ListingLaunchpad

Privacy Policy

Last updated & effective: August 22, 2026

Terms of Service · Privacy Policy · Extension Privacy

Overview

This policy explains how Cekan Holdings Ltd. (“Listing Launchpad,” “we,” “us”) collects, uses, and shares personal information through the Listing Launchpad web application, website, and related services. The browser extension has a supplementary policy of its own. We are a Canadian company and handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and other applicable privacy laws.

Two kinds of people use Listing Launchpad

  • Agents (our customers). Real estate professionals who create accounts. For their information, we decide how and why it is processed, as described in this policy.
  • Clients and members of the public. Sellers, buyers, rental applicants, open-house visitors, and others whose information an agent collects or manages through the Services (for example via a share link, intake form, application form, or sign-in kiosk). For this information, the agent is the organization responsible, and we process it on the agent’s behalf as a service provider. If you are a client, your first point of contact for questions or requests about your information is your agent; you can also contact us and we will help route your request.

Information we collect

Information you provide:
  • Account and profile — name, email, password (stored hashed by our authentication provider), phone, brokerage, board memberships, headshot, branding, and settings.
  • Listing content — property details, descriptions, photos, videos, documents, and generated marketing copy you keep in your workspace.
  • Client Data entered or collected through the Services — client contact details; identification documents gathered for FINTRAC purposes; rental applications (which may include employment, income, and reference information and supporting documents); open-house sign-ins; offer registrations; edits and comments submitted through share links.
  • Communications — messages you send us, and emails you compose and send through the Services. Conversations with the in-app Help & support assistant are part of this: our team may review them individually to provide support and improve the Services, and we keep them for up to 90 days.
Information collected automatically:
  • Log and device data (IP address, browser type, pages viewed, timestamps).
  • Usage events — which features are used and, for form-autofill, which fields were filled and corrected (used to improve matching accuracy).
  • Signup attribution — the campaign parameters, click identifiers, or referrer that brought you to the site, captured when you first visit and associated with your account at signup.
  • Cookies and local storage used for authentication, preferences, and the attribution above (these are essential and always on). With your consent, we also use analytics and advertising cookies — such as the Meta Pixel and Google — to measure and improve our marketing; you can accept or decline these in the cookie banner shown on your first visit, and they never load unless you accept.
  • Aggregate page-view counts from Vercel Web Analytics, our hosting provider’s built-in measure. It is cookieless — it stores nothing on your device and creates no cross-site identifier — so it runs without a consent prompt. Addresses, share links, and any other credential in a page’s address are removed before the page view is recorded.
Information from other sources: data you direct us to import from listing pages or documents; geocoding results for listing addresses; payment and subscription status from our payment processor (we never see full card numbers).

How we use information

  • To provide the Services: storing and syncing your workspace, generating content you request, sending emails you initiate, powering share links and client-facing forms, and processing payments.
  • To operate accounts: authentication, trials and subscriptions, support, and service messages.
  • To secure the Services: fraud and abuse prevention, debugging, and audit logging.
  • To improve the Services: analytics on how features are used, improving field-matching and import accuracy, and developing new features.
  • To comply with law and enforce our Terms of Service.
Client documents such as identification and application files are used only to provide the Services to the agent who collected them — we do not use them for analytics, marketing, or model training.

AI processing

When you use AI features — content generation, photo editing, translation, imports and data extraction, and voice dictation — the content needed for that request is sent to third-party AI providers (currently Anthropic, Google, and Deepgram) and processed under our account with them.
We do not permit AI providers to train on your content. This is a deliberate commitment, not an incidental one, and we secure it in whichever way a given provider requires: we use paid, commercial service tiers whose terms prohibit training, and where a provider would otherwise include your content in a model-improvement programme, we opt out of it on every request. Several of these providers do permit training on content submitted through their free or evaluation tiers, and we do not use those tiers for your content. Providers may retain content for a limited period for security and abuse monitoring under their own terms.
AI features run only when you, or a feature you have enabled, request them. Some features send documents you upload — such as an identification document or a status certificate — to an AI provider for the sole purpose of extracting the data you asked us to extract, on the same paid tiers and the same no-training terms.

When we share information

We share personal information only:
  • With service providers that host and power the Services, bound by contractual confidentiality and use restrictions. Currently: Supabase (database, authentication, file storage), Vercel (application hosting and cookieless page-view analytics), Anthropic, Google, and Deepgram (AI processing), Resend (email delivery), Stripe (payments), Jina AI and Microlink (fetching pages you ask us to import), and OpenStreetMap/Nominatim (geocoding listing addresses).
  • At your direction — when you create a share link, publish content, export data, email a client, deliver documents to a vendor, or connect an integration (such as a CRM), the recipient receives the data you chose to send. Their handling of it is governed by their own policies.
  • Within your team — if you join a team, your team leader and teammates can see listing data according to the team features you use.
  • For legal reasons — to comply with law, enforce our terms, or protect rights, safety, and security.
  • In a business transfer — if we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
We do not sell personal information. If that practice ever changed, we would update this policy, provide prominent notice, and obtain any consent required by law before doing so.

Shared building facts

For condominiums, the Services maintain a shared record of objective facts about a building: its corporation number and registry office, the property management company and its phone number, building and condo amenities, pet rules, the fee frequency, and what the common expense fee covers. A value is added only after two or more agents have independently recorded the same answer for the same building, and only when an agent entered or confirmed that value themselves — values imported from a listing, or produced by our AI research, are never added.
  • These records contain no personal information. They never identify the contributing agent, never include client information, and are not linked to any listing.
  • They never include anything specific to a unit — including its price, its own fees, and its locker or parking.
  • Any agent who sees a shared fact can report it as incorrect; enough reports withdraw it. Deleting your account removes your contributions, which can withdraw a fact that depended on them.
This is a database of verified answers. It is not used to train artificial-intelligence models, ours or anyone else’s.

Aggregated and de-identified data

We may create and use data that has been aggregated or de-identified so that it no longer identifies you, your clients, or any other individual — for example, market statistics, feature-usage trends, and model-quality metrics. We may use and share such data for any lawful business purpose, including commercial purposes and training and tuning our own models and matching systems, and we commit not to attempt to re-identify it.
Your content itself is not used to train models — not by the AI providers we use, and not by us. Client documents are never used for model training in any form. If we ever proposed to train on identifiable content, we would update this policy, provide prominent notice, and obtain any consent required by law before doing so.

Where information is stored

Our service providers store and process data on infrastructure that may be located in Canada, the United States, or other jurisdictions. While in another jurisdiction, information is subject to that jurisdiction’s laws and may be accessible to its courts and authorities under lawful process. We use providers with strong security practices and contractual safeguards regardless of location.

Retention

We keep personal information for as long as your account is active and as needed for the purposes above. Listing content and Client Data remain in your workspace until you delete them or close your account. After account closure, we make core data available for export for at least 30 days, then delete or de-identify it within a reasonable period, except where longer retention is required by law or where data persists briefly in encrypted backups before aging out. Conversations with the in-app Help & support assistant are kept for up to 90 days. Two categories are kept on statutory schedules regardless of account closure: billing and tax records, and any client identification your workspace collects for anti-money-laundering purposes (e.g. FINTRAC client identification), which we retain for the minimum period Canadian law requires.

Security

We protect information with encryption in transit, private storage buckets with owner-scoped access rules, row-level security on our database, scoped access tokens for share links, and least-privilege access internally. No system is perfectly secure; if we learn of a breach creating a real risk of significant harm, we will notify affected users and the Office of the Privacy Commissioner of Canada as required by law.

Your rights and choices

  • Access and correction — you can view and edit most of your information directly in the app, or ask us for a copy of the personal information we hold about you.
  • Deletion — you can delete listings, documents, and other content in the app at any time. You can also close your account yourself: go to Settings › Profile and choose “Close my account.” That schedules your account and its data for permanent deletion in 30 days, and you can cancel during those 30 days by signing back in. If you can’t sign in, you can request account deletion here.
  • Withdrawing consent — you may withdraw consent to optional processing at any time, subject to legal or contractual restrictions; some features may stop working as a result.
  • Marketing email — service and transactional messages are sent as part of providing the Services; any marketing messages we send include an unsubscribe link, consistent with CASL.
  • Complaints — contact us first and we will try to resolve your concern. You may also complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or your provincial privacy regulator.
If you are a client of an agent, we may refer your request to the agent responsible for your information and assist them in fulfilling it.

Children

The Services are for professional use and are not directed to anyone under 18. We do not knowingly collect personal information from children.

Changes to this policy

We may update this policy as the Services evolve. We will post updates here and revise the date at the top; for material changes we will give prominent notice (such as email or in-app notice) before they take effect.

Privacy Officer

Robert Cekan, Director of Cekan Holdings Ltd., is responsible for the protection of personal information at Listing Launchpad. Reach him at info@listinglaunchpad.ai with any question, access or correction request, or complaint about how your information is handled.

Contact

Privacy questions and requests: Cekan Holdings Ltd. · Hamilton, Ontario, Canada · info@listinglaunchpad.ai

Listing Launchpad is a product of Cekan Holdings Ltd. · listinglaunchpad.ai