Legal

Privacy Policy

Effective date: May 22, 2026  ·  PreBuildIQ Inc., Toronto, Ontario, Canada
Privacy Officer: info@prebuildiq.ca
This Policy covers both the PreBuildIQ marketing website (prebuildiq.ca) and the PreBuildIQ application platform.

Overview

PreBuildIQ Inc. ("PreBuildIQ", "we", "us") respects the privacy of its users and is committed to complying with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's Anti-Spam Legislation (CASL), and all other applicable Canadian privacy laws. This Privacy Policy describes the personal information we collect, how we use it, with whom we share it, how we protect it, and how you can exercise your rights in relation to it.

This Policy applies to personal information collected through our website (prebuildiq.ca), our application (app.prebuildiq.ca), and any communications you have with us. By using the Service, you agree to the collection and use of information in accordance with this Policy.

1. Information We Collect

We collect personal information in the following categories. We identify the purpose of collection at or before the time of collection, as required by PIPEDA.

1.1 Account Information. When you register, we collect your name, business email address, and company name. We use this to create and manage your account, identify you, and communicate with you about the Service. This information is required to provide the Service.

1.2 Authentication Data. Passwords are hashed using industry-standard cryptographic methods. We never store passwords in plain text. Authentication tokens are managed via our authentication provider (Supabase).

1.3 Project and Usage Data. When you use the Service, we collect: property addresses you submit for analysis; project details you enter; drawing files you upload to the Drawing Checker feature; reports and checklists generated; and records of features accessed. This data is necessary to deliver the Service and improve its accuracy. Property addresses are also used to query municipal data sources and, where enabled, geocoding providers (Mapbox).

1.4 Billing Data. Payment processing is handled by our third-party processor, Stripe. We do not store full credit card numbers or payment card data on our systems. We retain billing history (subscription tier, payment dates, invoice amounts) for legal and accounting purposes.

1.5 Technical and Log Data. Our servers automatically collect log data when you access the Service, including your IP address, browser type and version, operating system, referring URL, pages viewed, time and date of access, and session identifiers. This data is used for security monitoring, fraud prevention, debugging, and aggregate analytics. It is not used to identify you individually without your consent, except where required for security or legal purposes.

1.6 Communications. If you contact us by email or through contact forms, we retain the contents of your communication and our response in order to answer your inquiry and improve our customer support.

1.7 Cookies and Similar Technologies. See Section 10 below.

2. How We Use Your Information

We use personal information only for the purposes identified at the time of collection or as otherwise permitted by PIPEDA. Specifically:

  • Service delivery: to create and manage your account, generate reports and checklists, process drawing uploads, and provide all platform features
  • Billing and payments: to process subscriptions, issue invoices, and manage plan changes
  • Transactional communications: to send account confirmations, password resets, billing receipts, and service notifications necessary to the operation of the Service
  • Security and fraud prevention: to monitor for unauthorized access, abuse, or fraudulent activity
  • Service improvement: to analyze usage patterns, diagnose technical issues, and improve Service accuracy, coverage, and features; any analysis for improvement purposes uses anonymized or aggregated data where possible
  • Legal compliance: to comply with applicable law, respond to legal process, enforce our Terms of Service, and protect the rights and safety of PreBuildIQ and its users
  • Marketing communications: only with your express or implied consent, as described in Section 9 (CASL)

We will not sell, rent, trade, or otherwise share your personal information with third parties for their own independent marketing or commercial purposes.

3. How We Share Your Information

We do not sell or rent personal information. We share personal information only in the following circumstances:

3.1 Sub-Processors. We share personal information with third-party service providers ("sub-processors") who assist us in operating the Service, subject to contractual data protection obligations. See Section 4 for our full sub-processor list.

3.2 Legal Requirements. We may disclose personal information if required to do so by law or in good-faith belief that such disclosure is necessary to: (a) comply with a legal obligation, court order, or governmental request; (b) protect the rights, property, or safety of PreBuildIQ, its users, or the public; or (c) detect, prevent, or address fraud, security, or technical issues.

3.3 Business Transfers. If PreBuildIQ is involved in a merger, acquisition, financing, or sale of all or substantially all of its assets, personal information may be transferred as part of that transaction, subject to the acquirer agreeing to comply with this Privacy Policy or providing notice to affected users.

3.4 With Your Consent. We may share personal information with third parties when we have your express consent to do so.

3.5 Aggregated Data. We may share anonymized, aggregated, or de-identified data that does not identify any individual user with third parties for research, analytics, or industry reporting purposes.

4. Sub-Processors

The following third-party service providers process personal information on our behalf. We have entered into data processing agreements with each sub-processor requiring them to protect personal information to standards at least equivalent to those in this Policy.

ProviderPurposeData ProcessedLocation
Supabase Database, authentication, and storage Account data, project data, usage data, session tokens Canada / United States
Vercel Frontend hosting and edge compute IP addresses, request logs, session data United States (global edge)
Fly.io Backend API hosting Project data, API request logs United States (Toronto region)
Stripe Payment processing Billing data, payment card data (processed directly by Stripe; not stored by PreBuildIQ) United States
Resend Transactional email delivery Email address, email content (receipts, notifications, password resets) United States
Mapbox Address geocoding and autocomplete Property addresses submitted by users United States
Anthropic AI analysis of uploaded drawings (Drawing Checker feature) Contents of uploaded drawing files (PDFs). Under our API usage agreement, Anthropic does not use API inputs to train its models. United States
Microsoft Azure Document intelligence and OCR processing Uploaded drawing files United States / Canada

We will update this list if we add or change sub-processors. Where feasible, we will provide advance notice of material changes to sub-processors that may affect your personal information.

5. Cross-Border Transfers

PreBuildIQ is based in Canada. Some of our sub-processors are located in the United States. As a result, your personal information may be transferred to, stored in, or processed in the United States, which may have different privacy laws than Canada.

We take steps to ensure that personal information transferred to our sub-processors outside Canada is subject to comparable protections through contractual data processing agreements. By using the Service, you acknowledge and consent to the transfer of your personal information to countries outside Canada, including the United States, as described in this Policy.

If you are located in Quebec, you have additional rights under An Act respecting the protection of personal information in the private sector (Law 25). Please contact our Privacy Officer for details.

6. Data Retention

We retain personal information only as long as necessary for the purposes identified in this Policy, subject to legal retention requirements.

  • Active account data: retained for the duration of your account and subscription
  • Project and report data: retained for the duration of your account and for up to ninety (90) days after account closure
  • Billing and financial records: retained for seven (7) years as required by the Income Tax Act (Canada)
  • Log and technical data: retained for up to twelve (12) months, after which it is aggregated or deleted
  • Deleted account data: permanently deleted within thirty (30) days of account deletion, except where legal retention obligations apply
  • Uploaded drawings: retained for the duration of your account; deleted within thirty (30) days of account closure

Anonymized, aggregated data that does not identify any individual may be retained indefinitely for product improvement and analytics purposes.

7. Security

We implement appropriate technical and organizational measures to protect personal information against unauthorized access, disclosure, alteration, or destruction. Our security measures include:

  • TLS encryption for all data in transit between your browser and our servers
  • Encryption at rest for data stored in our database
  • Row-level security (RLS) policies that ensure each user can only access their own data
  • Access controls limiting employee access to personal information on a need-to-know basis
  • Regular security reviews and vulnerability assessments
  • Secure development practices including input validation and protection against common web vulnerabilities

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect personal information, we cannot guarantee its absolute security. If you discover a security vulnerability, please report it responsibly to info@prebuildiq.ca.

8. Your Rights Under PIPEDA

Under PIPEDA and applicable provincial law, you have the following rights regarding your personal information:

Right of Access Request a copy of the personal information we hold about you and information about how it is used and disclosed.
Right of Correction Request that we correct inaccurate or incomplete personal information about you.
Right to Withdraw Consent Withdraw consent to non-essential processing at any time, subject to legal or contractual restrictions. Withdrawal may limit or terminate your access to the Service.
Right to Erasure Request deletion of your account and personal information, subject to legal retention obligations.
Right to Complain File a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca if you believe we have not handled your information appropriately.
Right to Know Know the name or title of our Privacy Officer and how to contact them with questions or concerns.

To exercise any of these rights, contact our Privacy Officer at info@prebuildiq.ca. We will respond within thirty (30) days. We may require you to verify your identity before responding. For complex requests, we may extend this period by an additional thirty (30) days with notice.

9. Commercial Electronic Messages (CASL)

We comply with Canada's Anti-Spam Legislation (CASL). We will only send commercial electronic messages (marketing emails, promotional content, or news about our Service) with your express or implied consent as defined under CASL.

Express consent is obtained when you check a box to opt in to marketing communications during registration or at another point.

Implied consent exists where you have an existing business relationship with us (e.g., you are a current subscriber), in accordance with CASL's two-year implied consent period following your last commercial transaction.

You may withdraw consent to commercial electronic messages at any time by: (a) clicking the "Unsubscribe" link in any marketing email; or (b) contacting us at info@prebuildiq.ca. Withdrawal of consent will be processed within ten (10) business days.

Transactional messages (account confirmations, password resets, billing receipts, security alerts) are sent without requiring consent as they are necessary to the operation of the Service and are exempt from CASL's opt-in requirements.

10. Cookies and Similar Technologies

Our Website and Service use cookies and similar browser-based storage to operate and improve the Service.

Strictly necessary cookies: Authentication session cookies and security tokens required to maintain your logged-in session and protect your account. These cannot be disabled without preventing use of the Service.

Functional storage: We use browser localStorage to store your preferences (e.g., theme selection, address history) scoped to your account. This data does not leave your device and is not transmitted to third parties.

Analytics: We may use anonymized analytics to understand how users interact with the Service in aggregate. Any such analytics are collected in a privacy-preserving manner and do not track individuals across sites.

You can control cookies through your browser settings. Disabling strictly necessary cookies will impair your ability to use the Service.

11. Children's Privacy

The Service is a business productivity tool intended for use by adults (18 years of age or older) and organizations in the real estate development, planning, and construction industries. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have collected personal information from a minor without appropriate consent, we will promptly delete that information. If you believe we may have inadvertently collected information from a minor, please contact us at info@prebuildiq.ca.

12. Breach Notification

In the event of a security breach involving personal information, PreBuildIQ will assess whether the breach creates a "real risk of significant harm" to affected individuals, as required by PIPEDA's breach of security safeguards regulations. Where this threshold is met:

  • We will notify the Office of the Privacy Commissioner of Canada (OPC) as soon as feasible
  • We will notify affected individuals as soon as feasible and in plain language
  • We will maintain a record of all security breaches involving personal information for a minimum of twenty-four (24) months regardless of whether notification is required

Notification to individuals will describe the circumstances of the breach, the personal information affected, steps PreBuildIQ has taken to reduce harm, and steps individuals can take to protect themselves.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. The revised Policy will be posted on this page with an updated effective date.

For material changes that affect how we handle personal information, we will provide at least fourteen (14) days' advance notice by email to the address on file. Continued use of the Service after the effective date of any update constitutes acceptance of the revised Policy. If you do not accept a material change, you may close your account before the effective date.

Contact / Privacy Officer

PreBuildIQ Inc.
Toronto, Ontario, Canada
Privacy Officer: info@prebuildiq.ca

For questions, access requests, or complaints regarding our handling of personal information, contact our Privacy Officer. We will acknowledge your inquiry within five (5) business days and respond substantively within thirty (30) days.

You may also file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.