2. What we collect
Account information: name, work email, company, and role when you register or are invited to a tenant. Passwords are stored only as secure cryptographic hashes — we cannot read them.
Customer Data processed on behalf of tenants: records your organization stores in the platform (deals, projects, commissions, documents, contacts). For this data we act as a service provider to the tenant, which remains responsible for it.
Contact data about your organization's clients and counterparties: names, email addresses, and phone numbers of buyers, sellers, brokers, vendors, and other deal parties that your organization records in the platform.
Identity-verification records: where your organization uses FINTRAC compliance workflows, the platform stores identity-verification records — including metadata about government-issued identification documents (document type, reference numbers, verification method, and dates) — created by your organization to meet its record-keeping obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA). These are among the most sensitive records on the platform: access requires dedicated compliance permissions, records cannot be casually deleted, and identification-document numbers are masked in audit logs.
Financial transaction records: deal financials, commission calculations, trust deposit and receipt-of-funds records, and related accounting entries that your organization records in the course of its transactions.
Usage and device information: log data, IP address, browser type, pages viewed, and feature interactions, used for security, troubleshooting, and product improvement.
Communications: messages you send us through contact, demo, or support forms.