Privacy Policy
Strongside Strategy client tools: Formation and Loch Creative
Effective date: September 7, 2026
Strongside Strategy (“Strongside,” “we,” “us”) builds and operates private business tools for its clients and for its own team. This policy covers the tools listed below, which share one sign-in system and one set of practices.
Formation for Eric Brown Insurance, at ericbrown.strongsidestrategy.com: an operations tracker used by Eric Brown Insurance to manage carrier relationships, projects, recurring client-contact schedules, and call-backs.
Loch Creative, at loch.strongsidestrategy.com: a video production tracker used by Strongside Strategy and the clients it produces work for.
Both tools are private. Only people the business owner has approved can sign in. Nothing in them is public, and we do not sell or rent any information, ever.
Who this policy is for
You, the reader, are probably one of three people: a business owner who uses one of these tools, a team member the owner invited, or someone checking what a tool will do before connecting a Google account to it. This policy is written for all three. If anything here is unclear, email us at services@strongsidestrategy.com and a person will answer.
What we collect and why
Your Google account basics. When you sign in with Google, we receive your name, email address, and profile picture. We use the email address to check that you are on the tool’s approved list and to send you the tool’s own email (a morning summary, a sign-in link). We show your name and picture inside the tool so your colleagues can see who did what. That is all these three things are used for.
Your Google Calendar, read-only, only if you connect it. Formation and Loch Creative can show your upcoming calendar events alongside your work so you can plan the day from one screen. This is optional; the tool asks for it separately, after sign-in, from its Settings page, and works without it. If you connect it, the tool requests read-only access to your calendar. It reads event titles, times, locations, and attendee names as they appear in your calendar, displays them inside the tool, and refreshes that view about every twenty minutes. The tool cannot create, change, or delete calendar events, and cannot see the contents of your email, contacts, or files.
We keep the authorization token Google gives us so that the calendar keeps working without asking you to reconnect. The token is stored encrypted, with a key that lives outside the database. Calendar events themselves are held only in short-lived memory to draw the screen; we do not build a copy of your calendar in our database, and we do not use calendar data for anything other than showing it to you and the colleagues you share the tool with. You can disconnect the calendar at any time from the tool’s Settings page or by removing the tool at myaccount.google.com/permissions. Either action ends our access; we delete the stored token when you disconnect from Settings.
The business information you type into the tool. This is the point of the tool, and it is yours. Depending on which tool and how the business uses it, that can include: carrier and vendor names, contacts, contract terms and dates; project names, steps, notes, and deadlines; sign-in details for third-party portals the business uses (stored encrypted, shown only when you ask to reveal them, with each reveal logged); names and phone numbers of people who called the business and need a call back, with a short note; production schedules, client names, shoot and edit details; aggregate mail-delivery counts from a connected mailing service; and the notes and history entries team members write. We store this information to run the tool for you. We do not read it, analyze it for our own purposes, or use it for anything except operating and supporting the tool.
Ordinary technical records. Like any web application, the tool keeps short-lived logs of requests (time, page, the account making the request, error messages) so we can keep it running and fix problems. Logs are kept for a limited time by our hosting provider and are not used for advertising or profiling. We do not collect anything from your device beyond what the browser sends to any website, and we do not use advertising trackers or third-party analytics.
How we use information from Google
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we only use Google user data to provide and improve the features you can see in the tool (signing in, showing your calendar). We do not transfer Google user data to anyone except as needed to provide those features, to comply with law, or as part of a merger or acquisition with notice to you. We do not use Google user data for advertising, and we do not sell it. No human at Strongside reads your Google user data except with your permission, when needed for security or to comply with law, or in aggregated, anonymized form for internal operations. Google user data is never sent to artificial-intelligence or machine-learning services, and is not used to train any model.
Who else touches the data
We run the tools on a small number of well-known service providers, each of which handles data only on our instructions: Supabase (database and sign-in), hosted in the United States, East region, where business information and encrypted tokens live; Vercel (application hosting), United States; Resend (sending the tool’s own email, such as sign-in links and the morning summary); Google (sign-in, and the Calendar API when you connect a calendar); and Anthropic, an AI service used in Formation only to write a short morning summary of the business’s own tracker records, such as which carrier contracts are waiting and which project steps are overdue. Only the business’s own tracker records go to this service, never Google account data, calendar data, portal sign-in details, or phone numbers. The provider does not use this content to train models.
Some tools can also be connected, by the business owner, to services the business already uses, such as a mailing service (thanks.io) for delivery counts or a CRM calendar feed. Those connections send nothing from Google to the other service and nothing from the other service to Google; each holds only what the business owner chooses to connect, and each can be disconnected from Settings. We do not share information with anyone else, and we do not sell it. We would disclose information if the law required it, and we would tell you unless we were legally prevented from doing so.
How long we keep it
We keep business information for as long as the business uses the tool. When a business stops using a tool, we delete its database within 30 days of the owner’s request, or within 90 days of the tool being retired if no request is made. Encrypted Google tokens are deleted when you disconnect the calendar, when your account is removed from the tool, or when the tool is retired, whichever comes first. Backups made by our database provider expire on their own schedule, typically within 30 days.
Your choices and rights
You can see everything the tool holds about you by using the tool; there is no hidden profile. You can ask us to correct or delete your information, or to send you a copy, by emailing services@strongsidestrategy.com. We respond within 30 days. If you are a team member rather than the business owner, we may need to confirm the request with the owner, since the records belong to the business. You can withdraw calendar access at any time as described above. You can stop using Google sign-in and use an emailed sign-in link instead; ask the business owner to switch your account. Residents of California, the European Economic Area, the United Kingdom, and other places with privacy laws have additional rights, including the right to know, delete, correct, and object. We honor those rights for everyone, wherever they live.
Security
Connections to the tools are encrypted in transit. Sensitive values (Google tokens, third-party portal passwords, connected-service keys) are encrypted at rest with a key held outside the database. Access to the database is limited to the application and to Strongside staff who maintain it. Every table is protected by row-level rules so that only approved accounts can read it. No system is perfectly secure; if we learn of a breach affecting your information we will tell the business owner promptly and help them notify anyone affected.
Children
These tools are business software for adults. We do not knowingly collect information from anyone under 18.
Changes to this policy
If we change this policy in a way that matters, we will update the date at the top and tell the business owners of the affected tools by email before the change takes effect. Minor wording changes may be made without notice.
Contact
Strongside Strategy
services@strongsidestrategy.com
strongsidestrategy.com