NOVUS / RESTAURANT

Novus Stream Solutions

Privacy notice

Effective/version: August 28, 2026.

Novus Stream Solutions is a sole proprietorship trading as Novus Stream Solutions in London, Ontario, Canada and is the operator responsible for this public market-data service and optional authenticated restaurant workspace. We handle personal information in line with PIPEDA and other applicable privacy law.

Public browsing

Public market pages return aggregated provider observations, provenance, freshness, and source-health information. They do not query tenant purchases, uploaded rows, account details, session data, or raw provider payloads. Server logs and security infrastructure may process IP address, request metadata, user agent, and timestamps for delivery, abuse prevention, and incident response.

Accounts and workspace data

The free advanced beta processes account identity, hashed authentication credentials, sessions, organization membership, legal acceptance, imports, normalized restaurant records, analyses, actions, immutable report snapshots, and organization-specific supplier-match review decisions to provide the requested workspace and enforce tenant isolation. Match decisions record the reviewing administrator and evidence available at review time; they are not shared across organizations or used to train a cross-tenant model. Do not upload payment-card data, government identifiers, health data, children's data, secrets, or unnecessary personal information.

Purposes and lawful grounds

We process account and workspace information to provide the service you request; security and limited operational logs for service integrity and abuse prevention; records where required by law; and optional Analytics or Marketing data only under the consent rules described below. The product does not make solely automated decisions that produce legal or similarly significant effects.

Analytics and advertising

Google Analytics 4 is not requested until Analytics consent is explicitly granted. Eligible Adsterra banner and native advertising follows separate Marketing consent and regional rules. EEA, UK, Switzerland, and unknown regions require opt-in; a saved refusal or Global Privacy Control signal denies advertising everywhere. Ads are excluded from authentication, workspace, admin, legal, and error routes. Novus does not sell personal information for money. Ad delivery may be treated as targeted advertising or sharing in some jurisdictions; Marketing refusal and Global Privacy Control prevent Novus from making the ad request.

Sources, recipients, and transfers

Official data providers supply public observations under their own terms and licences. Better Auth supports account security; Turso stores application data; Vercel hosts the service; Google and Adsterra are optional recipients only when the applicable consent and route rules permit loading. Each provider may process data in other countries under its own contractual and legal safeguards.

Retention and security

Daily, dekadal, and fortnightly raw market observations are retained for up to 24 months; longer-lived monthly or annual series and compact aggregates may be kept for historical comparability and provenance. Account and tenant records, including saved report snapshots and supplier-match decisions, remain until deletion, an organization instruction, or a documented legal/security hold applies. Deleting an organization cascades its snapshots and match decisions. Sessions and access tokens can be revoked, passwords are hashed, and tenant records are server-isolated.

Choices and rights

Use Cookie Settings to grant or withdraw optional consent. Authenticated users can use the Privacy Center for access, correction, export, deletion, restriction, or objection requests. Applicable exceptions, identity verification, and lawful extensions may apply. Contact support@novusstreamsolutions.com. If a Canadian privacy concern is not resolved, you may contact the Office of the Privacy Commissioner of Canada; other local supervisory rights remain available where applicable.

Safeguards and incidents

We use access controls, server-side tenant scoping, secure production session cookies, rate limiting, encrypted transport, private-cache controls, and restricted administrator routes. No Internet system is completely secure. We assess suspected incidents, keep required breach records, and notify affected individuals and regulators when applicable thresholds are met.

Limitations and changes

The service is intended for adults and business users, not children. Material notice changes use a new version and require renewed acknowledgement where appropriate. The effective date changes when this notice is materially updated.