The Green Room
Legal

Privacy Policy

Last updated 7 July 2026


The short version: we collect the data you give us, the data your browser sends when you use the site, and the data third-party services hand back when you authorize a connection. We use it to run the Service for you. We do not sell it.

1. Who we are

The Green Room (the "Service") is operated by Mike Cameron, based in Alberta, Canada. You can reach us at mike@mikecameron.ca. For the purposes of data-protection law we are the controller of the personal data described below.

2. Information we collect

2.1 Information you provide

2.2 Information collected automatically

2.3 Information from connected services

When you connect a third-party service, we receive and store the minimum data needed to operate that connection on your behalf:

3. How we use information

4. Legal bases

Where the GDPR or equivalent law applies, we rely on:

5. How we share information

We do not sell personal information and we do not share it for advertising. We share it only in these cases:

6. Google user data — specific disclosures

The Service's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practical terms:

7. QuickBooks Online — specific disclosures

The Service's QuickBooks Online integration follows Intuit's policies for third-party apps. In particular:

8. Data retention

We keep account and content data for as long as your account is active. When you close your account we delete or anonymize personal data within 90 days, except where we are required to keep it longer for tax, accounting, or legal reasons. Server logs are retained for up to 90 days. Backups are retained on a rolling basis and overwritten in the normal course.

9. Security

We protect data in transit with TLS and at rest with the access controls of our hosting and storage providers. Passwords are hashed with bcrypt. OAuth refresh tokens are stored in the member's database row and are only accessible to server-side code. No system is perfectly secure; we do our best, and we tell you promptly if we learn of a breach that affects you.

10. International transfers

The Service is operated from Canada. Some of the infrastructure providers we use may store or process data in other countries, including the United States. Where required, we rely on contractual safeguards (such as the EU Standard Contractual Clauses) for those transfers.

11. Your rights

Depending on where you live, you may have the right to:

To exercise any of these rights, email mike@mikecameron.ca. We will respond within 30 days. If you are in the EU/UK and believe we have not handled your data properly, you can lodge a complaint with your local data-protection authority.

12. Children

The Service is intended for adults. We do not knowingly collect personal information from children under 16. If you believe we have, contact us and we will delete it.

13. Cookies

We use a single first-party session cookie to keep you signed in. We do not use third-party advertising or analytics cookies on the application surface. Public pages may include first-party analytics in the future; this policy will be updated if that changes.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "last updated" date above. Material changes will be communicated through the Service or by email.

15. Contact

Questions, requests, or complaints about this Privacy Policy can be sent to mike@mikecameron.ca.