1. Scope
This Policy explains how VirePay handles personal information when it provides its payment-orchestration and loan-servicing technology to business customers (lenders) in Canada, including Quebec.
VirePay is a technology and orchestration platform. It is not the lender, it does not become the lender because it processes borrower information on a lender's instructions, and it is not a bank, a payment provider or a financial institution.
This Policy applies to the VirePay web application, APIs and supporting infrastructure. It does not apply to a lender's own systems, to a loan-management system such as CreditBook SLOAN, or to a payment provider or financial institution, each of which has its own privacy practices.
2. Our role
For information about its own business customers, users and platform security — for example account registration, authentication, support and audit — VirePay determines the purposes of processing and acts on its own behalf.
For borrower and loan information supplied by a lender or its approved systems, VirePay generally processes that information for and on the instructions of the lender.
In the approved product architecture, VirePay does not:
- lend money or broker loans;
- own lender capital;
- hold or custody lender funds, or maintain a pooled VirePay balance;
- receive borrower funds for its own account;
- determine what a borrower owes;
- make underwriting or credit decisions.
Actual money movement is performed through the connected payment provider or financial institution, never by VirePay. No production payment provider is currently connected, so provider-dependent processing is described as unconfirmed rather than as a current production fact throughout this Policy.
The precise legal characterization of each role under federal and provincial privacy legislation, including Quebec's Law 25 and PIPEDA, and the allocation of responsibilities in a data processing agreement, is not settled in this draft.
Outstanding review: LEGAL REVIEW REQUIREDOutstanding review: PROVIDER CONFIRMATION REQUIRED
3. The Funding Wallet
A lender's Funding Wallet is a lender-specific funding account, wallet, subaccount or segregated balance held with — or reported by — the payment provider or financial institution serving that lender. VirePay reads provider-reported balances and transaction statuses and displays them to the lender as part of the orchestration workflow.
The Funding Wallet is not a VirePay wallet. The underlying funds are not held by VirePay, are not VirePay's property and never form part of a pooled VirePay balance. In the current sandbox, no provider is connected and all balances and transactions are simulated.
Outstanding review: PROVIDER CONFIRMATION REQUIRED
4. Money-movement workflows
VirePay orchestrates, records, tracks, reconciles and reports payment instructions. It does not take possession of funds at any point. The approved workflows are:
- Loan funding: the lender's loan-management system (LMS) instructs VirePay, and VirePay instructs the payment provider. Funds move from the lender's provider-held Funding Wallet or account, through the payment provider, to the borrower's bank;
- Collections: the LMS instructs VirePay, and VirePay instructs the payment provider. Funds move from the borrower, through the payment provider, to the lender's Funding Wallet or account;
- Transfer to bank: where supported and configured, funds move from the Funding Wallet or account, through the payment provider, to the lender's verified external business bank account.
For each workflow the platform records the instruction state, the provider outcome, any return or reversal, and reports the confirmed outcome back to the LMS.
Outstanding review: PROVIDER CONFIRMATION REQUIRED
6. Information we collect and process
Based on an inventory of the current application, the following categories are collected or processed:
- User account information: name, email address, account status and organization membership;
- Authentication information: the email address used as the sign-in identifier, password credentials handled by our authentication provider, session tokens, and sign-in verification state — the status of a verification challenge, the number of code entry attempts and resends, expiry times and the record that a session was verified. VirePay's own records do not store the verification code itself, any hash of it, or any password;
- Business customer information: lender organization name, configuration, roles, permissions and team membership;
- Borrower information supplied by the lender: name, contact details, borrower reference identifiers and loan relationship;
- Loan and servicing information: loan references, original principal, outstanding principal, contractual amounts, schedules and versions supplied by the authoritative system, servicing events, deferrals, holds, delinquency or default state, write-off status, amount and date as reported by the lender or its LMS, and payoff records;
- Payment information: payment instructions, attempts, statuses, settlement, return, NSF and reversal results, payment references, and principal, interest and fee allocations supplied by the LMS;
- Post-write-off recovery information: recovery events recorded as later events against the original loan reference;
- Funding and transfer information: provider-reported Funding Wallet balances and transaction statuses, and Transfer to Bank instructions and their status;
- Bank-related identifiers where supplied for a payment workflow, including masked or referenced account information;
- PAD authorization records and evidence documents uploaded by the lender, stored in a private, non-public bucket;
- Provider and integration references: payment-provider transaction identifiers, LMS identifiers, source-system identifiers and external record identifiers;
- Reconciliation information: source records, matches, exceptions and resolution history;
- Security and audit logs: append-only audit events recording who did what and when, and evidence-access events;
- Technical information processed by our hosting, authentication and infrastructure providers, which may include IP address, device and browser information, and request logs;
- Support communications, where a user contacts us.
7. What we do not do
- We do not perform credit checks and do not obtain credit-bureau information.
- We do not make credit or underwriting decisions and do not decide whether a borrower is approved.
- We do not determine what a borrower owes; amounts due are supplied by the authoritative lender or LMS.
- We do not decide that a borrower loan should be written off; a write-off is recorded only as reported by the authoritative lender or LMS.
- We do not sell personal information, and we do not use it for advertising or third-party marketing.
- The application currently sends no borrower emails or text messages; notification copy exists in the interface only.
- We do not collect lender licensing documentation merely because it might be useful. Any future collection would require a documented business, legal or provider requirement.
8. Why we process information
- to provide, operate, configure and support the VirePay platform;
- to authenticate users, to send and verify sign-in verification codes and password-reset messages by email, and to enforce verified sessions, permissions and tenant isolation;
- to process authorized payment and servicing workflows submitted by a lender or an approved system;
- to maintain accurate transaction, schedule, ledger and servicing records;
- to manage PAD workflow state and store lender-supplied evidence;
- to perform reconciliation and to detect and resolve exceptions;
- to generate operational, reconciliation and accounting-support reports for the lender from authorized lending and payment records;
- to detect, investigate and prevent fraud, abuse and security incidents;
- to respond to support requests;
- to maintain audit history and satisfy record-keeping, legal, regulatory and contractual requirements;
- to maintain, secure, test and improve the reliability of the service, using the minimum information necessary.
Accounting-support reporting is limited to organizing and presenting authorized records. VirePay does not calculate the lender's income tax payable, does not determine whether a write-off is legally or tax deductible, does not make tax or accounting decisions for the lender, and does not automatically add GST/QST to loan principal. Where accounting classifications are required, the lender or its LMS supplies the authoritative classification.
We do not use personal information for undisclosed purposes, and we do not rely on open-ended wording such as "any purpose".
10. Data minimization
VirePay collects only the information reasonably necessary for the purposes above. Lenders are responsible for limiting the borrower information they submit to what their workflow requires. Fields that are not required by an approved workflow, a provider requirement or a legal obligation are not requested, and speculative fields are not added on the basis that they might be useful someday.
11. Platform operations access
A small number of VirePay platform operators use administrative tooling to keep the service reliable. Under the approved privacy model, normal platform-operations access provides technical health, status and error information — not a lender's private financial or borrower data.
Normal platform-operations access does not include borrower identity or contact information; Funding Wallet, available-to-lend or available-to-transfer balances; individual loan, collection, bank-transfer or deposit amounts; outstanding principal; interest, fee, write-off or post-write-off recovery amounts; lender business-bank details; or raw PAD or bank information. These restrictions are enforced in the backend data-selection layer, not merely by hiding fields on screen.
Exceptional live access to a lender's workspace for support is time-boxed, requires an explicit short-lived authorization from the lender, and is recorded in the audit history.
12. Service providers and subprocessors
VirePay uses service providers to deliver the platform. Categories currently in use or planned are:
- cloud hosting, application runtime and managed database services;
- managed authentication services, including delivery of sign-in verification codes and password-reset messages by email;
- file storage for PAD evidence, in a private bucket reachable only through short-lived, server-issued access;
- payment providers and financial institutions — none is connected as at the effective date of this draft;
- email, messaging or notification providers — none is connected as at the effective date of this draft;
- monitoring, logging and security services;
- customer support tooling;
- analytics — no analytics or tracking provider is integrated as at the effective date of this draft.
Outstanding review: PROVIDER CONFIRMATION REQUIREDOutstanding review: PRODUCTION CONFIGURATION REQUIRED
13. Subprocessor register
VirePay maintains an internal register of the service providers it uses, the categories of information each may process and the processing locations. The register is maintained as an internal control and is made available to business customers on request under confidentiality. Specific security architecture details are not published.
14. Processing locations and cross-border transfers
Information may be stored and processed on infrastructure operated by our hosting and authentication providers. The production hosting region, database region, storage region and edge processing locations are not fixed in this draft and must be confirmed and documented before production.
VirePay does not claim that all information always remains in Canada. Where information may be processed outside a person's province or outside Canada, that will be disclosed and supported by contractual and organizational measures.
Quebec-specific requirements, including any privacy impact assessment required before communicating personal information outside Quebec, are handled separately and are not treated as satisfied by this Policy.
Outstanding review: PRODUCTION CONFIGURATION REQUIREDOutstanding review: LEGAL REVIEW REQUIRED
15. Safeguards
VirePay applies administrative, technical and physical safeguards appropriate to the sensitivity of the information, including:
- role-based access control and least-privilege access;
- email-based verification of each sign-in, using expiring numeric codes with limited entry attempts and resends, and a server-side verified-session check that gates sensitive operations;
- row-level tenant isolation enforced in the database rather than in the browser;
- encryption in transit, and encryption at rest as provided by our hosting and storage providers;
- private storage for PAD evidence, accessed only through short-lived, server-issued links with access events recorded;
- append-only audit logging of security-relevant and financial events;
- server-side validation of every state change, with idempotency and duplicate protection;
- monitoring and secure development practices, including automated tests for isolation and authorization invariants.
Outstanding review: SECURITY REVIEW REQUIRED
16. Limits of our security statements
No system is completely secure, and VirePay does not claim that its platform is "100% secure" or "bank-grade". Internal controls have been tested internally; independent penetration testing and third-party assurance have not been completed. Detailed security architecture is not published because doing so would create risk.
Outstanding review: SECURITY REVIEW REQUIRED
17. Retention
Retention periods are set by purpose and by legal, financial, audit, security and contractual requirements. In general:
- account and user records are retained while the business relationship continues, and thereafter as required;
- financial records, payment instructions, attempts, results, ledger entries and reconciliation evidence are retained for the periods required by law, by an approved payment provider or by contract;
- PAD authorization records and evidence are retained as required for the authorization, related disputes and applicable payment-rule requirements;
- audit and security logs are retained for a defined period appropriate to investigation and legal needs;
- support communications are retained for a limited period.
Outstanding review: LEGAL REVIEW REQUIREDOutstanding review: PROVIDER CONFIRMATION REQUIRED
18. Destruction and anonymization
When retention is no longer required, information is securely destroyed or irreversibly anonymized. VirePay does not promise immediate deletion of records that must be retained for legal, financial or audit reasons, including after an account is closed.
19. Privacy rights
Individuals in Canada have rights in respect of their personal information. The specific rights available depend on which federal or provincial law applies and on the role in which VirePay processes the information.
- make a privacy inquiry;
- request access to personal information VirePay holds about them;
- request correction of inaccurate or incomplete information;
- withdraw consent where consent is the applicable authority and withdrawal is legally available, subject to legal and contractual limits;
- request information about automated processing, where applicable;
- make a complaint to VirePay and to the applicable privacy regulator.
Outstanding review: LEGAL REVIEW REQUIRED
20. Requests about borrower information
Where VirePay processes borrower information for a lender, a request from a borrower is normally directed to that lender, which holds the lending relationship and the underlying records. VirePay will assist the lender as required by contract and applicable law, and will not delete or alter records where the lender or the law requires retention.
21. Privacy Officer
VirePay designates a person responsible for privacy compliance. The following details must be set before production:
- Title: [PRODUCTION CONFIGURATION REQUIRED]
- Contact email: [PRODUCTION CONFIGURATION REQUIRED]
- Mailing address: [PRODUCTION CONFIGURATION REQUIRED]
- Quebec person-in-charge of the protection of personal information, where required: [PRODUCTION CONFIGURATION REQUIRED]
Outstanding review: PRODUCTION CONFIGURATION REQUIRED
22. Privacy incidents
VirePay maintains an incident-response process that records incidents, assessment and escalation evidence. Where a confidentiality incident presents a risk of serious injury or otherwise triggers a legal notification obligation, VirePay will notify the affected individuals, the applicable regulator and its business customers as required by applicable law and by contract.
VirePay does not promise notification for every security event; routine blocked attempts and unsuccessful probes are logged and investigated but are not incidents requiring notice.
Outstanding review: LEGAL REVIEW REQUIRED
24. Age and intended users
The VirePay platform is intended for business use by authorized personnel of business customers. It is not directed to children, and VirePay does not knowingly create platform accounts for minors.
Borrower information is supplied by lenders; any age requirement applicable to a borrower is determined by the lender and the applicable lending law, not by VirePay. Final age-related wording is not settled in this draft.
Outstanding review: LEGAL REVIEW REQUIRED
25. Automated processing
VirePay does not perform automated credit decisions and does not use personal information to score, rank or profile borrowers for creditworthiness.
The platform automates technical workflow functions: receiving instructions from the LMS, validating workflow state, duplicate and idempotency protection, state transitions permitted by defined rules, suppression or holds where instructed by authoritative source data, provider status processing, reconciliation matching, and reporting confirmed outcomes to the LMS. These are operational workflow controls, not underwriting or independent loan-servicing decisions. VirePay does not independently generate a borrower's contractual repayment schedule.
26. Privacy impact assessments
VirePay maintains an internal requirement to complete a privacy impact assessment where required by applicable law or by internal policy, including before an information system project involving personal information, before a communication of personal information outside Quebec where applicable, and before onboarding a payment provider.
No assessment is claimed as completed. The assessments listed above are outstanding.
Outstanding review: LEGAL REVIEW REQUIRED
27. Changes to this Policy
Each published version carries a version number, an effective date and a last-updated date, and is archived. Historical versions are never rewritten. Material changes are communicated as required by applicable law and, where acknowledgement is collected, the acknowledgement is recorded against the specific version displayed.
28. Contact
Privacy inquiries, access and correction requests and complaints may be sent to the Privacy Officer at the contact details in section 21. Individuals may also contact the Office of the Privacy Commissioner of Canada or their provincial privacy regulator, including the Commission d'accès à l'information du Québec.
Outstanding review: PRODUCTION CONFIGURATION REQUIRED