Privacy & Security

Privacy Policy


Effective:
March 31, 2026

Table of Contents

 

1. Scope and Application

2. Personal Information We Collect, and How We Collect It

3. Purposes of Collection, Use and Disclosure

4. Sharing with Affiliates, Service Providers and Other Third Parties

5. Security Safeguards, Cross-Border Transfers and Retention

6. Your Privacy Rights

7. Updates & Contact Information


1. Scope and Application


This Privacy Policy applies to Questrade Financial Group Inc. and its subsidiaries (collectively, “we”, “us”, or “QFG”). It explains how our companies collect, use and disclose the personal information of individuals who use our financial products and services, as well as those who interact with us through various channels, such as our websites, mobile applications and social media. This enterprise-wide policy may be supplemented by additional privacy notices applicable to specific practices, and more detailed information shared at the time of registration for a particular product or service.

Learn More


This Privacy Policy describes how Questrade Financial Group Inc. and its subsidiaries collect, use, disclose, and safeguard personal information. Subsidiaries of Questrade Financial Group Inc. include:

  • Questrade, Inc.;

  • Questrade Wealth Management Inc.;

  • Questbank;

  • Questmedia Inc.;

  • Flexiti Financial Inc.;

  • Community Trust Company;

  • Zolo Ventures Ltd.;

  • Questrade Mortgage Corporation; and

  • Other subsidiaries and affiliates of Questrade Financial Group Inc.


This policy applies to the personal information of our customers, and of individuals who otherwise interact with us, including in relation to our deposit, investment, loan, credit card, securities, mortgages, real estate, and other financial products or services. It also applies to your use of our websites, mobile applications, and other digital properties.

This policy includes each of the following supplemental notices, which we have broken out to provide more detail regarding our privacy practices:

In the event of a conflict between this document and a supplemental notice, the supplemental notice will prevail.

In addition to this policy, product-specific notices may provide additional details on our privacy practices when you sign up or apply for new offerings, and will apply together with this policy.


2. What Personal Information We Collect, and How We Collect It


To provide you with our tailored products and a secure experience, we may collect your personal information; however, we will always limit our collection to what is reasonably necessary to fulfill the purposes for which it is collected.

We may collect this information in four ways: directly from you; from someone you have designated to provide us with information on your behalf, such as a broker; automatically through your interactions with us, such as interactions with our websites and applications; and from external sources, such as credit reporting agencies. 

Learn More


Definition of Personal Information
“Personal information” is any information that can be used to identify you, directly or indirectly. 

Categories of Personal Information 
We collect various types of personal information based on the products or services you use and your interactions with us. These categories include:

  • Contact Information: Information including your name, address, email, and phone number.

  • Background Information: Information such as your date of birth, age, gender, and marital status. 

  • Government Identification Information: Government-issued IDs and social insurance number (SIN).

  • Financial and Credit Information: Details regarding your assets, liabilities, income, expenses, net worth, and credit scores or reports obtained from credit reporting agencies.

  • Product, Transaction and Account Information: Products and services you have with us, credit card numbers, account numbers and balances, transaction history, and purchase history and preferences.

  • Technical and Usage Information: Your IP address, device ID, browser type, operating system, geolocation (if enabled on your device), and data about how you navigate our websites and apps (such as clickstreams and page response times).

  • Interaction and Behavioral Information: Recordings of phone or video calls, chat transcripts, and other customer feedback. We may also use device behavioral data, such as mouse patterns or keyboard rhythms, for fraud monitoring and security.

  • Biometric Information: Information that enables us, with your consent, to verify your identity (such as a photo of your face and a government ID used for facial matching).

  • Third Party Information: Information you provide us about others, such as beneficiaries or joint account holders. 

How We Collect Personal Information 
We collect personal information using the following methods:

  • Directly from You: When you complete an application, open an account, enter a promotion, communicate with our sales and service teams, or otherwise provide information directly to us.

  • From Others on Your Behalf: We may receive information from authorized representatives (such as a power of attorney), joint account holders, brokers, real estate agents, or financial data aggregators where directed by you.

  • Collected Automatically: We use cookies, software development kits (SDKs), web beacons, and similar technologies to gather technical data when you use our websites and mobile apps. We also, with notice to you, record calls and interactions, such as online chats, for security and training purposes.

  • From Third Parties and External Sources: We obtain data from third parties outside QFG, including credit reporting agencies, government bodies, public records, social media platforms, other financial and lending institutions, and identity verification and risk assessment services.


3. Purposes of Collection and Use 


We collect and use your personal information to provide you with and manage our products and services. Specifically, we may use your personal information to:

  • Deliver and Administer Services: Manage your accounts, process transactions, and communicate with you.

  • Verify Identity and Assess Risk: Meet anti-money laundering (AML) requirements and determine creditworthiness for loans or credit cards.

  • Maintain Security: Detect and prevent fraud or unauthorized account access.

  • Improve Your Experience: Conduct research and analytics to develop new products and services, and provide you with personalized offers based on your interactions with us.

  • Meet Legal Obligations: Fulfill reporting and other regulatory requirements.

Learn More


Why We Use Your Personal Information 

We use your personal information for the following primary purposes across our businesses:

  • Service Delivery and Account Management: We use your personal information to evaluate and process applications for accounts, loans, and other financial products and services. This includes opening and maintaining your records, processing payments, investments, transfers and withdrawals, and communicating with you regarding your accounts or inquiries. For real estate and mortgage services, this involves processing property offers, deal submissions, and funding arrangements.

  • Identity Verification: To comply with anti-money laundering (AML) and "know your client" (KYC) requirements, we use your personal information to verify your identity.

  • Credit Assessment: We use your personal information to assess your creditworthiness when you apply for a credit product in order to establish credit limits and manage financial risks, and may continue to do so on an ongoing basis throughout our relationship. See the Credit Checks and Credit Reporting Notice for more information.

  • Security and Fraud Management: We monitor activity across platforms and accounts to prevent and detect financial abuse, fraud, and other suspicious activities. This may include the use of third party risk assessment, geolocation, and digital behavioral data, such as mouse patterns or keyboard rhythms, to ensure that only authorized users are accessing your account.

  • Legal and Regulatory Compliance: We use your personal information to satisfy various legal and regulatory requirements. This includes:

    • Using your Social Insurance Number (SIN) for mandatory income tax reporting related to products which generate interest or investment income.

    • Fulfilling reporting obligations to regulators.

    • Complying with court orders, warrants, or other valid legal demands.

  • Research, Analytics, and Product Development: We perform research and statistical analysis to improve our service offerings. This includes using technical data (such as IP addresses) and website interactions (such as clicks and page response times) to optimize our digital properties and develop new features that better serve our clients.

  • Marketing and Sales: We may use your personal information to notify you of products, services, or promotions that may be of interest to you. This includes determining your eligibility for specific products, services, rewards or contests and conducting surveys to enhance your experience with us. See the Digital Privacy, Cookies and Interest-Based Advertising Notice for more information.


Automated Decision-Making (ADM) 
We may use automated decision-making tools to assess credit risk, assess eligibility for products, and prevent and detect fraud. For example, we may process your personal information using certain tools to make decisions on credit applications, or preventing fraud and other financial crimes. When we rely on an automated decision, we may notify you of the automated nature of the decision and tell you how to contact us to learn more, in accordance with applicable laws.


4. Sharing with Affiliates, Service Providers and Other Third Parties


To provide you with a comprehensive suite of financial services and to manage your relationship with us, we share personal information within QFG, which may include affiliates in other countries.

We also engage service providers and third party partners to support the provision of our products and services, or for legal, regulatory or other professional purposes when permitted or required by law.

Learn More


Internal Sharing Within QFG
We share personal information among QFG subsidiaries and affiliates to achieve the purposes set out in this Privacy Policy. This internal sharing helps us:

  • Deliver our products and services, manage our relationship with you, and provide a seamless and consistent customer experience across different products and services.

  • Understand your needs, personalize the service we provide you, and determine your eligibility for products offered by QFG.

  • Identify trends and patterns to help us improve our products and services.

  • Manage and assess group-wide risks, including credit and fraud risks, and collect debts owed to us.

  • Consolidate internal reporting and comply with legal and regulatory requirements.

Service Providers and Third Parties
We work with trusted third-party partners to help deliver our products and services. We use appropriate contractual safeguards to ensure these service providers protect your personal information and use it only for authorized purposes. Before partnering with any service provider, we assess their security practices to ensure they meet our standards for protecting your personal information.

Categories of service providers with whom we share personal information include:

  • Technology Infrastructure: Providers of cloud hosting, data storage, and the foundational software used to run our systems and secure our network.

  • Trust, Safety, and Risk Management: Service providers that help us verify identities, manage secure logins, prevent fraud, provide insurance, and monitor for and manage security threats and operational risks.

  • Communications and Customer Support: Services that facilitate our email, chat, and phone communications, including customer relationship management and help-desk tools.

  • Marketing and Analytics: Service providers that help us understand how you use our website, manage our advertising campaigns, and provide you with relevant updates.

  • Operations and Logistics: Vendors who assist with maintaining books and records, securities registration, processing and storage, order fulfillment, shipping, and delivery.

  • Product Performance and Quality Assurance: Tools used to monitor the health of our apps and websites, identify software bugs, and conduct user testing to improve our services.

We may share personal information with other third parties with whom we partner who, in addition to supporting our products and services, may also process personal information for their own authorized purposes. These include: 

  • Payment and Financial Processing: Secure third-party payment processors, billing platforms, and financial institutions used to facilitate your transactions.

  • Funding Partners and Investors: We share personal information with active and prospective funding partners and investors (such as those involved in loan sale programs) to manage credit risk, facilitate the funding of loans, and meet our contractual obligations to those partners.

  • Insurance Underwriters: Where you sign up for insurance related to our products, for example Flexiti’s Simply SecureTM insurance program, or mortgage or loan protection, we will share your personal information with the applicable underwriter as required to facilitate your enrollment.  

  • Credit Reporting Agencies: We exchange personal information with credit reporting agencies such as Equifax and TransUnion to assess creditworthiness and report credit history. See the Credit Checks and Credit Reporting Notice for more information.

  • Flexiti Merchant Partners: Flexiti shares personal information with its merchant partners to process your purchases, reconcile daily settlements, and manage loyalty programs and promotions. Additionally, subject to your withdrawal of consent, Flexiti may provide merchant partners with information to help them understand how customers are using their credit and for marketing purposes. 

Lastly, we may share information as permitted or required by law for legal, regulatory and other professional purposes:

  • Regulators: Including government regulators such as the Canada Revenue Agency and self-regulatory organizations, to fulfill reporting requirements.

  • Legal Authorities and Law Enforcement: In response to valid requests and production orders.

  • Professional Advisors: Including legal counsel, auditors and consultants.

  • Business Transactions: Potential partners in the event of a merger, acquisition, or sale of business assets.


5. Security Safeguards, Cross-Border Transfers and Retention


We use robust physical, technical, and organizational safeguards to keep your personal information secure. To provide our products and services, we may store or process your information outside of your province or Canada; in these cases, your data remains protected but may be subject to the laws of that local jurisdiction.

We only keep your information for as long as it is needed to provide our services or to meet our legal and regulatory obligations. Once it is no longer required, we ensure your data is either securely destroyed or permanently anonymized.

Learn More


How We Protect Your Personal Information 

We take the protection of your personal information seriously. We maintain a comprehensive privacy program with physical, technical, and organizational safeguards designed to protect your personal information against loss, theft, and/or unauthorized access, use or disclosure.

Our privacy controls include:

  • Access Controls: Limiting access to your personal information to authorized personnel on a 'need-to-know' basis.

  • Transparency: Ensuring you are informed of how your personal information is used before or at the time of collection.

  • Governance: Clear assignment of roles and responsibilities for managing data throughout its entire lifecycle, including the appointment of a Chief Privacy Officer.

  • Data Lifecycle Management: Standards for the secure retention, destruction, and anonymization of personal information.

  • Incident Response: Dedicated procedures for investigating suspected privacy incidents and responding to inquiries or complaints.

  • Individual Rights: Processes to help you easily exercise your rights and choices regarding your personal information.

We reinforce these protections through regular employee training and appropriate contracts that require our service providers to meet our confidentiality and security standards.

Where We Store and Process Your Personal Information 
To provide our services, we and our service providers may store or process your personal information in jurisdictions outside of your province or territory of residence, or outside of Canada.

While your personal information is in a foreign jurisdiction, it is subject to the local laws of that country. These laws may allow foreign courts, law enforcement, or national security authorities to access your personal information through valid legal requests. We ensure that any transfers of personal information are protected by contractual safeguards designed to maintain a level of protection comparable to our own standards in Canada.

If you have questions regarding our use of service providers outside of Canada, please contact our Privacy Office using the information provided below.

How Long We Retain Your Personal Information 
We only keep your personal information for as long as necessary to fulfill the purposes for which it was collected, or to meet our legal, tax, and reporting obligations. Our retention periods vary based on the type of data and the nature of our relationship with you. Once your personal information is no longer required, we securely destroy it or anonymize it so that it can no longer directly or indirectly identify you.


6. Your Privacy Rights

 


We want to ensure you understand your rights and choices when it comes to how your personal information is collected, used and disclosed, to help you make informed decisions about your privacy.

There are multiple options available for you to manage various privacy preferences, including: managing preferences within your accounts or marketing communications, contacting us directly, changing your browser settings, or using a third party unsubscribe functionality.

Learn More


Right to Access
You have the right to request information about:

  • What personal information was collected and the purposes for which it was collected.

  • The categories of third parties who have access to your personal information.

  • The jurisdictions where your personal information is stored and how long we keep it.

You also have the right to request access to the personal information we hold about you. 

Right to Correction

We make reasonable efforts to ensure the personal information we have about you is accurate, complete, and up-to-date. If any of the personal information we hold about you is inaccurate, you may be able to correct this information in your account profile. If you can’t update it yourself, or need help updating the information, please reach out to us so we can make any required corrections.

Right to Withdraw Consent 
Subject to applicable legal and regulatory requirements, you may withdraw your consent to certain uses or disclosures of your personal information at any time, as follows: 

  • Marketing: You can unsubscribe from promotional emails or SMS via the link in the message or by reaching out to us using the contact information below.

  • Intra-Affiliate Information Sharing: You can withdraw your consent for us to share your information among QFG affiliates for non-essential purposes, such as affiliate cross-promotion.

  • Non-Tax Use of SIN: If you previously consented to us using your SIN as a unique identifier (for non-tax purposes), you can withdraw this consent by reaching out to us using the contact information below.

  • Cookies: You can adjust your cookies settings at any time in your browser.


Please note that if you withdraw consent for us to process information required to provide a product or service, or meet our legal or regulatory obligations, we may no longer be able to maintain your account, or provide you with certain products or services.


7. Updates & Contact Information


Updates
We may update this Privacy Policy or the supplemental notices from time to time. Your continued use of our products and services evidences your acceptance of updates to the Privacy Policy.

The current version of the policy is available on our website: https://www.questrade.com/disclosure/privacy-policy-and-security/privacy-policy


Contact Information
If you have any questions or concerns about how we handle your personal information, please contact our privacy officer at the applicable Privacy Office:

Company  Email Address


Mailing Address

Questbank and
Community Trust Company                             

[email protected]             

Attention: Privacy Office           
5700 Yonge Street, Suite 1900
Toronto, ON M2M 4K2 Canada

All other QFG Affiliates

[email protected]


If the Privacy Office is unable to resolve a concern to your satisfaction, you may contact the Office of the Privacy Commissioner of Canada or the relevant provincial privacy regulator. Please let us know if you require assistance to identify the right regulator.