GMhigm.ai

Legal

Privacy Policy

Last updated: April 11, 2026

This Privacy Policy describes how 2378608 Ontario Inc., a corporation headquartered in Toronto, Ontario, Canada, carrying on business as Digital Trend (“GM,” “we,” “our”), handles information when you use the GM web application, mobile applications, messaging workflows, and related services (collectively, the “Service”). By using the Service you acknowledge this Policy.

GM is a business-to-business tool for business owners and on-site managers (“Operators”) to schedule, communicate with, and manage their staff (“Employees”). Operators are our customers; Employees interact with the Service through a mobile application, a web browser, or text message. This Policy applies to both.

Our data-minimization commitment. GM is designed to operate on the smallest set of information required to schedule and manage staff. An Operator supplies only a first name and mobile number to add someone to a team; the Employee then completes their own record directly. We do not collect or store banking or direct-deposit details, driver’s licence numbers, immigration or health records, or payroll withholdings. We do not profile Employees for advertising, credit, or background-check purposes. We do not sell or rent any information we handle, and we do not use it to train machine-learning models.

1. Information we handle

1.1 Information Operators provide directly

  • Account information: the Operator’s first name, business name, contact email, mobile phone number, and password credentials (stored only as a salted hash, never in plain text).
  • Business information: storefront city/region, operating hours, staffing templates, and billing-plan selection.
  • Billing information: subscription plan and invoice history. Payment cards are handled directly by our payment processor; GM never receives or stores full card numbers, CVV codes, or bank account details.

1.2 Information Operators provide about Employees

To run the Service, Operators give GM only what is needed to send a text message to the right person at the right time:

  • First name (or preferred display name).
  • Mobile phone number, required to identify the Employee and deliver notifications.
  • Role or job title, availability windows, and shift history on the Operator’s schedule.

Where an Operator adds an Employee to a team, GM collects the remainder of that Employee’s record from the Employee directly, on their own device and through a single-use link, rather than from the Operator. Two additional fields are required to complete a record:

  • Home address, used to confirm eligibility and commute distance.
  • Date of birth, where age affects what shifts may lawfully be worked.

The same form presents one optional field: a government tax identifier, provided for Operators who elect to retain it alongside the balance of the record rather than solely within their payroll system. GM does not require this field, does not depend on it for any function of the Service, and performs no calculation or filing with it; it is retained solely so that the Operator may furnish it to their payroll provider. An Employee may leave the field blank and complete onboarding without restriction. Where a value is supplied it is encrypted at rest, is not disclosed to on-site managers, and may be revealed only by the account owner. Each reveal and each export is recorded in an audit log.

GM does not ask for banking or direct-deposit details, immigration documents, driver’s licence numbers, health information, or emergency-contact details. Payroll processing, tax withholding, and benefits-of-record remain entirely with the Operator’s existing payroll provider — GM stores this information so the Operator can supply it to that provider, and does not calculate or file anything with it.

Operators warrant that they have the legal authority and appropriate consent to share the limited Employee information above with GM, and that they will inform their Employees of this sharing in accordance with applicable privacy laws.

1.3 Information Employees provide in use of the Service

  • Replies to onboarding, scheduling, and coverage prompts, whether submitted in the application or by text message, including preferred language.
  • Location at the two moments an Employee checks in to and out of a shift. GM records the coordinates the device reports at each of those moments, together with the resulting distance from the Location, so that an Operator can confirm a shift was worked on site. Collection is confined to those two actions: GM does not track location in the background, does not build a continuous trail of an Employee’s movements, and collects nothing between check-in and check-out or while the application is closed. These records are held with the shift and are removed with it.

1.4 Information from connected third-party services

  • When an Operator connects a point-of-sale (POS) system, GM ingests only the aggregated business data the Operator has authorized: sales and tender totals, product or service catalog, merchant tax- rate configuration, and merchant metadata. GM does not ingest cardholder data, customer names, customer contact details, loyalty identifiers, or other end-consumer personal information from any connected service. The integration is read-only; GM does not write to, modify, or delete data in the connected service.
  • GM stores only the access credentials required to make authenticated calls back to the integration. Those credentials are encrypted at rest and revoked immediately when the Operator disconnects the integration.

1.5 Photographs submitted by Operators

Managers can photograph receipts and supplier invoices to record costs. GM reads the amounts and supplier details from the image to save re-typing them. Images are stored against the Operator’s account and are not used for any purpose beyond the cost record they belong to.

1.6 Information we collect automatically

  • Usage data: pages visited, feature interactions, and aggregate message volume.
  • Network and browser data: IP address, browser type, operating system, and time-zone setting — used strictly for security, abuse prevention, and session management. IP addresses are retained only as long as needed for those purposes and are not used for advertising or cross-site tracking.
  • A device notification token, if you allow notifications, so a shift alert can reach that specific phone. It identifies the device, not the person, is supplied by Apple or Google rather than by us, and is discarded when notifications are turned off or the app is removed.
  • Cookies used to keep you signed in and remember preferences. GM does not use third-party advertising or marketing-attribution cookies on authenticated pages. You can control cookies in your browser settings; disabling them may degrade certain features.

2. How we use this information

  • To provide the Service. Building schedules, detecting late arrivals, finding shift coverage, sending reminders, confirming on-site check-ins, surfacing labor-cost reporting, and producing operations dashboards and forecasts.
  • To communicate with Operators and Employees. Transactional notifications (schedule published, coverage accepted, password resets, security alerts) and occasional product updates.
  • To power AI-assisted recommendations. GM uses machine-learning inference to summarize operations, answer questions, interpret incoming messages, and suggest actions. Only the text strictly needed for the requested task is sent to inference providers, under zero-retention and no-training contractual terms (see Section 3). Inference providers do not receive Employee phone numbers or billing details.
  • To bill for the Service and to detect fraud or abuse.
  • To comply with legal obligations and enforce our Terms of Service.

We do not sell personal information. We do not use Employee message content for advertising or to train publicly released models. We do not use Operator business data for cross-customer analytics without explicit consent.

3. Sub-processors and service providers

GM engages reputable third-party service providers to deliver the Service. Current categories include:

  • Cloud infrastructure and database hosting.
  • Message delivery (carrier-grade routing of text messages to Employees).
  • Transactional email delivery.
  • Payment processing for Operator subscriptions.
  • Connected point-of-sale providers, only when an Operator has explicitly authorized a POS connection from within the Service.
  • Machine-learning inference providers used to generate and interpret text in GM’s conversational interface. Data sent for inference is subject to the provider’s zero-retention and no-training terms; a current list of sub-processors is available upon written request to privacy@higm.ai.

Each sub-processor is contractually required to process information only on our documented instructions and to apply appropriate safeguards.

4. Sharing and disclosure

We share personal information only in these circumstances:

  • With the Operator that manages an Employee’s account. GM is the data processor; the Operator is the data controller for their staff records.
  • With sub-processors listed in Section 3, under binding data-processing agreements.
  • When compelled by valid legal process, to protect our legal rights, or to prevent fraud or imminent harm.
  • In connection with a corporate transaction (merger, acquisition, or asset sale), subject to confidentiality obligations.

5. International data transfers

GM is a Canadian company and primary processing and storage occur on servers located in Canada. Certain sub-processors — including message delivery and machine-learning inference — may process requests on infrastructure located in the United States. While information is in another jurisdiction it may be accessible to the courts and law-enforcement authorities of that jurisdiction. We contract with those providers on terms requiring safeguards comparable to our own, and require zero-retention and no-training terms wherever inference is involved.

6. Data retention

  • Active accounts: we retain data for the life of the Operator’s subscription, plus a 90-day grace period after cancellation during which the account can be reactivated.
  • Former Employees: when an Operator removes a staff member from their roster, we retain the shift history needed for that Operator’s labor reporting, but the Employee’s mobile phone number is promptly deactivated for messaging and pruned from active records on request.
  • After the account grace period, remaining information is deleted or irreversibly anonymized unless longer retention is required by law, necessary to resolve disputes, or needed to enforce our agreements.
  • Activity history — the record of shifts, check-ins, coverage and messages comprising an Operator’s feed — is retained for 12 months and then deleted. It constitutes operational history rather than an accounting record, and is retained only for so long as it remains necessary to the operation of the Operator’s business.
  • Records of access to sensitive information — identifying who revealed a tax identifier or exported a team list — are retained for 24 months to permit the detection and investigation of misuse. They are retained beyond ordinary activity history for that purpose, and are deleted with the account.
  • Billing is administered by our payment processor. Invoices, payments and tax records are held by that processor and by our accountants, where the retention periods prescribed by applicable tax law apply. GM stores only the identifiers linking an Operator’s account to that processor, and those identifiers are deleted with the account.

7. Security

We apply administrative and technical safeguards appropriate to the sensitivity of the information, including:

  • Passwords are hashed rather than stored. Operator passwords are protected with bcrypt and a salt unique to each password. The transformation is one-way, so a password cannot be recovered from our records by us or by anyone who obtained them. Account keys held by the Service are likewise stored only as hashes.
  • Encryption at rest for the sensitive fields we hold in recoverable form: tax identifiers, point-of-sale credentials, and other integration secrets.
  • Encryption in transit via TLS for all traffic to and from the Service.
  • Two-factor authentication on every Operator sign-in. A single-use code is sent by text message after a password is accepted, and cannot be skipped. Passkeys are supported as an alternative on the web.
  • Tenant scoping on every query. Each request is confined to the Locations the requesting account is entitled to see. This is enforced in the application, and reinforced by a restricted database role that limits what GM’s automated queries are able to return.
  • Physical and environmental controls at the facilities of the infrastructure providers on which the Service is hosted.

No system is perfectly secure. If we become aware of a breach that affects information you have entrusted to us, we will notify affected parties in accordance with applicable law.

8. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, or receive a portable copy of the information GM holds about you, and to object to certain processing. You may also withdraw a previously given consent.

Operators: the person who signed the account up can delete it at any time, without contacting us, from Owner → Settings in the application. Deleting an account closes it and its locations, erases personal details including home addresses, dates of birth and any tax identifiers, and deletes the activity history described in section 6. Shift and hours records are retained with no name attached, so that a past labour total remains accurate without identifying anyone. The deletion takes effect immediately and cannot be reversed.

Employees: the information GM holds about you is set out in sections 1.2 and 1.3 above. In summary, it comprises the name and mobile number your Operator supplied, the home address and date of birth you provided when completing your own record, a tax identifier if you chose to supply one, your shift activity (role, availability, and the shifts you worked), and the check-in and check-out records described in section 1.3. For broader requests, please contact the Operator who employs you; if you are unable to reach them, contact us at privacy@higm.ai and we will help route the request.

Canadian residents may exercise rights under the federal Personal Information Protection and Electronic Documents Act (PIPEDA), including the right to file a complaint with the Office of the Privacy Commissioner of Canada.

9. Children

GM is intended for use by businesses and their staff. We do not knowingly collect information from individuals under the age of 16. If you believe a minor has interacted with the Service, please contact us and we will remove what we hold.

10. Changes to this Policy

We may update this Policy from time to time. Material changes will be announced to the Operator’s registered email address and posted here with an updated “Last updated” date at the top of the page. Continued use of the Service after a change constitutes acceptance.

11. Contact

2378608 Ontario Inc. o/a Digital Trend
Toronto, Ontario, Canada
Email: privacy@higm.ai
General: ask@higm.ai