Privacy Policy

Last updated: March 30, 2026

1. Introduction

Phodo ("we", "us", "our") operates the website at phodo.ca and related services (the "Service"). This Privacy Policy explains what information we collect, how we use it, and your choices.

2. Information We Collect

2.1 Account Information

When you register, we collect your email address and the password you create. You may also provide a username, display name, bio, and avatar image.

2.2 Waitlist

If registration is full, you may join a waitlist by providing your email address, country (United States or Canada), and optionally opting in to email about product updates when more accounts become available. We store this information to notify you about access to the Service; it is not used to create an account until you complete registration yourself.

2.3 Photos & Collections

When you upload photos, we store the image files along with associated metadata such as filename, file size, dimensions, content type, and any captions or capture dates you provide. We also store collection information (names, descriptions, visibility settings).

2.4 Billing Information

If you subscribe to a paid plan, payment processing is handled by Stripe. We store your Stripe customer ID, subscription status, and plan details. We do not store your full credit card number — that is held securely by Stripe.

2.5 Tip Configuration

If you enable tips on your portfolio, you may provide an e-transfer email address and/or an external tip URL. This information is displayed publicly on your portfolio at your discretion.

2.6 Usage Data

We track your storage usage (bytes used and limit) to enforce plan limits. We do not use third-party analytics services. We do not track your browsing behaviour across other websites.

3. How We Use Your Information

We use the information we collect to:

Where required by law, our legal bases for processing include performance of our contract with you, compliance with legal obligations, our legitimate interests in operating and securing the Service, and your consent where applicable.

4. How We Store Your Data

Your account data is stored in a Supabase-hosted database. Your uploaded photos are stored on Cloudflare R2 object storage and served via cdn.phodo.ca.

We take reasonable technical and organizational measures to protect your data, including encrypted connections (HTTPS), httpOnly session cookies, and access controls. However, no method of transmission or storage is 100% secure.

5. Cookies

We use cookies for authentication and for a single optional preference: your reported IANA timezone (so we can format dates and times on our servers in line with your device). That preference is a first-party cookie, not used for advertising or cross-site tracking. For full details, see our Cookie Policy.

6. Data Sharing

We do not sell your personal information. We share data only in these cases:

We do not sell or share personal information for cross-context behavioral advertising.

7. Data Retention

We retain your data for as long as your account is active. When you delete photos or collections, they are moved to a recycle bin and permanently deleted after a retention period. If you delete your account, we will remove or de-identify your personal data and uploaded content within a reasonable timeframe, except where retention is required by law or reasonably necessary for legitimate business purposes such as fraud prevention, security, tax/accounting obligations, backup integrity, or dispute resolution.

Waitlist entries are kept until they are no longer needed for that purpose (for example, after you register, or after a reasonable period if you do not join). You may contact us to request removal from the waitlist before then.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

To exercise these rights, contact us at support@phodo.ca.

We may need to verify your identity before fulfilling certain requests. You may designate an authorized agent to submit requests on your behalf where permitted by law.

9. Children's Privacy

The Service is not directed to children. We do not knowingly collect personal information from users who are not old enough to consent to data processing under applicable law in their jurisdiction. If you believe a child has provided personal information without proper parental or guardian consent, contact us and we will review and delete the data where required.

10. International Transfers

Our service providers may process data in Canada, the United States, and other jurisdictions where they operate. When data is transferred across borders, we take reasonable steps to ensure appropriate safeguards are in place as required by applicable law.

11. Region-Specific Disclosures (Canada and U.S.)

Residents of certain U.S. states and Canadian provinces may have additional privacy rights under applicable law. If there is a conflict between this Policy and mandatory local law, the local law will control to the extent of the conflict.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a notice on the Service. The "Last updated" date at the top indicates the most recent revision.

13. Contact

If you have questions or concerns about this Privacy Policy, contact us at support@phodo.ca.