Privacy Policy

Last updated: April 2026

1. Who We Are

HaloBands is a product of Neo-2 Consulting Limited, based in Saskatoon, Saskatchewan, Canada. We provide NFC-enabled wearable memory bands and associated digital services.

2. Information We Collect

Account information: Email address, display name, and password hash when you create an account.

Content you upload: Photos, videos, voice recordings, and text that you add to your bands. This content is stored securely in the cloud.

Payment information: Processed securely by Stripe. We do not store your credit card details on our servers.

Device information: When using NFC features, we may collect device type and NFC tag identifiers for band verification.

Usage data: We collect anonymized analytics to improve the Service, including pages visited, features used, and error reports.

3. How We Use Your Information

  • + To provide and maintain the Service
  • + To process purchases and deliver physical bands
  • + To send transactional emails (order confirmations, memory notifications)
  • + To detect and prevent fraud or abuse
  • + To improve the Service based on anonymized usage patterns

We will never sell your personal data or uploaded content to third parties. We will never use your memories for advertising or training AI models.

4. Content Privacy

Private memories are visible only to the band owner and explicitly invited contributors.

Public memories are visible to anyone who taps the NFC band or visits the web memory viewer link.

Password-protected memories require a password to view, even when tapping the band.

5. Data Storage & Security

Your content is stored on Amazon Web Services (AWS) infrastructure in the United States. All data is encrypted in transit (TLS) and at rest (AES-256).

We implement industry-standard security practices including secure authentication, rate limiting, and regular security audits.

6. Data Retention

Your content is retained for as long as your account is active. If you delete a memory, it is permanently removed from our servers within 30 days.

If you delete your account, all associated content is permanently deleted within 30 days. Memorial bands with active contributors may be retained with consent of remaining contributors.

7. Third-Party Services

  • + Stripe — Payment processing
  • + AWS — Cloud infrastructure and media storage
  • + PostHog — Anonymized product analytics (opt-out available)
  • + Sentry — Error monitoring (no personal data collected)

8. Your Rights

You have the right to:

  • + Access all data we hold about you
  • + Download a copy of your content at any time
  • + Request correction of inaccurate information
  • + Delete your account and all associated data
  • + Opt out of analytics tracking

Canadian residents have additional rights under PIPEDA. EU residents have additional rights under GDPR.

9. Children's Privacy

The Service is not directed at children under 13. Parent-child bands are managed by the parent/guardian account holder. We do not knowingly collect personal information from children under 13.

10. Changes

We may update this policy from time to time. We will notify users of significant changes via email. The “last updated” date at the top reflects the most recent revision.

11. Contact

For privacy-related inquiries, contact our Privacy Officer at privacy@halobands.com.

Neo-2 Consulting Limited
Saskatoon, Saskatchewan, Canada