Huard
Privacy Policy
Last Updated: August 2026
1. Who We Are
Operator: W. Hasni
Operating As: Huard
Location: MontrΓ©al, QC, Canada
Email: support@huard.app
Huard is an application that helps you track your Costco receipts and get cashback notifications for purchase matches.
We take your privacy seriously. This policy describes how we collect, use, store, and protect your personal data in compliance with Canadian, Quebec, US, and international privacy laws.
2. Data We Collect
π± Account & Authentication
- Full name and email address
- Profile picture (via Google OAuth)
- Password (hashed with bcrypt, never stored in plain text)
- Account creation date and last access
πΈ Receipts & Items
- Receipt photos (temporary storage <1 hour)
- Extracted items (names, SKU, price, quantity)
- Purchase dates (manual entries)
- Purchase history
π³ Payment & Subscription
- Stripe transaction references (transaction ID only, no card details)
- Subscription plan (Free, PRO, Trial)
- Billing dates and renewal dates
- Payment status
π§ Communications
- Email address for cashback alerts and legal notices
- Notification preferences (opt-in/opt-out)
- Email frequency preferences
π Usage Data
- Clicks, interactions with the app (pages visited, actions taken)
- Access dates and times
- Browser type and device type
- IP address (for security and fraud prevention)
3. Legal Basis for Processing
We process your data on the following legal bases:
- Consent: You consent by creating an account or using Huard
- Contract Performance: Processing payments and delivering PRO services
- Legal Obligation: CASL (Canada's Anti-Spam Law) compliance
- Legitimate Interests: Security, fraud prevention, service improvement
4. How We Use Your Data
- β Authenticate your account and maintain secure sessions
- β Extract items from receipts via OCR technology
- β Match your items with active Costco cashback offers
- β Send cashback alerts (3 days and 1 day before expiration)
- β Process your PRO subscription and payments via Stripe
- β Send legally required communications (confirmations, policy updates)
- β Improve the app and your experience (analytics)
- β Prevent fraud and ensure security
- β Comply with legal obligations (CASL, Quebec Law, Federal Law)
5. Sharing Data with Third Parties
Your personal data is shared only with the following necessary third parties:
Google Cloud (Google)
Data Shared: Profile data (name, email, photo via OAuth only)
Purpose: Secure authentication
Compliance: Google Privacy Agreement, GDPR-compliant
Stripe (Payment Processing)
Data Shared: Transaction references, plan, billing dates (zero banking data)
Purpose: PRO subscription payment processing
Compliance: PCI-DSS Level 1, GDPR-compliant, federal law compliant
SendGrid (Email Delivery)
Data Shared: Email address only
Purpose: Sending cashback alerts and legal notices (CASL-compliant)
Compliance: CASL, CAN-SPAM, GDPR-compliant
Anthropic (Receipt OCR Processing)
Data Shared: Receipt photos (temporarily <1 hour)
Purpose: Automatic text extraction from receipts
Compliance: Photos automatically deleted, data processing agreement
Firecrawl (Public Costco Data Scraping)
Data Shared: Zero personal data
Purpose: Extraction of public Costco.ca cashback offers
Compliance: Public data scraping only
Firm Commitment: We NEVER sell your personal data. We do not share, exchange, or archive data with advertisers or third-party marketers.
6. Data Retention
While Your Account Is Active
All your data (profile, items, history) is retained as long as your account exists.
After Account Deletion
- Personal data: Deleted within 30 days
- Receipt photos: Deleted immediately after OCR (<1 hour). Zero archiving.
- Extracted items: Deleted within 30 days
- Stripe transaction logs: Retained 7 years (federal legal requirement)
- Access logs: Retained 30 days for security
Abandoned Accounts
If you abandon a PRO subscription without deleting your account, your data remains intact. You can log back in anytime.
7. Security of Your Data
Your personal data is protected by the following security measures:
- π Encryption in Transit: HTTPS/TLS 1.3 (mandatory)
- π Encryption at Rest: PostgreSQL via Neon, database-level encryption
- π Passwords: Bcrypt hashing with random salt (10+)
- π JWT Tokens: Short expiration (1 week), cryptographic signature
- π API Keys: Stored in protected environment variables (never in code)
- π Access: Multi-level authentication, audit of sensitive access
- π Fraud Prevention: Anomaly detection, blocking of suspicious patterns
Limitation: No system is 100% impenetrable. Keep your password secret and never share your account.
8. Your Rights
Under Quebec's Law on the Protection of Personal Information in the Private Sector, Canada's Federal Privacy Act, and GDPR (if applicable), you have the following rights:
Right of Access
You can request access to all personal data we hold about you.
Right of Correction
You can request correction or update of your inaccurate or incomplete data.
Right of Deletion
You can request deletion of your data, unless we have a legal obligation to retain it.
Right of Portability
You can request export of your data in a structured format (CSV, JSON, etc.).
Right to Withdraw Consent
You can withdraw consent anytime. This does not retroactively affect lawful processing already done.
Right to Unsubscribe (CASL)
Every marketing email contains an unsubscribe link. You can also manage preferences in Settings β Notifications.
How to Exercise Your Rights: Contact support@huard.app. We will respond within 30 days under applicable law.
9. Legal Compliance
π¨π¦ CASL (Canada's Anti-Spam Law, 2014)
- Every commercial email contains an unsubscribe link
- You have explicit control over email types received
- Clear sender identification (support@huard.app, W. Hasni)
- Unsubscribe processing within <10 days
πΊπΈ CAN-SPAM (US Anti-Spam Law)
- Accurate "from" and "reply to" information
- Clear subject line identifying promotional content
- Physical postal address or unsubscribe mechanism
- Honor unsubscribe requests within 10 business days
π¨π¦ Quebec's Privacy Law
- Explicit consent for data processing
- Access and correction of data upon request
- Commission d'accès à l'information (CAI) as recourse authority
π¨π¦ Canada's Federal Privacy Act
- Fair information practices principles
- Data minimization
- Transparency in practices
πͺπΊ GDPR (EU Data Protection)
- If you use Huard from the EU, data is processed under GDPR standards
- Right to be forgotten, data portability, etc.
10. Data Processors
The following third parties process data on our behalf:
- Neon (Database, Canada/USA): Encrypted PostgreSQL storage
- Railway (Hosting, Global): Server infrastructure
- Stripe (Payments, Global): Payment processing
- SendGrid (Email, Global): CASL-compliant email delivery
- Anthropic (OCR, Global): Temporary text extraction
- Google (OAuth, Global): Authentication
- Firecrawl (Web Scraping, Global): Costco.ca scraping
All processors are globally recognized vendors with security certifications (SOC 2, ISO 27001, or equivalent). Data does not leave your jurisdiction without explicit consent.
11. Updates to This Policy
We may update this privacy policy anytime. Minor changes (clarifications, typo fixes) take effect immediately.
For material changes (new data collection, new sharing, basis changes), we will:
- β Notify you by email at least 30 days before
- β Display a notice in the app
- β Give you the option to withdraw consent
Continued use of Huard after changes constitutes acceptance.
12. Children & Minors
Huard is for users 18 years or older. We do not knowingly collect data from minors.
If we discover a minor has created an account, we will delete it immediately. Parents/guardians suspecting minor data collection can contact support@huard.app.
13. International Data Transfer
Huard operates from Canada. Some processors (Google, Stripe, Anthropic) operate globally.
For EU or other users: your data is transferred internationally only if:
- β You have given explicit consent
- β It is necessary to provide our service
- β The destination country has legally recognized equivalent protections