Privacy Policy

Effective date: June 9, 2026 Last updated: June 9, 2026 Version: 1.0


1. Who we are

Muninn (“Muninn,” “we,” “our,” “us”) is a software-as-a-service estimating, invoicing, and project management platform for Canadian renovation contractors.

The Muninn service is operated by Great Raven Renovations Ltd., a British Columbia corporation, as the current operating entity. Operation of the Muninn service is being assigned to Muninn Technologies Inc. upon its incorporation; once that assignment takes effect, this Policy will be updated to name Muninn Technologies Inc. as the operating entity, and the substance of the privacy commitments set out below will continue without interruption.

This Privacy Policy covers two surfaces:

Together these are the “Service.”

If you have any questions, want to exercise a privacy right, or want to file a complaint, contact our privacy officer at privacy@muninn.ca.


2. What this policy covers and who it applies to

This Policy applies to three groups of people:

  1. Visitors to the marketing site (anyone browsing muninn.ca, signing up for the waitlist, downloading materials, or contacting us).
  2. Contractor users — the contractors and trades businesses who sign up for a Muninn workspace, their team members, and anyone who logs into app.muninn.ca.
  3. Client recipients — the homeowners, property managers, and other clients of contractor users who receive estimates, invoices, or approval links from a contractor and interact with the public client portal at /approve/:token.

Where this Policy says “you,” it means whichever of these groups you fall into. Where the distinction matters, we say so.

This Policy does not cover websites or services operated by third parties, even if you reach them through links in the Service.


3. Roles: controller, processor, and contractor relationship

Privacy law in Canada and elsewhere distinguishes between a controller (who decides why and how personal information is handled) and a processor (who handles it on a controller’s behalf).

What this means in practice: if you are a homeowner who received an estimate from a contractor through Muninn and you want a copy of your data deleted, contact the contractor first. Muninn will support the contractor in honouring your request, but the contractor controls the relationship and the data.

For Quebec residents, the privacy officer designated under Law 25 is reachable at privacy@muninn.ca.


4. What personal information we collect

We collect only what we need to run the Service. The categories below describe what is collected, from whom, and why.

4.1 From marketing-site visitors

Category Examples Why
Contact information Email address, optional name, optional company Waitlist signup, marketing communications you opted into
Device and browsing information IP address, browser type, operating system, referring URL, pages viewed, time on page Site analytics, security, fraud prevention
Cookie and tracking identifiers First-party cookies, Google Analytics identifiers, Google Tag Manager events Analytics, conversion measurement, ad attribution where consented
Communications you send us Email body, attachments, phone messages To respond to you

4.2 From contractor users (account holders and team members)

Category Examples Why
Account credentials Username, email, password hash, role, plan Authentication and access control
Company profile Company name, address, GST number, phone, logo Rendering estimates, invoices, and emails; tax reporting
Billing information Stripe customer ID, subscription tier, last-four payment card digits (Stripe-handled), invoice history Subscription billing
Workspace content Estimates, invoices, change orders, draw invoices, line items, templates, expenses, receipts, custom Terms & Conditions Core product functionality
Communications data Emails sent through the Service, message threads with clients, support tickets Product features and support
Device and session data IP address, browser, session tokens, audit timestamps Security, fraud prevention, debugging

4.3 From client recipients (homeowners, property managers, other clients of contractor users)

Most of this data is entered by the contractor user, not by the client directly.

Category Examples Why
Contact information Name, email, phone, mailing address, project address Quoting, invoicing, document delivery
Project information Scope of work, line items, photos, files uploaded by the contractor Quote and invoice generation
Approval and signature data Typed name, drawn signature, IP address, timestamp, decline reasons, message thread content Legally binding e-signature evidence
Payment information Stripe payment intent identifiers; full card numbers are never stored by Muninn Deposit and balance collection

4.4 From everyone, automatically

We collect technical log data on every request to the Service: IP, user-agent, request path, status code, and timing. We retain these logs for a limited period (see Section 9).


5. AI and optical-character-recognition (OCR) processing

Muninn uses third-party artificial-intelligence services to power two specific features:

  1. AI estimating assistance — interpretation of scope-of-work text and suggestion of line items.
  2. AI receipt OCR — extracting vendor, date, line items, and totals from images or PDFs of supplier receipts and invoices.

The third-party AI providers we currently use are:

What is sent to these providers:

What we instruct the providers to do:

We use these providers under their enterprise / API terms which prohibit training on customer content. Provider behaviour may change; the current providers and their stated terms are available on request from privacy@muninn.ca.

You can avoid sending data to AI providers by not using the AI estimating assistant and by entering receipt data manually instead of uploading photos.


6. Cookies, analytics, and similar technologies

The marketing site at muninn.ca uses cookies and similar technologies. The App at app.muninn.ca uses only the cookies strictly necessary to keep you signed in and secure.

Categories we use:

Category Examples Consent needed?
Strictly necessary Session cookies, CSRF tokens, load-balancing cookies No — these are required for the Service to function
Analytics Google Analytics, Google Tag Manager events Yes — you can opt in or out at first visit and at any time
Advertising attribution Google Ads conversion tags, Facebook Pages pixel (where used) Yes — opt-in only

The full list of cookies, retention periods, and opt-out instructions is summarized in the table above and in the consent banner shown on first visit.

In jurisdictions that require it (Quebec under Law 25; the EU and the UK under GDPR / UK-GDPR), we ask for your consent before setting any non-strictly-necessary cookie, and you can withdraw consent at any time.


7. How we use personal information

We use personal information for the following purposes:

  1. Providing the Service — running the App, rendering documents, delivering emails, processing payments, supporting e-signatures, generating reports.
  2. Account and billing administration — creating workspaces, managing team members, processing subscription payments through Stripe, sending invoices for the Service itself.
  3. Customer support — responding to your messages, debugging your account, restoring data from backups when you ask us to.
  4. Security and fraud prevention — detecting account compromise, rate-limiting abusive activity, preserving audit logs of approvals and signatures.
  5. Service improvement — measuring how features are used, fixing bugs, prioritizing the roadmap. We use aggregated and de-identified data wherever possible.
  6. Marketing communications — only with your consent, and only on the marketing-site surface. You can unsubscribe from any marketing email with one click; we do not send marketing emails to client recipients of contractor users.
  7. Legal and regulatory compliance — responding to lawful requests, defending claims, complying with tax and corporate-records obligations.

We do not sell personal information. We do not rent personal information. We do not use client-recipient data to train AI models.


Where Canadian, EU, UK, or Quebec law requires a specific legal basis for each processing activity, the bases we rely on are:

Activity Basis
Account creation and Service delivery Performance of the contract with you
Subscription billing Performance of the contract; legal obligation (tax records)
Security, fraud prevention, audit logs Legitimate interest
Marketing emails to opted-in subscribers Consent
Non-essential cookies and analytics Consent
AI processing of scope text and receipts Performance of the contract (with your knowledge and ability to opt out)
Sharing data with sub-processors (Section 11) Performance of the contract; legitimate interest
Responding to legal requests Legal obligation

You may withdraw consent at any time for activities where consent is the basis. Withdrawing consent does not affect processing done before the withdrawal.


9. How long we keep personal information

We keep personal information only as long as we need it for the purposes set out in this Policy, or as required by law.

Category Retention
Account and workspace data (active accounts) For the life of the account
Account and workspace data (after cancellation) 90 days, then permanent deletion unless legal hold applies
Backups containing account data 14 days (nightly rolling backup)
Estimates, invoices, signed approvals (closed accounts) 7 years from creation, to meet Canadian tax and contract-evidence requirements
Billing records 7 years (Canadian tax law)
Marketing-site visitor logs 12 months
Application server logs 90 days
Analytics data (Google Analytics) 14 months (configurable property setting)
Support tickets and email correspondence 3 years from last interaction

Client-recipient data is governed by the retention policy chosen by the contractor user who controls the workspace, subject to the legal minimums above for signed documents and billing.


10. How we secure personal information

We use a layered set of safeguards appropriate to the sensitivity of the data:

No system is perfectly secure. If you believe your account has been compromised, contact security@muninn.ca immediately.


11. Sub-processors and third parties we share data with

We share personal information only with the categories of recipient below, and only as needed:

Recipient Role Data handled Location
Stripe, Inc. Payment processing Billing identifiers, payment-card details (Stripe-handled), transaction records United States; PCI-DSS Level 1
Hetzner Online GmbH Application hosting (VPS) All workspace data Germany
Vercel Inc. Marketing site hosting Site analytics, deployment data United States and edge regions
Web Hosting Canada (WHC) Email hosting Inbound and outbound email Canada
Google LLC Google Generative AI (Gemini); Google Analytics; Google Tag Manager; Google Ads measurement AI inputs; analytics events United States
OpenAI, L.L.C. AI text generation for scope interpretation Scope text only United States
Cloudflare, Inc. DNS and edge protection (where used) IP addresses, request metadata Global
Facebook / Meta Platforms, Inc. Marketing-site advertising attribution (where used) Visitor identifiers, conversion events United States
Microsoft Corporation (Outlook) Email triage by the founder Inbound and outbound email United States and Canada

We have written terms with each of these recipients limiting their use of your data to providing the service to us.

Some recipients are located outside Canada. When personal information is transferred outside Canada or Quebec, it becomes subject to the laws of the recipient country and may be accessible to government and law-enforcement authorities there under those laws. We use contractual safeguards (data-processing agreements, standard contractual clauses where applicable) to require an equivalent level of protection.

If you would like the current list of sub-processors, email privacy@muninn.ca.


12. Cross-border data transfers

Muninn stores the App database on servers operated by Hetzner Online GmbH in Germany. Marketing-site hosting and several sub-processors are based in the United States. Email is hosted in Canada.

By using the Service, you understand and consent to the transfer of your personal information to these jurisdictions. Where required by Law 25, GDPR, or UK-GDPR, we rely on contractual safeguards with our sub-processors to maintain a level of protection comparable to the protections in your home jurisdiction.


13. Your privacy rights

Depending on where you live, you have some or all of the following rights:

To exercise any of these rights, email privacy@muninn.ca with enough information for us to identify your account or your relationship to the Service. We will respond within 30 days. If we need more time, we will tell you why and when to expect a full response.

If your data is held in a workspace controlled by a contractor user (you are a client recipient), please contact the contractor first; we will support them in honouring your request.


14. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact privacy@muninn.ca and we will delete it.


15. Quebec Law 25 — specific disclosures

This section applies to residents of Quebec and supplements the rest of this Policy.


16. Marketing emails (CASL)

Muninn complies with Canada’s Anti-Spam Legislation (CASL). We send commercial electronic messages only to recipients who have given express or implied consent, and every commercial message includes an unsubscribe mechanism and our identification and contact information. Transactional emails (estimates, invoices, account notifications, security alerts) are not marketing emails for CASL purposes.


17. Changes to this Policy

We will update this Policy from time to time. The version number and “last updated” date at the top will change with each revision. For material changes (a change in the data we collect, in the sub-processors we use, or in your rights), we will notify account holders by email or in-App notice at least 14 days before the change takes effect.

Previous versions of this Policy will be available on request from privacy@muninn.ca.


18. Contact

For all privacy-related questions, requests, and complaints:

We respond in English and French.


This Policy was prepared as an operational document for the Muninn Service. It is not a substitute for advice from a qualified Canadian privacy lawyer; obtain such advice before relying on it in disputes, regulatory filings, or M&A diligence.