Privacy Policy

Last updated: June 2026

What we collect

  • Account info: Your email address and display name. These are used for sign-in and to personalise your experience.
  • Sign-in with Google or Facebook: If you choose to sign in with Google or Facebook instead of email, we receive your email address, name, and profile picture from that provider: nothing more. We do not receive your contacts, posts, or friend list, and we never post anything to your Google or Facebook account on your behalf.
  • Incident reports: Type, description, and location. Reports are anonymous to the community and to moderators: your identity is never shown publicly, and moderators reviewing a report cannot see who filed it either. Admins can see reporter identity, for legal compliance and abuse investigation only; see "Reports to outside authorities" below for exactly when that access is used. The map location you place is stored at the precision you provide.
  • Photos: Images you attach to reports. We strip all metadata (EXIF, GPS tags) before storage. Photos are deleted automatically when the parent incident expires.
  • Safe Walk data: If you use Safe Walk, your real-time GPS coordinates are shared with the trusted contacts you select for the duration of the walk. Your current position and destination are permanently deleted when the walk ends: we do not store your route or movement history.
  • Trusted contacts: The email addresses and display names of people you add as trusted contacts. These people are notified when they are added. They do not have access to your data except during an active walk you share with them.
  • Usage data: Standard server logs (IP address, browser type, timestamps) used for security and rate-limiting. These are not tied to your account.

How we use it

  • Show safety reports to community members
  • Enable real-time location sharing during Safe Walk sessions
  • Moderate content to prevent abuse
  • Improve the service
  • Comply with legal requirements

We do not sell your data. We do not use it for advertising.

Third-party service providers

We use the following third-party services to operate Neighborhood Now. Each has been selected for security practices appropriate to the sensitivity of the data involved.

  • Supabase (United States): database and file storage. Holds your account data, incident reports, and photos. ISO 27001:2022 certified, SOC 2 Type II attested.
  • Vercel (United States): application hosting and delivery. ISO 27001:2022 certified, SOC 2 Type II attested.
  • Mapbox (United States): map tiles and routing. Used to display the map and calculate walking routes during Safe Walk.
  • OpenRouteService / HeiGIT (Germany): walking route calculations during Safe Walk sessions. Governed by German / EU privacy law.
  • Resend (United States): transactional email delivery (account notifications, trusted contact notifications).
  • OpenAI (United States): AI-assisted content moderation. Incident descriptions may be sent to OpenAI for moderation review. We do not send names, email addresses, or GPS coordinates to OpenAI.
  • Google / Facebook (United States): optional sign-in identity providers. If you choose to sign in this way, we receive your email, name, and profile picture from whichever provider you use. We never share your data with Google or Facebook beyond what's needed to complete sign-in, and we never post to your account on either platform.

Your data may be accessible to law enforcement in the United States, Germany, and other jurisdictions where our processors operate, under the laws of those jurisdictions.

Data retention

  • Incident reports: Automatically deleted after a type-specific period (between 6 and 72 hours for most incidents). Confirmations by other users extend this period.
  • Photos: Deleted automatically when the parent incident is deleted.
  • Safe Walk location: Current position and destination are permanently deleted when the walk session ends. No route history is stored.
  • Account data: Retained until you delete your account.

You can delete your account and all associated data at any time from your Profile page.

Reports to outside authorities

We want to be upfront about exactly when a report might leave the community, who could see it, and who it never goes to.

  • Anonymous to the community and to moderators. Nobody browsing the map or the feed, and no moderator reviewing a flagged post, can see who filed a report. Only admins can see reporter identity, and only for the legal and abuse-investigation reasons described on this page.
  • Possible forwarding to the City of Ottawa (311). For a small number of categories, noise complaints, road hazards, and some property damage or maintenance issues, a moderator may choose to forward a report to the City of Ottawa as an unverified community report, similar to how the city already treats reports it receives by phone or email. This feature is currently disabled while we confirm with the city that this forwarding path is workable and welcome. If and when it is enabled, forwarded reports go only for these applicable categories, are marked as unverified, and do not include your name, email, or account details.
  • We never contact police or emergency services on your behalf. Neighborhood Now does not call, email, or otherwise notify police, fire, or paramedic services about anything you report, and we never will as an automated or default behaviour. If you are in danger or believe a crime is in progress, call 911 yourself. Where relevant, the app may point you to the correct city or police reporting channel (for example, the non-emergency line or Ottawa Police's own online reporting tool) so you can report it yourself, but we do not submit anything on your behalf.
  • Valid legal demands. We comply with valid legal process, court orders, production orders, and preservation demands, when a request identifies its lawful authority. A request from police for reporter identity requires a warrant, production order, or a specific lawful-authority basis stated in writing. A phone call or email asking us to identify a reporter is not, on its own, enough for us to disclose anything.

Your rights

Under PIPEDA and applicable privacy laws, you have the right to:

  • Access: Download a copy of all data we hold about you (Profile → Export My Data)
  • Correction: Update your account info from your Profile page
  • Deletion: Delete your account and all associated data (Profile → Delete Account)
  • Withdraw consent: You can stop using Neighborhood Now at any time. Deleting your account removes all personal data.

If you were added as a trusted contact by someone else and want to be removed, contact us at privacy@suhsafe.ca and we will handle it promptly.

Security

We use industry-standard security measures including encrypted connections (TLS 1.3), row-level database security, role-based access controls, rate limiting, and regular security testing. Incident reports are separated from reporter identity at the database level: the public map and the moderator queue never expose who submitted a report. Only admin-level access can see that link, for the reasons described under "Reports to outside authorities" above.

Contact

Privacy questions or requests? Contact our Privacy Officer at privacy@suhsafe.ca

To report a security issue, email security@suhsafe.ca