Privacy Policy
Last updated August 25, 2026
1. Scope
This Privacy Policy explains what data Agency Clearstep ("we", "us") collects when you use the Agency Clearstep platform ("Service"), how we use it, and who processes it on our behalf. It works alongside our Terms of Service.
2. What we collect
- Account data — name, email address, password hash, assigned roles, team membership, and invitation records.
- Team content — process templates, versions, steps, metadata, client records, checklist answers, notes, and attachments you enter.
- Usage and operational data — sign-in events, page and feature usage, AI credit consumption, admin actions, and error diagnostics.
- Support data — the content of support requests you submit.
- Billing data — plan, subscription status, billing address, and payment references. Card details are handled by Stripe, our payment processor, and are never stored by us.
3. Multi-tenant architecture and security
The Service is multi-tenant: Teams share the same application and database, and each Team's records are isolated by tenant-scoped database security (row-level security policies keyed to your Team) plus application-level role checks. Data is encrypted in transit, and access by our personnel is limited to what is needed to operate and support the Service. Platform administrators may access Team records in a read-only capacity for support, billing, abuse investigation, and diagnostics, and such access is logged.
No system is perfectly secure. We cannot guarantee that unauthorized access, loss, or disclosure will never occur, and the Service is provided without an uptime or availability guarantee. Keep your own backups of anything business-critical.
4. Third-party processors
The Service depends on third-party vendors to operate, and those vendors process data on our behalf under their own terms and security practices. Categories include hosting and edge compute, managed database and authentication, email delivery, artificial-intelligence model providers (which process the prompts and process content you submit to AI features), payment processing, and error/usage analytics. Vendor outages, changes, or discontinuation can affect the Service. We do not sell your personal data or Team content, and we do not use your Team content to train public AI models.
Stripe (payment processing). Paid plans and AI credit purchases are processed by Stripe on our behalf. Stripe receives the data it needs to take payment, run subscriptions, prevent fraud, calculate applicable sales tax and VAT, and issue invoices and receipts — including your name, email address, billing address and country, and payment details. Stripe handles card data directly; we never receive or store it. Stripe processes this data as our processor and under its own privacy policy. Receipts, invoices, renewal reminders, and failed-payment notices are sent to you through Stripe.
5. How we use data
We use data to provide and secure the Service, authenticate users, enforce plan limits and AI credit metering, respond to support requests, detect abuse, comply with law, bill for paid plans, and improve reliability and features. We may send transactional email such as invitations, password resets, trial reminders, and service notices.
6. Retention and deletion
We retain Team content while your account is active and for a reasonable period afterward for backup, dispute, and legal-compliance purposes, after which it may be deleted permanently. Deactivated users, archived clients, and deleted drafts may be retained in logs or backups for a limited time. Team administrators can request deletion of their Team's data through the in-app Support → Contact form.
7. Your choices
You can update your name, email, and password in Settings, and Team administrators control roles, invitations, and deactivation. Depending on where you live, you may have rights to access, correct, export, or delete personal data; contact us through the Service and we will respond within a reasonable time.
8. Changes and Contact
We may update this Privacy Policy; material changes will be reflected by a new "last updated" date, and continued use after that date constitutes acceptance. If any provision is held unenforceable, the remainder stays in effect. For questions about privacy or data handling, please contact us through our contact form.