Privacy

What we collect, why, and what you can do about it.

In effect since 9 September 2026. This policy describes how CanSaveSpace handles personal information under PIPEDA and the provincial privacy legislation that applies where you live. If we change it in a way that affects you, we will say so here and date the change.

What we collect

When you create an account

  • · Email address (required — it identifies your account)
  • · First name, and last name if you provide one
  • · Phone number, optional
  • · A password, stored only as an argon2 hash — never in readable form

If you sign in with Google

  • · Your Google account identifier, email address and name
  • · We do not receive or store your Google password

As you use the platform

  • · Markets you save to your watchlist
  • · Property details and assumptions you enter into the analyzer
  • · Questions you send to the administrator, and questions you ask the AI analyst
  • · Reports you generate
  • · Counts of metered actions, so plan limits can be applied

Property figures you enter are your assumptions. They are stored so you can come back to them, and are visible only to your account.

Cookies

We use one cookie for signing in: savespace_session. It is httpOnly (JavaScript cannot read it), secure in production, and SameSite=Lax. It holds a random token, not your identity — the token is matched server-side against a session record, and only its hash is stored.

A short-lived cookie is also set during Google sign-in to protect against cross-site request forgery. It is deleted as soon as sign-in completes.

We use no analytics or advertising cookies, and no third-party tracking scripts. Our analytics are first-party: an identifier held in your browser’s sessionStorage that expires when you close the tab and never travels between sites. Figures you type into the calculators are kept in your own browser so the tools remember your work; they are never sent to us, and the Reset button on each calculator deletes them.

Who else processes your data

We use these providers to run the service. Each receives only what its function requires.

ProviderPurposeReceives
NeonDatabase hostingAll stored account and platform data
VercelApplication hostingRequest data, IP addresses, server logs
ResendTransactional emailYour email address and message contents
AnthropicAI Market AnalystYour question and the market data it is answered from
GoogleOptional sign-inOnly what OAuth requires, if you use it

Your information is stored outside Canada

Our database is hosted by Neon in the US East (Ohio) region of Amazon Web Services. Account data, saved scenarios, watchlists and questions are therefore stored in the United States. The other processors above operate globally distributed infrastructure and may process data in the United States or elsewhere.

While information is held in another country it is subject to that country’s laws, and may be accessible to its courts and law-enforcement or national-security authorities under those laws, regardless of the protections we apply. If you would rather your information were not stored outside Canada, please do not create an account — you can read every public page without one.

What we do not do

  • · We do not sell your personal information
  • · We do not share your saved properties or questions with other users
  • · We do not use your property assumptions as market data for anyone else
  • · We do not run advertising trackers on this site

Your choices

  • · Access — ask for a copy of what we hold about you
  • · Correction — update your name, email or phone from your dashboard at any time
  • · Deletion — ask us to delete your account
  • · Withdraw consent — unsubscribe from the newsletter using the link in any email

Deleting an account removes the account record and everything attached to it — watchlists, saved properties and scenarios, alerts, reports, questions and analyst conversations. That cascade is enforced by the database, not by a cleanup job that might miss something.

You can delete your own account without asking us, from your account settings. It takes effect immediately.

There is not yet a self-serve export. Ask us through the contact page and we will send you a copy of what we hold, at no charge, within 30 days as PIPEDA requires.

Security

  • · Passwords are hashed with argon2id and never stored in readable form
  • · Session and password-reset tokens are stored hashed, so a database copy yields no usable credentials
  • · Password reset links are single-use and expire after one hour
  • · Completing a reset signs you out of every other session
  • · All traffic is served over HTTPS

If there is a breach

If personal information is lost or accessed without authorisation and we judge that it creates a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada and notify you directly, as soon as feasible. We keep a record of every breach for at least 24 months, whether or not it met that threshold, which is what PIPEDA requires of us.

How long we keep things

WhatHow long
Your account and its contentsUntil you delete it
Sign-in sessions30 days, then they expire
Password reset links1 hour, single use
Email confirmation links48 hours, single use
Rate-limiting records24 hours
Record that you accepted the TermsKept as evidence of the agreement
Audit records of security-relevant actionsKept as evidence
Record that you asked us to stop emailing youKept, so we do not email you again
Breach recordsAt least 24 months

Backups are overwritten on a rolling basis. A deletion takes effect on live systems immediately; backups age out rather than being edited, because editing a backup would destroy its integrity. We will not delete an unused account without telling you first.

Children

This service is intended for adults making their own financial decisions and is not directed at children.

You must be at least 18 to hold an account. We do not knowingly collect personal information from anyone younger. If we learn that we have, we will close the account and delete the information attached to it.

Contact

For any privacy question or request, use the contact page.

Elijah Oluwunmi

A sole proprietorship based in Alberta, Canada
Calgary, Alberta, Canada

Privacy contact: info@cansavespace.ca

In effect since 9 September 2026. If you are not satisfied with how we handle a privacy request, you can complain to the Office of the Privacy Commissioner of Canada, or to your provincial privacy regulator where one has jurisdiction.