Privacy Policy
Helius Retail Technologies
17939973 Canada Ltd., operating as Helius Retail Technologies
570 Hood Rd Unit 14 #3111, Markham, ON L3R 4G7
Last updated: October 8, 2026
Privacy at a glance
- Helius sells retail software to businesses in Canada. This policy explains how we handle personal information about visitors to our website, our business customers and their staff, and the shoppers in our customers' stores.
- For our website and our business customers, Helius is responsible for the personal information we collect.
- For shoppers in a store that runs on Helius, the store operator is generally responsible. We process shopper information on the operator's behalf, as its service provider, to run the store's systems.
- We do not sell personal information. We do not store full payment card numbers. We do not use facial recognition or other biometric identification.
- Questions or requests: privacy@heliusretail.com.
Contents
- Who we are
- Our two roles
- What this policy covers
- Information we collect
- How we use information
- Consent and the legal basis for processing
- Cameras and video
- Access control and event logs
- Biometrics, facial recognition and new features
- How we share information
- Where information is stored and transferred
- How long we keep information
- How we protect information
- Your privacy rights
- Requests from shoppers
- Privacy breaches (confidentiality incidents)
- Children and minimum age
- Marketing emails and your choices
- Cookies
- Third-party websites and services
- Our Privacy Officer and how to contact us
- Changes to this policy
1. Who we are
Helius Retail Technologies ("Helius", "we", "us" or "our") is the operating name of 17939973 Canada Ltd., a federal corporation incorporated under the laws of Canada. Our registered and mailing address is 570 Hood Rd Unit 14 #3111, Markham, ON L3R 4G7.
We provide software to retail businesses in Canada, such as micro market operators and small staffed, self-serve or unstaffed stores ("operators" or "customers"). Our products are:
- Helius POS: self-checkout point-of-sale software for checkout lanes, with back-office inventory and reporting. On some plans it connects to security cameras through our integration partner, Solink.
- Helius Retail OS: a system for running staffed, hybrid or fully unstaffed stores. It includes mobile access control (shoppers unlock the store door in the Helius app), customer registration (verified shopper accounts), POS lanes, a back-office inventory management system, security camera integration, and event tracking that links door, lane and camera events.
In this policy, the "Services" means these products, our website at heliusretail.com, the Helius apps, and our related onboarding and support.
2. Our two roles
We handle personal information in two different roles. Which one applies depends on whose information it is.
| Whose information | Examples | Who is responsible | Where to send requests |
|---|---|---|---|
| Website visitors and people who contact us | Contact form details, emails, cookie data | Helius | Helius (see section 21) |
| Business customers and their staff (operators and their authorized users) | Account, billing, user logins, support history | Helius | Helius (see section 21) |
| Shoppers in operators' stores | Registration, app door unlocks, purchases, camera video, event logs | The store operator, generally. Helius processes this information on the operator's behalf as its service provider. | The store operator first. We will pass on any request we receive and help the operator respond. |
When we act as a service provider for an operator, we:
- use shopper information only to provide and support the Services for that operator, under our agreement with them and their instructions;
- protect it with the safeguards described in this policy;
- do not use it for our own marketing, and do not sell it; and
- return or delete it when our agreement with the operator ends, except where the law requires us to keep it (see section 12).
The operator decides which features to use in its stores (for example, cameras or customer registration), how long footage and logs are kept within the settings the system supports, and which of its staff can see them. The operator is responsible for its own privacy practices, including posting in-store signs, giving shoppers notice, and getting any consent the law requires. The operator's own privacy policy also applies to you as a shopper.
Shoppers receive this policy at registration. When you register a shopper account in the Helius app, you are shown this Privacy Policy and the Terms of Service, and you must accept them before your account is created. This policy is part of the notice you receive about how your information is collected and used, including camera video, door access logs, geolocation and behavioural analytics.
In some limited cases, Helius may be responsible for shopper information itself, for example for a Helius app account that can be used at stores run by more than one operator, or for information we use to secure and maintain our own systems. Where that applies, any additional privacy information presented in the Helius app explains the details.
3. What this policy covers
This policy covers personal information collected through our website, our dealings with business customers, and the Services.
It does not cover:
- an operator's own handling of personal information outside the Services (please read that operator's privacy policy);
- third-party services that have their own privacy policies, such as payment processors and Solink (see section 10); or
- any additional privacy information presented in the Helius app, which adds to this policy for app users.
"Personal information" means information about an identifiable individual, as defined in Canadian privacy law.
4. Information we collect
4.1 Website visitors and people who contact us
- Contact and inquiry details you give us, such as your name, business name, job title, email address, phone number, inquiry type, your message, and details about your store (for example, your current system, number of locations, lanes, cameras and province).
- Your marketing choices, such as whether you opted in to product updates or unsubscribed.
- Communications with us by email, phone, video call or chat.
- Business contact information from public sources. We may collect the work contact details of people at retail businesses (such as name, job title, business email and business phone) from public websites, business directories and similar sources, so we can contact them about our Services in their professional role. See section 18.
- Technical and cookie data, such as IP address, browser and device type, pages viewed, referring website, and approximate location derived from your IP address. See section 19 and our Cookies Policy.
4.2 Business customers and their authorized users
- Account and contact details: names, job titles, business email and phone numbers, store names and addresses.
- Login and user information: usernames, login credentials, user roles and permissions.
- Billing information: billing contact, billing address, invoices, payment history and tax numbers. Subscription payments are handled by our payment providers; we may receive limited card details such as card type, last four digits and expiry date, but not the full card number.
- Contract and support records: order forms, agreements, installation and onboarding notes, support requests and call notes.
- Back-office activity: log-ins and actions taken in the Services (for example, price changes, refunds or voids approved by a staff member), kept as an audit trail.
- Staff and contractor access credentials (Retail OS): for staff, vendors, delivery drivers or cleaners the operator gives door access to, we process their name, credential, access schedule and access history.
4.3 Operator store and business data
Product catalogues, prices, promotions, inventory, sales totals, lane and device settings, and store hours. This is mostly business information, not personal information, but it can include staff names or IDs linked to actions in the system.
4.4 Shopper information we process for operators
Depending on the features an operator uses, we process the following on the operator's behalf:
- Registration and verification (Retail OS): name, email address, phone number, home address (used to register and verify shopper accounts), customer ID, account credentials, the stores you are registered for, account status, and a record of when you accepted this Privacy Policy and the Terms of Service at registration. We also process the information needed to verify your identity and account, using the verification steps shown in the app at registration.
- App and door access: door unlock events (store, door, date and time, account, fob or device used, and whether entry was granted or denied), device identifiers, app version, and geolocation from your device, used to support unlocking the store door in the app and store access.
- Transactions: items scanned, prices, discounts, totals, date and time, lane and store, payment result, receipts, refunds and voids, and tokenized payment references and limited payment details returned by the payment processor (never the full card number). In Retail OS stores, transactions may be linked to your shopper account.
- Behavioural analytics: analytics about how shoppers use the store and the Helius app, based on door, app, lane, transaction and camera event data, such as visit and purchase patterns and unusual activity flagged for review. They are used for store operations and loss prevention. They do not use facial recognition or biometric information.
- Camera video and event metadata: video recorded by the store's security cameras, which may show shoppers, staff and anyone else in the store, and metadata that links video to events (for example, a void, refund, no-sale or discount at a lane, or a door unlock), including the time, camera, lane and store. See section 7.
- Support: information in any request you send to the operator or to us about a store visit or account.
4.5 Device, usage and technical data
IP addresses, device and operating system type, app version, crash and diagnostic logs from apps, lanes, payment terminals and access hardware, system and security logs, and information about how the Services are used.
4.6 Information we do not collect
- Full payment card numbers. Card payments are handled by third-party payment processors (see section 10). Card data goes directly to them and does not pass through Helius servers. Helius does not store full card numbers or security codes; we receive only tokenized payment references.
- Biometric information. We do not use facial recognition, facial geometry or any other biometric identification. See section 9.
- We do not intentionally collect sensitive information such as health information. Please don't send it to us.
5. How we use information
Website visitors and business contacts: to respond to inquiries, prepare quotes and assessments, book demos, send business marketing messages permitted under Canada's Anti-Spam Legislation (see section 18), understand how our website is used, and keep the website secure.
Business customers and authorized users: to set up and provide the Services; coordinate installation and hardware; manage users and permissions; bill and collect fees; provide support and training; send service, security and billing notices; keep audit trails; improve the Services (using anonymized or aggregated information wherever possible); and meet our legal, tax and accounting obligations.
Shoppers (on the operator's behalf): to register and verify shopper accounts (including using home address and other registration details for verification); let shoppers unlock the store door (including using device geolocation to support app door unlocks and store access); process checkout and provide receipts; update inventory; secure the store and prevent loss, including linking door, lane and camera events so the operator can review an incident; produce behavioural analytics on store and app usage for store operations and loss prevention; investigate theft, fraud or safety incidents at the operator's request; troubleshoot and secure the system; and meet legal requirements.
We do not:
- sell personal information or share it for third-party advertising;
- use shopper information for our own marketing;
- use camera footage for advertising or targeted offers; or
- use camera footage or shopper personal information to train artificial intelligence models without the operator's written agreement and any notice and consent the law requires.
Automated flags. Some features flag events for review (for example, a void or refund at a lane). A flag is a prompt for a person to review. The operator decides what action, if any, to take, such as suspending a shopper account. If a decision about an individual is ever based exclusively on automated processing, we will tell the affected individual as required by law, including under Quebec's rules on automated decisions.
We use personal information only for the purposes described in this policy, purposes identified when it is collected, or other purposes permitted or required by law. If we want to use it for a new purpose, we will ask for consent where required.
6. Consent and the legal basis for processing
We follow the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector as amended by Law 25, and other provincial private-sector privacy laws where they apply.
- Consent. We collect, use and disclose personal information with consent, except where the law allows otherwise. Consent may be express (for example, ticking a box) or implied where that is reasonable, such as using your business contact details to reply to your inquiry. We get express consent where the law requires it, including for sensitive information.
- Business contact information. Canadian privacy laws treat work contact information used to communicate with someone about their job or business differently from other personal information. We use it only for that purpose.
- Shopper information. When you register a shopper account in the Helius app, you receive this Privacy Policy and accept it, together with the Terms of Service, before your account is created. For shopper information we process as a service provider, the operator remains responsible for getting any other consent the law requires and for giving notice in its stores, such as signs at the entrance. Our agreements require operators to do so. Where the law requires separate, express consent for a particular use, it will be requested separately and will not be bundled into your acceptance of this policy.
- Withdrawing consent. You can withdraw consent at any time, subject to legal or contractual limits and reasonable notice, by contacting us (section 21) or, for shoppers, the store operator. If you withdraw consent, we may not be able to provide some Services. For example, a shopper who withdraws consent to registration may no longer be able to unlock a Retail OS store.
7. Cameras and video
- Purpose. Video is used for security, safety, loss prevention and investigating incidents, including reviewing checkout exceptions such as voids and refunds. It is not used for marketing or targeted offers, is not used for facial recognition, and is never sold.
- Who controls it. The operator decides whether to use cameras, where to place them, and who on its team can view footage. Pro plans support up to 8 cameras, and Retail OS supports more. Camera hardware is sold separately. Video is recorded on a video recorder on the store's own local network. Where the operator uses our camera integration, Solink provides video storage and camera analytics that link video to POS and event data (for example, a void or refund at a lane), for security and loss prevention. Solink may store video outside Canada (see section 11).
- Signs and notice. Operators must post clear signs at store entrances saying that video recording is in use, why, and who to contact, and must not place cameras in washrooms, changing areas or other private spaces. In Retail OS stores, shoppers also receive this Privacy Policy, including this section on cameras, and accept it when they register.
- Retention. Footage is kept for 14 to 30 days, depending on the storage capacity of each store's video recorder, and is then automatically overwritten or deleted. It is kept longer only if it is needed for an active incident or investigation, if it is subject to a legal hold, or if the operator sets a longer retention period where the law allows.
- Access controls. Access is limited to authorized operator staff, and to Helius and Solink personnel who need it to provide support, using role-based permissions.
- Disclosure. Footage is disclosed to police or other authorities only at the operator's direction, for example to report a crime, or when required by law, such as under a warrant or court order.
- Requests. Shoppers who want access to footage of themselves should contact the store operator. See section 15.
8. Access control and event logs
In Retail OS stores, each door unlock and lock event is logged with the store, door, time, account or credential used, and the result. Lane and camera events for the same visit can be linked into one timeline.
We use these logs to let authorized people into the store, keep an audit trail, support safety and security, investigate incidents, and troubleshoot the system. Logs are available to the operator's authorized staff and to Helius personnel who need them for support. By default, they are kept for 30 days and then deleted, unless they are needed for an active incident or investigation, are subject to a legal hold, or the operator sets a longer retention period where the law allows.
Staff, vendor and contractor credentials are managed by the operator, who can grant, limit by time window, or revoke access.
9. Biometrics, facial recognition and new features
Today, the Services do not use facial recognition or collect biometric information.
We are exploring computer-vision features, such as detecting behaviour that may indicate theft or crossing into restricted areas. These features are not live. Before we launch any new feature that uses biometric information or facial recognition, or that identifies, locates or profiles people in a new way, we will:
- assess its privacy impact, including a privacy impact assessment where Quebec law or good practice requires one;
- update this policy and give clear notice before the feature becomes available;
- get any consent the law requires, including express consent where biometric information is involved;
- make any declaration the law requires before use, such as a declaration to Quebec's Commission d'accès à l'information for biometric systems;
- make such features off by default where the law requires it, and require operators to update their in-store signs and notices before switching them on; and
- not use these features for advertising or targeted offers.
10. How we share information
We share personal information only as described below.
Service providers (subprocessors). We use service providers that host, secure or support our Services, under contracts that require them to protect the information and use it only to provide services to us. Our main service providers are:
| Provider | What they do for us | Location |
|---|---|---|
| Google Cloud | Hosts the Helius platform, including our applications and databases | Toronto, Canada (core application workloads) |
| Global Payments (including its Portico gateway) | Payment processing: card acquiring and authorization for lane payments | May include the United States |
| Advanced Mobile Payment (AMP) | Payment processing: payment terminals and terminal services | May include the United States |
| Stripe | Payment processing | May include the United States |
| Solink | Video storage and camera analytics linked to POS and event data, for security and loss prevention | May include the United States |
| SendGrid (Twilio) | Sends transactional emails (such as registration confirmations) and marketing emails | May include the United States |
| Microsoft 365 (including Microsoft Azure services that are part of it) | Internal email, documents and IT | May include the United States |
| Adobe (Adobe Acrobat Sign) | Electronic signature of contracts | May include the United States |
| Markovate | Software engineering and IT services | May include the United States |
| Base44 | Hosts our marketing website and contact form, and provides basic website analytics | May include the United States |
| Cloudflare | Website security (bot and spam protection on our contact form) | May include the United States |
Payment processors. Card payments are processed by Global Payments, Advanced Mobile Payment (AMP) and Stripe. Card data goes directly to them, and they handle it under their own privacy policies and the card network rules. Helius does not store full card numbers. Processing fees are charged by the processors, not Helius.
We also share personal information with:
- Video and camera partners. Solink, for operators that use our camera integration, to store video and link it to POS and door events.
- Hardware and installation partners, to deliver, install and service equipment at a store.
- Operators. Shopper information processed for a store is available to that store's operator and its authorized users. Business customer information is shared within that customer's own account.
- Legal and safety reasons: to comply with a law, warrant, court order or other lawful request; to protect the rights, property or safety of Helius, our customers, shoppers or others; and to detect or prevent fraud or security problems.
- Professional advisers, such as lawyers, accountants and auditors, under a duty of confidentiality.
- Business transactions: if we are involved in a financing, merger, acquisition or sale of all or part of our business, personal information may be shared with the parties involved under confidentiality obligations and as permitted by law, and will continue to be protected in line with this policy.
- With your consent, or as otherwise permitted or required by law.
We do not sell personal information, and we do not share it with third parties for their own advertising.
11. Where information is stored and transferred
Our core application workloads are hosted on Google Cloud in Toronto, Canada. Store video is recorded on equipment at the store. Some of our service providers (see section 10), including content delivery, email, payment and website providers, may store or access personal information outside Canada, including in the United States. When information is outside Canada, it is subject to the laws of that country and may be accessible to its courts, law enforcement and national security authorities.
We use contracts and other measures so that service providers protect personal information to a standard comparable to ours. Where Quebec law requires, we assess the privacy risks before personal information about Quebec residents is communicated outside Quebec. To learn more about our service providers outside Canada, contact our Privacy Officer.
12. How long we keep information
We keep personal information only as long as needed for the purposes in this policy, or longer if the law requires it. Then we securely delete it or anonymize it so it can no longer identify anyone.
| Information | Typical retention |
|---|---|
| Website inquiries and business contacts | 24 months after our last interaction. We keep a record of unsubscribe requests so we can honour them. |
| Customer account and contract records | For the life of the account, then 2 years |
| Billing and tax records | At least six years, as required by Canadian tax law |
| Shopper accounts | While the account is active. Deleted within 30 days after closure or a valid deletion request, unless needed for an open incident, an unpaid balance or a legal requirement |
| Transaction records | As set by the operator and required by tax law |
| Camera video | 14 to 30 days, depending on the storage capacity of each store's video recorder, then automatically overwritten or deleted. Kept longer only for an active incident or investigation, a legal hold, or a longer period set by the operator where the law allows |
| Door access and event logs | 30 days by default, then deleted. Kept longer only on the same terms as camera video |
| Records of privacy breaches | At least 24 months, as required by law |
| Security and system logs | 12 months |
| Backups | Deleted on a rolling schedule managed in our cloud hosting environment |
When an operator's agreement with us ends, we return or delete the shopper information we hold for that operator as set out in our agreement with them.
We may keep anonymized or aggregated information that cannot reasonably be used to identify anyone, as permitted by law.
13. How we protect information
We use reasonable administrative, technical and physical safeguards appropriate to the sensitivity of the information. These include: encryption of our production databases at rest; running our application services on a private Google Cloud network that is not directly exposed to the public internet, behind firewalls and a web application firewall; two-factor authentication, which the platform supports and our customer contracts require for administrators and operators; key-based administrative server access with password log-in disabled; role-based access controls that limit access to people who need it; a written incident response plan; security awareness training; and confidentiality obligations for our staff and service providers.
No system is completely secure, and we cannot guarantee that information will never be accessed without authorization. Customers are responsible for keeping their own passwords and devices secure and for managing who in their business has access.
14. Your privacy rights
Subject to exceptions in the law, you have the right to:
- access the personal information we hold about you and learn how it has been used and shared;
- correct information that is inaccurate or incomplete;
- withdraw consent (see section 6);
- ask us to delete information, or in Quebec, to stop disseminating it or to de-index it where the law allows;
- in Quebec, receive personal information you provided in a structured, commonly used technological format, or have it sent to another organization (data portability);
- be told when a decision about you is based only on automated processing, and ask for a person to review it (Quebec); and
- complain about how we handle your information.
How to make a request. Email privacy@heliusretail.com or write to our Privacy Officer (section 21). We may need to verify your identity first. We aim to respond within 30 days, and will tell you if we need more time as the law allows. Requests are generally free; if a fee is allowed, for example for reproducing large volumes of records, we will tell you first. If we refuse a request, we will explain why, unless the law prevents us.
Complaints. Please contact us first so we can try to fix the problem. You may also complain to:
- the Office of the Privacy Commissioner of Canada (priv.gc.ca);
- in Quebec, the Commission d'accès à l'information du Québec (cai.gouv.qc.ca); or
- the privacy commissioner of your province, where provincial privacy law applies (for example, Alberta or British Columbia).
15. Requests from shoppers
If you are a shopper and your request is about a store visit, your account at a store, a purchase or camera footage, please contact the store operator first, because they are generally responsible for that information. If you send the request to us, we will forward it to the operator and help them respond, as our agreement with them requires. Where Helius is responsible for the information itself (see section 2), we will respond directly.
16. Privacy breaches (confidentiality incidents)
We have procedures to investigate, contain and assess any suspected privacy breach (called a "confidentiality incident" in Quebec).
- Information Helius is responsible for: if a breach creates a real risk of significant harm (under PIPEDA) or a risk of serious injury (under Quebec law), we will notify the Office of the Privacy Commissioner of Canada and/or the Commission d'accès à l'information, and affected individuals, as required. We keep a record of all incidents, as the law requires.
- Shopper information we process for operators: we will notify the affected operator without undue delay, and within 48 hours as set out in our data processing agreement with the operator, and give them the information and help they need to meet their own notification obligations.
17. Children and minimum age
Our website and business Services are for businesses and are not directed at children or minors. To register for a Retail OS shopper account, you must be at least 18 years old, or the age of majority in your province or territory if that is higher. Under Quebec law, personal information about a child under 14 may not be collected without the consent of a parent or guardian, except as the law allows. If we learn that we have collected personal information from a child without the required consent, we will delete it.
18. Marketing emails and your choices
We send business marketing messages, such as product updates and offers, only where Canada's Anti-Spam Legislation (CASL) allows. That means with your express consent (for example, if you tick the unticked box on our contact form), or with implied consent as CASL permits. Examples of implied consent include an existing business relationship, or a work email address that has been published publicly without a statement that you do not want unsolicited messages, where our message is relevant to your role.
Every marketing email from us will:
- identify Helius Retail Technologies as the sender;
- include our mailing address, 570 Hood Rd Unit 14 #3111, Markham, ON L3R 4G7, and a way to contact us; and
- include an easy unsubscribe link. We process unsubscribe requests without delay, and in any case within 10 business days, as CASL requires.
You can also unsubscribe at any time by emailing hello@heliusretail.com. Even after you unsubscribe, customers will still receive service messages such as invoices, security notices and changes to these policies.
19. Cookies
Our website does not currently set any cookies. It uses browser storage and similar technologies to keep the site working and secure and, with your consent, for basic website analytics. We do not use advertising cookies, and we do not use non-essential technologies without your consent. For details, including how to control cookies, see our Cookies Policy.
20. Third-party websites and services
Our website and Services may link to or work with third-party websites and services, such as payment processors and Solink. Those third parties have their own privacy policies, and we are not responsible for their practices. Please review their policies before using them.
21. Our Privacy Officer and how to contact us
Helius has designated a Privacy Officer, who is responsible for our compliance with this policy and with Canadian privacy law.
- Privacy Officer, Helius Retail Technologies
- Email: privacy@heliusretail.com
- Mail: Privacy Officer, Helius Retail Technologies (17939973 Canada Ltd.), 570 Hood Rd Unit 14 #3111, Markham, ON L3R 4G7
For general questions, contact hello@heliusretail.com.
22. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page and change the "Last updated" date. If we make material changes, we will tell customers by email or in the Services, and post a notice on our website, before the changes take effect. If a change means we need new consent, we will ask for it.