LaunchX

Privacy Policy

Last updated: May 8, 2026 · Effective: May 8, 2026

Plain-English summary: We host websites for businesses. When you visit launchx.ca, we use a consent banner to let you decide what tracking loads. We store consent records in an encrypted database in Toronto, Canada. We name every third party we share data with. You can withdraw consent or request your data at any time by emailing [email protected].

1. Who we are

LaunchX (“we,” “us,” or “our”) is a Canadian web application development and managed-infrastructure service operated at launchx.ca. This policy applies to information we collect through launchx.ca and our authenticated client portal.

Privacy officer

Nick Simpson serves as our designated Privacy Officer under PIPEDA and Quebec Law 25. You can reach the Privacy Officer directly at [email protected] for any privacy question, request to access or correct your data, withdrawal of consent, complaint, or notice of a suspected breach.

2. What we collect

We collect personal information in four categories, depending on what you do on the site:

2.1 Account information (clients only)

When you create a LaunchX account: your name, email address, hashed password, and (optionally) company name. When you subscribe to a paid plan: a Stripe customer ID and subscription status that we use to authorize portal access. We never see or store your payment card details. Stripe handles those.

2.2 Site audit submissions

If you submit our public site audit form at /audit: the URL you asked us to audit, your name, your business email address, your IP address, and the explicit consent you give on the form. We then run our audit (PageSpeed, SSL, security headers, framework detection) against the URL and email you the report. We store a record of the audit and your consent for 1 year.

2.3 Consent records

Every interaction with our consent banner is recorded as a consent event. This includes when it's shown to you, when you grant or withdraw consent, and when you change categories. Each record includes: an anonymous visitor ID stored in your browser cookie, your IP address (encrypted at rest), your user agent, the page URL, the jurisdiction we detected, the exact version and text of the banner you saw, and the categories you granted. This is the legally-required audit trail under Quebec Law 25 and EU GDPR.

2.4 B2B visitor identification (with consent only)

If you grant Marketing & Visitor Identification consent on our banner, we run third-party B2B identification pixels that attempt to match the network you're browsing from to publicly-available business records. The result is the company-level information our providers can determine (company name, industry, approximate size) plus the pages you viewed on launchx.ca. We never see or store individual personal identifiers from these pixels for Canadian visitors. The named providers are listed in §5.

3. How we collect it

  • Direct form submissions: account signup, audit form, support tickets. You enter the data; we receive it.
  • Consent banner interactions: every click on Accept all, Reject non-essential, Save preferences, or Withdraw is recorded as a consent event.
  • First-party cookies: a single consent-state cookie (lx_consent) and the session cookie that keeps you logged into the portal. Both are described in our Cookie Policy.
  • Third-party pixels (only after marketing consent): Leadfeeder, RB2B, and Snitcher (during a time-limited validation trial). See §5.
  • Server logs: Cloudflare and our origin server log standard request metadata (IP, time, path, response code) for security and debugging. These logs are retained for 30 days then rotated.

4. Why we collect it (and the legal basis)

Under PIPEDA, all personal-information collection requires meaningful consent. Under EU GDPR Article 6, every collection needs a lawful basis. The bases we rely on:

  • Contract performance(PIPEDA §5(3); GDPR Art 6(1)(b)) covers account information, billing through Stripe, and the data we need to deliver your service.
  • Explicit consent (PIPEDA Principle 3; GDPR Art 6(1)(a)) covers analytics cookies, marketing/visitor-identification pixels, and audit-form submissions. Each is opt-in via the consent banner or the explicit checkbox on the audit form.
  • Legal obligation (GDPR Art 6(1)(c)) covers keeping the consent audit log itself, which we are required to maintain to demonstrate compliance.
  • Legitimate interest, narrowly (GDPR Art 6(1)(f)) covers security and abuse prevention via Cloudflare, and 30-day request logs. We do not rely on legitimate interest for any marketing or profiling purposes.

5. Third parties we share data with

Different categories of data go to different processors. We name every processor whose handling of your personal data requires your specific, informed consent. For infrastructure providers that enable basic service delivery, we describe the category and jurisdiction and will name the specific provider on request to [email protected]. We do not sell personal information to anyone, and we never grant access for purposes outside what we describe here.

5.1 Required infrastructure (always on, you can't opt out)

These providers enable the site to function. Your data only flows to them in the minimum quantity needed for the function they perform.

  • Hosting: application and database hosted in Toronto, Canada under Canadian law and PIPEDA jurisdiction.
  • Content delivery and security: a major US-based provider handles traffic routing, DDoS mitigation, and request filtering at the network edge.
  • Payment processing: a major US-based provider handles all subscription billing. We never see or store your card details.
  • Transactional email delivery: a US-based provider sends operational emails (account verification, password reset, audit reports) on our behalf.
  • Public uptime status page: a third-party operator hosts our public status page; aggregate availability data only, no personal information.

5.2 Visitor identification (only with marketing consent)

We name these explicitly because your consent to this category needs to be specific. None of these load until you grant marketing consent on the banner.

  • Leadfeeder (European Union, Germany) provides company-level B2B visitor identification.
  • RB2B(United States) provides company-level identification for Canadian and EU traffic; person-level identification for US traffic via the vendor's own geo-fencing.
  • Snitcher (Netherlands) provides company-level B2B visitor identification, used during a time-limited validation experiment. This provider may be removed after the evaluation period.

5.3 Site-audit diagnostics (only when you submit the audit form)

When you submit a URL to our public site-audit form, that URL is sent to public diagnostic APIs operated by industry standards organizations (such as Google PageSpeed, SSL Labs, and Mozilla Observatory) so we can generate the audit report. These services receive only the URL you submit, not your personal information.

Each provider operates under its own privacy policy. We share only the minimum information needed. When we add or remove a visitor-identification provider, we update this section and re-prompt for consent if the change materially affects what data is shared.

6. How long we keep your data

We hold each data type only as long as we need it for the purpose we collected it for, plus a reasonable buffer for compliance and dispute resolution. Records become eligible for deletion in our scheduled retention cycles when they hit these horizons:

  • Account information: kept while your account is active. After account closure, we retain the minimum needed for tax and legal compliance (typically 7 years from the last invoice for tax purposes).
  • Consent records: 3 years from your last interaction. The consent audit trail is kept long enough to defend against regulatory inquiries about consent provenance.
  • Audit-form submissions: 1 year from submission. Long enough to follow up if we're in conversation; short enough to minimize stored personal data.
  • Identified leads (B2B visitor identification): 2 years from last seen. Reset on each new visit. We delete the record entirely after 2 years of no return visits.
  • Compliance audit log: 3 years minimum. This is the tamper-evident forensic trail mandated by our compliance posture; it is append-only and cannot be modified.
  • Server request logs: 30 days, then rotated. Used only for security and debugging.

You can request earlier deletion at any time by contacting our Privacy Officer. We honour deletion requests within 30 days unless we are legally required to retain the data longer (in which case we tell you why).

7. How we protect your data

We apply security in multiple layers:

  • Encryption in transit: TLS 1.3 between your browser and Cloudflare, and between Cloudflare and our origin server.
  • Encryption at rest for IP addresses: every IP we store is encrypted with AES-256-GCM (a current NIST-approved authenticated encryption algorithm). The encryption key is held separately from the database and access is restricted to the Privacy Officer.
  • Append-only audit log: every change to consent records, audit submissions, and identified leads is recorded in a database table that is configured at the database level to reject UPDATE and DELETE operations. Even a fully-compromised application cannot tamper with the audit trail.
  • Database isolation: our PostgreSQL database accepts connections only from the application server on the same machine. It is not reachable from the public internet.
  • Daily encrypted backups: automated daily snapshots, encrypted, retained on a rolling schedule.
  • Access control: administrative access requires SSH keys (no passwords) and is limited to authorized personnel.

8. How to withdraw consent

You can change or withdraw consent at any time, with no consequence to your service:

  • Click Cookie settings in the footer of any page on launchx.ca to re-open the consent banner and adjust your categories.
  • Email the Privacy Officer at [email protected] with a withdrawal request. We respond within 30 days; in most cases within 48 hours.

Withdrawal stops new tracking immediately. We also instruct our processors to remove historical records where their APIs allow it. The consent audit log retains the original consent event and the withdrawal event as a paired record.

9. Your right to access, correct, or delete your data

You can ask us to:

  • Access: see what personal information we hold about you, in a portable format.
  • Correct: fix anything that is inaccurate or incomplete.
  • Delete: remove your data, subject to the legal retention exceptions in §6.
  • Object or restrict processing (EU/UK residents): limit how we use your data even where we have a legitimate-interest basis.

Email [email protected] to make a request. We respond within 30 days as required by PIPEDA. If we cannot fulfill your request (for example, where retention is legally required), we will tell you the specific reason.

10. Region-specific rights

10.1 Quebec residents (Loi 25)

Quebec's Act respecting the protection of personal information in the private sector (Law 25) gives you stronger rights. We detect Quebec visitors via the Cloudflare geolocation header and apply Law 25 mode automatically: opt-in by default, no implied consent, equally-prominent Accept and Reject options on the consent banner. Our Privacy Officer is named (Nick Simpson, [email protected]) and reachable directly. You have the right to data portability, correction, and erasure, with response timelines under 30 days. You can file a complaint with the Commission d'accès à l'information du Québec (CAI) if you believe we are not meeting our obligations.

10.2 EU/EEA/UK residents (GDPR)

Under GDPR you have the rights of access, rectification, erasure, restriction of processing, data portability, and to object. You have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent prior to withdrawal. Our consent banner uses a strict opt-in model in your jurisdiction (no tracking until you choose). You may lodge a complaint with your local Data Protection Authority. We do not have an EU establishment, so under Art 27 we will name a representative if our EU traffic volume requires one. At current scale we operate as a non-EU processor relying on consent and the Standard Contractual Clauses for any data transfer.

10.3 California residents (CCPA/CPRA)

California residents have the right to know what personal information we collect, to delete it, to correct it, to opt out of any sale or sharing, and not to be discriminated against for exercising these rights. We do not sell personal information. We do not engage in cross-context behavioural advertising. To exercise your rights, email [email protected].

10.4 Other Canadian provinces and the rest of the world

PIPEDA applies federally across Canada with provincial overlays in Alberta, British Columbia, and Quebec. In all Canadian jurisdictions you have the right to access, correct, and request deletion of your information, and to file a complaint with the Office of the Privacy Commissioner of Canada (OPC). For visitors elsewhere, the same rights described in this policy apply on a best-effort basis under whichever local privacy law governs.

11. Cross-border data transfer

Your personal information is primarily stored in Toronto, Canada, under Canadian law and PIPEDA jurisdiction. Specific data flows leave Canada in the cases below. By granting consent for a category that uses a non-Canadian provider, you also consent to the corresponding cross-border transfer.

  • Payment processing, content delivery, security, and outbound email: these required-infrastructure functions transit through United States-based providers.
  • Visitor identification (with marketing consent only): Leadfeeder processes data in the European Union; RB2B processes data in the United States; Snitcher (during the validation trial only) processes data in the Netherlands.
  • Site-audit diagnostics (only when you submit the audit form): the URL you submit is sent to United States-based public diagnostic APIs.

We rely on Standard Contractual Clauses or equivalent safeguards for transfers outside the jurisdiction of original collection.

12. Children's privacy

LaunchX is a B2B service. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child, contact the Privacy Officer and we will delete it.

13. Changes to this policy

When we materially change this policy (for example, when we add a new processor, change retention periods, or modify the lawful basis for any collection) we update the “Last updated” date at the top, and we bump the consent banner version so existing visitors see the banner again and can review the new terms. The previous version of this policy is preserved in our git history; we can produce it on request.

14. Contact

For any privacy question, request, or complaint:

Privacy Officer: Nick Simpson
Email: [email protected]
Mailing: by request via email

You can also file a complaint with:

  • Office of the Privacy Commissioner of Canada (OPC), for federal PIPEDA matters
  • Commission d'accès à l'information du Québec (CAI), for Quebec residents
  • Your local Data Protection Authority, for EU/EEA/UK residents

This policy is written in plain English to be understandable. It is not a substitute for legal advice. We have done our best to make every claim factually accurate against our actual systems; if you find a discrepancy between this policy and what we do in practice, please tell our Privacy Officer.