Privacy Policy
Effective October 7, 2026
1. Who We Are
Snapshot Listing Reports is operated by Heizmann Technologies Inc., a British Columbia corporation. This policy explains how we collect, use, disclose, and protect your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), the BC Personal Information Protection Act (PIPA), Canada's Anti-Spam Legislation (CASL), and applicable provincial legislation.
2. Information We Collect
| Account information | Full name, email address, password (hashed by Firebase) | You provide at registration |
| Consent records | IP address, consent method, consent version, timestamp — captured at signup and when toggling marketing preferences | Collected automatically for CASL compliance |
| Profile & branding | Phone, website, headshot, brokerage logo, banner image, brand colors, report template, conclusion text | You provide in settings |
| Property listings | Address, MLS number, list price, dates, platform URLs, listing type | You provide when adding listings |
| Seller information | Seller name, seller phone number (optional) — this is your client’s personal information | You provide |
| Uploaded images | Screenshots of platform listings, showing notification emails, comparable property images | You upload into the report wizard |
| Browser-extension captures | Cropped PNG images of regions you explicitly select; the URL of the page you captured from (stored on the capture record for your own reference, never shared); platform name, listing ID, reporting period, and capture timestamp | Created by you when you use the optional browser extension — see Section 15 |
| AI-extracted data | Traffic metrics (views, clicks, reach), showing details (buyer agent name, brokerage, date/time, feedback) | Extracted by AI from your uploaded images |
| Report data | Compiled traffic statistics, showing logs, price changes, comparable notes, AI-generated narrative | Generated by the Service from data you provide |
| Payment information | Payment card data is collected directly by Stripe — we never see or store your card numbers | Collected by Stripe at checkout |
| Usage & analytics | Pages viewed, performance metrics, custom events (e.g. report generated, listing created) | Collected automatically by Vercel Analytics and PostHog (if you consent) |
| Diagnostic data | Email address, page URL, browser type, screen size, error details; session replay recordings only if you accept analytics cookies | Collected automatically via Sentry when errors occur (see Section 12) |
| Referral data | Your referral code, referred user’s email | Generated at signup |
3. How We Use Your Information
- Account & profile: To authenticate you, provide the Service, and display your branding on reports and share pages
- Consent records: To demonstrate CASL compliance and respond to regulatory inquiries
- Listings & seller info: To generate reports for your properties; seller info is included in reports at your direction
- Uploaded images: To extract traffic metrics and showing data using AI; to include in reports
- Browser-extension captures: To pre-attach screenshots to the right listing and reporting period so they appear automatically in the report wizard; AI metric extraction runs only after you click "Import your Snapshots" in the wizard, never at capture time
- AI-extracted data: To pre-fill report fields for your review; to generate closing narrative paragraphs
- Payment info: Processed by Stripe to manage your subscription (we do not store card data)
- Usage analytics: To understand how the Service is used and improve it (only with your consent)
- Diagnostic data: To identify, diagnose, and fix technical issues (see Section 12)
- Referral data: To administer the referral program and credit rewards
4. AI Processing Disclosure
The Service uses Anthropic's Claude API (an artificial intelligence system) to:
- Extract traffic metrics (views, clicks, etc.) from screenshots you upload
- Parse showing notification details from screenshots you upload
- Read listing details (address, MLS® number, prices, listing date) from listing text you paste into Quick fill
- Generate closing narrative paragraphs for your reports
Your uploaded images, any listing text you paste, and associated data are transmitted to Anthropic PBC in the United States for processing. Anthropic retains API inputs for up to 30 days for safety and abuse monitoring. Anthropic does not use your data to train their AI models (per their API terms as of March 2026).
AI requests are rate-limited (up to 30 per minute per feature, plus a daily limit per account). Maximum payload size is 5 MB per image. AI outputs are estimates and may contain errors — you are responsible for reviewing all AI-generated content before use. You can avoid AI processing entirely by manually entering all data.
5. Third-Party Service Providers
We share your information with the following processors:
| Google Cloud (Firebase) | All account data, listings, reports, uploaded images | Authentication, database, file storage | US or Canada |
| Stripe | Payment card data (directly), email, subscription records | Payment processing, subscription management | US (Canadian operations) |
| Anthropic | Uploaded screenshots, pasted listing text, property addresses, agent names, traffic metrics | AI-powered metric extraction, showing parsing, narrative generation | United States |
| Vercel | Page view data, performance metrics, application logs | Hosting and analytics | United States |
| Sentry | Error messages, page URLs, browser type, screen size, email address, session replay recordings | Error tracking and diagnostics (see Section 12) | United States |
| PostHog | User ID, page views, custom events (if you consent to analytics) | Product analytics | United States |
| Resend | Email addresses, transactional email content (welcome, password reset, alerts) | Transactional email delivery | United States |
| Upstash | Request metadata (user ID, IP hash) | API rate limiting | United States |
We do not sell, rent, or trade your personal information to any third party for marketing purposes.
6. Cross-Border Data Transfers
Your data is transferred to and processed in the United States through our service providers (Vercel, Stripe, Anthropic, Sentry, PostHog, Resend, Upstash, and potentially Google Cloud). Under PIPEDA, we remain accountable for your personal information when it is transferred to processors outside Canada. We ensure that our providers maintain comparable privacy protections through their standard contractual terms and data processing agreements.
7. Consent & CASL Compliance
At registration, we capture your express consent to our Terms of Service and this Privacy Policy. We record the following for CASL compliance:
- Your IP address at the time of consent
- The consent method (e.g. "signup_form" or "settings_toggle")
- The consent version (currently v1.0)
- A timestamp of when consent was given
Marketing emails: You may opt in to marketing communications at any time in your account settings. You may withdraw marketing consent at any time via Settings. Transactional emails (account confirmations, password resets, billing notifications) do not require marketing consent and will continue to be sent as necessary to operate your account.
8. Data Retention
- Account data: Retained for as long as your account is active, plus 90 days after deletion to allow for reactivation or data export
- Listings, reports, uploaded images: Retained for the duration of your account; deleted upon account deletion
- Exit-survey contact information: When you delete your account or your subscription is canceled, we retain your name and email address for up to 6 months to send a single optional message asking why you left. We will not contact you if you previously declined marketing communications at signup. This data is never used for marketing, never shared with third parties, and is automatically redacted after 6 months — or sooner if you request removal by emailing support@snapshotlistingreports.ca. Anonymized records (plan tier and date) are preserved for long-term churn analytics
- Browser-extension captures (unattached): Automatically deleted within about 3 days of upload (never sooner than 48 hours) if not attached to a Report
- Browser-extension captures (attached to a Report): Retained for the same lifetime as the Report they were attached to
- Payment records: Retained by Stripe per their policies; we retain subscription status records for 7 years per CRA requirements
- Diagnostic data: Automatically purged 90 days after the error is resolved
- Session replays: Retained by Sentry for 90 days, then automatically deleted
- Share link tokens: Expire after 30 days; report documents persist until account deletion
- Referral data: Retained for the duration of both parties' accounts
- Consent records: Retained for the duration of your account plus 3 years, as recommended under CASL
9. Data Security
- All data in transit is encrypted using HTTPS/TLS
- Database access controlled by Firebase security rules restricting data to the owning user
- Passwords hashed by Firebase Auth using industry-standard algorithms
- Payment card data handled exclusively by Stripe (PCI DSS Level 1 compliant)
- API keys stored as environment variables, never in source code
- API endpoints protected by per-user rate limiting (Upstash Redis)
- Administrative access restricted to authorized Heizmann Technologies Inc. personnel only
No system is 100% secure; we cannot guarantee absolute security.
10. Your Rights Under PIPEDA & PIPA
You have the right to:
- Access: Request a copy of the personal information we hold about you — use the data export feature in Settings to download a JSON file of all your data
- Correct: Edit your profile, listings, and branding at any time through the Service
- Delete: Delete your account and all associated data through Settings (requires password confirmation)
- Withdraw consent: You may stop using the Service at any time; withdrawing consent may affect our ability to provide the Service
To exercise any of these rights, contact us at support@snapshotlistingreports.ca. We will respond within 30 days.
11. Account Deletion
You may delete your account through your account Settings. Deletion requires password re-authentication. Upon deletion, we will: delete your account, profile, and branding data; delete your listings, reports, and uploaded images; revoke all active share links; delete your Firebase Auth account; and request deletion from third-party processors where feasible. Some data may be retained where required by law (e.g., financial records for tax purposes, consent records under CASL). Deletion is completed within 30 days.
One exception: we retain your name and email address for up to 6 months following deletion for the sole purpose of one optional exit-survey contact, subject to your marketing-email preferences and your right to withdraw at any time by emailing support@snapshotlistingreports.ca. See the Data Retention section above for details.
12. Cookies, Tracking Technologies & Session Replay
Essential cookies: Used for authentication session management (Firebase Auth). These are necessary for the Service to function and cannot be disabled.
Browser-extension local storage: If you install the optional browser extension, it uses chrome.storage.local (in Chrome) or the equivalent extension storage API (in Firefox) to store your Firebase Auth tokens and your most-recent listing/period selection. This data lives only inside the extension on your computer, is never transmitted to us beyond what is needed to authenticate API calls, and is cleared automatically when you sign out of the extension or uninstall it. See Section 15 for full details.
Analytics (optional, consent-gated): If you accept analytics cookies, we load:
- Vercel Analytics: Anonymized page view and performance data
- Vercel Speed Insights: Core Web Vitals and page load times
- PostHog: Custom event tracking (e.g. report generated, listing created) — only for identified users, no autocapture
- Sentry session replay: A recording of a sample of browser sessions, used to diagnose and fix technical issues (see below)
No advertising, behavioural tracking, or cross-site tracking cookies are used. You may accept or decline analytics cookies through the cookie consent banner displayed on your first visit. If you decline, no analytics data is collected by Vercel or PostHog, and Sentry does not record session replays. You can change your preference at any time via the "Cookie Settings" link in the site footer.
Session replay (optional, consent-gated): Only if you accept analytics cookies, Sentry may record a replay of your browser session, including the moments leading up to a technical error (see Section 13). Replays are captured for about 30% of sessions in which an error occurs and 10% of other sessions (in production only). Replays help us diagnose and fix technical issues. Replay data is retained for 90 days and is accessible only to administrators.
13. Error Tracking & Diagnostic Data
When a technical error occurs in your browser while using the Service, we automatically collect diagnostic information through two systems:
Client-side error capture (Firestore):
- Your email address, the page URL, browser type (user agent), screen dimensions, the error message, and a technical stack trace
- A maximum of 50 error events are captured per browser session, with a 5-minute deduplication window
- Fatal errors trigger an email alert to administrators
- Data is automatically deleted 90 days after resolution and is accessible only to administrators
Sentry (third-party):
- Error details, stack traces, page URLs, browser metadata
- Session replay recordings (visual playback of browser activity leading to errors), only if you accept analytics cookies
- Performance traces (sampled at 20% of requests)
- Production environment only — disabled during development
- Data retained per Sentry's retention policies (typically 90 days)
This diagnostic data is used solely to identify, diagnose, and resolve technical issues.
14. Share Link Privacy
Share links are available on the Pro plan only. When you share a report via a share link, the following becomes publicly accessible to anyone with the URL: property address, traffic statistics, showing count, price changes, your name, phone, email, website, headshot, brokerage logo, and a downloadable PDF containing full report details (including buyer agent names, agencies, showing feedback, and AI-generated narrative). We track view count only — we do not collect personal information about share link visitors. Share links expire after 30 days.
15. Browser Extension Privacy
The Service includes an optional browser extension ("Snapshot Listing Reports — Capture Extension") available for Google Chrome and Mozilla Firefox. The extension lets you capture a region of any page you are viewing and upload it directly into your Snapshot Listing Reports account, where it is filed under a specific listing and reporting period for later use in a Report. The extension is free with every paid plan and is entirely optional — the Service works fully without it.
What the extension does:
- Captures only the screen region you explicitly drag-select after clicking "Take a Snapshot" in the extension popup
- Uploads the cropped image (PNG format) directly to your own Snapshot Listing Reports account on the same Firebase infrastructure that powers the web app
- Records metadata for each capture: the listing it belongs to, the reporting period, the platform name (e.g. "Realtor.ca"), the capture timestamp, and the URL of the page from which you captured
What the extension does NOT do:
- It does not read the contents of pages you visit
- It does not log, transmit, or store the URLs of pages you visit, except the URL of the specific page at the moment you click "Take a Snapshot"
- It does not scrape data, extract DOM contents, or run automation against any third-party site
- It does not share any data with advertisers, marketing networks, or any party outside your own Snapshot Listing Reports account
- It does not auto-capture, run in the background, or take any action without your explicit click
- It does not sell, rent, or transfer your data to any third party
Data stored locally in your browser (via the extension's storage API):
- Your Snapshot Listing Reports authentication tokens (Firebase ID token + refresh token) — used to identify you to your account
- The listing and reporting period you most recently selected — so you do not have to re-pick them after each capture
- The platform and capture type you most recently used — for convenience
- A short queue of any captures that failed to upload due to network loss, retried automatically once you are back online
This data lives only inside the extension on your computer and is cleared automatically when you sign out of the extension or uninstall it.
Data stored on Snapshot Listing Reports servers (Firebase, same infrastructure as the web app — see Sections 5 and 6):
- The cropped PNG image — stored at the Firebase Storage path
pendingCaptures/{your-user-id}/{listing-id}/{capture-id}.pngand accessible only to you, enforced by Firebase Storage security rules - The capture metadata listed above — stored in Firestore under the listing's
pendingCapturessubcollection, accessible only to you, enforced by Firestore security rules - The captured page URL (
source_url) is stored on the capture record solely for your own reference inside your account. It is never displayed publicly, never shared with any third party, and never included in any Report or share link.
Permissions the extension requests, and why:
| activeTab | Required so the extension can take a screenshot of the page you are currently viewing — only when you click the extension button. The extension cannot access any other tab without an additional, explicit click. |
| storage | Required to remember your sign-in session and your most-recent listing / period / platform selections so they persist between captures. |
| notifications | Required to confirm a successful upload to you with a desktop notification, useful when you have switched tabs away from the page you captured. |
| scripting | Required to inject the drag-rectangle overlay onto the page you are capturing, so you can select a region with your mouse. |
| Google API host permissions | Required so the extension can authenticate against your account and upload captures via Firebase. The only network endpoints the extension contacts are identitytoolkit.googleapis.com, securetoken.googleapis.com, firestore.googleapis.com, firebasestorage.googleapis.com, and snapshotlistingreports.ca. |
Retention of extension data:
- A capture that is not yet attached to a Report is automatically deleted within about 3 days of upload (never sooner than 48 hours), to prevent abandoned captures from accumulating
- A capture that has been attached to a Report is retained for the same lifetime as the Report itself (see Section 8)
- The local browser-storage data (auth tokens, last-used context) is cleared automatically on extension sign-out or uninstall
Your rights and controls over extension data:
- View your captures: the
/settings/extensionpage in the web app shows every capture with a thumbnail; click any thumbnail to see it full-size - Delete a capture: click the delete button on any capture from
/settings/extension, or click "Undo" on the in-page toast within 30 seconds of capturing - Sign out of the extension: click "Sign out" in the extension popup; this clears your session locally without affecting the web app
- Uninstall the extension: removing the extension from Chrome or Firefox clears all local extension data automatically. Captures already uploaded remain in your Snapshot Listing Reports account until you delete them or your account
- Stop using the extension at any time: the web app and all manual upload flows continue to work without it
Legal nature of the extension: The extension is a screen-capture tool, analogous to your operating system's built-in screenshot feature (e.g. Windows Snipping Tool, macOS Shift-Cmd-4). It captures only what you can already see on your own screen, in your own active browser session, and at the moment you click capture. It does not log into any third-party platform on your behalf, does not access any third-party platform data outside of what is rendered in your current browser tab, and does not constitute automated access to any third-party service under Heizmann Technologies Inc.'s interpretation of Canadian law (including the Criminal Code, the Personal Information Protection and Electronic Documents Act (PIPEDA), and applicable provincial privacy legislation). You remain bound by the terms of service of any third-party site you capture from; the extension does not negotiate or override those terms.
16. Children's Privacy
The Service is intended for licensed real estate professionals and is not directed at individuals under 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from a person under 18, we will delete it promptly.
17. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email at least 30 days before they take effect. The effective date at the top of this policy will be updated with each revision.
18. Breach Notification
In the event of a breach of security safeguards involving personal information that poses a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as required by PIPEDA. Where applicable, we will also notify the BC Information and Privacy Commissioner under PIPA. Where personal information is stored or processed outside Canada (see Section 6), our notification will include that fact. We will also maintain a record of all breaches for a minimum of 24 months, as required by law.
19. Regional Availability
The Service is not currently available in the Province of Quebec due to French-language and regulatory requirements. We do not knowingly collect data from Quebec residents through the Service. If you are located in Quebec and have inadvertently registered, please contact us to request account deletion.
20. Contact & Complaints
For privacy inquiries, data access requests, or complaints:
Privacy Officer: Kalvin Heizmann, Founder & CEO
Mailing Address: 3910 21A Ave, Vernon, BC, V1T 7T4, Canada
Email: support@snapshotlistingreports.ca
We will acknowledge your inquiry within 5 business days and provide a substantive response within 30 days, as required by PIPEDA. If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca or the BC Office of the Information and Privacy Commissioner at oipc.bc.ca.