This Agreement governs our processing of personal information on your behalf when you use RoadSnap in the course of a business. It is written to be read rather than survived: what we process and why, what we owe you, who else touches the data. It also covers what happens in an incident, how long we keep things, and how a transfer out of Québec or the EEA is covered.
No signature is needed: it applies when you accept our Terms. For a countersigned copy, or to ask for a change, write to privacy@roadsnap.app. Print / Save as PDF above gives a copy your legal team can mark up.
This Agreement forms part of the RoadSnap Terms of Service between Loon Island Group, inc. ("RoadSnap", "we", "the Processor") and the customer entity agreeing to those terms ("Customer", "you", "the Controller"). Where this Agreement and the Terms of Service conflict on the processing of personal information, this Agreement governs.
1. Definitions
Terms not defined here carry the meaning given in the applicable law. That means Québec's Act respecting the protection of personal information in the private sector, as amended by Law 25. It also means Canada's PIPEDA and Regulation (EU) 2016/679 ("GDPR").
- Personal Information — information about an identifiable individual, including information that identifies them indirectly or in combination with other information.
- Processing — any operation performed on Personal Information, whether or not by automated means.
- Sub-processor — a third party engaged by RoadSnap that processes Personal Information on our behalf to deliver the service.
- Security Incident — a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Information.
2. Roles
You are the Controller of the Personal Information you place in RoadSnap. We are the Processor, and we act only on your documented instructions.
Your use of the service is your instruction. Creating a workspace, inviting a colleague, connecting Jira or Slack, and exporting a roadmap are all instructions to process. Beyond those, we process only where the law requires it. Where a law compels us to process in a way you have not instructed, we will tell you first, unless that law forbids it.
3. What we process, and why
3.1 Categories of individual
Your personnel; anyone you invite into a workspace or share a roadmap with; and, where you connect Jira, the assignees of your Jira issues.
3.2 Categories of information
| Category | What it is | Why we hold it |
|---|---|---|
| Account identifiers | Email address; a system-generated user_id; the workspace_id of each workspace they belong to; role within it | To authenticate a person and decide what they may see and do |
| Content | Roadmaps, issue trees, node titles and notes, snapshots, history, and anything else you type | It is the service |
| Relationship data | Workspace membership, invitations, share links and who they were issued to | To enforce access and seat limits |
| Commercial data | Plan tier, subscription status, seat count, discount cohort, renewal dates | Billing and entitlement |
| Communication preferences | Per-channel consent, the record of when and how it was given, and suppression state | To honour choices and to prove they were made |
| Jira assignees | The Atlassian account id of an issue’s assignee, held in the roadmap’s Assignee column. The display name, held per workspace in a table of ours and reported to Atlassian every seven days | To show who holds a ticket, on a roadmap you synced with Jira |
| Comments and mentions | A comment’s text, its author’s identifier and address, and the people it mentions | Discussion on an item, and the email a mention sends |
| Usage telemetry | Allow-listed event names, a per-page-load random session identifier, a date, the referring hostname and a two-letter country | Product measurement |
| Technical data | IP address and user agent at the point consent is recorded | Evidence of consent under CASL and the GDPR |
Account identifiers are Personal Information and are declared as such. A user_id or workspace_id is a pseudonymous identifier, not anonymous data. It is stable, and anyone holding the mapping can link it to a person. It is therefore given the same protections as an email address throughout this Agreement. We say so because it is the
thing most often left out.
Usage telemetry is not linked to an individual. The session identifier is generated fresh on each page load, is never stored against an account, and cannot follow a person between sessions. Event names come from a published, closed list and never contain content.
3.3 What we never process
We do not process special categories of Personal Information, and RoadSnap is not intended for them. Those are health, biometrics, racial or ethnic origin, political opinions, religious beliefs, trade union membership and sexual orientation. We do not process payment card details: those go straight to Stripe and never reach our systems.
3.4 Duration
For as long as your account exists, plus the retention periods at section 8.
4. Our obligations
We will:
- Process Personal Information only on your instructions, as described above.
- Ensure that anyone authorised to process it is under an appropriate duty of confidentiality.
- Apply the technical and organisational measures described at section 6.
- Engage Sub-processors only under section 5.
- Assist you, so far as we reasonably can, with responding to individuals exercising their rights. Assist you in the same way with your own obligations for security, breach notification and impact assessments.
- Delete or return Personal Information under section 8.
- Make available the information reasonably needed to demonstrate compliance with this Agreement, and allow audits under section 10.
5. Sub-processors
You give general authorisation for the Sub-processors listed below. The current list is published at roadsnap.app/security.html and is part of this Agreement by reference.
| Sub-processor | Purpose | Where |
|---|---|---|
| Supabase | Managed database, authentication, sign-in emails | Database in Canada (Central); provider operations may occur elsewhere |
| Vercel | Application hosting and serverless functions | Global edge network |
| Cloudflare | DNS, domain registration, inbound email routing | Global |
| Resend | Outbound transactional and preference-based email | United States |
| Stripe | Payment processing and subscription management | Global; PCI-DSS Level 1 |
| Anthropic | The AI Assistant: answering questions about a plan, and proposing changes to it | United States. Engaged 29 August 2026. Named here in advance on 28 August, while it still received nothing. So the 30 days’ notice below ran before the feature existed. We do not permit your plans to be used to train models. |
What reaches the model, and when. When somebody uses the AI Assistant, we send Anthropic the question and an outline of that roadmap: item ids, titles and field values. Notes are not sent with it. If answering needs the detail in a branch, the AI Assistant asks for that branch and its notes are sent then. It can also run a web search, in which case a search phrase it composes leaves too. It also runs once when you open a roadmap, at most once a day and only on Pro and Team, to offer two short suggestions. Settings → Suggestions (daily, weekly or never) controls that, and off stops those calls entirely. Nothing is sent for anyone on Free, or for a workspace that has switched it off.
What we retain. For a question asked, one metering row — timestamp, who asked, workspace and roadmap, token counts, cost, outcome, and how many changes were proposed. Not the question and not the answer. For an unprompted suggestion, the suggestion itself and what the person made of it, so it is never repeated. Field values in the outline can include names in an Owner column and Jira account ids.
The suggestions RoadSnap makes without the AI Assistant are computed in your browser and sent nowhere. That covers an inherited value, a suggested priority and the critique in Insights, and was true before the AI Assistant shipped.
Connections you start — Atlassian (Jira) and Slack — are authorised by you when you connect them, per workspace. Once Jira is connected, we report the Atlassian account ids we hold back to Atlassian every seven days, as their user-privacy terms require. Nothing else about a plan goes to either.
Changes. We will give you at least 30 days' notice before adding or replacing a Sub-processor. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative. If none is practicable, you may terminate the affected service and receive a pro-rata refund of prepaid fees.
We remain liable to you for the acts and omissions of our Sub-processors as if they were our own.
6. Security
Measures are described in full at roadsnap.app/security.html. In summary:
- Encryption in transit and at rest, provided and maintained by our infrastructure providers. We do not hold or manage encryption keys.
- Passwordless authentication. No password database exists to be stolen.
- Isolation enforced by the database, not by application logic. Row-level security separates one customer's data from another's, so a bug in our code is not enough to cross that boundary.
- Least privilege for internal tooling. Our staff analytics application runs under a database role that is denied access to all tables by default. It is granted read access to a handful of usage summaries and the feedback people chose to send us. It is also granted one lookup, which records who asked and why before it returns an account’s metadata. It holds no grant on the tables that carry plans, users, memberships, workspaces or subscriptions: it cannot read customer content.
- Strict content security policy, no third-party trackers, no session replay.
- Multi-factor authentication on the administrative accounts that control the domain, the code, the deployment and the database.
- Backups taken daily and retained for seven days, and restore drills run at least quarterly with the measured result recorded.
7. Security Incidents
We will notify you without undue delay and within 72 hours of establishing that a Security Incident affecting your Personal Information has occurred. That clock starts when we establish the incident, not when we finish investigating it.
Our notice will describe the nature of the incident and the categories and approximate number of individuals and records concerned. It will give the likely consequences, the measures taken or proposed, and a contact point. Where we do not yet know part of that, we will say which part and when we expect to know. We will not delay the whole notice.
We keep a record of Security Incidents whether or not they meet a notification threshold.
Contact: security@roadsnap.app
8. Retention, return and deletion
| Data | Retained |
|---|---|
| Deleted roadmaps | 30 days, then permanently removed |
| Usage telemetry | 400 days, then purged by an automated job |
| Consent records and send log | 400 days |
| Backups | 7 days |
| Account and content | For the life of the account; destroyed 30 days after closure |
| Jira assignee names | Until Atlassian reports the account closed or changed, or the connection or workspace is removed |
| Assistant metering rows and unprompted suggestions | For the life of the workspace; no fixed period |
| Feedback sent to us | Kept while useful; the sender’s address is removed when their account is purged |
| Comments | With the roadmap; the author’s identifier and address are removed when their account is purged |
| Roadmap change log (who changed which item, when) | 400 days, then purged by an automated job |
| Support console audit log | 400 days |
On termination, you may export a complete copy of every roadmap at any time, without asking us. We will delete Personal Information within 90 days of account closure, except where a law requires us to retain it. Backups age out on the schedule above and are not selectively edited. Personal Information in a backup remains subject to this Agreement until the backup expires.
9. International transfers
Your roadmaps and account data are stored in Canada. Canada holds an adequacy decision from the European Commission, which is the transfer mechanism for personal information moving from the EEA to us.
Some Sub-processors operate outside Canada, and some processing — serving the app, routing requests, delivering email — must occur elsewhere. Where a transfer requires it, we rely on Standard Contractual Clauses and on the transfer terms of the Sub-processor concerned. Under Québec Law 25 we conduct a privacy impact assessment before any transfer outside Québec.
10. Audit
On reasonable notice, we will provide the information reasonably needed to demonstrate compliance with this Agreement. That includes completed security questionnaires and any third-party reports we hold. You may ask no more than once in any twelve-month period, and also following a Security Incident.
Where that is insufficient for your regulatory obligations, we will cooperate with an audit. It may be by you or an independent auditor bound by confidentiality, at your cost and at a time that does not disrupt the service.
11. Assistance with individual rights
Individuals may exercise their rights directly, and much of it needs no request: export and communication preferences are self-service. Account deletion is self-service: Plan & billing → Close my account. Access and billing end at once and the data is deleted 30 days later, inside the 90 days section 8 commits to. Within those 30 days it can be reopened. Closing is refused while you own a team workspace that other people are in, so one person leaving cannot delete another’s work. privacy@roadsnap.app is there for anyone who would rather a person did it.
Where you receive a request about Personal Information we process on your behalf, we will help you respond within the statutory period. If one of your users asks us directly, we refer them to you rather than act on it, unless the law requires otherwise.
12. Liability and duration
Liability under this Agreement is subject to the limitations in the Terms of Service. This Agreement requires no signature. It takes effect when you accept the Terms of Service; there is nothing to countersign. It continues for as long as we process Personal Information on your behalf.
13. Contact
Loon Island Group, inc. 349 Avenue Kensington, Westmount, Québec, Canada H3Z 2H2
- Privacy and this Agreement — privacy@roadsnap.app
- Security and incidents — security@roadsnap.app