Stackjoinery, Inc. ("Stackjoinery", "we", "us") is a United States company that designs, builds, and operates automations and AI agents for business clients. This policy explains what personal information we collect, why, how long we keep it, and the choices you have. It covers our website, our email, and the data we handle for clients during an engagement. If anything here is unclear, write to hello@stackjoinery.com and a person will answer.
1. Who this policy applies to
This policy applies to visitors to our website, people who correspond with us by email or through our contact form, and individuals whose data we encounter while doing work for a client. Our clients are businesses. We do not market to consumers, and we do not knowingly collect information from anyone under 16.
2. What we collect and how
Contact form and email. When you use our contact form or email us, we receive what you send: typically your name, work email, company, role, and a description of the process you want to automate, plus the date and any follow-up correspondence. The form requires only a name, an email address, and a message.
Website analytics. We use a privacy-focused analytics service that records page views, referring sites, approximate country, browser type, and screen size. It does not use cookies to track you across sites and does not build a profile of you.
Scheduling and calls. If you book a discovery call, our scheduling tool collects your name, email, and time zone. Calls are recorded only when every participant is told at the start and agrees.
We do not buy data about you from third parties, and we do not collect payment card details on this website. Invoices are paid through a third-party billing provider under its own policy.
3. How we use information
We use the information above to respond to your inquiry, scope and deliver engagements, send invoices and contracts, schedule and prepare for calls, keep the website secure, and understand how the site is used. If you have asked to hear from us, we may send occasional notes about our work; every message includes a one-click way to stop. We do not sell personal information, and we do not share it with advertisers.
Our legal bases, where they apply, are contract performance, legitimate interests (running the business, keeping systems secure, replying to inquiries), and consent (marketing email, call recordings).
4. Client data during engagements
Most of the personal information we encounter lives inside our clients' systems: customer records, support tickets, emails, orders, and patient or matter files, depending on the industry. We handle it under the following principles, which are written into every engagement agreement.
- We work inside accounts the client owns. Automations, workflows, and agents are built in the client's own tool accounts, cloud projects, and AI model accounts wherever practical. When an engagement ends, access is revoked and nothing needs to be migrated back.
- We do not train models on client data. We never use client data to train, fine-tune, or improve any AI model, ours or anyone else's. We configure the AI providers we recommend so that data sent to them is not used for training.
- Least access. We request the narrowest permissions that let us do the work, use named accounts rather than shared logins, and prefer read-only access until a workflow needs to write.
- Regulated data. For healthcare, financial, and similar clients we follow HIPAA-aware practices and the client's own policies, sign the agreements the client requires, and keep protected data inside the systems the client already trusts. We do not claim any certification we do not hold.
In these situations we act on our client's instructions as a service provider or processor. If you have a question about data a client holds about you, the client is the right first contact, and we will help them respond.
5. Subprocessors and sharing
We use a small number of third-party services to run the business. By category: cloud hosting, AI model providers (configured so they do not train on inputs), email and calendaring, video conferencing, contract signing, billing, and analytics. Each is bound by its own terms and, where personal data is involved, a data processing agreement. A current list of named providers is included in engagement agreements and available to clients on request.
We may also disclose information when the law requires it, to protect a person's safety, or as part of a merger or acquisition, in which case this policy continues to apply.
6. Retention
Inquiry and correspondence records are kept while we have an active conversation and for up to three years afterward, so we can pick up where we left off if you return. Contracts, invoices, and related records are kept for seven years to meet tax and accounting obligations. Analytics data is aggregated and does not identify you. Client data accessed during an engagement is not retained beyond the engagement, except where a support agreement requires ongoing access, and then only for its term.
7. Security
We use encryption in transit and at rest for the systems we control, multi-factor authentication on every account, and an access review at the start and end of each engagement. No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify you and any affected client without undue delay and within the timelines the law requires.
8. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, receive a copy in a portable format, object to or restrict certain processing, and withdraw consent where consent is the basis. These rights are described in the GDPR for people in the European Economic Area and the United Kingdom, and in the CCPA and similar state laws for US residents. California residents also have the right to know whether personal information is sold or shared (we do neither) and the right not to be discriminated against for exercising these rights.
To make a request, email hello@stackjoinery.com with the subject line "Privacy request". We will verify your identity using the email address we already hold and respond within 30 days. You can also lodge a complaint with your local data protection authority.
9. Cookies
This website sets one first-party item in local storage to remember your light or dark theme preference. Our analytics does not use cookies. If you book a call, the embedded scheduling tool may set its own functional cookies. We do not use advertising cookies, pixels, or cross-site tracking, so there is no consent banner to click through.
10. International transfers
We are based in the United States and process data there, including information you send from outside the US. Where a transfer mechanism is required, we rely on standard contractual clauses with our providers.
11. Changes to this policy
We will update this page when our practices change and revise the date at the top. Material changes affecting active clients are also sent to the client contact by email.
12. Contact
Stackjoinery, Inc.
Privacy inquiries: hello@stackjoinery.com
Offices in New York and Austin.