Privacy Policy
Version 1.0 · Effective date: June 10, 2026
Beta-period draft. A finalized, lawyer-reviewed version will replace this before general availability. Email privacy@preveio.com with questions.
1. Introduction
Preve.io, operating as Preve.io ("Company," "we," "us," or "our"), is committed to protecting the privacy of individuals whose personal information is processed through our platform. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the Preve.io platform (the "Service").
This Privacy Policy applies to: (a) mortgage brokers and agents who use the Service ("Brokers"); and (b) mortgage applicants whose documents are uploaded to the Service by their Broker ("Applicants"). We process Applicant data as a processor on behalf of the Broker (the controller).
By using the Service, you consent to the collection, use, and disclosure of personal information as described in this Privacy Policy. For Applicants, consent is obtained by your Broker before your documents are uploaded.
2. Information We Collect
We collect and process the following categories of personal information:
- (a) Broker Account Information. Name, email address, phone number, brokerage name, license number, province or state of licensure, and payment information (processed by Stripe; we do not store full payment card numbers).
- (b) Applicant Financial Documents. Documents uploaded by Brokers on behalf of Applicants, which may include: pay stubs, tax slips (T4, W-2), employment letters, bank statements, government-issued identification, purchase agreements, and other mortgage-related documents. These documents contain sensitive personal information including Social Insurance Numbers (SIN), Social Security Numbers (SSN), income amounts, employment details, banking information, and government identification numbers.
- (c) Extracted Data. Structured data extracted from uploaded documents by our AI-powered document processing system, including financial figures, dates, names, addresses, employer information, and account details.
- (d) Usage Data. Information about how you interact with the Service, including pages viewed, features used, session duration, browser type, operating system, IP address, and device information. This data is collected through analytics tools as described in our Cookie Policy.
3. How We Use Personal Information
We use personal information solely to provide and operate the Service. Specifically:
- Document Processing: To classify, extract data from, and validate uploaded mortgage documents using artificial intelligence.
- Lender Matching: To compare extracted applicant financial profiles against lender underwriting criteria and generate match assessments.
- Account Management: To create and manage Broker accounts, process payments, and provide customer support.
- Service Operations: To maintain, monitor, and improve the security, performance, and reliability of the Service.
- Communications: To send transactional emails (account verification, password resets, processing notifications) and, with consent, product updates.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
4. How We Do Not Use Personal Information
We do not use personal information, including uploaded documents and extracted data, to train artificial intelligence or machine learning models. We do not sell, rent, or trade personal information to third parties. We do not use personal information for advertising or marketing purposes unrelated to the Service.
5. Data Sharing and Sub-Processors
We share personal information only with the third-party sub-processors necessary to provide the Service. We require each sub-processor to maintain appropriate security measures and to process data only as instructed by us. Our current sub-processors are:
- (a) Supabase (Supabase Inc.). Purpose: Database hosting, user authentication, and file storage. Data processed: All Broker account data, Applicant documents, extracted data, and application records. Location: United States (AWS infrastructure).
- (b) Vercel (Vercel Inc.). Purpose: Application hosting and content delivery. Data processed: HTTP request metadata (IP addresses, user agent strings). Location: United States (global edge network).
- (c) Anthropic (Anthropic PBC). Purpose: AI-powered document classification and data extraction (Claude API). Data processed: Document content submitted for analysis. Anthropic does not use API inputs to train its models. Location: United States.
- (d) Google Cloud (Google LLC). Purpose: Optical Character Recognition (Document AI) for scanned documents only. Data processed: Scanned document images requiring OCR. Location: United States.
- (e) Resend (Resend Inc.). Purpose: Transactional email delivery. Data processed: Recipient email addresses and email content. Location: United States.
- (f) Sentry (Functional Software Inc.). Purpose: Error monitoring and application performance tracking. Data processed: Error logs, stack traces, and limited request metadata. We configure Sentry to exclude personal information from error reports. Location: United States.
- (g) PostHog (PostHog Inc.). Purpose: Product analytics (usage patterns, feature adoption). Data processed: Anonymized usage events and session data. PostHog is initialized only after you consent to analytics cookies. Location: United States.
6. Data Retention
We retain personal information only as long as necessary to fulfill the purposes described in this Privacy Policy. Our specific retention periods are:
- Broker Account Data: Retained for the duration of your active account plus twelve (12) months after account closure or subscription termination, to allow for account reactivation and to address any post-termination inquiries.
- Applicant Documents and Extracted Data: Retained for two (2) years from the date of upload, or until the Broker deletes the associated application, whichever comes first. Brokers may delete application data at any time through the Service.
- Usage and Analytics Data: Retained for twenty-four (24) months in an anonymized or aggregated form.
- Payment Records: Retained for seven (7) years as required by tax and financial reporting obligations.
- Audit Logs (consent records, access logs): Retained for five (5) years for regulatory compliance.
7. Data Security
We implement technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption at rest (AES-256) for all stored documents and extracted data.
- Encryption in transit (TLS 1.3) for all data transmitted between your browser and our servers.
- Row-Level Security (RLS) policies in our database to ensure data isolation between Broker accounts.
- Multi-factor authentication (MFA) for Broker accounts.
- Role-based access controls limiting employee access to personal information to those with a legitimate business need.
- Regular security assessments and vulnerability testing.
8. Cookies and Tracking Technologies
We use cookies and similar technologies as described in our Cookie Policy. Essential cookies are necessary for the Service to function and cannot be disabled. Analytics cookies are used only with your prior consent. You can manage your cookie preferences at any time through the cookie settings accessible from any page of the Service.
9. International Data Transfers
The Service is operated from Canada. Personal information may be transferred to and processed in the United States through our sub-processors listed in Section 5. We ensure that such transfers are subject to appropriate safeguards, including contractual commitments requiring sub-processors to protect personal information to a standard substantially similar to the protections provided under Canadian privacy law.
By using the Service, you acknowledge and consent to the transfer of your personal information to the United States for processing by our sub-processors.
10. Your Rights Under Canadian Privacy Law (PIPEDA)
If you are located in Canada, you have the following rights under the Personal Information Protection and Electronic Documents Act (PIPEDA):
- Access: You may request access to the personal information we hold about you.
- Correction: You may request correction of inaccurate or incomplete personal information.
- Withdrawal of Consent: You may withdraw your consent to the collection, use, or disclosure of your personal information, subject to legal or contractual restrictions. Withdrawal of consent may limit your ability to use the Service.
- Complaint: You may file a complaint with the Office of the Privacy Commissioner of Canada (OPC) if you believe your privacy rights have been violated.
11. Your Rights Under United States Privacy Laws
If you are located in the United States, you may have additional rights depending on your state of residence. This section describes the rights available under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and similar state privacy laws.
(a) Categories of Personal Information. In the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA: Identifiers (name, email, IP address); Financial Information (payment data processed by Stripe); Professional Information (license number, brokerage affiliation); Internet Activity (usage data, analytics); and Sensitive Personal Information (SIN/SSN, financial documents uploaded on behalf of Applicants).
(b) Your Rights. You have the right to: (i) Know what personal information we collect, use, and disclose about you; (ii) Request deletion of your personal information, subject to certain exceptions; (iii) Correct inaccurate personal information; (iv) Opt out of the sale or sharing of your personal information (we do not sell or share personal information for cross-context behavioral advertising); (v) Limit the use of sensitive personal information to purposes necessary to provide the Service; and (vi) Not be discriminated against for exercising your privacy rights.
(c) Exercising Your Rights. To exercise your rights, contact us at privacy@preveio.com or submit a request through the privacy settings in your account. We will verify your identity before processing your request. We will respond to verifiable consumer requests within forty-five (45) days. We do not sell personal information and have not sold personal information in the preceding 12 months.
(d) Other State Laws. Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and other states with comprehensive privacy laws may have similar rights. Contact us at privacy@preveio.com to exercise any applicable rights.
12. Data Breach Notification
In the event of a data breach involving personal information, we will: (a) investigate the breach promptly; (b) take steps to contain and remediate the breach; (c) notify the Office of the Privacy Commissioner of Canada and any other applicable regulatory authority within seventy-two (72) hours of becoming aware of a breach that creates a real risk of significant harm; (d) notify affected individuals as required by applicable law; and (e) maintain a record of all breaches.
13. Children
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete that information promptly.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated Privacy Policy on our website and notify you of material changes by email or in-app notification at least thirty (30) days before the changes take effect. We encourage you to review this Privacy Policy periodically.
15. Contact Us
If you have questions or concerns about this Privacy Policy or our privacy practices, please contact us at:
Preve.io
Privacy Officer: privacy@preveio.com
General Inquiries: support@preveio.com
Website: https://preveio.com