TransIQ
Pricing EN FR Log in Start free trial
Not yet configured. The operating entity has not been set. Until OPERATOR_LEGAL_NAME and OPERATOR_ADDRESS are configured, these documents name no party and are not enforceable. Set them before taking a paying customer.
Terms of Service Privacy Policy Acceptable Use

Privacy Policy

Version 2026-08-02 · Effective 2026-08-02

This Policy explains how [OPERATOR LEGAL NAME — SET THIS] (TransIQ, we) handles personal information. It is written to comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy law.

1. Two different roles — and why it matters to you

TransIQ handles personal information in two distinct capacities, and your rights depend on which applies:

Whose information Our role Who is accountable
Our business customers and their staff who hold TransIQ accounts — account, billing and support records We decide the purposes. We are the organization under PIPEDA. TransIQ — contact us directly.
A venue's guests and employees — bookings, orders, loyalty, allergy notes, shifts, timesheets, wages We process it on the venue's instructions, to provide the Service. We do not decide what it is collected for. The venue (the restaurant or café). Direct requests to them; we support them in answering.

If you are a guest or an employee of a venue that uses TransIQ, the venue is the organization accountable to you. We will help them respond, and we will not refuse a lawful request routed through them.

2. What we collect

From our business customers

  • Account details: name, business name, email, phone, role, password (stored only as a salted hash — never in readable form).
  • Billing details: plan, invoices, payment status. Card numbers are handled by our payment processor, never by us.
  • Usage and technical records: log-ins, IP address, browser, pages used, actions taken, error reports.
  • Support correspondence.

Processed on behalf of venues

  • Guests: name, phone, email, reservation and order history, table and seating, loyalty points and spend, notes recorded by staff, marketing preferences.
  • Allergy and dietary information — see section 3.
  • Employees: name, contact details, position, wage rate, availability, shifts, clock-in and clock-out records, hours worked, and — where the venue switches it on — the location check confirming an employee was on site when they clocked in.

3. Sensitive information: allergies, health and location

Allergy and dietary information is health information. Under PIPEDA it is sensitive by nature and attracts a higher standard of protection regardless of how it was collected.

It is used for one purpose: telling the venue's staff and kitchen what they need to know to serve that guest safely. It is not used for marketing, profiling or analytics, is not sold or shared for any commercial purpose, and is shown only to staff of the venue that recorded it.

Employee location. Where a venue enables the on-site check for clocking in, we record whether the employee was within the permitted distance of the venue and how far away they were. We do not track employees' location continuously, do not record it outside a clock-in or clock-out, and do not build a movement history. Venues must tell their staff that the check is on before enabling it.

4. Why we use it

  • To provide, secure, maintain and support the Service.
  • To authenticate users and prevent fraud and abuse.
  • To process payments and administer subscriptions.
  • To send service and transactional messages (booking confirmations, reminders, receipts, shift notifications, security notices).
  • To diagnose faults and improve reliability and performance.
  • To meet legal, tax and regulatory obligations.

We do not sell personal information. We do not share it for third-party advertising. We do not use guest or employee personal information to train machine-learning models.

5. Consent

We collect, use and disclose personal information with consent, except where the law permits or requires otherwise. For sensitive information — including allergy and dietary information — express consent is required, and the venue that collects it is responsible for obtaining it.

Consent may be withdrawn at any time, subject to legal and contractual restrictions and reasonable notice. Withdrawing consent may mean we can no longer provide part or all of the Service. Guests and employees should direct withdrawal requests to the venue.

6. Disclosure to others

We disclose personal information only:

  • to service providers who process it for us under contract and only on our instructions — hosting and database (Render, in Canada or the United States), transactional email delivery, error monitoring, and, where a venue enables them, payment processing, SMS delivery and banking-data providers;
  • to the venue whose guests or employees the information concerns;
  • where required by law, subpoena, warrant, court order or regulator, or to establish or defend a legal claim;
  • to a purchaser in connection with a sale, merger or reorganization of our business, subject to equivalent protection and to notice where the law requires it;
  • with consent.

7. Where information is stored, and cross-border access

Information is stored and processed in Canada and the United States. While it is in another country it may be accessible to the courts, law enforcement and national security authorities of that country, under that country's law. We use contractual and technical measures to protect it, but we cannot override foreign legal process. Contact privacy@transiqsys.com for details of our current providers and locations.

8. Safeguards

  • Encryption in transit (HTTPS/TLS) for all access to the Service.
  • Passwords stored only as salted hashes; reset tokens stored only as hashes and expiring after a short window.
  • Strict tenant separation: each venue's data is isolated, and access is filtered at the database-query layer so one venue cannot read another's records. This is tested continuously and monitored.
  • Role-based access, so staff see only what their role requires.
  • Audit logging of significant actions.
  • Automated backups with limited retention.
  • Brute-force protection and account lockout on repeated failed sign-ins.

No safeguard is perfect, and no system can be guaranteed secure.

9. Retention

We keep personal information only as long as needed for the purposes described, or as the law requires — for example, transaction and payroll records that must be kept for tax and employment-standards purposes. After a venue's account is terminated we make its data available for export for 30 days and then delete or de-identify it, subject to legal retention obligations and to backup cycles, from which data ages out.

10. Your rights

Subject to limited legal exceptions, you may:

  • ask whether we hold your personal information, and access it;
  • ask us to correct it if it is inaccurate or incomplete;
  • ask how it has been used and to whom it has been disclosed;
  • withdraw consent, subject to section 5;
  • complain about our handling of it.

We respond within 30 days. There is no fee for a reasonable request. If we refuse, we will tell you why and how to challenge that.

Guests and employees of a venue: please make your request to the venue, which is the accountable organization. If you cannot reach them, contact us and we will help route it.

11. Breach notification

Where a breach of security safeguards creates a real risk of significant harm, we will report to the Privacy Commissioner of Canada and notify affected individuals as PIPEDA requires, and we will notify the affected venue without unreasonable delay so that it can meet its own obligations. This obligation cannot be waived by contract.

12. Cookies

We use cookies that are necessary to operate the Service — keeping you signed in, protecting forms against cross-site request forgery, and remembering your language choice. We do not use advertising or cross-site tracking cookies. Blocking necessary cookies will stop the Service working.

13. Children

The Service is not directed at children and we do not knowingly collect their personal information. A venue may record a guest's name and a booking that includes children; venues must not enter more than is necessary.

14. Changes

We may update this Policy. Material changes will be posted with a new version and, where the law requires, notified. The version and effective date appear at the top.

15. Contact and complaints

Privacy Officer
[OPERATOR LEGAL NAME — SET THIS]
[REGISTERED ADDRESS — SET THIS]
privacy@transiqsys.com

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada — priv.gc.ca, 1-800-282-1376.

© 2026 TransIQ · 15918391 Canada Inc. · support@transiqsys.com