Privacy Policy

Effective Date: March 15th, 2023

Last Updated: April 6, 2026

At Chexy, we take your privacy seriously. This Privacy Policy explains what personal information we collect, why we collect it, and how we use and share it. It covers your use of the Chexy mobile application (the "App"), website (the "Website"), and all related features and services (collectively, the "Services").

This Policy remains in effect for as long as we hold your information, even after you stop using the Services. By providing us with your personal information, you are consenting to the collection, use, and sharing of your personal information as set out in this Policy.

This Policy does not apply to information you submit directly to third parties, including the organizations and individuals with which you connect on the Services. Please refer to our Terms of Use for additional context.

What information we collect and when we collect it


Personal information

“Personal Information” is any information provided to us or generated within our Services or Website that personally identifies or could be used to identify an individual, such as your name or email address ("Personal Information"). We may combine Personal Information with other information we collect; when we do, we treat the combined information as Personal Information.

Examples of the personal information we collect include:

  • Identifiers: Name, date of birth, phone number, email address, and mailing or billing address

  • Identity verification information: Government-issued photo ID and Social Insurance Number (collected solely for tax payment processing)

  • Financial information: Bank account details, credit and debit card data (tokenized via Evervault in accordance with PCI DSS standards), and transaction history

  • Device and usage data: Device type, operating system, IP address, session interactions, approximate location, push notification tokens, and product usage

  • Biometric data: If you enable biometric login on the App (e.g. Face ID or fingerprint), this is processed locally on your device and never stored on our servers

  • Rewards information: Your Aeroplan number, if you choose to provide it

  • Communications: Any information you share when contacting us

Some of this information is collected on our behalf by third-party service providers. See the "Where we send your personal information" section for more detail.


Other information

Other information is data that does not directly identify you on its own. When we combine Other Information with Personal Information, we treat the combined data as Personal Information. We, and our third-party service providers, collect information automatically through our Services. 

This may include information, such as:

  • Product interaction data: Features used, pages visited, and actions taken within the App and Website.

  • Log data: IP address, browser type, operating system, device identifiers, and referring URLs.

  • Cookies and tracking technologies: Data collected via cookies and similar technologies to allow our Services to recognize whether you have visited the Website before; it may also store user preferences and information. You can manage cookie preferences through your browser settings.

  • Approximate location: Inferred from your IP address.


How we use your information


We use the information we collect to:

  • Provide, maintain, and improve our Services, including processing household bill payments (e.g. rent, utilities, property taxes) and supporting credit building

  • Verify your identity and prevent fraud and financial abuse

  • Process transactions and send related communications, including payment confirmations and receipts

  • Administer your account and fulfill the terms of any agreement with us

  • Communicate with you, including sending security alerts, support messages, and service updates

  • Send you personalized marketing communications by email, where you have consented

  • Analyze usage patterns and product interactions to improve the App and Website

  • Report your payment history to credit bureaus (e.g. Equifax) with your consent, as part of our credit building feature

  • Comply with legal obligations, including our obligations as a registered Money Services Business (MSB) under FINTRAC

  • De-identify your information for internal reporting and trend analysis


Where we send your personal information

We do not sell your personal information to third parties. We share it only where necessary to deliver our Services, and never for third-party advertising or profit.

We may share your information with:

  • Payment Processors: We share your financial information with Zum Rails, Peoples Trust Company (PTC), Worldpay, and American Express to process bill payments on your behalf. These providers handle your data solely for payment processing purposes.

  • Identity Verification and Authentication: We use Plaid for identity verification, Trulioo for business identity verification (Chexy for Business), and Clerk for authentication and account management. All data collected through these third parties is handled in accordance with their respective privacy policies.

  • Credit Reporting: With your consent, we share your payment history with Equifax for the purpose of rent reporting and credit building. You may withdraw your consent at any time.

  • Communications and Support Providers: We use SendGrid and Customer.io for transactional and marketing email communications, respectively, and Intercom for customer support. These providers may have access to your name, email address, and interaction history for the purpose of delivering these services.

  • Analytics and Monitoring: We use Google Analytics and BigQuery for analytics and reporting, Statsig for feature flagging and experimentation, and Datadog for application monitoring and performance tracking. Datadog may collect IP address, device info, and session data that can be linked to individual accounts through real user monitoring (RUM). We limit logging of personal information where possible, though during troubleshooting we may temporarily capture additional data.

  • Rewards: If you provide your Aeroplan number, we share your name, Aeroplan number, and eligible transaction information with Air Canada to facilitate reward redemption.

  • Legal Obligations: We may disclose your information if required by law, court order, or a valid request from a government authority, or where we believe disclosure is necessary to prevent fraud, protect safety, or enforce our Terms of Use.

  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, in accordance with applicable law.


Where we store your data

Your information is stored on servers maintained by our cloud service providers, predominantly located in Canada and the United States. Many of our service providers are located outside of Canada. While we use appropriate safeguards to keep your information secure, the laws in other places may differ from those in Canada and authorities in those jurisdictions may access your information in accordance with their local laws.


How we protect your information

We maintain appropriate administrative, technical, and physical safeguards designed to protect your personal information from unauthorized access, use, modification, and disclosure. These include compliance with PCI DSS standards for handling payment card data and an annual SOC 2 Type 2 audit covering the security, availability, and confidentiality of our systems. While we take all reasonable steps to protect your data, no transmission over the internet is completely secure.


Data retention

We retain your personal information for as long as necessary to fulfill the purposes described in this Policy, or as required by law:

  • Active account data: Retained for the duration of your account.

  • Financial and identity records: Retained for 7 years after account closure, in accordance with CRA and FINTRAC requirements.

  • Marketing data: Once you opt out, we will not send you any further marketing communications.

  • All other data: Deleted or de-identified when no longer necessary.

If you request deletion of your personal data, it may not be possible to completely remove all information due to technological or legal constraints. We will take all reasonable steps to securely destroy or de-identify your information where full deletion is not possible.


Your rights

You have the right to:

  • Access the personal information we hold about you

  • Correct or update inaccurate information

  • Request deletion of your personal data

  • Withdraw your consent to certain uses of your data, including credit bureau reporting

  • Object to or restrict our processing of your data

  • Lodge a complaint with us or a relevant regulatory authority

To exercise any of these rights, log into your account and visit your profile settings, or contact us at privacy@chexy.co. We will respond within 10 business days.


Data breach notification

In the event of a data breach that poses a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada (OPC) as required under PIPEDA. We maintain internal procedures to detect, contain, and respond to privacy breaches in a timely manner.


Children's privacy

The Services are intended for individuals who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with information, please contact us and we will promptly delete it.


Marketing communications

From time to time, we may send you email communications about Chexy products, services, or promotions in accordance with Canada's Anti-Spam Legislation (CASL). You can opt out at any time by clicking the unsubscribe link in any marketing email or by contacting us at privacy@chexy.co. Please note that transactional and account-related messages are not subject to opt-out.


Governing law

This Policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, including the Personal Information Protection and Electronic Documents Act (PIPEDA). If you are a resident of Quebec, additional rights may apply under Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25).


Changes to this policy

We may update this Privacy Policy periodically. If we make material changes, we will notify you by email or through a notice on our Services before they take into effect. Continued use of the Services after that date means you accept the updated Policy.


Contact us

If you have questions, wish to exercise your rights, or want to make a complaint about how we handle your personal information, please contact us:

Email: privacy@chexy.co | Website: www.chexy.co

Last Updated: April 6, 2026

At Chexy, we take your privacy seriously. This Privacy Policy explains what personal information we collect, why we collect it, and how we use and share it. It covers your use of the Chexy mobile application (the "App"), website (the "Website"), and all related features and services (collectively, the "Services").

This Policy remains in effect for as long as we hold your information, even after you stop using the Services. By providing us with your personal information, you are consenting to the collection, use, and sharing of your personal information as set out in this Policy.

This Policy does not apply to information you submit directly to third parties, including the organizations and individuals with which you connect on the Services. Please refer to our Terms of Use for additional context.

What information we collect and when we collect it


Personal information

“Personal Information” is any information provided to us or generated within our Services or Website that personally identifies or could be used to identify an individual, such as your name or email address ("Personal Information"). We may combine Personal Information with other information we collect; when we do, we treat the combined information as Personal Information.

Examples of the personal information we collect include:

  • Identifiers: Name, date of birth, phone number, email address, and mailing or billing address

  • Identity verification information: Government-issued photo ID and Social Insurance Number (collected solely for tax payment processing)

  • Financial information: Bank account details, credit and debit card data (tokenized via Evervault in accordance with PCI DSS standards), and transaction history

  • Device and usage data: Device type, operating system, IP address, session interactions, approximate location, push notification tokens, and product usage

  • Biometric data: If you enable biometric login on the App (e.g. Face ID or fingerprint), this is processed locally on your device and never stored on our servers

  • Rewards information: Your Aeroplan number, if you choose to provide it

  • Communications: Any information you share when contacting us

Some of this information is collected on our behalf by third-party service providers. See the "Where we send your personal information" section for more detail.


Other information

Other information is data that does not directly identify you on its own. When we combine Other Information with Personal Information, we treat the combined data as Personal Information. We, and our third-party service providers, collect information automatically through our Services. 

This may include information, such as:

  • Product interaction data: Features used, pages visited, and actions taken within the App and Website.

  • Log data: IP address, browser type, operating system, device identifiers, and referring URLs.

  • Cookies and tracking technologies: Data collected via cookies and similar technologies to allow our Services to recognize whether you have visited the Website before; it may also store user preferences and information. You can manage cookie preferences through your browser settings.

  • Approximate location: Inferred from your IP address.


How we use your information


We use the information we collect to:

  • Provide, maintain, and improve our Services, including processing household bill payments (e.g. rent, utilities, property taxes) and supporting credit building

  • Verify your identity and prevent fraud and financial abuse

  • Process transactions and send related communications, including payment confirmations and receipts

  • Administer your account and fulfill the terms of any agreement with us

  • Communicate with you, including sending security alerts, support messages, and service updates

  • Send you personalized marketing communications by email, where you have consented

  • Analyze usage patterns and product interactions to improve the App and Website

  • Report your payment history to credit bureaus (e.g. Equifax) with your consent, as part of our credit building feature

  • Comply with legal obligations, including our obligations as a registered Money Services Business (MSB) under FINTRAC

  • De-identify your information for internal reporting and trend analysis


Where we send your personal information

We do not sell your personal information to third parties. We share it only where necessary to deliver our Services, and never for third-party advertising or profit.

We may share your information with:

  • Payment Processors: We share your financial information with Zum Rails, Peoples Trust Company (PTC), Worldpay, and American Express to process bill payments on your behalf. These providers handle your data solely for payment processing purposes.

  • Identity Verification and Authentication: We use Plaid for identity verification, Trulioo for business identity verification (Chexy for Business), and Clerk for authentication and account management. All data collected through these third parties is handled in accordance with their respective privacy policies.

  • Credit Reporting: With your consent, we share your payment history with Equifax for the purpose of rent reporting and credit building. You may withdraw your consent at any time.

  • Communications and Support Providers: We use SendGrid and Customer.io for transactional and marketing email communications, respectively, and Intercom for customer support. These providers may have access to your name, email address, and interaction history for the purpose of delivering these services.

  • Analytics and Monitoring: We use Google Analytics and BigQuery for analytics and reporting, Statsig for feature flagging and experimentation, and Datadog for application monitoring and performance tracking. Datadog may collect IP address, device info, and session data that can be linked to individual accounts through real user monitoring (RUM). We limit logging of personal information where possible, though during troubleshooting we may temporarily capture additional data.

  • Rewards: If you provide your Aeroplan number, we share your name, Aeroplan number, and eligible transaction information with Air Canada to facilitate reward redemption.

  • Legal Obligations: We may disclose your information if required by law, court order, or a valid request from a government authority, or where we believe disclosure is necessary to prevent fraud, protect safety, or enforce our Terms of Use.

  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, in accordance with applicable law.


Where we store your data

Your information is stored on servers maintained by our cloud service providers, predominantly located in Canada and the United States. Many of our service providers are located outside of Canada. While we use appropriate safeguards to keep your information secure, the laws in other places may differ from those in Canada and authorities in those jurisdictions may access your information in accordance with their local laws.


How we protect your information

We maintain appropriate administrative, technical, and physical safeguards designed to protect your personal information from unauthorized access, use, modification, and disclosure. These include compliance with PCI DSS standards for handling payment card data and an annual SOC 2 Type 2 audit covering the security, availability, and confidentiality of our systems. While we take all reasonable steps to protect your data, no transmission over the internet is completely secure.


Data retention

We retain your personal information for as long as necessary to fulfill the purposes described in this Policy, or as required by law:

  • Active account data: Retained for the duration of your account.

  • Financial and identity records: Retained for 7 years after account closure, in accordance with CRA and FINTRAC requirements.

  • Marketing data: Once you opt out, we will not send you any further marketing communications.

  • All other data: Deleted or de-identified when no longer necessary.

If you request deletion of your personal data, it may not be possible to completely remove all information due to technological or legal constraints. We will take all reasonable steps to securely destroy or de-identify your information where full deletion is not possible.


Your rights

You have the right to:

  • Access the personal information we hold about you

  • Correct or update inaccurate information

  • Request deletion of your personal data

  • Withdraw your consent to certain uses of your data, including credit bureau reporting

  • Object to or restrict our processing of your data

  • Lodge a complaint with us or a relevant regulatory authority

To exercise any of these rights, log into your account and visit your profile settings, or contact us at privacy@chexy.co. We will respond within 10 business days.


Data breach notification

In the event of a data breach that poses a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada (OPC) as required under PIPEDA. We maintain internal procedures to detect, contain, and respond to privacy breaches in a timely manner.


Children's privacy

The Services are intended for individuals who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with information, please contact us and we will promptly delete it.


Marketing communications

From time to time, we may send you email communications about Chexy products, services, or promotions in accordance with Canada's Anti-Spam Legislation (CASL). You can opt out at any time by clicking the unsubscribe link in any marketing email or by contacting us at privacy@chexy.co. Please note that transactional and account-related messages are not subject to opt-out.


Governing law

This Policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, including the Personal Information Protection and Electronic Documents Act (PIPEDA). If you are a resident of Quebec, additional rights may apply under Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25).


Changes to this policy

We may update this Privacy Policy periodically. If we make material changes, we will notify you by email or through a notice on our Services before they take into effect. Continued use of the Services after that date means you accept the updated Policy.


Contact us

If you have questions, wish to exercise your rights, or want to make a complaint about how we handle your personal information, please contact us:

Email: privacy@chexy.co | Website: www.chexy.co

Last Updated: April 6, 2026

At Chexy, we take your privacy seriously. This Privacy Policy explains what personal information we collect, why we collect it, and how we use and share it. It covers your use of the Chexy mobile application (the "App"), website (the "Website"), and all related features and services (collectively, the "Services").

This Policy remains in effect for as long as we hold your information, even after you stop using the Services. By providing us with your personal information, you are consenting to the collection, use, and sharing of your personal information as set out in this Policy.

This Policy does not apply to information you submit directly to third parties, including the organizations and individuals with which you connect on the Services. Please refer to our Terms of Use for additional context.

What information we collect and when we collect it


Personal information

“Personal Information” is any information provided to us or generated within our Services or Website that personally identifies or could be used to identify an individual, such as your name or email address ("Personal Information"). We may combine Personal Information with other information we collect; when we do, we treat the combined information as Personal Information.

Examples of the personal information we collect include:

  • Identifiers: Name, date of birth, phone number, email address, and mailing or billing address

  • Identity verification information: Government-issued photo ID and Social Insurance Number (collected solely for tax payment processing)

  • Financial information: Bank account details, credit and debit card data (tokenized via Evervault in accordance with PCI DSS standards), and transaction history

  • Device and usage data: Device type, operating system, IP address, session interactions, approximate location, push notification tokens, and product usage

  • Biometric data: If you enable biometric login on the App (e.g. Face ID or fingerprint), this is processed locally on your device and never stored on our servers

  • Rewards information: Your Aeroplan number, if you choose to provide it

  • Communications: Any information you share when contacting us

Some of this information is collected on our behalf by third-party service providers. See the "Where we send your personal information" section for more detail.


Other information

Other information is data that does not directly identify you on its own. When we combine Other Information with Personal Information, we treat the combined data as Personal Information. We, and our third-party service providers, collect information automatically through our Services. 

This may include information, such as:

  • Product interaction data: Features used, pages visited, and actions taken within the App and Website.

  • Log data: IP address, browser type, operating system, device identifiers, and referring URLs.

  • Cookies and tracking technologies: Data collected via cookies and similar technologies to allow our Services to recognize whether you have visited the Website before; it may also store user preferences and information. You can manage cookie preferences through your browser settings.

  • Approximate location: Inferred from your IP address.


How we use your information


We use the information we collect to:

  • Provide, maintain, and improve our Services, including processing household bill payments (e.g. rent, utilities, property taxes) and supporting credit building

  • Verify your identity and prevent fraud and financial abuse

  • Process transactions and send related communications, including payment confirmations and receipts

  • Administer your account and fulfill the terms of any agreement with us

  • Communicate with you, including sending security alerts, support messages, and service updates

  • Send you personalized marketing communications by email, where you have consented

  • Analyze usage patterns and product interactions to improve the App and Website

  • Report your payment history to credit bureaus (e.g. Equifax) with your consent, as part of our credit building feature

  • Comply with legal obligations, including our obligations as a registered Money Services Business (MSB) under FINTRAC

  • De-identify your information for internal reporting and trend analysis


Where we send your personal information

We do not sell your personal information to third parties. We share it only where necessary to deliver our Services, and never for third-party advertising or profit.

We may share your information with:

  • Payment Processors: We share your financial information with Zum Rails, Peoples Trust Company (PTC), Worldpay, and American Express to process bill payments on your behalf. These providers handle your data solely for payment processing purposes.

  • Identity Verification and Authentication: We use Plaid for identity verification, Trulioo for business identity verification (Chexy for Business), and Clerk for authentication and account management. All data collected through these third parties is handled in accordance with their respective privacy policies.

  • Credit Reporting: With your consent, we share your payment history with Equifax for the purpose of rent reporting and credit building. You may withdraw your consent at any time.

  • Communications and Support Providers: We use SendGrid and Customer.io for transactional and marketing email communications, respectively, and Intercom for customer support. These providers may have access to your name, email address, and interaction history for the purpose of delivering these services.

  • Analytics and Monitoring: We use Google Analytics and BigQuery for analytics and reporting, Statsig for feature flagging and experimentation, and Datadog for application monitoring and performance tracking. Datadog may collect IP address, device info, and session data that can be linked to individual accounts through real user monitoring (RUM). We limit logging of personal information where possible, though during troubleshooting we may temporarily capture additional data.

  • Rewards: If you provide your Aeroplan number, we share your name, Aeroplan number, and eligible transaction information with Air Canada to facilitate reward redemption.

  • Legal Obligations: We may disclose your information if required by law, court order, or a valid request from a government authority, or where we believe disclosure is necessary to prevent fraud, protect safety, or enforce our Terms of Use.

  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, in accordance with applicable law.


Where we store your data

Your information is stored on servers maintained by our cloud service providers, predominantly located in Canada and the United States. Many of our service providers are located outside of Canada. While we use appropriate safeguards to keep your information secure, the laws in other places may differ from those in Canada and authorities in those jurisdictions may access your information in accordance with their local laws.


How we protect your information

We maintain appropriate administrative, technical, and physical safeguards designed to protect your personal information from unauthorized access, use, modification, and disclosure. These include compliance with PCI DSS standards for handling payment card data and an annual SOC 2 Type 2 audit covering the security, availability, and confidentiality of our systems. While we take all reasonable steps to protect your data, no transmission over the internet is completely secure.


Data retention

We retain your personal information for as long as necessary to fulfill the purposes described in this Policy, or as required by law:

  • Active account data: Retained for the duration of your account.

  • Financial and identity records: Retained for 7 years after account closure, in accordance with CRA and FINTRAC requirements.

  • Marketing data: Once you opt out, we will not send you any further marketing communications.

  • All other data: Deleted or de-identified when no longer necessary.

If you request deletion of your personal data, it may not be possible to completely remove all information due to technological or legal constraints. We will take all reasonable steps to securely destroy or de-identify your information where full deletion is not possible.


Your rights

You have the right to:

  • Access the personal information we hold about you

  • Correct or update inaccurate information

  • Request deletion of your personal data

  • Withdraw your consent to certain uses of your data, including credit bureau reporting

  • Object to or restrict our processing of your data

  • Lodge a complaint with us or a relevant regulatory authority

To exercise any of these rights, log into your account and visit your profile settings, or contact us at privacy@chexy.co. We will respond within 10 business days.


Data breach notification

In the event of a data breach that poses a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada (OPC) as required under PIPEDA. We maintain internal procedures to detect, contain, and respond to privacy breaches in a timely manner.


Children's privacy

The Services are intended for individuals who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with information, please contact us and we will promptly delete it.


Marketing communications

From time to time, we may send you email communications about Chexy products, services, or promotions in accordance with Canada's Anti-Spam Legislation (CASL). You can opt out at any time by clicking the unsubscribe link in any marketing email or by contacting us at privacy@chexy.co. Please note that transactional and account-related messages are not subject to opt-out.


Governing law

This Policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, including the Personal Information Protection and Electronic Documents Act (PIPEDA). If you are a resident of Quebec, additional rights may apply under Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25).


Changes to this policy

We may update this Privacy Policy periodically. If we make material changes, we will notify you by email or through a notice on our Services before they take into effect. Continued use of the Services after that date means you accept the updated Policy.


Contact us

If you have questions, wish to exercise your rights, or want to make a complaint about how we handle your personal information, please contact us:

Email: privacy@chexy.co | Website: www.chexy.co