Legal · version 2026-06-28-v1
Privacy Policy
Effective: June 28, 2026 · Jurisdiction: Ontario, Canada. PIPEDA and Quebec's Law 25 apply in Canada; the CCPA/CPRA and other U.S. state privacy laws apply in the United States; the UK GDPR and EU GDPR apply where required. This policy explains what data we collect, why we collect it, and how we protect it.
1. Who we are
ST8GE is a service operated by a corporation incorporated in Ontario, Canada. Our primary privacy obligation is under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), supplemented by Quebec's Act respecting the protection of personal information in the private sector ("Law 25") where it applies. For U.S. residents, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) provisions in Section 10 apply, and we extend equivalent rights to residents of other U.S. states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other jurisdictions as enacted). For EEA or UK residents, the GDPR provisions in Section 11 apply.
2. What we collect and why
Account information
- Email address and encrypted password (required to create an account)
- Signup timestamp and last sign-in date (fraud prevention, usage analytics)
Agent profile (optional)
- Headshot photo, name, and brokerage name (to brand your shared tours)
- You can skip this entirely — it is not required to use ST8GE
Property photos
- Photos you upload are sent to Google Gemini (our AI render engine) for processing
- We store the rendered output (staged image) in your account; we do not permanently store your original uploaded photos on our servers beyond what is needed to complete the render
- See Section 5 for details on how Google handles these photos
Usage data
- Which features you use, which room types and styles you select, render frequency
- Purpose: to improve the product and, in aggregate anonymized form, to power Market Intelligence
Tour and shortlist data
- Tour codes, share links, and viewer engagement (opens, reactions)
- Client names and regions you enter for shortlists
- Buyer contact information captured through lead capture flows
- These are stored on your behalf and accessible only to you
Device and technical data
- Browser type, operating system, IP address (for security and performance)
- We do not use advertising cookies or third-party tracking pixels
3. What we do not do
- We do not sell your personal data to any third party
- We do not use your data for advertising targeting
- We do not share your property photos with anyone except the AI processor required to render them
- We do not build buyer profiles for resale; buyer data captured through your lead flows belongs to you
- We do not use advertising cookies or behavioral tracking SDKs
4. Legal basis for processing (PIPEDA / GDPR)
We process your personal information on the following grounds:
- Contract performance: Processing necessary to provide the service you signed up for (account, renders, tours)
- Legitimate interests: Security, fraud prevention, product improvement, aggregate analytics
- Consent: Optional profile setup; any future marketing communications (which will be opt-in only)
5. Google Gemini and AI processing
Important. When you upload a property photo to ST8GE, that image is transmitted to Google's Gemini API — a generative AI model — for rendering. As of our effective date, Google's paid Gemini API terms state that prompts and responses submitted through the paid tier are not used to train Google's generative models. We use the paid tier and do not opt in to any data-training program. You can review Google's current API terms at ai.google.dev/gemini-api/terms. If Google's terms change materially, we will update this policy and notify you.
We use Supabase (U.S.-based infrastructure) for database and authentication, and Cloudflare (global CDN) for content delivery. Both operate under their own privacy programs and are bound by data-processing agreements with us. Cross-border transfers of personal information from Canada or the EEA/UK to the United States are conducted under contractual safeguards (including Standard Contractual Clauses where required).
6. Data retention
- Account data: retained for the life of your account plus 30 days after deletion
- Rendered images: retained in your account until you delete them or your account closes
- Tour links: automatically expire and are deleted from our systems 24 hours after generation
- Client shortlists: automatically expire and are deleted 30 days after creation
- Usage logs: retained for 12 months in aggregate form, then purged or anonymized
7. Security
We implement commercially reasonable technical and organizational measures to protect your data, including encrypted transmission (TLS), encrypted storage, and access controls. No system is perfectly secure. If we become aware of a data breach that affects your personal information, we will notify you as required by applicable law.
8. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Request deletion of your account and associated personal data
- Object to or restrict certain processing
- Data portability (receive a copy of your data in a machine-readable format)
To exercise any of these rights, contact us at hello@st8ge.app. We will respond within 30 days. We may need to verify your identity before fulfilling a request.
9. Children
ST8GE is not directed at anyone under 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected such information, contact us immediately and we will delete it.
10. U.S. state privacy rights (CCPA/CPRA and other states)
If you are a resident of California, you have the right to know what personal information we collect, the right to delete it, the right to correct inaccuracies, the right to limit the use of sensitive personal information, the right to opt out of sale or sharing of personal information (we do not sell or share personal information as those terms are defined under the CCPA/CPRA), and the right not to be discriminated or retaliated against for exercising these rights. We do not process personal information for cross-context behavioral advertising. To submit a verifiable consumer request, contact us at hello@st8ge.app.
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other U.S. states with comprehensive privacy laws have substantially the same rights of access, correction, deletion, portability, and opt-out from targeted advertising or "sale." We honor these requests on the same terms.
11. EEA / UK residents (GDPR)
If you are in the European Economic Area or United Kingdom, you have additional rights under the EU GDPR or UK GDPR including the right to lodge a complaint with your local supervisory authority. Our legal bases for processing are described in Section 4. International transfers of data outside the EEA or UK are conducted under Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent transfer mechanisms where required.
11a. Marketing communications (CASL and CAN-SPAM)
Any marketing emails we send comply with Canada's Anti-Spam Legislation (CASL) and the U.S. CAN-SPAM Act: we send marketing messages only with your consent (express or implied), identify ourselves, and include a one-click unsubscribe link in every message. Transactional messages (account, security, render completion, billing) are not marketing and may be sent without separate consent. If your agent uses ST8GE's lead-capture flows to text or call buyers, those communications are subject to the U.S. Telephone Consumer Protection Act (TCPA), CASL, and applicable state "Mini-TCPA" laws — the agent, not ST8GE, is the sender and is responsible for obtaining required consent and honoring STOP / unsubscribe requests.
12. Changes to this policy
We will update this policy when our data practices change. We will notify you of material changes via email at least 14 days in advance. The version date at the top of this page always reflects the current version.
Privacy questions or data requests:
hello@st8ge.app · Toronto, Ontario, Canada
See also: Terms · Disclosures