Privacy Policy
1. Who is accountable
Shop Board Pro ("the service", "we") is operated from Toronto, Ontario. The person accountable for this policy is the operator, reachable at [email protected]. When the service is transferred to a corporation, that corporation becomes the accountable organization and this policy will say so.
Two roles matter throughout. Account holders (a shop's owner and the managers they invite) give us their information directly; we are the organization accountable for it. Shop records (technicians, work orders, clock-ins, messages) are collected by the shop, which decides what to enter and why; we hold and process them on the shop's behalf as its service provider, under the shop's instructions and this policy.
2. What we collect, and why
| Information | Purpose |
|---|---|
| Account email address, a hashed password, the shop's name and time zone | To create and secure your account and run the shop's day on its own clock |
| Technicians: a number, a name, a skill or credential tier, and where the shop enters them, a trade licence number, a Skilled Trades Ontario card number, a training-agreement number and an expiry date; a PIN stored only as a hash | To decide who may take which work under Ontario's compulsory-trade rules and to let a technician sign in at the floor tablet |
| Clock-ins (which technician signed in, when), work orders (a repair-order number, the services it needs, timestamps, the technician who took it), transfers, yields, and dispatch counts including the number of available jobs a free technician left waiting | To run the live board: call the next technician fairly, show elapsed time, and record the day |
| Messages and lobby promotions (text and images) that staff post | To show them on the shop's own screens |
| Daily archives and end-of-day reports, and the email addresses the shop configures to receive them | To keep the shop's history and deliver the reports the shop asked for |
| Which screen is signed in, a per-screen identifier kept in the browser's local storage, and software error reports (the error message, the page, the browser version, the build) | To coordinate announcements between screens, keep a screen on the page it was set to, and find and fix faults on screens nobody is watching |
| Platform access records: which platform staff member looked at a shop's setup and counts, when, and any change they made (a suspension and its reason, a theme switched on or off) | To show the shop who has looked at its account and what was changed |
| Service notices we email to account holders (planned maintenance, security notices, changes to these terms or this policy), and a copy kept in the shop's Store Admin | To tell the people who run the shop about the service they use; these are service messages, not marketing, and we send no marketing email |
What the service has no field for: vehicle owners or customers. A repair order in the service is a number and a list of services. The Lobby display shows order numbers and status only. We do not collect payment card numbers; if billing is introduced it will be processed by a payment provider and this policy will be updated first.
What we do not do: no advertising trackers, no third-party analytics, no sale, rental or trade of information, no profiling for any purpose other than running the board.
3. Consent
Account holders consent by creating an account and accepting these terms; the version accepted and the time are recorded. For shop records, the shop obtains any consent or gives any notice its staff are owed (see section 9). Consent for the transactional emails the shop configures is given by configuring them; each can be removed in Store Admin. We send no marketing email without express consent, in keeping with Canada's Anti-Spam Legislation (CASL).
4. Limiting collection, use and retention
We collect only what the table above lists and use it only for the stated purposes. Shop records stay until the shop deletes them or closes its store; deleting a store deletes every record that belongs to it. Software error reports are kept for up to 90 days. Email-delivery ledger rows are kept for up to 90 days. A nightly backup copy of the database is kept for up to 90 days for disaster recovery, so a record deleted from the service can remain in a backup until that copy expires. Platform access records are kept for as long as the shop exists so the shop can see them. A closed account's email address is removed from our authentication records when the account is deleted.
5. Accuracy
Shop records are entered and corrected by the shop in Store Admin. Account holders can correct their own email address and password in the service or by writing to us.
6. Safeguards
- Every shop's records are isolated by database row-level security; one shop cannot read another's data. This isolation is tested against the live database on every release.
- Passwords and technician PINs are stored as hashes and are never returned to a browser or to platform staff.
- Screens on a wall use a restricted "device" seat that cannot delete work orders, change settings or read the roster's credential numbers.
- Platform staff can see counts, statuses, settings and timestamps to support a shop, and the account holders' email addresses. They cannot read the content of a shop's messages, promotions, reminders, work orders, archives or reports: the platform console has no action that returns them. Every look at a shop's setup is written to the shop's own access log.
- All traffic is encrypted in transit (HTTPS and secure WebSockets).
7. Where your information is stored, and who processes it
| Provider | What they do | Where |
|---|---|---|
| Supabase (database, authentication, realtime) | Stores every record above | Canada (AWS Canada Central, Montréal, Québec) |
| Cloudflare (hosting) | Serves the application's own files from a global network; shop records do not pass through it — screens talk to the database directly | Global edge; application files only |
| Resend (email delivery) | Sends the emails the shop configures: invitations, verification and password-reset mail, end-of-day reports and management alerts | United States |
| GitHub (backups) | Holds a nightly backup copy of shop records, including the email addresses a shop enters, kept for up to 90 days so the service can be restored after a failure | United States |
Emails and their contents therefore leave Canada when sent, and so does the nightly backup copy. A shop that does not want its end-of-day report to travel by email can leave the recipient list empty and read reports in the service. Each provider is bound by its own contractual and security commitments; a current list is kept here and updated before a new provider is used.
8. Breach of security safeguards
If we learn of a breach that creates a real risk of significant harm to an individual, we will report it to the Office of the Privacy Commissioner of Canada, notify the affected shop and individuals as soon as feasible, and keep a record of every breach for 24 months, as PIPEDA requires. The shop is notified first, because it is the organization its staff know.
9. Shops and their staff: monitoring and employment records
The service records when a technician signs in at the floor tablet, which work they take and complete, and when a free technician leaves available work waiting. These are dispatch records, used to run the board fairly. Since September 2026 the End of Day report also summarises bay usage — how many work orders each bay or hoist carried, for how long, and how long it sat idle — computed from the bay label typed at the front desk. Those figures describe the shop's equipment; the block names no technician. They are visible to the shop's managers. They are not payroll or hours-of-work records: a clock-in here is a "ready for work" signal for the dispatch order and does not replace the time records an employer must keep under Ontario's Employment Standards Act. Any performance indicator the service shows is informational and is meant for a manager's judgment, not automatic discipline.
An Ontario employer with 25 or more employees must have a written electronic-monitoring policy that tells staff how and when they are monitored. A shop using this service should describe the service in that policy; we provide a plain-language disclosure the shop can adopt. Whether an employer must have the policy or not, we recommend telling technicians what the board records before the first shift on it.
10. Access, correction, and complaints
An account holder may ask what we hold about them, ask for a correction, or ask for their account to be deleted by writing to [email protected]. We answer within 30 days. A technician or other member of a shop's staff should ask the shop, which can see and correct its own records in Store Admin; where the shop asks us for help we will help. Anyone may complain about our handling of personal information to us first and, if unsatisfied, to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
11. Cookies and local storage
The service sets no advertising or analytics cookies. It uses the browser's local storage to keep a signed-in session, a screen's role (Board or Lobby), a per-screen identifier, a screen's own mute setting, and unsent writes while the screen is offline. Clearing site data removes all of it.
12. Changes
When this policy changes, the version and effective date above change, account holders are asked to accept the new version at their next sign-in, and the previous version remains available on request.