Privacy Policy
Version 2.0 · Last updated July 7, 2026
This policy is pending review by BC legal counsel and is not yet finalized.
2. Our privacy officer & how to reach us (accountability)
We have designated a Privacy Officer responsible for our compliance with PIPA. Direct all access, correction, questions, and complaints to: Privacy Officer, Support Captains — privacy@supportcaptains.com, British Columbia. Our privacy practices and complaint process are available on request. We maintain internal privacy policies, safeguards, and staff practices as part of a privacy management program.
3. Definitions
- Personal Information — information about an identifiable individual, as under PIPA/PIPEDA.
- Sensitive Information — higher-risk categories we treat with extra care: health (medications, allergies, conditions, notes), financial/administrative-legal (e.g., representation/authority references), and identity information.
- Care Recipient — the person at the centre of a circle.
- Representative — a person with valid legal authority to act for a Care Recipient who cannot consent (e.g., BC Representation Agreement, committee, guardianship).
- Zero-Knowledge Vault — documents encrypted client-side with a passphrase only you hold; we cannot read or recover them.
4. Whose information is in Support Captains, and consent
- You — the account holder coordinating care.
- The Care Recipient — your loved one.
- Other circle members — family, friends, and helpers you invite.
Because a circle holds sensitive information about the Care Recipient, that information must be authorized: the Care Recipient's own consent where they have capacity, or a Representative's authorization where they do not. A family relationship alone is not authorization. See our Consent & Authorization process and §9 below.
5. What we collect — by category and source
| Category | Examples | Source |
|---|---|---|
| Account & identity | Name, email, sign-in credentials (via our auth provider), optional photo | You |
| Care Recipient profile | Name, photo, contact details | You / your circle |
| Health information (sensitive) | Medications, allergies, conditions, care notes | You / your circle |
| Administrative/legal (sensitive) | Care contacts; references to authority (e.g., representation) | You / your circle |
| Documents | Files you upload (some to the Vault) | You / your circle |
| Coordination data | Needs, claims, updates, events, care-team contacts | You / your circle |
| Usage/technical | Basic logs needed to operate and secure the Service | Automatically |
6. Why we use it (purposes) and our basis
We use each category only to provide the Service — to run your circle, coordinate care, keep your record, and produce summaries you choose to share — and to secure and maintain it. Our basis is your consent (and, for the Care Recipient, their consent or their Representative's authorization). We do not sell your information, use it for advertising, or use it to train third-party AI models.
7. How we protect it
Encryption of sensitive health and administrative data; a Zero-Knowledge Vault for your most sensitive documents (encrypted with a passphrase only you hold — we cannot read or recover them); role-based access controls; and an audit log of access to sensitive information and of report link creation, access, and revocation. No system is perfectly secure, but we design for the sensitivity of what we hold.
8. Where your information is stored — cross-border (read this)
Most of your information — including your database records (names, needs, updates, and encrypted health/administrative fields) — is stored and processed in the United States (our database is hosted in Oregon). Your encrypted vault documents are stored in the United States (Virginia). This means that information may be subject to US law and accessible to US courts, law enforcement, or national-security authorities, sometimes without notice to us or you. Consistent with PIPEDA's accountability principle, we remain accountable for information under our control and use contractual and technical safeguards (including encryption) intended to provide comparable protection — but we cannot eliminate the risks of cross-border processing or promise immunity from foreign legal demands. By using the Service, you acknowledge this cross-border storage. Our current sub-processors:
| Provider | Purpose | Location |
|---|---|---|
| Neon | Database hosting (all core account data) | US (Oregon) |
| Vercel | App hosting / edge | US |
| Clerk | Authentication | US |
| Resend | Transactional/digest email | US |
| Vercel Blob | Encrypted vault-document storage | US (Virginia, iad1) |
| Stripe | Payments | US |
| Twilio (if SMS launches) | Text notifications | US |
We keep this list current and update it when sub-processors change.
9. Consent, capacity, and the Care Recipient
Storing a person's sensitive information requires authorization. Where the person has capacity, their own consent is the basis. Where they cannot consent, authorization must come from a Representative with legal standing (e.g., a BC Representation Agreement under s.7/s.9, committee, or guardianship). An enduring Power of Attorney generally covers financial affairs, not health care, and is not by itself authority over health information. Consent can be withdrawn at any time (§12).
10. Sharing
- Within your circle — per the permissions the captain sets.
- Care Team Report — only when you choose to share a summary, including via a time-limited link. A link is a deliberate disclosure that a recipient may copy or forward; Vault documents are excluded unless separately selected; creation/access/revocation are audit-logged.
- Service providers — only as needed to run the Service (§8).
- We never sell your information.
11. Retention & deletion
We keep information only as long as needed to provide the Service. Indicative schedule:
| Data | Retention |
|---|---|
| Active circle data | While the circle is active |
| Deleted circle | Removed within 30 days |
| Backups | Retained only as long as needed to operate the service |
| Audit logs | Retained for the period required for security and compliance purposes |
| Breach records | ≥ 24 months (see §13) |
Limits on deletion: information already shared (e.g., a report already sent) cannot be recalled; Vault content whose passphrase is lost is unrecoverable; and we may retain limited data where the law requires.
12. Your rights and how to exercise them
You can access, correct, delete, and withdraw consent (which leads to removal of the relevant information, subject to §11). To make a request, contact privacy@supportcaptains.com. We may need to verify your identity first. We will respond within 30 days (PIPA). If we can't fully comply, we'll explain why.
13. Data breaches
If a breach creates a real risk of significant harm (RROSH) — judged by the sensitivity of the information and the probability of misuse — we will, under PIPEDA, report to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, and we keep records of all breaches for at least 24 months. Under BC PIPA we maintain reasonable safeguards and will notify the OIPC BC and others where appropriate to the circumstances. Our internal runbook is the Breach Response Plan.
14. Minors
Accounts are for adults (19+ in BC). A Care Recipient may be a minor, but their information is entered only by an authorized parent/guardian, and mature-minor confidentiality and custody-related rules may apply.
15. Cookies, analytics & communications
We use only what's necessary to operate and secure the Service. We do not currently use analytics or tracking cookies; if this changes, we will update this section and describe your choices. We send service/transactional messages; any marketing messages will be opt-in with an unsubscribe option, and any SMS will follow applicable opt-in and STOP rules.
16. Changes
We may update this policy; we'll post the new version and date and, for material changes, notify you.
17. Complaints
If we haven't resolved your concern, you may contact the Office of the Information & Privacy Commissioner for BC (OIPC) or the Office of the Privacy Commissioner of Canada (OPC).
Contact us: Privacy Officer, Support Captains — privacy@supportcaptains.com