Privacy Policy

Last updated: July 13, 2026

1. Introduction

IF Advisory App ("we", "us", or "our") is a financial advisory and insurance services platform operated by your assigned advisor. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal and financial information when you use our application and related services (the "Service"). We are committed to protecting your privacy in accordance with applicable Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and provincial privacy legislation.

2. Information We Collect

We collect the following categories of information:

  • Identity information: full name, date of birth, sex, marital status, dependents, and government-issued identification details (e.g., driver's license, passport, PR card).
  • Contact information: email address, phone number, and residential/mailing address.
  • Financial information: income, occupation, employer, assets, debts, expenses, bank account details, risk tolerance, and financial goals.
  • Health and lifestyle information: height, weight, smoking status, and medical history relevant to insurance underwriting.
  • Account credentials: email and password used to authenticate your account within the Service.
  • Usage data: device information, pages visited, and interaction data collected through the Service.

3. How We Use Your Information

  • To provide financial planning, needs analysis, and insurance advisory services.
  • To prepare illustrations, recommendations, and compliance documentation.
  • To communicate with you regarding appointments, follow-ups, and service updates.
  • To fulfill regulatory, compliance, and "know your client" (KYC) obligations.
  • To integrate with third-party services such as Google Calendar and Google Meet, where you have authorized such connections, for the purpose of scheduling and conducting advisory meetings.
  • To improve the quality and security of the Service.

4. Legal Basis for Processing

We process your personal information based on your consent, for the performance of a contract (advisory services), and to comply with legal and regulatory obligations applicable to financial and insurance professionals in Canada.

5. Sharing and Disclosure

We do not sell your personal information. We may share your information with:

  • Insurance carriers and managing general agencies (MGAs) for the purpose of policy application and underwriting.
  • Service providers who support our operations (e.g., cloud hosting, email delivery) under appropriate data protection agreements.
  • Regulatory authorities when required by law.
  • Third-party applications (such as Google Calendar/Meet) only to the extent you explicitly authorize through OAuth consent.

6. Data Retention

We retain your personal information for as long as necessary to provide the Service and to meet legal, regulatory, and professional liability requirements, which may extend beyond the termination of our advisory relationship.

7. Data Security

We implement reasonable administrative, technical, and physical safeguards to protect your information, including encryption in transit, access controls, and row-level data isolation tied to your account. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your Rights

You have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate or incomplete information.
  • Withdraw consent for certain processing activities, subject to legal or contractual restrictions.
  • Request deletion of your information, where legally permissible.

9. Google API Data Disclosure

The Service offers an optional integration with Google Calendar and Google Meet to help you schedule advisory meetings and generate video conferencing links. This section explains in detail what Google data is accessed, how it is used, and the controls available to you.

9.1 Data Collected from Google

When you connect your Google account, the application only accesses Google Calendar events that are created or managed by you through the scheduling feature. Specifically, we may access:

  • Google Calendar event details (title, date, time, description) for events created or updated via the Service.
  • Google Meet conferencing data (meeting links and dial-in information) generated when you request a video meeting.
  • Your Google account email address, solely for the purpose of authenticating the connection.

We do not access your emails, contacts, documents, photos, drive files, or any Google data outside of the calendar events you create through this Service.

9.2 Purpose of Collection

The data is used solely to create and manage Google Calendar events and generate Google Meet links requested by you. We do not use Google data for advertising, analytics profiling, or any purpose unrelated to the scheduling feature.

9.3 Data Sharing

We do not sell, rent, or share Google user data with advertisers, data brokers, or unrelated third parties. Google Calendar data accessed through this integration is used exclusively within the Service to provide the requested scheduling functionality. Event details may be visible to your assigned advisor for the purpose of coordinating meetings, but are never shared externally beyond what you explicitly authorize.

9.4 Data Retention

Calendar data is retained only as long as necessary to provide the requested scheduling functionality. Event information is stored within the Service for the duration of the event lifecycle and for a limited period thereafter to support appointment records and compliance documentation. Users may disconnect Google Calendar at any time, after which no further Google data will be accessed.

9.5 Data Deletion

Users may revoke Google access at any time from their Google Account permissions page, which immediately prevents the Service from accessing any additional Google data. Users may also contact us to request deletion of any Google data stored within the Service, and we will process such requests in accordance with applicable privacy laws.

9.6 Security

Google data is protected using industry-standard security measures, including:

  • HTTPS: All data transmissions between your device, our servers, and Google's APIs are encrypted using HTTPS/TLS.
  • Encrypted transmission: OAuth tokens and API requests are transmitted over secure, encrypted channels.
  • OAuth 2.0: Authentication is performed exclusively through Google's OAuth 2.0 protocol — we never see or store your Google password.
  • Least privilege access: We request only the minimum Google API scopes required to create calendar events and generate Meet links, and no additional scopes.

9.7 Google API Limited Use Statement

The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

10. Children's Privacy

The Service is not directed to individuals under the age of 18, and we do not knowingly collect personal information from minors.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the Service and updating the "Last updated" date above.

12. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact your assigned advisor through the Service or at the contact details provided during onboarding.