Legal · Privacy

Privacy policy.

Last updated · May 12, 2026

1 · Who we are

FirstLaw Energy Inc. (“FirstLaw”, “we”, “us”) is a Montreal-based heat-pump company. This policy explains what personal information we collect on first-law.ca and connected hosts (e.g. first-law-heat-pumps.web.app) and how we handle it.

Privacy officer (Quebec Law 25 designation): phil@first-law.ca.

2 · What we collect

  • Investor dataroom sign-in — your email address (you submit it to receive a one-time sign-in link).
  • NDA acceptance record — full legal name, email, timestamp, browser user-agent string, and the NDA version you accepted. Stored when you click “I agree” on the dataroom NDA page.
  • Server access logs — IP address, request path, user-agent, timestamp. Collected by our host (Google Firebase Hosting) for security and abuse prevention.
  • Calculator inputs — when you use the savings calculator on the homepage, your inputs (square footage, climate, electricity rate, occupants) run only in your browser. We do not transmit or store them.

We do not use Google Analytics, Facebook Pixel, advertising trackers, remarketing cookies, or any third-party analytics service on the marketing site.

3 · Why we collect it

  • Email + NDA record — to gate access to confidential investor materials and to record your agreement to keep them confidential.
  • Server logs — to detect abuse, debug outages, and satisfy our hosting provider’s lawful obligations.
  • Calculator inputs — to compute your estimate locally in real time.

4 · Storage & cookies

The following storage mechanisms are used:

  • localStorage · key dataroomSignInEmail — temporarily holds your email during the magic-link sign-in flow. Removed immediately after sign-in completes. Used only on the dataroom sign-in path.
  • localStorage · key firstlaw-cookie-consent — remembers whether you have dismissed this site’s privacy notice. Stores only the values accept or decline.
  • IndexedDB · Firebase Authentication — stores your dataroom session token after sign-in. Cleared when you sign out.
  • Third-party cookies set by font hosts. Our pages load typefaces from cdn.fontshare.com (Cabinet Grotesk) and fonts.googleapis.com / fonts.gstatic.com (JetBrains Mono on the dataroom NDA page). Those hosts set their own cookies (e.g. _fontshare_key) to cache font requests; we do not read or control them.

5 · Third parties

  • Google Firebase (hosting, authentication, Firestore database). Personal information is stored on Firebase servers operated by Google LLC. Firebase’s privacy practices: firebase.google.com/support/privacy.
  • Telegram — when an investor signs the NDA, an internal notification (containing the signer’s name and email) is sent to our private Telegram channel so we know to provision dataroom access. Telegram’s policy: telegram.org/privacy.
  • Fontshare / Google Fonts — typeface delivery. They may log the IP and user-agent of font requests.

6 · How long we keep your data

  • NDA acceptance records — retained for the duration of the underlying confidentiality obligation (typically the term of the NDA plus any tail period), then deleted on request.
  • Sign-in emails — held only as long as you have an active dataroom session.
  • Server access logs — typical retention is 30–90 days, per Firebase defaults.
  • Cookie-consent flag — until you clear your browser storage.

7 · Your rights

Depending on where you live, you may have the right to access, correct, port, or delete the personal information we hold about you, and to withdraw consent for future processing. Under Quebec Law 25 you also have the right to be informed of automated decision-making (we use none).

To exercise any of these rights, email phil@first-law.ca. We respond within 30 days.

8 · Changes to this policy

We will update this page when our data practices change. The “Last updated” date at the top reflects the latest revision.

9 · Contact

FirstLaw Energy Inc., Montreal, Quebec, Canada
phil@first-law.ca