Privacy Policy

Last Updated: Sept 17, 2026

1. Introduction

SubtleZen Inc. (“SubtleZen”, “Company”, “we”, “our”, or “us”) respects your privacy and is committed to protecting personal information.

This Privacy Policy explains how we collect, use, disclose, store, transfer, and protect personal information when you access or use our websites, applications, products, services, and related offerings (collectively, the “Service”).

This Privacy Policy applies to:

  • Visitors to our website;
  • Users of our Service;
  • Customers and prospective customers;
  • Contractors, consultants, employees, and other individuals whose information may be processed through the Service;
  • Individuals who communicate with us.

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.


2. About Us

SubtleZen Inc. is a corporation organized under the laws of Alberta, Canada.

For privacy-related questions, requests, or concerns, contact:

Email: support@subtlezen.com


3. Scope of this Privacy Policy

This Privacy Policy applies to:

  • Our marketing website;
  • Our web application and platform;
  • Customer organizations, projects, and workspaces;
  • Customer support interactions;
  • Communications with us;
  • Third-party integrations connected to the Service.

This Privacy Policy does not apply to third-party websites, products, services, or applications that are not owned or controlled by SubtleZen.


4. Information We Collect

We collect information directly from users, from organizations using the Service, through integrated third-party services, and automatically through operation of the Service.

4.1 Account Information

We may collect:

  • Name;
  • Email address;
  • Job title;
  • Profile photo;
  • Phone number;
  • Account credentials;
  • Organization membership information.

4.2 Organization Information

We may collect:

  • Organization name;
  • Company address;
  • Billing information;
  • Subscription information;
  • Administrative settings.

4.3 Contractor and Workforce Information

Customers may provide information relating to contractors, consultants, vendors, employees, and other workforce participants, including:

  • Names;
  • Email addresses;
  • Roles and responsibilities;
  • Hourly rates;
  • Compensation information;
  • Country or location information;
  • Time tracking records;
  • Project participation information;
  • Performance-related information.

Customers are responsible for ensuring they have appropriate rights and permissions to provide such information to us.

4.4 Project and Operational Information

We may collect:

  • Project names;
  • Task descriptions;
  • Milestones;
  • Budget information;
  • Resource allocations;
  • Time entries;
  • Comments and notes;
  • Contract documents;
  • Invoices;
  • Receipts;
  • Purchase orders;
  • Other records or documents uploaded by customers.

4.5 Integration Data

When customers connect third-party services, we may collect information available through those integrations, including:

  • Issues and tickets;
  • Pull requests;
  • Commits;
  • Branch information;
  • Repository metadata;
  • Usernames;
  • Reviews and approvals;
  • Project tracking information;
  • Work activity metadata.

The Service is not designed to collect or store customer source code as part of its normal operation. However, source code, code snippets, or technical content may be incidentally included in information imported from integrated services or submitted by users.

4.6 Billing Information

We may collect:

  • Billing contact information;
  • Subscription information;
  • Transaction records;
  • Payment status information.

Payment card information is processed directly by our payment processor and is not stored within our systems.

4.7 Usage and Technical Information

We may automatically collect:

  • Login activity;
  • Authentication records;
  • IP addresses;
  • Browser type;
  • Device information;
  • Operating system information;
  • Session information;
  • Usage statistics;
  • Error logs;
  • Security logs;
  • Audit records.

4.8 Cookies and Similar Technologies

We use cookies and similar technologies to:

  • Authenticate users;
  • Maintain sessions;
  • Improve Service functionality;
  • Analyze Service usage;
  • Enhance security;
  • Measure website and product performance.

5. Sources of Information

We collect information:

  • Directly from users;
  • From customer organizations;
  • Through integrated third-party services;
  • Through cookies and analytics technologies;
  • From payment processors;
  • From service providers acting on our behalf.

6. How We Use Information

We may use information to:

  • Provide and operate the Service;
  • Create and manage accounts;
  • Authenticate users;
  • Process subscriptions and payments;
  • Deliver requested features;
  • Provide customer support;
  • Generate reports and analytics;
  • Track projects and work activities;
  • Calculate budgets, costs, and utilization metrics;
  • Improve and develop the Service;
  • Maintain security;
  • Detect fraud and abuse;
  • Comply with legal obligations;
  • Communicate with users;
  • Send product updates and service announcements;
  • Send marketing communications where permitted by applicable law.

7. AI and Analytical Features

We may use artificial intelligence, machine learning, statistical models, and other analytical technologies to provide insights, recommendations, summaries, forecasts, reporting, trend analysis, and performance-related analytics.

When we use third-party AI service providers to process Customer Data for AI-enabled features, we use provider terms, settings, or contractual commitments that do not permit those providers to use Customer Data to train or improve their own models. Customer Data may be processed by such providers only as necessary to provide and secure the applicable AI-enabled functionality or comply with applicable law.

This restriction does not apply to information that has been aggregated, anonymized, or de-identified so that it no longer reasonably identifies a Customer, Organization, or individual, where such use is permitted by applicable law.

Such tools are intended to assist customers in evaluating operational, project, and workforce information.

AI-generated insights, recommendations, or analytics may contain inaccuracies and should not be relied upon as the sole basis for employment, contracting, compensation, disciplinary, legal, or other significant decisions.

SubtleZen does not make employment, contracting, compensation, disciplinary, promotion, termination, or other legally significant decisions on behalf of customers.

Customers remain solely responsible for decisions relating to workforce management, contractor relationships, employment matters, and business operations.


Where applicable under GDPR, UK GDPR, and similar laws, we process personal information based on one or more of the following legal bases:

  • Performance of a contract;
  • Compliance with legal obligations;
  • Legitimate business interests;
  • Consent;
  • Protection of vital interests;
  • Public interest where applicable.

Our legitimate interests may include:

  • Operating and improving the Service;
  • Maintaining security;
  • Preventing fraud;
  • Providing customer support;
  • Developing new features;
  • Measuring and improving Service performance.

Where SubtleZen acts as a data processor, the customer organization is generally responsible for determining the applicable legal basis for processing Customer Data.


9. Controller and Processor Roles

Depending on the circumstances, SubtleZen may act as either a data controller or a data processor.

When organizations upload workforce, contractor, project, financial, or operational data to the Service, the customer organization generally acts as the data controller and SubtleZen acts as a data processor.

When we process information relating to website visitors, prospective customers, account holders, and business contacts, we generally act as a data controller.


10. Customer Responsibilities

Customers are responsible for ensuring that they have the necessary rights, permissions, notices, consents, and legal bases required to collect, use, and disclose information submitted to the Service.

Customers are solely responsible for determining the purposes and means of processing information they upload to the Service and for complying with applicable privacy, employment, labor, and data protection laws.

SubtleZen does not independently verify the accuracy or legality of information submitted by customers.


11. Sharing and Disclosure of Information

We do not sell personal information and do not share personal information for cross-context behavioral advertising as those terms are defined under applicable privacy laws.

We may disclose information:

  • To service providers;
  • To hosting providers;
  • To payment processors;
  • To analytics providers;
  • To AI and machine learning service providers where necessary to provide AI-enabled features;
  • To communication providers;
  • To professional advisors;
  • To affiliated entities;
  • To law enforcement authorities when required by law;
  • In connection with a merger, acquisition, financing, reorganization, or sale of assets.

12. Service Providers and Subprocessors

We may use third-party service providers and subprocessors to support operation of the Service, including providers supporting:

  • Cloud hosting;
  • Databases;
  • Authentication;
  • Email delivery;
  • Analytics;
  • AI and machine learning services;
  • Monitoring;
  • Payment processing;
  • Customer support;
  • Security services.

Current or anticipated providers may include:

  • Supabase;
  • Stripe;
  • Resend;
  • Netlify;
  • Cloudflare;
  • PostHog.

Our service providers and subprocessors may change from time to time as our business and technical infrastructure evolve.

Customers may contact us regarding material questions relating to subprocessors and data processing practices.


13. International Data Transfers

We may process and store information in countries other than the country where the information was originally collected.

Information may be processed and stored in the United States and other jurisdictions where our service providers operate.

Where required by applicable law, we implement appropriate safeguards for international transfers of personal information, which may include contractual protections, adequacy decisions, or other legally recognized transfer mechanisms.


14. Data Retention

We retain information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce agreements.

Customer Data

Customer Data remains under the control of the customer organization.

If a subscription is cancelled or expires, access to certain features of the Service may be suspended or limited. Unless otherwise required by law, Customer Data will generally remain stored within the Service until it is deleted by the customer or removed in accordance with the customer’s instructions.

Customers may delete organizations, projects, records, or other data through available Service functionality. Following a deletion request, information may be retained in active systems for up to 90 days to facilitate recovery, dispute resolution, legal compliance, system integrity, and operational purposes before being permanently deleted or anonymized.

Deletion of a project, organization, or other customer-controlled record may result in the deletion of associated synchronized data stored within the Service.

Deleted information may remain in backups or archival systems until those backups or archives are rotated, overwritten, or deleted in accordance with our backup retention practices.

Backups

System backups may be retained for up to 12 months.

Financial and Tax Records

Financial, accounting, billing, transaction, and tax records may be retained for up to seven years or longer where required by law.


15. Security

We implement reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction.

Such safeguards may include:

  • Encryption in transit;
  • Encryption at rest;
  • Role-based access controls;
  • Authentication mechanisms;
  • Security monitoring;
  • Audit logging;
  • Access restrictions.

Access to customer data is limited to authorized personnel and service providers who require access to perform their responsibilities.

No method of transmission or storage can be guaranteed to be completely secure.


16. Security Incidents

While no system can guarantee absolute security, we maintain processes designed to detect, investigate, and respond to security incidents.

Where SubtleZen acts as a data controller and applicable law requires notification, we will notify affected individuals, regulators, or other parties within the timeframes required by applicable law.

Where SubtleZen acts as a data processor for Customer Data, we will notify the relevant customer without undue delay after becoming aware of a personal information or personal data breach affecting that Customer Data and will provide reasonable assistance to support the customer’s legal obligations.

For example, where GDPR or UK GDPR applies, controllers may be required to notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a personal data breach unless the breach is unlikely to result in risk to individuals. Under Canadian law, organizations may be required to notify affected individuals and the Office of the Privacy Commissioner of Canada as soon as feasible where a breach creates a real risk of significant harm.


17. Your Privacy Rights

Depending on your location and applicable law, you may have rights including:

  • Access;
  • Correction;
  • Deletion;
  • Restriction of processing;
  • Data portability;
  • Objection to processing;
  • Withdrawal of consent.

To exercise privacy rights, contact:

support@subtlezen.com

We may request information necessary to verify your identity before responding to a request.


18. California Privacy Rights

Residents of California may have rights under applicable California privacy laws, including rights to:

  • Know what personal information is collected;
  • Access personal information;
  • Correct inaccurate information;
  • Request deletion;
  • Limit certain uses of personal information where applicable.

SubtleZen does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are defined under applicable California privacy laws.

To the extent we process information that constitutes sensitive personal information under applicable California privacy laws, we use and disclose such information only as reasonably necessary to provide the Service, maintain security, prevent fraud, comply with legal obligations, or for other purposes permitted by applicable law.


19. European and United Kingdom Privacy Rights

Individuals located in the European Economic Area, Switzerland, and the United Kingdom may have rights under applicable data protection laws.

Where SubtleZen acts as a processor on behalf of a customer organization, requests relating to customer-controlled information should generally be directed to the relevant customer organization.

Individuals in the EEA, UK, or Switzerland may also have the right to lodge a complaint with their local data protection supervisory authority.

If we receive a data subject request relating to information for which a customer organization is the data controller, we will promptly notify the relevant customer and provide reasonable assistance as required by applicable law.


20. Canadian Privacy Rights

Individuals may have rights under applicable Canadian privacy laws, including rights to access and correct personal information.

Individuals may also challenge our compliance with applicable privacy laws by contacting us using the information provided in this Privacy Policy.


21. Cookies and Analytics

We use cookies and similar technologies for the following purposes:

Essential Cookies

These cookies are necessary for:

  • User authentication;
  • Session management;
  • Security and fraud prevention;
  • Core Service functionality.

Analytics Cookies

These cookies help us:

  • Understand how users interact with the Service;
  • Measure product performance;
  • Improve functionality and user experience.

Third-Party Technologies

We may use third-party providers that place cookies or similar technologies in connection with authentication, payment processing, website performance, analytics, and security.

Where required by applicable law, we will request consent or provide choices for non-essential cookies and similar technologies.

Users can manage cookie preferences through browser settings. Disabling certain cookies may affect functionality of the Service.


22. Marketing Communications

We may send:

  • Product announcements;
  • Service updates;
  • Security notifications;
  • Newsletters;
  • Marketing communications.

Users may unsubscribe from marketing communications using available unsubscribe mechanisms.

Service-related communications may continue where necessary to provide the Service.


23. Children’s Privacy

The Service is intended for business users and is not directed to children under the age of 18.

We do not knowingly collect personal information from children under 18.

If we become aware that personal information from a child has been collected, we will take reasonable steps to delete it.


24. Data Processing Addendum

For customers subject to GDPR, UK GDPR, or similar data protection laws, SubtleZen may make available a Data Processing Addendum (“DPA”) governing the processing of customer data.

Customers who require a DPA or have questions regarding data processing requirements may contact us at:

support@subtlezen.com


25. Changes to this Privacy Policy

We may update this Privacy Policy from time to time.

If material changes are made, we may provide notice through the Service, by email, or by other reasonable means.

The updated version becomes effective upon posting unless otherwise stated.


26. Contact Us

If you have questions regarding this Privacy Policy or our privacy practices, contact:

SubtleZen Inc.
Alberta, Canada

Email: support@subtlezen.com