# Privacy Policy

**Effective date:** May 11, 2026
**Last updated:** May 11, 2026

Confirmed Attics & Insulation (“Confirmed Attics,” “we,” “our,” or “us”) respects your privacy. This Privacy Policy explains what personal information we collect when you visit our website, request a quote, book an inspection, or use our services, how we use that information, who we share it with, and the choices you have.

This policy is written to comply with Canada’s *Personal Information Protection and Electronic Documents Act* (**PIPEDA**), *Canada’s Anti-Spam Legislation* (**CASL**), and the Ontario *Consumer Protection Act*. If you are visiting from outside Canada, additional protections from your local laws (such as the EU GDPR or California’s CPRA) may apply where required.

## 1. Who we are

**Confirmed Attics & Insulation**
2600 John Street, Unit #208
Markham, Ontario, Canada
Phone: (647) 507-4072
Email: info@confirmedc.com

We are the **data controller** for the personal information described in this policy. Questions, requests, or complaints can be sent to the contact details above and will be answered within 30 days.

## 2. Information we collect

### 2.1 Information you give us directly

When you contact us, request a quote, book a site visit, or hire us for work, we collect:

– **Identity and contact information** — your name, email address, phone number(s), and the address of the property you want serviced.
– **Property information** — the type, size, age, and condition of the property; attic measurements, insulation type and depth, ventilation, moisture/mold findings, and similar inspection data captured during a site visit.
– **Service preferences and history** — the work you ask us to quote, the work we perform, photos before/during/after the job, materials used, and warranty registrations.
– **Payment information** — when you pay an invoice, payment processing is handled by Zoho Books and our payment processors. We never see or store your full credit card number.
– **Communications** — the content of emails, text messages, and phone calls you exchange with us (see §3 below for call recording).

### 2.2 Information we collect automatically when you visit our website

– **Device and browser data** — IP address (which we hash before storage), browser type, operating system, screen size, language, and referring page.
– **Usage data** — pages visited on confirmedc.com, time on page, scroll depth, clicks, form interactions, and approximate location (city-level, derived from IP).
– **Cookies and similar technologies** — see §6 below for the full list.
– **Advertising click identifiers** — when you arrive from a Google, Meta, or Local Services ad, we capture the click identifier the ad platform appends to the URL (`gclid`, `fbclid`, UTM parameters) and store it with any lead record you submit so we can measure advertising effectiveness.

### 2.3 Information we receive from third parties

– **Google, Meta, and Microsoft** — when you interact with our advertising, the platforms provide aggregated reporting on ad performance and, in the case of phone-call ads (Google Local Services Ads), the lead’s phone number and a summary of the call.
– **Zoho CRM** — leads forwarded from other channels (referrals, walk-ins, business partners).

## 3. Calls and call recording

When you call our main business line at (647) 507-4072, the call may be recorded for quality assurance, training, and to create a written record of the conversation. We use automated transcription (powered by OpenAI’s Whisper service) to produce a text transcript of the audio. The audio and transcript are stored in our customer relationship management system (Zoho), accessible only to authorized employees and contractors.

If you do not want a call to be recorded, please let the agent know at the start of the call and we will continue without recording.

We use AI tools to help our team draft replies, classify leads, and surface follow-up reminders. AI is a drafting aid — a human reviews and approves every message before it is sent.

## 4. How we use your information

We use your personal information to:

– **Provide our services** — respond to quote requests, schedule site visits, perform inspections, complete work, deliver warranties, and bill for services.
– **Communicate with you** — confirm appointments, send quotes, answer questions, follow up after work, send service reminders, and handle warranty claims.
– **Operate and improve our business** — analyze website traffic and form completion rates to make the site easier to use, train our staff, monitor service quality, and improve our work.
– **Advertise our services** — measure which advertising campaigns produce real customers (not just clicks), so we can spend our marketing budget wisely. See §7 for details.
– **Comply with legal obligations** — keep records required for tax, insurance, consumer-protection, and workplace-safety purposes.

**Legal basis (PIPEDA):** We rely on your consent (express or implied) to collect and use your personal information. By submitting a form on our website, calling us, or hiring us for work, you provide implied consent for the purposes listed above. You may withdraw consent at any time (see §10).

## 5. Who we share your information with

We do **not** sell your personal information. We share limited information only as described below:

| Recipient | What we share | Why |
|—|—|—|
| **Our employees, subcontractors, and contractors** | Whatever is necessary to do the job (name, address, scope of work, payment status) | To perform the work you hired us for |
| **Zoho Corporation** (CRM, Voice, Books) | All of the customer record | Our core operating system; data hosted in their cloud |
| **Google LLC** (Ads, Workspace, Maps, Analytics) | Advertising click identifiers, hashed email/phone for ad measurement, route addresses for our service vehicles | Advertising attribution, business email, mapping |
| **Meta Platforms** (Facebook/Instagram Ads) | Hashed email/phone and advertising click identifiers, in aggregated form | Advertising attribution |
| **Microsoft Corporation** (Clarity) | Anonymized session recordings and heatmap interaction data from confirmedc.com | Website usability analysis |
| **OpenAI** | Audio recordings of calls (used to produce transcripts and then deleted from OpenAI’s systems per their data-processing terms) | Call transcription |
| **Anthropic** | The text of conversations needing AI-drafted replies (no payment data, no Social Insurance Numbers, no other sensitive identifiers) | AI-powered draft suggestions for our team |
| **Twilio Inc.** | Phone numbers and SMS message content | Outbound text messaging |
| **Our professional advisors** (accountant, lawyer, insurer) | Whatever is required for their service to us | Standard business operations |
| **Government and regulators** | Whatever the law requires | Legal compliance |

Some of these providers store data outside Canada (the United States, the European Union, India). By using our services, you understand that your information may be processed in those countries under their applicable laws. We require each provider to apply appropriate safeguards by contract.

## 6. Cookies and tracking technologies

We use cookies and similar technologies for the following purposes:

– **Strictly necessary cookies** — keep our website working (form submissions, security).
– **Analytics cookies** — Microsoft Clarity, which records anonymized session replays and heatmaps; Google Analytics if installed.
– **Advertising cookies** — Google Ads conversion tracking, Meta Pixel, and a small first-party “click identifier capture” script we operate that stores your most recent and first ad-click parameters in your browser for up to 90 days.

You can disable non-essential cookies via your browser settings or via the consent banner on our site. You can also opt out of personalized advertising at:

– **Google:** https://adssettings.google.com
– **Meta:** Settings → Ads → Ad Preferences inside the Facebook app
– **Microsoft Clarity:** common browser cookie blockers or *Do Not Track* mode

Disabling these cookies will not stop you from using our website, but the experience may be less personalized and we will not be able to measure how our ads performed.

## 7. Advertising attribution and analytics

We use third-party advertising and analytics tools to measure how visitors discover and interact with our website, including Google Ads, Google Local Services Ads, Meta (Facebook/Instagram) Ads, Google Analytics, and Microsoft Clarity. These tools may set cookies and may receive limited information about your visit (page URL, referring URL, click identifiers, device type, approximate location).

For visitors who submit a contact or quote form, we may share **hashed identifiers** (a one-way SHA-256 hash of your email address or phone number) with these advertising platforms solely to measure ad effectiveness; the raw email or phone number is never sent and the hash cannot be reversed.

Microsoft Clarity may record an anonymized replay of your session for usability analysis; sensitive form fields are masked automatically. You can disable Clarity using common cookie blockers or by enabling “Do Not Track” in your browser.

## 8. Marketing communications and CASL

We may send you electronic messages — by email or SMS — about quotes, scheduled work, warranty matters, service reminders, and occasional promotions or seasonal advice (e.g., winter air-sealing tips).

In accordance with Canada’s Anti-Spam Legislation:

– We rely on **implied consent** for the first six months after you ask us to quote or hire us for work, and on **express consent** thereafter. You can give express consent by replying YES to any text message we send or by checking the consent box on our website forms.
– Every marketing email includes an unsubscribe link.
– You can stop SMS messages at any time by replying STOP. Replying HELP returns help instructions.
– You can withdraw consent for all marketing communications by emailing info@confirmedc.com.

Transactional messages (appointment confirmations, technician on-the-way notifications, invoices, warranty notices) are sent regardless of marketing preferences as part of the service you have engaged us to provide.

## 9. How long we keep your information

We keep your personal information only as long as we need it for the purposes described in this policy or as required by law, then delete or anonymize it:

| Record type | Retention period |
|—|—|
| Quotes and inspection records | 7 years (matches CRA tax-record retention) |
| Completed job records and invoices | 7 years |
| Warranty registrations | For the duration of the warranty + 2 years |
| Marketing-only contacts who never hired us | 3 years from last interaction |
| Call recordings and transcripts | 12 months |
| Website analytics and ad-attribution data | 26 months |
| Microsoft Clarity session recordings | 90 days |

## 10. Your rights

Under PIPEDA, you have the right to:

– **Access** the personal information we hold about you.
– **Correct** information that is inaccurate or out of date.
– **Withdraw consent** to our continued use of your information for any purpose, subject to legal or contractual restrictions (for example, we must keep invoices for tax purposes).
– **Complain** about our handling of your information.

To exercise any of these rights, email **info@confirmedc.com** with the words “Privacy request” in the subject line and tell us what you would like us to do. We will respond within 30 days. Verification of your identity may be required before we make changes.

If you are not satisfied with our response, you may also contact the **Office of the Privacy Commissioner of Canada** at https://www.priv.gc.ca or 1-800-282-1376.

## 11. Security

We use commercially reasonable technical and organizational safeguards to protect your personal information, including:

– TLS encryption for all data in transit between your browser and our servers.
– Encrypted storage of credentials and sensitive identifiers.
– Role-based access control — only employees who need information to do their job can see it.
– Annual review of third-party service providers’ security practices.

No system is perfectly secure. If we ever experience a breach involving your personal information, we will notify the Office of the Privacy Commissioner of Canada and any affected individuals as required by law.

## 12. Children’s privacy

Our services are intended for adults — homeowners and property managers. We do not knowingly collect personal information from children under the age of 13. If you believe a child has provided us with information, please contact us and we will delete it.

## 13. Links to other websites

Our website may link to third-party websites (for example, energy-rebate program pages). We are not responsible for the privacy practices of those sites; please review their policies before sharing personal information.

## 14. Changes to this Privacy Policy

We may update this policy from time to time. The “Last updated” date at the top of this page will reflect any changes. Material changes will also be highlighted in a prominent notice on our website for at least 30 days before they take effect.

## 15. Contact us

Privacy questions or requests:

**Confirmed Attics & Insulation**
2600 John Street, Unit #208, Markham, Ontario, Canada
**Email:** info@confirmedc.com
**Phone:** (647) 507-4072

Bulk Orders Quote

Submit Your Request and we'll get back to you ASAP.