Last updated: August 1, 2026
This policy explains what personal information 1000087914 Ontario Inc., operating as BrokrPay ("BrokrPay", "we", "us"), collects, how we use and share it, and your rights — in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada's Anti-Spam Legislation (CASL). It applies to the BrokrPay platform and related services (the "Services"), including when the Services are presented under a brokerage's own brand or domain — branding does not change who processes your information or how.
1. The four layers of data on BrokrPay
BrokrPay serves brokerages, their agents, and their staff — and, through the transactions module, holds records about the buyers, sellers, landlords and tenants those professionals represent. Who "controls" information depends on the layer, and there are four:
- Your account and billing data — your name, email, credentials, RECO number, payment records: BrokrPay is the controller. We decide how this information is used, as described here.
- Brokerage-administered data — your roster record, charges your brokerage posts, documents your brokerage manages, shifts and schedules: your brokerage directs this data and BrokrPay processes it on the brokerage's behalf to provide the Services.
- Agent Contact Data — data an agent collects about their own clients, leads, and contacts: the agent is the controller and BrokrPay is a processor acting on the agent's instructions. Contact Data is private to the agent: it is not accessible to the brokerage, other agents, or BrokrPay staff outside of platform operations. Agents are responsible for required notices and consents to their contacts.
- Transaction Party Data — information about the parties to a real-estate trade that appears in a brokerage's transaction records: client names, government identification documents, property addresses, prices and deposits, dates, and signatures contained in agreements and related paperwork. The individuals this information describes are usually not BrokrPay users — a buyer or seller named on an Agreement of Purchase and Sale has no account with us, has not signed up, and has not agreed to anything with BrokrPay. This layer is not Agent Contact Data: it is the brokerage's trade record, which the brokerage is required to create and keep under Ontario real-estate law.
- The brokerage is the controller of Transaction Party Data; BrokrPay is a processor, holding and displaying it on the brokerage's instructions to provide the Services.
- The brokerage — not BrokrPay — is responsible for the notices its clients received and the consents they gave, including any consent to have their identification and agreements held by a service provider on the brokerage's behalf.
- If you are a client of a brokerage and you want to access, correct, or ask questions about information about you held in a transaction record, contact the brokerage. Requests that come to BrokrPay directly will be referred to the brokerage that controls the record, and we will assist the brokerage in responding.
2. Information we collect
You provide: name and legal name, email, password (stored hashed), phone; RECO registration number and expiry; brokerage affiliation; birthday (only where your brokerage enables the birthdays feature); profile photo (optional); signed agreement records (franchise agreement, PAD agreements) including signature name, timestamp, and IP; documents you upload; messages, notes, and support communications; vendor suggestions; dispute descriptions.
Transactions (deal folders): where your brokerage enables the transactions module, we collect and store, on the brokerage's behalf, the contents of its deal files — the property address (which names the folder), MLS number, client name(s), deal type, deal status, and deal dates (listing expiry, sold-conditional date, closing date); the documents uploaded against each deal's checklist, which by design include sensitive categories such as government-issued client identification ("Client IDs"), FINTRAC forms, Agreements of Purchase and Sale, Form 801, trade record sheets, and lease agreements; deal notes exchanged between the agent and brokerage staff about the file; and the annotations a reviewer places on a document (numbered comment pins, freehand pen marks, and highlight boxes, stored as overlay data — the original file is never modified), together with the reviewer's decision, reason for rejection, and full name. Uploads are limited to PDF, PNG, and JPEG files up to 100 MB each; the files themselves are held in a private storage bucket and are opened only through short-lived signed links. Much of this is Transaction Party Data (Section 1) and is controlled by the brokerage.
Preferences: your profile photo where you choose to upload one, and your saved dashboard layout and display preferences.
Billing: handled by our payment processor, Stripe. We never store full card or bank account numbers — we store the payment-method brand, last four digits, expiry, and Stripe references, plus your complete charge, receipt, refund, and dispute history (amounts, dates, statuses, HST).
Collected automatically: log and usage data, IP address, browser/device information; authentication events; audit logs of significant actions (who did what, when); staff clock-in network address where the brokerage enables location-validated punch; email delivery events (sent, suppressed, bounced).
From third parties: payment events from Stripe (payment outcomes, refund and dispute status); information your brokerage enters about you when building its roster or posting charges.
3. How we use information
To operate, maintain, and secure the Services; to bill and collect fees, issue receipts, process refunds, and resolve disputes; to remit your brokerage's share of payments to it; to provide workplace features your brokerage enables; to send service, security, billing, and account messages; to provide support; to detect and prevent fraud and abuse; to comply with law (including tax record-keeping); and to monitor and improve the Services.
We do not sell personal information. We do not use your data for third-party advertising.
4. Notifications and email
We send transactional messages (payment confirmations and failures, receipts, dispute outcomes, account and security notices) as part of operating the Services — these are not marketing and are sent to all users. Marketing communications, if any, are sent only with consent as required by CASL, and always include an unsubscribe mechanism. In-app notifications can be managed in your dashboard.
5. Cookies and similar technologies
We use strictly necessary cookies and local storage for authentication and session management. We use no third-party analytics and no advertising cookies. Disabling necessary cookies prevents sign-in.
6. How we share information
Only as needed to provide the Services, with providers bound by confidentiality and data-protection obligations:
- Stripe — payment processing, payouts to your brokerage's connected account, and payment-method storage.
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Resend — transactional email delivery.
- Your brokerage — sees your roster record, charge history for brokerage-billed items, documents in its vault, disputes on its charges, and workplace activity in features it administers. Your brokerage does not see your Contact Data, your private notes, or payment-method details beyond what its billing role requires.
- Legal — where required by law, to enforce our Terms, protect rights and safety, or in a merger/acquisition/asset sale (with notice where required).
Who can see a transaction folder. A deal folder an agent creates is visible only to that agent until the agent presses "Send to office." Before that point the brokerage cannot see the folder, its documents, or its contents. Sending to the office is one-way and cannot be undone. Once a folder has been sent — and for any folder the brokerage itself creates — it is visible to every brokerage seat granted the transactions capability, not only to the agent's own manager; those seats can open, review, annotate, export, and change the status of the folder. Agents assigned to a folder see the folder's documents, review decisions, and the reviewer's full name.
Two things inside a folder are deliberately hidden from agents: a deal note a brokerage seat marks internal, and a checklist item a brokerage seat creates as internal. Internal notes and internal items are visible only to brokerage seats, are never sent to the agent, and are removed from agent-facing responses and exports on our servers rather than merely hidden in the interface.
7. White-label domains
When you use the Services on a brokerage-branded domain, your information is processed by BrokrPay identically to use on brokrpay.com. The brokerage whose brand appears has the access described in Section 6 — no more. The operator of the platform, and the entity responsible under this policy, is 1000087914 Ontario Inc. (operating as BrokrPay).
8. Administrative access and audit
Where the "view as" support feature is enabled by BrokrPay, a brokerage administrator may request a time-boxed "view as" session of one of their own agents' or staff members' accounts. A session opens only after the account holder confirms the request, and every session — who viewed, whom, and when — is recorded in the audit log. BrokrPay platform administrators access accounts only for support, security, and operations, and such access is logged.
Transaction activity feeds. Each deal folder carries its own activity record. Creating the folder, uploading or deleting a document, accepting or rejecting a document, adding annotations, changing the deal status or details, sending the folder to the office, and archiving it are each recorded with the full name of the person who did it and the time they did it. This record exists so that a brokerage can demonstrate who handled a trade file and when, and it is visible to brokerage seats and to the agents on the folder. Reviewers are not anonymous: when a document is accepted or rejected, or an annotation is shown to an agent, the reviewer's full name is displayed. Name records are kept even if the person's account is later deleted, so the history stays intelligible.
9. Data retention
- Active accounts: retained while your account exists.
- Financial records (charges, receipts, refunds, disputes, signed agreements): retained after account closure or deletion for accounting, tax, and legal purposes (generally seven years for tax records in Canada), then deleted or de-identified.
- Transaction records (deal folders, uploaded documents, review decisions, annotations, notes, and activity history): kept, not destroyed. Because a brokerage must retain its trade records under Ontario real-estate legislation, the transactions module is built to preserve them: a document that is "deleted" is soft-deleted — hidden from the working checklist while the underlying record and file are retained — and a folder that is closed out is archived, never hard-deleted. Retained for at least six years from the applicable date, consistent with TRESA record-keeping requirements for trade records, and thereafter subject to the brokerage's instructions. One exception: an agent may permanently delete a folder they created before it has been sent to the office — at that point it is a private draft the brokerage has never seen and no trade record has been filed; the folder and its uploaded files are then destroyed, including from file storage.
- Permanent deletion: when an account is permanently deleted, access ends, the associated payment profile at Stripe is deleted (the account can never be billed again), and personal data outside the retained financial records is removed. Where one login holds multiple roles, deletion of one role preserves the others.
- Logs: operational and audit logs are retained for 24 months, then deleted or aggregated.
10. Security
Safeguards include encryption in transit (TLS) and at rest, hashed passwords, role-based access control with row-level security in the database, scoped administrative access, and audit logging. Uploaded transaction documents are held in a private storage area that is not publicly reachable and are served only through links that expire after a few minutes. No system is perfectly secure; we cannot guarantee absolute security.
Breach notification. If personal information in our custody is lost, accessed, or disclosed without authorization and the breach creates a real risk of significant harm to an individual, we will notify the affected individuals and report the breach to the Office of the Privacy Commissioner of Canada, as soon as feasible, as PIPEDA requires. Where the information is controlled by a brokerage (Section 1), we will notify the brokerage so it can meet its own obligations. We maintain records of every breach of security safeguards involving personal information, whether or not it triggers notification, and make those records available to the Commissioner on request.
11. Where your information is stored, and international transfers
Your information is stored in Canada. The BrokrPay production database and the file storage that holds your uploaded documents — including every transaction document — are hosted by Supabase in its Canadian region (`ca-central-1`). Records at rest, including deal folders, client identification, agreements, receipts, and messages, reside in Canada.
Some processing nonetheless takes place outside Canada:
- Vercel hosts the application itself. Requests are served from Vercel's infrastructure in the United States and pass through its global edge network, so information in transit — including the contents of pages and files you view or upload — is processed in the United States on its way to and from the Canadian database.
- Stripe processes payments and stores payment methods on its own infrastructure, principally in the United States, and works with card networks and banks internationally.
- Resend delivers our transactional email from infrastructure in the United States; the contents of an email and the recipient's address are processed there.
Where personal information is processed outside Canada it remains subject to our contractual safeguards with those providers, and it may be accessible to the courts, law enforcement, and national security authorities of that country under its laws. Personal information transferred to a provider for processing remains under BrokrPay's control and protection, and your rights under PIPEDA are unaffected.
12. Your rights
Subject to PIPEDA, you may request access to, correction of, or deletion of your personal information, or withdraw consent (subject to legal and contractual limits — for example, financial records we must retain, and data your brokerage controls, for which we will refer you to the brokerage — this includes all Transaction Party Data described in Section 1, and records we are required to preserve as a brokerage's trade records under Section 9). Contact us via Section 15; we respond within 30 days and may need to verify your identity. If unresolved, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca).
13. Children's privacy
The Services are for real-estate professionals and brokerage staff and are not directed to children. We do not knowingly collect children's personal information.
14. Changes to this policy
We may update this policy; we will post the updated version, revise the "Last updated" date, and give additional notice of material changes (email or in-app).
15. Contact
Privacy Officer, 1000087914 Ontario Inc. (operating as BrokrPay), 80 Eastern Ave, Brampton, ON L6W 1X9, Canada — info@brokrpay.com.