Privacy
Privacy Policy — we index businesses, not people
Who is responsible for your information
Street Proof Labs Inc., an Alberta corporation operating the StreetProof™ brand, controls the personal information described in this policy and operates from Calgary, Alberta, Canada. Our Privacy Officer can be reached at privacy@streetproof.com. This policy forms part of the Terms of Service accepted by every Scout.
Our privacy rule for imagery
Faces and licence plates are blurred before any image becomes retained evidence, enters the recognition archive, or appears publicly. Unsanitized frames are processed transiently in the private privacy pipeline and are not retained as evidence.
If the privacy step fails, the image is quarantined and cannot be published or admitted to the recognition archive. We detect face regions for blurring; we do not identify people or build facial-recognition profiles.
Information we collect
Scout accounts
- Email address, name, date of birth, home city, optional public handle and avatar, account status, and the Terms version and time accepted.
- GPS position, accuracy, heading, capture time, image hash, camera metadata available at the shutter event, signed collection mode, and the business-name hint or category selected by the Scout.
- App and device integrity results, device-key identifier, capture signature, app version, and security events used to reject fabricated or altered submissions.
- Submissions, review states, points, Pioneer city reservations and badges, appeals, support requests, and related audit records.
Android permissions
- Camera is requested when a Scout opens capture or Drive Mode. Declining leaves capture unavailable; the rest of the app remains usable.
- Precise location while in use is requested for capture-time provenance and city resolution. It is not background location. Declining prevents evidence submission because the capture cannot be placed safely.
- Notifications are optional and are requested only for submission, account, and service updates. Declining does not block capture, review, points, or account access.
- Display over other apps (
SYSTEM_ALERT_WINDOW) is not used by a production Scout feature and is explicitly blocked from the release manifest. - Microphone and external-storage access are not used by production Scout features and are explicitly blocked from the release manifest. Captures use the in-app still camera and app-private staging.
Business claims
- Claimant email, official website, notes, claimed business record, verification method, status, timestamps, and audit history.
- For phone verification, the listed business phone, its last four digits, the verification provider reference, challenge result, and attempt history. StreetProof does not let the claimant substitute a different destination number.
- For document review, up to three PDF, JPEG, or PNG files connecting the claimant to the business, plus filename, size, file hash, delivery status, and review notes.
Business and public-source information
StreetProof records business names, categories, public branding, observed locations, public business phone numbers and websites, external place identifiers, and source-labelled match evidence. Public business-profile information supports identity matching; it does not by itself prove ownership or determine whether a business exists.
StreetProof may also analyze imagery made available under an approved public-data licence. Raw frames are processed in a private pipeline and are not republished. Only a privacy-scrubbed candidate may be retained temporarily for review. An accepted result keeps a derived brand observation, source licence, frame hash, privacy audit, and reviewer decision; exact sensor identifiers and source images remain private.
Service and security data
We process IP address, request time, endpoint, response status, device or browser information, rate-limit state, session identifiers, and security logs. Public API and MCP analytics use daily rotating keyed pseudonyms instead of storing raw IP addresses. StreetProof stores only coarse country and client-family labels for commercial reporting, not full user-agent strings or full referring URLs.
The public website uses a first-party, cookieless measurement signal to estimate sessions, landing pages, and visits to high-intent product pages. It stores a daily pseudonymous session key, page path, coarse country, device class, client family, and referring host. It does not store the raw IP address, URL query strings, or a cross-site advertising identifier. The signal is disabled when the browser sends Global Privacy Control or Do Not Track.
What we do not collect
- No background location or stored route history. While Drive Mode is armed in the foreground, the app processes location fixes transiently to bind retained frames to their capture event; only capture-event coordinates are submitted.
- Drive Mode creates temporary camera samples on-device while armed. A local image-quality and scene-change gate deletes blank, repeated, or GPS-ineligible files on the phone. Only a selected signed candidate enters the normal private upload and privacy pipeline.
- No contact lists, messages, call history, browsing history, or photo-gallery access.
- No advertising identifier and no third-party behavioural advertising.
- No facial identity, face template, fingerprint, or other biometric identification.
- We do not sell or rent personal information.
Why we use the information
- Operate accounts, authentication, business claims, submissions, points, Pioneer badges, and support.
- Verify that a capture came from the in-app camera on a registered device at the stated place and time.
- When a Scout opts in, use the location already attached to an accepted capture to check for nearby collection opportunities. This does not turn on continuous or background location.
- Blur sensitive regions, detect branded objects, read visible business text, match entities, prevent duplicates, and publish accepted evidence.
- Detect fraud, protect the ledger, secure accounts, investigate abuse, and handle appeals.
- Meet tax, accounting, legal, safety, and regulatory obligations.
- Create de-identified statistics, model evaluations, and product measurements.
We use consent where consent is appropriate and otherwise process information for purposes a reasonable person would consider appropriate to provide and secure the Services. Withdrawing consent may prevent StreetProof from providing a feature that needs that information.
Automated processing and human review
StreetProof uses automated privacy detection, device and app integrity checks, duplicate and travel checks, object detection, OCR, entity matching, and confidence scoring. These systems can accept, reject, quarantine, or hold a submission. They do not make employment, credit, insurance, housing, or government-benefit decisions. Scouts may appeal account sanctions and material point corrections for human review. Business-identity conflicts stay private until reviewed or independently corroborated.
Service providers and processing outside Canada
Core evidence and the StreetProof ledger are stored on StreetProof-controlled infrastructure in Canada. Limited information is handled by providers needed for specific functions:
- Google Play Integrity receives app, account, licence, and device-integrity request data for Android fraud prevention.
- Twilio Verify receives the listed business phone number and verification-delivery metadata for SMS or voice challenges.
- Outscraper receives a business-name and location query used to find candidate public business profiles.
- Email providers process recipient addresses, service messages, and business-claim documents delivered for manual review.
- Square processes member identity, checkout, recurring billing, payment, tax, receipt, and subscription information. StreetProof stores Square customer, order and subscription identifiers, but never receives or stores full card numbers.
- A payment or identity provider will be disclosed before any future compensated Scout program is enabled.
These providers may process information outside Canada, where it can be subject to the laws of that jurisdiction. StreetProof limits the fields sent to each provider and does not give them the right to use Scout or claimant information for their own advertising.
Public visibility
- A Scout’s real name and email are not published. A public handle is optional, and the public profile can be disabled.
- Public location displays are fuzzed or aggregated. StreetProof does not publish Scout routes or a person’s precise capture history.
- Evidence images contain privacy blurring. Exact internal capture coordinates may still be retained for verification and fraud review.
- Business records describe public commercial branding and source-labelled business information, not personal opinions or reviews.
Membership applications and billing
A membership application includes the company name, website, city, country, visible physical assets, applicant name, official email, optional phone number, plan choice, application reason, consent records, eligibility decision, and billing status. These fields are private except for the active roster information a funding member explicitly authorizes: company name, logo, city, member number, membership label, and Presence Record link. Square-hosted checkout receives the buyer and payment details needed to create and renew the subscription.
Retention
- Raw capture staging: normally deleted as soon as privacy processing succeeds or a capture is rejected. A failed or interrupted privacy job may remain in a private quarantine for recovery, with a hard maximum of 30 days.
- Scrubbed evidence: retained while the observation remains part of the index. Approved removal requests redact public access while preserving an audit entry.
- Claim documents: private object-storage copies are deleted after delivery to the controlled review mailbox or within 14 days, whichever comes first. The restricted mailbox copy is retained only through review and any necessary dispute period. File hashes, delivery records, and the claim decision may remain as an audit record.
- Account information: deleted or de-identified after account deletion, except security, dispute, tax, payment, and legal records that must or reasonably need to be retained.
- Membership and payment records: application, consent, invoice, subscription, tax, dispute, and audit records are retained for the active relationship and then for the period required for accounting, fraud prevention, contractual disputes, and Canadian law. The Founding 100 recognition list is editorial and can be corrected or removed when its description is inaccurate or no longer appropriate.
- Commercial telemetry: cookieless public-page, API, and MCP events are deleted after 90 days. Daily aggregates contain no IP addresses or pseudonymous visitor identifiers and may be retained indefinitely for historical reporting. When a machine business lookup returns no record, a bounded normalized organization name and requested city or industry may enter a private daily demand aggregate. Apparent email addresses, phone numbers, URLs, control characters, and arbitrary raw queries are rejected. Security, billing, and tax records follow separate necessity and legal-retention rules.
- Ledger records: accepted observations remain as de-identified, append-only records. Public association with a deleted Scout is removed.
Recognition archive
The recognition archive supports entity matching, model evaluation, false-match audits, and controlled reprocessing under a documented model and methodology. Only privacy-scrubbed material that passed the blocking privacy gate is eligible. Unsanitized frames, failed scrubs, weak or rejected candidates, duplicates, and unusable material cannot enter cold storage.
- Hot storage: eligible privacy-scrubbed candidates may remain for no more than 30 days.
- Cold-storage eligibility: retention beyond 30 days requires accepted, reviewed, training- or reference-worthy evidence plus current source-rights and jurisdiction approval.
- Maximum routine retention: 365 days from archive admission.
- Access: restricted to authorized StreetProof operators and service roles with a documented recognition, privacy, security, or legal purpose.
- Automatic deletion: expired or ineligible material is deleted by the archive lifecycle job.
- Documented holds: a specific legal or security hold can pause deletion only when its ID, reason, approver, and recorded time are present.
- Reprocessing audit trail: each run records the archive material, model and methodology versions, time, outcome, and resulting observation link where applicable.
Security
StreetProof uses encrypted credentials, restricted database roles, private object storage, signed sessions, rate limits, device and app integrity checks, audit logs, network controls, and access limited by job function. No system is risk-free. We investigate suspected incidents and notify affected people and regulators when Canadian law requires it.
Cookies and local storage
The public website does not use advertising cookies. Signed-in services use strictly necessary cookies or local device storage for sessions, security, preferences, and offline app operation. The public commercial-telemetry signal uses session storage only to avoid counting the same page repeatedly during one browser session; it expires when the browser session ends. Blocking those items may prevent sign-in or app functions.
Your Canadian privacy rights
Subject to applicable Canadian privacy law, including Alberta’s Personal Information Protection Act and PIPEDA where it applies, you may request access to or correction of your personal information, withdraw consent where processing depends on consent, or request deletion subject to lawful retention. We may need to verify your identity before acting.
Businesses and individuals can dispute or request removal of an observation through the removal process. StreetProof aims to acknowledge requests within two business days and resolve them or explain the status within ten business days. If you are not satisfied, you may contact the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada.
Changes and contact
Material changes receive a new version and require Scout re-acceptance. Privacy requests and questions: privacy@streetproof.com. Security reports: security@streetproof.com. Mailing location: Calgary, Alberta, Canada.
™