1. Who we are
Hayle Inc. is an Ottawa-based creative agency and software studio. This policy covers hayle.ca and the Hayle client and team portal, including inquiries, accounts, project collaboration, and optional Google Calendar sync. Separate agreements or notices may apply to other software products or work we perform for a client.
Privacy contact: David Qiudavid.qiu@hayle.caHayle Inc.1000 Innovation Dr, Suite 500Kanata, Ontario K2K 3E7, Canada2. Information we handle
- Inquiries and communications: your name, email address, company, project goals, services, timing, and messages you send through the website or directly to us.
- Accounts: name, email, company and phone number where provided, account identifiers, roles, and account-administration information. Firebase Authentication handles sign-in credentials. Administrators may issue temporary portal passwords; Hayle does not request your Google password.
- Project work: contacts, assignments, dates, comments, notes, approvals, content, resource links, meetings, and activity history submitted by you or authorized collaborators. Activity records may include the person making a change, its time, and previous and updated values.
- Billing references: service and order details, invoice links, amounts, payment status, and payment references. The portal does not collect card numbers through its own payment form. External payment services handle information under their own policies.
- Technical information: service providers process information such as IP addresses, browser details, request times, and diagnostics to deliver and protect the service.
Please share only information relevant to the work. Do not put passwords, card details, or unrelated sensitive information in notes or inquiry forms. Only provide another person's information when you are authorized to do so.
3. How we use information
We use information to answer inquiries, manage accounts, deliver services, coordinate projects, track approvals and billing, provide requested calendar features, maintain business records, and investigate service or security issues.
Authorized staff access information according to their responsibilities and portal permissions. Clients and collaborators receive access according to their account and project permissions.
Hayle Inc. does not sell personal information. Processing by a provider needed to run the service is described below. New uses requiring additional consent will be disclosed before they begin.
4. Google services
Google Sign-In
If you choose Google Sign-In, Google and Firebase provide account identifiers and available profile information, such as your name, email, verification status, and profile image, to establish your identity. Signing in does not itself authorize Calendar access.
Optional Google Calendar sync
Calendar permission is requested separately when you choose Sync to my Google Calendar. You can decline and continue using the portal without this feature. Google describes the permission and asks for your authorization.
The current integration creates or updates an event for the selected portal item in your primary Google calendar. It sends the title, dates or meeting times, location where provided, and a portal link and record identifier. People who can view that event under your Google Calendar sharing settings may see those details.
We process Google's event response to confirm the sync and return an event link. The portal stores the event identifier, related portal record identifier, sync time, and source revision. The short-lived authorization token is used for the request and is not saved in the portal database. This integration does not store a Google Calendar refresh token.
The feature does not list or import unrelated calendar events, read Gmail, or read the contents of Drive files. It does not continuously sync in the background. Changes are copied when you select Sync again; Google Calendar edits are not imported into the portal.
You can revoke access in your Google Account connections. Revoking access prevents future authorized requests but does not remove existing events or portal records. Delete calendar events in Google Calendar and contact David about information held by Hayle.
Limits on Google data use
Hayle's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. We use this data for the visible features described here, not for advertising, sale, or training generalized AI models. Transfers and human access are limited to what that policy permits, including consented feature delivery, necessary security work, and legal obligations.
5. Service providers and external links
The website is delivered through OpenAI Sites and its hosting infrastructure. The portal uses Google Firebase Authentication, Firestore, and Cloud Functions. Website fonts are served by Google Fonts. These services process information needed for their respective delivery, storage, authentication, and security functions.
The website's project-inquiry email handler uses Resend when delivery is configured, forwarding the inquiry to hello@hayle.ca. Direct emails are also processed by the email services used by the sender and recipient. Relevant information may be handled by authorized service providers or contractors as needed to deliver the work you request.
Resources may link to Google Docs, Sheets, Drive folders, invoices, and other external services. The current library stores links and related portal information, not document contents imported through the Drive API. Opening a link takes you to a service with its own access settings and privacy practices.
Information may be processed outside Canada, including in the United States. The portal's deployed Cloud Functions run in the United States; other providers and backups may use other locations. Information processed abroad may be subject to the laws and lawful-access requirements of those locations.
6. Browser storage and security
Browser storage keeps sign-in state and preferences, such as calendar views and filters. Google sign-in may use its own cookies and storage. Clearing or blocking storage may sign you out or reset preferences. Hosting and authentication providers also process technical records for service delivery and protection.
We use authenticated access and server-side permission checks. No online service is completely secure. Keep your account secure and notify Hayle if you suspect unauthorized access.
7. Retention and deletion
Our policy is to retain core project and service records for seven years after the relevant engagement is completed or terminated, where needed for documented client-support, contractual, or record-keeping purposes. For general client-account records, that period starts when the client relationship ends. Unnecessary personal information need not be kept for the full period; earlier deletion requests are considered against remaining retention requirements.
When a client leaves, routine collection stops. Necessary processing may continue to close the engagement, settle invoices, respond to requests, resolve disputes, or meet legal obligations. A new engagement does not automatically restart retention for every old project.
At the end of the applicable period, records are to be reviewed for secure deletion or irreversible anonymization. Documented legal requirements or necessary lawful holds may require longer retention. Tax and accounting records follow their applicable rules and starting dates. The seven-year default is not a blanket requirement for every inquiry, token, diagnostic log, calendar-sync link, or browser preference; those records depend on their specific purpose and service requirements.
Retention and deletion requests are handled manually through our privacy contact. The portal does not automatically delete records after seven years. Archiving keeps history and is not permanent deletion. Removing a resource link does not delete the original document. Revoking Google access does not delete existing events or portal history.
Copies held by service providers, email systems, or backups may remain subject to their retention cycles and applicable legal requirements. Ask our privacy contact about the records and copies relevant to your request.
8. Your choices and requests
Contact david.qiu@hayle.ca to ask about personal information we hold, request access or correction, withdraw consent where applicable, request deletion, or raise a privacy concern. We may need to verify your identity and consider other people's information in shared records. Where information must be retained, we will explain the relevant reason and limitations.
Depending on the circumstances, you can also contact the appropriate privacy regulator, including the Office of the Privacy Commissioner of Canada.
9. Policy updates
We update this policy when our practices change and show its effective date. Material changes to how information is used will be communicated, with additional consent sought where required before the new use begins.