Capitops

Privacy policy

Your data,
on the record.

Effective July 17, 2026

This is the whole policy — written to be read, not scrolled past. If anything here is unclear, email us and we’ll answer in plain English too.

1.Who we are

Capitops is a cloud and SaaS spend-analytics service operated by Capitops Technology Inc., a company incorporated federally in Canada and based in Ottawa, Ontario. Capitops Technology Inc. is the organization accountable for the personal information described in this policy. For anything in it — questions, access requests, complaints — contact hello@capitops.com, or write to us:

Capitops Technology Inc.
10-1338 Wellington St W

Ottawa ON K1Y 3B7

Canada

2.What we collect

We collect only what the service needs to work:

  • Account details. Your name, email address, and — if you sign in with Google — your profile image. Sign-in is by Google or an emailed sign-in link; we never see or store a password.
  • Organization profile. Optional details you choose to add: country, region, industry, team size, fiscal year start.
  • Connection credentials. The read-only role identifiers, API keys, or client secrets you provide to connect a source. These are envelope-encrypted with a dedicated key-management service before they are stored, and used only to read billing and usage data.
  • Spend and usage data. The billing rows we read from your connected providers — costs, services, resource identifiers, tags, license and seat counts — normalized to the FOCUS open billing specification.
  • Billing. Payments are handled by Stripe. Your card details go directly to Stripe and never touch our servers; we store only your plan and Stripe’s subscription identifiers.
  • Alert destinations. Slack webhook URLs, if you set up alerts or the monthly digest.
  • Visits to our public pages. On our marketing pages only — not once you’re signed in — we count page views ourselves: which page, the country, region and city our load balancer reports, and the site you arrived from, if any. We never store your IP address. To tell repeat views apart without a cookie we store a one-way fingerprint mixed with a secret that changes every day, which means today’s visits cannot be connected to yesterday’s or to you. It is built and hosted by us, and the totals are read only by us.

3.What we don’t collect

No third-party analytics, no advertising trackers, no session recording, and no profile of you across sites or over time. The only cookies are our own sign-in session cookies — the visitor counts described above use none. We do not sell or rent your data — to anyone, for anything.

4.Where your data lives

Our database runs in Google Cloud’s Montreal region (northamerica-northeast1). It has no public IP address and is reachable only over a private network. Connection credentials are additionally encrypted with Google Cloud KMS before storage.

5.When data crosses a border

Storage is in Canada; some reads and services are not, and we tell you exactly where before it happens:

  • Provider APIs are read where the provider hosts them, or where you’ve configured your own data to live — for most sources that’s a US endpoint today; Google Cloud is the exception, since we query your billing-export data in whatever region you configured it, which can be Canada. Each source’s connect page discloses its specific cross-border read before you connect it.
  • Stripe, our payment processor, is a US company.
  • The monthly digest is opt-in and sends only aggregate spend figures to Anthropic (US) to generate the plain-English summary. No credentials or resource-level data are included.
  • If you configure Slack alerts, alert text is delivered to Slack (US).

6.How long we keep it

Raw sync payloads and job logs are purged automatically on a schedule. Normalized spend data is kept while your account is active so your history keeps working. Public-page visit counts are deleted after about thirteen months. Request account deletion — email us — and we delete your organization’s data: credentials, spend rows, all of it.

7.Your rights

Under Canada’s federal privacy law (PIPEDA), you can ask for access to your data, correct it, export it, or have it deleted. Much of that is self-serve already — spend data exports as CSV, sources disconnect with one click — and the rest is an email away at hello@capitops.com, or a letter to the address in section 1. You also have the right to complain to the Office of the Privacy Commissioner of Canada.

8.Changes to this policy

If this policy changes, the new version is posted here with a new effective date. For material changes, we’ll email account holders before the change takes effect.