Privacy Policy
This Privacy Policy explains how 1001474709 Ontario Inc. operating as SMRTscan ("we," "us," or "our") collects, uses, and shares information when you use the SMRTscan mobile application and related services (the "Service").
If you do not agree with this policy, do not use the Service.
1. Information We Collect
1.1 Information You Provide
- Account information: Email address, phone number (optional), and display name.
- Receipt and document data: Images, PDFs, and extracted data including merchant names, dates, totals, line items, categories, tags, notes, job names, and reference numbers.
- Banking data: Bank account labels, CSV bank statement imports, paper bank statement images, transaction history, reconciliation status, and matched receipt links when you use banking features.
- Mileage and location data: Trip details you enter — start/end addresses, saved locations, distances, purposes, odometer readings, and vehicles. If you enable live GPS trip recording (an Ultra-plan feature), SMRTscan uses your device's precise location to record your driving route — including when the app is in the background or your screen is locked — for as long as a trip recording is active. Unless you also enable "Auto-detect Trips" (described below), background location is used only while a trip is actively being recorded, and we do not collect location data in the background at any other time. While a trip is actively recording, iOS displays a blue location indicator in your status bar, so you always know when SMRTscan is recording your route. You can stop a recording at any time, or revoke location permission entirely in your device Settings. Recorded routes, distances, stops, and timestamps are stored on your device and only sent to our servers if you enable cloud backup or share the trip to a workspace. Individual coordinate points (trip start, end, and any stops) are sent to a mapping/routing provider to convert coordinates into human-readable street labels and to optionally road-snap the driving distance (see Section 4). If you additionally opt in to "Auto-detect Trips" (an Ultra-plan feature, off by default, enabled in Settings → Mileage → Auto-detect Trips), SMRTscan uses your device's motion sensors together with low-power background location signals to recognize when you have started driving and, on detection, automatically starts a full trip recording on your behalf. During this passive monitoring phase no route is being recorded and the iOS blue indicator is not continuously shown; the blue indicator appears once a drive is detected and full GPS recording begins. Because auto-detection relies on background location, iOS may periodically remind you that SMRTscan has used your location in the background and show you a map of recent usage — this is standard iOS behaviour. If you choose "Don't Allow" on that reminder, automatic trip detection will stop until you re-enable Always Allow location access in your device Settings. Auto-detection requires Always Allow location permission, can be turned off at any time, and pauses automatically if you change your iOS location permission to anything other than Always Allow. Auto-detected trips appear in a Trip Inbox in the app for you to categorize as Business or Personal, or to delete.
- Motion & fitness data: If you enable "Auto-detect Trips," SMRTscan reads your device's motion & fitness activity (via Apple's Core Motion sensors) to recognize when you are driving versus walking, cycling, or stationary, so it can automatically start and stop trip recordings — and so it doesn't waste battery running GPS when you aren't driving. This motion data is processed entirely on your device; it is never collected, stored on our servers, transmitted to us, or shared with anyone. You can disable it at any time by turning off Auto-detect Trips or by revoking the Motion & Fitness permission in your device Settings.
- Employee and payroll data: Employee names, payroll details, tax forms, pay stubs, remittance records, and sensitive payroll fields such as SIN/SSN and employee bank details when you use payroll features.
- Settings and preferences: Custom categories, tags, saved locations, and export options.
- Support requests: Communications when you contact us for help.
1.2 Beta Program Information
If you sign up for our beta testing program (TestFlight), we collect:
- Email address: To send you TestFlight invitations and beta updates.
- Business information: Business name, industry, and size (optional) to understand our tester demographics and prioritize features.
- Feedback: Bug reports, feature requests, and general feedback you provide during testing.
Beta program data is used solely to manage the testing program and improve the Service. You can request removal from the beta program and deletion of this data at any time by contacting us.
1.3 Information Collected Automatically
- Usage data: Features used, scan counts, and interaction patterns within the app.
- Device data: Device type, operating system version, app version, and unique device identifiers.
- Advertising data: If you use the free tier, Google AdMob may process device information, IP address, ad impressions, and ad interaction data to serve and measure non-personalized ads where configured. We do not use this data to track you across apps and websites for advertising purposes.
- Diagnostic data: Crash reports and error logs to improve app stability.
1.4 Payments and Subscriptions
Payments are processed by Apple App Store or Google Play (or their payment providers). We do not collect or store your payment card details. We receive only subscription status and entitlement data from our subscription management provider (RevenueCat).
1.5 Cloud Backups (Optional)
If you enable cloud backup, receipt images and data may be uploaded to your connected cloud provider (iCloud or Google Drive). You control whether this is enabled, and backups are stored in your personal cloud account—not on our servers.
1.6 AI Processing
When you scan receipts or documents, images and extracted text may be processed through a Supabase Edge Function and sent to AI providers such as Anthropic Claude, OpenAI, or Google Gemini depending on your selected model, fallback mode, and feature used. AI requests are used to extract receipt, document, or bank statement data. Providers process this data to return the requested result.
We send only the data needed to extract your result, and we mask sensitive identifiers (such as full SIN/SSN and complete bank-account numbers) before transmission where technically feasible. Our AI providers process this data solely to return the requested result and, under our agreements with them, do not use your data to train their models. We maintain data-processing agreements with each provider.
1.7 SMRThelp (AI Q&A Assistant)
SMRThelp is an optional in-app assistant that answers questions about your own bookkeeping data. It is inactive until you accept an in-app consent notice, and we record the date of your consent.
When you ask SMRThelp a question, the app sends your question together with compact, app-computed summaries of your financial data (for example, expense totals by category, invoice and bill aging, mileage totals, bank account names, and recent receipt lines) and — unless you remove it — a short description of the screen you are viewing, to Google (Gemini API) via our Supabase Edge Function to generate the answer. All figures are computed by SMRTscan before transmission; the AI provider is used only to phrase and explain them. These summaries never include government identifiers (SIN/SSN), bank credentials, or other fields protected in your device's secure storage.
We do not store your SMRThelp questions or answers on our servers; conversations remain on your device. We record only usage counts (the number of questions asked per month) to enforce plan limits. As with our other AI processing, data submitted through the Gemini API is processed solely to return the requested result and is not used to train the provider's models.
2. How We Use Information
We use collected information to:
- Provide the Service: Scan, extract, store, categorize, and export your receipts and mileage data.
- Operate payroll and banking features: Store employee, payrun, tax form, bank statement, transaction, and reconciliation data when you use those features.
- Process subscriptions: Manage your subscription status and enforce plan limits.
- Sync and backup: Store your data when you enable cloud backup features.
- Improve the Service: Analyze usage patterns to enhance features, fix bugs, and improve reliability.
- Serve ads on the free tier: Display, limit, and measure ads and rewarded ad flows such as bonus scans.
- Provide support: Respond to your inquiries and troubleshoot issues.
- Send notifications: Warranty reminders, return window alerts, and price drop notifications (with your permission).
- Comply with law: Meet legal obligations and respond to lawful requests.
Express consent for sensitive information. Because some information we process is sensitive (for example, SIN/SSN, bank details, and precise location), we rely on your express, opt-in consent for those features. You can decline or disable them, and the rest of the app will continue to work.
Marketing communications (CASL). We send service messages (e.g., warranty and return reminders) as part of the app. We will only send promotional messages, such as price-drop alerts or product news, if you opt in. Every promotional message identifies us, includes our mailing address (148 Marksam Road, Guelph, Ontario N1H 6T6, Canada), and provides a one-tap unsubscribe that we honour promptly.
3. How We Share Information
We do not sell your personal information by default.
3.1 Optional Data Sharing Program
You may choose to participate in our optional Data Sharing Program through the app settings. This is voluntary. If we offer bonus scans or other in-app benefits for participation, the benefit will be disclosed in the app before you opt in.
If you opt in, we may share anonymized and aggregated data with third parties for:
- Market research: Anonymized spending trends and patterns (e.g., "X% of users in Ontario shop at grocery stores on weekends")
- Product improvement: Understanding how receipt formats vary to improve our AI extraction
- Industry analytics: Aggregated insights about retail and consumer behavior
What we DO NOT share even if you opt in:
- Your name, email, phone number, or any personally identifiable information
- Individual receipt images
- Your specific purchase history linked to you
- Your location beyond general region (e.g., province/state level only)
You can opt out at any time through Settings → Privacy → Data Sharing. Opting out will stop future data sharing immediately.
3.2 Other Sharing
We may also share information in these circumstances:
- Service providers: Third parties who process data on our behalf to operate the Service (see Section 4).
- Cloud storage providers: Your chosen backup provider (iCloud or Google Drive) when you enable backups.
- Legal requirements: Law enforcement or government authorities if required by law, court order, or to protect rights, safety, or security.
- Business transfers: If we merge with or are acquired by another company, your information may be transferred as part of that transaction. We will notify you of any such change.
3.3 Team Workspaces — Business Customers
If you use a shared team workspace, the workspace owner (for example, your firm or employer) controls the personal information added to that workspace and is responsible for having the necessary authority and consents to upload it, including any third-party employee information. For workspace data we act as a processor on the owner's behalf under our Data Processing Addendum, and workspace members should review the owner's own privacy practices. Contact privacy@smrtscan.app to request our Data Processing Addendum.
4. Service Providers
We use the following third-party services to operate the Service:
| Provider | Purpose | Data Processed |
|---|---|---|
| Anthropic (Claude API) | AI receipt and document data extraction | Receipt, document, and bank statement images or extracted text needed for the request |
| OpenAI | AI receipt and document data extraction | Receipt, document, and bank statement images or extracted text needed for the request |
| Google Gemini | AI receipt and document data extraction; SMRThelp Q&A answers | Receipt, document, and bank statement images or extracted text needed for the request; for SMRThelp, your question and app-computed financial summaries |
| Google ML Kit | On-device offline OCR | Receipt images (processed locally) |
| Apple Maps / OpenStreetMap (Nominatim) & OSRM | Geocoding and driving-distance calculation for mileage | Start/end addresses or coordinates you enter (or capture via GPS) for a mileage trip |
| Supabase | Authentication, workspace data, OCR Edge Functions, and cloud sync | Account credentials, user profile, workspace records, scan usage, and data sent to Edge Functions |
| RevenueCat | Subscription management | Anonymous user ID, subscription status |
| PostHog | Product analytics (feature usage, sessions, conversion) to improve the app | Pseudonymous user ID, app/screen interaction events, app version, platform, subscription tier. No receipt contents, no precise location, no advertising identifiers. Not used to track you across other companies' apps or websites. |
| Resend | Transactional email delivery (sign-in, confirmation, password reset) | Your email address and the message content |
| Apple iCloud | Cloud backup (optional) | Receipt data and images (your account) |
| Google Drive | Cloud backup (optional) | Receipt data and images (your account) |
| Google AdMob | Advertising and rewarded ads on the free tier | Device information, IP address, ad impressions, and ad interactions for non-personalized ads |
These providers process data as needed to provide their services and are governed by their own privacy policies. We maintain data-processing agreements with our processors, and our AI providers process your data solely to return the requested result and do not use it to train their models.
We maintain a current list of sub-processors (the third parties above). We will update this list and provide reasonable advance notice within the app before engaging a new sub-processor that processes your personal information, so you can review the change before it takes effect.
5. Data Storage and Security
5.1 Local Storage
- All receipt data, images, and personal information are stored locally on your device by default.
- Data is stored using local databases and secure storage mechanisms.
- Employee SIN/SSN and bank details are stored in device secure storage where supported; workspace cloud records use sentinel values rather than the raw local secret values.
- Biometric authentication (Face ID/Touch ID) is available to protect app access.
5.2 Cloud Storage (Optional)
- If you enable cloud backup, your data is transmitted over an encrypted connection (HTTPS) and stored in your personal cloud account (iCloud or Google Drive), where it is protected by that provider's security and access controls.
- We do not have access to your cloud storage credentials or backup data.
5.3 Security Measures
- All network communications use HTTPS/TLS encryption.
- Sensitive data (API keys, credentials) is stored in device secure storage.
- We use reasonable administrative, technical, and organizational measures to protect data.
We maintain a written information-security program with administrative, technical, and physical safeguards appropriate to the sensitivity of the data we handle, including access controls, encryption in transit and at rest, and periodic review. We update it as our business and the threat landscape change.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we take data protection seriously.
5.4 Data Breach Notification
If we become aware of a security incident (confidentiality incident) involving your personal information that creates a real risk of significant harm, we will: (a) notify you without undue delay; (b) report the incident to the Office of the Privacy Commissioner of Canada and, for Quebec residents, the Commission d'accès à l'information; and (c) notify any other regulator or affected party where required by law, including applicable U.S. state breach-notification statutes. We maintain a register of security incidents as required by law and will describe the nature of the incident, the information involved, and the steps you can take to protect yourself.
6. Data Retention
- Active use: We retain data for as long as you keep it in the app.
- Deleted items: Moved to "Recently Deleted" for 30 days, then permanently removed.
- Cloud backups: Remain in your cloud account until you manually delete them.
- Account deletion: All data is permanently deleted within 30 days of an account deletion request, except where we must retain limited records to comply with law.
Retention by data category:
| Data category | Retention | Trigger to delete |
|---|---|---|
| Receipts, mileage, accounting records | While your account is active; tax records are often kept 6–7 years by your own choice | Your deletion / account closure |
| GPS-recorded trip path (precise coordinates captured while a trip is actively recording) | Stored on your device only, unless you turn on cloud backup or share the trip to a workspace; lives with the trip it belongs to | Trip deleted or account closed |
| Payroll & SIN/SSN, employee bank details | Only while the payroll feature is in use; purged promptly after | Feature disabled / employee removed |
| AI request data (images/text sent to providers) | Transient — not retained beyond returning the result | On response |
| Diagnostics / crash logs | Short, fixed window (e.g., 90 days) | Auto-expiry |
| Account & support records | Life of account + limited legal-hold period | 30 days after deletion request |
7. Your Rights and Choices
You can:
- Access your data: View all stored data within the app.
- Export your data: Export receipts to CSV, PDF, or ZIP at any time.
- Update or delete data: Edit or delete individual receipts, trips, or reminders.
- Disable cloud backups: Turn off backups to keep all data local-only.
- Manage location access: Mileage works with manually entered addresses; if you enable GPS-based trip tracking or auto-detection, you can turn either off at any time in Settings (Mileage → Vehicle Settings → Auto-detect Trips), or revoke location permission entirely in your device Settings.
- Manage tracking choices: Use iOS tracking controls and in-app settings where available to control advertising personalization.
- Disable notifications: Manage push notifications in your device settings.
- Delete your account: You can delete your account and all associated data at any time directly in the app (Settings → Account → Delete Account), or by contacting privacy@smrtscan.app. We permanently delete your data within 30 days of the request, except where we must retain limited records to comply with law.
For Canadian Residents (PIPEDA)
You have the right to access, correct, and request deletion of your personal information. Because some of the information we handle is sensitive (such as SIN/SSN, bank details, and precise location), we rely on your express, opt-in consent for those features. Contact us, or use the in-app controls, to exercise these rights.
For Quebec Residents (Law 25)
If you reside in Quebec, in addition to the rights above you may: request access to and correction of your personal information; withdraw consent; request that we cease disseminating your information or de-index it; and receive the computerized personal information you have provided in a structured, commonly used technological format (data portability) — available today via Settings → Export. We conduct privacy impact assessments before transferring personal information outside Quebec and apply appropriate safeguards. You may contact our Privacy Officer at privacy@smrtscan.app, and you may lodge a complaint with the Commission d'accès à l'information du Québec.
For California Residents (CCPA/CPRA)
We collect categories of sensitive personal information under the CPRA, including government identifiers (SIN/SSN), financial account information, and precise geolocation, solely to provide the features you enable (payroll, banking, mileage). We do not use or disclose this sensitive information for purposes other than providing the Service, and we do not sell or share it for cross-context behavioral advertising. You have the right to limit the use of your sensitive personal information, to know, delete, and correct your personal information, to opt out of sale/sharing, and to be free from discrimination for exercising these rights. To exercise any right, contact privacy@smrtscan.app or use the in-app controls; an authorized agent may submit a request on your behalf with proof of authorization. We respond within 45 days (extendable once).
For Other U.S. State Residents
Depending on your state of residence (including Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and others), you may have rights to access, correct, delete, and obtain a portable copy of your personal data, to opt out of targeted advertising, sale, or certain profiling, and to appeal a denied request. To exercise these rights, contact privacy@smrtscan.app. Where required, we honor opt-out preference signals such as Global Privacy Control (GPC) on our website.
For European Residents (GDPR)
You have additional rights including:
- Right to access, rectification, and erasure.
- Right to restrict or object to processing.
- Right to data portability.
- Right to withdraw consent.
- Right to lodge a complaint with a supervisory authority.
8. Children's Privacy
The Service is not directed to children under 13 (or the applicable age of digital consent in your jurisdiction, which is 14 in Quebec). We do not knowingly collect personal information from children. Because the Service includes payroll, tax, and banking tools that form a binding contract, account holders should be at least 18 (or the age of majority in their jurisdiction); see the Terms of Service. If you believe we have collected information from a child, please contact us immediately and we will delete it.
9. International Data Transfers
If you use the Service outside Canada, your data may be processed in other jurisdictions where our service providers operate (including the United States). By using the Service, you consent to such transfers. For transfers of personal information outside Quebec or Canada, we carry out the assessments required by applicable law (including a privacy impact assessment under Quebec Law 25) and put appropriate contractual and technical safeguards in place.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top.
- Provide notice within the app.
- For significant changes, request your acknowledgment.
Your continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.
Accessibility
We are committed to making SMRTscan usable by everyone, consistent with the Accessibility for Ontarians with Disabilities Act (AODA) and recognized standards such as WCAG. If you encounter an accessibility barrier, or need this policy in an alternative format, contact us at privacy@smrtscan.app and we will work with you to provide the information or assistance you need.
11. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or need to report a concern, contact us at:
1001474709 Ontario Inc. operating as SMRTscan
The person responsible for the protection of personal information (Privacy Officer) is Jordi Von Fielitz, Director, reachable at privacy@smrtscan.app.
Email: privacy@smrtscan.app
Address: 148 Marksam Road, Guelph, Ontario N1H 6T6, Canada
Summary
| What We Collect | How We Use It | Your Control |
|---|---|---|
| Account info | Provide service | Update or delete |
| Receipt scans & data | Process and organize | Delete anytime |
| Mileage trips | Track business travel | Full control |
| Bank statements and transactions | Import and reconcile | Delete anytime |
| Employee and payroll records | Run payroll and create tax forms | Delete or update |
| Ad measurement data | Serve and measure non-personalized ads | Free tier only |
| Usage data | Improve the app | N/A (anonymized) |
| Device info | Troubleshooting | N/A (automatic) |
Personal-account data stays on your device unless you choose cloud backup or use a cloud/AI feature. Workspace data is cloud-canonical so invited workspace members can collaborate. We only share anonymized or aggregated data if you explicitly opt in.