Privacy Policy
This Privacy Policy explains how Atlantic Ops collects, accesses, uses, stores, shares, and protects information through our website, consulting services, applications, integrations, marketplace products, subscription services, and custom software solutions.
Effective date: July 18, 2026
1. Scope of This Privacy Policy
This Privacy Policy applies to Atlantic Ops websites, consulting engagements, applications, integrations, marketplace apps, subscription services, custom software, and other products or services operated by Atlantic Ops.
This includes Atlantic Ops products such as Linear, applications listed through third-party marketplaces, HubSpot-connected applications, and future Atlantic Ops products unless a separate product-specific privacy notice states otherwise.
Certain applications may require additional privacy disclosures based on the information they access, the third-party systems they connect to, or the functionality they provide. Where applicable, those disclosures supplement this Privacy Policy.
2. Our Role When Handling Information
Atlantic Ops may handle information in different capacities depending on the service being provided.
When you submit information directly to Atlantic Ops through our website, sales process, support channels, billing systems, or other direct interactions, Atlantic Ops determines how that information is used for legitimate business purposes.
When an organization connects an Atlantic Ops application to HubSpot or another third-party platform, the organization generally controls the business data contained in that connected account. Atlantic Ops accesses and processes that information only as required to provide, secure, maintain, support, and improve the requested application or service, subject to applicable agreements and law.
3. Information We May Collect
Depending on how you interact with Atlantic Ops, we may collect or process the following categories of information.
Contact and Business Information
This may include:
- Name.
- Business email address.
- Telephone number.
- Job title.
- Company name.
- Business address.
- Project requirements.
- Support requests.
- Communications with Atlantic Ops.
Account and Application Information
When you register for or use an Atlantic Ops product, we may process information such as:
- User and account identifiers.
- Organization or portal identifiers.
- Application settings and configuration.
- User roles and permissions.
- Subscription and account status.
- Installation and connection information.
- Application usage information.
Connected Platform Data
Atlantic Ops applications may connect to third-party platforms such as HubSpot or other business systems.
Depending on the application and permissions authorized by the customer, an application may access information such as:
- CRM records.
- Contacts.
- Companies.
- Deals.
- Tickets.
- Line items.
- Custom objects.
- Properties and field values.
- Record associations.
- Owners and users.
- Activities and engagement information.
- Application-specific business data.
The specific information an application can access depends on the permissions or OAuth scopes requested by that application and approved by the customer during installation.
Atlantic Ops applications are intended to request only the permissions required to provide their documented functionality.
Authentication and Integration Credentials
Applications may use OAuth tokens, API credentials, access tokens, refresh tokens, connection identifiers, or similar authentication mechanisms to communicate securely with connected platforms.
These credentials are used only to operate authorized integrations and application functionality and are treated as sensitive operational information.
Technical, Usage, and Diagnostic Information
We may collect technical information required to operate, secure, troubleshoot, and improve our services, including:
- IP address.
- Browser and device information.
- Operating system information.
- Application events.
- Error logs.
- Diagnostic information.
- Authentication events.
- API request metadata.
- Performance information.
- Feature usage information.
Billing and Transaction Information
Where a paid service or subscription is provided, we may process billing information, subscription details, payment status, invoices, and related transaction records.
Payment card or banking information may be processed directly by payment service providers rather than stored by Atlantic Ops.
4. How We Use Information
Atlantic Ops may use information for purposes including:
- Providing consulting and professional services.
- Operating Atlantic Ops websites and applications.
- Authenticating users and connected accounts.
- Performing actions requested by users through an application.
- Synchronizing information between authorized systems.
- Displaying connected information within applications.
- Maintaining application configuration and preferences.
- Providing technical support.
- Diagnosing errors and service interruptions.
- Monitoring security and preventing unauthorized use.
- Managing subscriptions and billing.
- Improving products, services, usability, and performance.
- Developing new features and products.
- Communicating service-related information.
- Complying with legal, contractual, and regulatory obligations.
Where possible, product analytics and product improvement activities may use aggregated, statistical, or de-identified information rather than identifiable customer data.
5. HubSpot-Connected Applications
Atlantic Ops develops applications and integrations that may connect directly with HubSpot.
When a customer installs an Atlantic Ops application through HubSpot, the application may request specific OAuth scopes. These scopes determine which HubSpot APIs and categories of information the application is permitted to access.
The permissions requested may differ by product. Atlantic Ops applications are designed to use authorized HubSpot data only for the functionality described for that application.
Depending on the application, data movement may be:
- Read-only from HubSpot.
- Written into HubSpot.
- Bi-directionally synchronized.
- Processed temporarily to perform a requested action.
- Stored when required for application functionality.
Product documentation and marketplace listings may provide additional information describing the specific data accessed and how it flows between HubSpot and the applicable Atlantic Ops application.
6. Atlantic Ops Applications and Products
Atlantic Ops develops marketplace applications, subscription services, custom applications, CRM extensions, integrations, portals, and other operational technology products.
Current and future products may have different technical architectures and data requirements. Each application should access only the information reasonably required for its intended functionality.
Where an application introduces materially different privacy practices, Atlantic Ops may publish additional product-specific documentation or a supplemental privacy notice.
7. Linear
Linear is an Atlantic Ops application and is covered by this Privacy Policy.
Information processed by Linear may include account information, configuration data, application usage data, technical logs, and information accessed from connected platforms where required to provide Linear's functionality.
As Linear evolves, additional product-specific disclosures may be published where new features materially change the categories of information accessed or the ways information is processed.
8. Custom Applications and Client Development
Atlantic Ops may design and operate custom applications, integrations, portals, automation, or other technical solutions for individual customers.
In these situations, the applicable contract, statement of work, data processing terms, technical documentation, or customer instructions may establish additional requirements governing information processed by the solution.
Where Atlantic Ops processes information solely on behalf of a customer, the customer is generally responsible for determining the lawful basis, notices, permissions, and internal policies governing its use of that information.
9. Information We Do Not Need
Customers should not intentionally provide Atlantic Ops with sensitive personal information unless it is specifically required for an agreed service and appropriate safeguards have been established.
Atlantic Ops applications should not be used to process highly sensitive information outside the documented scope and intended use of the applicable product.
10. Artificial Intelligence and Automated Processing
Atlantic Ops may use automation, machine learning, or artificial intelligence technologies in certain products or internal business processes.
Where an application uses artificial intelligence in a way that materially affects how connected customer data is processed, the applicable product documentation should describe that functionality.
Customer-connected CRM data will not be intentionally used to train general-purpose artificial intelligence models unless that use is specifically disclosed and appropriately authorized.
11. How We Share Information
Atlantic Ops may share or make information available to third parties where reasonably necessary to operate our business and provide our services.
This may include:
- Cloud hosting providers.
- Database and infrastructure providers.
- Authentication providers.
- Monitoring and error-tracking services.
- Analytics providers.
- Payment processors.
- Email and communication providers.
- Customer support platforms.
- Professional advisors.
- Integration and platform providers.
Service providers are expected to process information only as necessary to perform services for Atlantic Ops and subject to appropriate contractual or technical safeguards where applicable.
Atlantic Ops does not sell customer CRM data or connected-platform data as a commercial data product.
12. Third-Party Platforms and Services
Atlantic Ops products may integrate with third-party platforms such as HubSpot and other business applications.
Your use of those third-party platforms remains subject to their own terms, privacy policies, security practices, and contractual requirements.
Atlantic Ops is not responsible for the independent privacy practices of third-party platforms that we do not control.
13. International and Cross-Border Processing
Atlantic Ops is located in Canada, but we may use service providers, infrastructure, cloud platforms, or subprocessors located in Canada, the United States, or other jurisdictions.
As a result, information may be processed or stored outside the province or country in which the customer or individual is located and may be subject to the laws of those jurisdictions.
Where information is transferred to service providers for processing, Atlantic Ops remains responsible for using reasonable contractual, organizational, and technical measures appropriate to the nature and sensitivity of the information.
14. Data Security
Atlantic Ops uses administrative, organizational, and technical safeguards intended to protect information against unauthorized access, disclosure, alteration, misuse, destruction, or loss.
Depending on the system and sensitivity of the information, safeguards may include:
- Access controls and role-based permissions.
- Authentication controls.
- Secure handling of OAuth tokens and API credentials.
- Encrypted network communications.
- Restricted production access.
- Logging and monitoring.
- Software updates and vulnerability remediation.
- Backup and recovery controls.
- Vendor and service-provider controls.
No internet-based service or information system can be guaranteed to be completely secure.
15. Security Incidents and Breaches
Atlantic Ops maintains processes intended to identify, assess, contain, investigate, and respond to security incidents involving information under our control.
Where required by applicable law or contractual obligations, Atlantic Ops will provide appropriate notifications to affected customers, individuals, regulators, or other parties.
16. Data Retention
Atlantic Ops retains information only for as long as reasonably necessary for the purposes for which it was collected or processed, including:
- Providing the applicable product or service.
- Maintaining customer accounts.
- Providing support.
- Maintaining security and audit records.
- Resolving disputes.
- Meeting contractual obligations.
- Complying with legal, tax, accounting, or regulatory requirements.
Retention periods may vary based on the type of information, product, contractual requirements, security considerations, backup systems, and applicable law.
Information that is no longer required may be deleted, anonymized, aggregated, or securely destroyed.
17. Application Uninstallation and Account Termination
When a customer uninstalls an Atlantic Ops application, revokes access, or terminates a subscription, the application's authorization to access new information from the connected platform should cease in accordance with the relevant platform's authorization process.
Information previously stored by Atlantic Ops may be retained temporarily where necessary for account closure, backup cycles, security, troubleshooting, legal obligations, contractual requirements, or other legitimate purposes.
Stored customer information that is no longer required will be deleted, anonymized, or otherwise disposed of in accordance with applicable retention practices.
Customers may contact Atlantic Ops to request deletion of application data associated with a terminated account, subject to applicable legal and contractual limitations.
18. Access, Correction, and Deletion Requests
Individuals may request information about personal information Atlantic Ops holds about them and, where applicable, request access, correction, or deletion.
Requests may be subject to identity verification and limitations permitted or required by applicable law.
Where information is controlled by one of our customers and Atlantic Ops processes that information solely on the customer's behalf, we may direct the request to the applicable customer or assist that customer in responding.
19. Consent and Withdrawal
Where consent is the appropriate basis for collecting, using, or disclosing personal information, Atlantic Ops seeks to provide information about the relevant purposes at or before the time of collection.
Consent may be withdrawn where permitted, subject to legal, contractual, technical, or operational restrictions.
Withdrawing consent or revoking an integration may prevent certain products or services from functioning.
20. Cookies and Website Technologies
Atlantic Ops websites may use cookies, analytics tools, tracking technologies, and similar mechanisms to:
- Operate website functionality.
- Remember preferences.
- Measure website usage.
- Understand traffic and engagement.
- Improve website performance.
- Support marketing and communications.
Browser settings and applicable consent tools may provide options for controlling certain cookies or tracking technologies.
21. Communications
Atlantic Ops may send operational communications related to accounts, applications, subscriptions, projects, billing, support, security, or service changes.
Marketing communications may include an unsubscribe option where required or appropriate.
22. Aggregated and De-Identified Information
Atlantic Ops may create aggregated or de-identified information that no longer reasonably identifies an individual or customer.
Such information may be used for analytics, service improvement, benchmarking, product development, security analysis, and understanding general usage patterns.
23. Children's Privacy
Atlantic Ops products and services are designed for businesses and professional users and are not directed toward children.
We do not knowingly design our business applications for the collection of personal information from children.
24. Business Transactions
Information may be transferred as part of a merger, acquisition, financing, restructuring, sale of assets, or similar business transaction, subject to applicable confidentiality, contractual, and legal requirements.
25. Product-Specific Privacy Disclosures
Some Atlantic Ops applications may publish additional privacy or data-use documentation describing:
- The specific systems the application connects to.
- The permissions or OAuth scopes requested.
- The categories of information accessed.
- Whether information is read, written, synchronized, or stored.
- Application-specific retention practices.
- Product-specific subprocessors.
- Artificial intelligence or automated processing features.
- Additional security or compliance requirements.
Where a product-specific notice conflicts with this general Privacy Policy regarding the operation of that specific product, the more specific disclosure will apply to that product.
26. Accountability and Privacy Questions
Atlantic Ops is responsible for maintaining appropriate privacy practices for personal information under its control.
Privacy questions, concerns, complaints, or requests may be directed to Atlantic Ops through our contact page and should identify the request as a privacy-related matter.
Where appropriate, privacy matters will be directed to the person responsible for privacy compliance at Atlantic Ops.
27. Changes to This Privacy Policy
Atlantic Ops may update this Privacy Policy as our business, products, applications, integrations, technology, service providers, or legal obligations change.
Material changes may be communicated through our website, application, account notifications, email, or other reasonable methods where appropriate.
The effective date displayed at the top of this page identifies the current version.
28. Contact Atlantic Ops
Questions regarding privacy, application data, data deletion, connected-account information, or Atlantic Ops privacy practices can be submitted through our contact page.
Please include the relevant application, organization, and nature of the request so we can route it appropriately.