Skip to main content
Canadian Source Match
How It WorksPackagesResearch & EvidenceStrategicContactSign InRun a Free Match Check
Menu
How It WorksPackagesResearch & EvidenceStrategicContactSign InRun a Free Match Check

D. PRIVACY POLICY

Canonical document identifier: CSM-PRIVACY-POLICY

Version: 1.1.0

Effective / approval date: September 22, 2026

Launch scope: Canada excluding Quebec — Soft Launch 0.1

Status: LOCKED / APPROVED FOR IMPLEMENTATION

21.1 Scope

This Privacy Policy describes how Canadian Source Match collects, uses, discloses, protects, retains and otherwise handles personal information in connection with its Canadian B2B sourcing-research service.

Although CSM serves businesses and organizations, information concerning identifiable employees, owners, representatives and other individuals can still be personal information.


21.2 Privacy Accountability

CSM designates a Privacy Officer responsible for privacy compliance and governance.

The Privacy Officer oversees:

  • privacy practices;
  • questions and complaints;
  • access/correction requests;
  • privacy incidents;
  • provider/privacy review;
  • retention/privacy procedures.

The applicable title and contact information will be published where required.


21.3 Information CSM May Collect

Business/account information

  • name;
  • organization;
  • position/title;
  • business email;
  • business telephone where provided;
  • customer/account identifiers.

Authentication/security information

  • authentication events;
  • session metadata;
  • access/audit information;
  • IP/device/security information generated through ordinary system operation.

Request information

  • sourcing requirements;
  • specifications;
  • product/application information;
  • clarification responses;
  • Request/Scope history.

Customer-provided materials

  • documents;
  • drawings;
  • specifications;
  • supplier information;
  • other materials submitted for research.

Transaction information

  • package;
  • amount;
  • payment/refund state;
  • transaction references;
  • business/billing location where required;
  • tax/invoice information.

Where payment-card details are collected directly by CSM's payment provider, CSM does not need or intend to store complete card information.

Communications

  • support correspondence;
  • privacy communications;
  • transactional communications;
  • other business communications.

21.4 Purposes

CSM may process information to:

  • create/authenticate accounts;
  • protect account security;
  • verify business users;
  • administer customer relationships;
  • conduct Free Match Checks;
  • accept/manage Requests;
  • clarify requirements;
  • perform sourcing research;
  • perform QA;
  • generate Reports;
  • show Request status;
  • process payments/refunds;
  • provide secure Report access;
  • provide transactional communications;
  • provide support;
  • prevent misuse/fraud;
  • maintain audit/security records;
  • comply with legal obligations;
  • respond to privacy requests.

CSM will not use personal information for an unrelated purpose without an appropriate lawful basis or consent where required.


21.5 Business Contact Information

Canadian privacy law may treat some business-contact information differently where used solely for business/professional communications.

CSM does not assume that every piece of information associated with a business account is therefore outside privacy law.


21.6 Service Providers

CSM uses third-party service providers for defined operational purposes.

Launch provider categories include:

  • database, authentication and private storage;
  • application hosting;
  • payment processing;
  • public website hosting;
  • transactional email.

Providers may include:

  • Supabase;
  • Vercel;
  • Stripe;
  • Framer;
  • an approved transactional-email provider.

Postmark

Postmark is not to be described as an approved production provider unless Provider Activation Closure resolves its outstanding secondary-use/privacy issue.

If Postmark is not approved, an approved replacement must be substituted before production customer information is routed through transactional email.


21.7 Provider Accountability

CSM remains accountable for personal information under its control when service providers process information on CSM's behalf.

CSM uses contractual, technical and organizational measures appropriate to the processing and provider.

Provider use does not eliminate CSM's privacy obligations.


21.8 Processing Outside Canada

Depending on the provider and its subprocessors, personal information may be processed or accessed outside Canada.

Information processed in another jurisdiction can be subject to the laws and lawful-access requirements of that jurisdiction.

CSM does not represent that all customer information remains exclusively in Canada unless that has been specifically established for the relevant workflow.

Where applicable law requires more detailed processing-location disclosure, CSM will provide the required information based on the actual approved provider configuration.


21.9 Confidential Business Information

Not all confidential business information is personal information.

CSM protects Customer Confidential Information through contractual/confidentiality safeguards in addition to privacy obligations that apply to personal information.


21.10 AI and Automated Tools

Approved AI-assisted/automated tools may support sourcing-research workflows.

Customer information may enter only provider/workflow paths approved for that data.

AI output is not treated as evidence merely because an AI system generated it.

CSM does not use customer submissions for unrelated cross-customer research or general-purpose model training under its launch operating policy.


21.11 Safeguards

CSM uses safeguards appropriate to the circumstances, which may include:

  • authentication;
  • access controls;
  • Customer/Request isolation;
  • private storage;
  • authorization checks;
  • secure Report delivery;
  • audit records;
  • provider controls;
  • retention/deletion controls;
  • restricted-upload/quarantine controls.

No internet-connected service can guarantee absolute security.


21.12 Retention

CSM retains personal information only as long as reasonably necessary for the identified purpose and applicable:

  • business;
  • contractual;
  • security;
  • legal;
  • tax/accounting;
  • evidentiary

requirements.

An active Legal Hold or mandatory preservation requirement overrides ordinary deletion.

Account closure does not necessarily require immediate destruction of all related transaction, contractual, security or legal records.

Customer-facing Report availability is separate from CSM's internal retention of records. Expiration or removal of portal access to a Report does not mean that the Report or all related information has been deleted. Internal retention, deletion and preservation remain governed by CSM's applicable retention requirements, identified purposes, Legal Hold requirements and applicable law.


21.13 Access and Correction

Individuals may request access to personal information concerning them and correction of inaccurate information, subject to applicable law.

CSM may take reasonable steps to verify identity before responding.


21.14 Account Closure and Deletion

CSM evaluates account closure/deletion requests under applicable law and the approved retention schedule.

Where information must remain retained, account access may be disabled while required records remain protected.


21.15 Privacy Incidents

CSM maintains procedures for assessing suspected privacy/security incidents.

Where applicable law requires notification or reporting, CSM will follow the applicable threshold and timing.

CSM does not promise an artificial instantaneous response time.


21.16 Contact

Privacy questions, complaints and requests may be sent using CSM's published privacy contact.

CSM will respond as soon as reasonably practicable and within applicable legal requirements.

CSM may use the same monitored public mailbox for multiple functional contact roles where legally appropriate.


21.17 Provincial Requirements

Depending on the circumstances, federal and/or provincial private-sector privacy law may apply.

Nothing in this Policy waives rights that applicable privacy law makes mandatory.


21.18 Quebec

If CSM accepts Quebec customers, applicable Quebec privacy, contract and French-language requirements must be satisfied before paid authorization is enabled.


21.19 Changes

CSM may update this Privacy Policy to reflect changes in providers, law or operations.

CSM will maintain an effective date/version.

A future version will not be represented as having governed earlier processing where it did not.

Canadian Source Match

Research-backed sourcing intelligence for Canadian businesses.

CompanyHow It WorksResearch & EvidenceContact
PoliciesPrivacyTermsMatch GuaranteeRestricted Sourcing
Secure accountSign InYour RequestsFree Match Check
Canadian Source MatchB2B service · CanadaSoft Launch 0.1 · Canada excluding Quebec