Privacy Policy
Version 1.2 · Effective 2026-09-12 · 1001636023 Ontario Inc., operating as AlmondTill/G3N, an Ontario company. The companion to the Terms of Service (§10) — where the two overlap, the stricter protection wins. Questions and requests: privacy@almondtill.com.
How to read this
Two kinds of personal information pass through AlmondTill/G3N, and the law treats them differently:
- Information about you and your staff — the people who apply for, own, and operate a merchant account. For this information we are the organization accountable under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). This policy is mostly about it.
- Information about your customers — the shoppers whose profiles, orders, loyalty balances, and consent decisions live in your till. That information is Merchant Data under the Data Covenant (Terms §3). You are the organization accountable to your customers; we process it only on your instructions, as your service provider, and never for our own purposes. Section 3 below says what that means in practice.
1. Who we are and how to reach us
1001636023 Ontario Inc., operating as AlmondTill/G3N, an Ontario company (“AlmondTill/G3N”, “we”, “us”), operates the AlmondTill/G3N platform at almondtill.com and its related hosts (api.almondtill.com, office.almondtill.com, portal.almondtill.com).
Privacy questions and requests: privacy@almondtill.com. Our privacy officer: Babak Morshedizadeh, Director. Postal address: c/o Microhouse Systems Inc., 203-30 Royal Crest Court, Markham, Ontario, Canada L3R 9W8.
Mail sent to any @almondtill.com address (privacy@almondtill.com included) is received by Amazon SES, kept in our inbound mail store for two years, and forwarded to our privacy officer's mailbox, which is hosted by Google (Gmail) — see Sections 6 and 8. Write to privacy@almondtill.com for anything in Section 10.
2. What we collect about you and your staff, and why
We collect only what the Service needs to run. Nothing here is collected for advertising, profiling, or resale.
Your application. When you apply for a merchant account we receive what you type into the form: your email address, your desired login name, your business name and type, and — only if you choose to give them — your current system, your online channels, your locations, team size, sales volume, revenue band, your name, a referral code, and a free-text message. A person reads it to decide the application; it becomes your account record when approved.
Account identities. Your owner account and the staff accounts you create carry an email address, a login name, a display name, and the roles you assign. Passwords are never stored; we keep an Argon2id hash. API keys you mint are stored as a hash only and shown to you once.
Billing records. Your base fee, your kernel (usage) purchases, the invoices and credit notes we issue, and the payment method on file. Card payments are processed by Stripe; we store only the card brand, its last four digits, and Stripe's references — never the card number.
Owner identity verification. Owners verify their identity once, through Stripe Identity. The documents and selfie go to Stripe; we store the outcome (verified or not) and Stripe's session reference, and we never ask a verified owner again.
Security records. Each sign-in creates a session that expires after at most 24 hours (staff and API sessions), 7 days (paired devices), or 30 days (your customers' own sign-in sessions, where you offer them). Failed sign-ins are counted per identity and per IP address for 15 minutes to throttle brute-force attempts (5 failures per identity, 20 per address); a lockout is written to our operational logs with the address. Every change any principal makes is recorded as an event on the permanent log with who made it and when — this is the audit trail the Terms promise, and it is also how support and security investigations are conducted.
The support trail. Each request your staff’s app sends names the app, its build and the screen it came from — never a URL, a typed value or a keystroke. We keep that per-call record for 90 days, sealed: every row is encrypted under a key that belongs to your organization group, and nobody, including us, reads it without opening one of two doors: a support ticket you raised, or your own owner’s question “what did this user do?”. Every opening is written down — who opened it, which door, which user, which window, the ticket or the reason — where your owners can see it, and the openings themselves are permanent log events. It is yours: erased with your account or on request, and never used for analytics, for training or for anything but support.
Support and conversation. The support cases, messages, notes, and attachments you send us; the files you attach to the till's guided wizards as reference material (PDF, images, text, or CSV, up to 8 MiB each); and the questions you type to Aldric, the built-in consultant, or to the AI features. These are part of your Merchant Data and are kept as long as you keep them.
Operational logs. Our application logs (in AWS CloudWatch) hold request outcomes and fault lines. They are retained for one day. We do not run web-analytics, tracking pixels, or edge access logs: CloudFront access logging is off on every host, and the API gateways keep no access logs.
Mail we send you. Every email the platform sends (verification and password-reset links, your application’s review notice, usage and balance alerts, plan and charge notices, referral decisions) carries a two-line footer: one sentence saying what it was sent for and where the request came from, and a reference (ref M-XXXX-XXXX-XXXX). We keep one ledger row per sent email — the kind, the time, the origin, the reference, the event that fired it, the mail provider’s own id and a one-way hash of the address, never the address itself — so you can look any email up by its reference on your Profile, and support can trace it. It is account data: it lives as long as your account and leaves with it.
3. Your customers' information — processed on your behalf
Your till holds customer profiles (email, display name, phone numbers, addresses, price group, tags), their orders, tenders, returns, loyalty and gift balances, cases and messages, and their consent decisions. Under Terms §3 this is your data. We host, back up, secure, and display it solely to operate the Service for you; we do not sell it, share it beyond the subprocessors in Section 6, use it for advertising, use it to train AI models, or mine it for any secondary purpose. Our personnel access it only with your permission to provide support you requested, as strictly necessary to investigate a security incident, abuse, or a platform fault, or where law requires — and such access is logged.
The Service gives you the tools to meet your own obligations to your customers:
- Consent by purpose. Consent purposes are opt-in, versioned, and recorded per customer with where and when the decision was captured; withdrawal is exactly as easy as granting, and a withdrawal is recorded even where no grant existed so the customer is not asked again.
- Access and export. Every record is readable through the open API in machine-readable form.
- Erasure by de-identification. A verified erasure request removes the customer's personal information (profile, contact details, addresses) and leaves the commercial records — the sales, the tax facts — in place, unlinked from the person. Sales records are never destroyed, because your books must stay complete; the person is removed from them.
- Privacy requests. The engine tracks each request from receipt to fulfilment with evidence of what was done.
4. How we use information about you
Only to: operate the Service and your account; bill you for it; keep the platform secure and investigate abuse; provide the support you request; meet legal obligations. We do not sell personal information, use it for advertising, or use it to train artificial-intelligence or machine-learning models. Any use beyond these purposes happens only if you specifically opt in, purpose by purpose, revocably, and never bundled into these Terms or a “continue” button (Terms §3.5).
5. Cookies and browser storage
We set only strictly-necessary, first-party cookies. There are no analytics cookies, no advertising cookies, no third-party cookies, and no tracking pixels — so there is no consent banner.
| Cookie | Host(s) | Purpose | Lifetime | Attributes |
|---|---|---|---|---|
at_theme | almondtill.com, portal.almondtill.com | remembers light/dark mode | 1 year | HttpOnly, Secure, SameSite=Strict |
at_portal | portal.almondtill.com | your signed-in portal session (sealed token) | 24 hours | HttpOnly, Secure, SameSite=Strict |
at_office, at_office_<handle> | office.almondtill.com | your signed-in back-office session (sealed token) | 24 hours | HttpOnly, Secure, SameSite=Strict |
The back office also keeps two preferences in your browser's local storage: your theme choice and the last organization you worked in. Neither leaves your browser.
6. Who else touches the data (subprocessors)
We use a small, fixed set of providers, each only to deliver the Service and each bound to protections comparable to the Terms. We will disclose any change to this list before it takes effect (Terms §15).
| Provider | What for | What they receive |
|---|---|---|
| Amazon Web Services (US East / N. Virginia) | hosting, databases, file storage, the event log, backups, email delivery, receipt of mail sent to our @almondtill.com addresses, operational logs | all Merchant Data and account data, encrypted at rest and in transit; the messages you send to our @almondtill.com addresses |
| Google (Gmail) | the privacy officer's mailbox | a forwarded copy of each message sent to any @almondtill.com address — what you write to us, never anything from your till |
| Stripe | card payments, disputes, card readers, owner identity verification | payment and dispute details; identity documents for owner verification (held by Stripe) |
| OpenAI | the AI features you invoke — the built-in consultant, natural-language filters, wizard field suggestions and explanations, drafting aids | only the text you type and the reference material you attach for that request, plus the in-tenant context the feature needs; sent with storage disabled (the provider retains nothing from the request beyond its own abuse-monitoring terms); never used to train models |
| Zip2Tax | licensed US sales-tax rate tables | no personal information — we download tables; nothing is sent |
AI features are metered and run only when you use them; if the AI provider is not configured, the feature reports itself unavailable and nothing is sent.
Your own tools and assistants. When you connect your own software or AI assistant to the open API — including through the MCP doorway — what it reads leaves under its provider's terms, with only the permissions you assigned it. That is your choice and your provider, not a subprocessor of ours.
7. Where the data lives
Merchant Data and account data are stored and processed in the United States (AWS US East / N. Virginia). Because data is stored in the U.S., it may be subject to lawful access by U.S. authorities under U.S. law. If a court, regulator, or authority demands data from us, we will — unless legally barred — notify you promptly, disclose only what is legally required, and redirect the demand to you where possible (Terms §3.6, §3.8).
8. How long we keep it
- Sessions: until they expire (Section 2) or you sign out.
- Login-throttle counters: 15 minutes.
- Operational logs: one day.
- The mail ledger (one row per email we sent you — Section 2): for the life of your account.
- The support trail (Section 2): 90 days, then deleted by rule.
- Your account, your staff, your Merchant Data: for the life of your account. The event log and the revision archive are permanent business records by design — every change is an event, and your books can be replayed years later. Personal information inside them is removed by de-identification when you or your customer ask (Section 3), never by rewriting history.
- Backups: point-in-time recovery on the primary databases covers the trailing 35 days. The event log moves to cold storage after 90 days and is kept; long-term snapshots move to deep archive on creation and are deleted after ten years, on a fixed schedule. Deleted data leaves the recovery window as it ages out.
- Mail to our @almondtill.com addresses: two years in our inbound mail store; the forwarded copy in the privacy officer's mailbox is the working record of your request.
- After you leave: thirty days of export access, then deletion from live systems and aging out of backups, except records we must keep by law (Terms §11).
9. How we protect it
Encryption in transit (TLS everywhere) and at rest (server-side encryption on every database and bucket). Tenant isolation at the record level. Passwords hashed with Argon2id; API keys and device credentials stored as hashes; sessions sealed in HttpOnly, Secure, SameSite=Strict cookies. Least- privilege access for our own systems, each role's permissions mirrored in source and audited against the live estate. Every change an event on an append-only log. Point-in-time recovery on the primary databases. If we learn of a breach of security safeguards creating a real risk of significant harm, we will notify you without unreasonable delay with enough detail for your own PIPEDA obligations, and keep the records the law requires (Terms §3.9).
10. Your rights
You may ask to see the personal information we hold about you and your staff, to correct it, or to withdraw consent for any optional use; you may close your account and export your data at any time. Write to privacy@almondtill.com. We answer within the time PIPEDA allows. If you are not satisfied, you may complain to the Office of the Privacy Commissioner of Canada.
For your customers' rights, the tools are in the Service (Section 3); we assist you on request.
11. Children
The Service is offered to businesses, not to consumers in their personal capacity, and is not directed at children.
12. Changes
We will give notice of material changes before they take effect (Terms §15). The current version and its effective date are always shown at the top of this page.
- 1.1 (2026-09-10): added Mail we send you (Section 2) and its retention line (Section 8) — the ledger behind the reference on every email’s last line. A transparency addition; nothing else changed.