Privacy notice
On this page
Who we are
This service is operated by Trestle Path Analytics Corp., a corporation incorporated under the Canada Business Corporations Act, corporation number 1813547-9, with its registered office in British Columbia, Canada. The corporation is the organization accountable for the personal information described below.
Questions, access requests and deletion requests: info@trestlepath.com.
What we hold, and why
Nothing in this table comes from a schedule file. Everything below is about the account and the connection — who signed in, from what kind of browser, and whether that connection is still open. The schedules you load stay on your computer, and none of the records below can tell us anything about them.
| Information | Why we hold it | Kept for |
|---|---|---|
| Name, organization, email address | To identify your account and send you your activation key and service notices | Until the account is deleted |
| Password | Stored and verified by Google Firebase Authentication. We never see it. | Until the account is deleted |
| Activation key, licence type, trial end date | To grant and to end access | Until the account is deleted |
| Hashed IP address (one-way, salted; the address itself is never written down) | To distinguish one connection from another, so a shared licence is visible | 90 days |
| City, region and country of each sign-in | To spot a single account in use in several places at once | 90 days |
| Browser, operating system, device type | Same purpose, and to diagnose problems | 90 days |
| Date and time of each sign-in | Same purpose | 90 days |
| Characteristics of the browser and computer you sign in from — how your browser draws a test image and plays a test sound, your graphics hardware’s name, which of a fixed list of fonts you have, screen size, time zone, languages, platform, processor count, memory size, touch support, and whether the browser reports itself as automated | These are combined into a one-way hash that lets us recognise “the same computer” without knowing whose it is. It is how we tell a licence shared between two people apart from one person using a laptop and a phone | 90 days |
A random identifier stored by your browser (tp_device_id, in your browser’s local storage) | Helps recognise the same browser when the technical characteristics above change, for example after a graphics driver update | Until you clear your browser storage |
| A short note of what was measured — for example your graphics hardware’s name in readable form | So an administrator reviewing a flag can see what it was based on rather than an unexplained score | 90 days |
| A five-minute “still signed in” signal while the tool is open. It is sent by the sign-in system, and it carries only what identifies the connection: your account, the random browser identifier and the hashed network values already described above, a plain label such as “Chrome on Windows”, and the time. There is nothing about your work in it — no file, no file name, no schedule data, nothing you typed or clicked | Two connections answering at the same moment from different networks is the clearest sign of one licence being used by several people. It is a signal about the connection, not about the work: it is produced entirely outside the part of the tool that reads your schedule, so it does not know which file is open and could not report it | Rolling — each signal replaces the last; the current session only |
| The outcome of a sharing or trial-abuse assessment — a level, a score and the reasons in words | So a decision about an account can be explained and reviewed later | Until the account is deleted; cleared sooner if the flag is released |
| A one-way hash of your email address, recording that this address has used its free trial | The free trial is one per mailbox. The address itself is never stored — only a hash that can answer that one question | Kept after account deletion (see Your choices) |
| Subscription and billing records (plan, add-ons, invoices, payment status) | To give you the access you paid for, and to meet tax and accounting obligations | 7 years, as tax law requires |
| Messages sent through the contact form | To answer you | Until deleted by us |
What we do not do
- We do not store raw IP addresses, and the hashes we do store cannot be converted back into an address — not by you, not by us, and not by anyone who obtained a copy of the database. The same is true of the device characteristics, with one exception we would rather name than gloss: a short readable note of what was measured, such as your graphics hardware’s name, is kept alongside the hash so that a flagged account can be explained to a person.
- We do not use tracking cookies, analytics pixels or advertising tags, and there is no third-party advertising or analytics on this site. There are things your browser does store, and one of them is set by Google — all of it is listed under Cookies and browser storage below.
- We do not sell, rent or share personal information with third parties for their own purposes.
- We never receive, retain or read the schedule files you analyse. Every schedule you open is parsed by code running inside your own browser, and the file is never sent to us. To calculate a review, your browser sends our calculation service only the numbers the review needs (dates, durations, logic and lags, calendar working times, progress, float settings and resource quantities); they are held in memory while the review is calculated, then discarded — never stored, never logged. Names, descriptions, codes, notes, costs, file names and project names are never sent. The calculation service runs on Google Cloud in the United States. Every other record described in this notice sits outside your schedule: activity ends, licences get checked, sessions get counted — your schedule is not in any of it.
Why we record sign-in locations
Access is licensed per person. Recording the approximate location, the technical characteristics of the browser, and whether a session is still open lets us see when one set of credentials is being used by several people in several places — which is the one thing that undermines a per-person licence. All of these are properties of the connection. None of them is derived from, or reveals anything about, the schedules you analyse.
It is used for that purpose and no other. We never look at which schedules you open, which pages you use or what your analysis says — none of that reaches us in the first place. We do not use any of it to assess how hard or how long you work, and no one is managed or appraised on it.
To be exact about what that five-minute signal can and cannot show. It can show that an account had the tool open at a given time, from a connection we can distinguish from another connection. That much is unavoidable if simultaneous use is to be detectable at all. It cannot show anything about the schedule you had open — not its name, not its size, not a single activity in it — because your schedule is read by code running on your own machine and is never transmitted. The signal knows that a session is alive; it does not know what the session is doing. And the timing fact itself is used only for the purpose above: it is not retained as a history of your working hours.
Where a pattern looks like a shared licence, a person reviews it and contacts you before anything is done to the account. The one exception is a free trial, which software can place on hold on its own — explained next.
Automated decisions
One decision on this service is made by software without a person involved: a free trial can be placed on hold where the signals above suggest the same person is opening repeated trials. When that happens the trial is paused and the account returns to a waiting state.
What this is not: it is not a refusal, nothing is deleted, and it never applies to an account that has paid. You are emailed the moment it happens, an administrator reviews it, and a single click restores the trial. If you believe a hold is wrong, reply to that email or write to info@trestlepath.com and a person — not software — will look at it and tell you the outcome.
Every other consequence on this service, including any suspension of a paid licence, requires a person to decide it.
Cookies and browser storage
The complete list. There is no analytics on this site, no advertising, no pixel and no ad tag, so nothing below is here to measure you — but one item is set by Google, and saying nothing about it would be a lie of omission.
| What | Set by | What it is for | How long |
|---|---|---|---|
__session — a cookie | Us | Set only when you sign in. It is how our server confirms you may open the dashboard. It carries nothing about your work and cannot be read by scripts on the page. | Up to 5 days, or until you sign out |
| A Google reCAPTCHA cookie, on Google’s own domain | Part of the invisible bot check described below. It is what lets Google score the request. We never see it. | Set by Google; see their privacy policy | |
tp_session_hint — browser storage | Us | Remembers that you are signed in so the page header paints correctly instead of flashing “Sign in” for a moment. Decides nothing. | Until you sign out or clear browser storage |
tp_device_id — browser storage | Us | The random identifier described in the table above, used to recognise the same browser for licence-sharing checks. | Until you clear browser storage |
| Page preferences — browser storage | Us | Things you set inside the tool: a chosen report layout, an open panel, a theme. They stay in your browser and are never sent to us. | Until you clear browser storage |
None of these can be switched off, and we do not pretend otherwise. The sign-in cookie is what releases the product to you; the bot check is what keeps automated sign-ups and shared licences off a service sold per seat. We show a notice about them rather than a consent box with a refuse button that would refuse nothing. If you would rather not have any of it, the honest answer is not to sign in — and you can still read every page on this site.
Bot and abuse checks
Two third-party checks run on this site to keep automated sign-ups and scripted access out.
- Cloudflare Turnstile runs on the registration form, and on the contact form on our home page. It is fetched only once you start filling one of those in — if you never do, your browser never contacts Cloudflare. You may see a box to tick, or nothing at all.
- Google reCAPTCHA runs invisibly on every page of this site, including this one and the home page, to confirm requests come from a real browser on trestlepath.com rather than from a script written against our API. It shows no puzzle and asks you nothing. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Both providers receive technical information about the request in order to score it. Neither is used to build a profile of you for us, and we receive only the outcome.
Payments
Payments are processed by Paddle.com Market Ltd, who acts as the merchant of record for every purchase. Your card details are entered on Paddle's systems and are never seen, transmitted or stored by us — we receive only the fact that a subscription is active, what it includes, and when it renews. Paddle's handling of your payment information is governed by their own privacy policy.
Who can see it
Only administrators of Trestle Path Analytics. Access to the console is restricted by server-side security rules, not merely hidden in the interface, and every administrative action is written to an append-only audit log.
Where it is held
Your data is stored and processed in the United States. Account data is held in Google Cloud Firestore and Google Firebase Authentication in Google’s United States multi-region, and our server code runs in Google’s us-central1 region (Iowa). We are a Canadian corporation and remain accountable for it under Canadian law wherever it is held; it is subject to the laws of the country it is stored in, including lawful access requests there. If you are procuring on behalf of a public body and need this addressed formally, write to us and we will answer in writing.
The organisations that process personal information on our behalf are:
| Who | What they do for us |
|---|---|
| Google (Firebase / Google Cloud) | Accounts, sign-in, database, our server code, and the invisible reCAPTCHA check |
| Paddle.com Market Ltd | Merchant of record for every purchase (see Payments) |
| Resend | Delivers our email — confirmations, trial notices, account letters |
| Cloudflare | The Turnstile check on the registration form |
| Microsoft | Hosts our info@trestlepath.com mailbox; our admin console reads that one mailbox so enquiries can be answered in one place |
| ipwho.is, then ipapi.co | Convert an IP address into an approximate city at the moment of sign-in. The address is not retained afterwards, and if both are unavailable the city is simply left blank |
Your choices
You may ask us at any time to show you what we hold about you, to correct it, or to delete your account. Deletion removes the account, its sign-in history and the technical records attached to it, is permanent, and takes effect immediately. Write to info@trestlepath.com.
Two things deliberately survive deletion, and we would rather say so than have you find out. The one-way hash recording that an email address has used its free trial is kept, because the trial is one per mailbox and deleting the account would otherwise reset it — it holds no name, no address and nothing else about you. And where access was withdrawn after a decision, a record of that decision and the reasons for it is kept, because an account that has been removed cannot otherwise be accounted for later. Both are held only for those purposes. If you want either reviewed, write to us.
If you would rather not have sign-in activity recorded at all, please contact us before registering, as it is part of how licences are enforced.
Changes
If this notice changes in a way that affects what we collect, registered users will be told by email before the change takes effect.