Privacy Policy
Effective Date: March 15th, 2023
Last Updated: April 6, 2026
At Chexy, we take your privacy seriously. This Privacy Policy explains what personal information we collect, why we collect it, and how we use and share it. It covers your use of the Chexy mobile application (the "App"), website (the "Website"), and all related features and services (collectively, the "Services").
This Policy remains in effect for as long as we hold your information, even after you stop using the Services. By providing us with your personal information, you are consenting to the collection, use, and sharing of your personal information as set out in this Policy.
This Policy does not apply to information you submit directly to third parties, including the organizations and individuals with which you connect on the Services. Please refer to our Terms of Use for additional context.
What information we collect and when we collect it
Personal information
“Personal Information” is any information provided to us or generated within our Services or Website that personally identifies or could be used to identify an individual, such as your name or email address ("Personal Information"). We may combine Personal Information with other information we collect; when we do, we treat the combined information as Personal Information.
Examples of the personal information we collect include:
Identifiers: Name, date of birth, phone number, email address, and mailing or billing address
Identity verification information: Government-issued photo ID and Social Insurance Number (collected solely for tax payment processing)
Financial information: Bank account details, credit and debit card data (tokenized via Evervault in accordance with PCI DSS standards), and transaction history
Device and usage data: Device type, operating system, IP address, session interactions, approximate location, push notification tokens, and product usage
Biometric data: If you enable biometric login on the App (e.g. Face ID or fingerprint), this is processed locally on your device and never stored on our servers
Rewards information: Your Aeroplan number, if you choose to provide it
Communications: Any information you share when contacting us
Some of this information is collected on our behalf by third-party service providers. See the "Where we send your personal information" section for more detail.
Other information
Other information is data that does not directly identify you on its own. When we combine Other Information with Personal Information, we treat the combined data as Personal Information. We, and our third-party service providers, collect information automatically through our Services.
This may include information, such as:
Product interaction data: Features used, pages visited, and actions taken within the App and Website.
Log data: IP address, browser type, operating system, device identifiers, and referring URLs.
Cookies and tracking technologies: Data collected via cookies and similar technologies to allow our Services to recognize whether you have visited the Website before; it may also store user preferences and information. You can manage cookie preferences through your browser settings.
Approximate location: Inferred from your IP address.
How we use your information
We use the information we collect to:
Provide, maintain, and improve our Services, including processing household bill payments (e.g. rent, utilities, property taxes) and supporting credit building
Verify your identity and prevent fraud and financial abuse
Process transactions and send related communications, including payment confirmations and receipts
Administer your account and fulfill the terms of any agreement with us
Communicate with you, including sending security alerts, support messages, and service updates
Send you personalized marketing communications by email, where you have consented
Analyze usage patterns and product interactions to improve the App and Website
Report your payment history to credit bureaus (e.g. Equifax) with your consent, as part of our credit building feature
Comply with legal obligations, including our obligations as a registered Money Services Business (MSB) under FINTRAC
De-identify your information for internal reporting and trend analysis
Where we send your personal information
We do not sell your personal information to third parties. We share it only where necessary to deliver our Services, and never for third-party advertising or profit.
We may share your information with:
Payment Processors: We share your financial information with Zum Rails, Peoples Trust Company (PTC), Worldpay, and American Express to process bill payments on your behalf. These providers handle your data solely for payment processing purposes.
Identity Verification and Authentication: We use Plaid for identity verification, Trulioo for business identity verification (Chexy for Business), and Clerk for authentication and account management. All data collected through these third parties is handled in accordance with their respective privacy policies.
Credit Reporting: With your consent, we share your payment history with Equifax for the purpose of rent reporting and credit building. You may withdraw your consent at any time.
Communications and Support Providers: We use SendGrid and Customer.io for transactional and marketing email communications, respectively, and Intercom for customer support. These providers may have access to your name, email address, and interaction history for the purpose of delivering these services.
Analytics and Monitoring: We use Google Analytics and BigQuery for analytics and reporting, Statsig for feature flagging and experimentation, and Datadog for application monitoring and performance tracking. Datadog may collect IP address, device info, and session data that can be linked to individual accounts through real user monitoring (RUM). We limit logging of personal information where possible, though during troubleshooting we may temporarily capture additional data.
Rewards: If you provide your Aeroplan number, we share your name, Aeroplan number, and eligible transaction information with Air Canada to facilitate reward redemption.
Legal Obligations: We may disclose your information if required by law, court order, or a valid request from a government authority, or where we believe disclosure is necessary to prevent fraud, protect safety, or enforce our Terms of Use.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, in accordance with applicable law.
Where we store your data
Your information is stored on servers maintained by our cloud service providers, predominantly located in Canada and the United States. Many of our service providers are located outside of Canada. While we use appropriate safeguards to keep your information secure, the laws in other places may differ from those in Canada and authorities in those jurisdictions may access your information in accordance with their local laws.
How we protect your information
We maintain appropriate administrative, technical, and physical safeguards designed to protect your personal information from unauthorized access, use, modification, and disclosure. These include compliance with PCI DSS standards for handling payment card data and an annual SOC 2 Type 2 audit covering the security, availability, and confidentiality of our systems. While we take all reasonable steps to protect your data, no transmission over the internet is completely secure.
Data retention
We retain your personal information for as long as necessary to fulfill the purposes described in this Policy, or as required by law:
Active account data: Retained for the duration of your account.
Financial and identity records: Retained for 7 years after account closure, in accordance with CRA and FINTRAC requirements.
Marketing data: Once you opt out, we will not send you any further marketing communications.
All other data: Deleted or de-identified when no longer necessary.
If you request deletion of your personal data, it may not be possible to completely remove all information due to technological or legal constraints. We will take all reasonable steps to securely destroy or de-identify your information where full deletion is not possible.
Your rights
You have the right to:
Access the personal information we hold about you
Correct or update inaccurate information
Request deletion of your personal data
Withdraw your consent to certain uses of your data, including credit bureau reporting
Object to or restrict our processing of your data
Lodge a complaint with us or a relevant regulatory authority
To exercise any of these rights, log into your account and visit your profile settings, or contact us at privacy@chexy.co. We will respond within 10 business days.
Data breach notification
In the event of a data breach that poses a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada (OPC) as required under PIPEDA. We maintain internal procedures to detect, contain, and respond to privacy breaches in a timely manner.
Children's privacy
The Services are intended for individuals who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with information, please contact us and we will promptly delete it.
Marketing communications
From time to time, we may send you email communications about Chexy products, services, or promotions in accordance with Canada's Anti-Spam Legislation (CASL). You can opt out at any time by clicking the unsubscribe link in any marketing email or by contacting us at privacy@chexy.co. Please note that transactional and account-related messages are not subject to opt-out.
Governing law
This Policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, including the Personal Information Protection and Electronic Documents Act (PIPEDA). If you are a resident of Quebec, additional rights may apply under Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25).
Changes to this policy
We may update this Privacy Policy periodically. If we make material changes, we will notify you by email or through a notice on our Services before they take into effect. Continued use of the Services after that date means you accept the updated Policy.
Contact us
If you have questions, wish to exercise your rights, or want to make a complaint about how we handle your personal information, please contact us:
Email: privacy@chexy.co | Website: www.chexy.co
Last Updated: April 6, 2026
At Chexy, we take your privacy seriously. This Privacy Policy explains what personal information we collect, why we collect it, and how we use and share it. It covers your use of the Chexy mobile application (the "App"), website (the "Website"), and all related features and services (collectively, the "Services").
This Policy remains in effect for as long as we hold your information, even after you stop using the Services. By providing us with your personal information, you are consenting to the collection, use, and sharing of your personal information as set out in this Policy.
This Policy does not apply to information you submit directly to third parties, including the organizations and individuals with which you connect on the Services. Please refer to our Terms of Use for additional context.
What information we collect and when we collect it
Personal information
“Personal Information” is any information provided to us or generated within our Services or Website that personally identifies or could be used to identify an individual, such as your name or email address ("Personal Information"). We may combine Personal Information with other information we collect; when we do, we treat the combined information as Personal Information.
Examples of the personal information we collect include:
Identifiers: Name, date of birth, phone number, email address, and mailing or billing address
Identity verification information: Government-issued photo ID and Social Insurance Number (collected solely for tax payment processing)
Financial information: Bank account details, credit and debit card data (tokenized via Evervault in accordance with PCI DSS standards), and transaction history
Device and usage data: Device type, operating system, IP address, session interactions, approximate location, push notification tokens, and product usage
Biometric data: If you enable biometric login on the App (e.g. Face ID or fingerprint), this is processed locally on your device and never stored on our servers
Rewards information: Your Aeroplan number, if you choose to provide it
Communications: Any information you share when contacting us
Some of this information is collected on our behalf by third-party service providers. See the "Where we send your personal information" section for more detail.
Other information
Other information is data that does not directly identify you on its own. When we combine Other Information with Personal Information, we treat the combined data as Personal Information. We, and our third-party service providers, collect information automatically through our Services.
This may include information, such as:
Product interaction data: Features used, pages visited, and actions taken within the App and Website.
Log data: IP address, browser type, operating system, device identifiers, and referring URLs.
Cookies and tracking technologies: Data collected via cookies and similar technologies to allow our Services to recognize whether you have visited the Website before; it may also store user preferences and information. You can manage cookie preferences through your browser settings.
Approximate location: Inferred from your IP address.
How we use your information
We use the information we collect to:
Provide, maintain, and improve our Services, including processing household bill payments (e.g. rent, utilities, property taxes) and supporting credit building
Verify your identity and prevent fraud and financial abuse
Process transactions and send related communications, including payment confirmations and receipts
Administer your account and fulfill the terms of any agreement with us
Communicate with you, including sending security alerts, support messages, and service updates
Send you personalized marketing communications by email, where you have consented
Analyze usage patterns and product interactions to improve the App and Website
Report your payment history to credit bureaus (e.g. Equifax) with your consent, as part of our credit building feature
Comply with legal obligations, including our obligations as a registered Money Services Business (MSB) under FINTRAC
De-identify your information for internal reporting and trend analysis
Where we send your personal information
We do not sell your personal information to third parties. We share it only where necessary to deliver our Services, and never for third-party advertising or profit.
We may share your information with:
Payment Processors: We share your financial information with Zum Rails, Peoples Trust Company (PTC), Worldpay, and American Express to process bill payments on your behalf. These providers handle your data solely for payment processing purposes.
Identity Verification and Authentication: We use Plaid for identity verification, Trulioo for business identity verification (Chexy for Business), and Clerk for authentication and account management. All data collected through these third parties is handled in accordance with their respective privacy policies.
Credit Reporting: With your consent, we share your payment history with Equifax for the purpose of rent reporting and credit building. You may withdraw your consent at any time.
Communications and Support Providers: We use SendGrid and Customer.io for transactional and marketing email communications, respectively, and Intercom for customer support. These providers may have access to your name, email address, and interaction history for the purpose of delivering these services.
Analytics and Monitoring: We use Google Analytics and BigQuery for analytics and reporting, Statsig for feature flagging and experimentation, and Datadog for application monitoring and performance tracking. Datadog may collect IP address, device info, and session data that can be linked to individual accounts through real user monitoring (RUM). We limit logging of personal information where possible, though during troubleshooting we may temporarily capture additional data.
Rewards: If you provide your Aeroplan number, we share your name, Aeroplan number, and eligible transaction information with Air Canada to facilitate reward redemption.
Legal Obligations: We may disclose your information if required by law, court order, or a valid request from a government authority, or where we believe disclosure is necessary to prevent fraud, protect safety, or enforce our Terms of Use.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, in accordance with applicable law.
Where we store your data
Your information is stored on servers maintained by our cloud service providers, predominantly located in Canada and the United States. Many of our service providers are located outside of Canada. While we use appropriate safeguards to keep your information secure, the laws in other places may differ from those in Canada and authorities in those jurisdictions may access your information in accordance with their local laws.
How we protect your information
We maintain appropriate administrative, technical, and physical safeguards designed to protect your personal information from unauthorized access, use, modification, and disclosure. These include compliance with PCI DSS standards for handling payment card data and an annual SOC 2 Type 2 audit covering the security, availability, and confidentiality of our systems. While we take all reasonable steps to protect your data, no transmission over the internet is completely secure.
Data retention
We retain your personal information for as long as necessary to fulfill the purposes described in this Policy, or as required by law:
Active account data: Retained for the duration of your account.
Financial and identity records: Retained for 7 years after account closure, in accordance with CRA and FINTRAC requirements.
Marketing data: Once you opt out, we will not send you any further marketing communications.
All other data: Deleted or de-identified when no longer necessary.
If you request deletion of your personal data, it may not be possible to completely remove all information due to technological or legal constraints. We will take all reasonable steps to securely destroy or de-identify your information where full deletion is not possible.
Your rights
You have the right to:
Access the personal information we hold about you
Correct or update inaccurate information
Request deletion of your personal data
Withdraw your consent to certain uses of your data, including credit bureau reporting
Object to or restrict our processing of your data
Lodge a complaint with us or a relevant regulatory authority
To exercise any of these rights, log into your account and visit your profile settings, or contact us at privacy@chexy.co. We will respond within 10 business days.
Data breach notification
In the event of a data breach that poses a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada (OPC) as required under PIPEDA. We maintain internal procedures to detect, contain, and respond to privacy breaches in a timely manner.
Children's privacy
The Services are intended for individuals who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with information, please contact us and we will promptly delete it.
Marketing communications
From time to time, we may send you email communications about Chexy products, services, or promotions in accordance with Canada's Anti-Spam Legislation (CASL). You can opt out at any time by clicking the unsubscribe link in any marketing email or by contacting us at privacy@chexy.co. Please note that transactional and account-related messages are not subject to opt-out.
Governing law
This Policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, including the Personal Information Protection and Electronic Documents Act (PIPEDA). If you are a resident of Quebec, additional rights may apply under Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25).
Changes to this policy
We may update this Privacy Policy periodically. If we make material changes, we will notify you by email or through a notice on our Services before they take into effect. Continued use of the Services after that date means you accept the updated Policy.
Contact us
If you have questions, wish to exercise your rights, or want to make a complaint about how we handle your personal information, please contact us:
Email: privacy@chexy.co | Website: www.chexy.co
Last Updated: April 6, 2026
At Chexy, we take your privacy seriously. This Privacy Policy explains what personal information we collect, why we collect it, and how we use and share it. It covers your use of the Chexy mobile application (the "App"), website (the "Website"), and all related features and services (collectively, the "Services").
This Policy remains in effect for as long as we hold your information, even after you stop using the Services. By providing us with your personal information, you are consenting to the collection, use, and sharing of your personal information as set out in this Policy.
This Policy does not apply to information you submit directly to third parties, including the organizations and individuals with which you connect on the Services. Please refer to our Terms of Use for additional context.
What information we collect and when we collect it
Personal information
“Personal Information” is any information provided to us or generated within our Services or Website that personally identifies or could be used to identify an individual, such as your name or email address ("Personal Information"). We may combine Personal Information with other information we collect; when we do, we treat the combined information as Personal Information.
Examples of the personal information we collect include:
Identifiers: Name, date of birth, phone number, email address, and mailing or billing address
Identity verification information: Government-issued photo ID and Social Insurance Number (collected solely for tax payment processing)
Financial information: Bank account details, credit and debit card data (tokenized via Evervault in accordance with PCI DSS standards), and transaction history
Device and usage data: Device type, operating system, IP address, session interactions, approximate location, push notification tokens, and product usage
Biometric data: If you enable biometric login on the App (e.g. Face ID or fingerprint), this is processed locally on your device and never stored on our servers
Rewards information: Your Aeroplan number, if you choose to provide it
Communications: Any information you share when contacting us
Some of this information is collected on our behalf by third-party service providers. See the "Where we send your personal information" section for more detail.
Other information
Other information is data that does not directly identify you on its own. When we combine Other Information with Personal Information, we treat the combined data as Personal Information. We, and our third-party service providers, collect information automatically through our Services.
This may include information, such as:
Product interaction data: Features used, pages visited, and actions taken within the App and Website.
Log data: IP address, browser type, operating system, device identifiers, and referring URLs.
Cookies and tracking technologies: Data collected via cookies and similar technologies to allow our Services to recognize whether you have visited the Website before; it may also store user preferences and information. You can manage cookie preferences through your browser settings.
Approximate location: Inferred from your IP address.
How we use your information
We use the information we collect to:
Provide, maintain, and improve our Services, including processing household bill payments (e.g. rent, utilities, property taxes) and supporting credit building
Verify your identity and prevent fraud and financial abuse
Process transactions and send related communications, including payment confirmations and receipts
Administer your account and fulfill the terms of any agreement with us
Communicate with you, including sending security alerts, support messages, and service updates
Send you personalized marketing communications by email, where you have consented
Analyze usage patterns and product interactions to improve the App and Website
Report your payment history to credit bureaus (e.g. Equifax) with your consent, as part of our credit building feature
Comply with legal obligations, including our obligations as a registered Money Services Business (MSB) under FINTRAC
De-identify your information for internal reporting and trend analysis
Where we send your personal information
We do not sell your personal information to third parties. We share it only where necessary to deliver our Services, and never for third-party advertising or profit.
We may share your information with:
Payment Processors: We share your financial information with Zum Rails, Peoples Trust Company (PTC), Worldpay, and American Express to process bill payments on your behalf. These providers handle your data solely for payment processing purposes.
Identity Verification and Authentication: We use Plaid for identity verification, Trulioo for business identity verification (Chexy for Business), and Clerk for authentication and account management. All data collected through these third parties is handled in accordance with their respective privacy policies.
Credit Reporting: With your consent, we share your payment history with Equifax for the purpose of rent reporting and credit building. You may withdraw your consent at any time.
Communications and Support Providers: We use SendGrid and Customer.io for transactional and marketing email communications, respectively, and Intercom for customer support. These providers may have access to your name, email address, and interaction history for the purpose of delivering these services.
Analytics and Monitoring: We use Google Analytics and BigQuery for analytics and reporting, Statsig for feature flagging and experimentation, and Datadog for application monitoring and performance tracking. Datadog may collect IP address, device info, and session data that can be linked to individual accounts through real user monitoring (RUM). We limit logging of personal information where possible, though during troubleshooting we may temporarily capture additional data.
Rewards: If you provide your Aeroplan number, we share your name, Aeroplan number, and eligible transaction information with Air Canada to facilitate reward redemption.
Legal Obligations: We may disclose your information if required by law, court order, or a valid request from a government authority, or where we believe disclosure is necessary to prevent fraud, protect safety, or enforce our Terms of Use.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, in accordance with applicable law.
Where we store your data
Your information is stored on servers maintained by our cloud service providers, predominantly located in Canada and the United States. Many of our service providers are located outside of Canada. While we use appropriate safeguards to keep your information secure, the laws in other places may differ from those in Canada and authorities in those jurisdictions may access your information in accordance with their local laws.
How we protect your information
We maintain appropriate administrative, technical, and physical safeguards designed to protect your personal information from unauthorized access, use, modification, and disclosure. These include compliance with PCI DSS standards for handling payment card data and an annual SOC 2 Type 2 audit covering the security, availability, and confidentiality of our systems. While we take all reasonable steps to protect your data, no transmission over the internet is completely secure.
Data retention
We retain your personal information for as long as necessary to fulfill the purposes described in this Policy, or as required by law:
Active account data: Retained for the duration of your account.
Financial and identity records: Retained for 7 years after account closure, in accordance with CRA and FINTRAC requirements.
Marketing data: Once you opt out, we will not send you any further marketing communications.
All other data: Deleted or de-identified when no longer necessary.
If you request deletion of your personal data, it may not be possible to completely remove all information due to technological or legal constraints. We will take all reasonable steps to securely destroy or de-identify your information where full deletion is not possible.
Your rights
You have the right to:
Access the personal information we hold about you
Correct or update inaccurate information
Request deletion of your personal data
Withdraw your consent to certain uses of your data, including credit bureau reporting
Object to or restrict our processing of your data
Lodge a complaint with us or a relevant regulatory authority
To exercise any of these rights, log into your account and visit your profile settings, or contact us at privacy@chexy.co. We will respond within 10 business days.
Data breach notification
In the event of a data breach that poses a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada (OPC) as required under PIPEDA. We maintain internal procedures to detect, contain, and respond to privacy breaches in a timely manner.
Children's privacy
The Services are intended for individuals who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with information, please contact us and we will promptly delete it.
Marketing communications
From time to time, we may send you email communications about Chexy products, services, or promotions in accordance with Canada's Anti-Spam Legislation (CASL). You can opt out at any time by clicking the unsubscribe link in any marketing email or by contacting us at privacy@chexy.co. Please note that transactional and account-related messages are not subject to opt-out.
Governing law
This Policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, including the Personal Information Protection and Electronic Documents Act (PIPEDA). If you are a resident of Quebec, additional rights may apply under Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25).
Changes to this policy
We may update this Privacy Policy periodically. If we make material changes, we will notify you by email or through a notice on our Services before they take into effect. Continued use of the Services after that date means you accept the updated Policy.
Contact us
If you have questions, wish to exercise your rights, or want to make a complaint about how we handle your personal information, please contact us:
Email: privacy@chexy.co | Website: www.chexy.co