Privacy Policy

Policy Version: v1.0-2026-07-19 · Last Updated: July 19, 2026

This privacy policy describes how your personal data is collected, used, and protected in compliance with GDPR, PIPEDA, and Canadian privacy laws.

1. Data Controller

The data controller for your personal information is the business entity you registered with (the "Business"). The Business operates the Jalaram POS platform to manage its restaurant, retail, or service operations.

For privacy inquiries, contact the Business using the email address provided during registration, or contact Jalaram POS support to be redirected.

2. Personal Data We Collect

Owner/Officer Data: Name, SIN, birthdate, personal address, phone, and email — collected for CRA tax filing and corporate compliance (legal obligation).

Employee Data: Full name, role, hire date, hourly rate, SIN, certifications (Smart Serve, Food Handler), emergency contacts, and banking info for payroll — collected for employment and payroll tax obligations.

Customer Data: Name, phone, email, and allergy/dietary information — collected for reservations, orders, and loyalty programs (contract performance).

Transaction Data: Order details, payment amounts, tips, and payment method (last 4 digits only) — collected for service delivery and financial record-keeping.

Technical Data: IP address, device/browser info, and usage logs — collected for security, fraud prevention, and system monitoring (legitimate interest).

3. Legal Basis for Processing (GDPR Art. 6)

(a) Contract performance: Processing employee payroll, customer orders, and reservations to fulfil contractual obligations.

(b) Legal obligation: Collecting SINs for CRA tax remittance (T4, ROE), maintaining financial records per Income Tax Act requirements, and retaining payroll records for 6 years.

(c) Legitimate interests: Security monitoring (audit logs, IP tracking), fraud prevention, and system performance optimization.

(d) Consent: Marketing emails, location tracking, and non-essential data sharing. Consent can be withdrawn at any time.

4. How We Use Your Data

  • Processing payroll, generating T4s and Records of Employment (ROE)
  • Managing employee schedules, time clock entries, and tip distributions
  • Processing customer orders, reservations, and loyalty rewards
  • Generating financial reports, HST filings, and accounting records
  • Maintaining security audit trails for PCI DSS and fraud prevention
  • Sending transactional notifications (order status, schedule updates)

5. Data Retention

We retain personal data only as long as necessary for the purposes set out above:

  • Payroll & tax records: 6 years (CRA requirement)
  • Employee records: 7 years after termination (employment standards)
  • Financial/accounting records: 7 years (Income Tax Act)
  • Audit logs: 3 years for routine events, 7 years for security-critical events
  • Customer transaction data: 2 years after last interaction
  • Consent records: Retained for the duration of the relationship plus 3 years

After the retention period, data is permanently deleted or anonymized. Owners can initiate immediate data purging from Business Settings.

6. Third-Party Data Processors

We use the following third-party processors to operate the platform. Each processor is bound by a data processing agreement and only processes data on our instructions:

  • Stripe — Payment processing (PCI DSS Level 1 certified). Card data is tokenized; we never store full card numbers.
  • Uber Direct — Delivery dispatch for online orders. Customer name, address, and phone are shared for delivery purposes only.
  • Brevo — Transactional and marketing email delivery.
  • Base44 Platform — Cloud infrastructure, database hosting, and authentication services.

Data is processed in Canada and the United States. No data is transferred to jurisdictions without adequate data protection safeguards.

7. Your Data Subject Rights (GDPR Art. 15-22)

Under GDPR and PIPEDA, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of all personal data we hold about you.
  • Right to Rectification: Correct inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your personal data (subject to legal retention obligations).
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Restrict Processing: Limit how we process your data in certain circumstances.
  • Right to Object: Object to processing based on legitimate interests or for direct marketing.
  • Right to Withdraw Consent: Withdraw consent for processing based on consent at any time.

To exercise these rights, contact the Business using the email provided during registration. All requests are logged in our audit system and processed within 30 days.

8. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Art. 33).
  • Notify affected data subjects without undue delay if the breach is likely to result in a high risk (GDPR Art. 34).
  • Document all breaches, including the facts, effects, and remedial actions taken.

Our automated security monitoring system detects critical events in real-time and alerts business owners within 15 minutes. All security events are recorded in an immutable audit log.

9. Security Measures

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption: All data in transit uses TLS 1.2+. Sensitive fields (SINs, POS PINs) are SHA-256 hashed before storage.
  • Access Control: Role-based access (admin, owner, manager, employee) with row-level security on all data.
  • Audit Logging: All access to sensitive data (SINs, payroll, financial records) is logged with user identity, timestamp, and IP address.
  • Multi-tenancy Isolation: Each business's data is isolated via business_profile_id; users cannot access data from other businesses.
  • PCI DSS Compliance: Payment card data is never stored; Stripe handles all card processing.
  • Automated Alerts: Critical security events trigger immediate email alerts to business owners.

10. Data Export & Deletion

Business owners can export or delete all data associated with their business from the Business Settings page:

  • Data Export: Generate a complete backup of all business data (employees, payroll, transactions, inventory) — logged as a data_export audit event.
  • Data Purge: Permanently delete the business profile and all associated records — logged as a data_purge critical audit event. A backup is emailed before deletion.

Both actions are permanently recorded in the audit log with the user identity, timestamp, and IP address.

By using this platform, you acknowledge that you have read and understood this privacy policy. This policy may be updated periodically; users will be notified of material changes.

For questions about this policy or to exercise your data subject rights, contact the Business owner or Jalaram POS support.