Privacy Policy
This Privacy Policy explains how Exprow Consulting Inc. collects, uses, discloses, and protects personal data when you use our websites and services.
1. Information We Collect
We collect personal and business information that you provide to us and data from your use of the Platform:
- Account registration information, including name, email address, password, and optional phone number.
- Business profile information, including company name, role, industry, website, location, revenue model, and other business details you enter.
- Diagnostic inputs, including answers to AI diagnostic questions about bottlenecks, goals, team information, and operations.
- AI chat messages, report content, support messages, emails, and communications you send us.
- Payment data in the future if paid services are added. Stripe may process payment method data; Exprow does not store full credit card details.
- Usage data, including IP address, device and browser type, pages visited, logs, and similar technical information.
- Cookies and trackers used for essential functionality. No tracking or marketing cookies are used at present.
2. How We Use Your Information
We use collected data for the following purposes:
- To provide services, generate diagnostics, run analyses, and create reports.
- To send inputs to OpenAI, Perplexity, and similar services where needed to create AI-driven insights.
- To store inputs and report outputs in Supabase or similar systems so reports can be delivered and accessed.
- To manage accounts, login, preferences, and service communications.
- To send requested information, reports, and updates.
- To send marketing communications only with consent and with unsubscribe options consistent with Canada's Anti-Spam Legislation.
- To improve the Platform, troubleshoot issues, aggregate trends, and comply with legal obligations.
3. Cookies and Tracking
We will ask for consent before using any non-essential cookies. Essential cookies may be used for login, security, session management, hosting, and core functionality.
If we add Google Analytics, advertising pixels, or similar technologies in the future, they will only be enabled after consent through a cookie banner or equivalent consent mechanism.
4. Data Sharing and Third Parties
We do not sell your personal information. We share data only as necessary to operate the services, including with:
- OpenAI, to generate insights from user inputs and business context.
- Perplexity, to search public web data and return research results.
- Supabase, for authentication, database storage, and report records.
- Resend, to send report emails and service communications.
- Stripe, if future payments are enabled.
- Cloudflare, Vercel, and other hosting or infrastructure providers for hosting, caching, performance, and security.
- Law enforcement, regulators, or legal parties if legally required, limited to the minimum necessary.
5. Data Retention and Security
We retain personal data only as long as needed for the purposes described in this Policy or as required by law. Diagnostic data and reports may be retained so they can be delivered, reopened, or supported.
We use industry-standard security measures, including encryption in transit, access controls, and secure cloud services. No system is completely secure. In the event of a data breach, we will follow applicable Canadian breach notification rules.
6. Your Rights
Under PIPEDA and applicable laws, you may have the right to:
- Access a copy of personal data we hold about you.
- Request correction or update of inaccurate personal data.
- Request deletion of data in certain cases, subject to retention obligations.
- Withdraw consent, including unsubscribing from marketing emails.
- Make a complaint to Exprow or Canada's Privacy Commissioner if you believe your data has been mishandled.
- For EU users, exercise GDPR rights where applicable, including portability, restriction of processing, and deletion where no overriding obligation applies.
7. Children's Privacy
Our services are not directed at children under 18. We do not knowingly collect data from minors. If we learn that we have collected personal data from a child, we will delete it.
8. International Transfers
Because our services are global and use cloud providers, your data may be transferred to other countries, including through OpenAI, Supabase, Stripe, Resend, Cloudflare, and Vercel. We will take legal safeguards as required by applicable law.
9. Changes to this Policy
We may update this Privacy Policy when we add new features, change providers, or comply with new laws. Material changes will be posted on the site with a new date. Continued use indicates acceptance of the updated policy.
10. Contact Information
For privacy inquiries or data rights requests, contact privacy@exprow.co.