Privacy Policy
Last updated: 9 September 2026
This policy explains what personal information Settles collects, why, and what you can do about it. It is written to meet Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
Plain-language summary, with the detail below:
- We collect what is needed to run the software, and nothing to sell.
- We never sell personal information, and we never share it for advertising.
- We never see or store card numbers.
- We do not collect Social Insurance Numbers or bank details for your staff.
- Each business's data is isolated at the database level.
1. Two different relationships
Settles serves businesses. That creates two roles, and your rights differ depending on which applies to you.
If you signed up for Settles, we hold your information for our own purposes (billing you, supporting you), so we are responsible for it. Contact us directly with any request.
If your information is in Settles because a business you deal with put it there (you are a client of a contractor who uses Settles, or you work for one), then that business decides what is collected and why. We hold it on their behalf and act on their instructions. Please contact them first. If you cannot reach them, contact us and we will help you get to the right place.
2. What we collect
From the business that signs up
- Name, email, phone, and password (stored only as a cryptographic hash)
- Business name, address, and GST number if you provide one
- Your chosen plan and add-ons
- Payment card details, which go directly to Stripe. We receive only the card brand, last four digits, and expiry so we can show you which card is on file.
From people who work for that business
- Name, email, phone, role and start date
- Optionally a profile photo, and emergency contact details you choose to add
- Hours worked, and location captured only at clock in, clock out, job start and job complete, with browser permission
- Job notes, checklists and photos uploaded during work
We do not collect Social Insurance Numbers, and we do not collect staff banking information. Settles calculates pay figures; it does not pay anyone.
About the business's clients
- Name, business name, email, phone and addresses
- Service locations, including access notes and gate codes the business records
- Job history, invoices and payment records
- Whether they have agreed to receive texts, including the exact wording they agreed to, the date and time, and the IP address
Automatically
- Log data such as IP address, browser type and pages visited
- Records of significant actions in the app, for security and audit purposes
3. Why we collect it
We collect and use personal information to:
- provide the software you signed up for
- authenticate users and keep accounts secure
- bill you and collect payment
- send invoices, receipts and reminders that a business asks us to send
- send texts, once that feature is offered, where a business has enabled it and consent exists
- calculate pay figures from recorded hours and the rates a business enters
- detect and investigate fraud, abuse and security incidents
- meet legal obligations, including keeping financial records
- support you when you ask for help
We do not use personal information for advertising. We do not build profiles for marketing. We do not use one customer's data to serve another.
4. Location information
Location is captured only at four moments: clock in, clock out, job start and job complete. It requires browser permission and can be declined.
There is no continuous tracking. Settles does not follow anyone during the day or between jobs.
A clock-in far from the job site is flagged for a manager to review. It is never blocked automatically, and a flag is not a conclusion.
5. Card payments
We never see, receive or store card numbers, CVCs or full card details. Card entry happens in fields hosted by Stripe, on Stripe's systems.
When a card is saved for future use, Stripe holds it and gives us a token plus the brand, last four digits and expiry, so a person can recognise which card is on file.
Stripe's handling of that data is governed by Stripe's privacy policy.
6. Connecting your Gmail mailbox
This section is about one optional feature, and it is deliberately specific because it involves your email. Today it works with Gmail. Outlook is not yet offered; when it is, the same rules will apply and this policy will say so.
Settles can mark an invoice paid on its own when a client sends an Interac e-transfer. To do that it needs to read the notification your bank emails you when money arrives. You can either forward those emails yourself, in which case this section does not apply, or connect your mailbox once and let Settles read them.
What we access. With Gmail we request read-only access (gmail.readonly). That permission does not allow sending, replying, moving, deleting or changing anything in your mailbox, and we never do any of those things.
What we actually read. Every ten minutes we ask your mail provider for messages from the bank notification addresses only: Interac's own address for money you receive, plus any address you have added yourself in Settings. Nothing else in your mailbox is requested or received. We do not scan, index or search the rest of your mail.
What we keep. From each notification we store the amount, the date, the sender name, the reference number and the message the sender typed, so the matching payment appears on your invoice. We do not keep a copy of the email itself.
What we never do. We do not use this data for advertising. We do not sell it, and we do not share it with anyone other than the infrastructure providers listed above who store it on our behalf. We do not use it to train artificial intelligence or machine learning models. No person at Settles reads your mail: access is automated, and a human would only ever look at stored notification details with your explicit permission, or where security or the law requires it.
Limited Use. Settles's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Turning it off. Disconnect at any time in Settings, under Client payments. Disconnecting revokes our access with your provider and deletes our copy of the access credentials. You can also revoke it directly at myaccount.google.com/connections. Revoking stops the reading immediately; payments already recorded on your invoices stay, because they are your accounting records.
Where the credentials live. The tokens that let us read your mailbox are encrypted before they are stored, with a key held only on our servers, so a copy of our database on its own does not grant access to your mail.
7. Who we share it with
We share personal information only with service providers who help us run Settles, and only as far as needed:
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | United States |
| Vercel | Application hosting | United States |
| Stripe | Payment processing | United States / global |
| Resend | Sending email | United States |
| Google Maps | Displaying maps, converting addresses to coordinates | United States |
| Google (Gmail) | Reading bank e-transfer notifications, only if you connect a mailbox | United States |
| GitHub | Encrypted database backup copies, kept up to 90 days | United States |
| Cloudflare | Domain name service, and encrypted database backup copies | United States / global |
| Twilio | Sending text messages, once that feature is offered | United States |
We may also disclose information where the law requires it, to respond to a valid legal request, to protect someone's safety, or in connection with a sale or reorganisation of our business. If a sale happens, we will tell you.
We do not sell personal information to anyone, for any purpose.
8. Information stored outside Canada
Some providers above store data in the United States. Information stored there may be accessible to US authorities under their laws, including through court orders, regardless of where it came from.
By using Settles you consent to that transfer and storage. If it is unacceptable for your purposes, Settles is not the right tool for you and we would rather tell you that plainly.
9. How we protect it
- All traffic is encrypted in transit (HTTPS), and data is encrypted at rest by our database provider.
- Passwords are stored only as cryptographic hashes and are never recoverable.
- Each business's data is isolated at the database level, using row-level security rather than only application code, so a defect in one screen cannot expose another business's data.
- Access to pay information is restricted by role, and an owner controls whether managers can see it.
- Card data never touches our servers.
- Significant actions are logged with before and after values.
- The database is backed up every hour. Backup files are encrypted before they leave the database, and only we hold the key.
No system is perfectly secure. If a breach creates a real risk of significant harm, we will notify affected people and the Privacy Commissioner of Canada as PIPEDA requires.
10. How long we keep it
- Active accounts: for as long as the account exists.
- After cancellation: you can export for 30 days, then we may delete.
- Financial records (invoices, payments, ledger entries): six years, because tax law requires it. This applies even after an account is deleted, and it overrides a deletion request for those specific records.
- Consent records (text messages, saved cards): kept while consent stands and for a reasonable period after, so we can show what was agreed.
- Logs: normally under 12 months.
11. Your rights
Under PIPEDA you may:
- Ask what we hold about you and get a copy
- Correct it if it is wrong
- Withdraw consent, subject to legal and contractual limits
- Ask us to delete it, subject to the retention rules above
- Complain about how we handled your information
Write to support@settles.ca. We will respond within 30 days. We may need to verify who you are first, so that we do not disclose someone's information to the wrong person.
If your information is in Settles because a business put it there, please ask that business first, since they decide what is held and why.
If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner of Canada.
12. Cookies
We use only the cookies needed to keep you signed in and keep the service secure. We do not use advertising or cross-site tracking cookies, and we run no third-party analytics that profile you.
13. Children
Settles is a business tool and is not intended for anyone under 18. We do not knowingly collect information from children. If you believe we have, tell us and we will delete it.
14. Changes
We may update this policy. Material changes will be notified by email or in the app at least 30 days in advance. The date at the top always shows the current version.
15. Contact
support@settles.ca
Ask for the Privacy Officer if your question concerns this policy.