PoomAt
Sign in
PoomAt · Legal

Privacy Policy

Our commitment to protecting your personal data and privacy

Last updated: September 2, 2026

1. Introduction

Welcome to PoomAt's Privacy Policy. We respect your privacy and are committed to protecting your personal data. This privacy policy will inform you about how we look after your personal data when you visit our website and tell you about your privacy rights and how the law protects you.

This policy applies to all personal information we collect through our website, mobile applications, and related services. Please read this policy carefully to understand our practices regarding your personal data.

2. Data We Collect

We collect and process the following types of personal data:

  • Identity: Name, date of birth (for helpers, verification status)
  • Contact: Email, phone, mailing address
  • Account: Role, preferences, saved settings
  • Business Info: Company name, business registration number, and tax ID (for company helpers)
  • Usage: Pages visited, interactions, device and browser information, IP address
  • Location: On the website only, the Nearby Jobs map may request high-accuracy location through your browser. Only after you grant browser permission, the website sends latitude and longitude to PoomAt to fetch nearby jobs. The native Client and Helper iOS apps do not request GPS or Core Location permission.
  • Manual service-address resolution: When a Client service request needs geocoding or routing, PoomAt sends the full service address entered by the Client to Google Maps. Google returns precise latitude and longitude coordinates, commonly with three or more decimal places, which PoomAt stores with the service request for app functionality. This path is separate from browser GPS and from AI consent.
  • Payments: Tokenized payment method details (brand, last4, expiry); no full card numbers stored
  • Verification: Identity, work-eligibility, certification, and background-check documents you upload directly to PoomAt, plus status and metadata returned by third-party screening providers
  • Helper Interview Evidence: Camera video is required for every spoken or typed answer and is stored with the interview responses and evaluation results. Spoken answers use a server-generated microphone transcript and, on supported web browsers, may store microphone audio in the same evidence clip. For typed answers, the typed text is canonical and the evidence clip is video-only; microphone audio is not requested or stored.
  • Communications and Support: In-app messages, support requests, reports, and related attachments
  • Transactions and Device Data: Purchase history, payout or earnings records, push-notification identifiers, and device identifiers

We also collect, use and share Aggregated Data such as statistical or demographic data. Aggregated Data may be derived from your personal data but is not considered personal data as it does not directly or indirectly reveal your identity.

2.1 Helper Interview Microphone Processing and Private Camera Evidence

The automated Helper interview accepts spoken or typed answers. Camera video is required for every answer and is stored in private AWS infrastructure in Canada. Spoken answers use OpenAI Realtime for live microphone audio and speech transcription; on supported web browsers, that evidence clip also contains the answer’s microphone audio. Typed answers store video-only evidence and do not request or store microphone audio. The on-screen capture indicator tells you which tracks are being stored.

  • Purpose: The spoken-answer transcript or canonical typed answer, together with private camera evidence, shows that the interview was completed and supports experience and safety evaluation, fraud prevention, quality review, and later authorized human identity follow-up when reasonably necessary. Any stored recording audio is supporting evidence only and is never the canonical source of an interview answer.
  • Storage and access: Camera evidence, including microphone audio only when the capture indicator says it is included, is encrypted in transit and at rest in private AWS infrastructure located in Canada. Access is restricted to authorized personnel with a business need and is auditable.
  • Temporary web upload queue: On web, a completed audio-video evidence blob or typed-answer video-only evidence blob may remain in that browser’s IndexedDB upload outbox while a secure upload is retried. PoomAt attempts to delete it immediately after backend verification or a terminal interview result. If deletion is not confirmed, PoomAt deletes entries older than 24 hours the next time PoomAt runs in that browser.
  • Retention: Interview evidence is deleted by default 365 days after capture. If you delete your account, it is scheduled for deletion within 30 days, unless a legal hold, active dispute, fraud investigation, or applicable law requires a longer period.
  • No facial, liveness, emotion, or biometric recognition: Camera evidence is not used for automated facial recognition, face matching, liveness verification, biometric-template creation, emotion detection, or personality inference from appearance. Automated evaluation uses response content to produce an advisory recommendation only. An authorized human reviewer decides Helper and category approval.
  • OpenAI also receives call-connection metadata and a one-way pseudonymous account safety identifier for service delivery and abuse prevention; it does not receive the raw PoomAt account ID. By default, OpenAI may retain microphone audio and transcript content in abuse-monitoring logs for up to 30 days, or longer if required by law or reasonably necessary to protect its services or any third party from harm. Approved ZDR or MAM for the exact OpenAI project generally excludes customer content from those logs, but the disclosed Eyes Off and Safety Retention exceptions may retain content; Safety Retention may permit human review of flagged content to investigate or prevent severe-risk activity. OpenAI may also retain non-content system, usage, security, support, and legal records under its policies.
  • For spoken answers, OpenAI Realtime processes live microphone audio for the interview conversation and transcription. Typed answers do not use microphone audio. Advisory AI evaluation is routed through OpenRouter to the source-pinned google/gemini-3.5-flash model only on Google Vertex AI (Google Cloud). During each answer analysis, the request contains the current answer or transcript, up to four earlier answers to the same root question, the canonical question and question type, and the relevant service-category name. Final evaluation contains the canonical interview questions and eligible answers used for final evaluation, question types, selected service-category names and applicable licensing requirements, and voice transcript confidence when available. PoomAt requires Google Vertex routing with no provider fallback, data collection denied, and a zero-data-retention (ZDR) endpoint. Processing may occur outside Canada, and OpenRouter may keep non-content service metadata under its account and legal policies. Camera or video evidence, raw audio, internal IDs, PoomAt’s local scoring baseline, and separate account, contact, payment, or government-ID records are not added to evaluation requests. Anything you type or say remains part of your answer, so do not include unrelated personal information.

For an accessibility, religious, or privacy accommodation, contact PoomAt Support. For access, deletion, retention, or other privacy questions, contact the Privacy Officer at support@poomat.com.

2.2 Client AI-Assisted Service Requests (Client Voice Currently Disabled)

  • Data and purpose: After you choose AI, PoomAt may process the current typed request, your replies and prior messages in that request conversation, and limited saved-address context for up to 25 addresses. This release accepts compatible attachment images only, which may be sent for visual analysis. Saved street lines and postal codes are excluded unless you type them. These inputs are used to understand, guide, summarize, and draft the request. Client voice is currently disabled, so this release does not collect or transmit new Client microphone audio or create new Client voice transcripts. Older records may contain transcripts created by a past feature and remain subject to the retention terms below.
  • Providers and roles: Current Client text, chat, approved attachment, and request context are sent to OpenRouter as the routing gateway and then only to Google Vertex AI (Google Cloud) as the final model processor. Provider fallback is disabled, so a request fails instead of going to another model provider. No Client voice provider is active in this release. Before enabling Client voice or making another material provider, data, or purpose change, PoomAt will update this notice and require fresh consent before transmission.
  • International processing and provider controls: OpenRouter and Google Cloud may process the disclosed Client text AI information in the United States or other jurisdictions. PoomAt requires OpenRouter to deny data collection and use zero-data-retention routing only to Google Vertex AI, with no provider fallback. Provider handling follows the verified account controls, contracts, and policies; limited account, support, security, abuse-prevention, transaction, or legally required records may still be retained. Client voice providers are not active for this release.
  • PoomAt-side retention and deletion: While your account is active, PoomAt keeps Client AI conversation messages, analysis, media references, and request context while needed to provide and manage the request. When account deletion is accepted after any active service, payment, or dispute blockers are resolved, PoomAt immediately retires the AI conversation in its database, replaces message content, removes AI analysis and request context, removes media references, and queues the underlying stored media for deletion. Completed transaction, legal, financial, fraud, safety, or dispute records may be retained or de-identified only as described in Section 6. Withdrawing AI consent stops new AI processing but does not itself delete service requests already created; use the account-deletion or privacy-request controls in Sections 6 and 7 for deletion or access.
  • Consent, manual choice, and withdrawal: No described Client request content is sent to a third-party AI provider until you turn on an initially unchecked consent control and choose to continue with AI. Declining or closing the notice keeps AI blocked. “Create manually without AI” remains available. You may withdraw from Settings > AI Data Sharing or the equivalent web control; withdrawal blocks new AI-guided requests but does not delete requests already created. Use Sections 6 and 7 or support@poomat.com for access or deletion requests.

PoomAt requires OpenRouter and Google Cloud, including Google Vertex AI, to provide the same or equal protection described in this policy, including data minimization, disclosed-purpose limits, security, access controls, and equivalent onward-transfer protection. PoomAt does not authorize Client AI content for unrelated advertising, profiling, or model training. Limited account, support, security, abuse-prevention, or legally required records remain governed by applicable contracts, verified controls, and provider policies rather than an absolute no-retention promise.

2.3 Helper Stripe Identity Government ID, Selfie, and Biometric Processing

Separate from interview camera evidence: The Helper interview camera processing in Section 2.1 does not perform facial recognition, face matching, liveness verification, or biometric-template creation. Stripe Identity is a separate identity-verification flow. When a Helper starts document verification, PoomAt configures the Stripe-hosted flow to require live capture of a government-issued photo ID and a matching live selfie.

  • Data and purpose: Stripe collects the government-ID and selfie images, information entered by the Helper or extracted from the ID such as name, date of birth and ID number, device and browser information including IP address, fraud signals, and the verification result and insights. Stripe and PoomAt use this information to verify identity, check that the ID is authentic and belongs to the person presenting it, prevent fraud, protect platform safety, and determine Helper identity-verification eligibility.
  • Biometric comparison and access: Stripe uses computer vision and facial-recognition technology to create facial biometric identifiers from the ID photo and selfie and compare them. PoomAt does not receive those biometric identifiers or biometric templates. PoomAt receives verification status and reason or fraud insights and, as the business requesting verification, authorized PoomAt personnel may be able to access Stripe-hosted ID and selfie images, extracted identity data, and verification results. PoomAt requires Stripe to protect this data to the same or an equivalent standard as this policy and limits PoomAt access to authorized personnel with a business need.
  • Controller roles, Stripe use, and international disclosure: PoomAt and Stripe each act as independent controllers of personal data, and Stripe also processes data as PoomAt’s service provider. Stripe may analyze and use the data to operate and improve the services it provides, including risk evaluation and identity verification, under the Stripe Privacy Policy and Stripe Identity terms. Data may be processed in the United States or other jurisdictions and, where needed for evaluation, security, compliance, or law, disclosed to Stripe service providers or government authorities. Read the Stripe Privacy Policy at https://stripe.com/privacy.
  • Retention, withdrawal, redaction, and requests: Stripe states that biometric identifiers used for identity verification, fraud prevention, and security are retained for no more than one year, or until consent is withdrawn if earlier. Stripe typically retains other submitted identity data for three years, including captured images, typed or extracted data, device data, and verification results, but Stripe or PoomAt may retain data longer where applicable law requires or permits it. After PoomAt receives a verified-session webhook, PoomAt requests Stripe redaction; Stripe says redaction may take up to four days. That automatic request is not a promise that every failed, canceled, or incomplete session is immediately deleted. Contact support@poomat.com to request access, correction, deletion, or earlier Stripe redaction, subject to applicable legal retention. You may contact Stripe at privacy@stripe.com to withdraw biometric consent or request deletion of data Stripe controls. Where applicable law requires a non-biometric alternative, PoomAt will make a supported non-biometric procedure available; contact PoomAt Support before starting verification. It is not offered as a general automatic choice where law does not require it.

2.4 Phone Verification, SMS Delivery, and Messaging Preferences

PoomAt uses Twilio and participating telecommunications carriers to send phone-verification one-time passcodes (OTPs), observe their delivery, and receive carrier-required SMS preference commands. This processing occurs when you provide or verify a phone number, request or retry an OTP, or text a PoomAt sending number.

  • Data and purpose: PoomAt and Twilio process the sending and recipient phone numbers, the OTP message content, Twilio MessageSid, message type, sending route, delivery status and timestamps, provider error or failure information, and cost and currency. For an inbound message, Twilio sends PoomAt the sender and recipient numbers, MessageSid, message body, and related request metadata. PoomAt uses these data only to authenticate the phone number, prevent abuse and duplicate delivery, troubleshoot delivery, account for messaging cost, and honor SMS preferences.
  • STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT, REVOKE, and OPTOUT suppress future PoomAt SMS to that number; START, UNSTOP, and YES lift the suppression; HELP returns service and preference instructions without changing the preference. Commands are matched without regard to letter case. Carrier or Twilio filtering may also apply. A valid opt-out remains effective even if the related PoomAt account is later deleted or the number is attached to another account.
  • Providers, access, and international processing: The disclosed SMS data is transmitted to Twilio, its applicable subprocessors, and telecommunications carriers required to route the message. Processing and limited authorized access may occur in the United States, Canada, or other jurisdictions where different laws apply. PoomAt requests message-body discard and recipient-address obfuscation on outbound Twilio requests and configures signed primary and fallback inbound delivery paths. Where Twilio Message Redaction applies, Twilio states that unredacted messaging data remains accessible to its production systems for up to 24 hours and may then remain in separate limited-access storage for compliance purposes. Twilio and carriers may also retain limited routing, billing, security, abuse-prevention, support, or legally required records. PoomAt therefore does not promise zero provider retention.
  • PoomAt retention: A PoomAt SMS cost log keeps the raw recipient phone number and direct PoomAt user link for no more than 30 days for delivery reconciliation, support, fraud prevention, and abuse investigation. An automated retention job then replaces the raw number with a fixed redaction marker and removes the user link. Non-address accounting and delivery facts—including cost, currency, message type, Twilio MessageSid, status, timestamps, and failure classification—may remain as required for financial reporting, security, reliability analysis, disputes, and legal obligations. Access to identifiable records during the 30-day period is restricted to authorized personnel with an operational need.
  • Suppression retention: PoomAt does not copy the raw phone number into its durable SMS suppression ledger. It stores a secret-keyed HMAC recipient digest, which is pseudonymous rather than anonymous, plus current STOP or START state and timestamps. Inbound provider event identifiers and outbound one-shot send-authorization records are retained only with one-way recipient or provider digests, provider time, action, processing or delivery state, and operational timestamps. These records prevent replay or out-of-order commands, maintain the correct preference, support disputes, and demonstrate messaging compliance. An ACTIVE suppression does not expire automatically and is retained until a newer valid START-family command lifts it. A LIFTED state, APPLIED or STALE inbound event, and SENT, FAILED, UNKNOWN, or CANCELLED send-authorization record become eligible for deletion after three years and are then removed by a bounded daily process. PENDING inbound events and RESERVED or DISPATCHING send authorizations are not automatically deleted before they are safely resolved. A global legal hold pauses these deletions for an investigation, dispute, preservation request, or legal requirement. Because these records protect your opt-out, an account-deletion request does not remove an ACTIVE suppression. PoomAt deletes or renders the remaining ledger unlinkable when it is no longer needed for these purposes or the SMS channel is retired, subject to legal requirements.

You may change SMS preference by sending a supported STOP- or START-family command. For access, correction, deletion, or questions about PoomAt records, contact support@poomat.com. Provider-controlled records remain subject to applicable provider, carrier, and legal limits. Twilio Privacy Notice · Twilio Message Redaction documentation

3. How We Use Your Data

We use your personal data for the following purposes:

  • To register you as a new user and create your account
  • To provide and maintain our service, including matching clients with helpers
  • To process and complete transactions, and send related information including confirmations
  • To manage our relationship with you, including notifications about changes to our terms or privacy policy
  • To provide customer support and respond to your requests
  • To personalize your experience and deliver content relevant to your interests
  • To improve our website, products, and services
  • To protect the security and integrity of our platform
  • To verify helper identity and perform safety screening as applicable
  • To comply with legal obligations and resolve disputes

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason compatible with the original purpose.

4. Legal Basis for Processing

We process your personal data on the following legal bases:

  • Contract: To provide the platform and facilitate bookings
  • Legitimate Interests: Platform safety, fraud prevention, product improvement
  • Legal Obligation: Compliance with applicable laws and regulations
  • Consent: Where required (e.g., certain marketing, location services)

5. Data Security

We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used, accessed, altered, or disclosed in an unauthorized way. These measures include:

  • Encryption in transit and at rest for sensitive data
  • Secure authentication and session management
  • Least-privilege access controls
  • Regular security testing and monitoring
  • Third-party assessments where applicable

We have procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

6. Data Retention

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process your personal data, and whether we can achieve those purposes through other means.

When you delete your account, PoomAt disables it immediately, revokes any stored Sign in with Apple authorization, removes direct profile and sign-in data, and ends active sessions. Limited transaction, tax, dispute, fraud-prevention, and safety records may be retained where required by law or reasonably necessary to protect users. Helper interview content is redacted immediately and linked safety evidence is scheduled for deletion within 30 days, subject to legal holds, active disputes, or fraud investigations.

7. Your Rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data, including the right to:

  • Access: Request access to your personal data
  • Correction: Request correction of your personal data
  • Erasure: Request erasure of your personal data
  • Restriction: Request restriction of processing your personal data
  • Portability: Request transfer of your personal data
  • Objection: Object to processing of your personal data
  • Withdraw Consent: Withdraw consent where we rely on consent to process your personal data

You can exercise these rights by contacting us using the details provided in the "Contact Us" section below. These rights may be limited in some circumstances by local law requirements.

We aim to respond to requests within 30 days as required by Canadian privacy laws. Where permitted, we may extend this period with notice if a request is complex or numerous.

See account-deletion instructions or request deletion without signing in.

8. Third-Party Data Sharing

To provide our services effectively, we may share your personal data with trusted third-party service providers and partners. This includes:

  • Payments: Payment processors to store tokenized methods and process transactions
  • Verification: Identity and safety screening providers receive the information needed to perform the screening. Documents uploaded directly to PoomAt are stored and reviewed by PoomAt; provider-hosted verification may instead return status and metadata to PoomAt.
  • Communications: Email/SMS providers for notifications and support
  • Analytics: Providers that help improve performance and user experience
  • Google Maps Platform (manual service-address and routing path, separate from AI consent): When a Client service request needs address resolution for geocoding or routing, PoomAt sends the full service address entered by the Client to Google for geocoding. For distance calculations, routing, matching, and service planning, PoomAt may send precise origin and destination latitude and longitude coordinates to Google. Google also receives request metadata, including the Google Cloud account identifier and requesting PoomAt server IP address. Google may process and retain request logs for operations, support, security, and capacity planning according to its business needs and policies; PoomAt does not control or promise Google’s retention period or processing locations. PoomAt stores saved addresses and resulting precise and coarse location data as needed for app functionality. You can review, change, or delete your saved addresses in address or profile settings and contact support for applicable privacy requests. This manual location path is separate from AI features and AI consent. Google Privacy Policy · Google Maps Platform Terms
  • OpenAI also receives call-connection metadata and a one-way pseudonymous account safety identifier for service delivery and abuse prevention; it does not receive the raw PoomAt account ID. By default, OpenAI may retain microphone audio and transcript content in abuse-monitoring logs for up to 30 days, or longer if required by law or reasonably necessary to protect its services or any third party from harm. Approved ZDR or MAM for the exact OpenAI project generally excludes customer content from those logs, but the disclosed Eyes Off and Safety Retention exceptions may retain content; Safety Retention may permit human review of flagged content to investigate or prevent severe-risk activity. OpenAI may also retain non-content system, usage, security, support, and legal records under its policies.
  • For spoken answers, OpenAI Realtime processes live microphone audio for the interview conversation and transcription. Typed answers do not use microphone audio. Advisory AI evaluation is routed through OpenRouter to the source-pinned google/gemini-3.5-flash model only on Google Vertex AI (Google Cloud). During each answer analysis, the request contains the current answer or transcript, up to four earlier answers to the same root question, the canonical question and question type, and the relevant service-category name. Final evaluation contains the canonical interview questions and eligible answers used for final evaluation, question types, selected service-category names and applicable licensing requirements, and voice transcript confidence when available. PoomAt requires Google Vertex routing with no provider fallback, data collection denied, and a zero-data-retention (ZDR) endpoint. Processing may occur outside Canada, and OpenRouter may keep non-content service metadata under its account and legal policies. Camera or video evidence, raw audio, internal IDs, PoomAt’s local scoring baseline, and separate account, contact, payment, or government-ID records are not added to evaluation requests. Anything you type or say remains part of your answer, so do not include unrelated personal information.
  • Tax Authorities: To comply with tax reporting obligations (e.g., CRA, Revenu Québec)
  • Legal: Authorities or advisors when required by law

Important: We only share data that is necessary for service provision and ensure all third parties maintain appropriate security measures and comply with applicable privacy laws. We never sell your personal data to third parties for marketing purposes.

9. International Transfers

We may transfer your personal data to countries outside your country of residence, including to countries that may not provide the same level of data protection as your home country. We ensure appropriate safeguards are in place to protect your personal data in these cases.

Where required, we use standard contractual clauses or other approved transfer mechanisms. Our service providers may process data in the United States and other jurisdictions. Details are available upon request.

10. Third-Party Links

Our website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements.

11. Contact Us

If you have any questions about this Privacy Policy, you can contact us:

  • By email: support@poomat.com
  • By visiting our contact page

12. Changes to This Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this page. You are advised to review this Privacy Policy periodically for any changes.

13. Canada-wide (PIPEDA) and Quebec (Law 25)

13.1 PIPEDA (Canada)

  • We follow the principles of the Personal Information Protection and Electronic Documents Act (PIPEDA), including accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance.
  • You may request access to, correction of, or deletion of your personal information, subject to legal limitations. We will respond within timelines required by law.
  • We maintain safeguards appropriate to the sensitivity of the information and notify you of breaches as required by law.

13.2 Quebec Law 25 (Act to modernize legislative provisions as regards the protection of personal information)

  • For Quebec residents and processing subject to Quebec law, we comply with Law 25 requirements, including privacy impact assessments for high-risk projects, maintaining a person in charge of personal information, and enhanced transparency.
  • We honor Quebec-specific rights such as the right to be informed, to access, to correction, and to request cessation of dissemination (de-indexing) where applicable under law.
  • Cross-border transfers involving Quebec residents are conducted with appropriate safeguards and disclosures, including information on the jurisdictions where data may be communicated.
  • If a French version of this policy is provided, it will prevail for Quebec consumers in case of discrepancy.
  • For minors under 14 years of age, consent must be given by the holder of parental authority or by a guardian.

14. Marketing Communications (CASL)

We send marketing communications only with your consent, as required by Canada's Anti-Spam Legislation (CASL). You can withdraw consent at any time by using the unsubscribe link in our emails or by contacting us.

  • Transactional or service-related emails (e.g., receipts, booking updates) may still be sent as they are necessary to provide our services.
  • You can update your marketing preferences in your account settings or by contacting support.
  • Postal correspondence: PoomAt Technologies Inc., Vancouver, British Columbia, Canada. Request the current registered mailing address at support@poomat.com.

15. Automated Decision-Making

We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you. If this changes, we will provide clear notice and you will have the right to request human review and to present observations, consistent with applicable laws (including Quebec Law 25).

16. Supervisory Authorities and Complaints

If you are not satisfied with our response to a privacy request, you may contact the relevant privacy authority:

  • Office of the Privacy Commissioner of Canada (OPC): priv.gc.ca
  • Quebec — Commission d'accès à l'information (CAI): cai.gouv.qc.ca

17. Person in Charge of Personal Information (Privacy Officer)

We designate a person in charge of personal information (Privacy Officer). You can reach our Privacy Officer at support@poomat.com.