Privacy Policy
Effective 2026-05-26. Last updated 2026-05-26.
Data controller: Stratos House AI Inc.
1. Who we are
This Privacy Policy is published by Stratos House AI Inc. (“Stratos”, “we”, “us”, or “our”), a British Columbia corporation (BC1590751, Business Number 779978576) with a registered office at 807-27 Alexander St, Vancouver, BC V6A 1B2, Canada.
It covers personal information we handle across our public marketing site at stratosagency.ai, the client portal at portal.stratosagency.ai, the invoice portal at invoice.stratosagency.ai, and the proposals portal at proposals.stratosagency.ai (together, the “Services”).
This policy is written to comply with the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and the British Columbia Personal Information Protection Act (PIPA). It is written in plain language so you can actually read it.
2. Information we collect
- Account information via Clerk: email address, name, profile photo, and the workspace and role you belong to.
- Payment information via Stripe: payment-method tokens and transaction metadata. We never see or store full card numbers, CVCs, or bank credentials.
- Usage analytics: page views, referrer, device type, approximate geographic region, and timing of portal actions.
- Communication logs: email and message history you exchange with us in connection with your engagement.
- Uploaded documents: contracts, briefs, brand assets, financial files, and any other content you upload as part of a Client engagement.
- Cookies and similar technologies: see Section 6.
3. How we collect it
- When you sign up or sign in via Clerk.
- When you fill out a form on stratosagency.ai or any of our subdomains.
- When you use the portal (clicks, navigation, document uploads, signatures).
- Through cookies and tracking pixels as described in Section 6.
- From third-party services like Clerk (authentication) and Stripe (payments), in each case governed by their own privacy policies linked in Section 7.
4. How we use it
- To provide and operate the Services.
- To communicate with you about your engagement, account, and security.
- To process payments and issue invoices.
- To improve the Services and diagnose problems.
- To comply with legal, tax, and accounting obligations.
We never sell your personal information to third parties. We do not share it with advertisers. We do not use it to train public machine-learning models.
5. Lawful basis for processing
Under PIPEDA we rely on the following bases, in order of preference:
- Consent: you give us your information knowingly to receive the Services.
- Contractual necessity: we need it to deliver what your SOW or MSA describes.
- Legitimate interest, where permitted: security monitoring, fraud prevention, basic operational analytics.
6. Cookies and tracking
We use two categories of cookies and no advertising cookies.
- Essential cookies for authentication and CSRF protection, set by Clerk. These are required for sign-in and session integrity.
- Analytics cookies via Vercel Analytics for aggregate, privacy-friendly usage metrics. No cross-site tracking. No third-party advertising identifiers.
7. Third parties we use
We use a small set of vetted sub-processors to operate the Services. Each is contractually bound to handle data on our instructions.
| Vendor | What it gets | Hosting region | Privacy policy |
|---|---|---|---|
| Clerk | Account identifiers, email, name, profile photo, session tokens | United States | Policy |
| Stripe | Payment-method tokens, transaction metadata, billing email | United States, Canada, Ireland | Policy |
| Firebase (Google Cloud) | Application data, uploaded documents, audit logs | North America (nam5 multi-region) | Policy |
| Vercel | Hosting, edge logs, anonymized analytics | United States | Policy |
| Anthropic | Prompts and document excerpts you submit for AI processing | United States | Policy |
| OpenAI | Prompts and document excerpts you submit for AI processing | United States | Policy |
| Cloudflare | DNS lookups, TLS termination, CDN request metadata | Global edge network | Policy |
| Sentry | Error stack traces, browser context, redacted user identifiers | United States | Policy |
We will disclose information when compelled by Canadian law (lawful court order or warrant) and will notify you unless prohibited from doing so.
8. Where your data is stored
Your personal information is stored and processed in Canada and the United States via the vendors listed above. Where data leaves Canada, we rely on contractual safeguards that provide a comparable level of protection as required by PIPEDA Principle 4.1.3. Because some processors operate in the United States, your information may be subject to disclosure under foreign law (for example, the United States CLOUD Act).
For AI processing specifically, prompts containing Client data are sent to providers (Anthropic, OpenAI) on accounts configured with no-training and no-retention settings where the provider offers them, and with zero data-retention agreements in place where contractually available.
9. How long we keep it
- Account data: the duration of our relationship plus 7 years to satisfy Canadian tax-record retention.
- Communications: the duration of our relationship.
- Uploaded documents: as specified in the SOW or MSA with the relevant Client.
- Portal session data: 30 days.
- Backups: 90 days rolling.
When you ask us to delete an account, we de-identify the user record within 30 days but retain transaction-tied evidence (signed contracts, paid invoices, audit trail) for the legal-retention window above.
10. Your rights under PIPEDA
You have the right to:
- Access the personal information we hold about you.
- Ask us to correct information that is wrong or out of date.
- Withdraw your consent, subject to legal and contractual constraints.
- Ask us to delete your account.
- File a complaint with our Privacy Officer or the Office of the Privacy Commissioner of Canada.
To exercise any of these rights, contact our Privacy Officer at arshia@stratosagency.ai. We respond to access and deletion requests within 30 days.
11. Security measures
We apply security controls aligned with PIPEDA Schedule 1 Principle 7, including:
- Encryption in transit (TLS 1.3) and at rest where reasonable.
- Role-based access controls and least-privilege internal access.
- Append-only audit logging for sensitive actions.
- Rate limiting and abuse detection on authentication endpoints.
- Rotation of service-account and API keys on a fixed schedule.
- Security incident notification to affected users and, where required, to the Office of the Privacy Commissioner of Canada within 72 hours of discovery of a breach that creates a real risk of significant harm.
12. Children's information
The Services are not directed at children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it.
13. Changes to this policy
We may update this policy as the Services or applicable law evolve. We will post any changes here with an updated effective date. Material changes will be notified to active Clients by email at least 14 days before they take effect.
14. Contact
Privacy Officer: Arshia Navabi
Email: arshia@stratosagency.ai
Phone: 604-499-7771
Mail: Stratos House AI Inc., 807-27 Alexander St, Vancouver, BC V6A 1B2, Canada
15. Office of the Privacy Commissioner of Canada
If you are not satisfied with how we have handled a privacy concern, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.