Privacy policy
Version 3.3 · in effect from
This policy explains what personal information MapleCrew collects, why it is needed, who may receive it, how it is protected, and the choices available to you.
1. Who this covers
MapleCrew Inc. is responsible for the personal information described here. We are based in Ontario and operate under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
This policy covers customers, providers, and anyone who contacts us. It applies to the website, the booking platform and our email correspondence.
The short version
We collect what the service needs to work, we do not sell it, and you can ask to see it, correct it or have it deleted.
2. What we collect
From everyone
- Account details — name, email address, phone number.
- Technical data — IP address, browser and device type, page visits, website performance measurements, and the server logs needed to keep the service running and secure.
From customers
- The service address, and access notes such as “side gate, unlocked”.
- Your answers to the job questions, plus any notes and photos you attach.
- Booking and payment history. Full card numbers are handled by our payment processor and never reach our systems.
- Messages you exchange with a provider through the platform, and with our support team.
From providers
- Government photo identity, verified automatically through Stripe Identity, our identity verification provider — MapleCrew does not receive or store the underlying document image for a new verification.
- Provincial trade licences for regulated trades, with the licence number, trade and expiry date.
- Service area, rates, the services offered, and banking details for payouts.
- Tax-identification information for our own platform tax records — a Social Insurance Number, and a GST/HST registration number where a provider has one. A GST/HST number is never required.
- Ratings, reviews and job history.
Sensitive information
Identity documents, trade licences and Social Insurance Numbers are the most sensitive things we hold. A Social Insurance Number is encrypted before it is stored and is never shown back to anyone, provider included, once submitted. Access to sensitive information is limited to the people who need it, and every decision made against it is logged and attributed.
We do not buy personal information from data brokers, and we do not collect information about children. The platform is for adults.
3. Why we collect it
PIPEDA requires us to identify the purpose before or when we collect. These are ours, and we do not use your information for anything else without asking.
- To create and run your account.
- To match you with providers who offer the service and are actually available.
- To collect customer payments, process refunds, and release eligible provider earnings after the customer protection period.
- To verify that every provider is who they say they are, and holds the licences they claim — the promise the whole service rests on.
- To resolve disputes, where we need both sides' accounts and any photos.
- To keep the platform safe — detecting fraud, abuse and misuse.
- To measure website traffic and performance so we can maintain and improve the customer website.
- To answer you when you contact us.
- To meet tax, accounting and legal obligations in Ontario.
We send marketing email only if you have opted in, and every one has an unsubscribe link. Unsubscribing never affects your bookings.
5. The companies that help us run MapleCrew
We do not run every part of this service ourselves. The companies below process personal information on our behalf, only for the purpose described, and only under contract with us. They are not permitted to use your information for their own purposes.
- Supabase — our database, sign-in system and file storage. Most of what we hold lives here.
- Stripe — payments, provider payout accounts, and identity verification.
- Google Maps Platform — when you type or select an address, it is sent to Google to turn it into a location and to estimate travel distance.
- Resend — sends our transactional email, including sign-in codes and booking updates.
- Sentry — records technical errors so we can find and fix faults.
- Expo — delivers push notifications to our mobile apps.
- Vercel — hosts the customer website, measures page visits through Web Analytics, and records website performance metrics through Speed Insights.
We do not use advertising networks or data brokers, and we do not sell or rent personal information to anyone.
6. Where it is stored
Personal information may be stored or processed in Canada and in other countries where we or the companies above operate. Our main database is currently hosted in Australia, and several of the providers listed above operate in the United States.
While information is in another country, it can be accessed by the courts and law enforcement of that country under their laws, and those laws may differ from Canadian law. We cannot contract that away, so we would rather say so plainly.
We choose providers that offer protection comparable to what Canadian law requires, and we bind them contractually. If a provider or a hosting region changes, we will update this list.
7. How long we keep it
We keep personal information only for as long as it is reasonably needed for the purposes it was collected for — running the service, completing and settling bookings, resolving disputes, preventing fraud, enforcing our agreements, and meeting our legal, tax, accounting and regulatory obligations.
How long that is depends on the record. Some examples of what drives it:
- Booking, payment and refund records — kept after an account is closed. They are the record of money that moved, and tax and accounting rules require us to be able to produce them.
- Dispute records — kept while a dispute or a related claim is open, and afterwards where we may still need to account for the outcome.
- Provider qualification and licence records — kept while the provider is active, and afterwards where needed to explain a decision we made or to meet a legal obligation.
- Provider tax-identification information — kept while the provider is active and afterwards where needed to meet our own tax, accounting or legal record-keeping obligations.
- Fraud and security records — kept where reasonably necessary to protect customers, providers and the platform.
- Records of decisions we made about an account — kept, because they exist precisely to be reviewed later.
- Account details — until you close your account, after which they are anonymised as described below.
When information is no longer needed for any of these purposes, it is deleted, anonymised or otherwise securely disposed of in line with our retention practices.
We would rather not give you a number we cannot keep
We are working through a detailed retention schedule with professional advice, and we will publish specific periods here once they are settled and we can actually enforce them. Until then we have described what genuinely drives how long we hold things, rather than quoting dates we do not yet act on.
8. What happens when you delete your account
You can delete your account from the app, or from the account deletion page on this site. We do not make you email us to ask.
Deleting an account is not the same as erasing every trace of it, and we would rather be straight with you about the difference.
- Your sign-in is destroyed. The login record is permanently deleted and cannot be restored. You will not be able to sign back in.
- Your personal details are anonymised. Your name, phone number, address and location are removed from your profile, and your email address is replaced with an unusable placeholder so it can be used to register again later.
- Your bookings and payment records stay. They are the record of money that actually moved between you, a provider and us. We cannot rewrite them, and tax and accounting rules require us to keep them.
- An open dispute continues. If a dispute is unresolved, it runs to its conclusion — otherwise deleting an account would become a way to walk away from one.
- Uploaded files are deleted. Job photos and provider documents are removed from storage.
- Records of decisions we made are kept. If we approved, restricted or reviewed an account, that record remains, because it exists to be reviewed later.
If you are a provider with money still to be paid out, we may not be able to close your payout account until the balance clears. We will tell you if that applies to you.
Stripe keeps its own records of payments and identity checks under its own retention rules and legal obligations. Deleting your MapleCrew account does not erase those, and we cannot delete them on your behalf.
9. Your rights
Under PIPEDA you can:
- Ask what personal information we hold about you and get a copy.
- Ask us to correct anything inaccurate or incomplete.
- Ask us to delete information we are not required to keep.
- Withdraw consent for marketing at any time.
- Ask how we handled your information, and challenge our compliance.
Write to support@maplecrewservices.com. We will confirm receipt and respond within 30 days, as PIPEDA requires. If we cannot meet that, we will tell you why and when we can.
If you are not satisfied with our answer
You can complain to the Office of the Privacy Commissioner of Canada. You do not need our permission and you do not need to go through us first.
There are limits: we may not be able to delete records we must keep for tax or legal reasons, and we will not disclose information that would reveal another person's personal information.
You can permanently close your MapleCrew account from Account settings. See our account deletion instructions for the steps and what happens to retained records.
10. How we protect it
- Access is limited to the people who need it to do their job.
- Every action taken on an account by our operations team is logged and attributed to a named person.
- Payment card details are handled by our payment processor, not stored by us.
- A provider's Social Insurance Number is encrypted before it is stored, using a key our systems hold and nothing else does. It is never included in ordinary account displays, support tools, error reports or activity logs — only a masked reference (its last 3 digits) is ever shown again.
- Data is encrypted in transit.
No system is perfectly secure. If a breach creates a real risk of significant harm to you, we will tell you and the Privacy Commissioner promptly, as PIPEDA requires.
12. Changes to this policy
If this policy changes materially we will say so on the site before the new version takes effect, and the version and date at the top of this page will change. Previous versions are kept.
13. Contacting us about privacy
support@maplecrewservices.com reaches the person accountable for privacy at MapleCrew Inc., not the general inbox. Other ways to reach us are on the contact page.
Plain-language summaries in shaded boxes are there to help you read the document. They are not a substitute for the clause they sit beside, and where they differ the clause governs.