Tscale Logotscale

Privacy Policy

Effective date: 2026-07-10 · Last updated: 2026-08-01

This Privacy Policy explains how Tscale Solution collects, uses, stores, and protects personal information across everything we do: our website, our digital-marketing services, the customer dashboard we operate, and the public link-hub pages we host for our clients. It is organized around the ten fair information principles of Canada's federal privacy law, the Personal Information Protection and Electronic Documents Act (PIPEDA), and the provincial privacy laws that apply where we operate.

1. Who we are

Tscale Solution ("tscale", "we", "us") is a Canadian company, federally incorporated under the Canada Business Corporations Act (CBCA), with its head office in New Westminster, British Columbia. We serve customers across Canada, with operations centred in Metro Vancouver.

We provide website design and production, digital marketing (including Google Ads, Google Local Services Ads, search engine optimization, and social media), a customer dashboard at dash.tscale.ca, and public link-hub pages that our clients use to share their services.

2. Who this policy covers

This policy applies to:

  • Website visitors — people who browse tscalesolution.com and the sites we build.
  • Dashboard customers — businesses with an account on our customer dashboard.
  • Link-hub visitors — people who open a public link-hub page we host for a client.
  • Prospective customers — people who contact us through a form, the chat widget, or a tracked phone number.

3. Information we collect

We collect only what we need for the purposes described in this policy:

CategoryWhat it includesSource
Contact & inquiry detailsName, phone number, email address, and the message you send usA website form, the chat widget, or a tracked phone number
Account dataLogin credentials, your business profile, and dashboard settingsProvided when you open a customer dashboard account
Service-delivery dataInformation generated while we build your website and run your marketing (e.g. campaign settings, content you supply)Created in the course of delivering our services to you
Attribution & campaign dataThe page, source, or campaign an inquiry came from (UTM and similar web parameters)Standard web parameters when you arrive from a search or advertisement
Link-hub click countsAggregate, first-party counts of which links visitors tap on a client's link-hub page, plus an estimate of how many different people visitedLink-hub pages we host for clients (one first-party analytics cookie — see Principle 4)
Technical & security dataDevice and browser type, approximate (city-level) location, and aggregate site-usage measured by Google Analytics 4Collected automatically while you browse this site
Client lead data (processed for our clients)Contact and inquiry details that individuals submit to our clients through the tools we operate for themOur clients' own forms and tracked numbers

Two details are worth calling out:

  • Phone inquiries: we record the caller number, time, duration, and whether the call was answered. Calls are not recorded. Tracking numbers simply forward to the business's regular phone line and note which advertising source the call came from.
  • Website analytics are aggregate: the site-usage data above is collected via Google Analytics 4 while you browse — before and regardless of whether you contact us — and is not linked to your name or contact details.

4. Our roles: controller and service provider

We play two different roles depending on whose information is involved:

  • As the organization responsible (controller) — for personal information collected through our own website, marketing, and dashboard accounts, we decide the purposes and are accountable for it under this policy.
  • As a service provider (processor) — for lead data that individuals submit to our clients through the tools we build and operate for them, we process that data only on the client's behalf and under the client's instructions.

If you submitted your information to one of our clients (for example, through a clinic's own contact form) and want to access, correct, or delete it, that client is the organization responsible for it — we will direct your request to them and assist as needed.

5. Why we collect it and our legal basis

We collect and use personal information to respond to your inquiry; to route it to the right business and staff member; to follow up if a call was missed; to deliver the website and marketing services you have engaged us for; to operate and secure the customer dashboard; and to measure, in aggregate, how visitors use this website and which marketing channels inquiries come from.

Our legal basis under PIPEDA is your consent and, where applicable, the performance of a contract with you. We do not sell personal information, and we do not use it to advertise to you.

6. How we handle your information — PIPEDA's ten principles

The following ten sections track the fair information principles of PIPEDA, which govern how we collect, use, disclose, and protect personal information.

Principle 1 — Accountability

We are responsible for the personal information under our control. We have designated a Privacy Officer who is accountable for our compliance with this policy and applicable privacy law:

Daniel Kim, Privacy Officer
daniel.kim@tscalesolution.com

Principle 2 — Identifying purposes

We identify why we collect personal information at or before the time of collection. The purposes are those described in Section 5; if we ever want to use your information for a new purpose, we will identify it and, where required, seek your consent.

Principle 3 — Consent

By submitting a form, starting a chat, or calling a tracked number after seeing the posted notice, you consent to the collection and use of your information for the purposes above. Aggregate website analytics are collected when you browse this site and are not tied to submitting an inquiry. You may withdraw your consent at any time by contacting our Privacy Officer, subject to legal or contractual limits; we will explain any consequences of withdrawal.

Principle 4 — Limiting collection

We collect only the information needed for the purposes we have identified, by fair and lawful means.

Our link-hub pages set one cookie, and it only counts visits. It is a first-party analytics cookie holding a randomly generated number — no name, no email, no IP address — so the business whose page it is can estimate how many different people opened the page and how many came back. It expires after about 13 months. Apart from that, these pages record first-party counts of page views and link taps, a coarse device class (for example mobile or desktop), and a hash of the visitor's IP address and browser user-agent taken with a salt that changes daily and is deleted after 48 hours — the hash is what allows a single day to be counted when there is no cookie, it cannot be linked across days or pages, and neither the IP address nor the user-agent is stored. Every visitor number produced this way is an estimate, not an exact count. These pages use no advertising pixels, perform no cross-site tracking of visitors, and do no device fingerprinting. Visitors can switch all of this off — cookie and counting alike — from the "Cookies" link at the bottom of any link-hub page, which opens our Cookie Policy; declining stores one further cookie that holds the value 1 and no identifier, so that we remember the refusal. Nothing is set and nothing is recorded at all when a browser sends a Do Not Track or Global Privacy Control signal.

Principle 5 — Limiting use, disclosure, and retention

We use and disclose personal information only for the purposes it was collected for, and we keep it only as long as needed:

  • Raw attribution data (UTM): retained for 30 days, then deleted or reduced to aggregate counts.
  • Inquiry message text: the free-text content of your inquiry is automatically deleted 90 days after receipt.
  • Account and service-delivery data: kept for the duration of our engagement with you, plus any period required for legal holds or business records, then deleted.
  • Client lead data (service-provider role): retained and deleted according to each client's instructions.

Principle 6 — Accuracy

We keep personal information as accurate, complete, and up to date as is necessary for the purposes for which it is used. You can ask us to correct information that is inaccurate or out of date.

Principle 7 — Safeguards

We protect personal information with safeguards appropriate to its sensitivity, including:

  • Encryption in transit (TLS) for data moving between your browser and our systems.
  • Role-based access so staff can reach only the data their role requires.
  • Row-level security enforcing per-tenant isolation, so one business's data cannot be reached from another's context.
  • Access logging — every view of your contact details is recorded.

Principle 8 — Openness

We make our privacy practices readily available. This policy describes what we collect, why, who processes it, and how to reach our Privacy Officer, and we keep it current.

Principle 9 — Individual access

You may request access to the personal information we hold about you, ask us to correct it, or withdraw your consent. Contact our Privacy Officer (see Principle 1). We respond within 30 business days. For information you submitted to one of our clients, see Section 4.

Principle 10 — Challenging compliance

If you have a concern about how we handle your personal information, please raise it with our Privacy Officer first. If you are not satisfied, you may contact the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, for matters within its jurisdiction, the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca).

7. Google user data (Google Calendar integration)

We are building an optional Google Calendar integration for the customer dashboard. If you choose to connect your Google account, the following applies.

  • Scope requested: https://www.googleapis.com/auth/calendar.readonly (read-only access).
  • What we access: your calendar event titles, times, and basic event details.
  • Why: to display your today's and upcoming schedule inside your customer dashboard.
  • How it is handled: this information is displayed in your dashboard and is not stored beyond the temporary caching needed to display it. It is never shared with third parties and is never sold.
  • Not used for AI/ML: we do not use Google Calendar data to develop, improve, or train generalized artificial-intelligence or machine-learning models.

tscale's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke tscale's access to your Google account at any time at myaccount.google.com/permissions.

8. Service providers and international transfers

We use a small number of service providers under contract to deliver and secure our services:

ProviderRoleHosting region
SupabaseSecure database and authenticationUnited States (AWS us-west-2, Oregon)
VercelWebsite and application hostingUnited States
ChatwootChat widgetUnited States
WhatConvertsPhone-call tracking (metadata only, no recordings)United States
CloudflareTurnstile bot protection, plus network and securityUnited States / global
ResendTransactional email to staff (name and inquiry channel only — never your message text)United States
StripePayment processing for dashboard customersUnited States
Google LLCGoogle Analytics (aggregate site usage), Google Ads measurement, and the planned Google Calendar API integrationUnited States
UpstashInfrastructure servicesUnited States

Some of the providers above store or process information outside Canada (currently the United States). While outside Canada, information may be subject to the laws of those jurisdictions, including lawful access by their authorities. We choose providers with strong contractual and technical protections regardless of location, consistent with our accountability obligations under Canadian privacy law.

9. Children's privacy

Our services are directed at businesses, not to minors. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact our Privacy Officer and we will delete it.

10. Changes to this policy

We may update this policy as our services and legal obligations evolve. When we do, we will revise the "Last updated" date above. Material changes will be communicated through our website or the customer dashboard.

11. How to contact us

For any question about this policy or your personal information, contact our Privacy Officer, Daniel Kim, at daniel.kim@tscalesolution.com. We respond within 30 business days.

12. Provincial privacy rights

Depending on where you live in Canada, a provincial privacy law may apply in addition to, or instead of, PIPEDA:

  • British Columbia: our pilot operations are in BC and are governed by BC's Personal Information Protection Act (PIPA). Complaints may be made to the Office of the Information and Privacy Commissioner for BC (oipc.bc.ca).
  • Alberta: for Alberta residents, Alberta's Personal Information Protection Act (PIPA) applies, overseen by the Office of the Information and Privacy Commissioner of Alberta.
  • Ontario, Manitoba, Saskatchewan, and other provinces: PIPEDA applies as the default federal law, overseen by the Office of the Privacy Commissioner of Canada.
  • Quebec: we do not currently serve customers in Quebec. If and when we do, we will comply with Quebec's Law 25, including making this policy and the relevant services available in French.

You may escalate an unresolved concern to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca).