SiteVisit
Terms of ServiceClient loginGet started

Legal

Privacy Policy

Effective: September 23, 2026 · Last updated: September 24, 2026

SiteVisit is designed for business and workplace site access. This Policy explains what personal information SiteVisit processes, why it is used, when it is visible to host or home organizations, how GPS and welfare features work, and how to contact SiteVisit about your privacy rights.

1. Scope and accountability

This Privacy Policy applies to sitevisit.ca, the SiteVisit client portal, visitor application, QR and digital check-in experiences, communications, and related SiteVisit services.

SiteVisit is accountable for personal information under its control and is intended to operate in accordance with Alberta's Personal Information Protection Act (PIPA) and other applicable Canadian privacy laws.

Organization Customers also make independent decisions about their locations, staff, visitors, site rules, contacts and notifications. Depending on the context, an Organization Customer may have its own privacy obligations and may be responsible for providing additional notices or obtaining authority to collect, use or disclose personal information through SiteVisit.

2. Information we collect

Visitor profile and identity information

  • phone number and phone-verification status;
  • name, email address, company or organization, and position or title;
  • verified staff affiliation, where applicable;
  • account or profile status and device associations used to support verification and access.

Visit and site-access information

  • the Host Organization and location visited;
  • check-in and checkout times and sources;
  • visit reason, where required;
  • terms or policy acceptances;
  • access-policy results, affiliation status and related visit settings;
  • site log entries and other information submitted during a visit.

GPS verification information

When a location requires GPS verification, the Visitor's device provides its current location so SiteVisit can compare it with the site's configured coordinates. SiteVisit is designed to store the resulting verification information, such as approximate distance from the site, reported accuracy, configured radius and pass/fail result, rather than create a continuous location history.

No continuous GPS tracking. SiteVisit's current GPS feature is a point-in-time proximity check used during site access. It is not intended to follow a Visitor's movements throughout the day.

Welfare and safety workflow information

  • whether welfare monitoring is enabled for a visit;
  • scheduled check times and welfare status;
  • SMS or automated-call attempts and provider delivery status;
  • responses such as safe, needs help, no response or error;
  • escalation events, resolution status, resolution notes and the portal user who resolved an event where applicable.

Problem reports and photos

If problem reporting is enabled, SiteVisit may process a Visitor's description, an automated category or priority, a summary, a safety-concern indicator, and recipient information. Where photos are permitted, uploaded photos may be resized or compressed and transmitted as email attachments to recipients configured by the Host Organization. SiteVisit's current problem-report workflow does not use the uploaded photos as AI image input.

Site Assistant and AI usage

When a Visitor uses the Site Assistant, SiteVisit processes the question together with approved site knowledge supplied by the Host Organization so an answer can be generated. When full problem reporting is enabled, the written problem description may be sent for automated classification and summarization.

SiteVisit may record AI usage metadata such as the organization, location, person, visit, feature, model, provider request identifier and token counts. SiteVisit configures its current AI requests with provider-side storage disabled where supported.

Organization and portal information

  • organization name, business contact information and billing contact;
  • portal-user name, email, job title, role, account status and authentication information;
  • locations, addresses, coordinates, contacts, site knowledge, terms, access settings and notification preferences;
  • staff affiliations, partner relationships and related permissions.

Communications, device and technical information

We may process email, SMS, voice-call and push-delivery records, phone numbers, provider identifiers and statuses, message excerpts, push-subscription information, browser or device information, security events, and IP-address or user-agent information or hashed derivatives used for fraud prevention, security, troubleshooting and QR access controls.

Billing information

If SiteVisit introduces or enables paid services, we may process billing contact information, plan or usage information, invoice status and transaction identifiers. A third-party payment processor may collect payment-card information directly; SiteVisit does not need to receive full card numbers to provide normal billing functions.

3. How we collect information

We collect information:

  • directly from Visitors and portal users;
  • from Organization Customers that create locations, staff affiliations, contacts, partner relationships and policies;
  • automatically when the Service is used, including security, device and operational records;
  • from communications providers when they return message or call delivery information;
  • from a Visitor's device when the Visitor grants location or push-notification permission; and
  • from service providers used to operate requested features.

4. Why we use personal information

SiteVisit uses personal information for reasonable purposes including to:

  • create and maintain accounts and visitor profiles;
  • verify phone numbers, identities and staff affiliations;
  • process site entry, GPS verification, check-in and checkout;
  • show authorized organizations who is onsite and maintain visit history;
  • provide site terms, site information, logs and problem reporting;
  • operate welfare monitoring, notifications and escalation workflows;
  • support approved partner visibility between Host and Home Organizations;
  • generate Site Assistant responses and problem-report classifications;
  • send operational, security and service communications;
  • prevent abuse, investigate incidents, troubleshoot and secure the Service;
  • administer paid services if introduced or enabled; and
  • comply with law, enforce agreements and protect rights, safety and property.

5. Consent and other permitted processing

Where consent is required, SiteVisit seeks consent in a form appropriate to the information and purpose. Some processing may also be permitted without consent under applicable law, including certain employee-information, legal, security or emergency-related circumstances.

You may withdraw consent where the law allows, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent to information necessary for verification, site access or welfare communications may mean that a requested feature or site check-in cannot be completed.

6. How information is shared

Host Organizations

A Host Organization and its authorized portal users may receive or view information related to visits at its locations, including Visitor identity and company information, check-in status, visit reason where used, welfare status, problem reports, site logs and other information needed to administer that location.

Home Organizations and partners

If a Visitor has a verified staff affiliation and the organizations have an active SiteVisit partnership, relevant visit and safety-event information may be visible to the Visitor's Home Organization as configured by the participating organizations.

Configured contacts and recipients

Information may be sent to organization or location contacts selected for check-in, checkout, welfare, problem-report or other operational notifications. Problem-report text and attached photos may be emailed to configured recipients.

Service providers

We use providers to help operate SiteVisit. Depending on the enabled features, these may include:

  • Twilio for SMS and automated voice communications;
  • OpenAI for Site Assistant responses and text classification;
  • Google for organization-requested site-address geocoding;
  • Cloudflare for Turnstile bot-abuse and security verification on selected public account forms;
  • hosting, database, email, push-notification, security and infrastructure providers.

These providers receive only information reasonably needed to perform the applicable service and are subject to their own legal and contractual obligations.

Legal, safety and business reasons

We may disclose information where permitted or required by law, to respond to lawful process, investigate fraud or security issues, protect a person's safety, enforce agreements, or protect SiteVisit's rights and property. Information may also be transferred as part of a merger, financing, sale, restructuring or similar business transaction, subject to appropriate safeguards and applicable law.

7. Processing outside Canada

Some SiteVisit service providers may process or store information outside Canada. In particular, services used for communications, artificial-intelligence processing and geocoding may process information in the United States. Information processed in another country may be subject to that country's laws and lawful access by courts, law-enforcement or government authorities.

Questions about SiteVisit's use of service providers outside Canada may be directed to the Privacy Officer using the contact information below.

8. Cookies, sessions and similar technology

SiteVisit uses cookies, browser storage, device identifiers and related technology where needed to maintain sessions, remember visitor state, support application installation, protect QR access, prevent abuse and operate requested features.

SiteVisit does not currently use third-party advertising cookies and does not sell personal information for advertising.

9. Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, for legitimate business and site-recordkeeping needs, to meet contractual or legal obligations, to resolve disputes, and to maintain security and audit records.

Different records may require different retention periods. When information is no longer reasonably required, it should be securely destroyed, deleted or anonymized, subject to technical, backup, legal and recordkeeping constraints.

10. Security

SiteVisit uses reasonable administrative, technical and organizational safeguards appropriate to the nature and sensitivity of the information under its control. No internet, mobile, email or communications system can be guaranteed to be completely secure, and we cannot promise that unauthorized access or loss will never occur.

Where a privacy breach triggers notification or reporting obligations under applicable law, SiteVisit will take steps required by that law.

11. Access and correction

You may request access to personal information SiteVisit holds about you and may ask that inaccurate information be corrected, subject to exceptions permitted by law. Requests should be made in writing to the Privacy Officer.

We may need to verify your identity before responding. Where Alberta PIPA applies, an organization generally must respond to an access request within the period required by PIPA, subject to permitted extensions.

You may also ask about deletion or withdrawal of consent. Some information may need to be retained for legal, security, contractual or legitimate recordkeeping purposes.

12. Organization-controlled information

If your request concerns information controlled by a Host Organization or Home Organization—for example, site-specific visitor records, employee information or an organization's internal use of SiteVisit—we may direct you to that organization or coordinate with it as appropriate. SiteVisit cannot change an organization's independent records or legal obligations merely because the organization uses the platform.

13. Push notifications and communication choices

Push notifications are optional and can be disabled through your browser or device. Operational SMS, voice or email messages may be necessary for verification, welfare monitoring, site notifications or account security. If you block those communications, some SiteVisit features may no longer work as intended.

If SiteVisit later sends promotional electronic messages, they will be handled separately in accordance with applicable consent and unsubscribe requirements.

14. Minors

SiteVisit is designed for workplace and business site access and is not directed to children for general consumer use. If an organization permits a minor to use SiteVisit in a legitimate work, training or site-visitor context, that organization is responsible for ensuring it has any notice, consent, supervision or other authority required by law.

15. Changes to this Policy

We may update this Privacy Policy as the Service, service providers or legal requirements change. The current version will be posted here with an updated date. We may provide additional notice where a change is material or where required by law.

16. Privacy Officer and complaints

Privacy Officer, SiteVisit
admin@sitevisit.ca

Please contact the Privacy Officer first with questions, access or correction requests, or privacy complaints. If Alberta PIPA applies and you are not satisfied with SiteVisit's response, you may have the right to contact the Office of the Information and Privacy Commissioner of Alberta.

SiteVisit
TermsPrivacy© 2026 SiteVisit