Privacy Policy
Last updated: 19 September 2026.
1. Who this applies to
A distinction worth getting right: this app is a data processor for the support conversations, contacts, and tickets a tenant stores here — that data belongs to the tenant and their own end customers, governed by the tenant's own privacy policy and any data processing agreement between us. This policy is about data S13 Software Solutions Inc. ("S13", "we", "us") collects as the data controller — from the people who sign up for and administer a workspace ("you"), and from visitors of this site itself.
S13 also runs its own products (for example ClearanceBay and NetQuality) on this Service, in a single S13-owned workspace. For the people who use those products and contact their support, S13 is the tenant — the organization that decides what is collected and why — and the same protections described here apply to that data. Each of those products' own privacy notices describe anything specific to it.
This policy is written against the Personal Information Protection and Electronic Documents Act (PIPEDA), which applies to S13 as a Canadian organization handling personal information in the course of commercial activity.
2. What we collect
We collect the following categories of personal information:
- Account information: name, email address, and password (stored as a salted hash, never in plain text) for you and any agent you invite to your workspace.
- Billing information: billing email and subscription details. Card numbers are collected and stored directly by our payment processor, Square — we never receive or store full card numbers ourselves.
- Workspace configuration: your organization's name, branding, custom domains, and integration settings you choose to connect (e.g. Slack, WhatsApp, GitLab, Linear, Jira).
- Usage and log data: sign-in activity, API request metadata, and error/diagnostic data used to operate, secure, and improve the Service.
- Site visitor data: for visitors of our marketing pages who are not yet account holders, standard web server logs (IP address, user agent, requested page). We do not run third-party analytics or advertising trackers on this site.
We do not treat Customer Data (your own tickets, contacts, and messages) as covered by this section — see §1.
3. How we use it
We use the personal information described above to:
- Create and administer your account and workspace, and authenticate you;
- Process payment, send billing notices, and enforce plan allowances;
- Provide customer support and respond to inquiries you send us directly;
- Send service-related communications (security notices, changes to these terms, planned maintenance) — these are not marketing and cannot be opted out of while your account remains active;
- Send product and marketing communications, where you have not opted out, in accordance with applicable anti-spam law;
- Detect, investigate, and prevent fraud, abuse, and security incidents; and
- Meet legal, tax, and regulatory obligations.
We do not sell personal information, and we do not use it to train any AI model — see §5 for how AI providers are used.
4. Cookies and similar technologies
We use a session cookie to keep you signed in and a CSRF-protection cookie to secure form submissions — both are strictly necessary for the Service to function and are not used for tracking or advertising. We do not currently use analytics or advertising cookies on this site. If that changes, this section will be updated first, and consent will be requested where required by applicable law.
5. Third-party service providers (sub-processors)
We use the following categories of sub-processor to operate the Service. Each receives only the personal information necessary to perform its function, under a contract that requires it to protect that information.
- Payment processing: Square — billing and card storage.
- Transactional and marketing email: Postmark — delivering account, notification, and (where applicable) campaign email on your behalf.
- File storage: an S3-compatible object storage provider — ticket attachments you or your end customers upload.
- Network and edge: Cloudflare — all traffic to the Service passes through Cloudflare for DNS, TLS, DDoS protection and secure tunnelling to our servers, and Cloudflare issues certificates for a tenant's own verified custom domain. Cloudflare therefore sees request metadata (such as IP addresses) in transit.
- Error monitoring: Sentry — application error diagnostics, used to keep the Service reliable.
- AI providers: depending on your plan and configuration, models run by S13 on its own infrastructure, or Anthropic, OpenAI, Google (Gemini), Cohere, or AWS Bedrock power AI-assisted features (triage, suggested replies, translation, knowledge-base search). Workspaces on an eligible plan may instead configure their own key with a provider of their choice, in which case that provider's own terms govern, not ours.
- Communication channel integrations you choose to connect: Meta (WhatsApp Business), Slack, and similar, only when you enable that integration.
A current list naming each specific sub-processor and its role, updated as this list changes, is available on request at [email protected].
6. Data retention
We retain account and billing information for as long as your workspace is active, and for a limited period after cancellation to allow for reactivation or as required for tax and accounting records. Backups are retained on a rotating schedule (recent backups daily, tapering to a small number of yearly backups kept up to 2 years) and age out of that rotation in the ordinary course, rather than being retained indefinitely.
If you close your workspace, we delete or anonymize the personal information described in §2 within 90 days of closure, except where we are required to retain it longer by law (for example, financial records) or where it persists in a backup until that backup ages out of rotation per the schedule above.
7. Your rights (access, correction, deletion, export)
Under PIPEDA, you have the right to know what personal information we hold about you, to request access to it, to request correction of inaccurate information, and to withdraw consent to its use (subject to legal or contractual restrictions and reasonable notice). To exercise any of these rights over the account/billing information described in §2, contact [email protected]. We will respond within the time PIPEDA requires.
If you are an end customer of one of our tenants — someone who has submitted a support ticket or chatted with a tenant's widget — your data is controlled by that tenant, not by us; direct your request to them. Every workspace has built-in tools (in its contact settings) to export or erase an end customer's data on request, which we provide specifically so tenants can honor requests like yours.
8. International data transfers
Several of the sub-processors listed in §5 operate outside Canada, including in the United States. Personal information may therefore be processed in a jurisdiction with different data protection laws than Canada's, and may become accessible to that jurisdiction's courts, law enforcement, or national security authorities. Consistent with PIPEDA's accountability principle, we use contractual protections with our sub-processors intended to provide a comparable level of protection to personal information transferred this way.
9. Security
We maintain technical and organizational measures designed to protect
personal information, including encryption in transit (TLS) for all
traffic to the Service, encrypted storage of sensitive credentials
(API keys, integration secrets), password hashing, and access controls
limiting who can reach production systems. Our current security
posture is documented in more detail in COMPLIANCE.md in
our source repository, including what is not yet in place — we believe
in stating gaps plainly rather than implying a level of maturity we
haven't reached yet.
No method of transmission or storage is completely secure. If we become aware of a breach creating a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as PIPEDA requires.
10. Children's privacy
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16 as part of operating the Service itself. If you believe a child has provided us personal information, contact [email protected] and we will delete it.
11. Changes to this policy
We may update this policy from time to time. If a change is material, we will provide notice (such as an email to your workspace's owner, or a notice within the product) before the change takes effect. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact
Questions about this policy, or requests to exercise the rights described in §7, can be sent to [email protected], or by mail to:
S13 Software Solutions Inc.
1460 Chevrier Blvd, Unit 200
Winnipeg, MB, Canada R3T 1Y6