Mobile App Privacy Policy
BWA Horizon for iOS and Android — operated by BWA Solutions Inc., Ottawa, Ontario, Canada
Last updated: July 27, 2026
The BWA Horizon mobile app is a companion client for existing BWA Horizon customers. This policy explains what the app collects, how we use it, and where your data is stored.
1. Who this policy is for
The BWA Horizon mobile app is a companion client for existing BWA Horizon customers — restaurants and food businesses whose staff sign in with an account that BWA Horizon has already provisioned. It is not a consumer app and does not offer public sign-up from the app. You reach the app's data only after authenticating against an existing tenant account.
2. What the app collects
The mobile app itself touches a deliberately small surface.
2.1 Account credentials (you provide)
Your email address and password are entered on the sign-in screen and sent over HTTPS to the BWA Horizon backend to authenticate you. The password is never stored on the device. On success, a short-lived access token is stored in the platform secure keystore (iOS Keychain / Android Keystore) so you stay signed in. Signing out or uninstalling removes it.
2.2 Business data the app displays (we already hold it)
After you sign in, these screens read — but do not create new personal data from — your tenant's operational data:
- Today's order proposal
- Your savings summary
- Flyer and price deals
This is your business's procurement and pricing data, scoped to your tenant by row-level security on the backend. It is shown to you; it is not collected from your device. Uploading a sales export is the one path that does send data from your device, and it is covered separately in section 2.3. Personal-data fields that BWA Horizon holds server-side (account email, business contact details, supplier and delivery contacts) are governed by the company-wide privacy policy, not by the app alone.
2.3 Files you upload (you choose)
The app's Upload tab lets you send your own sales-history export to your BWA Horizon account. This is the one path where a file leaves your device.
- What is sent. A delimited-text file you pick yourself — CSV, TSV, or TXT only. The app checks the file extension before anything is sent; other file types are rejected on the device and never transmitted. There is no photo or image upload path in the app.
- When it is sent. Only when you deliberately choose a file and tap upload. Nothing is uploaded in the background, on a schedule, or automatically.
- Where it goes. Over HTTPS to the BWA Horizon backend, scoped to your tenant. It is parsed into your own sales and demand records — the same import pipeline as the web dashboard. You see a preflight summary of what was accepted or rejected and must confirm before anything is committed; you can cancel instead, which discards the upload server-side.
- Permissions. Choosing the file uses the operating system's own document picker, which runs outside the app. It grants access to that one file only and requires no photo-library, camera, or general storage permission.
- Retention. The uploaded file and the records created from it are retained under your tenant's configured retention window (see section 6), the same as data you enter in the web dashboard.
These files are your business's operational records. Where they happen to contain personal information (for example a staff or customer name in a free-text column), it is handled under this policy and the company-wide privacy policy on the same terms as the rest of your tenant's data.
2.4 Crash and performance diagnostics (automatic)
Crash reports and limited performance traces are collected via Sentry to keep the app stable. The SDK is configured so that no personal identifiers are automatically attached, with a 20% performance-trace sample rate. Diagnostics are only sent when a Sentry key is configured for the build; with no key configured, nothing is sent.
2.5 What the app does not collect
The app requests no location, contacts, camera, microphone, photos, health, or calendar access. Sending a sales export (section 2.3) uses the operating system's document picker, which is not photo-library or camera access and prompts for no such permission. The app contains no advertising or tracking SDKs, sets no advertising identifier, and does not track you across other companies' apps or websites. No Apple App Tracking Transparency (ATT) prompt is shown because no tracking occurs.
3. How we use this data
- Authenticate you and keep your session active.
- Show you your tenant's order proposals, savings, and deals.
- Import the sales history you upload into your tenant's own records, so it can inform your demand and procurement figures.
- Diagnose crashes and performance issues to keep the app reliable.
We do not use any of this data for advertising or for building cross-app profiles.
4. Sharing and service providers
We do not sell your personal information. Data is processed by a limited set of service providers engaged to run the platform. The mobile data paths above involve:
- Sentry — crash and performance diagnostics.
- Supabase — the primary datastore holding your business data.
- Railway — backend application hosting, which receives your sign-in request and serves your business data.
The wider BWA Horizon platform uses additional service providers for messaging, transactional email, delivery dispatch, and document processing. To request the current list of service providers, contact privacy@bwa-horizon.com.
5. Data location and cross-border transfer
Primary application data — your account record and your tenant's business data — is stored in Supabase, in the Canada Central (ca-central-1) region.
Other parts of the platform process data in the United States, including:
- Railway — backend application hosting and runtime logs.
- Vercel — web frontend hosting.
- Sentry — crash and performance diagnostics.
Additional service providers used by the wider platform (messaging, email, delivery, and document processing) may also process data outside Canada.
Because personal information may be processed outside Canada, it may be subject to the laws of the jurisdiction where it is processed, including lawful access requests by authorities there. We remain accountable for personal information transferred to a service provider for processing, and use contractual means to require a comparable level of protection.
6. Retention
Account data persists for the life of the account plus your tenant's configured retention window (365 days by default). Files you upload, and the records created from them, are retained under that same window; an upload you cancel before confirming is discarded. The on-device access token lives only until you sign out or uninstall. Diagnostic data follows Sentry's retention configuration.
7. Security
- All traffic between the app and our backend is over HTTPS.
- The session token is held in the OS-level secure keystore, not in plain app storage.
- Server-side, tenant data is isolated by row-level security; per-tenant secrets are encrypted at rest.
8. Your privacy rights
Subject to applicable law — including Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Law 25 — you may request access to, correction of, or deletion of your personal information, and may withdraw consent. To exercise a right, contact privacy@bwa-horizon.com or your BWA Horizon account contact. We will respond within the timelines required by applicable law.
9. Children
BWA Horizon is a business tool and is not directed to children. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this policy. Material changes will be reflected at the published policy URL with a new “Last updated” date.
11. Contact
BWA Solutions Inc.
Ottawa, Ontario, Canada
Privacy: privacy@bwa-horizon.com
Support: support@bwa-horizon.com