Privacy
Privacy Policy
Last updated 6 September 2026 · Version 2026.09.06 · CAREIZE, Ontario
This policy describes how CAREIZE (“we”) collects, uses, and discloses personal information in the course of providing commercial facility care in Ontario, in accordance with applicable Canadian privacy law (including the Personal Information Protection and Electronic Documents Act where it applies) and applicable Ontario law. It is not legal advice.
1. Data we collect
- Identity and contact: legal name, email, phone, company/building name.
- Service address: street number and name, unit, postal code, business hours.
- Access information you choose to provide (lockbox/keypad codes, alarm instructions).
- Plan selections, estimates, invoices, and service history (care stamps, notes).
- Optional photos or PDFs you attach to an invoice request (JPG, PNG, WEBP, PDF). Files are attached to the invoice-request email for our team to review and stored only with that request.
- Agreement evidence: typed legal name, agreement version, selected plan, selected service scope, quoted service price, timestamp, IP address, and user-agent when you submit an invoice request.
- Login security data: account identifier, authorized email, one-time verification codes (stored only as a hash), session cookies, IP address, and user-agent used to protect Client Portal, Staff Portal, and admin access.
- Optional marketing consent if you check that box.
- Referring company login email, if you enter one, used only to track referral credit eligibility.
- Callback requests: reason, preferred day and time, email, phone, and an optional note.
- Ask CAREIZE AI messages you type in the public chat. Chat transcripts are not stored by CAREIZE after the reply is generated. Messages are sent to the configured AI provider only to generate a reply.
2. Why we collect it
To quote, schedule, and deliver care; to invoice and collect payment; to maintain your Client Portal; to authenticate clients, staff, and administrators; to return callback requests; to answer public website questions through Ask CAREIZE AI; to investigate quality or damage reports; to meet legal and insurance record-keeping; and, only with separate consent, for marketing.
3. Access codes and building security
Access codes are used only for scheduled visits. Change codes anytime and notify us. Do not send payment card numbers through this website. Access codes and sensitive allergy or service notes are not sent to the public Ask CAREIZE AI assistant. We do not keep access codes after you change them or close the account, except as needed to complete an already-scheduled visit.
4. Photos and documents
This website does not upload or store photos. If you need to share photos, add a Drive link in “Anything else we should know?”, or send them by email or any of our social channels with your business name. Files are not used for marketing, social media, or advertising unless you give optional marketing consent, which you may withdraw in Client Portal or by emailing hello@careize.ca.
5. Cookies, local storage, and login sessions
We use essential cookies and local storage for language preference, CSRF protection, cookie-choice, and authenticated portal sessions. Client, staff, and admin sessions use HttpOnly, Secure (on HTTPS), SameSite cookies after two-step email verification. Session cookies expire (about 12 hours for clients and 8 hours for staff/admin) and are invalidated on logout. We do not currently run third-party advertising pixels. If we add analytics later, we will update the Cookie notice.
6. Login security
Client Portal access requires an account identifier plus the authorized email on file. Staff and admin access require an authorized company email. We send a single-use verification code that expires in 10 minutes. The account identifier and employee name or code are not authentication secrets. We apply rate limits, attempt limits, generic failure messages, and server-side session checks. Extra-service requests in the Client Portal use the authenticated server session — not a client-supplied account code — to identify the customer.
7. Third-party services
Hosting, email delivery of verification codes and service messages, and (when connected) payment processors may process data as our service providers, under contracts requiring confidentiality. We do not sell personal information.
7A. Ask CAREIZE AI and web search
Ask CAREIZE AI is a company website feature. Public questions are answered from our current Service Agreement, Privacy Policy, published pricing, services catalog, FAQs, and related public company knowledge. When a question requires public information that is not in those sources (for example a general Ontario law or tax-rate reference), the assistant may use web search through the configured provider. External search results are public information and are not company policy. We do not send Client Portal records, staff records, access codes, or other private account data to the public assistant. Chat transcripts are not retained by CAREIZE after the reply is generated.
8. Retention and deletion limitations
Quote and billing records are kept for at least seven (7) years to meet tax and commercial record requirements. Access codes are kept only while an account is active and deleted or overwritten when you change them or close the account. Agreement logs (typed name, version, plan, scope, quoted price, timestamp, IP, user-agent) are kept for the life of the commercial relationship plus seven years. Verification codes are hashed, expire shortly after issue, and are not reused. Session records are revoked on logout or expiry and then deleted in ordinary course. Because some records must be kept for tax, insurance, or legal reasons, we may not be able to delete every item on request until those duties end.
9. Your rights
You may request access to, correction of, or deletion of personal information we hold, subject to legal retention duties. Email hello@careize.ca with the subject “Privacy request”. We respond within 30 days. You may withdraw marketing consent at any time. You may complain to the Office of the Privacy Commissioner of Canada.
10. Security
We use HTTPS, CSRF tokens, rate limiting, honeypot fields, hashed verification tokens, HttpOnly session cookies, and server-side role checks. No portal or admin action relies on a client-supplied password, role, or hidden form field as the sole authorization.
11. Privacy breach response
If a privacy breach creates a real risk of significant harm, we will report it to the Privacy Commissioner of Canada and notify affected individuals as required by applicable law, and we will take reasonable steps to contain and remediate the incident.
12. Children
This site is for commercial (B2B) customers, not directed at children.
13. Contact
Privacy contact: hello@careize.ca · Ontario. Request a callback from Contact if you need a phone conversation.
Related: Cookie notice · Service Agreement