Implementation Intelligence Platform
Privacy Policy
1. What this policy covers
This policy describes how IIP collects, uses, stores, and shares information when you use the application, including when you connect third-party accounts such as Google.
Our role. For your account information and technical data described below, Wicked Oaks, LLC acts as the data controller (we decide how and why it is processed). For the project content you and your team put into IIP (plans, issues, risks, minutes, stakeholder details), we act as a data processor — we process it only on your instructions to provide the service, and it remains your organization's data.
2. Information we collect
Account information. When you create an account, we collect your name and email address (via our authentication provider, Supabase Auth).
Project data you enter. Project plans, issues, risks, meeting minutes, stakeholder details, and other content you or your team add to IIP. This data belongs to your organization; we process it only to provide the service.
Google account information. If you connect a Google account, we receive your basic profile information (name, email address, profile picture) via OpenID Connect scopes (openid, email, profile).
Google Sheets data (read-only). If you connect Google Sheets as a project-plan source, IIP requests read-only access (spreadsheets.readonly) to the spreadsheets you select. IIP reads cell data from those spreadsheets to sync your project plan into IIP. IIP never writes to, modifies, or deletes your spreadsheets.
Payment information. Payments are processed by Stripe. We do not store full payment card numbers; Stripe provides us with transaction records and subscription status.
Technical data. Standard server logs (IP address, browser type, timestamps) for security and diagnostics.
Cookies and local storage. We use only what is necessary for the app to function — authentication session storage and user preferences. We do not use advertising cookies, cross-site trackers, or third-party analytics beacons.
3. How we use information
- To provide, maintain, and improve IIP (including syncing your connected project-plan sources).
- To authenticate you and manage your account.
- To communicate about your account, billing, and service updates. We send only account- and service-related communications; you may opt out of any non-essential messages at any time.
- To detect and prevent abuse, fraud, and security incidents.
- We do not sell your personal information and do not share it for cross-context behavioral advertising. We do not use your Google data for advertising.
4. Google data — limited use
IIP's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- Google Sheets data is used only to provide the user-facing sync feature you configure — displaying and syncing your project plan within IIP at your direction. We do not use it to improve unrelated features.
- We do not transfer Google user data except: (a) as necessary to provide the user-facing features you configured, with your consent (our hosting and infrastructure providers below); (b) for security purposes, such as investigating abuse; (c) to comply with applicable law; or (d) as part of a merger, acquisition, or sale of assets, and only with your explicit prior consent.
- No human reads your Google user data except: with your affirmative agreement (e.g., a support request you initiate), as necessary for security purposes, to comply with applicable law, or in aggregated form for internal operations.
- We never sell or transfer Google user data to data brokers, advertising platforms, or information resellers; never use it for ads, including retargeting or personalized advertising; and never use it to determine credit-worthiness or for lending purposes.
5. How we share information
We share information only with the service providers required to operate IIP:
- Supabase — database and authentication hosting.
- Netlify — application hosting.
- Stripe — payment processing.
- Google — only the API calls necessary for the integrations you connect.
We will also disclose information if required by law or to protect the rights, safety, or property of Wicked Oaks, LLC, our users, or others. If our subprocessors change, we will update this policy.
6. International transfers
IIP is hosted in the United States, and the information we collect is transferred to, stored, and processed in the United States. Data protection laws there may differ from those in your jurisdiction. By using IIP, you consent to this transfer and processing.
7. Data storage and security
Data is stored in Supabase (PostgreSQL) with encryption in transit (TLS) and at rest. OAuth tokens for connected integrations are stored encrypted and are used only to perform the syncs you configure. Access to production data is restricted to authorized personnel.
8. Data retention and deletion
- Project data is retained for the life of your account. If you cancel, you may request deletion of your tenant data by contacting us; we will delete it within 30 days except where retention is required by law.
- Disconnecting a Google integration immediately stops future syncs. You may also revoke IIP's access at any time via your Google Account permissions page. Stored OAuth tokens are deleted upon disconnection.
- Server logs are retained for up to 90 days.
9. Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing. Contact us at the address above to exercise these rights.
10. Children's privacy
IIP is a business application and is not directed to children under 13. We do not knowingly collect information from children under 13.
11. Changes to this policy
We will post any changes on this page and update the effective date. Material changes will be communicated via email or in-app notice.
12. Contact
Questions about this policy or your data: contact@wicked-oaks.com.