Privacy Policy
Last updated: July 2, 2026
1. Who we are
Maintaire (“we”, “us”) is operated by North Refrigeration Inc., [FILL IN: STREET ADDRESS, CITY], Ontario, Canada. This policy explains how we collect, use, disclose, and protect personal information when you use our website and field-service management application (the “Service”).
Privacy Officer: [FILL IN: NAME], [FILL IN: TITLE, e.g. Founder & Privacy Officer] — privacy@maintaire.com. Contact them with any privacy question or request.
2. What we collect
- Account information: name, email, phone, company name, role, and password (stored only as a salted hash).
- Customer records you enter: your clients’ names, addresses, contact details, site and equipment information, job notes, photos, and documents. You control this data; we process it only to provide the Service (see Section 10).
- Customer portal accounts: if your service provider invites you to their customer portal, we collect your name, email, and password hash to operate your login.
- Electronic signatures: when someone signs an agreement or authorizes a payment through the Service, we record the signer’s name, the drawn signature image, the IP address, and a timestamp as an audit trail of the signature.
- Payment information: processed by Stripe. We never receive or store card numbers — only a payment token, card brand, and last four digits.
- Sensor telemetry: temperature readings and device status from monitoring hardware your organization installs. This is equipment data, not personal data, but site names and locations you assign to sensors are stored with it.
- Usage and device data: IP address, browser/device type, and security logs (e.g., sign-in attempts, rate limiting), used to protect and operate the Service.
- Communications: support messages and emails you send us.
We do not collect GPS or location data from workers’ devices, and we do not use advertising trackers.
3. How we use it
To provide and secure the Service; set up and manage accounts; process billing; provide support; send service notices (receipts, verification emails, alerts you configure); improve features; and, only with your express consent, send marketing emails. We do not sell personal information, we do not use your data to train AI models, and we do not use your data for advertising.
4. AI equipment assistant
The equipment assistant sends your question and relevant excerpts of the equipment manuals in your catalog to our AI provider, Anthropic, to generate an answer. This content is used solely to answer your question and is not used to train AI models. Don’t include personal information in assistant questions — it isn’t needed to answer them.
5. Legal bases and consent
We collect, use, and disclose personal information with your consent or as permitted or required by law (PIPEDA and, for Quebec residents, the Act respecting the protection of personal information in the private sector as amended by Law 25). You may withdraw consent at any time (subject to legal or contractual restrictions) by contacting the Privacy Officer; withdrawal may limit features that depend on that data.
6. Cookies and tracking
We currently use only strictly necessary cookies (login sessions and security) — no analytics or advertising cookies. See the Cookie Policy for the full list. If we ever add optional cookies, they will be off by default with a real accept/reject choice.
7. When we share information
- Service providers (subprocessors): payment processing (Stripe), cloud hosting (Render), transactional email ([FILL IN: TRANSACTIONAL EMAIL PROVIDER, e.g. Resend / SES]), and our AI provider (Anthropic). Each is bound by contract to protect your data and use it only to serve us. Current list: /legal/subprocessors.
- Your organization: if you use Maintaire through an employer or service-provider account, that workspace’s admins can see data created in the workspace.
- Shared document links: when your service provider emails you an invoice, report, or signing link, the document is reachable by anyone holding that unique link, without a login. Links use long random tokens and can be revoked.
- Integrations you enable: if your organization connects a third-party integration (for example, accounting software), the data needed for that integration is shared with that provider under its own privacy policy.
- Legal requirements: courts, regulators, or law enforcement where required by law.
- Business transfer: in a merger or sale, subject to this policy’s protections.
8. Where your data is stored
Our servers are located in [FILL IN: Canada / the United States]. If stored outside your province or Canada, your information may be accessible to authorities in that jurisdiction under local law. For Quebec residents, we assess such transfers as required by Law 25.
9. How long we keep it
Active account data is kept while your account is open. After account closure we delete or anonymize personal information within 90 days, except records we must keep longer (e.g., financial/tax records for 6 years; breach records for 24 months; signed agreements and their signature audit trails for the retention period your organization requires).
10. Data entered about your clients
When our business customers enter their own clients’ or employees’ information into Maintaire, or invite them to the customer portal, we act as a service provider processing that data on the customer’s instructions under our Data Processing Agreement. The business customer is responsible for having the right to collect that information. If you believe a Maintaire customer has entered your information, contact them directly or reach our Privacy Officer for help.
11. How we protect it
Encryption in transit (TLS), password hashing (bcrypt), organization-level data isolation, role-based permissions, rate limiting on authentication endpoints, security headers, and logging of administrative actions. No system is perfectly secure; if a breach creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada (and the CAI for Quebec residents) as required by law. See our security page for details.
12. Your rights
You may request access to your personal information, correction of inaccuracies, deletion (where the law allows), a copy in a portable format, and information about how your data has been used or disclosed. Send requests to the Privacy Officer; we respond within 30 days. If unsatisfied, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d’accès à l’information (cai.gouv.qc.ca).
13. Children
The Service is for business use and not directed to individuals under 18. We do not knowingly collect children’s information.
14. Changes
We’ll post updates here and, for material changes, notify you by email or in-app at least 30 days before they take effect.