Legal & Compliance

Privacy Policy

Effective date: January 1, 2026  ·  Last updated: June 1, 2026

Our commitment to your data

MycoFarm Inc. ("MycoFarm", "we", "our") operates a precision mushroom cultivation platform. This Privacy Policy explains what information we collect, how we use it, and the rights you have over it when you use our software, website (mycofarm.io), or any related services (collectively, the "Platform").

We built MycoFarm to run on-site, inside your facility. This architecture means that the vast majority of your operational data — sensor readings, grow logs, contamination events, and yield records — never leaves your local network unless you explicitly configure data-sharing features. This policy covers both our cloud services and the data handling practices of our on-premise software.

On-site first

Grow data stays inside your facility by default. No sensor data is transmitted to our servers without your explicit configuration.

Minimal collection

We only collect what's necessary to provide and improve our services. We do not sell personal data, ever.

Transparent by design

Every data category we process is documented here with a clear legal basis and purpose. No hidden flows.

Your rights matter

We honour PIPEDA and GDPR rights — access, correction, deletion, portability — with a simple request process.

What information we process

We collect data in three contexts: information you provide to us directly, information generated by your use of the Platform, and technical information necessary for the software to function.

Category Examples Legal basis Cloud?
Account data Name, work email, organization, role Contract Yes
Billing data Invoice address, payment method (tokenized via Stripe) Contract Yes
Grow room data Sensor readings, yield logs, contamination events, substrate records Contract / Legitimate interest Optional
Usage data Feature interactions, session duration, alert click-throughs Legitimate interest Yes
Device & log data Browser type, IP address, error logs, crash reports Legitimate interest Yes
Support data Diagnostic exports you attach to support tickets Consent Yes

We do not collect data from minors and our services are not directed at individuals under 18 years of age.

Why we process your information

We use the information we collect for the following purposes, each tied to a legal basis under PIPEDA and, where applicable, GDPR Article 6:

  • 01
    Delivering the PlatformProvisioning your account, running the software, processing sensor data you have opted to sync, generating alerts, and maintaining your HACCP logs. Legal basis: performance of contract.
  • 02
    Product improvementAggregated and anonymized usage patterns help us prioritize features, fix bugs, and improve model accuracy for contamination detection and yield forecasting. Legal basis: legitimate interest.
  • 03
    Customer supportDiagnosing issues you report, including reviewing logs or diagnostic exports you share with us during a support session. Legal basis: contract / consent.
  • 04
    Security & fraud preventionDetecting unauthorized access attempts, abuse of our API, and protecting the integrity of our systems and your data. Legal basis: legitimate interest / legal obligation.
  • 05
    Legal & compliance obligationsComplying with applicable laws, responding to lawful requests from regulators, and maintaining records required under applicable food safety standards. Legal basis: legal obligation.
  • 06
    Marketing communicationsSending product updates, cultivation guides, and occasional announcements — only where you have opted in. You can unsubscribe at any time. Legal basis: consent (CASL/GDPR opt-in).

Data that never leaves your facility

MycoFarm is architected as an on-premise platform. When you deploy the MycoFarm Engine on your local network, all grow room data — including sensor telemetry, substrate logs, spawn run records, contamination events, and harvest weights — is processed and stored exclusively on your infrastructure.

Default-private: No grow room data is transmitted to MycoFarm servers unless you explicitly enable Cloud Sync or a Remote Monitoring subscription. When these features are off, we have no access to your operational data.

If you activate Cloud Sync, data is encrypted in transit using TLS 1.3 and stored at rest using AES-256 encryption in our Canadian-hosted infrastructure (AWS ca-central-1). You retain full ownership of your data and can disable sync or request deletion at any time.

The software periodically contacts our licence verification server to validate your subscription. This check transmits only your licence key, software version, and a non-reversible installation identifier — never any grow room data.

Who we share data with

We do not sell, rent, or trade personal data. We share data only in the limited circumstances described below:

Recipient Purpose Data transferred
Stripe Inc. Payment processing Billing address, payment token
AWS (ca-central-1) Cloud infrastructure (if Cloud Sync enabled) Encrypted grow data you have opted to sync
Postmark Transactional email (alerts, account notices) Email address, alert content
Sentry Error monitoring Anonymized crash reports, stack traces
Authorities Legal obligations (court orders, regulatory requests) Minimum data required by applicable law

All sub-processors listed above are bound by data processing agreements consistent with PIPEDA requirements and, where applicable, GDPR Standard Contractual Clauses.

How long we keep data

We retain data only as long as necessary for the purpose for which it was collected, subject to legal requirements. For on-premise deployments, data retention is entirely under your control — we do not have access to it.

  • Account dataRetained for the duration of your subscription plus 12 months, unless you request earlier deletion. Required financial records are kept for 7 years per Canadian tax law.
  • Cloud Sync grow dataRetained according to your subscription tier (default: 24 months rolling window). You can purge all synced data from your account dashboard at any time.
  • Usage & log dataAnonymized usage data is retained for up to 36 months for product analytics. Raw IP logs are purged after 90 days.
  • Support dataDiagnostic exports and support tickets are deleted 12 months after ticket closure, unless you request earlier removal.

How we protect your data

We apply industry-standard technical and organizational measures to protect data we hold. Our cloud infrastructure is designed with security-first principles, and our on-premise software is engineered to minimize your attack surface.

Encryption at rest & in transit

All data stored in our cloud is encrypted with AES-256. All connections use TLS 1.3 with certificate pinning for the mobile app.

Access controls

Role-based access controls, SSO support, MFA enforcement, and least-privilege service accounts throughout our internal infrastructure.

Vulnerability management

We conduct regular penetration tests, run automated dependency scanning, and maintain a responsible disclosure program at security@mycofarm.io.

Breach notification

In the event of a breach affecting your data, we will notify you within 72 hours of becoming aware, consistent with PIPEDA and applicable breach reporting requirements.

No method of transmission or storage is completely secure. If you discover a potential security issue, please contact us immediately at security@mycofarm.io.

Rights over your personal data

Depending on where you are located, you may have the following rights with respect to personal data we hold about you. We honour these rights for all users regardless of jurisdiction.

  • 01
    AccessRequest a copy of the personal data we hold about you, including what categories of data, for what purposes, and with whom it has been shared.
  • 02
    CorrectionAsk us to correct inaccurate or incomplete personal data. Most account data can be updated directly in your dashboard.
  • 03
    DeletionRequest erasure of your personal data. We will fulfill deletion requests within 30 days, subject to legal retention obligations.
  • 04
    PortabilityReceive your data in a machine-readable format (JSON or CSV) for transfer to another service.
  • 05
    Objection & restrictionObject to processing based on legitimate interest, or request that we restrict processing while a complaint is under review.
  • 06
    Withdraw consentWhere processing is based on consent (e.g., marketing emails, Cloud Sync), you may withdraw consent at any time without affecting prior processing.

To exercise any right, email privacy@mycofarm.io from your registered address. We will respond within 30 days. You also have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC) or, where applicable, your local data protection authority.

Cookies and tracking

Our website (mycofarm.io) uses a minimal set of cookies. We do not use advertising cookies or participate in cross-site tracking networks.

Cookie Type Purpose Duration
mf_session Required Maintains your authenticated session Session
mf_lang Functional Stores your language preference (EN / FR) 1 year
mf_csrf Required CSRF protection token Session
_posthog Analytics Anonymized product analytics (PostHog, self-hosted) 1 year

You can disable non-essential cookies via the cookie banner on your first visit, or at any time from your account preferences. Disabling analytics cookies does not affect Platform functionality.

Updates to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Platform features. When we make material changes, we will notify you by email to your registered address and post a notice in the Platform dashboard at least 14 days before the changes take effect.

The effective date at the top of this page indicates when the current version was last updated. Continued use of the Platform after the effective date constitutes acceptance of the updated Policy. If you disagree with material changes, you may cancel your subscription before the effective date without penalty.

Questions about your privacy

If you have any questions about this Privacy Policy, want to exercise your rights, or have a concern about how we handle your data, please contact our Privacy Office. We aim to respond to all inquiries within 5 business days.

Privacy Office — MycoFarm Inc.

4000 rue Saint-Ambroise, Suite 210, Montréal, QC H4C 2C7 · privacy@mycofarm.io

Email Privacy Office