Skip to content
roofprint
Legal

Privacy Policy

Last updated June 2026

How Roofprint collects, uses, stores and protects your personal information. The verified legal entity name appears on signed contract documents. Written to Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA).

In plain language: We collect only what we need to price and build your roof, we store it in Canada, we never sell it, and you can ask to see or delete it any time.

What we collect

We collect the information needed to give you a planning range and, if you proceed, to complete your roof:

  • Your property address and the roof data we derive from it (size, pitch, imagery date);
  • Contact details you choose to give us — name, email, and optionally phone;
  • Project photos and notes from your assessment and installation;
  • Payment information, processed securely by Stripe — we never store full card numbers.

How we use it

We use your information to calculate your planning range, schedule and complete work, process payments and warranties, respond to you, and meet legal and tax obligations. We do not use it for anything you haven’t reasonably consented to.

Consent

We ask for meaningful consent at the point we collect your information, and you can withdraw it at any time. Marketing emails are strictly opt-in (never pre-checked), and every one has a one-click unsubscribe.

We never sell your information

We do not sell, rent or trade your personal information to anyone. We share it only with the service providers that help us operate (such as our payment, e-signature and email providers), under agreements that limit them to that purpose.

Where it’s stored

Your data is stored in Canada (Supabase, ca-central-1 region), encrypted in transit and at rest. Some traffic may transit global networks via our infrastructure provider; the data itself is held in Canada.

Retention & your rights

We keep your information only as long as needed for the purposes above and to meet legal/tax requirements, then securely delete it. Under PIPEDA you can ask to access or correct your information, or request deletion — email us and we’ll respond promptly.

Security & breach response

We protect your information with access controls, encryption, and malware scanning of uploads. In the unlikely event of a breach that poses a real risk of significant harm, we will notify affected individuals and the Privacy Commissioner as PIPEDA requires, and keep a breach record for 24 months.

Cookies & analytics

We use privacy-respecting analytics and load non-essential tracking only after you consent via our cookie banner, where you can accept or reject with equal ease.

Legal review notice: this launch policy is written to the current Canadian frameworks (PIPEDA, the Consumer Protection Act 2002, AODA / WCAG 2.2 AA and CASL). It is not legal advice; the production version is finalised with a licensed Ontario lawyer before production activation.

Questions about this policy? Use the contact page. See also our Terms and Accessibility statement.