Your clients' information is stored in Canada, encrypted, and used only to provide PolicyStream to you. We never sell it or use it for advertising. You, the advisor, decide what is collected and are responsible to your clients for it; we act on your behalf and follow your instructions.
1. Who we are
PolicyStream is operated by Policy Stream Inc., Calgary, Alberta, Canada. We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where they apply, provincial private-sector privacy laws, including those of Alberta, British Columbia and Quebec. We are following proposed federal privacy reform (currently Bill C-36, the Protecting Privacy and Consumer Data Act), which is not yet law, and will update our practices and this policy if and when new requirements come into force. Our Privacy Officer is accountable for our compliance and can be reached at [email protected].
2. Two kinds of information
Information about our customers and visitors. When advisors and brokerage staff create accounts, or anyone visits our website, we decide how that information is used and we are responsible for it under this policy.
Information about advisors' clients ("Client Data"). When an advisor uses PolicyStream to collect information from their clients, the advisor (and their brokerage) decides what is collected and why, and is responsible for it. We process Client Data as a service provider on the advisor's behalf and only on their instructions, under our Terms of Service (Schedule A sets out our data processing commitments). If you are a client of an advisor who uses PolicyStream, please contact your advisor first about your information; we will help them respond.
3. Information about advisors and visitors
- Account information: name, email, phone, brokerage, licence details you choose to provide, role and login and MFA settings.
- Billing information: plan, billing contact and payment history. Card details are collected and stored by our payment processor; we do not store full card numbers.
- Usage and device information: log data such as IP address, browser, pages and features used, and security events, used to run, secure and improve the Service.
- Communications: messages you send us and support requests.
- Consent records: the version of our Terms and this policy you accepted, when, and the IP address and browser used.
- Website information: basic analytics about visits to policystream.ca (see section 11).
4. Client information we process for advisors
Depending on how the advisor uses the Service, Client Data can include identity and contact details, date of birth, government ID images, beneficiary and ownership details, financial information, banking details for premium payments, insurance history, and health and lifestyle answers, as well as signatures, uploaded documents and related audit records (such as time, IP address and device information when a client opens a link or signs).
We use Client Data only to provide the Service to the advisor: to store it, show it to authorized users, generate documents, send messages the advisor requests, enter it into carrier forms when the advisor uses Autofill, secure the Service, provide support when asked, and meet legal obligations. We do not sell Client Data, use it for advertising, use it to contact clients for our own purposes, or share it with carriers or other third parties except at the advisor's direction or as set out in this policy.
5. How we use information
We use information about advisors and visitors to: provide and bill for the Service; authenticate users and protect accounts; provide support; send service, security and billing notices; improve the Service (including through de-identified, aggregated statistics); send product news and offers only with your consent as required by Canada's anti-spam legislation (CASL), with an unsubscribe link in every such email that we act on within 10 business days (service, security and billing messages are not marketing and continue while you have an account); and comply with law. We rely on your consent, which may be implied by your use of the Service where appropriate, and you may withdraw it subject to legal and contractual limits, although that may mean we cannot provide the Service.
6. Service providers and disclosure
We use a small number of service providers that process information on our behalf under written agreements requiring confidentiality and appropriate safeguards:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Application hosting, database, file storage, backups and email delivery (Amazon SES) | Canada (Central) |
| Helcim | Subscription payments | Canada |
| Compulife (when enabled) | Life insurance quote data; receives quote inputs only (such as age, sex, smoker status, province, amount and term), never names or contact details | Canada / United States |
| Cloudflare | Marketing website delivery and cookieless website analytics (no Client Data) | Global network |
We may also disclose information: when the advisor directs us to (for example, sending documents to a client or entering answers into a carrier form); to comply with law, a court order or a regulator's lawful request; to protect the rights, safety or security of our users, the public or PolicyStream; or to a successor in a merger, acquisition or sale of assets, under equivalent protections.
7. Where information is stored
Client Data, documents and backups are stored in Canada in the AWS Canada (Central) region. Emails from the Service are sent from the same Canadian region; once delivered, a message is handled by the recipient's own email provider, which may be outside Canada. Two limited exceptions: requests to the app pass through Amazon CloudFront edge locations in North America and Europe (encrypted in transit, not stored), and security records of requests that our web application firewall blocks or flags (IP address, web address requested and browser details, with sign-in tokens removed) are kept for 30 days in AWS's US East region, because AWS only offers that firewall there. Our marketing website is delivered through Cloudflare's global network, which does not receive Client Data. Information handled outside Canada may be accessible to courts and authorities there. You can ask our Privacy Officer about our use of service providers outside Canada.
8. Security
We protect information with safeguards appropriate to its sensitivity, including encryption in transit and at rest, two-step sign-in (optional for everyone and required for owners and admins of accounts with two or more people), role-based access, client links that expire and need a one-time email code on a new device, audit logging, a web application firewall, monitoring, backups and restricted, logged production access. No system is perfectly secure; see our Security page for more detail and for the responsibilities we share with advisors.
9. Retention
Advisors decide how long Client Data is kept while their account is active and can export or delete records. When an account closes, the advisor has 30 days to export their data; we then delete it from active systems within 90 days and from backups on their normal rotation, unless the law requires us to keep it. If an account is locked because a payment failed or a trial ended, we keep its data for 90 days from the lock so the advisor can pay and continue or ask us for an export; after that we may delete it in the same way. We keep account, billing and consent records for as long as needed for legal, tax and accounting purposes. Database backups are kept for up to 30 days and server logs for up to 90 days.
10. Your rights
You may ask to access or correct the personal information we hold about you, ask how it has been used and disclosed, or withdraw consent, by emailing our Privacy Officer. We will respond within 30 days (or tell you if we need the extra time the law allows). This policy is available in other formats on request. Clients of an advisor should contact that advisor, who controls their information; if you contact us, we will forward your request to them. You may also complain to the Office of the Privacy Commissioner of Canada or your provincial privacy commissioner.
11. Cookies and analytics
The PolicyStream app uses your browser's local storage (not advertising cookies) only for what it needs to work: keeping you signed in, remembering a trusted device and your selected brokerage. Our marketing website uses Cloudflare Web Analytics, which counts visits in aggregate without cookies and without tracking individuals across sites. We do not use Google Analytics or advertising pixels. We do not use advertising cookies in the app or client portal, and Client Data is never sent to analytics or advertising tools.
12. Autofill (beta) for Google Chrome
PolicyStream Autofill is our add-on for the Google Chrome browser, available in the Chrome Web Store. It enters a client's submitted answers into an insurance carrier's online application in the advisor's browser. It works only after the advisor connects it to their PolicyStream account with a personal access key, which they can revoke at any time in Settings.
- What it reads: the submitted applications the advisor can already see in PolicyStream (names, contact details, dates of birth, health and lifestyle answers and, where given, banking details for pre-authorized payments), and the wording of the questions on the carrier's application page, to check that each question still matches before filling it.
- Where it sends information: only into the carrier application the advisor has open, and to PolicyStream. If a carrier's question wording has changed, it sends PolicyStream the carrier name, the question and its new wording and the carrier site's host name (never the full page address or the client's answers) so we can review the change.
- What it stores: the advisor's access key, saved in their browser on their device. The selected client's answers are kept only in the browser's temporary memory and are cleared when Chrome closes.
- What it never does: submit an application, request signatures, tick a consent box, sell or share information, use it for advertising or any purpose other than filling the carrier application, or use it to determine creditworthiness or for lending.
Our use of information received from the add-on follows the Chrome Web Store User Data Policy, including its Limited Use requirements.
13. Breaches
We protect information with the safeguards described in section 8. If we become aware of a breach of security safeguards involving information we hold, we will contain it, assess the risk of harm and keep a record of every breach for at least 24 months (PIPEDA s. 10.3). For Client Data, we act as the advisor's service provider: we notify the advisor's brokerage without delay with the information they need, and support them in notifying their clients and the Privacy Commissioner, because the brokerage decides whether there is a real risk of significant harm and who must be told. For information we are responsible for, where there is a real risk of significant harm we will report to the Office of the Privacy Commissioner of Canada (and the Alberta Information and Privacy Commissioner or other commissioner where required) and notify affected individuals as soon as feasible.
14. Children
PolicyStream accounts are for adults working in insurance. Client Data can include information about minors (for example, a child insured or a beneficiary); the advisor collects it from a parent or guardian and is responsible for the consent.
15. Changes and contact
We may update this policy and will post the new version here with a new date. For material changes we will notify account owners by email or in the Service before they take effect, and ask users to accept the new version in the app.
Privacy Officer, Policy Stream Inc., Calgary, Alberta, Canada · [email protected]