This Privacy Policy explains how AppraisePoint Inc. (“AppraisePoint”, “we”, “us”) collects,
uses, discloses, and protects personal information when you access or use AppraisePoint’s websites, applications, and services
(collectively, the “Service”).
Summary: AppraisePoint is a professional platform for jewelry appraisals and grading documentation. You control your workspace and customer data.
We use personal information to operate the Service, secure it, support you, improve it, and meet legal requirements.
1) Who this Policy applies to
- Applicants: people requesting business access, including while an application is pending or after it is declined.
- Workspace users: appraisers, managers, editors, trainees, and other authorized users within a company workspace.
- Customer users: end customers who may receive limited access when enabled by a workspace.
- Website visitors: people who visit our public pages (including legal pages).
2) Key definitions
- Personal information means information about an identifiable individual (as defined under applicable Canadian privacy laws).
- Customer Content includes appraisal/grading records, client details, item details, images, documents, notes, and other data entered or uploaded into the Service.
- Workspace Admin means the user(s) who control workspace settings and user access for a company (e.g., “Jeweller Manager”).
3) What we collect
A. Information you provide
- Account and profile info: name, email address, phone number, role, login credentials (encrypted/hashed as applicable), and profile preferences.
- Workspace info: company name, country, configuration settings, billing preferences, and permitted users.
- Application information: business and contact details, business website, optional professional references, selected plan and billing-period preferences, and supporting information you provide for business review. Please provide only relevant information and ensure you are authorized to share any reference contact details.
- Customer Content: appraisal and grading data, client records, item descriptions, pricing inputs, uploaded photos/files, notes, and generated Outputs.
- Support communications: information you include when contacting support, including attachments and diagnostic details you provide.
B. Information collected automatically
- Usage data: interactions with features, pages visited, timestamps, feature performance, and error logs.
- Signing and plan usage: company and record identifiers, first-signing timestamps, usage month and time zone, and whether a signature counts toward a plan allowance. These accounting records are separate from the appraisal or grading document itself.
- Onboarding measurements: company-linked milestones, such as approval, first use, and paid activation, and aggregate counts of signup and plan-selection events. Company-linked records are not anonymous merely because they do not include a person's name.
- Operating-cost measurements: company-linked provider and model names, operation types, timing, outcomes, token or other processing-unit counts, estimated costs, and daily storage size and file counts. These cost-measurement records contain operational metadata rather than copies of prompts, documents, images, or audio. Content used by an AI or document-processing feature is handled separately as described below.
- Device/technical data: IP address, browser type, device type, operating system, and approximate location inferred from IP (typically city/region/country level).
- Security and session data: authentication events, session identifiers, and signals used to prevent abuse and protect accounts.
- Business-review records: review notes, outcomes, timestamps, reviewer details, and automated trust indicators derived from application information. Automated indicators assist a human review; they do not automatically approve or reject business access.
C. Payments and billing
Payments may be processed by third-party payment providers (for example, Stripe). We do not store full payment card numbers on our servers. Payment providers may collect and process your payment information under their own terms and privacy policies.
D. Third-party sign-in
If you sign up or log in using a third-party identity provider (for example, Google), we may receive basic profile information (such as name and email) from that provider to create or connect your account.
4) How we use personal information
We use personal information to:
- Provide the Service: create accounts, authenticate users, enable workspace features, generate reports, and deliver outputs.
- Review access requests: assess business eligibility, review supporting information, communicate application outcomes, and detect misleading or duplicate applications.
- Administer plans and capacity: account for first signatures, apply staff and usage allowances, manage Free and paid access, prevent allowance evasion, and measure onboarding and operating costs to evaluate pricing and resource needs.
- Operate and support: respond to support requests, troubleshoot issues, communicate about account or service changes.
- Security and fraud prevention: protect accounts, detect suspicious activity, prevent abuse, and enforce our Terms of Service.
- Improve the Service: understand feature usage, fix bugs, maintain performance, and develop new features.
- Billing and transactions: manage subscriptions, invoices, payment status, and related notifications.
- Legal compliance: comply with applicable laws and lawful requests, and protect our rights and users.
5) Consent and permitted processing
We collect, use, and disclose personal information for the purposes explained in this Policy with consent where required by applicable law. Consent may be express or implied where the law permits, depending on the information and circumstances. We process information without consent only where applicable law permits or requires it; a contract or business interest does not by itself override consent requirements.
You may contact us to ask about processing or withdraw consent, subject to applicable legal or contractual restrictions and reasonable notice. Withdrawing consent to processing needed for business review, account security, or a requested feature may prevent us from approving access or providing that feature. Where processing is optional and consent is required, we will provide a choice. For a new purpose that requires additional consent, we will seek that consent before using the information for that purpose.
6) How we share personal information
We may share personal information in the following circumstances:
- Within your workspace: workspace users may access information according to roles and permissions set by the Workspace Admin.
- Service providers: vendors who help us operate the Service, including hosting, monitoring, email delivery, support, payments, AI assistance, document recognition, transcription, and research or data services. The information provided depends on the function being performed.
- AI and content processing: when you use a feature that requires external processing, relevant text, item details, images, uploaded documents, audio, or queries may be transmitted to a provider to perform that function. This content processing is separate from the metadata used to measure operating costs. Provider processing and retention depend on the service and applicable arrangements; Canadian primary storage does not guarantee that provider processing occurs only in Canada.
- Legal and safety: if required by law, court order, or to protect rights, safety, and security of AppraisePoint, our users, or others.
- Business transfers: in connection with a merger, acquisition, financing, reorganization, or sale of assets (subject to appropriate safeguards).
We do not sell personal information.
7) Data residency and international transfers
- Primary storage (Canada): Customer Content is stored in Canada by default.
- Future regions: we may offer additional storage regions in the future (including the United States). If this changes for your workspace, we will provide notice through the Service, your account, or email as appropriate.
- Access worldwide: the Service can be used globally. Users may access data from outside Canada, and data may transit across borders as part of normal internet communications and service operations.
- Provider processing: service providers may process or store information outside Canada, including in the United States. This can include content submitted for AI assistance, document recognition, or transcription, as well as account and transaction information needed for other services. Information processed abroad may be subject to the laws and lawful access requirements of those countries.
- Provider enquiries: contact the person responsible for privacy at info@appraisepoint.com to request our policies and practices concerning service providers, including processing countries, purposes, and applicable retention and data-use arrangements.
8) Retention
We retain personal information as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary depending on the type of information, account status, contractual requirements, and applicable laws.
- Applications: pending or declined application information and review records may be retained to administer the application, respond to enquiries, prevent repeated abusive applications, and meet applicable legal requirements. A declined application does not by itself erase these records.
- Free workspaces and cancellation: cancelling a paid subscription normally returns an eligible workspace to Free. It does not request account closure or deletion of customer records. Free access has no scheduled expiry, but it is not a commitment to retain information indefinitely or provide permanent archival storage.
- Signing accounting: deleting or reopening an appraisal or grading record does not delete the separate first-signing accounting entry. We retain the company and original record identifiers, signing date, and allowance information needed to maintain accurate usage history, resolve disputes, and prevent repeated use of the same allowance.
- Operational records and backups: billing, security, onboarding, and cost-measurement records may need to be retained separately from workspace content. Deletion from active systems does not necessarily remove backup copies immediately. Retention must remain limited to reasonable business or legal purposes; information no longer needed for those purposes is to be securely deleted or anonymized.
- Deletion enquiries: contact info@appraisepoint.com to request deletion of personal information or ask about retention for a particular record type. We may need to verify your identity and authority and consider legal retention requirements and the rights of other people before acting.
9) Security
We use administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure.
- Access controls and role-based permissions within workspaces
- Secure authentication and session controls
- Encryption in transit (and where appropriate, encryption at rest)
- Monitoring and logging for security and operational integrity
No method of transmission or storage is 100% secure. You are responsible for using strong passwords and protecting your login credentials.
10) Your choices and rights
Depending on your location and applicable law, you may have rights to access, correct, update, or delete personal information, or to withdraw consent.
- Workspace users: you may be able to update certain profile information in your account settings.
-
Requests: you can request access, correction, deletion, or withdrawal of consent by contacting us at
info@appraisepoint.com.
- Workspace Admin control: if your account is managed by a workspace, the Workspace Admin may be able to administer or deactivate your account.
11) Customer Content and your responsibilities
If you upload personal information about your customers (e.g., client identity details, contact information, photos, and item records), you are responsible for ensuring you have the right to do so and for providing any notices and obtaining any consents required by applicable law.
12) Children and minors
The Service is intended for professional and business use and is not directed to children.
If you believe a minor has provided personal information through the Service without appropriate authorization,
please contact us at info@appraisepoint.com.
13) Cookies and similar technologies
We use cookies and similar technologies for essential functionality (such as login sessions), security, and to understand usage.
See our Cookies Policy for details.
14) Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the “Last updated” date. For material changes, we will provide additional notice and obtain any further consent required by applicable law. Posting an updated Policy does not replace consent where consent is required.
15) Contact us
If you have questions, requests, or concerns about privacy, contact: