Data Practices
We are transparent about how we handle your data. Learn about retention, deletion, export rights, multi-tenant isolation, and the subprocessors required to deliver the service.
Data Retention Policies
We retain your data only as long as necessary to provide our services and comply with legal obligations. Retention periods vary by data type and purpose. A formal data retention and deletion policy is being documented as part of our compliance programme.
General Retention Principles:
- Account Data: Retained while your account is active and for a reasonable period after deletion
- Transaction Data: Retained as required for tax and legal compliance
- Business Data: Retained as necessary for business operations and service delivery
- Backups: Production database backups run on an automated schedule to an encrypted repository separate from the application host, with retention enforced by policy and automated restore verification
For specific questions about data retention, contact info@toolswift.ca.
Data Deletion Procedures
You have the right to request deletion of your personal data. We have procedures in place to securely delete data upon request.
Deletion Process:
- Submit a deletion request via email
- We verify your identity before processing the request
- Data is deleted within 30 days of verification
- Some data may be retained for legal compliance (e.g., transaction records)
- Backup copies are removed according to the backup retention schedule after primary deletion
To Request Deletion: info@toolswift.ca
Data Export Capabilities
You have the right to receive a copy of your personal data in a structured, commonly used, and machine-readable format.
Exportable Data Includes:
- Account information and profile data
- Order history and transaction data
- Quotes history data
- Store details and inventory data
- Customer data
- Store analytics and sales data
To Request Export: info@toolswift.ca
Who Can Access Your Data
ToolSwift is a multi-tenant platform. Dealer data is scoped by store at the application layer so that one dealer cannot access another dealer's records.
- Beyond the dealer's own authorised users, two named ToolSwift staff hold access to production data for support and operational purposes
- Access is limited to those individuals by name and is not anonymous
- An append-only activity log with attribution is in our release pipeline and will record access and changes, including by ToolSwift staff
- ToolSwift does not sell customer data and does not share it other than with subprocessors required to deliver the service
User Data Rights
You have rights regarding your personal data under GDPR, CCPA, PIPEDA, and other applicable privacy laws.
Your Rights Include:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to certain types of processing
- Right to Withdraw Consent: Withdraw consent for data processing
To exercise these rights, contact info@toolswift.ca.
Data Security Measures
Sensitive operations are handled server-side. Credentials and privileged operations are never exposed to client-side code.
Password & Authentication
- Passwords hashed with bcrypt; never stored in recoverable form
- One-time passcode verification available for customer flows
Encryption
- All public traffic over HTTPS/TLS
- Traffic to infrastructure and storage providers encrypted in transit
- Backups held in an encrypted repository
- Encryption of live database storage at rest and database TLS are scheduled in our remediation plan
Infrastructure Access
- SSH key-based server access only; password auth disabled
- Named database administrator accounts
- Production access limited to two named staff
For more detail, see our Security page.
Subprocessors & Third-Party Sharing
Data is shared only with subprocessors required to deliver the service. A formal processor register with risk ratings and contractual security terms is being built as part of our compliance work. Principal providers hold recognised certifications.
Infrastructure & Platform:
- Hetzner: Backend compute, production MongoDB, and encrypted backup storage (ISO 27001 certified data centres)
- Vercel: Frontend hosting and edge delivery (SOC 2)
- Amazon Web Services: Object storage (S3), secrets management, and transactional email via SES (SOC 2 and ISO 27001)
- Payment processors: PCI DSS Level 1 certified providers; ToolSwift does not store cardholder data
Optional Commerce & Marketing Integrations:
- Google Merchant Center: Product catalog listings
- Facebook Catalog: Product catalog for advertising and e-commerce
- Klaviyo: Email marketing and customer engagement
Data shared with these services is limited to what is necessary for their functions and is subject to their privacy policies and our contractual agreements.
Artificial Intelligence
ToolSwift does not use artificial intelligence to process dealer or customer data in the version available to customers today. We are developing an AI assistant capability that is not enabled for customers. Before any AI feature is made available, we will provide detail of the data flows, subprocessors involved, and the controls applied.
Contact for Data Requests
To exercise your data rights or request information about our data practices:
- Email: info@toolswift.ca
- Support: support@toolswift.ca
- Website: toolswift.ca
We will respond to your request within 7 days, or as required by applicable law.