Legal
Privacy Policy
Effective date: May 12, 2026
Convass is a Canadian platform that lets owners and seekers connect directly without realtor commissions. Privacy is core to that promise: we collect the minimum information needed to run the service, we protect it with modern security, and we never sell it.
This document explains, in plain language, what we collect, why, how long we keep it, who we share it with, and the rights you have under Canadian privacy law. If you have any questions, email [email protected].
01. Scope and your consent
This Privacy Policy applies to information that Convass ("Convass", "we", "us") collects when you visit convass.com, create an account, post or browse listings, exchange messages through the platform, or interact with our transactional emails. By using the service, you consent to the practices described here. If you do not agree, please stop using Convass and ask us to delete any account you have created.
Convass operates from Canada and is governed primarily by the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws (including Ontario's housing and human rights frameworks). Where provincial law affords stronger protections than PIPEDA, the higher standard applies to residents of that province.
02. Information we collect
We collect the categories of information described below.
- Account data. Name, email address, password hash, optional phone number, profile photo, account role (renter, buyer, owner), preferences, and verification status (e.g. email-verified, ID-verified).
- Listing data. Property addresses, photos, asking prices, square footage, descriptions, amenities, open-house schedules, school links, and any other content you submit when publishing a listing.
- Communications. The contents of in-platform messages, inquiries, RSVPs, reviews, reports, and support tickets, including timestamps and read receipts.
- Activity data. Pages viewed, listings saved, searches performed, filters used, and the bounding box of map interactions when you use the explore tools.
- Device and network data. IP address, user-agent, referring page, approximate geolocation derived from IP (used for abuse signals only), and cookies / local-storage identifiers.
- Precise location. Only when you explicitly tap Locate me on the map or enter a commute origin address. Coordinates from Locate me stay in your browser and are never sent to our servers. Commute addresses are stored only to power the commute-time filter.
- Financial inputs. Income, down-payment, and debt figures you enter into the mortgage pre-qualification and affordability tools. These figures are processed in-session for calculation; we do not sell or share them, and we do not pull credit reports.
- Cookies and analytics. See section 7.
03. How we use your information
We use personal information only for the purposes stated below.
- Provide the service. Authenticate your account, publish your listings, deliver messages and notifications, run search and map filters, generate saved-search digests, and serve the mortgage and investment calculators.
- Protect users. Detect and prevent fraud, scraping, spam, harassment, discrimination, and account takeovers. We may review reported content and rate-limit suspicious activity.
- Improve reliability. Use error monitoring and aggregated, de-identified analytics to fix bugs, plan features, and understand performance.
- Communicate with you. Send transactional emails (verification, password reset, listing updates, RSVP receipts, saved-search digests). Marketing email is opt-in only and can be unsubscribed at any time using the link in the footer of any marketing message.
- Comply with law. Respond to lawful requests, meet audit and tax obligations, and enforce our Terms of Use.
We do not use your information to make automated decisions that produce legal or similarly significant effects without human review. Scoring features (e.g. offer strength, school proximity, walk score) are informational only and are not used to filter you.
04. Lawful basis for processing
Under PIPEDA we rely on the following bases.
- Performance of a contract. Processing required to deliver the service you signed up for.
- Legitimate interests. Operating, securing, and improving the service in ways a reasonable person would expect.
- Express consent. Optional features such as analytics cookies, marketing email, and precise location use.
- Legal obligation. Tax, accounting, and law-enforcement response.
06. International data transfers
Convass is hosted primarily in Canada. Some service providers (e.g. email, error monitoring) may store or process data in the United States or other jurisdictions. Where that occurs, we rely on provider contracts that incorporate substantially equivalent privacy safeguards. Your information remains subject to lawful access laws of any country where it is stored, and we will not weaken your privacy rights by transferring data outside Canada.
08. How we protect your information
We use industry-standard administrative, technical, and physical safeguards, including:
- HTTPS / TLS on all traffic, HSTS preload, and modern TLS suites.
- Passwords are stored only as one-way
scrypthashes with per-user salts. - Database access restricted via least-privilege roles and isolated network paths.
- Rate-limited and audit-logged moderation and admin endpoints.
- Routine dependency vulnerability scans and security headers (CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy).
No system is perfectly secure. If you discover a vulnerability, please contact [email protected]; we operate a good-faith coordinated-disclosure process.
09. Data retention
- Active accounts: while your account remains open.
- Inactive accounts (no sign-in for 24 months): may be soft-deleted after notice.
- Listings: retained while published and for up to 36 months after delisting to support analytics on sold/rented history (address obfuscated for delisted records).
- Messages: retained while either participant account is active; participants may request individual-message deletion.
- Logs and security events: typically 90 days.
- Financial / tax records: retained as required by Canadian tax law (typically 7 years).
When you delete your account, identifying fields are removed and retained content is irreversibly anonymized within 30 days, except where retention is required by law or to resolve an open dispute.
10. Your rights
Subject to applicable Canadian law, you have the right to:
- access the personal information we hold about you;
- correct inaccurate or incomplete information;
- request deletion ("right to be forgotten") where retention is not legally required;
- withdraw consent for optional processing (analytics, marketing, precise location);
- export a machine-readable copy of your account data;
- object to certain types of processing and ask for human review.
To exercise any of these rights, email [email protected] from the address on file. We will verify your identity before acting and respond within 30 days. If we cannot fulfil a request we will explain why.
You also have the right to complain to the Office of the Privacy Commissioner of Canada or your provincial privacy regulator.
11. Children
Convass is intended for adults aged 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact [email protected] and we will delete it promptly.
12. Third-party content and links
Convass surfaces school ratings, walk and transit scores, neighbourhood statistics, mortgage rates, and other data sourced from third parties under public-data or commercial licences. These are provided for informational purposes only and are not independently verified by Convass. The privacy policies of any external sites we link to are governed by those sites' own terms.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced at least 14 days in advance by email to verified addresses and by a banner on the site. The "Effective date" at the top of this page reflects the latest version. Continued use of Convass after a change indicates acceptance of the updated policy.