Crown Stone
Privacy policy
Last updated 21 August 2026
Crown Stone Inc. supplies natural stone and operates the Crown Construction Network, the software our customers and trade partners use to run their projects with us. This policy explains what personal information we collect, why, and what we do with it.
What we collect
- What you tell us. Your name, email address, phone number, company, and anything you write in an inquiry, quote request or sample request.
- Your account and its work. If you hold a Crown Construction Network account: your projects, quotes, orders, documents and the messages exchanged with us about them.
- Ordinary technical information. The pages requested from our site and the general information every web server records, used to keep the service running and secure.
Why we use it
To answer your inquiry, quote and supply your materials, run your projects, meet our legal and tax obligations, and keep the service secure. We do not sell personal information. We do not share it with anyone except the service providers who operate parts of the platform for us, and only what those providers need to do their job.
Google user data
Crown staff may connect their own Google Calendar to the Crown Construction Network so that site visits, calls and meetings appear on one board. This is optional, and it is always the individual’s own account and their own choice.
- What we request. One Google permission, calendar.events, which lets Crown read and create events on the connected calendar, plus your email address so we can show you which account is connected.
- What we do with it. We display your events on the Crown calendar board, and we create the bookings you make in Crown. That is the whole use.
- What we store.The connected account’s email address, and the Google refresh token, which is encrypted (AES-256-GCM) under a key held only in our server environment, never in the database. Your calendar events themselves are read when the board is open and are not copied into our records.
- What we never do. We do not sell Google user data, do not use it for advertising, do not use it to train any AI or machine-learning model, and do not transfer it to anyone except as needed to provide this feature or where the law requires it.
- Turning it off. Click Disconnect on the calendar screen. Crown revokes the grant with Google and deletes the stored token immediately. You can also revoke access yourself at myaccount.google.com/permissions.
Crown’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Where your information lives
Personal information is stored in Canada. Our database runs in a Canadian region and our application servers are in Toronto. Some service providers may process limited technical data outside Canada in the ordinary course of delivering their service.
How long we keep it
Account and transaction records are kept for as long as the relationship continues and then for the period our tax and legal obligations require. Inquiries that do not become accounts are kept only as long as they are useful to answer you. Calendar tokens are kept until you disconnect.
Your rights
Under Canadian privacy law (PIPEDA) you may ask what personal information we hold about you, ask us to correct it, and withdraw consent to marketing at any time. Write to [email protected] and we will answer.
Security
Access to customer records is restricted by account and enforced in the database itself, not only in the application. Credentials are held in server environments rather than in our code or database, and sensitive tokens are encrypted at rest. No system is perfect; if a breach ever affects you, we will tell you and the regulator as the law requires.
Changes and contact
If this policy changes materially we will update the date above and, where the change affects you, tell you directly. Questions about privacy go to [email protected].