Legal

Privacy Policy

This policy explains how StretchGroup Technologies Inc.(“StretchGroup,” “we,” “us”) collects, uses, shares, protects, and deletes personal information across StretchSuite and its applications, including accounts you connect to third-party platforms.

Effective July 11, 2026

1. Who we are

StretchSuite is an all-in-one business software suite operated by StretchGroup Technologies Inc.. This policy applies to stretchsuite.ca, the StretchSuite workspace and admin applications, and the individual StretchSuite apps (including StretchSocial, StretchCRM, StretchBooks, StretchMail, and others). Where an app has behavior specific to it, we call that out below.

2. Information we collect

We collect only what we need to provide and secure the service:

  • Account & identity: name, email, password (stored hashed), organization, and role.
  • Content you create: the data you put into the apps — contacts, posts, invoices, documents, messages, and files — which belongs to your organization.
  • Usage & device: log data, IP address, browser/device type, and feature usage, used to operate and secure the platform.
  • Payment: billing details processed by our payment processor; we do not store full card numbers.
  • Support: messages and context you send us when you request help.
  • Connected-account data: when you link a third-party account (see Section 5), the specific data that platform authorizes us to access.

3. How we use information

We use information to operate, maintain, secure, and improve the service; to provide the specific features you use; to authenticate you and enforce access controls; to process payments; to communicate with you about your account and support; and to comply with legal obligations. We do not sell your personal information, and we do not use your connected-account data for advertising.

4. Connected accounts & social integrations (StretchSocial)

StretchSocial lets you connect accounts you own on third-party platforms — such as LinkedIn, Meta (Facebook), and X (Twitter) — so you can schedule and publish content to them from your workspace. When you connect an account:

  • We use the platform’s official OAuth flow. We receive only the permissions (scopes) you approve — typically your basic profile/identity on that platform, your list of manageable Pages, and permission to publish content on your behalf, only when you direct us to.
  • We store the resulting access and refresh tokens encrypted at rest (AES-256-GCM) and use them solely to perform the actions you request (publishing scheduled posts, and reading back the performance metrics of posts you published).
  • We never post without your instruction, never message your contacts, and never sell or share this data with third parties.
  • You can disconnect any account at any time from StretchSocial. Disconnecting immediately deletes the stored tokens for that account. You can also revoke access directly in the third-party platform’s own settings.

Your use of each connected platform also remains subject to that platform’s own terms and privacy policy.

5. How we share information

We share information only with: service providers (“subprocessors”) that host, secure, and support the platform under contract; a payment processor for billing; and authorities where required by law. Within StretchSuite, your data is isolated to your organization and shared only with members you authorize. We do not sell personal information.

6. Data retention

We retain your information for as long as your account is active and as needed to provide the service and meet legal, tax, and security obligations. Connected-account tokens are retained only while the account is connected and are deleted on disconnect. When you close your account or request deletion, we delete or anonymize your personal information within a reasonable period, except where retention is legally required.

7. Your rights & data deletion

Subject to your jurisdiction, you have the right to access, correct, export, and delete your personal information, and to withdraw consent. To exercise any of these, or to request deletion of your data:

  • In-app: disconnect connected accounts in StretchSocial (deletes their tokens immediately), and use account settings to manage your data.
  • By request: email privacy@stretchsuite.ca with “Data deletion request” and the email address on your account. We will verify and process the request and confirm when complete.
  • Automated (platform) deletion: if you remove the StretchSuite app from a connected platform (e.g., Meta), that platform notifies us and we automatically purge the associated tokens and connected-account data for that platform.

8. Security

We protect information with encryption in transit (TLS) and encryption at rest for sensitive credentials (including all connected-account OAuth tokens), access controls scoped to your organization, audited administrative actions, and least-privilege service design. No system is perfectly secure, but we work to protect your data and to promptly address any issues.

9. Cookies & tracking

We use strictly necessary cookies to sign you in and keep the app secure, and limited analytics to understand and improve usage. We do not use third-party advertising trackers on the StretchSuite apps.

10. International transfers & children

We may process information in countries other than where you live; where we do, we use appropriate safeguards. StretchSuite is not directed to children under 16, and we do not knowingly collect their data.

11. Changes to this policy

We may update this policy from time to time. We will post the updated version here with a new effective date and, for material changes, provide additional notice.

12. Contact us

Questions or requests? Email privacy@stretchsuite.ca. We are StretchGroup Technologies Inc., and we will respond as promptly as we can.