Privacy
Privacy Policy.
This policy explains how the Nineteen Software company website handles personal information. It describes the website and company inquiry practices approved for launch, including free-consultation requests, Resources, analytics, security, providers, retention, and privacy requests.
- Effective:
- Last materially updated:
- Scheduled review:
Scope and accountability
About this policy.
Nineteen Software is a registered business name of 12674050 Canada Inc., based in Ontario, Canada. The company has designated a Privacy Officer who is accountable for this policy, privacy requests, complaints, retention decisions, and privacy reviews. Contact the Privacy Officer at privacy@nineteensoftware.com.
Nineteen Software uses the principles in Canada's Personal Information Protection and Electronic Documents Act as its conservative baseline for this commercial website. The website is available remotely, but this policy does not claim compliance with every privacy law worldwide.
This policy covers nineteensoftware.com, company inquiries, and qualified free-consultation requests. VoxJournal is a separate product with its own accounts, support, privacy, and legal surfaces. Read the VoxJournal Privacy Policy for product-specific practices.
Data inventory
What the website handles.
- Information you submit
- The company inquiry form collects your name, reply email, optional organization, one controlled inquiry category, and a message. It also receives a Turnstile security token and an empty anti-spam field. Do not send passwords, payment information, journal content, product-user information, or other sensitive information through this form.
- Network and security signals
- Cloudflare processes ordinary request, network, browser, TLS, and challenge signals for hosting, security, rate limiting, and Turnstile bot detection. A short-lived per-IP rate-limit counter keeps submission timestamps for no more than 10 minutes. Full IP addresses are not written to Nineteen Software application logs.
- Short-lived delivery controls
- To prevent accidental duplicate delivery, the Worker creates a secret-keyed digest from the normalized inquiry and keeps the duplicate-suppression claim for 10 minutes. The website does not operate an inquiry database.
- Temporary browser draft
- The Contact page temporarily saves the form draft in session storage in your browser so your message can survive a validation or delivery error. The draft is removed after a successful submission and normally ends when the browser tab's session is closed. It is not analytics data.
- Operational failure records
- A server failure record may contain a UTC timestamp, environment, generated correlation ID, controlled route and method, response status, duration, and a coarse error category. It excludes names, full email addresses, messages, request bodies, tokens, secrets, full IP addresses, arbitrary URLs, and persistent browser or device identifiers.
Company contact
How company and consultation inquiries are used.
Nineteen Software uses the information you voluntarily provide to validate, protect, assess, route, acknowledge, and respond to your company inquiry. A free-consultation request uses the same form, internal fit-and-capacity review, email delivery, and retention rules as other legitimate inquiries. Submitting a request does not create an account, book a meeting, accept a project, or subscribe you to marketing.
The Cloudflare Worker validates the form and Turnstile result, sends normalized text through Resend to the company mailbox at Zoho Mail, and sends a controlled acknowledgement to your reply address. Nineteen Software may then reply through company email. The receipt and requested reply are not newsletter enrolment or unrelated promotion.
The form does not require a separate consent checkbox because this processing is the expected use of a voluntary inquiry and is explained beside submit. You may instead email hello@nineteensoftware.com. Product support belongs on the separate VoxJournal support route.
Practical Resources
Resources do not collect worksheet answers.
Launch Resources are ordinary web pages with print-friendly worksheets. They have no download gate, account, newsletter capture, comments, or separate submission form. Anything you write on a printed worksheet is not sent to Nineteen Software. Resource visits may contribute only to the limited analytics below.
Measurement
Limited, governed analytics.
Cloudflare is the only launch analytics provider. Cloudflare Web Analytics measures aggregate page paths and web performance. A first-party endpoint records only approved outcome events for product views and opens, Services views, Resource views, consultation or company-contact starts and accepted submissions, support redirects, and governed outbound VoxJournal links.
Event properties are fixed approved values. Analytics never receives a form field, inquiry category, worksheet answer, message, email address, Turnstile token, arbitrary free text, full URL, referrer, inbound query string, or campaign value. Global Privacy Control and Do Not Track suppress the first-party outcome events.
Launch uses no optional analytics cookies, advertising pixels, session replay, cross-site identifiers, browser fingerprinting, social embeds, marketing automation, or newsletter tracking. Strictly necessary Cloudflare security processing, including Turnstile, may use network signals or security cookies under Cloudflare's controls. There is no optional-cookie consent banner for the approved launch configuration.
Service providers
Who helps operate the website.
- Cloudflare provides edge hosting, TLS, Workers, static assets, Turnstile, rate limiting, short-lived duplicate suppression, Web Analytics, Analytics Engine, and private operational-log storage on its global network.
- Resend delivers normalized inquiry email and the acknowledgement. Resend states that customer data is principally processed in the United States and that email and delivery logs on the applicable launch plans are normally kept for 30 days, with provider backups normally kept for seven days.
- Zoho Mail stores legitimate company correspondence and reply history. The company uses Zoho's Canadian service region, subject to Zoho's support, subprocessor, deletion, and backup controls.
- GitHub hosts source code, review, automation, and deployment records. GitHub is not part of the production inquiry path and must not receive real inquiry content, production form data, or message fixtures.
Providers may process information in Canada, the United States, or other countries where they and their subprocessors operate. Information in another country may be available to courts, law enforcement, or regulators under that country's laws. Nineteen Software remains accountable for provider selection and proportionate contractual and technical safeguards.
Record lifecycle
How long information is kept.
- Legitimate company and consultation correspondence is normally kept in company email for 24 months after the last substantive interaction.
- Spam or rejected unsolicited email is kept for no more than 30 days after classification and may be deleted sooner.
- Rate-limit timestamps and secret-keyed duplicate-suppression claims expire after 10 minutes.
- Privacy-safe application failure records are kept for 30 days or a shorter provider default. Cloudflare Analytics Engine custom events are kept for three months under the provider's current limit.
- Resend email and delivery logs follow the provider periods above. Deleting active Zoho correspondence does not immediately erase provider-controlled backups; those expire under provider controls.
- A safeguards-breach record is kept for at least 24 months after Nineteen Software determines that the breach occurred.
A scoped legal, security, fraud, complaint, insurance, or preservation hold may temporarily suspend ordinary deletion for an affected record. The Privacy Officer records and reviews the hold, and the record is deleted when it ends unless another lawful need remains.
Individual requests
Your choices and privacy requests.
You may ask about Nineteen Software's handling of your personal information, request access or correction, withdraw consent for an ongoing optional use, request deletion where information is no longer required, or make a complaint. These rights are subject to identity verification, applicable law, information about other people, provider backup limits, and valid retention or hold requirements; deletion is not an absolute right.
Email privacy@nineteensoftware.com. Nineteen Software requests only what is reasonably needed to verify identity and locate the record. Written access requests normally receive a complete response within 30 calendar days. A lawful extension, refusal, or redaction will include the reason and available complaint route.
If a concern is not resolved, you may challenge compliance with the Privacy Officer and may contact the Office of the Privacy Commissioner of Canada. Withdrawing consent does not undo completed processing and may prevent a reply when the information is needed to continue the inquiry.
Safeguards
Security and breach handling.
Nineteen Software uses HTTPS, managed bot checks, allowlisted form fields, strict validation, rate limiting, duplicate suppression, controlled email headers, least-privilege credentials, restricted provider access, privacy-safe logging, automated checks, and recovery procedures. No internet service can be guaranteed completely secure.
Suspected safeguards breaches are contained, investigated, and recorded separately from routine logs. Nineteen Software assesses required notification and reporting. Report a security concern tosecurity@nineteensoftware.com.
The general company form is not intended to collect children's personal information. A parent or guardian who believes a child has submitted personal information should contact the Privacy Officer.
Governance
Changes and scheduled review.
Nineteen Software reviews this policy and its data flows at least every six months and after a material change. A material update receives a new date here. Payments, accounts, sensitive information, attachments, newsletters, marketing tools, optional cookies, profiling, a materially different provider, or intentional targeting of another jurisdiction require a new privacy assessment before release.