Privacy Policy
Effective date: 2026-05-16. Version: draft 0.1. We are a Canadian (Ontario) company subject to PIPEDA, and where applicable, GDPR.
1. Who we are
Spuric Innovation Center, an Ontario corporation, operating SPUR Compute at ai.spuric.com. Privacy questions: privacy@spuric.com.
2. What we collect
- Account data - name, email, phone (optional), country, billing address, hashed password.
- Verification data (hosts) - government-issued photo ID, business registration documents, datacentre certifications, ownership declarations. Stored encrypted at rest.
- Usage data - which instances you rent, when, for how long, for billing and capacity planning.
- Payment data - processed by Stripe (cards) or wire/SEPA/Interac (bank). SPUR does not store full card numbers.
- Telemetry - SPUR Agent telemetry from host machines (GPU utilization, temperatures, uptime). No customer container contents.
- Logs - HTTP access logs, billing audit log, abuse-investigation records. Retained 13 months by default.
3. What we do not collect
- Contents of customer containers, model weights, datasets, or inference inputs/outputs - except as required for an active support ticket you opened, or an active abuse investigation under section 1 of the AUP.
- Cross-site advertising trackers.
- Biometric data beyond the liveness check at host verification (which is processed and discarded by our KYC provider, not stored by SPUR).
4. How we use it
- To deliver the Service (run your instances, charge your card, pay out hosts).
- To provide customer support when you contact us.
- To investigate abuse reports and protect the platform.
- To comply with legal obligations (tax, AML, court orders).
- To improve the Service (aggregated usage stats only, never individually identified).
We do not sell customer data. We do not run third-party advertising. We do not use customer data to train AI models.
5. Where it lives
Account, billing, and usage data is hosted in our Cambridge, Ontario, Canada datacentre. Verification documents are encrypted at rest in Canada. Payment-card processing is by Stripe, which may move card-network metadata across borders per its own privacy policy.
6. Who we share it with
- Payment processors - Stripe (cards), banks (wire/SEPA/Interac), SPUR Token contract (if elected).
- KYC providers - identity verification vendor (for hosts and high-risk customer accounts).
- Cloud services we use - Cloudflare (CDN + DDoS), Postmark (transactional email).
- Law enforcement / courts - when legally compelled, scope-limited to what is required.
7. Your rights
Under PIPEDA, GDPR, and similar regimes you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account (subject to legal retention requirements).
- Export your data (machine-readable format).
- Withdraw consent for non-essential processing.
- Lodge a complaint with your data protection authority.
Email privacy@spuric.com to exercise any of these. We respond within 30 days.
8. Security
TLS 1.3 in transit. AES-256 at rest. SOC 2 / ISO 27001-aligned controls (we are working toward formal certification). Verified Datacentre partner hosts maintain their own active third-party certifications.
9. Cookies
We use first-party cookies for: session authentication, CSRF protection, and a per-session preference store (theme + language). No tracking cookies. No third-party advertising cookies.
10. Children
SPUR Compute is not directed to anyone under 18. If we learn a minor has registered, we will delete the account and any associated data.
11. Changes
We update this policy with at least 30 days notice via email and on this page. Continued use after the effective date is acceptance.
12. Contact
Privacy questions: privacy@spuric.com
Postal: Spuric Innovation Center, 498 Eagle Street North, Cambridge, ON N3H 1C2, Canada