Privacy Policy
1. Who is responsible for the data
This Privacy Policy explains how the Canadian operator of Stalwart ("Stalwart", "we", or "us") handles personal information. A contractor using Stalwart is responsible for its own privacy notices and lawful instructions concerning its clients, staff, and suppliers.
2. Information we collect
Account and business information
Name, email, authentication records, business identity, contact details, plan, preferences, team roles, and support communications.
Business records supplied by users
Client and supplier contacts, estimates, agreements, signatures, invoices, payments, expenses, receipts, jobs, schedules, photos, forms, messages, crew records, and other content a user chooses to store.
Technical and usage information
IP address, browser and device information, timestamps, security events, page and feature interactions, delivery events, logs, and diagnostic information. Public approval links may record the signer, selected scope, consent choices, time, IP address, and browser details to preserve evidence of the transaction.
Payment information
Subscription and customer-payment providers process card and banking details. Stalwart generally receives tokens, account identifiers, payment status, amount, and limited transaction metadata rather than complete card numbers.
3. How we use information
- Provide quotes, invoicing, payments, jobs, scheduling, communications, reporting, and account features.
- Authenticate users, enforce permissions, prevent fraud, protect accounts, and investigate incidents.
- Deliver messages and record delivery, opening, reply, approval, and payment events.
- Provide support, troubleshoot issues, maintain records, and communicate service changes.
- Process subscriptions and comply with tax, accounting, legal, and regulatory duties.
- Measure and improve reliability, usability, and performance using aggregated or appropriately protected information.
- Use optional AI features only when enabled or requested, subject to the controls and provider disclosures shown in the product.
4. Consent and other lawful bases
Depending on the information and context, processing may be based on consent, performance of a contract, legal obligations, or legitimate business purposes permitted by Canadian privacy law. Consent requests are designed to be understandable and proportionate to the sensitivity of the information.
A client can approve a service agreement without agreeing to marketing. Marketing consent is requested separately and can be withdrawn without affecting an existing job or invoice.
5. When information is shared
We do not sell personal information. We may disclose information:
- To authorized users of the same business account and to the clients with whom records are shared.
- To service providers that supply hosting, databases, authentication, payments, email, text messaging, monitoring, document delivery, maps, support, or optional AI functions.
- At the account holder's direction, including exports and connected services.
- To comply with law, legal process, or a valid government request, or to protect rights, safety, security, and the integrity of the service.
- As part of a financing, reorganization, merger, or sale, subject to appropriate confidentiality and continued protection.
Providers are authorized to process information only for their contracted services and are expected to apply appropriate safeguards.
6. Processing outside Canada
Some providers or their systems may be located outside Canada. Information processed in another country may be subject to that country's laws and lawful access rules. We use contractual and technical safeguards appropriate to the service and information involved.
7. Retention and deletion
We retain information while an account is active and as reasonably needed to provide the service, resolve disputes, preserve transaction evidence, maintain security, and meet tax, accounting, legal, and backup obligations. Retention varies by record type and legal requirement. Information is deleted or de-identified when it is no longer reasonably required.
Account holders can export records and request account closure. A contractor may need to retain invoices, approvals, payroll, tax, warranty, or project records after a client asks for deletion where law permits or requires that retention.
8. Security
We use administrative, technical, and physical safeguards designed for the sensitivity of the information, including access controls, authentication, encryption in transit, provider security controls, audit records, and restricted database permissions. No method of storage or transmission is completely secure. Users must protect credentials, devices, shared links, and authorized access.
If a privacy breach creates a real risk of significant harm, we will investigate, document, notify affected organizations or people, and report to regulators as required.
9. Access, correction, and choices
Subject to legal exceptions, a person may ask to access or correct personal information held by Stalwart, withdraw consent, object to certain uses, or ask how information has been handled. For information controlled by a contractor, contact that contractor first; we will assist it as appropriate.
We may need to verify identity before completing a request. Withdrawing consent does not affect processing already completed and may prevent a requested feature from working where the information is necessary.
10. Email, text messages, cookies, and local storage
Operational messages such as receipts, approvals, schedule updates, payment notices, and security messages are sent to provide the requested service. Commercial electronic messages are sent with consent or another lawful basis and include required sender information and an unsubscribe method.
Stalwart uses browser storage and similar technology for authentication, preferences, demo data, security, offline operation, and essential product functions. A browser can clear or block storage, but doing so may sign the user out or disable features.
11. Children
Stalwart is business software and is not directed to children. Do not submit a child's information unless it is necessary for lawful business activity and appropriate consent and safeguards are in place.
12. Policy updates
We may update this Policy to reflect legal, operational, or product changes. The page will show the new effective date. Material changes will be communicated through the service or account contact information, and renewed consent will be requested when required.
13. Contact and complaints
Privacy questions, access or correction requests, and complaints can be sent through the Support channel available in Stalwart. We will investigate and respond within a reasonable time. A person may also contact the Office of the Privacy Commissioner of Canada or the applicable provincial privacy regulator.
Stalwart