Skip to main content

Privacy policy

Last updated: September 16, 2026

This policy describes what personal information Pathway Mortgage collects through this website, the client portal and our messaging, why we collect it, who processes it for us, how long it is kept, and the choices you have. It is written from how our systems actually work. It is a statement of our practices, not legal advice.

1. Who we are

Pathway Mortgage provides Level 2 Mortgage Agent services through Get A Better Mortgage, FSRA Licence #10874, a licensed mortgage brokerage in Ontario, Canada. In this policy, "we," "us," and "our" refer to Pathway Mortgage acting through Get A Better Mortgage. Our principal place of business is in Toronto, Ontario.

2. What we collect, form by form

You choose what to give us. Nothing on this website asks for a Social Insurance Number, a date of birth, or a bank account or card number, and you should not type those into any form or the chat.

  • Contact form and callback request: first and last name, email, phone, topic, your message, and how you heard about us.
  • Mortgage checkup and free mortgage review: name, email, phone, province, and the mortgage details you enter (property type, value, balance, lender, rate, term type, maturity date), any life changes you select, and optional notes. The free review has a checkbox that says you have your latest mortgage statement available. Ticking it records only a yes or no. No document is uploaded on that page; your strategist asks for the statement later through the client portal.
  • Online application: for up to two borrowers, first and last name, email and mobile number; property details (value or purchase price, balance, use, address, lender, renewal or closing date, down payment and its source where relevant); income type, annual amount and employer; how you heard about us; and your consent to the Terms of Use, this policy and electronic records, which we record with the date, time and IP address it was given. A saved but unfinished application (a draft) is stored so you can come back to it.
  • Client portal: your email address (for sign-in links), documents you upload (PDF, JPG, PNG, WEBP or HEIC, up to 12 MB each, at most 30 per application), support requests you send through the portal, and any document you sign electronically.
  • Calculator results by email and guide downloads: your name and email, and for the calculator, the figures you entered and the results.
  • Rate Watch: your email, first name, and the page you signed up from.
  • Chat assistant: the messages you type (see section 8).
  • With every form: the date and time, your IP address (used for rate limiting and for the consent record on the application), a reCAPTCHA spam score, and, if you accepted analytics cookies, your Google Analytics client identifier and Google Ads click identifier so we can tell which campaign a lead came from.

3. How we use it

We use this information to answer you, to review your mortgage and prepare and submit applications to lenders, to send the messages you asked for (sign-in links, application confirmations, one reminder if a draft is left unfinished for a day, Rate Watch updates), to keep our forms free of spam, to understand which pages and campaigns bring people to us, and to meet our record-keeping duties under the Mortgage Brokerages, Lenders and Administrators Act and FSRA rules.

4. Who we share it with

We share your information with mortgage lenders and insurers only as part of an application you have asked us to make, and with Get A Better Mortgage for licensing, supervision and compliance. We do not sell personal information. The service providers below process data on our instructions.

  • Resend (United States): sends our email (sign-in links, confirmations, notifications, Rate Watch, and messages your agent sends you). Resend receives your email address and the message.
  • Twilio (United States): sends text messages to existing clients who have given express consent. Twilio receives your mobile number and the message. Reply STOP to any message to stop; your number is added to a do-not-text list that we keep ourselves, and it is checked before every send.
  • Google reCAPTCHA (Google, United States): runs on every page to tell people from bots on our forms. It is a security function, not advertising. Google receives your IP address and browser signals and returns a score that we store with your submission. Google's privacy policy and terms apply.
  • Google Analytics and Google Ads (Google, United States): only if you accept them in the cookie banner. See section 6.
  • ZeroBounce (United States): when enabled, checks that an email address you enter can receive mail before we rely on it. It receives the address only.
  • Anthropic (United States): generates the chat assistant's replies. See section 8.
  • DocuSign (United States): provides electronic signatures inside the client portal when a document needs your signature. DocuSign receives your name, email and the document. The signed PDF is stored in the same encrypted document store as your uploads.
  • Stripe (United States): processes subscription payments for the agent platform we use (see section 9). Card details are entered on Stripe's own pages and never reach our servers. Website visitors and mortgage clients are not charged through this site.
  • Backblaze (United States): stores our nightly encrypted backups. See section 7.
  • Cloudflare and DigitalOcean: Cloudflare fronts the website for security and caching and sees your IP address; DigitalOcean hosts the server that stores the encrypted data described in section 7; that server is in DigitalOcean's Toronto, Canada data centre, so the data we hold stays in Canada. Encrypted backups go to Backblaze in the United States, and some of the processors listed above operate there too.

Where a provider is outside Canada, your information may be accessed by authorities under the laws of the country where it is processed or stored. Regulators such as FSRA and the courts may also require us to disclose records.

5. Email tracking and Rate Watch

Email tracking. Emails your agent sends you from our platform may include a tracking pixel and tracking links so we can see that a message was opened or a link was clicked. When that happens we record the time, a salted one-way hash of your IP address (never the address itself) and a shortened browser identifier. Detailed events are kept for 90 days and are then folded into per-message totals, which are dropped after 400 days. Most email programs let you block remote images, which blocks the pixel. The links do not carry any personal information.

Rate Watch. Rate Watch emails carry a one-click unsubscribe link (/intake/ratewatch/unsubscribe) and standard list-unsubscribe headers, and they show our mailing address. Unsubscribing adds your address to a suppression list that we keep and check before every send. Signing up again lifts the suppression.

6. Cookies, local storage, analytics and advertising

Consent first. On your first visit a banner offers "Accept all" or "Essential only". Until you choose, Google Analytics and Google Ads are told that storage is denied (Google Consent Mode v2), and the Google Ads tag is not loaded at all. If you accept, Google Analytics may set its cookies (_ga, _ga_*) and the Google Ads tag is loaded, which allows conversion measurement and remarketing (_gcl_* cookies). If you choose essential only, no advertising cookies are set and analytics runs without cookies, sending only aggregate, unidentified pings. You can change your choice at any time from the "Cookie settings" link in the footer. Your choice is stored in your browser under pm_consent with the date and a version number; when we change what we ask for, the banner returns.

What this site stores in your browser (localStorage and sessionStorage, set by our own scripts, never sent to advertising partners):

  • pm_consent: your cookie choice, its date and version.
  • pathway-lang: your English or French preference, kept for 30 days.
  • pw_portal_token: your client portal sign-in token, so you stay signed in. Sessions end after 30 days without use and always after 90 days, when you are asked for a new sign-in link. Signing out removes it.
  • _gclid: the Google Ads click identifier from the link that brought you here, attached to a form you later submit so we can credit the campaign.
  • pathway_checkup_leads and pathway_review_leads: a copy of a checkup or review submission that could not reach our server, so it can be retried; pathway_review_draft (session only): the review you are partway through.
  • pathway_chat_state: whether the chat window is open and its recent messages, so it survives a page change.
  • pw_rm_scenario (session only): the reverse mortgage estimate you carry into the review form.

reCAPTCHA sets a cookie on Google's domain (_GRECAPTCHA) for spam detection. Cloudflare may set a short-lived security cookie. These are essential and do not depend on the banner. You can clear any of this through your browser settings.

7. How we protect and keep it

Every contact, checkup, review, calculator and guide submission, every application and draft, and every portal session, support request and uploaded document is encrypted at rest with AES-256-GCM under keys that exist only on our server, and everything travels over TLS. The Rate Watch list (email, first name, sign-up page and date) is kept as a plain file on the same server with restricted permissions. Uploaded documents are checked by content type before they are accepted. Form endpoints are rate limited and the site sends a strict Content Security Policy. Every night we make an encrypted backup (AES-256 with a passphrase held off the server) and copy it to Backblaze; backups are kept for 7 days on our server and 30 days at Backblaze, then deleted. No method of storage is completely secure and we cannot promise absolute security.

Retention our systems enforce automatically:

  • Portal sign-in links: 15 minutes, single use. Portal sessions: 30 days without use, 90 days at most.
  • Unfinished application drafts: deleted after 60 days without activity. One reminder email is sent after 24 hours of inactivity, never more.
  • Portal upload copies: once a document has been attached to your working file, the portal's copy is deleted 30 days later. The working-file copy is kept with your mortgage file.
  • Email tracking events: 90 days in detail, totals for 400 days (section 5).
  • Chat transcripts: 90 days (section 8).
  • Backups: 7 days locally, 30 days at Backblaze.

Retention set by regulation: contact requests, reviews, applications and mortgage files are kept for as long as FSRA record-keeping rules require for a licensed brokerage, and are then disposed of securely. There is no automatic deletion of these records; requests to delete earlier are handled by hand (section 10).

8. AI chat assistant

The chat bubble on our pages is an AI assistant for general mortgage questions. Your messages are sent to Anthropic, a third-party AI provider, to generate a reply. Under Anthropic's API terms your conversation is not used to train its models. We keep a record of each conversation for up to 90 days to check the assistant's answers, to meet FSRA record-keeping duties, and to answer questions you may have about a past chat. Transcripts are encrypted at rest. Your IP address is stored as a one-way hash so the same visitor's sessions can be linked without keeping the address. We try to remove Social Insurance Numbers, card numbers, email addresses and phone numbers from messages before storage, but you should not rely on this: please do not share sensitive details in the chat. After 90 days transcripts are deleted automatically. To have one deleted sooner, email info@pathwaymortgage.ca with the approximate date and time and we will do so within 30 days.

9. MDMT, the agent platform

Mortgage Data Mining Tool (MDMT) at mdmt.pathwaymortgage.ca is a private platform for licensed mortgage agents. This section applies only to agents who sign in there. To prevent account sharing and meet FSRA obligations, MDMT records each sign-in with the time (UTC), licence name, IP address, approximate location (city, region and country derived from the IP by Cloudflare), browser and operating system string, and a session identifier. No GPS coordinates or postal codes are collected. Failed sign-ins are logged with the same fields and a redacted prefix of the key tried. Sessions end after 8 hours of inactivity; revoking a licence ends its sessions at once. Sign-in records are kept for 365 days and then purged. Agents may ask for their own sign-in history at info@pathwaymortgage.ca. Agent subscriptions are billed through Stripe; card details never touch our servers.

10. Your rights under PIPEDA

Under the Personal Information Protection and Electronic Documents Act you may ask what personal information we hold about you and receive a copy, ask us to correct it, and withdraw your consent to its collection or use, subject to the legal and contractual limits that apply to a mortgage file. You may also complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca). To exercise any of these rights, email info@pathwaymortgage.ca. We will respond within 30 days. To stop text messages, reply STOP. To stop Rate Watch, use the unsubscribe link in any Rate Watch email. To stop marketing emails from your agent, use the unsubscribe link in the email or write to us.

How to make a request. Email info@pathwaymortgage.ca and tell us whether you want access to, a correction of, or deletion of your personal information, and which form, application or file it relates to. We may ask you to confirm your identity before we release or change anything. We answer in writing within 30 days of receiving your request. If we need more time, as PIPEDA permits, we will tell you before those 30 days are up, explain why, and answer within a further 30 days at most. We correct information that is shown to be inaccurate or incomplete and, where appropriate, pass the correction on to lenders or insurers who received it. We delete information on request unless we are required to keep it, for example mortgage file records that FSRA record-keeping rules require us to retain (section 7); in that case we tell you what we are keeping and why. If we refuse any part of a request, we explain why in writing and remind you of your right to complain to the Office of the Privacy Commissioner of Canada.

11. If a breach of security safeguards happens

If personal information under our control is lost, or accessed or disclosed without authorization, because of a breach of our security safeguards, we act to contain it and assess whether it creates a real risk of significant harm to anyone affected, considering how sensitive the information is and how likely it is to be misused. Where there is a real risk of significant harm, we report the breach to the Office of the Privacy Commissioner of Canada and notify the affected individuals directly as soon as feasible, telling you what happened, what information was involved, what we have done, and what you can do to reduce the risk. We may also notify other organizations, such as a lender, when that can reduce the risk of harm. We keep a record of every breach of security safeguards, whether or not it had to be reported, for at least 24 months.

12. Changes to this policy

We update this page when our systems change and show the date at the top. Material changes to what we ask for in the cookie banner cause the banner to appear again.

13. Contact us

Questions about this policy or about your personal information:

Pathway Mortgage
Level 2 Mortgage Agent services provided through Get A Better Mortgage, FSRA Licence #10874
4-57 Lakeshore Road East, Mississauga ON L5G 1C9
Email: info@pathwaymortgage.ca

Ready to talk strategy?
Talk to an Advisor