Privacy Policy

Last updated: February 2026

Vayoo Financial Services Inc. (“Vayoo”, “we”, “us”, or “our”) is committed to protecting your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our platform and services.

We operate in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.

What You Need To Know

  • We collect identity, employment, banking, and document data to process applications.
  • Your data is encrypted, stored in Canada, and never sold.
  • OCR and AI can pre-fill forms, but you review and confirm before submission.
  • We only share data with approved providers and regulators when required by law.
  • You can request access, correction, or deletion under PIPEDA rights.

1. Information We Collect

1.1 Information You Provide

  • Account Information: Name, email address, phone number, and password when you create an account.
  • Identity Verification: Government-issued photo ID, date of birth, and address for Know Your Customer (KYC) compliance.
  • Employment Information: Employer name, address, job title, pay amount, pay frequency, and next pay date.
  • Banking Information: Bank name, bank address, routing number, and account number for loan disbursement and pre-authorized debit (PAD) processing.
  • Documents: Paystubs, bank statements, pre-authorized debit forms, cheque images, and other documents you upload.
  • Communication: Messages you send through our in-app communication channel.

1.2 Information Collected Automatically

  • Device Information: Browser type, device type, operating system, and screen resolution.
  • Network Information: IP address for geolocation-based province detection and fraud prevention.
  • Usage Data: Pages visited, features used, and session duration.
  • Cookies: Essential cookies for platform functionality and optional analytics cookies (see Section 8).

1.3 Information from Third Parties

  • Banking API Data: With your explicit consent, we retrieve account details and transaction history (up to 3 months) through our banking data provider to assess your financial profile.
  • Geolocation Data: We use IP-based geolocation services to detect your province for regulatory compliance (provincial lending license display).

2. How We Use Your Information

We use your personal information for the following purposes:

  • Account Management: Creating and managing your account, verifying your identity, and authenticating your sessions.
  • Service Delivery: Processing loan applications, cheque cashing transactions, currency exchange, gold loan assessments, pawning services, and digital wallet operations.
  • Document Processing: Using AI-powered optical character recognition (OCR) to extract information from your uploaded documents.
  • Risk Assessment: Evaluating your creditworthiness and determining loan eligibility based on your financial profile.
  • Regulatory Compliance: Meeting obligations under FINTRAC (anti-money laundering), applicable provincial payday lending laws, the Consumer Protection Act, and other applicable legislation.
  • Fraud Prevention: Detecting and preventing fraudulent activity, including duplicate account detection, document tampering, and transaction anomalies.
  • Communication: Sending you transactional notifications (payment reminders, loan status updates) and, with your consent, marketing communications.

3. Consent

We obtain your explicit consent before collecting, using, or disclosing your personal information, except where permitted by law. We capture the following types of consent, each stored as an immutable, timestamped, and versioned record:

  • Banking Data Access: Before connecting to your bank account or uploading bank statements.
  • Document Storage: Before storing any document you upload to our platform.
  • Risk Analysis: Before we use your financial data for credit assessment.
  • Pre-Authorized Debit (PAD): Before setting up automatic repayments from your bank account.
  • Electronic Communications: Before sending you marketing or promotional messages (in compliance with Canada's Anti-Spam Legislation — CASL).
  • Soft Credit Check: Before we run a soft credit inquiry for pre-qualification and underwriting.
  • Data Sharing with Third Parties: Before sharing your information with any external service provider.

You may withdraw your consent at any time by contacting us at support@vayoo.ai or through your account settings. Withdrawal of consent may affect our ability to provide certain services.

4. Disclosure of Information

We do not sell your personal information. We may disclose your information to:

  • Service Providers: Third-party providers that help us deliver our services (payment processing, identity verification, document processing), subject to confidentiality agreements.
  • Regulatory Authorities: FINTRAC for anti-money laundering reporting (Suspicious Transaction Reports, Large Cash Transaction Reports for transactions of $10,000 or more), and other regulators as required by law.
  • Legal Requirements: When required by law, regulation, or legal process.

5. Data Security

We implement industry-standard security measures to protect your personal information:

  • Encryption in transit (TLS 1.3) and at rest (AES-256).
  • Sensitive financial data (banking information, PAD authorization) is tokenized.
  • PCI-DSS aligned security practices.
  • Role-based access controls — staff access is limited to what is necessary for their job function.
  • Immutable audit trails for all data access and changes.
  • Regular security assessments and vulnerability testing.

6. Data Retention

We retain your personal information for as long as necessary to provide our services and comply with legal obligations:

  • Active accounts: Data is retained for the duration of your account relationship.
  • Regulatory records: Financial transaction records are retained for a minimum of 5 years as required by FINTRAC.
  • Closed accounts: Upon account closure, we anonymize personal data where possible while retaining records required for regulatory compliance.

7. Your Rights Under PIPEDA

You have the right to:

  • Access the personal information we hold about you.
  • Correct any inaccurate or incomplete information.
  • Withdraw consent for the collection, use, or disclosure of your information (subject to legal or contractual restrictions).
  • File a complaint with the Office of the Privacy Commissioner of Canada if you believe your privacy rights have been violated.

8. Cookies

We use the following types of cookies:

  • Essential Cookies: Required for platform authentication, security, and core functionality. These cannot be disabled.
  • Analytics Cookies: Used to understand how users interact with our platform and improve the experience. These are optional and can be declined.

We do not use advertising or tracking cookies. You can manage your cookie preferences through the cookie banner displayed when you first visit our platform.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice on our platform or sending you a notification. Your continued use of our services after any changes constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:

Privacy Officer
Vayoo Financial Services Inc.
Email: support@vayoo.ai

This Privacy Policy applies to all services provided by Vayoo Financial Services Inc., including short-term loans, term loans, lines of credit, gold loans, cheque cashing, currency exchange, pawning, and digital wallet services.