Privacy Policy
Effective date: March 1, 2026 · Last updated: September 5, 2026
MentorStack Inc. (“MentorStack,” “we,” “us,” or “our”) is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform and services.
1. Information We Collect
Account Information
When you create an account, we collect your name, email address, job title, organization name, and role within MentorStack (admin, mentor, or mentee).
Profile Data
Mentors and mentees may provide skills, interests, goals, availability preferences, seniority level, and optional demographic information (e.g. gender, ethnicity) used for aggregate DEI reporting. Demographic data is always voluntary and self-reported, and does not influence match scoring.
Usage Data
We automatically collect information about how you interact with the platform, including pages visited, features used, session frequency, and timestamps. This data helps us improve the product and provide engagement analytics to organization administrators.
Communication Data
Messages sent through our in-app messaging system are stored to enable mentor-mentee communication. Meeting notes and session summaries (including AI-generated content) are stored as part of the mentorship record.
2. The Law That Applies to Us
MentorStack is a Canadian company, so the law that governs how we handle personal information is the Personal Information Protection and Electronic Documents Act (PIPEDA), overseen by the Office of the Privacy Commissioner of Canada. PIPEDA applies to us regardless of where you are, and this policy is written to meet it.
PIPEDA is built on ten principles, and four of them create obligations you can hold us to directly:
- Accountability. A named individual is accountable for our compliance. See section 14.
- Individual access. You can ask what personal information we hold about you, and we must respond within 30 days. See section 8.
- Safeguards. We must protect your information with measures appropriate to how sensitive it is. See section 10.
- Challenging compliance. You can challenge our handling of your information with us, and escalate to the Privacy Commissioner if you are not satisfied. See section 8.
The GDPR applies to a customer's use of MentorStack where that customer is established in the European Economic Area or the United Kingdom, or is otherwise subject to it. We support GDPR obligations for those customers through our Data Processing Agreement. Section 14 explains our current position on EU and UK representatives.
Lawful bases for processing
Where the GDPR applies, we process personal data on the following legal bases. Under PIPEDA the equivalent question is consent, and what stands in for these bases is the consent your organisation and you give when an account is created and used.
- Contract performance:Processing necessary to provide the MentorStack platform and fulfill our obligations under your organization's subscription agreement (e.g., account creation, matching, messaging, analytics).
- Legitimate interest: Processing for product improvement, security, fraud prevention, and aggregate analytics, where our interests do not override your rights.
- Consent: Processing of voluntary demographic data for aggregate DEI reporting and optional AI-powered features. You may withdraw consent at any time without affecting prior processing.
- Legal obligation: Processing required to comply with applicable laws, regulations, or legal proceedings.
3. How We Use Your Information
- To provide, maintain, and improve the MentorStack platform
- To facilitate AI-powered mentor-mentee matching
- To generate session summaries, agendas, and engagement insights
- To send notifications, reminders, and system communications
- To provide aggregate analytics and reporting to organization administrators (never individually identifiable DEI data)
- To respond to support requests and communicate about your account
- To detect and prevent fraud, abuse, and security incidents
- To send product updates, feature announcements, and service-related communications to users who have opted in at registration. You may unsubscribe at any time by clicking the unsubscribe link in any such email or by contacting us at support@mentorstack.co.
4. Data Sharing
We do not sell your personal information. We share data only in the following circumstances:
- Within your organization:Administrators in your organization can view aggregate program metrics. Program admins can also see each member's progress metrics, including goals completed, skill growth, badges, and mentoring tenure. Your mentor or mentee can see your profile information, shared goals, and session history.
- Service providers: We name them rather than describing them in categories. Neon holds the database. Railway runs the application and its background jobs. Cloudflare stores uploaded files and delivers content. Resend sends email. Stripe handles subscription billing. WorkOS brokers single sign-on for organisations that enable it. Grafana Labs receives application logs and metrics. Doppler manages our production credentials (API keys, database access) but does not process customer personal data. AI features reach OpenAI both through OpenRouter, which brokers requests to the provider serving the model, and directly. Anthropic is also named as a sub-processor we can address directly, though no AI feature is configured to reach it at present. Section 5 covers the calendar connection to Microsoft. All of these are in the United States. The Data Processing Agreement lists each one with its purpose and location, and is the version we keep current.
- AI agent programs you connect: If you or your organisation connects an external agent to MentorStack, that program receives the data it asks for. You choose it, not us. Section 6 explains this in full.
- Legal compliance: We may disclose information when required by law, legal process, or to protect the rights and safety of MentorStack or others.
5. Third-Party Calendar Integrations
MentorStack offers an optional integration with Microsoft Outlook Calendar so scheduled mentorship meetings stay in sync with your personal calendar. This integration is off by default and is only enabled when you explicitly connect a calendar and grant access.
What we access
- Calendar events (Microsoft scope
Calendars.ReadWrite): to create, update, and delete the calendar event for a mentorship meeting you schedule, reschedule, or cancel in MentorStack. We only manage events created by MentorStack.
Google API Services Limited Use
If you connect a Google account in the future, MentorStack's use of Google user data will comply with the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we will not sell or transfer your Google calendar data to third parties, will not use it for advertising, and will not use it to develop, improve, or train generalized artificial intelligence or machine-learning models. Access by humans will be limited to what is necessary for security, to comply with applicable law, or with your explicit consent.
Storage and revoking access
OAuth access and refresh tokens are encrypted at rest. You can disconnect a calendar at any time from your MentorStack settings, which deletes the stored tokens, and you can also revoke access directly from your Microsoft account settings.
6. Programmatic and AI Agent Access
MentorStack runs a Model Context Protocol (MCP) server. It lets an AI agent program, such as Claude Desktop or Cursor or any other MCP client, connect to the platform and work with program data on behalf of the account it is connected as. Nothing is connected until someone connects it: access requires a key issued from inside MentorStack, either by you for your own account or by an administrator for your organisation.
We set this out at the same length as the calendar integrations above because it reaches considerably further. Once an agent is connected, it can read and write what the connected account can already see in the product: profiles, including the optional demographic answers where your organisation has turned on diversity reporting, goals and milestones, matches, meetings, in-app messages, survey responses, reflections, cohorts, skills, and program reports. Access is scoped to one organisation and to the role of the account the key belongs to, so a participant key cannot reach another participant's record.
You choose the agent, and it is not one of our providers. The program at the other end of the connection is selected and run by you or by your organisation. We do not choose it, we cannot see what it does with the data once it has it, and it is not a sub-processor of ours. Whoever operates it receives your data in their own right, on whatever terms you hold with them. If your organisation connected an agent on your behalf, your administrator knows which one it is.
Keys you issue for yourself expire after 90 days, and keys issued by an administrator carry an expiry set when they are created. You can revoke any of your own keys at any time from your settings, and an administrator can revoke the ones issued for the organisation. Revoking a key ends that agent's access immediately. Requests made with a key are rate limited, and every tool an agent runs is written to the same append-only audit log as activity in the web application, recording which tool ran, whose record it touched and whether it succeeded. The log records that a disclosure happened, not the content disclosed, so it never becomes a second copy of your messages or reflections.
7. Cookies & Tracking
We use essential cookies to maintain your session and preferences. We use analytics cookies to understand platform usage. You can manage cookie preferences through our consent banner or your browser settings. Declining stops analytics entirely: no storage on your device, and no analytics event sent at all. We do not use advertising trackers, and accepting the banner grants analytics only. It never enables advertising storage, advertising personalization, or the sharing of your data for advertising purposes.
If you accept, interaction events inside the application, such as creating a goal or scheduling a meeting, are sent to Google Analytics and carry an identifier for you personally. That identifier is an opaque code generated by our systems. It is not your name or your email address, and it is meaningless outside our database, but it is stable, so it can link your activity across sessions and devices. Those events also carry your organization’s internal account identifier, your organization’s plan, and whether you are an administrator. They never carry the contents of your goals, meetings or messages, and they never carry the optional diversity information described elsewhere in this policy. If you decline, none of this is sent.
Separately, our servers record a small number of product events that never touch your device and set no cookie, such as a subscription payment succeeding or an organization reaching a plan limit. These are sent to Google Analytics. They carry your organization’s internal account identifier, which is an opaque code meaningful only inside our systems; they carry no name, no email address and no identifier for you personally; and the device identifier they are filed under is a one-way hash of that organization code rather than anything taken from your browser, so they are not linked to your browsing session. They are used only to measure whether the product works. Because they involve no storage on your device, they fall outside the scope of the cookie banner. We rely on legitimate interests, and on the reasonable-purposes standard under PIPEDA, for this processing. You can ask us to stop it at any time using the contact details below.
Sub-Processors
MentorStack uses the following third-party services to operate this website:
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Google Analytics (Google LLC) | Website analytics | Page views, device info, anonymized IP | United States |
| Cloudflare, Inc. | CDN, hosting, image delivery | IP addresses, request metadata | Global (edge), origin United States |
| Microsoft (Bing IndexNow) | Search engine indexing | Public page URLs only | United States |
For the full platform sub-processor list, see our Data Processing Agreement.
Cookies We Use
| Name | Type | Purpose | Duration | Set after consent? |
|---|---|---|---|---|
| _ga | Analytics (third-party, Google) | Distinguishes unique visitors | 2 years | Yes |
| _ga_<container-id> | Analytics (third-party, Google) | Stores session state for GA4 | 2 years | Yes |
| cookie-consent (localStorage) | Essential (first-party) | Remembers your cookie preference | Persistent | No (essential) |
For full details on managing cookies, see our Cookie Policy.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Object to or restrict certain processing activities
- Withdraw consent where processing is consent-based
Exporting or deleting your own data
You do not have to ask your employer for this, and you do not have to ask us. Both controls sit in your own account settings inside the platform, and you operate them yourself.
Export. The export runs on request and returns a single file covering your profile, the organisations you belong to, your aspiration, reflections, survey responses, skill assessments and badges, your goals and their milestones, your meetings, your messages, the demographic answers you chose to give, and any resume you uploaded. Exports are limited to three per hour, and every request is written to our audit log. We do not tell your employer that you ran one.
Deletion. Requesting deletion starts a 14-day cooling-off period, and you can cancel it yourself at any point before it ends. Unlike an export, this one is visible to your organisation: administrators are notified when the period starts, because the organisation may hold a legal ground to keep some records. The Data Retention section below explains what is overwritten at the end of the 14 days and what is kept in anonymised form.
You can also write to privacy@mentorstack.co if you would rather we handled it, or if you can no longer sign in to your account.
Access requests and response times
Under PIPEDA we will respond to a request for access to your personal information within 30 days, at no cost or minimal cost. If we need longer, we will tell you why and give you a new date before the 30 days are up. If we refuse a request in whole or in part, we will tell you the reason and explain how to challenge it.
If you are not satisfied
Raise it with us first at privacy@mentorstack.co and we will work through it with you. If you are still not satisfied, you have the right to complain to the Office of the Privacy Commissioner of Canada. You do not need our permission and you do not have to come to us first, though it is usually faster.
Where your employer holds the answer
For most of the data in a mentorship program, your employer is the organisation that decides what is collected and why, and we handle it on their instructions. If you ask us to delete or correct something that your employer controls, we may need to refer you to them, and we will tell you when that is the case rather than leaving the request unanswered.
9. Data Retention
We retain your data for as long as your account is active or as needed to provide services. When you request deletion, your account enters a 14-day cooling-off period, after which we permanently overwrite your identifying details — your name, email address, and the free-text content you wrote, including goals, messages, and reflections. This happens within 30 days, except where retention is required by law.
We do not delete the underlying records themselves. Your organization's program history — that a mentorship took place, when meetings happened, and that goals were set and closed — is retained with your personal details removed, so the organization keeps a coherent record of its program. These records remain linked to one another, so this is erasure of your personal content rather than destruction of every row. If you would like a full account of exactly which fields are retained and why, contact privacy@mentorstack.co.
Genuinely aggregated statistics, from which no individual can be identified, may be retained for analytics purposes.
Backups. Deleting or anonymising your data on our live systems does not immediately remove it from backups. Backups exist only to restore service after a failure: nothing reads from them for analytics, reporting, or any other purpose, so your data sits unused there until the backup itself is replaced on its normal 30-day schedule. If a backup is ever restored, we reapply any deletion or anonymisation that happened after that backup was taken before the restored data returns to service.
10. Data Security
Our security measures are described in full in section 6 of the Data Processing Agreement. In summary: separation between customer organisations is enforced by row-level security in the database rather than by application code alone; traffic is encrypted in transit using TLS 1.2 or higher, with TLS 1.3 preferred; data at rest is encrypted by our infrastructure providers, with a further layer of AES-256-GCM encryption applied to stored integration credentials; passwords are stored using bcrypt and are never recoverable; multi-factor authentication is available to every user; and authentication, data changes and administrative actions are written to an append-only audit log.
We do not hold a SOC 2 report or ISO 27001 certification. Our control policies are documented and an independent audit is planned. We say this plainly because vague phrasing about “regular security audits” is easily read as a claim that third-party testing has happened, and it has not. No system is completely secure, and we will not imply otherwise.
If there is a breach
PIPEDA sets out what we must do if personal information under our control is lost, accessed without authorisation, or disclosed. Our commitments follow it:
- Where a breach creates a real risk of significant harm to someone, we report it to the Office of the Privacy Commissioner of Canada and notify the affected individuals, as soon as feasible after we become aware of it.
- We notify the affected customer organisation of any breach affecting their data within 72 hours of becoming aware of it, under section 7 of our Data Processing Agreement.
- We keep a record of every breach of security safeguards, whether or not it meets the reporting threshold, and retain those records for at least 24 months. PIPEDA requires this and allows the Privacy Commissioner to ask for them.
11. International Transfers
MentorStack Inc. is a Canadian corporation with its principal place of business in Toronto, Ontario. The infrastructure we use to run the platform is located in the United States. Section 4 names each provider, and our Data Processing Agreement lists each one with its purpose and location.
For personal data originating in the European Economic Area or the United Kingdom, there are two separate steps and they rely on different mechanisms:
- To MentorStack, in Canada.No additional safeguard is required. The European Commission recognises Canada as providing an adequate level of protection for organisations subject to PIPEDA, a decision it reviewed and maintained in January 2024. The United Kingdom recognises Canada on the same basis through its own adequacy regulations. MentorStack is an organisation subject to PIPEDA, which is what those decisions turn on.
- Onward, to our US service providers.This step does need a safeguard, and we hold the European Commission's Standard Contractual Clauses (Decision 2021/914/EU) with the providers named in section 4. Where UK data is involved, the UK International Data Transfer Addendum applies alongside them.
We are not certified under the EU-US or UK-US Data Privacy Framework and do not rely on it. We are a Canadian company and our own transfer position rests on Canadian adequacy.
12. Data Controller & Processor
MentorStack acts as a data processor when handling personal data on behalf of your organization (the data controller). Your organization determines the purposes and means of processing employee data within the platform. MentorStack acts as a data controller for account registration data, platform usage analytics, and direct communications with us.
Enterprise customers can review our Data Processing Agreement (DPA), which details our obligations as a processor, including sub-processor disclosures, breach notification procedures, and audit rights.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the effective date. For significant changes, we will provide additional notice via email or in-app notification.
14. Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
Email: support@mentorstack.co
MentorStack Inc.
Toronto, Ontario, Canada
For data protection inquiries: privacy@mentorstack.co
As PIPEDA's accountability principle requires, one individual is accountable for our compliance with this policy and with PIPEDA. That role sits with MentorStack's founder, and it is reachable at the privacy address below. We have not appointed a Data Protection Officer under GDPR Article 37, because demographic data is off by default, is not collected for most customers, and is not a core activity of the platform. We keep that assessment under review, and it would change if diversity reporting became a standard part of how the product is used. For all data protection inquiries, contact privacy@mentorstack.co.
We have not appointed a representative in the EU or the UK under Article 27 of the GDPR. We have no establishment in either region, we do not market or sell to customers there, and our pricing and platform are offered in the North American market. On that basis Article 3(2) does not currently apply to us. If that changes, and specifically before we onboard our first customer in the EEA or the UK, we will appoint a representative and update this page.
We say this rather than claiming the Article 27(2) exemption for occasional processing. That exemption applies to processing carried out outside the regular course of business, and running a mentorship platform would not qualify once we had users in those regions.
If you are in the EEA or the UK and the GDPR does apply to your use of MentorStack, you have the right to lodge a complaint with your local supervisory authority, and nothing on this page limits that right.