Start a check
SignAllow

Privacy Notice

What we collect, why, and who handles it

The check itself runs in your browser. The address you type, the measurements you enter, the answers you give the checklist, the result and the report are worked out on your own device. Address lookup and picked coordinates are processed as described below. Local checks stay on your device unless you explicitly choose Save to my account. That optional action sends the saved project name, address, measurements and selected answers to SignAllow, together with a dated result summary and the full research and customer-summary PDFs. These reports include the government map findings and source dates shown at the time of saving. Local history is never uploaded automatically.

Unfinished checks in this browser

While you fill in a check before submission, the tool automatically keeps one unfinished draft in this browser. It contains your address, municipality, sign type, form inputs and measurements, manual review choices, form step, last-edit time and, if you selected an address suggestion, its coordinates. Automatic map findings, calculated reports, account identifiers and payment details are not saved in the draft. Purpose: restore unfinished work without signing in or using a check. Drafts are not uploaded to your account or synchronized to other devices. Anyone using this browser profile can see the restored draft.

A draft expires 7 days after its last edit and is removed when the tool is next opened. Start fresh, a successful check, or clearing this site’s browser data removes it earlier. Opening a different check and editing it replaces the unfinished draft; existing saved projects and past checks are not deleted. Other tabs cannot silently overwrite a changed draft. Storage restrictions or private browsing may prevent saving or retaining it, and the tool shows a message when a save fails. On restoration, saved coordinates refresh the existing same-origin government map lookups described below; only the point is forwarded to those map servers. Old automatic findings are not treated as current.

Some things do leave your browser. This notice says exactly which, why, who handles them and for how long. It describes what the site does today.

Saved check allowances

To avoid charging again for a property refinement, your browser sends SignAllow a one-way fingerprint of the normalised address and municipality, plus a signed allowance when returning. The meter does not receive the raw address or measurements. A fingerprint may still be linkable to an address; we do not treat it as anonymous. The signed allowance contains that fingerprint, the municipality, issue and expiry times, and an opaque account or browser identifier. It is used only to validate the 90-day revision period, not for advertising or analytics, and is not sent to map providers.

Visitors receive an essential, secure browser-identification cookie lasting up to 90 days; each new visitor check can renew the cookie, but never extends an existing allowance. Browser storage keeps up to 100 recent allowances until removed or replaced. Clearing past checks removes those local allowances; clearing cookies removes visitor access to them. When you explicitly save a project, its allowance is stored with the inputs in our existing Cloudflare database and bound to your account, with the same expiry. People authorised to open the project can use it under that account. It remains with the project until updated or deleted; it is excluded from customer reports, share links and personal project-detail exports.

Optional project notes and next steps

When you choose Notes & next steps and save, we store the current notes text (up to 4,000 characters), next step (up to 500 characters), completion status, last editor’s membership email, save date, revision and accepted Privacy Notice version in our existing Cloudflare database. These are internal working notes to help you and selected project collaborators coordinate work. Anyone currently allowed to edit the project can read and update them; removing shared access also removes access to notes. They do not change the by-law assessment and are not included in report PDFs, web reports, shared check links or private project duplicates. Saving replaces the current notes; we do not keep a notes revision history. Clear text and save to remove it. The latest save date, editor email and revision remain with the project until its creator deletes the project or asks us to delete it. Project deletion removes these notes and metadata too. Existing database backups may retain deleted data temporarily as described below.

Product feedback

When you choose Give feedback and send the form, we store the category, message (up to 4,000 characters), optional reply email, a random submission reference, submission date and accepted Privacy Notice version in our existing Cloudflare review queue. If you tick Include basic diagnostics, we also store the page category, screen-size group and site build shown in the form. We do not attach the URL, address, project, report, account identity or browsing history. We use this to investigate problems and plan improvements, and may use your supplied email to respond about your message. No marketing subscription is created. Feedback is deleted after 12 months when the next feedback submission triggers cleanup; you may request earlier deletion from the Privacy Officer. Existing provider backups may retain deleted records temporarily. A separate keyed connection counter limits submissions for one hour; the connection address is not stored with feedback.

Internal job references

You may optionally save an internal job number of up to 64 characters with a project, alongside its existing name. It follows the project’s existing access, sharing and deletion rules. It is used for account display and search and included in your personal project-details export. It is excluded from customer PDFs, web reports and shared check links. Editing names or job numbers changes current project metadata without replacing earlier report versions.

Optional account-saved projects

If you have an active membership, you can explicitly save up to 200 projects to your account. We store the project name, check inputs (including address, municipality, sign type, dimensions and selected checklist answers), creation and update dates, the Privacy Notice version confirmed when saving, and an account-linked identifier in our existing Cloudflare database. Each new save can also retain a dated result summary, report reference, software and rules versions, and both generated PDFs in the same database, including map findings and source dates contained in the reports. Up to 20 dated versions are retained per project, with no automatic removal of older versions. This lets you reopen inputs or view and download the original saved reports on another device after signing in. New projects are private to the person who saved them, including individual teammates. On an active Pro account, the creator can explicitly share a project and all its dated versions with selected current teammates. Those selected can view and edit inputs, save new versions, download reports and make private duplicates. Only the creator can manage sharing or delete the project and its versions. We store the sharing selection and update date, creator and selected teammate email addresses, and the email address of the person saving each new report version. Selected collaborators can see the creator and saver email addresses. The sharing chooser lists existing team email addresses so a creator can select the intended people; it does not add people to the billing account.

We retain saved projects and dated versions until the creator deletes them or asks us to delete them. Sharing selections remain until the creator changes them, deletes the project, or a relevant teammate is removed. Removing a teammate revokes their shared access, and removes sharing on projects they created; re-adding the person does not restore those grants. Shared access is paused without an active Pro plan. Removing access cannot recall reports already downloaded or private duplicates already created. The creator can delete an individual dated version, or delete a project and all its versions. Cancelling a membership does not automatically delete projects: the account holder can still sign in to open, download or delete them, but an active membership is required to save changes. A removed teammate loses access; contact the Privacy Officer for access or deletion assistance. Deleting a project removes it and all its dated versions from the active database; provider recovery copies may remain under Cloudflare’s backup retention. Clearing browser history does not delete account-saved projects.

Appearance preference

When you choose System, Light or Dark while signed in, we store that choice, an account-linked identifier, a revision number and the latest save time in our existing Cloudflare database. Each teammate has a separate preference. It is used only to apply your theme across signed-in devices; it is not a marketing event and contains no check or project details. We keep the current preference until you replace it or ask the Privacy Officer to delete it. System follows each device’s own appearance setting. The effective browser choice is cached locally to apply it before the page loads; visitors use this browser-only storage. Clearing browser data removes the local copy, not the account preference. We do not upload an existing browser choice until you explicitly select or save a theme, or use the header theme switch while signed in.

Who is responsible

SRD Media Group Inc., carrying on business as SignAllow, is responsible for personal information under its control, including information that service providers handle for us. Our privacy contact is the Privacy Officer: admin@signallow.ca.

What we collect, and why

  • The municipality you pick. The rules for one municipality are fetched when you run a check on it, so its name is sent. Your address is not sent with the rules request. Address lookup and optional account-project saving are described separately below. Purpose: to show you the rules.
  • Which municipalities you have checked today. A second signed cookie lists the municipalities you have spent a check on in the last 24 hours, with the time each one expires, so the check you paid for keeps working while you refine it. It holds municipality names and times and nothing else, and it expires after 24 hours.
  • A count of checks. A cookie holds how many checks you have run, signed so it cannot be edited. It contains a number and nothing else. Purpose: the free-check allowance.
  • Your acceptance of the terms. A random reference number, the version of the Terms and of this notice, the date and time, and whether you accepted at first use or at checkout. No name, email or IP address is stored with it. Purpose: to show which terms applied to your use.
  • Ordinary server logs. Your IP address, browser and the pages requested, kept by Cloudflare. Purpose: to run and secure the site.
  • If you pay: your email address, an identifier for your Stripe customer record, which plan you are on, its status and renewal date, on Starter how many checks you have used in the current billing month, your acceptance of the terms at checkout, and a random access token your browser holds in a cookie. Purpose: to give you what you paid for, return it to you on another device, and keep the business records the law requires. Your account uses an emailed sign-in code, not a password.
  • If you have Pro and add teammates: each teammate's email address, the date it was added, and a separate random access token for that teammate. Purpose: to let the people you choose use your plan, and to end their access when you remove them. We do not email teammates when they are added.
  • If you ask to get back in: a one-way hash (a scrambled version that cannot be turned back into the original) of the six-digit code we email you, never the code itself. Purpose: to prove the address is yours.
  • Rate-limit counters. When you load a municipality's rules, use a free check, record an acceptance, report a correction or ask for a recovery code, a counter is kept against a keyed one-way hash of your IP address, not the address itself. Each counter is deleted when its window ends: an hour for most, a day for free checks and recovery-code attempts. Purpose: to stop automated abuse, code guessing, attempts to find out who our customers are, and free checks being reset by clearing cookies or opening a private window. An office or phone network that shares one address shares that day's free checks.
  • Anonymous usage counts. When you run a check we add one to a daily total for the combination of the municipality, the sign type and, if you chose one, the kind of user you said you are (business owner, property manager, sign company or multi-location brand). The total is a number; no address, IP address, cookie or other identifier is stored with it, and nothing links a count to you. Purpose: to see which cities and which kinds of user the tool is used for, so we can improve it. Counting can be switched off on our side; when it is off, nothing is sent.
  • Page statistics. Cloudflare Web Analytics counts page views and the pages requested without setting a cookie or identifying you. Purpose: to see which pages are used.
  • If you arrive from one of our ads: the click identifier Google adds to the ad’s link (a random string that contains no name or contact details). It is kept in a cookie in your browser for up to 90 days and, if you buy a plan in that time, attached to the purchase. Purpose: to tell Google Ads that an ad led to a sale, so we can see which ads are worth paying for. If you did not arrive from an ad, nothing is kept.
  • If you report a correction: what you type in the form, and your email address if you give one. We do not record your IP address with a correction. Purpose: to fix the figure and, if you asked, reply to you.
  • During the private beta: the site sits behind a sign-in run by Cloudflare, which records your email address and when you signed in. Purpose: to control who can reach the site during the beta. This ends when the beta does.

Purchased check balances

For each top-up, our existing Cloudflare database stores your Stripe customer, payment and checkout identifiers, amount paid including tax, five-check credit amount, counts used and reversed following refunds or disputes, and creation and update times. We use these records to deliver the purchase once, show the remaining balance, preserve it after subscription cancellation and handle refunds without removing unrelated purchases. They contain no addresses, measurements or reports. The records are kept while a purchased balance remains available, then under the purchase-record retention period below. Purchased checks have no expiry.

Payment and Stripe

Stripe processes payments for us. Your card details go directly to Stripe; we never see or store a card number. From Stripe we receive only the items listed under "If you pay". Stripe also handles some information under its own privacy policy for its own purposes, such as fraud prevention and its legal obligations. Cancelling, changing a card and downloading receipts happen in Stripe's billing portal, which we open for you.

Ask Scout — AI beta

If you choose to use Ask Scout, your questions, recent conversation, relevant project specifications and maintained by-law evidence are sent to OpenAI to prepare an answer. Scout is AI, is in beta and can make mistakes. Do not include confidential business information, personal information you do not need to share, credentials or payment details. Project names, internal job numbers, addresses, internal project notes, account emails, billing records, owner information and development records are not automatically sent. Information you type into chat may still contain those details; omit them.

Scout conversations are private to the signed-in person, including within a Pro team, and remain in our existing Cloudflare database. We keep up to 50 conversations with up to 60 questions each. Conversations expire after 90 days without activity and are removed during the next Scout cleanup request. You can delete a conversation in Ask Scout. Deletion removes the conversation content from our active database; it does not recall a request already processed by OpenAI or erase provider security logs. Saved projects and reports are separate and are not changed by chat.

OpenAI is an additional service provider for this optional feature. We use its API with response storage disabled. API content is not used to train OpenAI models by default; abuse-monitoring logs may contain content and ordinarily remain for up to 30 days, subject to OpenAI’s stated exceptions. We do not promise zero provider retention or Canada-only processing. See OpenAI API data controls.

We retain message counts, model names, token usage and estimated cost for up to 90 days, with removal during subsequent cleanup, to enforce allowances and control operating costs. These usage records do not contain question or answer text. Our normal service logs and backup handling also apply. Contact admin@signallow.ca for privacy requests, including after membership ends.

Service providers, and processing outside Canada

We use these service providers to run SignAllow. Each handles only what it needs to for the service it provides to us:

  • Cloudflare: hosting, the database that holds purchase records, optional saved projects, acceptance records, recovery codes, correction reports and the anonymous usage counts, server logs and cookie-free page statistics.
  • Stripe: payment and billing. If you arrived from one of our ads, the ad’s click identifier is stored with your purchase.
  • Google (Google Ads): only if a purchase followed a click on one of our ads, we give Google that click’s identifier, the confirmed payment time, the amount paid after discounts and before tax, the currency and an opaque invoice reference used to prevent duplicate counting and reconcile corrections. Google already knows about the click; this tells it the click led to a sale. We give Google no name, email address, address or anything about your checks. No Google script runs on this site.
  • Resend: sending the recovery code to your email address.
  • Geoapify: address suggestions as you type, when that feature is on. It receives only the text typed in the address field.
  • Municipal zoning map servers (Vaughan, Richmond Hill, Newmarket, Mississauga, Burlington, Milton): the zone at a picked address. Each receives only a latitude and longitude.
  • Government overlay map servers (City of Burlington, City of London, City of Markham, Toronto and Region Conservation Authority, Credit Valley Conservation, Central Lake Ontario Conservation Authority and Lake Simcoe Region Conservation Authority, including their ArcGIS hosting): mapped heritage districts and conservation areas at a picked point. Each receives only latitude and longitude with fixed map-query parameters. Toronto heritage districts and the city coverage boundary are checked against a dated City of Toronto open-data copy held on our server; no live point is sent to Toronto for that overlay.
  • GitHub: the site's source code. No customer information is stored there.

These providers process information in the United States and may do so in other countries. Information processed outside Canada is subject to the laws of those countries and may be accessible to their courts, law enforcement and national security authorities. We remain responsible for information we transfer to them for processing, and each provider also has its own privacy practices.

Project save and delete requests also use hourly counters linked to a hashed account identifier, to prevent automated abuse.

How long we keep it

  • Recovery codes: until used, or 15 minutes, whichever comes first.
  • Rate-limit counters: deleted once their window has passed: an hour for most, a day for free checks and recovery-code attempts.
  • Purchase records, and acceptances made at checkout: while you have access, and afterwards for six years, the period Canadian tax law requires for business records.
  • Acceptance records not tied to a purchase: two years.
  • Teammate email addresses and their access tokens: until the account holder removes them or the subscription is cancelled, whichever comes first. Either deletes both.
  • Correction reports, including any email address you gave: as long as the correction record is kept, so the history of a figure can be checked. Ask us and we will remove your email address from a report once it is closed.
  • Server logs: kept by Cloudflare under its retention settings. We do not export or combine them.
  • The ad click cookie: it expires 90 days after the click. A click identifier attached to a purchase is kept with the purchase record, and we stop giving it to Google 90 days after the click.
  • Anonymous usage counts and page statistics: kept indefinitely; they contain no personal information.

How we protect it

We collect as little as the service allows. Your proposed sign measurements and checklist answers stay on your device unless you explicitly save an account project. Generated reports stay on your device. Address suggestions and picked coordinates are processed only as described above. Beyond that, all traffic is encrypted, access tokens are random and held in cookies your browser's scripts cannot read, recovery codes are stored only as hashes, and access to the database and provider accounts is limited to the person who operates SignAllow.

If something goes wrong

If a breach of security safeguards involving personal information under our control creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify the people affected as soon as feasible. We keep a record of every breach of security safeguards involving personal information for at least 24 months.

Access, correction and deletion

You can ask what personal information we hold about you, ask us to correct it, or ask us to delete it. Write to admin@signallow.ca from the email address concerned; that is how we confirm the request is yours. We answer within 30 days. Deleting a purchase record ends the access it holds, and records the law requires us to keep, such as tax records, are kept for the required period and then deleted.

Complaints

If you are not satisfied with how we have handled your information or a request, tell us first at admin@signallow.ca. You can also complain to the Office of the Privacy Commissioner of Canada.

Cookies and browser storage

Three cookies, all strictly functional, all unreadable by the page's scripts: one counts your free checks, one lists the municipalities you have checked in the last 24 hours, and one carries your access token if you have paid.

A fourth cookie is set only if you arrive from one of our ads: it holds that ad’s click identifier for up to 90 days, as described above. It is our own cookie, not Google’s. You can remove it by clearing this site’s cookies.

Your browser's own storage (not a cookie) also keeps things for your convenience, on your device only: which version of the terms you accepted and its reference number, so you are not asked again; the kind of user you said you are, if you chose one; and your past checks, with any project name you gave them (the address, municipality, sign type, building type, lighting choice and measurements, and the headline answer). Local history is not sent to us automatically. Account projects are stored only when you choose to save them, as described above. You can see and clear local history on the Account page in the checker, or by clearing your browser's site data.

There is no analytics cookie and no third-party tracker: no Google, social media or other advertising script runs on this site, and no one else’s cookie is set. Page statistics come from Cloudflare Web Analytics, which does not use cookies.

Address lookup

When address suggestions are switched on, the text you type in the address field is sent to SignAllow as you type it, and SignAllow passes it to Geoapify, a geocoding service, which returns matching addresses. Geoapify receives only the text typed; it does not receive your IP address from us, your other choices, or any cookie. Address suggestions do not create a saved project; SignAllow's server may hold a copy of the suggestions for up to an hour so the same partial address is not looked up twice. Purpose: to help you type an address and set the municipality. When suggestions are off, the address field is a plain text box and what you type there stays in your browser unless you explicitly save an account project. Whether suggestions are on is shown by whether a list appears under the field.

When you pick a suggested address in one of the municipalities that publishes its zoning as a map service (today: Vaughan, Richmond Hill, Newmarket, Mississauga, Burlington and Milton), SignAllow sends the coordinates of that address — a latitude and longitude, nothing else — to SignAllow and on to that municipality’s own public zoning map server, which returns the zone at that point. The municipality receives a point; it does not receive the address text, your IP address from us, your other choices, or any cookie. SignAllow’s server may hold the answer for that point for up to an hour. Purpose: to set the sign district from the zoning, which you can change. This happens only after you choose a suggestion, never as you type, and only for those municipalities.

Address review flags

After you pick an address suggestion, your browser sends its latitude, longitude and selected municipality to SignAllow to screen available government map layers. External map servers receive only the point and fixed query parameters, not the address text, your IP address from us, your cookies, sign measurements or report. SignAllow may cache a map answer at the edge for up to one hour. Results and source dates are displayed in the check and included in the full PDF and saved web report; the customer summary excludes the overlay cards. Manual answers remain yours to change. Typing an address without selecting a suggestion does not trigger this lookup. If you go to checkout, the picked point is temporarily kept in your browser tab so the maps can be checked again when you return. This temporary copy is removed when the check is restored.

Links you share

“Copy link for your team” makes a link that carries the details of your check (the address, municipality, sign type, building type, lighting choice, measurements and project name) in the part of the link after the # sign. Browsers do not send that part to any server, so it does not reach us; anyone you send the link to can open it and see those details. Share it as you would share the address itself.

Reports you generate

A PDF or web page you download is generated in your browser and saved to your device. We do not receive a copy.

Changes to this notice

Each version of this notice has a version number and an effective date, shown below, and earlier versions are kept.

Privacy Notice, version 2026-09-27.14, effective 27 September 2026.

← Back to the checker