We’re privacy-first and cookieless by default.
We collect only the information required to underwrite Canadian mortgages, fulfill FSRA and FINTRAC obligations, and provide the services you request. Everything lives on Supabase (Montreal) with perfect row-level security, Cloudflare TLS, and immutable storage for AML evidence.
Identity, contact, property, employment, and financial records uploaded by you or your Broker team, plus chat transcripts, AML/KYC results, CRA consent state, and CASL marketing opt-ins. Sensitive files are converted to PDF and stored in Supabase Storage buckets that enforce “PDF only” uploads and six-year retention.
We process information to determine mortgage suitability, submit applications to lenders, satisfy FSRA record keeping rules (six years after the term expires), and FINTRAC record keeping rules (AML evidence for at least five years). We do not sell data or use it for unrelated profiling. Cross-border transfers are limited to transient routing through Cloudflare; the canonical database, backups, and object storage remain in Canada.
Every signature event is logged in public.borrower_consents with the full text you signed, timestamp, IP address, user agent, and source (Express wizard, Broker-assisted tasks, CRA assistant, etc.). Marketing forms (contact/renewal reminders) land in marketing_contact_requests orrenewal_reminders with the CASL statements you agreed to. Withdraw consent anytime by toggling settings in the dashboard or emailing [email protected].
GET /api/privacy/export while signed in.docs/compliance/05-incident-response-plan.md./dashboard/**, rate limits public endpoints, and rewrites Supabase callbacks to server routes so service-role keys never touch the browser.next.config.mjs.src/lib/logging.ts) so we can correlate access requests during audits.We maintain a living inventory in docs/compliance/vendors.csv. Core vendors today:
Each vendor goes through annual risk review (see docs/compliance/07-vendor-risk-management.md) that records data category, residency, and certification status.
Contact our Privacy Officer at [email protected] or mail 401-815 Hornby Street, Vancouver, BC V6Z 2E6. Quebec residents may also reach the CAI directly. When emailing us, include the deal ID (if applicable) and whether your request is an access, correction, consent withdrawal, or complaint so we can respond within the statutory timelines (30 days under PIPEDA / 30 days under Law 25).
Borrowers with an active account can sign in to the portal to exercise access rights any time. If you have not yet created an account, email us and we will securely verify your identity before fulfilling the request.