SuiteScore Zoning · Permits · Verdicts
SuiteScore Check your address →
SuiteScore — Privacy

Privacy notice

This is the complete draft of our privacy notice, prepared for review by legal counsel; version 1.0 will be published here. Specific wording may change on counsel's advice.

This notice explains what personal information SuiteScore collects when you use suitescore.ca, why we collect it, where it is processed, and what rights you have over it. It is written to be read, not skimmed: every company that touches your information is named below, before you pay — not after.

On this page
  1. What we collect
  2. Why
  3. Where it's processed
  4. Cross-border disclosure
  5. Your rights and deletion
  6. Retention
  7. Versioning
  8. Contact

What we collect

We collect only what the service needs to work. There are no accounts, no passwords, and no profiles.

Information you give us:

  • The property address you enter. This is the input for your report, together with the coordinates and property records that resolve from it. When it refers to an identifiable person's home, we treat it as personal information.
  • The email address you provide for report delivery and link recovery. We store it in protected form (keyed hashes and encrypted values), not as an open column anyone can browse.
  • If you use the chat assistant (when available): the question you type, including any situation you describe in it. We treat it as personal information and protect it accordingly.
  • Optional marketing consent. A separate, clearly optional checkbox. Leaving it unticked never affects your purchase or delivery.

Payment. Payments are handled by Stripe on Stripe-hosted pages. Your card number goes directly to Stripe; we never see or store it. We receive only the transaction outcome and the records Stripe provides (amount, time, a payment reference).

Records we create:

  • Order records (what you bought, when, and the price shown to you).
  • Consent and terms-acceptance records: the exact version of the wording you accepted, a cryptographic fingerprint (SHA-256) of that wording, the time, and a protected form of your IP address. This is the evidence that a contract was formed — we keep it so we can honour the contract, answer disputes, and prove what you were shown.
  • Delivery and recovery logs keyed to a hashed form of your email address.
  • Security logs used for rate-limiting and abuse prevention. Network addresses in these logs are stored as keyed hashes, not in raw form.

Cookies. We use only functional cookies — session, consent, and security cookies set by our infrastructure — never advertising or cross-site tracking cookies. Map tiles on report pages load from a mapping provider's servers, which, like any web request, see your browser's IP address.

What we do not collect: browsing profiles, advertising identifiers, or any personal information beyond what is listed above. Your report is built from public datasets (for example, City of Calgary open data and Statistics Canada publications); we do not send your personal information to those publishers — their data is loaded into our own systems on a schedule, and your address is matched against it there.

Why

We collect and use personal information for a short list of purposes, identified at or before the time of collection:

  1. To produce and deliver your report — the address is the subject of the assessment; the email is how the report and your contract copy reach you, and how you recover your link.
  2. To answer questions you ask in the chat assistant, when that feature is available.
  3. To process payment and prevent fraud — through Stripe.
  4. To keep the service safe and reliable — rate-limiting, abuse prevention, security monitoring, and error monitoring with personal information scrubbed before error reports leave our systems.
  5. To meet legal obligations — tax and accounting records, the emailed copy of your contract required by Alberta's consumer-protection rules, and journals of consent and terms acceptance.
  6. To send occasional marketing email — only if you separately opted in. The marketing checkbox is optional, never a condition of purchase, and every email includes an unsubscribe link that works in one click.

We do not sell personal information, and we do not use it for advertising profiles.

Where it's processed

Your information is stored primarily in Canada. Specific functions are performed by the service providers below. This list is deliberately complete in advance: it includes standby and failover providers we may switch to, and one planned provider, so that nothing appears here only after the fact.

Provider What it does with your information Where
Stripe Payment processing and hosted checkout. Stripe alone sees your card details; we receive payment confirmations, never card numbers. United States
Supabase Our primary database and file storage — addresses, report records, encrypted email values. Canada (ca-central-1, Montréal)
Google Cloud
  • (a) Runs the application in Google's Canadian region (Montréal); traffic to and from the site reaches it through Google's global network edge;
  • (b) holds the encryption keys used for the deletion mechanism described below (Cloud KMS, Canadian region);
  • (c) Google Maps Static and Street View imagery — your address's coordinates are sent to Google's Maps service to produce the satellite and street-level images in your report.
Application and keys: Canada (Montréal region); network edge: Google's global network; Maps imagery: United States. Google is a US-headquartered company.
MapTiler Converts the address you type into map coordinates (geocoding) and serves map tiles; your browser connects to MapTiler directly for tiles, which discloses your device's IP address to it. Global serving infrastructure; treated as a service provider outside Canada
Anthropic The AI models that draft and review the written sections of your report; they receive report inputs derived from your address. United States
AWS (Amazon Web Services) Standby failover: if a primary AI provider is unavailable, generation runs on AWS Bedrock instead; also available in-Canada for some functions. Listed here in advance so a switch never happens outside this notice. United States and Canada (ca-central-1)
Voyage AI Text-embedding computation supporting the chat assistant, when available. Listed here in advance. United States
Sentry Error monitoring, so we can find and fix failures. Personal information other than order, property and report identifiers and the product purchased is scrubbed at the source before error reports are sent. United States / European Union
Resend Transactional email — delivering your report link and your contract copy. Your email address and the message content pass through Resend. United States
Telegram Operational alerts to our own staff about system health and report delivery; alert messages may reference order, property and report identifiers and the product purchased — never your name or your email address. Outside Canada
Cloudflare Content-delivery and security layer planned for the public-launch window. Listed here in advance of activation. Global network, headquartered in the United States

Stripe

What it does

Payment processing and hosted checkout. Stripe alone sees your card details; we receive payment confirmations, never card numbers.

Where

United States

Supabase

What it does

Our primary database and file storage — addresses, report records, encrypted email values.

Where

Canada (ca-central-1, Montréal)

Google Cloud

What it does
  • (a) Runs the application in Google's Canadian region (Montréal); traffic to and from the site reaches it through Google's global network edge;
  • (b) holds the encryption keys used for the deletion mechanism described below (Cloud KMS, Canadian region);
  • (c) Google Maps Static and Street View imagery — your address's coordinates are sent to Google's Maps service to produce the satellite and street-level images in your report.
Where

Application and keys: Canada (Montréal region); network edge: Google's global network; Maps imagery: United States. Google is a US-headquartered company.

MapTiler

What it does

Converts the address you type into map coordinates (geocoding) and serves map tiles; your browser connects to MapTiler directly for tiles, which discloses your device's IP address to it.

Where

Global serving infrastructure; treated as a service provider outside Canada

Anthropic

What it does

The AI models that draft and review the written sections of your report; they receive report inputs derived from your address.

Where

United States

AWS (Amazon Web Services)

What it does

Standby failover: if a primary AI provider is unavailable, generation runs on AWS Bedrock instead; also available in-Canada for some functions. Listed here in advance so a switch never happens outside this notice.

Where

United States and Canada (ca-central-1)

Voyage AI

What it does

Text-embedding computation supporting the chat assistant, when available. Listed here in advance.

Where

United States

Sentry

What it does

Error monitoring, so we can find and fix failures. Personal information other than order, property and report identifiers and the product purchased is scrubbed at the source before error reports are sent.

Where

United States / European Union

Resend

What it does

Transactional email — delivering your report link and your contract copy. Your email address and the message content pass through Resend.

Where

United States

Telegram

What it does

Operational alerts to our own staff about system health and report delivery; alert messages may reference order, property and report identifiers and the product purchased — never your name or your email address.

Where

Outside Canada

Cloudflare

What it does

Content-delivery and security layer planned for the public-launch window. Listed here in advance of activation.

Where

Global network, headquartered in the United States

We have data-processing agreements with providers that handle personal information on our behalf, requiring a comparable level of protection to our own (PIPEDA, Schedule 1, clause 4.1.3). Public open-data pipelines (City of Calgary, Statistics Canada, Bank of Canada) process public records about properties and the economy — they do not receive your personal information and are therefore not listed as processors.

Cross-border disclosure

Some of the providers above store or process personal information outside Canada — primarily in the United States, and in the European Union for error monitoring. Some Canada-region services are operated by US-headquartered companies, and traffic to our site passes through global network infrastructure. While information is outside Canada, it is subject to the laws of the country where it is held, and courts, law enforcement and regulators there may be able to compel access to it under those laws. That is true of any service that uses international providers; we say it plainly rather than bury it.

Our controls for this are four commitments:

  1. Consent first. Before you submit personal information on a paid flow — and before the first chat exchange, when that feature is available — you are shown a click-through step that names these providers, including failover destinations. We do not process first and explain later.
  2. This document. This page is the versioned, standing description of the data flows, the providers (including failover providers), the regions, the retention periods, and your rights. When it changes, its version changes.
  3. Data-processing agreements. Contractual data-protection terms with each provider that handles personal information on our behalf.
  4. Alberta notice. As required by Alberta's Personal Information Protection Act, section 13.1: some of our service providers are outside Canada; you may obtain written information about our policies and practices with respect to those providers by contacting us (see Contact below); and the person who can answer your questions about how those providers collect, use, disclose or store personal information on our behalf is our Privacy Officer, also named in Contact.

Your rights and deletion

Access and correction. You may ask what personal information we hold about you, how it is used, and to whom it has been disclosed, and you may ask us to correct it (Alberta PIPA sections 24–25; PIPEDA Schedule 1, Principle 9 — Individual Access). We respond within the time limits PIPA sets — normally 45 days.

Withdrawing consent. You may withdraw consent at any time, subject to legal and contractual limits; we will tell you what the practical consequences are. Withdrawing marketing consent is one click — every marketing email carries an unsubscribe link, and unsubscribing never affects a report you have bought.

Deletion — how it actually works here, stated plainly. Our purchase and audit records are append-only by design: once written, they are never silently edited. That design is what lets us prove, years later, exactly what you bought, what you were shown, and what our systems did — protection that works in your favour in a dispute as much as ours. Because of it, deletion is engineered rather than pretended, in two layers:

  • Redaction: the record is hidden from every reading path we operate — staff tools, analytics, exports — through an enforced redaction layer, and
  • Key destruction: your personal details are stored encrypted with a per-record key; on a deletion request we destroy that key, which makes the encrypted copies — including those inside backups and disaster-recovery snapshots — permanently unreadable. Alberta's PIPA expressly recognizes rendering information non-identifying as a form of disposal (section 35(2)(b)).

You can start a deletion request at /delete-my-data or by writing to us. We act on our own systems promptly. Third-party providers hold short-lived operational copies (for example, delivery queues and model-provider caches); we do not control their deletion clocks and will not pretend otherwise: provider caches expire within their published windows — on their schedule, not ours. We tell you what we destroyed, and what expires on whose clock.

Honest limits. Some records must survive a deletion request for a time: records the law requires us to keep (tax records, consent evidence), records needed for an active dispute, and records under a legal hold. Alberta PIPA expressly permits retention needed for legal or business purposes even after consent is withdrawn (section 35(3)). When the retention reason ends, the same destruction discipline applies. We will tell you, in our response, which records we must keep and why.

Complaints. Contact our Privacy Officer first (see Contact). If you are not satisfied with our response, you may complain to the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada.

Retention

We keep personal information only as long as we reasonably need it for legal or business purposes, then destroy it or render it non-identifying (Alberta PIPA section 35). Current periods:

What How long Why
Paid report and order records (the report, its inputs, its frozen assessment record, and terms-acceptance evidence) 7 years from your last interaction with the report Dispute evidence and legal limitation periods
Chat questions on the free tier (when the chat assistant is available) Deletable by you at any time; purged on a 90-day cycle by destroying their encryption keys — unless the conversation is linked to a purchased report, in which case the 7-year schedule applies Customer-controllable data
Marketing-consent records (granted and revoked events, with the exact wording you saw) 6 years from each event Canada's anti-spam law places the burden of proving consent on the sender and gives regulators three years to open proceedings; we add a safety margin
Payment and tax records As required by tax and accounting law Statutory record-keeping
Security and rate-limit logs Only as long as needed for abuse prevention; stored as keyed hashes throughout Fraud and abuse prevention

Paid report and order records (the report, its inputs, its frozen assessment record, and terms-acceptance evidence)

How long

7 years from your last interaction with the report

Why

Dispute evidence and legal limitation periods

Chat questions on the free tier (when the chat assistant is available)

How long

Deletable by you at any time; purged on a 90-day cycle by destroying their encryption keys — unless the conversation is linked to a purchased report, in which case the 7-year schedule applies

Why

Customer-controllable data

Marketing-consent records (granted and revoked events, with the exact wording you saw)

How long

6 years from each event

Why

Canada's anti-spam law places the burden of proving consent on the sender and gives regulators three years to open proceedings; we add a safety margin

Payment and tax records

How long

As required by tax and accounting law

Why

Statutory record-keeping

Security and rate-limit logs

How long

Only as long as needed for abuse prevention; stored as keyed hashes throughout

Why

Fraud and abuse prevention

When a retention period ends, destruction is a deliberate, logged operational act — never a silent background edit.

Versioning

Versioned policy

This notice is versioned, and the version is load-bearing: when you accept our terms at checkout, your consent record stores the version identifier and a SHA-256 fingerprint of the exact wording you saw — so there can never be a dispute about which text you accepted. We do not edit a published version in place: any change becomes a new version with a new effective date, and past orders keep pointing at the version they were made under. The wording behind any version you accepted can be reproduced on request.

The current version appears in the footer of every page of this site. The current text is a working draft (tos-v0-draft-2026-07-13+privacy-v0-draft-2026-07-13); version 1.0 · effective [DATE] will be published here following legal counsel review.

Contact

Privacy Officer

[COPY-TBD-COUNSEL — name or position title; PIPA s.13.1(3)(b)]

Email

[email protected] (subject line "Privacy")

Mail

[COPY-TBD-COUNSEL — mailing address, published upon incorporation]

Write to the Privacy Officer to: request access to or correction of your personal information; obtain written information about our policies and practices regarding service providers outside Canada (Alberta PIPA sections 6(3) and 13.1(3)); ask questions about how those providers collect, use, disclose or store personal information for us; or make a deletion request if you prefer email to the /delete-my-data form.

If you are not satisfied with our response, you may contact the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada.