← Legal & Trust Centre

Privacy

Privacy Policy

How personal information is collected, used, disclosed, protected, retained, and made available to you.

RestoreCheck IQ Proof Grid trademarkRestoreCheck IQControl. Verify. Improve.™Policy edition 2026.07.24
This policy is written in plain language for transparency. It does not reduce rights or obligations that applicable law does not permit the parties to change.

1. Our commitment and scope

RestoreCheck IQ (“RestoreCheck IQ”, “we”, “us”, or “our”) provides a multi-tenant workflow, evidence, quality-control, reporting, integration, and support platform for restoration organizations. This Privacy Policy applies to our website, web application, installable mobile experience, customer support services, and related communications (collectively, the “Services”).

We use personal information only for identified, reasonable purposes and apply safeguards appropriate to its sensitivity. An organization that subscribes to the Services generally controls the project, claim, document, and workforce information it uploads; RestoreCheck IQ processes that information to provide the Services and according to the organization’s instructions. We remain responsible for personal information under our control, including information handled by service providers.

2. Information we collect

  • Account and identity information, such as name, business email, organization, job role, authentication status, and account preferences.
  • Registration, subscription, and transaction information, such as selected plan, billing cycle, billing method, payment status, invoices, and transaction references. Full payment-card data should be processed by the configured payment provider, not stored by RestoreCheck IQ.
  • Customer content that authorized users choose to provide, including projects, insurer or carrier requirements, claim references, property or loss details, documents, photos, invoices, comments, approvals, and quality-control records.
  • Support information, including case subject, description, contact information, troubleshooting data, authorized diagnostic scope, staff notes, and resolution history.
  • Technical and security information, including session and device signals, IP address or privacy-preserving derivatives, browser type, timestamps, authentication events, audit records, integration events, and error or performance diagnostics.
  • Integration information, such as API key metadata, webhook destinations, and connection status for customer-enabled services. Secret credentials are protected and are not displayed after creation where the product says so.
  • Mobile and offline information, including locally encrypted evidence queued for upload, sync status, and service-worker cache data. Device permissions are requested only when a feature requires them.
  • Communications and consent records, including registration confirmations, privacy choices, policy versions accepted, and marketing consent where separately requested.

3. How information is collected

We collect information directly from visitors, applicants, customers, and authorized users; automatically when the Services are used; from an organization that provisions or manages an account; from customer-configured integrations; and from service providers supporting hosting, storage, security, communications, billing, or customer support.

Customers must have authority to provide personal information and customer content to the Services. They are responsible for giving appropriate notices and obtaining required consents from their personnel, clients, claimants, property owners, vendors, and other individuals whose information they submit.

4. Why we use information

  • Provide, secure, authenticate, maintain, support, and improve the Services.
  • Create and administer registration applications, subscriptions, workspaces, authorized users, permissions, and two-factor authentication.
  • Store, organize, validate, compare, report on, and export customer-directed project and requirement information.
  • Process payments, maintain business records, and communicate service, security, billing, and support notices.
  • Detect, investigate, prevent, and respond to fraud, abuse, security incidents, service failures, and violations of our agreements.
  • Maintain tenant separation, access records, backup integrity, retention controls, legal holds, and disaster-recovery capability.
  • Understand product reliability and workflow effectiveness using minimized, aggregated, or de-identified operational information where reasonably possible.
  • Comply with law, enforce agreements, establish or defend legal claims, and protect people, customers, RestoreCheck IQ, and the public.

5. Consent and choices

Where consent is required, we seek meaningful consent in a form appropriate to the sensitivity and reasonable expectations involved. Core processing needed to provide a customer-requested Service is not presented as optional. Optional marketing, non-essential tracking, or materially new uses require an appropriate choice before they are enabled.

You may withdraw consent for consent-based processing, subject to legal or contractual restrictions and reasonable notice, by contacting privacy@restorecheckiq.ca. Withdrawal may prevent us from providing a feature that depends on that information.

6. When information is disclosed

We do not sell personal information and do not use customer project content for third-party advertising. Platform administrators do not receive routine access to customer project or document content. Any exceptional diagnostic access must be authorized, purpose-limited, time-bound, and auditable.

  • To the customer organization and its authorized users according to configured roles and permissions.
  • To vetted service providers that perform hosting, private object storage, database, email, billing, monitoring, security, or customer-authorized integration functions under contractual and confidentiality obligations.
  • To a customer-selected integration or destination when an authorized user directs the transfer.
  • To professional advisers, auditors, insurers, financing sources, or transaction counterparties subject to appropriate confidentiality and necessity controls.
  • To law-enforcement, regulators, courts, or other parties where required or permitted by law, or where reasonably necessary to protect rights, safety, security, or service integrity.
  • In connection with a merger, financing, reorganization, sale, or transfer, subject to lawful safeguards and notice where required.

7. International and interprovincial processing

Information may be processed in Canada or another country where an approved service provider operates. Information in another jurisdiction may be accessible to courts, law-enforcement, or national-security authorities under that jurisdiction’s laws. Before production launch, the current subprocessor register and hosting regions must be published in the Trust Centre. Customers with residency requirements should contact us before uploading regulated data.

Where Quebec requirements apply, we assess privacy factors before communicating personal information outside Quebec as required by law.

8. Retention and deletion

We retain personal information only as long as reasonably necessary for the identified purposes, customer instructions, security, dispute resolution, and legal obligations. Customer administrators may configure eligible evidence-retention periods. A legal hold, investigation, backup cycle, or statutory requirement may temporarily delay deletion.

Encrypted offline evidence is designed to expire from the local queue after a limited period. Deleting an account or workspace does not mean every backup copy disappears instantly; residual copies are isolated from ordinary use and removed through the backup lifecycle unless preservation is required.

To request access, correction, export, or deletion, use available account controls or contact privacy@restorecheckiq.ca. We will verify identity and authority before acting.

9. Safeguards and incidents

Our safeguards are designed to include tenant-scoped authorization, role-based access, two-factor authentication for privileged access, encryption in transit, private object storage, encrypted offline queues, managed secrets, audit records, backup controls, secure development checks, and monitored incident response. No system can be guaranteed perfectly secure.

We investigate suspected confidentiality or security incidents, take reasonable steps to contain risk and prevent recurrence, maintain required records, and notify affected individuals, customers, and regulators when applicable law requires it.

10. Access, correction, complaints, and privacy rights

Subject to applicable law, you may ask about the existence, use, or disclosure of personal information under our control; request access or correction; challenge compliance; or ask about retention and authorized access. Contact the Privacy Officer at privacy@restorecheckiq.ca.

If information was provided through your employer or another customer organization, we may direct the request to that organization when it controls the information. We will explain any lawful limitation on access and provide available complaint or regulator information.

11. Children

The Services are business tools and are not directed to children. Individuals must be legally capable of using the Services for their organization. Do not submit information about a child unless the customer has a lawful, necessary business purpose and all required authority, notice, consent, and safeguards.

12. Changes and contact

We may update this Policy to reflect changes in law, technology, or our practices. We will post the new version and effective date and provide additional notice or obtain consent where required for a material change. Privacy Officer: privacy@restorecheckiq.ca. Legal notices: legal@restorecheckiq.ca. Registered office: Canada.