RCIC App by Investatech — Privacy Policy
Last updated: July 27, 2026
This Privacy Policy explains how Investatech Inc. (“Investatech”, “we”, “us”) collects, uses, and protects personal information in connection with RCIC App by Investatech, the multi-tenant SaaS platform available at rcicapp.ca (formerly app.investatech.com) (the “Platform”). It applies to both our tenant customers (“Tenants”) and to the end-clients whose bookings, payments, or agreements pass through the Platform. Use of the Platform is governed by our Terms of Service.
About the product name. “RCIC App” is the name of a software product operated by Investatech Inc. Investatech is not a Regulated Canadian Immigration Consultant (RCIC), is not a law firm, and does not provide immigration, legal, or regulated professional advice. The Platform, the “RCIC App” name, and Investatech are independent of, and not endorsed by, sponsored by, or affiliated with, the College of Immigration and Citizenship Consultants (CICC), Immigration, Refugees and Citizenship Canada (IRCC), the Canada Border Services Agency (CBSA), the Immigration and Refugee Board of Canada (IRB), the Government of Canada, or any other regulator or government body. The licensed professional you engage (your Tenant) is the only party in this relationship who serves clients in a regulated capacity.
1. Our Role
When a Tenant uses the Platform to provide services to their own clients, the Tenant is the controller of their clients’ personal information and Investatech is a service provider (or processor under applicable law). Our handling of end-client data is governed by the Tenant’s own privacy notice. When the information in question is about the Tenant’s own account (email, password, business profile), Investatech is the controller.
When a Tenant enables the AI connector described in §11, the Tenant, as controller, decides whether its authorized users may disclose end-client information from draft Service Agreements to their own ChatGPT or Claude accounts. Investatech provides the technical mechanism and the controls. We do not decide which client records are sent, obtain consent from end-clients on the Tenant’s behalf, or control what the assistant provider does after receiving the information. The Tenant is responsible for ensuring that each disclosure is lawful, transparent, limited to what is necessary, and consistent with the Tenant’s CICC and other professional obligations.
2. Information We Collect
- Account information. Tenant email, password (hashed), business name, slug, timezone, currency, phone, address, website, logo, theme, and, if applicable, the regulated-consultant details (RCIC name, registration number, scope, languages) the Tenant chooses to store.
- Booking + invoice data. Client name, email, phone, notes, service selection, time slot, payment status, discount usage, additional-attendee details, and reference numbers. This is data the Tenant or their client submits through the Platform.
- Agreement snapshots. Text the client accepts (CICC or custom) and the timestamp of acceptance, retained as an audit record on the Tenant’s behalf.
- AI connector data flow. The AI connector does not collect a new category of end-client information or create a separate Investatech store of Service Agreement content. It allows an authorized Tenant user to disclose information already held in a draft Service Agreement to that user’s own ChatGPT or Claude account. We hold the OAuth connection information needed to operate the connection and the content-free audit metadata described in §11.
- Video conferencing connection data. When a consultant connects a Zoom account we hold the OAuth tokens, the Zoom account identifier, the account email address, and the granted permissions; and, per consultation, the Zoom meeting identifier and join link. Details and the reason each item is retained are in §4 under Video conferencing (Zoom).
- Attachments. Files (PDFs / images) a client uploads during an agreement flow are stored transiently in our private Supabase Storage bucket, emailed to both parties, and deleted from our storage after delivery. The email is the record of record.
- Transfer Room files. Files uploaded by the Tenant or by a client through the Transfer Room module (Premium subscribers) are encrypted under the Tenant’s per-tenant data key (DEK) and stored in our private Supabase Storage bucket for a limited window. See §6 for the retention timings. We never deliver Transfer Room files as email attachments, notifications carry only a link to the portal.
- Transfer Room portal access data. For each client portal session we hold: the participant email address (lookup key), the one-time 6-digit code hash, the verification timestamp, an HMAC-signed session cookie, and the IP address and user-agent of the authenticating device (for the audit log). The portal session expires after 30 minutes of inactivity.
- Payment metadata. We never see or store full card numbers. Stripe processes payments directly on the Tenant’s connected Stripe account; we retain only payment identifiers (intent IDs, status, amounts, refund history) needed to reconcile with the booking / invoice.
- Technical telemetry. Server logs (timestamps, request paths, status codes, IP address, user-agent), error traces, and aggregate analytics. We keep these for operational and security purposes.
3. How We Use Information
- To provide the Platform’s features to Tenants and their clients.
- To send transactional email (signup confirmation, password reset, booking confirmations, cancellations, reschedules, invoices, signed agreements, payment receipts).
- To detect, prevent, and respond to fraud, abuse, and security incidents, including rate-limiting and reCAPTCHA.
- To comply with legal obligations.
- To improve the Platform: we may analyze aggregate, de-identified usage patterns. We do not sell personal information and we do not use your content to train AI models.
4. Third-Party Services We Share With
We only share personal information with third parties that are necessary to deliver the Platform, or enable a disclosure to a connected service at the Tenant’s direction, and only for the purposes below. Each provider has its own privacy policy governing its processing.
- Supabase (hosting, Postgres database, authentication, object storage).
- Stripe / Stripe Connect (payment processing, identity verification of connected accounts).
- Google (Google Calendar for scheduling sync, Google OAuth for sign-in to Calendar, Google Drive, when the Tenant connects Drive from the Transfer Room module on the Premium tier, to copy received files into a folder the Tenant controls, and, when the Tenant uses Platform AI features available with the Premium tier, Google Gemini for document analysis and drafting assistance, and Google Translate for client-page translation).
- Anthropic (Claude API for Platform AI Service Agreement drafting assistance under Investatech’s paid API arrangement, and, separately, the Tenant user’s own Claude account when that user authorizes the AI connector).
- OpenAI (the Tenant user’s own ChatGPT account when that user authorizes the AI connector).
- Our SMTP provider (Siteground, for sending transactional email from info@investatech.com).
- Vercel (application hosting and CDN).
- Amazon Web Services (AWS) (S3 object storage and KMS key management for the RCIC Drive document storage module, hosted in the ca-central-1 (Montréal) region and replicated, as each firm is onboarded, to a separate Investatech-controlled AWS account in the ca-west-1 (Calgary) region for disaster recovery, both regions in Canada; AWS GuardDuty Malware Protection for S3 for on-upload malware scanning of files stored in RCIC Drive; SES, S3, SQS, and KMS for inbound-email processing, also hosted in ca-central-1). Document bytes and inbound email content processed via AWS remain in Canada.
- Zoom (video conferencing, when a consultant connects their own Zoom account, to create, update, and cancel the meeting for a consultation booked through the Platform).
- Google reCAPTCHA (bot protection on signup, password-reset, and booking-submission forms). When a form you submit is protected by reCAPTCHA, Google may collect device and browsing data subject to Google’s Privacy Policy and Terms of Service. Use of the Platform constitutes your acceptance of those terms for that purpose.
Video conferencing (Zoom)
If you connect your Zoom account, we store an access token and a refresh token issued by Zoom, together with your Zoom account identifier, the email address on that Zoom account, and the list of permissions you granted. The tokens are encrypted at rest using a key unique to your organization. We keep the account identifier because Zoom identifies you by it when you remove our application, and we need it to find and delete the right connection. We keep the account email so you can confirm which account is linked.
For each consultation booked through the Platform, we also store the Zoom meeting identifier and the join link, so that the meeting can be updated if the booking is rescheduled and cancelled if the booking is cancelled, and so the link can be shown to you and sent to your client.
We send Zoom only the meeting topic, start time, duration, and time zone. The meeting topic is the name of the service being booked, not the client’s name. We do not send client personal information, immigration case details, or documents to Zoom, and we do not access your meeting recordings, transcripts, participant lists, or meeting history. We do not store the host start link that Zoom returns when a meeting is created.
You may disconnect at any time from your integration settings; removing the application from your Zoom account also causes us to delete the stored credentials and the connection record.
5. International Transfers
The providers listed above may process information in the United States or other countries outside Canada. Information processed outside Canada may be subject to the laws of the foreign jurisdiction and may be accessible to its courts, law enforcement, or national security authorities.
For services Investatech contracts directly, where required, we rely on contractual or equivalent safeguards offered by the provider. The AI connector is different. Content sent through the connector goes to the Tenant user’s own OpenAI or Anthropic account under that user’s agreement with the provider, not under an Investatech paid API agreement. Investatech has no contract with the provider covering that connector content and cannot promise a comparable level of protection after the disclosure.
OpenAI and Anthropic may process AI connector content in the United States and in other locations identified in their policies. Before enabling or using the connector for client information, the Tenant is responsible for assessing the cross-border risks, giving the client any required notice, obtaining any required consent or authorization, and completing any assessment required by applicable law, including Quebec requirements where they apply.
By using the Platform you acknowledge the cross-border processing described in this section. This acknowledgement does not replace any notice, consent, or other legal authority that a Tenant must obtain from an end-client for a Tenant-directed disclosure through the AI connector.
6. Data Retention
- Active accounts: we keep account, booking, invoice, and agreement data for as long as the Tenant has an active account.
- After account deletion: we retain data for up to 90 days to allow reactivation, then it may be permanently deleted (see Terms §14).
- Agreement attachments: kept only long enough to be emailed, then deleted from our storage.
- Transfer Room files: short-by-design. Each transfer expires after the Tenant-configured window (14 days default, 1 to 30 days). Once a recipient downloads a file, its bytes are purged within 72 hours. Once a file is copied to the Tenant’s connected Google Drive, its bytes are purged within 24 hours. Files in revoked transfers are purged within 72 hours after revocation.
- Transfer Room audit log: the append-only event log (who activated a room, sent a transfer, viewed it, downloaded it, revoked it) is retained for the life of the Tenant’s account because Tenants may need to reconstruct the chain of custody for their professional records. IP addresses in the audit log are redacted to a /24 (IPv4) or /64 (IPv6) before storage.
- AI connector audit log: the append-only event log for connector calls is retained for the life of the Tenant’s account because Tenants may need to reconstruct the chain of custody for their professional records. The log records connector metadata, not Service Agreement content.
- AI connector content: once Service Agreement content has entered a ChatGPT or Claude conversation, it is held under the assistant provider’s terms and the user’s account plan and settings. Investatech cannot see, delete, expire, recall, or retrieve that copy. Deleting the agreement or the Tenant account in RCIC App does not delete content already disclosed to the assistant. Revoking the connection stops future access but does not retrieve past disclosures or remove information already retained or used by the provider under the applicable account terms and settings.
- Server logs: typically 30 to 90 days, longer if required for a security investigation or by law.
7. Your Rights
Under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws in Canada, you may:
- request access to your personal information we hold;
- ask us to correct inaccurate information;
- request deletion of your account and associated data (as a Tenant, you can do this from Settings → Delete Account; as an end-client, please contact your Tenant first, since they control your information);
- withdraw consent for optional processing (for example, by declining Platform AI on a given document, disabling or revoking an AI connector, or cancelling your Premium subscription); and
- lodge a complaint with the Office of the Privacy Commissioner of Canada or the applicable provincial privacy regulator.
A request to delete information from RCIC App cannot cause Investatech to delete information already disclosed through the AI connector. Revoking a connection stops that connected assistant from making future calls to RCIC App, but does not retrieve content already received by OpenAI or Anthropic. The Tenant and the user who controls the assistant account are responsible for using the provider’s privacy and deletion controls and for addressing the end-client’s request in relation to that provider-held copy.
To exercise any of these rights, email us at info@investatech.com. We will respond within 30 days.
8. Security
We use industry-standard measures to protect personal information: encrypted transport (TLS), encrypted storage at the database and object-storage layer, row-level security tenant isolation, hashed passwords, short-lived signed URLs for file uploads, secret-key-protected webhooks, and least-privilege service-role access. No system is perfectly secure; if we learn of a material breach affecting your data we will notify you in accordance with applicable law.
9. Cookies
Every cookie the Platform sets is strictly necessary to deliver the service you signed up for. We do not use advertising or cross-site tracking cookies on the Platform, which is why rcicapp.ca does not show a cookie banner, there is nothing on this domain you would need to consent to or reject.
The cookies the Platform sets:
- Authentication. Supabase sets HttpOnly session cookies (
sb-*-auth-token) so you stay signed in across page loads. - Idle session timeout.
iv_session_activityis an HttpOnly, HMAC-signed cookie that records the last time you interacted with the dashboard. After 90 minutes of inactivity the Platform forces a sign-out for your security; this cookie is how the server enforces that limit. - Device trust. When you tick “Remember this device for 30 days” after entering the email sign-in code, we set
investatech_device_trust(HttpOnly) so you can skip the code on the same browser for 30 days. - Language preference.
investatech_localeremembers whether you chose English or French in the dashboard. - Dashboard theme.
investatech_themeremembers your Light / Colourful / Dark Lite choice (one of three known values, no personal data). - Referral attribution. If you arrived from another tenant’s referral link,
iv_refrecords the referral code for up to 60 days so we can credit the referrer if you subscribe. The cookie carries the referral code only, no personal data. - Superadmin impersonation banner.
impersonator_email(HttpOnly) is set only when an Investatech operator is actively impersonating a tenant account for support and is cleared the moment impersonation ends. It exists so a visible banner makes clear who is signed in. - Consent record. The
cookie_consent_v1cookie (set by the marketing site at investatech.com) records your choices from the marketing-site cookie banner. The Platform itself does not write to this cookie.
Third-party scripts (Stripe Checkout, Google Calendar OAuth, Google reCAPTCHA) may set their own cookies when you interact with them. For the full cross-domain list see our Cookie Policy.
10. Children
The Platform is not directed at children under 16. Tenants are responsible for ensuring they have lawful authority to collect information about any end-client who is a minor.
11. AI Features
Platform AI
Platform AI means the existing AI features for which Investatech sends content to Google Gemini or Anthropic Claude using Investatech’s own paid API accounts. These features include document analysis, drafting assistance, client-page translation, and Service Agreement assistance.
Content a Tenant chooses to send through Platform AI is transmitted to the relevant provider and handled under that provider’s terms for paid API or commercial usage. Those terms, at the time of publication, state that API or commercial inputs and outputs are not used to train the provider’s models by default. Providers may change those terms. We will surface material changes we become aware of, and the Tenant can decline Platform AI on any document or cancel the Premium subscription at any time. Investatech does not use your content to train AI models.
Connector AI
Connector AI is the optional Model Context Protocol (MCP) connection at https://rcicapp.ca/api/mcp. It lets a Tenant user connect that user’s own ChatGPT or Claude account to RCIC App so the assistant can work with draft Service Agreements.
- Premium and off by default. Connector AI requires the Premium plan. It is off by default, and only the firm’s Owner can enable it for the firm.
- Individual authorization. After firm-level enablement, each team member must authorize their own assistant through OAuth 2.1. A connection belongs to that user and is never shared firm-wide.
- Revocation. A user can revoke their own connection immediately from My Profile → Connected apps. The Owner can also disable the feature for the firm.
- Rate limits. Each user is limited to 60 read calls and 20 write calls per minute. Each firm is also limited to 240 read calls and 80 write calls per minute.
- Audit log. Every connector call is written to an append-only audit log. The log records the tool used, the user, the firm, the agreement, the assistant provider, and the timestamp. It deliberately does not record the Service Agreement content.
What Connector AI Can Read
Connector AI can read the full draft Service Agreement selected by the Tenant user. Depending on what the Tenant has entered, this may include the client’s full legal name, email, phone number, home address, date of birth, preferred language, business contact details, identity corroboration method and notes (for example, “Passport” or “original examined in person”), matter type and summary, scope of services, fees and payment schedules, and information about other parties on the file, such as co-counsel, a sponsor, a third-party payer, or family members.
Connector AI cannot read signed PDF file contents, portal or signing tokens, credentials, any other firm’s data, or data from other Platform modules, including Transfer Room, Active File Review, bookings, invoices, calendars, or uploaded documents.
What Connector AI Can Write
Connector AI can create and edit draft Service Agreements only and can run an AI review. It cannot finalize an agreement, send one to a client, sign or countersign one, cancel one, or generate a public link to a signed PDF. Those are human-only actions.
Connector AI does not make an immigration or legal decision and does not replace the Tenant’s professional judgment. A qualified human user must review the assistant’s work and decide whether to use, change, or reject it before any agreement is finalized or sent.
Provider Terms, Training, and Retention
Connector AI is not covered by Investatech’s paid API arrangements. The content lands in the Tenant user’s own ChatGPT or Claude account and is governed by that user’s agreement, account plan, privacy settings, feedback choices, and other settings with OpenAI or Anthropic.
The training position depends on the plan and settings of the connected account. OpenAI states that content from its individual ChatGPT services may be used to improve models unless the user opts out, while content from ChatGPT Business, ChatGPT Enterprise, and its API is not used for model training by default. Anthropic states that content from Claude Free, Pro, and Max may be used for model improvement when the user permits it, when a conversation is flagged for safety review, or when the user otherwise opts in. Anthropic states that content from Claude for Work and its API is not used for model training by default. It also states that raw content retrieved through connectors, including MCP servers, is not included in model training unless it is copied into the conversation.
That last exception is narrower in practice than it sounds. When an assistant reads an agreement and then discusses it with you, repeating the client’s name, the fees, or the dates in its reply, that text becomes part of the conversation and is treated as conversation content. In ordinary use this happens often. You should not assume that information sent through the connector is broadly exempt from model training.
Provider safety, abuse-prevention, feedback, and retention practices may still apply under the relevant terms. Investatech cannot see or verify the connected plan, the settings, the feedback choices, or how connector content is represented in the assistant’s conversation. We cannot control the provider’s retention, require deletion, prevent any use permitted under the applicable terms, or recall content after it has been disclosed. Where a firm uses the connector with client information, we recommend connecting a business or enterprise plan rather than a personal one.
Tenant Responsibility and End-Client Notice
For the purposes of this Policy, Investatech treats Connector AI as a tenant-directed disclosure to the assistant provider, not as processing under Investatech’s paid API contract. The end-client is the data subject, but the Platform does not ask the end-client to approve the Owner’s firm-level enablement, each user’s connection, or each connector call. The Tenant must give its clients any notice required by law and obtain any required consent or other authorization before its users disclose client information through the connector.
The Tenant must also comply with the CICC Code of Professional Conduct and any other professional duty of confidentiality that applies. This includes disclosing no more information than is necessary for the specific task. Where Quebec law applies and the information is sensitive, the Tenant must obtain express consent unless a valid legal exception applies.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If a change is material we will notify Tenants by email or dashboard banner at least 30 days before it takes effect.
13. Email Communications and Consent (CASL)
We send tenants three categories of email. Different consent rules apply to each category under Canada’s Anti-Spam Legislation (CASL).
Transactional and account-related email. Signup confirmation, login one-time codes, password resets, billing receipts, booking notifications, signed-agreement deliveries, account suspension or closure notices, and similar messages required for the service to function. These are not Commercial Electronic Messages under CASL and we send them regardless of marketing consent. You cannot opt out of these while your account remains active.
Service alerts. Bug fixes that affect your account, security incidents, scheduled maintenance, and mandatory product changes. Default ON when you create your account; you may opt out via your notification preferences page. We reserve the right to send a service alert regardless of opt-out status when the message is materially important to your account security or data integrity.
Product updates and marketing. Feature announcements, training-session promotions, referral campaigns, and other Commercial Electronic Messages. Default OFF; we send these only when you have given express consent at signup or via your notification preferences page. Every such email carries an unsubscribe link that takes effect immediately.
Withdrawing consent. You may withdraw consent for service alerts or product updates at any time from Dashboard → Settings → Notifications, or by clicking the unsubscribe link in the footer of any such email. We honour unsubscribe requests immediately and keep a record of the change date, source, and IP address for our CASL compliance records.
Tenant-to-client emails. When the platform sends an email from your firm to your client (booking confirmation, signed agreement, written consultation answer, transfer-room notification, and so on), you are the CASL-responsible sender. We are the carrier. You collected the client’s consent when they interacted with you; the unsubscribe mechanism in those emails reaches you, not Investatech.
Sender of record. Investatech Inc., Toronto, Ontario, Canada. Email info@investatech.com for any consent question or to request a copy of your consent record.
14. Contact
Privacy Officer. Investatech Inc. has designated a Privacy Officer responsible for compliance with this Policy and with applicable privacy law, including the person-in-charge requirement under Quebec law.
Questions, access requests, correction requests, deletion requests, or complaints: info@investatech.com — Investatech Inc., Toronto, Ontario, Canada.