This policy is not finished.
It is missing entity — the registered legal entity, e.g. "Viktr Technologies Inc.", address, contactEmail, privacyEmail. Until those are filled in, treat this page as a draft — it does not identify a legal entity you can hold to it.
Privacy Policy
Last updated August 25, 2026
Viktr handles two kinds of people: the business owners who use the dashboard, and the guests who join a loyalty programme by giving a phone number at a counter. Guests never create an account with us and we never sell their data. A guest's phone number is stored twice — once hashed so we can recognise it, once encrypted so we can text it — and never as plain text.
Who we are
Viktr is loyalty and messaging software for small local businesses, operated by Viktr. Our privacy contact is not published yet.
There are two relationships to keep straight. When a business owner signs up, we are the organisation deciding how their account data is handled. When a guest joins a shop’s loyalty programme, the shop decides what to do with that membership and we process it on the shop’s behalf. A guest who wants to leave a programme can tell either of us; replying STOP to any message is the fastest route and takes effect immediately.
What we collect
From business owners
- Your Google account’s name, email address and profile picture. Sign-in is Google only, so this is what we receive. We never see your Google password.
- Your shop’s details — name, address, type, timezone, the reward you offer, and how many points it takes to earn it.
- Request logs containing IP address, browser user agent and the pages you visited, kept for security and debugging.
From guests
- A mobile number, given at a counter or through a shop’s QR code.
- A record of consent — the moment it was given, and the moment it was withdrawn if it ever is.
- Visits — when you came in and the points you earned.
- Message delivery results from our SMS carrier: delivered, failed, or opted out.
We do not collect a guest’s name, email address, payment details, or anything about what they ordered, and there is nowhere in the product to enter them.
How a phone number is stored
This is the part worth being specific about, because it is the only sensitive thing we hold. A guest’s number is never written to our database in readable form. It is stored two ways at once:
- As a keyed hash, so that when the same number is entered again we recognise the returning guest. A hash cannot be reversed into the number it came from.
- Encrypted, so a message can actually be sent. Decryption happens in memory, at the moment of sending, and the plain number goes to our SMS carrier and nowhere else.
The last four digits are kept separately and unencrypted, because that is what a member and a staff member use to identify an account at the counter. Screens in the dashboard show only those four digits.
Why we are allowed to text you
Canada’s Anti-Spam Legislation requires express consent before a commercial message is sent, and Viktr enforces it in code rather than by policy. A guest record with no recorded consent timestamp cannot be sent a message — the send path checks for it and refuses. Separately, no shop can send a guest more than two messages in any seven-day period, and that limit is counted server-side rather than trusted to the sender.
Every message identifies the shop it came from and ends with “Reply STOP anytime.” Replying STOP records the withdrawal against that guest immediately and permanently.
Who we share it with
Only the processors that make the product work, and only what each one needs:
| Processor | What it receives |
|---|---|
| Twilio | The guest’s number and the message body, at the moment of sending |
| Neon | The database, which holds everything described above |
| Owner sign-in; and, for menu reading, the PDF a shop uploads | |
| Groq | Shop profile and audience size when drafting a campaign — never guest numbers |
| Upstash | Scheduling and rate-limit counters, keyed by identifiers rather than numbers |
| Vercel | Hosting and request logs |
The models that draft campaign messages are given the shop’s own profile and the size of an audience. They are never given a phone number, a guest record, or a customer list. We do not sell personal information to anyone, and we do not use it for advertising.
One shop cannot see another’s guests
Separation between businesses is enforced by the database itself, not by application code remembering to filter. Every table holding guest data carries a row-level security policy that restricts it to a single business, and the application connects under a role that cannot bypass those policies. A query that forgets which shop it is asking about returns nothing rather than someone else’s customers.
How long we keep things
- Guest memberships — for as long as the shop’s account is active. If a shop closes its account we delete its guest records within 90 days.
- Withdrawn consent — the opt-out record itself is kept indefinitely. It has to be: it is the proof that we must not message that number again.
- Request logs — 30 days.
- Owner accounts — until you delete them, then within 30 days.
Your rights
Under PIPEDA, and under the provincial private-sector laws in Quebec, Alberta and British Columbia, you can ask what we hold about you, ask us to correct it, ask us to delete it, and complain to the Office of the Privacy Commissioner of Canada. Ask us first and we will answer within 30 days.
A guest asking about their own membership should include the shop’s name and the phone number in question. Because the number is stored hashed, we can only find a record by hashing the number you give us — which means we cannot answer a request that does not include it.
Where data lives
Our database and application run in the United States. Personal information is therefore stored and processed outside Canada and may be accessible to foreign courts and law enforcement under the laws of that country. We use processors that offer contractual protections comparable to Canadian requirements.
Children
Viktr is for businesses and their adult customers. We do not knowingly enrol anyone under 16. Tell us and we will remove the record.
Changes
If we change this policy in a way that affects how personal information is used, we will email account holders before it takes effect. The date at the top of this page is the date of the last change.