Legal
Privacy Policy
Effective September 4, 2026
This policy explains how Stehrway handles personal information in the Stehrway Portal at app.stehrway.com, in the scripts and booking pages the Portal serves to client websites, and in the emails the Portal sends. We wrote it to satisfy Canadian federal and provincial privacy law (PIPEDA, Quebec Law 25, British Columbia PIPA), the EU and UK GDPR, and the policies of the calendar providers you can connect (Google, Microsoft).
At a glance
- The Portal is an invite-only workspace for Stehrway clients and staff. There is no public sign-up, no advertising, and we never sell personal information.
- If you connect a Google or Microsoft calendar, we read only free/busy times (start and end of existing events, never their titles or attendees) and write the meetings people book with you. Tokens are encrypted at rest and deleted the moment you disconnect.
- For website analytics, forms, bookings and content editing on a client’s website, the client is the controller and we act as their service provider under their instructions.
- Questions or requests: hello@stehrway.com. We answer within 30 days.
1.Who we are and what this policy covers
The person responsible for personal information under this policy (the controller) is:
Torge Stehr, doing business as Stehrway
3578 146A StreetSurrey, BC V4P 1B2Canada
Email: hello@stehrway.com
Stehrway is a sole proprietorship established in British Columbia, Canada. Torge Stehr is the person in charge of the protection of personal information (privacy officer) for the purposes of PIPEDA and Quebec Law 25, and the contact point for the EU and UK GDPR.
This policy covers:
- the Stehrway Portal web application at app.stehrway.com, including its settings, Website Studio, analytics, forms, uptime, billing and booking features;
- the scripts the Portal hosts for client websites (the analytics tracker, the content editor and the booking widget) and the public booking API behind them;
- transactional email the Portal sends (invitations, notifications, booking confirmations, invoices).
It does not cover Stehrway’s marketing website, which has its own privacy policy, nor the websites of our clients. When you visit a client’s website, that client’s privacy policy applies; section 2 explains how the two relate.
2.The roles we play
Privacy law distinguishes between the organisation that decides why and how personal information is used (the controller, or in Canada the organisation “in control” of the information) and one that processes it on that organisation’s behalf (a processor or service provider). We play both roles.
Where Stehrway is the controller
- Portal accounts of clients, their team members and Stehrway staff.
- Calendar connections and booking pages that belong to a Portal user, including the bookings made on them.
- Billing, invoices and payments between Stehrway and its clients.
- Operations, security, logs and support.
Where Stehrway is a service provider (processor)
- Analytics, session replay and error monitoring on a client’s website (section 3.4).
- Form submissions sent from a client’s website (section 3.5).
- Content, images and drafts the client edits in the Website Studio (section 3.6).
- Bookings made on a booking page a client operates (section 3.3).
In those cases the client decides what is collected and for how long, we act only on the client’s documented instructions, and the client’s privacy policy governs. If you contact us about information a client holds through the Portal, we will pass your request to the client or point you to them, and help them answer it. Our processing commitments to clients are set out in our Terms of Service.
3.Information we collect and why
3.1 Portal accounts
Accounts are created by invitation from a Stehrway administrator or an organisation admin. We store the name and email address on the invitation; the profile you complete (display name, optional avatar image, time zone); your organisation and team memberships and roles; notification preferences; and what you do in the Portal that other users need to see (for example, who published a website change, requested a project, or reported an issue). Sign-in uses one-time codes sent to your email or a password you set; passwords are stored only as a salted hash by our authentication provider (section 6).
We use this to run your account, secure it, show you your projects, send you the notifications you chose, and send a weekly digest and service announcements. Everything the Portal emails you is transactional; we do not send marketing email to Portal users without separate consent.
3.2 Calendar connections (Google Calendar, Microsoft 365, iCal)
You can connect a calendar in Settings so that your booking pages only offer times when you are free and confirmed meetings land in your calendar. Connecting is optional and happens only when you click “Connect” and approve the request on Google’s or Microsoft’s consent screen.
What we ask for. From Google we request permission to see the list of your calendars, to read free/busy information, and to create, edit and delete events that Stehrway itself created (scopes calendar.calendarlist.readonly, calendar.freebusy and calendar.events.owned), plus your account identifier and email address so we can show which account is connected. From Microsoft we request basic profile information (User.Read), calendar read and write access (Calendars.ReadWrite) and the ability to refresh access while you are signed out (offline_access). Microsoft does not offer a free/busy-only permission; although the permission is broader, our code requests only the fields described below.
What we store.
- The provider’s account identifier and the account email address.
- The OAuth access and refresh tokens, encrypted with AES-256-GCM under a key that exists only on our server. For an iCal feed, the (private) feed URL is stored the same way.
- The list of your calendars: their identifiers, names, time zones and whether they are writable.
- Busy blocks: the start and end times of existing events only. From Google we call the free/busy endpoint, which returns intervals and nothing else. From Microsoft we request only each event’s identifier, start, end, show-as status and cancelled flag. We never receive or store event titles, descriptions, locations, attendees, attachments, email, contacts or files.
- For meetings booked through your booking page: the identifier of the event we created in your calendar and the Google Meet or Microsoft Teams link, if one was generated.
How we use it. Every five minutes, and whenever a visitor opens your booking page with data older than ten minutes, we refresh the busy blocks for the period your event types allow bookings in (between 14 and 120 days ahead) and replace the previous set. We use them solely to compute your availability. When someone books, we create an event in the calendar you chose containing the meeting title, time, the invitee’s name and email, their answers to your questions and the meeting link; if the booking is cancelled or rescheduled we update or delete that event. If the connection stops working, we email you once so you can reconnect.
What we never do. We do not use calendar data for advertising, do not sell it, do not share it with anyone other than the service providers needed to run the Portal (section 6), do not use it to train artificial-intelligence models, and do not let humans read it except with your explicit consent for a support request, to investigate abuse or a security incident, or where the law requires.
Google API Services User Data Policy
Stehrway Portal’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.Disconnecting. Settings → Calendar → Remove deletes the connection, its tokens, calendar list and busy blocks immediately. You can also revoke our access from your Google Account permissions or your Microsoft account privacy settings; the Portal then marks the connection as needing re-authorisation and stops syncing. Deleting your Portal account deletes all connections.
3.3 Bookings
When you book a meeting on a booking page (on a client’s website, or on a Stehrway page such as meet.stehrwaymedia.com), we collect the name, email address and time zone you enter, your answers to the host’s questions, the time you chose, the page you booked from, the referring page and your browser’s user-agent string. Your IP address is used to rate-limit the booking API and is not stored with the booking.
We use this to reserve the slot, create the event in the host’s connected calendar (so the host’s calendar provider receives your name and email as an attendee), send you a confirmation with a calendar file, remind you 24 hours and 1 hour before the meeting, and let you cancel or reschedule through the manage link in your confirmation. We store only a hash of that link’s secret. The host sees their bookings in the Portal. When the host is a client, the client is the controller of your booking.
3.4 Analytics, session replay and error monitoring on client websites
Stehrway Analytics is a first-party analytics service that a client can add to their own website. The website loads a small script from app.stehrway.com, and the data is stored in the Portal for that client. The client is the controller and their website’s privacy policy and cookie banner govern; we process the data as their service provider. The script can collect:
- pages viewed, time on page, active time, scroll depth, referrer and campaign (UTM) parameters;
- clicks (the element’s CSS selector and visible text, not screen coordinates) and repeated “rage” clicks;
- when a form field is focused or a form is submitted (not what was typed, unless the site calls the identify function below);
- device type, browser and operating system derived from the user-agent string;
- country, region and city derived from the IP address by our hosting provider at the edge; the IP address itself is used for rate limiting and is not stored;
- session replay: a recording of the page’s document structure and interactions that lets the client watch how a visit unfolded. Password fields are always masked; the client can mark further elements to be blocked or masked;
- an identity (typically name and email) only if the client’s site explicitly calls the identify function, for example after you submit a contact form, or reports a conversion from their server;
- custom events the client defines, and JavaScript errors that occur on the page.
The script sets one first-party cookie on the client’s website (_sw_vid) to recognise a returning browser. It never starts if your browser sends a Global Privacy Control or “Do Not Track” signal, and it supports a consent mode in which nothing is collected until the site’s banner records your consent. Sites built on Stehrway’s starter ship with express opt-in for visitors in Quebec, the EEA and the UK. Raw events are kept for 90 days and replay recordings for 30 days; only daily aggregate counts, which do not identify anyone, are kept longer.
3.5 Forms on client websites
When you submit a contact or other form on a client’s website that uses Stehrway Forms, the website forwards the submission to the Portal. We store the fields you entered, up to two attachments (in private storage, served only through short-lived signed links), a salted hash of your IP address, your user-agent string, the referring page, campaign parameters and browser language. The Portal notifies the client, optionally sends you an automatic acknowledgement in the client’s name, and delivers the submission to any integrations the client has connected. The client sets the retention period; delivery logs are pruned after 90 days. The client is the controller.
3.6 Website content and the Website Studio
Clients edit their website’s text and images in the Portal. We store drafts, revisions, scheduled changes and an audit trail of who changed what and when, and we publish approved changes to the website’s source-code repository. Images you upload or generate are held temporarily in the Portal and then committed to the website. Content you type may include personal information (for example a team page); the client is responsible for that content and is its controller.
Two assistive AI features are available: text rewriting and image alt-text, which send the relevant text or image together with the site’s brand-voice notes to Anthropic; and image generation, which sends your prompt to Black Forest Labs. Section 12 explains how these providers handle the data.
3.7 Billing
For clients we store billing contacts, billing addresses, tax registration numbers, invoices, line items, taxes, payments and subscription details. Card payments are handled by Stripe: your card details are entered on Stripe’s hosted checkout and never touch our servers; we keep only Stripe’s customer and payment-method references and the outcome of the payment.
3.8 Monitoring, logs and security
The Portal checks client websites for availability, certificate expiry and deployment failures; those checks concern the website, not its visitors. Error monitoring groups JavaScript errors reported by the analytics script, which can include page URLs. When a client reports an issue through the Portal we record their name, organisation, project, the category and message, and email it to Stehrway staff. Our hosting provider keeps standard server logs (IP address, user-agent, timestamps, requested URL) for a limited period, and the Portal keeps in-memory rate-limit counters keyed by IP address. Operational alerts go to staff by email and Telegram and name the affected site or project, not individuals.
4.Purposes and legal bases
Under PIPEDA and the provincial statutes we rely on your consent, which may be implied where the purpose is obvious and the information is not sensitive (for example, storing your name to run your account), and which we obtain expressly for anything else (for example, connecting a calendar). Where the EU or UK GDPR applies, the legal bases are:
| Purpose | Legal basis |
|---|---|
| Providing the Portal to you or your organisation, including accounts, projects, the Website Studio, billing and support | Performance of a contract, or steps at your request before entering one (Art. 6(1)(b)) |
| Connecting your calendar and computing availability; writing bookings to your calendar | Your consent, given on the provider's consent screen (Art. 6(1)(a)); you can withdraw it by disconnecting |
| Processing a booking you make, sending confirmations and reminders | Performance of a contract with you (Art. 6(1)(b)) |
| Analytics, session replay and forms on client websites | Determined by the client as controller; typically consent for analytics cookies and replay, and contract or legitimate interests for form handling |
| Security, abuse prevention, logs, backups, service announcements | Legitimate interests in running a secure, reliable service (Art. 6(1)(f)) |
| Invoicing, tax records, responding to lawful requests | Legal obligation (Art. 6(1)(c)) |
7.International transfers
Stehrway is established in Canada, and the Portal’s database and hosting are in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your information is therefore transferred outside your jurisdiction. Canada’s private-sector privacy law (PIPEDA) is recognised by the European Commission as providing adequate protection for commercial organisations, and by the UK under its adequacy regulations. For our providers in the United States we rely on their certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions where they hold it, and otherwise on the European Commission’s Standard Contractual Clauses (with the UK Addendum and Swiss amendments) incorporated in their data-processing agreements, together with the technical measures in section 9. You can ask us for details of the safeguards for a particular provider.
For residents of Quebec, Law 25 requires us to assess the privacy impact of communicating personal information outside Quebec before we do so. We carry out that assessment for each provider in section 6, taking into account the sensitivity of the information, the purposes, the safeguards and the legal framework of the destination.
8.How long we keep information
| Information | Retention |
|---|---|
| Portal account and profile | For the life of the account, then deleted within 30 days of closure |
| Calendar tokens, calendar list, busy blocks | Until you remove the connection or close your account; busy blocks are replaced on every sync |
| Bookings | While the host's account exists, so past meetings remain visible to the host; invitees and hosts can ask us to delete a booking |
| Analytics raw events | 90 days |
| Session replay recordings | 30 days |
| Analytics daily aggregates (counts only) | Kept for trend reporting; they do not identify anyone |
| Form submissions and attachments | The period the client configures; deleted together by a nightly job. Delivery logs: 90 days |
| Website drafts, revisions and audit trail | For the life of the client's website; temporary uploaded or generated images are cleaned up daily after their holding period |
| Invoices, payments and tax records | At least six years after the end of the tax year, as Canadian tax law requires |
| Server logs and rate-limit counters | Days (logs) or minutes (counters) |
When a retention period ends we delete or irreversibly anonymise the information. Backups are overwritten on a rolling schedule shortly afterwards.
9.How we protect information
- All traffic to the Portal, its scripts and its APIs is encrypted in transit with TLS.
- Our database and storage provider encrypts data at rest. Calendar tokens and private feed URLs are additionally encrypted by the Portal with AES-256-GCM under a key that is never stored in the database.
- Calendar connections use OAuth 2.0 with PKCE and signed, short-lived state; we request the narrowest scopes each provider offers.
- Accounts are invite-only, sign-in uses one-time codes sent to your email or a password, and access inside the Portal is scoped by organisation, team and role.
- Public endpoints (analytics, forms, booking) are validated per site key or origin allow-list and rate-limited.
- Stehrway staff can preview the Portal as a client user to help with support (“View as”); this is read-only, every action they take is still attributed to the staff member, and it is used only when needed.
- If a breach creates a real risk of significant harm, we notify the affected people and the Privacy Commissioner of Canada as PIPEDA requires, and, where the GDPR applies, the competent supervisory authority within 72 hours.
10.Your rights and choices
Depending on where you live you have some or all of the following rights, and we honour them for everyone regardless of location:
- to access the personal information we hold about you and to know how it has been used and shared;
- to have inaccurate or incomplete information corrected;
- to have information deleted, or its processing restricted, subject to legal retention duties;
- to receive information you gave us in a structured, machine-readable format (portability);
- to object to processing based on legitimate interests;
- to withdraw consent, for example by disconnecting a calendar, without affecting earlier processing;
- to complain to a supervisory authority: the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Office of the Information and Privacy Commissioner for British Columbia, your EU member state’s data-protection authority, or the UK Information Commissioner’s Office.
To exercise a right, email hello@stehrway.com from the address on your account, or write to the address in section 14. We may ask for information to verify your identity. We respond within 30 days (one month under the GDPR), and will tell you if we need longer for a complex request. Exercising your rights is free and will never affect the service you receive. Where we hold information as a client’s service provider, we will forward your request to the client and assist them.
Portal users can also update their profile and notification preferences, disconnect calendars and delete booking pages themselves in Settings. To close an account, ask your organisation admin or write to us.
11.Children
The Portal is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16 (or the age of consent in their jurisdiction). If you believe a child has provided us with personal information, contact us and we will delete it.
12.AI features and automated decisions
We make no decisions about you by automated means that have legal or similarly significant effects. The Portal’s AI features are assistive: they draft text, suggest alternatives, describe images or generate images, and a person reviews the result before it is published. Availability on booking pages is computed from the host’s rules and busy times, which is a scheduling calculation, not a decision about the person booking.
Text sent to Anthropic is processed under Anthropic’s commercial API terms, which prohibit training on customer content and delete inputs within their published retention limits. Image prompts sent to Black Forest Labs are processed under their API terms. Calendar data, booking data, form submissions and analytics are never sent to AI providers.
13.Changes to this policy
We update this policy when the Portal changes or the law does. The effective date at the top tells you which version applies. For material changes, for example a new category of information or a new purpose, we notify Portal users by email or an in-app notice before the change takes effect and, where consent is required, ask for it.
14.How to contact us
Torge Stehr, doing business as Stehrway
3578 146A StreetSurrey, BC V4P 1B2Canada
Email: hello@stehrway.com
Please put “Privacy” in the subject line so we can route your message quickly. If you are not satisfied with our answer, you can contact one of the authorities listed in section 10.