Privacy Policy

Information status: This privacy information describes the website’s current technical handling and names the services present in the deployed system. The applicable legal bases, provider contract and transfer safeguards, processing regions, and approved retention and final-deletion schedule still require organisational or legal confirmation. This notice is therefore not presented as final legal approval.

1. Controller and privacy contact

Controller: KanadaHomes Corporation Ltd., 100 King St W #5700, Toronto, ON M5X 1A9, Canada. For privacy questions and data-subject requests, contact office@kanadahomes.com. No data protection officer is identified because no appointed data protection officer is being claimed.

Your data-protection rights

Depending on the applicable law and the circumstances of the processing, you may have rights of access, correction, deletion, restriction, objection and data portability, and the right to withdraw consent without affecting processing already carried out. Other rights or limits may apply. You can exercise these rights by contacting office@kanadahomes.com.

2. Data you provide

Contact, project and configuration forms transmit the fields you enter. Depending on the form, these can include your name, email address, telephone number, destination country or region, message, model and project choices, budget, timeframe and configuration. The submission also includes the form type and language, consent choices and time, source page, a submission identifier and technical anti-abuse timing. Required fields are identified in each form. The system stores the enquiry before showing a successful receipt and creates email-outbox copies containing the information needed for the operator notification and customer confirmation.

3. Home configurator

In the home configurator, you first select your preferences and review the summary without submitting an enquiry. Contact details and configuration choices are transmitted only when you explicitly submit the final enquiry with the required consent. Merely entering details or leaving before submission does not create a new enquiry.

4. Optional first-party tracking

Your choice is stored in local storage in your browser with its decision time and has no application-set expiry; it remains until you change it or remove browser storage. With “Necessary only”, no optional session history is stored. Only after analytics consent, the site may keep in session storage up to 20 visited paths and 20 relevant link or button clicks for the current browser session, with limited referrer and device/browser context. URLs are stripped of query strings and hashes. Session storage normally ends when the browser session ends, subject to browser behavior. Analytics consent alone does not send this history to an external analytics service. If you later submit an enquiry, available consented details are stored with it in PostgreSQL. The separate advertising-click choice controls whether eligible advertising click identifiers may be attached. No advertising pixel or external analytics tracker is present in the current public code.

5. Purposes and submission status

Submitted information is used to receive and answer enquiries, review project information, administer leads, prevent duplicate or abusive submissions, and send operational notifications. A success receipt means the request was persisted; it does not claim that an email was delivered. The email outbox records attempts, status, provider identifier or error code and, where applicable, when Resend accepted a message. Provider acceptance is not proof of delivery to an inbox.

6. Systems and recipients currently used

The active public site and API run on the Replit platform. Enquiries, email-outbox payloads and administration records are stored in a PostgreSQL database reached through the server’s configured database connection. Resend is called through the Replit connector to send the operator notification and customer confirmation; those messages contain the relevant contact and enquiry information, and the visitor’s email is used as Reply-To only for the operator notification. Clerk handles authentication and session claims for the restricted administration area; the application then checks the authenticated Clerk user against its own role table before exposing lead records. Authorised administrators can view submitted enquiries. A partner should receive enquiry data only after the separate partner-consent choice or another confirmed basis.

7. Retention, deletion and technical logs

No approved retention period or automatic deletion job is implemented for leads, email-outbox payloads, audit entries or database backups. The administration delete action only marks a lead with a deletion time and hides it from normal administration views; it is not physical erasure, and no lead hard-delete endpoint is present. Pending email work for a marked lead is cancelled where the worker’s conditions apply. The application audit trail records the administrator identifier, action, entity type and identifier and limited changed-field metadata, not the enquiry body. Application request logs are configured for request identifier, method, path without query parameters and response status; selected authentication headers and cookies are redacted. Replit platform log and backup contents and retention, and the operational process for verified final erasure, still need confirmation.

8. Legal bases, transfers and review

The code establishes what is processed, but it does not establish the applicable legal basis for each purpose. The controller must confirm those bases and any required consent wording before final approval. Provider legal entities, processing regions, data-processing agreements, international-transfer routes and safeguards such as adequacy decisions or standard contractual clauses have not been established in the reviewed material and are not asserted here. The same confirmation is required for retention responsibilities, authorised internal recipients and any partner disclosure.

Frequently asked questions

For privacy questions and data-subject requests, contact office@kanadahomes.com.

Where can I ask about my personal data?

For privacy questions and requests for access, correction, deletion or other data-protection rights, contact office@kanadahomes.com.

What should I review before submitting a form?

Read the privacy information associated with the form, including its purpose, required fields and your rights.