CASI IT Solutions Inc.
Services Pricing About Contact Sign In

Legal

Privacy Policy

Last updated: October 4, 2026

CASI IT Solutions Inc. ("CASI," "we," "us," or "our") repairs computers, phones and other electronics, and provides business software that repair shops and other businesses use to run their work: repair tracking, invoicing and estimates, appointment booking, and a messaging inbox for conversations with their own customers across Facebook Messenger, Instagram, website chat and email. This policy explains what information we collect, why, who we share it with, and what rights you have over it.

This policy is written to meet Canada's federal private-sector privacy law (PIPEDA) and Alberta's PIPA.

1. Who's responsible for your information

CASI IT Solutions Inc. is accountable for the personal information described in this policy. Questions, requests, or concerns about your information can be directed to our Privacy Officer at hello@casi-it.com.

When a business uses our software to serve its own customers (for example, a repair shop tracking your vehicle's repair, or a business replying to your Facebook message), that business decides what information it collects about you and is responsible for it. We handle that information on the business's behalf, only to provide our software to them, and protect it as this policy describes.

2. What we collect, and why

InformationWhy we collect it
Name, email, phone number, address and other contact details you give us or a business using our software To respond to inquiries, book appointments, carry out repairs, send invoices and estimates, and manage your account
Account credentials (email or username, password, two-factor authentication setup) To let you sign in securely
Device or vehicle details and repair history To diagnose, quote, and carry out the work you've asked for
Invoices, estimates and payment records (not card numbers — see section 4) To bill for work and keep accurate business records
Messages sent to a business through our messaging inbox (Facebook Messenger, Instagram, website chat, our contact form), and the sender's name and profile picture as provided by Meta To deliver those messages to the business being messaged, and to let that business reply
Email subject, sender, a short body preview, and file attachments — only from the one folder a business chooses in a mailbox it connects to us To import vendor invoices sent to that folder automatically, so the business doesn't have to upload them by hand
Basic technical data (IP address, browser type, sign-in times) Security, fraud prevention, and keeping the sign-in system working correctly

We collect only what's needed for the purpose it's collected for, and we tell you that purpose at or before collection — for example, on the form where you provide the information.

3. Information from Facebook and Instagram

A business can connect its Facebook Page and linked Instagram professional account to our messaging inbox. When it does, we request these Meta permissions: pages_messaging, pages_show_list, pages_manage_metadata, instagram_basic and instagram_manage_messages. We use them only to:

  • show the business which Pages and Instagram accounts it can connect;
  • receive messages people send to that Page or Instagram account, along with the sender's name, profile picture and (on Instagram) username;
  • send the business's replies back to those people.

We store the connected Page or account's name and ID, an access token (encrypted), and the conversations themselves, so the business can read and answer them. We don't use this information for advertising, we don't sell it, and we don't share it with anyone other than the business it belongs to, except as required by law. Messages pass through Meta's platform under Meta's own terms as well as this policy.

To have this information deleted, see our data deletion instructions.

4. Service providers and other third parties

We share information only with the providers we need to run our services, and only for that purpose:

  • Meta (Facebook/Instagram) — for the messaging inbox, as described in section 3.
  • Google — if a business connects its Google Calendar, we write its appointment bookings to that calendar and read its busy times so we don't offer slots it can't take. If a business connects a Gmail mailbox for vendor-invoice import, we request read-only access (Google's gmail.readonly scope) but only ever act on the one folder or label the business selects, reading each new message's subject, sender, a short body preview and attachments. Messages that arrived before the connection are never imported, and the business can disconnect at any time, which stops all access immediately. CASI IT Solutions Inc.'s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We don't use Google user data for advertising, don't sell it, and don't let people read it except where the business asks us to for support, where it's needed for security, or where the law requires it.
  • Microsoft — the same calendar and mailbox features as above, for businesses that use Outlook or Microsoft 365 instead of Google, with the same limits.
  • Intuit QuickBooks Online — if a business connects its QuickBooks Online company, we keep its customers, items, inventory quantities, invoices, estimates, payments, employees and time entries in sync between QuickBooks and our software. We never access banking or tax filing data. The business can disconnect at any time.
  • Clover — if a business takes card payments through our software, card details are entered directly into Clover's secure payment fields and go straight to Clover. We never see or store card numbers; we keep only the payment's amount, status and Clover's reference number.
  • Telnyx — sends the text messages described in section 5.
  • Email delivery and hosting providers — an email delivery service sends our emails, a cloud server provider hosts our software, and an encrypted off-site storage provider holds our backups.

We don't sell personal information to anyone, for any purpose.

Some of these providers store or process information in the United States rather than Canada. They may use it only to provide their service to us, not for their own purposes. Information held outside Canada may be accessible to courts, law enforcement or national security authorities there, under that country's laws.

5. Text messages (SMS)

If you give a business that uses our software your mobile number and agree to receive texts, we send you messages about your own appointments, repairs, estimates, invoices and service reminders. Message frequency varies with your activity. Message and data rates may apply. Reply STOP to stop receiving texts, or HELP for help.

We do not share or sell your mobile phone number or your consent to receive texts with any third party or affiliate for marketing or promotional purposes. Mobile information is shared only with our text-messaging provider, to deliver the messages you asked for.

6. How long we keep information, and how to have it deleted

We keep information for as long as it's needed for the purpose it was collected for, or as required by law (for example, financial records). Security logs are kept for one year.

  • Account holders and customers can ask us to delete their information at any time by emailing hello@casi-it.com.
  • Facebook and Instagram users can have their messaging data deleted — see our data deletion instructions.
  • Businesses can disconnect any connected account (Facebook, Google, Microsoft, QuickBooks, Clover) at any time, which stops all further access.

7. Your rights

You have the right to:

  • Ask what personal information we hold about you
  • Ask us to correct inaccurate information
  • Ask us to delete your information, subject to legal or operational limits (for example, records we're required to keep)
  • Withdraw consent for optional uses of your information, such as text messages

To exercise any of these rights, email hello@casi-it.com. We'll respond within 30 days.

If you're not satisfied with our response, you can complain to the Office of the Privacy Commissioner of Canada or, for Alberta-specific matters, the Office of the Information and Privacy Commissioner of Alberta.

8. Security

We protect your information with encrypted connections (HTTPS) to our website and software, passwords stored only as a one-way hash (Argon2) so we never see them, two-factor authentication for staff accounts, encryption of stored access tokens for connected services, encrypted backups, and access limited to the people who need it. No system is perfectly secure, but we design ours with that goal in mind, and we'll notify you and the relevant authorities as the law requires if a breach puts your information at real risk.

9. Cookies

We use only the cookies necessary to make the site work — keeping you signed in and protecting forms from forgery. We don't use advertising or analytics cookies. If that changes, we'll update this policy and ask for consent before any non-essential cookie is set.

If you use a website chat widget powered by our software, your browser stores a token in local storage (not a cookie) so your conversation stays connected if you reopen the chat. It contains nothing beyond a reference to that conversation.

10. Communications

We only send you messages related to services you've requested or an account you hold. We won't send marketing or promotional messages without your consent, in line with Canada's Anti-Spam Legislation.

11. Children's privacy

Our services are not directed at children, and we don't knowingly collect personal information from anyone under 13.

12. Changes to this policy

We may update this policy as our services change. We'll post the updated version here with a new "last updated" date.

13. Contact us

Attention: Privacy Officer

CASI IT Solutions Inc.
102 Kirpatrick Link
Leduc, AB  T9E 0W2
Canada
hello@casi-it.com
© CASI IT Solutions Inc.
Privacy Policy Terms of Service Data Deletion Staff Sign In