In plain language
This is the whole policy in ten sentences. The detail follows, and where the two differ, the detail governs.
- We collect what the product needs to work — your name and email, the home you tell us about, the projects you post, the messages you send, and the documents you upload.
- We do not sell your data, and we never will. No advertising, no data brokers, no pay-to-rank in anyone's feed.
- Your eznest account data is stored in Canada — Montreal, on encrypted storage. Sign-in data is held by Clerk in the United States, and content sent to Nestor is processed by Amazon Bedrock in the United States.
- Nestor runs on Amazon Bedrock in the United States (each request is sent to us-east-1 and AWS may serve it from us-east-1, us-east-2 or us-west-2), and it will not process your information until you switch it on. Nothing you say to Nestor trains any AI model.
- We can read your messages and your documents. They are encrypted on our disks, not from us. Anyone who tells you a marketplace can't see your messages is describing a different product.
- We record how you use the product by default so it can get better at helping you; you can switch that off. We only use it to tailor what you see if you separately turn personalization on.
- You can export your data and close your account yourself, at any time, without asking us or paying a fee.
- We keep your data until you delete it. We do not have automatic expiry clocks on your account content, and we would rather say so than invent one.
- If something goes wrong with your information, we write it down — every incident, whatever its size — and we tell you and the regulators when the law requires it.
- You can complain to us, and then to the Privacy Commissioner of Canada if we have not put it right.
1. Who we are and what this covers
We operate the eznest platform: a home-services marketplace connecting homeowners with service providers, together with a set of tools for keeping track of a home ("the Platform").
We are the organisation accountable for the personal information described in this policy.
This policy covers the personal information we handle through:
- the eznest website and web application at eznest.ca;
- the eznest mobile applications;
- Nestor, the assistant built into both;
- our email and messaging to you.
It applies to homeowners and household members, service providers and their staff, and anyone who contacts us. Where we say "you", we mean whichever of those you are.
What this does not cover. It does not cover what a service provider does with information you give them directly, or what they do with your information after you hire them — they are an independent business and their own privacy practices are their responsibility, not ours. It does not cover other websites we link to.
The Platform is in an invite-only beta
Accounts today can only be created with an invitation code. That bounds who this policy currently applies to, and it means some capabilities described here as available are available to a small group. Where something is built but switched off, this policy says so plainly rather than describing it as though it were running.
2. Privacy Officer
Our Privacy Officer is accountable for the personal information under our control and for our compliance with this policy.
Niruban Kandasamy Privacy Officer, Eznest Technologies Inc. 226 Kinloch Crt, Nepean, Ontario K2J 5S9, Canada privacy@eznest.ca
Write to that address for anything in this policy: a question, an access request, a correction, a deletion, a complaint, or to tell us something has gone wrong. It reaches a person, not a queue.
3. What we collect
We have grouped this by where it comes from, because that is the question people actually ask.
3.1 Your account
| What | Notes |
|---|---|
| Email address, name | Both required. In production these come from your sign-in provider (Clerk) rather than being typed into eznest. |
| Phone number | Optional. Only if you add it to your profile — we never ask for it at sign-up. |
| Role | Homeowner, provider, or staff. |
| Invitation code, and the IP address you redeemed it from | While the beta is invite-only. |
| Identity link to your sign-in provider | The provider's identifier for you, plus the email and verification status they report. |
We do not hold your password. Clerk is our sole authenticator in production, so the credential you type lives with them, not with us. The password field on our own user records holds a random value that cannot be used to sign in.
Multi-factor authentication is not available today. We would rather tell you that than let you assume otherwise.
3.2 Your home and your household
All of this is optional, all of it is entered by you, and none of it is required to use the marketplace:
- the address, city, province and postal code of your home, plus property type, year built and floor area;
- purchase price and mortgage balance, if you choose to record them;
- rooms, appliances, systems, finishes, belongings (including serial numbers and purchase value), warranties, maintenance schedules and service history;
- your own list of trusted contractors, including their names and contact details;
- household members, and for a child or teen account, an optional date of birth, a guardian link, and the spending and access limits the guardian sets.
We do not turn your address into map coordinates. There is no geocoding of a homeowner's address anywhere in our system.
3.3 What you create on the Platform
Projects (title and description are required; budget, timeline, urgency and location are optional), bids and proposals, quotes and cover notes, appointments including the visit address, reviews, disputes, support tickets, reports of other users' content, and your personal to-dos, notes, reminders, checklists and expenses.
Messages between you and a provider are stored as ordinary text on our servers. They are encrypted on the disks they sit on, and access is restricted, but they are readable by us. They are not end-to-end encrypted, and we will not pretend otherwise.
3.4 Files you upload
Documents, project photos, provider portfolio images and evidence attached to a job are stored in Amazon S3 in Montreal, on a versioned, server-side-encrypted bucket with public access blocked. We also extract the text of documents you upload and store it in our database, so the assistant and search can find things inside them. Extraction runs on our own servers; no third-party OCR service sees your files.
3.5 What we observe
| What | Notes |
|---|---|
| Sign-in sessions | The IP address and browser user-agent for each session, plus when it was issued, when it expires, and whether it has been revoked. |
| Failed sign-in attempts | Email and source IP, for abuse protection. |
| Usage signals | Which parts of the product you use, recorded to make the product better at helping you. On by default; you can switch it off — see §7.3. |
| Mobile device tokens | Collected when you use the mobile app. They are not sent anywhere today — push notifications are switched off, so no token has ever reached Apple or Google. |
| Audit records | An append-only record of privileged actions taken on the Platform. Its detail field can contain email addresses. |
What we do not do here matters as much. There is no analytics library, no advertising tag, no crash-reporting SDK, no tag manager, and no tracking pixel anywhere in the eznest website or apps. We do not keep web-server access logs. There is nothing here that follows you to another website.
3.6 Your conversations with Nestor
If you switch Nestor on (§6), we store the whole conversation: every message you send, every reply, and every action Nestor took on your behalf including what it looked up and what it found. We also keep a short profile of you that Nestor writes for itself — a summary of who you are, your home, what you have going on, and what you have told it you prefer — which it re-reads at the start of every later conversation. We record how much AI usage your account has consumed.
3.7 If you use the personal-finances tools
These are optional and separate from the marketplace. If you use them, we store the bank statements you import — the account name and institution, a masked account number, balances, and every transaction with its description, date and amount. The raw text of an imported statement is encrypted with a key held in AWS Secrets Manager.
One honest limitation: the statement file you upload is written to the container's own disk, which is not durable storage. It should be treated as temporary. Only the extracted text is encrypted and kept.
3.8 If you are a service provider
Your business profile: display name, legal business name, headline, biography, logo, service area (city, province, radius and coordinates), categories and rate cards. Your verification documents, and the licence identifiers we check with regulators.
The eznest profile itself asks for business records — business registration, insurance certificates, trade certifications and the licence identifiers we check with regulators — and does not ask you to upload an individual's government identification to eznest. When Stripe Connect is enabled for a provider business, Stripe may require individual identity, beneficial-owner, bank and verification-document information to open or maintain the connected account. Stripe collects that information directly inside its hosted pages or Stripe-controlled embedded frames; eznest receives the account's verification status and requirements, not the identity documents or bank credentials.
Voice memos in the provider mobile app. During a site visit, the provider app can record a short audio note against the visit. Two things must be true first: you have granted the app microphone access, and the visit carries recording consent — the app refuses to record audio or video until consent has been recorded on the visit's Overview tab, because the person being recorded may not be you. The recording is written to the app's protected storage on your device and kept there with the visit. It is not uploaded to eznest. The app's visit-sync path that could carry visit media to our servers was retired on 2026-09-02; the production service ran a build that still exposed that path between 2026-08-26 and 2026-09-04, but the app had no App Store or TestFlight distribution in that window and a read-only census of production on 2026-09-01 found no projects at all, so there was nothing a visit could have been finalized against and no voice memo reached us. No other path in the app sends audio anywhere; we therefore do not receive, store, transcribe or otherwise process a voice memo, and deleting the app deletes them. If that changes, this policy and the App Store privacy label will say so before it does.
If you use the provider CRM, we store the contact details you enter for your own clients, including people who have never used eznest. You are responsible for having a basis to hold that information; we hold it for you as your service provider.
3.9 People who are not eznest users
We hold some personal information about people who never signed up:
- contacts a provider enters into their own CRM;
- contractors a homeowner adds to their trusted-contractor list;
- business contact information for Ontario service businesses collected from public sources for outreach, under Canada's anti-spam legislation, with an opt-out list we honour permanently.
If you are one of those people and want to know what we hold or want it removed, write to privacy@eznest.ca. We will act on it whether or not you have an account.
3.10 What we deliberately do not collect
- Payment card numbers or bank account details. We do not take payments today — the payments integration exists but is switched off, so no card, no bank account and no payment-processor customer record is created for you.
- Government identification, of anyone.
- Voice or audio, on our servers. Nestor's voice features are built but switched off in production, so no audio reaches us through Nestor. The provider mobile app can record a voice memo during a visit; it stays on the device and is never sent to us — §3.8 says exactly what happens to it.
- Precise or continuous location. The mobile app can record a single coarse check-in location as proof a provider attended a visit, and that is the only location capture in the product.
- Race, religion, political opinion, health information, sexual orientation, or biometric data. We have no field for any of them.
4. Why we use it
We use your personal information to run the Platform for you: to create and secure your account, to match you with providers and providers with work, to carry projects from a first description through to a completed job, to let you and a provider talk, to keep the records of what was agreed, to send you what you asked to be sent, to answer your support requests, and to keep the Platform safe from abuse.
We use it to meet our own legal obligations — tax and financial records, anti-spam compliance, and responding to lawful requests.
We use it, with your consent, to personalize what you see and to power Nestor. Those two are treated separately and are described in §6 and §7.3.
We do not use it to build an advertising profile, and we do not sell it. No third party pays us to reach you, and no provider can pay for placement in your results.
5. Who we share it with
5.1 Other people on the Platform
This is the part you control by using the product:
- When you post a project, the providers eligible to bid see its description and location. Your name, email and phone are not published with it.
- When you engage a provider, they see what they need to do the work — your name, the service address, the scope, and your messages.
- Reviews you write are shown publicly with your display name.
- Household members you invite see the home you share with them.
If you are named as your business's billing or signing contact. Providers can invoice each other and prepare business agreements on eznest. If you hold an owner, admin or finance role, an existing business counterparty can see your name, work email address and billing role; signing contacts are limited to owners and admins. This happens only after your business and theirs already have a commercial relationship on eznest, recorded by an invoice, agreement or active commercial relationship between the two. There is no directory of contacts, and a provider you have never dealt with cannot list your business's people.
To send a business its first invoice or prepare its first agreement, a provider must already know and enter an authorized contact's email address. We confirm whether that exact address belongs to someone with the required billing or signing authority and return their role — we do not return their name or echo the address, and we will not tell a provider who works somewhere or reveal an address they did not already have. These confirmations share one rate limit and are recorded in our audit log.
Corrected 2026-09-06. Until that date any invited provider could list the name, work email and role of every owner, admin and finance member of every validated business on the Platform, without any relationship to it. That was a defect, not a design; this section describes what the code does now.
Corrected 2026-09-07. The agreement signer picker had retained the same directory defect for owner/admin signing contacts after the billing picker was repaired. It now uses the same relationship gate and known-address bootstrap described above.
5.2 Companies that process data for us
Two, in production, today:
| Who | What for | Where |
|---|---|---|
| Amazon Web Services | Everything we run: the database, file storage, cache, secrets, transactional email, and Nestor's AI processing. | Storage: Canada (ca-central-1, Montreal). Processing: Canada and United States (us-east-1 for SES; Bedrock inference is sent to us-east-1 and may be served from us-east-1, us-east-2 or us-west-2). |
| Clerk, Inc. | Sign-in and account authentication. | United States. |
Clerk receives your email address, name, IP address and sign-in events directly from your browser. Amazon Bedrock receives the Nestor content described in §6 when you enable and use Nestor. These are the two active processing flows outside Canada.
Also live, but receiving no personal information about you: two Ontario regulators, the Home Construction Regulatory Authority and the Electrical Safety Authority, which we query with a provider's licence number to confirm it is valid. Both are in Canada.
We also read public reference data — weather, product recalls, map data, open government data. We send them nothing about you, with one exception worth naming: when we geocode a business address in our provider-outreach work, that address text goes to OpenStreetMap's geocoder in Europe. This never involves a homeowner's address.
Built, but switched off, and receiving nothing today: Stripe (payments and provider connected accounts), Apple and Google push notification services, Google Places, Intuit QuickBooks, and two alternative AI providers. For a provider in a controlled Stripe Connect rollout, Stripe may receive the identity, beneficial-owner, bank and verification information described in §3.8 directly through a Stripe-hosted page or Stripe-controlled frame. The rollout controls remain off today. We will tell affected users before enabling a material new processing flow.
Signing an agreement does not involve a third party. We sign contracts ourselves: the document never leaves our storage, and no e-signature vendor receives your name, your email, the contract or your signature. One thing does leave, and it is worth being exact about what: to record when a document was signed, we send a cryptographic digest of the signature — a 256-bit number — to an independent timestamp authority, which returns a signed token. The authority receives no document, no name, no email and no address, and cannot work backwards from the digest to any of them.
We do this because we are a party to these agreements and take a fee from them, so a "signed at" that we record is a claim by an interested party. The authority has nothing at stake, which is what makes its token worth something. The audit certificate we produce names which authority was used, and it separates the facts anyone can check for themselves — the document's digest and that token — from the facts that rest on our own record-keeping.
We maintain a machine-verified register of every one of these at subprocessors.yaml; an automated check in our build confirms each entry corresponds to something actually present in our code.
On contractual protections: we are a young company and we are candid about this. Formal data processing agreements with our processors are being put in place; we have not yet completed that work, and we are not going to claim protections we have not signed. Our Privacy Officer can tell you the current state for any named processor.
5.3 Other situations
- Professional advisors — lawyers, accountants and auditors, bound by confidentiality.
- Legal requirements — where we are required by law, or where disclosure is necessary to investigate a breach, prevent fraud, or protect someone's safety. We will tell you unless we are legally prohibited from doing so.
- A change in our business — if eznest is acquired or merges, your information may transfer as part of that. You would be told, and this policy would continue to apply until you were given notice of a replacement.
- Anything else — only with your consent.
5.4 What we never do
We do not sell personal information. We do not rent or trade mailing lists. We do not share your information with advertisers or data brokers. We do not let a provider pay to appear higher in your results. We do not combine your data with data bought from third parties to profile you. These are commitments in our privacy and ethics charter, not aspirations.
6. Nestor and artificial intelligence
6.1 Where it runs
Nestor runs on Amazon Bedrock, a third-party AI service operated by AWS, and requests are processed in the United States: each request is sent to us-east-1, and the Bedrock inference profiles we use may serve it from us-east-1, us-east-2 or us-west-2 (measured with AWS's GetInferenceProfile on 2026-09-11 and re-checked quarterly). Eznest account data remains stored in Canada; the prompt and context needed for each Nestor response are transmitted to and processed in the United States for that request.
The models in use are Mistral 7B Instruct, Meta Llama 3 70B Instruct, Mistral Large, and Amazon Titan Text Embeddings for search. If one is unavailable we fall back to another in the same region, which may include Anthropic's Claude 3 Sonnet.
6.2 What reaches the model
When you talk to Nestor: your message, your recent conversation history, a summary of your own account — your name, your home's basic details, counts of what you have on the go, your next appointment — the profile Nestor keeps of you, and the results of whatever it looks up on your behalf. Every one of those lookups is restricted to your own data. Nestor cannot read another user's information, and there is no path in the system by which it could.
6.3 Your consent, and its exact limits
Nestor will not process your personal information until you turn it on. The consent is express and separate from everything else, it is checked before anything is sent, and if we cannot confirm your consent for any reason the request is refused rather than allowed. You can withdraw it at any time in Settings → Privacy, and Nestor stops.
That gate covers your conversations with Nestor. It does not currently cover every AI-assisted feature. These use AI without a separate consent check:
- summarising a conversation, analysing bids, drafting a project description, and estimating a cost, when you ask for them;
- categorising transactions and reading statements in the personal-finances tools, if you use them;
- generating the search index for your own documents and usage signals;
- writing the summary Nestor keeps of you at the end of a conversation.
All of these run on the same Bedrock service in the United States, on your own data, for your own benefit. We are telling you about the gap rather than describing a blanket protection we have not built. Closing it is on our roadmap.
6.4 What we do not do with it
Nothing you say to Nestor, and nothing in your account, is used to train, fine-tune or improve any AI model. There is no training pipeline in our system. There is no cross-user aggregation feeding any model. AWS does not train its models on Bedrock inputs.
We should be precise about one related point: there is an account-level AWS setting for AI data retention that we have not yet applied. Until we have, we are not going to claim a zero-retention guarantee we cannot evidence.
We do not use content filtering provided by the AI service. Nestor's limits are in our own code: actions that change something require your explicit confirmation, some actions are prohibited outright, and there are caps on how much any single conversation can do.
6.5 Automated decisions
No AI decides anything about you that has a legal or similarly significant effect. Nestor suggests and drafts; you decide. No AI decides whether you get an account, what you pay, whether a provider is verified, or whether a dispute succeeds.
There is one automated action in the product: if you have set a threshold for approving small milestones automatically, work below it can be approved without you clicking. That is a rule you set, applied by arithmetic, not by a model — and it is inert today because payments are switched off.
6.6 Making Nestor forget you
Signed in, go to Privacy → Make Nestor forget me. It clears both your conversation history and the profile Nestor wrote about you from it — the two together, because clearing the transcripts while keeping the summary distilled from them is not forgetting. Nestor starts over knowing nothing about you.
It is immediate and self-serve. Closing your account clears both as well.
7. Your choices and your rights
7.1 Get a copy of your data
Signed in, go to Privacy → Download my data. It is immediate, self-serve, machine-readable, and free — no waiting period, no email, no fee.
It is a copy of the main categories of your data, not of everything we hold. It currently includes your account record, homes, projects, milestones, reviews, appointments, notifications, usage signals, to-dos, reminders, notes, expenses, supplies, rooms, belongings, home details, checklists, document listings, service history, trusted contractors, preferences and consents.
It does not include: your phone number, your session and IP records, the audit log, your device tokens, your identity links, your Nestor conversations or the profile Nestor keeps of you, your AI usage records, support tickets, disputes, bids and quotes, your provider profile, or anything in the personal-finances tools. Message bodies appear as a count rather than as text.
If you want any of those, ask the Privacy Officer and we will assemble them for you. We are working to close the gap.
7.2 Correct it
Change your name and phone in Settings → Account. Home details, projects and everything you have entered are editable where you entered them. For an email change, or anything you cannot reach, write to privacy@eznest.ca.
7.3 Control what we observe and how it is used
There are two separate switches, and they do different things:
| Switch | Default | What it controls |
|---|---|---|
| Personalization master switch (Settings → Privacy) | On — we record usage signals | Turning it off stops us recording usage signals at all, and turns off every form of personalization regardless of anything else. |
| Personalization consent (Settings → Privacy) | Off — you must grant it | We only use your own history to shape what you see if you grant this. Without it, matching still works, on neutral factors only. |
You can also erase every usage signal we have recorded about you, immediately and yourself, from Privacy → Erase my signals. That page also lists what we have observed, so you can look before you erase.
Marketing email and SMS are separate consents, each independently withdrawable, and every marketing message carries an unsubscribe. Transactional messages — about a project, a booking, a security event — are part of operating your account and are not a marketing preference.
7.4 Close your account
Settings → Account → Delete my account. You will be asked to re-confirm it is you, then to type DELETE.
What that erases: your home contents and belongings, your notes, to-dos, reminders, checklists and expenses, your preferences, your Nestor conversations and the profile Nestor keeps of you, your notifications, your device tokens, your usage signals and search index, your identity links, your AI usage records, your beta invitation record, and every outstanding sign-in session. Your account record itself is anonymized: your email is replaced, your name becomes "Deleted user", your phone is removed, and every access token is invalidated.
Your sign-in record at Clerk. Your sign-in itself lives with Clerk (§5.2), so closing your account has a second half that happens outside our systems: we ask Clerk, server to server, to delete your sign-in record. We make that request when our connection to Clerk is able to carry it. If it cannot be made yet, or Clerk does not confirm it, the request is recorded against your anonymized account as still owed and is completed later; it is not closed until Clerk confirms the record is gone. Whichever state that is in, signing in with that identity is refused — it never re-creates an account, and none of your erased data comes back. Clerk's identifier for you stays on the anonymized record so that identity can never be attached to a new account; Clerk never reuses it, and once your record there is deleted it points to nothing.
What we keep, and why:
- Financial records — the ledger and any invoices. Required for tax and accounting.
- The audit log — including the record of your deletion, and of whether Clerk has confirmed deleting your sign-in record.
- Your consent history — the record of what you consented to and when survives withdrawal, because it is the evidence of what we were permitted to do.
- Clerk's identifier for you — on the anonymized account record, as explained above, so an erased sign-in can never be attached to a new account.
What we do not yet erase, honestly stated: your home record and the documents, maintenance history and service records attached to it; your projects, milestones, reviews, messages and appointments; and files you uploaded remain in storage.
These are not oversights. A home can be shared with household members, so deleting yours could destroy someone else's records. Projects, messages and reviews are shared with a provider who is a party to them. We have not yet finished the rules for those cases and we would rather leave them than get them wrong. If you want them removed, ask the Privacy Officer and we will handle it individually. We will update this section as we resolve it.
If you cannot reach the button — for any reason — email privacy@eznest.ca and we will close the account for you.
7.5 Withdraw consent
Any consent can be withdrawn in Settings → Privacy: AI processing, personalization, marketing email, marketing SMS, data sharing. Withdrawal is recorded rather than erased, so there is a record of when it changed.
Some consents are structural: if you withdraw consent to what is necessary to operate your account, the way to give effect to that is to close the account.
7.6 Complain
Tell us first — privacy@eznest.ca. We will acknowledge you and tell you what we are doing.
If we do not resolve it, you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca, 1-800-282-1376). Quebec residents may also complain to the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).
7.7 Our service standard
We aim to answer an access or correction request within 30 days, at no charge. This is a commitment by our Privacy Officer rather than something automated — the export in §7.1 is instant, and everything else is handled by a person.
8. Where your data lives, and for how long
8.1 Where
All eznest-held personal information is stored in AWS Canada (Central), Montreal — the database, file storage, cache and secrets. This is enforced by a permission policy that denies requests to any other region, by a start-up check that refuses to run the service if it is misconfigured, and by a validation in our infrastructure definition.
We should be precise about the strength of that: it is a guardrail enforced by our own configuration and code, not a boundary imposed by AWS at an organisational level. We do not have an AWS Organization, so we cannot and do not claim organisation-level enforcement.
8.1.1 Foreign lawful access — the part most policies leave out
You should know two things about what "stored in Canada" does and does not protect you from.
Your sign-in data is held by Clerk in the United States. While it is there, it is subject to the laws of the United States, and may be accessible to United States courts, law enforcement and national security authorities under those laws, without notice to you or to us. We chose Clerk for the security of the sign-in itself, and we are telling you the trade-off rather than burying it.
Content sent to Nestor is processed by Amazon Bedrock in the United States. The prompt, recent conversation context, relevant account context and retrieval results described in §6 are subject to the laws of the United States while processed there. Your database records and uploaded files remain stored in Canada.
Canadian storage is not immunity, and we will not imply that it is. Our Canadian infrastructure is operated by Amazon Web Services, a United States company. Under the United States CLOUD Act, a US-headquartered provider can be compelled to produce data it controls regardless of the country the servers sit in. Keeping your data in Montreal meaningfully reduces exposure — it is why we did it, and why we enforce it in code — but it does not place your data beyond the reach of a US legal order served on our provider.
We tell you this here, and we will tell you again at the point we ask for anything sensitive. If we ever receive a legal demand for your information, we will tell you unless we are legally prohibited from doing so, and we will not hand over more than we are required to.
8.2 For how long
We keep your account data until you delete it. We do not run automatic expiry clocks on it, and we are not going to publish a retention schedule our systems do not enforce.
What we do enforce automatically, today:
| Data | Kept |
|---|---|
| Business-outreach records and the consent evidence behind them | 3 years |
| Business contact records never contacted | 1 year, then removed |
| Personal details of a business that declined outreach | Removed after 90 days |
| Operational job logs | 30 days |
| Marketing opt-outs | Permanently — an opt-out is honoured forever, by design |
| Security and privacy incident records | 5 years (see §9) |
Two more numbers worth knowing: database backups are retained 7 days, so deleted data persists in point-in-time recovery for up to a week; system logs are retained 30 days.
Financial records, the audit log and consent history are kept indefinitely, as described in §7.4.
9. Security, and what happens when something goes wrong
9.1 What protects your data
- Encrypted at rest — the database (AWS-managed keys), file storage, and the cache.
- Additional field-level encryption with AES-256-GCM for e-signature and financial personal information, with keys held in AWS Secrets Manager. The service refuses to start in production without them.
- Encrypted in transit — TLS 1.2 minimum, TLS 1.3 supported; all HTTP traffic is redirected to HTTPS. Inside our private network, traffic between the load balancer and the application runs unencrypted; the network itself is isolated and not reachable from the internet.
- A web application firewall in blocking mode in front of the site.
- Server-side session revocation — we can invalidate every outstanding session for an account instantly, and we do so on password change, sign-out-everywhere, and account deletion.
- Role-based access through a single authorization layer, so a homeowner surface cannot reach provider data.
- An append-only audit log of privileged actions.
9.2 What we are not going to overstate
- The audit log records actions, not every read of personal data. There is no data-access log.
- Audit writes are best-effort: a failure is logged rather than failing your request.
- eznest has not had an external security audit or penetration test. When it does, we will say so here.
- The production database runs in a single availability zone. That is a resilience limitation, not an encryption one, and we mention it because we would rather you knew.
- Two-factor authentication is not available (§3.1).
- Signing out of your identity provider does not currently propagate to your eznest session; signing out of eznest does.
No system is perfectly secure, and anyone who tells you otherwise is selling something.
9.3 Breach and incident handling
We keep a register of every privacy incident, whatever its size and whether or not anyone was harmed. Recording an incident is unconditional; whether it must be reported is assessed afterwards, and we record both the conclusion and our reasoning. Records are kept five years.
Incidents are classified by what actually happened, including four categories specific to the assistant: a model output containing another user's information, injected content causing an unintended action, a bypassed safety control, and audio captured without its disclosure.
When we will tell you. If we conclude a breach creates a real risk of significant harm to you, we will notify you as soon as feasible, directly. We will tell you what happened, what information was involved, what we have done about it, what you can do, and how to reach the Privacy Officer. We will report the same breach to the Office of the Privacy Commissioner of Canada, and to the Commission d'accès à l'information du Québec where a Quebec resident is affected.
Our internal procedure is published at incident-response-runbook.md.
10. Cookies
We set three cookies of our own. None of them tracks you, and none is used for advertising:
| Cookie | What it does | Lifetime |
|---|---|---|
eznest_qtoken | Keeps you signed in. Not readable by scripts. | 24 hours |
eznest_invite | Carries your invitation code through sign-up. Not readable by scripts. | 30 minutes, deleted once used |
ez_rm | Remembers that you prefer reduced motion. | 1 year |
Clerk sets its own cookies to maintain your sign-in. Those are theirs and are governed by their privacy policy.
There is no advertising cookie, no analytics cookie and no third-party tracker anywhere in the product. That is also why you will not see a cookie consent banner: every cookie we set is strictly necessary or a preference you chose.
11. Children
eznest is for adults. You must be the age of majority in your province to create an eznest account.
Household child and teen accounts are different, and deliberately so. A guardian can create an account for a young person in their household. When they do, the guardian sets what that account may do — spending limits, quiet hours, whether it can interact with the marketplace at all — and consents on the young person's behalf. We record that consent. We collect an optional date of birth for these accounts and nothing else beyond what the household tools need.
A guardian can see, export and delete a young person's account data at any time.
If you believe we have information about a child outside that structure, write to privacy@eznest.ca and we will delete it.
12. Quebec residents
Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25, gives you rights in addition to those above:
- A named person in charge. Our Privacy Officer (§2) is that person.
- An incident register. We maintain one, covering all confidentiality incidents regardless of severity, kept five years (§9.3), and we notify the Commission d'accès à l'information where there is a risk of serious injury.
- Portability. You can obtain the personal information you gave us in a structured, commonly used technical format (§7.1).
- De-indexing. You may ask us to stop disseminating your personal information, or to de-index a link, where dissemination causes serious injury to your reputation or privacy.
- Automated decisions. Where a decision is based exclusively on automated processing, you are entitled to be told and to have it reviewed by a person. As stated in §6.5, we make no such decision today; if we ever do, we will tell you before it takes effect.
- Transfers outside Quebec. The Clerk and Amazon Bedrock processing described in §5.2, §6 and §8.1 take personal information outside Canada.
A French version of this policy will be published when we open to Quebec.
13. Changes to this policy
If we make a minor change — clarifying wording, correcting a link, adding detail that does not change what we do with your information — we update this page and the "last updated" date.
If we make a material change — a new purpose, a new processor receiving your personal information, a change to how long we keep something, or a reduction in your rights — we will:
- tell you at least 30 days before it takes effect, by email and in the app;
- explain what changed and why, in plain language;
- where consent is required, ask for it again rather than assuming it.
Continuing to use eznest after a material change takes effect means you accept the updated policy. If you do not, you can close your account under §7.4.
We record what you accepted. When you create an account, we record which version of this policy and of the Marketplace Agreement was in force, when, and from what address — so that if it is ever in question, the answer is a record rather than an assumption. That record is kept even after you close your account, because it is the evidence of what we were permitted to do. It appears in your consent history.
14. Contact
Privacy Officer Niruban Kandasamy Eznest Technologies Inc. (CBCA no. 1801532-5) 226 Kinloch Crt, Nepean, Ontario K2J 5S9, Canada privacy@eznest.ca
Office of the Privacy Commissioner of Canada — priv.gc.ca · 1-800-282-1376 Commission d'accès à l'information du Québec — cai.gouv.qc.ca
Appendix A — Related documents
| Document | What it is |
|---|---|
| Homeowner Marketplace Agreement | The terms between you and eznest for using the marketplace. |
| Acceptable Use Policy | What you may and may not do on the Platform. |
| Privacy and Ethics Charter | The commitments this policy is built on, including no data mining and no pay-to-rank. |
| Subprocessor register | Every external party, machine-verified against our code. |
| Incident response runbook | How we record, assess and report privacy incidents. |
Appendix B — Change log
v1.4, corrected 2026-09-14. The inactive third-party e-signature transport, webhook, remote archive downloader, credentials and deployment wiring were removed from the product source. New agreements use Eznest's native signing ceremony; no new contract or signer information can be sent through the retired integration. Local historical archive reads and immutable database vocabulary remain until a separately authorized read-only production and former-vendor account census establishes the disposition of every historical record. This version removes the retired integration from the current subprocessor register without claiming that historical retention obligations have disappeared.
v1.4, corrected 2026-09-11. §1 (sentence 4), §6 (the AWS row), §9.2 and §9.4 said Nestor's requests are processed in us-east-1. Each request is sent to us-east-1, but the Bedrock inference profiles eznest uses (us.meta.llama3-3-70b-instruct-v1:0, us.amazon.nova-2-lite-v1:0, us.anthropic.claude-haiku-4-5-20251001-v1:0) are cross-region profiles that AWS may serve from us-east-1, us-east-2 or us-west-2 — measured with GetInferenceProfile on 2026-09-11. The policy now says the United States and names the three regions; the consent text in the product already said the United States and is unchanged. The destinations are re-checked quarterly and recorded in the subprocessor register.
v1.4, updated 2026-09-11. §7.4 now says what closing your account does with your sign-in record at Clerk. Before this change it did nothing: eznest erased its own records and left the Clerk sign-in record in place, so the same identity could open a new, empty account. Closing your account now also asks Clerk to delete that record, once our connection to Clerk can carry the request, and keeps the request on record as owed until Clerk confirms; in every state, signing in with an erased identity is refused rather than re-creating an account. To make that refusal hold, Clerk's identifier for you now stays on the anonymized account record, where erasure used to clear it. Under §13 this is a minor change: it adds detail about what deletion does, deletion removes more rather than less, nothing new is sent to any processor, and the one thing newly kept is a suppression key of the same kind as the deletion record §7.4 already said we keep. The effective date is unchanged, and it is recorded here for the same reason as the correction below.
v1.4, corrected 2026-09-12. §3.8 and the entry below said the visit-sync path was retired before the first production release. The repository's release record says otherwise: the first production image (2026-08-26) served a build that still exposed the path until the 2026-09-04 release carried the retirement. The sentences now say that, and rest the "no memo reached us" claim on what is backed — no App Store or TestFlight distribution of the app in that window and a 2026-09-01 production census with no projects — rather than on a date that was wrong.
v1.4, corrected 2026-09-11. §3.10 said "no audio of yours is processed". That was wrong about the provider mobile app, which can record a consented voice memo during a site visit and has been able to since before this policy was first published. The memo stays on the device and no memo has been sent to eznest — the one sync path that could have carried it was retired on 2026-09-02; a production build exposing that path did run from 2026-08-26 to 2026-09-04, but the app had no App Store or TestFlight distribution then and a 2026-09-01 census of production found no projects for a visit to be finalized against — so nothing about what eznest does with your information changed, and under §13 this is a correction to the page rather than a new version requiring re-acceptance. §3.8 now describes the voice memo on its own, and §3.10 says what "not collected" means for audio: not on our servers. We are recording it here for the same reason as the v1.1 corrections below.
v1.4 — 2026-09-07. The Stripe Connect disclosure now names the individual identity, beneficial-owner, bank and verification information Stripe may collect directly when a provider connected account is enabled. It also records that Model A account management can use Stripe-controlled frames embedded on the Payouts page. Stripe's production rollout remains switched off; this publication precedes activation rather than describing it as live.
v1.3 — 2026-09-07. The business-contact disclosure now covers both invoice billing contacts and agreement signing contacts. Both paths require an existing relationship before listing contacts and use the same audited, rate-limited known-address bootstrap for a first commercial document.
v1.2 — 2026-09-04. Signing became native: the third-party e-signature processor was removed from the contract path, and one narrow outbound flow was added — a cryptographic digest of a signature sent to an independent timestamp authority, which receives no document, name, email or address. See §5.2.
v1.1 — 2026-08-30. Published version aligned to the live United States Bedrock processing region and the final public legal set.
Corrections carried into the published policy:
- It named OneSignal as a push-notification processor. OneSignal has never been part of eznest. No push provider receives anything: push is switched off and no device token has left our systems.
- Earlier internal text stated that AI ran on eznest-operated infrastructure, not a third-party cloud. It runs on AWS Bedrock in us-east-1.
- It claimed we learn from de-identified, combined patterns across users to improve AI suggestions. No such mechanism exists, has ever existed, or is planned. Nothing is trained on your data.
- Earlier internal text omitted Clerk, our live identity provider, and did not disclose Bedrock processing in the United States.
- It published retention periods — 7 years for audit records, 24 months for behavioural data, 2 years for marketing — that nothing in our systems enforced. §8.2 now states what is actually enforced, and says plainly that account data is kept until you delete it.
- It described personalization as on by default with a one-tap opt-out. The reality is two separate switches with different defaults; §7.3 sets them out.
- It described the export as a complete copy of everything we hold, and account deletion as removing your data. §7.1 and §7.4 now list exactly what each covers and what it does not.
- It offered controls that were not reachable, including account deletion, which was impossible for every production user until 2026-08-28. That is fixed.
- It claimed TLS 1.3 minimum, analytics cookies we do not set, and a breach log that did not exist. The breach log now does (§9.3).
We are recording these here rather than quietly deleting them, because a privacy policy that has been wrong before should say so.