Legal
Privacy Policy
The secure contact-request form is active, and this policy describes its data flow. General direct-email contact is not offered. The email below is available only for privacy questions, consent withdrawal, deletion requests, and help if you're unsure about a form submission.
Who is responsible
Insure.ance is responsible for personal information handled through this website. The designated public role is the Insure.ance Privacy Contact. Privacy questions, access or correction requests, consent withdrawals, and deletion requests can be sent to [email protected].
Contact information is collected only to review and respond to the request a visitor chooses to send. It is not used for marketing or unrelated outreach without a separate, future consent process.
What the website handles
Calculator entries stay in your browser tab. They are not submitted, stored, connected to an identity, or used for analytics.
If the contact form is active, it asks only for a first name, email address, optional province or territory, an optional topic selected from a fixed list, and consent to receive a direct reply. The system also records the consent wording version, submission time, source page, status, an optional next-step due date, retention date, and a random lead reference. There is no phone field, open message box, or marketing signup.
If you email the privacy contact — for a privacy question, consent withdrawal, deletion request, or help with a form submission — the inbox receives your address, message, and anything else you choose to include. Please keep email to what the request needs and do not send health or medical details, Social Insurance Numbers, dates of birth, identity documents, policy or account numbers, or detailed financial information.
Why it is handled
Contact information is used only to review and reply to the request, keep a minimal record of its status, prevent abuse, meet legal or regulatory obligations, and respond to privacy requests. It is not sold, used for advertising, or added to a marketing list.
Consent and withdrawing it
The form requires an unticked consent box before submission. That consent covers one direct reply and any conversation you choose to continue; it does not create a professional relationship or consent to marketing. You can withdraw consent or end the conversation at any time by emailing [email protected]. Withdrawal does not affect handling that was already required by law.
Service providers and data location
Cloudflare hosts and protects the website. When the form is active, Cloudflare Pages Functions processes the request, Turnstile checks for automated abuse, and Cloudflare D1 stores the minimal contact record. Cloudflare may process or store information outside Canada. Its location hints do not guarantee Canada-only residency.
Email to the privacy contact is handled by Google Gmail, which processes information under its own service and privacy terms. No form contact details are placed in notification email; any notification contains only the random lead reference.
Technical and security information
The site has no first-party analytics, advertising pixels, or behavioural profiles. Like other hosted websites, Cloudflare necessarily processes network and device information to deliver the pages, prevent abuse, and operate Turnstile. The application does not store raw IP addresses, browser user-agent strings, form request bodies, or contact details in application logs.
Retention and deletion
- Rejected or obvious automated submissions are not stored.
- Every stored website-form request receives an immutable deletion deadline 89 days after receipt. An hourly purge is designed to remove due rows within the 90-day public target. Status and follow-up fields do not extend the schedule; a purge failure requires collection to be disabled until cleanup succeeds.
- If an inquiry needs to become a regulated or client record, the required information moves to the approved recordkeeping system. The website-form copy may be deleted sooner and remains subject to its original deletion schedule.
- Emails to the privacy contact are reviewed and deleted when no longer needed, normally within 180 days after the last activity unless a longer period is legally required.
You may request earlier deletion. Cloudflare D1 includes a provider-managed recovery window, so deleted rows may remain restorable until that window expires. A database recovery is a restricted incident process; after any recovery, records already past their deletion deadlines must be deleted again promptly.
Safeguards
The form code uses encrypted transport, strict server validation, bot verification, least-privilege service bindings, retention dates, and a server-side emergency-off switch. The production release procedure additionally requires an exact-path /api/lead rate limit, separated preview and production data, and restricted operator access. The public form cannot be built in live mode unless its required public configuration is present.
Your privacy rights
You may ask what personal information is held about you, request a correction, withdraw consent, or ask for deletion, subject to limited legal exceptions. Email [email protected]. Identity may need to be verified before information is disclosed or changed.
Please send a privacy concern to the address above so it can be reviewed. If it is not resolved, you may also contact the Office of the Privacy Commissioner of Canada.
Changes to this policy
Material changes to collection, purpose, providers, or retention will be reflected here before the changed practice is enabled.
Last updated: July 17, 2026.