1. Purpose
This policy defines how CanadaRentals.cc retains, manages, and securely disposes of personal information and consumer financial data. It ensures compliance with PIPEDA, Ontario legislation, and Plaid Inc.'s data handling requirements.
2. Guiding Principles
- Data Minimization — We collect only what is necessary for the stated purpose
- Purpose Limitation — Data is used only for the purpose consented to
- Storage Limitation — Data is retained only as long as necessary
- Security — All retained data is protected by appropriate safeguards
- Accountability — The Privacy Officer enforces this policy and documents disposal
3. Data Retention Schedule
Data category
Examples
Retention
Disposal method
Account data
Name, email, phone, login credentials
+2 yrs
Secure DB deletion; email confirmation sent
Tenant applications
Rental applications, references, employment
90 days
Automated purge from database
Financial data (Plaid)
Bank accounts, balances, transactions, income
90 days
Plaid token revoked via API; data purged
Identity verification
Government ID images, selfies, IDV results
90 days
Deleted from platform; provider instructed to purge
LTB legal documents
N4 notices, generated forms, filings
7 years
Secure deletion after mandatory period
Landlord listings
Property listings, photos, descriptions
+1 yr
Removed from database and storage
Platform usage logs
IP addresses, page views, error logs
90 days
Automated log rotation and deletion
Payment records
Transaction IDs, billing history
7 years
Encrypted retention; purged after 7 years
Support comms
Emails and help requests
2 years
Secure deletion from email systems
4. Consumer Financial Data (Plaid)
Plaid access tokens are stored as encrypted environment variables — never in application code or logs. They are revoked via the Plaid /item/remove API upon consumer request, application withdrawal, or expiry of the 90-day retention window.
Token management
- Only data fields necessary for verification are requested from Plaid
- Revocation is logged with timestamp in the audit log
- Raw financial data is not retained beyond the 90-day window
Consumer rights
- Request revocation and deletion at any time via help@canadarentals.cc
- Financial data deletion processed within 72 hours
- All other data deletion processed within 30 days
- Written confirmation of deletion sent by email
5. Disposal Methods
Database records
- Permanently deleted using SQL DELETE operations with post-deletion confirmation
- Database backups containing deleted records purged within 30 days
File and document storage
- Uploaded documents deleted from cloud storage with CDN cache invalidation
Third-party processors
- Written deletion request submitted to Certn, Verifast, or other processors used
- Confirmation of third-party deletion retained in audit log for 1 year
6. Requesting Deletion
Submit a deletion request at any time:
We will acknowledge within 5 business days, verify your identity, execute deletion, and send written confirmation. Certain records may be exempt where retention is legally required.
7. Policy Review
Reviewed annually by the Privacy Officer, or sooner following a material change to data practices, applicable legislation, or a security incident. Questions: help@canadarentals.cc