DataStealth
Legal

Privacy Policy

How DataStealth collects, uses, and protects your information.

Last updated September 2026 · DataStealth Inc.

1. Overview

This Privacy Policy describes how DataStealth Inc. ("DataStealth") treats information that it collects and receives related to your use of DataStealth products or services. DataStealth has established an internal privacy governance framework to support accountability and compliance with applicable privacy laws, including designated privacy leadership, documented policies, regular risk assessments, employee training, and ongoing monitoring.

2. Applicable Privacy Laws

Depending on your location and the nature of the data processed, DataStealth complies with PIPEDA (Canada), Quebec’s Law 25, GDPR (EEA, UK, Switzerland), and CCPA/CPRA (California). The specific law(s) applicable depend on your location, your customers’ locations, and the jurisdiction(s) of data subjects.

3. Data Controller and Data Processor Roles

For customer data processed through DataStealth Solutions, DataStealth acts as a data processor, processing data solely on customer instructions. For Account Information, billing data, and marketing data, DataStealth acts as a data controller.

4. Information Collection and Usage

DataStealth collects Account Information (identifiers, billing, payment) and Usage Information (logs, requests, performance metrics) needed to deliver and support Solutions. Authentication credentials are protected via cryptographic hashing, encryption at rest and in transit, and secure session management; passwords are never stored in plain text.

5. Information Sharing and Disclosure

DataStealth will not share collected information with third parties without consent, except where necessary to comply with law, protect our rights, or protect customers, users, employees, or the public. Any third party receiving Account Information or customer data under a contract with DataStealth must sign an NDA and limit use to the purpose provided. Website analytics and advertising providers are handled differently: they receive website usage data only where you have consented through our cookie banner, on their own published terms rather than under an NDA with DataStealth. Those providers, what they receive, and how to refuse them are listed in section 12.

6. Security

DataStealth maintains physical, electronic, cyber, and procedural safeguards. Information is stored in secure data centers located primarily in Canada and the United States, accessible only to authorized employees.

7. International Data Transfers and Storage

DataStealth processes and stores personal information primarily in Canada and the United States. Cross-border transfers are protected via Standard Contractual Clauses, Data Processing Agreements, and technical/organizational safeguards.

8. Data Retention and Deletion

Customer data is retained for the duration of the contractual relationship per customer instruction. Billing and financial records are typically retained a minimum of seven years. Upon contract termination, DataStealth will securely delete or return customer data at the customer’s written request.

9. Data Subject Rights

Depending on applicable law, you may have rights of access, correction, deletion, restriction, portability, and objection. PIPEDA requests are answered within 30 days, GDPR within one month (extendable), and CCPA/CPRA within 45 days (extendable).

10. Modification of Privacy Policy

DataStealth may change this Privacy Policy at any time by publishing the update on our website. Continued use of any Solution after posting constitutes acceptance of the modifications.

11. Cookies and Similar Technologies

DataStealth uses four categories of cookies and similar technologies on this website. Strictly necessary — required for the site to work. These cannot be switched off and are the only ones set before you make a choice. This includes the record of your own cookie choice, stored in your browser’s local storage as "ds-cookie-consent" and never sent to us. Functional — remember preferences you set, so choices persist between visits. Performance and analytics — measure which pages are used and how, including on-page interactions such as clicks and scrolling. Marketing and advertising — connect your visit to inquiries you send us, and share website usage data with advertising and audience providers. Nothing outside the strictly necessary category is set until you consent. You can accept all, reject everything non-essential, or choose per category, and you can change or withdraw your choice at any time using the "Cookie preferences" link in the site footer. Withdrawing consent clears the cookies for that category and reloads the page so the providers concerned stop running. Because your choice is stored in your browser, it is per-browser and per-device. Section 12 lists every provider and the specific cookies involved.

12. Website Service Providers and Cookies

The providers below receive data about your use of this website. Everything in the analytics and marketing categories runs only after you consent, and stops when you withdraw consent. Tags are delivered through Google Tag Manager, which is itself loaded only once you consent to analytics or marketing, and which is told your choice for every consent signal. Each provider processes the data it receives under its own privacy policy. Where a provider is used for advertising, the data it receives may be combined with data it holds from other websites.

ProviderDataStealth (this site)
What it doesRecords your cookie choice so you are not asked again. Strictly necessary; never sent to us.
Cookies and storageds-cookie-consent (browser local storage)
ProviderGoogle Tag Manager
What it doesDelivers the tags listed below. Loads only after you consent to analytics or marketing; collects nothing itself.
Cookies and storageNone
ProviderGoogle Analytics 4
What it doesMeasures which pages are viewed and how the site is used. Analytics.
Cookies and storage_ga, _ga_SLYYRNS685
ProviderContentsquare
What it doesRecords on-page interactions such as clicks and scrolling, to show how pages are used. Analytics.
Cookies and storage_cs_c, _cs_id, _cs_s
ProviderLinkedIn Insight Tag
What it doesMeasures advertising conversions and builds audiences on LinkedIn. Marketing.
Cookies and storageSets cookies on linkedin.com; receives page address, IP address and device details
ProviderMeta Pixel
What it doesMeasures advertising conversions and builds audiences on Facebook and Instagram. Marketing.
Cookies and storage_fbp
ProviderG2
What it doesIdentifies organisations researching DataStealth, for buyer-intent reporting. Marketing.
Cookies and storageReceives page address and IP address
ProviderLeadLander
What it doesIdentifies the organisation a visit comes from, so our sales team can follow up. Marketing.
Cookies and storageReceives page address and IP address
ProviderHubSpot
What it doesRuns our forms and live chat, and connects your visit to inquiries you send us. Marketing.
Cookies and storage__hstc, __hssc, __hssrc, hubspotutk, messagesUtk
ProviderGoogle Fonts
What it doesServes the typefaces used across the site. Strictly necessary, so it loads before you choose.
Cookies and storageNo cookies; your IP address is disclosed to Google
ProviderGoogle Maps
What it doesDisplays the office map on the Contact page only. Loads before you choose, on that page.
Cookies and storageGoogle cookies set within the embedded map
ProviderYouTube
What it doesPlays videos embedded in articles, using youtube-nocookie.com.
Cookies and storageNothing until you start playback
ProviderSanity
What it doesHosts article text and images, which your browser loads from their CDN.
Cookies and storageNo cookies

Compiled by observing a full-consent session on this site. If you find a cookie not listed here, please tell us using the contact details below.

13. Contact Us

Questions regarding this Privacy Policy can be directed to DataStealth’s DPO, Romeo Shakhawat, at info@datastealth.io, or by mail to DataStealth Inc., 5995 Avebury Rd Suite 600, Mississauga, ON L5R 3P9.