Privacy

Your employer owns the record. Momiji holds it for them, and does what they say with it.

Momiji is an HRIS and payroll system for Canadian employers. The company that subscribes is the custodian of its people’s information: it decides what goes in, who may see it, and how long it stays. Momiji processes that information on the employer’s instruction and for no other purpose. We do not sell it, we do not share it, and we do not use it to train anything.

Effective July 29, 2026. Momiji is operated by Greystone Strategic Partners Inc., Ontario, Canada.

What that means in practice

If you are an employee and you want to see your record, correct it, or ask why something is in it, your employer is the right place to start. They entered it and they can change it. Momiji will not hand your record to you over your employer’s head, and would not want the power to.

If you are the employer, the opposite applies: it is your data, you can read all of it, and the answers to your people’s questions are yours to give. Where the law gives an employee a right of access or correction, that right runs against you as the custodian, and Momiji’s job is to make honouring it straightforward rather than to stand in the middle of it.

Under Canadian federal privacy law, and under provincial employment standards legislation that sets what employment records must contain and how long they must be kept, that split is the normal arrangement for a payroll system. We are stating it plainly rather than leaving you to infer it.

One thing that follows from it, since it is the question every buyer asks: Momiji has no feature that lets us log in as you. There is no impersonation, no view as tenant, no support login, and no role in the system that can read another company’s records. What access we do have is set out in what we do not claim, further down, because it belongs with the honest answers rather than inside a sentence about encryption.

What we hold

Everything below is entered by your employer, or produced by Momiji from what they entered:

  • People. Name, contact details, job and department, employment dates, province of employment, pay rate, emergency contact, and whatever documents your employer chooses to keep on file.
  • Time. Punches with their timestamps, the site they were made against, and the location reading taken at that moment where the device provides one. Timesheets, approvals, and the corrections managers make.
  • Leave. Requests, balances, accruals, decisions, and who decided.
  • Expenses. Claims, receipt images, and what a model read off those images for a person to confirm.
  • Pay. Committed pay runs, statements, year-end slips, and the calculation trail behind each figure.
  • Documents. Files uploaded, files generated, and signatures with the fingerprint of the exact bytes they signed.
  • Who did what. An audit record of privileged actions, including who released a salary figure and when, though never the figure itself.

What we never hold

There is no Social Insurance Number column and no bank account, transit or institution column anywhere in the schema. They were removed early and never came back, which means Momiji holds no payment destination for anyone: net pay leaves your own bank against a printed wire sheet. A SIN is keyed in only at the moment a T4 slip is generated, appears on that slip in your own vault, and is never written to a database field.

We also hold no advertising identifier, no cross-site tracking profile, and no third-party marketing data about anyone. There is no advertising or attribution software in the product or in the app.

Where it lives

Every other company involved, and exactly what each one receives.

Momiji is not the only company that touches the system. These are all of them. If a vendor is not on this list, it does not receive your data, and if we add one this table changes before the vendor does.

SubprocessorWhat they receiveWhy
SupabaseThe application database and the files kept with it: your directory, time punches, leave, expenses, pay records, and every uploaded document, pay stub, T4 slip, receipt, avatar and signature. Sign-in itself runs here too, for both the web app and the phone.It is the database, the authentication provider, and the file store Momiji is built on.
VercelNo stored records. Requests to the web app and to this site pass through its network, and it runs the scheduled jobs behind backups, the location retention sweep, usage reporting and notifications.Hosting and the scheduler.
Cloudflare R2A complete second copy of every document in the product, refreshed nightly. Every pay stub, T4 slip, receipt and signature that exists in Momiji exists here as well. This is the broadest access on the list and we would rather say so plainly than let it sit inside a line about hosting.Supabase's own backups cover the database and exclude stored files, so a restore would otherwise leave your records and your documents disagreeing about what exists. The copy is deliberately held at a different vendor: a backup that shares a failure domain with the thing it protects is not a backup.
Cloudflare TurnstileA challenge token and the connecting address at the moment someone signs in, sets up an account, or accepts an invitation. Nothing about the account itself.The invisible CAPTCHA in front of sign-in, setup and invitation, on the web and on the phone.
AnthropicDocuments you upload during setup and receipt extraction, for the length of the request. Spreadsheets and CSV files are scanned first and any column holding a SIN, bank account, transit, institution, routing number or IBAN has its values replaced before the file leaves our servers. PDFs and photographs are sent whole, because reading them is the entire job being asked of the model.Reads uploaded documents and proposes structured data for a person to confirm. Commercial API data is not used to train models.
ResendRecipient email addresses and the wording of the notices we send: invitations, a statement is ready, a leave decision, a filing due. It also carries the sign-in mail the authentication system sends, such as a password reset. Payroll notices are written to carry no pay figures at all, so the amount stays in the vault rather than travelling through an inbox.Delivers invitations, sign-in mail, and notification email.
StripeBilling onlyThe subscriber's name, email and payment method, plus, once metered billing is switched on for a subscription, four usage quantities per period: employees, sites, provinces, and a weekly-frequency uplift. A reported meter event is a customer id and a number, nothing else. Never an employee's name, pay, or records of any kind. Card details never touch Momiji servers; they go straight to Stripe.Takes the subscription payment and bills usage above the plan's included allowance.
SentryMobile crash reportsCrash and error reports from the iOS and Android app, scrubbed on the device before they are sent. Identity is an allowlist of exactly three fields, a user id, an organization id and a role, so a crash report carries no name, email, address or network address as the person it belongs to. Screenshots, view hierarchies, session replay and captured request bodies are all off. Money-shaped strings, coordinates and URL query strings are redacted by pattern, values are redacted by field name, and console, touch and typing breadcrumbs are dropped outright.Tells us the app crashed and where, without telling us whose pay was on the screen when it did.
PostHogAnalyticsTwo separate streams, and the difference is the point. On this marketing site: anonymous pageviews, clicks and session recordings of these public pages, with query strings stripped and no identify call anywhere in the code. In the mobile app: a signed-in user's id, their organization id, their role, the names of screens they open, and the standard app and handset properties any analytics tool collects (app version, device model, operating system, language, time zone). Screen names only, never the parameters in them; no taps are recorded and no screen is replayed. No employee record content, no pay figures, no punch data, no document content, and no analytics of any kind inside the web app.Shows which parts of this site people read and which parts of the app get used.
ExpoMobile app deliveryOver-the-air updates to the app's JavaScript, and the push token your device is issued. Notification content passes through Expo's push service on its way to Apple or Google.Ships app fixes without waiting on a store review, and relays notifications.
Apple and GooglePush deliveryThe notification itself, on its way to your lock screen: a title, one short sentence, and a route into the app. Never a pay amount, a balance, a day count, or even the title of a document waiting for your signature.Their push services are the only way to reach a locked phone. A lock screen can be read by anyone standing near it, which is why the payload is written the way it is.
Microsoft 365Our inboxWhatever you choose to send to hello@mymomiji.com, and our reply.It is our email.

All of them are established providers operating under their own security and privacy terms. Momiji runs on Supabase and Vercel and keeps its document backup in Cloudflare’s eastern North America region, so the honest summary of where your records sit is North America. We do not claim Canadian data residency: no part of this stack offers it today, and our backup vendor has no Canadian jurisdiction to offer even if the database did. If residency is a requirement for you, ask us before you buy rather than after.

The mobile app

What the app on your phone can reach, and when.

The Momiji app asks for a small number of permissions and uses each one for a single, stated job. The most common worry is the honest one to answer first: it does not follow you around.

  • At the punch, once

    Location

    The app takes one reading at the moment you punch, and where the site has a geofence it compares that reading against the boundary. The reading is recorded on the punch whether the site is fenced or not, which we would rather tell you than have you assume otherwise. There are no watchers, no background location permission is requested, and nothing is read between punches. A punch made offline holds its coordinates on the device until it syncs, then they are deleted.

  • When you open the camera

    Camera and photos

    The camera scans punch and room codes and photographs receipts. Your photo library is read only for the images you pick yourself, for a receipt or a profile picture. The app has no feature that records audio, and the microphone permission is stripped out of the Android build entirely.

  • If you allow them

    Notifications

    A push token identifies your device to the notification service, and is registered against the organization you are signed in to so another tenant's notices can never reach it. Signing out removes it. If you refuse the permission, the app falls back to notices it generates on the device from your own reads, and those name the document waiting for you where a notice we send never would.

  • Handled by the operating system

    Face ID and fingerprint

    Unlock is the phone's own check. Momiji asks iOS or Android whether it was you and receives yes or no. No fingerprint, face or passcode data reaches the app, and none of it reaches our servers.

  • On the Pay screen

    Screenshots

    While the Pay screen is open, Android blocks screenshots and screen recording outright, and iOS blocks recording and mirroring. iOS offers no way to block a single still screenshot, so we do not claim one.

  • Inside the app sandbox

    What is stored on the device

    Your session, your saved logins and any queued offline punches are encrypted at rest, each under its own key held in the iOS Keychain or the Android Keystore. The read cache that lets the app work without a signal is not encrypted: it holds for 24 hours inside the app's own sandbox, protected by the operating system, and it holds only rows you were already entitled to read. Signing out deletes all of it.

  • Once per launch

    A check on the device itself

    The app asks whether the phone has been jailbroken or rooted, and reports the answer as a handful of true or false flags with the platform name. Nothing that identifies the handset, and no fingerprint of it. On a compromised device the Pay screen and document signing are withheld with a stated reason; everything else keeps working, so a rooted phone can still record a shift.

  • On your home screen

    The iOS widget

    If you add the widget, a small snapshot is written where the widget can read it: hours this week, days of vacation left, your next shift, how many documents are waiting, and for a leader a headcount and pending approvals. Never a pay amount, and never a confidential colleague. It is not encrypted, because a home screen is not a private place to begin with.

Two more things worth knowing. The app does not track you across other apps or websites, so it never asks permission to, and there is no advertising identifier anywhere in it. And when you open a document, the app mints a link that expires in five minutes and hands it to your phone’s own browser rather than rendering the file itself, so from that moment the document is in your browser’s hands and subject to whatever it does with downloads.

How long records are kept

Retention is mostly your employer’s call, and where it is not, the reason is either the law or a deliberate design decision we will name.

  • Location readings expire. Each company sets its own window, ninety days unless it changes it, and a nightly job erases the latitude, longitude and accuracy from every punch past that window. The punch itself stays, because the hours are the record; only the coordinates go.
  • Payroll records are kept, and are permanent by design. Once a pay run is committed its register cannot be edited or deleted through the product, by anyone, including your own owner account. A correction is a new reversing run that leaves both on the record. Employment and payroll records also carry statutory retention periods under federal and provincial law, and where the law requires a record to survive, the product keeps it.
  • Receipts and issued T4 slips are retained on purpose. Expense and payroll records need to outlast the person who filed them. The consequence is real and worth stating: a document filed in error cannot be deleted through the product today. If you need something removed, it is a conversation with us, not a button.
  • The audit log has no eraser. There is no update path and no delete path from the application, for any role.
  • Abandoned drafts are cleaned up. A receipt image left behind by a deleted draft line, a deleted draft report, or a capture abandoned before it was ever attached, is reclaimed weekly once it is at least forty-eight hours old and provably attached to nothing. Each deletion is written into that company’s own audit trail. An image that is still referenced, or whose age cannot be established, is kept.
  • Two things simply accumulate. An invitation that expires is marked expired rather than deleted, and the nightly document backup has no expiry on old copies. Neither is a leak, and both are records living longer than they need to, which is a different thing from a policy.

Your rights, and where to take them

If you are employed by a company that uses Momiji, ask your employer first. They are the custodian: access, correction, and questions about why something is on file are theirs to answer, and they can act on them the same day. Your own pay statements, slips and signed documents are already in your account for you to read and download whenever you want, one at a time. There is no single button that packages your whole record and none that erases it: both are requests we handle by hand today, and we would rather tell you that than imply a control that does not exist.

Anything about Momiji itself is ours to answer, and you do not need to go through your employer for it: how the system processes information, what a subprocessor in the table above receives, how a control works, or a complaint about us. Write to hello@mymomiji.com and a real person will answer. If you are running a formal security or privacy review, ask for the migration, policy or test behind any line on this page and you will get it. Where the honest answer is that something is not built, that is the answer you will get; our security page lists what we do not claim, on purpose.

If we cannot resolve something with you, the Office of the Privacy Commissioner of Canada takes complaints about organizations subject to federal privacy law.

This website, separately

The page you are reading is the marketing site, and it holds nobody’s employee records. It uses PostHog to see how it is read: pages visited, clicks, and recordings of these public pages. Visitors are anonymous, there is no sign-in and no identify call in the code, and the identifier is a random value in a cookie. Query strings are stripped before anything is sent, which matters because the Stripe session id on the checkout success page could otherwise be exchanged for a buyer’s name. Two disclosures we would rather make than leave you to find: these recordings capture text and mouse movement on the public pages, and this site does not honour Do Not Track.

None of that analytics software is in the web app at app.mymomiji.com, and it never will be. In the app a captured URL would carry an employee’s identifier and a recorded screen would be a salary leak played back frame by frame, which is why usage measurement there is built server side, inside the same tenancy rules as everything else.

Starting a subscription hands you to Stripe, which collects your name, email and payment method. We receive a confirmation and the email you used, so we can reach you to begin onboarding. Terms covers the agreement itself.

What we do not claim

Our security page ends with the gaps rather than the strengths, and this page keeps the same habit, because the fastest way to lose your trust is to have you discover one of these yourself.

  • Not everything on your phone is encrypted. The session, your saved logins and queued punches are. The 24-hour cache that lets the app work without a signal is not, and it can hold figures you have looked at, the coordinates on your own punches, and names from your directory. It sits inside the app sandbox under the operating system’s protection, which is real but is not the same as a key of ours.
  • iOS declares permissions the app does not use. Building on Expo brings default purpose strings for always-on location, motion and the microphone. The app has no code that uses any of them and never asks for them, and on Android the microphone permission is removed from the build outright. On iOS the strings still ship, which is untidy rather than harmful, and it is on the list to fix.
  • Analytics infers roughly where you are. We send PostHog no location at all, but it resolves the network address an event arrives from to an approximate city and country at its end. We do not use the result. It is derived, and we are not going to write a sentence that implies otherwise.
  • Crash reports are scrubbed by rule, not by proof. Identity is an allowlist, and money, coordinates and query strings are removed by pattern and by field name. A name quoted inside an error message would be truncated rather than caught. The breadcrumbs that would realistically carry one, console output and what you typed and tapped, are dropped entirely.
  • We hold no external audit. Momiji has no SOC 2 report and has not had an outside penetration test. Our reviews are internal, and we would rather say so than let a phrase imply otherwise.
  • We can technically read your data. There is no impersonation feature and no support login, but the keys that run the nightly backups, the retention sweep and the scheduled jobs bypass every tenancy rule by design, and the people who hold those keys are us. That is the ordinary position for hosted software and it belongs in daylight rather than in a footnote.

Changes

This page changes when the system changes, in the same release, not on an annual review cycle. The effective date at the top moves with it, and subscribing organizations are told by email when a change is material rather than editorial.

Contact

Momiji is operated by Greystone Strategic Partners Inc. of Ontario, Canada. Privacy questions, access requests about Momiji itself, and security reviews all go to hello@mymomiji.com. This policy is governed by the laws of the Province of Ontario and the federal laws of Canada that apply there.