Who is responsible
Controller and scope
Hockey Stick Advisory Pty Ltd (ABN 60 659 210 894) provides HockeyStick AI and is responsible for the HockeyStick-side processing described here. Our address is Level 2, 696 Bourke Street, Melbourne VIC 3000, Australia. This policy covers the HockeyStick AI platform, and supplements the company's general privacy policy. The sections below set out the platform's PartnerStack attribution data and the specifics of the Zoom integration.
- What we receive from Zoom and from Webinar registrants, and why we use each type.
- What HockeyStick stores and what it does not store.
- That OAuth tokens and sensitive values are encrypted.
- What happens on disconnect or removal from Zoom.
- That registration data is deleted when no longer needed, and no later than 90 days after the Webinar.
- That Zoom-derived personal information is removed within 24 hours of Zoom notifying us the app was removed.
- How to request access, correction, deletion or withdrawal of consent.
- That we complete deletion from our systems without falsely claiming the Zoom record was deleted, and that Zoom-side correction or deletion is the customer's manual action in Zoom.
- That deleted people are suppressed from re-import and future contact, and no person-derived reporting totals remain after deletion.
Platform data
PartnerStack attribution and reporting
Across the platform, HockeyStick AI integrates with PartnerStack to attribute and report partner-sourced revenue. From an authorized customer's PartnerStack account we receive partner, click, signup, paid-customer and revenue events, which the platform maps to its reporting model (clicks to leads, signups to trials, paid customers to activations, revenue to revenue) and enriches deterministically with the originating partner, asset, channel and region. We retain the reconciled attribution and reporting figures; PartnerStack payout data is out of scope. This data is used to measure programme performance and reconcile partner-sourced revenue, and is subject to the same deletion and suppression controls described below.
Zoom integration
Zoom data we read, write and retain
Host and authorization
We read the authorizing user's Zoom account identity and the granted permission set. We retain the Zoom account identifier, authorization status, permission set, expiry times and the encrypted OAuth grant so the engagement can make authorized calls and refresh access.
Webinar information
We list and read Webinar identifiers, topic, timing, timezone, duration, status and configuration needed to create, bind and verify the engagement's Webinar. We write the approved Webinar configuration to Zoom and retain the identity and verification evidence in HockeyStick.
Registration and enrolment
We send a consented registrant's first name, last name and email to Zoom. We read registrant identity, email, enrolment status and the private join link needed to complete the registration. HockeyStick retains the submitted identity, consent evidence and Zoom registrant identifier; the private join link is returned to the registrant and is not stored in the enrolment record.
Post-event attendance
We read the completed Webinar occurrence, Zoom registrant identifier, join and leave times and participant duration. HockeyStick retains occurrence and registrant fingerprints, timing, calculated watch time, match state and review evidence. Names and email addresses from the attendance response are not used as the attendance match key.
Purpose
Why we use this data
- Connect the licensed host to the correct authenticated HockeyStick engagement.
- Create or update an approved Webinar and verify the exact provider result.
- Enrol a person who submits the HockeyStick-hosted registration form and prevent duplicate provider writes.
- Reconcile attendance after the event and surface missing or ambiguous matches for staff review.
- Protect the integration, diagnose failures, prove consent and meet legal or audit obligations.
We do not sell Zoom integration data. We do not use the authorization to browse unrelated Zoom content.
Protection
Token storage and protection
HockeyStick uses Zoom's Authorization Code flow with PKCE. Short-lived authorization state is bound to the engagement, stored as a hash and expires after ten minutes. OAuth access and refresh grants are encrypted at rest using a separately managed application key. Access is restricted to authorized service paths, refresh rotation is concurrency-safe, and token-shaped values are redacted from diagnostics. No reviewer page stores tokens or makes a Zoom API request.
Sub-processors
Connected service and infrastructure providers
- Zoom receives Webinar and registrant data when an authorized customer uses the integration, and returns the data described above under Zoom's own terms.
- PartnerStack provides partner attribution and conversion data (clicks, signups, paid customers, revenue) for an authorized customer's programme, used for reporting.
- Cloudflare provides public-page and edge delivery for the isolated Activate Public site.
- DigitalOcean provides documented Production application, database and object-storage infrastructure.
We disclose data only where required by law or to protect the security and integrity of the service. Providers receive only the data needed for their role.
Retention & deletion
Disconnect, removal and lifecycle
Authorization behaviour (HAA-213 and HAA-283)
- Authorization state expires after ten minutes and is single-use.
- Production permits one active HockeyStick engagement per Zoom account. A second engagement's authorization fails closed even if the internal Test-only sharing flag is present; sharing can be enabled only by an explicit flag in the exact Test environment, and Staging, Production and an unknown environment reject it.
- A HockeyStick-initiated disconnect immediately removes the local authorization material and stops further use. HockeyStick asks Zoom to revoke the access token when no other active engagement shares the Zoom account. Temporary provider failures use bounded retries; only the encrypted access token needed for those retries is retained, and refresh tokens are not retained for retry.
- If a historical or explicitly Test-shared active engagement still maps to the same Zoom account, HockeyStick skips provider-wide revocation so the other connection keeps working. Retry and permanent-failure outcomes remain visible to operators.
- A valid Zoom
app_deauthorizedevent means Zoom has already removed the app, so HockeyStick does not call Zoom's revocation endpoint again. HockeyStick immediately removes local OAuth grants, pending authorization state, direct Zoom account identifiers and legacy Zoom media links, and marks every affected engagement as requiring authorization. - For every affected engagement, HockeyStick creates one replay-safe, monitored request to delete or anonymize Zoom-derived person data, with completion due exactly 24 hours after the event is received. Duplicate callbacks do not create duplicate lifecycle work; overdue and permanently failed requests are alerted.
- The deauthorization audit retains only one-way fingerprints needed for replay safety and the same 24-hour deadline. Signed webhook payload material is crypto-shredded after processing; bounded non-sensitive delivery metadata is retained for operational evidence.
Person-data lifecycle (HAA-216)
The HAA-216 provider-neutral consumer is implemented. It claims durable work with bounded leases and retries, deletes Zoom-derived attendance, attribution and webhook residue after app deauthorization, clears provider registrant and Webinar identifiers, and records completion evidence without retaining names, email addresses or provider identifiers. The exact 24-hour deadline remains monitored.
For HockeyStick-collected Webinar registration data, scheduled expiry runs at the earlier of the approved purpose end or 90 days after the Webinar. Data-subject access, local correction, deletion and consent-withdrawal are implemented, and deletion or withdrawal creates tenant-bound suppression that prevents replay, re-import and future contact. Aggregate reporting fails closed unless a current, approved audience decision permits retention, so no person-derived reporting totals remain after deletion.
Your choices
Access, correction, deletion and marketing
You may ask to access, correct or delete personal information associated with the Zoom integration, or withdraw a marketing choice, via the privacy and security contact path (begin the message with PRIVACY). Provide the engagement, Webinar and email needed to locate the record; we may verify identity and authority before acting. Local deletion or consent withdrawal prevents the identity from being replayed, re-imported or contacted again.
Beta readiness
Real-participant beta position
Changes to this policy
We will update this page when the permission set, launch capabilities, retention controls or providers materially change. A future AI Companion release would require an updated policy and a new authorization decision.