Privacy Policy
Your privacy matters to us. This policy explains exactly what data we collect, why we collect it, who we share it with, and what rights you have — in plain language, not legalese.
Data Controller: Waves Financial, a division of [Parent Co.] (referred to as "Waves Financial," "we," "us," or "our"), is responsible for the personal information collected through the website wavesfinancial.ca and associated services.
Scope: This Privacy Policy applies to all personal information collected by Waves Financial from visitors to our website, applicants for our loan products, and existing borrowers. It governs how we collect, use, store, share, and protect your personal information.
Applicable law: Waves Financial operates in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA), applicable provincial privacy legislation, and the Consumer Protection Acts of British Columbia, Ontario, Nova Scotia, New Brunswick, Prince Edward Island, and Newfoundland and Labrador.
Changes to this policy: We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. The current version is always available at wavesfinancial.ca/privacy-policy. We will notify active borrowers of material changes by email with at least 30 days' notice.
We collect the minimum personal information required to evaluate your loan application, manage your account, and comply with our legal obligations. Here is exactly what we collect:
Identity & contact information:
Financial & income information:
Technical & usage data:
What we do NOT collect: We do not access your credit bureau report (no hard or soft inquiry). We do not collect your Social Insurance Number unless required by law for tax reporting purposes. We do not store your online banking login credentials.
We collect personal data through the following methods:
1. Directly from you — when you fill out our loan application form, contact our support team, or communicate with us by phone or email. You provide this information voluntarily as part of requesting our services.
2. Via Flinks (bank income verification) — when you connect your bank account during the application process, Flinks provides us with read-only access to your recent banking transaction history (90 days). Your banking login credentials are entered directly into Flinks' secure environment and are never transmitted to or stored by Waves Financial. Flinks is a licensed open banking data provider operating under its own privacy policy. We use this data solely to verify your income and account standing.
3. Automatically through our website — when you visit wavesfinancial.ca, our systems automatically collect technical data such as your IP address, browser type, and pages visited. This is collected through cookies and standard web server logs. See Section 6 for details on our cookie use.
4. From third-party identity verification services — in some cases, we may use a third-party service to verify your identity against government records. This is done with your explicit consent as part of the application process.
We use your personal information only for the following purposes:
- Loan assessment: To evaluate your eligibility and determine an appropriate loan amount based on your income and account activity
- Identity verification: To confirm that you are who you say you are and that the information provided is accurate
- Account management: To create your borrower account, process payments via PAD, issue e-Transfer funds, and manage your loan lifecycle
- Customer support: To respond to your inquiries, resolve issues, and provide assistance related to your loan
- Legal & regulatory compliance: To meet our obligations under federal and provincial lending, privacy, anti-money-laundering, and tax legislation
- Fraud prevention: To detect and prevent fraudulent applications and unauthorized account access
- Service improvement: To analyze aggregated, anonymized data to understand how borrowers use our services and to improve our platform
- Marketing communications: To send you relevant promotional offers and product updates — only with your consent, which you may withdraw at any time
Legal basis for processing: We process your personal information on the basis of (a) your consent, given when you submit your application; (b) contractual necessity, to fulfill the terms of your Loan Agreement; and (c) legal obligation, to comply with applicable Canadian law.
No automated decision-making with legal effect: While our initial approval assessment is automated, any application that results in a decline or modified offer is reviewed and can be escalated to a human agent upon your request. You are never subject to a fully automated, unappealable decision.
Waves Financial does not sell, rent, or trade your personal information. We may share it only in the following limited circumstances:
| Recipient | Purpose | Data shared |
|---|---|---|
| Flinks | Income verification | Bank account connection (read-only) |
| Payment processor | PAD collection | Bank account details, payment amounts |
| Cloud infrastructure (Canada) | Data hosting | Encrypted application & account data |
| Email service provider | Transactional email | Name, email address |
| Identity verification service | KYC / fraud prevention | Name, DOB, government ID type |
| Collection agencies | Default only | Name, contact details, outstanding balance — only in the event of loan default |
| Government / regulatory authorities | Legal obligation | As required by law — only when legally compelled |
All third-party service providers are contractually obligated to use your data solely for the purpose for which it was shared, to protect it with appropriate security measures, and to delete it when no longer required. We do not permit third parties to use your data for their own marketing purposes.
Our website uses cookies — small text files stored on your device — to provide a functional, secure experience and to understand how our website is used. Here is a breakdown of the cookies we use:
How to manage cookies: You can configure your browser to refuse some or all cookies, or to notify you when a cookie is set. Note that disabling essential cookies will prevent our loan application from functioning. For instructions specific to your browser, visit allaboutcookies.org.
No cross-site tracking: We do not use cookies or other technologies to track you across third-party websites. Our tracking is limited to activity on wavesfinancial.ca.
Web analytics: We use web analytics tools (such as Google Analytics) to collect aggregated, anonymized data about how visitors use our website. This helps us understand which pages are most visited, identify technical issues, and improve the user experience. Analytics data is never linked to your personally identifiable information.
Email marketing: By accepting our Terms and Conditions, you consent to receiving occasional marketing emails from Waves Financial about our products, services, and promotions. These emails are sent by us directly and are never shared with third-party advertisers.
Unsubscribing: You may opt out of marketing emails at any time by clicking the "Unsubscribe" link at the bottom of any marketing email, or by emailing support@wavesfinancial.ca with the subject line "Unsubscribe." Opting out of marketing communications does not affect transactional emails related to your active loan (payment reminders, receipts, account updates).
Advertising pixels: We may use standard conversion tracking pixels (such as Google Ads or Meta Pixel) to measure whether visitors who clicked our ads went on to apply for a loan. These tools use cookies and collect anonymized data only. No personal loan data is ever shared with advertising platforms.
No targeted profiling: We do not build personal profiles for targeted advertising purposes, and we do not sell data to advertising networks or data brokers.
Where your data is stored: All personal data collected by Waves Financial is stored on secure servers located in Canada. We do not transfer personal information outside of Canada, except as required by applicable law or with your explicit consent.
Encryption in transit: All communications between your browser and our platform are protected by 256-bit SSL/TLS encryption. Look for the padlock icon in your browser's address bar when visiting wavesfinancial.ca.
Encryption at rest: Personal and financial data stored on our servers is encrypted at rest using industry-standard AES-256 encryption.
Access controls: Access to your personal information is strictly limited to Waves Financial employees and contractors who need it to perform their duties. All personnel with access to personal data are subject to confidentiality agreements and receive regular privacy training.
Security audits: Our systems undergo regular security audits and vulnerability assessments. We use industry-standard practices including firewalls, intrusion detection, and multi-factor authentication for administrative access.
Breach notification: In the event of a data breach that poses a real risk of significant harm to you, Waves Financial will notify you and the Office of the Privacy Commissioner of Canada (or applicable provincial authority) within the timeframes required by PIPEDA and applicable provincial law. We will provide you with clear information about what happened, what data was affected, and what steps we are taking.
We retain your personal information for the minimum period necessary to fulfill the purpose for which it was collected, and as required by applicable law.
- Active loan period: Your full account data is retained for the duration of your loan and for 7 years after final repayment, to comply with Canadian tax, financial record-keeping, and consumer protection legislation
- Declined applications: Data from unsuccessful applications is retained for 90 days for fraud prevention purposes and then securely deleted
- Marketing data: If you have opted out of marketing communications, your opt-out preference is retained indefinitely to ensure we honour your request
- Technical logs: Server logs and technical usage data are retained for up to 12 months for security and operational purposes
- Communications records: Records of support interactions (calls, emails, chats) are retained for 3 years to support quality assurance and dispute resolution
Secure deletion: When personal data is no longer required, it is securely deleted using methods that prevent recovery, or irreversibly anonymized so that it can no longer be linked to you as an individual.
You may request early deletion of your personal information at any time (see Section 10). Note that we are not able to delete data that we are legally required to retain, and deletion does not affect data already disclosed to third parties as described in Section 5.
Under PIPEDA and applicable provincial privacy legislation, you have the following rights regarding your personal information:
Request a copy of all personal information we hold about you, including how it is being used.
Request that inaccurate, outdated, or incomplete information be corrected or updated.
Request deletion of your personal information, subject to our legal retention obligations.
Withdraw your consent to processing at any time. This may affect our ability to provide services.
Unsubscribe from promotional communications at any time, with no effect on your loan or account.
Request your data in a structured, commonly used format where technically feasible.
Request human review of any automated decision that has affected you.
Lodge a complaint with the OPC of Canada or applicable provincial privacy commissioner.
How to exercise your rights: Submit a written request to privacy@wavesfinancial.ca clearly describing your request. We will acknowledge receipt within 5 business days and provide a full response within 30 calendar days. We may request proof of identity to verify your request. All rights requests are free of charge.
Limitations: Certain rights may be limited in specific circumstances — for example, we cannot delete data that we are legally required to retain, and withdrawal of consent for core processing activities may require us to terminate the loan service. We will explain any limitation clearly when responding to your request.
Waves Financial has designated a Privacy Officer responsible for compliance with this policy and applicable privacy legislation. For any privacy-related questions, requests, or complaints, please contact:
Escalation — Office of the Privacy Commissioner of Canada: If you are unsatisfied with our response to a privacy concern, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada:
- Website: priv.gc.ca
- Toll-free: 1-800-282-1376
- TTY: 1-800-282-1376
- There is no cost to file a complaint
Provincial privacy commissioners: Residents of British Columbia and Alberta may also contact their provincial privacy commissioner. In Quebec, complaints may be filed with the Commission d'accès à l'information (CAI).