This policy explains what personal information Supligo Inc. (“Supligo”) collects, why, who else sees it, and what you can do about it. It is written to meet Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), and — where a customer of ours has European or UK data subjects — the GDPR and UK GDPR.
Privacy contact: [email protected]. Postal: Supligo Inc., 2606 – 55 Regent Park Blvd, Toronto, Ontario M5A 0C2, Canada.
1. Two kinds of people, and two different roles
Supligo is used by wholesale suppliers to serve their own customers. That means personal information about two different groups reaches us, and our role differs between them.
- Our customers’ own staff — the people who sign up and use Supligo. For them we are the controller: we decide what to collect and why, and this policy is our commitment to them.
- Their customers’ contacts — the restaurant manager whose name, phone number and delivery address is in a supplier’s account. These people never signed up with us. For their information we are a processor, acting on the supplier’s instructions; the supplier is the controller and is responsible for having the right to hold it. If you are one of these people, contact the supplier you deal with — and if you cannot reach them, contact us and we will help.
2. What we collect
- Account information — name, business email address, role, and the business’s name, address, phone number and tax registration number.
- Authentication data — a password, or a PIN for staff signing in on a shared device, and the times sessions were created and used.
- Customer contacts — the names, emails, phone numbers and delivery addresses a supplier records for their own customers.
- Order and invoice records — what was ordered, picked, weighed, delivered and billed.
- Order messages — the text of what a customer sent, kept alongside the order created from it so a disagreement can be settled by looking at what was actually said.
- Delivery evidence — photographs taken at a delivery, the name of whoever accepted it, a timestamp, and the coordinates of the phone at that moment where the device provided them.
- Technical data — IP address, device and browser information, and application logs.
We do not collect: payment card numbers (we do not process payments between you and your customers), government identification, biometric data (Face ID is verified by your phone and never leaves it), or location in the background — the app reads a position only while a delivery stop is open on screen.
3. Why we collect it, and on what basis
Under PIPEDA we rely on consent, which for business account data is given when an account is opened and is implied for the operational uses described here. Where the GDPR applies, our bases are performance of a contract (running the service you signed up for), legitimate interests (securing the service, preventing abuse, improving it in the aggregated form described in section 6), and legal obligation (keeping records of account).
We do not use personal information for advertising, we do not sell it, and we do not disclose it for any purpose other than those set out here.
4. Who else receives it, and where
We use the sub-processors below. Each receives only what it needs, and each is bound by contract to protect it.
| Who | What they do | What they receive | Where |
|---|---|---|---|
| DigitalOcean, LLC | The server Supligo runs on — the database, the API, the web application and the background worker | Everything the product stores: supplier staff accounts, customer business contacts, addresses, order and invoice records, and the text of order messages. Also the HTTP request metadata of everyone who visits, including IP addresses. | Canada (Toronto) |
| Anthropic PBC | AI extraction — turning a customer’s order message into structured order lines | The text of the order message itself, which may contain the customer’s name, their business, quantities and any note they wrote. Nothing else: no price list, no account history, no contact database. | United States — outside Canada |
| Cloudflare, Inc. | Object storage (R2) for product photographs and delivery evidence | Product images uploaded by the supplier, and photographs taken by drivers at delivery — which may show a doorway, a loading bay, and goods left in place. | Automatic, with a Canadian jurisdiction restriction available on request — outside Canada |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | Recipient email addresses and the contents of the messages Supligo sends on a supplier’s behalf: invitations, order confirmations, invoices and delivery notices. | United States (us-east-1) — outside Canada |
Personal information leaves Canada in the ordinary course of running this service. The database and the servers running Supligo are in Toronto; AI extraction, email delivery and the storage of photographs happen outside Canada, in the United States or at a location the storage provider chooses. While information is outside Canada it is subject to the laws of the country it is in, including lawful access by that country’s courts and authorities. Where the GDPR applies, transfers rely on Standard Contractual Clauses.
We will tell customers before adding or replacing a sub-processor, so there is an opportunity to object.
We will also disclose information where the law requires it. Where we are lawfully permitted to tell the affected customer first, we will.
5. AI processing, specifically
When a customer’s order message is read by AI, the text of that message is sent to Anthropic PBC in the United States. It may contain a person’s name, their business, what they wanted and any note they wrote. Nothing else is sent: not your price list, not your customer database, not your order history.
We record how long the processing took and how much of the model’s capacity it used, so we can account for cost. The message itself is stored in our own database, against the order it produced.
6. Aggregated information
We use aggregated, de-identified information to operate and improve the service — how long extraction takes, how often a line needs correcting, which failures recur. This is information that cannot reasonably be linked back to a person or a business.
7. How long we keep it
- While your account is open — for as long as you need it. Order and invoice history is a business record and we do not delete it on our own initiative.
- After termination — available for export for 30 days, then deleted, except records we must keep by law. Canadian tax law requires records of account be retained for six years.
- Backups — cycled out on a rolling schedule. Deleting something removes it from live systems immediately; backups age out.
- Logs — operational logs are retained for a short operational period and are not used to build a profile of anyone.
8. Your rights, and how to use them
You have the right to:
- Access the personal information we hold about you, and be told how it has been used and who it has been disclosed to.
- Correct information that is wrong or incomplete.
- Delete it, subject to records we must keep by law.
- Export it in a portable form. Account owners can do this themselves, at any time, from settings — one file, no request needed.
- Withdraw consent, on reasonable notice, understanding that some withdrawals mean we can no longer provide the service.
- Complain — to us first, at [email protected], and then to the Office of the Privacy Commissioner of Canada, or to your own supervisory authority if you are in the EU or UK.
We respond to requests within 30 days. We may need to verify who you are first — which is itself a protection, not an obstacle.
9. How we protect it
- Encrypted in transit (TLS) and at rest.
- Passwords and PINs are stored only as scrypt hashes; session tokens only as SHA-256 hashes. None of them are ever returned by our API or included in an export — we cannot show you your own password because we do not have it.
- Every customer’s data is separated by tenant, and every query is scoped to one tenant.
- Access by our own staff is limited, reasoned, time-boxed, logged, and visible to you while it happens.
- Backups are taken regularly and restoration is tested rather than assumed.
If a breach creates a real risk of significant harm, we will report it to the Privacy Commissioner and notify affected individuals as soon as feasible, and we will keep a record of every breach as PIPEDA requires. Where we are a processor, we will notify the controlling customer without undue delay so they can meet their own obligations.
10. Children
Supligo is a tool for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16.
11. Changes to this policy
Every version is dated. For material changes we will give notice before they take effect and, where the change requires it, ask for renewed consent.