SmartVest Technologies Inc.
Privacy Policy
Version 2.4 · Effective August 31, 2026
This Policy explains what personal information SmartVest collects, why it is used, who receives it, the two-step referral consent model, safeguards and retention, and how to exercise privacy rights.
1. Accountability
SMARTVEST TECHNOLOGIES INC. is accountable for personal information under its control. The accountable contact is the Privacy Officer, SmartVest Technologies Inc., privacy@smartvest.ca. You may contact that address without creating an account for privacy questions, access, correction, withdrawal, deletion/account requests, complaints, or suspected unauthorized disclosure. Security concerns may be sent to security@smartvest.ca.
2. Information we collect
- Account and identity details such as name, email, role, authentication and preference information.
- Referral and Opportunity Case details provided with permission: name, contact method, broad category, commercial intent, origin and assignment path, referrer and professional identities, consent state, workflow status, and limited notes.
- Broad opportunity-questionnaire information such as objective or need type, broad financial or coverage band where relevant, general timeline, province, language, communication preference, and availability. Do not submit exact account numbers, health records, passwords, or unnecessary sensitive details.
- Professional or business profile, licence/verification, service, availability, capacity, and program information.
- Meeting, scheduling, confirmation, provider synchronization, support, notification, and outcome information.
- When enabled, Stripe customer, subscription, payment, funding, transfer, refund, dispute, invoice, tax-status, connected-account, and reconciliation metadata. SmartVest does not store raw bank credentials.
- Trust, integrity, audit, dispute, anti-circumvention, security, authentication, device, IP-derived, log, and operational information.
- Information supplied by referrers, clients, professionals, businesses, administrators, and integrated service providers.
3. Financial Architecture V2 information
If separately activated, SmartVest may collect business-acquisition identity and attribution information, campaign and program versions, participant acceptances, subscription qualification metadata, sold-product rule snapshots, Product Chargeback dates and limited evidence references, challenge and decision history, recovery-ledger entries, offsets, repayments, and financial-standing status. Ordinary public or participant views do not expose raw evidence or another person’s exact private recovery balance.
These records support contract administration, audit, dispute handling, fraud prevention, eligibility, accounting, and legal compliance. Financial acceptance records are immutable and version-specific. They do not activate a feature or create an entitlement by themselves.
4. Purposes
- Create, authenticate, secure, support, and administer accounts.
- Send and manage authorized referral introductions, Opportunity Cases, client choices, duplicate review, capacity reservations, and source-aware assignment.
- Use broad questionnaire answers to validate a requested opportunity, support client-selected assignment, and—only under an authorized policy—identify eligible Marketplace businesses.
- Share only information reasonably necessary with the selected or assigned professional or business after required consent and acknowledgement.
- Coordinate meetings, Calendar/Meet integrations, confirmations, and service messages.
- Operate marketplace, support, trust, integrity, audit, dispute, fraud-prevention, legal, and security functions.
- Process SmartVest Professional trials, subscriptions, invoices, receipts, payment status, cancellation, and related accounting records; if separately activated later, process individually funded referral obligations.
- Comply with law, enforce agreements, investigate incidents, preserve suppression choices, and establish or defend legal claims.
- Send optional marketing only with a valid basis and provide unsubscribe controls.
5. Two-step referral consent
A referrer must first confirm that the client agreed to the introduction and authorized the submitted contact information. That confirmation is limited; it is not the client’s unlimited consent. The invited client then independently sees the referrer, professional, category, purpose, and no-obligation notice and separately accepts or declines the referral, Terms, Privacy processing, referral sharing, and necessary service communications.
Declining stops the active workflow and unnecessary messages. SmartVest retains only information reasonably needed for suppression, security, audit, dispute, or legal obligations. Decline never opts a person into marketing.
6. Consent and choices
We present key information in understandable form at the point of decision and separate optional marketing from required service processing. You may withdraw optional consent through available controls or privacy@smartvest.ca, subject to legal or contractual limits. Withdrawal may prevent a requested feature from continuing but does not invalidate lawful prior processing. Material new purposes or document changes may require new consent.
7. Sharing with professionals and businesses
After client confirmation and professional acknowledgement, SmartVest may share the minimum necessary contact, category, locked broad questionnaire snapshot, scheduling, Opportunity Case status, and related service information with the selected or assigned professional or business. The receiving business cannot overwrite the original questionnaire or internal tier; client corrections are appended with an audit history. This does not authorize unrelated marketing. Underlying professionals must collect sensitive case information through their own appropriate processes and remain responsible for their independent privacy and regulatory duties.
8. Service providers and cross-border processing
SmartVest uses categories of providers including Stripe, Google Calendar/Meet, email delivery, cloud hosting, MongoDB database hosting, monitoring, security, and support tools. They may process information in Canada, the United States, or other jurisdictions where they or their subprocessors operate. Information may therefore be accessible to foreign courts and authorities under local law. SmartVest remains accountable for transferred information and uses contractual and other safeguards appropriate to the service and risk.
9. Stripe and Google
Stripe processes paid SmartVest plan and subscription information under its services and privacy terms. The cardless Starter trial and Free plan are maintained by SmartVest without creating a Stripe subscription. SmartVest stores customer, subscription, plan-entitlement, referral-credit cycle/event, invoice, receipt, payment-status, acceptance, and operational/accounting references, not raw card or bank credentials. Connected-account referral funding and transfer features remain dormant.
Authorized SmartVest Advisors and Businesses may voluntarily connect a Google account for supported scheduling, Google Calendar, and Google Meet functionality. SmartVest receives the connected Google identity and email and uses owner-calendar identifiers, event identifiers, event details, start and end times, attendee scheduling information required by the feature, and conference information only as needed to create, retrieve, update, reconcile, or cancel the authorized meeting event. Calendar creates the associated Google Meet conference; where the feature applies, SmartVest retrieves and updates that meeting space only to configure the implemented moderation and admission settings.
SmartVest does not request access to Gmail, Drive, Contacts, recordings, or transcripts. Google refresh credentials are encrypted at rest on the server and excluded from ordinary API responses; short-lived access credentials are held only in server memory and are not delivered to the browser. Disconnecting removes the stored Google credential, identity, email, and granted-scope data from the active connection, clears cached access, and attempts provider revocation. Future Google access then requires a new connection. SmartVest may retain limited non-credential meeting and audit records needed for security, integrity, disputes, legal obligations, and service history; those records do not contain reusable Google OAuth credentials.
SmartVest's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. SmartVest uses this information only to provide and secure the user-facing integration authorized by the connected Advisor or Business; it does not sell it, use it for advertising, or use it for unrelated purposes.
10. Communications and cookies
Necessary messages include account, security, legal, referral, scheduling, confirmation, and service information. Optional marketing is separate, defaults OFF, and supports unsubscribe. A referral invitation is a one-time service introduction, not marketing enrollment.
SmartVest uses necessary browser storage, tokens, cookies or similar technologies for authentication, security, preferences, and core operation. Any future non-essential analytics or advertising technology will require the disclosures and choices applicable at that time.
11. Trust and automated signals
SmartVest may calculate rules-based trust, integrity, reliability, fraud, and security signals from platform records. Authorized people review consequential integrity decisions where appropriate. Public professional/referrer metrics are informational and sample-size protected. SmartVest does not publish internal client risk scores as ratings. You may challenge materially inaccurate factual information.
12. Limiting collection and use
We seek information proportionate to the stated functions. Initial referrals should contain only a name, appropriate contact method, broad category, and limited optional context—not financial, health, or other sensitive case files. We do not use personal information for unrelated purposes without a valid legal basis or new consent where required. SmartVest does not sell personal information.
13. Retention
We keep account and operational data while needed to provide the service and for a reasonable period afterward. Referral, consent, audit, integrity, suppression, security, support, meeting, and—if activated—financial records may be retained according to legal, tax, accounting, dispute, fraud-prevention, contractual, and backup requirements. On Google disconnection, reusable OAuth credentials and active connected-identity data are removed as described above; limited meeting and audit metadata may remain only for those legitimate purposes. We delete, anonymize, or securely isolate information when it is no longer reasonably required. Account closure does not require immediate destruction of every record.
14. Safeguards and incidents
SmartVest uses administrative, technical, and organizational safeguards appropriate to sensitivity, including role-based access, least-privilege database access, credential protection, audit controls, secure transport, monitoring, backup, and incident procedures. No system can guarantee absolute security.
SmartVest assesses suspected breaches, keeps required breach records, and reports to the Privacy Commissioner and notifies affected individuals when required by applicable law, including where there is a real risk of significant harm. Report suspected compromise to security@smartvest.ca.
15. Access, correction, complaints, and deletion requests
Write to privacy@smartvest.ca to ask whether we hold personal information about you, request access or correction, ask about consent or retention, request account deletion, or make a complaint. We will verify identity, respond within applicable timelines, and explain any lawful exception, extension, fee, or refusal. We may correct information or annotate a disagreement as appropriate.
If a concern is not resolved, you may contact the Office of the Privacy Commissioner of Canada or another competent privacy regulator.
16. Minors
Users must have reached the age of majority where they reside and have legal capacity. SmartVest does not intentionally operate a minor-user or minor-referral workflow. Contact privacy@smartvest.ca if you believe a minor’s information was submitted.
17. Updates and contact
We version this Policy and show its effective date. Material changes may require notice or new acceptance. Contact: Privacy Officer, SMARTVEST TECHNOLOGIES INC., privacy@smartvest.ca. Support: support@smartvest.ca. Security: security@smartvest.ca. General: info@smartvest.ca.