Draft — to be reviewed by counsel before general commercial launch. Policy is written under Canada's PIPEDA and CASL. 草稿版 — 正式營運前將由律師審閱,依加拿大 PIPEDA 與 CASL 制定。
1. Scope
This Privacy Policy applies to OwnCrew and all products offered under the owncrew.ai domain and related services, including but not limited to:
OwnCrew Time Clock — Android application, package ai.owncrew.timeclock, distributed via Google Play and directly
The Time Clock app is a workplace attendance tool installed by a business owner on a shared kiosk device. Data is collected only at the moment an employee punches in or out:
Precise location (GPS)— recorded only at punch time to verify the employee is within the store's geofence. Not collected in the background.
Camera photo — captured only at punch time as attendance attestation. Stored privately; only the store owner sees it via the admin panel.
Device identifier— an app-generated identifier binding a specific tablet to a store as a "kiosk". Used to enforce revocation of unauthorized devices.
Employee display name — entered by the store owner into the admin panel; displayed on the kiosk so staff can select themselves at punch time.
Facial features (biometric data)— a 512-dimensional numeric vector ("face embedding") is computed from the punch photo inside the kiosk browser and transmitted to OwnCrew servers, where it is stored alongside the punch record. On subsequent punches, new embeddings are compared against the same employee's own recent history (past 30 days) to detect potential buddy-punching. This is sensitive personal information under PIPEDA and equivalent laws. This feature is opt-in per employee: on the employee's first use, a written "Photo & Facial Recognition Consent Form" is shown on the kiosk screen (gated by the photo_consent_at record) and must be accepted before any punch can proceed on this device. No embedding is stored or compared until acceptance is recorded. Employees who choose not to accept cannot punch via the OwnCrew Time kiosk and should arrange an alternate time-tracking method with the store operator. To withdraw consent after acceptance and request deletion of stored embeddings, contact privacy@owncrew.ai — see §7.
3b. OwnCrew Salon (booking & appointment management)
Depending on your role, we collect:
Store owner account: email, name, store name, store URL slug, opening hours, services, staff information.
Customer data uploaded by the store: name, email, phone, appointment history, chat / message content, CASL marketing consent flag. This data belongs to each individual store.
Payment data: processed by Stripe; we do not directly store full credit card numbers.
System logs: login times, action history (activity_log), IP address (only briefly for CASL-consent proof), user agent, email delivery events (bounce, open, unsubscribe).
For a store's own account data (owner email etc.), OwnCrew is the data controller. For customer data uploaded into the store, the store is the controller and OwnCrew acts only as a data processor under the store's instructions.
3c. Other OwnCrew Services
Web-based services may collect account email, phone number (for CASL-compliant notifications), and aggregated usage analytics to improve product quality. Individual product pages disclose additional detail.
4. How Data Is Stored and Secured
All data transmitted over HTTPS (TLS 1.2+).
Stored on Supabase (Postgres + Storage) with encryption at rest.
Photos stored in private buckets, accessed via short-lived signed URLs; not publicly indexable.
OwnCrew Salon uses row-level security (RLS) so each store only sees its own data; sensitive columns are encrypted at rest.
Kiosk device sessions authenticated via server-signed JWT cookie (30-day maximum lifetime, revocable at any time by the store owner).
Passwords and API secrets never transmitted to the client or logged in plaintext.
Access rights and dependency vulnerabilities reviewed on a regular cadence.
5. Data Sharing
We do notsell or rent personal data. We do not share data with third parties for advertising, and we do not use one store's customer data for cross-store marketing.
We use the following service providers strictly to operate the platform (data processors):
Google Cloud — Google Play distribution for OwnCrew Time Clock
Sentry — error and performance diagnostics for our web properties (not enabled inside the OwnCrew Time mobile app)
Anthropic(Claude AI) — AI inference for the OwnCrew Salon AI chat replies and for Florist AI product features. Prompts you submit are sent to Anthropic for inference; under Anthropic's commercial terms your data is not used to train models and is not retained beyond the request lifecycle except as required for abuse review under their published policy.
Stripe — subscription and payment processing; we do not receive full credit card numbers
These vendors have their own privacy policies and process data under their respective contracts. We prefer Canadian / US regions and vendors that hold SOC 2 or ISO 27001 attestations. We may disclose data if required by valid legal process or to protect the rights and safety of users.
6. Retention
OwnCrew Salon — store & customer records: retained until the store owner voluntarily deletes the account. After deactivation, records are automatically removed within 90 days unless preservation is requested.
Salon activity log: up to 12 months, then aggregated to statistics and the detail rows are deleted.
Email delivery events: 6 months.
Encrypted backups: 30 days.
OwnCrew Time Clock — punch records: retention period is set by the store owner (data controller); records are deleted within 30 days of account deletion or a written employee request, subject to legal retention obligations (e.g. payroll audit).
Time Clock — kiosk device sessions: expire after 30 days of inactivity and can be revoked at any time from the store admin panel.
Biometric face embeddings: deleted within 7 days of a written request from the employee, independent of any other punch-record retention.
Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable law, you may:
Access the personal data we hold about you
Correct inaccurate or outdated data
Delete your personal data (subject to legal/contractual retention obligations; biometric face embeddings are deleted within 7 days of request, independent of any other punch-record retention)
Obtain a copy (data portability)
Withdraw consent for future processing (including biometric processing consent; withdrawal takes effect on the next punch and does not affect punches already recorded)
Use the unsubscribe link at the bottom of every marketing email
Transactional email (appointment confirmations, reminders, reschedule and cancellation notices) is necessary for the service and falls under CASL implied consent; separate opt-in is not required.
Marketing email (rebooking reminders, store newsletters) is only sent when the customer explicitly checks the consent box on the booking page. Every marketing email carries an unsubscribe link and the recipient may withdraw consent at any time.
9. Security Measures
Transport encryption: TLS 1.2+ for all in-transit data.
Encryption at rest for database and storage.
Row-level security (RLS) tenant isolation in OwnCrew Salon.
Regular dependency vulnerability audits and access-permission reviews.
10. Data Breach Notification
If a personal data breach occurs and creates a real risk of significant harm, we will notify affected stores and customers within 72 hours of discovery and file with Canadian authorities as required by law.
11. Children
OwnCrew products are business tools not directed at users under 18. We do not knowingly collect personal information from children. If we become aware such data has been collected, it will be deleted.
12. Advertising and Tracking
OwnCrew Time Clock contains no advertising, no ad SDKs, no cross-site tracking pixels, and no third-party analytics inside the app. OwnCrew Salon similarly contains no advertising and no cross-site advertising trackers. The marketing website may use privacy-respecting analytics (aggregate only, no personal identifiers).
13. Cookies
Our web properties use functional cookies only — for authentication and session management. No advertising cookies.
14. International Data Transfers
Data may be processed in the United States by our service providers (Vercel, Supabase, and others listed in §5). By using OwnCrew you consent to such transfer, subject to safeguards required by applicable law.
15. Changes to This Policy
Material changes will be notified via email to registered users at least 14 days in advance, and shown as a banner in the dashboard. The effective date at the top of this page reflects the latest revision. Prior versions are available on request to privacy@owncrew.ai.
16. Contact
Privacy inquiries: privacy@owncrew.ai (primary) — General product enquiries: hello@owncrew.ai OwnCrew · Chiao-wan Huang · British Columbia, Canada