Privacy Policy
Effective: April 15, 2026 | Last updated: April 15, 2026
ClaimShow is operated by Founder 8 Strategic Risk & Capital Advisory Inc. (“we”, “us”, or “our”). We are committed to protecting your personal information in compliance with the Personal Information Protection and Electronic Documents Act(PIPEDA) and Alberta’s Personal Information Protection Act (PIPA).
This policy explains what we collect, why we collect it, who we share it with, and what rights you have. Plain English is our goal — no legalese.
1. What We Collect
| Category | Examples | When collected |
|---|---|---|
| Account information | Full name, email address, password (hashed) | On sign-up |
| Property details | Street address, postal code, property type, damage description | When submitting a claim estimate |
| Photos | Damage photos you upload; may contain embedded EXIF data including GPS coordinates | When uploading photos |
| Geolocation (indirect) | GPS coordinates extracted from photo EXIF metadata (stripped after processing) | On photo upload |
| Payment information | Billing name, last-four digits, card type, billing postal code. Full card numbers are never stored by us — handled by our PCI-compliant payment processor. | On subscription sign-up or upgrade |
| Usage & technical data | Browser type, IP address (anonymised), pages visited, error events (PII-stripped) | Automatically while using the service |
2. Why We Collect It
- Generate damage estimates. Your photos, property details, and damage descriptions are the inputs our AI needs to produce an accurate, Xactimate-comparable estimate.
- Provide and improve the service. We use aggregated, de-identified data to retrain and improve our AI models. Individual claims are never used to train third-party AI without your consent.
- Process payments. We pass billing information to our payment processor to charge your subscription.
- Communicate with you. We send transactional emails (estimate ready, receipt, password reset). We do not send marketing emails without your explicit opt-in.
- Security & compliance. We log errors and unusual activity to detect fraud and protect our systems.
3. Who We Share Your Data With
We do not sell your personal information. We share data only with the third-party service providers listed below, under written agreements that restrict their use of your data to the purposes described.
| Provider | Purpose | Data shared | Region |
|---|---|---|---|
| Anthropic | AI damage classification & description generation | Photos, damage descriptions (no account PII) | United States |
| Supabase | Database hosting & authentication | All data stored in our database | Canada (ca-central-1) |
| Vercel | Application hosting & edge delivery | Request logs (IP anonymised), static assets | Canada / Global CDN |
| Payment processor | Payment processing | Billing name, card token, amount | United States |
| Sentry | Error tracking & performance monitoring | Error events — PII is scrubbed before transmission; no names, emails, or payment data | United States |
| Upstash | Rate limiting (Redis) | Anonymised IP hash only — no PII | United States |
We may also disclose your information if required by law (e.g., a valid court order or regulatory demand) or to protect our legal rights.
4. How Long We Keep Your Data
- Estimates & claim records: 7 years from the date of creation, in line with insurance industry record-keeping standards.
- Photos: Retained for the life of the associated estimate, then deleted. EXIF geolocation data is stripped within 24 hours of upload after being used to validate the property location.
- Account data: Deleted within 30 days of receiving a verified deletion request, except where retention is required by law.
- Payment records: Retained for 7 years per CRA (Canada Revenue Agency) requirements.
- Error logs: Automatically purged after 90 days.
5. Your Rights Under PIPEDA
You have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your account and associated personal data (subject to legal retention obligations).
- Withdraw consent for non-essential data processing at any time. Note: withdrawing consent for core processing (e.g., AI analysis) means we cannot generate estimates for you.
- Know how your data is used— ask us anything; we will respond within 30 days.
- File a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca if you believe we have mishandled your information.
6. How to Exercise Your Rights
You have two ways to act on your rights:
- In-app: Go to Settings → Account → Data & Privacy to download your data or delete your account.
- By email: Send a request to info@claimshow.com. Include your account email so we can verify your identity. We respond within 30 days.
7. How We Protect Your Data
- All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Database access is protected by row-level security (Supabase RLS).
- Passwords are hashed using bcrypt; we never store plaintext passwords.
- Photos are stored in private, access-controlled buckets with signed URLs.
- We conduct regular security audits and restrict internal access to personal data on a need-to-know basis.
8. Breach Notification
In the event of a breach that creates a real risk of significant harm, we will notify the Office of the Privacy Commissioner of Canada and affected individuals as soon as feasible — and in no case later than 72 hours after we become aware of the breach. We maintain a breach record as required by PIPEDA.
9. Cookies & Tracking
We use only essential session cookies required for authentication. We do not use advertising cookies or third-party tracking pixels. You can disable cookies in your browser, but this will prevent you from signing in.
10. Children’s Privacy
ClaimShow is not directed at anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
11. Updates to This Policy
We may update this policy when our practices change or when law requires it. When we make material changes, we will notify you by email (to the address on your account) and by displaying a notice in the app at least 30 days before the changes take effect. The effective date at the top of this page always reflects the current version.
12. Privacy Officer & Contact
Our designated Privacy Officer is responsible for our compliance with PIPEDA and PIPA.
Ross HuarttPrivacy Officer, ClaimShow
Founder 8 Strategic Risk & Capital Advisory Inc.
Calgary, Alberta, Canada
Email: info@claimshow.com
See also: Terms of Service