Skip to content

FoodPlug Privacy Policy

Last updated: September 2, 2026

This Policy explains how FoodPlug E-Services Inc. ("FoodPlug") collects, uses, discloses, retains, and protects personal information for Customers, guest Customers, Vendors, Vendor staff, visitors, support contacts, and other Users.

1. Accountability and roles

FoodPlug is responsible for personal information under its control. Our Privacy Officer oversees this Policy, requests, complaints, provider review, and incident response.

Vendors are independent businesses and may separately control information received for fulfilment, accounting, support, safety, or lawful marketing. Contact the Vendor about its independent practices.

Privacy contact: hello@myfoodplug.ca, subject “Privacy Request”
Attention: Privacy Officer
Mailing address: 19572 Fraser Way, Pitt Meadows, BC V3Y 0A9, Canada

Which privacy laws apply

FoodPlug operates in Canada and is subject to the federal Personal Information Protection and Electronic Documents Act (PIPEDA).

Where you are in a province with its own substantially similar private-sector privacy law, that law may apply to FoodPlug instead of or alongside PIPEDA. Those provinces are Quebec (the Act respecting the protection of personal information in the private sector), British Columbia, and Alberta (each a Personal Information Protection Act). Provincial health-information laws may also apply to specific records.

FoodPlug is not a bank, money-services business, or other federally regulated financial institution, and the financial record-keeping rules that apply to those businesses do not apply to FoodPlug. Where a payment provider is subject to those rules, the obligation is the provider's, not FoodPlug's.

2. Information we collect

Information you provide

We may collect name, email, phone, credentials, business and storefront details, ownership and authority information, registrations, licences, permits, business numbers, GST/HST registration status and effective dates, product tax classifications, tax-collector status, insurance information, billing and payout details, menus, prices, ingredients, allergens, images, Orders, fulfilment locations, delivery address, messages, reviews, support, complaints, refunds, disputes, safety incidents, and marketing preferences.

Allergy, dietary, and health-related Order instructions may be sensitive. Submit only information necessary for the Vendor to address the Order.

Vendor verification documents

If you are a Vendor, FoodPlug may ask you to upload documents as evidence for FoodPlug's own manual review, such as a food permit or operating approval, a food-safety training certificate, or another document FoodPlug specifically asks you for.

Why we collect them. For one purpose only: so a person at FoodPlug can look at them and decide whether to show a "Documents reviewed" note on your storefront. FoodPlug is not a licensing authority. We do not inspect you, approve you, or check your document with any government body, and we do not share what you send with any authority. Meeting the food-safety and business rules set by your province and municipality is your responsibility.

What we do not collect this way. FoodPlug does not ask you to upload government identification, proof of address, banking documents, ownership documents, or a date of birth. Those are collected by our payment provider, directly, and FoodPlug never receives or stores them.

Who can see them. Only FoodPlug staff with a compliance-review role. Documents are stored privately, encrypted at rest where our storage provider supports it, and are never published, indexed, or linked from a public page. A reviewer opens one through a link that expires within minutes and is created fresh each time it is used. Customers never see them.

If we cannot accept one. We tell you which of a fixed set of reasons applies, and you can send a replacement. Your account is not closed and your storefront is not removed because a single document was not accepted. Section 9 sets out how long we keep one we could not accept.

Payments, payouts, and verification

Stripe or another provider may collect card, bank, legal name, address, date of birth, government identification, ownership, tax, transaction, fraud, sanctions, and verification information directly.

FoodPlug may receive tokens, limited card or bank details, connected-account identifiers, capability and verification status, outstanding requirements, transaction, refund, dispute, payout, and risk results. FoodPlug does not intend to store full card numbers or online-banking credentials where a provider handles them. FoodPlug does not build identity-verification forms, does not receive the documents a Vendor uploads to the payment provider, and does not store copies of them.

Manual transactions and External Records

We may collect transaction origin, payment method and status, amount, dates, counterparty details, references, receipts, notes, links, audit history, and the identity of a user who created or changed a record. We use this to distinguish facilitated transactions from bookkeeping records, calculate fees, reconcile balances, prevent misuse, support Users, and preserve evidence.

Automatic information

We may collect IP address, browser, device, operating system, pages and features used, referral URL, session and authentication information, approximate location from IP, cookies, and error, performance, security, and audit logs.

Third parties

We may receive information from Vendors, payment and identity providers, authentication services, delivery providers, analytics and error-monitoring services, fraud services, public registries, government sources, and other Users involved in an Order or complaint.

3. Purposes

We use information to provide and secure accounts; publish storefronts; transmit Orders; facilitate payments, payouts, refunds, and disputes; coordinate fulfilment; send service messages; provide support; verify Vendors and authority; determine whether a Vendor or FoodPlug is the legal Product Tax collector; calculate, collect, report, remit, refund, reconcile, and audit tax; prevent fraud and fee avoidance; investigate complaints and safety incidents; conduct recalls; maintain legal, tax, transaction, and audit records; improve performance and usability; create aggregated or de-identified reporting; enforce agreements; and comply with law.

We use information for marketing only where permitted and with required consent.

We obtain meaningful consent where required and explain material collections, uses, disclosures, and consequences. We may rely on another lawful authority where consent is not required, including to perform a contract, prevent fraud, collect a debt, investigate a breach, protect safety, or comply with law where applicable.

Optional analytics, marketing, or other non-essential uses will have an appropriate choice where required. You may withdraw consent subject to reasonable notice and legal or contractual limits. Withdrawal may prevent a feature that requires the information from operating.

5. Disclosure

Vendors and transaction participants

For an Order, we share necessary information with the relevant Vendor and providers, including name, contact information, Order, pickup or delivery details, payment status, and instructions you submit.

Service providers

Providers may support hosting, storage, authentication, email/SMS, payments, banking, payouts, verification, analytics, error monitoring, security, fraud prevention, support, mapping, delivery, legal, and accounting services.

They may process information only for authorized purposes under appropriate arrangements. Payment and identity providers may independently control some regulated processing.

We may disclose information to comply with lawful requests; file tax returns and platform reports; respond to the Canada Revenue Agency or provincial tax authorities; protect Users, FoodPlug, or the public; investigate fraud, safety, privacy, or security; enforce agreements; establish or defend claims; cooperate with regulators and health authorities; or complete a financing, merger, reorganization, sale, or acquisition subject to safeguards.

We may disclose information for another purpose with consent.

FoodPlug does not sell or rent personal information or disclose it for another organization's advertising.

6. Public information

Storefront details and public reviews may be visible to anyone. Vendors should not publish a home address, personal phone number, or other private information unless intentionally required and lawful.

7. Cookies and analytics

FoodPlug may use essential cookies for operation, authentication, security, and preferences and non-essential technologies for performance or analytics where permitted.

Analytics and error tools may receive technical and usage data configured by FoodPlug. FoodPlug will minimize submitted content and personal information sent to those tools. FoodPlug does not use advertising networks or third-party behavioural advertising unless this Policy and required consent are updated first.

Where required, a consent control will allow non-essential technologies to be rejected or withdrawn without disabling essential operation.

8. Marketing and anti-spam

FoodPlug may send necessary account, Order, security, safety, support, and legal messages.

Commercial electronic messages are sent only with a lawful basis and required consent. They identify the sender and provide contact information and a working unsubscribe method. FoodPlug records consent and processes unsubscribe requests within the legally required period.

Vendors must obtain their own consent before independent marketing to Customers.

9. Retention

FoodPlug retains information only as long as needed for the identified purpose, law, tax/accounting, disputes, chargebacks, fraud, safety, recalls, enforcement, and backup recovery.

FoodPlug will maintain a documented retention schedule. As baseline rules, subject to legal review and holds:

  • rejected or expired Vendor documents are isolated from active workflows and deleted or irreversibly anonymized when no longer required for appeal, fraud, safety, or legal evidence;
  • Order, payment, tax, and fee records are retained for the period required by tax, corporate, limitation, and payment rules;
  • support, complaint, dispute, and safety records are retained through the applicable risk and limitation period;
  • verification and identity records are minimized, with sensitive originals handled by the verification provider where practical;
  • security-breach records are retained for at least 24 months from determination of the breach where PIPEDA applies; and
  • backups expire on a controlled cycle and are not returned to active use except for recovery or legal requirements.

When no longer required, information is deleted, anonymized, or securely disposed of. Deleted information may persist for a limited period in encrypted backups until those backups age out on their normal cycle, and is not restored into the live system.

Retention of Vendor verification documents

A document you upload for verification is kept while it is the current evidence behind your review status. If you replace it or close your store, it is deleted.

If we cannot accept a document, we keep it only while it still serves a purpose, and we tell you the date it will be deleted on the page where you uploaded it.

  • Documents we could not read, that were incomplete, that were the wrong kind, that were duplicates, or that had expired: kept up to 30 days from the decision, so you can see what you sent while you prepare a replacement.
  • Documents held for a security review, because the file could not be opened safely or its contents cannot be accepted: kept up to 30 days from the decision, then deleted. While a document is held this way, nobody can open it through FoodPlug, including you and the reviewer who flagged it.
  • Documents flagged for a possible fraud concern, and documents refused for a reason outside the list above: kept up to 90 days from the decision.

90 days is the maximum, not the normal period. Most documents we could not accept are deleted in 30 days. If you send a replacement and we accept it, the one it replaced is deleted 14 days later, or on its original date if that is sooner. We do not extend a deletion date because a replacement arrived.

Legal and fraud holds. We can pause a deletion where we have a documented reason, such as a regulator request, a fraud investigation, or an actual or reasonably anticipated legal claim. A hold is recorded with the reason for it and an expiry date, and it ends on that date unless it is deliberately replaced. A hold cannot be open-ended.

How deletion works. We delete the uploaded file and every copy derived from it. FoodPlug does not create thumbnails, run text extraction, or keep cached or temporary copies of a verification document, so there is one stored file for each one you send and deleting it removes the document.

What we keep afterwards. After a document is deleted we keep only a short record that it was handled: the kind of document, the date you sent it, the date it was decided, the standardized reason it was not accepted, who or what made the decision, the final status, the date it was deleted, and the history of any legal hold. That record deliberately does not include the file, any permit or licence number, or the reviewer's own notes. We keep it so we can show that a document was reviewed and deleted properly.

10. International processing

Providers may process information in Canada and other countries. Foreign courts, law enforcement, or authorities may access it under local law. FoodPlug uses contractual, technical, and organizational safeguards appropriate to sensitivity.

11. Security and incidents

FoodPlug uses reasonable safeguards such as access control, encryption in transit and where appropriate at rest, authentication, logging, least-privilege access, monitoring, backups, provider review, and incident response. Staff access is limited to the role that needs it. No system is completely secure.

Uploaded verification documents are held in private storage that is not publicly readable and is not served from a public address. A reviewer opens one through a link that expires within minutes and is created fresh each time. A file that cannot be opened safely is held so that nobody can open it through FoodPlug at all, and is deleted once the security review window closes. Holding a file this way is not an accusation against the Vendor who sent it, and does not by itself affect their account.

FoodPlug investigates incidents, contains and remediates them, keeps required breach records, and reports to regulators and notifies affected people as soon as feasible where a breach creates a real risk of significant harm or another law requires notice.

Vendors must promptly report incidents affecting FoodPlug Customer information.

12. Your rights

Subject to applicable law, you may request access, correction, information about use and disclosure, withdrawal of consent, deletion, portability, or review of a significant automated decision. FoodPlug may verify identity and may retain information required for Orders, tax, fraud, safety, disputes, or law.

FoodPlug will respond within the period required by applicable law. Where we refuse or delay a request, we will tell you why and how to complain. If dissatisfied, ask the Privacy Officer to reconsider and you may complain to the appropriate federal or provincial privacy regulator.

Vendor verification documents specifically. You can see every document you have sent, and open it, on your compliance page. You correct one by sending a replacement rather than by editing it, because the record of what was reviewed has to stay accurate. You can withdraw a document while it is still waiting for review. Once a document has been reviewed it becomes part of a record we keep for the periods described in section 9, and we will not delete it early where doing so would remove evidence needed for a dispute, a fraud or security review, or a legal hold. We will tell you which of those applies.

To make any of these requests, contact us using the details in section 16.

13. Guest checkout and minors

Guest checkout is not anonymous. FoodPlug collects information needed to submit, fulfil, support, and document the Order.

FoodPlug is not directed to children who cannot legally complete the transaction. A parent or guardian must supervise permitted minor use. Contact us if a child provided information improperly.

14. Automated tools

FoodPlug may use automated tools to detect fraud, prioritize risk, identify unusual activity, calculate fees, or improve the Services. FoodPlug will not make a solely automated decision with a significant legal effect where prohibited without required safeguards.

15. Changes

FoodPlug may update this Policy for changes to practices, providers, Services, or law. FoodPlug will revise the date and provide additional notice for material changes. New consent will be requested where required.

16. Contact and complaints

FoodPlug E-Services Inc.
19572 Fraser Way, Pitt Meadows, BC V3Y 0A9, Canada
Attention: Privacy Officer
Email: hello@myfoodplug.ca
Subject: Privacy Request