Privacy Policy
Last updated June 2026
How Roofprint collects, uses, stores and protects your personal information. The verified legal entity name appears on signed contract documents. Written to Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA).
What we collect
We collect the information needed to give you a planning range and, if you proceed, to complete your roof:
- Your property address and the roof data we derive from it (size, pitch, imagery date);
- Contact details you choose to give us — name, email, and optionally phone;
- Project photos and notes from your assessment and installation;
- Payment information, processed securely by Stripe — we never store full card numbers.
How we use it
We use your information to calculate your planning range, schedule and complete work, process payments and warranties, respond to you, and meet legal and tax obligations. We do not use it for anything you haven’t reasonably consented to.
Consent
We ask for meaningful consent at the point we collect your information, and you can withdraw it at any time. Marketing emails are strictly opt-in (never pre-checked), and every one has a one-click unsubscribe.
We never sell your information
We do not sell, rent or trade your personal information to anyone. We share it only with the service providers that help us operate (such as our payment, e-signature and email providers), under agreements that limit them to that purpose.
Where it’s stored
Your data is stored in Canada (Supabase, ca-central-1 region), encrypted in transit and at rest. Some traffic may transit global networks via our infrastructure provider; the data itself is held in Canada.
Retention & your rights
We keep your information only as long as needed for the purposes above and to meet legal/tax requirements, then securely delete it. Under PIPEDA you can ask to access or correct your information, or request deletion — email us and we’ll respond promptly.
Security & breach response
We protect your information with access controls, encryption, and malware scanning of uploads. In the unlikely event of a breach that poses a real risk of significant harm, we will notify affected individuals and the Privacy Commissioner as PIPEDA requires, and keep a breach record for 24 months.
Cookies & analytics
We use privacy-respecting analytics and load non-essential tracking only after you consent via our cookie banner, where you can accept or reject with equal ease.
Questions about this policy? Use the contact page. See also our Terms and Accessibility statement.
