ScaleToad Privacy Notice

Version: 2026-10-08.1
Effective: October 8, 2026
Operator: Fort de dossiers inc., trading as ScaleToad
Address: 6185 Taschereau Blvd, Brossard, QC J4Z 0E4, Canada
Privacy contact: support@scaletoad.com, attention: Management — privacy requests
Toll-free telephone: pending activation; use the written contacts above.

1. Scope and responsibility

This notice explains our processing of personal information when you visit ScaleToad, create an account, rent infrastructure or contact us. Management handles privacy requests for Fort de dossiers inc. We remain responsible for our own processing and applicable obligations when using providers. Your mandatory privacy rights are preserved wherever applicable.

If you process other people's information on a server, you determine the purposes and permissions for that processing. We host it on your instructions, subject to security and legal obligations. This notice does not replace any processing agreement required for your use case. Contact us before placing regulated information in the service or requesting additional terms.

2. Information and purposes

  • Accounts: email, display name, password hashes, verification/reset records, sessions, IP addresses and security events support sign-in, recovery, fraud prevention and access control. Optional administrator authentication uses encrypted factor information and hashed recovery codes.
  • Purchases and contracts: orders, amounts/currency, payment references, balance/promotion events, rental terms, cancellation requests, acceptance language/version and audit records support delivery, accounting, refunds, disputes and evidence of your instructions. Stripe collects hosted card details; we do not store full card numbers or card security codes.
  • Servers: allocations, selected images, network/access settings, public SSH keys and encrypted guest password-verifier material, if selected, enable provisioning, connection, reconciliation and removal. Your disks contain what you put on them. Necessary infrastructure access can occur for security, support, recovery, abuse investigation or lawful requests.
  • Communications: information you provide in support, privacy, cancellation or abuse requests lets us answer and investigate. Include only necessary information; never send passwords, private keys or full card details.

Information necessary for a requested account or service is required to provide it. Display names and guest-password login are optional. Refusing necessary information can prevent that service; it does not authorize unrelated use.

3. Cookies and browser storage

The panel uses a necessary sign-in cookie, normally lasting up to 30 days, and browser storage for preferences and selected configuration. Security controls can end access earlier. Disabling necessary cookies prevents sign-in. The current service does not use advertising cookies or sell personal information. Guest contents are not used to train general-purpose AI models. Future optional tracking or unrelated processing requires a clear notice and the choices or consent required by applicable law.

4. Recipients and locations

OVHcloud supplies the current Canada East infrastructure. Stripe processes payments. Account mail passes through our mail infrastructure and your chosen email provider. Management may handle contact requests in its independently hosted mailbox. We share only information needed for the relevant function, security, disputes or legal obligations.

Payment, email and operational processing may occur outside Québec or Canada. The VM location does not guarantee every account, payment or support record stays there. Before a new transfer or provider is used, we must satisfy the assessment, protection and notice requirements applicable to that activity. Disclosure may be legally required, necessary to protect people/infrastructure, or part of a lawful business transfer subject to applicable safeguards.

5. Protection and recovery

We use access controls, purpose-appropriate password/token hashing, encryption of sensitive application secrets and restricted operational access. Protection is proportionate to information and risk; no system guarantees perfect security. We handle incidents and required notices under applicable law.

Operational checkpoints and available storage snapshots support maintenance. They do not promise independent disaster recovery or customer disk restoration. Local control-plane checkpoints can contain personal information and matching protected secrets; they exclude guest disks. Keep your own backups unless a separately agreed, enabled backup service specifies its actual coverage.

6. Retention

We retain information only for its necessary purpose and lawful accounting, security, contract or dispute obligations. Active accounts/services require working records. After closure, payment and contract evidence can remain for applicable legal periods, unresolved disputes or holds, without authorizing a new unrelated purpose. Guest removal follows the purchased service's lifecycle. Completed expired authentication-mail delivery records are cleaned up after seven days. Other account, payment, security and checkpoint records have distinct retention needs; closure does not immediately erase every copy. We review retention on closure/privacy requests and must destroy or lawfully anonymize information no longer needed, subject to legal holds. Snapshots do not justify indefinite use.

7. Requests and choices

Write to our privacy contact or postal address to request access, correction, account closure, processing information, consent withdrawal or other applicable rights, including portability where required. We may proportionately verify identity. We explain refusals/legal retention restrictions and applicable review/complaint options. Withdrawal can affect a service requiring the information, but does not remove mandatory rights or permit unrelated processing. You may complain to the competent authority, including Québec's Commission d'accès à l'information or Canada's Office of the Privacy Commissioner as applicable.

8. Changes

We publish dated versions and explain material changes through appropriate service notices. This notice is not blanket consent to future purposes. Additional consent is requested where required before a new optional use. The Terms of Service describe service rights; they do not waive mandatory privacy rights.