Application Technologies and Cookies Policy

Canadian English Version

This Policy explains the use of technical tools within the OPHIR mobile application and, where applicable, on OPHIR websites. It supplements the OPHIR Privacy Policy and Terms of Service.

Service Operator

OPHIR is operated by:

Soavinjato Andrianarisoa
1203 Rue Normont
Laval, Québec H7G 3H3
Canada

General inquiries: contact@joinophir.app
Privacy inquiries: privacy@joinophir.app
Support: support@joinophir.app

Plain-Language Overview

The OPHIR mobile application does not use browser cookies in the same manner as a conventional website. To operate securely, the application may use authentication tokens, secure local storage, installation identifiers, operating-system permissions, security logs, and diagnostic tools.

As of the effective date of this Policy:

  • OPHIR does not use advertising SDKs;
  • OPHIR does not track users across applications and websites operated by other companies;
  • OPHIR does not use connected financial-account data for advertising;
  • OPHIR does not sell personal information;
  • Plaid, Apple, Google, and financial institutions may use their own technologies within their interfaces;
  • optional analytics or tracking technologies will not be enabled without the notice and consent required by applicable law.
EnvironmentMain technologiesPurpose
Mobile applicationTokens, secure storage, installation identifier, system permissions, and diagnosticsSign-in, security, preferences, stability, and requested features
OPHIR websiteStrictly necessary cookies, session tokens, and local storageWebsite operation, security, and remembering user choices
Plaid and financial institutionsTechnologies controlled by the applicable providerAuthentication, consent, and secure account connection
Apple and GoogleSystem and platform technologiesApplication distribution, subscriptions, notifications, and security

1. Scope

This Policy applies to:

  • the OPHIR mobile application;
  • OPHIR websites and web pages;
  • account registration, sign-in, and account-management interfaces;
  • financial-account connections;
  • notifications, support, and related digital functionality,

collectively, the “Service.”

This Policy governs technologies used by OPHIR or by providers acting on its behalf. It does not govern independent processing by Plaid, Apple, Google, financial institutions, or other third-party services.

2. Mobile Application Technologies

2.1 Authentication and Session Tokens

After you sign in, the application may receive a secure token that allows it to authenticate your session without transmitting your password with every request.

A token may be terminated:

  • when you sign out;
  • when it expires;
  • when security information changes;
  • when suspicious activity is detected;
  • when the account is deleted;
  • when OPHIR revokes the token.

Tokens are not intended for advertising tracking.

2.2 Secure Local Storage

The application may store limited information on the device to:

  • preserve language and interface preferences;
  • support secure authentication;
  • remember selected functionality;
  • maintain temporary application state;
  • prevent the loss of unsaved actions.

Sensitive information should be stored using available secure operating-system mechanisms. OPHIR does not store your online-banking password in the application's local storage.

2.3 Installation Identifier

OPHIR may create an internal identifier for a particular installation of the application in order to:

  • associate a secure session with the installation;
  • deliver service notifications;
  • diagnose errors;
  • detect misuse;
  • prevent duplicate technical events.

An installation identifier is not a financial-account number and is not used for cross-service advertising.

2.4 System Permissions

The application may request an operating-system permission only when it is required for a selected feature.

Depending upon the functionality, permissions may include:

  • notifications;
  • biometric unlock;
  • network access;
  • other permissions explained at the time of the request.

You may change permissions through iOS or Android settings. Withdrawing a permission may disable the dependent feature, but should not affect unrelated functionality.

2.5 Logs and Diagnostics

OPHIR may collect limited technical information, including:

  • application and operating-system version;
  • device type and model;
  • the time and nature of a crash;
  • network status;
  • technical error codes;
  • the sequence of technical events leading to an error;
  • information about suspicious activity.

This information is used for security, error correction, and service stability. OPHIR seeks to avoid including the contents of financial transactions, notes, or user messages in diagnostic logs.

3. SDKs and Embedded Components

An SDK is a software component that helps implement a particular application function. OPHIR may use SDKs for:

  • Plaid connectivity;
  • authentication;
  • notifications;
  • subscription validation;
  • crash diagnostics;
  • security.

Before implementing an SDK, OPHIR should assess:

  • what information it collects;
  • the purposes for collection;
  • whether the provider acts only for OPHIR or also for its own purposes;
  • where the information is processed;
  • whether collection can be limited;
  • whether user consent is required;
  • whether the SDK is consistent with App Store and Google Play disclosures.

As of the effective date of this Policy, OPHIR does not use an SDK for cross-service behavioural advertising.

4. Website and Cookies

4.1 Application to the Website

Browser cookies apply primarily to OPHIR websites and web pages, rather than to the core operation of the mobile application.

An OPHIR website may use strictly necessary cookies or local storage to:

  • maintain a secure session;
  • protect a form or request;
  • preserve a language selection;
  • remember a privacy choice;
  • prevent misuse;
  • ensure that a page functions properly.

4.2 Optional Cookies

If OPHIR introduces optional analytics, advertising, or profiling on its own website, the relevant technologies will not be activated until the required information has been provided and consent has been obtained, unless applicable law permits otherwise.

Users should be able to:

  • accept optional categories;
  • reject them;
  • change their choice later;
  • continue using core functionality after rejecting optional technologies.

4.3 Browser Controls

A browser may allow you to view, block, and delete cookies, clear local storage, or restrict third-party tracking.

Blocking strictly necessary technologies may prevent a secure web page or sign-in process from functioning.

5. Plaid and Financial Account Connections

When you connect an account, the application may open Plaid Link or a secure interface provided by your financial institution.

Plaid and the financial institution may use their own tokens, cookies, local storage, logs, and security mechanisms to:

  • authenticate you;
  • display institutions and accounts;
  • record consent;
  • secure the connection;
  • prevent fraud;
  • support reauthentication;
  • resolve connection errors.

OPHIR does not control every technology used by Plaid or a financial institution. Their independent processing is governed by their own policies.

Plaid's End User Privacy Policy:
https://plaid.com/legal/#end-user-privacy-policy

Plaid Portal, where available:
https://my.plaid.com

Unless OPHIR expressly states otherwise, the application does not receive or store your online-banking password.

6. Apple, Google, and System Services

Apple and Google may process technical information in connection with:

  • application distribution;
  • subscriptions and receipts;
  • system notifications;
  • platform security;
  • diagnostics;
  • device settings.

You may manage certain settings through iOS or Android settings, your Apple ID, your Google account, and the applicable application-store interface.

OPHIR does not request permission under Apple's App Tracking Transparency framework if the application does not track user activity across applications and websites operated by other companies for advertising or disclosure to a data broker.

If such tracking is introduced in the future, OPHIR must first:

  • update this Policy and the Privacy Policy;
  • clearly explain the purpose;
  • obtain Apple's system permission where required;
  • provide the applicable Android controls;
  • update App Store and Google Play disclosures.

7. Analytics

OPHIR may process technical information necessary to protect the Service and maintain its stability.

Optional product analytics that allow OPHIR to understand the use of screens and features should be:

  • separated from strictly necessary diagnostics;
  • limited to defined purposes;
  • configured to minimize collection;
  • disclosed to users;
  • activated on the basis of the appropriate choice or consent, where required.

Analytics information is not used to sell a financial profile or for third-party behavioural advertising.

8. Advertising and Tracking

As of the effective date of this Policy:

  • OPHIR does not display behavioural advertising;
  • OPHIR does not use advertising identifiers to create a cross-service profile;
  • OPHIR does not disclose connected financial-account data to advertising networks;
  • OPHIR does not sell or rent personal information.

Ordinary service communications about subscriptions, security, new features, or OPHIR operations are not third-party behavioural advertising.

9. Consent and Settings

Strictly necessary technologies may be used without separate consent where they are required for a requested feature, security, or legal compliance.

For an optional technology, OPHIR provides information about:

  • the information collected;
  • the purpose;
  • the provider or categories of recipients;
  • the consequences of consenting or declining;
  • the method for withdrawing the choice.

Where required by applicable law, consent must be clear, free, informed, specific, temporary, granular, understandable, and requested separately from other written information.

You may withdraw consent through an available OPHIR interface or by contacting privacy@joinophir.app. Withdrawal does not affect the lawfulness of prior processing or override mandatory retention requirements.

10. Retention

Technical information is retained only for as long as reasonably necessary for the relevant purpose.

CategoryGeneral retention principle
Session tokenUntil sign-out, expiration, revocation, or replacement
Application preferencesUntil changed, reset, or the application or account is deleted
Installation identifierWhile the installation remains active or the identifier is needed for security and diagnostics
Security logIn accordance with the retention schedule and investigation requirements
Diagnostic informationFor a limited period necessary for analysis and correction
Consent choiceAs long as necessary to apply and demonstrate the choice

Deleting the application may remove local information, but does not necessarily delete server-side information or information independently controlled by a third-party provider.

11. Security

Depending upon the technology, OPHIR may use:

  • encryption in transit;
  • secure operating-system storage;
  • limited token lifetimes;
  • access controls;
  • secret-management practices;
  • request-integrity verification;
  • monitoring of suspicious activity;
  • vulnerability management;
  • incident-response procedures.

No system can guarantee absolute security. You are responsible for protecting your device, passcode, account, and email.

12. User Rights

If technical information directly or indirectly identifies a user, it may constitute personal information.

Depending upon applicable law, you may:

  • request access;
  • request correction;
  • withdraw consent;
  • request deletion in circumstances provided by law;
  • obtain information about purposes, categories, and recipients;
  • submit a complaint.

Requests may be sent to privacy@joinophir.app. To protect the account, OPHIR may request reasonable identity verification.

13. Changes to this Policy

OPHIR may update this Policy when the application, website, providers, technologies, or law changes.

The updated version will identify a new date. Before activating a materially new optional technology, OPHIR will provide notice and obtain new consent where required.

14. Related Documents

This Policy supplements:

15. Language

This Canadian English version serves as OPHIR's administrative master version. A French version is provided for users in Québec and wherever required by applicable language law. Other translations may also be provided for convenience.

Nothing in any language version limits rights that cannot be waived. If different versions are inconsistent, mandatory law and the version that must legally prevail will govern.

16. Contact Information

For questions about application technologies, SDKs, cookies, or personal information:

Soavinjato Andrianarisoa
OPHIR Privacy Officer
1203 Rue Normont
Laval, Québec H7G 3H3
Canada
privacy@joinophir.app

General and legal inquiries: contact@joinophir.app
Support: support@joinophir.app
General information: hello@joinophir.app

When contacting us, do not send online-banking passwords, complete payment-card numbers, one-time authentication codes, or other secret credentials.