Privacy Policy
Effective Date: March 22, 2026
1. Introduction
MapleBull ("we," "our," or "us") operates the MapleBull mobile application and website (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your personal information in compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's Anti-Spam Legislation (CASL), and applicable provincial privacy legislation. By creating an account or using the Services, you consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy. If you do not agree, please do not use the Services. You may withdraw your consent at any time by contacting us or deleting your account.
2. Accountability
MapleBull is responsible for the personal information under our control. Our Privacy Officer is responsible for our compliance with this Privacy Policy and PIPEDA. Questions or concerns may be directed to: Privacy Officer MapleBull Email: [email protected]
3. Identifying Purposes — Why We Collect Your Information
We collect personal information for the following identified purposes: • To create and manage your user account and verify your identity. • To provide and operate the Services, including displaying live precious metals prices, dealer comparisons, and educational content. • To save your preferences and personalize your experience across devices. • To send push notifications and email alerts you have expressly opted into regarding price movements and market conditions (in compliance with CASL). • To improve the Services' functionality and user experience. • To respond to your support inquiries and communicate service-related updates. • To comply with legal obligations and enforce our Terms of Service. We will not use your personal information for any purpose other than those identified above without first obtaining your consent.
4. Consent
We obtain your meaningful consent before collecting, using, or disclosing your personal information: Express Consent: When you create an account, you expressly consent to the collection and use of your information by accepting this Privacy Policy and our Terms of Service. Your consent is recorded with a timestamp. Implied Consent: Continued use of the Services after being notified of material changes to this Privacy Policy constitutes implied consent to the updated terms. Withdrawal of Consent: You may withdraw your consent at any time by: • Deleting your account through the app or website (Account → Delete Account). • Disabling push notifications through your device settings. • Contacting us at [email protected]. Please note that withdrawing consent may affect our ability to provide certain features of the Services. CASL Compliance: We only send commercial electronic messages (CEMs) to users who have provided express consent. Each CEM includes an unsubscribe mechanism and our contact information. We honour unsubscribe requests within 10 business days.
5. Limiting Collection
We limit the collection of personal information to what is necessary for the identified purposes. We collect the following categories of information: Account Information: When you create an account, we collect your email address, display name, username, and profile biography. If you sign in via Apple or Google, we receive the identity token and basic profile information provided by those services. Consent Records: We record the date and time you accept the Terms of Service and Privacy Policy. User Preferences: Display preferences (currency, dark mode), notification settings, and price refresh interval are stored locally on your device. Watchlist & Alerts: Products on your watchlist and price alert configurations are stored locally on your device and, when you are signed in, in our cloud database. Search History: Your recent bullion search queries (up to 8) are stored locally on your device. We do not collect or store payment information, precise geolocation data, biometric data, or Social Insurance Numbers. We do not use analytics SDKs, advertising frameworks, or third-party crash-reporting services.
6. Limiting Use, Disclosure, and Retention
Use: We use your personal information only for the purposes identified in Section 3 or as required by law. Disclosure: We do not sell, rent, or share your personal information with third parties for their marketing purposes. We may disclose personal information: • To our cloud service providers (see Section 8) who process data on our behalf under contractual obligations. • When required by law, regulation, court order, or governmental request. • To protect the rights, property, or safety of MapleBull, our users, or the public. Retention: We retain your personal information only as long as necessary: • Account Data: Retained while your account is active. Upon account deletion, all profile data, watchlist items, and alerts are permanently removed within 30 days. • Consent Records: Retained for 3 years after account deletion to demonstrate compliance with PIPEDA and CASL. • Local Data: Persists on your device until you delete the app or clear its data.
7. Accuracy
We take reasonable steps to ensure that personal information is accurate, complete, and up-to-date for the purposes for which it is used. You may update your personal information at any time through: • The "Edit Profile" feature in your account settings. • Contacting us at [email protected]. We encourage you to keep your information current to ensure proper service delivery.
8. Safeguards
We protect personal information with security safeguards appropriate to the sensitivity of the information: Technical Measures: • All data in transit is encrypted using TLS 1.2 or higher. • Authentication is handled through industry-standard protocols (OAuth 2.0, magic link email verification). • Database access is governed by row-level security policies ensuring users can only access their own data. • Service credentials are managed through secure vault storage. Organizational Measures: • Access to personal information is restricted to authorized personnel on a need-to-know basis. • Our cloud infrastructure provider (Supabase, Inc.) maintains SOC 2 Type II compliance. No method of electronic transmission or storage is 100% secure. If you become aware of a security vulnerability, please contact us immediately at [email protected].
9. Openness
We are committed to being transparent about our policies and practices for managing personal information: • This Privacy Policy is readily available through the app (Settings → Privacy Policy) and on our website at https://maplebull.ca/privacy. • We will notify you of material changes to this Privacy Policy through the app and, where appropriate, by email. • You may request information about our privacy practices by contacting our Privacy Officer.
10. Individual Access
Under PIPEDA, you have the right to access your personal information held by MapleBull and to challenge its accuracy. Right of Access: You may request a copy of the personal information we hold about you by contacting [email protected]. We will respond within 30 days of receiving your request. Right of Correction: If your personal information is inaccurate or incomplete, you may request correction. We will make the necessary amendments and, where appropriate, notify third parties to whom the information was disclosed. Right of Deletion: You may delete your account and all associated data at any time through the app (Account → Delete Account) or by contacting us. Upon receiving a deletion request: • Your profile, watchlist, alerts, and all user-generated content will be permanently deleted. • Deletion is processed within 30 days. • Consent records are retained as described in Section 6. Right of Portability: You may request a machine-readable export of your personal information by contacting us. We may refuse access in limited circumstances permitted by PIPEDA and will provide reasons for any refusal.
11. Third-Party Services
The Services integrate with the following third-party services: Supabase (supabase.com): User authentication and profile storage. Data may be processed in the United States and is subject to Supabase's privacy policy at https://supabase.com/privacy. Apple Sign In / Google Sign In: If you choose to authenticate using Apple or Google, your identity verification is processed by the respective provider under their privacy policies. Market Data Providers: We retrieve spot prices and market data from third-party APIs (including Goldpricez, metals.dev, GoldAPI, Bank of Canada, Yahoo Finance, LBMA, and Shanghai Gold Exchange). These services receive API requests but do not receive your personal information. We require that our service providers protect personal information in a manner consistent with this Privacy Policy.
12. International Data Transfers
Your personal information may be transferred to and processed in countries other than Canada, including the United States, where our cloud service providers (Supabase, Inc.) operate. In accordance with PIPEDA Principle 4.1.3, we ensure that personal information transferred to third parties for processing is protected by contractual or other means that provide a comparable level of protection. By creating an account, you consent to the transfer of your information to these jurisdictions. We ensure that any cross-border transfers comply with PIPEDA requirements.
13. Children's Privacy
The Services are not intended for use by individuals under the age of 13, or under the age of majority in their province of residence without parental consent. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without appropriate consent, we will take steps to delete such information promptly. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected].
14. Challenging Compliance
You have the right to challenge our compliance with this Privacy Policy by contacting our Privacy Officer at [email protected]. We will investigate all complaints. If a complaint is found to be justified, we will take appropriate measures, including amending our policies and practices if necessary. If you are not satisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada: Office of the Privacy Commissioner of Canada 30 Victoria Street Gatineau, Quebec K1A 1H3 Toll-free: 1-800-282-1376 Website: https://www.priv.gc.ca
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes: • We will update the "Effective Date" at the top of this policy. • We will notify you through the app and, where the change materially affects how we handle your personal information, by email. • Material changes take effect 30 days after notification unless you delete your account or withdraw consent before that date. Your continued use of the Services after the effective date constitutes acceptance of the updated Privacy Policy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact: MapleBull — Privacy Officer Email: [email protected] General: [email protected] Website: https://maplebull.ca/privacy
© 2026 MapleBull. All rights reserved. · [email protected]