Skip to main content

Privacy Policy

Last updated: March 2026

Introduction

CivilProposal is operated by Lifesaver Technology Services Inc. ("we," "our," or "us"), a British Columbia, Canada corporation. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use CivilProposal (sourced civil site scoping intelligence and proposal drafts for Canadian civil engineering firms). Some infrastructure providers we use may process or store data outside Canada. See the Data Storage Location and International Data Transfers sections below.

We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA), as applicable. Lifesaver Technology Services Inc. is accountable for personal information under its control and has designated a privacy contact at [email protected]. Our company-wide privacy practices are described in the Lifesaver Privacy Policy; this page describes CivilProposal-specific collection and subprocessors.

Marketing Communications (CASL)

We may send transactional emails about your account, security, billing, and service operation without additional consent. Promotional or marketing emails about CivilProposal or other Lifesaver products are sent only with consent where required under Canada's Anti-Spam Legislation (CASL). You may unsubscribe from marketing messages using the link in those emails or by contacting [email protected].

Information We Collect

Account Information

When you create an account, we collect your email address, name, and profile information provided through our authentication provider (Supabase Auth). Authentication records are currently stored in Supabase's Canada Central region.

User-Entered Content

We store the proposal data, project information, and content you create within the application. This includes client names, project details, proposal drafts, and related documents.

Usage Data

We collect information about how you interact with the service, including feature usage, timestamps, and error logs. This data is used to improve the service and diagnose technical issues.

How We Use Your Information

  • To provide, maintain, and improve our services
  • To process your requests and transactions
  • To communicate with you about your account and service updates
  • To ensure security and prevent fraud
  • To comply with legal obligations

Data Storage and Security

Your data is stored on secure servers using industry-standard encryption. We implement technical and organizational measures designed to protect your information from unauthorized access, loss, or alteration. However, no method of transmission over the internet or electronic storage is completely secure.

Data Storage Location

Our service infrastructure is split across Fly.io in Toronto and Supabase in Montreal (Canada Central). Certain subprocessors, including OpenAI, Stripe, PostHog, and Google Analytics, may process limited data in the United States.

We have implemented appropriate safeguards to protect your information in accordance with this Privacy Policy, including encryption in transit and at rest, access controls, and contractual protections with our service providers.

Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

  • With service providers who assist in operating our platform, subject to confidentiality agreements and data protection requirements:
    • Fly.io (Canada): application hosting and runtime infrastructure
    • Supabase (Canada): database storage and authentication. Supabase receives account and application data needed to operate the service.
    • OpenAI (US): generates proposal text under their API terms. Before transmission, identifying details are replaced with placeholder tokens on our servers, and real values are restored only in the final document on our own infrastructure. The following firm, client, team, and credential fields are ALWAYS tokenized before any OpenAI request: client and firm names; firm and signatory addresses, email addresses, phone numbers, and websites; signatory names and titles; the firm's PE license number and insurance certificate note; every team member's name, title, PE license, biography, and past-project descriptions; and subcontractor company names. Uploaded reference proposals are STORED in your private firm library but are NEVER sent to any AI provider - their text is not used for tone matching, style extraction, or any other AI-facing purpose. Non-identifying project context (project type, city/province, scope items, facility size, and dataset-derived site intelligence such as zoning and floodplain status) is sent so the model can produce substantive content. The automated redaction is best-effort and may not catch every identifying detail that a user places inside a free-text field. Under OpenAI's API data-usage policy, data submitted through the API is not used to train their models and is retained only transiently (up to 30 days) for abuse and misuse monitoring before deletion, unless a zero-retention arrangement applies.
    • Stripe (US): payment processing for subscriptions. Stripe collects and processes your payment information (credit card, billing address) directly. We do not store your full payment card details.
    • PostHog (US): product analytics (feature usage, funnels) when you accept analytics cookies. Session replay may be enabled; see cookie preferences.
    • Google Analytics (US): aggregated website traffic analytics when you accept analytics cookies (Consent Mode).
  • When required by law or to respond to legal process
  • To protect our rights, property, or safety, or that of our users
  • With your explicit consent

Some service providers (including OpenAI, Stripe, PostHog, and Google Analytics) may process your information in data centers located in the United States. These providers are contractually required to protect your information in accordance with applicable privacy laws.

Non-identifying project information is transmitted to OpenAI to generate your proposal; every identifying firm, client, signatory, team, credential, and reference-proposal field is either replaced with a placeholder or withheld entirely before transmission. Reference proposals uploaded to your firm library are stored on our infrastructure only and are never sent to any AI provider. Because the automated redaction operates on structured fields, it may not catch identifying details a user places inside free-text notes. Professional Engineers should assess their professional confidentiality obligations under their provincial PE code of ethics before transmitting client or RFP data.

Your Rights

Under PIPEDA and BC PIPA (as applicable), you have the right to:

  • Access your personal information
  • Request correction of inaccurate information
  • Request deletion of your personal information
  • Withdraw consent for data processing where applicable
  • File a complaint with the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia

To exercise these rights, contact [email protected]. We will respond to access and correction requests within 30 days where required by law. You may file a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca or the Office of the Information and Privacy Commissioner for BC at www.oipc.bc.ca.

Data Breach Notification

In the event of a data breach that poses a real risk of significant harm, we will notify affected individuals and regulators as required by PIPEDA and PIPA, including the Office of the Privacy Commissioner of Canada and, where applicable, the Office of the Information and Privacy Commissioner for British Columbia. Notification will include the nature of the breach, the information involved, steps we have taken to mitigate the breach, and steps affected individuals can take to protect themselves. We maintain records of all breaches for a minimum of 24 months as required by law.

To report a suspected security vulnerability or incident involving the Service, contact [email protected].

Data Retention

We retain your information for as long as your account is active or as needed to provide services. If you delete your account, we will delete or anonymize your personal information, except where we are required to retain it for legal or legitimate business purposes. Specifically, we retain financial records for 7 years (CRA requirements), legal dispute records as long as necessary to resolve the dispute, and records required by court order for the duration specified.

Cookies and Tracking

We use cookies and similar technologies to maintain your session, remember your preferences, and analyze service usage. You can control cookies through your browser settings, though this may affect functionality.

CivilProposal uses session cookies (authentication) and analytics cookies (usage tracking). You can disable analytics cookies in your browser settings without affecting core application functionality.

International Data Transfers

Your core application data and authentication records are stored in Canada. Other service providers may process limited data in the United States as described above. By using our Service, you consent to that cross-border processing where required to operate the service.

We ensure appropriate safeguards are in place to protect your information, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Contractual protections with service providers requiring data protection standards
  • Access controls and security measures to prevent unauthorized access
  • Compliance with applicable privacy laws to the extent possible

Please note that information stored in the United States may be subject to access by U.S. authorities under applicable laws. If you have concerns about data storage outside of Canada, please contact us before using the Service.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the service after such changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact our privacy team:

Privacy: [email protected]

Security: [email protected]

Lifesaver Technology Services Inc.

Kelowna, British Columbia, Canada

www.lifesavertech.ca

Company-wide terms: Lifesaver Terms of Service

Company-wide privacy: Lifesaver Privacy Policy