Privacy Policy

Version 2026-08-03

Who this policy is for

BoomerangDepot recovers company equipment from departing employees on behalf of employers. That means we hold information about two kinds of people, and your rights are the same either way:

  • Account holders — people at a client company who sign in to use the service.
  • Employees — people whose contact and shipping details an employer gave us so we could arrange a device return. If that is you, you never signed up with us and may not have heard of us before. See or correct what we hold about you.

1. Information We Collect

From account holders: name, email address, and company information.

From employers about their employees: name, email address, phone number, home shipping address, and optionally an internal employee identifier, department, termination date, and free-text notes. We collect this to ship a return kit to the right person at the right address and nothing else.

Automatically, for security: when you sign in we record your IP address, browser and device type, operating system, and the approximate city and country your IP resolves to. This is used to show you your own active sessions so you can spot access you do not recognise, and to detect attacks. We also record login times and which features are used.

2. How We Use Information

To provide and improve our services, arrange and track equipment returns, communicate with you about your account or your return, bill client companies, and keep the platform secure. We do not use personal information to make automated decisions about you, and we do not sell it.

3. Who We Share It With

We do not sell your personal information. We share it only with the service providers below, each of which processes it on our instructions for the stated purpose:

  • Neon (United States) — our database. Holds all of the above.
  • Vercel (United States) — application hosting and analytics.
  • Resend (United States) — sends our email. Receives the recipient name, email address, and the details of the return being discussed.
  • Upstash — rate limiting. Receives IP addresses, briefly.
  • Sentry (United States) — error monitoring. Configured not to collect personal information.
  • Stripe (United States) — billing for client companies. Receives company name and billing contact only, never employee data.
  • Google Analytics — website usage measurement. Receives your IP address and the pages you visit. Analytics and advertising cookies are disabled by default, so no such cookies are set unless you consent.
  • Shipping carriers — receive the employee name and address needed to deliver and collect the return kit.

We require each provider by contract to protect personal information to a comparable standard and to use it only for the purpose we specify.

4. Data Security

We encrypt data in transit (TLS) and at rest. In addition, four particularly sensitive employee fields — street address lines, postal code, and free-text notes — are protected with application-level (field) encryption, so they are unreadable in the database without a separate key. Employee city, province and phone number are not field-encrypted; they are protected by the encryption at rest and the access controls described here.

Access to employee contact and address details is limited to staff at the employer who need it, and every such access by our own staff is logged. We enforce hashed passwords, a strong password policy checked against known breach data, and short-lived rotating sessions.

5. International Data Storage and Transfers

Your personal information is stored and processed on servers in the United States (our database is hosted in AWS US East and our application runs in Washington, DC). As a result, your data may be subject to the laws of those jurisdictions, including lawful access requests by courts, law enforcement, and government authorities there — potentially without notice to us or to you. By using the service you acknowledge this cross-border storage and processing. We take steps to ensure your data receives a comparable level of protection wherever it is handled.

6. How Long We Keep It

We publish our actual retention periods rather than a general statement:

  • Employee contact and address details — permanently erased 90days after the employee record is deactivated, regardless of whether the employer’s account is still open. We keep the name and the fact a return happened so the employer retains a coherent record; the phone number, address and notes are destroyed.
  • Sign-in session records — deleted 30 days after the session expires or is revoked.
  • Security and access logs — kept 365 days, then deleted. These record which staff account accessed which record and when, so that we can investigate any incident.
  • Account holder data — kept while the account is active. You may request deletion at any time.

7. Your Rights

Under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) you have the right to know what personal information we hold about you, to get a copy of it, to challenge its accuracy and have it corrected, and to ask us to delete it. You may also opt out of non-essential communications.

Account holders can download a full copy of their data from the profile page at any time. Employees can request a copy or a correction here — no account needed.

We respond to requests within 30 days. If the information came from your employer, we will also pass your correction to them, because they are the source of it.

8. Contact

Our privacy officer is accountable for our compliance with this policy and with PIPEDA. For any privacy question, request, or complaint, contact info@boomerangdepot.ca.

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.