Privacy Policy
Harbour (“we”, “us”) provides software for digital agencies to operate websites, CRM, communications, automations, and related workflows. This policy describes how we handle personal information when you visit our website or use the product. We design our practices to align with Canadian privacy expectations under PIPEDA for commercial activities.
Accountability
Questions and requests: privacy@getharbour.io. We are responsible for personal information under our control, including information transferred to subprocessors.
Information we collect
- Account and workspace data (name, email, role, agency settings)
- Customer/CRM content you choose to store (contacts, messages, sites)
- Usage, diagnostics, and security logs needed to operate Harbour
- Payment-related identifiers processed by Stripe (we do not store full card numbers)
Consent and purpose
We collect and use personal information to provide and secure Harbour, authenticate users, bill subscriptions, communicate about the product, and meet legal obligations. Where required, we obtain consent or rely on appropriate exceptions. You should obtain the consents your clients and contacts expect before uploading their information.
Email marketing (CASL)
Commercial electronic messages sent through Harbour (when email campaigns are enabled) must comply with Canada’s Anti-Spam Legislation (CASL): valid consent, clear sender identification, and a working unsubscribe mechanism. You are responsible for the lawfulness of lists and message content you send.
Limited collection, use, retention
We aim to collect only what is needed for the stated purposes. We retain information while your workspace is active and for a reasonable period afterward for backups, disputes, and legal requirements, then delete or anonymize it.
Safeguards
We use access controls, encryption in transit, and least-privilege practices appropriate to a multi-tenant SaaS. No safeguard is perfect; report concerns to security@getharbour.io.
Openness, access, and correction
You may request access to or correction of personal information we hold about you by contacting privacy@getharbour.io. Workspace owners may export or request deletion of customer content as described in our Terms.
Sharing and subprocessors
We do not sell personal information. We use subprocessors to host and operate the product, including:
- Vercel — application hosting and related infrastructure
- Neon / Postgres — primary database
- Vercel Blob — object storage for selected durable artifacts
- Stripe — payments and billing
- Twilio — SMS/voice when messaging features are enabled
- Nylas — email and calendar when those integrations are enabled
Subprocessors may process data in Canada, the United States, or other regions where they operate. We will update this list as the stack changes.
Messaging compliance
When SMS is enabled, identity verification is collected and reviewed by Twilio (Trust Hub / Compliance Embeddable). Harbour stores opaque connection identifiers and status fields only — not business registration documents submitted for compliance.
Public forms
Public lead forms remain disabled until bot protection, rate limiting, and consent capture are in place. Do not treat unpublished or unprotected forms as production-safe.
Contact
Privacy: privacy@getharbour.io
Legal identity and mailing address will be published here before broad commercial launch.
Last updated: July 21, 2026