Privacy policy

What we collect, why, and how to make us delete it.

Shelterbelt is a reputation analysis service operated by Colin Coakwell, a sole proprietor in Saskatoon, Saskatchewan. This policy covers both people who contact us and members of the public whose public reviews we read — whether about a client or about a business we are researching.

Last updated: 5 September 2026. If we change this policy we will change this date, and we will not apply a materially different use to information already collected without asking first.

1. Who we are, and how to reach us

"Shelterbelt" is a working name used by Colin Coakwell, sole proprietor, Saskatoon, Saskatchewan, Canada; it is not a registered business name. There is no separate legal entity: the business and the person are the same, and Colin is the person accountable for personal information under this policy. He is also the person who will answer you.

Privacy contact: privacy@shelterbeltintel.com

2. The two kinds of information we hold

Almost every privacy policy covers only the first of these. Ours has to cover both, because the second is the substance of the service.

(a) Information you give us

If you use the form on this site, we collect the email address and business name you type, and which button you used. Our server additionally records your IP address and browser type.

  • Why the IP and browser type: only to rate-limit the form and block spam and abuse. They are not used to identify you, profile you, or track you across sites.
  • How long: we clear the IP and browser type after 90 days. We keep the enquiry itself — including the business name — until you ask us to delete it, or until 24 months after our last contact with you, whichever comes first — then it is deleted automatically.
  • What we do with your email and business name: reply to you, and prepare what you asked us for. That is all. We do not sell or rent them, and we do not add you to a marketing list.

(b) Public review information we read about businesses

Our service reads publicly visible reviews and business listings — the ones any member of the public can see without signing in. That material includes things members of the public wrote, and their names as they chose to display them.

We read two kinds of business, and we would rather say so than let you assume the first. One is a client, and the trade it is measured against. The other is a business we are researching as a possible client — reading its public reviews to work out whether we have anything useful to tell it, and to understand its trade. That happens before, and often instead of, any engagement: most businesses we read never become clients and are never contacted. The same minimizing below applies to both, from the moment of capture, and the erasure right further down is the same for both.

We minimize it at the moment of capture, before it is stored:

  • A reviewer's displayed name is reduced to a single initial. "Jane Doe" is stored as "J......". The rest of the name is never written down.
  • Personal information inside the review text — the reviewer's own name, other individuals named in the body, and anything shaped like a phone number, an email address, or a link — is stripped out of the text itself at the same moment, not merely hidden from reports.
  • We keep the review's rating, its date, and its (redacted) text, because that is what the analysis reads.

The limits of that, honestly. The text pass is an automated filter, not a promise of perfection. It deliberately leaves alone a first name that is also an ordinary English word — a reviewer named Bill keeps "the bill was higher than quoted", because a redaction that swallowed the complaint would help nobody — and the local model that removes a third party you name in your review ("the tech, Dave, was great") is a filter, not a guarantee, so an unusual name can still slip through. We are telling you where the edges are rather than claiming there aren't any. If something personal survived in a review of yours, write to us (below) and we will take it out — on the same terms as any other removal request further down, including telling you where a copy we cannot reach remains.

What we do not do: we do not build, buy, enrich, or sell a profile of any individual reviewer. We do not try to work out who a reviewer is, or link them across platforms or to anything else we know. We report patterns to our clients. The name field from your review never reaches a client — that part is absolute. But a client's report quotes review text, so if a name survived the text pass described above (an ordinary-word first name, or someone else you named), it can appear there. We would rather tell you that than round it up to "no name ever reaches a client".

How long we keep it: we do not run a deletion clock, and we are not going to tell you we do. What protects you here is what happens at the moment we collect: your name is cut to a single initial before anything is stored, and an automated pass takes out phone numbers, email addresses, links, and other people’s names from the text. That runs on every review, every time, and there is no path into our store that skips it.

What we hold after that, in that reduced form, we keep for as long as it is doing the job it was collected for — producing a report, and letting a business compare against last year if it asks for a second one. We used to say twelve months and then stripping. That was a promise about a job we had built but never run, so it has gone rather than been restated in softer words.

If you want your material gone, that right does not depend on a clock — it is below, under “If you wrote a review we hold”, and it is the same whether we read your review yesterday or three years ago.

3. How we collect it — and what we will not do to get it

Collection is automated, from public pages, and deliberately limited. We commit that we:

  • hold no account credentials for any review platform and never sign in to one;
  • create no fake, pretext, or impersonating accounts;
  • access nothing behind a login, a paywall, or a private group;
  • do not run CAPTCHA-solving software ourselves, and have not contracted anyone to solve CAPTCHAs for us — though see the limit below;
  • read each site's robots.txt and do not fetch a page its published rules disallow — and where those rules cannot be read at all, we treat the page as disallowed rather than assume permission.

Two limits on that, because a list like the one above invites you to assume more than it says. We don't fetch most pages ourselves: we buy Google review data from a commercial provider, and read other public pages through a commercial web-access provider whose job is retrieving pages that would otherwise be blocked. We can tell you what we do — no logins, no fake accounts, no CAPTCHA-solving software of our own, no ignoring published rules. What we can't tell you is what happens inside that provider's infrastructure: it may handle a challenge there, including when our software retries a request that came back blocked. We don't control or inspect that, so we don't claim otherwise. And the robots.txt rules we honour are the ones written for everybody (User-agent: *); because that provider manages its own identity, we can't honour a rule aimed at one named crawler, and we won't claim we do.

4. Cookies, analytics and tracking — there are none

This website sets no cookies. It uses no local storage or session storage. It runs no analytics of any kind — no Google Analytics, no pixels, no tag manager, no heatmaps, no session recording. It loads nothing from a third party: no external fonts, no CDN scripts, no embedded video or maps. Every typeface is one already installed on your device.

The light/dark toggle changes this page only, in your browser, for as long as the page is open; it stores nothing and remembers nothing between visits.

This is why you were not shown a cookie banner. A consent banner would be theatre: there is no tracking here to consent to. We send no analytics, advertising or tracking data from your browser — only the ordinary requests needed to load the page, and anything you deliberately submit through the form.

Our web host keeps standard server logs (including IP addresses) for a short period as an ordinary part of running any website securely. We do not use those logs to identify or track visitors.

5. Who else handles the information — our suppliers, named

We are one person, not a data centre. Doing this work means passing information through established third-party services. Naming them is the point of this section.

SupplierWhat it handles for usWhere
OutscraperCollects public Google reviewsUnited States
Bright DataFetches public pages on non-Google review sitesUnited States / global
SupabaseStores the minimized review dataUnited States
AnthropicThe AI model that reads review text and drafts repliesUnited States
Google (Gmail)Delivers our reports to usUnited States
VercelHosts this website and our internal dashboardUnited States
NeonStores enquiries from this siteUnited States
ResendEmails us your enquiryUnited States

Each handles information only on our instructions and only to perform the function above. None of them is permitted to use it for their own purposes, and we sell, rent, and license personal information to no one.

6. Processing outside Canada — stated plainly

The suppliers above process data in the United States. That means information described in this policy is stored and processed outside Canada and is subject to the laws of the country where it is held, including lawful access by that country's courts and authorities. This is true of essentially every cloud service a small Canadian business can use, but PIPEDA requires that we tell you rather than let you assume otherwise, and that is what this section is for.

Where the minimizing happens — precisely, because "we minimize" could otherwise mislead you. It happens on our own machine, the moment we receive the data and before we store it. So what we store, and what we send to the AI provider, never includes the name field from your review — that reduction to a single initial is absolute.

The review text that goes with it is redacted too, but with the limits described above: an ordinary-word first name is left alone on purpose, and the pass that removes other people's names is a local model — a filter, not a guarantee — so an unusual name can slip through. So a name can still occasionally reach the AI provider inside the words of a review. We'd rather tell you that than let "we minimize names" quietly become "no name ever".

It does not mean no personal information crosses the border at all. The two suppliers who collect for us — Outscraper and Bright Data — necessarily see the public page as it is published, name and all, because fetching that page is the job we pay them for, and nothing can be minimized before it has been collected. What they handle is exactly what any member of the public sees on that page, and we ask them for nothing beyond it. We would rather tell you that than write "no name ever leaves our machine", which would read better and be false. None of it is ever sold.

7. Your rights, and how to actually use them

You can ask what we hold about you, ask for a copy, ask us to correct it, or ask us to delete our copy. We do not charge for any of this, and we will answer within 30 days.

If you contacted us

Write to privacy@shelterbeltintel.com, or just reply to any message from us, and ask. We will delete your email address and your enquiry and confirm when it is done. There are no conditions and we do not keep a copy "for our records".

If you are a member of the public whose review we hold

The same rights apply to you, even though you never contacted us and never agreed to anything. Write to privacy@shelterbeltintel.com and tell us the business you reviewed, the platform, and roughly what your review said — a sentence or two of it is enough. We ask for the wording because we already reduced your name to a single initial, so the text of the review is how we locate your specific record among the others. Once we have found the specific review and are satisfied it is yours to ask about — from the detail you can give us — we delete it from the record our reports are built from, and we write to you within 30 days telling you exactly what we removed and where any copy remains. That second half matters and we would rather say it than let “deleted” imply more than it does: if a report quoting your review has already gone to a business, that copy is in their hands and we cannot reach it, and any copy inside a document we have already produced is taken out by hand rather than by the same automatic step. So a confirmation from us covers the database, not every copy that has already left it.

Being straight with you about three things. First, we will ask only for enough detail to find the right record — we will never ask you to prove your identity with government ID, because we hold no identity to check it against: we deliberately reduced your name to one initial before storing anything. Second, if we cannot match what you send to one specific review, or cannot satisfy ourselves the review is yours, we will ask you for a little more rather than guess — and if we still cannot, we will explain why we are unable to act. Deleting a review we are not sure is yours could erase someone else's words, which is a harm we will not cause on an unverifiable request. Third, deleting our copy does not remove your review from Google, Facebook, or wherever you posted it — we do not control those and cannot alter, hide, or remove anything on them. Only the platform you posted on can do that.

8. What we never do

  • We never write, buy, sell, exchange, incentivize, solicit, or AI-generate reviews — for a client or anyone else.
  • We never suppress, filter, gate, or route away negative reviews.
  • We never post, publish, or send anything on a client's behalf. We draft; the client posts.
  • We never sell, rent, or license personal information.
  • We never use the information we collect to train an AI model.

9. Security

Access to the data is limited to Colin Coakwell. Credentials are not shared. The databases are not publicly reachable, and the internal dashboard is behind authentication. We minimize at capture precisely because the most reliable way to protect personal information is not to hold it: a name we never wrote down cannot be breached, and a reviewer's phone number stripped from the text before storage is not ours to lose.

10. Complaints

If you are not satisfied with how we have handled your information or your request, please tell us first at privacy@shelterbeltintel.com — we would rather fix it. You also have the right to complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca, 1-800-282-1376), and you do not need our permission to do so.

This policy is written in plain English on purpose. It describes what our systems actually do, not an aspiration. It is not legal advice.