Privacy Policy
Version 2026-09-08 · Effective 8 September 2026
Draft — not yet reviewed by legal counsel. This document is a structured starting point written around PIPEDA's ten fair information principles and CASL's consent requirements, amended below to disclose our handling of personal information for organizations and users based in the Kingdom of Saudi Arabia. It has not been reviewed by a lawyer and must not be relied on as legal advice — the Saudi amendment (§5a) in particular is a placeholder for counsel with Saudi PDPL experience to review, not a compliance determination. Have counsel review it before launch. The version string above is real: it is recorded against every account that accepts this policy.
MaterialDocket ("we", "us") provides an estimating and procurement platform for contractors in Canada, the United States, and Saudi Arabia. This policy explains what personal information we collect, why, and what you can do about it. It is written to meet our obligations under the Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada's Anti-Spam Legislation (CASL), and — for organizations based in Saudi Arabia — is amended in section 5a to address the Kingdom's Personal Data Protection Law (PDPL).
1. Accountability
We are responsible for personal information under our control. Our Privacy Officer is reachable at privacy@materialdocket.com and is accountable for our compliance with this policy.
When we use service providers to process personal information on our behalf, we require them by contract to provide a comparable level of protection.
2. What we collect, and why
Information you give us when you sign up
| What | Why |
|---|---|
| Your name and email address | To create and secure your account, and to contact you about it |
| Your company name and details (address, phone, size, work categories) | To set up your organization and put your company details on the documents you produce |
| Your password | Stored only as a cryptographic hash, never in readable form |
Information you enter as you work
Clients, projects, estimates, inventory, and supplier relationships. Some of this is personal information about other people — most often your own clients, who are frequently private individuals. You are responsible for having a proper basis to enter their information; we process it on your behalf.
Consent records
When you accept our Terms and Privacy Policy, or opt in to marketing email, we record: which consent it was, the version of the document, whether you granted it, the time, and the IP address and browser user-agent of the request. We collect these last two because CASL and PIPEDA require us to be able to prove consent, and we cannot do that from a checkbox alone.
These records are append-only. They cannot be edited or deleted from within the product, by you or by us — that is what makes them evidence.
Technical information
Server and security logs, including IP addresses, generated when you use the Service.
We do not collect payment card numbers. Payments are handled by our payment processor; we store only the identifiers it gives us so we can tell whether your subscription is active.
3. Purposes
We use personal information to: provide and operate the Service; authenticate you and keep accounts secure; bill you; provide support; meet legal obligations; detect and prevent abuse; and — only if you have opted in — send product updates.
We do not sell personal information, and we do not use your data to train machine learning models.
4. Consent
We ask for your consent when you sign up, and we ask for it in two separate places on purpose:
- Terms of Service and Privacy Policy — required to hold an account. You cannot use the Service without agreeing to them.
- Product updates by email — entirely optional, never pre-ticked, and never bundled with the required consent. This is CASL express consent.
Withdrawing consent. You can turn off product-update email at any time from Settings → Preferences → Notifications. We are not sending product-update email yet; your preference is recorded now and honoured from the first message we send. When we do begin, every such message will carry an unsubscribe link. We action a withdrawal by either route promptly, and in any case within 10 business days, as CASL requires. Withdrawing marketing consent does not affect service messages we must send you about your account — billing notices, security alerts, and changes to these documents.
Withdrawing consent to the Terms or this Privacy Policy means closing your account, since we cannot operate the Service without them.
Note that withdrawing consent does not erase the record that you once gave it. That record is what proves we had a basis to contact you at the time, and we are required to keep it.
5. Disclosure and where your data lives
We share personal information only with service providers who need it to run the Service:
| Provider | Role |
|---|---|
| Supabase | Database, authentication, and file storage |
| Vercel | Application hosting |
| Stripe | Payment processing |
| Resend | Transactional email |
Some of these providers process or store data outside Canada, including in the United States. While it is there, it may be accessible to foreign courts, law enforcement, and national security authorities under the laws of that country. We use providers that offer contractual and technical safeguards, but we cannot put your data beyond the reach of foreign law.
We may also disclose personal information where required by law, or to establish or defend a legal claim. If we are ever compelled to hand over your data, we will tell you unless we are legally prohibited from doing so.
If MaterialDocket is involved in a merger or sale, personal information may transfer as part of that transaction, subject to this policy.
The supplier registry. MaterialDocket maintains a shared registry of supplier companies — legal names, domains, and branch addresses — visible to all users so that everyone sees one canonical record instead of private duplicates. Your private relationship data (contacts, notes, negotiated prices) is never part of it. Your clients are never in the registry: they are frequently private individuals, and publishing their names and addresses platform-wide would be neither proportionate nor reversible.
5a. Organizations and users based in Saudi Arabia
Placeholder pending review by counsel qualified in Saudi PDPL. This section is drafted to disclose our current architecture honestly, not to assert that it satisfies the Kingdom's Personal Data Protection Law. Do not treat it as a compliance determination.
If your organization is based in Saudi Arabia, this section applies to you in addition to the rest of this policy.
Where your data is processed. MaterialDocket's infrastructure runs in
Canada (ca-central-1). We do not currently operate a Saudi-hosted instance.
This means personal information you or your organization submits — including
information about your own clients and staff — is transferred out of the
Kingdom of Saudi Arabia and processed and stored in Canada, subject to the
safeguards and foreign-law risks described in section 5 above.
Basis for the transfer. [Placeholder: the specific PDPL Article 29 exception or Saudi Data & Artificial Intelligence Authority (SDAIA) approval route relied on for this cross-border transfer is to be confirmed by counsel — for example, transfer necessary to perform a contract with the data subject, or transfer under adequate safeguards, as PDPL and its Implementing Regulations define them.]
Your rights under PDPL. In addition to the rights described in section 8, where PDPL applies to you we intend to honour the data subject rights it provides, including the right to be informed, the right to access, the right to request correction, and the right to request destruction of personal data that is no longer necessary for the purpose it was collected — subject to the same retention obligations described in section 6. [Placeholder: confirm the process and response timeline for a PDPL-specific request, and whether it differs from the PIPEDA-oriented process in section 8.]
Contact for Saudi data subjects. [Placeholder: a designated contact point for PDPL-related inquiries, if one is required or advisable, in addition to privacy@materialdocket.com; and whether SDAIA notification obligations apply to us as a data controller or processor in this arrangement.]
If we open a Saudi-hosted instance in future, this section will be updated to reflect it, and the version above will be bumped so affected accounts are asked to re-consent.
6. Retention
We keep personal information only as long as we need it:
- Account and business data — for as long as your account is open, then 30 days after closure so you can export it, then deleted or irreversibly anonymized.
- Consent records — for 3 years after the consent ends or the account closes, whichever is later. CASL requires us to be able to prove consent, and this is the window in which we could be asked to.
- Billing records — as long as tax law requires.
- Security logs — typically 90 days.
7. Safeguards
Data is encrypted in transit and at rest. Access between companies is enforced in the database itself, not only in application code, so one company's users cannot read another's records. Internal access is limited to staff who need it, and our support console is read-only: it cannot modify tenant data, and it deliberately cannot see your consent records' IP addresses.
No system is perfectly secure. If a breach creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as PIPEDA requires.
8. Your rights
You may:
- See what we hold about you, and get a copy;
- Correct anything inaccurate — most of it directly in Settings;
- Withdraw marketing consent, as described in section 4;
- Ask us to delete your personal information, subject to the retention obligations in section 6;
- Complain — to us first, at privacy@materialdocket.com. If you are not satisfied, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
We respond to access requests within 30 days. We may ask you to verify your identity first.
If you are a client of one of our customers: a contractor using MaterialDocket may hold your information. We process it on their behalf, so please contact them directly. If you cannot reach them, contact us and we will help.
9. Cookies
We use cookies that are strictly necessary to run the Service — keeping you signed in and protecting against cross-site request forgery. We do not use advertising cookies or third-party tracking pixels. Blocking necessary cookies will stop you from signing in.
10. Children
The Service is for businesses. We do not knowingly collect personal information from anyone under 18. If we learn we have, we will delete it.
11. Changes to this policy
We may update this policy. When we make a material change we will bump the version above, publish the updated policy, and ask you to accept it the next time you sign in. We will not apply a materially different purpose to information we already hold without asking you first.
12. Contact
Privacy Officer — privacy@materialdocket.com
To confirm before launch: the Privacy Officer contact, the registered business name and mailing address, and the retention periods above must be reviewed and filled in before this policy is published.