Back to Inventro

Privacy Policy

Last Updated: August 14, 2026

This Privacy Policy explains how Inventro Inc. (“Inventro”, “we”, “us”) collects, uses, and protects personal information related to Tenants, Tenant staff, and website visitors. It applies under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Canadian provincial privacy legislation, and, where we offer the Services to people in the European Economic Area, under the General Data Protection Regulation (GDPR). Where the two differ, we apply whichever gives you the stronger protection.

1. Accountability

Inventro is responsible for the personal information under its control. Our Privacy Officer can be reached at sales@inventro.io. We are committed to the ten fair information principles set out in PIPEDA.

2. Information Collected

We collect the following categories of personal information:

  • Account information: Name, email address, business name, and phone number provided during registration
  • Authentication data: Hashed passwords and OAuth tokens (e.g., Google sign-in)
  • Usage data: Feature usage patterns, session duration, and actions taken within the platform
  • Technical data: IP address, browser type, device type, operating system, and referring URL
  • Billing information: Plan selection and billing cycle (payment processing is handled by third-party providers)

3. Purpose of Collection and Use

Personal information is collected and used for the following identified purposes:

  • Providing, operating, and maintaining the Services
  • Authenticating users and securing accounts
  • Processing transactions and sending transactional emails
  • Improving platform performance and user experience
  • Communicating service updates, security alerts, and support messages
  • Complying with legal obligations and enforcing our Terms

We will not use personal information for purposes beyond those identified without obtaining further consent.

4. Legal Bases and Consent

Where the General Data Protection Regulation (GDPR) applies, we rely on the following legal bases for each purpose. Consent is only one of them, and it covers analytics and marketing rather than the operation of the Services themselves:

PurposeLegal basis
Providing, operating, and maintaining the ServicesPerformance of a contract, Art. 6(1)(b)
Authenticating users and securing accountsPerformance of a contract, Art. 6(1)(b), and our legitimate interest in keeping the Services secure, Art. 6(1)(f)
Transactional email, such as booking confirmations, quotes, invoices, and contractsPerformance of a contract, Art. 6(1)(b)
Billing, payment processing, and subscription managementPerformance of a contract, Art. 6(1)(b), and compliance with tax and accounting obligations, Art. 6(1)(c)
Error monitoring and diagnostics, and organization-level server telemetryOur legitimate interest in keeping the Services working, reliable, and secure, Art. 6(1)(f)
Service messages, such as maintenance notices and policy changesPerformance of a contract, Art. 6(1)(b), and our legitimate interest in keeping you informed about the Services you use, Art. 6(1)(f)
Website measurement, product analytics, and session recordingsYour consent, Art. 6(1)(a), given separately per purpose and withdrawable at any time
Marketing messagesYour consent, Art. 6(1)(a)
Retention of financial records and responding to legal requestsCompliance with a legal obligation, Art. 6(1)(c)

Where we rely on legitimate interests, we have considered the impact on you and concluded that the processing is limited to what is necessary and does not override your rights. You may object to that processing at any time — see Section 10.

Where we rely on consent, you may withdraw it at any time and withdrawal is as easy as giving it. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew, and it does not stop the processing we carry out on the other bases above, which is necessary to provide the Services to you.

Where the GDPR does not apply, you consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy, and you may withdraw that consent at any time by contacting us, subject to legal or contractual restrictions. We will inform you of the implications of withdrawal.

5. Cookies and Tracking Technologies

Inventro uses the following technologies on its website and platform:

  • Essential cookies: Required for authentication, session management, and security. These cannot be disabled.
  • Local storage: Used to store user preferences (for example, theme and analytics-consent choices). If you accept analytics, it also stores a random journey identifier and recognized campaign attribution tokens.
  • Consent-controlled analytics: You choose these three purposes separately, and none of the tools load until you allow that specific purpose. Website measurement uses Google Analytics 4 for acquisition and website conversions. Product analytics uses PostHog for product funnels and feature usage. Session recordings uses Microsoft Clarity for masked session recordings, heatmaps, and interaction diagnostics. Google and Microsoft process this data in the United States.
  • Functional scheduling: The Demo page can load a Calendly scheduling frame after you explicitly request it. Calendly processes the information you submit directly in that frame under its own privacy practices.

We do not use these tools for advertising, retargeting, or advertising personalization. Browser analytics events exclude names, email addresses, phone numbers, customer records, free-form text, record identifiers, and full URLs. Clarity Identify is disabled, and sensitive application and customer-document surfaces are masked.

You can decline every purpose without losing access to the Services, and withdrawing is as easy as allowing: reopen Privacy choices from the website footer, or from Profile when you are signed in. Withdrawal clears the browser storage for the purposes you turned off and stops further collection for them on that device. We record which purposes you chose and when, so your decision can be evidenced.

Separately, Inventro records limited organization-level operational events on its servers, such as a product being created, a storefront being published, or a subscription changing state. This server-side telemetry contains internal identifiers, enums, counts, booleans, and monetary amounts—not customer content—and supports service operation, reliability, activation, and product improvement. It is not controlled by the browser cookie preference.

6. Third-Party Processors (Subprocessors)

Inventro uses the following vetted subprocessors to deliver the Services:

  • Amazon Web Services (AWS) — Cloud hosting, database, data storage (S3), and content delivery. Data is processed in the United States (us-east-1), with backups replicated to us-west-2.
  • Resend — Transactional email delivery. Sends booking confirmations, quotes, invoices, and contracts, including PDF attachments, and receives the recipient address and delivery status for each message. Processed in the United States.
  • Stripe — Payment processing, payouts via Stripe Connect, and subscription billing. Processed in the United States.
  • Google LLC — When you connect your Google Calendar, Inventro communicates with the Google Calendar API to create and manage events on the calendar you select. See Section 7 below for details.
  • Google Analytics — Consent-controlled website acquisition, page, and conversion measurement.
  • PostHog — Consent-controlled browser product analytics and organization-level server operational telemetry.
  • Microsoft Clarity — Consent-controlled, masked session recordings, heatmaps, and interaction diagnostics.
  • Sentry — Error monitoring and diagnostics, processed in the United States. Receives crash reports carrying internal user and organization identifiers, and, when an error occurs, a masked replay of the moments leading up to it. Text is masked and media blocked in those replays. This runs on our legitimate interest in keeping the Services working and secure, not on your analytics choices, and is never used for advertising or profiling.
  • Calendly — Demo scheduling when you choose to load and use its scheduling frame.

Personal information is never sold to third parties. Subprocessors are contractually bound to process data only as instructed by Inventro and to maintain appropriate security measures. This list will be updated as subprocessors change.

7. Google User Data and Third-Party Integrations

When you connect a Google account to Inventro (for example, to sync bookings to your Google Calendar), Inventro accesses and processes a limited set of Google user data on your behalf. Inventro’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7.1 Scopes Requested

When you connect Google Calendar, Inventro requests the following OAuth scopes:

  • openid and email — to identify the Google account being connected and confirm it belongs to you.
  • https://www.googleapis.com/auth/calendar— to create a dedicated “Inventro” calendar in your account (if you choose the dedicated-calendar option) and to read calendar metadata needed to write events.
  • https://www.googleapis.com/auth/calendar.events — to create, update, and delete the booking-related events (deliveries and pickups) that Inventro manages on the calendar you select.

7.2 How We Use Google User Data

Google user data obtained through these scopes is used solely to provide the Google Calendar integration feature you have requested. Specifically, Inventro:

  • Creates a dedicated calendar in your Google account (if you chose the dedicated option) named according to your input;
  • Writes events to the calendar you selected — each event describes a booking delivery or pickup (customer name, booking reference, address, time, items) generated from data already in your Inventro account;
  • Updates or deletes events Inventro previously created when the underlying booking changes or is cancelled;
  • Stores the encrypted OAuth refresh token, the connected Google account email, the selected target calendar ID, and a mapping between Inventro bookings and the corresponding Google event IDs so updates can be applied.

Inventro does not read, store, or process events on your calendar that it did not itself create, and does not access any other Google services or data.

7.3 Limited Use

In accordance with Google’s Limited Use policy, Inventro:

  • Uses Google user data only to provide and improve the Google Calendar integration feature you explicitly enabled;
  • Does not sell Google user data, and does not transfer it to third parties except as needed to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with appropriate notice;
  • Does not use Google user data to serve advertisements, including retargeting or personalized ads;
  • Does not use Google user data to train, develop, or improve generalized AI or machine-learning models;
  • Does not allow humans to read Google user data unless we have your explicit consent for specific messages, it is necessary for security purposes (such as investigating abuse), it is required to comply with applicable law, or the data has been aggregated and anonymized in a way that cannot reasonably be linked back to an individual user or Google account.

7.4 Storage, Retention, and Disconnection

OAuth refresh tokens are encrypted at rest. You may revoke Inventro’s access at any time by disconnecting Google Calendar from Organization → Integrations → Google Calendar inside Inventro, or by revoking access directly at myaccount.google.com/permissions. When you disconnect, Inventro stops accessing your Google account and deletes the stored OAuth tokens. Events that Inventro previously wrote to your Google Calendar remain in your calendar; you may delete them from Google directly. If you permanently close your Inventro account, all stored Google integration data (tokens, calendar IDs, event-mapping records) is deleted in accordance with Section 8 (Retention and Disposal).

8. Security Safeguards

We implement administrative, technical, and organizational safeguards proportionate to the sensitivity of the information, including:

  • Encryption in transit (TLS) and at rest (AES-256)
  • Hashed and salted password storage
  • Tenant-level data isolation
  • Role-based access controls
  • Regular security reviews and monitoring

9. Retention and Disposal

Personal data is retained for the duration of your active account. Upon account termination:

  • Account and booking data is retained for up to thirty (30) days to allow recovery, then permanently deleted
  • Financial records may be retained for up to seven (7) years as required by Canadian tax law
  • Signature audit trails, including the signer’s name, IP address, and browser user agent, are retained for ten (10) years as evidence that a contract was executed. This record is kept for the establishment and defence of legal claims and therefore survives a request for erasure
  • Security and audit logs may be retained for up to one (1) year

See Section 7.4 above for Google integration data handling on disconnection.

10. Your Rights

You have the right to:

  • Access your personal information held by Inventro
  • Correct inaccurate or incomplete information
  • Withdraw consent to the collection, use, or disclosure of your information, where we rely on consent
  • Request deletion of your personal information, subject to legal retention requirements
  • Export your data in a machine-readable format
  • Restrict processing while a dispute about accuracy or our legal basis is resolved, so that we store your information without otherwise using it
  • Object to processing that we carry out on the basis of legitimate interests, including any processing for direct marketing, which we will stop on request

To exercise any of these rights, contact us using the details in Section 13. We may need to confirm your identity before acting on a request, and we will not charge a fee unless a request is manifestly unfounded or excessive.

We respond within one month. Where a request is complex, or where you have made several requests, we may extend this by up to two further months and will tell you within the first month if we do, along with the reason.

If you are unhappy with our response, you may complain to a supervisory authority. In the European Economic Area you may complain to the authority in the country where you live, where you work, or where the issue arose. In Canada you may complain to the Office of the Privacy Commissioner of Canada.

11. International Transfers

Your personal information is processed in the United States by the subprocessors listed in Section 6, with production systems hosted in AWS us-east-1 and backups replicated to us-west-2. Appropriate contractual safeguards are in place to ensure your information receives a comparable level of protection.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-platform notification at least thirty (30) days before taking effect.

13. Contact

For privacy inquiries, access requests, or complaints:

Inventro Inc.
Privacy Officer
Ontario, Canada
Email: sales@inventro.io

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada.

© 2026 Inventro Inc. All rights reserved.