Privacy Policy

Last Updated: September 9, 2026

1. Who We Are

Project Tray, operating as Project Tray (“Project Tray,” “we,” “us,” or “our”), respects your privacy and is committed to protecting personal information under our control.

This Privacy Policy applies to projecttray.com and the Project Tray services covered by this policy, including account registration, subscriptions, demonstrations, customer support and our processing of information through the platform.

Project Tray provides business software for project management, customer and supplier management, quotations, billing, inventory, scheduling, reporting and time logging.

We handle personal information in accordance with applicable Canadian privacy legislation, including the Personal Information Protection and Electronic Documents Act (PIPEDA), where applicable.

2. Our Role and Your Organization’s Role

We handle personal information in two main contexts.

Our own business activities: We are responsible for information we collect to manage website inquiries, subscriptions, billing, account relationships, support and our own permitted marketing.

Information managed by customer organizations: Businesses using Project Tray may enter information about their employees, customers, suppliers and other contacts. We refer to this as “Customer Data.” When we process Customer Data on a customer’s behalf, we do so to provide the agreed services, follow the customer’s lawful instructions and meet applicable legal requirements.

The customer organization determines why it collects Customer Data, what it enters and how it uses the available features. Its privacy notices and workplace policies also apply. Our processing depends on the services and deployment arrangements agreed with that organization.

For requests about Customer Data, contact the organization that entered or manages the information first. You may also contact us for assistance. These arrangements do not remove our own legal responsibilities.

3. Personal Information We Collect

Contact, Account and Subscription Information

We may collect your name, business email address, telephone number, organization, job title, username, account preferences, subscription details and billing address. An authorized administrator may provide information to create or manage your user account.

We also process authentication and account-recovery information needed to administer access. Please do not send your password through a general contact form or ordinary email.

Inquiries and Support Information

When you contact us, request a demonstration or submit a support ticket, we collect the information you provide. This may include your contact details, inquiry, screenshots, error messages, diagnostic files and correspondence.

Customer Data in the Platform

Depending on the features used, Customer Data may contain customer and supplier contacts; project descriptions and work orders; quotations, invoices and payment-status records; schedules and assignments; uploaded artwork and photographs; messages and notes; and user-linked time entries or activity records.

Only information relating to an identifiable individual is personal information. Business records may contain both personal and non-personal information.

Technical Information

Our website and service infrastructure may process IP addresses, browser and device information, access times, session identifiers, requested pages, referring sources, errors and security events. Additional usage information depends on the analytics and other technologies enabled, as described in Section 10.

4. How We Use Personal Information

We use relevant information to respond to inquiries, arrange demonstrations, create and administer accounts, manage subscriptions, process billing and provide support.

For customer organizations, we process Customer Data to operate the features they use, such as managing projects, maintaining contacts, preparing quotations, tracking invoices, coordinating schedules and producing reports.

We also use necessary information to maintain service reliability, diagnose problems, protect accounts, investigate misuse, maintain appropriate records, resolve disputes and comply with legal obligations. Optional marketing is addressed separately in Section 11.

Customer Data is not permission to build an unrelated marketing database. We do not use customer organizations’ contact lists, project files or employee records for our own unrelated advertising or another customer’s campaigns.

5. Organization Administrators, Permissions and Time Logging

Project Tray supports user and group permissions. Your organization determines your role and which records you may access or change.

Depending on permissions and configuration, administrators and other authorized users may access business records associated with your account, including assigned projects, time entries, reports and activity information. Messages are visible to their intended participants and may be subject to administrative access under the applicable configuration and organizational policies.

Where time logging is used, records may associate your identity with a project, work phase, recorded duration and related notes. Authorized managers may use reports for scheduling, costing, billing and operational review.

Your organization is responsible for explaining its workplace use of these features and meeting applicable privacy and employment requirements. Ask your administrator which records are collected, who can see them and how they are used. This policy does not grant an employer unrestricted monitoring rights.

6. Consent and Meaningful Choices

We identify the purposes of collection at or before collection and obtain meaningful consent where required. We seek express consent where required for sensitive information or uses outside reasonable expectations.

You may withdraw consent by contacting us, subject to legal or contractual restrictions and reasonable notice. We will explain relevant consequences, including where certain information is necessary to maintain an account or deliver a requested service.

Optional marketing or tracking is not made a condition of receiving services when it is unnecessary for those services. Visiting the website, opening an account or accepting this policy does not provide blanket consent to unrelated uses.

Customer organizations must have appropriate authority to provide personal information and must give required notices and obtain required consents for their own activities.

7. Files, Demonstrations and Technical Support

Please provide only the information needed for a project or support request. Remove unnecessary personal information from screenshots, exports, artwork and other attachments where possible.

Use fictitious or appropriately anonymized information in demonstrations unless a separate arrangement authorizes the use of real records. Do not place confidential customer or employee information in public discussions or demonstration environments.

Where support requires access to an account or Customer Data, access is limited to authorized troubleshooting, maintenance or other agreed work. Any temporary support access or diagnostic copy is handled under the applicable service arrangements and retention requirements.

8. Subscription Billing and Payment Information

We process billing contacts, subscription selections, invoices, payment confirmations and transaction references to administer Project Tray subscriptions and services.

Where a third-party payment provider is used, it processes payment information under the applicable payment arrangements and its privacy notice. We receive the information needed to reconcile payments, manage renewals and provide billing support.

A customer organization’s use of Project Tray to record its own invoices or receivables is separate from our collection of subscription payments. Those business records remain Customer Data as described in Section 2.

Do not enter full payment card details into ordinary project notes, messages or support tickets.

9. Integrations and Information from Other Sources

Where an integration or import is available and authorized by your organization, information may move between Project Tray and the connected system. The information involved depends on the integration, permissions and selected functions.

We may also receive information from your organization when it invites you to an account, from a payment provider confirming a transaction, or from a service provider assisting with a support request.

Before connecting another service, review its permissions and privacy notice. Disconnecting an integration may prevent future exchanges but does not necessarily delete information already received by the other provider.

10. Cookies, Analytics and Similar Technologies

Our website and account services may use cookies or similar technologies for login sessions, security, shopping-cart functions and preferences. These technologies can store identifiers on your device or record interactions with the service.

Where enabled, analytics tools help assess traffic and performance. Advertising tools may measure campaigns or associate website visits with advertising audiences. Embedded content and spam-prevention tools may send technical information to their providers when loaded.

[COMPLETE BEFORE PUBLICATION: Identify the actual cookie, analytics, advertising, embedded-content and form-tracking providers; the information and purposes involved; relevant durations; privacy-policy links; and the exact controls available. State whether any form information is collected before submission. Remove categories that are not used.]

We obtain consent where required and respect applicable choices. Browser settings can block or remove many cookies, but may not control every tracking technology. Blocking essential cookies may affect account or checkout functions. Where a consent-management tool is provided, it offers additional controls for the technologies it manages.

11. Marketing and Service Communications

We send promotional electronic messages only with valid consent or another basis permitted by Canada’s Anti-Spam Legislation (CASL). Messages include the required sender identification and an unsubscribe method.

You may unsubscribe without charge through the message or by contacting us. We process unsubscribe requests within 10 business days.

We may continue to send non-promotional account, billing, support or security communications where permitted by law. We do not use these messages to bypass marketing preferences.

An inquiry, user invitation or unfinished purchase does not automatically authorize unrestricted promotional follow-up. Messages sent by a customer organization through its own workflows are subject to that organization’s responsibilities and communication preferences.

12. How We Share Information

We do not sell or rent personal information, customer contact lists or Customer Data for independent third-party marketing.

We share relevant information with authorized users within a customer organization as determined by its permissions and instructions. We may also provide necessary information to providers of hosting, storage, email delivery, payment processing, technical support, security, accounting and other services needed to operate Project Tray.

For providers processing information on our behalf, we limit its use to the relevant services and use contractual or other appropriate measures to require confidentiality and comparable protection. We remain accountable for information under our control.

We may disclose information with your consent or where required or permitted by law, including in response to valid legal process. Information involved in a proposed or completed merger, acquisition or similar transaction is handled subject to applicable legal requirements and confidentiality safeguards.

13. Processing Outside Canada

Some service providers may process or store personal information outside Canada. While in another jurisdiction, the information may be subject to that jurisdiction’s laws and lawful access by courts, law enforcement or government authorities.

We remain responsible for information transferred for processing on our behalf and take appropriate steps to protect it. Specific data-location commitments depend on the applicable service arrangement; this policy does not promise that all information remains in Canada.

Contact us for information about providers and processing locations relevant to your account or service.

14. Retention, Account Closure and Deletion

We retain personal information only as long as needed for identified purposes or legal requirements. Account records support subscriptions; support records assist with service issues; billing records support accounting obligations; and security logs support investigation and protection.

Customer Data is retained and deleted according to the customer’s lawful instructions, applicable service arrangements and legal requirements. Closing an individual user account may not remove that user’s contributions from the organization’s project history or business records.

Before ending a service, an authorized administrator should contact us about available export, return and deletion arrangements. Account closure does not necessarily mean immediate removal from every backup. Restricted backup copies follow the applicable retention cycle; legal holds may require particular records to be retained longer.

[COMPLETE BEFORE PUBLICATION: Confirm the customer-data export window, deletion timing following closure, backup-retention period and where customers can find these terms.]

When information is no longer required, we securely delete, destroy or effectively anonymize it. We may retain limited unsubscribe records to continue respecting marketing preferences.

15. Safeguards and Privacy Incidents

We use administrative, technical and physical safeguards appropriate to the sensitivity of the information and the risks involved. These include appropriate access restrictions and measures to protect information against unauthorized access, loss, misuse or disclosure.

No electronic transmission or storage system is completely secure. Users should protect their credentials, use available security controls and promptly report suspected unauthorized access.

We investigate privacy incidents, take steps to contain them and assess potential harm. Where PIPEDA applies, we maintain records of breaches of security safeguards involving information under our control. Where a breach creates a real risk of significant harm, we report it to the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, as required by law.

For incidents involving Customer Data, we inform and cooperate with the relevant organization under applicable law and the service arrangement, without limiting our own obligations.

16. Access, Correction and Privacy Requests

You may request access to personal information we hold about you, information about its use and disclosure, and correction of inaccurate or incomplete information.

We may verify your identity using information proportionate to the request. Where PIPEDA applies, we respond to access requests within 30 calendar days, subject to legally permitted extensions and required notice. Access is provided at minimal or no cost, with advance notice of any proposed charge.

Where access must be limited under applicable law, we explain the reasons and complaint options, subject to legal restrictions. We provide non-exempt information where it can reasonably be separated from protected information.

You may also request deletion or withdraw consent. These requests are subject to legal requirements and relevant service obligations; we explain any justified retention rather than promising unconditional deletion.

For Customer Data controlled by your organization, contact its administrator or privacy representative. We assist the responsible organization as appropriate and address requests relating to our own processing directly.

17. Public Content and Third-Party Websites

Where a public forum, review or comment feature is available, information you post may be visible to other people. Avoid posting confidential information or someone else’s personal information without authority.

We obtain appropriate permission before publishing identifiable testimonials or case studies for our own promotion. Uploading private project materials does not automatically authorize us to publish them.

Links to independently operated websites and platforms are governed by those services’ own privacy notices. This does not remove our responsibility for providers processing information on our behalf.

18. Children’s Privacy

Project Tray is intended for business use and is not directed at children. We do not knowingly collect children’s personal information through our own website without appropriate consent.

Contact us if you believe information has been provided without appropriate consent so that we can investigate and take appropriate action. Customer organizations remain responsible for the lawful handling of any children’s information they enter into their accounts.

19. Changes to This Privacy Policy

We may update this policy when our services, technology, privacy practices or legal requirements change. The Last Updated date will reflect publication of the revised version.

For material changes, we provide additional notice where appropriate and obtain new consent where required before using information for a new purpose. Updating this page does not, by itself, authorize an incompatible use of previously collected information.

20. Privacy Contact and Complaints

For privacy questions, access or correction requests, consent withdrawals or complaints, contact:

Project Tray – Privacy Inquiries
1146 Westport Crescent, Unit 1
Mississauga, Ontario L5T 1G1
Canada

Telephone: 1-866-289-7051
Email: info@projecttray.com
Website: www.projecttray.com

Please mark your message “Privacy Request” and include enough information for us to understand it without sending unnecessary sensitive details.

We will review and investigate privacy complaints and communicate our response. You may also raise a concern with the Office of the Privacy Commissioner of Canada or another applicable privacy regulator. You do not need our permission to contact a regulator.