Privacy Policy
This policy explains what personal information AppSite handles, why, and what rights you have. Who is legally responsible for the data differs between our two hosting models, so read the edition that matches your workspace.
Your workspace runs on AppSite-operated Google Cloud infrastructure. Your data is stored in shared databases, separated from other customers by tenant identifier and enforced server-side security rules. AppSite operates, deploys, patches, monitors and backs up the platform for you.
Who is responsible for your data
For data your organization puts into the platform, your organization is the controller and AppSite is the processor: we handle it on your instructions.
For account, billing and support data we hold about you directly, AppSite is the controller.
What we collect
Account information: name, email address, organization, role and authentication identifiers.
Usage information: sign-in events, module and feature usage, API calls, AI credit consumption, and error and audit logs. This is used to operate, secure, meter and support the service.
Billing information: plan, invoices, payment status and billing contact. Card details are handled by our payment processors and are not stored by AppSite.
Support information: what you send us when you contact support.
Content: whatever your organization chooses to store in its workspace. AppSite does not control what you put there — including whether you put sensitive information in it.
Where your data is stored
In Google Cloud projects operated by AppSite, in Canadian and United States regions. Records are separated by tenant identifier and access is enforced by server-side security rules.
Why we use it
To provide and operate the service; to authenticate users; to secure the platform and investigate abuse; to meter usage and bill accurately; to provide support; to send service and administrative messages; and to meet legal obligations.
We do not sell personal information. We do not use your workspace content to train machine learning models. We do not use your workspace content for advertising.
Service and administrative email — sign-in, security notices, billing, and messages your workspace generates — is part of the service and is not marketing.
Marketing email, if any, requires opt-in and carries an unsubscribe link. Unsubscribing from marketing does not stop service email.
Who else processes it
We use the subprocessors listed on this page. Each is engaged under terms requiring appropriate confidentiality and security. We will give notice of a new subprocessor that materially affects the processing of your data.
| Subprocessor | Purpose | Location |
|---|---|---|
| Google Cloud Platform / Firebase | Application hosting, database, authentication, file storage, serverless functions | Canada and United States |
| Twilio SendGrid | Transactional and notification email delivery | United States |
| Stripe | Payment processing and subscription billing | United States and Canada |
| Square | Payment processing for in-person and hosted checkout | United States and Canada |
| Google (Gemini API) | AI generation features, where the customer enables them | United States |
| Anthropic (Claude API) | AI generation and assistance features, where the customer enables them | United States |
How long we keep it
Workspace content is kept while your subscription is active. After termination you have 30 days to export, after which content is deleted from active systems. Backups age out on their normal rotation, within 90 days.
Audit, security and billing records are kept as long as needed for legal, tax and accounting obligations, typically seven years.
Security
Data is encrypted in transit with TLS and at rest by the cloud provider. Access is role-based and enforced server-side. Administrative actions are logged. Highly sensitive fields should be encrypted before storage — see our Security Policy.
No system is perfectly secure. If a breach affects your personal information we will notify you and any regulator as required by law, without undue delay.
Your rights
Depending on where you live you may have rights to access, correct, delete, port or restrict your personal information, and to withdraw consent.
If your data is in a workspace run by an organization, direct your request to that organization first — they control it. We will support them in responding.
To exercise a right against AppSite directly, contact privacy@appsite.ca. We respond within 30 days.
Children
The platform is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact privacy@appsite.ca and we will delete it.
Changes
We will post changes here with a new effective date, and give notice of material changes.
Contact
Privacy questions: privacy@appsite.ca
Appsations, Inc., British Columbia, Canada
privacy v2.1.0 · shared · f81e9e691397a036
Your platform runs inside your own Google Cloud organization, on projects and a billing account you own. Your data is never stored in AppSite's shared databases. AppSite delivers the software to repositories you control, and you perform the deployment. AppSite holds no standing access to your environment.
Who is responsible for your data
Your workspace data is stored in cloud projects you own, under your own agreement with your cloud provider. Your organization is the controller and also the operator of the storage. AppSite does not hold that data and cannot access it unless you grant access.
AppSite is the controller only for the account, billing, licensing and support data we hold about you directly.
What we collect
Account information: name, email address, organization, role and authentication identifiers.
Usage information: sign-in events, module and feature usage, API calls, AI credit consumption, and error and audit logs. This is used to operate, secure, meter and support the service.
Billing information: plan, invoices, payment status and billing contact. Card details are handled by our payment processors and are not stored by AppSite.
Support information: what you send us when you contact support.
Content: whatever your organization chooses to store in its workspace. AppSite does not control what you put there — including whether you put sensitive information in it.
Where your data is stored
In Google Cloud projects that you own, in the regions you select. AppSite does not copy your workspace data into its own systems.
AppSite retains only the account, billing, licensing and support records needed to maintain the relationship.
Why we use it
To provide and operate the service; to authenticate users; to secure the platform and investigate abuse; to meter usage and bill accurately; to provide support; to send service and administrative messages; and to meet legal obligations.
We do not sell personal information. We do not use your workspace content to train machine learning models. We do not use your workspace content for advertising.
Service and administrative email — sign-in, security notices, billing, and messages your workspace generates — is part of the service and is not marketing.
Marketing email, if any, requires opt-in and carries an unsubscribe link. Unsubscribing from marketing does not stop service email.
Who else processes it
We use the subprocessors listed on this page. Each is engaged under terms requiring appropriate confidentiality and security. We will give notice of a new subprocessor that materially affects the processing of your data.
| Subprocessor | Purpose | Location |
|---|---|---|
| Google Cloud Platform / Firebase | Software runs on projects owned and billed by the customer; Google is the customer's own provider, contracted directly | Regions selected by the customer |
| Twilio SendGrid | Transactional and notification email delivery | United States |
| Stripe | Payment processing and subscription billing | United States and Canada |
| Square | Payment processing for in-person and hosted checkout | United States and Canada |
| Google (Gemini API) | AI generation features, where the customer enables them | United States |
| Anthropic (Claude API) | AI generation and assistance features, where the customer enables them | United States |
How long we keep it
Retention of your workspace content is under your control, because it is stored in your own projects on the retention and backup settings you configure.
AppSite keeps account, billing and licensing records as long as needed for legal, tax and accounting obligations, typically seven years.
Security
Data is encrypted in transit with TLS and at rest by the cloud provider. Access is role-based and enforced server-side. Administrative actions are logged. Highly sensitive fields should be encrypted before storage — see our Security Policy.
No system is perfectly secure. If a breach affects your personal information we will notify you and any regulator as required by law, without undue delay.
Your rights
Depending on where you live you may have rights to access, correct, delete, port or restrict your personal information, and to withdraw consent.
If your data is in a workspace run by an organization, direct your request to that organization first — they control it. We will support them in responding.
To exercise a right against AppSite directly, contact privacy@appsite.ca. We respond within 30 days.
Children
The platform is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact privacy@appsite.ca and we will delete it.
Changes
We will post changes here with a new effective date, and give notice of material changes.
Contact
Privacy questions: privacy@appsite.ca
Appsations, Inc., British Columbia, Canada
privacy v2.1.0 · dedicated · db79516102191d2b