Privacy
Privacy policy
This policy covers the website at cloudversa.io and the CloudVersa platform and applications. It is written to be read rather than skipped.
Last updated 2026-09-02
Who this is
CloudVersa is operated by Pegasus Mortgage Lending Center Inc., 1457 McCowan Road, Suite 202, Toronto, Ontario M1S 5K7, Canada. You can reach us about anything on this page at info@cloudversa.io.
This policy has two halves, because two quite different things happen. The public website collects almost nothing. The applications hold whatever your organisation puts into them, and your organisation decides what that is.
What this website does not do
We do not run analytics, advertising, tag managers, chat widgets, A/B testing or marketing pixels on this site. We do not build a profile of you, we do not sell or share personal information, and we do not track you across other websites.
This site sets no cookies of its own. Nothing here asks you to accept cookies because there is nothing to accept.
What we collect when you use the contact form
If you send us a message, we receive the name, email address, and any company name, subject and message text you type. That message is delivered to our own email inbox and is used to answer you and to keep a record of the conversation. It is not added to a mailing list and it is not passed to anyone else.
The form is served and handled entirely by this site. Your message does not pass through a third-party form service.
Information inside the CloudVersa applications
When your organisation uses a CloudVersa application, it decides what information goes in and who may see it. We hold and process that information on your organisation’s behalf and on its instructions. Your organisation is responsible for what it collects and for having the right to hold it; we are responsible for looking after it while it is with us.
What that includes depends entirely on the application and on how your organisation uses it. It typically covers the records you create, the people and businesses you record against them, files you upload, and the history of what was done and by whom.
To run the account itself we also hold the name, email address and sign-in details of each person your organisation admits, which application each of them has been given, and a record of activity needed to operate and secure the service.
We do not sell your organisation’s information, we do not share it with anyone except the providers named below who process it for us, and we do not use it to advertise. We do not use the contents of your records to build products for anyone else.
Who else processes information for us
We use a small number of providers to run the service. Each receives only what it needs, and each acts on our instructions:
- Vercel — hosts this website and the applications, and keeps short-lived technical logs of requests.
- Supabase — provides the database and the sign-in service behind accounts.cloudversa.io.
- Square — takes payment. Card details are entered with Square and are held by Square, not by us. We see that a payment succeeded, not the card.
- Google Workspace — carries our own email, including messages sent through the contact form.
These providers operate in more than one country, so information may be stored or processed outside Canada, including in the United States, and may be subject to the laws of those countries. If you need to know where a specific piece of information is held, ask us.
This list is the whole of it today. If we add or replace a provider we will change this list and move the date at the top of the page.
Services you connect yourself
An application may let your organisation connect an outside service it already uses — an accounting package, a mailbox, a payment provider. Those connections are optional and are made by your organisation, not by us.
When one is connected, information is exchanged between that service and CloudVersa for as long as the connection lasts, in whichever directions the connection requires. That service is run by someone else, under their own privacy policy, and what they do with what they receive is governed by that policy rather than this one. Disconnecting stops any further exchange; it does not undo what has already been shared.
QuickBooks Online
Law Office can connect to a firm’s QuickBooks Online company so that bookkeeping entries reach the firm’s own ledger instead of being typed twice. The connection is optional, it is made by the firm from the QuickBooks settings screen, and it is authorised through Intuit — we never see the firm’s QuickBooks password.
We ask Intuit for one permission, accounting. We do not ask for payroll access and we do not ask for payments access.
Within that permission we use four things: the company’s details, its chart of accounts, its customer records, and journal entries. We read the first three so entries can be matched to the right accounts and clients, and we write customers and journal entries representing work the firm has already recorded in Law Office. We do not use a firm’s QuickBooks data for any purpose other than keeping those two records in step, and we never use it to build anything for another customer.
The access tokens for the connection are held encrypted. A firm can disconnect at any time from the same settings screen, which stops any further exchange in either direction.
Server logs
Like any website, ours is served by a hosting provider that keeps short-lived technical logs — the requested address, the time, a response code, and the IP address the request came from. These exist so the service can be kept running and abuse can be stopped. We do not use them to identify visitors to this website.
Nothing here is loaded from another company
Every part of this website — its code, its typefaces and its images — is served from our own domain. There is no analytics, no tag manager, no chat widget, no advertising pixel and no embedded content from anyone else, so visiting a page here tells no third party that you did.
Until 2 September 2026 the contact page embedded a map from Google Maps, which told Google when that page was opened. It has been removed and replaced with a link you choose to follow.
Links to other sites
Some pages link out — to Google Maps for directions, and to accounts.cloudversa.io to sign in. Once you follow a link you are on someone else’s site, under their policy, not ours. Until 2 September 2026 we also published a page of headlines read from other publishers’ feeds; that page has been replaced with our own writing, and this site no longer fetches anything from anyone else.
How long we keep things
We keep contact form messages for as long as we need them to deal with your enquiry and to keep a reasonable business record of it. If you would like your message deleted, ask us and we will delete it.
Information inside an application is kept for as long as your organisation keeps it there. When an organisation’s account ends, we will not delete its data for at least 30 days, so there is time to ask us for a copy. After that it is removed, except anything we are required to keep by law.
Your choices
You can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it. Write to info@cloudversa.io and we will respond. If you are not satisfied with how we have handled it, you may contact the Office of the Privacy Commissioner of Canada.
If the information is inside an application, it is held on your organisation’s instructions, so the quickest route is usually your organisation’s CloudVersa administrator. Ask us either way and we will help, and we will tell your administrator rather than change their records without them knowing.
Security
We take reasonable steps to protect information, including restricting access to it and separating one organisation’s data from another’s. We do not claim to have been assessed against any external security or compliance standard, and we will not imply an assessment we have not had. If a particular standard matters to your business, ask us where things stand before you rely on it.
Changes to this policy
If this policy changes we will update the date at the top of the page. Material changes will be described here rather than made quietly.
The related documents are the terms of use and the end-user licence agreement.