Personal information protection

Privacy Policy

Last updated: August 31, 2026 — version 2026-08-31

This policy explains what personal information RoomStack collects, why it is used, who it may be shared with, and the choices and rights available to you.

It applies to the public website, demo requests, accounts, invitations, the RoomStack platform, and support communications. A customer organization may also be responsible for information it places in its projects; contact that organization for decisions it controls.

1. Information we collect

  • Identity and contact information: name, professional email, optional phone number, organization, department, location, and language.
  • Account and access information: roles, permissions, associated organizations and projects, invitations, terms acceptance, sign-in dates, and security activity.
  • Professional content: project and building data, sheets, documents, comments, activity, imports, exports, and data provided through authorized integrations.
  • Support and communications: demo or support requests, messages, attachments, and communication history.
  • Technical data: IP address and request or security logs, browser and device type, session identifiers, errors, and information needed to operate and protect the service.

2. Sources

We receive this information directly from you, from your organization or a user who invites you, automatically when you use the service, and from integrations your organization chooses to authorize.

3. Purposes

  • create and administer accounts, organizations, roles, projects, and invitations;
  • provide requested collaboration, storage, synchronization, import, and export features;
  • authenticate users, prevent abuse, investigate incidents, and protect RoomStack;
  • respond to requests, provide support, and deliver operational or legal notices;
  • maintain, diagnose, and improve service reliability, accessibility, and security;
  • meet legal, contractual, accounting, and evidentiary obligations.

4. Sign-in cookie and browser storage

RoomStack currently uses one strictly necessary application cookie, “roomstack-auth”. It contains an authentication token, is unavailable to page JavaScript (HttpOnly), is transmitted securely in production (Secure), and limits cross-site sending (SameSite=Lax). Without “Keep me signed in,” it is a session cookie whose token expires no later than 12 hours. With that option, it persists for up to 7 days. It is used only to maintain and secure sign-in and therefore does not require separate consent.

RoomStack currently uses no advertising or analytics cookies. If a non-essential cookie or similar technology is added, it will be blocked until you make a choice and this policy will be updated.

Browser local storage holds functional preferences such as language, theme, time zone, measurement units, and certain display settings. During the browser session, session storage holds the context of an activated support mandate: its identifier, a temporary activation token, the target organization, the approved scope and access level, its expiration, and the authorized projects. This context is used only to authenticate and limit delegated support access; it is removed when the mandate is exited or revoked, or when browser session data is cleared. These values are not used for advertising.

5. Sharing and service providers

We share information only with authorized people in your organization, project collaborators based on their permissions, and providers that help us operate hosting, storage, transactional email, support, security, and requested integrations. Providers receive only what their mandate requires and are subject to protection obligations.

Public pages may load fonts from external services. Those services then receive technical data needed to fulfill the request, including the IP address and standard browser information.

We may also disclose information when required by law, to protect rights or safety, or in a properly governed business transaction. We do not sell or rent personal information.

6. Processing location

Primary application data is hosted in Canada. Some providers or authorized members of an organization may nevertheless process information outside Québec. Before entrusting information to a provider, RoomStack assesses relevant factors and implements appropriate contractual or technical safeguards.

7. Retention

We retain information for as long as needed to provide the service, meet the agreement with the organization, maintain security and audit records, resolve disputes, or comply with law. Periods vary with the nature of the information. At the end of the applicable period, information is securely deleted, anonymized, or destroyed.

8. Security safeguards

RoomStack uses administrative, technical, and physical safeguards proportionate to the sensitivity of the information, including access controls, organization and project isolation, encrypted communications, logging, and backup and incident procedures. No system eliminates all risk; promptly report suspicious activity.

9. Your rights and choices

Subject to law, you may request access to or correction of your personal information and, in some cases, deletion, withdrawal of consent, or information about processing. We may verify your identity and may need to refer a request to the organization that controls project data. You can update several account details in RoomStack and manage browser data through browser settings.

10. Minors

RoomStack is a professional service for organizations and is not designed to knowingly collect information from anyone under 14 without required authorization.

11. Changes and contact

We may update this policy. A material change will be communicated appropriately and the date above will be updated.

To exercise a right, ask a question, or make a complaint, contact RoomStack’s person in charge of personal information protection at info@roomstack.ca. You may also contact the Commission d’accès à l’information du Québec where that law applies.