Legal
Privacy
We hold three different kinds of data and they are governed differently. This page separates them instead of averaging them into one paragraph.
- Last updated
- 2026-09-01
- Status
- Draft, pending legal review
This document is a working draft written by the ShareCo team and is pending review by Canadian counsel. It describes what we actually do today. Where it conflicts with a signed engagement letter, the engagement letter governs.
In short
- We do not sell data, run advertising trackers, or share enquiry details with anyone outside ShareCo.
- Your Salesforce data stays in your org. We reach it with named accounts issued to individual ShareCo people, never a shared login.
- Test records we create during an engagement are deleted once the work is verified.
- You can ask for a copy of what we hold about you, or ask us to delete it, by writing to privacy@shareco.ca.
The summary is not the agreement. The numbered sections below are.
Who we are
ShareCo is a Salesforce consultancy and training business operating from Vancouver, British Columbia. We are the organisation responsible for the personal information described here.
Privacy questions, access requests and complaints go to privacy@shareco.ca. A named person on our team owns that inbox and answers it. We aim to respond within five business days and to resolve access requests within thirty days, which is the period British Columbia law sets.
The three kinds of data we hold
Most privacy notices blur these together. They carry different risk and different rules, so we keep them apart.
- Enquiry data
- What you type into the contact form on this site, plus the email thread that follows. Held by ShareCo. Small, and entirely under our control.
- Academy account data
- Your name, work email, organisation, course progress, assessment scores and any certificate we issue. Held by ShareCo because a certificate has to stay verifiable after you finish.
- Client system data
- The records inside your Salesforce org, your accounting system and your other connected tools. This is yours. It stays in your systems. We work inside them rather than copying them out.
What this website collects
- The fields you submit on the contact form: your name, work email, company, Salesforce edition, what you are trying to do, and your deadline.
- Standard web server logs, including IP address, user agent and requested path, kept for security and debugging.
- Aggregate page view counts, with no cross-site identifier and no advertising profile attached to them.
We do not run advertising pixels, we do not sell or rent contact details, and we do not add anyone to a mailing list from a contact form submission. Newsletter subscription is a separate action you take on purpose.
Client data during an engagement
During an engagement we work inside systems you own. The controls are described in full on the security page. The privacy-relevant parts are these.
- Access is granted to named individuals at ShareCo, under your own user administration, with the permissions the work requires and no more. You can revoke it yourself at any time without asking us.
- We do not export production data to our own machines as a matter of course. Where a specific piece of analysis needs an extract, we agree the scope first, work in a location you control where possible, and delete the extract when the analysis is signed off.
- Test records we create while verifying work are deleted once verification is complete. Where a record cannot be deleted, we tell you which one and why.
- Person-level data is not sent to AI models. Where a model is used on your records, the inputs are minimised to what the task needs, and contact names are excluded from prompts.
- Screenshots and written documentation that leave your org are redacted before they do.
Why we are allowed to hold it
For enquiry and Academy data we rely on your consent, given when you submit a form or create an account, and on the legitimate need to perform the contract you have entered into with us. You can withdraw consent for marketing at any time without affecting service delivery.
For client system data we act as a service provider to you. Your own privacy obligations to your customers and staff continue to apply, and our engagement letter records that we process that data only on your instructions.
We operate under the federal Personal Information Protection and Electronic Documents Act and, for private-sector activity in our home province, the British Columbia Personal Information Protection Act.
Service providers and where data sits
We use third-party providers for hosting, email, payment processing and error monitoring. Some of them store data in the United States, which means that data can be subject to lawful access requests under United States law. We state that plainly rather than burying it.
We will give you the current list of providers, what each one holds and where it is hosted, on request to privacy@shareco.ca. We do not consider that list confidential.
Client system data is a deliberate exception. It stays in the systems you already run, under whatever residency terms you have agreed with those vendors. We do not add a hop.
How long we keep things
- Enquiries that did not become work
- Deleted 24 months after the last message in the thread.
- Engagement records
- Kept for 7 years after the engagement ends, because tax and professional record-keeping rules require it. Working extracts are deleted much earlier, at sign-off.
- Academy accounts and certificates
- Kept while the account is active. A certificate record is kept indefinitely so its public verification link keeps working, because a credential nobody can check is worthless. You can ask us to revoke and delete one.
- Server logs
- Kept for 90 days, then deleted.
Your rights
- Ask what personal information we hold about you and get a copy of it.
- Ask us to correct anything that is wrong.
- Withdraw consent, subject to legal and contractual obligations that we will name if any apply.
- Ask us to delete what we hold, where we are not required to keep it.
- Complain to us first, and then to the Office of the Information and Privacy Commissioner for British Columbia or the Office of the Privacy Commissioner of Canada if you are not satisfied.
We do not charge for access requests. We will confirm your identity before releasing anything, because handing your data to someone impersonating you is the failure that matters most here.
If something goes wrong
If we confirm an incident affecting your data, we tell you within one business day of confirming it, with what we know, what we do not yet know, and what we are doing. We do not wait for a complete picture before the first message.
Where a breach creates a real risk of significant harm we report it to the Office of the Privacy Commissioner of Canada and notify affected individuals, as federal law requires. We keep a record of every breach for at least 24 months, including the ones that did not meet the reporting threshold.
Changes to this notice
When this notice changes we update the date at the top. If a change materially affects how we handle personal information, we email account holders rather than relying on you to re-read the page.