PRIVACY POLICY
FP Operations Ltd. (FirmPay)
Last Updated: January 27, 2026
Address: 59 York Downs Dr., Toronto, Ontario, M3H 1H7
Website: www.firmpayfx.com
Email: info@firmpayfx.com
Introduction
FP Operations Ltd., doing business as “FirmPay” (“Company,” “we,” “us,” or “our”), is an Ontario corporation registered with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) as a money service business and with the Bank of Canada as a payment service provider.
We respect your privacy and are committed to protecting the confidentiality and security of the personal information entrusted to us in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), applicable provincial privacy laws, Canadian Anti-Spam Legislation (CASL), and the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA).
Section 1. Scope of This Policy
This policy describes how we collect, use, disclose, and protect personal information when you interact with our websites, applications, products, and programs (collectively, the “Services”).
It applies to:
- Visitors to or users of our website and mobile applications;
- Prospective and current customers (and their personnel) who use our foreign exchange and payment services;
- Service providers, business partners, and other third parties; and
- Individuals whose information we process on behalf of our customers (“Customer Data”).
Section 2. Information We Collect
We limit the collection of personal information to what is necessary for our business purposes and legal obligations. Types of information include:
- Identification & Contact Information: Name, date of birth, citizenship, residential/business address, email, telephone number, and unique identifiers (e.g., Social Insurance Number, only where required by law).
- Regulatory Compliance (KYC/KYB): Nationality, residency, occupation, beneficial ownership, source of funds/wealth, PEP/HIO disclosures, and copies of identity documents required under the PCMLTFA.
- Payment & Financial Data: Bank account and routing numbers, billing information, payment purpose, transaction timestamps, and details for payers/beneficiaries.
- Technical & Usage Data: IP address, login credentials, browser type/version, time-zone settings, operating system, and clickstream data (URLs, page response times, and interactions).
- Marketing & Communications: Preferences, survey responses, and interactions with our emails.
- Recruitment Data: Resumé details, background-check results, and references for job candidates.
Section 3. How We Collect Information
We collect information through:
- Direct Interactions: Information and supporting documents you provide by the onboarding process, filling in forms, registering for Services, or corresponding with us via phone or email.
- Automated Technologies: Usage details and IP addresses collected through cookies, web beacons, and other tracking technologies as you navigate our Website.
- Third-Party Sources: Data from credit bureaus, identity verification vendors, public records, and regulatory bodies to ensure accuracy and prevent fraud.
Section 4. Purposes & Legal Bases for Processing
We process personal information based on your consent, the performance of a contract, compliance with legal/regulatory obligations, or our legitimate business interests. Primary uses include:
- Providing Services: Setting up accounts, processing transactions, and providing customer support.
- Regulatory Compliance: Performing mandatory due diligence, transaction monitoring, and reporting to FINTRAC or other authorities.
- Security & Fraud Prevention: Detecting and mitigating suspicious activities and protecting the integrity of our Services.
- Communication & Marketing: Sending administrative notifications or promotional messages (where consent is obtained). You may opt out of marketing at any time.
Section 5. Disclosure and Transfer of Information
We do not sell or rent your personal information. We disclose it only:
- To Service Providers: Third parties performing services on our behalf (e.g., cloud hosting, payment processing) who are contractually bound to protect your data.
- Within Our Corporate Group: To subsidiaries and affiliates (including FirmPay Inc.) for legitimate business purposes.
- For Legal/Safety Reasons: To comply with court orders, respond to government requests, or protect the rights and safety of FirmPay and our users.
- Business Transactions: In the event of a merger, sale, or transfer of assets.
Cross-Border Transfers: We may process or store information outside of Canada (e.g., in the United States). In these cases, your information may be subject to the laws and access rights of those foreign jurisdictions.
Section 6. Customer Data
When we process data on behalf of our customers, we do so strictly in accordance with our agreements with those customers. We do not control the privacy practices of our customers and encourage individuals to contact them directly with questions.
Section 7. Data Security and Safeguards
We use physical, electronic, and administrative measures proportional to the sensitivity of the information, including:
- Encryption of data in transit and at rest.
- Multi-factor authentication and role-based access controls.
- Network monitoring and an Incident Response Plan within the RPAA Operational Risks framework.
- User Responsibility: You are responsible for keeping your account password confidential.
Section 8. Data Retention
We retain personal information only as long as necessary to fulfill the purposes for which it was collected or to satisfy legal requirements. Specifically, we must retain certain identification and transaction records for at least five (5) years to comply with the PCMLTFA.
Section 9. Your Rights and Choices
Subject to limited legal exceptions, you have the right to:
- Access: Request the personal information we hold about you.
- Correction: Request updates to inaccurate or incomplete information.
- Withdrawal of Consent: Withdraw your consent to data processing at any time, though this may limit our ability to provide certain Services.
- Opt-Out: Unsubscribe from marketing communications via the provided links or by contacting us.
Section 10. Cookies and Tracking Technologies
We use cookies and similar technologies to remember preferences, conduct analytics (via tools like Google Analytics), and improve website performance. You can manage cookie settings through your browser, though disabling them may affect website functionality.
Section 11. Automated Decision-Making
We do not make decisions with significant legal effects solely through automated means. If such processing is introduced, we will provide transparency regarding the logic involved and your rights.
Section 12. Contact Information
For questions or to exercise your rights, please contact our Privacy Officer at:
Email: privacy@firmpayfx.com Attention: Privacy Officer
If you are dissatisfied with our response, you may contact the Office of the Privacy Commissioner of Canada (OPC) at www.priv.gc.ca or 1-800-282-1376.
