Legal
Privacy Policy
Effective August 22, 2026
This Privacy Policy explains how IntoPaid Acquisition Labs (“IntoPaid,” “we,” “us”) collects, uses, and shares personal information when you visit intopaid.com, join the waitlist, create an account, or use the IntoPaid Service.
It should be read with our Terms of Service. Questions: [email protected].
Contents
- Who we are
- Two kinds of data
- Information we collect
- How we use it
- AI Ticket Assist
- Sharing
- Cookies and tracking
- Retention and deletion
- Your rights
- Security
- Children
- International transfers
- Changes
- Contact
Who we are
IntoPaid Acquisition Labs operates IntoPaid from Canada.
IntoPaid Acquisition Labs
PO Box 75025, Vancouver RPO Main Street, BC, V5X 4V7
[email protected]
Two kinds of data
Merchant (controller) data. If you have an IntoPaid login, join the waitlist, or email us, we decide how to use that information to run accounts, billing, support, and our own product emails. We are the controller of that data.
Customer (processor) data. When you forward or send inquiry emails, Instagram threads, website-form submissions, notes, and related payment or pickup details into IntoPaid, you are the controller of your customers’ personal information. We process that content only to provide the Service to you. We do not sell personal information. We do not use customer inquiry content to advertise to those customers.
End customers should contact the shop they wrote to for access or deletion of order-ticket data. We will help that shop where we can.
Information we collect
Account and waitlist
- Business name, your name, login email, password hash (if you set a password), and Google account identifiers/tokens if you sign in with Google.
- Session information, including IP address and user agent, while you are signed in.
- Waitlist email, help-center feedback, and messages you send to [email protected] or through in-app contact forms.
- Invite and referral codes, and whether an invited shop later starts paying.
Workspace content you send us
- Tickets and messages: customer name, email, phone, subject, message bodies, tags, pickup date/time/notes, and internal notes (notes are not emailed to the customer).
- Brand assets: display name, logo (uploaded and stored by us), colors, website, social links, and email templates.
- Public form submissions from an embed you publish (name, email, phone, subject, message, depending on the fields you enable).
- Instagram identifiers, handles, and profile images for tagged threads, if you connect Instagram.
- Shopify customer, product, draft order, and paid-order identifiers needed to quote and mark tickets paid, if you connect Shopify.
Billing
We store Stripe customer and subscription identifiers, plan status, and invoice/receipt metadata. Payment card numbers are collected and stored by Stripe, not by IntoPaid.
Product email to merchants
We send lifecycle and product email to shop owners (welcome, tips, billing, referrals, and similar) from [email protected]. Those messages may include open and click tracking as described below. Password resets, security notices, and similar transactional mail may still send if you unsubscribe from marketing.
Website visits
When you browse intopaid.com, Google Analytics may collect pages viewed, referrer, device and browser type, and approximate location. We use this to understand traffic, not to advertise to your customers.
How we use it
We use personal information to:
- Provide the inbox, quotes, invoices, reminders, calendar, win-back (on eligible plans), and related features.
- Create and secure accounts, including Google sign-in.
- Process subscriptions, pauses, cancellations, and add-ons.
- Send customer-facing email or Instagram replies that you initiate, under your brand.
- Email you about the product, waitlist, billing, and (where allowed) marketing; you can unsubscribe from marketing.
- Provide support via [email protected] and our internal ops inbox.
- Protect the Service (fraud, abuse, security) and comply with law.
- Improve reliability and features of IntoPaid.
- Understand how visitors use intopaid.com, using Google Analytics.
Under Canadian privacy law we rely on purposes a reasonable person would consider appropriate in the circumstances, and on your consent where required (including when you create an account or enable an integration). Where GDPR or similar laws apply, we rely on performance of a contract, legitimate interests (operating and securing a B2B SaaS), consent (for example Assist, optional marketing, some cookies from third-party widgets), and legal obligation.
AI Ticket Assist
Assist is off by default. It runs only when you enable it in Settings and tap Assist (or use Assist-powered drafts such as Grow win-back drafts). We then send the relevant thread text and ticket fields to OpenAI to generate suggestions you must confirm. Assist does not run in the background on every inbound email.
IntoPaid does not train AI models on your inbound email or ticket content. Turning Assist off stops further AI processing. OpenAI processes prompts under its own terms and privacy policy.
Sharing
We share personal information with service providers who process it on our instructions to operate IntoPaid (billing, email delivery, hosting, security, website analytics, and AI Assist when you run it), and with platforms you connect yourself — such as Shopify, Instagram, or Google sign-in. We do not sell personal information.
We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets (the buyer would still need to honor this policy or provide notice).
We do not run ads or audience targeting on your customers’ behalf.
Cookies and tracking
We use:
- Essential session cookies so you can stay signed in, plus short-lived cookies during Google signup/sign-in.
- Google Analytics on intopaid.com to see which pages are visited, approximate location, device, and referrer. Google may set its own cookies. This is for understanding our site, not for running ads on your behalf. See Google’s privacy policy and Google’s Analytics opt-out.
- hCaptcha, which may set its own cookies when the widget is shown.
We do not use advertising cookies on intopaid.com. Marketing email we send to shop owners may use Postmark open and click tracking so we can see whether a message was received. You can unsubscribe from those product emails.
Customer transactional mail on a ticket (acknowledgments, replies, invoices, payment and pickup reminders) is sent without Postmark open or click tracking. Grow win-back sequences you enroll may record opens via a first-party pixel on intopaid.com and clicks via a redirect on our domain, so you can see whether a follow-up was opened. That tracking is part of a feature you turn on for your customers.
Retention and deletion
We keep account and workspace data while your shop is active. Trashed tickets are purged after roughly 30 days. After you cancel, tickets stay on file for 90 days so you can return, then may be deleted.
To delete your IntoPaid account and tenant data (leads, messages, notes) from our primary database, email [email protected] from the login address on the account. We will process verified requests. Limited copies may remain in backups, logs, or billing records for a period needed for security, dispute resolution, and legal compliance. Stripe and Postmark retain information under their own policies. Waitlist emails are kept until you ask us to remove them or we no longer need them.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or obtain a copy of personal information we hold about you, to withdraw consent, to unsubscribe from marketing, or to complain to a privacy regulator (in Canada, including the Office of the Privacy Commissioner of Canada). California residents may have additional rights under the CCPA/CPRA, including to know, delete, and correct personal information and to opt out of “sale” or “sharing” — we do not sell or share personal information for cross-context behavioral advertising. Where GDPR applies, you may also have rights to restrict or object to certain processing and to lodge a complaint with a supervisory authority.
Email [email protected] to exercise these rights. We may need to verify the request. If you are an end customer of an IntoPaid shop, contact that shop first; they are the controller of your ticket.
Security
We use industry-standard measures appropriate to a hosted SaaS product (including encrypted transport, hashed passwords, and access controls for staff tools). No method of transmission or storage is completely secure. You should use a strong unique password and protect access to your email and Google account.
Children
The Service is for businesses. We do not knowingly collect personal information from children under 16. If you believe we have, contact us and we will delete it.
International transfers
We are based in Canada. Vendors listed above may process data in the United States and other countries. If we transfer personal information from the EEA, UK, or Switzerland, we use appropriate safeguards (including the vendor’s contractual terms) where required.
Changes
We may update this policy. The effective date at the top of the page will change when we do. Material changes will be announced by email or in the app when reasonable.
Contact
Privacy requests and questions: [email protected]
IntoPaid Acquisition Labs
PO Box 75025, Vancouver RPO Main Street, BC, V5X 4V7