Privacy Policy
Last updated: February 23, 2026
Autoflow Technology INC. (“we”, “our”, or “the Company”), operating as CoShop, is committed to protecting your personal information. This Privacy Policy explains what information we collect, why we collect it, and how we use it — in plain language.
This policy applies to all users of CoShop, including customers, vendors, and visitors, and is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA), the federal privacy law of Canada.
1. What Information We Collect
We only collect information that is necessary to operate the CoShop marketplace. Here is what we collect and from whom:
All registered users (customers and vendors)
- Name and email address — provided when you create an account.
- Password — stored as a one-way cryptographic hash (we cannot read your password).
- Session data — a temporary token stored in your browser to keep you signed in.
Vendors (additional)
- Business name, description, and location — entered in your store profile. This information is publicly displayed on your store page.
- Logo and product images — uploaded by you and stored in our image storage service.
- Product listings — names, descriptions, prices, and tax settings you enter.
Customers (additional)
- Order history — items ordered, quantities, prices, and order status. This is linked to your account and visible to the relevant vendor(s).
Visitors (no account required)
- You can browse products and add items to your cart without creating an account. We do not collect any personal information from visitors. Cart contents are stored locally in your browser only.
2. Why We Collect It
We collect personal information for the following purposes:
- To operate your account — sign you in, identify you as a customer or vendor, and show you your orders or dashboard.
- To process orders — pass your order details to the relevant vendor so they can fulfill it.
- To send order notifications — email confirmations and status updates related to your orders.
- To display vendor stores publicly — your business name, location, and products are shown to shoppers on your store page.
- To improve the platform — understand how CoShop is used and fix issues.
We do not sell your personal information. We do not use it for advertising or share it with third parties for marketing purposes.
3. How We Share Information
We share your information only as necessary to operate CoShop:
Between customers and vendors
When you place an order, your name, email, and order details are shared with the vendor(s) you ordered from so they can fulfill and communicate about your order.
Third-party service providers
We use the following services to operate CoShop. Each has its own privacy policy. Some are based in the United States, which means your data may be transferred outside of Canada:
- Supabase (US) — our database and image storage provider. Your account data, orders, and uploaded images are stored on Supabase infrastructure.
- Vercel (US) — our hosting provider. All web requests pass through Vercel’s servers.
- Resend (US) — our email delivery service. Your email address is passed to Resend to deliver order confirmation emails.
By using CoShop, you consent to your information being processed in the United States by these providers, where privacy laws may differ from Canadian law.
Legal
We may disclose personal information if required by law, court order, or to protect the rights and safety of users or the public.
4. How Long We Keep It
We retain your personal information for as long as your account is active. If you ask us to delete your account, we will remove your personal information within 30 days, except where we are required by law to retain it (e.g., financial records).
Order records may be retained for up to 7 years for tax and accounting purposes, as required under Canadian law.
5. How We Protect It
- Passwords are hashed using bcrypt — they are never stored in plain text.
- All data is transmitted over HTTPS (encrypted in transit).
- Access to vendor data and order data is restricted by role — vendors can only see their own orders; customers can only see their own account.
- Database access is restricted to application code only — no public database access.
No system is completely secure. If you believe your account has been compromised, contact us immediately at coshopns@gmail.com.
6. Cookies and Local Storage
CoShop uses the following browser storage:
- Session cookie — set when you sign in, used to keep you authenticated. Expires when you sign out or your session ends.
- Cart (localStorage) — your cart contents are saved in your browser’s local storage so they persist between visits. This data never leaves your device unless you proceed to checkout.
We do not use advertising cookies, tracking pixels, or analytics cookies.
7. Your Rights Under PIPEDA
Under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to:
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to correct inaccurate or incomplete information.
- Withdrawal of consent — withdraw consent for us to use your information. Note that withdrawing consent may prevent you from using CoShop.
- Deletion — request deletion of your account and associated personal data, subject to legal retention requirements.
- Complaint — file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca if you believe we have not handled your information appropriately.
To exercise any of these rights, contact us at coshopns@gmail.com. We will respond within 30 days.
8. Children’s Privacy
CoShop is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has created an account, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent revision. For significant changes, we will notify registered users by email where reasonably possible.
Continued use of CoShop after changes are posted constitutes your acceptance of the updated policy.
10. Contact Our Privacy Officer
For any privacy-related questions, requests, or concerns, please contact us. Under PIPEDA, we are required to designate someone accountable for privacy compliance — that person can be reached at:
Privacy Officer — Autoflow Technology INC.
Operating as CoShop
Nova Scotia, Canada
We will respond to all privacy requests within 30 days.