Privacy Policy
Effective date: March 1, 2026
1. Introduction
BondStack Technologies (“BondStack”, “we”, “our”) is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.
2. Information We Collect
- Contact form data: name, email address, business type, and the challenge or message you describe
- Free tool data: business type, department/pain points you enter, and email address (collected at report gate)
- Usage data: pages visited, time on site (via analytics — no personally identifiable information stored)
- Communications: emails or calls you initiate with us
We do not collect payment information directly. We do not collect sensitive personal information such as SIN, health data, or financial account numbers.
3. How We Use Your Information
- To respond to your inquiry or book a discovery call
- To deliver your free AI automation report
- To send you information about BondStack services you've expressed interest in (with your consent under CASL)
- To improve our website and free tool
- To comply with legal obligations
We will not sell, rent, or trade your personal information to third parties.
4. Legal Basis and Consent (CASL)
By submitting a contact form or free tool request, you provide express consent to receive follow-up communications from BondStack related to your inquiry. You may withdraw consent at any time by replying “unsubscribe” to any email or contacting us at info@bondstack.ca.
5. Third-Party Service Providers
We use the following trusted third-party services that may process your data on our behalf:
- Anthropic (Claude API) — AI processing of your free tool inputs to generate automation recommendations. Inputs are not stored by BondStack beyond session processing.
- Supabase — Database hosting for lead capture (name, email, business type). Hosted in cloud infrastructure.
- Vercel — Website hosting and serverless functions. May log IP addresses and request metadata.
- GoHighLevel (GHL) — CRM platform used to manage client relationships and follow-up communications.
Each provider is contractually bound to protect your data and use it only for the services they provide to us.
6. Data Retention
- Contact form submissions: retained for up to 2 years or until you request deletion
- Free tool reports: report tokens expire after 48 hours; email/business type retained for lead follow-up
- We will delete your personal information upon request
7. Your Rights Under PIPEDA
You have the right to:
- Access your personal information we hold
- Request corrections to inaccurate data
- Withdraw consent for marketing communications
- Request deletion of your data
To exercise these rights, contact us at info@bondstack.ca.
8. Security
One of our co-founders holds an ISO Internal Auditor certification and teaches Information Security at a renowned Canadian polytechnic. Every system we build — including this website — is reviewed for data exposure risks before it goes live. We use HTTPS, access controls, and minimal data retention as standard practice.
Security Disclaimer: While we apply industry-recognized security practices and our team holds relevant certifications, no system or data transmission over the internet can be guaranteed to be 100% secure. BondStack does not warrant or guarantee absolute security of your information. You provide your personal information at your own risk and are responsible for maintaining the confidentiality of any access credentials you hold.
9. Cookies
Our website uses minimal, functional cookies. We do not use third-party advertising cookies. Analytics, if any, use privacy-first tools that do not track individual users.
10. Changes to This Policy
We may update this policy periodically. The effective date at the top of this page will reflect the most recent revision. Continued use of our website constitutes acceptance of any updates.
11. Contact Us
For privacy inquiries: