Privacy
What we collect, why, and what you can do about it.
In effect since 9 September 2026. This policy describes how CanSaveSpace handles personal information under PIPEDA and the provincial privacy legislation that applies where you live. If we change it in a way that affects you, we will say so here and date the change.
What we collect
When you create an account
- · Email address (required — it identifies your account)
- · First name, and last name if you provide one
- · Phone number, optional
- · A password, stored only as an argon2 hash — never in readable form
If you sign in with Google
- · Your Google account identifier, email address and name
- · We do not receive or store your Google password
As you use the platform
- · Markets you save to your watchlist
- · Property details and assumptions you enter into the analyzer
- · Questions you send to the administrator, and questions you ask the AI analyst
- · Reports you generate
- · Counts of metered actions, so plan limits can be applied
Property figures you enter are your assumptions. They are stored so you can come back to them, and are visible only to your account.
Cookies
We use one cookie for signing in: savespace_session. It is httpOnly (JavaScript cannot read it), secure in production, and SameSite=Lax. It holds a random token, not your identity — the token is matched server-side against a session record, and only its hash is stored.
A short-lived cookie is also set during Google sign-in to protect against cross-site request forgery. It is deleted as soon as sign-in completes.
We use no analytics or advertising cookies, and no third-party tracking scripts. Our analytics are first-party: an identifier held in your browser’s sessionStorage that expires when you close the tab and never travels between sites. Figures you type into the calculators are kept in your own browser so the tools remember your work; they are never sent to us, and the Reset button on each calculator deletes them.
Who else processes your data
We use these providers to run the service. Each receives only what its function requires.
| Provider | Purpose | Receives |
|---|---|---|
| Neon | Database hosting | All stored account and platform data |
| Vercel | Application hosting | Request data, IP addresses, server logs |
| Resend | Transactional email | Your email address and message contents |
| Anthropic | AI Market Analyst | Your question and the market data it is answered from |
| Optional sign-in | Only what OAuth requires, if you use it |
Your information is stored outside Canada
Our database is hosted by Neon in the US East (Ohio) region of Amazon Web Services. Account data, saved scenarios, watchlists and questions are therefore stored in the United States. The other processors above operate globally distributed infrastructure and may process data in the United States or elsewhere.
While information is held in another country it is subject to that country’s laws, and may be accessible to its courts and law-enforcement or national-security authorities under those laws, regardless of the protections we apply. If you would rather your information were not stored outside Canada, please do not create an account — you can read every public page without one.
What we do not do
- · We do not sell your personal information
- · We do not share your saved properties or questions with other users
- · We do not use your property assumptions as market data for anyone else
- · We do not run advertising trackers on this site
Your choices
- · Access — ask for a copy of what we hold about you
- · Correction — update your name, email or phone from your dashboard at any time
- · Deletion — ask us to delete your account
- · Withdraw consent — unsubscribe from the newsletter using the link in any email
Deleting an account removes the account record and everything attached to it — watchlists, saved properties and scenarios, alerts, reports, questions and analyst conversations. That cascade is enforced by the database, not by a cleanup job that might miss something.
You can delete your own account without asking us, from your account settings. It takes effect immediately.
There is not yet a self-serve export. Ask us through the contact page and we will send you a copy of what we hold, at no charge, within 30 days as PIPEDA requires.
Security
- · Passwords are hashed with argon2id and never stored in readable form
- · Session and password-reset tokens are stored hashed, so a database copy yields no usable credentials
- · Password reset links are single-use and expire after one hour
- · Completing a reset signs you out of every other session
- · All traffic is served over HTTPS
If there is a breach
If personal information is lost or accessed without authorisation and we judge that it creates a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada and notify you directly, as soon as feasible. We keep a record of every breach for at least 24 months, whether or not it met that threshold, which is what PIPEDA requires of us.
How long we keep things
| What | How long |
|---|---|
| Your account and its contents | Until you delete it |
| Sign-in sessions | 30 days, then they expire |
| Password reset links | 1 hour, single use |
| Email confirmation links | 48 hours, single use |
| Rate-limiting records | 24 hours |
| Record that you accepted the Terms | Kept as evidence of the agreement |
| Audit records of security-relevant actions | Kept as evidence |
| Record that you asked us to stop emailing you | Kept, so we do not email you again |
| Breach records | At least 24 months |
Backups are overwritten on a rolling basis. A deletion takes effect on live systems immediately; backups age out rather than being edited, because editing a backup would destroy its integrity. We will not delete an unused account without telling you first.
Children
This service is intended for adults making their own financial decisions and is not directed at children.
You must be at least 18 to hold an account. We do not knowingly collect personal information from anyone younger. If we learn that we have, we will close the account and delete the information attached to it.
Contact
For any privacy question or request, use the contact page.
Elijah Oluwunmi
A sole proprietorship based in Alberta, Canada
Calgary, Alberta, Canada
Privacy contact: info@cansavespace.ca
In effect since 9 September 2026. If you are not satisfied with how we handle a privacy request, you can complain to the Office of the Privacy Commissioner of Canada, or to your provincial privacy regulator where one has jurisdiction.