This Privacy Policy explains how UnionStack Software Inc. collects, uses, discloses, stores and protects personal information through unionstack.ca, the UnionStack platform, related applications and our business operations. In this policy, UnionStack Software Inc. is referred to as UnionStack, we, us or our.
UnionStack is designed for labour unions. The information handled through the platform can be sensitive. We use personal information only for identified purposes, limit access according to role and tenant, and apply contractual, organizational and technical safeguards appropriate to the information.
1. Scope and responsibility
Information UnionStack controls
UnionStack determines how personal information is handled when you visit our public website, contact us, request a trial, administer a UnionStack account, receive support, interact with our business, or when we use information to operate, secure and improve our services. For this information, UnionStack is accountable for the practices described in this policy.
Customer-controlled information
A union or other subscribing organization determines why and how its records are used in UnionStack. This customer-controlled information may include records about members, employees, representatives, organizers, event participants and other people connected with the customer. UnionStack handles that information to provide the service and according to the customer's instructions, our agreement with the customer and applicable law.
If your information was entered into UnionStack by a union or another subscribing organization, direct access, correction, deletion and consent questions to that organization first. UnionStack supports customers in responding to valid requests but generally cannot decide independently how their records should be used or deleted.
2. Information we handle
The information we handle depends on your relationship with UnionStack and on the features a customer chooses to use. It may include the following categories.
- Website and business inquiries, including your name, email address, organization, inquiry topic and message.
- Account and administration information, including contact details, sign-in identifiers, roles, permissions, authentication events, account status and support communications.
- People and membership records, including contact information, identifiers, membership details, positions, classifications, relationships, organizations and agreements.
- Case and grievance information, including participants, notes, deadlines, evidence, documents, decisions and correspondence.
- Communications information, including connected mailbox configuration, sender and recipient information, message content, attachments, delivery status, consent and suppression records.
- Meeting, collaboration and event information, including attendance, registrations, agendas, minutes, emergency contacts and accommodation or accessibility requirements.
- Organizing and strike-operation information, including campaign relationships, assessments, evidence, attendance, scheduling, alerts, accessibility constraints, incidents and payment records.
- Finance information, including dues and remittance records, expenses, receipts, payment status, banking information, tax identifiers and tax or withholding documents where a customer uses those functions.
- Member-site and digital membership-card information, including portal activity, eligibility, card identifiers and information selected for an issued wallet pass.
- Technical and security information, including IP address, browser and device information, request timestamps, diagnostic events, audit history and security alerts.
- Subscription and payment information. Stripe may collect payment-card details directly. UnionStack may receive customer, subscription, invoice and payment-status information from Stripe, but does not need to store a card security code.
Sensitive information
Customer-controlled records may reveal union membership, labour-relations activity, financial details, government identifiers, accessibility requirements, emergency information or other information considered sensitive under applicable law. Customers should collect and use sensitive information only when it is necessary and authorized. UnionStack applies additional access, encryption, audit, retention and disclosure controls where supported by the relevant feature.
Do not send member records, case details or other confidential information through the public website contact or privacy-request forms. We will request a secure method when additional information is needed to verify or fulfil a request.
3. Where information comes from
We may receive personal information directly from you, from a UnionStack customer or its authorized users, through an authorized import or API, from a connected mailbox or integration, from an identity or payment provider, from public registration forms, and automatically through service operation and security logging.
A customer chooses which optional integrations to configure and is responsible for having authority to connect an account, import information and instruct UnionStack to process that information.
4. Why we use information
- Provide, configure and administer UnionStack services for customers and authorized users.
- Create and protect accounts, authenticate users and enforce roles and permissions.
- Store connected customer records and perform workflows initiated or configured by authorized users.
- Deliver support, answer inquiries and communicate about trials, subscriptions, service changes and security matters.
- Process subscriptions, invoices and payments.
- Detect abuse, prevent fraud, investigate security events, maintain audit records and protect the availability and integrity of the services.
- Monitor reliability, diagnose errors and improve service operation.
- Meet legal, regulatory, accounting and contractual obligations and establish, exercise or defend legal claims.
- Use optional analytics on the public website only after the visitor has accepted analytics cookies.
Depending on the context and applicable law, we rely on consent, performance of a contract, compliance with legal obligations and legitimate business purposes that do not override an individual's rights. A customer is responsible for determining the authority that applies to its use of customer-controlled information.
5. When information is disclosed
UnionStack does not sell personal information. We disclose information only as needed to provide and secure the services, follow a customer's authorized instructions, complete a transaction, respond to a valid legal requirement, protect rights and safety, or complete a corporate transaction subject to appropriate safeguards.
Authorized users within a customer may see information according to that customer's configuration, record relationships and role-based permissions. Customers are responsible for assigning appropriate access and reviewing it as responsibilities change.
Service providers and optional integrations
We use service providers under contractual or equivalent safeguards. Depending on deployment and customer configuration, these may include Microsoft Azure for hosting and storage, Microsoft or Google for identity and connected email, customer-selected IMAP and SMTP providers, Stripe for subscription payments, Mailchimp for authorized audience synchronization, Google Maps Platform for address assistance, Google Wallet and Apple Wallet for requested membership passes, Apple Push Notification service for pass updates, and operational monitoring, email-delivery, security-scanning and reverse-proxy providers.
An integration receives only the information needed for the selected function. Providers may use subprocessors or disclose information where legally required. Their independent handling of information is also governed by their terms and privacy notices. Customers should review optional provider paths during configuration and procurement.
6. Data location and international processing
UnionStack production services and primary customer data are hosted in Microsoft Azure Canada Central. Canadian hosting does not mean every enabled data flow remains only in Canada. Optional providers selected by UnionStack or a customer may process limited information in another province, country or legal jurisdiction. Information processed elsewhere may be accessible to courts, law enforcement or regulators under the laws of that jurisdiction.
UnionStack remains accountable for providers it engages to process personal information on its behalf and uses contractual, technical and organizational measures intended to provide a comparable level of protection. A customer remains responsible for evaluating providers it selects or connects.
7. Google user data
When an authorized customer administrator connects a Gmail mailbox, UnionStack accesses the connected account only for the email functions the administrator authorizes. This may include mailbox identity, message metadata, sender and recipient details, message bodies and attachments. UnionStack uses this information to receive and send email, maintain threaded correspondence, associate messages with authorized operational records, support case intake configured by the customer, and diagnose mailbox delivery or connection problems.
Google mailbox information may be stored in the customer's UnionStack tenant so authorized users can work with correspondence and retain an auditable operational record. Access is governed by customer roles and record permissions. UnionStack does not use Google user data for advertising, does not sell it, and does not permit people to read it except when necessary to provide support or security, comply with law, or perform an action authorized by the customer.
A customer administrator can disconnect a Google mailbox. Disconnecting stops new mailbox synchronization but does not automatically delete correspondence already retained as a customer record. The customer controls the retention and deletion of stored correspondence, subject to configured retention rules, legal holds and applicable law. Requests concerning stored customer correspondence should be directed to the customer.
UnionStack's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. UnionStack presents additional information during the mailbox connection process so an administrator can understand the requested access before authorizing it.
8. Cookies and public-site analytics
The public UnionStack website does not load Google Analytics unless it is configured by UnionStack and you choose Accept analytics. If enabled and accepted, Google Analytics uses first-party cookies and receives information such as a randomly generated browser identifier, visited pages, referral information, browser and device characteristics, approximate location and event timestamps. Advertising personalization and Google Signals are disabled in the website integration.
Your analytics choice is stored in your browser so the site can respect it on later visits. You can change the choice on the Cookie information page. Search Console verification, the sitemap, RSS and llms.txt do not set analytics cookies. Authenticated UnionStack services may use essential cookies or similar storage for sign-in, security, session continuity and user preferences. Essential technologies cannot always be disabled without ending the related function.
9. Retention and deletion
UnionStack keeps personal information only as long as reasonably necessary for its identified purpose, a customer's documented instructions, contractual requirements, security, dispute resolution and applicable law. Retention depends on the type and context of the information rather than on a single period.
- Customer-controlled records are retained according to the customer's configuration and instructions, subject to product retention controls, legal holds, backups and applicable law.
- Account and subscription information is retained while needed to provide and administer the service and for a reasonable period after the relationship ends.
- Billing, accounting and certified tax or withholding records are retained for the period required by tax, employment, accounting and other applicable requirements. Some certified tax records may require retention for six years after the relevant tax year.
- Support, sales and privacy inquiries are retained long enough to respond, keep an appropriate record and meet legal obligations.
- Security, audit and diagnostic records are retained according to their risk, operational purpose and configured retention class.
- Backups are protected and expire through controlled backup cycles. Deletion from active systems may not immediately remove information from an immutable backup, but restored information remains subject to the original deletion requirement.
Where deletion is not permitted or technically immediate, we restrict further use and retain only what is required. Aggregated or de-identified information that cannot reasonably identify an individual may be retained for operational analysis.
10. Security safeguards
UnionStack uses administrative, technical and physical safeguards appropriate to the sensitivity of the information. These include tenant separation, role-based authorization, encryption in transit and at rest where supported, protected credentials, audit records, secure development practices, monitoring, backup controls and incident-response procedures.
No internet service or storage system can be guaranteed completely secure. Customers and users must protect credentials, use appropriate access settings and notify UnionStack promptly about suspected unauthorized access. Additional information is available on the Security and trust page.
11. Access, correction and privacy choices
Depending on applicable law, you may ask for access to personal information UnionStack controls, request correction, withdraw consent for future optional processing, or ask about retention and disclosure. Rights can be limited where another person's privacy, legal privilege, a legal hold, security, contractual obligations or another lawful exception applies.
Submit a request at unionstack.ca/data-request or email legal@unionstack.ca. We may need to verify your identity and clarify the scope before responding. We will not ask you to place sensitive records in the public request form. If the request concerns information controlled by a UnionStack customer, we will normally direct the request to that customer or assist the customer with its response.
You may change your public-site analytics choice at unionstack.ca/cookies. You may unsubscribe from optional UnionStack marketing using the instructions in the message. Withdrawing consent does not affect processing already completed and may not apply to information required to provide a requested service or meet legal obligations.
12. Minors
UnionStack does not direct its public website, trials or customer administrator accounts to children. A customer may have lawful records about members, dependants, event participants or other individuals who are minors. The customer is responsible for obtaining any required authority and using age-appropriate notices or consent. UnionStack handles those records only to provide the service under the customer's instructions and applicable law.
13. Changes to this policy
We may update this policy when our practices, services, providers or legal obligations change. We will publish the revised date at the top of the policy. When a change materially affects how we handle personal information, we will provide additional notice where appropriate or required.
14. Contact the Privacy Officer
Questions, privacy requests and complaints may be directed to the Privacy Officer at legal@unionstack.ca or through unionstack.ca/data-request.
UnionStack Software Inc., 224 Eagle Pl, Regina, Saskatchewan S4Y 1H4, Canada
We will review a complaint, investigate where appropriate and explain the outcome. You may also contact the privacy regulator with jurisdiction over the matter.