Privacy Policy

Effective Date: February 1, 2026

Last Updated: February 1, 2026

Introduction

Inspekto AI Inc. ("Inspekto," "we," "us," or "our") is an Alberta corporation (Corporation Number: 2027839030) committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website and services (collectively, the "Service"). We comply with applicable privacy laws in Canada, including the Personal Information Protection and Electronic Documents Act (PIPEDA), and relevant U.S. state laws, including the California Consumer Privacy Act (CCPA) and similar legislation. By using our Service, you agree to the practices described in this Policy. If you do not agree with this Policy, please do not use our Service.

1. Information We Collect

We collect only the personal information necessary to provide our Service, process transactions, and improve your experience. The information we collect includes:

1.1 Account Information

When you create an account, we collect your email address and password. Your password is stored securely using industry-standard hashing and encryption. We may also collect additional profile information you choose to provide, such as your name or company name.

1.2 Payment Information

When you purchase credits or subscriptions, payment processing is handled by our third-party payment processor, Stripe. Stripe collects your payment card information, billing address, and related transaction data. We do not directly receive, process, or store your complete payment card details. We retain basic transaction records (transaction ID, amount, date, and status) to manage your account balance and provide receipts.

1.3 Usage Data

We automatically collect certain technical information when you use our Service, including your IP address, browser type and version, device type, operating system, pages visited, features used, date and time of access, and referring website URLs. This data helps us maintain, secure, and improve our Service.

1.4 Authentication and Storage Data

We use Supabase for user authentication and data storage. Supabase processes your account credentials and stores your account data in accordance with their security standards. Your data is encrypted both in transit and at rest.

1.5 Cookies and Tracking Technologies

We use cookies and similar technologies to maintain your session, remember your preferences, and analyze how our Service is used. Essential cookies are necessary for core functionality such as maintaining your logged-in session. You can control cookie settings through your browser, though disabling certain cookies may affect Service functionality.

2. How We Use Your Information

We use your personal information for the following purposes:

  • Service Provision: To create and manage your account, authenticate your identity, provide access to features, and deliver the services you request.
  • Transaction Processing: To process payments, manage your credit balance, generate receipts, and maintain transaction records for accounting purposes.
  • Service Improvement: To analyze usage patterns, troubleshoot technical issues, optimize performance, and develop new features.
  • Communication: To send you essential service notifications, account updates, security alerts, and respond to your inquiries. We will only send marketing communications if you have opted in, and you may unsubscribe at any time.
  • Security and Fraud Prevention: To detect and prevent unauthorized access, fraudulent activity, security threats, and to enforce our Terms of Service.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, and governmental requests, including tax and financial reporting obligations.

3. How We Share Your Information

We do not sell, rent, or trade your personal information. We share your information only in the following limited circumstances:

3.1 Service Providers

We engage trusted third-party service providers to perform functions on our behalf, including:

  • Stripe: Payment processing and transaction management
  • Supabase: User authentication, database hosting, and data storage
  • Hosting Providers: Web hosting and infrastructure services

These service providers are contractually bound to protect your information and use it solely to provide services to us.

3.2 Legal Requirements

We may disclose your information when required by law or in response to valid legal processes, such as court orders, subpoenas, or government requests. We may also disclose information to protect our rights, prevent fraud, enforce our Terms of Service, or protect the safety of our users or the public.

3.3 Business Transfers

If Inspekto AI Inc. is involved in a merger, acquisition, asset sale, or bankruptcy, your personal information may be transferred as part of that transaction. We will notify you of any such change and the choices you may have regarding your information.

4. Data Security

We implement industry-standard security measures to protect your personal information, including:

  • Encryption: All data transmitted between your browser and our servers is encrypted using SSL/TLS (HTTPS). Passwords are hashed using cryptographic algorithms and never stored in plain text.
  • Access Controls: Access to personal information is restricted to authorized personnel who require it to perform their duties. All team members are bound by confidentiality obligations.
  • Secure Infrastructure: We use Supabase for secure data storage with encryption at rest, and Stripe (PCI DSS Level 1 certified) for payment processing.
  • Regular Monitoring: We continuously monitor our systems for security vulnerabilities and unauthorized access attempts.

While we take reasonable steps to protect your information, no internet transmission or electronic storage method is completely secure. You are responsible for maintaining the confidentiality of your account credentials. Please notify us immediately if you suspect unauthorized access to your account.

5. Data Retention

We retain your personal information only as long as necessary for the purposes described in this Policy or as required by law:

  • Account Data: Retained while your account is active. Upon account deletion, we will delete or anonymize your personal information, except where retention is required for legal or legitimate business purposes.
  • Transaction Records: Retained for the period required by applicable tax, accounting, and financial regulations (typically 7 years in Canada).
  • Usage Logs: Retained for up to 12 months for security monitoring and service improvement purposes, unless longer retention is required for security investigations.

When information is no longer needed, we securely delete or anonymize it in accordance with our data retention policies.

6. Your Privacy Rights

You have the following rights regarding your personal information:

  • Right to Access: You may request a copy of the personal information we hold about you and information about how we process it.
  • Right to Correction: You may request that we correct inaccurate or incomplete information. You can also update certain information directly through your account settings.
  • Right to Deletion: You may request that we delete your personal information, subject to certain legal exceptions (such as records we are required to retain for tax or legal purposes).
  • Right to Withdraw Consent: Where we rely on your consent to process your information, you may withdraw that consent at any time.
  • Right to Data Portability: You may request a copy of your data in a structured, commonly used format.
  • Right to Object: You may object to certain types of data processing, including direct marketing.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

Exercising Your Rights

To exercise any of these rights, please contact us at inspektoai@gmail.com. We will verify your identity before processing your request and respond within the timeframes required by applicable law (typically 30 days under PIPEDA, 45 days under CCPA). There is no fee for making a request unless it is excessive or manifestly unfounded. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada or your state Attorney General's office, as applicable.

7. Cross-Border Data Transfers

Inspekto AI Inc. is based in Alberta, Canada, and serves users in Canada and the United States. Your personal information may be transferred to, stored, and processed in jurisdictions outside your province or state, including the United States. Data stored in these jurisdictions may be subject to local laws and accessible by law enforcement and government authorities in those jurisdictions. We implement appropriate safeguards for international transfers, including contractual protections with our service providers. By using our Service, you consent to these transfers.

8. Children's Privacy

Our Service is not directed to individuals under 13 years of age, and we do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately, and we will take steps to delete such information and terminate the account.

9. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, technologies, or legal requirements. We will post the updated Policy with a new "Effective Date" and notify you of material changes through email or a prominent notice on our website. Your continued use of the Service after changes become effective constitutes acceptance of the updated Policy. We encourage you to review this Policy periodically.

10. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us:

Inspekto AI Inc.

Corporation Number: 2027839030

Address: Apt 508, 1110 11th Street SW, Calgary, AB, Canada

Email: inspektoai@gmail.com

We are committed to addressing your privacy concerns and will respond to your inquiry promptly. In accordance with PIPEDA, we have designated personnel responsible for privacy compliance who can be reached through the contact information above.