Privacy Policy
Effective date: June 12, 2026
This Privacy Policy explains how Canopy Solutions LLC, a New York limited liability company (“Canopy,” “we,” “us,” or “our”), collects, uses, shares, and protects information in connection with the Canopy platform — the Bloom back-office application, the Roots loyalty application, the runcanopy.app website, and related services (the “Services”).
We collect information from two main groups: Operators (the businesses that use Bloom and Roots, and their staff) and End Users (retail customers of participating stores who join a loyalty program operated through Roots). Questions or requests: support@runcanopy.app, or by mail at Canopy Solutions LLC, 10 Stella St, Matamoras, PA 18336.
1. Our role: controller and processor
For Operator account data and our websites, Canopy decides how information is used. For End User data processed inside an Operator’s loyalty program — enrollment records, points, activity — the Operator is the controller and Canopy is a processor (service provider): the store decides what program to run, whom to enroll, and what messages to send; Canopy provides the platform. Operators are responsible for obtaining lawful consent from their customers; review your store’s own privacy practices for how it uses your information.
2. Information we collect
From Operators
- Account information — business name and address, representative name, email, phone, industry, point-of-sale system, and other signup details.
- Authentication information — login email, password hashes (never plaintext), session tokens, IP addresses, browser user-agent, and login timestamps.
- Business data — point-of-sale transactions, fuel data, distributor invoices and EDI files, bank settlement files, expenses, schedules, and similar records the Operator connects or uploads.
- Uploaded documents — photos and PDFs of invoices and similar paperwork submitted to the document-reading feature.
- Payment information — handled by our payment processor when a subscription is billed; we do not store full payment-card numbers.
- Usage and support — features used, settings configured, actions taken in the dashboard, and messages sent to support.
From End Users (customers of our Operators)
- Identity information — first and last name, date of birth (used for the program’s age gate), mobile phone number, and optionally email address.
- Consent records — the exact text of any consent you were shown, the timestamp, the IP address and device user-agent at the time, the channel (SMS or email), the terms version you accepted, and any later opt-out events. This is kept as an append-only audit log for compliance with the TCPA and similar laws.
- Membership and activity — which stores you joined, points balance, offers issued and redeemed, transaction activity at participating stores, and timestamps.
- Communication records — messages sent to you on behalf of a store (including message bodies), delivery status from our SMS provider, and any STOP or HELP replies.
- Portal and tablet data — portal session information and pages viewed; for in-store tablets, the device token, paired store, and the cashier associated with actions requiring authorization.
Automatically
- Log and device data — IP address, browser type, operating system, referring URL, pages accessed, and timestamps, used for security and troubleshooting.
- Cookies — only strictly necessary cookies (authentication, session management) and functional preferences. We do not use third-party advertising cookies, tracking pixels for behavioral advertising, or cross-site tracking.
What we do not collect
We do not collect Social Security numbers or government IDs, payment-card numbers (our payment processor handles those), biometric data, precise GPS location, or your browsing history outside our Services. We do not knowingly collect data from anyone under 18 (see Section 11).
3. How we use information
- Providing the Services — dashboards, reconciliation, reporting, loyalty enrollment and points, issuing and redeeming offers, and sending the messages stores have configured.
- Communications — transactional messages (account setup, password resets, enrollment and reward notices) and, only with documented consent, marketing messages (see Sections 4 and 5).
- AI document reading — invoice photos and PDFs are processed by a third-party AI provider (currently Anthropic) acting as our processor, to extract vendors, line items, and amounts for the operator’s review. Per our API agreement, this content is not used to train AI models.
- Compliance — maintaining the TCPA consent audit trail, responding to legal requests, complying with breach-notification laws, and enforcing our Terms of Service.
- Security and abuse prevention — detecting fraud, securing the Services, and maintaining audit logs of staff and operator access. Canopy staff access customer data only for legitimate operational purposes, and that access is logged.
- Service improvement — using aggregated or de-identified information that does not identify any person or store.
4. How we share information
We do not sell personal information — and have not in the preceding twelve months — and we do not share it with third parties for their own marketing or for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and similar laws.
- With the store you enrolled with (End Users) — each Operator sees the enrollment, points, consent status, and activity of members of its own program. Operators cannot see your data from other stores, even if you joined more than one.
- With service providers acting on our behalf — SMS delivery (Twilio), email delivery (Resend), AI document processing (Anthropic), payment processing, and hosting infrastructure — each contractually limited to processing data only to provide their service to us.
- For legal reasons — to comply with a subpoena, court order, law, or regulation; to protect any person’s safety; to prevent fraud or abuse; or to investigate or defend legal claims.
- In a business transaction — if Canopy is acquired or merges, or sells substantially all its assets, information may transfer to the acquiring entity subject to this policy; we will notify you of material changes.
- With your consent — anything else, only with your specific consent.
5. Mobile numbers and text messaging
This section applies to mobile information collected through the Roots loyalty SMS program (see the SMS Program terms).
- No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.
- Text-messaging originator opt-in data and consent are never shared with, or sold to, any third party — the sharing categories in Section 4 exclude this data, except for the messaging service providers and carriers strictly necessary to deliver the messages you opted in to receive.
- Your mobile number is used only to operate the loyalty program(s) you joined: enrollment confirmations, points and reward updates, and offers from your store. Each store’s program has independent consent — opting out of one store does not affect another.
- You can opt out at any time by texting STOP, and get assistance by texting HELP or emailing support@runcanopy.app. After a STOP request we send one final confirmation message and then stop messaging you. We keep a record of your opt-out so we can honor it.
- Message frequency varies; message and data rates may apply.
6. Email
We send transactional email (account setup, password resets, enrollment and account notices) as part of operating the Services. Marketing or promotional email is sent only where permitted by law and your choices; every marketing email identifies Canopy as the sender, includes our postal address (10 Stella St, Matamoras, PA 18336), and contains a working unsubscribe link. Unsubscribe requests are honored within 10 days, and opting out of marketing does not stop transactional notices your account requires. Email addresses and message contents are processed by our email delivery provider solely to deliver our messages.
7. Data retention
- Consent and opt-out records are retained as long as necessary to demonstrate compliance with the TCPA and similar laws — this protects both you (proof you opted out) and us (proof of compliance). These records are append-only.
- Operator business data is kept while the account is active; after termination, operators may request an export within 30 days, and we delete or de-identify account data within a reasonable period after a verified deletion request, subject to the items below.
- Transaction and financial records may be retained up to seven years for tax and accounting purposes.
- Audit logs of staff and administrative access are retained for at least three years.
- Backups may contain residual data for a limited period (typically up to 30 days) before rotation.
- Legal holds — information needed to defend legal claims is retained until the relevant limitation periods expire.
If you leave a loyalty program and ask the store or us to delete your membership, we delete or de-identify your enrollment information, keeping only what is needed to honor your opt-out (for example, your number on a do-not-message list) or to meet the obligations above.
8. Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information, including: encryption in transit (TLS/HTTPS); hashed credentials and encrypted integration secrets; role-based access controls (operator, staff, tablet device, cashier) with per-store scoping; signed, authenticated data-ingestion channels; append-only audit logs of consent events and staff access; tenant isolation so one Operator cannot access another’s data; and timely security updates. No method of transmission or storage is perfectly secure; we encourage strong, unique passwords.
If a security breach affects your personal information, we will notify you as required by applicable law, including New York’s SHIELD Act and Pennsylvania’s Breach of Personal Information Notification Act, and will notify regulators where required.
9. Your rights and choices
We honor the following for all users in the United States, regardless of state of residence:
- Know and access — ask what personal data we have about you and receive a copy in a portable format.
- Correct — request correction of inaccurate data (operators can edit account details in Settings).
- Delete — request deletion, subject to the retention exceptions in Section 7.
- Opt out of marketing — text STOP to any SMS, use the unsubscribe link in any marketing email, adjust portal preferences, or email us. Store programs have independent consent and are managed separately.
- Opt out of “sale”/“sharing” — not applicable: we do not sell personal data or share it for cross-context behavioral advertising.
- Non-discrimination — we will not discriminate against you for exercising any right.
How to exercise these rights
Email support@runcanopy.app with the subject “Privacy Request,” or write to the address below. We respond to verified requests within 45 days. Verification typically means confirming control of the phone number or email on the account. You may use an authorized agent with written proof of authorization; we may still verify your identity directly. If we decline a request, we will explain why; you may appeal by replying within 30 days, and we will respond to the appeal.
10. State-specific disclosures
California (CCPA/CPRA)
In the preceding twelve months we collected these categories of personal information, for the purposes in Section 3, shared only as described in Section 4: identifiers (name, phone, email, IP address); customer records (date of birth, transaction history); commercial information (points, redemptions); internet/network activity (portal usage, login records); approximate geolocation (from IP); and electronic communications (SMS message content). We collect no biometric, precise-geolocation, or inference data, and we do not use sensitive personal information beyond permitted purposes. We do not sell or share personal information as the CPRA defines those terms. California residents may exercise the rights in Section 9.
Virginia, Colorado, Connecticut, Texas, and similar states
Residents of states with comprehensive privacy laws have rights materially similar to Section 9, which we extend to everyone. Use the same contact and appeal process.
New York
We maintain the reasonable safeguards required by the New York SHIELD Act and follow New York’s breach-notification requirements, including notice to the Attorney General where required.
Pennsylvania
We follow Pennsylvania’s Breach of Personal Information Notification Act for security incidents affecting Pennsylvania residents.
11. Children
The Services are for business users and adult consumers; they are not directed to anyone under 18, and we do not knowingly collect their information. Loyalty enrollment collects a date of birth and enforces the program’s age gate. Stores selling age-restricted products remain responsible for age verification at the point of sale. If you believe someone under 18 has provided us information, contact us and we will delete it.
12. Do Not Track and Global Privacy Control
We do not respond to Do Not Track signals because there is no settled standard for interpreting them. We honor opt-out preferences expressed through the Global Privacy Control where applicable — though note we do not sell or share personal data in any case.
13. International users
The Services are intended for use in the United States, and information is processed in the United States. If you are located outside the United States, please do not use the Services.
14. Changes to this policy
We may update this policy from time to time. We will post the revised version here with a new effective date, and for material changes we will notify operators through the Services or by email (and End Users by message where appropriate). Continued use after the effective date means you accept the updated policy.
15. Contact
Canopy Solutions LLC
10 Stella St, Matamoras, PA 18336, United States
support@runcanopy.app