Stalwart
Stalwart legal

Privacy Policy

Effective July 20, 2026 · Version 2026-07-20
Privacy in one paragraphWe collect only the information needed to run, secure, support, and improve Stalwart. Contractors control the customer and job data they place in the app. We do not sell personal information. We use service providers to operate the product, retain records only as needed, and support access and correction requests.

1. Who is responsible for the data

Stalwart account dataThe Operator decides why account, subscription, support, security, and product-usage information is processed.
Contractor customer dataThe contractor decides why client, quote, job, invoice, message, photo, and payment records are processed. Stalwart processes them to provide the service.

This Privacy Policy explains how the Canadian operator of Stalwart ("Stalwart", "we", or "us") handles personal information. A contractor using Stalwart is responsible for its own privacy notices and lawful instructions concerning its clients, staff, and suppliers.

2. Information we collect

Account and business information

Name, email, authentication records, business identity, contact details, plan, preferences, team roles, and support communications.

Business records supplied by users

Client and supplier contacts, estimates, agreements, signatures, invoices, payments, expenses, receipts, jobs, schedules, photos, forms, messages, crew records, and other content a user chooses to store.

Technical and usage information

IP address, browser and device information, timestamps, security events, page and feature interactions, delivery events, logs, and diagnostic information. Public approval links may record the signer, selected scope, consent choices, time, IP address, and browser details to preserve evidence of the transaction.

Payment information

Subscription and customer-payment providers process card and banking details. Stalwart generally receives tokens, account identifiers, payment status, amount, and limited transaction metadata rather than complete card numbers.

3. How we use information

Depending on the information and context, processing may be based on consent, performance of a contract, legal obligations, or legitimate business purposes permitted by Canadian privacy law. Consent requests are designed to be understandable and proportionate to the sensitivity of the information.

A client can approve a service agreement without agreeing to marketing. Marketing consent is requested separately and can be withdrawn without affecting an existing job or invoice.

5. When information is shared

We do not sell personal information. We may disclose information:

Providers are authorized to process information only for their contracted services and are expected to apply appropriate safeguards.

6. Processing outside Canada

Some providers or their systems may be located outside Canada. Information processed in another country may be subject to that country's laws and lawful access rules. We use contractual and technical safeguards appropriate to the service and information involved.

7. Retention and deletion

We retain information while an account is active and as reasonably needed to provide the service, resolve disputes, preserve transaction evidence, maintain security, and meet tax, accounting, legal, and backup obligations. Retention varies by record type and legal requirement. Information is deleted or de-identified when it is no longer reasonably required.

Account holders can export records and request account closure. A contractor may need to retain invoices, approvals, payroll, tax, warranty, or project records after a client asks for deletion where law permits or requires that retention.

8. Security

We use administrative, technical, and physical safeguards designed for the sensitivity of the information, including access controls, authentication, encryption in transit, provider security controls, audit records, and restricted database permissions. No method of storage or transmission is completely secure. Users must protect credentials, devices, shared links, and authorized access.

If a privacy breach creates a real risk of significant harm, we will investigate, document, notify affected organizations or people, and report to regulators as required.

9. Access, correction, and choices

Subject to legal exceptions, a person may ask to access or correct personal information held by Stalwart, withdraw consent, object to certain uses, or ask how information has been handled. For information controlled by a contractor, contact that contractor first; we will assist it as appropriate.

We may need to verify identity before completing a request. Withdrawing consent does not affect processing already completed and may prevent a requested feature from working where the information is necessary.

10. Email, text messages, cookies, and local storage

Operational messages such as receipts, approvals, schedule updates, payment notices, and security messages are sent to provide the requested service. Commercial electronic messages are sent with consent or another lawful basis and include required sender information and an unsubscribe method.

Stalwart uses browser storage and similar technology for authentication, preferences, demo data, security, offline operation, and essential product functions. A browser can clear or block storage, but doing so may sign the user out or disable features.

11. Children

Stalwart is business software and is not directed to children. Do not submit a child's information unless it is necessary for lawful business activity and appropriate consent and safeguards are in place.

12. Policy updates

We may update this Policy to reflect legal, operational, or product changes. The page will show the new effective date. Material changes will be communicated through the service or account contact information, and renewed consent will be requested when required.

13. Contact and complaints

Privacy questions, access or correction requests, and complaints can be sent through the Support channel available in Stalwart. We will investigate and respond within a reasonable time. A person may also contact the Office of the Privacy Commissioner of Canada or the applicable provincial privacy regulator.

Launch requirement: The Operator's registered legal name, mailing address, and designated privacy contact must be added before public commercial launch. Canadian privacy counsel should review this production draft and the actual provider list.