MafcoBook™ Request your workspace

Legal

Privacy Policy

Effective July 30, 2026 · How we handle personal information.

This Privacy Policy explains how Mafco Technology Ltd. ("MafcoBook", "we", "us") handles personal information in connection with our website and the MafcoBook platform (the "Service"). We are committed to handling personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.

Two different roles. This policy covers information for which we decide the purposes — mainly our website visitors and the businesses (and their staff) that use MafcoBook. When a business uses MafcoBook to manage information about its own clients or patients, that business is responsible for that information and we act only as its service provider (processor). That relationship — including personal health information under Ontario's PHIPA — is governed by our Data Processing Agreement, and questions about a specific business's records should go to that business.

Contents

  1. Who we are
  2. Information we collect
  3. How & why we use it
  4. Cookies & similar technologies
  5. Sharing & sub-processors
  6. Where your data is stored
  7. Security
  8. Retention
  9. Your rights
  10. Children
  11. Changes
  12. Contact us

1. Who we are

Mafco Technology Ltd. operates MafcoBook, an online booking and client-management platform for service businesses. For personal information described in this policy, we are the organization accountable for it under PIPEDA. Our contact details are in Section 12.

2. Information we collect

Information you provide

  • Enquiry & onboarding information — when you request a workspace or contact us: business name, your name, email, phone, address, industry, and website details.
  • Account information — credentials and profile details for you and your Authorized Users.
  • Support & communications — messages, support tickets, and feedback you send us.
  • Billing information — plan details and billing contact. Payment-card details are handled by our payment processor; we do not store full card numbers.

Information collected automatically

  • Usage & device data — log data such as IP address, browser type, pages viewed, and timestamps, used to operate, secure, and improve the Service.
  • Security signals — bot-protection challenges (see cookies).

Client Data (as processor)

Information a business enters about its End Clients (appointments, contact details, notes, and any health information) is Client Data. We process it only on that business's behalf under the DPA; this policy's collection/use sections do not describe our own purposes for Client Data.

3. How & why we use personal information

We use personal information to: provide, maintain, and secure the Service; set up and administer accounts; process billing; respond to enquiries and provide support; send service and administrative messages; understand and improve how the Service is used; prevent fraud, abuse, and security incidents; and comply with legal obligations. We rely on your consent and on the other bases permitted by PIPEDA (such as performing our contract with you and our legitimate business interests handled reasonably). We do not sell personal information. We send commercial electronic messages only in accordance with Canada's Anti-Spam Legislation (CASL), and you can unsubscribe from marketing messages at any time.

4. Cookies & similar technologies

We use a small number of strictly necessary cookies and similar technologies to keep you signed in, remember preferences, and secure the Service. Our sign-up and login flows use Cloudflare Turnstile to distinguish humans from bots. We keep non-essential tracking to a minimum. You can control cookies through your browser, though disabling essential cookies may affect how the Service works.

5. Sharing & sub-processors

We do not sell personal information and share it only as needed to run the Service or as required by law:

ProviderPurposeLocation
SupabaseDatabase, authentication, and file storageCanada (ca-central-1)
CloudflareWebsite hosting/CDN and bot protection (Turnstile)Global edge; content served from Canada
ResendTransactional email delivery (confirmations, reminders, notices)See provider
Payment processorSubscription billing [confirm provider]See provider

These providers act as our service providers/sub-processors and are bound to protect the information and use it only to provide their services to us. We may also disclose information to comply with legal process, protect our rights or the safety of others, or in connection with a business transaction (such as a merger or asset sale), with appropriate safeguards. The current sub-processor list is maintained in the DPA.

6. Where your data is stored

We host the Service's primary database and files in Canada (Supabase's ca-central-1 region). Some service providers (for example, email delivery and global content delivery) may process limited information outside Canada; where that occurs, the information remains subject to appropriate contractual and security safeguards and may be accessible to foreign courts or authorities in accordance with the laws of those jurisdictions. [Confirm and disclose any routine processing outside Canada — e.g. a US region.]

7. Security

We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit, tenant isolation with row-level security, access controls on a need-to-know basis, and multi-factor authentication for administrative access. No method of transmission or storage is completely secure, but we work to protect personal information and to respond promptly to incidents.

8. Retention

We keep personal information for as long as needed to provide the Service and for legitimate business or legal purposes (such as billing records and dispute resolution), after which we delete or de-identify it. Client Data is retained and deleted according to the business's instructions and the DPA.

9. Your privacy rights

Subject to applicable law, you may request to access the personal information we hold about you, ask us to correct it, or withdraw consent (which may limit our ability to provide the Service). To make a request, contact us using Section 12; we may need to verify your identity. If your request concerns records held by a business that uses MafcoBook (its Client Data), please contact that business directly — we will refer such requests to them. If you have an unresolved concern, you may contact the Office of the Privacy Commissioner of Canada (or your provincial regulator).

10. Children

The Service is intended for businesses, not for use by children. We do not knowingly collect personal information directly from children through our website. Where a business uses MafcoBook to serve minors, that business is responsible for obtaining any necessary consents as controller of that Client Data.

11. Changes to this policy

We may update this policy from time to time. We will post the updated version with a new effective date and, for material changes, provide additional notice where appropriate.

12. Contact us

For privacy questions or requests, contact our Privacy Officer:

Mafco Technology Ltd.
Ottawa, ON, Canada
Email: [email protected]
Phone: 613-299-9830

MafcoBook™ Online booking & CRM for personal service businesses.
Home Terms Privacy DPA Request a workspace

© 2026 Mafco Technology Ltd. All rights reserved.