Gid legal
Privacy Policy
How we collect, use, protect, and give you control over your information.
Last Updated: August 23, 2026 · Version 2026-08-23
1. Introduction
This Privacy Policy describes how Gid Solutions, Inc., a Delaware corporation operating as "Gid AI" ("we", "our", or "us"), with its principal place of business at 390 Henri-Bourassa, Papineauville, Quebec, Canada, J0V 1R0, collects, uses, shares, and protects information when you use the Gid platform, our AI-assisted hospitality operations and employee engagement service.
We built Gid with privacy by design and aim to be transparent about every piece of data we touch. This Policy is read alongside our Terms of Service, our Data Processing Agreement, our list of Sub-processors, and our Acceptable Use Policy.
2. Information We Collect
We collect information through three channels, and no others: directly from you, when you create an account, complete your profile, write a message, upload a file or record audio; from your employer or workspace administrator, who may enter your role, schedule, compensation and employment records on your behalf; and automatically from your use of the service, as your device and our servers generate usage, diagnostic and technical data. We do not buy personal information from data brokers, and we do not collect data about you from advertising networks or social platforms.
Account and Profile Information
- Contact details (name, email, phone number and address)
- Profile details you or your organization provide, such as date of birth, emergency-contact information, role and employment information
- Company information (business name, locations, role and industry)
- Account credentials and authentication data
- Profile preferences and settings
Workforce, Financial and Operational Information
- Scheduling, attendance, time-clock and training records
- Salary, wage, hourly-rate, tip-sharing and other compensation information when your organization uses those features
- Your organization's subscription, billing and transaction records, payment status and processor references. These are held against the organization rather than against an individual user, and Gid does not store raw payment-card numbers
- POS, PMS, reservation, sales and other operational records when the corresponding integrations or features are used
Guest Allergen and Dietary Information
- Allergen and dietary information recorded about menu items, recipes, suppliers and restaurant guests, for reservation, menu, training and operational food-safety workflows
- This information describes dishes and restaurant guests. It is not health information about the people who use Gid, and Gid does not collect health information about its users
User Content and Communications
- Team messages, AI conversations, support requests, feedback and abuse-report notes
- Photos, videos, audio recordings, transcripts, files and documents you upload or create
- Training submissions, task content and other user-generated operational content
Service Usage Data
- Training session participation and progress
- Communication and delivery logs (SMS, email, push, voice and app interactions)
- Performance metrics and feedback
- Feature usage, navigation and other app interactions
Technical Information
- Device and browser information, push tokens and device or other identifiers
- IP addresses, used transiently to rate-limit requests and prevent abuse, and retained only as a one-way hash. Gid does not infer, derive or store any geographic location from them, and the apps request no location permission on either platform
- Usage analytics, app interactions and system performance data
- Crash logs, diagnostics, log files, error reports and security events
3. How We Use Your Information
Service Delivery
- Provide personalized AI coaching and training
- Generate insights and performance analytics
- Facilitate communication between team members
- Optimize scheduling and workforce management
AI Processing (Gid Assistant)
Gid's assistant features are powered by AI models operated by third-party providers. When, and only when, you use an AI feature, the content that feature needs is transmitted to the AI provider selected for that request, for the sole purpose of generating the response returned to you. The providers are named in Section 5.
- What is sent: the text you write in an AI feature; images and documents you submit for analysis; audio you record when you use a voice feature; and the workspace context required for that specific request, which may include schedule, task, training or teammate information relevant to what you asked.
- When it is sent: only at the moment you use an AI feature. Gid does not send your content to an AI provider in the background, on a schedule, or while you are not using the assistant.
- What it is used for: generating the response to that request, and nothing else. The AI providers act solely as our processors. They are contractually prohibited from using your content to train or improve their models, and OpenAI additionally operates under a zero data retention arrangement for our API traffic.
- Your permission comes first: Gid asks for your explicit permission inside the app, on a screen that names the providers and describes the data, before any content is sent to an AI provider. If you decline, AI features remain off and the rest of Gid keeps working. See Section 6 to withdraw permission at any time.
We do not sell your personal information, we do not monetize it, and we do not share it with any third party for advertising, profiling or cross-context behavioural purposes. Your content is never used to train Gid's own models or the models of any provider.
Platform Improvement
- Analyze usage patterns to improve our services
- Develop new features and capabilities
- Ensure system reliability and performance
- Conduct security monitoring and threat detection
Communication
- Send service updates and important notices
- Provide customer support and technical assistance
- Share product updates and new features
4. Data Infrastructure and Security
Cloud Infrastructure
We utilize enterprise-grade cloud infrastructure to ensure data security and availability:
- Google Cloud Platform: Primary hosting and data processing
- Firebase: Real-time database and authentication services
Security Measures
- Encryption in transit and provider-managed encryption at rest; this is not a claim of end-to-end encryption
- Role-based access controls and multi-factor authentication where configured
- Code review, automated checks, monitoring, and incident-response procedures; Gid does not claim an independently certified security program
- Google Cloud and Firebase provider certifications apply only to services included in the providers' published scope; they do not certify Gid
- Provider-managed resilience plus backup and recovery controls where configured
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share data only in these limited circumstances:
Service Providers
- Trusted third-party services that process data on our behalf to operate the platform, subject to their function and our contractual arrangements
- Cloud infrastructure providers (Google Cloud, including Firebase)
- Third-party AI providers, named individually below
- Analytics, diagnostics and monitoring services
- Email, SMS, push-notification and customer-support services
- Payment processors and billing services
Our current provider inventory and processing purposes are listed on the Sub-processors page. We do not treat a service-provider transfer as a sale of personal information.
Third-Party AI Providers
When you use an AI feature, the content described in Section 3 is transmitted to one of the following providers, each of which acts solely as our processor and handles that content only on our documented instructions:
- OpenAI, L.L.C. — prompt content, conversation context and system instructions. Contracted under a zero data retention arrangement, with no training on customer data.
- Anthropic, PBC — prompt content, conversation context and system instructions. No training on customer data.
- Google LLC (Vertex AI / Gemini API) — prompt content, conversation context and system instructions. No training on customer data, under Google Cloud enterprise terms.
These providers receive your content to generate a response and for no other purpose. They do not receive it for their own commercial use, they do not use it to train or improve their models, and none of these transfers is a sale of personal information. Per-vendor terms, data locations and safeguards are itemized on the Sub-processors page.
Protection Required of Every Third Party
We confirm that every third party with whom we share user data — including the AI providers named above, cloud infrastructure providers, communication services and any parent, subsidiary or related entity that may access user data — is bound by a written agreement requiring it to provide the same or equal protection of user data as is stated in this Privacy Policy and as required by applicable app store guidelines and data protection law. Those agreements impose confidentiality, security safeguards, use limited to the purpose we specify, restrictions on onward transfer, and deletion or return of the data at the end of the engagement. Where a provider cannot meet that standard, we do not share user data with it.
Legal Requirements
- When required by law, regulation, or legal process
- To protect our rights, property, or safety
- To prevent fraud or security threats
Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
6. Your Rights and Choices
Access and Control
- Access: Request copies of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your personal data
- Portability: Request eligible personal data in a structured, commonly used format
- Restriction: Limit how we process your information
Withdrawing Your Permission for AI Processing
You can withdraw your permission for AI processing at any time, from inside the app, without deleting your account. Open Settings › Gid Assistant & Data Sharing and choose Withdraw Gid assistant permission.
- The withdrawal applies to your account immediately. Any AI session in progress ends, and no further content from your account is sent to an AI provider.
- Gid keeps working without AI: schedules, tasks, training records and human team chat all remain available. AI-powered features become unavailable or fall back to a limited non-AI behaviour.
- The choice is yours alone and applies only to your account. It does not change your teammates' accounts, and it does not delete workplace records your employer keeps.
- You can grant permission again at any time from the same screen. The same screen also shows your current status and repeats the disclosure of what is sent and to whom.
Permission is requested before any content is sent to an AI provider — during workspace signup, when an invited employee joins, and again at first use of an AI feature if no choice has been recorded. Declining is always available and never blocks access to the rest of the service.
Account Deletion
Account deletion is available to all users in all regions, regardless of whether GDPR, CCPA, PIPEDA, or DPDP applies to you. You can request deletion of your account and in-scope personal data using any of these methods:
- In the app (primary path): Account Settings → Delete My Account. This is the primary in-app control for the account-deletion functionality required by Apple App Store Guideline 5.1.1(v) and Google Play's account-deletion policy.
- Online, no login required: Visit www.gidai.ca/delete-account. The web form is publicly reachable so users who have uninstalled the app can still request deletion.
- By email: Send a request to privacy@gidai.ca with the subject line "Account Deletion Request".
The first-party deletion process targets account credentials, personal profile information, training records, scheduling data, and user-generated content attributable to you within the request scope, including:
- Chat messages and channel posts you authored;
- Voice-agent transcripts and call recordings tied to your account;
- Training submissions and capsule responses;
- Uploaded media (avatars, files, images, documents);
- Any custom configurations or preferences attached to your profile.
There is one 30-day grace window, which starts only after an authenticated in-app request or after you open the one-time link requested from the public web form. During that window, cancel using the link in the grace-start email. After the window, the next scheduled daily purge attempts first-party deletion; failed required steps remain open for retry. An applicable legal hold or an active, unresolved content-safety or security report concerning the deletion subject can pause destructive processing so required evidence is not destroyed. Provider and analytics erasure or lawful-retention verification can remain open after first-party deletion.
- Restricted billing, POS transaction and cash-reconciliation records, tip-sharing/payroll allocations, policies, ledgers, source-integrity evidence, and related audit records for up to 7 years where required for tax, accounting, payroll, compliance, fraud, or legal purposes;
- A restricted deletion-control record that temporarily retains the account identifier, email, and membership proof only while external erasure or retention is being completed and evidenced;
- After that verification, a minimized seven-year deletion lifecycle record containing a hashed email and timestamps;
- Hashed email on our suppression list, so we never re-contact you after deletion.
Retained records are restricted to the stated operational, evidentiary, security, or legal purpose and are not used to continue providing the deleted account. Full retention details are in Section 7.
Communication Preferences
- Opt out of marketing communications
- Control notification settings
- Manage data sharing preferences
7. Data Retention
We retain your information only as long as necessary to:
- Provide our services and support your account
- Comply with legal obligations
- Resolve disputes and enforce our agreements
- Improve our services and security
Typically, we retain:
- Account data: While your account is active and during the single 30-day deletion grace window; first-party deletion is then attempted by the scheduled daily purge, subject to required retries and lawful holds
- Usage analytics: 24 months
- Communication logs: 12 months
- Restricted financial and payroll evidence: up to 7 years where required. This can include billing, closed POS checks and payments, cash sessions and end-of-day reports, tip-sharing allocations, policies, ledgers, source manifests, and related compliance or audit evidence. These records are not used to continue the deleted account; the deletion workflow stores a count-only inventory and Privacy Operations must evidence a necessity review at least annually.
8. International Data Transfers
We primarily operate in Canada, the United States, and India. When we transfer data internationally, we ensure appropriate safeguards are in place:
- Standard contractual clauses approved by data protection authorities
- Adequacy decisions from relevant regulatory bodies
- Certification schemes and codes of conduct
9. Compliance and Regulations
We comply with applicable data protection laws, including:
- GDPR: European General Data Protection Regulation (EU and UK)
- CCPA: California Consumer Privacy Act
- PIPEDA: Personal Information Protection and Electronic Documents Act (Canada, federal)
- DPDP: Digital Personal Data Protection Act, 2023 (India)
- Industry standards: Restaurant and hospitality data protection requirements
9.A Your data subject rights and how to exercise them
Wherever you live, you have the same operational toolkit to control your personal data. We acknowledge rights requests within 72 hours and provide the formal response within 30 days. Account deletions include a separate 30-day grace window in case you change your mind.
Right of access and portability (Quebec Law 25, GDPR Art 20 where applicable, PIPEDA Principle 9, DPDP Section 11)
You may submit a verified request for access to your personal data or, where the applicable portability right applies, receive eligible personal data in a structured, commonly used, machine-readable format.
- Request instructions: Visit gidai.ca/data-export or email privacy@gidai.ca from the address associated with your account using the subject "Personal Data Access Request".
- Identity and scope review: Our privacy team verifies the requester and determines the personal data in scope without disclosing another person's confidential information or unrestricted company-wide records.
- Response time: We acknowledge requests within 72 hours and provide the formal response within 30 days.
- Security exclusions: Password hashes, access tokens, API keys, security credentials, and other secrets are never included.
Right to erasure (GDPR Art 17, PIPEDA Principle 9, DPDP Section 12)
Request permanent deletion of your account and in-scope personal data. We use one 30-day grace window so a verified request can be cancelled before destructive processing begins.
- Inside the Gid app: Account Settings, then "Delete my account". You confirm by typing your email and acknowledging the consequences.
- From the web: gidai.ca/delete-account. Submitting the form requests a one-time secure link; opening a valid link starts the grace period.
- Cancel within the 30-day grace period using the link Gid attempts to send in the separate grace-start email. After the grace period, the scheduled daily purge attempts first-party deletion. Failed steps are retried, and applicable legal holds suspend destructive processing.
- Request scope: an employee or non-Founder request is user-only. A Founder request defaults to the selected company workspace and company-scoped content, as explained on the deletion page.
- Stripe subscription: for a recognized Founder account, the service attempts cancellation when the grace period starts. Cancelling deletion does not automatically restore the subscription.
- External verification and audit: after first-party deletion, limited identifiers are temporarily retained in a restricted control record solely to complete and evidence provider and analytics erasure or lawful retention. They are removed when that work is evidenced; a minimized lifecycle record with a hashed email and timestamps is retained for seven years.
Right of access, correction, restriction, and objection
Email privacy@gidai.ca with the right you want to exercise. We acknowledge requests within 72 hours and provide the formal response within 30 days, in line with GDPR Art 12, PIPEDA's Openness principle, and DPDP Section 13. Account deletion follows the separate grace, purge, hold, and external-verification lifecycle described above.
India Grievance Officer (DPDP Section 13)
Our designated Grievance Officer is Alexandre Verville, founder, reachable at privacy@gidai.ca. Response time: 72 hours. If your concern is not resolved, you may contact the Data Protection Board of India.
Cookie consent
We do not load any analytics cookies until you accept them in the consent banner shown on your first visit. Decline is honored permanently for 12 months; we also auto-decline when your browser sends Do Not Track or Global Privacy Control signals. You can change your choice anytime by clicking Cookie preferences.
Suppression list
If you exercise your right to erasure or unsubscribe from our cold-email outreach, your email address (hashed) is added to a global suppression list. We will never contact you again unless you explicitly subscribe back. This protects you from accidental re-engagement after deletion.
9.B U.S. state privacy rights
If you are a resident of a U.S. state with a comprehensive privacy law — including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, or Montana — you have specific rights regarding your personal information. We honor these rights for all U.S. residents, regardless of state of residence, to simplify the experience.
Your rights
- Right to know. Request a list of the categories of personal information we collect, the sources, the purposes, and the categories of third parties we share with.
- Right of access. Request a copy of the specific pieces of personal information we have collected about you in the preceding 12 months (24 months for California requests from January 2024 onward).
- Right to delete. Request that we delete personal information we have collected from you.
- Right to correct. Request that we correct inaccurate personal information.
- Right to opt out of sale, sharing, and targeted advertising. We do not sell personal information, we do not share personal information for cross-context behavioral advertising, and we do not engage in targeted advertising as those terms are defined in U.S. state privacy laws. No opt-out is needed because these activities do not occur.
- Right to limit use of sensitive personal information. We do not use sensitive personal information for purposes that require an opt-out under California, Connecticut, or Colorado law.
- Right to opt out of profiling that produces legal or similarly significant effects. We do not engage in such profiling. Some features may inform managerial decisions; final decisions are made by a human, and AI outputs are advisory only (see Terms Section 5).
- Right to non-discrimination. We will not discriminate against you for exercising any of these rights (such as by denying service, charging different prices, or providing a lesser quality of service).
- Right to appeal. If we deny your request, you may appeal the decision by replying to our response with "Appeal" in the subject line. We will respond within 45 days. Required appeal mechanism under Virginia, Colorado, and Connecticut law; we honor it for all U.S. residents.
How to exercise your rights
- In the Gid app: Account Settings → "Delete my account" for account deletion.
- From the web: gidai.ca/data-export for access and portability request instructions, or gidai.ca/delete-account for account deletion.
- By email: privacy@gidai.ca with the right you want to exercise in the subject line.
- Why there is no phone line: Gid operates exclusively online and has a direct relationship with the consumers from whom it collects personal information, so under the CCPA regulations at 11 CCR § 7020(c) an email address is the required method for submitting requests. Use privacy@gidai.ca.
Identity verification
To protect you, we verify the identity of the requester before disclosing or deleting personal information. For account-holders, we begin with the email associated with the account and may use authenticated account records or request the minimum additional information needed. If we cannot reasonably verify identity, we will inform you and explain why.
Authorized agents
You may use an authorized agent to submit a request on your behalf. We require the agent to provide a signed written authorization from you (or, in California, a power of attorney). We will still verify your identity directly before fulfilling the request.
Universal opt-out signals
For users protected under California, Colorado, or Connecticut law, we honor the Global Privacy Control (GPC) and other recognized universal opt-out preference signals as a valid request to opt out of "sale" and "sharing" (where those activities apply). Because we do not engage in either, the practical effect is to confirm that no opt-out is needed.
Categories of personal information we collect (CCPA §1798.110)
- Identifiers: name, email, phone, account identifier, and IP addresses retained only as a one-way hash.
- Customer records (Civil Code § 1798.80(e)): employment role, work address, work phone.
- Protected classifications: only where the Customer chooses to record them for compliance purposes (such as EEO categories).
- Commercial information: billing and subscription records, held against the subscribing organization rather than against an individual user.
- Internet or other network activity: log files, request metadata, feature usage.
- Geolocation: none. We collect neither precise nor approximate geolocation, we derive no location from IP addresses, and the apps request no location permission.
- Audio, electronic information: chat messages, voice transcripts (when Customer enables voice features).
- Professional or employment information: schedules, training records, performance metrics.
- Inferences: generated from the above for the purposes of providing the Service (such as suggested training topics).
We do not collect "sensitive personal information" categories beyond what is strictly necessary for the Service (such as account credentials, which CCPA classifies as sensitive). We do not use sensitive personal information to infer characteristics about you.
Retention
See Section 7 (Data Retention) above. For California consumers, the retention periods listed there constitute the disclosure required by CCPA § 1798.130(a)(5)(D).
Notice at collection
This Policy serves as our "notice at collection" under CCPA § 1798.100(b). We collect categories of personal information only for the business purposes described in Section 3 (How We Use Your Information).
Quebec Law 25 specific rights
For Quebec residents, in addition to the rights above, we provide:
- Privacy Officer / Person in charge of personal information: Alexandre Verville, privacy@gidai.ca;
- Privacy Impact Assessment obligations for new technologies, automated decisions, and confidential disclosures, conducted as required by Law 25;
- Right to be informed of automated decisions that produce legal effects. Where Gid uses AI features that materially influence a decision about you, we will inform you and explain the principal factors and parameters on request;
- Right to data portability in a structured, commonly used technological format (see § 9.A "Right to portability");
- Complaints may be filed with the Commission d'accès à l'information du Québec at cai.gouv.qc.ca.
10. Children's Privacy
Our services are designed for business use and are not intended for individuals under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected such information, we will take steps to delete it promptly.
11. Updates to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. We will:
- Notify you of material changes via email or platform notification
- Post the updated policy on our website
- Update the "Last Updated" date at the top of this policy
Your continued use of our services after such changes constitutes acceptance of the updated policy.