Framlyn Privacy Policy
Effective: July 24, 2026
Last Updated: July 25, 2026
This Privacy Policy explains how Framlyn Inc. ("Framlyn", "we", "our", or "us") collects, uses, discloses, retains, and protects personal information through the Framlyn marketplace, mobile applications, websites, APIs, administration tools, communications, and related services (collectively, the "Service").
This document applies to customers, visitors, farmers, merchants, and other approved sellers. Framlyn is accountable for personal information in its custody or control and has designated a Privacy Officer whose contact information appears below.
Privacy at a glance: Framlyn does not sell personal information and does not use personal information to track users across other companies' apps or websites for third-party advertising. Payment-card details are entered through payment-provider interfaces; Framlyn receives transaction identifiers and limited metadata rather than full card numbers or security codes. Seller verification documents are not public.
This document applies to:
- customers who browse, order, pay, and manage addresses or saved payment methods
- farmers or sellers who create storefronts, upload products, complete onboarding, receive payouts, and provide verification materials
If you do not agree with this Privacy Policy, do not use Framlyn.
- Information We Collect
We collect information you provide directly, information created through your use of the platform, and some information from service providers.
1.1 Account and profile information
Depending on how you use Framlyn, we may collect:
- name
- email address
- phone number
- password and authentication credentials
- account type, such as customer or farmer
- profile image or profile-related information
- date of birth and gender when optionally provided in the profile flow
- profile photographs
1.2 Farm and seller information
For farmer or seller accounts, we may collect:
- farm name
- farm address
- map location, latitude, and longitude
- owner or operator name
- farm description and operating details
- pickup, meetup, delivery-region, schedule, and fulfillment instructions
- business structure, legal name, tax residency, business and GST/HST numbers, tax status, producer scale, farm-income status, registrations, licences, permits, exemptions, and related certifications or attestations
- payout onboarding information and payout status
- onboarding and subscription status
- storefront subscription history
- information provided to substantiate claims such as organic, local, certified, licensed, inspected, or exempt
1.3 Verification and onboarding documents
To review and approve farmer accounts, we may collect uploaded verification materials, including:
- government ID
- proof of address
- farm photos
- business or farm-related documents
- any follow-up materials provided during review
We may also store filenames and file metadata, upload source, review status, review notes, requests for clarification, and approval or rejection decisions related to these materials. Camera and photo-library access is requested only when you choose to capture or select an image or document. Verification documents are stored in restricted systems and are not displayed on public storefronts.
1.4 Orders and transaction information
When you place or manage orders, we may collect:
- products viewed, added to cart, or purchased
- order contents and order history
- order status updates
- delivery or pickup details
- meetup details, delivery confirmation information, cancellation reasons, coupons, discounts, fees, and taxes
- payment status
- transaction references, including third-party payment identifiers
1.5 Payment and payout information
Framlyn uses third-party payment providers, including Stripe, to process customer payments, saved payment methods, subscriptions, and farmer payouts.
We do not intend to store raw payment card numbers or card security codes on our backend. Instead, we may store limited payment-related metadata such as:
- Stripe customer or payment method identifiers
- payment intent identifiers
- last four digits of a payment method
- card brand
- expiry month and year
- payout onboarding state
- subscription, featured-placement, billing, refund, dispute, chargeback, and payout records
Stripe and its related services may collect and process payment information directly under their own privacy terms.
1.6 Location and address information
With permission or when you enter or select an address, we may collect:
- saved addresses
- delivery addresses
- selected map coordinates
- address autocomplete requests and geocoded results
- precise or approximate device location used to show nearby farms and personalize location-based results
You can use many location features by entering an address manually. Framlyn does not request background location unless a clearly disclosed feature requires it and applicable app-store and legal requirements are met.
We use this information to improve local farm discovery, order fulfillment, and location relevance.
1.7 Device, usage, and notification information
We may collect technical and usage information such as:
- device tokens for push notifications
- platform or device identifiers
- app usage events
- login and security event logs
- IP address and request metadata
- device ID, operating system/platform, app version, user agent, timestamps, crash or error information, and authentication, verification, and two-factor-security events
1.8 Communications and support information
If you contact us or receive platform communications, we may store:
- customer support messages
- account and order emails
- password reset and email verification events
- push notification records
- support-ticket contents, linked order or farm, status, priority, and internal support notes
- transactional, recall, and promotional communication records, including consent and unsubscribe records where applicable
1.9 Content, preferences, and marketplace activity
We may collect product and farm photographs, product listings, favorites, reviews, ratings, search or browsing activity, cart activity, storefront tags and preferences, and other content you submit.
1.10 Attestation and audit information
When a seller accepts terms or certifies tax, licensing, eligibility, product, or compliance information, we may record the exact attestation, its version, timestamp, user and farm identifiers, IP address, user agent, source, and related metadata. These records help demonstrate consent, certification, and marketplace compliance.
1.11 How we collect information
We collect information:
- directly from you when you create an account, place an order, create a storefront, upload content, contact support, or change a setting
- automatically from your device and use of the Service, subject to device permissions and applicable consent requirements
- from sellers or customers involved in the same order, such as fulfillment updates, complaints, reviews, or dispute information
- from payment, payout, identity, mapping, notification, hosting, security, email, and app-store providers
- from public or official sources when reasonably necessary to verify a seller's business, licence, registration, or compliance claim
- How We Use Information
We use personal information to:
- create and maintain accounts
- authenticate users and secure the platform
- process orders and facilitate marketplace activity
- enable customers to browse farms and buy physical goods
- enable farmers to create storefronts and manage products
- review and verify farmer onboarding submissions
- process payouts and payment setup through Stripe
- process storefront billing and subscription renewals
- send account, order, review, billing, and verification notices
- provide push notifications and email updates
- detect abuse, fraud, suspicious activity, and policy violations
- improve app performance, reliability, and product features
- comply with legal obligations and enforce our terms
- calculate fees, discounts, taxes, refunds, chargebacks, and seller payouts
- administer support tickets, reviews, favorites, promotions, featured placement, and delivery confirmation
- send promotional communications where consent or another lawful basis exists and maintain suppression records after opt-out
- How We Share Information
We may share information in the following categories.
3.1 With other users of the marketplace
When reasonably necessary for a transaction, support, safety, or a legal obligation:
- customers may see farm names, descriptions, product listings, approximate business details, and storefront content
- farmers may receive the customer's name, order contents, fulfillment method, delivery address or selected pickup information, delivery instructions, order status, and a contact method needed to fulfill purchases
We do not publicly display seller verification documents, government identification, private review notes, payout information, tax records, or a home address unless the seller knowingly selected that address as public storefront or pickup information. Where an exact residential location is not needed, Framlyn limits public display to an approximate location or business-service area.
3.2 With service providers
We may share information with vendors and processors that help us operate Framlyn, including:
- Stripe for payments, subscriptions, and farmer payouts
- Firebase or other notification providers for push notifications
- hosting, cloud, database, logging, and infrastructure vendors
- mapping and address tools
- email delivery providers
- storage providers used for public images and private verification documents
Service providers process information for us under their own contracts and privacy terms. Payment networks, financial institutions, and connected-account providers may act independently for some processing they perform.
3.3 For legal and safety reasons
We may disclose information if reasonably necessary to:
- comply with law, regulation, legal process, or government request
- protect users, the platform, or the public
- investigate fraud, abuse, chargebacks, or policy violations
- enforce our legal rights or agreements
3.4 Business transfers
If Framlyn is involved in a merger, acquisition, financing, restructuring, or sale of assets, personal information may be transferred as part of that process, subject to applicable law.
3.5 No sale or cross-context behavioural advertising
Framlyn does not sell personal information for money and the current app does not use personal information for third-party targeted or cross-context behavioural advertising. We will update this Policy and obtain consent where required before materially changing those practices.
3.6 Promotional communications
Framlyn sends promotional emails, texts, or similar commercial electronic messages only with consent or another basis permitted by Canada's anti-spam law. Promotional messages identify the sender, provide required contact information, and include a working unsubscribe method. We process unsubscribe requests as required by law and may retain a suppression record so an opted-out address is not added again unintentionally.
Transactional messages about an account, order, security event, seller review, subscription, payout, recall, or support request may continue after a marketing opt-out when needed to provide the Service or comply with law.
- Legal Basis and Consent
We identify the purposes for collection at or before collection and collect, use, and disclose personal information only for purposes a reasonable person would consider appropriate. Where required by applicable law, we rely on one or more of the following bases:
- your consent
- performance of a contract with you
- compliance with legal obligations
- our legitimate interests in operating, securing, and improving the platform
Some information is required to create an account, complete an order, operate a seller account, meet tax or payment obligations, or protect the marketplace. Optional information and device permissions are identified in context. You may withdraw consent where permitted, but doing so may prevent us from providing a related feature.
- Retention
We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:
- maintain accounts and order history
- complete reviews and resolve disputes
- comply with tax, accounting, payment, or legal obligations
- protect against fraud and abuse
Framlyn uses record-specific retention schedules and considers sensitivity, transaction and dispute periods, tax and accounting obligations, food-safety and recall needs, fraud patterns, litigation risk, and technical backup cycles.
- Account and profile information is generally retained while an account is active and for a limited closure period needed to complete deletion, prevent fraud, and address support or reactivation issues.
- Restricted farmer and marketplace order, payment, payout, invoice, tax, accounting, platform-reporting, refund, dispute, chargeback, attestation, and audit records are generally retained for at least six years from the end of the tax year or calendar year to which they relate. A record is retained longer only where another legal requirement, an unresolved audit, dispute, chargeback, investigation, recall, litigation matter, or active legal hold requires it.
- Seller verification documents are retained for the shortest period reasonably needed for review, follow-up, fraud prevention, and legal or provider requirements.
- Support, safety, recall, complaint, and enforcement records are retained according to the seriousness of the issue and applicable legal or limitation periods.
- Security, access, and diagnostic logs are retained on rolling schedules appropriate to incident detection, investigation, reliability, and audit.
- Backup copies are overwritten or deleted through normal cycles unless preserved for a legal hold or incident investigation.
When information is no longer reasonably required, we delete it, anonymize it so it is no longer reasonably capable of being associated with an individual, or securely restrict access pending deletion. Account deletion does not require deletion of records Framlyn or a seller must lawfully retain.
Retention schedule after account deletion:
| Record category | Normal treatment |
|---|---|
| Profile, saved addresses, favourites, cart, device tokens, credentials, public descriptions and images | Deleted or anonymized after the recovery period displayed when the request is submitted (30 days by default) and resolution of blocking orders or subscriptions |
| Seller verification documents | Deleted after account deletion unless a documented fraud, regulatory, dispute, safety, or legal-hold need requires restricted retention |
| Final customer fulfillment details and review comments | Removed or anonymized when no longer needed for fulfillment, dispute, safety, recall, or legal purposes |
| Seller sales, orders, tax, invoices, payments, payouts, platform-reporting records and accounting ledgers | At least six years from the end of the tax year or calendar year to which the record relates |
| Refund, chargeback, fraud, safety, recall, audit, insurance, litigation and regulatory records | Only for the documented investigation, dispute, contract, limitation, regulatory or legal period that applies to the record |
| Active legal hold | Until the hold is released, even when that is longer than the normal six-year period |
| Minimal deletion audit record | Retained with the restricted ledger to demonstrate the request, recovery period, completion, retained-record deadline, and any legal hold |
- Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the sensitivity of the information, including authentication, authorization controls, restricted administrative access, private storage for verification documents, transport security, and security logging. However, no system is completely secure, and we cannot guarantee absolute security.
You are responsible for maintaining the confidentiality of your credentials and for notifying us if you suspect unauthorized access to your account.
- Your Choices and Rights
Depending on your jurisdiction, you may have rights to:
- access personal information
- correct inaccurate information
- request deletion of certain information
- withdraw consent where processing is based on consent
- object to or restrict certain processing
- request information about how your data is used
- complain about our handling of personal information and receive information about applicable recourse
- for Québec residents, request computerized personal information in a structured, commonly used technological format where the statutory portability right applies, and exercise applicable de-indexation or automated-decision rights
You may also be able to:
- update profile information inside the app
- manage saved addresses
- manage notifications through your device settings
- deny or revoke camera, photo-library, location, and notification permissions in device settings
You can start an account deletion request from the Delete Account section in your Framlyn profile or the public account-deletion webpage. Web requests require email verification. Once confirmed, deletion is scheduled after the recovery period displayed when the request is submitted, which is 30 days by default. Framlyn may change this setting prospectively, but a change does not alter the scheduled deletion date for an existing request. You may cancel from the app before the displayed deletion date. A farmer storefront is hidden when deletion is scheduled so it cannot accept new marketplace activity.
After the recovery period and resolution of blocking open orders or subscriptions, Framlyn deletes or anonymizes ordinary profile information, saved addresses, local payment-method metadata, favourites, carts, push tokens, active credentials, public profile and storefront content, and verification documents that no longer have a documented retention need. Customer fulfillment addresses and review comments are removed from final orders associated with a deleted customer account.
Account deletion does not erase the restricted farmer sales, tax, accounting, platform-reporting, payout, invoice, refund, chargeback, attestation, recall, safety, fraud, audit, dispute, or legal records described above. Retained records are access-restricted, are not used for marketing or ordinary account activity, and are deleted or anonymized when the applicable six-year period or other documented legal period and any legal hold expire.
You may also submit a request to support@framlyn.com with "Privacy Request" in the subject line. We may verify identity, explain a permitted refusal, and provide information about recourse where required.
- Children
Framlyn accounts, purchases, and seller storefronts are intended for people who have reached the age of majority in their province or territory and can enter into a binding agreement. Framlyn does not knowingly allow a child to create an independent account or knowingly collect personal information from a child contrary to applicable law. A parent or guardian who believes a child provided information should contact the Privacy Officer.
- International and Regional Issues
Framlyn and its providers may process and store information in Canada, the United States, or other countries where they operate. Information in another jurisdiction may be accessible to courts, law enforcement, or regulators under that jurisdiction's laws. We use contractual and other safeguards appropriate to the processing.
- Third-Party Services
Framlyn may link to or rely on third-party services, including payment and payout providers. Their privacy practices are governed by their own terms and policies. We encourage you to review them, especially Stripe's policies for payment and payout processing.
- Automated Processing
Framlyn may use rules and risk signals to flag transactions, accounts, documents, or listings for fraud, safety, compliance, or manual review. The current Service does not use solely automated processing to make decisions that have legal or similarly significant effects on users. Before introducing such a system, Framlyn will provide information and rights required by applicable law.
- Privacy Incidents
Framlyn maintains an incident-response process. Where a breach creates a real risk of significant harm, Framlyn will notify affected individuals and the Office of the Privacy Commissioner of Canada as required, notify other regulators where applicable, keep legally required breach records, and take reasonable mitigation steps.
- Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last Updated" date and may provide additional notice where appropriate.
- Cookies, Third-Party Sites, and App Stores
Framlyn websites may use essential cookies or similar technologies for sign-in, security, preferences, and service operation. Non-essential analytics or marketing technologies will be used only with any notice and choice required by law. The Service may link to third-party sites or app stores whose independent privacy practices apply.
- Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact:
Privacy Officer
Framlyn Inc.
Toronto, Ontario, Canada
Framlyn investigates privacy complaints through its internal process. You may also contact the Office of the Privacy Commissioner of Canada or the privacy regulator in your province, including the Commission d'accès à l'information du Québec, where applicable.