to hundreds of thousands of consumers — far above Colega's scale.
- Texas and Nebraska skip the thresholds but exempt small businesses, keeping one rule for everyone: don't sell sensitive personal data without consent. We hold no sensitive data and sell nothing, so that rule is satisfied by the shape of the product.
Who answers for your data
- Your building is the controller (in CCPA terms, the "business") of its member list; Colega is its service provider / processor, holding the data on the building's instructions under a written agreement.
- Formally, privacy requests route through your building. Practically, we honor access, correction and deletion requests for anyone, threshold or no threshold — ask your building's admin, or write to us directly.
- Buildings get a full export (CSV) or complete deletion of everything within 30 days of asking, normally the same week.
Where your data lives
In the European Union — the opposite concern from the one most US privacy pages address. The database is pinned to the EU by a jurisdiction restriction set at creation, with read replication off, so there are no copies elsewhere. Today Colega has no US-resident database. If your company requires US data residency, say so before you sign up — that is a decision made before onboarding, not after.
Contact
Privacy: privacy at meetcolega dot com · Everything else: legal at meetcolega dot com. You'll get an answer from the person who wrote the code, not a ticket queue.