Privacy Policy
Effective Date: September 19, 2026
Last Updated: September 22, 2026
Platform Provider: Startum Identity Platform ("Startum", "we", "us", or "our")
1. Introduction & Overview
Startum is an OpenID Connect (OIDC) and OAuth 2.0 Identity Provider designed with privacy-first architecture. Startum is operated and hosted in Canada. We utilize Cloudflare infrastructure for DNS resolution, DDoS mitigation, Web Application Firewall (WAF) filtering, and edge routing.
This Privacy Policy explains how Startum collects, processes, stores, and protects personal data in compliance with Canadian privacy legislation (including the Personal Information Protection and Electronic Documents Act - PIPEDA), applicable provincial privacy acts, and international privacy standards (including GDPR and CCPA).
2. Core Privacy Guarantee: Pairwise Subject Identifiers (sub)
To prevent cross-site user tracking and protect user identity across independent services, Startum implements Pairwise Subject Identifiers (RFC 7591 / OIDC Core 1.0 Section 8).
- Unique per Application: When you sign in to Application A and Application B, each application receives a completely different, cryptographically generated subject ID (
sub). - Non-Linkable: Application A cannot match or link your account activity with Application B based on your subject identifier.
- Cryptographic Derivation: Pairwise subject IDs are calculated using an internal master secret combined with your unique Startum account ID and the requesting application's Client ID:
$$\text{sub} = \text{HMAC-SHA256}(\text{MasterKey}, \text{startum\_id} \parallel \text{client\_id})$$
3. Data Hosting & Cloudflare Infrastructure
- Canadian Data Storage: All core identity databases, account credentials, and authorization grant stores are hosted on server infrastructure located in Canada.
- Edge Security via Cloudflare: Startum routes incoming internet traffic through Cloudflare systems for secure DNS resolution, TLS termination, edge caching, and protection against malicious traffic. Cloudflare processes transient request metadata (IP addresses, HTTP headers) strictly for threat analysis and DDoS mitigation in accordance with strict data processing agreements.
4. Information We Collect
A. Information You Provide Directly
- Account Credentials: Username, verified primary email address, hashed password (processed using argon2id/bcrypt with unique cryptographic salts).
- Profile Claims: Display name, profile picture URL, optional contact phone number, and account preferences.
- Developer Information: Organization name, contact email, registered application names, redirect URIs, and API client credentials when registering OAuth applications.
B. Information Processed During Authentication
- Session & Token Identifiers: Cryptographically secure session tokens (
startum_session), authorization codes, PKCE verifiers, and refresh tokens. - Audit & Security Logs: IP address, HTTP User-Agent string, login timestamps, authorization scope history, and login anomaly metadata used strictly for rate-limiting, fraud detection, and security audit trails.
5. How We Use Your Information
Startum uses collected data strictly for the following purposes:
- Authentication & Identity Provisioning: Verifying your identity and issuing OIDC Identity Tokens (
id_token) and Access Tokens (access_token) to authorized applications. - Account Security: Detecting suspicious login attempts, enforcing multi-factor verification, preventing brute-force attacks, and notifying you of new security events.
- User Consent Control: Tracking which applications you have authorized and the specific scope permissions (
openid,profile,email) you granted to each client. - Platform Operations: Operating, maintaining, and improving the Startum infrastructure, Developer Portal analytics, and developer application registration.
We do not sell your personal data, construct advertising profiles, or monetize your identity information.
6. Scope Permissions & Data Sharing with Third-Party Apps
In compliance with Canadian PIPEDA transparency mandates, when you sign in to a third-party application using Startum ("Continue with Startum"), you are explicitly prompted with a Consent Screen displaying the exact scope permissions requested by that app:
| Scope Requested | Claims Disclosed to Application |
|---|---|
openid (Required) |
Unique pairwise subject identifier (sub) for that specific app. |
profile |
Display name and profile picture URL. |
email |
If identity masking is enabled, a pseudo-anonymous, relay-forwarded email address. If disabled, the primary verified email address and verification status. |
Third-party applications receive only the data associated with the scopes you explicitly approve. You can revoke authorization for any application at any time via the Startum Account Portal under Authorized Apps.
7. Data Retention & Account Closure
- Active Accounts: Personal identity data is retained for as long as your Startum account remains active.
- Token Invalidation: Revoking access to an application immediately invalidates all associated refresh tokens and access tokens issued to that application.
- Account Deletion: Upon requesting account deletion via the Account Portal, your primary account profile, credentials, and active sessions are permanently deleted from active databases within 30 days.
8. Security Measures
Startum implements defense-in-depth technical and organizational security standards:
- End-to-end TLS encryption for all transit data (
HTTPS). - Proof Key for Code Exchange (PKCE, RFC 7636) mandatory for public OAuth authorization code flows.
- Strict
SameSite=Lax,HttpOnly,Secureweb session cookies. - Cryptographic salt-and-hash algorithms for identity store secrets.
9. Your Privacy Rights (PIPEDA, GDPR, CCPA)
Under Canadian privacy laws (PIPEDA) and international privacy frameworks, you possess the following statutory rights regarding your personal identity data:
- Access & Portability: Request an exportable archive of your personal profile data and granted OAuth application permissions.
- Correction: Update your display name, email, avatar, or account security preferences directly within the Account Portal.
- Consent Revocation: Instantly disconnect third-party OAuth apps from accessing your identity.
- Erasure: Request full account termination and removal of identity records.
To exercise these rights, navigate to your Startum Account Portal settings or contact [email protected].
10. Contact & Governing Jurisdiction
This Privacy Policy is governed by the laws of Canada and applicable provincial laws. If you have questions or requests regarding this policy, contact:
Email: [email protected]
Developer Portal: https://develop.startum.cloud