Legal
Privacy Policy
Last updated: April 30, 2026
This Privacy Policy describes how 9839429 Canada Inc. (operating as ChiefOS) ("ChiefOS", "we", "us", "our") collects, uses, discloses, and protects personal information when you use our website, web portal, and messaging-based features (including WhatsApp ingestion). We are subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Canadian provincial privacy laws.
1. What information we collect
Account information
- Email address and authentication credentials used to create and access your account.
- Phone number, if you connect a messaging integration (e.g. WhatsApp).
- Business name and profile information you provide during onboarding.
Customer Data (business records)
- Receipts, invoices, and financial documents you submit by photo, file upload, or email.
- Transaction records including amounts, dates, vendors, categories, and job assignments.
- Time entries, job records, tasks, and reminders you log through the platform.
- Voice messages and text messages sent through connected messaging channels.
- Metadata associated with submitted records (file names, timestamps, source channels).
Usage and technical information
- Page views, feature interactions, and navigation activity within the platform.
- Device type, browser, operating system, and IP address.
- Request timestamps, error logs, and security event logs.
Payment information
- Billing status and subscription tier. Payments are processed by Stripe and we do not store full card numbers or CVV codes.
2. How we use information
- Operate, maintain, and improve the Service.
- Process and organize business records you submit.
- Generate AI-assisted insights, summaries, and answers about your business data.
- Authenticate your identity and protect account security.
- Send transactional communications such as receipts, account alerts, and support responses.
- Send product updates, feature announcements, and relevant offers (you may opt out — see Section 9).
- Comply with applicable laws and respond to lawful requests from authorities.
- Investigate and prevent fraud, abuse, and security incidents.
3. Artificial intelligence and automated processing
ChiefOS uses AI systems to analyze submitted records, categorize transactions, extract data from receipts, generate summaries, and answer questions about your business activity.
These systems process your Customer Data as part of the Service. AI-generated outputs are informational only and may contain inaccuracies. You remain responsible for reviewing important financial or operational decisions.
We do not use individually identifiable Customer Data to train third-party AI models without your consent. Aggregated and de-identified data may be used to improve our own systems (see Section 4).
4. Platform analytics and supplier intelligence
ChiefOS may create aggregated, anonymized, or de-identified datasets derived from platform activity. This section explains how that data is generated, protected, and used.
What we collect for analytics purposes. As part of normal operation of the Service, ChiefOS records which products from supplier catalogs you select or quote during job costing and purchasing workflows, the quantities involved, the general region your account is associated with (province/state level), and the timing and frequency of those selections. This activity data is collected regardless of whether you complete a purchase.
How we aggregate and anonymize it. Raw quoting activity is processed through an aggregation pipeline that: (a) strips all tenant-identifying fields (tenant_id, owner_id, user_id, job IDs, business names); (b) groups data by product, region, and time period; and (c) suppresses any data point that does not represent activity from at least five (5) distinct business accounts (k-anonymity threshold). The result is statistical market intelligence — demand counts, trend lines, and regional breakdowns — with no path back to any individual business.
What we share with suppliers. ChiefOS may provide Aggregated Analytics to suppliers participating in our Supplier Portal, including as a paid feature. Suppliers receive only: product-level demand counts, regional demand distributions (province/state level or coarser), seasonal trend data, and category comparison data. Suppliers never receive your business name, tenant ID, specific job details, financial data, employee information, or any data that could identify you.
What we never share. We never sell, rent, or disclose your individual Customer Data — financial records, job details, crew information, Ask Chief conversations, receipts, or documents — to any supplier or third party for commercial purposes.
Your opt-out right. You may opt out of having your quoting activity included in Aggregated Analytics shared with suppliers via our contact form or by writing to privacy@usechiefos.com. We will action your request within 30 days. Opting out does not affect your access to the Service.
These datasets cannot reasonably be used to reconstruct individual customer records and may also be used internally to improve platform reliability, develop new features, conduct research, and refine machine learning systems.
5. How we share information
We do not sell personal information. We share information only when necessary to operate the Service or comply with legal obligations.
Service providers (subprocessors)
- Supabase — authentication, database storage, and file storage.
- Vercel — application hosting and delivery.
- Twilio — messaging infrastructure for WhatsApp ingestion.
- Stripe — subscription billing and payment processing.
- OpenAI / Anthropic — AI model providers used to process submitted records and generate insights.
- SendGrid / Postmark — transactional email delivery.
All service providers are bound by data processing agreements and are permitted to use your information only as needed to provide their services to us.
Legal requirements
We may disclose information if required to do so by law, court order, or lawful request from a government authority, or where we believe disclosure is necessary to protect the rights, property, or safety of ChiefOS, our users, or the public.
Business transfers
If ChiefOS is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
6. Cookies and tracking
Our website and portal use cookies and similar technologies to support authentication, remember your preferences, and understand how users navigate the platform.
Types of cookies we use
- Essential cookies: Required for authentication and core platform functionality. Cannot be disabled.
- Analytics cookies: Help us understand usage patterns to improve the Service. You may decline these.
Most browsers allow you to control cookies through browser settings. Disabling essential cookies may prevent certain features from working.
7. Data retention
- Account and workspace data is retained while your account is active.
- If you close your account, you may request an export of your data within 30 days. After that period, your data will be scheduled for deletion.
- Deleted or purged records may persist in encrypted backups for up to 90 days before being permanently removed.
- We may retain certain information longer where required by law or for legitimate business purposes (e.g., billing records for tax compliance).
- Aggregated or anonymized data derived from your records may be retained indefinitely as it does not identify you.
8. Security
- All data is transmitted using HTTPS/TLS encryption.
- Data at rest is stored using encrypted infrastructure provided by our hosting partners.
- Access controls and least-privilege practices limit who can access your data internally.
- Tenant isolation architecture prevents cross-account data access.
- Security events are logged and monitored for anomalies.
No method of transmission over the internet or electronic storage is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security.
9. Marketing communications and opt-out
We may send you product updates, tips, and relevant offers by email. You can opt out of marketing communications at any time by:
- Clicking "Unsubscribe" in any marketing email we send.
- Writing to privacy@usechiefos.com and requesting to be removed from marketing lists.
Opting out of marketing emails will not affect transactional messages related to your account or subscription (e.g., receipts, security alerts, or support responses).
10. Children's privacy
The Service is intended for use by adults and is not directed at children under 18 years of age. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected such information, please contact us at privacy@usechiefos.comand we will delete it promptly.
11. Your rights
Subject to applicable law, you have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request that inaccurate or incomplete information be corrected.
- Deletion: Request that we delete your personal information, subject to our legal retention obligations.
- Data portability: Request an export of your Customer Data in a machine-readable format.
- Withdrawal of consent: Where processing is based on consent, you may withdraw it at any time. This will not affect processing already carried out.
- Objection: Object to certain types of processing, including direct marketing.
To exercise any of these rights, contact us at privacy@usechiefos.com. We will respond within 30 days. We may need to verify your identity before processing your request.
US Privacy Rights
California Residents (CCPA/CPRA). If you are a California resident, you have the following additional rights: (1) the right to know what personal information we collect, use, disclose, and sell; (2) the right to delete personal information we have collected, subject to certain exceptions; (3) the right to opt out of the sale or sharing of your personal information; (4) the right to correct inaccurate personal information; and (5) the right to limit the use of sensitive personal information. ChiefOS does not sell personal information as defined under CCPA. The Aggregated Analytics described in Section 4 do not constitute a "sale" or "sharing" of personal information because the data is anonymized below the threshold of personal information before it is shared. To exercise any of these rights, contact privacy@usechiefos.com.
Other US State Privacy Rights. Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states with comprehensive privacy laws have similar rights to access, correct, delete, and opt out of certain processing. ChiefOS honors these rights regardless of which US state you reside in. Contact privacy@usechiefos.com to exercise any of these rights.
12. Data breach notification
In the event of a data breach that poses a real risk of significant harm to individuals, we will notify affected users and, where required by law, the relevant privacy commissioner. Notification will be provided without unreasonable delay and will include:
- A description of what happened and what information was involved.
- Steps we have taken or are taking to address the breach.
- Steps you can take to reduce the risk of harm.
- Contact information for further questions.
13. International data transfers
ChiefOS is a Canadian company (Ontario) and your data may be processed in Canada, the United States, and other jurisdictions where our infrastructure providers operate. For users in Canada, transfers to the US are subject to applicable legal orders in that jurisdiction. For users in the US, data processed in Canada is subject to Canadian privacy law (PIPEDA). We apply contractual and technical safeguards — including data processing agreements with all subprocessors — to protect your data regardless of where it is processed.
Where data is transferred internationally, we take reasonable steps to ensure appropriate protections are in place consistent with PIPEDA and, for US users, applicable state privacy laws.
14. Cookies and similar technologies
We use cookies on the public ChiefOS website and inside the portal. Strictly necessary cookies (login session, bot prevention, your consent choice itself) are always on. Analytics, marketing, and preference cookies are optional and require your consent.
For full details on every category, the third parties involved (Supabase, Cloudflare, Plausible, Vercel, Stripe, Postmark), retention periods, and how to change your choices at any time, see our Cookie Policy. You can also re-open the consent banner from the “Cookie preferences” link in the site footer.
15. Changes to this policy
We may update this Privacy Policy as the Service evolves or legal requirements change. We will notify you of material changes by email or by posting a notice in the platform before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
16. Contact us
For privacy questions, access requests, or complaints, contact our privacy team via our contact form or write to:
ChiefOS Privacy
9839429 Canada Inc.
privacy@usechiefos.com
If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.
ChiefOS is a product of 9839429 Canada Inc. This policy is provided for transparency. It is not legal advice.