Your data is yours.
We built Aamey privacy-first from the ground up. Here is exactly how we protect your biometric data, payments, and personal information.
Biometric data (BIPA-compliant)
- โFace geometry processed on-device where possible.
- โZero Data Retention (ZDR): biometric features used for rendering, not stored by default.
- โExplicit consent required before any biometric storage.
- โ24-hour deletion SLA upon request โ data wiped from all systems.
- โRevoke consent at any time in Settings.
Payment security (PCI SAQ-A)
- โAll payment card data handled exclusively by Stripe.
- โAamey is PCI SAQ-A compliant โ we never see or store raw card numbers.
- โStripe's infrastructure is PCI DSS Level 1 certified.
- โRefunds and disputes handled through Stripe's secure dashboard.
Privacy (PIPEDA + Quebec Law 25)
- โPersonal data processed under Canadian privacy law (PIPEDA).
- โQuebec Law 25 compliant โ privacy impact assessments completed.
- โData residency: personal data stored in Canada by default.
- โNo data sold or licensed to third parties.
- โRight to access, correct, and erase your data at any time.
Infrastructure security
- โAll data encrypted in transit (TLS 1.3) and at rest (AES-256).
- โPrivate self-hosted infrastructure โ not shared cloud tenants.
- โAutomated vulnerability scanning and dependency audits.
- โAccess controls: role-based, least-privilege, audit-logged.
Sub-processors
Aamey uses the following trusted sub-processors to deliver our service. All sub-processors are bound by data processing agreements (DPAs).
Anthropic
AI language model (beauty chat, recommendations)
USA
Stripe
Payment processing and merchant of record
USA
MinIO
Object storage (images, media, exports)
Canada (self-hosted)
Redis
Session caching and real-time features
Canada (self-hosted)
PostgreSQL
Primary application database
Canada (self-hosted)
Resend
Transactional email delivery
USA
Certifications
PCI SAQ-A
ActivePayment card data handled by Stripe only.
BIPA Compliance
ActiveIllinois Biometric Information Privacy Act.
PIPEDA
ActiveCanadian federal privacy law.
Quebec Law 25
ActiveQuebec provincial privacy law.
SOC 2 Type II
PendingAudit in progress โ estimated 2026.
ISO 27001
PendingInformation security management standard.
Security questions?
Contact our privacy and security team at [email protected]
Looking to report a vulnerability? View our responsible disclosure policy
Joorus Inc. ยท 250 Consumers Road, Suite 719, Toronto, ON M2J 4V6 ยท GST 712534965RT0001