Skip to content
INSTANT.CREDIT

Privacy Policy

Privacy Policy

Last updated: August 25, 2026

Effective date: August 25, 2026

This Privacy Policy describes how 9352-1300 Québec Inc., a corporation incorporated under the Business Corporations Act (Québec), CQLR c. S-31.1, having its head office at 9900 Boul. Cavendish, Saint-Laurent (Québec) H4M 2V2, doing business as INSTANT.CREDIT (“INSTANT.CREDIT”, “we”, “us”, “our”), collects, uses, communicates, retains, and protects personal information in the course of operating its website https://business.instant.credit (the “Site”), and of providing or arranging business-purpose financing (the “Services”).

We are subject to the Act respecting the protection of personal information in the private sector, CQLR c. P-39.1, as amended by the Act to modernize legislative provisions as regards the protection of personal information (“Law 25”) (together, the “Québec Privacy Act”), and, where applicable, to the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (“PIPEDA”).

Language / Langue

A French-language version of this Privacy Policy is in preparation and will be published at https://business.instant.credit/politique-de-confidentialite/. Une version française de la présente politique de confidentialité est en cours de préparation et sera publiée à cette adresse. Once published, in the event of any discrepancy, the French version prevails to the extent required by the Charter of the French Language, CQLR c. C-11. A French-language version is available on request at privacy@instant.credit.

1. Scope

For purposes of this Policy, “personal information” has the meaning given to it in the Québec Privacy Act: any information which relates to a natural person and allows that person to be identified, directly or indirectly. This Policy applies to the personal information of natural persons — including business owners, directors, officers, guarantors, and other individuals connected to an applicant business. It does not apply to information that concerns only a juridical person (for example, a corporation’s financial statements), except where that information also identifies a natural person.

This Policy applies in addition to our Terms and Conditions and to any credit agreement or consent form you sign with us. Where you have signed a specific consent form, that consent governs the matters it addresses.

2. Person in Charge of the Protection of Personal Information

In accordance with section 3.1 of the Québec Privacy Act, INSTANT.CREDIT has designated a person in charge of the protection of personal information (the “Privacy Officer”). The Privacy Officer oversees our compliance with this Policy and with applicable privacy law, and is the point of contact for all requests, questions, and complaints concerning personal information.

3. Personal Information We Collect

We collect only the personal information that is necessary for the purposes identified in section 4 below.

3.1 Information you provide to us

  • Identity and contact details — full name, date of birth, residential address, email address, mobile and other telephone numbers, and, only where required for credit-reporting or regulatory purposes, social insurance number;

  • Business information — legal name, trade name, business number, address, ownership structure, time in business, industry, revenue, and financial information concerning the applicant business;

  • Identity (KYC) documents — government-issued photo identification (driver’s licence, passport, provincial ID) and images of such documents provided for identity verification;

  • Application information — the information you submit in an application form or provide to us by telephone, email, SMS, or chat, including bank statements and supporting documents you upload.

  • Credit bureau reports — credit reports and scores concerning you obtained from credit reporting agencies, including TransUnion of Canada, Inc. and Equifax Canada Co., after you have given the express consent described in section 6;

  • Bank-account verification data — account details, balances, and transaction history retrieved from your financial institution through Flinks Technology Inc., a bank-connection provider, when you choose to connect your bank account to verify your banking information;

  • Biometric identity-verification data — where you choose to complete remote identity verification, our identity-verification provider (currently Onfido), acting on our behalf, captures a live image of your face and a digital representation (template) extracted from it, and compares it against your government-issued identity document, with the express consent you give at that step. The collection and use of this data is governed by sections 44 and 45 of the Act to establish a legal framework for information technology, CQLR c. C-1.1. Biometric verification is optional — a non-biometric alternative is available on request — and biometric data is used solely for identity verification and destroyed promptly after verification;

  • References and verifications — information from references, landlords, other financial institutions, and public registries (such as the Registraire des entreprises du Québec, the RDPRM, and equivalent registries elsewhere in Canada) used to verify your application.

3.3 Records generated in the course of the Services

  • Electronic-signature records — signed documents, signature certificates, and related audit-trail data (such as signer email, IP address, and timestamps) generated through PandaDoc, our electronic-signature provider;

  • SMS and other communications — the content of SMS messages, emails, and other communications exchanged with us, and records of when they were sent and received;

  • Account and servicing records — payment history and records relating to the administration of any financing you obtain through us.

3.4 Information collected automatically on the Site

When you visit the Site, standard technical information — such as your IP address, browser type, and the pages requested — is recorded in the ordinary server logs of our hosting infrastructure and used for security and operation of the Site. The Site does not load third-party analytics, advertising, or profiling scripts. Section 15 describes the Site’s use of cookies and similar technologies in detail.

4. Purposes of Collection and Use

We collect, use, and communicate personal information for the following purposes:

  • (a) verifying your identity and the identity of the persons connected to an applicant business;

  • (b) receiving, assessing, and deciding on applications for financing, including evaluating creditworthiness;

  • (c) conducting credit checks, fraud screening, and anti-money-laundering and sanctions verification;

  • (d) preparing, delivering, and obtaining signatures on financing documents;

  • (e) establishing, administering, servicing, and collecting on any financing provided by us, and enforcing our rights under any agreement;

  • (f) communicating with you about your application, your account, and the Services, including by SMS as described in section 14;

  • (g) with your consent, sending you commercial electronic messages about products and services that may interest you;

  • (h) maintaining business and regulatory records, including records required under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, S.C. 2000, c. 17 (the “PCMLTFA”);

  • (i) detecting, investigating, and preventing fraud, security incidents, and unlawful activity;

  • (j) complying with legal and regulatory obligations and responding to lawful requests from public authorities; and

  • (k) any other purpose for which we obtain your consent.

We do not use personal information for purposes other than those identified above without first obtaining your consent, except where permitted or required by law. We do not sell personal information.

We collect personal information directly from you wherever possible, and from third parties only with your consent or as otherwise permitted by law. Depending on the sensitivity of the information and the circumstances, consent may be express or implied; sensitive information — including biometric information, financial information, banking data, and social insurance number — is collected and used only with your express consent.

You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice, by contacting the Privacy Officer. Withdrawing consent may prevent us from processing your application or continuing to provide certain Services. Withdrawal does not affect processing that occurred while your consent was in effect, nor information we are required by law to retain.

6. Express Consent for Credit Checks

Before we obtain a credit report concerning you, you sign an express written consent — presented to you and signed electronically as part of the application process — authorizing us to obtain credit reports from TransUnion of Canada, Inc., Equifax Canada Co., and/or another consumer reporting agency, at the time of application and, where you have so consented, on an ongoing basis during the term of your account for the purposes of administering it, evaluating ongoing creditworthiness, and collecting amounts owing. We may also report information about your account, including payment history, to credit reporting agencies.

7. Communication of Personal Information to Third Parties

We may communicate personal information to:

  • Service providers retained to perform functions on our behalf, including credit reporting agencies (TransUnion of Canada, Inc.; Equifax Canada Co.), our bank-connection provider (Flinks Technology Inc.), our identity-verification provider (currently Onfido), our electronic-signature provider (PandaDoc), our SMS and telecommunications providers, our application-processing platform, and our hosting, document-management, professional-services, and collections providers;

  • Service providers — we communicate your application information to the service providers that support our underwriting and funding, including credit bureaus, bank-verification and identity-verification providers, for the purpose of assessing and funding your application;

  • Credit reporting agencies and other creditors, for credit-reference purposes;

  • Public authorities, regulators, law enforcement, and FINTRAC, where required or permitted by law; and

  • Successors or assignees in connection with a merger, acquisition, financing, securitization, or sale of all or part of our business or assets, subject to confidentiality undertakings appropriate to the transaction.

When we entrust personal information to a service provider, we enter into a written agreement requiring the provider to use the information only for the purposes of its mandate, to keep it confidential, to apply appropriate security measures, and to return or destroy it at the end of the mandate, in accordance with section 18.3 of the Québec Privacy Act.

8. Communication Outside Québec and Canada

Some of our service providers store or process personal information outside Québec, including elsewhere in Canada and in the United States. Personal information located in another jurisdiction is subject to the laws of that jurisdiction, including lawful access by its public authorities.

Before communicating personal information outside Québec, we assess the privacy-related factors required by section 17 of the Québec Privacy Act — the sensitivity of the information, the purposes for which it is used, the protective measures (including contractual measures) that apply, and the legal framework of the receiving jurisdiction — and we proceed only where the assessment establishes that the information will receive adequate protection.

9. Retention

We retain personal information only as long as necessary for the purposes for which it was collected, or as required by law. As a general rule:

  • application information of declined or abandoned applicants is retained for up to twenty-four (24) months after the decision or abandonment;

  • customer account, financing, and KYC records are retained for seven (7) years following the end of the business relationship, or such longer period as applicable law requires (the PCMLTFA requires retention of certain records for at least five years);

  • biometric verification data is destroyed promptly after successful verification, in accordance with section 44 of the Act to establish a legal framework for information technology, CQLR c. C-1.1;

  • Site log and browser-storage data are retained only briefly, as described in section 15.

When personal information is no longer required, we securely destroy it or anonymize it in accordance with section 23 of the Québec Privacy Act.

10. Safeguards

We protect personal information with physical, administrative, and technical safeguards proportionate to its sensitivity, including encryption of data in transit, access controls limiting access to personnel who need the information to perform their duties, logging, confidentiality undertakings, and incident-response procedures. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security; we encourage you to protect your own devices and credentials.

In accordance with sections 3.5 to 3.8 of the Québec Privacy Act, we maintain a register of confidentiality incidents and, where an incident presents a risk of serious injury, we notify the Commission d’accès à l’information du Québec (the “CAI”) and the affected individuals with diligence.

11. Automated Processing

Where a decision concerning you is based exclusively on automated processing of your personal information, we inform you at the time of, or before, the decision, in accordance with section 12.1 of the Québec Privacy Act. On request, you are entitled to be informed of the personal information used to render the decision and of the principal factors and parameters that led to it, to have that information corrected, and to submit observations to a member of our personnel who has the authority to review the decision.

12. Your Rights

Subject to the restrictions provided by law, you have the right to:

  • Access the personal information we hold about you (s. 27 of the Québec Privacy Act; Principle 4.9 of PIPEDA);

  • Rectify personal information that is inaccurate, incomplete, or ambiguous (s. 28);

  • Withdraw your consent to the use or communication of your personal information, as described in section 5;

  • Receive the computerized personal information you provided to us in a structured, commonly used technological format, or have it communicated to a person or body authorized by law to collect it (s. 27);

  • Request de-indexation of a hyperlink attached to your name where its dissemination contravenes the law or a court order (s. 28.1); and

  • Be informed about automated decision-making and submit observations, as described in section 11.

Requests should be addressed in writing to the Privacy Officer using the contact details in section 2. We respond within thirty (30) days of receipt, as required by section 32 of the Québec Privacy Act. We may need to verify your identity before acting on a request. Access is free of charge; reasonable fees for transcription, reproduction, or transmission may apply and will be communicated to you in advance.

13. Complaints

If you are dissatisfied with how we handle your personal information or with our response to a request, you may file a complaint with the Privacy Officer. You may also, at any time, complain to the Commission d’accès à l’information du Québec (www.cai.gouv.qc.ca) or, for matters governed by PIPEDA, to the Office of the Privacy Commissioner of Canada (1-800-282-1376, www.priv.gc.ca).

14. SMS and Electronic Communications

Where you have provided your mobile telephone number and the required consent, we may send you SMS messages concerning your application, your account, and the Services — for example, application status updates, document requests, and servicing notices — and, only where you have separately consented, marketing messages, in accordance with Canada’s Anti-Spam Legislation, S.C. 2010, c. 23 (“CASL”).

  • You may opt out of SMS messages at any time by replying STOP to any message. After you reply STOP, we send at most one confirmation message and then cease SMS communications to that number, except as required to complete a transaction you have already entered into.

  • Message and data rates charged by your mobile carrier may apply.

  • You may unsubscribe from marketing emails at any time via the unsubscribe link in any message or by writing to unsubscribe@instant.credit.

  • Opting out of marketing communications does not affect transactional communications relating to an application or account you hold with us.

15. Cookies and Website Technologies

The Site is deliberately light on tracking. Specifically:

  • No analytics or advertising trackers. The Site does not load third-party analytics, advertising, retargeting, or social-media tracking scripts, and does not use cookies to profile you.

  • Local browser storage. The Site stores two preferences in your browser’s local storage: your display-theme choice (light or dark) and your response to the cookie notice. These values remain on your device, are not transmitted to us, and can be cleared at any time through your browser settings.

  • Web fonts. The Site loads its typeface from Google Fonts. When a page loads, your browser requests the font files from Google’s servers, which necessarily receive your IP address; that request is subject to Google’s own privacy policy.

  • Application form. When you open the online application, it is served in a frame from our secure application platform on a separate domain. That platform uses only the cookies and browser storage strictly necessary to operate your application session, and it loads only when you choose to start an application.

  • Server logs. Our hosting infrastructure keeps standard, short-lived server logs (IP address, request, timestamp) for security and reliability.

  • Outbound links. The Site contains links to third-party services — for example, WhatsApp for chat and a scheduling service for booking calls. Once you leave the Site, the third party’s own terms and privacy policy apply.

Because the Site does not use technologies that identify, locate, or profile you within the meaning of section 8.1 of the Québec Privacy Act, no such technology is active by default, and none is activated without your consent. If we introduce any such technology in the future, we will update this Policy and request your consent before activating it.

16. Minors

The Site and the Services are directed to businesses and their principals, not to minors. We do not knowingly collect personal information from a minor under fourteen (14) years of age without the consent of the person having parental authority, in accordance with section 4.1 of the Québec Privacy Act, and we do not extend credit to minors.

17. Changes to this Policy

We may amend this Policy from time to time. When we do, we will post the revised Policy on the Site and update the “Last updated” date above. Material changes will be communicated by reasonable means, which may include a notice on the Site or an email to the address on file. The version published on the Site is the version in force.

18. Contact

9352-1300 Québec Inc. d/b/a INSTANT.CREDIT


Questions about this policy? Email the Privacy Officer at privacy@instant.credit or call (514) 600-0924.

French version: Politique de confidentialité

Call Now Apply Now