Privacy Policy
Last updated: December 30, 2026
1. Information We Collect
We only collect personal information when necessary to provide services. Information is collected by fair and lawful means, with your knowledge and consent.
Information you provide directly:
- Name and contact information (email, phone number)
- Business name and details
- Project requirements and preferences
- Payment information (processed securely by Stripe)
Information collected automatically:
- IP address and approximate location
- Browser type and device information
- Pages visited and time spent on site
- Referring website
2. How We Use Information
We use collected information to:
- Respond to your inquiries and provide requested services
- Process payments and send invoices
- Improve our website and services
- Send occasional updates about our services (with your consent)
- Comply with legal obligations
We do not share personally identifying information with third parties except when required by law or with your explicit consent.
3. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this policy:
- Client records: 7 years after the last transaction (for tax and legal purposes)
- Contact form submissions: 2 years, or until you request deletion
- Analytics data: 26 months (anonymized)
- Email marketing: Until you unsubscribe
4. Cookies and Tracking
We use cookies to analyze website traffic and optimize your experience. Types of cookies we use:
- Essential cookies: Required for website functionality
- Analytics cookies: Help us understand how visitors use our site
- Preference cookies: Remember your settings (e.g., dark mode)
You can manage cookie preferences through your browser settings. Disabling certain cookies may affect website functionality.
5. Third-Party Services
We use the following third-party services that may collect data:
- Supabase: Database and authentication (data stored in North America)
- Stripe: Payment processing (PCI-DSS compliant)
- Cloudflare: Security and performance
- Cal.com: Appointment scheduling
Each service has its own privacy policy governing data use.
6. Data Security
We take commercially reasonable steps to protect your data:
- All data transmitted via HTTPS encryption
- Secure password hashing and authentication
- Regular security audits and updates
- Limited employee access to personal data
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security but will notify affected users promptly in the event of a data breach.
7. Your Rights Under PIPEDA (Canada)
Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to:
- Access your personal information held by us
- Request correction of inaccurate information
- Withdraw consent for data collection (subject to legal limitations)
- File a complaint with the Privacy Commissioner of Canada
To exercise these rights, contact us at privacy@axrategy.com. We will respond within 30 days.
8. Your Rights Under GDPR (European Union)
If you are a resident of the European Economic Area (EEA), you have additional rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a structured format
- Right to Object: Object to processing for marketing purposes
Legal Basis for Processing: We process data based on contract performance, legitimate interests, and/or your consent.
To exercise GDPR rights, contact privacy@axrategy.com. We will respond within 30 days. You may also lodge a complaint with your local supervisory authority.
9. Your Rights Under CCPA (California)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights:
- Right to Know: Request disclosure of personal information collected, used, and shared
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt out of the sale of personal information (we do not sell personal data)
- Right to Non-Discrimination: Equal service regardless of exercising privacy rights
To exercise these rights, contact privacy@axrategy.com or call +1-647-607-3046. We will verify your identity before processing requests. We will respond within 45 days.
We do not sell personal information. We do not discriminate against users who exercise their privacy rights.
10. International Data Transfers
Your data may be transferred to and processed in countries other than your own, including Canada and the United States. We ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by relevant authorities
- Working only with service providers who maintain adequate data protection
11. Children's Privacy
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on our website at least 30 days before taking effect. Continued use of our services after changes constitutes acceptance of the updated policy.
Contact Us
For privacy-related questions or to exercise your rights, contact us at:
Privacy Inquiries: privacy@axrategy.com
General Inquiries: hello@axrategy.com
Phone: +1-647-607-3046
Axrategy Inc.
Toronto, Ontario, Canada