CornerStoneIQ Privacy Policy

Version 2026-08-13 · Effective August 13, 2026 · Supersedes all prior versions
Privacy Officer: privacy@cornerstoneiq.ca · Support: support@cornerstoneiq.ca

The short version. CornerStoneIQ is mortgage-workflow software used by licensed Canadian mortgage brokerages. Brokerages use it to collect their clients' documents, read figures out of those documents, calculate qualification numbers, and send their clients email.

We hold two different kinds of information: information about our customers (the brokers and brokerages who buy the software), and information about their clients (borrowers), which we hold on the brokerage's behalf and under the brokerage's direction.

We do not sell personal information, we do not use it for advertising, we do not use it to train generalized artificial-intelligence models, and we run no analytics or cross-site tracking of any kind. If a broker connects a mailbox, we look only for correspondence with that broker's own clients. Every detail of all of this is set out below.

1. About this policy

1.1 This policy explains how CornerStoneIQ ("CornerStoneIQ", "we", "us", "our") handles personal information. It applies to:

1.2 "Personal information" means information about an identifiable individual, as that term is used in Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") and in substantially similar provincial legislation. We operate in accordance with PIPEDA and, where applicable, the Act respecting the protection of personal information in the private sector (Quebec), the Personal Information Protection Act (British Columbia), and the Personal Information Protection Act (Alberta).

1.3 This policy is a statement of our privacy practices. It is not a contract. Your contract with us is the CornerStoneIQ Terms of Service, which you accepted when you created an account and which governs your use of the service. Where this policy and the Terms of Service both address the handling of client data, they are intended to be read together; if they genuinely conflict, the Terms of Service govern the parties' obligations to each other and this policy governs our privacy practices.

1.4 The service is offered to businesses in Canada. It is not directed at, marketed to, or intended for individuals in the European Economic Area, the United Kingdom, or other jurisdictions whose data-protection laws impose registration, representation, or transfer-mechanism requirements on us, and we do not knowingly market or sell subscriptions into those jurisdictions.

2. Our two roles

2.1 It matters which of two roles we are playing, because it determines who is accountable to you and who you should approach with a request.

2.2 We are the accountable organization for account information. When a broker, manager, or brokerage signs up, we decide what information we need in order to open, secure, bill, and support that account. For that information — described in section 3.1 — we are directly accountable to you under PIPEDA, and you can exercise all of the rights in section 13 with us.

2.3 We act on the brokerage's behalf for client file information. Everything a broker enters or uploads about a borrower — contact details, documents, income figures, identification, deal terms, credit and bank information — is collected by the brokerage from its own client, for the brokerage's own purposes, under the brokerage's own consent and privacy obligations. We process that information only on the brokerage's instructions and only to provide the service. In privacy law terms, the brokerage is the accountable organization and we are its service provider. We never use client file information for our own purposes.

2.4 A practical consequence: if you are a borrower and you want to see, correct, or delete what is held about you, the brokerage you are working with is the right first point of contact. We will help them respond, and section 14 explains what to do if you cannot reach them.

2.5 Each brokerage's data is held in a logically separated tenant. One brokerage cannot see another brokerage's data. Within a brokerage, an individual broker sees only the client files they own, while a manager account can see all files belonging to that brokerage — this is a deliberate feature of the product and brokerages should account for it in their own privacy notices.

3. Information we collect

3.1 Account and brokerage information. Your name; business email address; the brokerage's name and, where provided, its business details; your role (manager, broker, or solo operator); your password, which is stored only as a salted scrypt hash and never in a form we or anyone else can read; email-verification and password-reset tokens; the version and timestamp of the Terms of Service you accepted; team membership and invitations; and your in-app preferences, including your email greeting, signature, message templates, automation settings, document-checklist templates, and pipeline-stage templates.

3.2 Client file information. Information about the brokerage's clients, entered by a broker or supplied by the client, which may include: name, email address, telephone number, mailing and property addresses, date of birth, marital and dependant status, employment and employer details, income, assets, liabilities, existing mortgage and maturity details, the subject property and deal terms, notes recorded by the broker, and co-applicant information. Depending on the file, it can also include sensitive information such as government-issued identification details, credit obligations, and bank account activity. Brokerages are responsible for having their clients' consent for all of this.

3.2.1 We do not store Social Insurance Numbers. A client's documents — T4 slips, Notices of Assessment — routinely print a SIN, and those documents pass through our systems to be read. We do not ask our document reader to extract the SIN, we do not keep it in any record, and any nine-digit sequence that reaches a stored text field is automatically redacted before it is written. SINs recorded by earlier versions of the service have been permanently deleted. This is a deliberate design decision: a Social Insurance Number is the single most damaging identifier to lose, and the safest way to protect one is not to hold it.

3.3 Documents and their contents. Files uploaded by a broker or a client, or retrieved as attachments from a connected mailbox — for example pay stubs, employment letters, T4s, notices of assessment, T1 Generals, bank and investment statements, mortgage statements, purchase agreements, and government identification. We store the file itself, and we store what our systems read out of it: the document's classification, the figures extracted from it, the year and employer it relates to, the identification fields read from a government ID, the reconciliation and duplicate-detection results, and an audit record of any field a broker later edited by hand, including the previous value, the new value, who changed it, and when.

3.4 Connected mailbox information. If a broker connects a mailbox — by OAuth (Google or Microsoft) or by app-specific password (Gmail, Outlook, iCloud, or another IMAP provider) — we collect and store: the connected email address; the access and refresh tokens or the app-specific password, always encrypted at rest; the granted permission scopes; and a mailbox activity log recording each connection, disconnection, message-content read, and send, with timestamps. From the mailbox itself we retrieve message metadata (sender, recipient, subject, date) and attachments from correspondence matching the broker's own clients' email addresses only, together with the message text needed to associate an attachment with the right client and to decide whether a client has replied. Section 4 sets out the Google-specific detail; section 5 covers the other providers.

3.5 Client portal information. Where a brokerage uses the client portal, we collect: the client's portal access credentials and personalized invitation link; if the brokerage enables two-factor authentication, a time-based one-time-password (TOTP) secret, stored encrypted, and the recovery codes issued with it; portal session records; and anything the client uploads or submits through the portal.

3.6 Electronic signature information. Where a document is signed in the service, we retain the evidence that makes the signature meaningful: the signer's name; the typed or drawn signature image; the date and time of signing; the IP address the signature was made from; a cryptographic (SHA-256) hash of the document as sent and as executed; and a chronological event log of the request, view, signature or decline, and any stated reason. This record is deliberately immutable so that it remains reliable evidence.

3.7 Bank account information (optional feature). If a brokerage enables bank-data collection and a client chooses to use it, the client connects their bank through a third-party aggregator. We receive account balances, holder details, and transaction history, and we store the derived analysis (income deposits, balance trends, and risk findings such as non-sufficient-funds events). We never receive or store the client's online banking username or password — those are entered with the aggregator, not with us. This feature is unavailable on our hosted service unless a live provider has been configured; where it is not configured, no bank data is collected at all.

3.8 Credit bureau information (optional feature). If a brokerage enables credit-report retrieval and holds its own bureau credentials, we store those credentials encrypted, and we store the report returned for a client — including reported liabilities and balances — and reconcile it against the liabilities on the file. As with bank data, this feature is unavailable on our hosted service unless live bureau credentials have been configured. Pulling a credit report requires the client's consent, which the brokerage is responsible for obtaining.

3.9 Payment and billing information. Subscriptions are processed by Stripe. Stripe collects and holds the payment card directly; we never receive, see, or store full card numbers. We store the subscription's status, plan, billing period, customer and subscription identifiers, the last four digits and brand of the card as reported to us, and the invoice and payment-event history needed to run billing and support.

3.10 Technical, log, and security information. When the service is used we automatically record: IP address; browser and device type (user agent); the pages and API endpoints requested and their timestamps; session identifiers; sign-in, sign-out, failed sign-in, and session-revocation events; automated-scan and automation events; and application error and diagnostic logs. Our server infrastructure also keeps operating-system-level access and security logs, including records of blocked or repeated failed connection attempts.

3.11 Support communications. If you email us or contact us for support, we keep the message, your contact details, and our reply, so that we have a record of the issue and its resolution.

3.12 Information we do not collect. For the avoidance of doubt, we do not use advertising cookies, cross-site trackers, web beacons, analytics platforms, session-replay tools, fingerprinting, or social-media pixels. We do not collect precise geolocation, biometric identifiers, health information, or information about your activity on other websites. We do not buy personal information from data brokers, and we do not enrich or append to the information you give us from outside sources.

4. Google user data

4.1 This section applies if a broker connects a Google account to CornerStoneIQ. It is written to satisfy Google's disclosure requirements and to be plainly understandable.

4.2 The permissions we request, and why

ScopeWhat it allowsWhy we need it
gmail.readonly Read-only access to Gmail messages and attachments. To find the mortgage documents a client has emailed to their broker, download those attachments into the client's file, and detect that the client has replied so a duplicate follow-up email is not sent.
gmail.send Send email as the signed-in user. It does not permit reading, deleting, or modifying anything. To send the broker's document-request and follow-up emails from the broker's own address, so the client receives them from the person they are actually working with.

We request these two scopes and no others. We do not request permission to delete mail, modify labels or settings, access Google Drive, Contacts, Calendar, or the broker's Google profile beyond the email address of the connected account. A broker may instead connect Gmail with an app-specific password; OAuth is offered because it is the safer of the two.

4.3 What we actually access

4.4 Limited Use commitment

CornerStoneIQ's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

4.5 AI processing of mailbox content

Attachments retrieved from a connected mailbox are processed by an artificial-intelligence document-reading service (Anthropic — see section 9) for the sole purpose of classifying the document and extracting the figures the broker needs. This is a user-facing feature of the service and is permitted under the Limited Use requirements as processing necessary to provide it. Anthropic acts as our service provider, is contractually bound to process the content only on our instructions, and does not use content submitted through its API to train its models. Message bodies are used for attribution and reply detection within our own systems.

4.6 How Google user data is stored and for how long

OAuth access and refresh tokens are encrypted at rest with a key held only on our servers and are scoped to the individual broker who granted them. Attachments and the figures extracted from them are stored in the client's file and are retained on the same basis as all other client file information (section 12). Message bodies are used transiently for attribution and reply detection and are not retained as a mail archive; we do not build a copy of the mailbox.

4.7 Revoking access and deleting the data

5. Microsoft, Apple, and other mailbox connections

5.1 Microsoft (OAuth). We request Mail.Read, Mail.Send, User.Read (to identify the connected mailbox address), and offline_access (to keep the connection alive without asking you to sign in repeatedly). Everything in sections 4.3, 4.5, and 4.6 applies identically. One difference must be stated plainly: Microsoft does not offer an endpoint that lets an application revoke its own tokens server-side. When you disconnect, we delete our copy of the tokens immediately and stop all access, but to withdraw the grant on Microsoft's side you should also remove CornerStoneIQ at your Microsoft account's app-permissions page (account.live.com/consent/Manage, or your organization's Azure portal for a work account).

5.2 Apple iCloud and other IMAP providers. These are connected with an app-specific password that you generate at your provider and enter once. We store it encrypted at rest and use it to sign in to your provider's IMAP and SMTP servers to perform the same two functions: search for correspondence with your own clients and download their attachments, and send your email as you. Disconnecting deletes our copy of the password immediately; you should also revoke the app-specific password at your provider, which is the only way to be certain it can no longer be used by anyone.

5.3 Whichever method is used, the mailbox activity log described in section 3.4 records connections, disconnections, content reads, and sends, and is visible to the broker in Settings.

6. How we use information

6.1 We use personal information only for the following purposes:

6.2 We do not use personal information for any purpose materially different from those above without first obtaining consent, unless the law permits or requires us to.

6.3 We do not sell, rent, licence, or trade personal information to anyone, for any purpose, and we do not disclose it for a third party's own marketing.

7. Consent and withdrawal

7.1 Brokers and brokerages. By creating an account and using the service you consent to our handling of your account information as described in this policy. Consent to information that is genuinely necessary to deliver the service — your email address, your password hash, billing status, security logs — cannot be withdrawn while you keep an account, because without it we cannot provide or secure the service. You may withdraw it by closing your account.

7.2 Optional features are separately consented. Connecting a mailbox, enabling automated follow-up email, enabling the client portal, enabling bank-data collection, and enabling credit-report retrieval are each optional, each require a distinct act of consent, and each can be turned off independently in Settings without closing your account.

7.3 Borrowers. The brokerage obtains the borrower's consent, not us. Brokerages warrant in our Terms of Service that they have obtained every consent and given every notice required by law before putting a client's information into the service. A borrower who wishes to withdraw consent should tell their broker; the broker can then delete the file or the specific information, subject to any records the brokerage itself is legally required to keep.

7.4 Withdrawing consent may make some or all of the service unusable, and we will tell you if that is the case before acting on the request. Withdrawal is not retroactive: it does not undo processing that was lawful when it happened, and it does not require us to delete records we must keep by law.

8. Automated processing and artificial intelligence

8.1 The service performs automated processing. Specifically, it: classifies uploaded and emailed documents by type; extracts figures and fields from them, including from government identification; detects duplicate documents; reconciles figures across documents; calculates income, ratios, and qualification estimates; derives a pipeline stage for each file; generates draft text for forms, letters, and submission notes; and, where a broker enables it, decides when to send a follow-up email.

8.2 Parts of this use third-party artificial-intelligence models (see section 9). AI systems make mistakes — misreading figures, misclassifying documents, and producing plausible but incorrect output are all known failure modes.

8.3 The service makes no decision about any individual. It does not approve, decline, score, rank, or make any lending, credit, insurance, or eligibility decision, and its output has no legal or similarly significant effect on anyone by itself. Every figure and document it produces is presented to the licensed broker for review, is editable, and must be independently verified by that broker before it is relied on, shown to a client, or submitted to a lender, insurer, or regulator. Any decision that follows is made by a human — the broker, and ultimately the lender or insurer.

8.4 Where a broker edits an extracted figure, we keep the original value, the new value, who changed it, and when, so the provenance of every number on a file is auditable.

8.5 If you are an individual whose information was processed this way and you want to know what information was used and where it came from, ask your brokerage, or contact us under section 13 and we will help.

9. When we disclose information

9.1 Service providers. We disclose personal information to the providers listed below, each only to the extent needed for its function, each bound by contract to use it solely on our instructions and to protect it with comparable safeguards. This is our complete list of providers that may handle personal information.

ProviderWhat it doesWhat it may handleLocation
VultrApplication and database hosting; server backupsAll data in the serviceToronto, Canada
CloudflareAuthoritative DNS for our domainDNS query metadata only — no application traffic passes through itGlobal
AnthropicAI classification of documents and extraction of figuresContents of documents submitted for readingUnited States
StripeSubscription billing and payment processingBroker/brokerage billing contact and payment details (collected by Stripe directly)United States / Canada
ResendDelivery of our own account, security, and billing emailRecipient email address and message content of those emailsUnited States
Google / Microsoft / Apple or another mail providerThe broker's own connected mailboxMail the broker sends and receives — under the broker's own relationship with that providerPer that provider
Flinks (only if bank-data collection is enabled)Bank account aggregationClient's banking credentials (entered with Flinks, never with us), accounts, and transactionsCanada
Equifax Canada (only if credit retrieval is enabled)Credit report retrievalClient identifiers needed to request a report; the report returnedCanada

9.2 At your direction. We disclose information to whomever you direct — for example, the recipient of an email you send through the service, a client you invite to the portal, or a person you send a document to for signature. Exports you download or generate (including files prepared for deal-submission platforms) leave our control the moment you download or transmit them, and what happens to them afterwards is your responsibility.

9.3 Within a brokerage. A manager account can see all client files belonging to that brokerage, including files owned by other brokers on the team.

9.4 Legal and protective disclosure. We may disclose personal information where required or permitted by law: in response to a subpoena, warrant, court order, or other lawful demand from a body with jurisdiction; to comply with a legal obligation; to investigate a suspected breach of an agreement or a contravention of law; to detect, prevent, or address fraud, security, or technical issues; to protect the rights, property, or safety of any person; or to obtain legal advice. Where we may lawfully do so, and it would not compromise an investigation, we will tell the affected account holder before disclosing.

9.5 Business transactions. If we are involved in a merger, acquisition, financing, reorganization, or sale of all or part of our business, personal information may be disclosed to the parties involved and transferred to a successor. Any disclosure before the transaction closes will be limited to what is necessary to evaluate it and will be subject to confidentiality obligations restricting use to that purpose. A successor will remain bound by this policy, and we will give notice of any change of control before your information becomes subject to a different policy. Google user data is transferred in this circumstance only with notice to affected users and their consent where required.

9.6 Aggregated and de-identified information. We may create and use information that has been aggregated or de-identified so that it does not identify you or any individual — for example, counting how many documents of a given type were processed. We do not attempt to re-identify it and we do not permit anyone else to.

9.7 With consent. Any other disclosure is made only with your consent.

10. Where data is stored, and cross-border transfers

10.1 The application, the database, and their backups are hosted in Toronto, Canada. Client files, documents, and account records live there.

10.2 Some of the providers in section 9.1 operate outside Canada, principally in the United States. In particular, documents submitted for AI reading are processed in the United States, subscription billing is processed by Stripe, and our own account and security email is delivered by Resend.

10.3 You should know what that means. While personal information is in another country, it is subject to the laws of that country, and courts, law enforcement, national-security authorities, and regulatory bodies there may be entitled to obtain access to it under those laws — including without notice to you or to us. This is true of any organization that uses foreign service providers, and we tell you because PIPEDA requires that you be informed of it.

10.4 We remain accountable for personal information we transfer to a provider for processing. We use contractual and other means to require a comparable level of protection while it is in their hands, and providers may use it only to perform the function we engaged them for.

10.5 If your brokerage's own regulatory or client commitments require that data never leave Canada, do not enable the AI document-reading feature, and contact us before relying on the service.

11. How we protect information

11.1 We use safeguards appropriate to the sensitivity of the information, including:

11.2 No system is perfectly secure. We cannot guarantee that the service, or any transmission to or from it, will never be compromised. You share responsibility: keep your password strong and unique, do not share accounts, remove team members promptly when they leave, revoke app-specific passwords when you stop using them, and tell us immediately at privacy@cornerstoneiq.ca if you suspect unauthorized access.

11.3 If you believe you have found a security vulnerability, please report it to privacy@cornerstoneiq.ca rather than disclosing it publicly. We will acknowledge your report and will not pursue action against good-faith research that does not access other people's data, degrade the service, or exfiltrate information.

12. Retention and deletion

12.1 We keep personal information only as long as it is needed for the purposes in section 6, or as long as the law requires. Our schedule:

InformationRetention
Client files, documents, extracted figures, notes, forms, and signature recordsFor as long as the brokerage's account is active, or until the brokerage deletes them. On account closure: deleted within 30 days of the end of the export window in 12.2.
Account and brokerage recordsFor as long as the account is active; deleted within 30 days of closure, except records of the Terms version accepted and of billing, which are kept as below.
Mailbox tokens and app-specific passwordsDeleted immediately on disconnect or account closure. Google grants are additionally revoked with Google at that moment.
Mailbox activity logWith the account; deleted on closure.
Billing and tax recordsUp to 7 years, as required by Canadian tax and corporate record-keeping law. Stripe retains its own records under its own policy.
Security, sign-in, and server logsUp to 12 months, then deleted or aggregated.
Application error and diagnostic logsUp to 90 days.
Support correspondenceUp to 24 months after the issue is resolved.
Records of a privacy breach24 months from the day we determine the breach occurred, as PIPEDA requires.
BackupsDeleted data persists in encrypted backups for up to 35 days and is then overwritten on the ordinary backup cycle. Restored backups are re-processed to honour deletions.

12.2 On account closure we make your data available for export on written request for 30 days (the Terms of Service set out the exception for termination involving fraud or unlawful use). After that window we delete it on the schedule above.

12.3 You can delete sooner. Brokers can delete a document, a client file, or a whole account's data at any time in the application, and can request full deletion under section 13. When we delete, we delete — subject only to the backup cycle in the table and to records we are legally required to keep.

12.4 Your own record-keeping obligations are yours. Mortgage brokerages are subject to record-retention rules under provincial legislation and under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act — FINTRAC generally requires certain client and transaction records to be kept for at least five years. CornerStoneIQ is not an archival or system-of-record service and must not be relied on to satisfy those obligations. Keep your own copies of anything you are required to retain, and export before you close your account.

12.5 Information that has been irreversibly aggregated or de-identified may be kept indefinitely, as it no longer identifies anyone.

13. Your privacy rights

13.1 Subject to the limited exceptions in 13.4, you have the right to:

13.2 How to exercise a right. Email privacy@cornerstoneiq.ca and tell us what you want and enough detail to find your information. We will verify your identity first — usually by confirming you control the account email address — because releasing information to the wrong person is itself a breach.

13.3 Our timeline. We acknowledge requests promptly and respond within 30 days. If we need an extension the law allows, we will tell you within the original 30 days, explain why, and tell you of your right to complain to the Privacy Commissioner. Access is provided free of charge; if a request is unusually voluminous and a cost is unavoidable, we will give you an estimate first and proceed only if you accept it.

13.4 Limits. We may be unable to act on part of a request where the law requires or permits us to refuse — for example where doing so would reveal personal information about another individual that cannot be severed, would reveal confidential commercial information, is subject to solicitor-client privilege, was generated in a formal dispute-resolution process, relates to an ongoing investigation or the detection of fraud, or where we are legally required to keep the information. If we refuse, we will tell you in writing, give our reasons and the provision relied on, and explain how to complain.

13.5 If your request concerns a client file and you are not the brokerage that owns it, see section 14 — we will forward the request to the brokerage rather than act on it ourselves, because the information is theirs.

13.6 We will not retaliate against anyone for exercising a privacy right.

14. If you are a borrower or client of a brokerage

14.1 If a mortgage broker uses CornerStoneIQ to work on your file, we hold your information for that brokerage, on its instructions. We did not collect it from you, we have no relationship with you, and we cannot tell whether your broker has your consent — that is the brokerage's responsibility.

14.2 Contact your brokerage first. They can show you everything on your file, correct it, or delete it, and they can answer questions about why it was collected. They are the organization accountable to you.

14.3 If you cannot reach them, or they are no longer in business, email privacy@cornerstoneiq.ca. We will confirm your identity, tell you which brokerage holds your information, forward your request to them, and — where we are permitted to act without their instruction, or where they no longer exist — help you directly. We will respond to you within 30 days either way.

14.4 If you used a client portal, uploaded documents, connected a bank account, or signed a document electronically, sections 3.5 to 3.7 describe exactly what was recorded, including the IP address captured with an electronic signature.

14.5 You may complain to the Office of the Privacy Commissioner of Canada or to your provincial commissioner at any time (section 22), whether or not you have complained to us first.

15. Cookies and similar technologies

15.1 We use only strictly necessary cookies. We do not use advertising, analytics, or cross-site tracking cookies, and there are no third-party cookies on our sites.

CookiePurposeLifetime
connect.sidKeeps a broker signed in to the workspace. Strictly necessary.Up to 7 days; cleared on sign-out
csiq.portal.sidKeeps a client signed in to the client portal, separately from any broker session on the same device. Strictly necessary.Session / up to 7 days; cleared on sign-out

15.2 Both are marked HTTP-only, so page scripts cannot read them, and in production both are marked Secure so they are sent only over HTTPS.

15.3 We also use ordinary browser storage on your own device to remember interface preferences. That stays on your device and is not transmitted to us as a tracking signal.

15.4 Because we use no tracking cookies, there is nothing to consent to and no cookie banner. Blocking strictly necessary cookies in your browser will prevent you from signing in. We do not track you across other websites, so a browser "Do Not Track" or Global Privacy Control signal has nothing to act on here.

15.5 Emails we send you (account, security, and billing email) contain no tracking pixels. Emails a broker sends through the service are the broker's own; brokerages are responsible for what they include in them.

16. Email we send you, and CASL

16.1 We send account holders transactional and service email: verification, password reset, security alerts, billing and renewal notices, changes to this policy or the Terms, and support replies. These are necessary to operate your account and are not marketing; you cannot unsubscribe from them while you have an account.

16.2 We send commercial email only with the consent Canada's Anti-Spam Legislation requires, or where CASL permits it in an existing business relationship. Every commercial message identifies us, gives a contact address, and carries a working unsubscribe link that we honour within 10 business days, as CASL requires.

16.3 Email that a broker sends to their own clients through the service — including automated follow-ups — is the broker's message from the broker's mailbox. The broker is responsible for having the consent CASL requires for those recipients, as their Terms of Service confirm.

17. Children

17.1 The service is a business tool for licensed mortgage professionals. It is not directed at children, and we do not knowingly collect personal information directly from anyone under the age of majority for our own purposes.

17.2 A brokerage may occasionally have reason to record information about a minor within a client file — for example a dependant named on an application. That information is client file information under this policy, is the brokerage's responsibility, and is subject to the same protections and retention rules as the rest of the file.

17.3 If you believe a child's information has been provided to us in error, contact privacy@cornerstoneiq.ca and we will act with the brokerage to remove it.

18. Privacy breaches

18.1 We maintain safeguards designed to prevent unauthorized access to, disclosure of, or loss of personal information, and we investigate every suspected incident.

18.2 If a breach of security safeguards occurs and it is reasonable to believe it creates a real risk of significant harm to an individual, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, as PIPEDA requires — and we will notify any other organization or government institution that may be able to reduce the risk of harm. Notice will describe what happened, what information was involved, what we are doing, and what you can do.

18.3 Where the affected information is client file information, we will notify the brokerage without unreasonable delay so it can meet its own notification obligations to its clients and regulators, and we will give it the information it reasonably needs to do so.

18.4 We keep a record of every breach of security safeguards, whether or not it was reportable, for 24 months from the day we determine it occurred, and will provide those records to the Commissioner on request.

19. Third-party links and services

19.1 The service links to and interoperates with things we do not control: your email provider, your bank's authentication flow, credit bureaus, payment pages hosted by Stripe, deal-submission platforms you export to, and ordinary web links. Their handling of your information is governed by their own privacy policies, not this one, and we are not responsible for their practices.

19.2 Compatibility with a third-party platform — including exports formatted for a lender or deal-submission system — does not imply any affiliation with, sponsorship by, or endorsement from that platform.

20. Province-specific information

20.1 Quebec. We have designated a Privacy Officer accountable for our compliance, reachable at privacy@cornerstoneiq.ca (section 22). Sections 8 and 10 give the disclosures Quebec law requires about automated processing and about processing outside Quebec; section 13 covers the right to receive computerized personal information in a portable format. We do not use personal information to profile, locate, or identify individuals. This document and our Terms of Service are drawn up in English at the express wish of the parties; les parties ont expressément demandé que la présente politique soit rédigée en anglais.

20.2 British Columbia and Alberta. Where BC's or Alberta's Personal Information Protection Act applies instead of PIPEDA, we handle personal information in accordance with it, including its access, correction, and — in Alberta — its notification requirements, and you may complain to the applicable provincial commissioner (section 22).

20.3 Other provinces. PIPEDA applies to our commercial activities across Canada except where a province has enacted substantially similar legislation, in which case that legislation applies to activity within the province. Whichever applies, the practices in this policy are the practices we follow.

21. Changes to this policy

21.1 We may update this policy as the service, our providers, or the law changes. The version and effective date are shown at the top, and the current version always governs.

21.2 If a change is material — for example a new category of information, a new purpose, a new service provider that handles personal information, or a change in where data is stored — we will notify account holders by email or in-service notice before it takes effect, and where the law requires consent for the new practice we will ask for it rather than assume it.

21.3 Non-material changes (clarifications, corrections, formatting) take effect when posted.

21.4 Continuing to use the service after a change takes effect means you accept the updated policy. If you do not, you may close your account under section 12.

21.5 Prior versions are available on request from privacy@cornerstoneiq.ca.

22. Contact us and complaints

22.1 Our Privacy Officer is accountable for CornerStoneIQ's compliance with this policy and with applicable privacy law, and is your point of contact for every question, access or deletion request, and complaint:

22.2 Complaints. Tell us in writing what happened and what you would like done. We will acknowledge promptly, investigate every complaint, respond within 30 days, and tell you what we found and what we changed. If we were wrong, we will correct it — including amending our practices or this policy.

22.3 If you are not satisfied with our response, you may complain to a regulator:

22.4 You do not have to complain to us before going to a regulator, and nothing in this policy limits any right or remedy you have under applicable law.


← cornerstoneiq.ca  ·  app.cornerstoneiq.ca