Trust Center

Security, data handling and compliance overview

GDPR alignedCASL compliantPrivacy-first trackingConsent-based data

This page outlines our internal controls, data handling practices and security procedures to support compliance, reliability and transparency.

Internal security procedures

Business continuity and disaster recovery plans established

We maintain documented business continuity and disaster recovery procedures to support operational resilience and data availability.

Business continuity and disaster recovery plans tested

Plans are reviewed periodically to validate effectiveness and readiness in case of incidents.

Data retention procedures established

Formal data retention and deletion policies govern the lifecycle of customer data.

Data classification policy established

Data is classified based on sensitivity and access is restricted accordingly.

Data access controls implemented

Access to data is restricted to authorized personnel based on role and necessity.

Product security

Control self-assessments conducted

Internal reviews are conducted regularly to confirm controls are operating effectively.

Data transmission encrypted

All data transmitted is encrypted using industry-standard HTTPS/TLS protocols.

Trusted infrastructure providers used

We rely on established providers such as Shopify and Klaviyo for secure data processing.

Incident response procedures established

We maintain internal processes to detect, respond to and resolve security incidents.

Data handling & privacy

Consent-based data collection enforced

Data is only processed when users provide explicit consent through cookie banners or opt-in forms.

No tracking without consent

Tracking is limited to users who have accepted cookies and the privacy policy.

No email without opt-in

All communications are opt-in and handled via Klaviyo.

No invasive tracking techniques used

We do not use fingerprinting or unauthorized tracking methods.

Compliance

GDPR alignment

Our data practices follow GDPR principles including consent, transparency and data minimization.

CASL compliance

We comply with Canadian Anti-Spam Legislation by enforcing opt-in communication.

Tracking transparency

Tracking accuracy improvement (consent-based)

Our technology improves tracking reliability for users who have already consented, especially where browser restrictions limit attribution.

No bypass of consent mechanisms

We do not override or bypass consent frameworks implemented on websites.

Security & privacy inquiries

For any security or privacy questions, reach out to our team at support@ypsometro.ai.