Last updated 2026-06-24
This policy applies to ShopLog.ca (the “Service”), (the “we” / “us”). It explains what personal information we collect, how we use it, and your rights under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and equivalent provincial laws.
From you (the user): your name, email address, role, plant assignment, and (when applicable) initials or display name. We use these to authenticate you and to attribute actions in the audit log.
From your employer (the customer): production data entered through the Service — work order numbers, customer names, product names, scrap counts, downtime reasons, operator-on-duty attribution. This data belongs to the customer organization, not to ShopLog.
Automatically: sign-in events (timestamp, IP address), basic usage analytics via Google Analytics (anonymized page views, route changes), and standard server logs.
We do not sell, rent, or share your personal information or your employer’s production data with third parties for marketing purposes. Ever.
The customer organization (your employer) owns the production data entered into ShopLog. We are a processor, not a controller, of that data. The customer can export, correct, or delete their data at any time through the Service or by emailing us. When a customer cancels their account, we retain a backup for 30 days for recovery purposes, then delete it permanently.
ShopLog runs on trusted cloud infrastructure:
Both Render and Vercel are SOC 2 Type II certified. Data in transit is encrypted with TLS; data at rest is encrypted at the storage layer. Because our infrastructure is in the United States, your data may be subject to U.S. law including lawful access requests — we will resist any request that exceeds what the law strictly requires.
Active accounts: as long as the account exists. Cancelled accounts: 30 days of backup retention, then permanent deletion. Audit logs: retained for the life of the account, then deleted with the rest of the data on cancellation. Sign-in/usage logs: 90 days rolling.
You have the right to:
To exercise any of these rights, email hello@codekraftbysilva.com. We respond within 30 days.
If we discover a breach of personal information that creates a real risk of significant harm, we will notify affected users and the Office of the Privacy Commissioner of Canada within 72 hours of discovery, in line with PIPEDA’s mandatory breach notification rules.
We use a single first-party cookie to keep you signed in (a JWT stored in browser localStorage, technically not a cookie but equivalent in function). Google Analytics sets analytics cookies for anonymized usage statistics — only after you accept the consent banner on first visit. We don’t use advertising cookies, retargeting pixels, or third-party trackers.
Changed your mind, or want to opt out of analytics?
When we update this policy, we’ll bump the “Last updated” date at the top. Material changes (anything that meaningfully reduces your rights or expands what we collect) will be announced via email to account owners at least 30 days before taking effect.
Questions, requests, or complaints: hello@codekraftbysilva.com
CodeKraft by Silva · Edmonton, Alberta, Canada