Privacy Policy
Last updated 12 September 2026
1. Who we are
Ranging ("we", "us") operates the website at ranging.ca and the portal at portal.ranging.ca from 200–1017 Fort Street, Victoria, British Columbia V8V 3K5, Canada.
We are responsible for the personal information described in this policy. To ask a question about it, or to exercise any of the rights in section 10, write to admin@ranging.ca or use the request form at portal.ranging.ca/public/dsar. We answer privacy requests within 30 days, as Canadian law requires.
2. What this policy covers
This policy covers:
- the website at ranging.ca, including the contact form on it; and
- the portal at portal.ranging.ca, the signed-in application where partner organizations and supplier companies use Ranging.
Together we call these the Services.
What Ranging does. Ranging monitors public procurement and innovation portals in Canada and allied countries and matches the opportunities it finds against profiles of supplier companies, producing a ranked, deadline-aware list for each company. Partner organizations — accelerators, economic development agencies and industry associations — use it across a portfolio of companies. Supplier companies use it for themselves, free of charge.
The opportunity records we collect from procurement portals are public business information, not personal information, and this policy does not concern them. This policy is about information that identifies people.
3. Whose information we handle
Four groups, because the answers differ:
1. Website visitors who read ranging.ca or use its contact form. 2. Partner users — staff at an accelerator, agency or association who use the portal on their organization's behalf. 3. Company users — founders and staff at a supplier company who use the portal for their own company. 4. People named in information an organization gives us — for example, a partner adds a portfolio company and provides a founder's name and email, or a company provides material that names its own staff or client contacts. You may be in this group without having contacted us yourself. Section 6 explains what we do about that.
4. What we collect
On the website
The contact form asks for your email address (required), and optionally your name and organization. When you submit it, Cloudflare's network tells our server a two-letter country code for your connection; we store that and nothing else about your location. We do not store your IP address.
The website sets no cookies and uses no tracking pixels. We use Umami, a cookieless analytics service, to count page views and link clicks. It does not build a profile of you and does not follow you to other websites. The form is protected by Cloudflare Turnstile; to check you are not a bot, your IP address is sent to Cloudflare as part of that check, and we neither receive nor store it.
On the portal
- Account information — your name, email address, the organization you belong to, and your role in it. That is the whole of what our own database holds about you personally.
- Authentication — sign-in is handled by Stytch, which holds your login credentials and session records. We never see or store a password.
- Sign-in with Google or Microsoft — you can sign in using a Google or Microsoft work account. If you do, the provider gives us your name, email address and a stable account identifier, and nothing more. We do not receive your contacts, calendar, files or mail, and we do not ask for permission to. Google and Microsoft handle your sign-in under their own privacy policies.
- A session cookie —
stytch_session_jwt, which keeps you signed in. It is strictly necessary for the portal to work; without it the portal cannot tell one signed-in person from another. There is nothing to opt into and no advertising cookie to refuse. - Company information — profiles describing a company's capabilities, technology readiness and eligibility, and supporting material a company chooses to provide. This is mostly business information, but it can name people — personnel, client contacts, referees.
- Confidential business and financial information — a company may choose to give us material it treats as confidential, including financial information, because it helps assess fit and eligibility. We accept it only with the company's consent, we treat it as confidential, and we use it solely to provide the Services to that company and the partners it has authorized. Our Terms of Use set limits on what may be submitted; see "What we deliberately do not collect" below.
- Usage records — what you do in the portal, including which opportunities you open, pursue, skip or snooze, and when. We use this to run the product, to improve matching, and to report to a partner on its own portfolio. Where we report beyond the company itself, we do it in aggregate or with individuals removed.
- Server and security logs — our hosting and application infrastructure records the IP address, browser type, timestamp and requested resource for each request to the portal. We use these logs only to keep the Services running and secure, to diagnose faults and to investigate suspected misuse. They are not used for analytics or profiling and are deleted on the schedule in section 11.
Google API Services
Where we receive information through Google APIs (for example, when you sign in with Google), our use of that information complies with the Google API Services User Data Policy, including its Limited Use requirements.
What we deliberately do not collect
- We do not use advertising, marketing or cross-site tracking cookies anywhere.
- We do not buy contact lists or enrich your record from data brokers.
- We do not ask for, and do not want, personal information about health, racial or ethnic origin, religious belief, sexual orientation, or other categories of that kind. Please do not send it.
- We do not want classified, controlled-goods or otherwise export-controlled material, or anything you are not permitted to disclose to us. Do not upload it. See our Terms of Use.
5. Why we use it, and on what basis
We use personal information to operate the Services: to create and secure accounts, to match opportunities to companies and explain the match, to send the alerts and digests you have asked for, to answer you when you contact us, to report to a partner organization on the portfolio it runs, to keep the Services secure, and to meet legal obligations.
Under the Personal Information Protection and Electronic Documents Act (PIPEDA) and the equivalent laws of British Columbia, Alberta and Quebec, we rely on your consent, which you give by using the Services after reading this policy, and which you can withdraw at any time under section 10. Where a company gives us confidential business or financial information, we rely on that company's express consent. We do not use your information for a new purpose without asking you first.
In limited situations Canadian law allows us to collect, use or disclose personal information without consent, and we may do so where it applies — for example, to investigate a suspected breach of our Terms of Use or of the law, to detect or prevent fraud, to comply with a subpoena, warrant, court order or other lawful demand, or in connection with a business transaction as described in section 8. We do not treat these exceptions as a general licence, and we rely on them only where the law permits.
We do not sell personal information. We do not share it for anyone else's marketing. Where we use what we learn from the Services to improve them or to build new products, we do so with aggregated or de-identified information, not with records that identify you.
6. Information an organization gives us about you
If a partner organization adds a company to its portfolio, or a company gives us material naming its people or contacts, we hold that information on that organization's behalf and use it only to provide the Services to them. The organization is responsible for having the right to give it to us and for telling the people concerned.
Two commitments we build into the product rather than only promising here:
- A company owns its own material. A partner organization gets access to it, never ownership. Access is specific, recorded, visible to the company, and revocable, and it lapses automatically when the relationship between them ends.
- Access is logged, so a company can be told who has looked at what.
If you believe we hold information about you because someone else gave it to us, write to admin@ranging.ca. We will tell you what we hold, correct it, or delete it, and we will tell you which organization provided it so you can take it up with them.
7. Automated processing and AI
Ranging's rankings, fit assessments and the written rationale behind them are produced by automated processing, including large language models provided by Anthropic and OpenAI. Both are listed in the table in section 8.
- These outputs are advisory. A person decides what to do with them. Ranging does not make decisions about individuals, and it makes no decision about anyone's eligibility, funding, employment or contracts.
- The material we send to these providers for assessment is company and opportunity information. We do not send account credentials, and we minimize personal information in what we send.
- Our agreements with these providers do not permit them to train their models on your information, and they are bound to use it only to provide the service to us.
- If we add or change an AI provider, we will update this policy and the table in section 8, and we will tell anyone with an account before the change takes effect.
You can ask us how an assessment about your company was produced, and ask us to have a person review it. Write to admin@ranging.ca.
8. Who else handles it
Each provider is bound by contract to protect the information and to use it only to provide its service to us.
| Provider | What it does | Where it processes |
|---|---|---|
| Cloudflare, Inc. | Hosts ranging.ca; stores contact form submissions; anti-spam checks | Global network, including the United States |
| Fly.io, Inc. | Hosts the portal application and API; server logs | Canada |
| Neon, Inc. | The portal's Postgres database — accounts, companies, matches — and its backups | United States |
| Stytch, Inc. | Sign-in, session management, credentials | United States |
| Google LLC | Optional sign-in with a Google account | United States |
| Microsoft Corporation | Optional sign-in with a Microsoft account | United States |
| Anthropic, PBC | Large language models used for ranking and fit assessment | United States |
| OpenAI | Large language models used for ranking and fit assessment | United States |
| Resend (Plus Five Five, Inc.) | Sends our notification and confirmation emails | United States |
| Umami Software, Inc. | Cookieless website analytics on ranging.ca | United States |
Beyond these providers, we disclose personal information only: with your consent; to our professional advisors, who are bound to keep it confidential; where required by a Canadian law, court order or lawful demand by a public authority; or to a purchaser or successor if the business is sold or reorganized, in which case this policy continues to apply until the new owner publishes its own and notifies you.
9. Where your information is processed
We will be plain about this, because our customers work in defence and will ask.
The portal's application and API run in Toronto. The portal's database is currently hosted in the United States (AWS us-east-1), so account records, company profiles and matches are stored there. Our email, authentication, analytics and AI providers also process in the United States.
While information is in another country it is subject to that country's laws, and courts and law enforcement there may be able to compel access to it under that country's legal process, including United States law. Canadian privacy law permits this transfer and requires us to tell you it happens and to hold our providers to a comparable standard of protection.
If data residency matters to your organization, raise it with us before you onboard — write to admin@ranging.ca and we will tell you exactly where things stand and what we can commit to in a written agreement.
10. Your rights
You have the right to know what we hold about you and how we have used it; to see it and get a copy; to correct it; to withdraw your consent, subject to legal or contractual limits we will explain at the time; to have it deleted where we have no legal reason to keep it; and to unsubscribe from any commercial email instantly and at no cost.
To exercise any of these, use the request form at portal.ranging.ca/public/dsar or write to admin@ranging.ca. We may ask you to confirm your identity so we do not disclose your information to someone else. There is no charge.
If you are not satisfied with how we handled a privacy question, please tell us first — we would rather fix it. You may also complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca, 1-800-282-1376), or to your provincial commissioner in British Columbia, Alberta or Quebec.
Quebec residents may also ask for their information in a structured, commonly used technological format, and have the additional rights given by Law 25.
11. How long we keep it
- Contact form submissions — while we have an active relationship or a live prospect of one, then two years from last contact, then deleted.
- Portal accounts — while the account is active. When an account is closed we delete the personal information in it within 90 days, except where we must keep something to meet a legal obligation.
- Company material — while the company's relationship with us continues. When a relationship between a company and a partner ends, the partner's access ends immediately.
- Server and security logs — 30 days, then deleted, unless a specific entry is needed for an ongoing security investigation.
- Email correspondence — up to seven years, the period Canadian tax and business records law expects us to be able to reconstruct our dealings.
- Backups — our database provider keeps backups so we can recover from a fault. Information you have asked us to delete may persist in a backup for up to 30 days after it is removed from the live database. Backups are encrypted, are not used for any other purpose, and are not restored except to recover the service.
- Aggregated and de-identified information — indefinitely. It does not identify you.
12. How we protect it
Everything runs over HTTPS. Access to the portal requires authentication through Stytch. Which records an account can see is enforced centrally in the API, not in the browser, so one organization cannot reach another's data. Administrative access to production is limited to the people who need it, using credentials held in an access-controlled system.
No system is perfectly secure and we will not pretend otherwise. If a breach of security safeguards creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as PIPEDA requires. We keep a record of breaches as the law requires.
13. Email from us
If you submit the contact form we send one confirmation email and then reply personally. Portal accounts receive service email — alerts, digests and notifications — which you control in your account settings. Anything promotional identifies us, gives our contact details, and carries a working unsubscribe link, as Canada's Anti-Spam Legislation (CASL) requires. Unsubscribing takes effect immediately and never affects a reply to a question you asked us.
14. Cookies and Do Not Track
The website sets no cookies. The portal sets one strictly necessary session cookie, described in section 4. We use no advertising or cross-site tracking technology anywhere, so a "Do Not Track" or Global Privacy Control signal changes nothing about how we behave — we already do not do the thing it asks us to stop.
15. Children
The Services are for businesses and the people who work in them. They are not directed at children and we do not knowingly collect personal information from anyone under the age of majority in their province. If you believe a child has sent us information, write to admin@ranging.ca and we will delete it.
16. Changes
We will update this policy as Ranging changes, and the date at the top will tell you when. If a change materially affects how we handle information we already hold — including adding or changing an AI provider under section 7 — we will notify account holders before it takes effect and, where the law requires, ask for your consent.
17. Contact
Privacy questions and requests
Privacy Officer
Ranging
200–1017 Fort Street
Victoria, British Columbia V8V 3K5
Canada
admin@ranging.ca
portal.ranging.ca/public/dsar