Privacy Policy
This is written in plain English on purpose. The whole point of this company is that people aren't numbers — and that starts with how your information is treated. If anything here is unclear, email me at steven@beyondjustleadership.com and I'll give you a straight answer.
What this covers
This policy covers the Beyond Just Leadership website (beyondjustleadership.com), the training portal, and the Around the Table 1-on-1 app (table.beyondjustleadership.com).
What we collect
- Your account: name, email, and anything you add to your profile (a photo, a title).
- Training activity: which modules you've opened and completed, your reflection answers, and the badges you've earned.
- Around the Table content: the working material of your 1-on-1s — check-ins, shared notes, private notes, commitments, reviews, and peer feedback.
- Pulse surveys: answered anonymously. Survey responses are stored without your identity attached, and results are only ever shown for groups of five or more people.
- Google Calendar, only if you connect it: we store the token that lets the app keep your 1-on-1s on a private calendar it creates for you. If you also turn on full calendar access (a separate, opt-in step), the app can read your calendar to help set up your team and show your week. Both are covered in detail below, and you can disconnect at any time.
- Payments: handled by Stripe, our payment processor. We never see or store your card number.
The walls that matter, said plainly: a manager's private notes are never visible to their report — and a report's private notes are never visible to their manager. That separation is enforced in the database itself, not just hidden in the interface. Company admins and leaders see aggregate health signals only; they cannot read anyone's 1-on-1 content. Pulse surveys are anonymous by design.
What we do with it
We use your information to run the product you signed up for — and that's it. We don't sell your data. We don't share it with advertisers. We don't use your notes, check-ins, or reflections to train AI models. There are no ad trackers on the site; the only thing stored in your browser is what keeps you signed in.
How we protect it
Your information is protected by real security measures, not just good intentions. Every connection to the site, the portal, and the app runs over an encrypted connection (HTTPS/TLS), so nothing travels in the clear. Your data sits in our database at Supabase, hosted in the United States, encrypted at rest and behind their access controls and monitoring.
Who can read what is enforced inside the database itself, by row-level security on every table — private notes, 1-on-1 content, survey answers, and the Google account tokens described below. The wall holds even if a screen or a link is wrong, because the database won't hand your rows to another account. We don't store passwords at all, since there are none to store: you sign in with Google or with a one-time code emailed to you.
On our side, access is limited to the one person who runs this company, and only when it's needed to fix something you've reported or keep the service running. Each service provider listed below gets only what it needs to do its job and is bound by its own security commitments. If your data is ever exposed, we'll email you within 72 hours of finding out and tell you plainly what happened and what to do about it.
Google Calendar access
Connecting Google Calendar is always your choice, and it comes in two levels.
- The private calendar (default). When you connect, Around the Table keeps your recurring 1-on-1s on a separate "Around the Table" calendar it creates for you, with a reminder the day before. At this level the app only writes to that one calendar — it never reads anything else on your calendar.
- Full calendar access (opt-in). If you turn this on (a separate step you choose), the app can read your calendar, read-only, to do two things: suggest the people you lead from your recurring 1-on-1s so you don't type your whole team in by hand, and show your upcoming week so you can protect that time. It stays read-only: with this access the app never creates, edits, or deletes anything on your calendar.
Either way, what the app reads from your calendar is shown only to you, the signed-in manager. It's never shown to your team or your organization, never sold, and never used for advertising. Around the Table's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. You can disconnect Google Calendar at any time from your profile, and you can revoke the app's access directly from your Google Account permissions.
The connection itself is treated as sensitive data and protected accordingly: the Google token is stored in our database, encrypted at rest by our host, locked to your account by row-level security, never shown in the app, never shared with your team or any other company, and deleted when you disconnect or delete your account. Calendar events are read over an encrypted connection when you're using the app; we don't keep a copy of your calendar, and the only thing saved is what you explicitly confirm — the people you choose to add to your team list.
Who helps us run it
A short list of service providers process data on our behalf: Supabase (our database and authentication, hosted in the United States), Netlify (website hosting), Resend (transactional email, like invites), Stripe (payments and receipts), and Google (calendar sync, only if you connect it). Each receives only what it needs to do its job.
Your team's data belongs to your team
What you write in Around the Table is yours. We store it and display it to the people your role says should see it — nothing more. If you're part of a company account, your organization's admin manages membership, but even they can't read your 1-on-1 content.
Keeping and deleting
We keep your data while your account is active so your history — the running record of your 1-on-1s — stays intact. Want it gone? Email steven@beyondjustleadership.com and we'll delete your personal data within 30 days, except what we're legally required to keep (like purchase records).
A few standard things
This product is built for working adults; it isn't intended for anyone under 16. If the policy changes, the new version is posted here with a fresh date — and if a change is significant, account holders get an email. This policy is governed by the laws of Arizona, United States.
Questions
Email steven@beyondjustleadership.com. A person answers — the same one who built it.