For anyone visiting this website
Website Privacy Policy
Last updated August 8, 2026
This policy explains, in detail, what happens to information about you when you browse the Marketing Powered by Sharpnd website, request an invite, or contact us. Separate policies cover stores that subscribe to the platform and shoppers who opt into a store's marketing list.
1. Who we are and how to reach us
Marketing Powered by Sharpnd (the "Service", "we", "us", "our") is operated by Sharpnd, a sole proprietorship owned by Vule Basovic and operating from Ontario, Canada. We are the controller of the personal information described in this policy — that is, we decide why and how it is used.
- Business name and operator: Sharpnd, sole proprietorship of Vule Basovic
- Privacy contact: contact@sharpnd.ca
- Subject line that gets fastest routing: "Privacy request — website"
- Scope of this document: the public marketing website and the sign-in screens. It does not cover data held inside a store's account, which is addressed in the Store Privacy Policy and the Customer Privacy Policy.
2. Definitions used in this policy
- Personal information — information about an identifiable individual, including online identifiers such as an IP address when it can be linked to a person.
- Processing — any operation performed on personal information: collection, storage, use, disclosure, retention or deletion.
- Sub-processor — a third-party provider we rely on to run the Service, which may handle personal information on our instructions.
- Visitor — you, when you browse the website without signing into a store account.
3. Information we collect from visitors
Collected automatically
- IP address and approximate region derived from it.
- Browser type and version, operating system, device type, screen size and language.
- Requested URL, referring URL, timestamp, response status and response time.
- Error and crash diagnostics generated when a page fails to load correctly.
Provided by you
- Your email address and message content if you email us or request an invite.
- Any business details you volunteer while discussing access, such as store name and location.
What we deliberately do not collect
- We do not require an account to read the public pages.
- We do not run third-party advertising pixels or cross-site tracking networks on this website.
- We do not collect payment card numbers on this website; billing is handled by our payment processor when a store subscribes.
- We do not knowingly collect information from children.
4. Canadian privacy law that applies to us
Sharpnd operates from Ontario and serves Canadian retailers. Ontario has no general private-sector privacy statute, so the federal Personal Information Protection and Electronic Documents Act (PIPEDA) governs our commercial handling of personal information here, together with its ten fair information principles in Schedule 1.
- PIPEDA — accountability, identifying purposes, consent, limiting collection, use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. Breaches of security safeguards posing a real risk of significant harm are reportable to the Privacy Commissioner of Canada and to affected individuals, and we keep a record of every breach for 24 months as PIPEDA requires.
- Quebec (Law 25), Alberta PIPA and British Columbia PIPA may apply instead of PIPEDA to residents of those provinces; we apply the higher standard where they differ.
- CASL governs any commercial electronic message we send, and also governs the store campaigns run on the platform. See the Marketing & Consent Policy.
- Competition Act — public claims we make about the Service must be truthful and not misleading in a material respect.
- Ontario — the Consumer Protection Act, 2002, the Electronic Commerce Act, 2000 and the Limitations Act, 2002 apply to our dealings with Ontario users where relevant.
- We do not knowingly collect personal health information, so Ontario's PHIPA does not apply; do not submit health information to the Service.
5. Why we use it, and the consent that supports it
Under PIPEDA we must identify the purpose of a collection at or before the time it happens, and limit use to those purposes. Ours are:
- To deliver the website — serving the pages and assets you request. Supported by your implied consent in requesting the page, and reasonably necessary to provide what you asked for.
- To secure the Service — rate limiting, abuse detection, fraud prevention and blocking automated attacks. Collected without consent where PIPEDA permits it for investigating a breach of an agreement or a contravention of law, and otherwise on implied consent.
- To troubleshoot — diagnosing errors from log and crash data. Implied consent; reasonably necessary to keep the Service working.
- To improve the product — aggregate, non-identifying page and feature usage. Where information is de-identified so it can no longer be linked to you, it falls outside the definition of personal information.
- To respond to you — replying to invite requests and support email. Express consent, given by contacting us.
- To meet legal obligations — responding to lawful requests and keeping records we are required to keep. Permitted, and in some cases required, without consent.
We do not use your information for any new purpose without telling you and, where the law requires it, obtaining fresh consent. Consent is never a condition of receiving something unless the information is genuinely required to provide it.
7. Third-party sign-in providers
Sign-in is provided through Google and Apple. When you choose one of them, you are redirected to that provider, you authenticate there, and the provider returns a verified identifier and email address to us. We never see or receive your password.
- Your interaction with the provider is governed by that provider's own privacy policy.
- We request the minimum profile scope needed: a stable user identifier, verified email address, and where available a display name.
- We do not request access to your contacts, calendar, files, or mailbox contents.
8. Service providers and sub-processors
We rely on a small number of providers to run the Service. Each is bound by contract to process data only on our instructions and to maintain appropriate safeguards.
- Application and edge hosting — serves the website and runs server-side logic; handles request logs.
- Managed database and authentication platform — stores account, store, campaign, subscriber and consent records; verifies sign-in tokens.
- Identity providers — Google and Apple, for sign-in only.
- Payment processor — handles subscription billing for stores; card details go to the processor, never to us.
- Email delivery — used for transactional messages such as invites and account notices.
We will update this list when it changes materially. Ask us at contact@sharpnd.ca for the current named list if you need it for a vendor review.
9. Disclosure of personal information
We disclose personal information only in these circumstances:
- To the service providers listed above, strictly to operate the Service.
- Where required by law, court order, subpoena, or a valid request from a regulator or law-enforcement body with jurisdiction.
- To establish, exercise or defend legal claims, or to protect the rights, safety and property of Sharpnd, our users or the public.
- In connection with a merger, acquisition, financing or sale of assets, where the recipient is bound to honour this policy for the information transferred.
- With your direction or consent.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
10. Transfers for processing and where data is stored
The Service is operated from Ontario for Canadian retailers. Our hosting and database providers may store or process data on servers located outside your province or country, including in the United States. PIPEDA treats a transfer to a service provider as a use, not a disclosure, but it makes us accountable for the information the whole time: we remain responsible for it, we use contractual measures to require a comparable level of protection, and we require encryption in transit and at rest.
While information is in another jurisdiction it may be accessible to the courts, law enforcement and national security authorities of that jurisdiction under that country's laws. Write to contact@sharpnd.ca to ask where your information is stored or which providers are involved. If you are a Quebec resident, Law 25 privacy impact assessment obligations for outside-Quebec transfers are handled by the store that collected your information, with our support.
11. Retention periods
- Web and security logs: retained for a short operational window — generally no more than 90 days — then deleted or aggregated, unless kept longer for an active security investigation.
- Error diagnostics: retained while the underlying defect is open, then discarded.
- Correspondence and invite requests: retained while the conversation is relevant and for a reasonable period afterwards so we can answer follow-up questions, then deleted on request.
- Aggregated statistics: may be kept indefinitely because they no longer identify anyone.
12. How we protect information
- Encryption in transit using HTTPS across the entire site, and encryption at rest at the database layer.
- Row-level access rules in the database so records are readable only by the accounts entitled to them.
- Sensitive operations run on the server, not in your browser, so they cannot be bypassed by editing client-side code.
- Least-privilege access for administrators, with privileged keys held only in server environments.
- Regular automated security scanning of the application and its dependencies.
- Escaping and validation of user-supplied text before it is rendered or exported.
13. Your rights under PIPEDA and how to complain
Under PIPEDA — and provincial equivalents where they apply — you may ask us to:
- Confirm whether we hold personal information about you, tell you how it has been used, and give you access to it.
- Tell you to whom it has been disclosed, to the extent we are able.
- Correct information that is inaccurate or incomplete, and pass the correction to anyone who received the original.
- Delete information we no longer need to keep.
- Provide a copy of the information in a usable form.
- Withdraw consent, subject to legal or contractual restrictions and reasonable notice — we will tell you what withdrawal means for the service you receive.
- Challenge our compliance with this policy.
Email contact@sharpnd.ca; requests can be made in English or French. We will verify your identity proportionately to the sensitivity of the request and respond within 30 days, as PIPEDA requires, or tell you in writing why we need an extension of up to a further 30 days. Access is provided at little or no cost, and we will tell you the cost before proceeding if any applies. We may refuse access in the limited circumstances PIPEDA allows — for example where disclosure would reveal another person's information or is subject to solicitor-client privilege — and we will explain the reason and your right to complain.
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (30 Victoria Street, Gatineau QC K1A 1H3; 1-800-282-1376; priv.gc.ca), or to your provincial regulator — the Commission d'accès à l'information du Québec, or the Information and Privacy Commissioner of Alberta or of British Columbia. Ontario's Information and Privacy Commissioner oversees public bodies and health information rather than commercial businesses like ours, so PIPEDA and the federal Commissioner are the route for complaints about this Service.
14. Automated decision-making
We do not make decisions about you that produce legal or similarly significant effects using solely automated processing. Automated systems are used only for security filtering (for example, rate limiting abusive traffic), and a human reviews any dispute about being blocked.
15. Security incidents
If a breach of security safeguards involving your personal information creates a real risk of significant harm, we will notify affected individuals and the applicable regulator without unreasonable delay, describe what happened, what information was involved, what we have done, and what you can do. We maintain internal records of breaches as required by law.
16. Do Not Track and global privacy signals
Because we do not operate behavioural advertising or cross-site tracking on this website, there is nothing for a Do Not Track or Global Privacy Control signal to switch off. We still honour any opt-out request you send us directly.
17. Children
The Service is intended for businesses and adult shoppers. We do not knowingly collect personal information from children under 13, or under the age of digital consent where that age is higher. If you believe a child has provided information to us, email contact@sharpnd.ca and we will delete it.
18. Links to other sites
Our pages may link to store websites, provider documentation or other third-party resources. We do not control those destinations and are not responsible for their privacy practices. Review their policies before providing information to them.
19. Changes to this policy
We may update this policy as the Service evolves. The "Last updated" date at the top always reflects the current version. If a change materially reduces your rights or expands how we use personal information, we will provide prominent notice — in the product, by email to account holders, or both — before it takes effect. Continuing to use the Service after the effective date means you accept the updated policy.