Privacy Policy

Version 2.1.0 · Effective 2026-08-01
AppSite — Appsations, Inc.
Contact: paul@appsite.ca

This policy explains what personal information AppSite handles, why, and what rights you have. Who is legally responsible for the data differs between our two hosting models, so read the edition that matches your workspace.

Shared Platform edition This is the edition that applies to shared tenancy. Reading the wrong one? Show the dedicated edition

Your workspace runs on AppSite-operated Google Cloud infrastructure. Your data is stored in shared databases, separated from other customers by tenant identifier and enforced server-side security rules. AppSite operates, deploys, patches, monitors and backs up the platform for you.

Who is responsible for your data

For data your organization puts into the platform, your organization is the controller and AppSite is the processor: we handle it on your instructions.

For account, billing and support data we hold about you directly, AppSite is the controller.

What we collect

Account information: name, email address, organization, role and authentication identifiers.

Usage information: sign-in events, module and feature usage, API calls, AI credit consumption, and error and audit logs. This is used to operate, secure, meter and support the service.

Billing information: plan, invoices, payment status and billing contact. Card details are handled by our payment processors and are not stored by AppSite.

Support information: what you send us when you contact support.

Content: whatever your organization chooses to store in its workspace. AppSite does not control what you put there — including whether you put sensitive information in it.

Where your data is stored

In Google Cloud projects operated by AppSite, in Canadian and United States regions. Records are separated by tenant identifier and access is enforced by server-side security rules.

Why we use it

To provide and operate the service; to authenticate users; to secure the platform and investigate abuse; to meter usage and bill accurately; to provide support; to send service and administrative messages; and to meet legal obligations.

We do not sell personal information. We do not use your workspace content to train machine learning models. We do not use your workspace content for advertising.

Email

Service and administrative email — sign-in, security notices, billing, and messages your workspace generates — is part of the service and is not marketing.

Marketing email, if any, requires opt-in and carries an unsubscribe link. Unsubscribing from marketing does not stop service email.

Who else processes it

We use the subprocessors listed on this page. Each is engaged under terms requiring appropriate confidentiality and security. We will give notice of a new subprocessor that materially affects the processing of your data.

SubprocessorPurposeLocation
Google Cloud Platform / FirebaseApplication hosting, database, authentication, file storage, serverless functionsCanada and United States
Twilio SendGridTransactional and notification email deliveryUnited States
StripePayment processing and subscription billingUnited States and Canada
SquarePayment processing for in-person and hosted checkoutUnited States and Canada
Google (Gemini API)AI generation features, where the customer enables themUnited States
Anthropic (Claude API)AI generation and assistance features, where the customer enables themUnited States

How long we keep it

Workspace content is kept while your subscription is active. After termination you have 30 days to export, after which content is deleted from active systems. Backups age out on their normal rotation, within 90 days.

Audit, security and billing records are kept as long as needed for legal, tax and accounting obligations, typically seven years.

Security

Data is encrypted in transit with TLS and at rest by the cloud provider. Access is role-based and enforced server-side. Administrative actions are logged. Highly sensitive fields should be encrypted before storage — see our Security Policy.

No system is perfectly secure. If a breach affects your personal information we will notify you and any regulator as required by law, without undue delay.

Your rights

Depending on where you live you may have rights to access, correct, delete, port or restrict your personal information, and to withdraw consent.

If your data is in a workspace run by an organization, direct your request to that organization first — they control it. We will support them in responding.

To exercise a right against AppSite directly, contact privacy@appsite.ca. We respond within 30 days.

Children

The platform is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact privacy@appsite.ca and we will delete it.

Changes

We will post changes here with a new effective date, and give notice of material changes.

Contact

Privacy questions: privacy@appsite.ca

Appsations, Inc., British Columbia, Canada

privacy v2.1.0 · shared · f81e9e691397a036