Privacy Policy
Effective Date: December 17, 2024
Last Updated: December 17, 2024
1. Introduction
This Privacy Policy describes how Capysaurus LLC ("Capysaurus," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our capacity management platform and related services (the "Service") available at capysaurus.com.
By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.
2. Information We Collect
2.1 Information You Provide Directly
When you use our Service, you may provide us with the following types of information:
Account Information:
- Email address
- Name
- Password (stored in encrypted/hashed form)
- Organization name
Organization and Team Data:
- Team member names and email addresses
- Role levels and titles
- Capacity targets and allocations
- Salary and compensation information (if you choose to include it)
Client and Work Data:
- Client/customer names and identifiers
- Work catalog definitions
- Effort scores and assignments
- Capacity and workload data
Communications:
- Support requests and correspondence
- Feedback and suggestions
2.2 Information Collected Automatically
When you access our Service, we automatically collect certain information:
Usage Data:
- Pages and features accessed
- Actions taken within the Service
- Time spent on pages
- Error logs and performance data
Device and Connection Information:
- IP address
- Browser type and version
- Operating system
- Device identifiers
- Referring URLs
Cookies and Similar Technologies:
- Session cookies (required for authentication)
- Analytics cookies (to understand usage patterns)
- Security cookies (for spam and bot protection)
2.3 Information from Third Parties
We may receive information from third-party services we use:
- Stripe: Payment and billing information
- Google Analytics: Website usage data
- Google reCAPTCHA: Security verification data
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Providing and Maintaining the Service
- Creating and managing your account
- Authenticating your identity
- Providing the capacity management features you request
- Processing payments and managing subscriptions
- Sending transactional communications (account confirmations, password resets, billing notifications)
3.2 Improving the Service
- Understanding how users interact with the Service
- Identifying and fixing bugs and technical issues
- Developing new features and functionality
- Analyzing usage patterns and trends
3.3 Communications
- Responding to your inquiries and support requests
- Sending important notices about the Service (security alerts, policy changes)
- Sending optional marketing communications (only with your consent)
3.4 Security and Compliance
- Protecting against unauthorized access, fraud, and abuse
- Verifying identity and preventing bot/spam activity
- Complying with legal obligations
- Enforcing our Terms of Service
3.5 Aggregated and Anonymized Analysis
- Creating anonymized, aggregated data for research and benchmarking
- Improving our understanding of capacity management patterns
- Developing industry insights (without identifying individual users or organizations)
4. How We Share Your Information
We do not sell your personal information. We may share your information in the following limited circumstances:
4.1 Service Providers
We share information with third-party service providers who assist us in operating the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database hosting and authentication | Account data, all application data |
| Stripe | Payment processing | Billing information, payment details |
| Resend | Transactional email delivery | Email addresses, email content |
| Google Analytics | Website analytics | Usage data, device information |
| Google reCAPTCHA | Security/spam protection | IP address, browser data |
| ImprovMX | Email forwarding | Email addresses, email content |
These providers are contractually obligated to protect your information and use it only for the purposes we specify.
4.2 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities, including:
- Court orders or subpoenas
- Law enforcement requests
- Regulatory investigations
- Protection of our legal rights
4.3 Business Transfers
If Capysaurus is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
4.4 With Your Consent
We may share your information for other purposes with your explicit consent.
4.5 Within Your Organization
Information you input into the Service (such as team member data, client information, and capacity data) is accessible to other authorized users within your organization based on the permissions set by your organization's administrator.
5. Data Storage and Security
5.1 Data Location
Your data is stored on servers located in the United States (US-East-1 region) through our infrastructure provider, Supabase.
5.2 Security Measures
We implement commercially reasonable technical and organizational measures to protect your information, including:
- Encryption of data in transit (TLS/SSL)
- Encryption of sensitive data at rest
- Secure password hashing
- Access controls and authentication requirements
- Regular security assessments
- Employee training on data protection
5.3 Security Limitations
While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.
5.4 Breach Notification
In the event of a data breach that affects your personal information, we will notify you in accordance with applicable law.
6. Data Retention
6.1 Active Accounts
We retain your information for as long as your account is active and as needed to provide the Service.
6.2 After Account Termination
After you close your account:
- We retain your data for a reasonable period to allow for account reactivation
- We may retain certain information as required by law or for legitimate business purposes (such as resolving disputes or enforcing our agreements)
- Aggregated and anonymized data may be retained indefinitely
6.3 Deletion Requests
You may request deletion of your organization's data at any time by contacting us at support@capysaurus.com. We will comply with deletion requests within ninety (90) days, except where:
- Retention is required by applicable law
- Data is needed to resolve ongoing disputes
- Data has been anonymized and cannot be linked to you
7. Your Rights and Choices
7.1 Access and Correction
You can access and update most of your account information directly through the Service. For assistance, contact us at support@capysaurus.com.
7.2 Data Portability
You may request a copy of your data in a commonly used, machine-readable format by contacting support@capysaurus.com.
7.3 Deletion
You may request deletion of your personal information as described in Section 6.3.
7.4 Marketing Communications
You may opt out of marketing communications at any time by:
- Clicking the "unsubscribe" link in marketing emails
- Contacting us at support@capysaurus.com
Note: You cannot opt out of transactional communications related to your account and the Service.
7.5 Cookies
Most web browsers allow you to control cookies through their settings. Note that disabling certain cookies may affect the functionality of the Service.
8. Special Categories of Data
8.1 Salary and Compensation Data
The Service allows you to optionally input salary and compensation information. This is sensitive data, and we treat it with additional care:
- Salary data is stored with the same security measures as all other data
- Access to salary data is controlled by your organization's administrator
- We do not access individual salary data except as necessary to provide technical support
8.2 Employment-Related Data
You may input employment-related information about team members (names, roles, capacity data). You are responsible for:
- Ensuring you have the legal right to collect and process this information
- Complying with applicable employment and privacy laws
- Informing affected individuals about your use of the Service
9. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us at support@capysaurus.com.
10. International Users
10.1 Data Transfers
If you are accessing the Service from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States, where our servers are located.
10.2 Legal Basis for Processing (for EEA/UK Users)
If you are located in the European Economic Area or United Kingdom, our legal basis for processing your personal information includes:
- Contract: Processing necessary to provide the Service you requested
- Legitimate Interests: Processing for our legitimate business interests (improving the Service, security)
- Consent: Processing based on your consent (marketing communications)
- Legal Obligation: Processing required by law
10.3 Additional Rights (for EEA/UK Users)
If you are located in the EEA or UK, you may have additional rights under GDPR, including the right to:
- Lodge a complaint with a supervisory authority
- Object to certain processing
- Restrict processing in certain circumstances
To exercise these rights, contact us at support@capysaurus.com.
11. California Privacy Rights
11.1 California Residents
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including:
- Right to Know: Request information about the categories and specific pieces of personal information we collect
- Right to Delete: Request deletion of your personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
11.2 Do Not Sell
We do not sell personal information as defined under the CCPA.
11.3 Exercising Your Rights
To exercise your California privacy rights, contact us at support@capysaurus.com. We may need to verify your identity before responding to your request.
12. Third-Party Links and Services
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing them with any personal information.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated Privacy Policy on our website
- Updating the "Last Updated" date at the top of this policy
- Sending an email notification for significant changes (if you have provided us with your email address)
Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Capysaurus LLC
Email: support@capysaurus.com
Address: 15288 Radiance Dr, Noblesville, IN 46060
We aim to respond to all inquiries within thirty (30) days.
15. Additional Disclosures
15.1 Analytics
We use Google Analytics to understand how users interact with our Service. Google Analytics collects information such as how often users visit the site, what pages they visit, and what other sites they used prior to coming to our site. We use this information to improve our Service. Google Analytics collects only the IP address assigned to you on the date you visit our site, rather than your name or other identifying information.
You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout
15.2 Security Tools
We use Google reCAPTCHA to protect the Service from spam and abuse. reCAPTCHA collects information about your device and behavior to determine whether you are a human or automated bot. This data is subject to Google's Privacy Policy: https://policies.google.com/privacy
By using Capysaurus, you acknowledge that you have read and understood this Privacy Policy.