Back to home

PaidPainter Ltd.

Privacy Policy

Effective Date: April 8, 2026

This Privacy Policy (“Policy”) describes how PaidPainter Ltd. (“PaidPainter,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with the PaidPainter platform at paidpainter.com and related services (collectively, the “Services”). This Policy applies to all individuals who access or use the Services.

By accessing or using the Services, you agree to the terms of this Policy. This Policy is incorporated by reference into PaidPainter’s Terms of Service.

1. Who We Are and How to Reach Us

PaidPainter Ltd. is the controller of personal information collected through the Services. We are incorporated federally under the Canada Business Corporations Act (CBCA) and registered provincially, operating from Moncton, New Brunswick, Canada.

For all privacy-related inquiries, requests, or complaints:

PaidPainter Ltd. — Privacy Office

Moncton, New Brunswick, Canada

Email: hello@paidpainter.com

Website: https://paidpainter.com

We will acknowledge receipt of your inquiry within five (5) business days and respond substantively within thirty (30) days, or such shorter period as required by applicable law.

2. Scope and Legal Basis

2.1 Applicable Law

PaidPainter is subject to Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. Additional rights for California, USA residents are described in Section 12 of this Policy.

2.2 Consent

Under PIPEDA, we obtain meaningful consent from individuals before collecting, using, or disclosing their personal information, except where the law permits otherwise. By registering for an Account and using the Services, you provide express consent to the practices described in this Policy. You may withdraw consent at any time by contacting hello@paidpainter.com, subject to legal and contractual restrictions. Withdrawal of consent may result in our inability to provide some or all of the Services.

3. Information We Collect

3.1 Information You Provide Directly

  • Registration information: name, email address, and password.
  • Organization details: business name, address, and contact information.
  • Billing information: payment method details processed by Stripe. PaidPainter does not store full payment card numbers.
  • Quote and project data: client names, site addresses, pricing inputs, scope of work details, and all data you create within the Services.
  • Company Profile data: labour rates, overhead expenses, crew size, operational assumptions, and other configuration data you enter.
  • Client data: names, addresses, and contact details of your clients that you enter into quotes. See Section 8 regarding your obligations as data controller for client data.
  • Communications: support requests, feedback, and correspondence you send to us.

3.2 Information Collected Automatically

When you access the Services, we and our service providers may automatically collect:

  • Log data: IP address, browser type and version, operating system, referring URLs, and pages viewed.
  • Device information: device identifiers and hardware model.
  • Usage data: features accessed, actions taken within the Services, timestamps, and session duration.
  • Analytics data: collected via Firebase Analytics (see Section 5.1 for details).
  • Cookies and similar tracking technologies (see Section 7).

3.3 Information from Third Parties

  • Authentication providers such as Google, if you use single sign-on.
  • Stripe, which may provide transaction confirmations and billing status.

3.4 AI Feature Data

When you use AI Features, including My Coach and AI-generated scope of work descriptions, the content you input is transmitted to Google Gemini via the Genkit framework for processing. This data is subject to Google’s applicable data processing terms. PaidPainter does not use your individual AI inputs to train its own models.

4. How We Use Your Information

PaidPainter uses your personal information to:

  • Create and manage your Account and provide, operate, and maintain the Services.
  • Process payments and manage billing, including fraud detection, via Stripe.
  • Personalize your experience within the Services, including pre-populating fields based on your Company Profile.
  • Generate AI-powered outputs, including My Coach outputs and scope of work descriptions, based on the data you enter.
  • Communicate with you, including account confirmations, billing receipts, product updates, security alerts, and support responses.
  • Improve and develop the Services, including analyzing usage patterns and troubleshooting.
  • Enforce our Terms of Service and other legal rights.
  • Comply with applicable legal obligations.
  • In the future, if a CRM or client follow-up feature is introduced, client data you have entered may be used to power those features. You will be notified and this Policy will be updated before any such use is activated.

We do not sell your personal information to third parties. We do not use your personal information for targeted advertising on third-party platforms.

5. How We Share Your Information

5.1 Service Providers

We disclose personal information to third-party service providers that perform services on our behalf:

Google Firebase (Authentication, Firestore, App Hosting)

Stores and manages your Account data, User Data, and authentication. Firebase infrastructure is operated by Google Cloud and may store and process data in data centres located in the United States and other jurisdictions outside Canada. Firebase is subject to Google’s data processing terms, including standard contractual clauses where applicable.

Firebase Analytics (Google)

Collects aggregated usage and analytics data to help us understand how the Services are used. This includes session data, feature usage, and device/browser information. Firebase Analytics data is processed by Google and subject to Google’s privacy terms.

Google Gemini via Genkit (AI Processing)

Receives project details and other inputs you provide when using AI Features, for the purpose of generating AI outputs. Google’s use of this data is governed by its Cloud Data Processing Addendum.

Stripe (Payment Processing)

Receives your email address, billing details, and subscription status for the purpose of processing payments. Stripe’s handling of your payment data is governed by Stripe’s Privacy Policy, available at stripe.com/privacy.

Email Service Providers

Used for delivery of transactional and service communications.

All service providers are contractually required to use your personal information only to provide services to PaidPainter and to maintain appropriate security safeguards.

5.2 Business Transfers

If PaidPainter undergoes a merger, acquisition, reorganization, or asset sale, your personal information may be transferred as part of that transaction. We will notify you before your personal information becomes subject to a materially different privacy policy.

5.3 Legal Compliance

We may disclose your personal information if required by law, regulation, or valid legal process, including court orders or law enforcement requests. Where permitted, we will notify you of such disclosure.

5.4 Protection of Rights

We may disclose your personal information where necessary to investigate, prevent, or take action against violations of our Terms of Service, fraud, or safety issues.

5.5 With Your Consent

We may share your personal information with third parties when you have provided express consent.

6. Data Breach Notification

PaidPainter takes data security seriously. In the event of a data breach that poses a real risk of significant harm to affected individuals, PaidPainter will:

  • Internally escalate and assess the breach within 72 hours of discovery.
  • Notify affected users by email to the address on their Account as soon as reasonably practicable.
  • Report the breach to the Office of the Privacy Commissioner of Canada as required under PIPEDA.
  • Take all reasonable steps to contain and remediate the breach.

If you believe your Account has been compromised, contact us immediately at hello@paidpainter.com.

7. Cookies and Tracking Technologies

PaidPainter uses cookies and similar technologies to operate the Services and analyze usage.

Strictly necessary cookies:Required for authentication, session management, and core functionality. These cannot be disabled without impairing your ability to use the Services.
Analytics cookies:Used via Firebase Analytics to collect aggregate information about how users interact with the Services, allowing us to improve performance and usability.

A cookie consent notice is displayed on your first visit to the Services. You may configure your browser to refuse some or all cookies at any time. Disabling strictly necessary cookies will impair your ability to use the Services.

PaidPainter does not currently respond to Do Not Track (DNT) browser signals.

8. Client Data — Your Obligations as Data Controller

When you enter your clients’ personal information (such as names, addresses, and contact details) into the Services as part of creating quotes or using other platform features, you are acting as the data controller for that client data. PaidPainter acts as the data processor.

As the data controller, you are responsible for:

  • Having a lawful basis for collecting and storing your clients’ personal information.
  • Ensuring your clients are aware their information may be stored in a third-party software platform.
  • Complying with any applicable privacy law governing your collection and use of client personal data.

PaidPainter’s obligations as data processor for client data are limited to: storing that data securely, keeping it confidential, and deleting it upon Account termination per Section 10.3.

9. Data Storage and Security

9.1 Storage Location

Your personal information is stored in Firebase Firestore, a cloud database operated by Google Cloud. Data may be stored and processed in data centres located outside of Canada, including the United States. By using the Services, you acknowledge and consent to this transfer.

9.2 Security Measures

PaidPainter implements reasonable administrative, technical, and physical safeguards, including:

  • Encrypted data transmission via TLS/HTTPS.
  • Firebase Authentication for secure access management.
  • Role-based access controls limiting employee access to personal information.
  • Firestore security rules restricting data access on a per-user and per-organization basis.

No method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security.

9.3 Data Retention

  • Active Account data is retained for as long as your Account is active or as necessary to provide the Services.
  • Upon cancellation, User Data is retained for thirty (30) days to allow for export, then deleted.
  • Billing records and transaction history are retained for a minimum of seven (7) years to comply with tax and accounting obligations.
  • Anonymized and aggregated analytics data may be retained indefinitely.
  • Data required to be retained by applicable law will be retained for the legally mandated period.

10. Inactive Accounts

If your Account has had no active Subscription and no login activity for a period of twelve (12) consecutive months, PaidPainter may notify you by email of our intent to delete your Account and associated data. If no response is received within thirty (30) days of that notice, PaidPainter reserves the right to permanently delete your Account and all associated data.

11. Your Privacy Rights

11.1 Right to Access

You may request access to the personal information we hold about you. Contact hello@paidpainter.com. We will respond within thirty (30) days.

11.2 Right to Correction

You may request correction of inaccurate or incomplete personal information. Many fields can be updated directly through your Account settings.

11.3 Right to Deletion

Subject to legal retention obligations, you may request deletion of your personal information by contacting hello@paidpainter.com. We will process your request within thirty (30) days and notify you of any information we are legally required to retain.

11.4 Right to Withdraw Consent

You may withdraw consent to our processing of your personal information at any time by contacting us. Withdrawal may limit our ability to provide certain Services.

11.5 Right to Lodge a Complaint

If you believe we have not handled your personal information in accordance with applicable law, you may lodge a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca, or with the applicable provincial privacy commissioner.

12. Additional Rights for California Residents

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you additional rights. This section supplements the rest of this Policy.

12.1 Categories of Personal Information Collected

In the past twelve (12) months, PaidPainter has collected: identifiers (name, email, IP address); commercial information (billing records, subscription history); professional information (business name, trade details); and internet activity data (usage data, log data).

12.2 Your CCPA/CPRA Rights

California residents have the right to: know what personal information we collect and how it is used; request deletion of personal information; correct inaccurate personal information; opt out of the sale or sharing of personal information (PaidPainter does not sell or share personal information for cross-context behavioral advertising); and non-discrimination for exercising privacy rights.

To exercise these rights, contact hello@paidpainter.com. We will respond within forty-five (45) days, with a possible extension of an additional forty-five (45) days where reasonably necessary.

12.3 Authorized Agents

California residents may designate an authorized agent to submit requests on their behalf. The agent must provide written authorization signed by you.

13. Children’s Privacy

The Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from individuals under 18. If you believe we have inadvertently collected information from a minor, contact us at hello@paidpainter.com and we will promptly delete it.

14. Third-Party Links

The Services may contain links to third-party websites. This Policy does not apply to the privacy practices of those third parties. We encourage you to review their privacy policies independently.

15. Changes to This Policy

PaidPainter may update this Policy at any time. Material changes will be communicated by email or prominent in-app notice at least fifteen (15) days before taking effect. The effective date at the top of this Policy will always reflect the most recent update. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.

16. Contact Us

PaidPainter Ltd. — Privacy Office

Moncton, New Brunswick, Canada

Email: hello@paidpainter.com

Website: https://paidpainter.com

This Privacy Policy was last updated on April 8, 2026.