Privacy Policy
Last updated: August 31, 2026
1. Introduction
SBM Portal ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our business management platform located at https://codeflippers.com and any related services (collectively, the "Services").
We operate in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA), Ontario's privacy legislation, and other applicable Canadian privacy laws. By using our Services, you consent to the practices described in this policy.
2. Information We Collect
2.1 Personal Information
We collect the following personal information when you register for our Services or book an appointment:
- Identity Information: Name, email address, phone number
- Address Information: Street address, city, province, postal code
- Account Information: Username, password (encrypted), account preferences
- Vehicle Information: Vehicle make, model, year, VIN (Vehicle Identification Number), license plate number, mileage, and specifications
- Service History: Appointment records, service details, work orders, and inspection results
2.2 Automatically Collected Information
When you access our Services, we automatically collect:
- Device Information: Browser type, operating system, device identifiers
- Usage Data: Pages visited, time spent, interactions with our Services
- Location Data: General geographic location based on IP address (not precise GPS location)
- Session Data: Session tokens, authentication status
2.3 Payment Information
We do not directly process or store credit card information. Any payment processing is handled by third-party payment processors who maintain their own privacy policies and security standards compliant with PCI-DSS requirements. Our platform subscription billing is handled by Stripe; participating businesses may process customer payments through their own Stripe or Square accounts. Card details are tokenized by the processor and are never transmitted through or stored on our servers.
3. How We Use Your Information
We use your personal information for the following purposes:
- Service Delivery: To schedule, manage, and complete your requested services and appointments
- Account Management: To create and maintain your customer account
- Communication: To send appointment confirmations, reminders, service updates, and respond to your inquiries
- Record Keeping: To maintain service history records for your account
- Legal Compliance: To comply with applicable laws, regulations, and legal processes
- Business Operations: To improve our Services, analyze usage patterns, and ensure platform security
- Loyalty Programs: To track and manage customer loyalty tier benefits
4. Legal Basis for Collection
Under PIPEDA, we collect and use your personal information only with your consent and for purposes that a reasonable person would consider appropriate in the circumstances. Our legal bases include:
- Consent: Your explicit consent when registering or booking services
- Contract Performance: Necessary to provide the services you request
- Legal Obligation: Compliance with regulatory requirements and applicable standards
- Legitimate Business Interest: Improving services and maintaining platform security
5. Information Sharing and Disclosure
We may disclose your personal information to:
- Service Providers: Third parties who assist in operating our platform under contractual obligations to protect your data
- Third-Party Data Providers: External APIs for reference data and lookup features to obtain accurate specifications
- Business Partners: Suppliers or service partners when necessary to complete your service
- Legal Authorities: When required by law, court order, or government regulation
- Business Transfers: In connection with a merger, acquisition, or sale of assets (with notice to affected customers)
5.1 Processors We Use
The following service providers process personal information on our behalf. Each is contractually bound to use your information only to provide its service and to protect it in accordance with applicable law:
- Stripe — SaaS subscription billing and, where a business chooses, customer payments
- Square — customer payment processing (online checkout and terminal) where a business chooses
- Telnyx / Twilio — SMS appointment reminders and notifications
- Zoho / ZeptoMail — transactional email delivery
- Cloud infrastructure and backup storage — hosting, database, and encrypted backup storage (including S3-compatible object storage)
- Vehicle data lookup APIs — VIN decoding and reference data for accurate vehicle specifications
Where a business uses its own payment gateway credentials, payments are processed under that business's processor relationship with Stripe or Square, not ours.
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
6. Data Security
We implement appropriate security measures to protect your personal information:
- Encryption: SSL/TLS encryption for data transmission; encryption of sensitive stored data
- Access Controls: Role-based access restrictions; authentication requirements for staff
- Secure Storage: Database security measures and secure server infrastructure
- Security Headers: Implementation of X-Frame-Options, Content-Security-Policy, and other protective headers
- Regular Reviews: Periodic security assessments and vulnerability monitoring
While we implement robust security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
7. Data Retention
We retain your personal information only as long as necessary for the purposes outlined in this policy:
- Account Data: Retained while your account is active and anonymized or deleted after account closure, except where retention is required by law
- Appointment Records: Customer-identifying details in appointment history are anonymized 7 years after the customer's most recent appointment
- Work Orders & Service Records: Retained as required for warranty claims and Ontario business record regulations (7 years)
- Deleted Records: Soft-deleted records are permanently purged from our systems 730 days after deletion (24 months), and no later
- Payment Webhook Events: Processed payment events are deleted 30 days after processing
- Session Data: Automatically deleted after session expiration
- Backups: Encrypted backups are retained for a rolling 30-day window
Upon account deletion, we will anonymize or delete your personal information except where retention is required by law.
8. Your Rights and Choices
Under Canadian privacy law, you have the following rights:
8.1 Access and Information
You may request access to your personal information and details about how it has been used. We will respond within 30 days.
8.2 Correction
You may request correction of inaccurate or incomplete personal information. You can update most information directly through your account settings.
8.3 Withdrawal of Consent
You may withdraw consent for certain uses of your personal information at any time, subject to legal or contractual restrictions. Withdrawal may limit your ability to use certain Services.
8.4 Account Deletion
You may request deletion of your account. Note that service records may be retained for legal compliance purposes.
8.5 Complaints
If you believe our handling of your personal information violates privacy laws, you may file a complaint with us. If unresolved, you may contact the Office of the Privacy Commissioner of Canada.
9. Cookies and Tracking
We use cookies and similar technologies to operate our Services:
- Session Cookies: Essential for authentication and maintaining your logged-in state
- Security Cookies: CSRF protection tokens to prevent cross-site request forgery attacks
- Functional Cookies: Remember preferences and improve user experience
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect your ability to use our Services.
10. Third-Party Links
Our Services may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review the privacy policies of any third-party sites you visit.
11. Children's Privacy
Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately for removal.
12. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Significant changes will be notified through our Services or by email. The "Last Updated" date indicates the most recent revision.
13. Contact Information
For privacy-related inquiries, requests, or complaints, please contact:
SBM Portal Privacy Officer
Email: [email protected]
Phone: [Insert Phone Number]
Address: [Insert Business Address]
Province of Ontario, Canada
We will acknowledge receipt of your inquiry within 5 business days and respond substantively within 30 days, as required under PIPEDA.
14. Regulatory Authority
For matters not resolved through our internal process, you may contact:
Office of the Privacy Commissioner of Canada
Website: www.priv.gc.ca
Phone: 1-800-282-1376
Address: 30 Victoria Street, Gatineau, Quebec K1A 1H3
This Privacy Policy is provided for informational purposes and constitutes a legal agreement between you and SBM Portal regarding the handling of your personal information in accordance with Canadian privacy legislation.