TrackPoint × Edwards MBATrackPoint is bringing AI roleplays to the Edwards School of Business MBA programRead the story
Product
PricingResources
Try a RoleplaySign In

TrackPoint Privacy Policy

Last Updated: September 28, 2026

TrackPoint Technologies Inc. ("TrackPoint", "we", "us", or "our") operates an AI roleplay training platform. Organizations build training modules from their material, assign them to their people, and score performance against their own rubrics. This Privacy Policy explains how we collect, use, disclose and safeguard information when you use our platform and related services (the "Services").

Because the Services involve recordings of practice sessions, we have tried to be specific about what we hold and who can see it. We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

Summary

  • We do not sell personal information to advertisers, data brokers or anyone else.
  • We do not use your User Content to train generalized AI models. Recordings and organizational material are used to produce your results and to maintain and support the Services, including diagnosing and fixing problems.
  • Your administrators can review your sessions. They see usage, completion and scores, and can open an individual practice session, including its transcript, feedback and, for roleplays, the audio recording.
  • You can delete your recordings from your account at any time, together with their results and diagnostic records. Closing your account from your settings ends your access but keeps your recordings and results on file; to have them erased, contact our Privacy Officer.

1. Terms Used in This Policy

  • Services: the TrackPoint website, platform and related services.
  • Customer: the company or institution that contracts with TrackPoint.
  • Organization: a Customer's workspace, administered by one or more administrators who manage seats, build training modules and set rubrics.
  • Learner: an individual who holds a seat in an Organization and completes practice sessions and assessments.
  • User Content: recordings of practice sessions, the transcripts derived from them, and the source material an Organization uploads to build training modules and rubrics.

2. Information We Collect

We collect what the Services require in order to operate, and no more.

Account Information

Name, email address and authentication credentials. Where an Organization uses single sign-on, we receive the identifiers its identity provider asserts rather than a password.

Practice Session Recordings

Audio and video of the roleplay, together with the transcript generated from it. This content is what the Services analyze in order to produce scores and feedback.

Organizational Source Material

Documents, playbooks, policies, case notes or call transcripts uploaded by administrators so that training modules reflect the Organization's own business.

Assessment and Completion Data

Rubric scores, pass and fail outcomes, attempt counts, assignment status and completion timestamps. This is the data an Organization reports on.

Usage Data

Features used, and the frequency and duration of sessions.

Billing Information

Subscription and invoice records. Payment card details are collected and stored by our payment processor. We do not store full payment card numbers.

Technical Information

IP address, browser and device information, and diagnostic and security logs.

Connected Integration Data

Where you choose to connect a third-party account, the limited data described in section 5.

3. How We Use Information

  • To deliver training and assessment: to run practice sessions, generate transcripts and feedback, score against your Organization's rubrics, and report completion.
  • To administer accounts: to authenticate you, manage seats, provide support and send service communications.
  • To process payments: to manage subscriptions and billing.
  • To maintain and improve the Services: using usage data and aggregated or de-identified data. Roleplay diagnostic records, which, apart from you, only authorized TrackPoint staff can access, are used to resolve support requests and to diagnose and fix problems with the Services. We do not use your User Content to train generalized AI models.
  • To protect the Services: to detect and prevent fraud, abuse and security incidents, and to meet our legal obligations.

Where PIPEDA requires consent, we obtain it. Where you are a Learner within an Organization, your Customer is responsible for establishing the basis for your participation and for informing you of it.

4. AI and Automated Processing

The Services use artificial intelligence to play a roleplay character, transcribe and analyze practice sessions, and produce scores and written feedback against the rubric your Organization defines.

  • Scores and feedback are training aids. They may be incomplete or inaccurate, and they are not a professional, clinical, legal or medical assessment.
  • No TrackPoint employee reviews your sessions by default. Internal access is limited to the circumstances described in section 7.
  • Your User Content is processed to generate your results and to maintain and support the Services, including diagnosing and fixing problems. It is not used to train, develop or improve generalized AI models.
  • Your Organization determines how scores are used. Any employment, academic or credentialing decision, and any human review of it, is the Organization's responsibility.

5. Google Calendar Integration

The Google Calendar integration is optional and off by default. Its purpose is to suggest a relevant practice scenario ahead of a scheduled meeting. It is not required in order to use the Services.

When you connect it, we read your primary calendar's time zone, which determines when your daily practice email is delivered in your local time, and we read your upcoming events and those of the previous 30 days, to recognize recurring meetings. We also store the connected calendar's email address.

What we retain

From each event we retain only the following:

  • the event title
  • the start time
  • the duration
  • the email domains of the attendees
  • the number of attendees

What we discard

We do not retain event descriptions, locations, conference links, or individual attendee email addresses. These are discarded at the point of retrieval and are never written to our systems. We retain attendee domains rather than addresses, which identifies the company involved without identifying the individuals. Google's event identifier is stored only as a one-way hash.

Credential handling

The credential authorizing our access is encrypted at rest and is never sent to your browser.

Disconnecting

You can disconnect at any time from your account settings. Disconnecting revokes our access at Google and permanently deletes the stored credential and the meeting records derived from your calendar. Roleplays you practised for a meeting, including the meeting details they were built from, stay in your roleplay library and history until you delete them there. You can also review and revoke access directly at myaccount.google.com/permissions, which stops our access. To delete our stored copies as well, also disconnect here; if we find the access revoked first, we delete them ourselves.

6. Google Limited Use

TrackPoint's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, we do not use it for advertising, and we do not use it to train, develop or improve generalized AI models. It is used only to provide the practice reminder feature you enabled.

7. Organization and TrackPoint Access

What an organization administrator can see

  • seat assignment and account status
  • usage and activity data, including session counts and last activity
  • assignment and completion status
  • rubric scores and pass or fail outcomes
  • aggregate reporting across their Organization
  • a Learner's individual practice sessions, including the transcript, feedback and, for roleplays, the audio recording

TrackPoint personnel

Internal access to Customer data is limited to staff who require it, and only in order to resolve a support request raised by you or your administrator, to diagnose and fix a problem with the Services, to investigate a security or integrity issue, or to meet a legal requirement. Access is role-based and logged.

8. Sharing and Disclosure

We do not sell personal information. We disclose it only in the following circumstances:

  • Service providers: the subprocessors described in section 9, each bound by contract to protect the information and to use it only to provide their service to us.
  • Your Organization: as described in section 7.
  • Legal requirements: where required by law, or where necessary to enforce our agreements or protect the rights, property or safety of any person.
  • Business transfer: in connection with a merger, acquisition or sale of assets, subject to the acquirer continuing to honour this policy.

9. Subprocessors

We engage third parties by function, each limited to what their service requires:

CategoryPurpose
Cloud infrastructure providersHosting, storage, databases and compute
AI service providersSpeech processing, roleplay conversation and scoring
Payment processorSubscription billing and payment card handling
Email delivery providerTransactional and notification email
Analytics and monitoring providersProduct analytics and error tracking
IP geolocation providerDetermining your country from your IP address
Form handling providerDelivering contact and demo request forms

A current list of named subprocessors is available to Customers on request.

10. Data Residency and International Transfers

TrackPoint offers regional data residency in Canada, the United States and Europe. An Organization's region is agreed at onboarding, and Canada is the default where no other region is agreed.

Residency covers where your data is stored. Live roleplay conversations and AI analysis of sessions may be processed by our AI service providers outside your Organization's residency region, for example in the United States for a Canadian or European Organization.

TrackPoint is a Canadian company and our personnel administer the Services from Canada.

11. Retention and Deletion

We retain information for the periods below. Some categories have no automatic expiry and are kept until they are erased on request.

CategoryRetention
Account dataFor the life of the account, and after it is closed until it is erased on request or your administrator removes you
Recordings and uploadsUntil you delete them, the Customer contract ends, or your administrator removes you. Closing your account does not erase them, and we do not apply an automatic expiry
Roleplay diagnostic recordsUntil you delete the session, your account is erased, or your administrator removes you. A roleplay that ended before producing a session you can delete, or whose session was deleted before this policy took effect, keeps its record until one of the latter two
Assessment and completion recordsFor the term of the Customer contract, for reporting and audit purposes, unless your administrator removes you from the Organization, which deletes them
Calendar-derived meeting recordsUntil you disconnect the Google Calendar integration or close your account, or we find the access revoked at Google. Roleplays you practised for a meeting, including the meeting details they were built from, stay in your roleplay library and history until you delete them there
Stored integration credentialUntil you disconnect, at which point it is revoked at the provider and deleted, or until we find the access already revoked at Google
Billing recordsAs required by Canadian tax and corporate record-keeping law
System and security logsOn a rolling basis, for security and audit purposes

You can delete individual recordings from your account at any time. This removes the recording, its results and, for a roleplay, its diagnostic record. You can close your account from your account settings (single sign-on users, through their Organization) or by contacting us. Closing your account from settings ends your access but keeps your recordings and results on file; to have them erased, contact our Privacy Officer. Where you are a Learner within an Organization, your administrator may also remove your account. Deletion of User Content is irreversible.

12. Security

  • Encryption in transit and at rest for personal information, User Content and recordings.
  • Credential encryption: third-party integration credentials are encrypted at rest using authenticated encryption and are never exposed to the browser.
  • Role-based access control, separating learner, organization administrator and internal roles.
  • Multi-factor authentication: an Organization that uses single sign-on can require it in its own identity provider, for sign-ins made through single sign-on.
  • Single sign-on is available for Organizations that require it.
  • Least-privilege internal access, granted for a stated reason and logged.

We complete customer security questionnaires and will sign a data processing agreement on request.

13. Your Rights Under PIPEDA

  • Access: review your account information, recordings and results in your account (full transcripts while your licence is active and has usage remaining), or request an account of what we hold.
  • Correction: update your information in settings, or ask us to correct information you cannot edit.
  • Deletion: delete recordings from your account, or ask our Privacy Officer to erase your account and its content.
  • Portability: request a copy of your personal information in a structured, commonly used, machine-readable format.
  • Withdraw consent: subject to legal and contractual limits. Withdrawing consent may mean we can no longer provide the Services to you.
  • Complain: to us, and to the Office of the Privacy Commissioner of Canada.

We respond within the timelines PIPEDA sets. If you are a Learner and the data belongs to your Organization, we may need to direct your request to them, and we will tell you if we do.

14. California Privacy Rights

This section applies to California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").

Categories collected and purposes

We collect identifiers (name, email, account and device identifiers); commercial information (subscription and billing records); internet and network activity (usage and diagnostic logs); audio and visual information (practice session recordings); professional or employment-related information (role, Organization, assessment results); and, where you enable it, limited calendar-derived information. We collect these for the purposes described in section 3.

No sale or sharing

We do not sell personal information and we do not share personal information for cross-context behavioural advertising, as the CPRA defines those terms.

Your rights

  • Know and access: the categories and specific pieces of personal information we have collected about you.
  • Delete: request deletion, subject to legal exceptions.
  • Correct: request correction of inaccurate information.
  • Opt out: we do not sell or share personal information. We will honour a request if that ever changes.
  • Non-discrimination: we will not deny service, charge a different price, or provide a different quality of service because you exercised a right.

How to exercise these rights

Contact our Privacy Officer using the details in section 18. We will verify your identity against the information associated with your account before acting. Authorized agents may submit requests with proof of authorization. Where TrackPoint acts as a service provider to your Organization, we will forward your request to them.

15. United States Users

If you are in the United States, you may request access to, correction of, or deletion of your personal information by contacting our Privacy Officer, regardless of your state of residence. We apply the rights described in this policy to all United States users rather than distinguishing by state. The United States is one of the regions we offer for data residency, and your Organization's region is agreed at onboarding.

16. Breach Notification

We maintain an incident response process. In the event of a breach of security safeguards involving personal information:

  • Affected individuals and Customers: where the breach creates a real risk of significant harm, we will notify affected individuals and the relevant Customer as soon as feasible, which is the standard PIPEDA sets. The notice will describe what occurred, what information was involved, the steps we are taking, and the steps you can take.
  • Regulators: we will report to the Office of the Privacy Commissioner of Canada and to other authorities where required.
  • Records: we maintain records of breaches of security safeguards whether or not notification was required.

17. Children's Privacy

The Services are intended for individuals aged 18 or older, or the age of majority in their jurisdiction. We do not knowingly collect personal information from children. Where an educational institution enrols students, that institution is responsible for confirming eligibility and for obtaining any consent its own regulations require.

18. Contact Us

For questions, requests or complaints about this policy or our data practices, contact our Privacy Officer through the contact form on our website or by mail:

Privacy Officer

TrackPoint Technologies Inc.

15-230 Innovation Blvd.

Saskatoon, SK

S7N 2X8

Canada

Organizations conducting a vendor security review may request our current subprocessor list, our security questionnaire responses, and a data processing agreement.

19. Changes to This Policy

We may update this Privacy Policy. We will post the revised policy on this page and update the "Last Updated" date. Where a change materially reduces your rights, we will give notice through the Services or by email before it takes effect.

20. Related Policies

This Privacy Policy works together with the following:

  • Terms and Conditions - the agreement governing use of the Services.
  • Acceptable Use Policy - what you may and may not do on the platform.
  • Copyright Policy - intellectual property and our notice-and-takedown process.

See how AI roleplays can transform your team's performance.

Transform your team's performance.

Try a RoleplayBook a Demo

Train your Team with AI Roleplays.

Platform

  • Product
  • Security
  • Pricing
  • FAQs

Use Cases

  • Learning & Development
  • Sales
  • Customer Support
  • Human Resources

Industries

  • Technology
  • Healthcare
  • Financial Services
  • Training Agencies
  • Education

Company

  • About
  • Resources
  • Careers
  • Tech Social
  • Contact

© 2026 TrackPoint Technologies Inc. All rights reserved.

Privacy PolicyTerms of ServiceCopyrightUsage Policy