Privacy

Privacy at RealViu.

How RealViu handles personal information about customers and the buyers and sellers whose records are stored in the platform, including what we collect, why we use it, who processes it and the rights available under Canadian privacy law.

Not legal advice

These pages are written to be understood, not as a substitute for independent legal counsel. If you have questions about how a clause applies to your brokerage, contact us — we won't guess at legal advice, but we'll point you to the right section.

Privacy Policy

Governed by PIPEDA (Canada) · plus Quebec's Law 25 if we serve Quebec-based customers · Last updated September 2, 2026

Policyv1 · in force from 2 Sep 2026, 13:15 Toronto

Ontario has not enacted a general private-sector privacy law of its own — unlike Quebec, British Columbia and Alberta — so the federal Personal Information Protection and Electronic Documents Act (PIPEDA) governs how we handle personal information in the course of our commercial activity here.

1Two kinds of personal information

We handle personal information in two different roles, and the difference matters. Information about our customers — the brokerage staff who open accounts — we collect and use for our own purposes. Information about your clients — the buyers and sellers in your CRM — we process only on your instructions, as your service provider.

2What we collect about customers

  • Account details: name, business name, email, phone, brokerage and licence information.
  • If you sign in with Google, we receive your name, email address and profile photo from your Google account — enough to create and authenticate your account, and nothing more. We don't request access to your Gmail, contacts or Drive.
  • If you sign in or verify your account by SMS, we receive the phone number you provide and use Twilio to send a one-time passcode to it. We don't use that number for marketing messages without separate consent. Standard message and data rates may apply to the SMS itself.
  • Billing details processed by Stripe. We never see full card numbers.
  • Usage and device data: pages viewed, features used, IP address, browser.
  • AI-material upload records: the approving administrator's name or account identifier, timestamp, the version of the notice accepted, identifiers for the related upload and network-verification evidence. Depending on the notice version, that network evidence is either an IP address or a one-way keyed cryptographic fingerprint of the IP address. A fingerprint remains personal information in our care because it is linked to an identifiable administrator and can be used by us to test a candidate address. When a notice says that a fingerprint is used, the address itself is not stored in that acceptance record.
  • Support conversations and anything you send us.

3Why we use it

To provide and secure the service, bill you, support you, tell you about changes, and improve the product. We also use AI-material upload records to confirm that an authorised administrator accepted the notice presented for a particular upload, administer the agreement, investigate disputes or misuse, and establish or defend legal claims. We use personal information for marketing only with the consent Canada's anti-spam law (CASL) requires, and every marketing email carries a working unsubscribe link.

4Client data in your CRM

Enquiries, saved searches and alert subscriptions belong to you. We store and process them so the platform works, and we don't use them for our own marketing or sell them. You decide retention and deletion; we act on your instructions.

5Service providers

We use a small set of infrastructure providers to run the platform, and we choose them deliberately rather than defaulting to a single all-in-one host:

  • Amazon Web Services (AWS) — our own elastic compute servers, primarily in Canada (AWS ca-central-1).
  • Amazon SES — transactional email, sent over private IPs.
  • Amazon S3 — internal backups and infrastructure artifacts, separate from the customer file storage described below.
  • Amazon CloudWatch — server monitoring and activity logs.
  • Supabase — our database layer, run with redundant copies across multiple regions.
  • Redis Enterprise — caching, session state and rate limiting, alongside Supabase.
  • Backblaze B2 — file storage, split into a public bucket for content served to visitors and a private bucket that's never publicly accessible.
  • Repliers — the MLS listing data API behind property search.
  • Cloudflare — CDN, SSL/TLS including white-label SSL on your own domain, domain security, and bot verification on our forms.
  • Google — the "Sign in with Google" option, so you can authenticate without a separate password. Governed by Google's Privacy Policy for the data Google itself holds.
  • Twilio — delivery of one-time passcodes by SMS when you sign in or verify your phone number.
  • Stripe — payments. We never see full card numbers.
  • An in-house AI model — fine-tuned on OpenAI's technology and paired with our own vector database and embeddings, run entirely on our own infrastructure, so it can stay current with your site's listings and content. Your account's conversations and data are never shared with, or used to train, any public model.

Our client admin dashboard is not hosted on any publicly reachable server. It runs on premises, on our own hardware, with access restricted to our staff through multi-factor authentication — there is no internet-facing login to it. We do not currently run third-party analytics or advertising trackers on this site — if that changes we will update this policy and, where required, ask for consent first.

We do not sell your data, or your clients' data, to any third party, and we do not disclose it to one for their own purposes. The only exception is where we are compelled to by a valid order of a court in Canada. Some of the providers above may process data outside Canada; where that applies we use contractual protections comparable to those PIPEDA requires.

6Cookies and tracking

We said in an earlier version of this policy that we set no analytics or advertising cookies, and that this section would say so if that changed. It has changed, so here it is.

Nothing in the analytics or marketing categories below is set until you choose to allow it. Until you choose, they are switched off — not defaulted on — and that applies everywhere, not only where the law requires it. You can change your mind at any time using Cookie settings at the bottom of any page.

  • Strictly necessary — keeping you signed in, protecting our forms from abuse through Cloudflare Turnstile, and remembering the cookie choice you made so we stop asking. These are always on, because the site cannot work without them.
  • AnalyticsGoogle Analytics 4, loaded through Google Tag Manager. It tells us which pages get read, where visitors lose interest, and which of our own templates and plans draw attention. We look at it in aggregate; we are not trying to identify you.
  • Marketing — measurement of which advertising actually brings brokerages to us, so we stop paying for the advertising that does not. When we run campaigns this means Google Ads. If you arrive from an ad, the click identifier in the link may be carried through to our signup page so a signup can be matched to the campaign that produced it.

We use Google Consent Mode, so before you choose, Google's tags are told explicitly that storage is denied and they behave accordingly. We do not sell your personal information, we do not use it to build advertising profiles about you, and we do not share it with data brokers.

Your browser can also block or delete cookies directly. Blocking the strictly necessary ones will break sign-in and our contact forms.

7How long we keep it

Account data for the life of the account plus 24 months. Billing records for 6 years, per Canada Revenue Agency recordkeeping requirements. Client data you control is deleted 30 days after termination unless you ask sooner. Backups roll off within 35 days.

We keep the personal information in an AI-material upload acceptance record only for as long as reasonably necessary to evidence, administer or enforce the agreement, in accordance with a written retention schedule that accounts for applicable limitation periods. An active dispute, investigation, access request, legal hold or legal obligation may suspend scheduled disposal for the affected record. When the retention purpose ends, we delete the personal fields or render them irrecoverable and may retain only non-personal information needed to preserve the integrity of the acceptance ledger.

8Your rights

You can ask for access to your personal information, correction of anything wrong, or deletion where the law allows. Write to support@realviu.com and we respond within 30 days. Because Ontario has no separate provincial privacy regulator for private-sector complaints, you can also complain to the Office of the Privacy Commissioner of Canada, the federal regulator with authority here.

9Security and breaches

We use encryption in transit and at rest, access controls and logging. If a breach creates a real risk of significant harm, we notify affected people and the Privacy Commissioner of Canada as soon as feasible, as PIPEDA requires, and we tell affected customers promptly.

10Contact

Privacy contact: support@realviu.com — 100 King Street West, Toronto, Ontario M5X 1A9, Canada.

Privacy request?

Ask for access to your personal information, correction of anything wrong, or deletion where the law allows. We respond within 30 days.

Email support
Get started Assist Call