PRIVACY POLICY

Your information should have a defined job.

CannaTally separates minimal public-Website acquisition information from signed-in application records and limits collection to purposes that can be explained.

PUBLIC WEBSITE

The public Website can use limited technical and first-touch information needed to operate the site, understand acquisition and preserve a referral into the CannaTally application. The intended acquisition record is deliberately small: a random visitor identifier, first-seen time, landing path, referrer host and campaign parameters when present.

CROSS-DOMAIN HANDOFF

CannaTally.com and CannaTally.me are separate domains. A short-lived opaque handoff reference can connect a Website visit to a later account event without placing an email address, cannabis history, medical information or other sensitive account data in the URL.

SUPPORT REQUESTS

When you contact CannaTally, the Website collects the contact and request details you submit so a tracked support case can be created and staff can respond. Do not include passwords, sign-in codes, full payment-card numbers or unnecessary medical information in a support request.

SIGNED-IN APPLICATION DATA

Account details, products, purchases, journal entries, allotment records, scans and settings belong to the signed-in application experience. They are not Website acquisition analytics and should not be copied into public Website telemetry.

WHY INFORMATION IS USED

Information is used to operate and secure CannaTally, provide requested features and support, connect acquisition steps when appropriate, prevent abuse, troubleshoot problems and meet legal obligations. We do not treat cannabis history as an advertising profile.

DATA MINIMIZATION

CannaTally’s Website acquisition design does not require cannabis usage, inventory, allotment history, product history, medical conditions, precise location, device fingerprinting or session replay. Sensitive information should not be collected merely because it might be useful later.

SERVICE PROVIDERS

CannaTally can use infrastructure and communications providers to perform specific services on its behalf. Access should be limited to what the provider needs for that service. Purelymail can provide support-mailbox and email transport functions; the application support case, not an email inbox, is the authoritative support record.

SECURITY & ACCESS

Administrative access does not automatically justify access to sensitive customer information. Technical and organizational controls should limit access according to role and need, while secrets used for Website-to-application integration remain server-side.

YOUR CHOICES

Where the applicable product controls are available, customers can review or correct account information and use supported account controls for export or deletion. Privacy or data questions can be submitted through Contact CannaTally.

RETENTION & DELETION

Information should be retained only for as long as needed for the documented purpose, security, support, legal obligations or legitimate operational requirements, then deleted or de-identified according to the applicable retention process. Different records can require different retention periods.

HEALTH-ADJACENT INFORMATION

Cannabis records can be sensitive. CannaTally designs privacy and incident-response controls with that sensitivity in mind. Whether a particular privacy or breach-notification law applies depends on the facts and applicable law; this Policy does not claim that sensitive information falls outside those protections.

Have a privacy or data question?

Use Contact CannaTally and choose Privacy / data so the request can be routed as a tracked support case.