Last updated: January 2026
This Privacy Policy explains how thePeopleStack Services Inc. ("thePeopleStack," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information, and describes the privacy rights available to individuals whose personal information we handle.
This Policy applies to two distinct categories of personal information, which are treated differently below:
thePeopleStack Services Inc. is a Canadian corporation headquartered at 2080 McNeill Ave, Victoria, BC V8S 2X8. Our workforce consists of employees and independent contractors located in Canada and the United States, delivering services exclusively through certified SaaS platforms — thePeopleStack does not operate its own servers or data centres.
thePeopleStack's primary privacy obligations arise under Canadian law:
Additional frameworks apply only where specifically triggered:
thePeopleStack does not meet the applicability thresholds for the CCPA/CPRA (California) or comparable US state privacy statutes and does not represent compliance with those laws in this Policy. If our client base or processing activity changes such that a US state law is triggered, this Policy will be updated accordingly.
Information collected directly (website and business contacts):
Information collected automatically (website usage data):
Client engagement data:
thePeopleStack does not sell personal information, and does not use client engagement data for any purpose other than delivering the contracted service.
Under PIPEDA, thePeopleStack collects, uses, and discloses personal information only for purposes a reasonable person would consider appropriate in the circumstances, and generally relies on one or more of the following grounds: your consent; the necessity of the processing to perform a contract with you or your employer; compliance with a legal obligation; or thePeopleStack's legitimate business interests, balanced against your privacy interests. Where GDPR applies by virtue of a client contract, the applicable legal basis is identified in that client's DPA.
Our website may use cookies or similar technologies operated by our website platform provider to support core site functionality and to understand aggregate site usage. We do not use cookies to build advertising profiles or to sell personal information. You can control cookies through your browser settings; disabling cookies may affect some website functionality.
thePeopleStack delivers all services exclusively through the following certified SaaS platforms. Each subprocessor is required to hold at least one recognised third-party security certification and to be bound under an executed Data Processing Agreement before any personal data flows through it.
SubprocessorPurposeKey CertificationsRipplingPrimary HR, payroll, and workforce management platformISO 27001, ISO 27018, ISO 42001, SOC 1 & 2, CSA STAR L2Google WorkspaceEmail, documents, communicationsISO 27001, SOC 2, SOC 3SlackInternal and client communicationsISO 27001, SOC 2 Type 2AttioCRM — client relationship managementISO 27001 (A-LIGN)ClickUpProject and engagement managementISO 27001, ISO 27018, SOC 2 Type 2HarvestTime tracking and invoicingSOC 2 (via host), AES-256, TLS 1.2/1.3PandaDocContracts and e-signaturesSOC 2 Type 2, FIPS 140-3
We will notify affected clients at least 30 days before adding or replacing any subprocessor that will process their data.
thePeopleStack is a Canadian corporation. Because our subprocessors are located in the United States and the United Kingdom, personal information may be transferred to and processed in those jurisdictions. These transfers are governed by the contractual safeguards in thePeopleStack's executed subprocessor DPAs and, where GDPR is triggered by a client contract, by Standard Contractual Clauses incorporated into that client's DPA. All data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256).
Subject to applicable law, you have the right to:
We will respond to a verified rights request within 30 days. Requests should be directed to our Privacy Officer using the contact details below. Where the personal information relates to a client engagement, we will direct the request to the relevant client or assist that client in responding, consistent with the applicable DPA, rather than acting on it unilaterally.
Our website and services are directed at businesses and are not intended for individuals under the age of 16. We do not knowingly collect personal information from children.
thePeopleStack protects personal information using administrative, technical, and organisational measures including mandatory multi-factor authentication, full-disk encryption on all contractor devices, encryption in transit and at rest, individually assigned credentials, and a documented Incident Response Plan. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
In the event of a security incident affecting personal information, thePeopleStack follows a defined notification process, including notifying affected clients and, where required, notifying the Office of the Privacy Commissioner of Canada or other applicable regulator.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology stack, or legal obligations. The "Last updated" date at the top of this Policy will be updated accordingly, and material changes will be communicated to active clients as required under their DPA.
Questions, comments, or rights requests relating to this Privacy Policy should be directed to:
Darin Herle, Privacy Officer
darin@thepeoplestack.co
+1 778.676.8684