Privacy & information handling
Data Retention & Safeguards Policy
1. Purpose and scope #
This policy explains how Instant Record Check retains and protects personal information used for identity verification, criminal record checks, accounts, support, and related operations. It applies to applicants, people whose information is processed, and organizations using the platform. Retention is subject to applicable privacy, consumer-reporting, accounting, and other legal requirements.
2. Retention principles #
We retain information only for as long as reasonably necessary for the purposes for which it was collected, evidence and authentication, security, dispute handling, legal obligations, and other lawful needs. A completed report may be retained for evidence or authentication; it is not reused as a new criminal record check. Different systems and copies may be deleted at different times.
For personal-information-agent activity in Quebec, the applicable statutory seven-year period measured from collection is a maximum, not a minimum. This legal maximum is distinct from the seven-year operational period measured from check completion or record creation.
3. Safeguards relevant to retained information #
Information in transit is protected using TLS, and scheduled external backup archives are encrypted. Access controls and other technical and organizational safeguards are calibrated to the sensitivity of the information. The production database and PDF filesystem are not encrypted at rest.
4. Current operational configuration #
The current configuration uses a seven-year period for criminal record checks and linked identity and TransUnion information. The period is measured from completion for information linked to a completed check and from creation for unlinked information; accounts remain while linked data exists. Long-horizon cleanup for screening files is currently handled in review mode, and automatic deletion is not yet enforced by that mechanism. Requests concerning screening-file deletion are handled under applicable legal duties, including statutory response deadlines. Scheduled external encrypted backups are configured to expire after approximately 30–35 days, but that period does not apply to every operational copy or snapshot.
Consent, order, support, request, incident, security, accounting, and communications records are retained as long as reasonably necessary for their purposes and applicable legal or evidentiary obligations. Some shorter-lived records are deleted automatically: session tokens after 30 days, failed-login records after 90 days, certain entity-less audit context after 90 days, and advertising click identifiers in checkout and conversion records after 90 days. Provider retention periods, API-log periods, analytics-retention maxima, and request-register periods may differ.
5. Identity-verification data #
Quebec identity verification currently uses TransUnion knowledge-based questions. The verification flow exchanges questions, choices, and answers and produces a pass/fail result; Instant Record Check may retain the raw response for diagnostics. Outside Quebec, Stripe Identity is primary and TransUnion may be a fallback. Stripe hosts the ID and selfie capture and comparison flow, while Instant Record Check receives outcomes and reason codes in the routine platform flow. Provider retention is governed by the provider’s service and applicable arrangements.
6. Reports, copies, and sharing #
Reports are generated and delivered by the Instant Record Check platform based on the result determined by a partner municipal police service. They reflect the issuance date and are retained for evidence and authentication, not for a new check. A result is shared with the named partner organization only after the applicant’s separate express opt-in. Withdrawal stops authorized future sharing prospectively but does not retrieve copies already disclosed or undo lawful processing.
7. Deletion and backups #
Information must be deleted when its purpose and applicable retention obligations end, subject to legal requirements. Scheduled external encrypted backups are configured to expire after approximately 30–35 days; this period does not apply to every backup, system, provider copy, operational copy, or log, and deleting information from production does not immediately remove every other copy.
Where a provider holds a copy and deletion is required, a request may be sent through applicable contractual or operational mechanisms. A legal hold does not override a statutory maximum; any continued retention must remain lawful.
8. Location and cross-border processing #
Primary application and database hosting is in Quebec and operations are in British Columbia. We use providers including Stripe, TransUnion, OVH, Netlify, SendGrid, Klaviyo, Intercom, PostHog, Sentry, Google, and Microsoft. These providers may process information outside Quebec and Canada, including in the United States and the European Union; we use PostHog’s European Union hosting region. Foreign processing may subject information to the laws and lawful access rules of those jurisdictions.
9. Quebec and incidents #
The French Privacy Policy and applicable Quebec law govern Quebec privacy procedures. The privacy officer is the Chief Executive Officer. Quebec-related questions may be sent to confidentialite@instantrecordcheck.ca. If a confidentiality or security incident occurs, Instant Record Check works to contain and assess it, and notifies the applicable regulator and affected persons when the serious-harm threshold or another legal duty requires notification. Required incident records are maintained.
10. Contact and review #
Questions about retention, deletion, safeguards, or personal information may be sent to privacy@instantrecordcheck.ca or, for Quebec-related matters, confidentialite@instantrecordcheck.ca. The policy may be updated when practices or legal obligations change. If activities cease, the privacy officer oversees the handling and secure destruction of personal information under applicable retention duties and any required notice to the Commission d’accès à l’information. A transfer of files remains subject to the consent and other requirements of applicable law.