Legal

Privacy Policy

Effective date: July 8, 2026 · Digital ByteTeck Consulting Inc.

This Privacy Policy explains how Corviq (“Corviq,” “we,” “our,” or “us”), a product of Digital ByteTeck Consulting Inc., collects, uses, stores, and protects information when you use our platform. We are committed to transparency and to complying with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), the European Union’s General Data Protection Regulation (GDPR) for EU data subjects, and the California Consumer Privacy Act (CCPA) for California residents.

1. Who We Are

Digital ByteTeck Consulting Inc. operates the Corviq platform — an accountability and AI-monitoring product for digital marketing agencies. Our principal place of business is Mississauga, Ontario, Canada. Corviq is the data controller for personal information collected through our website (corviq.ai) and platform.

Questions about this policy may be sent to privacy@corviq.ai.

2. Information We Collect

2.1 Information you provide directly

  • Account information: name, work email address, job title, and the name of your agency when you register.
  • Billing information: payment method details processed directly by our payment processor (Stripe). Corviq does not store full card numbers or CVVs.
  • Communications: messages you send us via email, support tickets, or waitlist forms.
  • Client records: information about your agency’s clients that you enter into Corviq (client names, account identifiers, campaign metadata). This data is owned by you; see Section 3.

2.2 Information collected automatically

  • Log data: IP address, browser type, pages visited, timestamps, and referring URLs, retained for security and debugging purposes.
  • Session identifiers: an opaque session token stored in an HttpOnly, Secure cookie named bt_session. This cookie is strictly necessary for authentication and cannot be disabled without preventing platform access. See Section 5.
  • Usage data: aggregate feature usage, error events, and performance metrics used to improve the platform. We do not link usage events to individual end-users of your clients.

2.3 Advertising platform data

When you connect a platform account (Google Ads, Meta Ads Manager, Shopify, etc.), Corviq retrieves campaign, budget, performance, and audience data via read-only OAuth tokens issued by those platforms. This data belongs to you and your clients. Corviq uses it solely to power monitoring, alerts, and reporting features as described in Section 4.

3. Third-Party Platform Access (Google Ads, Meta, Shopify)

Corviq integrates with advertising and e-commerce platforms using read-only OAuth 2.0 authorization. This means:

  • Corviq requests only the minimum scopes necessary to read campaign performance, budget, and audience data. We do not request permission to create, edit, pause, or delete campaigns or ad sets unless a specific write feature is explicitly enabled and documented.
  • Platform credentials (OAuth tokens) are encrypted at rest using AES-256 and stored only in our Canadian Cloud SQL instance. They are never logged.
  • You may revoke Corviq’s access to any platform at any time by disconnecting the account in Corviq’s platform settings or directly in the platform’s connected-apps dashboard. Revocation stops all data retrieval immediately.
  • Data retrieved from these platforms is stored in our Canadian data region (see Section 6). We do not share this data with third parties for advertising or profiling purposes.

Use of data retrieved from Google Ads is also governed by Google’s API Services User Data Policy, including the Limited Use requirements.

4. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Corviq platform.
  • Generate AI-powered monitoring signals, anomaly alerts, performance reports, and accountability scores based on your connected platform data.
  • Send transactional emails (account verification, billing receipts, critical anomaly alerts). You may opt out of non-critical notifications in your account settings.
  • Respond to support requests and communications you initiate.
  • Detect security incidents, fraud, and platform abuse, and maintain audit logs for compliance purposes.
  • Comply with legal obligations under Canadian law, court orders, or regulatory requests.

We do not: sell your personal information or your clients’ data to third parties, use your advertising platform data to train AI models offered to other customers, or share your data for behavioural advertising purposes.

5. Cookies and Session Management

Corviq uses the following cookies:

NameTypePurposeDuration
bt_sessionStrictly necessaryAuthenticates your session. HttpOnly, Secure, SameSite=Lax. No personal data in the cookie value — it is an opaque token resolved server-side.Session

We do not use advertising cookies, tracking pixels, or third-party analytics cookies on the platform. Our marketing website (corviq.ai) may include a first-party analytics tool that collects aggregate page-view counts without fingerprinting individual visitors.

6. Data Storage and Security

  • All customer data is stored in Google Cloud Platform’s Canada region (northamerica-northeast1, Montréal). Data does not leave Canada at rest.
  • Data is encrypted in transit (TLS 1.2+) and at rest (AES-256 via Cloud SQL Transparent Data Encryption and application-layer field encryption for sensitive values such as OAuth tokens).
  • Session tokens are stored in Redis with short TTLs and are invalidated on logout. Redis is not accessible from the public internet.
  • Access to production systems is restricted to authorized personnel via MFA-protected accounts. We maintain audit logs of administrative access.
  • Corviq is pursuing SOC 2 Type II certification (target: Q3 2026) and is aligned with OWASP Application Security Verification Standard (ASVS) Level 2.

No method of data transmission or storage is 100% secure. If you believe your account has been compromised, contact security@corviq.ai immediately.

7. Data Retention

  • Active accounts: data is retained for the duration of your subscription plus 90 days after cancellation, to allow account recovery.
  • Advertising platform data: historical metric data is retained for up to 3 years to support trend analysis and reporting. You may request earlier deletion (see Section 9).
  • Audit and security logs: retained for 1 year to support security investigations and compliance obligations.
  • Billing records: retained for 7 years as required by Canadian tax law.
  • Deleted accounts: personal information is purged within 30 days of account deletion, except where retention is required by law. Anonymized aggregate metrics may be retained indefinitely.

8. Sharing and Disclosure

We do not sell, rent, or trade your personal information. We share data only in the following circumstances:

  • Service providers: subprocessors who assist us in delivering the platform (Google Cloud, Stripe for payments, transactional email providers). All subprocessors are bound by data processing agreements and process data only as instructed by us.
  • Legal compliance: when required by applicable law, court order, or governmental authority with jurisdiction over us.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to the successor agreeing to protect your data under terms no less protective than this policy.
  • With your consent: in any other circumstance where you have given explicit consent.

9. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access: request a copy of the personal information we hold about you.
  • Correction: request correction of inaccurate or incomplete information.
  • Deletion: request deletion of your personal information, subject to retention obligations described in Section 7.
  • Portability (GDPR/CCPA): receive your data in a structured, machine-readable format.
  • Withdrawal of consent: withdraw consent to processing where consent is the legal basis, without affecting prior processing.
  • Objection and restriction (GDPR): object to or request restriction of certain processing activities.
  • Non-discrimination (CCPA): we will not discriminate against you for exercising your privacy rights.

To exercise any of these rights, email privacy@corviq.ai with “Privacy Request” in the subject line. We will respond within 30 days (PIPEDA) or the applicable statutory period for your jurisdiction. We may need to verify your identity before fulfilling a request.

10. International Data Transfers

Corviq stores all customer data in Canada. Some subprocessors (for example, our transactional email provider) may process data outside Canada. Where data is transferred internationally, we ensure adequate protection through contractual safeguards (Standard Contractual Clauses for EU data, or equivalent protections).

11. Children’s Privacy

Corviq is a B2B platform intended for use by marketing professionals. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that we have inadvertently collected such information, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify active account holders by email at least 14 days before the changes take effect, and update the effective date at the top of this page. Your continued use of Corviq after the effective date constitutes acceptance of the revised policy.

13. Contact Us

For privacy inquiries, data access requests, or to reach our Privacy Officer:

Digital ByteTeck Consulting Inc.
Mississauga, Ontario, Canada
privacy@corviq.ai

You also have the right to file a complaint with the Office of the Privacy Commissioner of Canada if you believe we have not handled your personal information in accordance with PIPEDA.