1. Who is responsible
Our person in charge of the protection of personal information (privacy officer) is Daniel Izeti, Founder. Contact: privacy@checkedcanadian.ca, Toronto, Ontario, Canada. A mailing address is available on request at that address.
2. What we collect and why
Most of what we collect is business contact information about people acting for a company. PIPEDA treats an employee's name, title, work address, work phone, and work email as business contact information when used to communicate with them in that role, but we still protect it. Cost breakdowns and supporting documents uploaded for a Check are confidential business information; they may also contain personal information (for example, supplier contact names or payroll totals) and are handled under this policy.
See the data inventory table in section 12.
3. Consent
- Account holders: by creating an account you consent to the uses described here. Consent for optional uses (marketing email, analytics cookies, the AI assistant) is asked separately and can be withdrawn at any time.
- Buyers sending RFQs: your name, email, and message are shared with the manufacturer you chose. That is the purpose of the feature.
- Visitors: we collect only what is needed to serve the page and basic, aggregated analytics. Non-essential tracking is off until you turn it on.
- Quebec residents: consent for any secondary purpose is requested separately, in clear language, and privacy settings default to the most protective option.
- We do not sell personal information. We do not use personal information to make decisions about you by automated means alone. If that changes, we will tell you at the time (see 08-ai-assistant-policy).
4. Where your data is stored and cross-border transfers
- Primary database and file storage: Supabase, hosted in the AWS ca-central-1 region (Montreal, Canada). Uploaded Check documents stay in this region.
- Web hosting and edge delivery: Vercel. Vercel is a United States company and may process request logs and cached page content on servers outside Canada, including in the United States.
- Billing: Stripe, Inc. (United States). Stripe receives the billing contact's name, email, business address, and payment card details. We never see or store full card numbers.
- Transactional email: Resend, Inc. (United States).
- Analytics: none at present. If we add analytics we will update this policy first. See section 8.
- AI assistant (if enabled): Anthropic, PBC (United States). See 08.
Information processed outside Canada is subject to the laws of that country and may be accessible to its courts and authorities. For Quebec residents, we have assessed each transfer outside Quebec as Law 25 requires and use contractual safeguards with each provider.
5. How long we keep it
See the retention column in section 12. When a retention period ends we delete or anonymise the data. Backups roll off within 35 days after deletion.
6. Your rights
You may ask us to: access the personal information we hold about you; correct it; delete it (subject to legal retention); withdraw consent; and, for Quebec residents, receive it in a structured, commonly used format (data portability) and ask about any decision made exclusively by automated processing. Write to privacy@checkedcanadian.ca. We respond within 30 days. If you are not satisfied you may complain to the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'accès à l'information.
7. Security
Data is encrypted in transit and at rest. Check documents are accessible only to the reviewer assigned to the file and the privacy officer, through role-based access in the database. We keep audit logs of access to Check documents. We use multi-factor authentication on all administrative accounts.
8. Cookies and analytics
- Essential cookies: login session and security. No consent needed.
- Analytics: none. We do not run analytics or advertising scripts and set no non-essential cookies.
- No advertising cookies. We do not run third-party ad trackers.
- You can change your choice at any time from the "Cookie settings" link in the footer.
Quebec's Law 25 (section 8.1) requires that any technology that identifies, locates, or profiles a person be off by default and be disclosed. We follow that rule for all visitors, not only Quebec ones.
9. Breach process
If we discover a breach of security safeguards involving personal information, we will: contain it; assess whether it creates a real risk of significant harm; if so, report to the Office of the Privacy Commissioner of Canada (and the Commission d'accès à l'information for Quebec residents) and notify affected individuals as soon as feasible; notify any other organization that can reduce the harm; and record the breach in our breach register, which we keep for at least 24 months as PIPEDA requires, whether or not the breach was reportable.
10. Children
The Platform is for businesses and adults. We do not knowingly collect information from anyone under 18.
11. Changes
We will post changes here and, for material changes, email account holders at least 30 days in advance.
12. Data inventory
| Data element | Purpose | Legal basis / consent | Retention | Processor(s) |
|---|---|---|---|---|
| Account name, work email, password hash, role | Create and secure account | Consent at sign-up; necessary for the service | Life of account + 12 months | Supabase (CA) |
| Company name, address, business number, website, photos, description | Public listing | Consent; business contact information | Life of listing + 90 days (then removed from public view; archived 12 months) | Supabase (CA), Vercel (US edge cache) |
| Buyer name, email, company, RFQ message | Deliver RFQ to manufacturer | Consent when sending | 24 months from last message | Supabase (CA), email provider |
| Check submission: cost breakdown, invoices, bills of materials, supplier names | Perform the Check | Contract with manufacturer; confidential business information | 12 months after Check outcome, then deleted | Supabase (CA) only; never sent to AI or analytics |
| Check outcome record (company, product line, claim type, date, status) | Public record page | Contract; published with manufacturer's agreement | Permanent public history of status changes (valid, expired, revoked) | Supabase (CA), Vercel |
| Billing contact, invoice history | Charge fees, tax records | Contract; legal obligation | 7 years (CRA record-keeping) | Stripe (US), Supabase (CA) |
| Payment card data | Process payment | Contract | Held by Stripe only; we store last four digits and brand | Stripe (US) |
| Transactional email logs | Deliver and troubleshoot email | Necessary for service | 90 days | Email provider |
| Marketing consent record (source, date, type) | Prove CASL consent | Legal obligation | 3 years after consent withdrawn | Supabase (CA) |
| Server and access logs (IP, user agent, timestamps) | Security, abuse prevention | Legitimate need; disclosed | 30 days (Vercel), 90 days (Supabase audit logs) | Vercel (US), Supabase (CA) |
| AI assistant conversation text | Support and search help | Opt-in consent at first use | 30 days, then deleted from our side; provider retention per 08 | Anthropic (US), Supabase (CA) |
| Support emails | Answer questions | Consent when you write to us | 24 months | Email provider |
| Breach register | Legal obligation | PIPEDA s. 10.3 | 24 months minimum | Internal |