Skip to main content

Privacy Policy

Effective Date:

Kurli Inc. ("Kurli," "we," "us," or "our") is committed to handling personal information responsibly. This Privacy Policy explains how Kurli collects, uses, discloses, retains, and protects personal information in connection with the Kurli platform, websites, web applications, mobile applications, desktop applications, including the Kurli Retail application ("Retail App"), products, support channels, and related services, collectively referred to as the "Services."

This Privacy Policy applies to business customers that subscribe to the Services ("Merchants"), individuals who access or use the Services on a Merchant’s behalf, including employees, contractors, managers, and in-store staff ("Authorized Users"), website visitors, prospective customers, and other individuals who communicate with Kurli.

This Privacy Policy does not replace a Merchant’s own privacy obligations. Merchants remain responsible for providing any required notices, obtaining any required consents or other lawful authority, and responding to individuals whose personal information the Merchant collects through or submits to the Services.

1. Scope and Privacy Roles

1.1 Information Kurli Handles for Its Own Purposes

Kurli is responsible for personal information that it collects and uses for its own business purposes, including account administration, billing, support, security, service communications, business development, application distribution, service improvement, and compliance.

1.2 Merchant Customer Data

Merchants may submit or generate information through the Services about their customers, employees, contractors, suppliers, transactions, inventory, and business operations ("Merchant Customer Data"). As between Kurli and the Merchant, the Merchant controls the purposes for which Merchant Customer Data is collected and used. Kurli generally processes Merchant Customer Data as a service provider on the Merchant’s instructions, as necessary to provide the Services, and as otherwise permitted by the applicable agreement or law.

Individuals seeking access to, correction of, or deletion of Merchant Customer Data should ordinarily contact the relevant Merchant first. Kurli may refer such requests to the Merchant and will provide reasonable assistance where required by contract or applicable law.

2. Personal Information We Collect

The personal information Kurli collects depends on how an individual interacts with the Services. Kurli limits its collection of personal information to information reasonably necessary for the purposes described in this Privacy Policy or otherwise identified at or before the time of collection.

2.1 Business, Account, and Identity Information

Kurli may collect names, business email addresses, telephone numbers, job titles, account credentials, business names, store locations, licensing or registration information, roles, permissions, and other information supplied during registration, onboarding, verification, account administration, or use of the Services.

2.2 Billing and Payment Information

Kurli may collect billing contact details, billing addresses, subscription selections, Add-On purchases, quantities, invoices, payment status, transaction identifiers, tax information, and limited payment-card details made available by the payment processor, such as card brand, expiry date, and the last four digits.

Full payment-card numbers and security codes are generally collected and processed directly by Kurli’s payment processor rather than stored by Kurli. The payment processor handles that information under its own privacy policy and legal obligations.

2.3 Merchant Customer and Operational Data

Depending on the Merchant’s use of the Services, Merchant Customer Data may include customer contact details, sales and transaction records, inventory records, product information, loyalty or customer relationship information, order details, staff activity, store operations, notes, audit information, and other information entered into or generated through the Services.

Merchants must not submit personal information that is unnecessary for their use of the Services or that they are not authorized to collect, use, or disclose.

2.4 Device, Application, Usage, and Diagnostic Information

When an individual accesses or uses the Services, including the Retail App, Kurli and its service providers may automatically collect technical, device, application, usage, and diagnostic information.

Depending on the device, operating system, application version, configuration, and features used, this information may include IP address, device type or model, operating system and version, application version, browser type, language or locale, device or application identifiers, session identifiers, referring pages, access times, screen or page views, feature usage, application events, user interactions, network information, authentication events, audit logs, crash reports, error reports, performance information, and other diagnostic or security information.

Some of this information may be generated automatically by the Services, the Retail App, the operating system, an application distribution platform, or third-party software libraries and service providers used to operate, secure, analyze, monitor, or troubleshoot the Services.

2.5 Communications and Support Information

Kurli may collect information contained in support requests, emails, chat messages, feedback, survey responses, call notes, diagnostic submissions, screenshots or files voluntarily provided for support purposes, and other communications with Kurli.

2.6 AI Inputs and Outputs

Where a Merchant uses an artificial intelligence or automated feature, Kurli may process the prompts, source material, instructions, generated content, extracted information, feedback, and related technical data required to operate, secure, evaluate, and support that feature.

2.7 Information from Integrations and Other Sources

Kurli may receive information from services connected by a Merchant, payment processors, identity or fraud-prevention providers, application stores, operating-system providers, business partners, publicly available sources, and other third parties where permitted by law. Information received from an integration depends on the Merchant’s configuration and the permissions granted to that integration.

2.8 Retail App Device Permissions and Device Data

The Retail App may request access to certain device capabilities where necessary to provide a feature used by a Merchant or Authorized User. The specific permissions available depend on the device, operating system, application version, Merchant configuration, and features being used.

These permissions may include:

  • Camera access where required to scan barcodes, QR codes, capture images, or perform another Retail App function that requires use of the device camera;
  • Photos, files, and storage access where required to select, import, attach, upload, download, export, save, or otherwise interact with business information or files;
  • Location information, including location information made available by the device or operating system, where required for a Retail App feature, operational workflow, security function, or other functionality identified to the Authorized User when permission is requested; and
  • Other device capabilities where reasonably necessary for a feature of the Retail App and disclosed through the application or applicable operating-system permission request.

The Retail App will request operating-system permission where required before accessing protected device capabilities. Authorized Users can generally manage or withdraw these permissions through their device or operating-system settings. Refusing or withdrawing a permission may prevent the affected feature from functioning properly.

Information accessed through a device permission may be processed locally on the device or transmitted to Kurli or an authorized service provider, depending on the feature being used. Information transmitted to Kurli is handled in accordance with this Privacy Policy.

2.9 App Stores, Distribution Platforms, and Software Providers

The Retail App may be distributed through application stores or other distribution channels, including platforms operated by Apple, Google, or other authorized providers, and may also be made available directly by Kurli.

Where the Retail App is obtained or used through an application store, operating-system platform, or similar distribution provider, Kurli may receive information made available by that provider, such as application installation information, application version information, device information, crash reports, diagnostic information, performance information, or aggregated usage information, subject to the individual’s settings and the provider’s practices.

Application stores, operating-system providers, and other distribution platforms may independently collect and process information under their own terms and privacy policies. Kurli does not control information collected independently by those providers.

Where Kurli provides a direct download of the Retail App, information associated with downloading, installing, updating, authenticating, securing, or using the Retail App may be processed by Kurli and its infrastructure or service providers as necessary to provide, maintain, secure, and support the application.

3. How We Use Personal Information

Kurli may use personal information to:

  • provide, operate, configure, maintain, and support the Services;
  • operate and support Kurli’s mobile and desktop applications, including the Retail App;
  • create and administer Merchant and Authorized User accounts;
  • authenticate users and manage roles, permissions, devices, sessions, and access;
  • associate Authorized User activity with the appropriate Merchant, store, account, role, device, session, transaction, or audit record;
  • synchronize information between the Retail App and Kurli’s systems and maintain the integrity and consistency of Merchant operational data;
  • process payments, subscriptions, Add-Ons, taxes, refunds, and billing records;
  • provide customer support and respond to inquiries or requests;
  • monitor performance, troubleshoot errors, diagnose crashes, and improve reliability;
  • process information obtained through camera, file, location, or other device permissions for the feature or workflow for which access was requested;
  • protect the Services against fraud, abuse, unauthorized access, and security threats;
  • maintain audit trails and support regulatory or contractual compliance;
  • analyze application performance, maintain compatibility, and develop, test, deploy, and support application updates;
  • develop, test, analyze, and improve features and user experience;
  • provide AI-assisted extraction, generation, classification, summarization, curation, recommendation, or operational assistance features requested by a Merchant;
  • send service notices, security alerts, billing messages, application notices, and administrative communications;
  • send marketing communications where permitted by law and honour opt-out requests;
  • enforce agreements, investigate disputes, and establish, exercise, or defend legal claims;
  • comply with applicable legal, tax, accounting, regulatory, and law-enforcement requirements; and
  • create aggregated or de-identified information that does not reasonably identify an individual.

Kurli will not use personal information for a new purpose that is materially different from the purposes described in this Privacy Policy without providing additional notice and obtaining consent where required by law.

Kurli obtains consent where required by applicable privacy law or relies on another lawful authority where consent is not required or would be inappropriate. The form of consent may vary depending on the sensitivity of the information and the reasonable expectations of the individual.

An individual may withdraw consent to Kurli’s future collection, use, or disclosure of personal information, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent may prevent Kurli from providing some or all of the Services.

Authorized Users may manage certain Retail App permissions, including permissions relating to camera, files, photos, storage, location, or other protected device capabilities, through the settings made available by their device or operating system. Disabling a permission may cause features that depend on that permission to become unavailable.

Marketing communications may be stopped by using the unsubscribe mechanism in the message or by contacting Kurli. Kurli may continue to send non-promotional communications concerning an active account, billing, security, application operation, legal notices, or requested support.

5. When We Disclose Personal Information

Kurli does not sell or rent personal information. Kurli may disclose personal information in the following circumstances:

5.1 Service Providers and Subcontractors

Kurli may disclose personal information to service providers that support hosting, databases, backups, payment processing, communications, analytics, application performance monitoring, crash reporting, customer support, security, authentication, application distribution, artificial intelligence features, professional services, and other business operations.

This may include third-party software libraries, software development kits ("SDKs"), APIs, infrastructure providers, analytics providers, crash and diagnostic services, and other technologies incorporated into or used by the Services or Retail App.

Kurli requires service providers that process personal information on Kurli’s behalf to process that information only for authorized purposes and to implement appropriate privacy and security safeguards consistent with applicable law and the nature of the services they provide.

5.2 Merchant Instructions and Integrations

Kurli may disclose information to a third-party service or integration when a Merchant or Authorized User enables that integration, requests the disclosure, or otherwise directs Kurli to do so. The third party’s handling of information is governed by its own terms and privacy practices.

Kurli may disclose personal information where required or permitted by law, including in response to a valid court order, subpoena, regulatory request, law-enforcement request, or other legal process.

5.4 Protection of Rights, Safety, and the Services

Kurli may disclose information where reasonably necessary to investigate fraud, security incidents, unlawful conduct, violations of the Terms of Use, unauthorized account or device activity, or threats to the rights, property, or safety of Kurli, a Merchant, an individual, or another person.

5.5 Business Transactions

Personal information may be disclosed as part of a proposed or completed financing, merger, acquisition, reorganization, sale of assets, or similar business transaction, subject to applicable law and appropriate confidentiality protections.

5.6 Professional Advisers

Kurli may disclose information to lawyers, accountants, auditors, insurers, and other professional advisers where reasonably necessary for them to provide services to Kurli.

5.7 Aggregated and De-Identified Information

Kurli may use and disclose aggregated or de-identified information for analytics, benchmarking, research, service improvement, and business planning, provided the information does not reasonably identify an individual.

5.8 Application Stores and Platform Providers

Kurli may disclose or make information available to an application store, operating-system provider, device platform, or application distribution provider where necessary to distribute, install, update, secure, diagnose, or support the Retail App, or where an Authorized User directs or permits such interaction through the applicable platform.

Where such a provider independently determines how it collects and uses information through its own application store, operating system, account, or device services, its processing is governed by its own terms and privacy practices.

6. Service Providers and Cross-Border Processing

Kurli and its service providers may process or store personal information in Canada and in other jurisdictions. This may include information processed through cloud infrastructure, application distribution services, analytics, diagnostics, communications, artificial intelligence providers, or other service providers supporting the Services.

Personal information processed outside an individual’s province or country may be accessible to courts, law-enforcement authorities, regulators, or national security authorities under the laws of that jurisdiction.

Kurli remains responsible for personal information under its control and uses contractual, organizational, and technical measures designed to require service providers to provide an appropriate level of protection. Kurli also considers the nature of the information, the purpose of the processing, and the risks associated with the service provider and processing location.

7. Artificial Intelligence and Automated Processing

Kurli may use artificial intelligence and automated systems to provide features such as content extraction, classification, summarization, generation, curation, recommendations, and operational assistance.

Kurli may use third-party AI service providers to perform some of this processing. Information submitted to an AI feature may be transmitted to those providers where necessary to produce, secure, or support the requested result.

Kurli does not use Merchant Customer Data to train generalized artificial intelligence models and does not permit third-party AI service providers to use Merchant Customer Data to train their generalized models, except where the Merchant has expressly agreed otherwise. Kurli does not use Merchant Customer Data for unrelated third-party advertising or resale.

Kurli may use limited technical information, feedback, aggregated information, or de-identified information to evaluate, secure, and improve the Services where permitted by law and the applicable agreement.

AI-generated outputs may be incomplete or inaccurate and should be reviewed by an authorized person before being relied upon. Kurli does not use AI to make decisions about an individual that produce legal or similarly significant effects without appropriate human involvement, notice, and safeguards where required by law.

8. Cookies, Local Storage, SDKs, and Similar Technologies

Kurli may use cookies, browser storage, application storage, local device storage, software development kits ("SDKs"), application programming interfaces ("APIs"), pixels, application identifiers, and similar technologies in connection with its websites, web applications, mobile applications, desktop applications, and other Services.

These technologies may be used to:

  • keep users signed in and maintain authenticated sessions;
  • remember settings, preferences, Merchant configuration, and interface choices;
  • support application functionality and synchronization;
  • secure accounts, devices, sessions, transactions, and the Services;
  • understand usage and how features are used;
  • collect crash, performance, diagnostic, and error information;
  • diagnose technical problems and improve reliability;
  • measure application and website performance; and
  • support marketing technologies where implemented and permitted by law.

These technologies may include:

  • Strictly necessary technologies required for authentication, security, billing flow, synchronization, application operation, and other core functionality;
  • Preference technologies used to remember settings, configurations, and interface choices;
  • Analytics and diagnostic technologies used to understand performance, diagnose crashes or errors, measure reliability, and understand how features are used; and
  • Marketing technologies used only where implemented and permitted by law.

Browser, device, operating-system, or application settings may allow an individual to block, restrict, reset, or delete certain technologies or identifiers. Disabling strictly necessary technologies may prevent parts of the Services from functioning.

Where required by applicable law, Kurli will provide a cookie notice, consent mechanism, application permission request, or other appropriate choice before using non-essential technologies or accessing protected device capabilities.

9. Safeguards

Kurli uses administrative, technical, and organizational safeguards designed to protect personal information against loss, theft, unauthorized access, disclosure, copying, use, modification, or disposal. Depending on the nature and sensitivity of the information, these measures may include:

  • encryption in transit and at rest where appropriate;
  • role-based access controls and authentication measures;
  • session, device, and account security controls;
  • logging, monitoring, and audit capabilities;
  • backup, recovery, and business-continuity measures;
  • secure software-development and change-management practices;
  • application signing, update, distribution, and release controls where applicable;
  • vendor due diligence and contractual safeguards;
  • incident-response procedures; and
  • confidentiality and security obligations for personnel and contractors.

No electronic system, application, storage system, or transmission method is completely secure. Kurli cannot guarantee absolute security. Merchants and Authorized Users are responsible for maintaining the confidentiality of credentials, securing devices used to access the Services, using appropriate access controls, installing appropriate application and operating-system updates, and promptly reporting suspected unauthorized activity.

10. Privacy and Security Incidents

Kurli maintains procedures to assess, contain, investigate, document, and respond to suspected privacy or security incidents.

Where an incident affects Merchant Customer Data, Kurli will notify the affected Merchant in accordance with the applicable agreement and law and will provide information reasonably necessary for the Merchant to assess and meet its own obligations.

Where Kurli is legally responsible for the affected personal information, Kurli will notify affected individuals, regulators, or other organizations when required by applicable law.

11. Retention, Deletion, and Anonymization

Kurli retains personal information only for as long as reasonably necessary to fulfil the purposes described in this Privacy Policy, provide and secure the Services, maintain legitimate business records, comply with legal and regulatory obligations, resolve disputes, enforce agreements, and protect Kurli, its Merchants, and the Services.

Retention periods vary according to the type and sensitivity of the information, the Merchant’s configuration, legal or contractual requirements, whether the information is required for an active account, and the systems in which the information is maintained.

Device, application, diagnostic, security, and audit information may be retained for periods reasonably necessary to troubleshoot problems, maintain security, investigate incidents, support Merchant operations, comply with legal obligations, or maintain appropriate business and audit records.

Some information stored locally by the Retail App may remain on a device until it is removed through application functionality, account sign-out, application data controls, uninstallation, operating-system controls, or other applicable device-management procedures. Merchants and Authorized Users are responsible for appropriately securing and managing devices on which the Retail App is installed.

Following account termination, Merchant Customer Data will be handled in accordance with the Terms of Use, the applicable subscription or data-processing agreement, and Kurli’s retention procedures. Data may remain in encrypted backups until those backups are overwritten or deleted through the ordinary backup cycle.

When personal information is no longer required, Kurli will securely delete it, destroy it, or anonymize it, subject to legal, contractual, and technical limitations. Kurli may retain aggregated or de-identified information that does not reasonably identify an individual.

12. Access, Correction, Withdrawal, Deletion, and Complaints

Kurli takes reasonable steps to maintain personal information that is accurate, complete, and up to date where necessary for the purposes for which it is used.

Subject to applicable law, an individual may request:

  • access to personal information Kurli holds about the individual;
  • information about how that personal information has been used or disclosed;
  • correction of inaccurate or incomplete personal information;
  • withdrawal of consent for future processing, subject to legal or contractual restrictions;
  • deletion of personal information where Kurli is not required or permitted to retain it; and
  • review of a concern or complaint regarding Kurli’s privacy practices.

Kurli may need to verify identity before processing a request. Kurli may also decline or limit a request where permitted or required by law and will explain the reason where legally required.

Requests relating to Merchant Customer Data should ordinarily be directed to the Merchant that collected the information. Kurli will assist the Merchant where required by the applicable agreement or law.

Deleting the Retail App from a device does not necessarily delete information previously transmitted to Kurli or stored in a Merchant account. Requests concerning personal information held by Kurli should be submitted using the contact information below. Requests concerning Merchant Customer Data should ordinarily be submitted to the applicable Merchant.

An individual may challenge Kurli’s compliance by contacting the Privacy Officer using the details below. Individuals may also have the right to complain to the Office of the Privacy Commissioner of Canada or an applicable provincial privacy regulator.

13. Merchant and Authorized User Responsibilities

Merchants and Authorized Users are responsible for:

  • providing accurate and current account information;
  • restricting access to authorized personnel;
  • configuring roles and permissions appropriately;
  • protecting passwords, authentication devices, account credentials, and devices used to access the Services;
  • maintaining appropriate device, operating-system, application, and endpoint security;
  • ensuring that personal information submitted to the Services was collected lawfully;
  • providing required privacy notices and obtaining required consent or other lawful authority;
  • appropriately configuring and managing device permissions used by Authorized Users;
  • responding to individuals regarding Merchant Customer Data; and
  • promptly notifying Kurli of suspected unauthorized access, device loss, credential compromise, or misuse.

14. Children and Minors

The Services are designed for business use and are not directed to children. Kurli does not knowingly create accounts for children or solicit personal information directly from them. A Merchant must not authorize a minor to use the Services unless that use is lawful and appropriate for the Merchant’s business.

15. Changes to This Privacy Policy

Kurli may update this Privacy Policy from time to time to reflect changes in the Services, applications, device capabilities, third-party services, legal requirements, or privacy practices. The revised version will be posted with a new effective date.

Kurli will provide additional notice of material changes where appropriate. If a material change introduces a new purpose that requires consent, Kurli will seek that consent before using personal information for the new purpose.

16. Contact the Privacy Officer

Questions, access or correction requests, deletion requests, withdrawals of consent, and privacy complaints may be directed to:

Privacy Officer
Kurli Inc.
111 Bunchberry Way, Brampton, ON L6R2E7
Canada
Email: privacy@kurli.co