Crisphive

Privacy Policy

Last updated: August 26, 2026

This Privacy Policy explains how WicWac Inc., operating as Crisphive ("Crisphive," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use our website, applications, and services (collectively, the "Service").

1. Who We Are

Crisphive is a technology platform for scheduling and managing mobile service teams. Crisphive is a brand of WicWac Inc., a company federally incorporated in Canada.

WicWac Inc. (Operating as Crisphive)

Suite 1420, 99 Bank Street

Ottawa, Ontario K1P 1H4

Canada

Contact Email: support@crisphive.com

2. Scope of This Policy

This Privacy Policy applies to:

  • Visitors to our website
  • Users of our applications and platform
  • Customers, account administrators, and authorized users
  • Business contacts and communications
  • Businesses and individuals who submit data for a free Shadow Schedule Audit (see Section 4)

It does not apply to third-party websites or services linked from Crisphive.

3. Information We Collect

3.1 Information You Provide Directly

We may collect:

  • Name, email address, phone number
  • Mobile phone number, when you enable SMS notifications or SMS-based login
  • Company name and role
  • Account login credentials
  • Billing and payment information
  • Support requests and communications
  • Communication preferences, including marketing opt-in and opt-out status
  • Any data you upload or enter into the Service ("Customer Data")
  • Scheduling and operational data you submit for a Shadow Schedule Audit ("Audit Data" — see Section 4)

3.2 Information Collected Automatically

When you use the Service, we may collect:

  • IP address
  • Device type, operating system, browser
  • Usage logs, timestamps, feature interactions
  • Approximate location (city/region)
  • Email interaction data (such as delivery, open, and click events) used to operate and improve our communications

This data helps us operate, secure, and improve the Service.

3.3 Customer Data (Service Data)

Customer Data may include:

  • Employee names and contact details
  • Job schedules, assignments, locations
  • Notes, comments, and operational data

You control this data. We process it only to provide the Service. Customer Data — including records about field operations personnel such as technicians, crews, and drivers — is owned and controlled by the business that holds the account, and remains on that business's account when personnel leave the business (see Section 11.3).

One-Way Confidentiality Undertaking

4. Shadow Schedule Audit Data

4.1 What This Section Covers

If you request a free Shadow Schedule Audit, you send us one or more days of your real operational scheduling information — which may include job locations, appointment time windows, technician or crew rosters, and related dispatch details ("Audit Data"). Because Audit Data is commercially sensitive and is shared with us before any customer relationship exists, this section is our unilateral, binding confidentiality undertaking to you. It applies automatically to every audit — you do not need to sign anything for it to take effect.

4.2 Single-Purpose Use — Our Undertaking to You

We undertake that Audit Data will be used for one purpose only: to perform your Shadow Schedule Audit — rebuilding your submitted schedule under the same constraints — and to prepare, deliver, and discuss your audit report with you. That is the entire scope of use.

Without limiting the foregoing, we will not:

  • Use Audit Data for marketing, advertising, or promotional purposes, or to contact anyone identified in it
  • Use Audit Data to train, fine-tune, or improve any machine-learning or AI model
  • Sell, rent, license, or trade Audit Data to anyone
  • Combine Audit Data with other customers' data, or use it for benchmarking, published statistics, or industry reports, whether or not anonymized
  • Use Audit Data to solicit your employees, contractors, or customers

4.3 Confidential Treatment

We treat Audit Data as your confidential information. Access is restricted to Crisphive personnel who need it to perform your audit and who are bound by confidentiality obligations, and it is protected using the safeguards described in Section 12. We will not disclose Audit Data to any third party, except to the service providers that host our infrastructure (acting on our instructions under contractual confidentiality) or where disclosure is required by law, regulation, or court order — in which case, where lawful, we will notify you promptly.

4.4 Deletion

Unless you enter into a subscription or other commercial agreement with us, we delete your Audit Data within thirty (30) days after delivering your audit report, except for copies in routine backups (which remain protected by this section until deleted in the ordinary course) or as required by applicable law. You may also request earlier deletion at any time by emailing legal@crisphive.com. For clarity, Audit Data is deleted on this faster timeline and does not follow the general deletion schedule in Section 11.2.

4.5 Audit Methodology and Limitations — Not a Binding Plan

The Shadow Schedule Audit is produced using Crisphive's own internal scheduling algorithms and large language models (LLMs), which assist in interpreting your submitted data and generating the report. (Consistent with Section 4.2, your Audit Data is processed by these systems to produce your report but is never used to train or improve any model.)

The audit report is an illustrative, point-in-time simulation based solely on the data you submit and the assumptions stated in the report. It is provided for information only, and — for absolute clarity — it is not:

  • A binding agreement, offer, quotation, or commitment of any kind by WicWac Inc. or Crisphive
  • A guarantee, warranty, or prediction of results, savings, or performance — all figures are estimates and may contain errors or omissions inherent in algorithmic and LLM-generated output
  • Professional, financial, legal, or operational advice
  • An operational playbook, plan, or instruction set for running your business

You are solely responsible for any decision you make, or refrain from making, in reliance on the audit or its report. For clarity, this subsection concerns the audit outputs only: it does not diminish the confidentiality undertaking in Sections 4.2 to 4.4, which remains binding on us.

4.6 Release; No Liability

To the maximum extent permitted by applicable law, WicWac Inc. (operating as Crisphive) and its subsidiaries, affiliates, and brands, and each of their respective directors, officers, employees, contractors, and agents (together, the "Crisphive Parties"), are indemnified and held harmless by you from, and shall have no liability for, any claim, loss, damage, cost, or expense of any kind — whether direct, indirect, incidental, special, consequential, exemplary, or punitive, and under any theory of liability — arising out of or relating to the audit, the audit report, or any use of or reliance on either, and you release the Crisphive Parties from all such claims. Nothing in this section excludes or limits liability that cannot be excluded or limited under applicable law. If you and Crisphive sign a mutual non-disclosure agreement, the warranty and liability provisions of that agreement govern to the extent of any conflict with this section.

4.7 Legal Effect; Signed NDA Available

Sections 4.2 to 4.4 are intended to be legally binding on WicWac Inc. as a unilateral undertaking in favour of each business that submits Audit Data, and — together with Sections 4.5 and 4.6 — survive for two (2) years from the date we receive your Audit Data. If you prefer a signed agreement, a mutual non-disclosure agreement is available on request — email legal@crisphive.com. If we sign an NDA with you, that NDA governs to the extent of any conflict with this section.

In plain words: the schedule you send us is used to run your audit and for nothing else — no marketing, no model training, no resale, no benchmarking — and it's deleted within 30 days of your report unless you decide to continue with Crisphive. The report itself is a free, algorithm- and LLM-generated estimate: informative, but not a promise, not advice, and not a plan you're bound to — and decisions you make with it are yours.

5. How We Use Information

We use personal information to:

  • Provide and operate the Service
  • Perform the Shadow Schedule Audit, strictly within the limits of Section 4
  • Authenticate users and manage accounts, including by SMS one-time passcode (OTP)
  • Process payments and subscriptions
  • Send Functional Communications necessary to operate your account and the Service (see Section 7)
  • Send Marketing Communications where permitted by law and your preferences (see Sections 7 and 8)
  • Communicate about updates, support, and service notices, including by SMS where you have consented
  • Improve features, performance, and security
  • Comply with legal and regulatory obligations

We do not sell personal information.

6. SMS Communications (Notifications and One-Time Passcodes)

Crisphive may send you text (SMS) messages for two distinct purposes: service notifications and login verification via one-time passcodes (OTP). This section explains how consent is obtained for each, how to opt out, and how we handle your mobile number.

6.1 SMS Service Notifications

We may send transactional and informational SMS messages related to your use of the Service, such as schedule changes, dispatch and job alerts, account activity, and service notices. Consent to receive these notifications is obtained through your acceptance of our Terms & Conditions when you create an account or use the Service. These messages are not marketing messages.

6.2 SMS One-Time Passcodes (OTP)

If you choose to log in to the Service using SMS verification, we will send a one-time passcode to your mobile number. Consent for OTP messages is obtained separately and expressly: you must check a consent box when electing to log in via SMS. By checking the box, you authorize Crisphive to send OTP messages to the mobile number you provide, solely for the purpose of verifying your identity and securing your account.

6.3 Never Share Your OTP Codes

One-time passcodes are confidential security credentials. Do not share your OTP code with anyone — including anyone claiming to represent Crisphive. Crisphive and WicWac Inc. will never call, text, or email you to ask for an OTP code. If someone asks you for a code, do not provide it and report the incident to support@crisphive.com immediately.

6.4 Message Frequency, Rates, and Opting Out

  • Message frequency varies based on your account activity and settings.
  • Message and data rates may apply, depending on your mobile carrier and plan.
  • You may opt out of SMS notifications at any time by replying STOP to any message, or by adjusting your notification settings or contacting support@crisphive.com. Reply HELP for assistance.
  • Opting out of SMS notifications does not disable OTP messages if you continue to use SMS-based login. If you no longer wish to receive OTP messages, switch to another available login method.
  • Withdrawing SMS consent may limit certain features, such as SMS-based login or real-time dispatch alerts, but will not affect your ability to use the rest of the Service.

6.5 Compliance with Applicable Laws

Our SMS practices are designed to comply with the laws of the jurisdictions in which we operate and in which our users reside ("the laws of the land"), including, as applicable, Canada's Anti-Spam Legislation (CASL) and PIPEDA, the U.S. Telephone Consumer Protection Act (TCPA) and applicable CTIA and carrier messaging guidelines, and the GDPR and ePrivacy rules for users in the EEA, UK, or Switzerland. Where local law requires a different or higher standard of consent, that standard prevails. See Section 8 for details of our CASL compliance program.

6.6 No Sharing of Mobile Information

Your mobile phone number and SMS opt-in status are used only to deliver the messages described above. Mobile information and SMS consent data will not be shared with or sold to third parties or affiliates for marketing or promotional purposes. We share mobile numbers only with the telecommunications and messaging service providers that deliver messages on our behalf, under contractual confidentiality.

7. Email Communications

Crisphive sends two distinct categories of email: Functional Communications and Marketing Communications. This section explains the difference, the consent basis for each, and your choices.

7.1 Functional Communications (Essential — Cannot Be Opted Out Of)

Functional Communications are emails that are integral to operating your account and delivering the Service. It is important that you receive them. They include, without limitation:

  • Account and security emails (registration confirmations, login verification, password resets, suspicious-activity alerts)
  • Billing and subscription emails (invoices, receipts, payment failures, renewal and price-change notices)
  • Service and operational emails (schedule and dispatch notifications, outage and maintenance notices, critical product changes)
  • Legal and policy notices (changes to these policies, required disclosures, breach notifications)

Consent to receive Functional Communications is obtained through your acceptance of our Terms & Conditions and is a condition of holding an account. Because these emails are necessary for the operation, security, and administration of the Service and may contain information you are required to receive by law or contract, you cannot opt out of Functional Communications while you maintain an account. The only way to stop receiving them is to close your account. Functional Communications are not marketing and are exempt from marketing consent requirements under applicable law.

7.2 Marketing Communications (Optional — Opt-Out Anytime)

Marketing Communications include newsletters, product announcements, promotions, event invitations, surveys, and similar content. We send Marketing Communications only where permitted by applicable law — on the basis of your express consent, an existing business relationship where the law allows it, or another lawful basis — and every Marketing Communication includes a clear and functioning unsubscribe mechanism. You may opt out of Marketing Communications at any time by:

  • Clicking the unsubscribe link in any marketing email
  • Adjusting your communication preferences in your account settings
  • Emailing support@crisphive.com

We will honor opt-out requests promptly and in any event within the timeframe required by applicable law (for example, within 10 business days under CASL). Opting out of Marketing Communications does not affect Functional Communications, which you will continue to receive while your account is active.

7.3 Compliance with Applicable Laws

Our email practices are designed to comply with the laws of the jurisdictions in which we operate and in which our users reside, including, as applicable, Canada's Anti-Spam Legislation (CASL), the U.S. CAN-SPAM Act, and the GDPR and ePrivacy rules for users in the EEA, UK, or Switzerland. Where local law imposes a different or higher standard, that standard prevails. See Section 8 for details of our CASL compliance program.

7.4 Your Responsibilities and Delivery Disclaimer

Email is not a guaranteed delivery medium. You are responsible for keeping the email address on your account accurate and current, for ensuring that emails from Crisphive are not blocked or filtered (including checking spam or junk folders), and for reviewing Functional Communications in a timely manner. A Functional Communication is deemed given when sent by us to the email address on file for your account. To the maximum extent permitted by applicable law, Crisphive and WicWac Inc. are not liable for any loss, damage, or consequence arising from your failure to receive, read, or act on a communication where that failure results from an inaccurate or outdated email address, spam or security filtering, mailbox limitations, or the acts or omissions of third-party email providers or networks.

Canadian Compliance

8. Canada's Anti-Spam Legislation (CASL)

Crisphive is a Canadian company, and Canada's Anti-Spam Legislation (CASL) governs the commercial electronic messages ("CEMs") — emails and SMS messages with commercial content — that we send to electronic addresses in Canada. This section explains how we comply. Where Sections 6 and 7 and this section overlap, the stricter standard applies.

8.1 What Counts as a CEM

A CEM is an electronic message that encourages participation in a commercial activity — for example, our newsletters, product announcements, promotions, event invitations, and similar Marketing Communications (Section 7.2). The following are not CEMs and may be sent without marketing consent, consistent with CASL's exemptions:

  • Functional Communications under Section 7.1 (account, security, billing, service, and legal notices)
  • SMS service notifications and OTP messages under Section 6
  • Messages that deliver something you requested, such as your Shadow Schedule Audit report, a quote, or a response to your inquiry
  • Messages that complete or facilitate a transaction you have already agreed to

8.2 Consent — Express and Implied

We send CEMs only with valid consent:

  • Express consent. You actively opt in — for example, by checking an unchecked box when subscribing to our newsletter or requesting marketing content. We never use pre-checked boxes, and consent to marketing is never a condition of using the Service or receiving a Shadow Schedule Audit. Express consent remains valid until you withdraw it.
  • Implied consent — existing business relationship. If you purchase a subscription or enter into a contract with us, CASL implies consent for two (2) years from the purchase or the end of the contract. If you make an inquiry or application to us — including requesting a Shadow Schedule Audit — CASL implies consent for six (6) months from the inquiry.
  • Implied consent — conspicuous publication / provided address. For business-to-business outreach, we may rely on an electronic address you have conspicuously published (for example, on your company website) or given to us, without a statement that you do not wish to receive unsolicited CEMs, and only where the message is relevant to your business role or function.

When implied consent expires, we stop sending CEMs to that address unless you have given express consent in the meantime.

8.3 Shadow Schedule Audit and CASL

Requesting a Shadow Schedule Audit creates implied consent (as an inquiry) to contact you, the requester, at the contact details you provide on the audit form, for up to six (6) months. This is separate from, and does not diminish, our undertaking in Section 4.2: we will never use contact information of employees, technicians, or customers contained within your Audit Data for marketing or any other outreach.

8.4 Message Identification and Unsubscribe

Every CEM we send:

  • Identifies WicWac Inc. (operating as Crisphive) as the sender and includes our mailing address (Suite 1420, 99 Bank Street, Ottawa, Ontario K1P 1H4, Canada) and a way to contact us
  • Contains a clear, no-cost unsubscribe mechanism that works for at least sixty (60) days after the message is sent
  • Reflects unsubscribe requests promptly, and in any event within ten (10) business days, as stated in Section 7.2

Unsubscribing from Marketing Communications does not affect Functional Communications (Section 7.1) or requested deliverables such as your audit report.

8.5 Records of Consent

We keep records sufficient to demonstrate consent for each CEM recipient, including the date, source, and method of consent (for example, form submission details) and the date and handling of every unsubscribe request, as noted in Section 11 (Data Retention and Deletion).

8.6 Questions and Complaints

Questions about our CASL practices can be sent to support@crisphive.com. You may also contact the Canadian Radio-television and Telecommunications Commission (CRTC), which enforces CASL, or file a report through the Government of Canada's Spam Reporting Centre at fightspam.gc.ca.

In plain words: if it's a marketing message, we only send it when the law says we can — you opted in, you're a customer, or you recently asked us something — every message says who we are, and one click stops them. Account, billing, security, and audit-delivery emails aren't marketing and keep working regardless.

10. How We Share Information

We may share information with:

  • Service providers (hosting, payment processing, analytics, support, SMS delivery, email delivery)
  • Sub-processors acting on our behalf under contractual confidentiality
  • Legal authorities if required by law or to protect rights and safety
  • Business transfers (e.g., merger, acquisition, asset sale)

All sharing is limited to what is necessary. Mobile information is never shared for third-party marketing (see Section 6.6), email addresses are never sold or shared with third parties for their own marketing purposes, and Audit Data is never shared except as narrowly permitted by Section 4.3.

11. Data Retention and Deletion

11.1 How Long We Retain Information

We retain personal information:

  • For as long as your account is active
  • As needed to provide the Service
  • As required by law or legitimate business purposes

OTP codes are short-lived, single-use credentials and are not retained after they expire or are used. Records of marketing consent and opt-out requests are retained as required to demonstrate compliance with applicable law (see Section 8.5). Audit Data is retained and deleted on the shorter timeline set out in Section 4.4.

11.2 Deletion Requests — Timeline

Our full deletion process is set out in our Data Deletion Policy, which forms part of this Privacy Policy. In summary, once a deletion request is verified (or an account is terminated):

PeriodWhat happens
Days 0–30The data is deactivated and removed from Service use, then retained in identifiable form for thirty (30) days to allow verification, error or fraud recovery, and completion of in-flight transactions.
Day 30The data will be irreversibly anonymized — identifiers are permanently removed so it can no longer be linked to any individual or business.
Days 30–365The anonymized data will be retained for a further three hundred and thirty-five (335) days, and is used only for aggregate statistics, capacity planning, Service performance and security analysis, and demonstrating regulatory compliance.
Day 365The anonymized data will be permanently purged from active systems; backup copies are overwritten in the ordinary course of our backup rotation.

Where applicable law — primarily the laws of Canada (including PIPEDA and substantially similar provincial legislation) and the United States (including applicable state privacy laws) — requires a shorter timeline or a different standard, that law prevails. Data subject to a legal hold or a statutory retention obligation (for example, tax and billing records, or CASL consent records) is retained only as required and only for that purpose.

11.3 Field Operations Personnel Who Leave a Business

If a field operations worker (such as a technician, crew member, or driver) leaves a business that uses the Service, the Customer Data relating to that worker belongs to the business and remains stored on the business's account. The business — as owner and controller of its Customer Data — chooses what to do with it: retain, export, anonymize, or delete it, subject always to the local laws that apply to the business, including employment-records retention requirements and privacy legislation. Crisphive acts as a service provider (processor) for this data. Departed personnel who wish to exercise rights over their data should contact the business directly; if they contact us, we will forward the request to the business where feasible or direct them to it, and we will assist the business in responding within legally required timelines. Where applicable law gives departed personnel rights directly against Crisphive, we will honour them. See Section 6 of the Data Deletion Policy for details.

11.4 Account Termination

Upon account termination, Customer Data may be exported by the business on request and then enters the deletion timeline in Section 11.2, subject to legal obligations.

Data Deletion Policy

12. Data Security

We implement reasonable administrative, technical, and physical safeguards designed to protect personal information, including:

  • Access controls
  • Encryption in transit (where applicable)
  • Secure hosting environments
  • Role-based permissions
  • Time-limited, single-use one-time passcodes for SMS login

No system is 100% secure, but we work to protect your data.

13. Your Rights

13.1 Canada (PIPEDA and CASL)

You have the right to:

  • Access your personal information
  • Request corrections
  • Request deletion of your personal information, handled per our Data Deletion Policy (see Section 11.2)
  • Withdraw consent (subject to legal/contractual limits), including consent to SMS communications and Marketing Communications
  • Unsubscribe from commercial electronic messages at any time under CASL (see Section 8.4)

13.2 European Union, UK, and Switzerland (GDPR)

You may have the right to:

  • Access, correct, or delete personal data
  • Restrict or object to processing, including objecting to direct marketing at any time
  • Data portability
  • Withdraw consent
  • Lodge a complaint with a supervisory authority

To exercise any of these rights, email support@crisphive.com. We respond within one month of receiving a verified request; for complex or numerous requests, this may be extended by up to two further months, in which case we will tell you within the first month. We do not charge a fee unless a request is manifestly unfounded or excessive. If your data is in Customer Data or Audit Data that we process on behalf of a business (see Section 9.1), we may direct your request to that business as the controller. You may also lodge a complaint with your local supervisory authority, the UK Information Commissioner's Office (ICO), or the Swiss Federal Data Protection and Information Commissioner (FDPIC).

13.3 United States

Certain U.S. state privacy laws provide residents with rights regarding access, deletion, correction, and portability of personal data, and the right not to be discriminated against for exercising them. We honour applicable state requirements, including verified deletion requests, within the timelines those laws prescribe; where a state law requires faster action than the timeline in Section 11.2, the state law timeline governs. Requests can be submitted as described in Section 3 of the Data Deletion Policy.

14. Data Processing Addendum (GDPR)

If you are an enterprise or EU customer, our Data Processing Addendum (DPA) applies and is incorporated by reference. The DPA governs:

  • Processing instructions
  • Confidentiality
  • Sub-processors
  • Cross-border transfers (Standard Contractual Clauses)

We engage sub-processors only under written terms imposing data protection obligations at least as protective as those in our DPA, and we remain responsible for their performance. A current list of sub-processors is available on request from legal@crisphive.com, and DPA customers may subscribe to notice of sub-processor changes.

15. International Data Transfers

Personal information may be processed or stored outside your country of residence, including in Canada, the United States, or other jurisdictions. When required, we rely on lawful transfer mechanisms such as:

  • Adequacy decisions, where the destination benefits from one (Canada holds an EU adequacy decision for PIPEDA-covered commercial organizations)
  • Standard Contractual Clauses (SCCs), supplemented for the UK by the International Data Transfer Addendum and adapted as recognized by the Swiss FDPIC for transfers from Switzerland
  • Additional contractual, technical, and organizational safeguards where a transfer assessment indicates they are needed

16. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Enable core site functionality
  • Improve performance and usability
  • Understand usage trends

You can control cookies through your browser settings. Disabling cookies may affect functionality.

17. Children's Privacy

The Service is not intended for children under 16. We do not knowingly collect personal information from children.

18. Third-Party Services

The Service may integrate with third-party tools. Their privacy practices are governed by their own policies. We are not responsible for third-party privacy practices.

19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or other reasonable means. Continued use of the Service constitutes acceptance of the updated policy.

20. Contact Us

If you have questions, requests, or concerns about this Privacy Policy or your personal information, contact us at:

WicWac Inc. (Operating as Crisphive)

Suite 1420, 99 Bank Street

Ottawa, Ontario K1P 1H4

Canada

Email: support@crisphive.com

Audit confidentiality and NDA requests: legal@crisphive.com