TGB //Ecosystem Navigator

Privacy Policy

Last updated: August 27, 2026

1. Introduction

The Groundbreakers Inc. ("Groundbreakers," "we," "our," or "us") is a corporation incorporated under the Canada Business Corporations Act and based in Ontario, Canada. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard personal information when you use the Ecosystem Navigator (the "Service").

Ian Barker, MBA, Founder and Editor, is our Privacy Officer and the person accountable for privacy questions, requests, and complaints. His contact information appears at the end of this Policy.

2. Information We Collect

Account and Organization Information

  • Name, email address, job title, professional role, profile details, and organization membership
  • Authentication identifiers and account status managed through Firebase Authentication
  • Organization names, team membership, invitations, permissions, brand profiles, and uploaded logos

Diagnostic, Research, and User Content

  • Locations, regions, roles, perspectives, and other context you provide
  • Diagnostic questions, answers, scores, generated reports, recommendations, citations, and stakeholder briefs
  • Evidence Base records, collections, saved findings, Ask conversations, and cross-report analyses
  • Documents you upload and information extracted from those documents
  • Build session names, invitations, participant email addresses, completion status, assigned places or roles, individual reports, and group outputs
  • Public or private report share links and information about their creation and use

Payment Information

Payment processing is handled by Stripe. We do not receive or store complete payment card numbers. We receive billing and subscription information needed to administer your account, such as:

  • Stripe customer ID
  • Subscription status
  • Plan, payment status, transaction amount, currency, and limited payment-method details provided by Stripe

Operational Product Activity

  • Pages visited, features used, event timestamps, referrer, device type, and approximate screen size
  • Diagnostic starts, progress, abandonment, report generation and delivery, failures, sharing, and Build activity
  • Purchase-funnel events such as entering checkout, completing a purchase, or reaching a subscription gate
  • A first-party session identifier and, for authenticated or purchase events, account ID, email address, plan, locality, role, or session context where needed to understand and support the event
  • IP address, browser information, security logs, and diagnostic error information generated by our hosting and application systems

We also collect optional Google and Firebase Analytics data only when you allow optional analytics, as explained below.

Communications

We collect information you include in support requests, privacy correspondence, feedback, report emails, and other communications with us.

Public and Derived Local Knowledge

When a user requests research about a place, we may collect and derive structured information from web-search results, public websites, open data, and licensed sources. This may include organization and institution names, publicly identified actors, programs, facilities, infrastructure and other ecosystem assets, categories, descriptions, source URLs, publication details, and provenance or quality signals. Publicly available information about an identifiable person remains personal information where applicable law treats it that way.

3. How We Use Your Information

We use your information to:

  • Provide the Service: Tailor questions, generate reports, extract uploaded documents, answer questions, create briefs, and provide exports and share links
  • Operate Build and Explore: Manage diagnostic sessions, participant access, report access, Evidence Base records, collections, and group or cross-report views
  • Apply Permission-Based Sharing: Where sharing controls are available, apply the selected audience and allowed actions to source records, derived findings, Explore analyses, exports, network aggregates, and publication snapshots
  • Monitor Product Performance: Notify the founder of important service events, understand the diagnostic and purchase funnels, investigate failures and abandonment, and improve reliability and usability
  • Communicate: Send invitations and service messages, respond to inquiries, and provide customer support
  • Process Payments: Manage subscriptions, billing, fraud prevention, and account access through Stripe
  • Benchmark: Create protected comparison datasets and anonymous or aggregate benchmark outputs as described below
  • Build Product Intelligence: Retain and analyze complete reports and related diagnostic, role, geographic, source, and research context to evaluate output quality, improve the Service and its methods, and develop cross-report comparisons and insights
  • Maintain Local Knowledge: Preserve and update structured facts and provenance about local actors and assets so later reports can use accumulated, source-aware regional knowledge
  • Security and Legal Compliance: Authenticate users, prevent abuse, preserve records, enforce our Terms, and comply with legal obligations

4. Data Sharing

We do not sell personal information. We disclose information only as needed for the purposes described in this Policy, including to:

  • Google Cloud and Firebase: Hosting, databases, storage, authentication, application security, and optional analytics
  • Automated Analysis Providers: Question tailoring, report generation, Q&A, synthesis, and extraction of content from uploaded documents
  • Stripe: Checkout, subscription billing, payment processing, and fraud prevention
  • Email Delivery Providers: Service emails, invitations, report delivery, and operational notifications
  • Mapping, Search, and Public Data Providers: Geocoding, maps, local research, and statistical context. We minimize personal information sent to these providers and generally query them using place or topic information
  • Your Organization and Chosen Recipients: Organizers, authorized organization members, session participants, and people with whom you choose to share reports or links, according to the feature and permissions shown in the Service
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

Service providers may change as the Service develops. We require providers to handle information only for authorized purposes and use contractual or other safeguards appropriate to the service. We remain accountable for personal information transferred to processors under our control.

Workspace ownership, organization membership, payment, sponsorship, network affiliation, shared geography, and service-provider status do not by themselves make every item visible or authorize onward disclosure. The Service may apply separate permissions for viewing source material, analyzing it, exporting it, publishing it, resharing it, and managing access. When an authorized user shares content, we disclose it to the selected audience at the selected level of detail and record information needed to administer, audit, expire, or revoke that access.

Customer-directed sharing may include a named or reasonably identifiable finding about a person, organization, place, session, or source when the customer and releasing user have the required authority. This is distinct from a benchmark or network aggregate released by Groundbreakers. We do not treat generated, summarized, or de-identified content as automatically safe to share more broadly when its sources or subjects remain reasonably inferable.

Revoking a grant or public link stops future access through the Service but cannot recall a copy, export, email, or screenshot already received. Recipients of non-public content are subject to the Terms and any purpose, confidentiality, duration, or onward-use restrictions shown with the share.

5. Benchmarking and Anonymization

Benchmarking, comparison, and product learning are core functions of the Service. We may retain complete generated reports and associated diagnostic responses, scores, recommendations, respondent roles, geographic context, source metadata, and structured local knowledge in a restricted internal product-intelligence corpus. Authorized personnel and systems may analyze full report text and linkable records internally where permitted by law to evaluate quality, improve the product and methodology, conduct research, and develop benchmark or comparison models. We do not expose the underlying full reports, invitation lists, uploaded documents, free-text conversations, or individual narrative answers to unrelated users as source records.

Before displaying benchmark or comparison results to unrelated users or the public, we use data minimization, aggregation, de-identification, minimum cohort thresholds, suppression of small or distinctive groups, broadening of role or geography labels, or other controls appropriate to the context. This permits insights such as patterns across a sufficiently large cohort of mayors or equivalent officials, or respondents in the Pacific Northwest, without naming the respondents, customers, organizations, specific places, or source reports where those details could identify them. We design external outputs not to identify an individual respondent or reveal a private report. Because identifiability depends on context, location, cohort size, role, and available outside information, records that have only been de-identified are still handled as personal information where they could reasonably be linked to a person. Only information that is no longer reasonably capable of being associated with an identifiable individual is treated as anonymous.

When we process customer-controlled personal information solely as a processor, the customer's instructions and our Data Processing Addendum govern. We retain or use linkable processor data for our independent product-intelligence purposes only where the customer has authorized that controller processing and applicable law permits it. We may create and retain information that has been irreversibly anonymized so it is no longer personal information.

Explore, Q&A, and automated synthesis are restricted to records the requesting user is authorized to analyze. A derived result remains subject to the permissions and sensitivity of its contributing sources. Network summaries use only the artifact classes, recipients, date ranges, aggregation levels, and privacy controls accepted for that network; affiliation does not permit drill-through to source reports, responses, documents, private conversations, or participant identities.

6. Safeguards

We use administrative, technical, and organizational safeguards appropriate to the nature of the information, including:

  • Encryption of data in transit (HTTPS/TLS)
  • Encryption of data at rest
  • Secure authentication via Firebase
  • Access controls and separation between user, organization, and administrator functions
  • Logging, monitoring, and procedures for investigating security events

While we strive to protect your data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

7. Data Retention and Deletion

We retain account, document, session, and active Evidence Base information while your account or organization uses the Service and for as long as reasonably needed for the purposes described in this Policy, legal obligations, dispute resolution, security, and business records. As described below, some report, product-intelligence, local-knowledge, and operational records are intended to be retained indefinitely, subject to applicable law and valid privacy rights. You may delete individual reports from your workspace or request deletion of your account and associated personal information by contacting us.

Product intelligence and report corpus

We intend to retain indefinitely a restricted internal product-intelligence copy of complete generated reports and related diagnostic, role, geographic, research, source, score, and recommendation data. We use this corpus for report-quality review, product and methodology improvement, research, and protected benchmarks and comparisons. Indefinite retention does not remove applicable access, correction, deletion, restriction, withdrawal, or objection rights. Where a valid request or applicable law requires deletion or cessation, we will remove or stop using the affected personal information unless another lawful ground requires or permits retention.

Public local knowledge

We intend to retain structured local-knowledge records and their source provenance indefinitely so knowledge about regional actors and assets can support later research, reports, source verification, comparisons, and product improvement. We do not claim a right to retain or reproduce entire third-party webpages or protected databases unless permitted by law, licence, or source terms. We review correction or deletion requests concerning identifiable people and update stale or inaccurate information where appropriate.

Operational product activity

First-party operational product activity records are retained indefinitely. Their purpose is to provide a longitudinal record of product performance, diagnostic and purchase funnels, report delivery, reliability, and important customer events. These records may include direct identifiers for authenticated, support, or purchase events. Access is restricted to authorized administration, and applicable access, correction, and deletion rights continue to apply to records that remain personal information.

Deleting a report

When you delete a saved report, we remove it from Reports & Results, active Explore analysis, collections, public share links, and active report analysis tools. It will no longer be used by your Explore charts or interactive evidence queries. Workspace deletion does not automatically delete the restricted internal product-intelligence copy of the complete report and related data described above, operational product activity, security logs, billing records, or benchmark statistics already created from it. The internal report copy is not made available to unrelated customers as an identifiable report. To request broader deletion or object to internal product-intelligence use, contact the Privacy Officer. A record that remains reasonably linkable to a person continues to be treated as personal information.

Build sessions

If a report was created as part of a diagnostic session, the session organizer may retain access to the participant report, session-level results, and aggregate outputs as disclosed when the participant joins the session. Where the organization is the controller and we are its processor, linkable participant information is included in our independent product-intelligence corpus only as authorized by that organization and permitted by law; otherwise, only irreversibly anonymous information may remain for those independent purposes after processor deletion. Participants may contact us to request access, correction, deletion, or exclusion of personal information from active analysis, subject to legal and contractual obligations.

When we complete an account-deletion request:

  • Personal information is deleted, anonymized, or retained where a disclosed continuing purpose, lawful basis, or legal obligation applies, including the product-intelligence purposes described above
  • Anonymous aggregate data may be retained for benchmarking and service-quality purposes
  • Operational product activity is handled as described above, subject to applicable privacy rights
  • Billing, tax, fraud-prevention, and security records may be retained as required by law or legitimate business obligations
  • Residual copies may remain in protected backups until they are overwritten in the ordinary backup cycle

8. Your Rights

Depending on your location, you may have the right to:

  • Access: Request a copy of your personal data
  • Correction: Update inaccurate or incomplete data
  • Deletion: Request deletion of your data
  • Withdraw Consent: Withdraw consent for optional processing, subject to legal or contractual restrictions and reasonable notice
  • Additional Rights: Request deletion, portability, restriction, or objection where the law that applies to you provides those rights

To exercise these rights, contact us at ibarker@thegroundbreakers.net

We may need to verify your identity before completing a request. We will respond in accordance with applicable law. If we cannot resolve a Canadian privacy concern, you may contact the Office of the Privacy Commissioner of Canada.

People in the EEA, European Union, and United Kingdom can find lawful bases, transfer safeguards, regulator complaint rights, and representative information in our EU and UK Privacy Addendum.

9. Cookies, Operational Events, and Optional Analytics

We use cookies and browser storage needed for authentication, security, preferences, session continuity, and first-party operational event correlation. The Service also sends first-party operational events to our own application systems so we can know when diagnostics begin, reports are generated or fail, users enter the purchase funnel, and purchases complete. These records support operation, customer service, founder notifications, and product performance. They are not used for third-party advertising and are not controlled by the optional analytics choice.

Google Tag Manager, Google Analytics, and Firebase Analytics are optional. We load them only after you select "Allow optional analytics." You may decline them and continue to use the Service, or change your choice later from this Privacy Policy. Your choice is stored in your browser.

10. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we learn we have collected data from a child, we will delete it promptly.

11. International Processing

We are based in Ontario, Canada. Personal information may be processed in Canada, the United States, or other countries where our providers operate. It may therefore be subject to the laws of those jurisdictions and accessible to courts, law enforcement, or national-security authorities where legally required. We use contractual or other measures intended to provide a comparable level of protection while information is processed for us.

12. Privacy and Security Incidents

We maintain procedures to assess privacy and security incidents. Where required by law, we record breaches, report them to the appropriate regulator, and notify affected individuals when a breach creates a real risk of significant harm.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. The "Last updated" date at the top indicates when the policy was last revised.

14. Contact the Privacy Officer

For privacy-related questions or concerns:

Email: ibarker@thegroundbreakers.net

Ian Barker, MBA
Founder and Editor; Privacy Officer
The Groundbreakers Inc.
604 Mount Pleasant Road
34023
Rosedale, ON M4S 0C4
Canada