Data processing agreement
Between **David McConnell, operating as Treadstock** ("Treadstock", "we") and the shop named on the licence ("you"). Forms part of the Treadstock licence terms. Last updated 3 September 2026.
This is the document PIPEDA principle 4.1.3 has in mind when it says an organisation must use contractual means to ensure a comparable level of protection when it hands personal information to a third party to process. You are the organisation. We are the third party.
1. Which of us is which
You decide what personal information is collected about your customers and why. We hold and process it only on your instructions, to provide the service. In the language of most privacy laws you are the controller or organisation, and we are the processor or service provider.
2. What we process, and why
| Categories of people | Your customers; your staff |
| Categories of data | Customer name, phone, email, notes; licence plate and vehicle description; photographs of tires and storage areas; storage fees and whether they are paid. Staff name, role, hashed PIN or password, registered devices, sign-in times, IP address and browser, and a permanent record of actions taken |
| Purpose | Running the tire storage service you have licensed, and nothing else |
| Duration | For as long as you are a customer, then 30 days (see §8) |
No payment card data is processed. The software records that a card was used; it has no facility to store or transmit a card number.
3. What we will not do
We will not sell, rent, share or publish your data. We will not use it to train any model. We will not aggregate it with other shops' data and publish or sell the result — including anything derived from what you charge for storage. We will not use it for our own purposes at all, beyond what is needed to run and secure the service and to bill you.
If you ever see us contradict this, hold us to it: it is a term of the agreement, not a statement of intent.
4. Where it is, and who else touches it
Your data is stored in the United States. Our sub-processors:
| Sub-processor | What they do | Where |
|---|---|---|
| Railway Corp. | Hosts the application and the database | San Francisco, USA |
| Cloudflare, Inc. | Stores photographs; serves the site | USA |
That is the complete list. We will tell you at least 30 days before adding another, and if you object on reasonable grounds you may end the licence under clause 8 of the terms with a refund of anything paid in advance.
Because your data crosses the border, US authorities could in principle compel access to it under US law. Nobody can contract that away, and any supplier who tells you otherwise is wrong. If you are in Quebec, note that Law 25 asks you to assess a transfer outside the province in writing before making it; this section is written to give you what that assessment needs.
5. How it is protected
- Each shop's records are isolated in the database itself, enforced by row-level security rather than by application code, and an automated test proves two shops cannot see each other on every deployment.
- The application connects with a database account that cannot bypass that isolation, cannot delete rows, and cannot alter the schema.
- Passwords and PINs are stored as argon2id hashes.
- Photographs sit in a private bucket and are served only through links that expire after five minutes.
- All traffic uses TLS.
- Every change is recorded in an append-only, cryptographically chained log, so tampering is detectable.
- Our own operator tooling cannot display your customers, plates, photographs or fees.
Access by our staff to anything more than counts and health information requires signing in to your shop with your permission, and that sign-in is recorded in your own log where you can see it.
6. If there is a breach
We will tell you without undue delay, and in any case within 72 hours of becoming aware of a breach affecting your data, with what we know: what happened, who is affected, what we are doing, and what we suggest you do. We will help you meet your own obligation to notify affected individuals and the Privacy Commissioner.
We keep a record of every security breach, whether or not it is reportable, for at least 24 months, as PIPEDA requires.
7. Helping you answer your customers
If one of your customers asks to see, correct or delete what you hold about them, you can do the first two yourself in the software. For anything you cannot do yourself, tell us and we will help within 30 days at no charge.
If a regulator asks you questions about how the data is handled, we will give you what you need to answer them.
8. Getting it back, and getting rid of it
At any time, without asking us, you can export your sets, history and photographs as spreadsheets and image files.
When the licence ends, your data stays reachable for 30 days so you can export it. After that we delete it — records, staff accounts and photographs. Ask us sooner and we will do it sooner. What survives deletion is our own note that a shop existed and was deleted, containing no personal information.
9. Audit
You may ask us, once a year, to describe and evidence how we meet this agreement, and we will answer honestly and in writing. We are a small company and do not hold SOC 2 or ISO 27001 certification; we would rather say so than imply otherwise.
10. Term
This agreement lasts as long as we hold your data, and the obligations in §3, §6 and §8 survive the end of the licence.
Signed as part of the Treadstock licence.
David McConnell, operating as Treadstock · 52 Shannondoe Crescent, Kanata, Ontario K2M 2H1, Canada · [email protected]