Privacy Policy

Nesto is provided by Nesto Inc. (formerly 10319376 Canada Inc), Ontario Mortgage Brokerage licence number 13044

Nesto Inc. (Nesto Inc. is hereinafter referred to as “we”, “us”, and “our”) is committed to the privacy and security of your personal information. This privacy policy (or “Policy” for short) describes how we collect, use, disclose and otherwise process your personal information, how we protect it and the controls you have over it.

This Policy is incorporated into, and is subject to, our Terms of Service. Capitalized terms used but not defined in this Policy have the meaning ascribed in our Terms of Service.

This Policy applies to the Services, including to your interactions in the course of your use thereof whether by phone, email, online chat or otherwise. This Policy does not extend to websites, mobile applications or other services of third parties. We are therefore not liable for their privacy policies, procedures and practices.

By using the Services, by communicating with us or by agreeing to receive communications from us such as our newsletter and commercial electronic messages, you accept the terms and conditions of this Policy. If you do not agree with the terms and conditions of this Policy, or if you lack the capacity or authority to agree to these terms and conditions, do not install the App, browse the Site, or otherwise access or use the Services.


  • Changes to this Policy


Please revisit this page periodically to stay aware of any changes to this Policy, which we may update from time to time. If we modify the Policy, we will make it available through the Site and the App, indicate the date of the latest version, and comply with applicable laws. Your continued use of the Site and the App after the revised Policy has become effective indicates that you have read, understood and agreed to the current version of the Policy. If you disagree with any changes made to the Policy, please uninstall the App and cease to use the Services. Additionally, if you reinstall the App or restart using the Services, you are considered to have accepted the Policy then in effect.


  • How we Collect Information


Some personal information is provided to us voluntarily by you (for example, when you create an account in order to use the Services) while some personal information is collected automatically (for example, when your browse the Site, cookies are placed on your Device (as defined in Section 3 below).

More precisely and without limitation, we collect your personal information in the following circumstances:

        1. When you create an account in order to use the Services;
        2. When you request our Services, such as when you request information about mortgages, or when you upload documents or information to your account;
        3. When you communicate with us by phone, email, online chat or otherwise;
        4. When you schedule a meeting with one of our representatives or advisors with regards to the Services;
        5. When you sign-up to our newsletter;
        6. When you interact with the digital content on the Site or on the App;
        7. When you participate in a contest or in a survey;
        8. When you post comments on the Site or on the App; and
        9. When you choose to give us permission to access your personal information from third party websites (for example, by linking to social media networks). When you do so, you allow us to collect information based on your settings and in accordance with the privacy policies of such Third Party Services. It is your responsibility to control your settings and to read and understand those policies.


  • What Information Is Collected


    • Personal Information

For the purpose of this Policy, “personal information” means information about an identifiable individual pursuant to the Personal Information Protection and Electronic Documents Act S.C. 2000, c.5.

For example and without limitation, we consider your given name, surname, date of birth, postal address, telephone number, mobile phone number and email address as personal information.

In order to provide you with the Services, we may be required to obtain from you sensitive information such as financial information (for example, your income, your assets, and your indebtedness), information from your employer (for example, an employment statement). We may also ask for your Social Insurance Number (SIN) so that we can provide your information to a credit reporting agency in order to perform a credit analysis. The SIN is the best way to ensure that the information we are provided by the reporting agency actually refers to you. Providing your SIN assists us with accurate and timely processing of your application.

    • Information Collected Automatically

Like most modern Internet sites and mobile applications, the Site and the App use cookies to record user browsing activity, such as pages visited, or technological information such as the Internet browser and operating system used to visit the Site or the App. The use of cookies and similar tracking technologies enables us to improve the Site’s or App’s performance, remember your preferences/settings, offer you an optimal experience with the Site or the App, personalize the Services and, in accordance with applicable laws, send you advertisements tailored to your interests.

A cookie is an alphanumeric online identifier that is set on your computer, tablet or mobile (“Device”)when you use the Site or the App.

Cookies can be set by us on your Device or by a third party (such as our partners).

The Site and the App contain content from and hyperlinks to certain third parties’ websites, locations, platforms, and services (“Third Party Services”). In addition, the Site and the App contain cookies operated by third parties. For example, we use certain third party analytics services, such as Google Display Network Impression Reporting, Google Analytics Demographics and Interest Reporting and other integrated services that require Google Analytics to collect information, including the collection of information via cookies. Similarly, ad serving services, advertisers, and other third parties may use tracking technologies on the Site and on the App and on the Third Party Services to track your activities across time and services, and tailor ads to you based on your activities, which may include sending you an ad on a Third Party Service or third party device after you have left the Website.

The Site and the App contain social media plugins provided by social media platforms in order to allow you to interact with us on these platforms. By browsing the Site or using the App, your browsing information may be transferred directly to the relevant social media platform, even without direct interaction on your part, due to the sole presence of the buttons on the Site and on the App. These cookies are not under our control. Please consult the privacy policies of each of these social media platforms to know more about their use of cookies and other tracking technologies and how they work.

In general, the information collected by cookies is not considered personal information since it cannot be used to identify you. You may set your Internet browser to reject cookies if desired; however, this may result in loss of functionality of certain features of the Site and the App.

Please note that we use the web analysis tool Smartlook to continuously develop our Site and provide visitors with the best possible experience. Smartlook is provided by our software partner Smartlook Inc, Lidicka 2030/20 602 00 Brno Czech Republic (“Smartlook”). Smartlook records the DOM (Document Object Model) elements within the browser window together with the associated CSS styles. The DOM is the interface between HTML and dynamic JavaScript. All elements become objects that can be called, changed, added and deleted dynamically. CSS is a stylesheet language for electronic documents and together with HTML and DOM one of the core languages of the World Wide Web. Dynamic changes to DOM elements, e.g. by using Javascript, are also recorded. This allows sessions to be recorded on dynamic web pages. Smartlook also uses cookies, which enable session-based analysis of your use of the website. The data generated by the cookie and other records about visits to our websites are sometimes stored, processed and made available to us by Smartlook. Smartlook only records your IP address and deletes it automatically after a period of 30 days at the latest. By using the “Discard user IP addresses” extension, we ensure that Smartlook does not transmit your IP address to us. Furthermore, form fields and other areas that contain personal data are not recorded. For this we use the mechanism “Excluded elements”, which is part of the functionality of Smartlook. For clarification, no personal data will be transmitted to us by Smartlook. For more information, please refer to Smartlook privacy policy, which can be found here: <>.

    • Information About Someone Else

As set forth in the Terms of Use, your account is intended for your use and information between accounts is not shared, even if the accounts are both involved in the same transaction. Therefore, if you wish to co-purchase a property with another individual, you will each need to upload documents to your individual accounts, since the documents in one account are not accessible to another. YOU MUST ENSURE THAT YOU HAVE THE REQUIRED CONSENT OF YOUR CO-PURCHASER PRIOR TO SHARING ANY OF THEIR PERSONAL INFORMATION WITH US.

    • Children’s Information

We do not knowingly collect personal information from children through our Services. If you are a minor under the laws applicable to your place of residence, please do not submit to us any personal information without the express consent of a parent or guardian.


  • How we Use Information


We take steps designed to ensure that only those employees who need access to your personal information to fulfill their employment duties will have access to it. We may use your personal information to:

        1. Manage the account creation process on the Site or on the App and, more generally, manage your account;
        2. Deliver the products and services you have requested through the Services;
        3. Design, maintain, analyze, manage, improve, market and provide products and services via the Site or the App;
        4. Help us perform transactions and verify your identity with the transaction you have requested;
        5. Provide access to the Site and the App;
        6. Respond to your queries, questions and comments;
        7. Perform quality assurance, marketing and other business analysis;
        8. Organize contests and other promotional activities;
        9. Contact you in connection with products and services you have requested;
        10. Communicate with you about changes to our policies;
        11. Send you surveys with regards to the Services, namely satisfaction surveys, in accordance with applicable laws or with your consent (if required);
        12. Understand your needs and interests and provide you with optimal services and personalized advertisements, services and products by performing profiling, where permitted under applicable laws or with your consent (if required);
        13. Improve the Site and the App performance, respond to your requests regarding the Site and the App, remember your preferences/settings with regards to the Site and the App;
        14. Send you specific information, promotional and marketing communications about us or third party products and services (for example, offers, discounts, newsletters and birthday communications), where permitted under applicable laws or with your consent (if required);
        15. Protect against error or fraud;
        16. Comply with legal and auditing requirements;
        17. Investigate breaches of the Terms of Service or the Policy; and
        18. Collect debts owed to us by you.


  • Disclosure of Personal Information


In certain circumstances or in order to perform the Services, we may disclose your personal information with:

    • Financial Institutions:

In order to provide you with the Services and the products and services that you have requested, we may share your personal information with financial institutions;

    • Promotional Partners

We may share your personal information with third parties who may associate themselves with us for any activities such as contest and other promotions;

    • An Acquirer, Successor or Assignee

In the event of change of ownership, sale, merger, liquidation, reorganization, acquisition of Nesto, in whole or in part, or in the event of any other business transactions or bankruptcy, your personal information may be transferred as part of the transaction;

    • Law Enforcement, Governmental and Administrative Entities

We may disclose your personal information with law enforcement, government and administrative entities if required to do so by law or in the good-faith belief that such action is necessary to comply with applicable laws, in response to a facility valid court order, judicial or other governmental subpoena or warrant, or to otherwise cooperate with law enforcement, governmental and administrative entities;

    • Social Media Networks or other Service Providers

We may share your personal information with social media networks and other service providers to use their marketing tools for the purposes of target and look alike marketing. For example, we may use Customer Audiences from Facebook to match the people on our customer list with people on Facebook. This enables us to target our advertisements on Facebook to the audience that has been created by Facebook through its Customer Audiences tool.

Please note that once we share your personal information with a third party, it may become subject to such third party’s privacy practices. Please note that we make commercially reasonable efforts to have your personal information used by third parties in a manner that is consistent with this Policy.


  • Storage of your Personal Information


While your personal information will be collected and stored on servers in Canada, it may be disclosed to, stored and/or otherwise processed by third parties who are located in other countries. For example, some of the service providers that process or handle personal information on our behalf are located outside of Canada. Regardless of where the processing of your personal information takes place, we will take steps to protect your personal information in accordance with this Policy, data protection laws, and where required by applicable laws, recognized data transfer mechanisms. While we use reasonable means to safeguard your personal information, it is subject to the legal requirements and governmental authorities of the foreign jurisdictions in which it is located. For example, we may be legally required to disclose personal information to a governmental authority of a foreign jurisdiction in which your personal information is located.


  • Personal Information Security


We have adopted reasonable security procedures to help protect against loss or theft, unauthorized access, disclosure, copying, use, or modification to the personal information you provide to us. While we strive to protect your personal information, we cannot guarantee or warrant the security of any personal information you disclose or transmit via our Services and cannot be responsible for the loss, theft, unauthorized access, disclosure, copying, use, or modification of your personal information, unless such acts are the result of our gross negligence or wilful misconduct or unless otherwise provided by law.


  • Retention Period


We will retain your personal information only as long as is necessary for the fulfillment of the purposes outlined in this Policy or for a longer period if required or permitted under applicable laws. Please note that if you merely unsubscribe from marketing communications such as the newsletter, we may nonetheless continue to use your personal information for marketing and business analytics purposes, unless you withdraw your consent to this activity by following the procedure set out in the “Withdrawal of Consent” section of this Policy.


  • Right to Consult and Correct Personal Information


You have the right to consult all personal information that relates to you and that is held by us, and to correct any such personal information that is inaccurate or outdated.

Information stored in your account profile may be consulted through our Site or App and corrected directly by you if necessary.

Information collected by cookies is stored in cookie files located on your device, and thus can be accessed or modified by you without involving us.

For all other privacy-related requests, you may contact us via email using the contact information in the “Contact Us” section of this Policy. Depending on the nature of your request, a reasonable fee may be required before we transcribe, reproduce, or transmit your personal information.


  • Withdrawal of Consent


You may withdraw your consent to our collection, use or disclosure of your personal information at any time by contacting us via email using the contact information in the “Contact Us” section of this Policy. However, before we implement the withdrawal of consent, we may require proof of your identity or quality.

In some cases, withdrawal of your consent to our collection, use or disclosure of personal information may mean that we will no longer be able to provide certain products or services to you, including access to the Site or the App.

  • Anti-Spam Policy

We are committed to complying with Canada’s Anti-Spam Law as it may be amended from time to time, and any other applicable rules and regulations under or relating to Canada’s Anti-Spam Law.

Commercial Electronic Messages (CEMs)

All electronic messages that encourage participation in a commercial activity (CEMs) sent to you from us will be in compliance with the requirements of Canada’s Anti-Spam Law, including, without limitation:

  1. Sender identification and sender contact information;
  2. Any unsubscribe mechanism;
  3. The processing requests to no longer receive CEMs; and
  4. Ensuring that any CEM you receive from us includes a descriptive subject line consistent with the purpose for our contacting you.


In most cases, our CEMs provide you with the ability to unsubscribe or opt out of receiving our CEMs. Any “unsubscribe” link in our CEMs will remain operational for 60 days following the sending of the CEMs. When you unsubscribe using the links provided in our CEMs, your request will be processed as soon as possible, and no later than 10 business days after you send the request. Please note that even if you unsubscribe, there are certain contexts in which we can still send you messages.

Third Parties

We do not knowingly do business with any company that participates in sending spam.

Changes to this Anti-Spam Policy

We may amend this policy at any time by publishing a new version of it on this website.


  • Contact


If you have any questions or comments about this Policy or your personal information, or to make a request to access your personal information or have it corrected, please communicate with our Privacy Officer by email using the following contact information:

[Last update: February 2020]

Published 02/11/2021 14:11 EST