TansiHub ("TansiHub," "we," "us," or "our"), operated by [TANSIHUB LEGAL ENTITY] of [BUSINESS ADDRESS, ONTARIO, CANADA], respects your privacy. This Privacy Policy explains what personal information we collect, why we collect it, how we use and disclose it, and the choices you have. We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Ontario privacy law.
By creating an account or using TansiHub, you consent to the practices described here. If you do not agree, please do not use the platform.
On this page
- Information we collect
- Identity & biometric verification
- How we use your information
- Payment & escrow information
- How we share information
- Location data
- Data retention & deletion
- How we protect your information
- Your rights & choices
- Cookies & similar technologies
- Children
- International processing
- Changes to this policy
- Contact & complaints
1. Information We Collect
We collect the following categories of personal information:
- Account information — name, email address, phone number, password (stored hashed), postal/location code, and your role (seeker, provider, or both).
- Profile information — profile photo, description, skills, service radius, and provider qualifications or licences you upload.
- Identity verification data — government-issued ID images, a verification selfie / liveness capture, and (optionally) Indigenous community documents. See Section 2.
- Transaction information — jobs and listings you post or bid on, messages, reviews, and escrow payment records.
- Payment information — processed by Stripe; see Section 4. We do not store full card numbers.
- Device & usage information — IP address, device and browser type, app version, and interactions with the platform, used for security, fraud prevention, and reliability.
- Communications — support requests, dispute submissions, and evidence you provide.
2. Identity & Biometric Verification
To keep the marketplace safe, TansiHub offers identity verification. When you choose to verify, we collect an image of your government-issued ID, a live verification selfie, and — if you are verifying Indigenous community status — the community document you provide.
Biometric processing. Your verification selfie is analysed to confirm a live human and to compare your face against the photo on your ID. This facial analysis is performed using Amazon Web Services (AWS Rekognition) and, for document reading, an AI service (Google Gemini). We use this data solely to verify your identity and prevent fraud — never to sell, advertise, or build a facial-recognition database. We rely on your express consent, collected at the time of verification, for this processing.
Verification documents are stored in a private, access-controlled vault. Live copies are automatically deleted on a rolling 30-day basisafter upload. Before deletion, a sealed copy is moved to a separate, restricted compliance archive that we retain only where required for legal, safety, tax, or dispute-resolution purposes, for a maximum of seven (7) years, after which it is permanently purged (unless it is subject to an active legal hold). Access by our staff to either the live vault or the sealed archive is restricted, logged, and permitted only for legitimate compliance or safety reasons.
3. How We Use Your Information
We use personal information to:
- Create and manage your account and match seekers with providers;
- Facilitate jobs, listings, bidding, messaging, and reviews;
- Process escrow payments and payouts, and calculate our service fee;
- Verify identity and Indigenous community status where you request it;
- Detect, prevent, and investigate fraud, abuse, safety issues, and policy or legal violations;
- Provide customer support and resolve disputes;
- Send transactional and service messages (and, where permitted, updates you can opt out of);
- Comply with legal, regulatory, and tax obligations in Canada.
4. Payment & Escrow Information
Payments are processed by Stripe, Inc. and its Canadian services, including Stripe Connect for provider payouts. When you pay, funds are held in escrow and released to the provider on completion, per our Terms of Service. Card details are collected and stored by Stripe under its own privacy policy; TansiHub receives limited transaction metadata (amounts, status, identifiers) but not your full card number. Providers who receive payouts complete Stripe's onboarding and provide information directly to Stripe as required by law.
5. How We Share Information
We do not sell your personal information. We share it only as follows:
- Between users, as needed for a job — e.g. a seeker's general location (town) and a provider's profile are shown to enable a match. Precise home addresses are shared only when required to perform an accepted job.
- Service providers (processors) — Supabase (database & storage), Stripe (payments), AWS (identity/biometric analysis & secure audit storage), Google (AI document reading, maps, push notifications), Upstash (rate-limiting), Resend (email), and Cloudflare (security/CDN). Each processes data on our behalf under contract.
- Legal & safety — to comply with a law, court order, or lawful request; to enforce our Terms; or to protect the rights, safety, or property of users, the public, or TansiHub.
- Business transfers — in a merger, acquisition, or asset sale, subject to this policy.
6. Location Data
With your permission, providers may share device location to appear "online" and be matched to nearby jobs. Seekers provide a postal/location code and, for accepted jobs, a service address. You can disable location permissions at any time through your device settings; some matching features may then be unavailable.
7. Data Retention & Deletion
We keep personal information only as long as necessary for the purposes above or as required by law (including tax and financial-record requirements). Identity-verification images follow the minimization schedule in Section 2. Certain records — such as immutable audit logs, transaction and dispute records, and information under a legal hold — are retained longer where required for legal, accounting, or safety reasons.
When you delete your account, we remove your profile and associated data, including your identity-verification documents from both the live vault and the sealed compliance archive. We may retain, in de-identified or minimized form, records we are legally required to keep (such as transaction and immutable audit records). If your account is subject to an active legal hold, deletion is paused until the hold is lifted, so that information required for a legal or safety matter is not destroyed.
8. How We Protect Your Information
- Encryption of data in transit (HTTPS/TLS) and at rest;
- Private, access-controlled storage for identity documents (no public links);
- Role-based administrative access, multi-factor authentication for privileged accounts, and audit logging of sensitive access;
- Rate limiting, fraud detection, and a secondary immutable audit archive.
No method of transmission or storage is perfectly secure, but we work to protect your information using safeguards appropriate to its sensitivity.
9. Your Rights & Choices
Under PIPEDA and applicable law, you may:
- Access the personal information we hold about you;
- Correct inaccurate or incomplete information;
- Withdraw consent or request deletion, subject to legal retention limits;
- Opt out of non-essential communications.
To exercise these rights, contact us at [privacy@tansihub.ca]. We may need to verify your identity before responding. We will respond within the timeframes required by law.
10. Cookies & Similar Technologies
We only use cookies and local storage that are strictly necessary or functional. We do not use advertising, marketing, or third-party analytics/tracking cookies, and we do not sell your data. Because we set no non-essential cookies, we do not require a consent banner under applicable Canadian privacy law; we disclose what we set below for transparency.
| Name | Type | Purpose |
|---|---|---|
sb-…-auth-token | Strictly necessary | Keeps you signed in (Supabase authentication). |
tansi_return | Strictly necessary | Remembers where to send you after sign-in (1 hour). |
tansi_on_duty_* | Functional | Remembers your on/off-duty status locally (providers). |
notif-dismissed, cat-nudge-dismissed | Functional | Remembers prompts you dismissed so they don't reappear. |
Third-party services we use for security and core features may set their own strictly-necessary cookies: Cloudflare Turnstile (bot/CAPTCHA protection on sign-in), Stripe (payment fraud prevention at checkout), and Google Maps(address search). You can clear or block cookies via your browser settings, but disabling strictly-necessary cookies may prevent you from signing in, paying, or using core features.
11. Children
TansiHub is not intended for anyone under [18] years of age. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
12. International Processing
Some of our service providers may process or store data outside Canada (for example, in the United States). Where this occurs, the information may be subject to the laws of that jurisdiction, and we take steps to ensure it is handled with protection comparable to that required under Canadian law.
13. Changes to This Policy
We may update this policy from time to time. Material changes will be posted here with an updated date and, where appropriate, communicated to you. Your continued use of TansiHub after changes take effect constitutes acceptance.
14. Contact & Complaints
Questions or complaints about your privacy can be sent to our Privacy Officer at [privacy@tansihub.ca] or [BUSINESS ADDRESS]. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.