Mulla Inc← Back to site

Privacy Policy

Last updated: September 10, 2026

This policy explains what personal information Mulla Inc. collects when you visit this site or create an account to access our projects, prototypes and client materials — why we collect it, who processes it on our behalf, how long we keep it, and how you can get it back or have it deleted.

The short version: we collect the minimum needed to let the right people into the right projects. We do not sell personal information, and we do not use it for advertising.

1. Who we are

Mulla Inc., operating as The Mulla Co ("we", "us", "our"), is an enterprise technology consulting firm based in Ontario, Canada. We are the organization responsible for the personal information described in this policy (the "data controller" for the purposes of European and UK data protection law).

Privacy questions, access requests and deletion requests: hello@themullaco.com.

2. What this policy covers

This policy applies to our public website and to the account-gated areas of it — sign-in, your client dashboard, presentations, shared documents, and product previews. It does not cover third-party sites we link to, or services governed by a separate signed consulting agreement with your organization; where a signed agreement addresses the handling of your organization's data, that agreement governs that data.

3. Information we collect

a. Account credentials — your email address and password

To create an account you give us an email address and a password. Authentication is operated for us by Supabase. Your password is transmitted over an encrypted connection and stored by Supabase only as a salted cryptographic hash — never as readable text.

We cannot see your password. Nobody at Mulla Inc. can read, retrieve or recover it — not even to help you. If you forget it, the only route back in is a reset link sent to your email address. For the same reason, we will never ask you for your password by email, phone or message; treat any such request as fraudulent.

We also store the timestamps Supabase records for your account: when it was created, when you last signed in, and whether your email address has been confirmed.

b. Signing in with Google

If you choose "Continue with Google" instead, Google authenticates you and sends us your email address, basic profile details (such as your name) and profile picture. We never receive your Google password. Your use of Google's service is subject to Google's own privacy policy.

If you sign in on the TIFF Browser (/tiff), we also store the diary you keep there — the films you mark as seen, with the date, rating and review — and link any rush-line counts you post to your account, so both follow you across devices. Only you can read them. Signing in there gives no access to any other part of the site.

c. Access and authorization records

Access to projects is granted individually, so we keep records of who has been granted what: your email address against the presentations you have been invited to, the products you have been granted access to, and any documents shared with you.

d. Documents we share with you

Market analyses, reports and similar files we make available to you are stored in Supabase Storage and indexed against your email address so that only you and we can retrieve them.

e. Contact form

If you send us a message through the site, we store the name, email address and message you provide, plus a salted SHA-256 hash of your IP address. We store the hash — not the IP address itself — purely to enforce rate limits and block automated spam. A copy of your message may also be emailed to us through Resend so we can reply.

f. Passcode-protected presentations

Some presentations are opened with a short numeric passcode rather than an account. In that case we do not collect your email address. We do record each unlock attempt — which presentation, whether the code was correct, and a salted hash of the IP address — to rate-limit guessing, and we set a signed cookie in your browser so you are not asked for the code again on that device. Passcodes themselves are stored only as hashes.

g. Analytics and technical data

We use Google Analytics to understand which pages are used and how the site performs. It collects, via cookies and similar technologies, information such as the pages you view, referring page, approximate location derived from your IP address, device type, browser and operating system. Our hosting provider, Vercel, also processes standard server request logs, which include IP addresses, for security and reliability.

h. What we never ask for

We do not ask for and do not want payment card numbers, government identifiers, health information or other sensitive categories of personal information through this site. Please do not send them to us through the contact form.

4. Cookies

  • Authentication cookies (essential) — set by Supabase to keep you signed in. Without these the gated areas cannot work.
  • Presentation unlock cookie (essential) — a signed cookie recording that you entered the correct passcode for a specific presentation.
  • Google Analytics cookies (analytics) — used to measure site usage. You can block these with your browser settings or a browser extension without losing access to anything.

5. Why we use your information, and our legal basis

  • To create and secure your account and let you sign in — necessary to provide the service you asked for (contractual necessity; consent under PIPEDA).
  • To decide what you may access and to show you the right presentations, documents and products — contractual necessity and our legitimate interest in protecting confidential material.
  • To reply to you when you contact us — consent, and our legitimate interest in responding to enquiries.
  • To keep the site secure — rate limiting, spam prevention, abuse investigation — our legitimate interest in protecting the service and its users.
  • To understand and improve how the site is used — our legitimate interest in improving the service; consent where required by local law.
  • To meet legal and record-keeping obligations — legal obligation.

We do not sell personal information, we do not share it with advertisers, and we do not use it to make automated decisions that produce legal or similarly significant effects about you.

6. Who we share it with

We share personal information only with service providers who process it on our behalf, under contract, for the purposes above:

  • Supabase — authentication, database and file storage.
  • Vercel — website hosting and request logging.
  • Google — optional sign-in, and analytics.
  • Resend — delivery of transactional and notification email.

We may also disclose information if we are legally required to, or where necessary to establish, exercise or defend legal claims or to protect the rights and safety of people using the service. If our business is reorganized, acquired or merged, information may transfer as part of that transaction; it would remain subject to a policy no less protective than this one.

7. Where your information is stored

Our providers operate data centres in Canada, the United States and elsewhere, so your personal information may be stored or processed outside your province or country. While it is in another jurisdiction it may be accessible to the courts, law enforcement and national security authorities of that jurisdiction. Where personal information of individuals in the European Economic Area or United Kingdom is transferred, we rely on Standard Contractual Clauses or another lawful transfer mechanism offered by the provider.

8. How long we keep it

  • Account information — for as long as your account is active, and then for up to 12 months, unless you ask us to delete it sooner.
  • Access and invitation records — while access is granted, and then for up to 24 months as a record of who was given confidential material.
  • Contact form messages — up to 24 months, so we can pick up the thread of a conversation.
  • Unlock attempt logs — a short period, typically no more than 90 days, for abuse prevention.
  • Analytics data — according to Google Analytics retention settings, typically 14 months.

9. How we protect it

  • All traffic to and from the site is encrypted in transit (HTTPS/TLS).
  • Passwords are stored only as salted hashes; nobody at Mulla Inc. can read them.
  • Database access is restricted by row-level security policies, so accounts can only read the records that belong to them.
  • Access to gated projects is granted individually and can be revoked at any time.
  • IP addresses used for rate limiting are salted and hashed rather than stored.

No system is perfectly secure, and we cannot guarantee absolute security. Please use a strong password that you do not use anywhere else, and tell us immediately at hello@themullaco.com if you believe your account has been compromised. If a breach of security safeguards creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as required by law.

10. Your rights and choices

You can, at any time:

  • Ask what we hold about you and get a copy of it.
  • Correct information that is wrong or out of date.
  • Delete your account and the personal information attached to it. Email us and we will action it, subject to anything we must keep by law.
  • Withdraw your consent to our use of your information. Note that withdrawing consent for account information means we can no longer give you access to gated projects.
  • Opt out of analytics using your browser settings or the Google Analytics opt-out add-on.

If you are in the European Economic Area or the United Kingdom, you additionally have the right to data portability, to restrict or object to certain processing, and to lodge a complaint with your local supervisory authority.

To exercise any of these, email hello@themullaco.com. We will respond within 30 days. We may need to verify your identity — usually by confirming you control the email address on the account — before we act. If you are unhappy with our response, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.

11. Children

This is a business service and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.

12. Changes to this policy

We may update this policy as the service changes. The "last updated" date at the top always reflects the current version. If we make a change that materially affects how we use information you have already given us, we will tell account holders by email before it takes effect.

13. Contact us

Mulla Inc. (The Mulla Co), Ontario, Canada — hello@themullaco.com. See also our Terms & Conditions.

© 2026 Mulla Inc. (The Mulla Co)Privacy PolicyTerms & Conditionshello@themullaco.com