Privacy Policy
Effective Date: July 22, 2026
1. Introduction
Fircus Solutions Inc. ("Fircus," "we," "our," or "us") respects your privacy and is committed to protecting the personal information entrusted to us.
This Privacy Policy explains how Fircus collects, uses, stores, safeguards, discloses, and retains personal information when you:
Visit our website at www.fircus.ca;
Contact us by telephone, email, online forms, or any other communication method;
Request a merchant processing statement review;
Request a quote, pricing proposal, or information regarding our products or services;
Apply for a merchant account, payment processing services, point-of-sale devices, payment gateways, or other related products or services;
Become a customer, prospective customer, business partner, broker, sales representative, independent contractor, supplier, service provider, or job applicant; or
Otherwise interact with Fircus in connection with our business activities.
Fircus collects, uses, discloses, safeguards, and retains personal information in accordance with applicable Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and any applicable provincial privacy legislation, as amended from time to time.
By providing personal information to Fircus, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, disclosure, storage, and retention of your personal information as described herein, subject to your rights under applicable law. Where required by law, Fircus will obtain your express consent before collecting, using, or disclosing your personal information.
2. Definition of Personal Information
For the purposes of this Privacy Policy, "personal information" means information about an identifiable individual.
Information is considered personal information when it identifies an individual directly or when it can reasonably be combined with other available information to identify that individual.
Personal information may include, but is not limited to, information relating to a business owner, director, officer, shareholder, signing authority, guarantor, employee, independent contractor, sales representative, job applicant, or any other individual associated with a business.
Certain business contact information, such as an individual's name, business title, business address, business telephone number, or business email address, may not be considered personal information under applicable privacy laws when it is collected, used, or disclosed solely for business-related communications. Nevertheless, Fircus will handle such information responsibly and in accordance with applicable legal and industry standards.
3. Information We May Collect
The personal and business information collected by Fircus depends on the nature of your relationship with us, the products or services you request, and any legal, regulatory, or contractual requirements applicable to our business.
3.1 Contact and Identification Information
We may collect the following contact and identification information:
First and last name;
Business name and operating (DBA) name;
Job title or position;
Business and residential addresses;
Email address;
Business, mobile, and telephone numbers;
Date of birth;
Preferred language;
Signature;
Government-issued identification, where required; and
Information used to verify your identity.
Government-issued identification may include a driver's licence, passport, or other acceptable identification document.
Fircus does not routinely request or collect provincial health card numbers as a form of identification.
3.2 Business Information
We may collect information relating to your business, including:
Legal business name;
Doing-business-as (DBA) or trade name;
Business address and operating location(s);
Shipping address;
Business telephone number and email address;
Website address;
Business registration number;
GST/HST number;
Date the business was established;
Nature and type of business;
Products and services offered;
Ownership structure;
Incorporation or registration information;
Names and ownership percentages of owners, shareholders, directors, officers, partners, guarantors, or signing authorities;
Business licences, permits, or registrations, where applicable;
Information regarding current or previous payment processing relationships; and
Information regarding anticipated or actual payment processing activity.
3.3 Merchant Processing Information
To evaluate, establish, and administer merchant processing services, we may collect:
Current or previous merchant processing statements;
Monthly credit and debit card processing volumes;
Average transaction size;
Maximum transaction size;
Card-present and card-not-present transaction percentages;
Information relating to e-commerce, mail order, telephone order, recurring payments, or in-person transactions;
Chargeback, refund, fraud, and dispute history;
Processing methods and business delivery practices;
Terminal, gateway, point-of-sale, software, and equipment requirements;
Merchant Identification Numbers (MIDs);
Information relating to your existing processor, acquiring bank, financial institution, payment gateway, or payment service provider; and
Transaction activity and merchant account administration information.
Merchant processing statements provided to Fircus are treated as confidential business information and are used primarily to evaluate existing processing costs, identify potential savings, assess merchant processing needs, and prepare customized pricing proposals or service recommendations.
3.4 Financial and Banking Information
Where required for merchant account applications, underwriting, payment processing services, or related business purposes, we may collect:
Business banking information;
Void cheque or pre-authorized debit (PAD) information;
Bank account holder information;
Financial statements;
Credit-related information;
Tax information;
Information regarding outstanding financial obligations or financial history; and
Information reasonably required for settlement, billing, funding, reserves, refunds, chargebacks, or other merchant account administration.
Fircus does not intentionally collect, retain, or store payment card information relating to ordinary customer purchase transactions unless such collection is specifically required for a lawful, disclosed, and legitimate business purpose.
Payment transactions are generally processed by independent third-party payment processors, acquiring banks, payment gateways, sponsoring financial institutions, and payment networks. Fircus does not control the privacy or security practices of these independent organizations.
3.5 Communications and Customer Service Information
We may collect information relating to our communications with you, including:
Emails and written correspondence;
Telephone call notes;
Messages submitted through our website or online forms;
Customer service and technical support requests;
Complaints, compliments, feedback, reviews, and survey responses;
Records of meetings, demonstrations, consultations, and sales discussions;
Instructions, preferences, or authorizations you provide; and
Information exchanged during account servicing, contract administration, or ongoing business relationships.
3.6 Website and Technical Information
When you visit our website, we or our authorized service providers may automatically collect certain technical and usage information, including:
Internet Protocol (IP) address;
Browser type and version;
Device type;
Operating system;
Approximate geographic location;
Pages viewed;
Links clicked;
Date and time of your visit;
Referring website or source;
Time spent on our website;
Website navigation and interaction information;
Cookie identifiers; and
Information collected through cookies, analytics tools, or similar technologies.
Although this information may not directly identify you, it may constitute personal information when combined with other information that can reasonably identify an individual.
3.7 Employment, Broker, and Representative Information
If you apply for employment or seek to work with or represent Fircus as a broker, independent contractor, sales representative, consultant, or other business partner, we may collect:
Resume or curriculum vitae (CV);
Employment history and business experience;
Education, training, certifications, and professional qualifications;
References;
Licensing or registration information;
Criminal background information, where legally permitted and reasonably necessary for the position or engagement;
Banking and tax information required for compensation or payment;
Sales production and performance information;
Contractual, commission, and compensation information; and
Communications relating to recruitment, onboarding, engagement, performance, or ongoing business relationships.
4. How We Collect Information
Fircus may collect personal and business information from a variety of lawful sources, including:
Directly from you;
From an owner, director, officer, partner, shareholder, employee, representative, independent contractor, or other authorized agent of your business;
Through our website, online forms, or other electronic communications;
Through telephone calls, emails, written correspondence, applications, meetings, consultations, demonstrations, or other communications with Fircus;
From merchant processing statements, applications, contracts, supporting documentation, or other information you provide;
From payment processors, acquiring banks, sponsor banks, financial institutions, payment gateways, point-of-sale providers, equipment providers, technology partners, or other service providers involved in delivering or supporting our services;
From credit reporting agencies, identity verification providers, fraud prevention services, or other third-party verification services, where permitted by law;
From publicly available sources, public registries, government records, or other publicly accessible information;
From referrals, business partners, affiliates, or other third parties authorized to share information with us;
From fraud prevention systems, sanctions screening services, anti-money laundering (AML) verification providers, regulatory authorities, or compliance databases; and
By any other lawful means, including with your consent where required by applicable law.
Fircus seeks to collect only the personal and business information that is reasonably necessary to fulfill the identified business purposes described in this Privacy Policy or as otherwise permitted or required by applicable law.
5. Purposes for Collecting and Using Information
Fircus may collect, use, disclose, and retain personal and business information for one or more of the following purposes, as applicable:
Responding to inquiries and requests for information;
Communicating with prospective customers, merchants, customers, business partners, brokers, sales representatives, independent contractors, suppliers, and other authorized contacts;
Preparing quotes, pricing proposals, and service recommendations;
Reviewing merchant processing statements and related documentation;
Comparing existing payment processing costs with proposed products and services;
Preparing pricing analyses, cost comparisons, and potential savings assessments;
Assessing eligibility for merchant accounts, payment processing services, equipment, or related products;
Preparing, processing, and submitting merchant account applications and supporting documentation;
Verifying identity, business ownership, signing authority, and other information required to establish or administer an account;
Conducting credit, fraud, risk, compliance, anti-money laundering (AML), sanctions screening, identity verification, and underwriting reviews where permitted or required;
Establishing, administering, maintaining, supporting, and servicing merchant accounts and related business relationships;
Providing payment processing products, merchant services, and related business solutions;
Supplying, configuring, delivering, installing, replacing, maintaining, recovering, or supporting point-of-sale terminals, payment gateways, e-commerce solutions, software, and related equipment;
Managing billing, settlements, funding, payments, collections, reserves, fees, commissions, account balances, and other financial transactions;
Processing refunds, chargebacks, retrieval requests, disputes, adjustments, and account reconciliations;
Preventing, detecting, investigating, and responding to fraud, unauthorized transactions, suspicious activity, cybersecurity incidents, or other unlawful conduct;
Complying with the requirements of payment networks, payment processors, acquiring banks, sponsor banks, financial institutions, anti-money laundering legislation, sanctions programs, regulatory authorities, contractual obligations, and applicable industry standards;
Creating, maintaining, and administering business records and internal documentation;
Responding to customer service requests, technical support inquiries, and account administration matters;
Improving our website, products, services, customer experience, operational efficiency, and business processes;
Conducting internal analysis, reporting, auditing, quality assurance, training, compliance monitoring, business planning, and risk management;
Managing relationships with payment processors, acquiring banks, sponsor banks, financial institutions, service providers, brokers, independent contractors, consultants, suppliers, technology providers, and other business partners;
Recruiting, evaluating, engaging, compensating, and managing employees, job applicants, brokers, sales representatives, independent contractors, consultants, and other personnel;
Sending newsletters, product updates, educational materials, service announcements, marketing communications, or promotional information where permitted by applicable law and, where required, with your consent;
Enforcing our agreements, protecting the rights, property, security, and legal interests of Fircus, our customers, and our business partners;
Meeting our legal, regulatory, accounting, tax, insurance, contractual, audit, and compliance obligations;
Responding to subpoenas, court orders, lawful requests, regulatory investigations, legal proceedings, or other legal processes;
Carrying out any other purpose disclosed to you at or before the time your information is collected; and
Carrying out any other purpose for which you have provided consent or that is otherwise permitted or required by applicable law.
Fircus will use personal information only for the purposes for which it was collected or for purposes that are reasonably related to those purposes, unless additional consent is required or the use is otherwise permitted or required by applicable law.
6. Consent
Fircus obtains meaningful consent for the collection, use, disclosure, and retention of personal information where required by applicable law.
Consent may be obtained in a variety of ways, including:
Expressly, either verbally or in writing;
Electronically, including through online applications, electronic signatures, emails, or website forms;
Through agreements, contracts, applications, service requests, or other documents; or
Implied where permitted by law, based on an individual's actions, the nature of the business relationship, or the reasonable expectations of the individual.
The type and form of consent obtained may depend on several factors, including:
The sensitivity of the personal information;
The purposes for which the information is collected, used, or disclosed;
The reasonable expectations of the individual; and
Applicable legal, regulatory, contractual, or industry requirements.
You may choose not to provide certain personal information or withdraw your consent, subject to legal or contractual restrictions and reasonable notice where applicable. However, if sufficient information is not provided, or if consent is withdrawn, Fircus, its payment processors, acquiring banks, sponsor banks, financial institutions, or other service providers may be unable to provide, establish, maintain, administer, or continue the products or services you have requested. This may include circumstances where personal information is required for identity verification, underwriting, fraud prevention, compliance, account administration, contractual obligations, or other legal and regulatory purposes.
7. Withdrawal of Consent
Subject to applicable laws and any legal, contractual, regulatory, payment processor, acquiring bank, sponsor bank, payment network, or other service provider requirements, you may withdraw your consent to the collection, use, or disclosure of your personal information at any time by providing reasonable notice to Fircus, unless such consent is required for the ongoing provision of a product or service or is otherwise required or permitted by law.
Withdrawal of consent may affect Fircus's ability to:
Process, evaluate, or complete a merchant account or related service application;
Provide, establish, maintain, administer, or support payment processing products or related services;
Maintain, service, or continue an existing merchant account or business relationship;
Comply with legal, regulatory, contractual, underwriting, fraud prevention, risk management, payment network, processor, or compliance requirements; and
Respond to requests or fulfill obligations that require the personal information for which consent has been withdrawn.
A withdrawal of consent does not have retroactive effect and will not affect any collection, use, disclosure, retention, or processing of personal information that was lawfully carried out before the withdrawal became effective.
Where applicable, Fircus will advise you of the likely consequences of withdrawing your consent. To withdraw your consent or to discuss how such a withdrawal may affect your relationship with Fircus, please contact the Fircus Privacy Officer using the contact information provided in this Privacy Policy.
8. Marketing Communications
Where permitted by applicable law, Fircus may send you information about our products, services, promotions, special offers, newsletters, educational materials, events, industry updates, and other business opportunities that may be of interest to you.
You may opt out of receiving promotional or marketing communications from Fircus at any time by:
Clicking the unsubscribe link included in our marketing emails;
Replying to a marketing email with a request to unsubscribe; or
Contacting Fircus directly using the contact information provided in this Privacy Policy.
Fircus will process unsubscribe requests within the time required by applicable law. Please note that opting out of marketing communications will not affect communications that are necessary to administer your relationship with Fircus.
Even if you choose not to receive marketing communications, Fircus may continue to send you non-promotional communications, including those relating to your account, merchant services, applications, transactions, billing, contracts, technical support, security alerts, fraud prevention, legal notices, regulatory requirements, or other service-related and administrative matters.
9. Disclosure of Personal Information
Fircus does not sell, rent, or trade personal information to third parties for their independent marketing purposes.
Fircus may disclose personal and business information to third parties where reasonably necessary to provide products or services, administer a business relationship, fulfill contractual obligations, comply with legal or regulatory requirements, protect legitimate business interests, or as otherwise permitted or required by applicable law.
Personal information may be disclosed to:
Payment processors;
Acquiring banks;
Sponsor banks;
Card networks, payment networks, and other payment system participants;
Financial institutions;
Merchant account underwriting, credit, fraud, compliance, risk management, and account administration departments;
Identity verification, authentication, and Know Your Customer (KYC) service providers;
Credit reporting agencies, where permitted by applicable law;
Fraud prevention, anti-money laundering (AML), sanctions screening, compliance monitoring, and cybersecurity service providers;
Equipment manufacturers, distributors, suppliers, leasing companies, logistics providers, and delivery service providers;
Point-of-sale, payment gateway, e-commerce, software, and technology providers;
Website hosting, cloud hosting, data storage, telecommunications, email, cybersecurity, and other information technology service providers;
Customer service, technical support, implementation, installation, maintenance, and repair providers;
Accountants, auditors, tax advisors, lawyers, insurers, consultants, and other professional advisors;
Brokers, independent contractors, sales representatives, referral partners, agents, affiliates, or other authorized business partners;
Government departments, regulatory authorities, payment network authorities, courts, tribunals, law enforcement agencies, or other persons or organizations legally authorized to receive such information; and
Any purchaser, investor, lender, assignee, successor, or other party involved in an actual or proposed financing, merger, acquisition, reorganization, sale of assets, or other corporate transaction, subject to appropriate confidentiality obligations where applicable.
Fircus may also disclose personal information:
With your knowledge and consent, where required;
To collect or recover outstanding debts or enforce payment obligations;
To detect, prevent, investigate, or respond to fraud, unauthorized transactions, security incidents, cyber threats, or other unlawful or suspicious activities;
To establish, exercise, protect, or defend legal rights, claims, or legal proceedings;
To comply with applicable laws, regulations, court orders, subpoenas, warrants, lawful requests, or other legal processes;
To protect the rights, property, safety, or security of Fircus, its customers, business partners, employees, representatives, or the public; or
In an emergency involving the life, health, safety, or security of an individual where disclosure is authorized or required by law.
Fircus requires service providers and other authorized third parties that receive personal information on its behalf to use such information only for the purposes for which it was disclosed, to maintain appropriate administrative, technical, and physical safeguards to protect the information, and to comply with applicable privacy and confidentiality obligations. Fircus does not control the privacy practices of independent third parties when they collect, use, or disclose personal information on their own behalf.
10. Processing and Storage Outside Canada
Fircus may use third-party service providers, including payment processors, acquiring banks, sponsor banks, financial institutions, cloud service providers, software providers, technology providers, data hosting providers, and other business partners that process or store personal information outside Canada.
As a result, personal information may be transferred to, processed in, or stored in another province, territory, or country in connection with the products and services provided by Fircus.
Where personal information is transferred outside Canada, it becomes subject to the laws of the jurisdiction in which it is processed or stored. Accordingly, personal information may be accessible to courts, law enforcement agencies, government authorities, or regulatory bodies in those jurisdictions in accordance with applicable local laws.
Fircus takes reasonable steps to select reputable service providers and, where appropriate, requires them by contract or other legally appropriate means to maintain reasonable privacy, confidentiality, and security safeguards that are appropriate to the sensitivity of the information and consistent with applicable legal requirements. While Fircus seeks to protect personal information throughout its lifecycle, no method of electronic transmission or storage can be guaranteed to be completely secure.
11. Merchant Statements and Confidential Business Information
Merchant processing statements and related business documents submitted to Fircus are collected, used, and retained only for legitimate business purposes, which may include:
Reviewing current merchant processing costs, rates, fees, and pricing structures;
Identifying opportunities to reduce payment processing costs or improve merchant services;
Preparing pricing comparisons, cost analyses, and customized savings estimates;
Evaluating historical processing activity, transaction patterns, and merchant processing requirements;
Assessing eligibility for payment processing products and services;
Preparing quotations, merchant services proposals, recommendations, and pricing offers;
Preparing, supporting, or facilitating merchant account applications and related documentation;
Conducting underwriting, risk assessment, fraud prevention, compliance, or due diligence reviews where applicable; and
Administering or supporting an existing or proposed merchant relationship.
Fircus treats merchant processing statements and related business documents as confidential business information and uses reasonable administrative, technical, and physical safeguards to protect them from unauthorized access, use, disclosure, alteration, or destruction.
Merchant processing statements and related confidential business information will not be sold, rented, or disclosed except:
With the authorization or direction of the merchant or other authorized representative;
To payment processors, acquiring banks, sponsor banks, financial institutions, or authorized service providers where reasonably necessary to evaluate, establish, administer, or support the requested products or services;
Where disclosure is required or permitted by applicable law, regulation, court order, or other lawful authority;
Where reasonably necessary to detect, prevent, investigate, or respond to fraud, security incidents, unauthorized activity, or other unlawful conduct; or
Where reasonably necessary to establish, exercise, protect, or defend the legal rights, interests, or obligations of Fircus or to administer the merchant relationship.
Fircus will retain merchant processing statements only for as long as reasonably necessary to fulfill the purposes for which they were collected or as otherwise required or permitted by applicable law, contractual obligations, or legitimate business requirements.
12. Payment Card Information
Fircus is a merchant services provider and does not ordinarily accept or process consumer payment card transactions directly through its website or maintain payment card processing systems for ordinary consumer purchases.
Where payment card transactions are processed through a third-party payment gateway, payment processor, acquiring bank, or other payment service provider, those transactions are generally processed by organizations that are responsible for maintaining compliance with the applicable Payment Card Industry Data Security Standard (PCI DSS) and other applicable payment network requirements.
Except where specifically required for a lawful, disclosed, and legitimate business purpose, Fircus does not intentionally collect, retain, or store:
Full payment card numbers (Primary Account Numbers or PANs);
Card Verification Value (CVV), Card Verification Code (CVC), Card Identification Number (CID), or other card security codes;
PINs or encrypted PIN blocks; or
Other sensitive authentication data as defined by applicable PCI DSS requirements.
If Fircus is required to collect or retain payment card information for a lawful and disclosed business purpose, such information will be handled only to the extent necessary and protected using reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the information and applicable legal requirements.
Merchants are independently responsible for complying with applicable PCI DSS requirements, payment network rules, and the terms and conditions of their merchant services agreements, including maintaining the security of payment card information processed, transmitted, or stored within their own systems or business operations. Nothing in this Privacy Policy transfers or limits those obligations.
13. Security Safeguards
Fircus maintains reasonable administrative, technical, organizational, and physical safeguards designed to protect personal information against loss, theft, unauthorized access, unauthorized use, unauthorized disclosure, unauthorized copying, modification, destruction, and other unauthorized or unlawful processing.
Depending on the sensitivity of the information and the nature of the services provided, these safeguards may include:
Password-protected systems and user authentication measures;
Role-based access controls and restrictions based on legitimate business need;
Secure electronic communications and network connections;
Encryption of information where appropriate and commercially reasonable;
Firewalls, anti-malware software, endpoint protection, and other security technologies;
Secure storage of electronic and physical records;
Confidentiality agreements and privacy obligations applicable to employees, independent contractors, representatives, and authorized service providers;
Procedures governing the collection, access, use, disclosure, retention, and disposal of personal information;
Secure document destruction and media disposal practices;
Ongoing monitoring, testing, and review of security measures where appropriate;
The use of reputable third-party service providers that are expected to maintain appropriate security safeguards; and
Security incident response, investigation, containment, and recovery procedures designed to address suspected or actual privacy or security incidents.
Access to personal information is limited to individuals who require such access to perform their legitimate business responsibilities or to fulfill contractual, legal, regulatory, or operational requirements.
Although Fircus takes reasonable steps to safeguard personal information appropriate to its sensitivity, no method of electronic transmission over the Internet, electronic storage system, website, computer network, or security technology can be guaranteed to be completely secure. Accordingly, Fircus cannot guarantee the absolute security of personal information and disclaims liability for unauthorized access, loss, theft, alteration, disclosure, or destruction resulting from circumstances beyond its reasonable control, provided that Fircus has complied with its applicable legal obligations.
14. Privacy and Security Incidents
Fircus maintains procedures for identifying, assessing, responding to, and managing suspected or confirmed privacy and security incidents involving personal information.
Where Fircus becomes aware of a suspected or confirmed privacy or security incident, we will take reasonable steps appropriate to the circumstances to:
Contain the incident and help prevent further unauthorized access, use, disclosure, loss, or destruction of personal information;
Investigate the nature, scope, and potential impact of the incident;
Mitigate, where reasonably possible, the risk of harm to affected individuals and to Fircus;
Preserve evidence and maintain appropriate records relating to the incident;
Implement corrective measures designed to reduce the likelihood of similar incidents occurring in the future; and
Review and, where appropriate, improve our privacy and security policies, procedures, or safeguards.
Where required or permitted by applicable law, Fircus may:
Notify affected individuals;
Notify applicable privacy commissioners, regulators, payment processors, acquiring banks, sponsor banks, financial institutions, payment networks, service providers, insurers, law enforcement authorities, or other appropriate parties;
Maintain records of privacy or security incidents as required by applicable law; and
Cooperate with regulatory authorities or other organizations involved in responding to or investigating the incident.
The timing, content, and method of any notification will be determined by Fircus based on the nature of the incident and the requirements of applicable law. Nothing in this Privacy Policy obligates Fircus to provide notice where notification is not required by law or where providing notice could interfere with an investigation or is otherwise restricted or prohibited by law.
15. Retention of Personal Information
Fircus retains personal and business information only for as long as reasonably necessary to fulfill the purposes for which it was collected, or as otherwise required or permitted by applicable law, contractual obligations, or legitimate business requirements.
Personal information may be retained for purposes that include:
Fulfilling the purposes for which the information was collected;
Establishing, administering, maintaining, and servicing customer, merchant, broker, contractor, employee, representative, or other business relationships;
Providing products, services, technical support, and account administration;
Complying with the requirements of payment processors, acquiring banks, sponsor banks, financial institutions, payment networks, tax authorities, accounting standards, insurance requirements, contractual obligations, and applicable legal or regulatory requirements;
Detecting, preventing, investigating, and responding to fraud, unauthorized activity, security incidents, or other unlawful conduct;
Resolving disputes, complaints, or legal proceedings;
Enforcing contracts, agreements, policies, and legal rights;
Establishing, exercising, protecting, or defending legal claims or legal obligations; and
Maintaining business, financial, accounting, audit, compliance, and corporate records.
The length of time personal information is retained may vary depending on factors including:
The nature, sensitivity, and volume of the information;
The purpose for which it was collected;
The nature and duration of the business relationship;
Applicable contractual obligations;
Applicable laws, regulations, and industry standards;
Requirements imposed by payment processors, acquiring banks, sponsor banks, financial institutions, or payment networks;
Applicable limitation periods and potential legal claims; and
Operational, business continuity, security, audit, and recordkeeping requirements.
When personal information is no longer required for the purposes for which it was collected, Fircus will, where appropriate and subject to applicable legal or contractual requirements, securely delete, destroy, anonymize, or de-identify the information using methods reasonably designed to prevent unauthorized access or reconstruction.
Archived records containing personal information will be retained only where reasonably necessary and will remain subject to appropriate administrative, technical, organizational, and physical safeguards, including access restrictions based on legitimate business need.
16. Accuracy of Information
Fircus takes reasonable steps to ensure that personal information used to make significant business, legal, regulatory, underwriting, or account administration decisions is as accurate, complete, and up to date as is reasonably necessary for the purposes for which it is used.
Individuals are responsible for providing accurate information to Fircus and for promptly notifying us of any changes to their personal or business information that may affect the products or services we provide or our ongoing business relationship.
Upon receiving a written request, Fircus will take reasonable steps to correct or update personal information that is demonstrated to be inaccurate, incomplete, or out of date, subject to any legal, regulatory, contractual, or recordkeeping requirements. Where appropriate, Fircus may also notify third parties to whom the corrected information was disclosed, where reasonably practicable or as required by applicable law.
Requests to review, correct, or update personal information may be submitted to the Fircus Privacy Officer using the contact information provided in this Privacy Policy.
17. Access to Personal Information
Subject to applicable law, you may request access to the personal information that Fircus holds about you and may request information regarding how your personal information has been collected, used, disclosed, or retained.
To protect your privacy and the privacy of others, Fircus may require sufficient information to:
Verify your identity and authority to make the request;
Locate and identify the requested records;
Clarify the nature and scope of the request; and
Protect the personal information, confidentiality, and legal rights of other individuals or organizations.
Fircus will respond to access requests within the time required by applicable law. Where permitted or required by law, Fircus may extend the time for responding to a request or charge a reasonable fee, provided notice is given where required.
Access to personal information may be limited or refused where permitted or required by applicable law, including where the requested information:
Is protected by solicitor-client privilege, litigation privilege, or other legally recognized privilege;
Contains confidential commercial, proprietary, or trade secret information;
Relates to another identifiable individual or would unreasonably disclose another person's personal information;
Could reasonably be expected to interfere with a legal, regulatory, fraud prevention, security, or internal investigation;
Cannot be disclosed due to legal, regulatory, contractual, payment network, processor, or security requirements; or
Is otherwise exempt from disclosure under applicable law.
Where access is denied in whole or in part, Fircus will provide the reasons for the refusal and information about any available recourse or complaint process where required by applicable law.
Requests to access personal information should be submitted to the Fircus Privacy Officer using the contact information provided in this Privacy Policy.
18. Correction of Personal Information
You may request that Fircus correct, update, or complete personal information that you believe is inaccurate, incomplete, or out of date.
To help us evaluate your request, Fircus may require sufficient information or supporting documentation to verify your identity, assess the requested correction, and confirm the accuracy of the revised information.
Where Fircus determines that a correction is appropriate, we will update our records within a reasonable time, subject to any legal, regulatory, contractual, audit, or recordkeeping requirements that require us to retain the original information.
Where a material correction is made and it is reasonably necessary or required by applicable law, Fircus may notify relevant third parties, including service providers, payment processors, acquiring banks, sponsor banks, financial institutions, or other organizations to whom the information was previously disclosed, provided it is reasonably practicable to do so.
If Fircus determines that a requested correction is not appropriate, we may decline the request where permitted by applicable law. Where required, Fircus will provide an explanation for the decision and information regarding any available recourse or complaint process.
19. Deletion and Limitation Requests
Subject to applicable law, you may request that Fircus delete, anonymize, de-identify, or limit the use of your personal information in certain circumstances.
Fircus will consider each request on a case-by-case basis. However, Fircus may be unable to delete or restrict the use of personal information where its continued retention or use is required or permitted by applicable law, contractual obligations, legitimate business purposes, or industry requirements.
Personal information may need to be retained for purposes including:
Compliance with legal, regulatory, or governmental requirements;
Payment processor, acquiring bank, sponsor bank, payment network, or financial institution requirements;
Fraud prevention, identity verification, compliance monitoring, or risk management;
Accounting, tax, audit, insurance, or financial reporting obligations;
Establishing, administering, maintaining, or enforcing contracts, agreements, or business relationships;
Resolving disputes, complaints, chargebacks, or investigations;
Establishing, exercising, protecting, or defending legal rights or legal claims;
Security, cybersecurity, business continuity, or recordkeeping requirements; or
Any other purpose permitted or required by applicable law.
Where deletion or anonymization is not available or appropriate, Fircus may restrict the use of the personal information, securely retain it for the applicable purpose, or de-identify the information where legally permissible and operationally appropriate.
Where Fircus is unable to comply with a deletion or limitation request, we will provide an explanation to the extent required by applicable law.
20. Complaints and Privacy Questions
If you have any questions, concerns, or complaints regarding this Privacy Policy or Fircus' collection, use, disclosure, retention, or protection of your personal information, you may contact the Fircus Privacy Officer using the contact information provided in this Privacy Policy.
Upon receiving a privacy inquiry or complaint, Fircus will make reasonable efforts, as appropriate to the circumstances, to:
Acknowledge receipt of the inquiry or complaint;
Review the information provided and assess the issues raised;
Conduct an investigation where appropriate;
Respond within a reasonable time or within any time period required by applicable law;
Take reasonable corrective or remedial action where warranted; and
Review our privacy practices or procedures where appropriate to help prevent similar issues from occurring.
To properly investigate or respond to a privacy inquiry or complaint, Fircus may request additional information, documentation, or identity verification from the individual making the request.
If you are not satisfied with Fircus' response, you may have the right to contact the appropriate privacy regulator or supervisory authority having jurisdiction over your complaint, in accordance with applicable law.
21. Privacy Officer
Fircus has designated a Privacy Officer who is responsible for overseeing Fircus' privacy management program, ensuring compliance with applicable privacy laws, responding to privacy requests, and managing privacy-related questions, concerns, and complaints.
Privacy-related inquiries, requests, or complaints may be directed to:
Fircus Solutions Inc.
Attention: Privacy Officer
Toll-Free: 1-844-461-7220
Website: www.fircus.ca
Email: privacy@fircus.ca
The Privacy Officer will make reasonable efforts to respond to privacy-related inquiries and requests within the time required by applicable law or, where no specific timeframe applies, within a reasonable period based on the nature and complexity of the request.
22. Cookies and Similar Technologies
Fircus may use cookies and similar technologies to operate, secure, analyze, maintain, and improve its website, products, services, and online user experience.
Cookies are small text files that are stored on your device or web browser when you visit a website. Fircus may also use similar technologies, such as web beacons, pixels, local storage, scripts, tags, or other technologies that perform comparable functions.
These technologies may be used to:
Enable essential website functionality;
Remember visitor preferences and settings;
Improve website navigation and user experience;
Maintain website security and help prevent unauthorized activity;
Understand how visitors interact with our website;
Measure website traffic and performance;
Diagnose technical issues and improve website reliability;
Support analytics, advertising, and marketing activities where permitted by applicable law; and
Improve our products, services, communications, and website content.
Depending on your browser or device settings, you may be able to block, disable, or delete cookies. However, doing so may affect the functionality, performance, or availability of certain features of the Fircus website.
Where required by applicable law, Fircus will obtain your consent before using non-essential cookies or similar technologies.
22.1 Types of Cookies
Fircus may use one or more of the following categories of cookies and similar technologies, depending on the features and functionality available on our website:
Essential Cookies
These cookies are necessary for the operation, security, and core functionality of the website. They enable basic features such as page navigation, secure access to website areas, and fraud or security protections. Because these cookies are necessary for the website to function, they generally cannot be disabled through our website.
Functional Cookies
These cookies help remember your preferences and settings, enhance website functionality, and provide a more personalized browsing experience.
Analytics Cookies
These cookies help us understand how visitors use our website by collecting information about website traffic, visitor interactions, navigation patterns, and website performance. The information collected may be used to improve the design, functionality, content, and overall user experience of our website.
Advertising and Remarketing Cookies
These cookies may be used to measure the effectiveness of advertising campaigns, understand user interests, and display advertisements based on previous visits to our website or other websites. Fircus will use these technologies only where they have been implemented and where permitted by applicable law.
22.2 Analytics Information
When analytics technologies are enabled, they may collect information such as:
Internet Protocol (IP) address;
Device type and browser information;
Operating system;
Pages viewed;
Date and time of website visits;
Referring websites or web pages;
Approximate geographic location;
Website navigation patterns and interactions; and
Other technical or usage information generated through your interaction with our website.
Fircus may use website analytics services provided by Google Analytics or other reputable analytics providers to help understand website usage, improve website performance, analyze visitor trends, and enhance our products and services.
Where analytics technologies collect personal information or require consent under applicable law, Fircus will obtain such consent before activating non-essential analytics technologies.
22.3 Advertising Pixels and Remarketing
Fircus may use advertising, remarketing, conversion tracking, or similar technologies provided by third-party advertising platforms, including Google Ads, Meta (Facebook and Instagram), LinkedIn, or other advertising providers.
These technologies may use cookies, pixels, tags, or similar technologies to:
Measure the effectiveness of advertising campaigns;
Understand website visitor interests;
Improve advertising relevance;
Measure conversions; and
Display advertisements based on previous visits to the Fircus website or interactions with our online content.
Advertising and remarketing technologies described in this Privacy Policy apply only to the extent that they have been installed, configured, or enabled on the Fircus website. If these technologies are not in use, the related provisions of this section do not apply.
Fircus does not control how independent third-party advertising providers collect, use, or disclose information on their own behalf. Users should review the applicable privacy policies of those providers for additional information regarding their data collection and advertising practices.
22.4 Managing Cookies
You may manage, restrict, disable, or delete cookies and similar technologies through:
Your web browser settings;
The Fircus website's cookie consent or preference management tool, where available;
Device privacy settings, where applicable; or
Advertising preference or opt-out tools provided by third-party advertising providers.
Please note that disabling certain cookies or similar technologies may affect the functionality, security, performance, or availability of some features of the Fircus website.
Where required by applicable law, you may withdraw or modify your cookie preferences at any time using the cookie management tools made available by Fircus, where applicable.
23. CAPTCHA and Website Security Tools
To help protect our website, online services, and users, Fircus may use CAPTCHA services, spam filters, bot detection tools, fraud prevention technologies, website security monitoring, intrusion detection systems, and other security-related technologies.
These technologies may be used to:
Prevent automated or malicious submissions;
Reduce spam and fraudulent activity;
Protect website forms and online services;
Detect suspicious, abusive, or unauthorized activity;
Prevent unauthorized access to our systems and information;
Monitor website security and system integrity; and
Help maintain the availability, reliability, and security of the Fircus website and related services.
Depending on the technology used, these security tools or their service providers may collect technical information such as Internet Protocol (IP) addresses, browser and device information, operating system details, timestamps, website interactions, security event data, or other technical information reasonably necessary to detect, prevent, or investigate suspicious or unauthorized activity.
Any third-party providers offering these security services may collect, use, process, or store information in accordance with their own privacy policies and applicable legal requirements. Fircus encourages users to review the privacy policies of those providers where appropriate.
Where required by applicable law, Fircus will obtain any necessary consent before enabling non-essential technologies that collect personal information.
24. Third-Party Websites
The Fircus website may contain links to third-party websites, applications, platforms, services, social media pages, or other online resources that are owned or operated by independent organizations.
These links are provided solely for your convenience and do not constitute an endorsement, recommendation, approval, or representation by Fircus regarding any third-party website, product, service, or organization unless expressly stated otherwise.
Fircus does not own, operate, or control third-party websites and is not responsible for:
The content, accuracy, or availability of third-party websites or services;
The privacy, security, or data handling practices of third parties;
The products, services, or information offered by third parties;
Information that you voluntarily submit directly to a third party; or
Any loss, damage, or other consequences arising from your use of or reliance on a third-party website or service.
Any personal information that you provide directly to a third-party website or service is collected, used, disclosed, stored, and protected in accordance with that third party's own privacy policy, terms of use, and applicable practices. Fircus has no control over, and assumes no responsibility for, the privacy or security practices of independent third parties.
Before providing personal information or conducting business through a third-party website or service, you should carefully review the applicable privacy policy, terms of use, and security practices of that third party.
25. Children's Privacy
Fircus' website, payment processing products, and merchant services are intended for businesses and individuals who are at least 18 years of age. Our products and services are not directed to, marketed to, or intended for children.
Fircus does not knowingly collect, use, or disclose personal information from children under the age of 18 through its website or in connection with its products or services without appropriate authorization or where otherwise permitted or required by applicable law.
If Fircus becomes aware that personal information relating to a child under the age of 18 has been collected without appropriate authorization, we will take reasonable steps, as appropriate in the circumstances and subject to applicable legal requirements, to delete, de-identify, or otherwise appropriately address the information.
If you believe that a child has provided personal information to Fircus without appropriate authorization, please contact the Fircus Privacy Officer using the contact information provided in this Privacy Policy so that we can investigate and take appropriate action.
26. Business Transactions
Fircus may disclose, transfer, or otherwise make available personal and business information in connection with an actual, proposed, or prospective business transaction where such disclosure is reasonably necessary to evaluate, negotiate, finance, complete, or administer the transaction, or where otherwise permitted or required by applicable law.
Business transactions may include, but are not limited to:
The sale or purchase of all or part of Fircus' business;
A merger, amalgamation, or acquisition;
Financing or refinancing arrangements;
A corporate reorganization or restructuring;
An assignment or transfer of contractual rights or obligations;
The sale, transfer, or assignment of assets;
The sale, transfer, or assignment of a merchant portfolio or customer accounts;
A joint venture, strategic partnership, or similar business arrangement;
Insolvency, bankruptcy, receivership, creditor protection proceedings, or other similar corporate transactions; or
Any other transaction involving a change in the ownership, control, or operation of all or part of Fircus' business.
Where reasonably appropriate, Fircus will take steps to require prospective purchasers, successors, lenders, investors, or other authorized recipients to protect personal information through confidentiality obligations and to use the information only for purposes related to the proposed or completed transaction, unless otherwise permitted or required by applicable law.
If a business transaction is completed, personal information may be transferred as part of the transferred business assets and will continue to be protected in accordance with applicable privacy laws and any applicable contractual obligations.
27. Legal Requirements
Fircus may collect, use, retain, preserve, or disclose personal and business information without your knowledge or consent where such collection, use, retention, preservation, or disclosure is permitted or required by applicable law.
Without limiting the generality of the foregoing, Fircus may collect, use, retain, preserve, or disclose information to:
Comply with applicable laws, regulations, regulatory requirements, court orders, subpoenas, warrants, or other lawful legal processes;
Respond to lawful requests or investigations by government departments, regulatory authorities, law enforcement agencies, courts, tribunals, or other legally authorized bodies;
Comply with payment network rules, processor requirements, acquiring bank or sponsor bank obligations, anti-money laundering (AML) legislation, sanctions programs, or other legal and regulatory compliance obligations;
Detect, prevent, investigate, or respond to fraud, identity theft, money laundering, cybersecurity incidents, unauthorized transactions, security threats, or other unlawful or suspicious activity;
Enforce contracts, agreements, policies, terms and conditions, or other legal rights and obligations;
Collect outstanding debts, recover amounts owing, or otherwise enforce payment obligations;
Protect the rights, property, safety, or security of Fircus, its customers, employees, representatives, contractors, payment processors, acquiring banks, sponsor banks, business partners, service providers, or the public;
Establish, exercise, protect, or defend legal rights, claims, or legal proceedings; or
Carry out any other activity that is permitted or required by applicable law.
Where permitted by applicable law, Fircus may also preserve records or information that may be relevant to an actual or anticipated legal proceeding, regulatory investigation, audit, or dispute, even where a request for deletion or withdrawal of consent has been received.
28. Changes to This Privacy Policy
Fircus may amend, revise, or update this Privacy Policy from time to time to reflect changes in our:
Business operations and practices;
Products, services, or business offerings;
Website functionality or technology;
Service providers or business partners;
Privacy, security, or data management practices;
Applicable laws, regulations, regulatory guidance, or industry standards; or
Other operational or legal requirements.
The most current version of this Privacy Policy will be posted on the Fircus website at www.fircus.ca and will indicate the applicable "Effective Date" or "Last Updated" date.
Where required by applicable law, or where a change materially affects the way Fircus collects, uses, discloses, or otherwise processes personal information, Fircus may provide additional notice, obtain updated consent, or take any other steps required by applicable law before the changes take effect.
Your continued use of the Fircus website or our products and services following the effective date of an updated Privacy Policy constitutes your acknowledgment of the revised Privacy Policy. However, nothing in this section limits or replaces any consent requirements imposed by applicable law.
29. Contact Information
Questions, concerns, requests, or complaints regarding this Privacy Policy or Fircus' privacy practices, including requests for access to personal information, corrections, withdrawal of consent, deletion requests, or other privacy-related matters, may be directed to:
Fircus Solutions Inc.
Attention: Privacy Officer
Toll-Free: 1-844-461-7220
Website: www.fircus.ca
Email: privacy@fircus.ca
Fircus will make reasonable efforts to respond to privacy-related inquiries and requests within the time required by applicable law or, where no specific timeframe applies, within a reasonable period based on the nature and complexity of the request.