Legal
Confidentiality Policy
Our governance policies and practices for personal information, published as Québec's Law 25 requires.
Last updated: 10 August 2026
In force — some details still being finalised
Law 25 §3.2 requires an enterprise to establish and implement governance policies for personal information and to publish detailed information about them. This page is that publication, and it describes how we operate today.
Including where we fall short. Items highlighted like this are things we have not built yet. We would rather state them plainly than describe a process that does not exist.
Showing: United States — we could not detect your region, so this is the default.
Location detection is a convenience only. Your actual rights depend on where you live, not on what this page guessed.
1. What this document is
The Privacy Policy tells you what we collect and what your rights are. This document is different: it describes how we govern personal information internally — who is accountable, how long things are kept, how they are destroyed, and what happens when something goes wrong or someone complains.
It applies to personal information about both:
- Business Users — the businesses and staff using Runday
- End-Clients — their customers, whose records they store in Runday
2. Who is responsible
The person with the highest authority over the protection of personal information at Runday is its founder, who acts as Privacy Officer, contactable at [email protected]. That person is accountable for this policy, for handling requests and complaints, and for deciding whether an incident must be reported.
Runday is a small team. Where a role below is described in the singular, that is because one person currently performs it, not because responsibility is vague.
3. Roles across the life of the information
Access is limited by role, and enforced by the database itself rather than only by what the interface chooses to show. A business's records are unreachable from another business's account.
- Business owner — creates the account, controls their own client and staff records, and decides who on their team has access.
- Staff (manager, stylist, barber, front desk) — access only their own business's data, and only the parts their role needs. A staff member sees their own earnings, not the whole payroll.
- Runday personnel — administrative access to production data is used only to operate the service, investigate a fault, or meet a legal obligation. Formal access log and internal approval step not yet in place.
- Processors — Supabase (hosting and database), Resend (transactional email), Google Analytics (website measurement), Cloudflare and Contabo (network and servers). Stripe is integrated for future subscription billing but processes no payments while Runday is free.
4. Keeping and destroying information
Personal information is kept only while it serves the purpose it was collected for, or while the law requires it. In practice:
- While an account is active — records are retained so the business can actually use its own history: past appointments, sales, and commission records.
- Deactivation instead of deletion, inside the product — archiving a service or deactivating a staff member deliberately preserves the financial history attached to them. A commission record that quietly vanished when someone left would make past pay periods impossible to audit.
- After an account closes — data remains available for export for 30 days, then is deleted from our active systems, except records we must keep for tax or accounting purposes. Deleting an account from Settings removes the data immediately rather than waiting out that window.
- Destruction — deleting an account from Settings removes every record belonging to it in a single operation: locations, staff, services, clients, appointments, walk-ins, sales, commission records and the staff portal logins. It is a real delete, not a hidden flag, and it runs immediately rather than being queued for later. Encrypted backups held by our hosting provider expire on their own cycle within 30 days, after which no copy remains. Records we are required to keep for tax or accounting purposes are the one exception, and are held for the six years Canadian tax law requires.
5. How information is protected
- Encrypted in transit over HTTPS/TLS, and at rest by our hosting providers
- Row-level security in the database, so tenant isolation is a property of the data layer rather than a promise made by the interface
- Passwords hashed by our authentication provider; never stored in readable form
- Staff logins created by an owner must be changed by the staff member on first use
- Rate limiting on public endpoints, and file-type validation on uploads
- Not yet in place: mandatory multi-factor authentication, formal staff privacy training, and a periodic access review.
6. Information held outside Québec
Runday's database is hosted in Canada (Montreal). Some personal information still leaves Canada: the application server for rundays.ca is in France, and processors including Stripe, Resend, and Google Analytics operate in the United States. Full detail is in the Privacy Policy.
Law 25 requires a privacy impact assessment before personal information is communicated outside Québec, weighing sensitivity, purpose, protections, and the legal framework of the destination. No assessment has been completed for the transfers that remain — the France-hosted application server and the U.S.-based processors above.
7. Privacy impact assessments
Law 25 requires an assessment before launching any project to acquire, develop or overhaul a system involving personal information, and before transferring it outside Québec.
No PIA process has been established and none has been carried out, including for the cross-border transfer above.
8. Confidentiality incidents
If personal information is accessed, used, disclosed, or lost without authorisation:
- We take reasonable steps to reduce the risk of harm and prevent a recurrence
- We assess whether the incident presents a risk of serious injury, considering sensitivity, likely use, and possible consequences
- Where it does, we notify the Commission d'accès à l'information and the affected individuals promptly
- Where a Business User's clients are affected, we notify the Business User so they can meet their own obligations
- Incident register — Law 25 requires a register of all confidentiality incidents, not only reportable ones. We keep one, recording what happened, whose information was involved, whether it presented a risk of serious injury, who was notified, and what we changed as a result. Entries are kept for five years after the incident becomes known. There are no entries to date.
9. Complaints
Complaints about how we handle personal information go to [email protected]. We will:
- Acknowledge receipt and confirm who is handling it
- Investigate, and ask for anything else we need to understand what happened
- Respond in writing with our findings and what we intend to do, within 30 days, the period Law 25 sets for access requests
- Tell you how to escalate if our answer does not satisfy you
You can complain to a regulator at any point, without going through us first — the Commission d'accès à l'information du Québec or the Office of the Privacy Commissioner of Canada.
If you are an End-Client — a customer of a business that uses Runday — start with that business. They control your record; we hold it for them.
10. Keeping this current
This policy is reviewed when the way we handle personal information changes, and otherwise at least once a year. The date at the top reflects the last change.
11. If you are outside Québec
To be written: United States — state-level security programme and breach notification requirements.
12. Contact
- Runday, operated from Québec, Canada
- Privacy Officer (Runday's founder) — [email protected]
- Runday is run by its two founders and is not yet a registered company. A registered entity name and business address will be added here once it is.
See also our Privacy Policy, Cookie Policy, and Terms of Service.