Legal

Privacy Policy

Effective September 30, 2026 · revision 1

Esta política se mantiene en inglés y la versión en inglés es la vinculante. Su acuerdo de servicios es un documento distinto: cuando el trato se lleva en español, se prepara en español y en inglés, y usted lo firma una sola vez. Si tiene dudas sobre esta política, escríbanos a admin@vstreamx.com.

VstreamX Studio Inc. (“VstreamX”, “we”, “us”) provides operations and software services to companies. This policy explains what personal information we collect through vstreamx.com and our client portals, how we use it, who processes it on our behalf, and the choices you have. We handle personal information in line with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA). We operate from Brandon, Manitoba. Manitoba has no private-sector privacy statute in force, so PIPEDA is the law that governs how we handle your personal information. The individual accountable for this policy is named in section 11, and section 12 says whose information this policy covers and whose it does not.

01

What we collect

  • Contact form. Your name or company, email address, service interest, message, optional budget range, and basic campaign context (UTM parameters and the referring page). This is stored in our database so we can respond to you.
  • Portal accounts. For clients: name, email address, and the records connected to the engagement — projects, milestones, deliverables, messages, support tickets, files you upload, and billing records.
  • Billing information. Invoices, payment status, dates, amounts, and a payment reference returned by our payment processor. We never see or store card numbers — see Payments below.
  • Proof of authority. When you electronically sign an agreement, or authorise us to keep your card on file for a plan, we record the IP address and browser your device reported at that moment, together with the exact wording you accepted. We keep this in full — it is not anonymized — because its only purpose is to show who gave that authority and when, if the agreement or a charge is ever disputed. This is separate from the website analytics described under Cookies & storage, where IP addresses are anonymized and are never linked to your account.
  • Site assistant. Messages you send to our website chatbot are processed by OpenAI, acting as a subprocessor, to generate replies. If you share your email in the chat to be contacted, we save the conversation with your inquiry. Please do not share sensitive personal information in the chat.
02

How we use it

We use personal information to respond to inquiries, deliver contracted services and operate client portals, issue and collect invoices, and send transactional email — replies to your messages, and account, project, or billing notifications.

We do not sell personal information, and we do not use it for third-party advertising.

03

Payments

Card payments are processed by Stripe. When you pay an invoice online, your card details are entered on and transmitted directly to Stripe’s systems — they never touch our servers. Stripe’s handling of your payment data is governed by Stripe’s privacy policy.

What we keep is the business record: the invoice, its amount and status, the payment date, and Stripe’s payment reference — the information required to account for the transaction and show it in your billing history. Where you authorise us to charge that card again on a plan, we also keep the authority itself: the exact words you accepted, the amount and cadence they state, and the IP address and browser recorded at the moment you accepted them.

04

AI-assisted operations

We use AI tooling, under human supervision, to help our team work — drafting replies, summarizing project information, and analyzing documents you share with us. In doing so, relevant content (for example an inquiry, a support ticket, or a project document) may be processed by OpenAI or Anthropic acting as subprocessors via their business APIs, which do not use the data to train their public models.

Work we deliver to you is reviewed by a person before it reaches you.

Two assistants are different, and we say so plainly: the assistant on our website and the assistant inside your client portal reply to you automatically, without a person reading the reply first.

05

Cookies & storage

On our public marketing pages we use Google Analytics to understand how visitors use the site (pages viewed, general region — IP addresses are anonymized) — and only if you accept the consent banner; choosing “Essential only” means no analytics loads at all. We do not use advertising cookies or cross-site tracking, and analytics is never loaded inside the business or admin portals. You can change your choice any time via Cookie Preferences in the footer; you can also opt out globally at tools.google.com/dlpage/gaoptout.

For abuse protection, our forms and app services use Google reCAPTCHA Enterprise (Firebase App Check) as strictly necessary security processing — it runs regardless of the analytics choice and is governed by Google's privacy policy.

Portal users receive functional storage only — an authentication session and a theme preference — which is required for the portal to work.

06

Service providers & international transfers

We rely on a small set of service providers to run VstreamX, each limited to its purpose:

  • Google Cloud / Firebase — hosting, database, file storage, and authentication.
  • Stripe — payment processing (see Payments).
  • OpenAI and Anthropic — supervised AI assistance (see AI-assisted operations).
  • Google Analytics — consented marketing-site analytics only.
  • Google Workspace — business email.
  • Meta (WhatsApp, Messenger and Instagram) — if you choose to message us on one of those channels, your messages pass through Meta’s platform under Meta’s own terms.
  • Independent contractors — the specialists who carry out client work are independent contractors rather than employees, and some may work from outside Canada. They handle personal information only to do that work, and our accountability for it (section 11) does not change.

Some of these providers process data on servers outside Canada, primarily in the United States. While in another jurisdiction, information is subject to that jurisdiction’s laws — which means it may be accessible to the courts, law enforcement and national security authorities of that country, under their laws and without notice to you or to us. We choose providers with strong, contractually committed security and privacy practices.

07

Retention

We keep personal information while it remains relevant to the business relationship. Automatic deletion is not switched on yet, so rather than promise a deletion that does not happen, here is what we keep and for how long:

  • Financial records — invoices, receipts, and payment records are retained for at least six years as required by Canadian tax law.
  • Signed agreements and proof of authority — a signed agreement, the IP address, browser and accepted wording recorded with it or with a card authority, and our audit log of account actions are kept with no end date at present, because they are the only evidence of what was agreed and who agreed to it. They are never used for anything else, and never for analytics or marketing.
  • Inquiries — we have not set a deletion period yet for inquiries from people who did not become clients, and nothing deletes them automatically today. You can ask us to delete yours at any time.
  • Everything else — you can request deletion at any time (see Your rights); we honour it except where a legal obligation requires keeping a record.
08

Your rights

You may request access to, correction of, export of, or deletion of your personal information by emailing admin@vstreamx.com. You may also withdraw your consent to our use of your personal information at any time, subject to legal or contractual restrictions and reasonable notice; tell us and we will explain what that would mean for your account and any engagement in progress before it takes effect. We respond within 30 days of receiving your request, as PIPEDA requires; if we need longer, we tell you within those 30 days why, and for how long. Those requests reach the accountable individual named in section 11. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada.

09

Security

Data is encrypted in transit with TLS and at rest on Google Cloud infrastructure. Access to client data is role-based and enforced by server-side security rules; app requests are attested with Firebase App Check; and payment credentials are held by Stripe, not by us.

If a breach creates a real risk of significant harm to you, PIPEDA requires us to report it to the Privacy Commissioner of Canada, to notify you as soon as feasible, and to keep a record of every breach. The individual named in section 11 is responsible for doing so. If you believe your information has been exposed, write to admin@vstreamx.com.

10

Updates to this policy

We may update this policy from time to time. The effective date above always reflects the current version, and material changes will be posted on this page.

11

Who is accountable

PIPEDA requires an organization to designate an individual who is accountable for its compliance, and to make that person’s identity available. For VstreamX Studio Inc. that individual is:

Ricardo Javier Sandoval Sandoval

Chief Financial Officer, VstreamX Studio Inc.

admin@vstreamx.com
Office B - 1043 Rosser Ave, Brandon MB R7A 0L5, Canada

That accountability covers all personal information in our custody, including information transferred to the service providers listed in section 06. Other people here handle personal information day to day; delegating the work does not move the accountability.

12

Whose information this covers

This policy covers personal information that we decide about: people who visit vstreamx.com, people who contact us, and the people at our client companies who use the portal. For that information VstreamX is the organization accountable under PIPEDA, and sections 01 to 11 apply to it.

It does not cover the information held inside a system we build or run for a client — the records that system keeps about that client’s own customers. That information belongs to the client. The client decides what is collected and why; where we touch it at all, we act on their written instructions and only to deliver the engagement. How it is handled is set out in the agreement we sign with that client and in the law of that client’s own country, not on this page. If you are a customer of one of our clients and want to know how your information is handled, ask them — they can answer that, and we cannot answer it for them.

Two things follow, and we would rather write them down than leave them implied. Where we do hold such information, our accountability for personal information in our custody still applies — section 11 does not stop at the boundary above. And a client’s own country may place duties on us directly, whatever this policy says; where it does, those duties are written into that client’s agreement rather than onto this page, so that one country’s law never quietly becomes every client’s.

Questions about privacy? Email admin@vstreamx.com.