Privacy Policy
Effective September 3, 2026
Canary Scale is operated by Izoox, LLC ("we", "us"). It monitors advertising and store performance for the brands and agencies that connect their accounts. This policy explains what we collect, why, how long we keep it, and how to get it deleted. Questions: [email protected].
What we collect
- Account information. Your name, email address, password (hashed), and the organization and workspaces you belong to.
- Platform credentials. OAuth tokens and API keys for the ad platforms, stores, and analytics tools you connect. They are encrypted at rest, requested with read-only scopes wherever the platform offers them, and are never shown back in the app or returned by our API.
- Daily performance metrics. Aggregate rows per day — spend, impressions, clicks, conversions, orders, revenue, refunds, customer counts. This is the product's working data.
- Limited order references. To tell new customers from returning ones we store platform-issued customer identifiers and first-order timestamps from your connected store. We do not store your customers' names, emails, addresses, or payment details.
- Billing. Payments are processed by Stripe; we never see or store full card numbers.
How we use it
To compute the statistics, alerts, and daily analysis you signed up for; to deliver them to the destinations you configure (Slack, email, and the rest); and to operate, secure, and bill the service. A compact summary of your aggregate metrics is processed by our AI provider to write your daily brief. We do not sell data, share it across customers, or use it for advertising. Each workspace's data is isolated and visible only to the people you invite.
How long we keep it
Raw API responses: 14 days, for debugging disputed numbers, then deleted automatically.
Daily metrics and statistics: for the life of the workspace.
After cancellation: your workspace goes read-only for 30 days — long enough to export — then all of its data is permanently deleted.
Offboarding removes every database row for the workspace, purges its file storage, and revokes the platform tokens it held. You can also request deletion at any time at [email protected].
Platform obligations
We honor Shopify's mandatory GDPR webhooks (customer data requests, customer redaction, shop redaction) and Meta's data-deletion callback. Disconnecting a platform stops collection from it immediately.
Who processes data for us
- Laravel Cloud / AWS (US) — hosting, database, and file storage
- Stripe — billing
- Anthropic — AI analysis of aggregate metrics
- Cloudflare — email delivery and network security
- Twilio — SMS alerts, where enabled
A data processing agreement is available on request.
Security
Transport encryption everywhere, credentials encrypted at rest, per-workspace data isolation enforced in the application and covered by automated tests, and read-only platform access — Canary Scale never modifies your campaigns or store.
Changes
If this policy changes materially we will email workspace owners before the change takes effect.