Privacy Policy
The short version
- We collect what we need to run your account and bill for it, and nothing for advertising. The site uses no analytics and no tracking cookies.
- There is one cookie: the one that keeps you signed in.
- We do not sell personal information.
- Are you a homeowner or job applicant? Your records belong to the radon company you dealt with; we hold them on its behalf. Start here.
Contents
Who we are and what this covers
RadonCRM (“we”, “us”) provides RadonCRM, software that radon testing and mitigation companies use to run their business. This policy explains how we handle personal information on radoncrm.com, in the RadonCRM app and in the pages it serves. It is written to meet Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta’s Personal Information Protection Act.
Two different roles
Information about our own customers. For the people who sign up for and use RadonCRM, and for visitors to radoncrm.com, we decide what is collected and why. That is what most of this policy covers.
Information a radon company keeps in RadonCRM. When a radon company uses RadonCRM, it stores records about its own customers (homeowners and property owners), job applicants and staff: names, contact details, addresses, appointments, radon readings, quotes, signatures and invoices. That company is responsible for that information. We process it only on its behalf and on its instructions, under our Data Processing Terms.
If you booked a radon test, signed a quote or applied for a job through a RadonCRM page, please contact the radon company you dealt with about your information. Its name is on your confirmation email, quote or booking page. If you cannot reach it, write to us and we will pass your request on.
What we collect
- Account details. Your company’s name, and the name, email address and role of each user. Passwords are stored only as a salted scrypt hash; we cannot read them.
- Company settings. Business contact details, time zone, currency, email templates and the other settings you configure.
- Billing. Your plan, subscription status, number of teams, and the customer and subscription identifiers Stripe gives us. Card details go directly to Stripe; we never see or store a full card number.
- Communications. What you send us when you ask for help, and our replies.
- Technical information. The IP address and browser details that come with every request, used for security, rate limiting and server logs, and a record of when you sign in. In the operator console we keep an audit trail of administrative actions.
We do not use analytics services, advertising networks, tracking pixels or session-recording tools on radoncrm.com or in the app.
How we use it
- to create and run your account, and to provide the features you use;
- to bill you, and to keep the records tax law requires;
- to send you service email: sign-up verification, password resets, invitations, billing notices, security alerts and notice of changes to our terms;
- to keep the Service secure, prevent abuse and fix problems;
- to answer you when you contact us;
- to meet legal obligations.
We do not send marketing email without your consent, and you can withdraw that consent at any time.
Cookies and local storage
RadonCRM sets one cookie, named session, when you sign in. It holds a random token that keeps you signed in, cannot be read by scripts on the page (HttpOnly), and is not sent to other websites (SameSite=Lax). It lasts 30 days, or 12 hours for the demo account, and is deleted when you sign out. It is strictly necessary: without it you cannot sign in.
We set no analytics, advertising or third-party cookies, and the site does not use your browser’s local storage.
Who we share it with
We share personal information only with providers that help us run the Service, only as much as each one needs, and under contracts that require them to protect it:
| Provider | What for | What it receives |
|---|---|---|
| Our cloud hosting provider | Runs the servers and stores the database and backups | All data held in the Service, encrypted in transit |
| Stripe | Subscriptions, card payments, invoices and receipts | Billing contact, company name, team count, payment details you give Stripe |
| Our email delivery provider (SendGrid, Postmark, Resend or an SMTP service) | Delivers the email the Service sends | Recipient address and the message |
| Google Fonts | Serves the typefaces on radoncrm.com | Your IP address and browser details when the page loads |
| jsDelivr | Serves open-source interface libraries used by the app | Your IP address and browser details when the app loads |
| OpenFreeMap | Map tiles for the Radon Risk Map | Your IP address and the map area being viewed |
A radon company can also connect its own services — its own SMTP or SendGrid account for sending mail, or Calendly to import bookings. Information then goes to that service under the company’s own agreement with it.
We may also disclose information when the law requires it, to protect the rights, safety or security of our customers, the public or ourselves, or as part of a sale or reorganisation of our business, in which case the buyer must honour this policy. We do not sell personal information.
Where it is stored
Our servers and some of the providers listed above may be located outside Alberta and outside Canada, including in the United States. Information stored there is protected by our contracts with those providers, but it may be accessible to courts and authorities in that country under its laws.
How long we keep it
- Account information is kept while your account is open, and deleted within 30 days of the account being closed.
- Backups of the database are taken daily and only the most recent 14 are kept, so deleted information leaves our backups within about two weeks.
- Billing records are kept for as long as Canadian tax law requires (generally six years).
- Sessions are deleted when they expire; password-reset links expire after an hour and sign-up verification links after 48 hours; both are stored only as one-way hashes.
- Server logs are kept for a short period for security and troubleshooting, then overwritten.
How we protect it
- All traffic to radoncrm.com is encrypted with TLS.
- Passwords are hashed with scrypt, and reset tokens are stored only as hashes and work once.
- Every request for company data is checked against the signed-in user’s company, so one company cannot see another’s records.
- Sign-in, sign-up, password reset, the careers form and the Partner API are rate-limited against guessing and abuse, and API keys are stored only as hashes.
- Operator access to the platform is restricted to named accounts, and administrative actions are logged.
No system is perfectly secure. If a breach of security safeguards involving your personal information creates a real risk of significant harm, we will notify you and the Privacy Commissioner as the law requires.
Your choices and rights
You can ask to see the personal information we hold about you, ask us to correct it, or withdraw consent to a use of it (which may mean we can no longer provide the Service). Most account details can be changed directly in Settings. Email us at steven@radoncrm.com and we will answer within 30 days.
If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner of Alberta.
Children
RadonCRM is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 18 for our own purposes.
Changes to this policy
When we change this policy we update the date at the top of the page. If a change materially affects how we use information we already hold, we will email account contacts before it takes effect.
Contact
Questions, requests or complaints about privacy go to our privacy contact: RadonCRM, Calgary, Alberta, Canada, steven@radoncrm.com.