← Back to Snapshot Listing Reports

Privacy Policy

Effective October 7, 2026

1. Who We Are

Snapshot Listing Reports is operated by Heizmann Technologies Inc., a British Columbia corporation. This policy explains how we collect, use, disclose, and protect your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), the BC Personal Information Protection Act (PIPA), Canada's Anti-Spam Legislation (CASL), and applicable provincial legislation.

2. Information We Collect

Account informationFull name, email address, password (hashed by Firebase)You provide at registration
Consent recordsIP address, consent method, consent version, timestamp — captured at signup and when toggling marketing preferencesCollected automatically for CASL compliance
Profile & brandingPhone, website, headshot, brokerage logo, banner image, brand colors, report template, conclusion textYou provide in settings
Property listingsAddress, MLS number, list price, dates, platform URLs, listing typeYou provide when adding listings
Seller informationSeller name, seller phone number (optional) — this is your client’s personal informationYou provide
Uploaded imagesScreenshots of platform listings, showing notification emails, comparable property imagesYou upload into the report wizard
Browser-extension capturesCropped PNG images of regions you explicitly select; the URL of the page you captured from (stored on the capture record for your own reference, never shared); platform name, listing ID, reporting period, and capture timestampCreated by you when you use the optional browser extension — see Section 15
AI-extracted dataTraffic metrics (views, clicks, reach), showing details (buyer agent name, brokerage, date/time, feedback)Extracted by AI from your uploaded images
Report dataCompiled traffic statistics, showing logs, price changes, comparable notes, AI-generated narrativeGenerated by the Service from data you provide
Payment informationPayment card data is collected directly by Stripe — we never see or store your card numbersCollected by Stripe at checkout
Usage & analyticsPages viewed, performance metrics, custom events (e.g. report generated, listing created)Collected automatically by Vercel Analytics and PostHog (if you consent)
Diagnostic dataEmail address, page URL, browser type, screen size, error details; session replay recordings only if you accept analytics cookiesCollected automatically via Sentry when errors occur (see Section 12)
Referral dataYour referral code, referred user’s emailGenerated at signup

3. How We Use Your Information

  • Account & profile: To authenticate you, provide the Service, and display your branding on reports and share pages
  • Consent records: To demonstrate CASL compliance and respond to regulatory inquiries
  • Listings & seller info: To generate reports for your properties; seller info is included in reports at your direction
  • Uploaded images: To extract traffic metrics and showing data using AI; to include in reports
  • Browser-extension captures: To pre-attach screenshots to the right listing and reporting period so they appear automatically in the report wizard; AI metric extraction runs only after you click "Import your Snapshots" in the wizard, never at capture time
  • AI-extracted data: To pre-fill report fields for your review; to generate closing narrative paragraphs
  • Payment info: Processed by Stripe to manage your subscription (we do not store card data)
  • Usage analytics: To understand how the Service is used and improve it (only with your consent)
  • Diagnostic data: To identify, diagnose, and fix technical issues (see Section 12)
  • Referral data: To administer the referral program and credit rewards

4. AI Processing Disclosure

The Service uses Anthropic's Claude API (an artificial intelligence system) to:

  • Extract traffic metrics (views, clicks, etc.) from screenshots you upload
  • Parse showing notification details from screenshots you upload
  • Read listing details (address, MLS® number, prices, listing date) from listing text you paste into Quick fill
  • Generate closing narrative paragraphs for your reports

Your uploaded images, any listing text you paste, and associated data are transmitted to Anthropic PBC in the United States for processing. Anthropic retains API inputs for up to 30 days for safety and abuse monitoring. Anthropic does not use your data to train their AI models (per their API terms as of March 2026).

AI requests are rate-limited (up to 30 per minute per feature, plus a daily limit per account). Maximum payload size is 5 MB per image. AI outputs are estimates and may contain errors — you are responsible for reviewing all AI-generated content before use. You can avoid AI processing entirely by manually entering all data.

5. Third-Party Service Providers

We share your information with the following processors:

Google Cloud (Firebase)All account data, listings, reports, uploaded imagesAuthentication, database, file storageUS or Canada
StripePayment card data (directly), email, subscription recordsPayment processing, subscription managementUS (Canadian operations)
AnthropicUploaded screenshots, pasted listing text, property addresses, agent names, traffic metricsAI-powered metric extraction, showing parsing, narrative generationUnited States
VercelPage view data, performance metrics, application logsHosting and analyticsUnited States
SentryError messages, page URLs, browser type, screen size, email address, session replay recordingsError tracking and diagnostics (see Section 12)United States
PostHogUser ID, page views, custom events (if you consent to analytics)Product analyticsUnited States
ResendEmail addresses, transactional email content (welcome, password reset, alerts)Transactional email deliveryUnited States
UpstashRequest metadata (user ID, IP hash)API rate limitingUnited States

We do not sell, rent, or trade your personal information to any third party for marketing purposes.

6. Cross-Border Data Transfers

Your data is transferred to and processed in the United States through our service providers (Vercel, Stripe, Anthropic, Sentry, PostHog, Resend, Upstash, and potentially Google Cloud). Under PIPEDA, we remain accountable for your personal information when it is transferred to processors outside Canada. We ensure that our providers maintain comparable privacy protections through their standard contractual terms and data processing agreements.

7. Consent & CASL Compliance

At registration, we capture your express consent to our Terms of Service and this Privacy Policy. We record the following for CASL compliance:

  • Your IP address at the time of consent
  • The consent method (e.g. "signup_form" or "settings_toggle")
  • The consent version (currently v1.0)
  • A timestamp of when consent was given

Marketing emails: You may opt in to marketing communications at any time in your account settings. You may withdraw marketing consent at any time via Settings. Transactional emails (account confirmations, password resets, billing notifications) do not require marketing consent and will continue to be sent as necessary to operate your account.

8. Data Retention

  • Account data: Retained for as long as your account is active, plus 90 days after deletion to allow for reactivation or data export
  • Listings, reports, uploaded images: Retained for the duration of your account; deleted upon account deletion
  • Exit-survey contact information: When you delete your account or your subscription is canceled, we retain your name and email address for up to 6 months to send a single optional message asking why you left. We will not contact you if you previously declined marketing communications at signup. This data is never used for marketing, never shared with third parties, and is automatically redacted after 6 months — or sooner if you request removal by emailing support@snapshotlistingreports.ca. Anonymized records (plan tier and date) are preserved for long-term churn analytics
  • Browser-extension captures (unattached): Automatically deleted within about 3 days of upload (never sooner than 48 hours) if not attached to a Report
  • Browser-extension captures (attached to a Report): Retained for the same lifetime as the Report they were attached to
  • Payment records: Retained by Stripe per their policies; we retain subscription status records for 7 years per CRA requirements
  • Diagnostic data: Automatically purged 90 days after the error is resolved
  • Session replays: Retained by Sentry for 90 days, then automatically deleted
  • Share link tokens: Expire after 30 days; report documents persist until account deletion
  • Referral data: Retained for the duration of both parties' accounts
  • Consent records: Retained for the duration of your account plus 3 years, as recommended under CASL

9. Data Security

  • All data in transit is encrypted using HTTPS/TLS
  • Database access controlled by Firebase security rules restricting data to the owning user
  • Passwords hashed by Firebase Auth using industry-standard algorithms
  • Payment card data handled exclusively by Stripe (PCI DSS Level 1 compliant)
  • API keys stored as environment variables, never in source code
  • API endpoints protected by per-user rate limiting (Upstash Redis)
  • Administrative access restricted to authorized Heizmann Technologies Inc. personnel only

No system is 100% secure; we cannot guarantee absolute security.

10. Your Rights Under PIPEDA & PIPA

You have the right to:

  • Access: Request a copy of the personal information we hold about you — use the data export feature in Settings to download a JSON file of all your data
  • Correct: Edit your profile, listings, and branding at any time through the Service
  • Delete: Delete your account and all associated data through Settings (requires password confirmation)
  • Withdraw consent: You may stop using the Service at any time; withdrawing consent may affect our ability to provide the Service

To exercise any of these rights, contact us at support@snapshotlistingreports.ca. We will respond within 30 days.

11. Account Deletion

You may delete your account through your account Settings. Deletion requires password re-authentication. Upon deletion, we will: delete your account, profile, and branding data; delete your listings, reports, and uploaded images; revoke all active share links; delete your Firebase Auth account; and request deletion from third-party processors where feasible. Some data may be retained where required by law (e.g., financial records for tax purposes, consent records under CASL). Deletion is completed within 30 days.

One exception: we retain your name and email address for up to 6 months following deletion for the sole purpose of one optional exit-survey contact, subject to your marketing-email preferences and your right to withdraw at any time by emailing support@snapshotlistingreports.ca. See the Data Retention section above for details.

12. Cookies, Tracking Technologies & Session Replay

Essential cookies: Used for authentication session management (Firebase Auth). These are necessary for the Service to function and cannot be disabled.

Browser-extension local storage: If you install the optional browser extension, it uses chrome.storage.local (in Chrome) or the equivalent extension storage API (in Firefox) to store your Firebase Auth tokens and your most-recent listing/period selection. This data lives only inside the extension on your computer, is never transmitted to us beyond what is needed to authenticate API calls, and is cleared automatically when you sign out of the extension or uninstall it. See Section 15 for full details.

Analytics (optional, consent-gated): If you accept analytics cookies, we load:

  • Vercel Analytics: Anonymized page view and performance data
  • Vercel Speed Insights: Core Web Vitals and page load times
  • PostHog: Custom event tracking (e.g. report generated, listing created) — only for identified users, no autocapture
  • Sentry session replay: A recording of a sample of browser sessions, used to diagnose and fix technical issues (see below)

No advertising, behavioural tracking, or cross-site tracking cookies are used. You may accept or decline analytics cookies through the cookie consent banner displayed on your first visit. If you decline, no analytics data is collected by Vercel or PostHog, and Sentry does not record session replays. You can change your preference at any time via the "Cookie Settings" link in the site footer.

Session replay (optional, consent-gated): Only if you accept analytics cookies, Sentry may record a replay of your browser session, including the moments leading up to a technical error (see Section 13). Replays are captured for about 30% of sessions in which an error occurs and 10% of other sessions (in production only). Replays help us diagnose and fix technical issues. Replay data is retained for 90 days and is accessible only to administrators.

13. Error Tracking & Diagnostic Data

When a technical error occurs in your browser while using the Service, we automatically collect diagnostic information through two systems:

Client-side error capture (Firestore):

  • Your email address, the page URL, browser type (user agent), screen dimensions, the error message, and a technical stack trace
  • A maximum of 50 error events are captured per browser session, with a 5-minute deduplication window
  • Fatal errors trigger an email alert to administrators
  • Data is automatically deleted 90 days after resolution and is accessible only to administrators

Sentry (third-party):

  • Error details, stack traces, page URLs, browser metadata
  • Session replay recordings (visual playback of browser activity leading to errors), only if you accept analytics cookies
  • Performance traces (sampled at 20% of requests)
  • Production environment only — disabled during development
  • Data retained per Sentry's retention policies (typically 90 days)

This diagnostic data is used solely to identify, diagnose, and resolve technical issues.

14. Share Link Privacy

Share links are available on the Pro plan only. When you share a report via a share link, the following becomes publicly accessible to anyone with the URL: property address, traffic statistics, showing count, price changes, your name, phone, email, website, headshot, brokerage logo, and a downloadable PDF containing full report details (including buyer agent names, agencies, showing feedback, and AI-generated narrative). We track view count only — we do not collect personal information about share link visitors. Share links expire after 30 days.

15. Browser Extension Privacy

The Service includes an optional browser extension ("Snapshot Listing Reports — Capture Extension") available for Google Chrome and Mozilla Firefox. The extension lets you capture a region of any page you are viewing and upload it directly into your Snapshot Listing Reports account, where it is filed under a specific listing and reporting period for later use in a Report. The extension is free with every paid plan and is entirely optional — the Service works fully without it.

What the extension does:

  • Captures only the screen region you explicitly drag-select after clicking "Take a Snapshot" in the extension popup
  • Uploads the cropped image (PNG format) directly to your own Snapshot Listing Reports account on the same Firebase infrastructure that powers the web app
  • Records metadata for each capture: the listing it belongs to, the reporting period, the platform name (e.g. "Realtor.ca"), the capture timestamp, and the URL of the page from which you captured

What the extension does NOT do:

  • It does not read the contents of pages you visit
  • It does not log, transmit, or store the URLs of pages you visit, except the URL of the specific page at the moment you click "Take a Snapshot"
  • It does not scrape data, extract DOM contents, or run automation against any third-party site
  • It does not share any data with advertisers, marketing networks, or any party outside your own Snapshot Listing Reports account
  • It does not auto-capture, run in the background, or take any action without your explicit click
  • It does not sell, rent, or transfer your data to any third party

Data stored locally in your browser (via the extension's storage API):

  • Your Snapshot Listing Reports authentication tokens (Firebase ID token + refresh token) — used to identify you to your account
  • The listing and reporting period you most recently selected — so you do not have to re-pick them after each capture
  • The platform and capture type you most recently used — for convenience
  • A short queue of any captures that failed to upload due to network loss, retried automatically once you are back online

This data lives only inside the extension on your computer and is cleared automatically when you sign out of the extension or uninstall it.

Data stored on Snapshot Listing Reports servers (Firebase, same infrastructure as the web app — see Sections 5 and 6):

  • The cropped PNG image — stored at the Firebase Storage path pendingCaptures/{your-user-id}/{listing-id}/{capture-id}.png and accessible only to you, enforced by Firebase Storage security rules
  • The capture metadata listed above — stored in Firestore under the listing's pendingCaptures subcollection, accessible only to you, enforced by Firestore security rules
  • The captured page URL (source_url) is stored on the capture record solely for your own reference inside your account. It is never displayed publicly, never shared with any third party, and never included in any Report or share link.

Permissions the extension requests, and why:

activeTabRequired so the extension can take a screenshot of the page you are currently viewing — only when you click the extension button. The extension cannot access any other tab without an additional, explicit click.
storageRequired to remember your sign-in session and your most-recent listing / period / platform selections so they persist between captures.
notificationsRequired to confirm a successful upload to you with a desktop notification, useful when you have switched tabs away from the page you captured.
scriptingRequired to inject the drag-rectangle overlay onto the page you are capturing, so you can select a region with your mouse.
Google API host permissionsRequired so the extension can authenticate against your account and upload captures via Firebase. The only network endpoints the extension contacts are identitytoolkit.googleapis.com, securetoken.googleapis.com, firestore.googleapis.com, firebasestorage.googleapis.com, and snapshotlistingreports.ca.

Retention of extension data:

  • A capture that is not yet attached to a Report is automatically deleted within about 3 days of upload (never sooner than 48 hours), to prevent abandoned captures from accumulating
  • A capture that has been attached to a Report is retained for the same lifetime as the Report itself (see Section 8)
  • The local browser-storage data (auth tokens, last-used context) is cleared automatically on extension sign-out or uninstall

Your rights and controls over extension data:

  • View your captures: the /settings/extension page in the web app shows every capture with a thumbnail; click any thumbnail to see it full-size
  • Delete a capture: click the delete button on any capture from /settings/extension, or click "Undo" on the in-page toast within 30 seconds of capturing
  • Sign out of the extension: click "Sign out" in the extension popup; this clears your session locally without affecting the web app
  • Uninstall the extension: removing the extension from Chrome or Firefox clears all local extension data automatically. Captures already uploaded remain in your Snapshot Listing Reports account until you delete them or your account
  • Stop using the extension at any time: the web app and all manual upload flows continue to work without it

Legal nature of the extension: The extension is a screen-capture tool, analogous to your operating system's built-in screenshot feature (e.g. Windows Snipping Tool, macOS Shift-Cmd-4). It captures only what you can already see on your own screen, in your own active browser session, and at the moment you click capture. It does not log into any third-party platform on your behalf, does not access any third-party platform data outside of what is rendered in your current browser tab, and does not constitute automated access to any third-party service under Heizmann Technologies Inc.'s interpretation of Canadian law (including the Criminal Code, the Personal Information Protection and Electronic Documents Act (PIPEDA), and applicable provincial privacy legislation). You remain bound by the terms of service of any third-party site you capture from; the extension does not negotiate or override those terms.

16. Children's Privacy

The Service is intended for licensed real estate professionals and is not directed at individuals under 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from a person under 18, we will delete it promptly.

17. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email at least 30 days before they take effect. The effective date at the top of this policy will be updated with each revision.

18. Breach Notification

In the event of a breach of security safeguards involving personal information that poses a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as required by PIPEDA. Where applicable, we will also notify the BC Information and Privacy Commissioner under PIPA. Where personal information is stored or processed outside Canada (see Section 6), our notification will include that fact. We will also maintain a record of all breaches for a minimum of 24 months, as required by law.

19. Regional Availability

The Service is not currently available in the Province of Quebec due to French-language and regulatory requirements. We do not knowingly collect data from Quebec residents through the Service. If you are located in Quebec and have inadvertently registered, please contact us to request account deletion.

20. Contact & Complaints

For privacy inquiries, data access requests, or complaints:

Privacy Officer: Kalvin Heizmann, Founder & CEO

Mailing Address: 3910 21A Ave, Vernon, BC, V1T 7T4, Canada

Email: support@snapshotlistingreports.ca

We will acknowledge your inquiry within 5 business days and provide a substantive response within 30 days, as required by PIPEDA. If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca or the BC Office of the Information and Privacy Commissioner at oipc.bc.ca.