Startly helps mortgage brokers collect documents from their clients. That means we handle sensitive financial information, and we take that seriously. This policy explains, in plain English, what we collect, why, where it lives, and how to get it removed. It is written with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and its ten fair information principles in mind.
Who we are
Startly ("we", "us") operates the website startly.io and the Startly document collection service (the "Service"). Our privacy contact is privacy@startly.io.
There are two kinds of people whose information we handle:
- Brokers: licensed mortgage professionals and brokerage staff who hold a Startly account.
- Clients: borrowers who receive a document request from a broker and upload files through the Startly portal. Clients do not create an account with us.
When a broker uses Startly to collect documents from a client, the broker is the organization responsible for that client relationship and for having the appropriate consent to collect those documents. Startly processes the documents on the broker's behalf and under the broker's instructions.
What we collect
From brokers
- Name, work email, phone number, brokerage name and licence jurisdiction.
- Account and billing details. Payments are handled by a third-party processor; we do not store full card numbers.
- Usage information: which requests were created, sent, viewed and completed, and when.
From clients
- The name, mobile phone number and/or email address a broker enters to send a request.
- The documents a client uploads in response to a checklist (for example identification, income and banking documents) and any notes they add.
- Technical information needed to deliver and secure the portal: IP address, device type, browser, and the time of each verification and upload.
From waitlist visitors
- Email address and, optionally, your role, brokerage and monthly file volume, plus the page and campaign (UTM) parameters you arrived from.
We do not ask for, and ask clients not to upload, Social Insurance Number cards. Brokers should collect credit consent through their own signed forms.
How we use it
We use personal information only for the purposes it was collected for:
- Delivering document requests by SMS and email, verifying a client's identity using the last four digits of their phone number, and accepting uploads.
- Sending reminders about outstanding items until a checklist is complete, and letting clients opt out at any time.
- Giving brokers a secure place to review, download and organize the files for a mortgage application.
- Keeping an audit log of who sent, viewed and uploaded what, so brokers can meet their record-keeping obligations.
- Operating, securing and improving the Service, including detecting abuse.
- Contacting waitlist members about early access and product updates. You can unsubscribe at any time.
We never sell personal information. We do not use client documents to train models, build profiles, or market to clients.
Where it lives
The Service runs on Cloudflare's global network. Uploaded documents are stored encrypted at rest in Cloudflare object storage, with every file scoped to the brokerage that requested it. Application data such as request status and the audit log is stored in Cloudflare's database services. Data in transit is encrypted with TLS.
Some brokerages switch on automated review, which checks an uploaded document against that brokerage's own checklist rules (for example, whether every page of a statement is present) and shows the result to the broker. For those brokerages only, uploaded documents are also sent to Google's Gemini service to perform the check. Google processes them on our behalf, does not use them to train its models, is instructed to delete the uploaded copy when the check finishes (and removes any copy within 48 hours regardless), and keeps request logs for a limited period to detect abuse. A person at the brokerage always makes the decision about your document.
Because Cloudflare and Google operate globally, data may be processed outside Canada, including in the United States, and may be subject to the laws of those jurisdictions. We use contractual and technical safeguards to protect it, and we are working toward a Canada-only storage option for brokerages that require it.
Retention and deletion
- Client documents are permanently deleted 90 days after the broker archives the request. A request with no activity for 90 days is archived automatically. Brokers can delete individual files or whole requests sooner at any time.
- Audit log entries (who did what and when, without file contents) are retained for the broker's record-keeping period, which they control in their account settings.
- Broker account information is retained while the account is active and deleted within 30 days of a closure request, except where we must keep it for legal, tax or dispute-resolution reasons.
- Waitlist information is deleted when you unsubscribe or within 24 months of your last interaction with us.
Sharing
We share personal information only with:
- The broker or brokerage that created the request. That is the whole point of the Service.
- Service providers who help us run Startly, such as cloud hosting, SMS and email delivery, automated document review (Google, only for brokerages that have switched it on), and payment processing. They may only use the information to provide the service to us.
- Authorities, when required by law or to protect the rights and safety of our users or the public.
- A successor, if Startly is acquired or merges, under the same protections described here.
Your rights
Under PIPEDA you can ask what personal information we hold about you, ask us to correct it, withdraw consent, and ask us to delete it. If you are a client, your documents belong to your mortgage file, so we will usually coordinate a request with your broker, but you can always contact us directly at privacy@startly.io and we will respond within 30 days.
If you are not satisfied with our response, you can contact the Office of the Privacy Commissioner of Canada.
Security
We protect personal information with measures appropriate to its sensitivity, including encryption in transit and at rest, a verification gate before any client can view or upload to a request, short-lived access tokens, brokerage-scoped access controls, and logging of access to files. No system is perfectly secure. If we become aware of a breach that creates a real risk of significant harm, we will notify affected people and the Privacy Commissioner as PIPEDA requires.
Cookies and analytics
We use strictly necessary cookies to keep brokers signed in and to keep a client's portal session secure. On the marketing site we use privacy-respecting analytics with IP anonymization to understand which pages are useful. We do not use advertising cookies and we never send document contents, names or email addresses to analytics providers.
Changes
We will post any changes to this policy on this page and update the date at the top. If a change materially affects how we handle client documents, we will notify brokers by email first.
Contact
Privacy questions, access requests and complaints: privacy@startly.io.
See also our Terms of Service.