Privacy Policy

Last updated: May 15, 2026
Company: AppSite / Appsations Inc.
Contact: paul@appsationsinc.com

This policy is published for AppSite tenant modules and public-facing AppSite services. Final wording should be reviewed before production launch where required.

Overview

Appsations Inc. respects privacy and is committed to protecting personal information. This Privacy Policy explains how information may be collected, used, disclosed, protected, retained, and deleted when people use AppSite websites, tenant modules, dashboards, forms, client portals, or connected services.

Information we collect

Depending on the service, we may collect names, email addresses, phone numbers, business details, account login information, booking or service details, messages, support requests, billing records, app settings, uploaded content, device and browser data, usage data, and security logs.

We aim to collect only the information reasonably necessary to provide, secure, maintain, and improve the service.

Sensitive information

Some AppSite modules may involve confidential or sensitive information. Sensitive information should only be submitted when necessary for the service. Where supported, selected sensitive fields may be encrypted before they are stored so the database stores encrypted content instead of readable client content.

How we use information

We may use personal information to provide services, manage accounts, respond to requests, process bookings or transactions, operate dashboards, maintain security, improve user experience, send service notices, meet legal obligations, and protect our rights.

Google account sign-in for internal admin tools

Internal AppSite SDK administration tools used by authorized Appsations Inc. staff may include an optional “Google Account” sign-in for connecting a dedicated Google Cloud account when provisioning tenant infrastructure. This sign-in requests the https://www.googleapis.com/auth/cloud-platform scope (to list and create Google Cloud projects under the signed-in account) and https://www.googleapis.com/auth/userinfo.email (to display which account is signed in). Access tokens obtained this way are used only client-side to call the Google Cloud Resource Manager API on behalf of the signed-in staff member, are held only in the browser session, are never transmitted to or stored on any Appsations Inc. server or database, and expire automatically per Google's standard OAuth token lifetime. This feature is restricted to authorized personnel and is not available to the public.

Firebase, Firestore, and cloud providers

Our services may use Firebase, Firestore, Google Cloud, and trusted third-party providers for hosting, authentication, storage, security, payments, analytics, and service operations. Cloud providers may store or process information in Canada, the United States, or other jurisdictions.

Encryption and security

We use reasonable safeguards that may include HTTPS/TLS, cloud-provider encryption at rest, Firebase Authentication, Firestore Security Rules, role-based access control, limited administrator access, logging, monitoring, and selected client-side encryption for sensitive fields.

Default cloud-provider encryption is treated as a baseline safeguard. For highly sensitive data, our recommended direction is to encrypt selected fields before they are written to Firestore where practical.

Client-side encrypted data

Some services may encrypt sensitive fields before storage. If we do not hold the decryption key, we may not be able to recover readable content.

Disclosure

We do not sell personal information. We may disclose personal information to service providers, payment processors, professional advisors, legal or regulatory authorities where required, security providers, or with user consent.

Legal requests

If we receive a legal request for user information, we will review it and respond as required by law. Where data is encrypted client-side and we do not possess the decryption key, we may not be able to provide readable content.

Cookies and analytics

We may use cookies, analytics, and similar technologies to operate the service, remember preferences, understand usage, improve performance, and protect against misuse. See our Cookie Notice for more information.

Retention and deletion

We retain personal information only as long as reasonably necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law. Users may request access, correction, or deletion by contacting paul@appsationsinc.com.

Contact

Privacy, security, and data requests: paul@appsationsinc.com