BlindFab
HomeSign In

Privacy

Privacy Policy

How BlindFab collects, uses, discloses, protects, and retains information across the public website, demo requests, and the BlindFab operating platform.

Last updated July 23, 2026

Overview

This Privacy Policy explains how BlindFab collects, uses, discloses, protects, and retains information when you visit blindfab.com or blindfab.ca, request a demo, communicate with us, or use the BlindFab application and related services.

BlindFab is built for multi-tenant business operations. Customer workspaces may contain operational records such as leads, quotes, orders, product configuration, inventory, warehouse activity, manufacturing work orders, production history, HR records, permissions, audit history, telephony context, and other business data submitted by authorized users.

Information we collect

The information we collect depends on how you interact with BlindFab and how your organization configures the service.

  • Account and workspace information, such as name, email address, company, role, authentication state, workspace membership, and permission assignments.
  • Demo, support, and contact information, such as the details you submit through a demo request, email conversation, support request, or similar communication.
  • Anonymous public-site funnel events, such as a landing view, demo-button click, form start, submitted request, scheduler view, or confirmed booking. These events use a random session identifier, page path, placement, allowlisted campaign fields, and referrer host; they do not contain your name, email, company, full referrer URL, IP address, or arbitrary query string.
  • Customer workspace data submitted by authorized users, including CRM records, dealer information, quotes, orders, measurements, product models, inventory records, warehouse activity, manufacturing and fulfillment records, HR and administrative records, files, notes, communications, and audit history.
  • Usage, device, and diagnostic information, such as browser type, device information, IP address, approximate region, pages or app surfaces viewed, timestamps, log events, error reports, and security-relevant activity.
  • Communication information, such as email delivery events, telephony or messaging metadata, call notes, recordings, transcripts, or related content when those capabilities are enabled by an authorized workspace.
  • Connected financial-account information, such as financial institution and account identifiers, account type and name, masked account number, balances, transactions, pending and posted transaction history, liabilities, connection health, and authorization or settlement metadata when an authorized user enables banking features.

How we use information

  • Provide, operate, secure, maintain, and improve BlindFab and related public website experiences.
  • Authenticate users, route users to the correct workspace, enforce permissions, support tenant isolation, and maintain audit history.
  • Process demo requests, respond to inquiries, provide support, communicate service information, and manage customer relationships.
  • Measure how the public demo funnel is used so we can understand which paths lead to requests and scheduled demonstrations.
  • Enable configured ERP workflows, including quoting, ordering, product configuration, inventory, barcode scanning, work orders, manufacturing, warehouse operations, reporting, HR, permissions, audit history, mobile workflows, and telephony.
  • Provide user-authorized banking workflows, including importing account balances and transactions, reconciling and classifying activity, managing cash position, and initiating or tracking payments only after the required user authorization and approval.
  • Detect, investigate, and prevent security incidents, abuse, errors, unauthorized access, and activity that may violate agreements or applicable law.
  • Comply with legal, regulatory, contractual, accounting, tax, dispute-resolution, and recordkeeping obligations.

Customer workspace data

Customer workspace data belongs to the customer or the relevant rights holder. BlindFab processes workspace data to provide the service, support authorized users, maintain the system of record, and perform work requested by the customer or workspace administrators.

Workspace administrators are responsible for deciding which users may access a workspace, what permissions they receive, what data is submitted, and whether certain workflows, such as communications, HR, mobile, or telephony features, are enabled.

How we share information

We do not sell personal information. We share information only as needed to provide and protect BlindFab, comply with obligations, or follow customer instructions.

  • Service providers that help us operate BlindFab, including hosting, database, authentication, email, communications, storage, analytics, security, monitoring, support, and infrastructure providers.
  • Customer administrators and authorized workspace users according to configured roles, permissions, and workspace workflows.
  • Legal, compliance, safety, and security recipients when required to comply with law, enforce agreements, protect rights, investigate abuse, or respond to valid legal process.
  • Professional advisors, auditors, insurers, or transaction counterparties where reasonably necessary for business operations, financing, corporate transactions, or similar events.

Text messaging and mobile information

If you separately check an SMS consent box and provide a mobile number, BlindFab may send customer-care text messages about demo coordination, account access, support, orders, workflow events, appointments, or service. Message frequency varies. Message and data rates may apply. Reply STOP to opt out or HELP for help. Consent is not a condition of purchase.

Mobile information, text-messaging originator opt-in data, and consent are not sold, rented, or shared with third parties or affiliates for their marketing or promotional purposes. We may disclose the minimum information needed to messaging providers, mobile carriers, and service vendors solely to deliver and operate the messaging program or as required by law.

Google user data and Limited Use

When an authorized user connects a Google account (for example, Gmail, Google Calendar, or Google Contacts) to BlindFab, BlindFab requests access only to the data needed to provide the feature the user enabled. For a connected Gmail mailbox this includes reading, organizing, sending, and syncing the user's email messages, drafts, labels, send-as identities, and the account email address; for Calendar and Contacts it is limited to the corresponding calendar and contact data.

Access is granted per user through Google's consent screen, can be reviewed at any time, and can be revoked by disconnecting the account inside BlindFab or from the user's Google Account permissions page (myaccount.google.com/permissions). When an account is disconnected, BlindFab revokes the associated tokens with Google and stops further synchronization.

BlindFab's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not transfer it to others except as necessary to provide and improve the user-facing features, with the user's consent, for security purposes, or to comply with applicable law. We do not allow humans to read Google user data unless we have the user's consent for specific messages, it is necessary for security or to comply with applicable law, or the data is aggregated and anonymized for internal operations such as abuse prevention and service reliability.

Connected financial accounts and Plaid

When an authorized user connects a financial account, BlindFab uses Plaid to present the financial institution connection experience and obtain the account data and provider tokens needed for the features the user enables. Financial institution credentials are entered into the Plaid experience and are not stored by BlindFab.

Depending on the institution, country, products approved for BlindFab, and features selected by the user, Plaid may provide account and institution details, masked account numbers, balances, transactions, pending-to-posted updates, liabilities, identity or account-ownership information, connection and consent status, and payment authorization or settlement information.

BlindFab uses connected financial data only to provide the user-requested accounting, bank-feed, reconciliation, cash-management, fraud-prevention, support, and payment features; protect the service; and meet legal, audit, and recordkeeping obligations. BlindFab does not sell connected financial data or use it for advertising.

BlindFab may share the minimum necessary information with Plaid, the connected financial institution, an authorized payment processor, and infrastructure or security providers to operate the requested feature. Their handling of information is also governed by their applicable terms and privacy notices.

Financial account consent and disconnection

A financial account is connected only after an authorized user completes the provider consent flow. The user can disconnect the connection from BlindFab. Disconnecting revokes or removes the provider connection where supported, stops future synchronization, and prevents new use of that connection for payment initiation.

Disconnecting does not erase accounting entries, reconciliation evidence, settlement records, audit history, or other records that BlindFab or the customer must preserve to maintain financial correctness, comply with law, resolve disputes, or support an immutable system of record. Where deletion is permitted, requests may be sent to the contact below and will be evaluated against the customer's instructions and applicable retention requirements.

Cookies and similar technologies

BlindFab may use cookies, local storage, and similar technologies to keep users signed in, remember workspace and interface preferences, support security controls, diagnose issues, and understand how public and app surfaces are used.

Your browser may allow you to block or delete cookies. Some authentication, workspace routing, security, preference, and app functionality may not work correctly if required storage is disabled.

Retention

We retain information for as long as needed to provide BlindFab, maintain operational records, comply with legal and contractual obligations, resolve disputes, enforce agreements, support audit history, and preserve the integrity of customer workspaces.

Because BlindFab is a system of record, some records may need to be retained for audit, traceability, security, accounting, legal, or business continuity reasons even after an account changes or a request is made.

Provider credentials and connection tokens are retained only while needed to maintain an authorized connection and are revoked or removed when the connection is disconnected where the provider supports revocation. Imported financial evidence, posted accounting records, reconciliation history, and settlement history may be retained longer under the customer's retention schedule or applicable accounting, tax, audit, legal-hold, and dispute requirements.

Anonymous public-site funnel events are retained for 13 months and then deleted through a daily guarded cleanup.

Security

BlindFab uses administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure. These safeguards include workspace isolation, role-based access, authentication, audit-oriented design, and backend-enforced controls.

No online service can guarantee absolute security. Customers and users must protect account credentials, use appropriate access controls, and notify us promptly about suspected unauthorized access.

International processing

BlindFab and its service providers may process and store information in Canada, the United States, and other jurisdictions where we or our providers operate. Information may be subject to the laws of those jurisdictions.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal information. To make a request, contact us at the email below.

If your information is inside a customer workspace, we may direct you to the relevant workspace administrator or customer because they control the workspace data and user permissions.

Children

BlindFab is designed for business use and is not directed to children. We do not knowingly collect personal information from children through the public website.

Changes to this policy

We may update this Privacy Policy from time to time. The updated version will be posted on this page with a new last updated date. Material changes may also be communicated through appropriate channels.

Contact

Questions, requests, or privacy concerns can be sent to info@blindfab.ca. Please include enough detail for us to understand the request and identify the relevant workspace or interaction.

BlindFab

PrivacyTerms of ServiceTerms of UseContact