Privacy Policy
Learn how we collect, use, and protect personal information when you use Getme Online websites, CRM, and related services.
Last updated:
Overview
This Privacy Policy explains how Getme Online ("we", "us", "our") collects, uses, discloses, and protects personal information in connection with our website, CRM platform, payment integrations (such as Stripe), communication tools (such as Zoom and email), and accounting and invoicing systems.
What personal information we collect and for what purposes.
How we obtain consent and your choices regarding the use and disclosure of your personal information.
How we protect personal information, how long we keep it, and with whom it may be shared.
Your rights under Canadian privacy laws and how to contact us with questions or complaints.
1. Accountability
We are responsible for personal information under our control and are committed to handling it in a manner consistent with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, British Columbia's Personal Information Protection Act (PIPA).
We have designated a Privacy Officer who is accountable for our compliance with this Privacy Policy and applicable privacy laws. You can contact our Privacy Officer using the contact details at the end of this Policy.
2. Identifying Purposes
We identify and document the purposes for which personal information is collected before or at the time of collection. We only collect personal information that is reasonably necessary for these purposes.
We collect and use personal information for purposes such as: operating our website and CRM platform, creating and managing user accounts, and authenticating users; processing payments and subscriptions (for example, via Stripe or similar payment processors) — we do not store full credit card numbers on our own servers; scheduling and hosting meetings or product demos using integrated tools (for example, Zoom or similar conferencing services); sending transactional emails (such as invoices, account notifications, security alerts) and, where permitted, marketing and informational emails; maintaining accounting, invoicing, and tax records as required by applicable laws and regulations; providing customer support, troubleshooting, and improving the performance and security of our services; generating analytics, usage statistics, and reports to understand how our services are used and to improve our products; complying with legal and regulatory requirements, responding to lawful requests, and protecting our rights, property, and the safety of our users and the public.
3. Consent
We obtain your knowledge and consent for the collection, use, or disclosure of personal information, except where inappropriate or permitted by law. Consent may be express (for example, checking a box or signing a form) or implied (for example, when you provide information to use a feature and it is clear what the information will be used for).
You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice. If you withdraw consent, we will explain any consequences this may have on your ability to use our services (for example, we may no longer be able to process payments or maintain your account).
4. Limiting Collection
We limit the collection of personal information to what is necessary for the purposes identified in this Policy or at the time of collection. We collect information by fair and lawful means and avoid collecting information that is not relevant to the services we provide.
5. Limiting Use, Disclosure, and Retention
We do not use or disclose personal information for purposes other than those for which it was collected, except with your consent or as required or permitted by law.
We may share personal information with third parties who assist us in delivering our services, such as: payment processors (for example, Stripe) that process payments securely on our behalf; email and communication providers used to send transactional and support emails; video conferencing tools (for example, Zoom) used for demos, onboarding, and support meetings; cloud hosting, backup, and infrastructure providers that host our applications and data; accounting, invoicing, and CRM-related tools that help us maintain accurate financial and business records; professional advisors (such as lawyers or accountants) where reasonably necessary for compliance, legal, or audit purposes.
Getme uses third-party shipping infrastructure providers, including Shippo, Inc., to calculate carrier rates, purchase shipping labels, generate tracking information, validate addresses, and produce shipping and customs documents. To provide these features, recipient contact and address details, order information, and parcel information may be shared with the provider. Shippo’s privacy and data-processing terms are available at privacy.goshippo.com.
We enter into appropriate agreements with third-party service providers to require them to protect personal information and to use it only for the purposes for which it was disclosed.
We retain personal information only as long as necessary to fulfill the purposes for which it was collected, to meet legal, tax, and regulatory requirements (for example, record-keeping requirements under Canadian tax law), and to resolve disputes or enforce agreements. In general, business and tax-related records must be kept for at least six years from the end of the last tax year they relate to, unless a longer period is required by law.
When personal information is no longer required, we take reasonable steps to securely destroy, erase, or anonymize it.
6. Accuracy
We make reasonable efforts to ensure that personal information is as accurate, complete, and up to date as necessary for the purposes for which it is to be used. You are encouraged to update your account information and notify us if your personal details change.
7. Safeguards
We implement reasonable physical, organizational, and technical safeguards to protect personal information against loss, theft, unauthorized access, disclosure, copying, use, or modification.
Safeguards may include secured data centers, access controls, password policies, encryption in transit and at rest where appropriate, role-based access, and regular security monitoring. For payment information, we rely on PCI-compliant payment processors such as Stripe to handle card details securely.
Despite our efforts, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we work continuously to maintain and improve our safeguards.
8. Openness
We make information about our privacy practices readily available. This Privacy Policy is intended to provide clear and understandable information about how we handle personal information. You may contact us at any time if you have questions about our privacy practices or would like more details about how your personal information is managed.
9. Individual Access and Rights
Upon written request and subject to certain legal exceptions, we will inform you of the existence, use, and disclosure of your personal information under our control and provide you with access to that information.
You have the right to request correction or updating of your personal information if it is inaccurate or incomplete. In some cases, you may also request that we restrict or delete certain information, subject to our legal obligations (for example, mandatory retention periods for financial and tax records).
To exercise these rights, please contact us using the details in the "Contact Us" section. We may need to verify your identity before processing your request. We will respond within a reasonable time frame, in accordance with applicable privacy laws.
10. Challenging Compliance
You may challenge our compliance with this Privacy Policy and applicable privacy laws by contacting our Privacy Officer. We will investigate all complaints and concerns in a fair and timely manner.
If you are not satisfied with our response, you may have the right to file a complaint with the Office of the Privacy Commissioner of Canada or, where applicable, the Office of the Information and Privacy Commissioner for British Columbia.
12. Third-Party Services and International Transfers
Our services may rely on third-party providers whose servers are located outside your province or outside Canada, including in the United States or other jurisdictions. This means that personal information may be transferred to, processed, and stored in foreign jurisdictions where different privacy laws may apply.
We engage subprocessors to help provide the Services in categories such as cloud hosting and infrastructure, payments, shipping and logistics, email and communications, analytics, AI-assisted features, support, and security. A current list of these subprocessors — with each provider’s purpose, the data processed, and processing location — is maintained on our Subprocessors page at /legal/subprocessors. Where we process merchant customer data on a merchant’s behalf, we do so as a service provider or processor on the merchant’s instructions, and the terms of that processing — including subprocessor and international-transfer obligations — are set out in our Data Processing Addendum at /legal/dpa.
When we transfer personal information outside Canada, we take reasonable steps to ensure that appropriate safeguards are in place and that the information is provided only to organizations that have committed to protecting it in a manner consistent with this Policy and applicable privacy laws.
By using our services, you understand that your personal information may be processed in countries that may have different privacy and data protection laws than your home jurisdiction.
13. Payments, Stripe, and Financial Information
When you make a payment or subscribe to one of our services, payment details (such as credit card numbers and security codes) are processed directly by our third-party payment processors, such as Stripe. We do not store full credit card numbers or CVV codes on our servers.
We may store limited billing information (such as your name, business name, billing address, partial card information, transaction dates, and amounts) for invoicing, subscription management, refunds, fraud prevention, and tax and accounting purposes.
Your use of payment services is also governed by the terms and privacy policies of those providers (for example, Stripe's Privacy Policy at stripe.com/privacy). We encourage you to review those policies to understand how they handle your information.
14. Zoom and Communication Tools
If you schedule or attend a demo, onboarding, or support call with us through Zoom or similar tools, we may collect information such as your name, email address, meeting time, and any information you choose to share during the session.
By default, we do not record calls without notifying you. If a session is recorded for training or quality purposes, we will clearly inform you in advance, and you may choose not to participate.
Information processed by Zoom or similar providers is subject to their own privacy policies and terms of use. We recommend reviewing those policies for further information.
15. Merchant Customer Data and Connected Accounts
Our platform allows you to store and manage personal information about your own customers, leads, or contacts inside the CRM. You are responsible for ensuring that you have obtained all necessary consents and have provided appropriate notices to those individuals.
In some cases, you may choose to connect third-party accounts (for example, email, calendar, communication, or accounting systems) to our platform using secure OAuth or similar methods. When you do this, we only access the information and permissions you authorize, and we use that information solely to provide the requested integrations and features.
For the personal information about your own customers, leads, and contacts that is processed through your storefront, checkout, bookings, invoices, CRM, shipping, and related tools, Getme generally acts as a service provider or processor on your behalf, processing that information in accordance with this Policy, our Data Processing Addendum, and your instructions. You remain responsible for your own privacy notices, legal basis, consents, and instructions, and for your compliance obligations toward your customers and contacts.
To clarify our respective roles: Getme acts as a service provider or processor for merchant customer personal information processed through storefronts, checkout, bookings, CRM, invoices, shipping, and related tools, and merchants remain the controller or business responsible for their own customers and storefront visitors. Getme acts as an independent business or controller for merchant account data, billing, subscription management, platform administration, security, support, legal compliance, and communications. Payment providers, including Stripe, may process payment, identity, fraud-prevention, dispute, payout, and compliance information as independent controllers or businesses under their own terms and privacy policies.
We do not sell merchant customer data, and we do not use merchant customer data for unrelated advertising purposes. We process it only to provide the Services on your behalf, on your instructions, and as otherwise permitted by our agreement with you and applicable law.
16. Online Store, Checkout, and Customer Data
When you run an online store or accept bookings through the platform, we process information about your customers and their transactions on your behalf so that the storefront, checkout, orders, and related features work. Depending on the features you use, this may include cart contents and checkout sessions; order and purchase history; product and subscription details; billing, shipping, and delivery addresses; contact details; tax information applied to a transaction; payment status and payment metadata (but not full card numbers or CVV codes, which are handled by our payment processors); refund, return, and dispute status; customer account data; and information about visitors to your storefront, such as device, browser, and usage data collected through cookies and similar technologies.
We process this information to provide and operate the Services on your behalf — for example, to display the storefront, calculate totals and applicable taxes, process orders and bookings, arrange shipping, generate invoices and reports, handle refunds and disputes, and provide support and security. We act as a service provider or processor for this information, as described in Section 15 and in our Data Processing Addendum.
You are responsible for the personal information you collect from your customers and storefront visitors through the Services, including providing appropriate privacy notices, obtaining any required consents, configuring cookie and tracking tools where applicable, and honoring your customers’ privacy rights. Information about visitors to your storefront is also subject to your own privacy policy.
17. Breach Notification
We maintain safeguards designed to protect personal information, but no system can be guaranteed to be completely secure. If we become aware of a security breach involving personal information, we will assess the incident and take reasonable steps to contain and address it, and we will notify affected individuals, merchants, regulators, or other parties where required by applicable law.
We keep records of breaches of security safeguards as required by applicable law. Under PIPEDA, we report and notify breaches that create a real risk of significant harm to the Office of the Privacy Commissioner of Canada and to affected individuals, as required.
Where we process personal information on behalf of a merchant as a service provider or processor, we will notify the merchant of a relevant breach without undue delay so that the merchant can assess and meet its own notification obligations, as described in our Data Processing Addendum.
18. AI-Assisted Features
We may offer AI-assisted features that help merchants generate, summarize, classify, translate, draft, analyze, or improve content, including product descriptions, website copy, customer messages, support replies, marketing text, business information, uploaded files, images, or other materials submitted through the Services.
To provide these features, information submitted to AI-assisted features — including prompts, instructions, merchant content, store information, customer messages, uploaded files, metadata, and related outputs — may be processed by third-party AI service providers acting on our behalf.
We use AI service providers to deliver the requested AI functionality, maintain security, prevent abuse, troubleshoot errors, and improve the reliability of the Services. We do not use merchant customer data submitted to AI-assisted features for unrelated advertising purposes. We do not use merchant customer personal information submitted to AI-assisted features to train, fine-tune, or improve first-party or third-party AI models unless expressly agreed in writing.
Our current AI service providers, the purposes for which they are used, the categories of data processed, and processing locations are listed on our Subprocessors page at /legal/subprocessors.
AI-generated outputs may be inaccurate, incomplete, outdated, or unsuitable for a specific legal, financial, medical, tax, or professional purpose. Merchants are responsible for reviewing, editing, and verifying AI-generated outputs before relying on them, publishing them, or sending them to customers.
You should not submit sensitive personal information, payment card details, government identification numbers, passwords, health information, children’s information, or other highly sensitive information into AI-assisted features unless it is necessary for the feature and you are authorized to do so.
19. Merchant Responsibility for Customer Data
Merchants are solely responsible for determining what personal information they collect from their customers, visitors, leads, contacts, and end users, and for ensuring they have a valid legal basis, consent, notice, and authority to collect, use, disclose, transfer, and process that information through the Services.
Merchants are also responsible for the accuracy of the customer data they upload or enter, and for responding to their own customers’ inquiries, complaints, and privacy requests, such as access, correction, or deletion requests.
Merchants are responsible for their own privacy policies, cookie notices, marketing consents, customer communications, product or service disclosures, refund and return practices, tax settings, shipping settings, and compliance with laws that apply to their business, industry, customers, and jurisdictions.
Getme does not control and is not responsible for the content, products, services, privacy practices, data collection choices, customer communications, or legal compliance of merchant storefronts, websites, bookings, invoices, CRM records, or connected third-party accounts, except to the limited extent required by applicable law and our agreement with the merchant.
In short, Getme protects the platform and the data under our control, and merchants are responsible for their own customers, storefronts, content, notices, consents, legal basis, products, communications, and compliance.
20. Children's Privacy
Our merchant dashboard and business services are intended for users who are at least the age of majority in their province or territory of residence. We do not knowingly collect personal information from children under 13 through our own business services, and if we become aware that we have done so without appropriate consent, we will take reasonable steps to delete it as soon as possible.
Merchant storefronts and sites built on the platform may be accessed by customers and visitors of different ages. Merchants are solely responsible for ensuring their stores, content, and data practices comply with laws relating to minors and children’s data, including any age restrictions, parental-consent requirements, and limits on collecting or processing children’s personal information.
Age thresholds for children’s data vary by jurisdiction. In Quebec, consent for the personal information of a minor under 14 must generally be given by a person having parental authority, as described in our Quebec (Law 25) section below.
21. Quebec Privacy Rights (Law 25)
If you or your customers are in Quebec, Quebec’s Act respecting the protection of personal information in the private sector, as amended by Law 25, may apply to the processing of personal information.
We handle confidentiality incidents involving personal information by taking reasonable measures to reduce the risk of harm and prevent recurrence. Where a confidentiality incident presents a risk of serious injury, we notify the Commission d’accès à l’information and affected individuals as required, and we maintain a register of confidentiality incidents.
Quebec law also provides individuals with rights such as access, correction, and, in certain cases, de-indexing or portability of their personal information, and sets specific rules for the personal information of minors under 14, for which consent must generally be given by a person having parental authority. You may exercise applicable rights by contacting our Privacy Officer.
23. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this Policy and may provide additional notice (such as by email or a prominent notice on our website).
We encourage you to review this Policy periodically to stay informed about how we handle personal information.
24. Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy or our privacy practices, or if you wish to exercise your rights, please contact our Privacy Officer.
You can contact us using the contact form on our website or by email at: [email protected].