Privacy Policy
Bizbio Inc. Privacy Policy
Operator: Bizbio Inc. (“Bizbio”, “we”, “us”)
Version: 1.0 (corporate notice)
Effective date: 10 September 2026
Jurisdiction: London, Ontario, Canada
This is the current public Privacy Policy of Bizbio Inc. It covers personal information we collect through Bizbio-owned websites, brands, and products, including Verified Reality (verifiedreality.ca), related apps, and customer support (together, the “Services”).
This Policy is a notice, not a waiver of statutory privacy rights. Using the Services means you have read this Policy. Where we show a click-wrap or cookie banner, that records consent for the specific processing described there.
Contact: privacy@bizbio.ca · Bizbio Inc., London, Ontario, Canada.
1. Who we are
Bizbio Inc. is a Canadian company. We operate our own brands and products. Verified Reality is one of those owned brands. We do not sell advertising audiences built from other companies’ customer lists.
Depending on how you deal with us, you may be:
• a site visitor or prospective customer;
• a client or Pro subscriber of an owned brand (including Verified Reality);
• an independent contractor Verifier on Verified Reality (not a Bizbio employee);
• a billing, support, or business contact.
Clients remain responsible for personal information they supply about their own matters. Bizbio processes that information to operate the Services they asked for.
2. Personal information we collect
2.1 Account and commercial data
Name, email, phone, organization, billing and payout details (including Stripe identifiers where used), addresses, and support communications.
2.2 Website and advertising measurement
Pages viewed, referral source, device and browser signals, and cookie or tag identifiers when you accept non-essential cookies on an owned site. This may include Google Analytics, Google Ads, Meta Pixel, and the LinkedIn Insight Tag.
2.3 Product and field data (owned brands that capture media)
Where you use Verified Reality or a similar Bizbio product: capture telemetry (time, device, location signals where permitted), content hashes, optional sensor association (PRNU associates media with a camera sensor — it does not identify a person), and media you choose to seal. Field video may incidentally depict bystanders; the person capturing is responsible for lawful capture.
2.4 Verifier dossier photos
Where a Verifier uploads dossier photos, we may compare a session image to the enrolled dossier (for example with Amazon Rekognition) to reduce account sharing. That is identity matching of the enrolled Verifier only, and only with that purpose-specific consent.
3. How we use personal information
We use the information in Section 2 to:
• provide and support the Services you asked for (accounts, billing, capture, sealing, delivery, payouts);
• prevent fraud and abuse;
• comply with law and produce records we actually hold when legally compelled;
• improve the Services using aggregated or de-identified diagnostics where feasible;
• operate Bizbio’s own first-party advertising, as described in Section 8.
We do not sell personal biometric profiles. We do not use vault media, Truth Packets, capture files, or client-matter contents to build advertising profiles.
4. Advertising, hashed lists, and B2B targeting
All advertising-audience data is first-party from Bizbio and our owned brands. We do not upload client lists, broker lists, or any third-party contact file.
4.1 Primary use — exclude existing customers
We may upload hashed identifiers from our current Pro subscriber and Verifier email lists (typically a cryptographic hash of an email address you gave us, collected under this Policy) to Meta, Google, and LinkedIn. The purpose is customer exclusion: so acquisition campaigns are not shown to people who already have an account, and budget reaches new prospects. We do not send the clear-text email to those platforms for this match.
4.2 Planned secondary use — incomplete signup
We may use first-party measurement tags (including the LinkedIn Insight Tag and equivalent Meta / Google tags) on verifiedreality.ca and other owned Bizbio sites to re-engage visitors who did not finish registration, subject to that site’s cookie banner.
4.3 Planned secondary use — account-based B2B targeting
We may upload company-name lists of regional law firms, insurers, and property managers in southwestern Ontario so advertising platforms can match those organizations for ads about our B2B verification service. Those lists are firm names we compiled for our own marketing. They are not personal data of those firms’ clients and are not taken from a client vault.
4.4 Cookies and tags
Non-essential advertising and analytics cookies / tags on owned sites use a denied default until you accept the banner. Rejecting leaves those tags off. Our banner is first-party consent, not a certified IAB TCF platform. Cookie tags (Section 4.2) are separate from hashed customer-list matching (Section 4.1).
4.5 Your choices
Object or withdraw consent: privacy@bizbio.ca. For cookies, use the site banner. Withdrawal does not undo matching or delivery that already occurred.
5. Storage, access, and residency
Application data is stored primarily in Canada, or in comparable jurisdictions used by our processors. Staff access is restricted, logged, and used for support, security, operation, and lawful process.
Where an owned product stores sealed media, that media is encrypted in transit and at rest. Bizbio maintains limited key-escrow / recovery capability so users can recover access, support can function, and we can comply with lawful demands for data we can technically decrypt. We are not a no-keys host. Vault media is still not used for advertising.
Optional public-ledger (Arweave) write, where offered, is opt-in. A successful write may leave a hash or encrypted payload that Bizbio cannot delete from the third-party ledger. That is a technical limit, not a waiver of PIPEDA (or GDPR, where it applies) rights in company-held copies. Disposing of keys plus deleting company-held copies is treated as practical erasure of readable personal information we control.
6. Retention
We keep account and billing records as needed for tax, payout, and disputes. Vault media follows the plan you selected. Integrity hashes and logs may be kept longer than playable media. Advertising hashes and matched-audience membership last only as long as needed for the campaign or exclusion, then are removed from the platform when we next update that list. Making a file unavailable in a product UI is not the same as legal deletion.
7. Processors
We use processors for hosting, storage, email, payments (Stripe), and (for Verifier dossier matching) Amazon Rekognition. Meta, Google, and LinkedIn receive hashed identifiers and/or tag signals for the advertising uses in Section 4. They act on our instructions or as independent controllers of their own ads systems. Ask privacy@bizbio.ca for the current list.
If a processor is in the United States, the transfer uses that vendor’s terms (including Standard Contractual Clauses or another lawful tool they publish).
8. Your rights (Canada — PIPEDA)
You may request access, correction, withdrawal of optional consent, and deletion of company-held personal information, subject to legal retention and the public-ledger limits in Section 5. You may complain to the Office of the Privacy Commissioner of Canada.
Email privacy@bizbio.ca. We will respond within the time PIPEDA requires.
This Policy does not ask you to waive a statutory erasure right as a condition of using our core Services.
9. EEA and United Kingdom (GDPR / UK-GDPR)
Where GDPR or UK-GDPR applies, you also have the rights of access, rectification, erasure, restriction, portability, objection to legitimate-interest processing, and withdrawal of consent, and you may lodge a complaint with your supervisory authority (including the ICO) as well as the Privacy Commissioner of Canada.
Lawful bases we rely on:
• Contract — operating your account and delivering the Services you requested.
• Legitimate interests — security, fraud prevention, integrity logs, de-identified diagnostics; we do not use these to override your rights.
• Consent — non-essential advertising cookies/tags; hashed-list custom audiences / customer exclusion (Section 4); Verifier dossier matching; optional public-ledger write. Withdrawal does not undo completed processing.
• Legal obligation — tax, accounting, and compelled production of records we hold.
Verifier facial-geometry matching, where GDPR Article 9 applies, is based on explicit consent. PRNU is not treated as a biometric of a person.
We aim to respond within one month.
10. Children
The Services are directed at businesses and independent adult contractors, not at children.
11. Incidents
If a breach of unencrypted personal information meets PIPEDA’s real-risk-of-significant-harm threshold, we will notify affected individuals and the Privacy Commissioner as soon as feasible.
12. Governing law
This Policy is governed by the laws of Ontario and the federal laws of Canada. Courts in London, Ontario have jurisdiction over disputes that cannot be resolved informally, without limiting any non-waivable statutory complaint right.
13. Changes
Material changes will be posted on this page with a new version number and effective date. Continued use after that date is acceptance, except where law requires a fresh consent for a new purpose.
Questions: privacy@bizbio.ca · Bizbio Inc., London, Ontario, Canada.