Ripn

How we protect personal information

Last updated: October 8, 2026

This page sums up the rules MN8 Technologies Inc. follows to protect the personal information it holds through Ripn, as Quebec's Act respecting the protection of personal information in the private sector requires. Our Privacy Policy explains what we collect, why, and the choices you have.

1. Who is responsible

MN8's person in charge of the protection of personal information is our Privacy Officer. The role is held by MN8's President. The Privacy Officer approved these rules and answers every question and complaint about personal information.

You can reach the Privacy Officer at team@ripn.app, or by mail at 390 Grosvenor Avenue, Westmount, Quebec H3Z 2M2, Canada, marked "Attention: Privacy Officer".

2. Who can see personal information

Access is limited to the people who need it to run Ripn, help you, keep Ripn secure or meet a legal obligation, and only to what their role needs. Anyone who works on Ripn for MN8 signs a confidentiality commitment and is trained on these rules before getting access. Our service providers can only use personal information to provide their service to us, under written contracts that require them to protect it.

3. How long we keep information, and how we destroy it

We keep personal information only for as long as we need it for the purposes in our Privacy Policy, or as long as the law requires. The periods for each kind of information are in section 12 of the Privacy Policy.

When information reaches the end of its period, or when you delete your account, we delete it from our database, our file storage and our providers' systems within 30 days, except the records section 12 of our Privacy Policy keeps for a set time, such as support messages. Backups are overwritten on their normal cycle. Information the law makes us keep, such as tax records, is kept apart and deleted when that period ends. We only anonymize information instead of deleting it when the result can no longer reasonably identify anyone.

4. Before a new project, and before information leaves Quebec

Before we start a project that involves personal information, such as a new feature that uses it or a new service provider, we assess the privacy risks and build in the protections the project needs. We do the same before we communicate personal information outside Quebec, and we only go ahead when the information will be adequately protected, including by a written agreement with the recipient.

5. Privacy by default

Ripn starts at the most private setting where the law asks for it. Nothing is sent to the AI that reads receipts until you agree. Usage analytics stay off until you turn them on in Canada, the European Economic Area, the United Kingdom and Switzerland. Ad measurement only runs if you allow it. Marketing emails are only sent if you ask for them.

6. Confidentiality incidents

If personal information is accessed, used, shared or lost without authorization, we act quickly to reduce the risk of harm and to stop it happening again. We keep a register of every incident. When an incident presents a risk of serious injury, we notify the Commission d'accès à l'information du Québec and the people affected, as the law requires, and other regulators where their laws apply.

7. Requests and complaints

To access or correct your personal information, to withdraw a consent, or to complain about how we handle your information, write to the Privacy Officer at team@ripn.app. We confirm that we received it, look into it, and answer in writing within 30 days. Using your rights is free.

If you are not satisfied with our answer, you can contact the Commission d'accès à l'information du Québec (cai.gouv.qc.ca), the Office of the Privacy Commissioner of Canada (priv.gc.ca), or the privacy regulator where you live.

8. Keeping these rules up to date

We review these rules at least once a year and whenever our activities change, and we update this page when they change.