Privacy

HockeyStick AI Privacy Policy

How HockeyStick AI handles personal information across the platform, the PartnerStack attribution data it uses for reporting, and the specific data, encryption, retention and deletion controls for the Zoom integration.

Updated 24 August 2026

Who is responsible

Controller and scope

Hockey Stick Advisory Pty Ltd (ABN 60 659 210 894) provides HockeyStick AI and is responsible for the HockeyStick-side processing described here. Our address is Level 2, 696 Bourke Street, Melbourne VIC 3000, Australia. This policy covers the HockeyStick AI platform, and supplements the company's general privacy policy. The sections below set out the platform's PartnerStack attribution data and the specifics of the Zoom integration.

This policy confirms, for the initial seven-permission Zoom release:
  • What we receive from Zoom and from Webinar registrants, and why we use each type.
  • What HockeyStick stores and what it does not store.
  • That OAuth tokens and sensitive values are encrypted.
  • What happens on disconnect or removal from Zoom.
  • That registration data is deleted when no longer needed, and no later than 90 days after the Webinar.
  • That Zoom-derived personal information is removed within 24 hours of Zoom notifying us the app was removed.
  • How to request access, correction, deletion or withdrawal of consent.
  • That we complete deletion from our systems without falsely claiming the Zoom record was deleted, and that Zoom-side correction or deletion is the customer's manual action in Zoom.
  • That deleted people are suppressed from re-import and future contact, and no person-derived reporting totals remain after deletion.

Platform data

PartnerStack attribution and reporting

Across the platform, HockeyStick AI integrates with PartnerStack to attribute and report partner-sourced revenue. From an authorized customer's PartnerStack account we receive partner, click, signup, paid-customer and revenue events, which the platform maps to its reporting model (clicks to leads, signups to trials, paid customers to activations, revenue to revenue) and enriches deterministically with the originating partner, asset, channel and region. We retain the reconciled attribution and reporting figures; PartnerStack payout data is out of scope. This data is used to measure programme performance and reconcile partner-sourced revenue, and is subject to the same deletion and suppression controls described below.


Zoom integration

Zoom data we read, write and retain

Host and authorization

We read the authorizing user's Zoom account identity and the granted permission set. We retain the Zoom account identifier, authorization status, permission set, expiry times and the encrypted OAuth grant so the engagement can make authorized calls and refresh access.

Webinar information

We list and read Webinar identifiers, topic, timing, timezone, duration, status and configuration needed to create, bind and verify the engagement's Webinar. We write the approved Webinar configuration to Zoom and retain the identity and verification evidence in HockeyStick.

Registration and enrolment

We send a consented registrant's first name, last name and email to Zoom. We read registrant identity, email, enrolment status and the private join link needed to complete the registration. HockeyStick retains the submitted identity, consent evidence and Zoom registrant identifier; the private join link is returned to the registrant and is not stored in the enrolment record.

Post-event attendance

We read the completed Webinar occurrence, Zoom registrant identifier, join and leave times and participant duration. HockeyStick retains occurrence and registrant fingerprints, timing, calculated watch time, match state and review evidence. Names and email addresses from the attendance response are not used as the attendance match key.

Not part of this release. HockeyStick AI does not request access to Zoom media files, AI Companion summaries or account-wide administration data.

Purpose

Why we use this data

  • Connect the licensed host to the correct authenticated HockeyStick engagement.
  • Create or update an approved Webinar and verify the exact provider result.
  • Enrol a person who submits the HockeyStick-hosted registration form and prevent duplicate provider writes.
  • Reconcile attendance after the event and surface missing or ambiguous matches for staff review.
  • Protect the integration, diagnose failures, prove consent and meet legal or audit obligations.

We do not sell Zoom integration data. We do not use the authorization to browse unrelated Zoom content.

Protection

Token storage and protection

HockeyStick uses Zoom's Authorization Code flow with PKCE. Short-lived authorization state is bound to the engagement, stored as a hash and expires after ten minutes. OAuth access and refresh grants are encrypted at rest using a separately managed application key. Access is restricted to authorized service paths, refresh rotation is concurrency-safe, and token-shaped values are redacted from diagnostics. No reviewer page stores tokens or makes a Zoom API request.

Sub-processors

Connected service and infrastructure providers

  • Zoom receives Webinar and registrant data when an authorized customer uses the integration, and returns the data described above under Zoom's own terms.
  • PartnerStack provides partner attribution and conversion data (clicks, signups, paid customers, revenue) for an authorized customer's programme, used for reporting.
  • Cloudflare provides public-page and edge delivery for the isolated Activate Public site.
  • DigitalOcean provides documented Production application, database and object-storage infrastructure.

We disclose data only where required by law or to protect the security and integrity of the service. Providers receive only the data needed for their role.

Retention & deletion

Disconnect, removal and lifecycle

Authorization behaviour (HAA-213 and HAA-283)

  • Authorization state expires after ten minutes and is single-use.
  • Production permits one active HockeyStick engagement per Zoom account. A second engagement's authorization fails closed even if the internal Test-only sharing flag is present; sharing can be enabled only by an explicit flag in the exact Test environment, and Staging, Production and an unknown environment reject it.
  • A HockeyStick-initiated disconnect immediately removes the local authorization material and stops further use. HockeyStick asks Zoom to revoke the access token when no other active engagement shares the Zoom account. Temporary provider failures use bounded retries; only the encrypted access token needed for those retries is retained, and refresh tokens are not retained for retry.
  • If a historical or explicitly Test-shared active engagement still maps to the same Zoom account, HockeyStick skips provider-wide revocation so the other connection keeps working. Retry and permanent-failure outcomes remain visible to operators.
  • A valid Zoom app_deauthorized event means Zoom has already removed the app, so HockeyStick does not call Zoom's revocation endpoint again. HockeyStick immediately removes local OAuth grants, pending authorization state, direct Zoom account identifiers and legacy Zoom media links, and marks every affected engagement as requiring authorization.
  • For every affected engagement, HockeyStick creates one replay-safe, monitored request to delete or anonymize Zoom-derived person data, with completion due exactly 24 hours after the event is received. Duplicate callbacks do not create duplicate lifecycle work; overdue and permanently failed requests are alerted.
  • The deauthorization audit retains only one-way fingerprints needed for replay safety and the same 24-hour deadline. Signed webhook payload material is crypto-shredded after processing; bounded non-sensitive delivery metadata is retained for operational evidence.

Person-data lifecycle (HAA-216)

The HAA-216 provider-neutral consumer is implemented. It claims durable work with bounded leases and retries, deletes Zoom-derived attendance, attribution and webhook residue after app deauthorization, clears provider registrant and Webinar identifiers, and records completion evidence without retaining names, email addresses or provider identifiers. The exact 24-hour deadline remains monitored.

For HockeyStick-collected Webinar registration data, scheduled expiry runs at the earlier of the approved purpose end or 90 days after the Webinar. Data-subject access, local correction, deletion and consent-withdrawal are implemented, and deletion or withdrawal creates tenant-bound suppression that prevents replay, re-import and future contact. Aggregate reporting fails closed unless a current, approved audience decision permits retention, so no person-derived reporting totals remain after deletion.

Honest completion. HockeyStick completes deletion from its own systems without falsely claiming the corresponding Zoom record was deleted. Correction or deletion of a registration already enrolled in Zoom is a manual action the customer performs in Zoom; a request that depends on that provider operation fails closed until it is available, and HockeyStick does not report local completion while provider data or provider mail capability remains live.

Your choices

Access, correction, deletion and marketing

You may ask to access, correct or delete personal information associated with the Zoom integration, or withdraw a marketing choice, via the privacy and security contact path (begin the message with PRIVACY). Provide the engagement, Webinar and email needed to locate the record; we may verify identity and authority before acting. Local deletion or consent withdrawal prevents the identity from being replayed, re-imported or contacted again.

Beta readiness

Real-participant beta position

[Position to confirm] The agreed statement on real-participant beta use will appear here. Prerequisites recorded to date: privacy-owner ratification of the purpose and retention decision, approved real-cohort aggregate evidence, a provider-owner decision and tested Zoom-side operation for correcting or deleting an already-enrolled registration, and intended-environment verification of the deletion worker, alert recipients and data-subject runbook. Until confirmed, provider-enrolled correction or deletion fails closed with an explicit provider-operation requirement rather than claiming incomplete work succeeded.

Changes to this policy

We will update this page when the permission set, launch capabilities, retention controls or providers materially change. A future AI Companion release would require an updated policy and a new authorization decision.