Privacy Policy — WeInspect
Version v1.9-2026-08-11Dernière mise à jour : 2026-08-11
Version v1.9 — effective 2026-08-11
This policy complies with the Act respecting the protection of personal information in the private sector (RLRQ c P-39.1, as amended by Law 25 / Bill 64), the Civil Code of Québec, and applicable regulations.
30-second summary
┌─ What we do with your data ────────────────────────────┐
│ │
│ Data collected │
│ ────────────── │
│ ✓ Account (email, hashed password) │
│ ✓ Professional profile (license, signature) │
│ ⚠ Inspections (with your consent) — addresses, photos │
│ ⚠ Audio dictation (with explicit consent) │
│ ⚠ Geolocation (with explicit consent) │
│ ✓ Technical data (IP, browser, security logs) │
│ │
│ What we DO NOT do │
│ ───────────────── │
│ ✗ We do not resell your data │
│ ✗ We do not use it to train AI models │
│ ✗ No advertising cookies │
│ ✗ No Facebook/Google/LinkedIn pixels in the app │
│ ✗ No automated marketing profiling │
│ │
│ Hosting │
│ ─────── │
│ ✓ Your data stored in Canada (Supabase ca-central) │
│ ⚠ AI processes in transit in the U.S. (no training, │
│ Zero Data Retention) │
│ │
│ Your powers │
│ ────────── │
│ ✓ Disable AI in one click │
│ ✓ Export all your data (ZIP) │
│ ✓ Delete your account (30-day grace) │
│ ✓ Free complaint to CAI if you are not satisfied │
│ │
└────────────────────────────────────────────────────────┘
Plain language: We collect only what's needed to make WeInspect work. We keep your data in Canada by default. AI works for you, never on you. If you want to delete everything, two clicks. If you're unhappy, the CAI is there for you — free of charge.
1. Who we are
WeInspect is residential inspection software designed in Québec for building inspectors certified under BNQ 3009-500. It is operated by [LEGAL ENTITY], a [legal form] with its head office at [HEAD OFFICE ADDRESS], Québec, Canada.
- Québec Enterprise Number (NEQ) : [NEQ]
- GST number : [GST NUMBER]
- QST number : [QST NUMBER]
2. Personal information protection officer (DPO)
In accordance with section 8.1 of Law 25, we appoint an officer responsible for the protection of personal information:
- Designation : the person responsible for the protection of personal information
- Email : dpo@ouiinspect.ca
- Postal address : [HEAD OFFICE ADDRESS], to the attention of "Personal Information Protection Officer"
You may contact the DPO at any time to exercise your rights, file a complaint, or ask any question about how your data is processed.
3. Personal information we collect
3.1 Account information
- First name, last name, email
- Password (hashed, never stored in cleartext)
- Phone number (optional)
- Profile picture (optional)
- Professional license number (RBQ, AIBQ, AICQ, etc., optional)
3.2 Professional profile information
- Business name, professional address
- Specialties, certifications
- Logo, electronic signature
- Banking details (only via Stripe — we never store your card number)
3.3 Inspection-related information
- Addresses of inspected properties
- GPS coordinates at the time of capture (with your consent)
- Photos taken in the field
- Audio recordings dictated (with your explicit consent, see section 4)
- Annotations, transcriptions, drafted findings
- Your clients' data (name, email, phone, address) that you enter into WeInspect
3.4 AI-generated information
- Automatic transcriptions (Whisper)
- Generated findings (Claude Sonnet 4.6)
- Photo classification suggestions
- AI feature usage history (for credit tracking)
3.5 Technical information
- IP address, browser type, operating system
- Pages visited, session duration, in-app actions
- Device identifier (mobile)
- Scrubbed mobile crash reports (app version, OS, stack traces, technical breadcrumbs without emails, tokens, GPS, notes, photos or transcripts)
- Cookies (see our Cookies Policy)
3.6 Payment information
- Stripe handles all card data. We only receive: payment status, last digits of card, card brand, billing address, amount.
3.7 Waitlist sign-up information
Collected via the public /waitlist page when a visitor requests to join the private beta:
- Email address
- Full name
- Current inspection software
- Annual inspection volume
- Primary region (QC)
- Acquisition source (LinkedIn, referral, search, association, event)
- Phone number (optional — reserved for the design partner program)
- IP address, user-agent, consent version (CASL/Act 25 evidence)
3.8 Team and inspection-sharing information (S09)
When you use the "multi-inspector team" feature to share an inspection with another BNQ 3009-500 certified inspector:
- Team name (commercial, chosen by the owner)
- Member list: email address and user identifier of each invited inspector
- Sent and received invitations: recipient email, proposed role (admin / inspector), status (pending, accepted, declined, expired, cancelled)
- Team action audit log (creation, rename, deletion, invitation, acceptance, removal, ownership transfer, role change) — retained for 5 years for inspector professional liability and Law 25 sec. 27 compliance, plus Civil Code of Québec art. 2925
- For each action: who triggered it (
actor_user_id), who was the target where applicable (target_user_id), and the details (detailsJSON — may contain an invitation email address in cleartext as long as the invitation has not been accepted)
Team inspection sharing lets multiple inspectors access the same inspection (read-only for invited members, write for the owner) without duplicating the data. This purpose is grounded in contract performance between you and the team you join.
3.9 Proof of student status (S13)
If you request activation of the student plan, you upload proof of your student status (e.g. a student card or enrolment letter — a document that may contain your name, photo, and the name of your institution). This document is sensitive personal information:
- Purpose: verify your eligibility for the student plan (manual review by a WeInspect administrator).
- Legal basis: your explicit consent (
student_status_verification), collected just before the upload. - Retention: the document is kept for at most 90 days after the decision (approval or rejection), then the file is automatically purged; only the decision metadata is retained for audit purposes. An administrator's access to the document is logged (audit trail).
- Lifecycle: the administrator enters the end-of-study date that limits student access. We retain that date, the status (approved, rejected, or expired), and minimized approval-operation metadata; terminal operations are deleted after 90 days.
- Notifications: Resend receives your email address and only the content needed to notify you of approval, rejection, or expiry. The proof itself is never sent to Resend.
Proof of student status is never shared with a third party or used for marketing.
4. Purposes of processing
We process your information for the following purposes:
| Purpose | Legal basis | Categories of data | |---|---|---| | Provide the WeInspect service | Contract performance | Account, profile, inspections | | Generate findings via AI | Explicit consent | Audio, photos, inspections | | Bill your subscription | Legal obligation | Payment, profile | | Security, fraud prevention | Legitimate interest | Technical, IP | | Improve the product (aggregated analytics) | Legitimate interest | Anonymized technical | | Product communications | Consent | Email | | Marketing communications | Consent (separate) | Email | | Manage the beta waitlist | Explicit consent | Waitlist + technical | | Team inspection sharing (S09) | Contract performance | Teams, members, invitations, audit | | Team transactional notifications (invitation, addition, removal, ownership transfer) | Contract performance | Email + team name | | Student-status notifications (approval, rejection, expiry) | Contract performance | Email + decision and end date, where applicable | | Legal compliance | Legal obligation | All as needed |
5. Explicit consents (Law 25 sec. 12-15)
Plain language: before we process your voice, your photos, your location, or send you marketing, we ask you explicitly and separately. No "I accept everything at once". No opt-in hidden in the conditions. You can always say no — the app works, just without that feature.
For the following processing activities, we obtain your free, informed, specific, and revocable consent:
- AI processing: finding generation, audio transcription, photo classification, chatbot
- Audio recording: voice dictation in the field
- Geolocation: GPS capture during inspection
- Marketing: product/promotional emails (separate from account)
- Design partner program: use of testimonials + photo in marketing (post-validation)
- Waitlist sign-up: public registration for the private beta and design partner program (collected on
/waitlist) - Product telemetry: anonymized usage events for improvement
- Student status verification: upload of proof of eligibility for the student plan (manual review, retained at most 90 days)
You may withdraw your consent at any time from /settings/privacy. Withdrawal has no retroactive effect on processing already carried out.
6. Retention periods
Plain language: your inspections stay directly accessible for 730 days, then move to archive for up to 7 years total from their creation — because the law requires it of you (QC inspector professional liability). After that, they are permanently deleted. Your raw audio disappears after 90 days once transcribed. If you close your account, 30 days of grace just in case, then everything is really deleted — except what the law forces us to keep (invoices 7 years).
| Category | Duration | Justification | |---|---|---| | Active account | While your account is active + 30 days after deletion | Service + cancellation grace period | | Completed inspections | 7 years total: 730 days in direct access, then archive for up to 1825 additional days | QC inspector professional obligation + evidence | | Raw audio (dictation) | 90 days after transcription | Security + transcription improvement | | Inspection photos | With the inspection (7 years total) | Evidence + client deliverable | | Technical logs | 90 days | Security + debugging | | Consent audit logs | 7 years | Law 25 obligation | | Team audit (team_membership_audit) | 5 years after the event | Inspector professional liability + Law 25 sec. 27 + Civil Code art. 2925 | | Team invitations (team_invitations) | While active; 7 days after expiry or refusal | Team authentication + CASL sec. 13 | | Terminal or blocked student-plan approval operations | 90 days | Technical recovery, decision evidence, and minimization | | Waitlist sign-up (active) | While your sign-up is active | Waitlist service + beta invitation | | Waitlist sign-up (post-unsubscribe) | 3 years after unsubscribe | CASL sec. 13 consent evidence | | Billing data | 7 years | QC + CRA tax obligations | | Anonymized aggregated analytics | Indefinite | No personal information after anonymization |
After the retention period, data is permanently deleted or irreversibly anonymized.
Deletion is immediate in active systems. It then propagates to encrypted backups, which are kept only for the length of their cycle — at most 365 days, with a 35-day immutability period on each backup. These backups are used solely to restore service after a disaster; they are neither browsable nor used for any other purpose.
7. Third parties and subprocessors
Plain language: we're not alone running WeInspect. The DB is at Supabase in Canada. Payments at Stripe. AI at Anthropic and OpenAI in the U.S. (no-training, zero retention). Mobile crash reports go through Sentry with strict PII scrubbing. No "data broker partner", no "indirect monetization". We list each one below with a link to their own policy so you can verify.
We share information with the following third parties, only for the purposes described:
| Third party | Role | Country | Link | |---|---|---|---| | Supabase (Supabase Inc.) | Database + auth + storage | Canada (ca-central-1 region) | <https://supabase.com/privacy> | | Anthropic (Anthropic PBC) | AI finding generation (Claude Sonnet 4.6) | United States (encryption in transit + at rest, no training on customer data) | <https://www.anthropic.com/legal/privacy> | | OpenAI (OpenAI LLC) | Audio transcription (Whisper) + RAG embeddings | United States (no training on API data) | <https://openai.com/policies/privacy-policy> | | Stripe (Stripe Payments Canada) | Payments + invoicing | Canada/U.S. (PCI DSS Level 1) | <https://stripe.com/privacy> | | Resend (Resend Inc.) | Transactional email delivery (verification, password reset, exports, account deletion, team notifications, and student-status decisions/expiry) | United States | <https://resend.com/legal/privacy-policy> | | Netlify (Netlify Inc.) | Application hosting + CDN | United States (SOC 2) | <https://www.netlify.com/privacy> | | Plausible (Plausible Insights OÜ) | Product analytics (cookieless, anonymized) | European Union (GDPR) | <https://plausible.io/privacy> | | Sentry (Functional Software, Inc.) | Scrubbed mobile crash reports | United States | <https://sentry.io/privacy/> | | Microsoft (Microsoft Corporation, Azure AI Translator) | Finding text translation (FR↔EN) | Requested region: Canada (canadacentral) — residency not guaranteed by the global endpoint, worst case United States (on par with OpenAI/Anthropic) | <https://privacy.microsoft.com/privacystatement> |
7.1 Cross-border transfers (Law 25 sec. 17)
Some processing takes place outside Québec (United States, European Union). Before any transfer, we assess the equivalent protection offered by the receiving jurisdiction and put in place standard contractual protection clauses. We never transfer your private data for AI model training purposes — our contracts with Anthropic and OpenAI explicitly exclude this use. Mobile crash reports sent to Sentry are limited to scrubbed technical diagnostics.
7.2 Default Canadian hosting
All your data stored in our database (account, inspections, photos, audio) is hosted by Supabase in the ca-central-1 (Canada) region. Only real-time AI processing involves transient transmission to Anthropic/OpenAI APIs (end-to-end encrypted, non-persistent on third-party side), and scrubbed mobile crash reports transit through Sentry.
8. Your rights (Law 25 sec. 27-30, 32, 36-37, 41-42)
Plain language: you can request anything — copy, correction, deletion — free of charge and without justification. You click in
/settings/privacyor write to the DPO. We have 30 days to respond. If we drag our feet or say no, the CAI is your independent and free recourse.
You have the following rights:
| Right | How to exercise it | |---|---| | Access: obtain a copy of all your data | /settings/privacy/export (automatic ZIP export) or write to the DPO | | Rectification: correct inaccurate data | Edit directly in the app, or write to the DPO | | Deletion: delete your account and your data | /settings/privacy/delete (30-day grace period, then permanent deletion) | | Portability: receive your data in a structured format | ZIP export (JSON + original photos + audio + PDF) | | Objection / consent withdrawal: refuse a processing activity | /settings/privacy toggles | | De-indexation: request that your name no longer be associated with a public search result | Write to the DPO | | Complaint: file a complaint with the CAI | <https://www.cai.gouv.qc.ca/lacces-aux-documents-et-la-protection-des-renseignements-personnels/depot-dune-plainte> |
Response time: 30 days maximum (Law 25 sec. 32).
9. Automated decisions
AI generates suggestions for findings, transcriptions, and photo classifications. No decision is made automatically about you without human validation. You, the inspector, retain final professional responsibility for the content published in your reports. You may refuse, modify, or ignore any AI suggestion.
10. Security
We protect your data through:
- TLS 1.3 encryption in transit
- At-rest encryption (AES-256, Supabase level)
- Multi-factor authentication (MFA) available
- Postgres Row-Level Security (RLS): each user can only access their own data
- Annual security audits
- Strong password policy (12+ characters, HaveIBeenPwned check)
- Audit logs for access to sensitive data
In the event of a confidentiality incident affecting your information, we will notify you and the CAI as soon as practicable (Law 25 sec. 3.5-3.7), in accordance with our legal obligations.
11. Minors' information
WeInspect is intended for adult professionals (building inspectors). We do not knowingly collect information from minors under 14. If you believe a child has provided us with information, contact the DPO for immediate deletion.
12. Cookies and trackers
See our Cookies Policy for details.
13. Changes to this policy
We may modify this policy. In case of substantial changes:
- You will be notified by email + in-app notification 30 days before the effective date
- For certain processing activities (AI, marketing), a new explicit consent will be required
- Version history is available at
/privacy-policy/history
13bis. If WeInspect ceases operations (Act 25 art. 22)
Plain language: if we have to shut down the platform, you'll get at least 30 days' notice and 60 days to download all your data. No data disappears without giving you a chance to retrieve it.
If we permanently cease WeInspect operations (voluntary closure, bankruptcy, or transfer to a third party that you reject), we commit to:
- Minimum 30-day notice before the effective shutdown:
- Email to all addresses associated with active accounts - Banner in the app at every login - Public announcement on the homepage and Trust Center /transparency - Notification to the Commission d'accès à l'information du Québec (CAI) if the shutdown involves a transfer to a third party
- 60-day export window starting from the announcement:
- Self-service export (/profile/privacy/export) remains available and free for the entire window - Format: ZIP with signed manifest, schema documented at /transparency/data-export-schema - Manual export available by email to support@ouiinspect.ca (reply < 7 business days) for technical issues
- Guaranteed data destruction after the export window:
- Complete deletion of databases (production + backups) - Deletion of stored files (photos, audio, PDFs) - Deletion of data held by our sub-processors (Supabase, Anthropic, OpenAI, Stripe, Resend, Netlify, Plausible, Sentry, Plooto if applicable) — each sub-processor provides a destruction attestation per its DPA - Exception: tax data required by law (Stripe invoices, GST/QST returns) is retained for 7 years by our accountant per Quebec Tax Act and CRA obligations, and destroyed at term
- Destruction attestation signed by the DPO:
- Public document published at /transparency/closure - Includes: shutdown date, number of accounts affected, sub-processors notified, sub-processor attestations received, confirmed destruction date - Retained 7 years as evidence for the CAI or any complaint
- Third-party acquisition case:
- If WeInspect is acquired by a third party, we will notify you before the transfer takes effect - You may oppose the transfer and recover your data + delete your account before the assignment (Act 25 art. 30) - If you do not respond within 30 days, the transfer proceeds with the buyer continuing to honor this policy
- Post-shutdown audit log retention:
- admin_audit_logs, ai_request_audit, user_consents (proof of consent) are pseudonymized but retained 7 years with an external custodian designated by the DPO, as audit evidence for the CAI or in case of complaint - The DPO destruction attestation certifies this separate retention
Reference: Act 25 art. 22 — Destruction of personal information once the purposes for which it was collected or used have been accomplished, except for periods set by law.
14. Governing law and jurisdiction
This policy is governed by the laws of Québec and applicable federal laws of Canada. Any dispute will be submitted to the competent courts of the judicial district of [JUDICIAL DISTRICT], province of Québec, Canada.
15. Complaint to the CAI
If you are not satisfied with our handling of your data or our response to your request, you may file a complaint free of charge with the Commission d'accès à l'information du Québec:
Commission d'accès à l'information du Québec
525, boul. René-Lévesque Est, bureau 2.36
Québec (Québec) G1R 5S9
Phone: 418 528-7741 or 1 888 528-7741
Website: <https://www.cai.gouv.qc.ca>
Last updated: 2026-08-11 Previous version: v1.8 (2026-05-14 — added §3.8 teams / inspection sharing S09) Changes v1.8 → v1.9: §6 — fixed the retention period for completed inspections, which contradicted itself ("730 days (7 years after final publication)"): the actual period is 7 years total, 730 days in direct access then archive, which the automated purge now enforces. Photos aligned to the same period. Added a clarification on how deletion propagates to encrypted backups (365-day cycle at most, 35-day immutability).