Privacy Policy
Last updated: July 2, 2026
Please have this reviewed by legal counsel. This policy reflects CabShopSoft's actual data practices but has not yet been reviewed by a lawyer. Have qualified legal counsel review it before you rely on it.
This Privacy Policy explains how Exact Cabinets Ltd. ("CabShopSoft", "we", "us") collects, uses, discloses, and safeguards personal information when you use the CabShopSoft platform and related services (the "Service"). We are committed to protecting privacy in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, where it applies, the EU/UK General Data Protection Regulation (GDPR).
1. Our role: controller and processor
CabShopSoft is a business-to-business platform used by cabinet shops and dealers ("Customers") to run their operations.
- For account, billing, and platform-usage data of our Customers and their staff, we act as a data controller.
- For the data a Customer enters about their own clients, employees, and projects (e.g. a shop's customer list, an installer's location), we act as a data processor on that Customer's behalf. The Customer is the controller of that data and is responsible for having a lawful basis to collect it. Business Customers may request our Data Processing Agreement.
2. Information we collect
Information you provide
- Account & profile: name, email, username, password (stored only as a salted hash), company profile, and optional two-factor authentication data.
- Billing: plan selection and billing contact. Card payments are processed by our payment processor; we do not store full card numbers on our servers.
- Operational content you enter: your clients' names, billing and delivery addresses, emails and phone numbers; quotes, jobs, invoices, drawings, and uploaded files.
- Employee & field data: staff records, time/attendance entries, commissions/payouts, and — where you enable it — employee location (GPS) captured at clock-in/clock-out and shown on a live staff map.
Information collected automatically
- Security & audit logs: IP address, browser/user-agent, and timestamps of key actions, kept to secure the Service and investigate incidents.
- Cookies: we use a strictly-necessary session cookie to keep you logged in and, optionally, a "trusted device" cookie for two-factor authentication. We do not use third-party advertising or cross-site tracking cookies.
3. How we use information & legal bases
We use personal information to provide, secure, bill for, and improve the Service, to communicate with you, and to comply with legal obligations. Where the GDPR applies, our legal bases are:
- Performance of a contract — to deliver the Service you signed up for.
- Legitimate interests — to secure the platform, prevent fraud, and operate our business, balanced against your rights.
- Legal obligation — to meet tax, accounting, and other legal requirements.
- Consent — for optional features such as employee location tracking, which a Customer must configure lawfully and, where required, with the individual's consent. Consent can be withdrawn at any time.
We do not sell personal information, and we do not use your operational content or your clients' data to train AI models.
4. How we share information (sub-processors)
We share personal information only with service providers ("sub-processors") that help us run the Service, under contracts that require them to protect it. Current sub-processors:
| Provider | Purpose | Region |
| DigitalOcean | Cloud hosting & database | United States |
| Cloudflare | DNS, CDN, TLS, DDoS protection | Global |
| Brevo | Transactional email delivery | EU |
| Google Workspace | Inbound business email | Global |
| Helcim | Payment processing | Canada |
| Anthropic (and, if a Customer enables them, other AI providers) | Optional AI assistant features (only data a Customer submits to a task) | United States |
We may also disclose information if required by law, to enforce our agreements, or in connection with a merger or acquisition (with notice where required).
5. International data transfers
Our servers are hosted in the United States. If you are in Canada, the EU, or the UK, your information will be transferred to and processed in the United States and other countries. Where the GDPR applies, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses for these transfers. Under PIPEDA, we remain accountable for information transferred to service providers for processing.
6. Data retention
We keep personal information only as long as needed for the purposes above:
- Employee location (GPS) data: retained for 90 days, then automatically deleted.
- Business records (quotes, jobs, invoices, and related customer contact details): retained for up to 7 years to meet tax, warranty, and accounting requirements, unless you delete them sooner.
- Security and audit logs: retained for a limited period appropriate to security needs.
- When a Customer closes their account, we delete or de-identify their data within a reasonable period, except where retention is legally required.
7. Your privacy rights
Subject to applicable law, you may request to access, correct, export (portability), delete, or restrict the processing of your personal information, and to withdraw consent or object to certain processing.
- You can exercise these rights by contacting us using the details below and, where available, using the in-app privacy tools (Settings → Privacy & Data) that let account administrators export or erase an individual's data.
- If your data was entered by a cabinet shop or dealer that uses CabShopSoft (i.e. you are their customer or employee), please contact that business directly, as they control that data. We will assist them in responding to your request.
- You may also contact us using the details below. We will respond within the timeframes required by law. You have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada or, in the EU/UK, your local supervisory authority.
8. How we protect data
We use technical and organizational safeguards including encryption in transit (HTTPS/TLS), hashed passwords, optional two-factor authentication, network isolation, access controls, firewalling, intrusion mitigation, and audit logging. No system is perfectly secure, but we work continuously to protect your information and will notify affected parties and regulators of a data breach as required by law.
9. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from children under 16.
10. Changes & contact
We may update this policy from time to time; material changes will be posted here with a new "Last updated" date. For privacy questions or to exercise your rights, contact:
Exact Cabinets Ltd.
Attn: Privacy
Alberta, Canada
Email: [email protected]