KEYTRAIL

Privacy Policy

Effective 23 September 2026 · Last updated 6 October 2026

The short version

Your deals are stored in your Keytrail dashboard, encrypted. Your email, files and calendar stay in your own Google account.

The dashboard at dashboard.keytrail.ca keeps your transaction records, so the dashboard and the Chrome extension's side panel in Gmail see the same deals. Gmail, Drive and Calendar are reached under your own Google permissions, in one of two ways you choose: with Google sign-in, where you give Keytrail access once on Google's own consent screen, or through your own copy of a Google Apps Script project. Either way, the dashboard works out what to do (which label, which folder, which date) and makes each request to Google, or asks your project to; it reads what it needs for that, such as label names, file names and message subjects, and never keeps a copy of your email or files.

There is no analytics, no tracking, no advertising, and nothing is sold. You can download everything the dashboard holds, or delete your account and all of it, at any time from your account page.

Who this applies to

This policy covers the Keytrail dashboard (dashboard.keytrail.ca), the Keytrail for Gmail Chrome extension, and the Google Apps Script project distributed with them for agents who prefer it to Google sign-in. It is written for the real estate agent who uses them to manage their own transactions, and it also describes the client pages an agent can choose to share.

The product is provided by Tyler Wiese, Ontario, Canada.

What the dashboard stores

WhatWhyKept until
Your email addressYour sign-in and your accountYou delete your account
Your transactions: property address, client names, type and status, MLS number, lawyer, cooperating agent, brokerage deal ID, sale price and commission, the Gmail label, Drive folder and calendar each deal uses, sync notes, its dates with any notes on them, and its paperwork checklist: which items you ticked and when, and which items (by name, such as "Deposit receipt") the last Drive check found missing. After a closing, which follow-ups (a check-in, a review ask, each anniversary) you marked done or skipped, and when. File names and contents stay in your Drive; the dashboard reads only the names, through your Apps Script, to tick the list, and does not keep themThe product itself: the dashboard and the extension both read them from hereYou delete your account. A deal you remove is hidden from every view but kept, encrypted, until then.
If you connect with Google sign-in: your Google account's email address, the permissions you granted, and the refresh token Google gives Keytrail (encrypted). The short-lived access tokens made from it are held only in memory, for under an hourSo Keytrail can make the Gmail, Drive and Calendar requests described below, including the hourly runYou disconnect on your account page (which also withdraws the access at Google), remove Keytrail at Google Account permissions, or delete your account
If you use your own Apps Script project: its address and access keySo the dashboard can ask your project to act, for example to forget the link when you delete your accountYou connect a different project or delete your account
Your workspace settings: the Google Calendar and Drive folder your deals use, your time zone, how long email sorting runs after a closing, and your reminder choices (encrypted)Your Apps Script reads them each hour, so it files and schedules things where you choseYou change them or delete your account
Which milestone email drafts have already been made for each dealSo each draft is made onceYou delete the deal's record with your account
The Chrome extension's connection: a one-way hash of each browser's token, when it was made and last used, and for ten minutes a hash of the one-time code you get to connect itSo the side panel can reach your dealsYou disconnect it on your account page, connect more than five browsers (the oldest lapses), or delete your account
Your default brokerage split (your share and a flat fee)Starting new deals with your usual splitYou change it or delete your account
The wording you give the milestone email drafts, and which are switched on (the wording is encrypted)Your Apps Script prepares the drafts in your Gmail; nothing is sent from hereYou reset the wording, or delete your account
Your contacts: details you add to a person (name, role, email, phone, company, a note), all encrypted except the roleThe contacts page, and suggesting names as you typeYou delete the contact, or your account
Your expenses: date, category and amount, the deal each was for, and any note (the note is encrypted; the amount is kept readable so totals can be worked out without decrypting)The Income card's profit and the accountant's exportYou delete the expense, or your account
Your deadline email and weekly summary settings (how often, what time, your time zone) and the day each was last sentSending the deadline email, if you turn it onYou delete your account
Listing data for each of your listings: the property details you keep for the forms and MLS (such as legal description, PIN, zoning, lot size, taxes, building details, inclusions and remarks), its rooms and their sizes, and where each value came from (encrypted). Fill from Drive files has your Apps Script read the text of the documents in the listing's Drive folder (such as a GeoWarehouse or MPAC report, the tax bill, a status certificate, a filled-in MLS data form or the listing agreement); the details found are shown to you, and only the ones you tick are kept. The files' text is not keptSo the side panel can type them into the listing forms and MLS for youYou clear a value, or delete your account
What you teach the side panel about a website: its address, and for each listing field the place on the page you clicked, or that Fill matched and you confirmed (a page selector), and the words beside it, and the boxes you said were not a field. Never a value from the page. If your brokerage made you a recipe editor and you press Make this the default for everyone, these places (not any listing values) become the starting point for every Keytrail agent on that websiteSo the panel can read that website or fill that form again next timeYou tell the panel to forget a field, or delete your account
Client-page links you createSo a link you send a client opens their pageYou revoke the link or delete your account
Client forms your clients send from your buyer and seller links: every answer they give (names, contact details, their current or property address, occupation, financing and property details), the signature on a seller's form, and the names of the files they upload. All of it is encrypted. The files themselves are saved straight into your Google Drive, not hereShowing you the form, putting it on a deal, and making its PDFYou delete the form, or your account. A form you dismiss is hidden but kept until then
Buyer files: for a buyer you keep without a property yet, the Gmail label and Drive folder made for them, each offer's address and whether it is open, lost or became a deal, and any notes carried over from a deal you moved into it (encrypted with the form)Sorting the buyer's email and their offers' email, and turning an offer into a dealYou delete the form, or your account
What the dashboard remembers about your Google items: the identifiers of folders, labels and filters it made, and where a long job (such as email sorting) left offSo each hourly run carries on instead of starting over, and nothing is made twiceYou delete your account
Your dashboard layout: the order of its sections and which you hidShowing the dashboard the way you arranged itYou change it or delete your account
Sign-in records: sessions, one-time sign-in links, and a count of recent sign-in requests per network addressKeeping you signed in, and stopping sign-in abuseSessions last 30 days; sign-in links expire after 15 minutes; request counts are short-lived

How it is protected

Being plain about access. Encryption protects your records if the database itself were exposed. It does not stop the service's operator: the encryption keys are held by the service so it can show you your deals. I do not look at your records, except with your explicit consent to fix a problem you have reported, or where the law requires it.

Service providers

Neither receives your transactions for any purpose of its own. Nothing is shared with anyone else.

Cookies

The dashboard sets one cookie, ta_session, which keeps you signed in. It is marked HttpOnly and Secure, is sent only to this site, and ends when you sign out or after 30 days. There are no other cookies, and no third-party scripts.

Importing deals

A spreadsheet you import is read in your browser; only the rows you choose to import are sent to the dashboard. If you import from Notion, the Notion secret you paste is sent with each request to read your database and is then discarded; it is never stored, and nothing in Notion is changed.

Client pages

If you create a client link for a deal, anyone holding that link can see its property address, its dates, which paperwork items are due and whether each is in (by name only, never a file), and your name and contact details. It never shows the client's name, MLS number, lawyer, prices, documents or notes. Revoking the link stops it working immediately.

While a deal is open, the page also lets your client send you documents (a PDF, photo or Word file, up to 5 MB, at most 15 a day). Each file passes through the dashboard without being stored there and is saved by your own Apps Script project into the deal's Drive folder, under Client Uploads. The dashboard keeps only a note on the deal saying a document arrived, and a count of documents not yet filed.

On a listing, you can record feedback from showings. The feedback, the interest level and the showing agent's name are encrypted with your other deal details. Your seller's page shows the feedback and interest of the showings you mark as shared, never who showed the home.

Once an hour, Keytrail also reads the showing emails BrokerBay sends you (confirmations and cancellations, found by their sender and subject) through your own Apps Script, and puts each booked showing on the listing it names: its day, time and type, and the showing agent's name and brokerage. Those are encrypted like the rest. Your seller's page shows the day and time of upcoming showings only, never who is coming. No other email is read for this.

Client forms

You can send new clients a link to a buyer or seller form. Anyone holding the link can fill it in; it shows your name, brokerage and contact details, and nothing about any deal. What they send is stored as described above and appears on your dashboard. Files they upload (such as ID for FINTRAC) pass through the dashboard without being stored there and are saved by your own Apps Script project into a New client forms folder in your Drive, and later into the client's own folder. When they type an address, what they type is sent to Google Places for suggestions. Each link accepts a limited number of forms and address lookups a day, and Make new links on your account page stops the old ones working.

The Chrome extension

The extension keeps the following in Chrome's storage on your computer. None of it is sent anywhere except as described below.

WhatWhyKept until
Its own token for your dashboard, and your account's email address, from the one-time code you paste into itSo the panel can reach your dealsYou connect again, disconnect it on your account page, or uninstall
Display density, collapsed sections, status and document filtersSo the panel looks the way you left itYou clear it or uninstall
The subject line of the email you last opened outside your transaction labelsSo the panel can offer a new transaction for an address it namesReplaced by the next email you open; ignored after 30 minutes
The Gmail label you last selected, and whether Gmail is in dark modeSo the panel opens on the right transaction and matches your themeYou clear it or uninstall
A cached copy of your transaction listSo the panel appears instantly instead of waiting on a requestWhen you close the browser, and immediately after any change you save

On mail.google.com the extension reads exactly three things: the label in the page address, so it knows which transaction you are looking at; when an email is open outside your transaction labels, its subject line, from the page title Gmail sets, so it can offer to start a transaction for an address it names; and the page background colour, so it can match Gmail's theme. The subject is kept only on your computer, for 30 minutes. It does not read your messages. It talks to one place only: your dashboard at dashboard.keytrail.ca, for your deals and everything you do to them. The dashboard asks your own Apps Script project for anything in Gmail, Drive or Calendar. It also asks dashboard.keytrail.ca once a day which extension version is current.

Listing data. On a listing's Listing tab, the side panel can read or fill the web page you have open (a property report, a city's tax or zoning page, a listing form, or your MLS). The first time you press one of those buttons, Chrome asks whether to let Keytrail read and change websites; you can say no, and you can take it back at chrome://extensions. Even with that permission, the extension looks at a page only when you press Read this page, Fill this page, Teach, or Show what it knows, and only in the tab you have open. Reading takes just the values at the places you taught or, on a page you have not taught, the values beside words that name your listing fields (such as “PIN” or “Zoning”); it shows them to you and sends to your dashboard only the ones you tick. Filling types your saved values into the boxes you taught. On a form you have not taught, it first reads the words beside each box (never what is typed in them) to find the ones that match your listing fields, and shows you those matches to confirm before typing anything. It never submits or saves anything on the page. Nothing else on the page, and no browsing history, is read or kept.

Connecting with Google sign-in

When you press Connect Google, Google shows you exactly what Keytrail is asking for, and you approve it on Google's own page. Keytrail asks for:

PermissionUsed for
Your email addressShowing which Google account is connected
Read, compose and modify Gmail messages and labels (gmail.modify)Applying transaction labels to mail, listing a deal's attachments (their names, and each message's subject, sender and date), saving attachments you choose to file, reading the showing emails BrokerBay sends you, and leaving email drafts in your Drafts. Keytrail never sends or deletes your email
Manage Gmail filters (gmail.settings.basic)Creating the filters that sort incoming mail by property address, or by a searching buyer's own email address
Google Drive (drive)Creating transaction and buyer folders, saving attachments you choose to file and files clients send, listing a deal folder's file names for its paperwork checklist, attaching a deal's documents to a draft, and reading the text of a document you ask it to read
Google Calendar events, your list of calendars, and calendars Keytrail makes (calendar.events, calendar.calendarlist.readonly, calendar.app.created)Creating and updating events for transaction dates and their reminders, and choosing or making the calendar they go in

Keytrail's servers make these requests for you when you act, and once an hour to keep labels, folders, dates and drafts in order. They take from each answer only what the request needs, as described in the table at the top of this page, and keep nothing else. Wherever this policy says your Apps Script project does something, with Google sign-in Keytrail does it in the same way, through the same Google services. To read a PDF, Keytrail has Google Drive convert a temporary copy to text, reads it, and deletes the copy.

You can withdraw the access at any time: Disconnect on your account page withdraws it at Google too, or remove Keytrail at Google Account permissions.

If you use your own Apps Script project

Your copy of the project runs under your Google account, with permissions you grant it when you first run it:

PermissionUsed for
Read, compose and modify Gmail messages and labelsApplying transaction labels to mail, listing a deal's attachments (their names, and each message's subject, sender and date), saving attachments you choose to file, and leaving email drafts in your Drafts (never sending them), including the lawyer package with documents from the deal's Drive folder attached
Manage Gmail settings (filters and labels)Creating the filters that sort incoming mail by property address, or by a searching buyer's own email address
Google DriveCreating transaction and buyer folders, saving attachments you choose to file and files clients send, and listing a deal folder's file names for its paperwork checklist
Google Calendar eventsCreating and updating events for transaction dates and their reminders
See your list of calendars, and make a Keytrail calendar if you askChoosing the calendar your deal dates go in
Connect to external servicesReaching your dashboard
Manage its own triggersThe hourly maintenance that keeps labels and dates in order

Your project passes the dashboard only what each request answers: label and filter names, message identifiers and, for a deal's documents list, each message's subject, sender and date; file and folder names; and the events Keytrail made in your calendar. It never passes the body of your email, and never a file's contents except as described next. It also talks to:

Google API Services User Data Policy

Keytrail's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: Google user data is used only to provide the features described here; it is not transferred to anyone except as needed to provide those features; it is never sold; it is not used for advertising; and no human reads it except with your explicit consent, to resolve a problem you have reported, or where required by law.

Your choices

Do not share your project's access key, or an extension code while it is still valid: whoever holds them can act for you. Treat them like passwords.

Children

This is a professional tool for licensed real estate agents. It is not directed at anyone under 18 and does not knowingly collect information from children.

Changes to this policy

If the product starts doing something materially different with your data, this page will be updated and the dates at the top will change. Treat the effective date as authoritative.

Contact

Questions about this policy, or about how the product handles something not covered here:

info@keytrail.ca

If you are in Canada and are not satisfied with a response, you may contact the Office of the Privacy Commissioner of Canada.