This Privacy Policy describes how Operating legal entity will be published here before the first real paid pilot shift.("Kavoro", "we") collects, uses, and shares personal information when you use the Kavoro marketplace platform. This is a draft for counsel review under PIPEDA and applicable Manitoba privacy law.
Information we collect (from product implementation)
- Account information: email address, password (stored by Supabase Auth), account type (worker or employer), and email verification status.
- Profile information: name, phone, area, headline, skills, availability, languages, emergency contact (if provided), and profile preferences stored in
public.profiles. - Employer information: legal/display business name, category, area, locations, addresses, geocoded coordinates, verification status, and organization membership roles.
- Shift and application data: shift postings, applications, selection and employment-offer snapshots, employment-offer acceptances, confirmation status, applicant snapshots, and related timestamps.
- Legal acceptances: records of which platform, worker, employer, and privacy documents you accepted, with document version identifiers and timestamps.
- Messaging: conversation metadata and message bodies between workers and posting businesses for connected shifts.
- Attendance and hours: QR check-in/out timestamps, work records, submitted minutes, employer approvals/disputes, and related notes.
- Payroll-related records: approved pay lines, payroll batch/export metadata, and sandbox payroll simulation status (no live wage payment processing in current pilot foundation).
- Notifications and email delivery: in-app notification records and transactional email delivery logs (recipient, template/event type, delivery status).
- Security and abuse controls: rate-limit bucket metadata keyed by action and hashed server attestation subjects; standard web server/IP headers processed by our host and auth flows.
Information we do not intentionally collect in the current product
- Social Insurance Numbers (SIN) — not stored in Kavoro database tables reviewed for pilot.
- Bank account numbers for worker payout — not stored in current pilot foundation.
How we use information
To operate the marketplace: authenticate users, display shifts, route applications, facilitate messaging, record attendance and hours, support employer payroll export workflows, send transactional emails, prevent abuse, and provide customer support.
Service providers (supported by repository configuration)
- Supabase — authentication, PostgreSQL database, and local/ hosted backend infrastructure configured via
NEXT_PUBLIC_SUPABASE_URL. - Vercel — application hosting when deployed to Vercel (including
VERCEL_URL/SITE_URLconfiguration). - Resend — transactional email delivery when
RESEND_API_KEYis configured. - Google Maps Platform — map display and address autocomplete when Google Maps keys are configured (
NEXT_PUBLIC_GOOGLE_MAPS_API_KEY, server geocoding key). - Sentry — error monitoring when
NEXT_PUBLIC_SENTRY_DSNis configured.
We do not list a processor unless the codebase or deployment configuration supports its use.
Retention and security
Records are retained while accounts are active and as needed for payroll, dispute, and legal obligations. Row Level Security and role-scoped RPCs restrict access in the database. Draft retention schedules require counsel review.
Your choices
You may update profile fields, withdraw applications where permitted, and contact support for access or correction requests. Account deletion workflows require operational process during pilot.
Contact
Privacy questions: support@kavoro.ca (pilot channel — designate privacy contact before launch).
