DRAFT STATUS: PRE-RELEASE REVIEW
Privacy Notice
A source-backed draft describing the information handled by the current website implementation.
Draft and scope notice
This is a pre-release working draft, not a published privacy policy. It describes behavior visible in the current website and repository, not an unbuilt issuer product, retail list, or future entitlement.
The owner supplied 17 Julies Walk, Halifax, Nova Scotia as a company address and requested GDPR-aligned best practices. That direction does not establish GDPR compliance or determine which law applies. The legal entity, controller or processor roles, applicable jurisdictions, service-provider locations, retention schedule and rights process still require owner and qualified legal confirmation. No entity or jurisdiction is asserted by this draft.
1. Scope
This draft applies to the blueledger.ai website paths and server routes currently present in the repository, including public forms, account registration and sign-in, ticker reports, the application database, the HubSpot CRM handoff, Stripe checkout handoff and the custom analytics preference.
It does not certify a separate issuer workspace, issuer authorization, retail-interest mailing list, product onboarding, live monitoring service or future data-processing arrangement. Those disclosures must be versioned with the relevant release.
2. Personal Data We Collect
| Collection Method | Data Categories | Examples |
|---|---|---|
| Retail interest form | Double opt-in list | Email address, optional first name and optional interest preference are stored with consent version, source, timestamps and confirmation state. Resend sends confirmation and welcome emails; retail interest data is not imported into HubSpot or campaign tools. |
| Contact form | Required inquiry data | Name, email address, and message. The server validates these fields before storing a contact submission in the application database. |
| Contact form | Optional inquiry data | Company and selected topic or role. The current form has no file-upload control; do not put confidential documents in a message. |
| Other website forms | Requested resource data | Whitepaper requests collect name, email, optional company and role; ticker lookups collect email and ticker; Academy signups collect email and optional track. |
| Account registration | Account and session data | The registration UI uses an email as the username, stores a one-way scrypt-derived password hash and optional display name, and creates a PostgreSQL-backed session after sign-in. |
| Application database | Submission records | Contact, whitepaper, Academy, ticker-lookup, account, and authenticated ticker-lookup records include generated identifiers and created timestamps where defined by the current schema. |
| HubSpot CRM | CRM processing | Contact, whitepaper, ticker-lookup, and registration routes attempt to create or update a CRM contact. Contact messages and ticker details may be added as CRM notes. |
| Optional custom analytics | Allowlisted interaction events | The client sends fixed event names and bounded dimensions only when custom-event consent is accepted and a tracker is available. Form values, email addresses and message text are not sent by the custom analytics helper. |
Retail interest form
Double opt-in list
Email address, optional first name and optional interest preference are stored with consent version, source, timestamps and confirmation state. Resend sends confirmation and welcome emails; retail interest data is not imported into HubSpot or campaign tools.
Contact form
Required inquiry data
Name, email address, and message. The server validates these fields before storing a contact submission in the application database.
Contact form
Optional inquiry data
Company and selected topic or role. The current form has no file-upload control; do not put confidential documents in a message.
Other website forms
Requested resource data
Whitepaper requests collect name, email, optional company and role; ticker lookups collect email and ticker; Academy signups collect email and optional track.
Account registration
Account and session data
The registration UI uses an email as the username, stores a one-way scrypt-derived password hash and optional display name, and creates a PostgreSQL-backed session after sign-in.
Application database
Submission records
Contact, whitepaper, Academy, ticker-lookup, account, and authenticated ticker-lookup records include generated identifiers and created timestamps where defined by the current schema.
HubSpot CRM
CRM processing
Contact, whitepaper, ticker-lookup, and registration routes attempt to create or update a CRM contact. Contact messages and ticker details may be added as CRM notes.
Optional custom analytics
Allowlisted interaction events
The client sends fixed event names and bounded dimensions only when custom-event consent is accepted and a tracker is available. Form values, email addresses and message text are not sent by the custom analytics helper.
The current contact form has no upload field. Please do not submit shareholder records, brokerage statements, credentials or other confidential material through a website message.
3. How We Use Personal Data
| Purpose | How it is used |
|---|---|
| Website requests | Validate and store the information needed to respond to contact, resource, ticker-lookup and Academy requests. |
| CRM follow-up | Attempt to create or update a HubSpot contact and preserve a submitted message or ticker detail as a CRM note where that route supports it. A saved local submission does not prove CRM delivery. |
| Account operation | Create an account, authenticate a user and provide authenticated dashboard ticker-lookup history. The current repository does not show email verification or password-recovery routes. |
| Checkout when enabled | When a configured Stripe price is selected, the server can create a hosted Stripe Checkout session. Product availability, prices, entitlements and billing terms remain release-dependent. |
| Optional custom analytics | Measure bounded interaction events after custom-event consent. The repository does not establish the deployment-level tracker configuration or its retention settings. |
| Retail interest updates | Send confirmation emails after a request and a welcome after explicit confirmation. Each message includes an unsubscribe route. Campaign sending requires separate authorization. |
Website requests
Validate and store the information needed to respond to contact, resource, ticker-lookup and Academy requests.
CRM follow-up
Attempt to create or update a HubSpot contact and preserve a submitted message or ticker detail as a CRM note where that route supports it. A saved local submission does not prove CRM delivery.
Account operation
Create an account, authenticate a user and provide authenticated dashboard ticker-lookup history. The current repository does not show email verification or password-recovery routes.
Checkout when enabled
When a configured Stripe price is selected, the server can create a hosted Stripe Checkout session. Product availability, prices, entitlements and billing terms remain release-dependent.
Optional custom analytics
Measure bounded interaction events after custom-event consent. The repository does not establish the deployment-level tracker configuration or its retention settings.
Retail interest updates
Send confirmation emails after a request and a welcome after explicit confirmation. Each message includes an unsubscribe route. Campaign sending requires separate authorization.
We use only the information needed for the requested website action and the operational follow-up described above. Current routes do not establish a promise to train models on submitted information, sell personal data, or create a marketing subscription.
4. How Information Is Shared
- Application database and session store - submitted website data and account/session records are stored by the application as defined in the current schema and authentication setup.
- HubSpot CRM - relevant form and registration routes make a best-effort CRM request. A provider failure is logged server-side and does not mean a local record was removed.
- Stripe - when checkout is enabled and selected, the server creates a hosted Stripe Checkout session. The website does not collect card fields in its own forms.
- Custom analytics - fixed interaction events are sent only after the custom-event preference is accepted and only with allowlisted, non-personal dimensions.
- At your direction - information is sent when you submit a form or choose an action that requires a third-party handoff.
Provider contracts, locations, subprocessors and transfer safeguards are not established by this code review and must be confirmed before publication.
5. Cookies and Similar Technologies
The current website uses essential browser storage for site behavior and the custom-event preference. Authenticated sessions use an HTTP-only, same-site session cookie; production configuration marks that cookie secure. The preference is stored under the client key bl-cookie-consent.
The custom analytics helper sends no event without accepted consent. The repository does not include a tracker bootstrap, so any automatic pageview service, identifier, cookie and retention behavior is deployment-dependent and requires confirmation before publication.
Custom analytics event preference
You can change whether optional custom interaction events may be sent. Declining disables future custom events from this client when the preference can be saved.
6. Service Locations and Providers
The application database, CRM, Stripe and any analytics provider may process information in locations determined by their deployment and contracts. The current repository does not verify those locations, subprocessors, international transfer mechanism or applicable regional privacy role.
Provider notices and the actual contracting entity must be supplied by the operations and legal owners before this page can be published. For the preview only, privacy questions may be directed to privacy@blueledger.ai; mailbox ownership and monitoring still require confirmation.
7. Data Retention
The database records created timestamps, but the current application does not define a fixed deletion schedule for contact, resource-request, ticker-lookup, Academy or account records. The PostgreSQL-backed session cookie is configured for a 30-day maximum age; this does not establish a retention period for account or form records.
Retail interest records follow a configured schedule: pending requests are deleted after 30 days; delivery identifiers, statuses and failure details are cleared after 90 days; confirmed records remain while subscribed; unsubscribed and suppressed records are retained for six years as consent and suppression evidence, then deleted.
HubSpot, Stripe and any analytics provider have separate retention controls. No universal duration is stated here until the responsible owner documents the schedule, legal holds, suppression behavior and deletion process.
8. Privacy Questions and Requests
For questions about information submitted through the website, contact privacy@blueledger.ai. Include enough context to identify the relevant record, but do not send confidential documents.
Requests will be reviewed under the requirements that apply after the entity, role, jurisdiction and verification process are confirmed. This draft does not promise a response period or a particular set of regional rights.
9. Security
The current server code sets common response headers, uses production-only secure session cookies, and applies rate limits to several public routes. Passwords are processed as one-way hashes; the source does not establish encryption-at-rest, penetration testing, certification, uptime or a complete security program.
No online service is completely secure. Please do not send confidential material through a website form. For the preview only, security concerns may be directed to security@blueledger.ai; mailbox ownership and incident-response commitments require security-owner confirmation.
10. Children and Unauthorised Submissions
Do not submit information about another person, including a child, through a website form unless you are authorised to do so. The appropriate age and regional requirements require legal confirmation before publication.
11. Changes and Publication
The privacy owner and qualified counsel must confirm the entity, applicable jurisdictions, provider disclosures, retention schedule, rights process, security description and version date before publication. This draft does not change those policies or create an approval record.
Preview privacy questions: privacy@blueledger.ai
Preview security concerns: security@blueledger.ai