Legal

Privacy Policy

Effective date: May 12, 2026

Convass is a Canadian platform that lets owners and seekers connect directly without realtor commissions. Privacy is core to that promise: we collect the minimum information needed to run the service, we protect it with modern security, and we never sell it.

This document explains, in plain language, what we collect, why, how long we keep it, who we share it with, and the rights you have under Canadian privacy law. If you have any questions, email [email protected].

01. Scope and your consent

This Privacy Policy applies to information that Convass ("Convass", "we", "us") collects when you visit convass.com, create an account, post or browse listings, exchange messages through the platform, or interact with our transactional emails. By using the service, you consent to the practices described here. If you do not agree, please stop using Convass and ask us to delete any account you have created.

Convass operates from Canada and is governed primarily by the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws (including Ontario's housing and human rights frameworks). Where provincial law affords stronger protections than PIPEDA, the higher standard applies to residents of that province.

02. Information we collect

We collect the categories of information described below.

  • Account data. Name, email address, password hash, optional phone number, profile photo, account role (renter, buyer, owner), preferences, and verification status (e.g. email-verified, ID-verified).
  • Listing data. Property addresses, photos, asking prices, square footage, descriptions, amenities, open-house schedules, school links, and any other content you submit when publishing a listing.
  • Communications. The contents of in-platform messages, inquiries, RSVPs, reviews, reports, and support tickets, including timestamps and read receipts.
  • Activity data. Pages viewed, listings saved, searches performed, filters used, and the bounding box of map interactions when you use the explore tools.
  • Device and network data. IP address, user-agent, referring page, approximate geolocation derived from IP (used for abuse signals only), and cookies / local-storage identifiers.
  • Precise location. Only when you explicitly tap Locate me on the map or enter a commute origin address. Coordinates from Locate me stay in your browser and are never sent to our servers. Commute addresses are stored only to power the commute-time filter.
  • Financial inputs. Income, down-payment, and debt figures you enter into the mortgage pre-qualification and affordability tools. These figures are processed in-session for calculation; we do not sell or share them, and we do not pull credit reports.
  • Cookies and analytics. See section 7.

03. How we use your information

We use personal information only for the purposes stated below.

  • Provide the service. Authenticate your account, publish your listings, deliver messages and notifications, run search and map filters, generate saved-search digests, and serve the mortgage and investment calculators.
  • Protect users. Detect and prevent fraud, scraping, spam, harassment, discrimination, and account takeovers. We may review reported content and rate-limit suspicious activity.
  • Improve reliability. Use error monitoring and aggregated, de-identified analytics to fix bugs, plan features, and understand performance.
  • Communicate with you. Send transactional emails (verification, password reset, listing updates, RSVP receipts, saved-search digests). Marketing email is opt-in only and can be unsubscribed at any time using the link in the footer of any marketing message.
  • Comply with law. Respond to lawful requests, meet audit and tax obligations, and enforce our Terms of Use.

We do not use your information to make automated decisions that produce legal or similarly significant effects without human review. Scoring features (e.g. offer strength, school proximity, walk score) are informational only and are not used to filter you.

04. Lawful basis for processing

Under PIPEDA we rely on the following bases.

  • Performance of a contract. Processing required to deliver the service you signed up for.
  • Legitimate interests. Operating, securing, and improving the service in ways a reasonable person would expect.
  • Express consent. Optional features such as analytics cookies, marketing email, and precise location use.
  • Legal obligation. Tax, accounting, and law-enforcement response.

05. How we share information

We do not sell personal information. We share it only in the narrow circumstances below.

  • Between users, with your action. When you contact a listing owner (or accept an inquiry), your display name, photo, and message contents are visible to the other party. Owners' listing addresses are revealed to a viewer only after a valid inquiry relationship is established or the owner publishes the listing as fully public.
  • Service providers (processors). Vetted infrastructure providers acting on our instructions: Postgres hosting, email delivery, error monitoring, image storage, geocoding, and SMS. Each is bound by contract and confidentiality obligations.
  • Public open-data sources. Convass uses public data (school directories, transit data, walk-score data, neighbourhood statistics, EQAO and Fraser Institute school ratings) to enrich listings. These do not contain your personal information.
  • Legal and safety. We may disclose information when required by law, court order, or to protect users from imminent harm. We will challenge requests that appear overbroad or unlawful where reasonably possible.
  • Corporate transactions. If Convass is acquired or merged, personal information may transfer to the successor under the same protections set out here. We will notify users in advance.

06. International data transfers

Convass is hosted primarily in Canada. Some service providers (e.g. email, error monitoring) may store or process data in the United States or other jurisdictions. Where that occurs, we rely on provider contracts that incorporate substantially equivalent privacy safeguards. Your information remains subject to lawful access laws of any country where it is stored, and we will not weaken your privacy rights by transferring data outside Canada.

07. Cookies, analytics, and tracking

We use a small set of cookies and similar technologies.

  • Strictly necessary. Authentication, session integrity, CSRF protection. These cannot be disabled if you want to use the site while signed in.
  • Preferences. Saved searches, comparison shelf, recently viewed listings, cookie consent state. Stored in your browser's local storage where possible to reduce server-side persistence.
  • Analytics (opt-in). Product analytics (page views, feature usage) are loaded only after you grant consent in the cookie banner. We disable third-party session-recording features and IP-mask all events.
  • Error monitoring. Used to capture stack traces of unhandled errors. PII filtering is enabled and message bodies are not transmitted.

You can withdraw cookie consent at any time from the link in the footer or by clearing your browser's site data.

08. How we protect your information

We use industry-standard administrative, technical, and physical safeguards, including:

  • HTTPS / TLS on all traffic, HSTS preload, and modern TLS suites.
  • Passwords are stored only as one-way scrypt hashes with per-user salts.
  • Database access restricted via least-privilege roles and isolated network paths.
  • Rate-limited and audit-logged moderation and admin endpoints.
  • Routine dependency vulnerability scans and security headers (CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy).

No system is perfectly secure. If you discover a vulnerability, please contact [email protected]; we operate a good-faith coordinated-disclosure process.

09. Data retention

  • Active accounts: while your account remains open.
  • Inactive accounts (no sign-in for 24 months): may be soft-deleted after notice.
  • Listings: retained while published and for up to 36 months after delisting to support analytics on sold/rented history (address obfuscated for delisted records).
  • Messages: retained while either participant account is active; participants may request individual-message deletion.
  • Logs and security events: typically 90 days.
  • Financial / tax records: retained as required by Canadian tax law (typically 7 years).

When you delete your account, identifying fields are removed and retained content is irreversibly anonymized within 30 days, except where retention is required by law or to resolve an open dispute.

10. Your rights

Subject to applicable Canadian law, you have the right to:

  • access the personal information we hold about you;
  • correct inaccurate or incomplete information;
  • request deletion ("right to be forgotten") where retention is not legally required;
  • withdraw consent for optional processing (analytics, marketing, precise location);
  • export a machine-readable copy of your account data;
  • object to certain types of processing and ask for human review.

To exercise any of these rights, email [email protected] from the address on file. We will verify your identity before acting and respond within 30 days. If we cannot fulfil a request we will explain why.

You also have the right to complain to the Office of the Privacy Commissioner of Canada or your provincial privacy regulator.

11. Children

Convass is intended for adults aged 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact [email protected] and we will delete it promptly.

12. Third-party content and links

Convass surfaces school ratings, walk and transit scores, neighbourhood statistics, mortgage rates, and other data sourced from third parties under public-data or commercial licences. These are provided for informational purposes only and are not independently verified by Convass. The privacy policies of any external sites we link to are governed by those sites' own terms.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced at least 14 days in advance by email to verified addresses and by a banner on the site. The "Effective date" at the top of this page reflects the latest version. Continued use of Convass after a change indicates acceptance of the updated policy.