DRAFT FOR COUNSEL REVIEW. Placeholders throughout. Counsel edits this file directly and MUST bump the `Version:` line above — the version is recorded with every consent in `lt_consents`.
Volora Lite — Privacy Policy
Last updated: September 1, 2026 · Version 2026-09-01
This policy explains what Volora Lite collects, why, and your rights under PIPEDA. It covers realtor and client accounts on lite.volora.io.
1. What we collect
Account details (name, email, phone, brokerage, RECO number, board), verification evidence you submit, content you upload (MLS sheets, photos), the documents you generate, messages you send on the platform, billing records (handled by Stripe — we never store card numbers), and product usage events. Usage analytics are recorded without personal information — events carry internal identifiers and enums only, never names, emails or property addresses. [PLACEHOLDER — counsel: full inventory table.]
2. Why we collect it
To run your account, verify registrant status (a legal/professional obligation), produce the reports you request, process payments, keep the service safe (rate limiting, abuse prevention — including a Cloudflare Turnstile check at signup), and improve the product. We do not sell personal information. [PLACEHOLDER — counsel: purposes/consent mapping.]
3. Where your data lives
Your data is stored with our processor Supabase in the AWS ca-central-1 (Montréal, Canada) region. Payment data is processed by Stripe. Report-generation AI processing is performed by Anthropic as a processor on the minimum content needed for the report you requested. [PLACEHOLDER — counsel: processor list with locations and safeguards.]
4. MLS data uploaded by realtors
MLS sheets and comparable data are uploaded by the realtor, on the realtor's behalf, and are stored only inside that realtor's account and the reports generated from them. They are never pooled across accounts or used to build a public database.
5. Retention
Verification evidence is deleted 30 days after a decision. Usage events are pruned after 12 months. Uploads and documents live as long as your account does. Billing and audit records are kept as long as the law requires. [PLACEHOLDER — counsel: retention schedule.]
6. Your rights (access, correction, deletion)
You can access and correct your information in Settings, export your data by contacting us, and delete your account from Settings — deletion removes your uploads, ends connections, anonymizes chat for counterparties and cancels billing, subject to records we must keep. Complaints: you can reach the Office of the Privacy Commissioner of Canada. [PLACEHOLDER — counsel: request process and timelines.]
7. Safeguards
Row-level security on every table, encrypted transport and storage, private-by-default file buckets behind signed URLs, mandatory multi-factor authentication for administrators, append-only audit logs of admin actions, and rate limits throughout. [PLACEHOLDER — counsel: safeguards summary appropriate to publish.]
8. Contact
Privacy officer: [PLACEHOLDER — name, email, mailing address].