Privacy Policy

Last updated: September 2, 2026

This Privacy Policy describes how ApisCore ("we") collects, uses, stores, and shares information when you use our apiary management service at apiscore.ca and related deployments.

Information we collect

We collect information needed to operate a secure multi-tenant apiary platform.

  • Account data: name, email, organization name, province or territory, password hash, MFA secrets when enabled, team role, and organization memberships.
  • Operational data: apiaries, hives, inspections, treatments, harvests, inventory, contracts, labels, traceability records, landowner details, signatures, expenses, and files you enter.
  • Communications: support messages, feedback, and email/SMS delivery metadata for notifications you or your organization enable.
  • Integration data: OAuth tokens and sync metadata for connected accounting or sensor services, when you connect them.
  • Usage and security data: httpOnly session cookies, hashed session tokens, login and audit logs, platform administrator actions (including view-as events), and diagnostic logs required to secure the Service.

Cookies and authentication

We use a session cookie to keep you signed in. The cookie is httpOnly, expires after seven days of inactivity, and uses Secure and SameSite protections in production.

Session tokens are stored in hashed form at rest. We do not store your password in plain text.

You can end a session by logging out. Password resets and certain security changes invalidate existing sessions.

How we use information

We use your data to provide the Service, authenticate users, enforce permissions, generate reports and labels, run scheduled compliance and operations jobs you enable, deliver notifications, improve reliability, and investigate abuse or security incidents.

We do not sell personal information. We do not use operational hive data for unrelated advertising.

Marketing-style broadcasts respect opt-out preferences where applicable. Required notices about terms, privacy, or major platform changes may still be sent to account holders.

AI processing

When AI features are enabled, we may send content you submit—such as field inspection text, Hive Assistant questions, short operational summaries built from your records, or voice audio for transcription—to Google (Gemini) for processing.

We configure AI to support beekeeping operations, not to make definitive disease diagnoses. AI providers process data under their own terms and privacy policies.

If AI is disabled, we may use local rule-based parsing instead and will not send that content to an AI provider for those features.

Sharing and processors

We share data only as needed to operate the Service, at your direction, or to comply with law.

  • Hosting, database, and infrastructure providers that process data on our behalf under contractual safeguards.
  • Email delivery (for example Zoho Mail) for password resets, invites, reports, and alerts you enable.
  • SMS delivery (for example Twilio) when your deployment is configured and your organization enables text alerts.
  • Google (Gemini) when AI features are enabled and you use them.
  • Accounting platforms (for example QuickBooks) when you explicitly connect them.
  • Sensor or webhook integrations when you register devices or endpoints.
  • Public trace, landowner, grower, or portal pages when you publish a tokenized link—only the fields you choose to expose.

Public and shared links

Some features generate tokenized URLs for landowners, growers, honey traceability, or hive QR scans. Anyone with the link may see the limited information configured for that page until you revoke or disable access.

Do not share portal or trace links more broadly than intended. You are responsible for the operational data you choose to expose.

Retention and security

We retain account and operational data while your organization uses the Service. You may export reports and CSV financial exports at any time where the feature is available.

We use industry-standard measures including password hashing, hashed session and invite tokens, CSRF protections for cookie-based requests, role-based access control, and encrypted transport (HTTPS) in production.

No method of transmission or storage is completely secure. Report suspected unauthorized access promptly.

Your rights (Canada)

Under PIPEDA and applicable provincial privacy laws, you may request access to or correction of personal information we hold about you, subject to legal exceptions.

Contact us to exercise these rights. We will respond within a reasonable period.

Contact

Privacy questions: support@apiscore.ca

Create account · Terms of Service