Privacy Policy
Version 1.0 · Effective May 2, 2026 · Last updated May 2, 2026
1. Introduction & Scope
Riant Technologies Inc. ("Riant," "we," "us," or "our") operates a marketplace connecting customers with independent bakers across Canada. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use the Platform.
This Policy is designed to comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's Anti-Spam Legislation (CASL), Quebec's Act respecting the protection of personal information in the private sector (as amended by Law 25, formerly Bill 64), British Columbia's Personal Information Protection Act (BC PIPA), Alberta's Personal Information Protection Act (Alberta PIPA), and other applicable provincial privacy legislation. Where this Policy conflicts with a mandatory provincial privacy law applicable to you, the law prevails. As Riant expands beyond its initial Ontario operations, Riant will publish a Provincial Schedule for each new province at launch in that province; the Provincial Schedule forms part of this Policy upon publication and supersedes any conflicting general reference for residents of that province.
Capitalized terms not defined here have the meanings given in our Terms of Service.
2. Information We Collect
2.1 Information You Provide
- Contact information (name, email address, phone number, mailing or pickup address)
- Account credentials (email, password — passwords are hashed and never stored or transmitted in plain text)
- Profile information (photos, bio, business details for Providers)
- Order and quote details (event date, servings, design preferences, allergens, delivery instructions, inspiration images)
- Communications between users, support inquiries, and dispute submissions
- Reviews, ratings, and other content you publish on the Platform
- Payment information — collected and stored directly by Stripe; Riant does not store full card numbers, CVV, or banking credentials
2.2 Information Collected Automatically
- Device information (browser type, operating system, device identifiers)
- Log data (IP address, access times, pages viewed, referring URL)
- Approximate geographic location derived from IP address — we do not collect precise GPS location
- Error and performance data (crash reports, page-load times) collected solely to improve Platform stability
- Cookies and browser local storage (see Section 6)
2.3 Information from Third Parties
When you sign in through a third-party identity provider (such as Google) or complete payment onboarding through Stripe, we receive limited information from that provider — typically your name, email, profile photo, and a verified-account indicator. We use this information only as described in this Policy.
2.4 Sensitive Personal Information (Provider Tax IDs)
As a reporting platform operator under Canada's Reporting Rules for Digital Platform Operators (Part XX of the Income Tax Act), we collect and retain each Provider's legal name, date of birth or business registration date, address, tax identification number (Social Insurance Number for sole proprietors or Business Number for incorporated entities), and, where provided, GST/HST registration number. Tax identification numbers are stored in an encrypted form using an authenticated encryption key managed outside the application database; the plaintext value is never displayed in the Provider dashboard and is decrypted only by a small number of authorized administrators for the sole purpose of preparing our annual filing to the Canada Revenue Agency. Every decryption is written to an immutable audit log.
3. How We Use Your Information
We use your information for the following appropriate purposes (the standard PIPEDA articulates as purposes a reasonable person would consider appropriate in the circumstances):
- Platform Operations: to provide, operate, maintain, and improve the Platform, including processing transactions, facilitating communication between Customers and Providers, and enabling account management.
- Transaction Processing: to process orders, payments, refunds, and payouts, and to send related transactional communications (order confirmations, receipts, fulfillment updates).
- Customer Support: to respond to inquiries, investigate and resolve disputes, and provide service.
- Service Communications: to send administrative notices, security alerts, technical updates, and policy changes necessary for the operation of your account. These cannot be opted out of while your account is active.
- Marketing Communications: to send commercial electronic messages where you have provided express or implied consent under CASL. You may withdraw consent at any time — see Section 11.
- Personalization: to personalize your experience and surface relevant Providers and content.
- Analytics and Improvement: to analyze usage patterns, monitor Platform performance, and improve our services.
- Safety, Trust, and Security: to detect, prevent, and address fraud, abuse, security incidents, and Platform-rule violations — including review of user-to-user communications when an Order dispute is opened or a Trust & Safety investigation is underway (see Section 5.4).
- Tax Compliance: to calculate, collect, and remit applicable sales taxes (GST/HST/PST/QST) as Merchant of Record, and to comply with the Reporting Rules for Digital Platform Operators.
- Legal Compliance: to comply with applicable laws, regulations, legal processes, and lawful governmental requests.
4. Data Minimization & Retention
4.1 Minimization
We collect only the personal information necessary to operate the Platform and fulfill the purposes described above. Where a feature can function with less personal information (for example, approximate location instead of precise GPS), we choose the less-intrusive option.
4.2 Retention Schedule
We retain personal information only as long as necessary for the purposes for which it was collected, and to meet legal, accounting, and dispute-resolution obligations. Specific periods:
| Data category | Retention period | Reason |
|---|---|---|
| Account profile (name, email, phone, addresses) | Lifetime of account + 24 months | Post-closure inquiries, fraud prevention |
| Transaction records (orders, payments, payouts, refunds) | 7 years from transaction date | CRA tax-record retention requirements |
| Tax identification (SIN / Business Number — encrypted at rest) | 7 years | Reporting Rules for Digital Platform Operators |
| User-to-user messages | Lifetime of account + 24 months | Dispute resolution, Trust & Safety |
| Dispute records (issues, evidence, determinations) | 7 years from resolution | Legal defence, audit trail |
| Authentication tokens and session data | Until logout or expiry | Session security |
| Server logs (IP, request metadata) | 90 days | Security investigation, debugging |
| Reviews and ratings | Lifetime of the Provider's account | Marketplace integrity for other Customers |
When personal information is no longer needed, we securely delete or anonymize it. Where deletion is not possible (for example, a record contained within a legally required transaction history), we restrict access and use it only to satisfy the obligation that requires its retention.
5. How We Share Information
We do not sell, rent, or trade your personal information for third-party marketing. We share information only as described below.
5.1 With Other Users
The Platform is a marketplace, so some information is shared between Customers and Providers to enable transactions. We share only the minimum necessary at each stage:
- When browsing: Customers see Provider business information (name, photos, location at city level, ratings, reviews) — not Provider phone, email, or street address.
- When a quote is requested: the Provider sees the Customer's first name, requested event date, servings, allergens, design notes, and any inspiration images. The Provider does not see the Customer's email, phone, or address until the order is paid and confirmed.
- When an order is paid: the Provider receives the Customer's name, contact information, and (for delivery) the delivery address; the Customer receives the Provider's pickup address and contact details.
- After fulfillment: Customers may publish a review under their first name and last initial; Providers may publish a single reply.
5.2 With Service Providers (Sub-processors)
We share information with vetted vendors that perform services on our behalf — payment processing, cloud hosting, transactional email, address autocomplete, error monitoring, and AI-assisted features. Each is contractually bound to use your information only for the services they provide to us and to maintain appropriate security. The current list is published in Section 7 (Sub-processors).
5.3 With Tax Authorities
As a reporting platform operator under Part XX of the Income Tax Act (Canada), we are required to report Provider information annually to the Canada Revenue Agency, including legal name, address, date of birth or business registration date, tax identification number, GST/HST registration number (where held), and gross consideration paid or credited to the Provider in each calendar quarter. This reporting is a statutory obligation and is not subject to consent. Each Provider receives a copy of what was reported about them, on or before the statutory deadline each year, from their Tax documents tab. Access to decrypted tax identification numbers on our side is restricted to a small number of authorized administrators acting for the sole purpose of preparing the annual filing, and every such access is written to an immutable audit log.
5.4 In Disputes & Trust & Safety
When an Order dispute is opened, a Trust & Safety report is filed, or we have a reasonable belief that the Platform's rules or applicable law have been violated, our staff may review communications between the parties involved (including chat messages, attachments, and order metadata) to investigate, mediate, and resolve the matter. By using the Platform you acknowledge and consent to this review, which is limited to what is reasonably necessary for the investigation.
5.5 For Legal Reasons
We may disclose information where we believe in good faith that disclosure is necessary to (a) comply with applicable law, regulation, legal process, or enforceable governmental request; (b) enforce our Terms of Service or Provider Agreement; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect the rights, property, or safety of Riant, our users, or the public, as required or permitted by law.
5.6 Business Transfers
In connection with a merger, acquisition, reorganization, financing, bankruptcy, or sale of all or substantially all of our assets, your personal information may be transferred as part of that transaction. We will notify affected users by email and prominent notice on the Platform.
5.7 With Your Consent
For any purpose not described in this Policy, we will share your information only with your explicit, informed consent.
6. Cookies & Local Storage
We use only essential cookies and browser local storage required to operate the Platform. We do not use third-party analytics, advertising, or tracking cookies.
What we use
- Authentication tokens: secure session management to keep you signed in.
- User preferences: display settings (such as light/dark mode) and notification preferences.
- Application state: temporary data needed for the Platform to function correctly.
What we don't use
- Third-party analytics cookies (e.g., Google Analytics)
- Advertising or remarketing cookies
- Social-media tracking pixels
- Cross-site tracking technologies
Because we use only essential cookies, no cookie consent banner is required under applicable Canadian law. You can manage cookies through your browser, but disabling them may prevent certain features (such as staying signed in).
7. Sub-processors
The following third-party providers process personal information on our behalf to deliver the Platform. Each is bound by a written data-processing agreement and security commitments.
| Provider | Purpose | Data categories | Processing location |
|---|---|---|---|
| Lovable Cloud (Supabase infrastructure) Privacy | Primary database, authentication, file storage, edge functions | Substantially all Platform data | United States / Canada |
| Stripe (Payments, Connect, Tax, Identity) Privacy | Payment processing, Provider payouts, sales-tax calculation, Provider identity verification | Payment credentials, transaction data, Provider identity verification (name, address, date of birth). Provider tax identification numbers (SIN / BN) are stored encrypted by Riant, not by Stripe. | United States |
| Resend Privacy | Transactional email delivery (order, quote, account, dispute notifications) | Email address, name, message content | United States |
| Google Places API Privacy | Address autocomplete and validation | Partial address strings typed into address fields | Global (Google infrastructure) |
| Lovable AI Gateway (Google Gemini) Provider terms | AI-assisted features (see Section 8) | Portfolio image URLs, business name, baker-supplied context strings | United States / Global |
| Sentry Privacy | Error and performance monitoring | Browser type, IP address, error stack traces, user identifier (where signed in) | United States |
We update this list when we add, remove, or materially change a sub-processor. Material changes will be communicated through the Platform or by email to affected users in advance where practicable.
8. Automated Processing & AI
We use automated tools and limited AI features to operate the Platform. We are transparent about what they do, what data they receive, and how decisions involving you are made.
Current AI-assisted features
- Portfolio alt-text suggestions. When a Provider uploads a portfolio image, we may send the publicly hosted image URL plus minimal context (business name, specialty) to the Lovable AI Gateway (Google Gemini) to suggest a descriptive caption. Suggestions are drafts shown to the Provider; nothing is published without the Provider's review and acceptance.
- Rate-limiting and abuse signals. Automated rules detect unusual patterns (e.g., burst requests) to protect Platform availability. These rules may temporarily slow or block individual requests; they do not produce significant decisions about your account.
Reserved future use
We may extend AI-assisted features to include search ranking, Customer–Provider matching, and automated content-safety review of images and messages. Any such extension will continue to operate within the safeguards described in this Section, and we will update this Policy if the categories of data processed materially change.
Training and model use
We do not permit our AI providers to use Platform data to train their foundation models, in accordance with the API terms governing our integration with the Lovable AI Gateway and Google Gemini.
Human-in-the-loop guarantee
Decisions with significant effects on you — including account suspension or removal, payout release, refund determinations, dispute outcomes, and Provider application approvals — always involve human review. We do not make such decisions on the basis of fully automated processing.
Your rights
You may object to AI-assisted processing of your information, request information about the logic and consequences of any automated processing that affects you, or request human review of an outcome by contacting privacy@riant.app. Quebec residents have additional rights under Section 13.
9. International Data Transfers
Several of our sub-processors store or process personal information outside Canada — primarily in the United States, and in some cases globally (Google services). Personal information transferred outside Canada is subject to the laws of the destination jurisdiction and may be accessible to law-enforcement or national-security authorities of that jurisdiction.
Our safeguards include: (i) written data-processing agreements with each sub-processor requiring protections comparable to Canadian privacy law; (ii) preference for sub-processors that maintain SOC 2 Type II, ISO 27001, or PCI DSS attestations; (iii) transfer impact assessments where required by Quebec Law 25, considering the destination jurisdiction's legal regime, the sensitivity of the information, and the contractual and technical safeguards in place; and (iv) encryption in transit and at rest for sensitive fields.
10. Data Security
We implement technical and organizational measures appropriate to the sensitivity of the information, including:
- TLS encryption for all data in transit and encryption at rest for sensitive fields
- Row-level security on our database so users can access only their own data
- Hardened authentication: password hashing, breach-password screening, complexity requirements, and second-factor authentication available to all users
- Least-privilege access controls and an immutable audit log of administrative actions
- Webhook signature verification on all payment and identity callbacks
- Vendor security review of each sub-processor before integration
No method of transmission or storage is 100% secure. While we use commercially reasonable measures, we cannot guarantee absolute security.
11. Your Privacy Rights
Subject to applicable law, you have the following rights with respect to your personal information:
- Access: request access to the personal information we hold about you.
- Correction: request correction of inaccurate or incomplete information.
- Withdraw consent: withdraw consent for collection, use, or disclosure of your personal information at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent may limit your ability to use certain features.
- Deletion: request deletion of your personal information, subject to legal retention obligations (see Section 4.2). You can also delete your account directly from your Account page.
- Portability: request a copy of the personal information you have provided to us in a structured, commonly used, machine-readable format (JSON or CSV).
- Cessation of dissemination / deindexation: request that we cease disseminating personal information about you, or deindex links that cause you serious injury (Quebec residents — see Section 13).
- Object to automated processing: object to AI-assisted processing of your information or request human review of an outcome (see Section 8).
- Complain: lodge a complaint with the privacy regulator having jurisdiction over your residence (see Section 16).
To exercise any of these rights, contact privacy@riant.app. We will respond within 30 days, as required by PIPEDA, and within the timelines required by applicable provincial law.
Withdrawing marketing consent
You can manage marketing-email and notification preferences at any time from your Account page, or by clicking the unsubscribe link at the bottom of any marketing email. Withdrawal does not affect transactional and account communications, which we must continue to send while your account is active.
12. Data Breach Notification
If a breach of security safeguards involves your personal information and creates a real risk of significant harm, we will notify you and the appropriate privacy regulator without undue delay, in accordance with PIPEDA's breach-notification provisions and applicable provincial law (including Quebec's Law 25, which requires notification to the Commission d'accès à l'information). Notifications will describe the nature of the breach, the information involved, the steps we are taking, and the steps you can take to protect yourself.
13. Quebec Residents (Law 25)
If you reside in Quebec, the following additional rights and protections apply under the Act respecting the protection of personal information in the private sector, as amended by Law 25.
- Person in charge of personal information protection. The role designated under Law 25 sits with our Privacy Officer, contactable at privacy@riant.app.
- Right to data portability. You may request a copy of computerized personal information you provided to us, in a structured, commonly used technological format.
- Right to cessation of dissemination, deindexation, or re-indexation. You may, in the cases provided by law, require us to cease disseminating your personal information or to deindex any link that causes you serious injury to your reputation or privacy.
- Transfers outside Quebec. Before transferring your personal information outside Quebec, we conduct an assessment of the privacy-related factors of the transfer, considering the sensitivity of the information, the purposes of use, the protection measures in place, and the legal regime of the destination jurisdiction. We use such transfers only where the assessment demonstrates adequate protection (see Section 9).
- Decisions based exclusively on automated processing. Where a decision affecting you is based exclusively on automated processing of your personal information, you have the right to be informed of that fact, the principal personal information used, and the reasons and principal factors leading to the decision; to submit observations to a person in a position to review the decision; and to request that the decision be reviewed (see Section 8).
- Conflict of laws. Where this Policy conflicts with a mandatory provision of Law 25, Law 25 prevails for Quebec residents.
14. Children's Privacy
The Platform is not intended for individuals under 18 (or the age of majority in your province, whichever is greater). We do not knowingly collect personal information from minors. If we learn that we have collected information from a minor, we will take prompt steps to delete it. If you are a parent or guardian and believe your child has provided us with personal information, please contact privacy@riant.app.
15. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or services. For material changes that affect how we collect or use your personal information, we will notify you at least 30 days in advance by email and prominent notice on the Platform. Non-material changes (such as clarifications or formatting) take effect on posting. We encourage you to review this Policy periodically.
16. Contact Us
For questions about this Privacy Policy, our practices, or to exercise any of your rights, contact our Privacy Officer:
Privacy regulators
If you are not satisfied with our response, you may contact the privacy regulator with jurisdiction over your residence: