SHIFTNOW

Privacy Policy

Effective date: January 1, 2026

Contents

1. Introduction 2. Information We Collect 3. How We Use Information 4. Legal Bases for Processing 5. Data Sharing and Disclosure 6. Cookies and Tracking Technologies 7. Data Retention 8. Data Security 9. Your Rights and Choices 10. Privacy for Children 11. International Data Transfers 12. Third Party Services 13. Data Breach Response 14. Changes to This Privacy Policy 15. Contact Information

1Introduction

This Privacy Policy explains how Shift Now Corp., operating the website shiftnow.hair, collects, uses, discloses, and safeguards information when you visit the website or use the services described on it. The website and its related services are designed, developed, and operated by the developer ShiftNow. Our registered business address is 151 Carlson Close Nw, Edmonton, AB T6R 2J7, Canada.

We wrote this policy to be straightforward and useful. It tells you what information we collect, why we collect it, how we protect it, and what choices you have. By accessing or using the website, you acknowledge that you have read and understood this policy. If you do not agree with any part of it, you should stop using the website. We encourage you to review this page regularly because we may update it from time to time as our practices or the law evolves.

This policy covers only our own website and services. It does not cover the practices of third parties whose websites or tools we may reference or link to. When you leave our website, the privacy practices of the destination site apply. We are not responsible for the content or privacy standards of those external services.

2Information We Collect

We collect information that you provide to us directly, information that we gather automatically when you use the website, and in limited cases, information we receive from third parties who help us operate. Each category is described below so you know exactly what data is involved and why we need it.

Information you provide directly includes your name, email address, telephone number, company name, and the content of any message you send through the contact form or by email. We collect this information when you request information about our services, ask a question, request a proposal, or otherwise communicate with us. You are never required to provide this information, but without it we may not be able to respond to your inquiry or provide the service you requested.

Information collected automatically includes your device type, browser type, operating system, internet protocol address, approximate geographic region, the pages you visit, the time and date of your visit, the referring website, and other standard usage statistics. We collect this data through server logs and standard web technologies, as described in the section on cookies and tracking technologies.

In some cases we receive information from third parties, including publicly available business records, references you provide, and information shared by partners who introduce your company to us. We combine this information with data we already hold only when it helps us serve you better and when we are permitted to do so under applicable law.

3How We Use Information

We use the information we collect for purposes that are directly related to operating the website and delivering our services. The primary purposes are responding to your inquiries, preparing proposals, delivering the computer systems design and integration services you request, and providing ongoing support and maintenance.

We also use information to improve the website and our services. Usage data helps us understand which pages are useful, which content interests our visitors, and where visitors encounter friction. We use that understanding to make the website faster, clearer, and more helpful over time.

We may use contact information to send you service-related communications, including project updates, security notices, and administrative messages that are necessary to our relationship. We may also send you occasional updates about our services and capabilities that we believe are relevant to your business, if you have not opted out. You can ask to stop receiving marketing communications at any time.

Finally, we use information for security and legal purposes, including detecting and preventing fraud or abuse, protecting the rights and safety of our company and our clients, and complying with legal obligations such as record keeping requirements and lawful requests from authorities.

4Legal Bases for Processing

We process personal information on the basis of applicable privacy laws, including the laws of Canada, the European General Data Protection Regulation where it applies, and other relevant frameworks. The legal bases we rely on are consent, contract, legitimate interests, and legal obligation.

Consent applies when you choose to provide information, for example when you fill out our contact form or subscribe to communications. Where we rely on consent, you may withdraw it at any time, and doing so will not affect the lawfulness of processing that took place before the withdrawal.

Contract applies when we need to process information to enter into or perform an agreement with you, such as a service agreement for a systems design project. Legitimate interests apply when processing is necessary for purposes such as improving the website, protecting our systems, and conducting normal business operations, provided that our interests do not override your rights and freedoms.

Legal obligation applies when we must process information to comply with a law, regulation, court order, or other binding requirement. Where processing is based on this ground, we will process only the information required to satisfy the obligation and no more.

5Data Sharing and Disclosure

We do not sell personal information, and we do not rent it to anyone. We share personal information only in the limited circumstances described in this section, and always under arrangements that require the recipient to protect the data to at least the same standard we apply ourselves.

We share information with service providers who help us operate, including web hosting providers, analytics providers, email and communications providers, and accounting or legal advisors. These providers receive only the information they need to perform their specific function, and we require them to use it only for that function.

We may share information in connection with a business transaction, such as a merger, acquisition, reorganization, or sale of assets. In that event, we will require the new owner to honor this policy or to notify you before your information is used in a materially different way.

We may disclose information when required by law, including in response to a subpoena, court order, or other legal process, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, or to investigate and prevent unlawful activity. Finally, we may share information with your consent or at your direction.

6Cookies and Tracking Technologies

The website uses cookies and similar technologies to function properly and to understand how visitors use the site. A cookie is a small text file that a website stores on your device. Cookies can be necessary for the site to work, or they can be used to remember preferences and measure usage.

Strictly necessary cookies are required for basic functions such as keeping your session secure and maintaining consistent behavior across the site. These cookies cannot be disabled without preventing parts of the site from working.

Analytics cookies help us count visits, understand which pages are popular, and learn where visitors spend the most time. The data collected through these cookies is aggregated and is not used to identify individual visitors. We use this information only to improve the site.

You can control cookies through your browser settings. Most browsers allow you to block or delete cookies, and you can set your browser to alert you when a site tries to place a cookie. If you disable cookies, some features of the website may not work as intended, but you can still view the content of the site. We do not use advertising or cross-site tracking cookies.

7Data Retention

We keep personal information only as long as necessary for the purposes described in this policy, or as required by applicable law. Our retention periods are designed to balance your privacy interests with our legitimate operational needs.

Information you submit through the contact form is kept for a reasonable period to allow us to respond to your inquiry and to maintain a record of our business relationship. If we enter into a service agreement with you, project-related records are retained for the term of the agreement and for a reasonable period afterwards to support audits, warranties, and legal requirements.

Automated usage logs are retained in a form that can identify a device for a limited period, typically long enough to diagnose technical issues and prevent abuse. After that period, we aggregate or delete the raw logs. We do not retain raw usage data indefinitely.

When information is no longer needed, we delete it or anonymize it in a way that it can no longer be linked to you. Some information may be retained longer where required by tax, accounting, or other legal obligations, and in those cases the data is restricted to the purpose of that obligation.

8Data Security

We apply reasonable administrative, technical, and physical safeguards designed to protect personal information against loss, theft, and unauthorized access, disclosure, alteration, and destruction. Security is a core part of our engineering practice, not an afterthought.

On the technical side we use encryption for data in transit and at rest where appropriate, restrict access to personal information to employees who need it to perform their duties, and require strong authentication for systems that store sensitive data. We review our security controls regularly and update them as threats evolve.

On the organizational side we train our staff in data protection practices, limit access according to the principle of least privilege, and maintain clear procedures for handling and reporting incidents. Our engineering team applies security reviews as a standard part of every system we build, including systems we build for clients.

No method of transmission or storage is completely secure. While we work hard to protect your information, we cannot guarantee absolute security against every conceivable threat. If you believe your information has been compromised, please contact us immediately using the details at the end of this policy so we can investigate and respond.

9Your Rights and Choices

Depending on where you live, you may have rights over the personal information we hold about you. We honor these rights to the extent required by law and will respond to every legitimate request without undue delay.

You have the right to access the personal information we hold about you and to receive a copy of it in a portable, commonly used format where required by law. You have the right to request correction of inaccurate or incomplete information so that our records reflect the facts.

You have the right to request deletion of your personal information in certain circumstances, for example when the information is no longer needed for the purposes for which it was collected. You also have the right to object to processing based on legitimate interests, to request restriction of processing in limited cases, and to withdraw consent where processing is based on consent.

To exercise any of these rights, contact us at the address or email listed at the end of this policy. We may need to verify your identity before acting on a request, which is a security measure to protect your information from being disclosed to the wrong person. If you are not satisfied with our response, you may lodge a complaint with the privacy regulator in your jurisdiction.

10Privacy for Children

Our website and services are directed at businesses and professionals, not at children. We do not knowingly collect personal information from children under the age of 13, and we do not design our content or features to appeal to children.

If you are a parent or guardian and you believe that your child has provided personal information to us without your knowledge, please contact us using the details at the end of this policy. We will take reasonable steps to delete that information from our records as quickly as possible and to prevent it from being collected again.

We also respect the higher standards applied in jurisdictions such as the European Economic Area, where the age at which children may consent to the processing of personal information is higher. In those jurisdictions, we will not knowingly collect information from anyone below the applicable age without verifiable parental consent.

Because our services are business oriented, in practice we receive very little information relating to children. If the situation ever arises, the protections described in this section will apply. We encourage families to stay involved in their children online activities and to speak with their children about protecting personal information online.

11International Data Transfers

Shift Now Corp. is based in Canada, and our primary operations are located in Edmonton, Alberta. Information we collect may be stored and processed in Canada and, in limited cases, in other jurisdictions where our service providers operate.

When personal information is transferred across borders, we ensure that appropriate safeguards are in place to protect it, consistent with applicable data protection laws. This may include contractual clauses approved by relevant authorities, reliance on adequacy decisions where available, and standard security practices regardless of the location of the data.

The laws of the country where data is stored may differ from the laws of your own country. However, we apply the same internal standards to personal information regardless of where it is stored. We do not transfer personal information to a jurisdiction unless we are satisfied that the recipient can provide a comparable level of protection.

If you have questions about international transfers or the safeguards we use, you can contact us using the details at the end of this policy and we will provide you with the relevant information where permitted by law.

12Third Party Services

Our website may contain links to websites and online services operated by third parties, including our business partners, industry resources, and the software platforms we use internally. These links are provided for your convenience.

When you follow a link to a third party website, you leave our site and the privacy practices of that website apply to any information you provide there. We do not control those websites, and we are not responsible for their content, their privacy policies, or their security practices.

We may use third party tools to understand website usage and to support our communications, for example analytics platforms and email services. Where these tools process personal information, we require them to process it only on our behalf and in accordance with our instructions, and we review their practices before we engage them.

We encourage you to read the privacy policy of every website you visit, including the sites we link to. You should assume that any personal information you submit to a third party website is subject to that third party own policy, not to this one.

13Data Breach Response

We take data security incidents seriously and maintain procedures designed to detect, contain, and respond to breaches of personal information in a timely manner. Our response plan is tested and reviewed regularly as part of our security program.

When we become aware of a potential breach, our first priority is to contain it and prevent further exposure. We then assess the scope of the incident, determine what information was affected, and take steps to secure the affected systems and data.

Where applicable law requires notification, we will notify affected individuals and the relevant supervisory authority without undue delay after we have confirmed the breach and assessed its risk. Notifications will describe the nature of the incident, the categories of information involved, and the steps we are taking in response.

We document every incident, including the cause, the response, and the lessons learned, so that we can strengthen our controls over time. Our clients benefit from this experience directly, because the same disciplines are applied to every system we design, integrate, and operate on their behalf.

14Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, new technologies, or legal requirements. When we make changes, we will revise the effective date at the top of this page so you can easily see when the policy was last updated.

If we make material changes that affect how we use or disclose personal information, we will take reasonable steps to make you aware of the update, for example by displaying a notice on the website or, where appropriate, by sending a notice to the email address we hold for you.

Your continued use of the website after changes take effect constitutes your acceptance of the revised policy. If you do not agree with the revised terms, you should stop using the website and, if you wish, contact us to have your information deleted or updated.

We encourage you to review this page periodically. Keeping this policy current is part of our commitment to transparency, and we aim to make every version of it clear and easy to understand for our visitors and clients.

15Contact Information

If you have questions, concerns, or requests relating to this Privacy Policy or to the handling of your personal information, please contact us. We will respond to your message as quickly as we reasonably can, and in any event within the time frames required by applicable law.

Our company contact details are as follows. Shift Now Corp., 151 Carlson Close Nw, Edmonton, AB T6R 2J7, Canada. You can reach us by email at serve@shiftnow.hair or by telephone at +12188249639.

When you contact us, please describe your question clearly and provide enough detail for us to verify your identity if necessary. This helps us respond accurately and protects your information from being disclosed inappropriately.

If you are located in a jurisdiction with a data protection regulator and you are not satisfied with our response to a complaint, you may have the right to lodge a complaint with that regulator. We would always welcome the opportunity to resolve a concern directly with you first.

Return to ShiftNow Home · Terms of Service · Services · Contact