MovingChecklist · Legal

Privacy Policy

Effective date: July 7, 2026

MovingChecklist (movingchecklist.ca) is operated by Kai By Design ("KBD", "we", "us"), Ontario, Canada. This policy explains what personal information we collect, why, and how it's protected. We follow Canada's federal privacy law, PIPEDA (the Personal Information Protection and Electronic Documents Act).

Who we hold information about

Agents (our customers). Name, email, phone, brokerage, real-estate registration number, password (stored only as a salted hash — we cannot read it), and the branding and message copy you set up.

Clients of agents (people moving). Name, email, phone, moving addresses and dates, checklist progress, and notes — entered by the client's agent or by the client themselves inside their checklist. Your agent is the custodian of this relationship: we process this information only on the agent's behalf, to run the checklist. We never use client information for our own marketing, and we never sell personal information — anyone's.

After a move, we may ask a client for a short post-move review: a rating and comments about their agent and about the service itself, whether they gave permission for their words about their agent to be quoted publicly (first name only), and whether they clicked through to leave a Google review. Ratings and comments about the service itself go to the people who run the platform, not to the agent. Nothing a client writes is ever published automatically — even with permission, a person chooses where a quote appears.

Prospective agents (lead form). If you submit the "For agents" form on our landing page: name, email, phone, brokerage, and your message. Used only to respond to you about MovingChecklist.

People moving who aren't yet a client (the "Get started" form). If you submit the public mover form on our landing page: name, email, phone, your situation (e.g. buying, selling, renting), and — if you're working with a REALTOR — their name and brokerage, plus your message. Used only to follow up with you about getting set up.

Technical. Standard server logs (IP address, request path, time) and error reports, kept for security monitoring and debugging. We also keep a single "last used" timestamp per account and per checklist (when an agent last signed in, when a mover last opened their link) — recorded at most once per hour, so agents and our team can spot stalled moves and unused access. No browsing history or per-click trail is kept.

What we use it for

  • Operating the checklist: building the timeline, tracking progress, showing local utility information for the destination.
  • Sending the emails the product is built on: the private checklist link and the weekly check-in digest, sent on the agent's behalf. Every recurring email includes an unsubscribe link (CASL compliance).
  • Account security: login, rate-limiting, error monitoring.
  • Billing, when paid plans apply (handled by our payment processor; we do not store card numbers).

We do not use advertising trackers or third-party analytics. The only cookies are the session cookies that keep agents signed in.

Client access links

Clients access their checklist through a private link rather than a password. Treat that link like a key: anyone holding it can view the checklist. Links expire (currently 120 days from issue) and the agent can regenerate one at any time, which disables the old link.

Who else touches the data (service providers)

We use a small number of service providers to run MovingChecklist:

  • DigitalOcean — cloud hosting (application and database).
  • Resend — delivers the transactional emails (checklist links, digests).
  • Sentry — receives error reports so we can find and fix failures.
  • Square — payment processing, once paid plans apply to an account.
  • Geoapify (Germany) — powers the address suggestions while you type in the address fields; the partial address you type is sent to look up matches, and is never linked to your name or account.

Some providers process data outside Canada (notably in the United States). Wherever it is processed, your information gets the protection described in this policy, and our providers are bound by their own contractual and legal safeguards.

How it's protected

Encrypted connections (HTTPS) everywhere; passwords stored as salted hashes; client links that expire and can be revoked; per-tenant isolation so one agent's data is never visible to another; rate-limited logins; daily encrypted backups; error and uptime monitoring.

How long we keep it

  • Active account data: for the life of the account.
  • Closed accounts: exported to the agent on request, then deleted from the live system within 30 days; backups age out on rotation after that.
  • Lead-form submissions: until the conversation concludes or you ask us to delete them.

If something goes wrong

If a breach of security safeguards creates a real risk of significant harm to anyone whose information we hold, we will notify the affected agents and individuals, and the Office of the Privacy Commissioner of Canada, as PIPEDA requires — without unreasonable delay.

Your rights

You can ask us at any time to:

  • show you the personal information we hold about you;
  • correct it;
  • delete it (for client data, we will loop in your agent, since they own the relationship);
  • explain any part of this policy.

Write to hello@movingchecklist.ca — we reply within 1 business day. If you're not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca).

Changes to this policy

If this policy changes materially, we will notify agents by email and update the effective date above.