Lab analysis is performed independently by Lex Scientific Inc. (C-NRPP certified, Guelph, ON). Results are reported against the Health Canada guideline of 200 Bq/m³. RadonTest.ca™ coordinates kit logistics and sample submission only. RadonTest.ca™ does not provide medical advice or health assessments.
Privacy policy
Effective Date: May 7, 2026
Last Updated: May 7, 2026
RadonTest.ca™ ("we," "us," or "our") operates the RadonTest.ca™ website and guided radon testing service (the "Services"). RadonTest.ca™ is powered by Shopify. This Privacy Policy describes how we collect, use, and disclose your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector (Law 25), and applicable Canadian privacy laws.
If there is a conflict between our Terms of Service and this Privacy Policy, this Privacy Policy controls with respect to personal information.
By placing an order or using our Services, you consent to the collection and use of your personal information for service delivery and customer support. Use of your test result for research, public health, or commercial licensing is governed by separate, granular consent captured at registration (see Section 6).
1. Information We Collect
- Contact information: name, email, phone (if provided, for support purposes only), shipping and billing address.
- Payment information: handled by Shopify Payments — we do not store credit card numbers.
- Order information: items purchased, order date, transaction details, browsing/cart activity.
- Radon test results: Bq/m³ value associated with your shipping address; test start and end dates.
- Service interaction data: emails sent and received, reminder history, return tracking, audit log of changes to your test record.
- Home characteristic data (collected at registration): home type, floors above grade, approximate home size, decade built, foundation type, floor where detector is placed, test purpose (initial test, retest, real estate, post-mitigation, new construction within 7-year warranty period, commercial), and whether a mitigation system is currently installed.
- Communications with us: information you include in support inquiries.
- Device and usage information: IP, browser, pages visited, via cookies (see Section 10).
Radon test results linked to your address are sensitive personal information. Express consent is required for any use of these results for research or commercial purposes (see Section 6).
2. How We Collect Your Information
- Directly from you when you place an order, register, or contact us.
- Automatically via cookies and similar technologies when you use the Services.
- From service providers acting on our behalf.
3. How We Use Your Information
- Order fulfilment and service delivery: process orders, ship kits, send placement instructions and reminders, return coordination, deliver results.
- Test context and placement guidance: tailor your results report based on home characteristics.
- De-identified research and data initiatives (granular express consent — see Section 6).
- Customer support: respond to inquiries and resolve issues.
- Marketing emails: only where you have opted in via your preferences page at portal.radontest.ca/preferences. You can change this at any time; transactional emails (order confirmation, reminders, results) are always sent regardless of marketing preference.
- Security and fraud prevention.
- Legal and compliance.
- Service improvement using aggregate, de-identified data.
4. How We Share Your Information
We use a small number of third-party service providers to operate RadonTest.ca — for storefront and checkout, hosting, database, email, shipping, and lab analysis. Each receives only the data it needs to perform its function on our behalf. We require all service providers to protect your information at a level comparable to PIPEDA. We do not sell, rent, or trade your personal information for marketing purposes.
| Recipient | Data Shared |
|---|---|
| Shopify Inc. | Name, email, address, payment, order details |
| Vercel Inc. | All operational personal information |
| Supabase (Canadian region) | All personal information |
| Resend | Email, name, message content |
| Canada Post | Name, shipping address |
| ShipStation | Name, shipping address |
| Lex Scientific Inc. (Guelph, ON — C-NRPP certified, ISO 17025) | Name, address, detector barcode, floor tested, test dates |
| Vercel Analytics | IP, page views |
We may also disclose personal information when you direct us to, in connection with a business transaction (with notice), or to comply with legal obligations.
5. Relationship with Shopify
Services hosted by Shopify, which collects and processes information to provide the Services. Information may be transmitted to Shopify and third parties in countries other than where you reside. See Shopify's Consumer Privacy Policy and Shopify Privacy Portal.
6. De-Identified and Aggregated Data — Granular Consent
Because address-linked radon results are sensitive personal information, your consent for any research, public health, or commercial use of this data is captured separately at registration via explicit, granular opt-in. You may decline any or all of these uses without affecting your test service.
During registration, you will be asked to choose, independently, whether to permit each of the following uses of your de-identified result:
- Tier 1 — Public radon awareness map and public health research: a publicly accessible map showing aggregated radon levels by Forward Sortation Area (the first three characters of your postal code), and contributions to public health agencies (Health Canada, provincial health authorities).
- Tier 2 — Academic research: your individual de-identified record may be shared with academic researchers under a Data Use Agreement that prohibits any attempt to re-identify individuals.
- Tier 3 — Commercial data licensing: your de-identified result may be included in datasets licensed commercially to real estate data providers and building science researchers. RadonTest.ca will never disclose your name, address, or contact information.
De-identification methodology. We remove all direct identifiers (name, full address, email, phone, payment data) before any data is used in research or licensed externally. We use the first three characters of your postal code (Forward Sortation Area) rather than the full postal code, and home characteristics are recorded in ranges rather than exact values. We suppress any FSA with fewer than 20 results from external publications and licensing exports to reduce re-identification risk in low-density areas. Despite these measures, we cannot guarantee absolute anonymization — we use "de-identified" to reflect this technical reality.
Withdrawal. Change preferences anytime at portal.radontest.ca/preferences or email privacy@radontest.ca. Withdrawal stops future use of your record; we make reasonable efforts to remove your record from datasets in active circulation, subject to active Data Use Agreements.
Your service is unaffected by your choice. Whether you opt in to none, one, two, or all three tiers, you receive the full RadonTest.ca testing service.
7. Data Storage and Security
Primary customer database stored on Canadian servers. Shopify holds commerce and payment data on its own infrastructure. Some operational services (email, shipping label generation) may process your information in the United States — see Section 8.
Protections include:
- Encryption in transit (HTTPS/TLS) and at rest.
- Row-level security on the database; role-based admin access.
- Multi-factor authentication on all admin accounts.
- API keys in secure environment variables, never in code.
- Audit logging of all admin access to customer data.
- Rate limiting and bot defenses on portal endpoints.
- Content Security Policy and other HTTP security headers.
Address-linked radon results are classified as sensitive PII; access restricted to authorized personnel on a need-to-know basis with full access logging.
No method of electronic storage is 100% secure. We take reasonable measures and recommend you avoid unsecure channels for confidential information.
8. International Transfers and Privacy Impact Assessment
Your primary record is stored on Canadian servers. Some service providers operate in the United States, where information may be subject to foreign laws.
Pursuant to Quebec Law 25, RadonTest.ca conducts a Privacy Impact Assessment (PIA) for transfers of personal information outside Quebec. The PIA is reviewed annually and is available to Quebec residents on request at privacy@radontest.ca.
We contractually require service providers to protect your information at a level comparable to PIPEDA.
9. Data Retention
- Order and contact information: 7 years after most recent order activity.
- Radon test results: 7 years from analysis date, then de-identified for aggregate research or deleted on request.
- Home characteristic data: same schedule as test results.
- Email records: 7 years for service delivery evidence.
- Consent records: retained indefinitely as audit trail of your consent decisions (PIPEDA accountability).
- Payment information: per Shopify's retention policies.
De-identified aggregate data, where consented under Section 6, may be retained indefinitely after the 7-year period. You may request deletion at any time, subject to technical limitations on data already in circulating aggregate datasets.
10. Cookies and Tracking Technologies
At this time, RadonTest.ca uses only strictly necessary cookies required for the site to function — shopping cart, checkout, login session, and basic site security. These cannot be disabled because the site cannot operate without them.
We do not currently load advertising, marketing, or third-party analytics cookies. The first-party performance metrics we collect (Vercel Analytics — see Section 4) do not use third-party tracking cookies and aggregate visit data without identifying individual users.
A cookie consent banner and granular cookie-preference controls will be introduced in a future update; this section will be updated when those are live, and Quebec residents will be re-prompted for consent under Quebec Law 25 Article 8.1 at that time.
11. Your Rights and Choices
Under PIPEDA (with additional Quebec Law 25 rights for QC residents):
- Access — request a copy of personal information we hold about you.
- Correction — request correction of inaccurate or incomplete information.
- Deletion — request deletion (subject to legal retention obligations).
- Withdraw consent — anytime, subject to legal or contractual restrictions.
- Data portability — receive a structured copy and request transfer.
- De-indexation (Quebec) — in certain circumstances.
- Communication preferences — manage marketing and reminder preferences at portal.radontest.ca/preferences, or unsubscribe via the link in any marketing email.
Self-service: manage all consents and request data export or deletion at portal.radontest.ca/preferences. Or contact privacy@radontest.ca — we respond within 30 days, no fee, no discrimination.
12. Breach Notification
If a data breach creates a real risk of significant harm, we will:
- Notify you within 72 hours of becoming aware.
- Report to the Office of the Privacy Commissioner of Canada and (where applicable) Commission d'accès à l'information du Québec.
- Describe the breach, information involved, and steps we're taking.
- Provide guidance to protect yourself.
Records of all security safeguard breaches retained for minimum 24 months and available to the Privacy Commissioner upon request.
13. Third Party Websites and Links
Third-party links are not endorsed; review their policies.
14. Children's Privacy
Services not directed to individuals under 18. We do not knowingly collect children's personal information. Parents/guardians may contact us to request deletion.
15. Changes to This Policy
Updates posted with revised "Last Updated" date. Material changes communicated by email where possible. Where a change materially affects how your data is used, renewed consent will be requested at your next interaction.
16. Complaints
Contact our Privacy Officer at privacy@radontest.ca. Acknowledged within 7 days. Unresolved complaints may go to the Office of the Privacy Commissioner of Canada (www.priv.gc.ca) or, for Quebec residents, the Commission d'accès à l'information du Québec (www.cai.gouv.qc.ca).
17. Privacy Officer and Contact
Designated Privacy Officer: Ger McNamee, founder of RadonTest.ca, reachable at privacy@radontest.ca.
RadonTest.ca maintains an internal privacy management program reviewed annually.
RadonTest.ca™ — Operated by 1514890 Ontario Inc.
11E-900 Greenbank Road, #510, Nepean, Ontario K2J 4P6
Phone: (613) 690-6328 • Email: support@radontest.ca