Privacy Policy
1. Who We Are
Protein Market Terminal is operated by 1001744194 Ontario Inc., incorporated in Ontario, Canada, with a mailing address at PO Box 99900 ZS 086 994, RPO Castlewood, Toronto ON M5N 0A5. This policy explains what personal information we collect, why, and what you can do about it.
We are the party accountable for the personal information described here. Questions, access requests, and complaints go to our Privacy Officer, Jim Langlois, at admin@proteinterminal.com.
2. What We Collect
We collect only what the Service needs to function. In practice that is:
- Name — your first and last name, which are required when you create an account. We use them to address you in emails and to identify your account in support conversations.
- Email address — required. Used as your login identifier, to send account activation and password reset links, and for service notices.
- Password — stored only as a bcrypt hash. We cannot read, recover, or tell you your password; we can only help you reset it.
- IP address — we record the IP address of each sign-in and each page view, along with the approximate country, region, and city we derive from it. Please note: we retain the IP address itself, not only the derived location. We use this for security (spotting unusual sign-in activity) and for usage analytics.
- Device and browser information— your browser's user agent string, which identifies browser type, version, and operating system, plus screen size. Used for compatibility and to distinguish mobile from desktop usage.
- Usage data — which pages you view, when, the referring page, the features you use, and your sign-in history.
- AI assistant queries — the questions you type into the AI assistant, the database query generated in response, and the answer returned. These are stored against your email address. See section 7 for how long we keep them.
- Support messages — if you use the contact form, we store the name, email address, subject, and message you submit, linked to your account if you are signed in.
- Session cookie — an authentication token to keep you signed in. See section 5.
3. What We Do Not Collect
- Payment information— all payment processing is handled by Stripe. We never see, store, or have access to your card number, bank account, or other financial details. We store only Stripe's customer and subscription identifiers so we can tell which tier your account is on.
- Postal address, phone number, date of birth, or employer — we do not ask for these and have nowhere to put them.
- Third-party tracking or advertising — we do not use Google Analytics, Facebook Pixel, advertising networks, session recording, or any third-party analytics service. Our analytics are built in-house and the data stays on our own server.
- Sensitive personal information — we do not collect health, biometric, racial, religious, political, or precise-geolocation data.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done so.
4. How We Use Your Data
- Providing the Service — authenticating you, remembering your preferences, and showing you the data your tier includes
- Account and billing management — managing your subscription tier and feature access
- Security — detecting unusual sign-in activity, abuse, and attempts to circumvent access controls
- Service improvement — understanding which reports and features are actually used, and diagnosing errors in the AI assistant
- Communication — service updates, billing notices, and changes to these terms. We do not send marketing email you did not ask for.
We rely on your consent, given when you create an account, together with our legitimate interest in operating and securing the Service. We do not use your data for automated decision-making that has a legal or financial effect on you.
5. Cookies & Browser Storage
We use one cookie and a small amount of browser storage. We do not use advertising or cross-site tracking cookies.
Cookie:
- session — your authentication token. It is set by our server as an
HttpOnlycookie, which means page scripts cannot read it, and it is markedSecurein production so it is only sent over HTTPS. It expires after 30 days or when you sign out.
Browser storage (stays on your device, never sent to us as a set):
- pmt-theme — your light/dark mode choice
- pt-session-id — a random identifier, regenerated each browser session, used to group your page views into a single visit for analytics. It is not tied to your identity and is discarded when you close the tab.
- pmt-analysis-expanded — whether you expanded the report analysis panel
6. Third-Party Services
The Service relies on the following third parties. Those that receive your personal information are marked.
- Stripe (receives your email address and payment details directly) — payment processing for paid subscriptions. Subject to Stripe's Privacy Policy.
- Resend (receives your name and email address) — delivers our transactional email: account activation, password resets, and service notices. Subject to Resend's Privacy Policy.
- Anthropic (receives the text of your AI queries)— powers the AI market briefs and the natural language assistant. Your question and the relevant market data are sent to Anthropic's API to generate an answer. We do not send your name, email address, or IP address with the query. Subject to Anthropic's Privacy Policy.
- DigitalOcean, LLC (hosts all data described in this policy) — provides the server and database. See section 9 on data location.
- MaxMind (receives nothing) — this product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com. We use a copy of their database stored on our own server to turn an IP address into an approximate location. Your IP address is never sent to MaxMind.
Government and market data sources (USDA, CFTC, Statistics Canada, and others) supply market data to us. We send them nothing about you. They are listed in our Market Data Disclaimer.
7. How Long We Keep Things
- Account data (name, email, password hash, tier) — kept while your account exists, and deleted when you delete your account.
- Analytics data (page views, sign-in events, IP addresses, approximate location, user agent) — automatically deleted after 12 months by a scheduled weekly job.
- AI assistant queries — automatically deleted after 90 days by a scheduled daily job.
- Support messages — kept while we may need them to handle a related dispute or support history, and reviewed periodically.
- Aggregated statistics — counts and totals that cannot be traced back to any individual may be kept indefinitely.
8. Your Rights
You have the right to:
- Ask what personal information we hold about you, and receive a copy of it
- Ask us to correct information that is wrong or out of date
- Delete your account and the personal information attached to it
- Withdraw your consent to our processing, by deleting your account
- Ask how we handled your information, and complain if you are unsatisfied
You can change your name, email address, and password yourself from your account settings. For anything else, including deletion, contact Jim Langlois at admin@proteinterminal.com. We respond within 30 days.
Exercising these rights costs nothing and we will not degrade your service for asking. If you are not satisfied with our response, Canadian users may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
9. Where Your Data Is Stored
Your account, analytics, and AI query data is stored in our primary database, which is operated by DigitalOcean, LLC and located in Toronto, Canada. Your personal information therefore sits in Canada at rest.
Some processing still happens outside Canada, because three of our service providers operate primarily in the United States:
- Stripe — payment processing, receives your email address
- Resend — email delivery, receives your name and email address
- Anthropic — AI processing, receives the text of your AI queries
While your information is with those providers it may be accessible to foreign courts, law enforcement, and national security authorities under the laws of that country. We use providers that apply comparable protection by contract, but we cannot exempt data from the laws of the jurisdiction it passes through. By using the Service you acknowledge this transfer.
10. Security
We use encrypted connections (HTTPS), bcrypt password hashing, HttpOnly session cookies, a read-only database role for AI-generated queries, rate limiting, and role-based access controls. Administrative access is limited to the operator of the Service.
No system is completely secure and we cannot guarantee absolute security. If a breach occurs that creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as required by law, and will tell you what happened and what to do about it.
11. Children
The Service is a commercial tool intended for use by people in the meat and protein industry. It is not directed at children, and you must be at least 18 to hold an account. We do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will remove it.
12. Changes to This Policy
We may update this policy. The version number and date at the top of this page will change, and material changes will be emailed to registered users at least 14 days before they take effect. Continuing to use the Service after that point means you accept the updated policy.