Privacy Policy

Information we collect

We collect account and access information such as name, business email, authentication events, role, tenant membership, authorization status, and MFA status. When a customer uses PayCanvas, we may process worker names or workforce identifiers; roles, locations, services, and work dates; hours, shifts, bookings, sales, tips, commissions, and pools; pay rates or rule references; earnings, payroll lines, adjustments, and employee totals; exceptions, unresolved questions, decisions, and review notes; source provenance, calculation lineage, and audit events.

Our infrastructure providers process limited device, browser, IP address, request, diagnostic, performance, and security information needed to deliver and protect the service. As of this policy's effective date, PayCanvas does not load third-party behavioral analytics scripts on its public pages.

How we use information

  • Provide, secure, maintain, and troubleshoot PayCanvas.
  • Authenticate users and enforce tenant, role, OAuth, and MCP permissions.
  • Run customer-authorized payroll preparation and analysis workflows.
  • Maintain source provenance, audit history, abuse prevention, and reliability.
  • Respond to support, privacy, legal, and security requests.
  • Understand and improve the public website and product experience.

AI connector data

When an authorized user connects PayCanvas to ChatGPT or another supported MCP client, that customer directs PayCanvas to disclose the tenant-scoped information requested through the enabled tools. Depending on the permissions the user selects, confirmed tools may also start bounded source collection, record an immutable non-payroll review note, apply a PayCanvas-offered factual resolution, copy selected prior-period adjustments, or queue a provisional payroll calculation. Each limited action is subject to live access checks and, where applicable, an exact preview and explicit confirmation. The public connector cannot approve, export, submit, fund, or pay payroll.

The public MCP tools are not designed to request or return Social Security numbers or other government identifiers; bank account or routing information; payment-card data; health or benefits information; passwords, API keys, access tokens, authorization codes, or MFA codes; or raw provider credentials and original provider payloads. Responses pass through a restricted-data boundary before they are returned.

The chosen AI client processes disclosed information under its own terms and privacy policy. Its storage, memory, training, and retention behavior depends on that service and the customer's or user's account settings. Disconnecting PayCanvas stops future connector access but does not delete information the AI client already received; requests concerning that copy must be directed to the AI-client provider.

How we share information

We may share information with infrastructure, authentication, hosting, monitoring, analytics, communication, and other service providers that help us operate PayCanvas; with a customer's authorized users and connected services; when required by law; or as part of a corporate transaction. We do not sell personal information or share it for cross-context behavioral advertising.

Retention schedule

  • Account, membership, and OAuth records: active access remains until it is disabled, revoked, or the account ends. Revocation blocks future connector use immediately. The account, grant status, and related audit record currently have no fixed automatic expiration and remain until a verified deletion request is completed or a legal, contractual, security, or payroll-record obligation requires retention.
  • Payroll inputs and evidence: payroll inputs, results, adjustments, resolutions, review notes, provenance, calculation versions, and audit evidence currently have no fixed automatic expiration. They remain immutable while retained and are kept until the customer directs verified deletion or the customer relationship ends, subject to payroll-record duties, legal holds, dispute needs, and contractual instructions.
  • Support communications: the website sends inquiries to PayCanvas's business email service and does not create a separate PayCanvas database record. Messages in the support mailbox currently have no fixed automatic expiration and remain until deleted through the ordinary support process or a verified request, subject to legal or dispute needs.
  • Security and infrastructure logs: hosted application request and runtime logs are retained for no more than 30 days. Supabase project logs available to PayCanvas are retained for up to seven days on the current plan. PayCanvas does not copy these logs into a separate long-term analytics store.
  • Website analytics: PayCanvas does not currently load third-party behavioral analytics scripts on public pages and does not maintain a separate website-analytics database.
  • Backups: the production database uses rotating daily physical backups with a seven-day recovery window. After primary deletion, a deleted database record may therefore remain in a backup for up to seven additional days and is removed as the backup rotates out. Storage objects are not included in those database backups; deleting an object from primary storage does not leave a restorable copy in a database backup.
  • Legal holds and customer instructions: where a customer instructs longer preservation, or law, litigation, an investigation, or a dispute requires it, the affected records are retained until that instruction or obligation ends and are then handled under the applicable schedule above.

We use administrative, technical, and organizational safeguards, but no system can guarantee absolute security.

Your choices and rights

You may ask to access, correct, or delete personal information, subject to customer control, payroll-record obligations, legal exceptions, and identity verification. You can control browser cookies through browser settings and disconnect an MCP authorization from the applicable client or PayCanvas account controls.

Children, changes, and contact

PayCanvas is a business service and is not directed to children under 13. We may update this policy and will post the revised effective date here. Contact hello@paycanvas.io or AJAI LLC, 26897 Spyglass Dr, Orange Beach, AL 36561, with privacy questions or requests.