Legal
Privacy Policy
How Daybook Technologies Inc. collects, uses, discloses and protects personal information.
Version 1.0 | Effective: October 7, 2026
1. Introduction and Scope
Daybook Technologies Inc. (“Daybook,” “we,” “us” or “our”) is a federally incorporated Canadian company registered to operate in Prince Edward Island. Daybook operates a cloud-based business management platform (the “Platform”) that helps businesses manage client and employee records, appointments and scheduling, invoicing and payments, communications, websites and forms, document and image processing, and related business workflows, including artificial intelligence and automated processing features.
This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with the Platform. Personal information processed through the Platform may include:
(a) Customer Account Information: information Daybook collects or generates concerning businesses that subscribe to the Platform (“Customers”), and their administrators, employees, contractors and other authorized users, including account-registration details, contact information, billing and payment-status information, subscription-plan information, account activity, last-sign-in information, feature usage, engagement information, support communications, and account health or engagement indicators;
(b) Customer Content: information that Customers or their users upload, enter, transmit, generate or otherwise make available through the Platform, including information about the Customer’s clients, employees, contractors and other individuals; and
(c) End User Information: information relating to individuals who interact with a Customer through the Platform, including through Customer websites, client or parent portals, quote or registration forms, appointment-booking tools, connected email accounts and calendars, email or text communications, document or photo uploads, and other public-facing or interactive features of the Platform.
This Policy applies to all of these categories of information. Please read it carefully. If you have questions, contact our Privacy Officer using the details in Section 2. For further clarity, this Policy primarily addresses information processed in connection with the Platform and Daybook’s relationships with Customers and their users.
2. Who We Are and How to Contact Us
Daybook Technologies Inc. is federally incorporated in Canada and registered to operate in Prince Edward Island.
Privacy Officer
- Email: ryan@daybookpro.com
- Phone: (902) 218-5519
- Mailing Address: 17282 Route 2, Milton, PE C1E 0W2
Our Privacy Officer is responsible for overseeing our compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and for responding to privacy inquiries and complaints.
Daybook is committed to the ten fair information principles set out in Schedule 1 of PIPEDA: Accountability; Identifying Purposes; Consent; Limiting Collection; Limiting Use, Disclosure, and Retention; Accuracy; Safeguards; Openness; Individual Access; and Challenging Compliance.
3. Daybook’s Role and Your Customer’s Role
The allocation of responsibility between Daybook and a Customer is important where an individual’s personal information is processed through the Platform on behalf of that Customer.
Daybook as service provider
When a Customer uses the Platform to manage information about its clients, employees, contractors or other individuals, Daybook acts as a service provider. Daybook processes Customer Content on the Customer’s instructions to provide, operate, secure and support the Platform and perform the processing activities described in this Policy and the applicable agreement with the Customer. The Customer, not Daybook, generally determines what information is collected, for what purposes and for how long.
Daybook’s responsibility for Customer Account Information
For Customer Account Information, such as account registration, administrative contact and billing information, Daybook determines the purposes for which the information is collected, used and disclosed. Daybook is responsible for that information under PIPEDA and other applicable privacy laws.
Sales Partners
Daybook may appoint an independent sales representative, referral partner, reseller, agency or other sales partner (“Sales Partner”) to introduce a Customer to Daybook, administer or support Daybook’s commercial relationship with the Customer, assist with onboarding or training, or provide first-line account or support assistance.
A Sales Partner may receive limited Customer Account Information for these purposes. Where a Sales Partner processes Customer Account Information on Daybook’s behalf, the Sales Partner acts as a service provider to Daybook. Where a Sales Partner processes Customer Content or other personal information on behalf of a Customer through Daybook, the Sales Partner may act as a subprocessor subject to Daybook’s contractual and legal obligations.
Sales Partners are not provided with general access to a Customer’s client lists, jobs, invoices or other Customer Content solely because they introduced or are assigned to the Customer. They may, however, receive Customer Content included in a support or assistance request as described in this Policy.
What this means for individuals
If your personal information is held in the Platform as a client of a Daybook Customer (for example, as a parent whose child is enrolled at a day camp that uses the Platform), you should direct requests concerning access, correction, withdrawal of consent, deletion or retention of your information to that Customer in the first instance. Daybook will assist Customers in responding to such requests.
4. Information We Collect
(a) Customer Account Information
We collect the following information directly from Customers when they register for and use the Platform:
- Business name, address, and contact details.
- Name and contact details of account administrators and authorized users.
- Billing and payment-related information: Payment-card processing is handled by Stripe. Daybook receives information such as payment status, card type, the last four digits of the payment card, billing address and transaction identifiers. Daybook does not receive or store full payment-card numbers or card security codes. Daybook may make subscription and payment-status information available to an assigned Sales Partner but does not provide the Sales Partner with full payment-card numbers or card security codes.
- Account activity logs and support communications.
- Subscription plan, subscription status, payment status and related commercial information.
- Account activity, including dates of sign-in or other account activity.
- Feature-usage, adoption and engagement information.
- Account health or engagement scores and the information used to generate those indicators.
- Support, onboarding, training and account-management requests and communications.
- Information identifying the Sales Partner assigned to the Customer and the source or referral through which the Customer was introduced to Daybook.
(b) Customer Content
Customers and their users may upload, enter, transmit, generate or otherwise make information available through the Platform. Depending on how a Customer uses the Platform, Customer Content may include:
- Client names, addresses, telephone numbers, email addresses and other contact information; appointment, scheduling, job and service records; quotes, invoices, receipts, supplier bills, bank statements and other business and financial records; emails and mailbox information obtained from connected email accounts, including message content, sender and recipient information, subject lines, headers, attachments and message status; calendar events and associated attendee, scheduling, location and meeting information; text messages, voice notes, photographs and other communications or files.
- For day camp, daycare and similar Customers: children’s names, dates of birth, allergies, health and medical information, emergency contacts, care information and authorized pickup persons.
- Employee and contractor information, including names, dates of birth, home addresses, Social Insurance Numbers, banking or direct-deposit information, compensation and pay rates, TD1 forms and payroll records.
- Information submitted through Customer websites, quote requests, registration forms, client or parent portals, appointment-booking tools and other forms or public-facing features made available through the Platform.
- Any other information a Customer or its users choose to enter, upload, transmit or collect through the Platform.
Daybook does not generally determine what Customer Content a Customer chooses to collect or enter into the Platform. Customers are responsible for ensuring that they have the legal authority to collect, use and disclose Customer Content and to provide it to Daybook for processing in connection with the Platform. Social Insurance Numbers, banking information, health and medical information, and other information of a similarly sensitive nature are treated as sensitive personal information and are subject to safeguards appropriate to the sensitivity of that information.
(c) End User Information
Individuals may interact with the Platform even if they are not Customers or registered users of Daybook. This includes individuals who visit or interact with a Customer website; submit or approve a quote; complete a camp, daycare or other registration form; book or request an appointment; upload a photograph, document or other file; communicate with a Customer by email or text message; access a client, parent or other end-user portal; or otherwise provide information through a public-facing or interactive feature of the Platform.
Information submitted through these interactions may become Customer Content and may be processed by Daybook on behalf of the applicable Customer. The Customer is responsible for determining the purposes for which this information is collected and for providing any notices and obtaining any consents required by applicable law.
(d) Support and Assistance Requests
When a Customer or user asks Daybook for support, onboarding, training or account-management assistance, Daybook collects the contents of the request and related communications. This information may include the sender’s name and contact details, message content, screenshots, documents, attachments and any Customer Content or personal information included by the sender.
Where the Customer has an assigned Sales Partner, Daybook may route the request to that Sales Partner. The Sales Partner may read the complete request and any information included with it for the purpose of responding to, coordinating or escalating the request.
Customers and users should not include personal information about clients, employees, children or other individuals unless the information is reasonably necessary to obtain assistance and the Customer has authority to disclose it for that purpose.
(e) Technical and Usage Information
We collect certain information automatically when the Platform is accessed:
- Technical logs, error reports and crash diagnostics;
- Application usage information, such as features accessed and session duration, collected through the operation of the Platform rather than through third-party advertising or analytics cookies;
- IP address, browser type, device type, operating system, timestamps and similar technical information;
- Authentication, access and security logs; and
- Information collected from browser storage, reCAPTCHA, email tracking and similar technologies described in section 17.
5. Children’s Personal Information
The Platform is supplied to businesses and is not directed or marketed to children. Daybook does not independently solicit personal information from children for its own purposes. However, a Customer may use the Platform to collect or process information about children or may permit a child to interact with a form, portal, communication tool or other Platform feature. In those circumstances, Daybook processes the information on behalf of the Customer.
A Customer may also authorize an employee, apprentice, counsellor or contractor who is at least sixteen (16) years old but has not reached the age of majority to use the Platform. The Customer is responsible for supervising that individual’s use of the Platform and obtaining any consent or authorization required by applicable law.
AI Features, including AI assistants made available through a portal or other interactive interface, are not intended for direct access or use by persons under eighteen (18) years of age. Customers must not enable or knowingly permit a person under eighteen (18) years of age to access or interact directly with an AI Feature. Daybook may use age-screening, account permissions and other technical measures to restrict access to AI Features.
This restriction does not necessarily prevent an authorized adult user from using an AI Feature to process information concerning a child where the Customer has obtained the required authority and the processing is otherwise permitted by applicable law and the terms applicable to the AI service. Children’s information may be particularly sensitive, and Customers should avoid submitting it to an AI Feature unless the processing is reasonably necessary for an identified purpose.
Where a Customer, including but not limited to a day camp or daycare, uses the Platform to manage information about children in their care, that Customer is responsible for:
(a) obtaining all required parental or guardian consents before entering children’s information into the Platform;
(b) providing appropriate privacy notices to parents and guardians;
(c) limiting collection to what is necessary for the purposes of their program; and
(d) responding to requests from parents and guardians regarding their child’s information.
Daybook processes children’s personal information only as directed by the Customer and only to provide the Platform.
Children’s health, allergy, medical, and emergency information is treated as sensitive personal information and is subject to safeguards appropriate to the sensitivity of the information and the reasonably foreseeable risks associated with its processing.
Parents and guardians who have questions about how their child’s information is handled in the Platform should contact the Customer (for example, the day camp or daycare) directly.
If a parent or guardian believes their child’s information has been entered into the Platform without appropriate consent, they may also contact Daybook’s Privacy Officer at ryan@daybookpro.com.
6. Why We Collect and Use Personal Information
Daybook uses personal information for the purposes described below. Where Daybook processes Customer Content on behalf of a Customer, the particular purposes are generally determined by that Customer. Where Daybook processes Customer Account Information or technical and usage information for its own purposes, Daybook determines those purposes subject to applicable law.
(a) To provide and operate the Platform
- Hosting, maintaining, and securing the service
- Processing Customer Content as directed by Customers
- Enabling parent and guardian portal access
- Connecting and synchronizing authorized email accounts, mailboxes and calendars
- Reading, receiving, organizing, drafting and sending email as directed or configured by Customers and their users
- Reading, creating, updating and managing calendar events and appointments
(b) To manage the customer relationship
- Account setup, billing, invoicing, and payment processing
- Customer support and troubleshooting
- Sending service-related notices, such as maintenance windows, security alerts, and policy updates
(c) To administer Sales Partner relationships
- Identifying and administering the Sales Partner assigned to a Customer
- Attributing Customers and subscriptions to Sales Partners
- Calculating, verifying and administering referral fees and commissions
- Providing Sales Partners with limited information concerning subscription and payment status
- Monitoring account adoption, engagement and use
- Identifying Customers that may require onboarding, training, support or account-management assistance
- Enabling an assigned Sales Partner to provide first-line support or account assistance
- Reassigning Customers between Sales Partners and revoking access when it is no longer required
Daybook may generate an account health or engagement score or similar indicator using factors such as subscription status, frequency of access, feature usage, adoption and engagement. Daybook uses these indicators to manage customer relationships and identify whether onboarding, training or support may be useful. They are not intended to assess an individual’s creditworthiness, professional competence or legal compliance and are not used by Daybook to make decisions producing legal or similarly significant effects on an individual.
(d) To improve the Platform
- Diagnosing errors, correcting defects and monitoring performance
- Using aggregated or de-identified information for analytics and product improvement, provided the information cannot reasonably be used, alone or in combination with other reasonably available information, to identify an individual or Customer.
- Daybook does not use identifiable Customer Content for product development or improvement without the applicable Customer’s express consent.
(e) AI Features and Automated Processing
The Platform includes artificial intelligence and automated processing features (“AI Features”) that assist Customers and users with business operations and communications. Depending on the feature, AI Features may read, classify and analyse incoming emails and attachments; draft communications; interpret message threads and assist with or perform appointment booking; extract or analyse information from receipts, supplier bills, bank statements, payroll reports, void cheques and other documents; transcribe voice notes; analyse photographs and images; generate website copy and other written content; generate summaries and reports; and respond to questions or requests submitted by Customer personnel, clients or other end users. Some AI Features are initiated directly by a user, while others may operate automatically or in the background as part of a workflow configured or enabled by the Customer. Additional information is set out in Section 8.
(f) Legal and compliance purposes
- Complying with applicable law, court orders, and regulatory requirements
- Enforcing the Subscription Agreement
- Preventing fraud and protecting Platform security
(g) Message delivery and tracking
- Delivering Customer emails and other communications
- Recording delivery, bounce and suppression status
- Recording whether and when emails sent through the Platform are opened and associated technical information, such as IP address, browser type or device information
- Making message-delivery and opening information available to the Customer that sent the message
7. Consent
Daybook obtains meaningful consent for the collection, use and disclosure of personal information where consent is required by applicable law. The appropriate form of consent depends on the sensitivity of the information and the reasonable expectations of the individual.
Daybook may rely on:
(a) express consent where appropriate, including for sensitive personal information or processing that would not reasonably be expected by the individual;
(b) implied consent where the purpose is apparent, the information is not sensitive and the processing is reasonably necessary to provide a requested product or service; and
(c) an exception to consent permitted or required by applicable law, including where the collection, use or disclosure is required by law.
Where Daybook processes Customer Content on behalf of a Customer, the Customer is responsible for identifying the purposes of collection, providing required privacy notices and obtaining any consent required from its clients, employees, contractors, parents, guardians and other individuals. Daybook relies on the Customer’s instructions and representations concerning that authority.
Individuals may withdraw consent at any time by contacting the relevant Customer or, for Customer Account Information, by contacting Daybook’s Privacy Officer. Withdrawal of consent may affect the ability to use the Platform or receive certain services.
Although Customers are responsible for their collection purposes and instructions, Daybook remains responsible for processing Customer Content in accordance with its contractual obligations, implementing appropriate safeguards, limiting access and use to authorized purposes, and using appropriate contractual or other protections for service providers that process personal information on Daybook’s behalf.
Consent to receive marketing communications from Daybook is separate and optional. It is not a condition of using the Platform.
Where a Customer submits a support or assistance request that contains personal information about another individual, Daybook relies on the Customer’s representation that the information is reasonably necessary for the request and that the Customer has authority to disclose it to Daybook and, where applicable, the assigned Sales Partner.
Daybook limits a Sales Partner’s use of personal information to authorized account-management, onboarding, training, support, commission-administration and related purposes. A Sales Partner is not permitted to use Customer information for unrelated prospecting, advertising, sale or other independent purposes.
8. AI Features and Automated Processing
Certain features of the Platform use artificial intelligence services, including services provided by Google and other service providers identified in Section 11, to analyse, extract, classify, transcribe, generate, summarize or otherwise process Customer Content (“AI Features”). AI Features may process emails, text messages, attachments, business and financial documents, voice recordings or voice notes, photographs and images, website content, appointment and scheduling information, and other Customer Content. AI Features may also generate communications, summaries, website content, responses and other outputs (“AI Outputs”). Some AI Features operate only when initiated by a user; others may operate automatically or in the background where the Customer has enabled or configured the applicable functionality. When an AI Feature is used, relevant Customer Content may be transmitted to an artificial intelligence service provider for processing outside Canada, including in the United States. Further information about cross-border processing is provided in Section 10.
Certain AI Features may also perform or initiate actions, including creating or updating records, drafting or sending communications, and scheduling appointments (“AI Actions”). Where a Customer enables an AI Feature to perform an AI Action automatically, the Customer is responsible for configuring and monitoring that functionality, reviewing material actions and correcting errors.
Age restrictions: AI Features are not intended for direct access or interaction by persons under eighteen (18) years of age. Customers are responsible for accurately configuring age-related permissions and must not permit persons under eighteen to interact directly with AI Features. Daybook may restrict or disable AI access where the applicable user is known or reasonably believed to be under eighteen.
AI Accuracy: AI Outputs are generated probabilistically and may be incomplete, inaccurate, outdated or unsuitable for the intended purpose. Users should independently review AI Outputs before relying on them. Where an AI Feature performs or initiates an AI Action automatically, the applicable Customer should maintain oversight appropriate to the nature and consequences of the action. AI Features are not a substitute for professional judgment.
Decisions about individuals: AI Features must not be used to make consequential decisions about individuals, including decisions about a child’s care, health, or safety, without independent human review of the underlying source record.
Daybook configures and uses third-party AI services under commercial terms intended to prohibit Customer Content submitted through the Platform from being used to train or improve general-purpose artificial intelligence models. Daybook does not knowingly submit Customer Content to a free or unpaid AI-service tier that permits the provider to use that Customer Content for general-purpose model training or improvement.
An individual who believes that an AI Output or AI Action has been used in a manner that significantly affects them may request information or human review by contacting the Customer whose account was used. The individual may also contact Daybook’s Privacy Officer, and Daybook will assist the Customer as appropriate and as required by applicable law.
Customers may contact Daybook at ryan@daybookpro.com to request information about available controls for enabling or disabling AI Features. The availability of such controls may depend on the Customer’s plan and the applicable functionality.
9. Communications Sent Through the Platform (CASL)
The Platform enables Customers to send electronic messages, including email and SMS, to their own clients on their behalf. Examples include appointment reminders, invoices, quotes, registration communications, automatically drafted or sent messages, and other notifications. These messages are sent by the Customer, not by Daybook.
Customers are responsible for complying with Canada’s Anti-Spam Legislation (CASL) and all other applicable anti-spam and electronic communications laws. This includes obtaining required consents from recipients, including accurate sender identification in messages, and providing a functional unsubscribe mechanism.
Daybook provides technical functionality to support compliance, including unsubscribe mechanisms, but does not review or approve the content of messages sent by Customers.
If you wish to unsubscribe from messages sent by a Customer through the Platform, please use the unsubscribe link in the message or contact that Customer directly.
Daybook may send service-related communications to Customers, such as invoices, security alerts, maintenance notices and policy updates. Depending on their content and purpose, these messages may not be commercial electronic messages or may be exempt from certain CASL consent requirements. Daybook will obtain any consent required by CASL before sending marketing or promotional communications and will include the identification and unsubscribe information required by applicable law.
10. Where Your Information is Stored and Processed
Primary database – Canada
The primary production database containing Customer Content is hosted using Google Firebase infrastructure in the Toronto, Ontario region. Certain Customer Content may also be transmitted to, temporarily processed by or retained through other infrastructure and service providers as described below and in section 11.
Server processing – United States
Most server application code that reads and processes Customer Content runs in the United States using Google Cloud Functions. This processing may include information obtained from connected email accounts and calendars.
AI and automated processing – outside Canada
When AI Features or other automated processing features are used, relevant Customer Content may be transmitted to and processed by service providers outside Canada, including in the United States. The location of processing may depend on the applicable service provider and functionality and may not be selectable by Daybook.
Connected email and calendar services
Where a Customer or user connects a Google or Microsoft account, email, mailbox, calendar and related account information may be transmitted between the Platform and Google or Microsoft and processed outside Canada, including in the United States. The information processed depends on the permissions granted and the functionality enabled by the Customer or user.
Payment processing
Payment information is processed by Stripe, which operates globally. Please refer to Stripe’s privacy policy for details of where payment data is processed.
Support access
Daybook personnel may remotely access Customer Content from Canada or other locations to provide technical support. Daybook personnel do not read email or other messages received from a connected Google or Microsoft account, except with the permission of the user or Customer, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the information has been aggregated and anonymized for internal operations.
Sales Partner access
An assigned Sales Partner may access limited Customer Account Information and may review support or assistance requests submitted by the Customer. The location from which a Sales Partner accesses personal information depends on the Sales Partner assigned to the Customer. Daybook will identify Sales Partners that process personal information as service providers or subprocessors, together with their processing locations, on its current service-provider or subprocessor list.
If a Sales Partner accesses personal information from outside Canada, the information may be subject to the laws of the jurisdiction from which it is accessed, including lawful access by courts, law-enforcement, regulatory or national-security authorities.
What this means for you
Although Daybook’s primary production database is located in Canada, some personal information, including sensitive personal information and information about children, employees, contractors and other individuals, may be transmitted to and processed outside Canada, including in the United States. Personal information processed outside Canada may be subject to the laws of the jurisdiction in which it is processed and may be accessible to courts, law enforcement, regulatory or national security authorities in accordance with those laws.
Safeguards
Daybook uses contractual, technical, and organizational safeguards to protect personal information processed outside Canada and remains accountable for that information under PIPEDA.
11. Service Providers and Subprocessors
Daybook uses service providers and subprocessors to operate and support the Platform. Before permitting a service provider to process personal information, Daybook takes reasonable steps to assess the provider and uses contractual or other measures appropriate to the nature and sensitivity of the information and the applicable processing.
Daybook may also use Sales Partners to provide customer relationship management, onboarding, training and first-line support. A Sales Partner that receives only non-personal corporate or commercial information is not necessarily a subprocessor. A Sales Partner that processes personal information on Daybook’s behalf is required to comply with contractual confidentiality, privacy, security, use and deletion restrictions.
| Service Provider | Location | Purpose |
|---|---|---|
| Google Firebase | Canada and outside Canada, including the United States | Database and file storage |
| Google Cloud Platform/Google Cloud Functions | Outside Canada, including the United States | Server application hosting, server-side processing and related infrastructure |
| Google AI Services | Outside Canada, including the United States | AI Features and automated processing |
| Stripe | Global | Payment processing |
| Twilio | Outside Canada, including the United States | SMS and communications services |
| Postmark | Outside Canada, including the United States | Incoming email processing |
| Replicate | Outside Canada, including the United States | AI and image/photo analysis |
| Google Maps | Outside Canada, including the United States | Mapping and location-related functionality |
| Google reCAPTCHA | Outside Canada, including the United States | Spam, fraud and automated-abuse prevention on public forms |
| Google Workspace and Google APIs | Outside Canada, including the United States | Business productivity, communications and related services |
| Microsoft Corporation/Microsoft 365 | Outside Canada, including the United States | Connected business productivity, communications and related services |
| GitHub | United States | Tracking of support requests (names, email addresses and screenshots are removed before a request is sent) |
| Anthropic | United States | AI-assisted investigation of support requests |
| Apple | Outside Canada, including the United States | Push notifications to Apple devices |
| Meta Platforms | Outside Canada, including the United States | Facebook content embedded in Customer websites, where a Customer adds it |
| Affirm | Canada and the United States | Pay-over-time payment options, where a Customer offers them |
| Klarna | Outside Canada, including the United States | Pay-over-time payment options, where a Customer offers them |
| unpkg (content delivery network) | Outside Canada, including the United States | Delivery of a document-viewer component to the browser |
Each Sales Partner that processes Customer Personal Information as a Subprocessor will be identified on Daybook’s current Subprocessor list by legal name, processing purpose and processing location. An up-to-date list of Daybook’s material subprocessors is available on request by contacting ryan@daybookpro.com.
12. Third-Party Connections and Integrations
The Platform may permit a Customer or user to connect third-party applications, accounts, platforms or services (“Third-Party Services”), including Google accounts, Google Workspace, Microsoft 365, email accounts, mailboxes, calendars, payment accounts and other business applications.
Depending on the integration and permissions enabled, Daybook may access, retrieve, read, index, analyse, display or store emails, attachments, calendar events and related information, and may draft or send emails or create, modify or delete calendar events at the Customer’s or user’s direction. Daybook performs these activities only to the extent reasonably necessary to provide the functionality selected, configured or requested by the Customer or user.
When a Customer or user enables an integration, Daybook receives authorization to access the connected account and to transmit information to, and receive information from, the Third-Party Service. The Customer is responsible for ensuring that it and its users have authority to connect the account and permit Daybook to process the information available through it.
The permissions requested for a connected account will depend on the applicable functionality. For example, email functionality may require permission to read, receive, organize, draft or send email, while calendar functionality may require permission to read, create, update or delete calendar events. Daybook will request only those permissions reasonably required to provide the enabled functionality.
Third-Party Services are operated independently of Daybook and are subject to their own terms, privacy policies and data-handling practices. Daybook does not control and is not responsible for the collection, use, disclosure, retention or security of information by a Third-Party Service after information has been transmitted to that service at the Customer’s direction, except to the extent required by applicable law.
Customers and users can revoke Daybook’s access through the applicable account or integration settings. Disconnecting an account stops future access through that connection but does not necessarily delete information previously received from or transmitted to the Third-Party Service. Information previously stored in the Platform will be retained and deleted in accordance with section 14.
Daybook’s use and transfer to any other application of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements. Daybook uses information received from Google APIs only to provide or improve user-facing functionality requested or enabled by the Customer or user, maintain and secure the applicable integration, comply with applicable law, or as otherwise permitted by the Google API Services User Data Policy.
Google user data. When a user connects a Gmail or Google Workspace mailbox, Daybook asks for permission to read, send and organize email in that mailbox and to know the account’s email address. With that permission Daybook: (a) copies messages from the mailbox’s Inbox and Sent folders, with their attachments, into the Customer’s Daybook Inbox — first those from the previous fourteen (14) days, then new messages as they arrive — where they are matched to the Customer’s clients and jobs; (b) sends email that the user writes or approves in Daybook from that mailbox; and (c) keeps read and unread status the same in Daybook and in the mailbox. A connected mailbox feeds the Customer’s shared Daybook Inbox, which the Customer’s owners, administrators and office managers can read. Email content may be processed by the AI Features described in Section 8, for example to summarize a message or recognize a new enquiry, only to provide those features to the Customer. Daybook does not use Google user data for advertising, does not sell it, does not use it to train or improve general-purpose artificial intelligence models, and does not allow people to read it except as described in Section 10. Access to a connected account is held as an encrypted credential. A user can disconnect the mailbox at any time in Daybook or in their Google Account; disconnecting stops further access, and information already copied into Daybook is retained and deleted as described in Section 14.
13. Disclosure of Personal Information
Daybook does not sell personal information.
Daybook does not disclose personal information to third parties except in the following circumstances:
(a) to subprocessors as described in Section 11, to the extent necessary to provide the Platform;
(b) as directed or authorized by the Customer, including to provide an integration or disclose information to a person authorized by the Customer;
(c) to an assigned Sales Partner, to the extent reasonably necessary to identify and administer the Customer account, attribute the Customer or subscription, calculate or verify commissions, monitor subscription and payment status, monitor product adoption and engagement, identify support or training needs, and manage Daybook’s commercial relationship with the Customer;
(d) to an assigned Sales Partner for the purpose of receiving, reviewing, responding to or escalating a support, onboarding, training or account-management request submitted by or on behalf of the Customer, including any Customer Content or personal information included in the request;
(e) where required or permitted by applicable law, including in response to a court order, warrant or lawful request from a governmental, regulatory or law-enforcement authority;
(f) where permitted by applicable law and reasonably necessary to detect, prevent or investigate fraud, security incidents, unlawful activity or threats to the rights, property or safety of Daybook, its Customers or other persons; or
(g) in connection with a proposed or completed financing, merger, reorganization, acquisition or sale of all or part of Daybook’s business or assets, subject to appropriate confidentiality and privacy safeguards and any notice or consent required by applicable law.
Daybook does not provide a Sales Partner with general access to a Customer’s client lists, jobs, invoices or other Customer Content solely because the Sales Partner introduced or is assigned to the Customer. Access to Customer Content is limited to information included in or reasonably necessary to address a support request submitted or authorized by the Customer, or as otherwise directed or authorized by the Customer.
14. Retention and Deletion
- Customer Account Information: Customer Account Information is retained for the duration of the subscription and for a reasonable period thereafter for legal, tax, and audit purposes, typically seven (7) years for financial records.
- Customer Content: Customer Content is ordinarily retained for the duration of the Customer’s subscription. Upon expiry or termination of a paid subscription, Daybook will make Customer Content available for export for thirty (30) days and may restrict access during that period to read-only access or export functionality. After that period, Daybook may delete Customer Content from its active systems, unless continued retention is required by applicable law. Customers are responsible for exporting and retaining records they are required to preserve under applicable law, professional standards or contractual obligations before the export period expires. Residual copies in backup systems may remain until deleted or overwritten in the ordinary course of Daybook’s backup-retention cycle.
- Expired free trials: If a prospective Customer does not begin a paid subscription after a free trial, Daybook may provide access to Customer Content for export for thirty (30) days after the trial expires. After that period, Daybook may restrict access and may delete the Customer Content from active systems in accordance with its retention practices. Prospective Customers are responsible for exporting information they wish to retain before the export period expires. Residual backup copies may remain until deleted or overwritten through Daybook’s ordinary backup-retention cycle.
- Security and breach records: Records of breaches of security safeguards are retained for at least twenty-four (24) months after the day on which Daybook determines that the breach has occurred, as required by the Breach of Security Safeguards Regulations made under PIPEDA.
- Technical and usage logs: Technical and usage logs are retained for periods reasonably necessary for security, troubleshooting, operation and administration of the Platform and are thereafter deleted or anonymized, subject to applicable legal requirements.
- Connected-account information: Information received from a connected Google, Microsoft or other third-party account is retained only for as long as reasonably necessary to provide the enabled functionality and in accordance with the retention periods applicable to the Customer’s account and Customer Content. Revoking or disconnecting an account stops future access through that connection but does not automatically delete information previously imported into or stored in the Platform. Previously stored information is kept with the Customer’s other Customer Content and may be deleted upon account termination in accordance with this section.
- Sales Partner access and copies: Daybook retains records identifying the Sales Partner assigned to a Customer and related referral, commission, account-management and support activity for periods reasonably necessary to administer the relationship, resolve disputes, comply with tax and accounting requirements and enforce applicable agreements. When a Sales Partner is removed or reassigned, Daybook revokes the Sales Partner’s access and requires the Sales Partner to return or delete personal information in its possession or control that is no longer required for an authorized purpose, unless continued retention is required by applicable law. Information retained pursuant to law remains subject to applicable confidentiality, security and use restrictions.
Retention periods may be extended where required or permitted by applicable law or where reasonably necessary to establish, exercise or defend a legal claim, resolve a dispute, investigate a security incident or enforce an agreement.
15. Security Safeguards
Daybook maintains administrative, technical and physical safeguards appropriate to the sensitivity of the personal information, the purposes for which it is processed and the reasonably foreseeable risks. Depending on the relevant system and processing activity, these safeguards may include:
- Encryption of data in transit and at rest
- Role-based access control
- Audit logging and monitoring
- Incident response procedures
- Individual credentials and role-based access restrictions for Sales Partners
- Access limited to Customers assigned to the Sales Partner
- Contractual confidentiality, privacy, security and use restrictions
- Training and incident-reporting requirements
- Access revocation and return or deletion requirements following reassignment or termination
No security measure is perfect. In the event Daybook confirms that a breach of security safeguards has occurred involving Customer Content, Daybook will notify the affected Customer without undue delay and provide available information reasonably necessary to assist the Customer in assessing and fulfilling its notification and recordkeeping obligations. Where Daybook controls the affected personal information, Daybook will provide any notification required by applicable law.
Daybook does not knowingly provide Sales Partners with unrestricted access to Customer accounts or Customer Content. Sales Partner access is intended to be limited to assigned Customers, authorized Customer Account Information and Customer Content included in or reasonably necessary to address an authorized support request.
16. Your Rights
Under PIPEDA, individuals have the right to:
(a) be informed of the existence, use, and disclosure of their personal information;
(b) access their personal information held by Daybook;
(c) request correction of inaccurate or incomplete information;
(d) withdraw consent, subject to legal or contractual restrictions; and
(e) challenge Daybook’s compliance with PIPEDA.
Customers and users may request access to or correction of personal information contained in Customer Account Information, including inaccurate account activity or engagement information, by contacting Daybook’s Privacy Officer. A request concerning an account health or engagement indicator will be assessed by reference to the underlying account information used to generate that indicator.
How to exercise your rights
Contact Daybook’s Privacy Officer at ryan@daybookpro.com.
If your personal information is held in the Platform as a client of a Daybook Customer, please direct your request to that Customer in the first instance. Daybook will assist the Customer in responding to your request.
Where Daybook is responsible for the personal information, Daybook will respond to an access request within thirty (30) days or within any extended period permitted by applicable law. Where Daybook processes the information on behalf of a Customer, Daybook may refer the request to that Customer and assist the Customer in responding.
Complaints
If you are not satisfied with Daybook’s response to your privacy concern, you may file a complaint with the Office of the Privacy Commissioner of Canada:
- Website: www.priv.gc.ca
- Address: 30 Victoria Street, Gatineau, QC K1A 1H3
- Telephone: 1-800-282-1376
17. Cookies and Tracking Technologies
The Platform uses limited browser storage and similar technologies necessary to provide and operate the Platform. Daybook does not currently use analytics cookies to track use of the Platform. Depending on the feature used or enabled by the applicable Customer, the technologies used by or through the Platform may include:
- Browser and local storage, which may store information in a user’s browser or device to maintain authentication, remember settings and support offline or interrupted-connectivity functionality;
- Google reCAPTCHA or similar technology on public-facing forms to detect spam, automated submissions, fraud or abuse, which may result in information about the browser, device or interaction being transmitted to Google. Use of reCAPTCHA is subject to Google’s applicable privacy policy and terms; and
- Email open tracking in emails sent through the Platform, including messages, quotes and invoices. A tracking pixel or similar technology may record whether and when an email is opened and, depending on the technology and recipient’s email settings, may collect an IP address, browser type, device information or similar technical information. This information may be made available to the Customer that sent the message.
Browser or device settings may allow individuals to control certain browser storage technologies. Disabling technologies necessary for the operation of the Platform may affect its functionality.
Some email applications allow recipients to limit this tracking by blocking remote images or changing privacy settings. These controls are provided by the recipient’s email application and may not prevent every form of message tracking.
18. Changes to This Privacy Policy
Daybook may update this Privacy Policy from time to time to reflect changes in our practices, the Platform, or applicable law.
Material changes, particularly those involving new AI processing activities, new foreign processing locations, new uses of children’s personal information, or materially broader uses of personal information, will be communicated to Customers before taking effect and may require renewed consent.
The current version of this Policy and its effective date will be posted at https://daybookpro.com/privacy. Where required by applicable law, Daybook will provide additional notice or obtain consent before a material change takes effect. Continued use of the Platform after the effective date of a change constitutes acknowledgement of the updated Policy but does not replace any consent required by applicable law.
19. Contact Us
For any privacy-related questions, requests, or complaints, please contact:
- Organization: Daybook Technologies Inc.
- Privacy Officer email: ryan@daybookpro.com
- Phone: (902) 218-5519
- Mailing Address: 17282 Route 2, Milton, PE C1E 0W2
You may also contact the Office of the Privacy Commissioner of Canada if you have concerns about how your personal information has been handled:
- Website: www.priv.gc.ca
- Address: 30 Victoria Street, Gatineau, QC K1A 1H3
- Telephone: 1-800-282-1376