Business continuity and disaster recovery plans established
We maintain documented business continuity and disaster recovery procedures to support operational resilience and data availability.
Security, data handling and compliance overview
This page outlines our internal controls, data handling practices and security procedures to support compliance, reliability and transparency.
We maintain documented business continuity and disaster recovery procedures to support operational resilience and data availability.
Plans are reviewed periodically to validate effectiveness and readiness in case of incidents.
Formal data retention and deletion policies govern the lifecycle of customer data.
Data is classified based on sensitivity and access is restricted accordingly.
Access to data is restricted to authorized personnel based on role and necessity.
Internal reviews are conducted regularly to confirm controls are operating effectively.
All data transmitted is encrypted using industry-standard HTTPS/TLS protocols.
We rely on established providers such as Shopify and Klaviyo for secure data processing.
We maintain internal processes to detect, respond to and resolve security incidents.
Data is only processed when users provide explicit consent through cookie banners or opt-in forms.
Tracking is limited to users who have accepted cookies and the privacy policy.
All communications are opt-in and handled via Klaviyo.
We do not use fingerprinting or unauthorized tracking methods.
Our data practices follow GDPR principles including consent, transparency and data minimization.
We comply with Canadian Anti-Spam Legislation by enforcing opt-in communication.
Our technology improves tracking reliability for users who have already consented, especially where browser restrictions limit attribution.
We do not override or bypass consent frameworks implemented on websites.
For any security or privacy questions, reach out to our team at support@ypsometro.ai.