DRAFT — pre-launch. This policy is draft text pending legal review. The final version will be published before public Phase 2 launch.
Privacy Policy
1. What we collect
- When you create an account: email, display name, region (province/territory), topic interests, locale (EN/FR).
- When you use the service: post content, reactions, reports, login times, IP address (retained max 30 days for spam defence), browser user-agent (for spam defence).
- Optional profile: bio, avatar URL.
- Guardian applicants: credentials submitted privately for verification, stored outside the forum database, encrypted, accessed only by the Founder and a designated Admin, retained while you are a Guardian plus 90 days.
2. What we don't collect
- Your real name (unless you choose to use it as your display name).
- Your precise location (only province/territory region).
- Tracking cookies (no analytics cookies; Plausible is cookieless).
- Ads or marketing data — there are no ads on TowerWatch.
- Cross-site tracking — none.
3. Why we collect it
To operate the service, defend against abuse, and send notifications you opt into.
4. Where it lives
Supabase Toronto region (ca-central-1). Data residency in Canada. Backups encrypted at rest, stored on Canadian infrastructure.
5. Who else sees it
- Supabase (hosting and database) — our data processor.
- Cloudflare (DDoS protection and caching) — sees request metadata.
- Resend (transactional email) — sees email addresses and email body for notifications you opt into.
- Plausible (analytics) — cookieless, aggregate page-view metrics only, no PII.
- That's it. No advertisers. No data brokers. No tracking partners.
6. Your rights under PIPEDA
- Access — request a copy of your data (in-app export).
- Correction — edit your profile or contact us.
- Deletion — delete your account in-app; we hard-delete within 30 days.
- Withdraw consent for optional things (notifications, etc.).
7. Retention
Account-deleted data is hard-deleted within 30 days; IPs are rotated within 30 days; the audit log is retained indefinitely (anonymised for deleted users).
8. Children
TowerWatch is 13+. We do not knowingly collect data from anyone under 13.
9. Breach notification
If a breach affects you, we will notify you as soon as feasible and notify the Privacy Commissioner of Canada as required.
10. Changes
Material changes will be announced to active accounts.
11. Contact
team@wildfire-ready.ca — subject prefix "Privacy —".
Last updated: 2026-05-12.