Privacy Policy

Effective August 12, 2026 · Version 2026-12

1. Who we are

Operator. LTOWatch.com is operated by Pronome Technologies Ltd., a corporation incorporated under the laws of Alberta, Canada, incorporated 2026-08-11 ("LTOWatch," "we," "us," or "our"). Pronome Technologies Ltd. is the organization accountable for personal information under this policy.

Privacy Officer. The Privacy Officer is responsible for this policy, access and correction requests, complaints, service-provider questions, and breach response. Contact details are in section 17.

2. Scope and Alberta privacy framework

LTOWatch is a business-to-business service designed for licensed Alberta retail liquor businesses. This policy covers the LTOWatch website and account, the LTOWatch browser extension, inquiries, billing, support, and related administrative activity. The primary privacy framework for the service is Alberta's Personal Information Protection Act (PIPA). Nothing in this policy limits any requirement that applies under mandatory law.

In this policy, a Third-Party Retailer Portal means a third-party catalogue, ordering, supplier, distributor, wholesaler, or retail-network portal supported by the LTOWatch browser extension from time to time. Each such portal is independent from LTOWatch.

Personal information means information about an identifiable individual. Business and product information may not be personal information on its own; where a record is linked to an identifiable owner, employee, contact, or user, we handle the linked record in accordance with this policy. This policy does not govern a Third-Party Retailer Portal, Stripe, or another third party's independent handling of information.

3. Information we collect

We limit collection to information reasonably required for the purposes identified in this policy. Depending on how you interact with LTOWatch, the categories below may apply.

CategoryExamplesMain purposes
Account and eligibilityName; login and business email; hashed password; phone; business name and type; city and Alberta province; AGLC licence number; timezone; account and verification status; terms/privacy acceptance dates.Create and secure an account, verify Alberta-market eligibility, administer approvals, record consent, and communicate about service access.
Application and reviewSubmission, approval and review dates; staff notes; information requests; status history; staff actor; and an application snapshot containing submitted business/contact details.Conduct and audit account review, answer application questions, prevent inconsistent decisions, and support compliance.
InquiryFirst and last name; business name and city; email; phone; optional message; eligibility confirmation; verification/contact status; source page; risk flags; staff notes and correspondence.Verify and answer inquiries, assess eligibility, prevent abuse, and maintain a service record.
Linked browser and extensionStable random device ID; device label/platform; pairing and revocation status; token hash; created/last-used times; extension version; scan state and technical errors. The raw pairing bearer token is stored locally in the extension.Link an authorized browser, authenticate extension requests, resume scans, show access status, troubleshoot, and revoke access.
Catalogue and scan activityProduct data selected by the extension from a supported Third-Party Retailer Portal, including SKU, name, size, category/type, country, supplier, availability, unit/case pricing, price changes, LTO dates, and new-listing status; scan scope, filters, timing, progress, counts, metrics and errors.Maintain an account-scoped catalogue, detect changes, provide freshness and scan status, and improve reliability.
Commercial activityWatchlist items; recent search queries; named saved filters; catalogue observations; account-specific price/availability history; confirmed-purchase details such as quantity, date, prices, reference prices, savings/variance, status, and void/review information.Provide watchlists, saved views, purchase records, reports, comparisons, and account analytics.
BillingStripe customer/subscription/checkout/invoice/payment/refund identifiers; plan, status, trial and billing-period dates; cancellation/grace status; country/region and tax status; amounts/currency; notice and reconciliation records; payment-link reference.Start and administer subscriptions, reconcile payment state, provide billing support, and maintain accounting/audit records.
Communications and supportTransactional emails, verification and reset requests, billing notices, support content, inquiry replies, and related delivery/failure status.Authenticate users, deliver the service, respond to requests, provide support, and document important notices.
Password-reset requestAn email address submitted through the password-reset form, including an address that is not associated with an LTOWatch account; request, retry, and delivery status. The outbox stores no reset token or rendered message.Process account recovery without revealing whether the address is registered; control abuse; deliver an authorized reset email; and diagnose delivery failures.
Technical and securitySession and CSRF identifiers; IP address; browser/user-agent and request metadata; timestamps; paths/status codes; anti-abuse counters; logs; authentication, security and error events.Operate and protect the service, detect bots/abuse, enforce rate limits, diagnose failures, and investigate security events.
Enforcement recordsWhere an application is rejected or an account is suspended or terminated under our Terms of Use: the decision, its date, the responsible staff member, the recorded reasons, and the business and representative details from the account or application it relates to.Enforce the decision, identify and decline a later application from the same business or representative, keep review decisions consistent, respond to a reconsideration request, and defend the decision if it is challenged.

Information we deliberately do not collect

LTOWatch does not ask for or store your password, credential, or session cookie for any Third-Party Retailer Portal, or payment-card number, CVC, or full card details. Stripe collects payment details in its hosted service. The extension does not place orders. We do not use advertising pixels or third-party behavioural advertising SDKs in the reviewed implementation.

4. How we collect information

From you. We collect information when you register, accept legal terms, submit or verify an inquiry, update your account, link a browser, create a watchlist or filter, confirm a purchase, use hosted billing, request support, or otherwise communicate with us.

Through the extension. At your direction, the extension reads allowlisted product and commercial fields from a supported Third-Party Retailer Portal through your browser's existing authenticated session and sends the selected fields and scan metadata to LTOWatch. It does not send the portal credential or session to LTOWatch.

Automatically. The website, extension, hosting environment, security controls, and service providers automatically generate technical information such as IP address, device/browser signals, cookies, request metadata, logs, and event timestamps.

From providers and administrators. Stripe returns limited payment and subscription results. Cloudflare returns bot-assessment results. Authorized LTOWatch administrators generate review, audit, support, access-grant, and security records when administering the service.

5. How we use information

Provide the service. Create accounts; authenticate users and extensions; maintain account-scoped catalogue data; run scans; show price, availability and LTO insights; provide watchlists, purchase records, reports and saved filters.

Verify and administer access. Confirm email and Alberta-market eligibility; review applications; link and revoke browsers; answer inquiries; and manage support.

Process billing. Initiate hosted Stripe checkout, maintain subscription access, reconcile invoices/refunds, deliver billing notices, and maintain financial records.

Protect LTOWatch and users. Detect bots, fraud and abuse; apply rate limits; investigate incidents; prevent unauthorized account access; maintain logs and audits; and enforce our terms.

Communicate. Send service, verification, security, billing, legal and support messages. Account creation does not enrol you in promotional marketing.

Maintain and improve. Diagnose errors, monitor performance and freshness, understand feature use, and improve reliability. Where practical, we use aggregated or de-identified information for this purpose.

Meet legal and business obligations. Respond to lawful requests, establish or defend legal claims, maintain appropriate records, and complete an authorized financing, reorganization or transfer of the business.

6. The browser extension and Third-Party Retailer Portals

The extension operates only on configured pages of supported Third-Party Retailer Portals and uses the session already established in your browser. You choose when to pair the browser and start a scan. The extension maps and uploads allowlisted product fields; it does not provide LTOWatch with a portal password or session cookie and it does not order products. Each Third-Party Retailer Portal remains an independent service, and its terms and privacy practices apply to your relationship with it.

Local extension storage. The extension stores a pairing bearer token, a stable random device ID, configuration, scan progress, recent scan summary, and access/revocation state in Chrome extension storage. Account-private insights may be cached in session storage and displayed in the relevant Third-Party Retailer Portal page for no more than five minutes; that cache is cleared when the browser session ends and on relevant access changes. Unpairing clears the account token and account-specific caches, but a device ID or technical settings may remain until you clear the extension's storage or uninstall it.

7. Cookies and similar technologies

LTOWatch uses essential Django session and CSRF cookies to keep you signed in and protect requests. The regular session can remain valid for up to 14 days, subject to logout, expiry, revocation and configuration. A private staging environment may use a signed access cookie for up to 12 hours. These are operational and security cookies, not advertising cookies.

Cloudflare Turnstile may process client IP address, TLS fingerprint, user-agent, site key and origin, and may use strictly necessary cookies or similar signals to distinguish people from bots and improve bot detection. We do not use the reviewed implementation for targeted advertising or cross-site marketing profiles.

8. When we disclose information

We do not sell or rent personal information and do not disclose it to data brokers or behavioural advertising networks. We may disclose only what is reasonably necessary in the circumstances below.

Service providers. Hosting/database, transactional email, bot prevention, payment processing, support, security and professional service providers acting for authorized purposes.

Within an account. Authorized users and administrators of the same business account may see account information and account-scoped catalogue, scan, watchlist, purchase and reporting data according to their permissions.

Legal, safety and enforcement. Government, regulators, law enforcement, courts, insurers or advisers where required or permitted by law, or reasonably necessary to protect rights, safety, the service or users.

Business transition. A prospective or completed corporate successor, purchaser, investor or adviser in connection with incorporation, financing, reorganization, sale or transfer, subject to confidentiality and legal safeguards.

With consent. Another person or organization where you direct us or otherwise consent, or where a lawful exception permits the disclosure.

9. Service providers outside Canada

Some providers collect, use, disclose, store, or permit access to personal information outside Canada. While there, information may be subject to the laws and lawful-access processes of that country. Our Privacy Officer can answer questions and provide access to our policies and practices concerning these providers.

ProviderCountry/regionAuthorized purposesInformation
Render / database hostUnited States (Oregon)Web application, database, backups, logs, availability and infrastructure support.Account, catalogue, commercial, billing, inquiry, communications and technical records.
PurelymailUnited States (Northern Virginia)Transactional email delivery, routing, abuse prevention and support.Recipient/sender addresses, names, message content, delivery metadata and diagnostics.
StripeCanada, United States, and other Stripe locations; India may apply to certain authentication/security dataHosted checkout, payment, subscription, tax, fraud, portal and billing support.Identity/contact, device/IP, payment and billing information supplied to Stripe; LTOWatch references and results.
Cloudflare TurnstileUnited States and other Cloudflare network locationsBot detection, website protection and improvement of Turnstile.IP address, TLS fingerprint, user-agent, site key/origin and bot-assessment signals.

10. Consent and choices

We seek consent appropriate to the circumstances and may collect, use or disclose information without consent where PIPA or another applicable law permits. Consent may be express—for example, accepting the policy or submitting an inquiry—or implied where the purpose is obvious and the information is not sensitive. We will not require consent beyond what is reasonable to provide a product or service.

You may withdraw consent on reasonable notice by contacting the Privacy Officer, subject to legal or contractual restrictions and reasonable notice. We will explain the likely consequences. Withdrawal may prevent us from providing an account, extension access, billing, support, or another requested feature.

LTOWatch currently sends operational and transactional messages, not promotional marketing based merely on account registration. If promotional marketing is introduced, we will provide the choice and unsubscribe mechanism required for that activity rather than treating account acceptance as marketing consent.

11. Retention and destruction

We retain personal information only for as long as reasonably required for the identified business or legal purposes. Relevant factors include whether an account is active, service and support needs, auditability, security, accounting and tax requirements, disputes, legal claims, and backup cycles. When information is no longer required, we securely destroy it or make it anonymous.

RecordRetention
Unverified registration30 days after creation
Unverified inquiry14 days after creation
Password-reset outboxPending requests are kept until delivered, discarded, or abandoned. Delivered and discarded requests are deleted one hour after completion. Abandoned requests are deleted within 7 days after abandonment.
Anti-abuse cacheGenerally 5 minutes to 24 hours in the required shared Redis production cache.
Website sessionUp to 14 days; it may end sooner through logout, expiry, revocation, or configuration.
Staging access cookieUp to 12 hours where private staging access is enabled.
Active account and linked business dataWhile the account is active and for 24 months after closure; then deleted or anonymized, except for records subject to a longer period below or a legal hold.
Verified inquiry and correspondence24 months after the last communication.
Catalogue observations90 days; records needed to substantiate a confirmed purchase follow the applicable billing, audit, or dispute period.
Billing, audit and security recordsSecurity and application logs: 90 days. Billing, accounting, and related audit records: 6 years after the end of the last tax year to which they relate.
Enforcement records (rejection, suspension, termination)24 months after the rejection, suspension, termination, or final reconsideration decision.
Provider logs/backupsProvider logs and backup copies: 90 days. Information subject to a legal hold is retained until the hold ends and is then securely deleted.

12. Security and privacy breaches

We use safeguards reasonable for the sensitivity of the information, including HTTPS, secure cookie settings, password hashing, hashed extension credentials, role and account scoping, CSRF protection, rate limits, audit records, token revocation, environment separation, and restricted administrative access. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

If a privacy breach creates a real risk of significant harm to an individual, we will notify the Office of the Information and Privacy Commissioner of Alberta without unreasonable delay, take reasonable steps to contain and reduce harm, and notify affected individuals where required or otherwise appropriate.

13. Access and correction

You may make a written request to access personal information about you in our custody or control, learn how it has been used or disclosed as provided by PIPA, or request correction of an error or omission. Email the Privacy Officer with enough detail to identify the records. We may need to verify your identity and authority before responding.

We will respond within 45 days unless PIPA permits an extension. Access may be limited where PIPA requires or permits withholding, including to protect another individual's information, confidential opinions or legal matters. We may charge a reasonable access fee only as permitted by law and after providing an estimate; we do not charge to correct personal information. If we do not make a requested correction, we will annotate the record where required.

14. Account closure, deletion, and extension storage

Self-service account deletion is not currently available. To close an account, request deletion, revoke linked browsers, or ask about retention, contact the Privacy Officer. We will assess the request under PIPA and our legal and operational obligations. We may retain limited billing, audit, security, enforcement, dispute or legal records after closure and will restrict them to the remaining purpose.

Unpairing a browser revokes its LTOWatch credential and clears account-specific extension caches covered by the unpair flow. To remove all remaining local device identifiers and configuration, clear the extension's site/extension storage or uninstall the extension. Account closure may also require terminating or updating the hosted Stripe subscription or customer relationship under the applicable billing process.

15. Accuracy, minors, and Alberta-market eligibility

Please keep account and business contact information accurate and tell us when it changes. LTOWatch is intended for adults acting for Alberta retail liquor businesses and is not directed to minors. We do not knowingly collect personal information from anyone under 18 through the service. If you believe a minor has submitted information, contact the Privacy Officer.

16. Changes to this policy

We may update this policy as the service, providers, corporate operator, or legal requirements change. We will post the updated version and effective date. Where a change is material, we will provide additional notice or seek new consent where required. The incorporation of Pronome Technologies Ltd. is reflected in section 1 and the operator details at the top of this policy.

17. Contact and complaints

Privacy Officer

Email: support@ltowatch.com

Organization: Pronome Technologies Ltd., operating as LTOWatch.com

Province: Alberta, Canada

Mailing address: 117 Central Ave W, Linden, Alberta, T0M 1J0

Phone: (403) 879-7839

If you are not satisfied with our response, you may complain to the Office of the Information and Privacy Commissioner of Alberta.