Privacy Policy

This section presents the privacy policy, outlining the practices for collecting, using, and protecting personal data.
image (10)
Last update: Septembre 30, 2026

Version: 2026-09-30

This Privacy Policy explains how RIOH inc. (“RIOH“, “we“, “us” or “our“) collects, uses, discloses, keeps and protects personal information in connection with the IoTcare asset-tracking and geolocation platform, its web and mobile applications and its related services (the “Platform“). It also explains your rights and how to exercise them.

It is written to comply with the Act respecting the protection of personal information in the private sector (Québec, “Law 25”), the Personal Information Protection and Electronic Documents Act (Canada) and, where they apply, other privacy laws such as the European General Data Protection Regulation.

This Policy covers the Platform only. It does not cover the rioh.io website, or the practices of the organizations that use the Platform, which remain responsible for their own.

1. Key terms
  • “Customer” means the organization (company, public body, institution or other entity) that holds an account on the Platform.
  • “Authorized User” or “you” means an individual who uses the Platform under a Customer’s account.
  • “Customer Data” means the data a Customer and its Authorized Users put into the Platform, or that the Customer’s devices and connected systems send to it — including location data.
  • “Personal information” means any information about an individual that allows that individual to be identified, directly or indirectly.
  • “Deployment Model” means how the Platform is provided to a Customer: IoTcare Cloud (SaaS), Dedicated Cloud or On-Premises (see Section 3).
2. Our two roles

RIOH handles personal information in two different capacities, and your rights are exercised differently in each.

2.1 On behalf of the Customer. Most of the personal information in the Platform is Customer Data: the Authorized Users of an organization, and any individual whose information the organization records or tracks with the Platform. For this information, the Customer decides why and how it is processed, and RIOH processes it on the Customer’s behalf and on its instructions, as its service provider, under the Terms of Use and any agreement signed with the Customer. The Customer is responsible for informing the individuals concerned and for obtaining any required consent.

2.2 For our own purposes. RIOH also handles some personal information for its own purposes: to manage accounts and subscriptions, to bill, to secure the Platform, to answer questions and support requests, to run its partner program, and to meet its legal obligations. For this information, RIOH is responsible and this Policy describes its practices.

3. Deployment models
 IoTcare Cloud (SaaS)Dedicated CloudOn-Premises
Who hosts the Platform and Customer DataRIOH, on shared infrastructure with logical isolation between CustomersRIOH, on infrastructure dedicated to one CustomerThe Customer, on its own servers and networks
RIOH’s role for Customer DataService providerService providerNone, except during support the Customer requests
Where this Policy appliesIn fullIn full, except where the agreement with the Customer provides otherwiseOnly Section 20 and to information the Customer chooses to share with RIOH

Customer Data is never mixed between Customers, whatever the Deployment Model.

4. Information we process on behalf of Customers

Depending on how a Customer uses the Platform, Customer Data may include:

  • Authorized User accounts: name, work email address, role, departments, language, time zone and display preferences, profile picture (optional), and phone number (optional, for SMS verification).
  • Identity from single sign-on: when a Customer connects its identity provider (for example Microsoft Entra ID, or another OIDC or SAML provider), we receive your name, email address and, where configured, your group memberships, to create or update your account and assign your role.
  • Assets, buildings and floor plans: asset names, identifiers, categories, pictures and custom properties; building addresses and footprints; floor plans and zones. These are normally about objects and places, but a Customer may enter personal information in them (for example a name in an asset’s properties).
  • Device and location data: identifiers of trackers, locators, gateways and GPS devices (for example MAC address, IMEI, ICCID, phone number of a SIM card), their battery level and signal, and the positions they report — latitude and longitude, floor, accuracy, speed, heading and time — together with the history of those positions, the zones entered and left, and the resulting alerts.
  • Alerts: alert rules, the users or email addresses (including outside recipients chosen by the Customer) that receive them, and who acknowledged each alert.
  • Imports and exports: the files a Customer uploads (for example spreadsheets of assets), including the raw rows, and the export files it generates.

The Platform does not ask for, and Customers should not enter, sensitive information (for example health information) that is not needed for their purpose.

5. Information we collect for our own purposes

Information that falls under both roles. Your user account exists independently of any organization and can give access to several of them: RIOH is responsible for it for its own purposes, as described in this Section. Your membership in an organization, and what that organization records about you, are Customer Data (Section 4). Some information, such as your name, email address, profile picture and phone number, appears in both Sections because it serves both purposes. When you exercise your rights (Section 16), RIOH responds directly for your user account and the information described in this Section, and forwards to the Customer, or helps it handle, the part of the request that concerns Customer Data.

  • Account and sign-up: name, email address, password (stored only as a one-way hash), language, and the date you accepted the Terms of Use and this Policy.
  • Organization and billing: organization name, address, phone, website, industry, size and intended use, entered during onboarding; the billing name, address, email and tax numbers collected through our payment provider, Stripe; the type and last four digits of the payment card (the full card number is handled only by Stripe); the Plan, device counts and invoices.
  • Security: second-factor settings (authenticator secret and recovery codes are stored encrypted), verification codes, sign-in history (date, IP address, browser and device, sign-in method), and alerts about sign-ins from new devices.
  • Support and sales: what you send us through the help form or by email (name, email, optional phone, organization, the page you were on and your message). When the Owner of an organization without a payment method uses the pricing estimator and the estimate exceeds a threshold (currently CAD 250 per month), our sales team is notified with the Owner’s name, email, phone and estimate so that we can offer help.
  • Partner program: when you arrive through a partner’s referral link, the partner code and campaign, and, if you sign up, the partner credited for the referral. For partners themselves: contact names, emails, phone numbers and payment details.
  • Cookie choices: a random identifier, your choice, the date and the version of this Policy, with the IP address and browser from which the choice was made, as proof of consent (see Section 15).
6. Service and usage data

To operate, secure, support and improve the Platform, we record technical information about how it is used and performs:

  • Activity log: a record of significant actions in each organization — sign-ins and failed sign-ins (with the email entered and IP address), changes to users, roles, security settings, devices, assets, buildings, zones, billing and data exports, and support access (Section 14). The Customer’s administrators can see their organization’s log.
  • Application logs: technical events and errors from our servers, which may include identifiers such as an email address or an IP address.
  • Health monitoring: checks that the Platform’s components are running. Where RIOH operates or monitors a deployment, these checks report the status of the service to RIOH’s monitoring tools; they contain no Customer Data.
  • Web analytics: only if you consent, through Google Analytics (Section 15).

We use this information to run the service, detect and investigate incidents and abuse, provide support, understand which features are used, and produce aggregated statistics that do not identify any Customer or individual.

7. Location data and tracking of individuals

The Platform is built to locate objects, but a Customer may also use it to locate people — for example through a badge worn by a staff member, a vehicle assigned to a driver, or a phone registered as a tracker. When it does:

  • The Customer decides whether to track individuals, for what purpose and with which devices, and must inform them beforehand, as the law requires for any technology that allows a person to be located, and obtain their consent where required.
  • RIOH processes this location data only to provide the Platform to that Customer. We do not use it to profile individuals, to advertise, or for any purpose of our own, and we never sell it.
  • Retention follows the Customer’s Plan (Section 12), and the Customer’s administrators control who in the organization can see which assets.

If you are being located through the Platform and have questions, contact your organization first; you can also contact our Privacy Officer (Section 22).

8. How we use personal information

We use personal information only for the purposes for which it was collected, or for compatible purposes permitted by law:

  • to create and manage accounts, authenticate users and apply the roles set by the Customer;
  • to provide the Platform’s features: maps, positions, history, zones, alerts, reports, imports and exports;
  • to send service messages: email verification, password reset, verification codes, security notices (new device, password or two-factor changes), invitations, alerts configured by the Customer, subscription and billing notices, and notices about the organization (ownership transfer, deletion, restoration, plan changes);
  • to bill, collect payment and meet our tax and accounting obligations;
  • to secure the Platform and prevent fraud and abuse, including by protecting sign-in forms from automated attacks;
  • to answer support and sales requests, and to follow up on a pricing estimate as described in Section 5;
  • to credit and pay partners for referrals;
  • to improve the Platform, using Service Data and aggregated statistics;
  • to comply with the law and respond to lawful requests from authorities, and to establish or defend legal claims.

No marketing without consent. We do not currently send newsletters or marketing emails from the Platform. If we offer them in the future, we will send them only with your express consent and every message will let you unsubscribe.

No automated decisions. We do not make decisions about individuals based exclusively on automated processing of their personal information.

9. Consent

By creating an account and accepting the Terms of Use, you consent to the collection and use of your personal information as described in this Policy for the purposes of Section 8. Where the law requires a separate consent — for example for analytics cookies (Section 15) — we ask for it separately and you can refuse it without losing access to the Platform. You may withdraw a consent at any time, subject to legal or contractual restrictions; we will explain the consequences, for example that some features may no longer work.

For Customer Data, the Customer is responsible for obtaining any consent required from the individuals concerned (Section 2.1).

10. Sharing and service providers

We do not sell or rent personal information. We share it only in the following cases:

  • Within the Customer’s organization, according to the roles and visibility rules the Customer configures.
  • With our service providers, who process it for us under written agreements that require them to protect it and to use it only for the services they provide:
ProviderWhat it does for usInformation involvedLocation
Microsoft AzureHosting, storage, backups (IoTcare Cloud and Dedicated Cloud)All Platform dataCanada
StripePayments, invoicing, tax calculation (IoTcare Cloud)Billing name, email, address, tax numbers, payment method, device countsUnited States / Canada
MapboxBase maps and satellite imagery; address search; displaying the address of a place, such as a building or a vehicle’s stopYour IP address and browser; the addresses you search; the coordinates of the places displayed; anonymous usage events sent by Mapbox’s map libraryUnited States
Provider to be selected (currently handled manually)Sending emailsRecipient address, message contentCanada
TwilioSending SMS verification codesPhone number, codeUnited States
CloudflareBot protection on sign-in forms (Turnstile); delivery of some interface imagesIP address, browser signalsGlobal network
GoogleWeb analytics, only with your consentPages viewed, IP address (anonymized), browser, identifier stored in a cookieUnited States
IconifyDelivery of interface iconsIP address, browserGlobal network
  • With services the Customer connects. When a Customer enables an integration — its identity provider for single sign-on, a location system from a vendor such as HPE Aruba, Cisco Spaces or Meridian, or a cellular connectivity platform — data is exchanged with that service on the Customer’s instructions and under the vendor’s own terms.
  • With partners, only the fact that an organization signed up through their referral and the amounts on which their commission is calculated.
  • In a business transaction, such as a merger, acquisition or financing, where the information is necessary to conclude it, under an agreement requiring the other party to protect it and to use it only for that purpose.
  • When required or permitted by law, for example to comply with a court order, or to protect the rights, safety or property of RIOH, our Customers or others.

We keep an up-to-date list of our service providers and will notify Customers before adding a new provider that processes Customer Data in IoTcare Cloud.

11. Transfers outside Québec

Some of our providers process information outside Québec, including in other Canadian provinces and in the United States (see Section 10). Before communicating personal information outside Québec, we assess whether it will receive adequate protection, taking into account its sensitivity, the purposes, the safeguards in place and the applicable legal framework, and we put written agreements in place. Information processed outside Québec may be accessible to authorities there under local law.

12. Retention

We keep personal information only as long as needed for the purposes for which it was collected, or as required by law, and then destroy or anonymize it.

InformationRetention
Location historyAccording to the Customer’s Plan — currently 30 days on the Free plan and 365 days on the paid plan, or as set in the agreement for Contract Deployments. Older history is deleted automatically.
Current position and latest reading of each deviceReplaced at each new report; deleted with the device or asset.
Activity logAccording to the Customer’s Plan — currently 30 days on the Free plan and 365 days on the paid plan. Entries not linked to an organization: 30 days.
Sign-in history12 months.
Items the Customer deletes (assets, devices, places, categories, departments)Kept 30 days in “Recently deleted” so they can be restored, then permanently deleted.
Export files7 days.
Cookie consent records13 months, then the question is asked again.
A deleted organization and its Customer Data90 days (restoration window), then permanently deleted; see Section 17.
BackupsOverwritten within 30 days.
Invoices and accounting recordsAs required by tax law (currently 6 years).
Authorized User accountsFor as long as the account belongs to at least one organization. An account that no longer belongs to any organization is deleted after 12 months of inactivity, following an email notice 30 days before deletion; see Section 17.
Application logs90 days
Support and sales correspondenceFor as long as needed to handle the request and follow up, 3 years after the last exchange.
13. Security

We protect personal information with measures appropriate to its sensitivity, including:

  • encryption of data in transit (HTTPS/TLS) and of secrets at rest (single sign-on secrets, API keys, SMS and email credentials, SIM credentials, two-factor secrets and recovery codes);
  • passwords stored only as salted one-way hashes; optional or Customer-mandated two-factor authentication by authenticator app, email or SMS;
  • strict separation of each Customer’s data, checked by automated tests, and access to map images through short-lived tokens limited to the user’s organization;
  • role-based access within each organization, and visibility restrictions on sensitive asset categories;
  • protection against automated attacks, rate limiting and security headers;
  • an activity log of significant actions, and a log of every support access (Section 14);
  • daily backups;
  • confidentiality commitments and access limited to what each RIOH employee needs.

No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we act promptly on any incident (Section 18).

14. Access by RIOH personnel

Authorized RIOH personnel may access Customer Data only when necessary to provide support requested by the Customer, to maintain and secure the Platform, to investigate an incident or abuse, or to comply with the law. Support staff may, to diagnose a problem, view the Platform as a specific user sees it. Every such session is recorded — who accessed which account, when, from where and why — and is visible to the Customer’s administrators in their organization’s activity log. RIOH’s platform administrators cannot enter a Customer’s organization without this support mechanism. In an On-Premises deployment, RIOH has no access unless the Customer grants it.

15. Cookies and similar technologies

A cookie is a small file stored by your browser. The Platform also uses your browser’s local storage for similar purposes. We use:

Strictly necessary — always active, because the Platform cannot work without them:

NamePurposeDuration
authjs.session-token (and variants)Keeps you signed in securelyUp to 30 days
authjs.csrf-token, authjs.callback-urlProtects forms; returns you to the right page after sign-inSession
NEXT_LOCALERemembers your language1 year
blob_tokenGives access to your organization’s floor plans and map images1 hour
onboarding_dismissedRemembers that you skipped the setup guide1 year
rioh_consent_uuidRemembers your cookie choice13 months
iotcare_session, XSRF-TOKENUsed only while signing in with single sign-on2 hours
Cloudflare TurnstileDistinguishes people from bots on sign-in formsSet by Cloudflare

Referral — set only when you arrive through a partner’s referral link:

NamePurposeDuration
iotcare_viaRecords the partner code and campaign so the partner is credited if you sign up. It contains no information about you.30 days

Analytics — only if you accept them:

NamePurposeDuration
_ga, _ga_<id>Google Analytics: measures how the Platform is used, with an anonymized IP address13 months

Local storage. The Platform stores display preferences in your browser (for example map style, date format, time zone, currency, map layers, recently viewed assets and dismissed messages). They stay on your device and are not used to track you. The Mapbox map library also stores an anonymous identifier and sends usage events to Mapbox (Section 10).

Your choice. Non-essential cookies are off until you accept them; refusing them is as easy as accepting them, and does not limit your use of the Platform. Your choice is kept for 13 months, after which — or when this Policy changes significantly — we ask again. You can change it at any time on the Privacy preferences page, available from the footer of the sign-in pages and from your account settings. Withdrawing your consent stops analytics immediately and deletes its cookies. If a deployment uses no analytics tool, no choice is asked. You can also block or delete cookies in your browser settings, but blocking strictly necessary cookies will prevent you from signing in.

16. Your rights

Subject to the law, you have the right to:

  • access the personal information we hold about you, and obtain a copy of it;
  • have it corrected if it is inaccurate, incomplete or ambiguous;
  • withdraw your consent to a use of your information;
  • receive computerized personal information you provided to us in a structured, commonly used technological format, or have it transmitted to another organization (portability);
  • ask us to stop disseminating your information or to de-index a hyperlink attached to your name, where the conditions of the law are met;
  • be informed of the provider categories and the purposes for which your information is used, and of how long it is kept;
  • where the GDPR applies, object to certain processing, request its restriction or the erasure of your information.

How to exercise them. You can view and update your profile, phone, picture, password and sign-in history in your account settings, and your cookie choice on the Privacy preferences page. For anything else, contact our Privacy Officer (Section 22). We may need to verify your identity. We will respond in writing within 30 days of receiving your request.

Customer Data. If your request concerns information your organization controls (Section 2.1), we will forward it to the Customer, or help the Customer answer it, unless the law or our agreement with the Customer requires us to answer it directly.

Complaints. If you are not satisfied with our answer, you can contact the Commission d’accès à l’information du Québec (www.cai.gouv.qc.ca), the Office of the Privacy Commissioner of Canada (www.priv.gc.ca) or, where applicable, your local data-protection authority.

17. Closing an account and deleting data
  • Your user account. Your organization’s administrators can remove you from the organization at any time. To close your user account itself, contact your organization or our Privacy Officer; we will delete or anonymize your account information, except what we must keep by law or that remains part of an organization’s records (for example the activity log, for its retention period). A user account that no longer belongs to any organization and remains inactive for 12 months is deleted automatically. We notify you by email 30 days before deletion; signing in before that date is enough to keep your account.
  • An organization. The Owner can delete the organization from the Platform. All access stops immediately. For 90 days, the Owner can restore it intact with the link sent by email, and export its data. After 90 days, the organization and its Customer Data are permanently deleted, and backup copies are overwritten within 30 days.
  • Return to the Free plan. When a paid subscription ends, location history and activity-log entries older than the Free plan’s retention period are deleted. When that return is not voluntary, for example after a failed payment, deletion takes place only after a grace period of 30 days, announced to the Owner by email; no data is deleted if a paid subscription is restored during that period.
18. Privacy incidents

If a confidentiality incident occurs — unauthorized access, use, disclosure or loss of personal information — we take reasonable measures to reduce the risk of harm and prevent recurrence, and we record it in our incident register. If the incident presents a risk of serious injury, we notify the Commission d’accès à l’information and the individuals concerned, as the law requires. For Customer Data, we notify the Customer without undue delay and in any case within 72 hours of confirming the incident, and we assist it in meeting its own obligations.

19. Minors

The Platform is intended for organizations and their personnel. It is not directed at children, and we do not knowingly collect personal information from anyone under 14 years of age other than as Customer Data entered by a Customer, which is responsible for obtaining the consent required by law.

20. Dedicated Cloud and On-Premises deployments
  • Dedicated Cloud. RIOH hosts and operates the Platform for a single Customer, as its service provider, under the agreement signed with that Customer. This Policy applies, except where that agreement provides otherwise (for example on hosting location, retention periods, the service providers used, or incident notification).
  • On-Premises. The Customer installs the Platform on its own infrastructure and is solely responsible for the personal information it contains, including hosting, security, backups, retention and the rights of individuals. RIOH does not receive this information, except: (a) what the Customer chooses to share with RIOH, for example during a support intervention it requests; and (b) technical information from services the Customer chooses to keep enabled, which may include RIOH’s map, map-editing or health-monitoring services, and third-party services such as maps (Mapbox), email or SMS delivery. The agreement with the Customer lists which of these are used. Questions about an On-Premises deployment should be addressed to the Customer that operates it.
  • In both cases, no cookie choice is requested when no analytics tool is enabled, and the strictly necessary cookies of Section 15 still apply.
21. Changes to this Policy

We may update this Policy to reflect changes to the Platform, our practices or the law. We will post the new version with its date. If the changes are significant, we will notify you by email or in the Platform before they take effect and, where required, ask for your consent again. Significant changes to the use of cookies will also bring the cookie choice back.

22. Contact — Privacy Officer

Our Privacy Officer is responsible for the protection of personal information at RIOH and handles questions, requests and complaints:

Privacy Officer — Dan Rousseau, Director of Operations
RIOH inc.
9545, rue Sainte-Madeleine
Mirabel (Québec) J7N 2N2
Canada
Email: info@rioh.io
Telephone: +1 438 830-6837

We will investigate every complaint, tell you the outcome, and correct the situation if the complaint is justified.