Legal

Privacy Statement

This statement explains what information Third West Labs collects across this website and the Cairnpoint platform, how we use and protect it, who we share it with, and the choices you have.

Last updated: July 22, 2026

1. Who we are

Third West Labs LLC is a Mississippi-registered limited liability company and an independent software studio — the operator of Cairnpoint, a white-label risk-assessment platform sold to managed service providers (MSPs). In this statement, “we,” “us,” and “our” refer to Third West Labs LLC. For any privacy question, contact us at privacy@thirdwestlabs.com.

2. Scope

This statement covers two things:

  • This website (https://thirdwestlabs.com) — our public, marketing-facing pages.
  • The Cairnpoint service — the application used by MSP partners and the guided questionnaire completed by their prospects.

3. Our role: controller and processor

For website visitors and for the account and billing information of our MSP customers, Third West Labs is the data controller.

For assessment data an MSP creates about its own prospects and clients — external scan results, Microsoft 365 posture data, and questionnaire responses — the MSP is the controller and Third West Labs acts as a processor, handling that data only on the MSP's instruction. If you are a prospect who received a questionnaire link, the MSP that invited you is responsible for that data; direct access and deletion requests to them, and we will support their instruction.

4. Information we collect

Website visitors

  • Analytics. We use analytics to understand how the site is used and to improve our product — never to sell your data or to serve advertising. This includes Cloudflare Web Analytics (cookieless, no cross-site tracking) and may include Google Analytics and Microsoft Clarity, which set first-party analytics cookies and record usage such as pages viewed, referring links, approximate (city-level) location from your IP address, device and browser type, and on-page interactions. We use these only in aggregate to improve the product.
  • Contact. If you email us, we receive the contents of your message and your email address.

MSP customers (Cairnpoint account holders)

  • Identity & sign-in. You sign in with your organization's Microsoft Entra work account. We receive your name, email address, and Microsoft tenant identifier. We never see or store a password — authentication is federated to Microsoft, and your organization's MFA and Conditional Access policies apply as they are.
  • Billing. Company name, billing email, and subscription status. Payments are processed by Stripe on Stripe-hosted pages; your card details never touch Cairnpoint.
  • Usage & audit records. Operational logs of actions taken in the platform, kept for security, troubleshooting, and audit.

Assessment data (processed for the MSP)

  • External attack-surface scans — passive analysis of a target's publicly reachable internet footprint.
  • Microsoft 365 posture reviews — a read-only review of a tenant's security configuration via the Microsoft Graph.
  • Questionnaire responses — answers a prospect provides through a guided discovery link.

Cairnpoint is not designed to receive protected health information (PHI), payment card data, or other regulated sensitive personal data. Please do not submit such data into scans or questionnaires.

5. How we use information

  • Provide, operate, secure, and improve the website and Cairnpoint.
  • Authenticate users and enforce access controls.
  • Run assessments and generate reports at the MSP's direction.
  • Process subscriptions, invoices, and payments.
  • Respond to support requests and communicate service notices.
  • Detect, investigate, and prevent abuse or security incidents.
  • Meet legal, tax, and accounting obligations.

We do not sell personal information, and we do not use assessment data to train models or for advertising.

6. Tenant isolation

Every MSP is its own tenant, signed in through its own Microsoft Entra tenant. Prospects, assessments, and reports are scoped to that MSP and are not pooled with other customers. Third West Labs holds no standing access to a tenant's data; support access exists only when an MSP mints a short-lived, audited access code from its own console, and it expires automatically.

7. Service providers and sharing

We share information only with the vendors that run the service, each bound to protect it and use it only to provide their service to us:

  • Microsoft Azure — cloud hosting and storage.
  • Microsoft — federated sign-in (Entra); read-only Graph access for posture reviews; and website usage analytics (Microsoft Clarity), used only to improve the product.
  • Stripe — payment processing and billing.
  • Cloudflare — content delivery, edge security, and cookieless analytics.
  • Google — website usage analytics (Google Analytics), used only to improve the product.

We may also disclose information when required by law, to enforce our agreements, or to protect the rights, safety, and security of our users and the service. If our business is transferred, information may move with it under this statement.

8. Data security

  • Encryption in transit (TLS) and at rest.
  • Least-privilege access and role-based access controls.
  • Read-only Microsoft 365 scanning — we do not change your configuration.
  • Audit logging of sensitive actions and time-boxed, audited support access.
  • No local passwords — sign-in is federated to Microsoft Entra.

No system is perfectly secure, but we work to protect your data with industry-standard safeguards.

9. Data retention and deletion

We keep account and assessment data for as long as an MSP's workspace is active. When a subscription is canceled, the MSP chooses to keep its data (the default) or request deletion. A suspended workspace is eligible for permanent purge after a retention window (90 days by default), and purge is an irreversible, confirmed action. Billing and tax records are retained as long as the law requires. Aggregate, non-identifying analytics may be kept indefinitely.

10. Your choices and rights

  • MSP administrators manage their own users (invite, change role, disable, remove) and can request data deletion from their console or by contacting us.
  • Prospects who completed a questionnaire should direct access or deletion requests to the MSP that invited them; we will act on that MSP's instruction as its processor.
  • Depending on where you live, you may have rights to access, correct, delete, or restrict the use of your personal information, or to object to certain processing. To exercise them, contact privacy@thirdwestlabs.com.

11. Cookies and analytics

This website does not use advertising or cross-site tracking cookies, and we do not sell your data. Cloudflare Web Analytics is cookieless. Where we use Google Analytics or Microsoft Clarity to improve the product, they set first-party analytics cookies; you can block or clear cookies in your browser and use your browser's “Do Not Track” or Global Privacy Control signal. The Cairnpoint application uses only the strictly necessary cookies required to keep you signed in and to operate securely.

12. Children

Our website and Cairnpoint are business tools intended for organizations, not for children, and are not directed to anyone under 16. We do not knowingly collect personal information from children.

13. International users and governing law

We operate from the United States, and information we process is stored and handled there. If you access the service from outside the United States, you understand that your information will be processed in the United States. This statement is governed by the laws of the State of Mississippi, USA, without regard to its conflict-of-laws rules.

14. Changes to this statement

We may update this statement as the service evolves. When we do, we will revise the “Last updated” date above, and we will provide a more prominent notice for material changes.

15. Contact us

Questions, requests, or concerns about privacy? Email privacy@thirdwestlabs.com and we'll respond promptly.