privacypolicy.
The short version: we collect what we need to operate the service, we do not sell or share your data with third parties, and we do not use your information for marketing purposes.
This Privacy Policy describes how MSP Automator Labs, LLC, a New Jersey limited liability company doing business as StackJack.io (“StackJack,” “we,” “us,” or “our”) collects, uses, and protects information in connection with the StackJack application (the “Service”) and the stackjack.io website (the “Site”).
By using StackJack or visiting the Site, you agree to the practices described in this policy. If you do not agree, please do not use the Service or the Site.
What we collect, and why.
Account information
When you create a StackJack account, we collect what you provide during registration: your name, email address, company or organization name, and billing information. Payment processing is handled by Paddle, our Merchant of Record — and by WooPayments (Stripe) for legacy WooCommerce subscriptions — we never store your full credit card number, CVV, or raw payment credentials. We retain only what the payment processor provides to confirm your subscription (last four digits, card brand, billing address, transaction identifiers).
API request & usage data
When you use StackJack with your connected platforms, we log tool call metadata (which tool was invoked, timestamp, response status, latency), aggregate call volume counts for rate limiting and plan enforcement, and error/diagnostic logs for debugging. We do not log the content or payload of API responses from your connected platforms.
Website technical data
When you visit stackjack.io, we may collect standard technical information: IP address, browser type and version, operating system, referring URL, pages visited, time on pages, and navigation paths. We use cookies strictly necessary for site functionality (WooCommerce cart, login sessions). We do not use third-party advertising trackers or retargeting pixels.
Connector credentials — Client ID & Secret · Free & Pro plans
You provide a Client ID and Client Secret for each connector — your platform API application credentials (e.g., HaloPSA, Autotask PSA, NinjaRMM, or CIPP Client ID and Secret; ConnectWise Manage API keys). These are encrypted at rest using AES-256 and used exclusively to authenticate API requests to your platform on your behalf. StackJack never has access to your platform password.
Connector credentials — OAuth PKCE · all plans
Each team member authenticates as themselves via the OAuth 2.0 PKCE flow. StackJack facilitates the handshake but never sees or stores your platform password. We receive and store OAuth access and refresh tokens, encrypted at rest, used solely to authenticate requests under your individual identity. Tokens are issued by your platform, not StackJack.
MCP client connections
Your subscription supports unlimited MCP client connections (e.g., Claude Desktop, Cursor, Copilot). We log which MCP client initiated each tool call for audit and rate-limiting purposes. Per-user tool restrictions you configure are enforced at the proxy level.
Team invites
If you use team invite functionality, we collect the email addresses of invited team members and associate their accounts with your subscription for access control and audit logging.
Pass-through proxy
StackJack does not store, cache, index, or retain the content of API responses from your connected platforms. Your ticket details, client records, device information, asset data, invoices, and all other business data flows through StackJack in transit and is discarded after the request completes.
These purposes, no others.
Service operation
Authenticating your connections to HaloPSA, Autotask PSA, NinjaRMM, ConnectWise Manage, CIPP, and other supported platforms. Routing MCP tool calls between your AI assistant and your connected platforms. Enforcing plan-level rate limits and tool access controls.
Account management
Managing your subscription, processing payments through Paddle (or WooPayments for legacy subscriptions), communicating with you about your account status (subscription confirmations, billing notices, critical service notifications), and providing customer support when you contact us.
Service reliability
Monitoring service health, diagnosing errors, and analyzing aggregate usage patterns (tool call volumes, error rates, latency) to improve reliability and performance. This analysis is performed on metadata only — never on the content of your business data.
Hard no’s.
Never sell your data
Your account information, usage data, connector credentials, and any business data that transits through StackJack will never be sold to any third party, under any circumstances, for any reason.
Never share for marketing
We do not provide, rent, license, or disclose your information to third parties for their marketing, advertising, or promotional purposes. We do not operate an email marketing list, newsletter, or promotional mailing program. Period.
Never train AI on your data
The business data that flows through StackJack from your connected platforms (tickets, clients, devices, invoices, etc.) is never used to train, fine-tune, or improve any machine learning or AI model — ours or anyone else’s.
Never store your business data
StackJack is a proxy. Your HaloPSA tickets, Autotask PSA tickets, NinjaRMM device records, ConnectWise Manage service tickets, CIPP tenant data, client information, financial data, and all other business content passes through in transit and is not persisted, cached, indexed, or retained after the API response is delivered.
Never spam you
You will only receive transactional communications related to your account: subscription confirmations, billing notices, and critical service notifications. That’s it. No drip campaigns, no “just checking in,” no promotional emails.
A short list, on purpose.
StackJack integrates with a limited number of third-party services essential to operating the platform. They receive only the minimum information required.
Paddle · merchant of record
Paddle processes all new StackJack purchases as our authorized reseller and Merchant of Record. Payment information is transmitted directly to Paddle — StackJack servers never receive your full card number. Paddle’s privacy policy governs their handling of your payment data.
WooPayments (Stripe) · legacy payment processing
WooPayments, powered by Stripe, processes payments for legacy WooCommerce subscriptions. Payment information is transmitted directly to Stripe via their client-side SDK — StackJack servers never receive your full card number. Stripe’s privacy policy governs their handling of your payment data. Legacy subscribers can self-migrate to Paddle billing at any time in the StackJack Portal under Billing → Migration.
WooCommerce · storefront & orders
The stackjack.io storefront is powered by WooCommerce on our self-hosted WordPress installation. Order records are stored in our WooCommerce database and not shared with Automattic or any WooCommerce-affiliated entity.
Your connected platforms · HaloPSA, NinjaRMM, CIPP, …
StackJack communicates with platforms you explicitly connect using credentials you provide. Data exchanged is governed by your existing agreements with those vendors. StackJack acts as an authorized intermediary — we transmit requests and responses but do not independently access, analyze, or retain the data.
AI providers · Anthropic, OpenAI, …
StackJack is consumed by AI assistants through the MCP protocol. The AI provider sends tool call requests to StackJack, and StackJack returns the results. The AI provider’s own privacy policy governs how they handle conversation content. StackJack does not send data to AI providers beyond the tool call responses they request.
We do not use any third-party analytics platforms, advertising networks, data brokers, customer data platforms, or any other service that would result in your data being shared outside the providers listed above.
How it’s protected.
No system is perfectly secure. While we implement robust protections, we cannot guarantee absolute security. If we become aware of a security breach affecting your data, we will notify you in accordance with applicable law. See the full security brief.
Kept only as needed.
Account data
Retained for the duration of your active subscription and for a reasonable period afterward to facilitate reactivation and comply with legal and financial record-keeping obligations.
Connector credentials
Deleted when you disconnect a connector or cancel your subscription. Encrypted credentials are purged from our systems; we do not retain copies.
Usage metadata & logs
Retained for up to 90 days for operational and debugging purposes, then automatically purged.
Business data (API payloads)
Never retained. StackJack is a pass-through proxy. Response data exists only in memory for the duration of the request and is not written to any persistent storage.
To request deletion of your account and all associated data, use the data deletion request form below or contact support@stackjack.io. We will process deletion requests within 30 days.
Yours to exercise.
Depending on your jurisdiction, you may have the following rights regarding your personal information.
To exercise any of these rights, submit the data deletion & privacy request form below, or email support@stackjack.io. We will respond to verified requests within 30 days.
Delete it — on the record.
Use this form to request deletion, export, or correction of your personal data. Requests go directly to support@stackjack.io — our privacy contact — and are logged and tracked to closure.
Billing and payment records are held by Paddle, our Merchant of Record. If your request covers payment data, note it above and we will forward the relevant portion to Paddle on your behalf.
The rest of the print.
Children’s privacy
StackJack is a business-to-business service designed for managed service providers and IT professionals. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that we have collected personal information from a minor, we will delete it promptly.
International data processing
StackJack’s infrastructure is hosted on Microsoft Azure in two regions: the United States (Azure East US and West US 2) and the European Union (Azure Sweden Central). You choose your data residency region at checkout, and your tenant’s data is processed and stored in that region. If you are in the EEA or UK and select the US region, by using StackJack you consent to the transfer and processing of your data in the United States. We apply the same protections regardless of region.
Cookies
The stackjack.io website uses cookies strictly necessary for site operation: session cookies to maintain your login state, WooCommerce cookies for storefront functionality (cart, checkout, account management), and standard WordPress session/authentication cookies. We do not use advertising cookies, third-party tracking cookies, or retargeting pixels of any kind.
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify active subscribers by email and update the “Last updated” date at the top. Changes will not be applied retroactively. If a change materially reduces your rights or expands how we use your data, we will obtain your consent before applying it to data collected under the previous policy.
Questions about your privacy?
If you have questions about this policy, your data, or your rights — reach out.