Privacy policy.
This policy describes what personal information we collect through greenlitconsulting.ca, why we collect it, and what you can do about it. It applies to anyone who visits the site or contacts us through it.
Who we are
Greenlit is a Canadian licensing and compliance consultancy serving fintech operators — money services businesses, payment service providers, crypto asset trading platforms, and the AML programs that sit underneath them. Throughout this policy, "we," "us," and "our" refer to Greenlit. "You" means anyone interacting with greenlitconsulting.ca.
We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
What we collect
We only collect what we need to respond to you and deliver our services.
Information you give us directly
- Contact form submissions: your name, work email, company, role (optional), the service you're exploring, where you are in your licensing journey, and anything you write in the message field.
- Newsletter subscriptions: your email address.
- Direct emails or messages: any personal information you choose to include when you write to us at team@greenlitconsulting.ca or contact us through any other channel.
Information we collect automatically
Our website does not currently use third-party analytics, advertising trackers, or social media pixels. The web server hosting greenlitconsulting.ca may log standard request information (IP address, user agent, referring URL, timestamp) for security and uptime purposes. We do not combine those logs with form submissions or attempt to identify visitors from them.
Cookies
We do not set first-party tracking cookies on greenlitconsulting.ca. If we add analytics or other cookie-setting tools in the future, we will update this policy and provide notice on the site before they go live.
Why we collect it
- To respond to your inquiry and schedule a scope call.
- To assess whether your business is one we can help, and to recommend a referral if it isn't.
- To send you the email briefing if you've subscribed.
- To meet our own professional, legal, and recordkeeping obligations.
We will not use your information for marketing other than the briefing you've opted into, and we don't sell or rent personal information to anyone.
Who we share it with
We share personal information with a small number of service providers strictly to operate the site and run our practice:
- Form delivery: contact form submissions pass through a hosted form-handling service that relays them to our inbox. That service receives the form contents in transit. (Provider: Web3Forms — see web3forms.com for their privacy notice.)
- Email: we use a business email provider to receive and respond to your messages.
- Hosting: the website is hosted by a third-party hosting provider; standard server logs reside there.
We only disclose personal information beyond these providers when required by law, when you've given us consent, or when sharing is necessary to deliver a service you've engaged us for (for example, lawful information requests in the course of a regulatory filing).
Where it's stored
Personal information is stored on systems located in Canada and the United States, depending on the provider. By submitting information through this site, you understand it may be processed outside the province where you reside and may be subject to the laws of those jurisdictions. We choose providers that offer reasonable safeguards consistent with PIPEDA expectations.
How long we keep it
- Form submissions and email correspondence: retained for as long as needed to respond to you and, where an engagement results, to meet professional record-keeping requirements (typically seven years).
- Inquiries that don't lead to an engagement: retained for up to 24 months, then deleted.
- Newsletter subscriptions: retained until you unsubscribe.
Your rights under PIPEDA
You have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Withdraw consent for any use we've described above (subject to legal or contractual restrictions, which we'll explain if they apply).
- Unsubscribe from the email briefing at any time using the link in any briefing email.
- Complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) if you believe we've mishandled your information.
To exercise any of these rights, email team@greenlitconsulting.ca with "Privacy request" in the subject line. We'll respond within 30 days.
Security
We use reasonable physical, organizational, and technical safeguards to protect personal information — including encrypted transport (HTTPS), access controls on our systems, and provider selection focused on data-protection posture. No method of transmission or storage is perfectly secure; we work to reduce risk but cannot guarantee absolute security.
Children
Greenlit's services are for businesses. We do not knowingly collect personal information from anyone under the age of 18. If you believe a child has provided information through the site, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. When we make material changes, we'll update the "Last updated" date at the top of the page and, where appropriate, give notice through the site or by email. Continued use of the site after a change means you accept the revised policy.
Contact us
Privacy questions, access requests, and complaints all go to the same address:
Greenlit
Email: team@greenlitconsulting.ca
Subject line: Privacy request