Policy Version: v1.0-2026-07-19 · Last Updated: July 19, 2026
This privacy policy describes how your personal data is collected, used, and protected in compliance with GDPR, PIPEDA, and Canadian privacy laws.
The data controller for your personal information is the business entity you registered with (the "Business"). The Business operates the Jalaram POS platform to manage its restaurant, retail, or service operations.
For privacy inquiries, contact the Business using the email address provided during registration, or contact Jalaram POS support to be redirected.
Owner/Officer Data: Name, SIN, birthdate, personal address, phone, and email — collected for CRA tax filing and corporate compliance (legal obligation).
Employee Data: Full name, role, hire date, hourly rate, SIN, certifications (Smart Serve, Food Handler), emergency contacts, and banking info for payroll — collected for employment and payroll tax obligations.
Customer Data: Name, phone, email, and allergy/dietary information — collected for reservations, orders, and loyalty programs (contract performance).
Transaction Data: Order details, payment amounts, tips, and payment method (last 4 digits only) — collected for service delivery and financial record-keeping.
Technical Data: IP address, device/browser info, and usage logs — collected for security, fraud prevention, and system monitoring (legitimate interest).
(a) Contract performance: Processing employee payroll, customer orders, and reservations to fulfil contractual obligations.
(b) Legal obligation: Collecting SINs for CRA tax remittance (T4, ROE), maintaining financial records per Income Tax Act requirements, and retaining payroll records for 6 years.
(c) Legitimate interests: Security monitoring (audit logs, IP tracking), fraud prevention, and system performance optimization.
(d) Consent: Marketing emails, location tracking, and non-essential data sharing. Consent can be withdrawn at any time.
We retain personal data only as long as necessary for the purposes set out above:
After the retention period, data is permanently deleted or anonymized. Owners can initiate immediate data purging from Business Settings.
We use the following third-party processors to operate the platform. Each processor is bound by a data processing agreement and only processes data on our instructions:
Data is processed in Canada and the United States. No data is transferred to jurisdictions without adequate data protection safeguards.
Under GDPR and PIPEDA, you have the following rights regarding your personal data:
To exercise these rights, contact the Business using the email provided during registration. All requests are logged in our audit system and processed within 30 days.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
Our automated security monitoring system detects critical events in real-time and alerts business owners within 15 minutes. All security events are recorded in an immutable audit log.
We implement appropriate technical and organizational measures to protect your personal data:
Business owners can export or delete all data associated with their business from the Business Settings page:
data_export audit event.data_purge critical audit event. A backup is emailed before deletion.Both actions are permanently recorded in the audit log with the user identity, timestamp, and IP address.
By using this platform, you acknowledge that you have read and understood this privacy policy. This policy may be updated periodically; users will be notified of material changes.
For questions about this policy or to exercise your data subject rights, contact the Business owner or Jalaram POS support.