Skip to content

Black Anvil Privacy Policy

Effective date: September 10, 2026

1. Introduction

Black Anvil Inc. ("Black Anvil", "we", "our", or "us") provides marketing attribution and consulting services that help businesses measure and improve customer acquisition and retention. Protecting personal information is central to how we work. This policy explains what information we handle, the two different roles we play when we handle it, how we protect it, and the choices available to the people it concerns.

2. Two roles, and why the difference matters

We handle personal information in two distinct capacities, and different parts of this policy apply to each.

  • As the organization responsible for our own business. When you visit our website, contact us, or engage us as a client, we decide how your information is handled. For that information we are the responsible organization, and Sections 3 and 5 through 16 apply.
  • As a service provider to our clients. When we deliver services to a client, we may handle information that belongs to that client and their customers, either through access the client grants us to their own systems or through measurement code we install on the client's website. We handle that information only to provide the service, under the client's instructions and our written agreement with them. The client remains the organization accountable for that information. Section 4 describes how we treat it.

3. Information we collect about you (the client)

We collect information about you in two ways.

  1. Information you provide directly
    • Name, business email address, phone number, and other contact details.
    • Billing details such as company address and payment card, processed through our payment provider. Black Anvil does not store full card numbers.
    • Content you send us in the course of an engagement, such as marketing assets, campaign records, and correspondence.
  2. Information collected automatically
    • Our website is hosted on a third-party platform. Like most websites, the host and any tools embedded on our pages may log standard technical information, such as your IP address, and may set cookies when you visit. See Section 12.

We do not operate client-facing accounts, logins, or dashboards. There is nothing for you to log into, and we hold no credentials belonging to you.

4. Information we handle on behalf of our clients

When a client engages us, we handle information about that client's customers in two ways.

Access to the client's own systems. A client may grant us access to systems they already operate, such as advertising accounts, analytics, websites, CRMs, or accounting software. Where they do:

  • We access only what is necessary to deliver the agreed service.
  • We use it only to provide the service to that client, never for our own marketing or any unrelated purpose.
  • We work against the customer IDs, record numbers, or other identifiers those systems provide, rather than names or contact details, wherever the work allows it.
  • We do not retain raw personal information about a client's customers in our own records.
  • Access is granted and revoked by the client, and is scoped to what the engagement requires.

Measurement code on the client's website. In some engagements we install our own measurement code on a client's website to record how visitors arrive and which pages they reach. Where we do:

  • It records only the page address, the time, the advertising codes that brought the visitor to the site, and the client's name.
  • It does not record IP addresses, names, contact details, or anything a visitor enters into a form, and it does not identify individual visitors.
  • It may store the advertising codes in the visitor's browser for the duration of that visit, so that the visit can be connected to the advertisement that prompted it. This is cleared when the visitor closes the tab and is not shared with any other website.
  • The client authorizes the installation in our written agreement with them.

The client remains the organization accountable for information we handle on their behalf. On request, or at the end of an engagement, we return or delete the information we hold for them.

If you are a customer of one of our clients and have a question about your information, please contact that business directly, as they are responsible for it. We will support them in responding.

5. How we use information

We process information only for legitimate business purposes, including to:

  • Provide, operate, and maintain our services.
  • Connect to the third-party platforms our clients authorize, to unify marketing and sales reporting.
  • Generate analytics and reports for our clients.
  • Process payments and manage billing.
  • Detect, prevent, and respond to security incidents, technical issues, and misuse.
  • Improve our services.
  • Comply with legal obligations and enforce our terms.

6. Our data-minimization approach

We are built to hold as little personal information as possible.

  • Wherever the work allows it, we use the customer IDs, record numbers, or other identifiers supplied by a client's own systems, rather than names or contact details.
  • We do not store raw personal information about our clients' customers in our attribution records.
  • Our website measurement code does not collect IP addresses and does not identify individual visitors.
  • Before information is sent to an AI provider for processing, personal identifiers are removed. We do not send raw personal information to those providers.
  • We do not collect, store, or process personal health information.

7. Data storage and security

  • Our application data is stored in a Supabase Postgres database hosted in the AWS Canada (Central) region.
  • Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256.
  • Access to production systems is protected by role-based access control, multi-factor authentication, and audited activity logs.
  • Backups are encrypted and retained for a maximum of 30 days before secure deletion.

8. Sharing and service providers

We do not sell or rent personal information.

Providers we use to run Black Anvil

Category Provider Purpose Safeguards
Hosting and infrastructure Netlify, Supabase Host our website, database, and application services Data processing terms; encrypted storage
Marketing and CRM HubSpot Our own website, marketing, and contact records Access limited to authorized personnel
Payments Stripe Process fees and refunds PCI-DSS compliance; tokenized payment data
AI providers Anthropic (Claude) Produce analytics and written reporting Personal identifiers removed before processing
Legal requirements Courts, regulators Respond to lawful requests Verified requests only; minimum necessary data

Client platforms we connect to

These are systems our clients own and operate. We access them only with the client's authorization, and the client controls that access.

Category Platform Purpose
Advertising Google Ads, Meta Import advertising performance and manage campaigns
Analytics Google Analytics Measure website performance
Websites WordPress Install and maintain measurement code
CRM and operations HubSpot, Jobber Read the campaign and customer records the client authorizes
Accounting QuickBooks Read the revenue records the client authorizes

We keep this list current and will confirm the providers in use on request.

9. Processing outside Canada

Our own database is hosted in Canada. Some of the providers listed in Section 8 operate outside Canada, including in the United States. Where information is processed outside Canada, we use contractual and other means to ensure it receives a comparable level of protection, consistent with Canadian privacy law. Because we minimize and de-identify the information we hold, the personal information exposed to cross-border processing is limited.

10. Data retention

We keep personal information only as long as necessary to provide our services, resolve disputes, and meet legal obligations. Campaign and attribution data is retained for the duration of the engagement and deleted or anonymized within 90 days of its conclusion, unless a longer period is required by law. Information we handle on behalf of a client is returned or deleted in line with our agreement with that client.

11. Your rights and choices

Depending on your location, you may have the right to:

  • Access, correct, or delete your personal information.
  • Object to or restrict certain processing.
  • Withdraw consent at any time, which does not affect processing carried out before withdrawal.
  • Receive your information in a portable form.

To exercise these rights, contact privacy@blackanvil.ca. We may need to verify your identity before acting on a request. If your information is held by us on behalf of one of our clients, we will direct your request to that client, who is responsible for it.

12. Cookies and tracking technologies

Our website at blackanvil.ca is hosted on HubSpot, which uses cookies and similar technologies to operate the site and measure its performance. You can control cookies through your browser settings, though disabling them may affect how the site functions.

Measurement code we install on a client's website is described in Section 4. It does not set cookies.

13. Breach notification

If a breach of our security safeguards creates a real risk of significant harm to an individual, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as required by law. We maintain a record of security breaches. Where a breach affects information we handle on behalf of a client, we will notify that client without undue delay so they can meet their own obligations.

14. Children's privacy

Our services are not directed to children under 16, and we do not knowingly collect personal information from children. If we learn that a child has provided us with personal information, we will delete it promptly.

15. Accountability

Matthew Winchester is responsible for privacy compliance at Black Anvil. Questions, requests, and complaints can be directed to privacy@blackanvil.ca. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada.

16. Changes to this policy

We may update this policy to reflect changes in technology, law, or our practices. If changes are material, we will notify affected clients by email at least 30 days before they take effect. The revised policy supersedes prior versions.

17. Contact us

  • Email: privacy@blackanvil.ca
  • Address: Purdy's Wharf, 1969 Upper Water Street #1300, McInnes Cooper Tower, Halifax, NS B3J 3R7

Copyright Black Anvil Incorporated