Privacy Policy – ABMBooks
Effective Date: November 2023 · Last Updated: July 7’th, 2026
ABM Technologies Inc. (“ABMTechnologies”, “ABMBooks”, “we”, “us”, or “our”) is committed to protecting the privacy of the individuals and businesses who use our bookkeeping, payroll, invoicing, and expense-management services. This Privacy Policy explains how we collect, use, disclose, and protect your personal and business information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and any applicable provincial privacy laws.
Your data belongs to you. ABMBooks acts as a custodian and processor of the information you and your business entrust to us. We do not sell, rent, or trade your personal or business information. We use it only to operate and improve the services you have signed up for, as described below.
1. Information We Collect
We collect and store only the information needed to provide our services:
A. Account and Identity Information
Full name, company name, email, phone number
Government-issued IDs and Business Numbers (e.g., CRA BN, GST/HST number)
Passwords and login credentials (never stored in plain text)
B. Financial and Payroll Data
Employee names, Social Insurance Numbers (SINs), salaries, hours worked
Direct-deposit and bank account details
Invoices, quotes, expense records, and supplier payment details
Tax-related information (T4, ROE, PD7A, GST/PST filings)
C. Location Data (only when enabled by your employer)
If your organization turns on geofenced time tracking, we collect GPS coordinates at the moment an employee clocks in or out in order to verify the punch occurred at an approved work location. See Section 6.
D. Mobile Device Data (mobile app users)
A push-notification token that lets us deliver alerts (e.g., a new shift or an available pay stub) to your device. Notification content deliberately excludes sensitive financial details.
E. Technical Information
IP address, browser type, device information
Usage logs and diagnostic data
Cookies and session identifiers (for performance and security)
2. Purpose of Collection
Your data is used only for the following purposes:
- Provide, support, and enhance our payroll, bookkeeping, invoicing, and expense software
- Automate compliance with the CRA, provincial tax bodies, and payroll laws
- Process invoice payments and authorized supplier payments
- Verify attendance at approved work locations, where geofenced time tracking is enabled
- Deliver service alerts, updates, and support responses
- Detect and prevent fraud and unauthorized access
- Analyze aggregate usage trends to improve product performance.
3. Consent & Your Choices
By using our service, you consent to the collection and processing of your information as described. You may:
- Withdraw consent (this may affect service delivery)
- Request deletion of non-essential data
- Opt out of marketing communications at any time
- Disable device location permissions or push notifications for ABMBooks mobile application(s) at the device level at any time
4. Disclosure of Information — We Do Not Sell Your Data
We never sell, rent, or lease your personal or business information to anyone. We disclose information only in these limited circumstances:
- To you and the users your organization authorizes. Access is strictly controlled by role (see Section 5).
- To service providers who help us operate the platform (for example, payment processing, cloud hosting, and notification delivery). These providers act on our instructions, are bound by written confidentiality and data-protection obligations, and may use your information only to provide their service to us — never for their own purposes. A summary of these providers is in Section 7.
- To the CRA or government authorities where legally required, or to comply with a valid legal request.
- To legal or regulatory bodies in connection with fraud investigations or legal claims.
5. Data Storage & Protection
Protecting your information is core to how ABMBooks is built, not an afterthought. Our safeguards include:
- Canadian data residency — your data is stored on secured servers located in Canada.
- Encryption in transit and at rest.
- Strict tenant isolation — each organization’s data is logically separated, and every request is validated against your authenticated session so that one customer can never access another customer’s records.
- Enterprise-grade authentication — sign-in is managed through a dedicated enterprise identity provider.
- Role-based access control — both customer users and internal ABMBooks staff receive only the minimum access their role requires.
- Secrets management — credentials and encryption keys are held in a managed, access-controlled key vault, separate from application data.
- Hardened application layer — security response headers, protections against over-submission of data, and error handling designed to never expose internal system details.
- Secure, regular backups and ongoing security review.
6. Location Data
Location tracking is off by default and is used only where an employer explicitly enables geofenced time tracking for their organization.
We collect a GPS location only at the moment an employee clocks in or out, to confirm the punch occurred within an approved work location. We do not track employees’ location continuously or in the background.
Location access requires the employee to grant device permission, which can be declined or revoked at any time in device settings.
Employers who enable this feature are responsible for informing their employees and for complying with applicable employment and privacy laws.
Map imagery and address search in our work-location picker are provided by OpenStreetMap and its geocoding service (see Section 7).
7. Third-Party Sub-Processors
To deliver our services we rely on a small number of trusted, reputable providers. We share only the information necessary for each to perform its function, under strict contractual protections, and none of them are permitted to use your data for their own purposes. These include:
- Payment processing — card payments are processed by Moneris, a leading PCI-DSS-compliant Canadian payment processor. We do not store full card numbers on our systems.
- Bank payments — authorized supplier payments are made via Pre-Authorized Debit (PAD) through regulated banking channels, only under mandates you have expressly authorized.
- Authentication — identity and login security (Auth0).
- Mobile notifications — push-notification delivery via the applicable mobile platform services (Expo, and Apple/Google notification services). Notification content excludes sensitive financial information.
- Mapping — OpenStreetMap map tiles and Nominatim address search, used only within the work-location picker.
8. Access, Correction & Retention
You may request:
- A copy of your personal data
- Correction of inaccurate information
- Deletion, where permitted by law
- Financial and payroll records are retained for at least 7 years to comply with CRA recordkeeping requirements, unless a longer period is required by law or you request otherwise for non-essential data.
9. Children’s Privacy
Our services are not intended for individuals under the age of 14, and we do not knowingly collect data from minors.
10. Data Breach Notification
In the event of a data breach that poses a real risk of significant harm to an individual, we will:
- Notify affected users as soon as feasible,
- Report the breach to the Office of the Privacy Commissioner of Canada (OPC), as required by PIPEDA, and
- Keep a record of all data breaches, whether reportable or not, for a minimum of 24 months.
11. Updates
We may update this Privacy Policy from time to time. You will be notified of material changes via email or dashboard alert, and the “Last Updated” date above will reflect the most recent revision.
12. Contact Us
For privacy questions, data access requests, or complaints:
Email: info@abmbooks.com
Address: Office 200 – 500 Portage Ave, Winnipeg, MB R3C 3X1.
Suite 120, 2710 17 Ave SE, Calgary, AB T2A 0P6.
