Privacy Policy
Last updated: August 26, 2026
This Privacy Policy explains how WicWac Inc., operating as Crisphive ("Crisphive," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use our website, applications, and services (collectively, the "Service").
1. Who We Are
Crisphive is a technology platform for scheduling and managing mobile service teams. Crisphive is a brand of WicWac Inc., a company federally incorporated in Canada.
WicWac Inc. (Operating as Crisphive)
Suite 1420, 99 Bank Street
Ottawa, Ontario K1P 1H4
Canada
Contact Email: support@crisphive.com
2. Scope of This Policy
This Privacy Policy applies to:
- Visitors to our website
- Users of our applications and platform
- Customers, account administrators, and authorized users
- Business contacts and communications
- Businesses and individuals who submit data for a free Shadow Schedule Audit (see Section 4)
It does not apply to third-party websites or services linked from Crisphive.
3. Information We Collect
3.1 Information You Provide Directly
We may collect:
- Name, email address, phone number
- Mobile phone number, when you enable SMS notifications or SMS-based login
- Company name and role
- Account login credentials
- Billing and payment information
- Support requests and communications
- Communication preferences, including marketing opt-in and opt-out status
- Any data you upload or enter into the Service ("Customer Data")
- Scheduling and operational data you submit for a Shadow Schedule Audit ("Audit Data" — see Section 4)
3.2 Information Collected Automatically
When you use the Service, we may collect:
- IP address
- Device type, operating system, browser
- Usage logs, timestamps, feature interactions
- Approximate location (city/region)
- Email interaction data (such as delivery, open, and click events) used to operate and improve our communications
This data helps us operate, secure, and improve the Service.
3.3 Customer Data (Service Data)
Customer Data may include:
- Employee names and contact details
- Job schedules, assignments, locations
- Notes, comments, and operational data
You control this data. We process it only to provide the Service. Customer Data — including records about field operations personnel such as technicians, crews, and drivers — is owned and controlled by the business that holds the account, and remains on that business's account when personnel leave the business (see Section 11.3).
4. Shadow Schedule Audit Data
4.1 What This Section Covers
If you request a free Shadow Schedule Audit, you send us one or more days of your real operational scheduling information — which may include job locations, appointment time windows, technician or crew rosters, and related dispatch details ("Audit Data"). Because Audit Data is commercially sensitive and is shared with us before any customer relationship exists, this section is our unilateral, binding confidentiality undertaking to you. It applies automatically to every audit — you do not need to sign anything for it to take effect.
4.2 Single-Purpose Use — Our Undertaking to You
We undertake that Audit Data will be used for one purpose only: to perform your Shadow Schedule Audit — rebuilding your submitted schedule under the same constraints — and to prepare, deliver, and discuss your audit report with you. That is the entire scope of use.
Without limiting the foregoing, we will not:
- Use Audit Data for marketing, advertising, or promotional purposes, or to contact anyone identified in it
- Use Audit Data to train, fine-tune, or improve any machine-learning or AI model
- Sell, rent, license, or trade Audit Data to anyone
- Combine Audit Data with other customers' data, or use it for benchmarking, published statistics, or industry reports, whether or not anonymized
- Use Audit Data to solicit your employees, contractors, or customers
4.3 Confidential Treatment
We treat Audit Data as your confidential information. Access is restricted to Crisphive personnel who need it to perform your audit and who are bound by confidentiality obligations, and it is protected using the safeguards described in Section 12. We will not disclose Audit Data to any third party, except to the service providers that host our infrastructure (acting on our instructions under contractual confidentiality) or where disclosure is required by law, regulation, or court order — in which case, where lawful, we will notify you promptly.
4.4 Deletion
Unless you enter into a subscription or other commercial agreement with us, we delete your Audit Data within thirty (30) days after delivering your audit report, except for copies in routine backups (which remain protected by this section until deleted in the ordinary course) or as required by applicable law. You may also request earlier deletion at any time by emailing legal@crisphive.com. For clarity, Audit Data is deleted on this faster timeline and does not follow the general deletion schedule in Section 11.2.
4.5 Audit Methodology and Limitations — Not a Binding Plan
The Shadow Schedule Audit is produced using Crisphive's own internal scheduling algorithms and large language models (LLMs), which assist in interpreting your submitted data and generating the report. (Consistent with Section 4.2, your Audit Data is processed by these systems to produce your report but is never used to train or improve any model.)
The audit report is an illustrative, point-in-time simulation based solely on the data you submit and the assumptions stated in the report. It is provided for information only, and — for absolute clarity — it is not:
- A binding agreement, offer, quotation, or commitment of any kind by WicWac Inc. or Crisphive
- A guarantee, warranty, or prediction of results, savings, or performance — all figures are estimates and may contain errors or omissions inherent in algorithmic and LLM-generated output
- Professional, financial, legal, or operational advice
- An operational playbook, plan, or instruction set for running your business
You are solely responsible for any decision you make, or refrain from making, in reliance on the audit or its report. For clarity, this subsection concerns the audit outputs only: it does not diminish the confidentiality undertaking in Sections 4.2 to 4.4, which remains binding on us.
4.6 Release; No Liability
To the maximum extent permitted by applicable law, WicWac Inc. (operating as Crisphive) and its subsidiaries, affiliates, and brands, and each of their respective directors, officers, employees, contractors, and agents (together, the "Crisphive Parties"), are indemnified and held harmless by you from, and shall have no liability for, any claim, loss, damage, cost, or expense of any kind — whether direct, indirect, incidental, special, consequential, exemplary, or punitive, and under any theory of liability — arising out of or relating to the audit, the audit report, or any use of or reliance on either, and you release the Crisphive Parties from all such claims. Nothing in this section excludes or limits liability that cannot be excluded or limited under applicable law. If you and Crisphive sign a mutual non-disclosure agreement, the warranty and liability provisions of that agreement govern to the extent of any conflict with this section.
4.7 Legal Effect; Signed NDA Available
Sections 4.2 to 4.4 are intended to be legally binding on WicWac Inc. as a unilateral undertaking in favour of each business that submits Audit Data, and — together with Sections 4.5 and 4.6 — survive for two (2) years from the date we receive your Audit Data. If you prefer a signed agreement, a mutual non-disclosure agreement is available on request — email legal@crisphive.com. If we sign an NDA with you, that NDA governs to the extent of any conflict with this section.
5. How We Use Information
We use personal information to:
- Provide and operate the Service
- Perform the Shadow Schedule Audit, strictly within the limits of Section 4
- Authenticate users and manage accounts, including by SMS one-time passcode (OTP)
- Process payments and subscriptions
- Send Functional Communications necessary to operate your account and the Service (see Section 7)
- Send Marketing Communications where permitted by law and your preferences (see Sections 7 and 8)
- Communicate about updates, support, and service notices, including by SMS where you have consented
- Improve features, performance, and security
- Comply with legal and regulatory obligations
We do not sell personal information.
6. SMS Communications (Notifications and One-Time Passcodes)
Crisphive may send you text (SMS) messages for two distinct purposes: service notifications and login verification via one-time passcodes (OTP). This section explains how consent is obtained for each, how to opt out, and how we handle your mobile number.
6.1 SMS Service Notifications
We may send transactional and informational SMS messages related to your use of the Service, such as schedule changes, dispatch and job alerts, account activity, and service notices. Consent to receive these notifications is obtained through your acceptance of our Terms & Conditions when you create an account or use the Service. These messages are not marketing messages.
6.2 SMS One-Time Passcodes (OTP)
If you choose to log in to the Service using SMS verification, we will send a one-time passcode to your mobile number. Consent for OTP messages is obtained separately and expressly: you must check a consent box when electing to log in via SMS. By checking the box, you authorize Crisphive to send OTP messages to the mobile number you provide, solely for the purpose of verifying your identity and securing your account.
6.3 Never Share Your OTP Codes
One-time passcodes are confidential security credentials. Do not share your OTP code with anyone — including anyone claiming to represent Crisphive. Crisphive and WicWac Inc. will never call, text, or email you to ask for an OTP code. If someone asks you for a code, do not provide it and report the incident to support@crisphive.com immediately.
6.4 Message Frequency, Rates, and Opting Out
- Message frequency varies based on your account activity and settings.
- Message and data rates may apply, depending on your mobile carrier and plan.
- You may opt out of SMS notifications at any time by replying STOP to any message, or by adjusting your notification settings or contacting support@crisphive.com. Reply HELP for assistance.
- Opting out of SMS notifications does not disable OTP messages if you continue to use SMS-based login. If you no longer wish to receive OTP messages, switch to another available login method.
- Withdrawing SMS consent may limit certain features, such as SMS-based login or real-time dispatch alerts, but will not affect your ability to use the rest of the Service.
6.5 Compliance with Applicable Laws
Our SMS practices are designed to comply with the laws of the jurisdictions in which we operate and in which our users reside ("the laws of the land"), including, as applicable, Canada's Anti-Spam Legislation (CASL) and PIPEDA, the U.S. Telephone Consumer Protection Act (TCPA) and applicable CTIA and carrier messaging guidelines, and the GDPR and ePrivacy rules for users in the EEA, UK, or Switzerland. Where local law requires a different or higher standard of consent, that standard prevails. See Section 8 for details of our CASL compliance program.
6.6 No Sharing of Mobile Information
Your mobile phone number and SMS opt-in status are used only to deliver the messages described above. Mobile information and SMS consent data will not be shared with or sold to third parties or affiliates for marketing or promotional purposes. We share mobile numbers only with the telecommunications and messaging service providers that deliver messages on our behalf, under contractual confidentiality.
7. Email Communications
Crisphive sends two distinct categories of email: Functional Communications and Marketing Communications. This section explains the difference, the consent basis for each, and your choices.
7.1 Functional Communications (Essential — Cannot Be Opted Out Of)
Functional Communications are emails that are integral to operating your account and delivering the Service. It is important that you receive them. They include, without limitation:
- Account and security emails (registration confirmations, login verification, password resets, suspicious-activity alerts)
- Billing and subscription emails (invoices, receipts, payment failures, renewal and price-change notices)
- Service and operational emails (schedule and dispatch notifications, outage and maintenance notices, critical product changes)
- Legal and policy notices (changes to these policies, required disclosures, breach notifications)
Consent to receive Functional Communications is obtained through your acceptance of our Terms & Conditions and is a condition of holding an account. Because these emails are necessary for the operation, security, and administration of the Service and may contain information you are required to receive by law or contract, you cannot opt out of Functional Communications while you maintain an account. The only way to stop receiving them is to close your account. Functional Communications are not marketing and are exempt from marketing consent requirements under applicable law.
7.2 Marketing Communications (Optional — Opt-Out Anytime)
Marketing Communications include newsletters, product announcements, promotions, event invitations, surveys, and similar content. We send Marketing Communications only where permitted by applicable law — on the basis of your express consent, an existing business relationship where the law allows it, or another lawful basis — and every Marketing Communication includes a clear and functioning unsubscribe mechanism. You may opt out of Marketing Communications at any time by:
- Clicking the unsubscribe link in any marketing email
- Adjusting your communication preferences in your account settings
- Emailing support@crisphive.com
We will honor opt-out requests promptly and in any event within the timeframe required by applicable law (for example, within 10 business days under CASL). Opting out of Marketing Communications does not affect Functional Communications, which you will continue to receive while your account is active.
7.3 Compliance with Applicable Laws
Our email practices are designed to comply with the laws of the jurisdictions in which we operate and in which our users reside, including, as applicable, Canada's Anti-Spam Legislation (CASL), the U.S. CAN-SPAM Act, and the GDPR and ePrivacy rules for users in the EEA, UK, or Switzerland. Where local law imposes a different or higher standard, that standard prevails. See Section 8 for details of our CASL compliance program.
7.4 Your Responsibilities and Delivery Disclaimer
Email is not a guaranteed delivery medium. You are responsible for keeping the email address on your account accurate and current, for ensuring that emails from Crisphive are not blocked or filtered (including checking spam or junk folders), and for reviewing Functional Communications in a timely manner. A Functional Communication is deemed given when sent by us to the email address on file for your account. To the maximum extent permitted by applicable law, Crisphive and WicWac Inc. are not liable for any loss, damage, or consequence arising from your failure to receive, read, or act on a communication where that failure results from an inaccurate or outdated email address, spam or security filtering, mailbox limitations, or the acts or omissions of third-party email providers or networks.
8. Canada's Anti-Spam Legislation (CASL)
Crisphive is a Canadian company, and Canada's Anti-Spam Legislation (CASL) governs the commercial electronic messages ("CEMs") — emails and SMS messages with commercial content — that we send to electronic addresses in Canada. This section explains how we comply. Where Sections 6 and 7 and this section overlap, the stricter standard applies.
8.1 What Counts as a CEM
A CEM is an electronic message that encourages participation in a commercial activity — for example, our newsletters, product announcements, promotions, event invitations, and similar Marketing Communications (Section 7.2). The following are not CEMs and may be sent without marketing consent, consistent with CASL's exemptions:
- Functional Communications under Section 7.1 (account, security, billing, service, and legal notices)
- SMS service notifications and OTP messages under Section 6
- Messages that deliver something you requested, such as your Shadow Schedule Audit report, a quote, or a response to your inquiry
- Messages that complete or facilitate a transaction you have already agreed to
8.2 Consent — Express and Implied
We send CEMs only with valid consent:
- Express consent. You actively opt in — for example, by checking an unchecked box when subscribing to our newsletter or requesting marketing content. We never use pre-checked boxes, and consent to marketing is never a condition of using the Service or receiving a Shadow Schedule Audit. Express consent remains valid until you withdraw it.
- Implied consent — existing business relationship. If you purchase a subscription or enter into a contract with us, CASL implies consent for two (2) years from the purchase or the end of the contract. If you make an inquiry or application to us — including requesting a Shadow Schedule Audit — CASL implies consent for six (6) months from the inquiry.
- Implied consent — conspicuous publication / provided address. For business-to-business outreach, we may rely on an electronic address you have conspicuously published (for example, on your company website) or given to us, without a statement that you do not wish to receive unsolicited CEMs, and only where the message is relevant to your business role or function.
When implied consent expires, we stop sending CEMs to that address unless you have given express consent in the meantime.
8.3 Shadow Schedule Audit and CASL
Requesting a Shadow Schedule Audit creates implied consent (as an inquiry) to contact you, the requester, at the contact details you provide on the audit form, for up to six (6) months. This is separate from, and does not diminish, our undertaking in Section 4.2: we will never use contact information of employees, technicians, or customers contained within your Audit Data for marketing or any other outreach.
8.4 Message Identification and Unsubscribe
Every CEM we send:
- Identifies WicWac Inc. (operating as Crisphive) as the sender and includes our mailing address (Suite 1420, 99 Bank Street, Ottawa, Ontario K1P 1H4, Canada) and a way to contact us
- Contains a clear, no-cost unsubscribe mechanism that works for at least sixty (60) days after the message is sent
- Reflects unsubscribe requests promptly, and in any event within ten (10) business days, as stated in Section 7.2
Unsubscribing from Marketing Communications does not affect Functional Communications (Section 7.1) or requested deliverables such as your audit report.
8.5 Records of Consent
We keep records sufficient to demonstrate consent for each CEM recipient, including the date, source, and method of consent (for example, form submission details) and the date and handling of every unsubscribe request, as noted in Section 11 (Data Retention and Deletion).
8.6 Questions and Complaints
Questions about our CASL practices can be sent to support@crisphive.com. You may also contact the Canadian Radio-television and Telecommunications Commission (CRTC), which enforces CASL, or file a report through the Government of Canada's Spam Reporting Centre at fightspam.gc.ca.
9. GDPR — Roles, Legal Bases, and Your Choices
For users in the EEA, UK, or Switzerland, this section explains how we process personal data under the GDPR and equivalent UK and Swiss law. Read it together with Section 13.2 (your rights), Section 14 (our Data Processing Addendum), and Section 15 (international transfers).
9.1 Our Roles — Controller and Processor
WicWac Inc. acts as a data controller for personal data we collect for our own purposes — website visits, account registration, billing, support, and marketing. We act as a data processor for Customer Data (Section 3.3) and Audit Data (Section 4), which we process only on your documented instructions to deliver the Service or perform your audit. Where we act as processor, the Data Processing Addendum described in Section 14 governs our processing.
9.2 Legal Bases for Processing
Where we act as controller, we process personal data under the following legal bases:
- Performance of a contract (including Functional Communications necessary to operate your account, and performing a Shadow Schedule Audit you have requested)
- Legitimate business interests (including service security notices and, where permitted, business-to-business marketing)
- Compliance with legal obligations (including legally required notices)
- Consent, where required (including express consent for SMS-based login via OTP and for Marketing Communications where consent is the applicable basis)
9.3 Marketing and ePrivacy
Where consent is the applicable basis for Marketing Communications, we obtain it through an affirmative, unchecked opt-in — the same standard described in Section 8.2 — and every marketing message includes a working unsubscribe mechanism (Section 8.4). Where we rely on the existing-customer ("soft opt-in") exception under ePrivacy rules, we do so only for our own similar products and services, and you are offered an opt-out at the time your address is collected and in every message thereafter.
9.4 Objecting and Withdrawing Consent
You may object to or withdraw consent for direct marketing at any time (see Section 7.2), without giving a reason and without affecting the lawfulness of processing before withdrawal. This does not affect Functional Communications necessary to perform our contract with you, or processing we carry out under another legal basis.
11. Data Retention and Deletion
11.1 How Long We Retain Information
We retain personal information:
- For as long as your account is active
- As needed to provide the Service
- As required by law or legitimate business purposes
OTP codes are short-lived, single-use credentials and are not retained after they expire or are used. Records of marketing consent and opt-out requests are retained as required to demonstrate compliance with applicable law (see Section 8.5). Audit Data is retained and deleted on the shorter timeline set out in Section 4.4.
11.2 Deletion Requests — Timeline
Our full deletion process is set out in our Data Deletion Policy, which forms part of this Privacy Policy. In summary, once a deletion request is verified (or an account is terminated):
| Period | What happens |
|---|---|
| Days 0–30 | The data is deactivated and removed from Service use, then retained in identifiable form for thirty (30) days to allow verification, error or fraud recovery, and completion of in-flight transactions. |
| Day 30 | The data will be irreversibly anonymized — identifiers are permanently removed so it can no longer be linked to any individual or business. |
| Days 30–365 | The anonymized data will be retained for a further three hundred and thirty-five (335) days, and is used only for aggregate statistics, capacity planning, Service performance and security analysis, and demonstrating regulatory compliance. |
| Day 365 | The anonymized data will be permanently purged from active systems; backup copies are overwritten in the ordinary course of our backup rotation. |
Where applicable law — primarily the laws of Canada (including PIPEDA and substantially similar provincial legislation) and the United States (including applicable state privacy laws) — requires a shorter timeline or a different standard, that law prevails. Data subject to a legal hold or a statutory retention obligation (for example, tax and billing records, or CASL consent records) is retained only as required and only for that purpose.
11.3 Field Operations Personnel Who Leave a Business
If a field operations worker (such as a technician, crew member, or driver) leaves a business that uses the Service, the Customer Data relating to that worker belongs to the business and remains stored on the business's account. The business — as owner and controller of its Customer Data — chooses what to do with it: retain, export, anonymize, or delete it, subject always to the local laws that apply to the business, including employment-records retention requirements and privacy legislation. Crisphive acts as a service provider (processor) for this data. Departed personnel who wish to exercise rights over their data should contact the business directly; if they contact us, we will forward the request to the business where feasible or direct them to it, and we will assist the business in responding within legally required timelines. Where applicable law gives departed personnel rights directly against Crisphive, we will honour them. See Section 6 of the Data Deletion Policy for details.
11.4 Account Termination
Upon account termination, Customer Data may be exported by the business on request and then enters the deletion timeline in Section 11.2, subject to legal obligations.
12. Data Security
We implement reasonable administrative, technical, and physical safeguards designed to protect personal information, including:
- Access controls
- Encryption in transit (where applicable)
- Secure hosting environments
- Role-based permissions
- Time-limited, single-use one-time passcodes for SMS login
No system is 100% secure, but we work to protect your data.
13. Your Rights
13.1 Canada (PIPEDA and CASL)
You have the right to:
- Access your personal information
- Request corrections
- Request deletion of your personal information, handled per our Data Deletion Policy (see Section 11.2)
- Withdraw consent (subject to legal/contractual limits), including consent to SMS communications and Marketing Communications
- Unsubscribe from commercial electronic messages at any time under CASL (see Section 8.4)
13.2 European Union, UK, and Switzerland (GDPR)
You may have the right to:
- Access, correct, or delete personal data
- Restrict or object to processing, including objecting to direct marketing at any time
- Data portability
- Withdraw consent
- Lodge a complaint with a supervisory authority
To exercise any of these rights, email support@crisphive.com. We respond within one month of receiving a verified request; for complex or numerous requests, this may be extended by up to two further months, in which case we will tell you within the first month. We do not charge a fee unless a request is manifestly unfounded or excessive. If your data is in Customer Data or Audit Data that we process on behalf of a business (see Section 9.1), we may direct your request to that business as the controller. You may also lodge a complaint with your local supervisory authority, the UK Information Commissioner's Office (ICO), or the Swiss Federal Data Protection and Information Commissioner (FDPIC).
13.3 United States
Certain U.S. state privacy laws provide residents with rights regarding access, deletion, correction, and portability of personal data, and the right not to be discriminated against for exercising them. We honour applicable state requirements, including verified deletion requests, within the timelines those laws prescribe; where a state law requires faster action than the timeline in Section 11.2, the state law timeline governs. Requests can be submitted as described in Section 3 of the Data Deletion Policy.
14. Data Processing Addendum (GDPR)
If you are an enterprise or EU customer, our Data Processing Addendum (DPA) applies and is incorporated by reference. The DPA governs:
- Processing instructions
- Confidentiality
- Sub-processors
- Cross-border transfers (Standard Contractual Clauses)
We engage sub-processors only under written terms imposing data protection obligations at least as protective as those in our DPA, and we remain responsible for their performance. A current list of sub-processors is available on request from legal@crisphive.com, and DPA customers may subscribe to notice of sub-processor changes.
15. International Data Transfers
Personal information may be processed or stored outside your country of residence, including in Canada, the United States, or other jurisdictions. When required, we rely on lawful transfer mechanisms such as:
- Adequacy decisions, where the destination benefits from one (Canada holds an EU adequacy decision for PIPEDA-covered commercial organizations)
- Standard Contractual Clauses (SCCs), supplemented for the UK by the International Data Transfer Addendum and adapted as recognized by the Swiss FDPIC for transfers from Switzerland
- Additional contractual, technical, and organizational safeguards where a transfer assessment indicates they are needed
17. Children's Privacy
The Service is not intended for children under 16. We do not knowingly collect personal information from children.
18. Third-Party Services
The Service may integrate with third-party tools. Their privacy practices are governed by their own policies. We are not responsible for third-party privacy practices.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or other reasonable means. Continued use of the Service constitutes acceptance of the updated policy.
20. Contact Us
If you have questions, requests, or concerns about this Privacy Policy or your personal information, contact us at:
WicWac Inc. (Operating as Crisphive)
Suite 1420, 99 Bank Street
Ottawa, Ontario K1P 1H4
Canada
Email: support@crisphive.com
Audit confidentiality and NDA requests: legal@crisphive.com