Legal
Privacy Policy
Last updated 31 August 2026
Sundog Labs (sundoglabs.ca) is the application platform operated by BRH Consulting. This policy describes how we collect, use, and protect information when you use the platform, including tenant workspaces hosted on subdomains of sundoglabs.ca.
Who this applies to
This policy covers platform operators, tenant administrators and staff who sign in to a workspace, and individuals who interact with tenant-hosted features (for example, opening an invoice link sent by a tenant). Each tenant is responsible for the client and business records they enter into their workspace.
Information we collect
- Account data — email address, name where provided, and authentication identifiers managed through Firebase Auth.
- Tenant workspace data — records your organization creates or uploads while using a product (clients, invoices, visits, files, and related metadata), stored in our database infrastructure.
- Connected email — when a tenant admin connects Gmail, we store the mailbox address and encrypted OAuth tokens so the workspace can send email on that admin's behalf. We do not read the contents of your Gmail inbox as part of the standard send feature.
- Technical logs — request metadata, error reports, and security events generated by our hosting provider when you use the service.
How we use information
- Provide, secure, and maintain the platform and tenant workspaces.
- Authenticate users and enforce role-based access within a tenant.
- Send email when a authorized user requests it from a connected mailbox (for example, emailing an invoice to a client).
- Diagnose problems, prevent abuse, and improve reliability.
- Comply with law and respond to valid legal requests.
Service providers
We use subprocessors to run the platform, including Google (Firebase Authentication, Gmail API, and cloud hosting), Supabase (managed PostgreSQL), and related infrastructure vendors. These providers process data on our instructions and under their own terms and security programs.
Retention
We retain workspace data while a tenant account is active and for a reasonable period afterward to support backups, billing, or legal obligations. Tenants may request deletion of their workspace data by contacting us. Some logs may be kept longer in aggregated or anonymized form.
Security
We use industry-standard measures including encrypted transport (HTTPS), tenant isolation in the application and database layers, encrypted storage of sensitive tokens, and access controls for platform administration. No method of transmission or storage is completely secure.
Your choices
- Tenant admins can disconnect a linked Gmail account at any time from workspace email settings.
- Platform users may contact us to access or correct account information we control.
- Clients who receive links from a tenant should contact that tenant directly about their business records.
Changes
We may update this policy from time to time. We will post the revised version on this page with an updated date. Continued use of the platform after changes take effect constitutes acceptance of the updated policy.
Contact
Questions about this policy: brian@brhconsulting.ca.