Legal
Privacy Policy
Last updated 2026-08-20 · Pre-production draft, PIPEDA-aligned
FoundWall is a Canada-first platform for reporting and recovering lost, stolen and found pets and property. This policy explains what we collect, why, who else sees it, how long we keep it, and how you can access, correct or delete it. It is written to match what the product actually does, not a generic template.
1. Who is responsible for this data
FoundWall is operated by [OWNER TO CONFIRM: legal entity name and registered address]. The product's mobile application identifier (com.innovaconsult.foundwall) references an Innova Consult entity, but a specific privacy-policy controller name and registered address needs a current corporate-status check before publication — do not assume that any particular legal name is still valid without confirming it first.
For clarity, "FoundWall", "we", "us" and "our" in this policy refer to that operating entity, and "you" refers to anyone who uses the FoundWall web app, mobile app, or public pages.
2. What this policy covers
This policy covers the FoundWall web application, the FoundWall mobile app (iOS and Android, built with Expo), and the public marketing pages at this domain. It does not cover third-party sites we link to (for example resale marketplaces we may link to or one day monitor) or services you use independently, such as your device's operating system.
FoundWall does not currently use AI-based matching, automated marketplace scraping, police integration, rewards or payments in a way that changes the categories of personal information described below. If that changes, this policy will be updated first, and the change will trigger a fresh internal privacy review before it ships.
3. Information we collect
We separate what you tell the public from what stays private to your account. Both are described here.
Account information
- Authentication account identifier and email address
- Optional display name
- Locale/region
- Session and sign-in metadata
Public incident information (what you choose to publish)
- Incident type, category and status (for example "lost," "stolen," "found," "resolved")
- Your description and any attributes you select
- Photos you upload, sanitized to remove embedded EXIF/GPS metadata before publication
- A generalized location and an approximate date/time — never an exact address or GPS point
Private incident information (never public by default)
- Exact location or address, where you choose to supply one
- Private notes
- Hidden verification characteristics (details you keep back to confirm a rightful claimant)
- Police occurrence numbers or insurance references, if you add them
- Serial numbers, microchip numbers, and other device/ownership identifiers
- Proof-of-ownership files you upload
Communications
- Private message content and participants, exchanged in-platform between users
- Timestamps, block records and abuse reports
Security and operations
- Security events, limited IP and session metadata
- Audit events for privileged/staff actions
- Moderation records
- Privacy requests, breach records and legal-request records, where applicable
Mobile app specifics
If you enable notifications on the mobile app, we store an Expo push token together with your user ID, your Supabase session ID, your device platform (iOS/Android) and the Expo project ID, in a restricted server-side table — this is not kept in the app's own local storage. As of this policy, mobile push delivery is feature-gated off in production, so this processing is not yet active for end users; the description above reflects what happens once it is switched on.
Separately, and entirely on your device, the mobile app keeps: an in-progress incident-report draft for up to 30 days so you don't lose unsent work; a staged photo pending upload, which may still contain EXIF/GPS data locally until it uploads; and private-message drafts for up to 7 days. These live in your device's OS-secure storage, are never sent automatically, and are never uploaded to FoundWall's backend as a "draft" — only a message or report you actually submit reaches our servers.
4. Information we do not collect
To be specific about the boundary, FoundWall does not:
- Send your exact GPS coordinates to our servers — only a city/locality and province, derived by reverse-geocoding on your device
- Collect advertising identifiers
- Access your contacts
- Access Bluetooth or local-network scanning
- Fingerprint your device
- Run third-party analytics or crash-reporting SDKs — none are integrated at this time
- Track your location in the background or continuously
5. How we use information
| Data | Purpose | Ever public? |
|---|---|---|
| Account / email | Authentication, service notices | No |
| Incident public projection | Community discovery and recovery | Yes |
| Generalized location | Local discovery without precise exposure | Yes (rounded) |
| Exact location | Private recovery context, owner record | No |
| Private identifiers (serial/chip) | Ownership verification, future matching | No by default |
| Proof documents | Optional ownership support | No |
| Messages | Recovery communication between users | No |
| Abuse reports | Trust & safety | No |
| Security / audit events | Abuse and security detection, accountability | No |
| Marketing consent | Optional marketing, opted in separately | No |
We do not bundle marketing consent with the consent you give to use the service, and we don't hide sensitive processing inside a generic "accept terms" checkbox.
7. Cross-border transfers
FoundWall is built Canada-first: our database, file storage and application hosting run on Canadian infrastructure (AWS ca-central-1 for Supabase; Montréal for Vercel). Push-notification delivery is the one part of the system that is not Canada-resident by nature — Apple's and Google's notification services operate outside Canada, and we disclose that transfer here rather than implying everything stays in-country.
Before we turn on any new processor located outside Quebec, we conduct a transfer assessment consistent with Quebec's private-sector privacy law, and we track that assessment alongside our vendor register. That register is still being finalized — [OWNER TO CONFIRM: vendor/subprocessor register sign-off status] before this policy is treated as production-final.
8. How long we keep information
We can state exact retention for some categories today, because they're already enforced in the system:
- Disabled mobile push registrations, and their provider ticket/receipt records: deleted after 30 days
- Incident-publication and media upload idempotency records (technical de-duplication records, not your content): deleted after a 30-day window
- Raw media you upload but never finish publishing (an abandoned draft photo): withdrawn and deleted after 31 days
- On-device incident-report drafts and staged photos: up to 30 days, cleared automatically or when you discard them
- On-device private-message drafts: up to 7 days
For everything else — how long an active account, a resolved incident, a message thread or a proof document is kept — our internal Privacy Impact Assessment currently describes categories and targets ("kept while active," "a finite recovery-history window after resolution," and similar) rather than locked numeric periods. [OWNER TO CONFIRM: final numeric retention periods for account, incident and message data] is an open pre-production item, and we are not going to publish specific day-counts for those categories until they are actually the day-counts the system enforces. Security, audit and legal-hold records are kept longer, under restricted access, for accountability and breach-response purposes. Backups expire on their own separate, documented lifecycle.
9. Your rights and how to exercise them
Depending on where you live in Canada, you may have rights under the federal Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta's PIPA, British Columbia's PIPA, or Quebec's private-sector privacy Act as amended by the Law 25 reforms — including rights to access, correct, and request deletion of your personal information, and to withdraw consent where consent is the basis for processing.
You can exercise these through the in-app Privacy Center at /settings/privacy (sign-in required), where you can submit:
- An access request
- A correction request
- A deletion request
- A consent-withdrawal request
- A complaint
- A general privacy question
Each request gets a reference number and moves through a reviewed, rate-limited intake — it is not a raw, unmoderated database write — so we can verify identity and scope sensitive exports safely rather than emailing exact locations, messages or ownership documents as an ordinary attachment. You can also escalate a complaint to the Office of the Privacy Commissioner of Canada, or the equivalent provincial regulator, at any time.
A privacy contact reachable without an account is [OWNER TO CONFIRM: public privacy-request email or postal address].
10. Deleting your account and data
Submitting a deletion request through the Privacy Center begins a reviewed process — it does not guarantee instant erasure. Records that must be kept under a legal hold, for security or breach-record integrity, or because they are inside a backup's normal lifecycle, may be retained longer than the rest of your account, and we will tell you which categories that applies to when it does.
Account-level deletion and device-level deletion are different things. When we delete your account, we can remove or anonymize what's stored on our servers according to the process above — but we cannot remotely erase a copy of your data sitting in an offline device, an old phone backup, or a device you no longer control. If you have local drafts on the mobile app (see Section 3), clearing them is a device action, not something the server can reach into and guarantee for you.
11. Security
We separate public and private data at the database level with row-level security, require server-side authorization for sensitive operations, keep uploaded files in private storage behind signed URLs, strip identifying metadata from published photos, log security-relevant events, and require multi-factor authentication for staff accounts with elevated access. No system is unbreachable; if a security incident affects your personal information, we maintain a breach record and follow the notification process described below.
12. Children
FoundWall is not intentionally designed for children, and we have not yet finalized a minimum eligibility age for the service. [OWNER TO CONFIRM: minimum age to use FoundWall]. We do not knowingly collect more personal information than necessary from a child, and we do not use youth personal information for marketing. If we learn a young child has created an account outside our eligibility policy once it is set, we will take reasonable steps to remove it.
13. Breach notification
We maintain a record of every security-safeguard breach involving personal information, not only ones that turn out to be reportable. Where a breach creates a real risk of significant harm, we follow the applicable notification path — for example, notifying the Office of the Privacy Commissioner of Canada and affected individuals under PIPEDA, the relevant provincial regulator under Alberta or BC's PIPA, or the Commission d'accès à l'information under Quebec's law where a serious-injury risk applies — as soon as feasible, alongside affected users.
14. Changes to this policy
We'll update this policy as our processors, features or retention rules change — adding a new processor, turning on push notifications for real, or locking in final retention numbers are all things that will be reflected here, not left stale. We'll update the "Last updated" date above when we do, and for material changes we'll look for a more visible way to flag it than a date change alone.
15. Contact
For an account-linked privacy request, use the in-app Privacy Center at /settings/privacy. For anything else, contact [OWNER TO CONFIRM: general privacy/legal contact email].
See also: Safety Rules · Terms of Service · Trust & safety overview