Last Updated: August 24, 2026
This Privacy Policy explains how Brisk Pay collects, uses, discloses, protects, and retains personal information when you access our website, register for or use the Brisk Pay platform, use our products and services, communicate with us, or otherwise interact with Brisk Pay.
Brisk Pay is committed to handling personal information responsibly and in accordance with applicable Canadian privacy, financial services and regulatory requirements.
For the purposes of this Privacy Policy, personal information means information about an identifiable individual as defined under applicable privacy law.
This Privacy Policy should be read together with our Terms and Conditions and Compliance & AML Programme.
The information we collect depends on your relationship with Brisk Pay, the services you use and the information required to provide those services or meet applicable legal and regulatory requirements.
Personal and Contact Information
We may collect information including:
Full legal name
Date of birth
Residential address
Email address
Telephone number
Government-issued identification information
Copies or images of identification documents
Other information required to confirm your identity
Business Information
Where you use Brisk Pay on behalf of a company or other legal entity, we may collect:
Legal business name
Trading name, where applicable
Business registration or incorporation information
Registered and operating addresses
Nature of the business
Business contact information
Directors and authorized representatives
Shareholder and ownership information
Ultimate Beneficial Owner information
Corporate documents and supporting records
Information relating solely to a business may not constitute personal information. However, information relating to identifiable directors, shareholders, beneficial owners, representatives, employees or other individuals will be handled as personal information where required by applicable law.
Verification and Compliance Information
Where required to provide our services or comply with legal and regulatory obligations, we may collect or generate information relating to:
Identity and business verification
Beneficial ownership
Customer due diligence
Source of funds
Source of wealth, where appropriate
Purpose and expected nature of transactions
Customer and transaction risk assessments
Politically Exposed Person or Head of International Organization status, where applicable
Sanctions and compliance screening
Supporting invoices, contracts or other transaction documentation
Information provided during compliance reviews
We may request additional information where necessary to verify a customer, understand a transaction or meet our legal and regulatory obligations.
When you use Brisk Pay to make, receive or manage payments or other financial transactions, we may collect and process information including:
Transaction amounts
Currencies
Exchange rates
Transaction dates and times
Sender information
Beneficiary information
Bank, payment account or wallet information
Payment instrument information
Transaction reference numbers
Transaction purpose
Transaction history
Counterparty information
Origin and destination of funds
Fees and charges
Transaction status
Supporting payment information
Some transaction information may be received from or shared with banks, financial institutions, payment providers and other service partners involved in providing the relevant service.
Brisk Pay may receive information from third parties where necessary to provide our services, verify customers or businesses, prevent fraud, manage risk or meet legal and regulatory obligations.
These parties may include:
Identity verification providers
Business verification providers
Banks and financial institutions
Payment service providers
Regulated financial services partners
Compliance and screening providers
Fraud prevention providers
Corporate registries
Publicly available sources
Government or regulatory sources
We may combine information received from these sources with information provided directly to Brisk Pay.
When you access the Brisk Pay website, application or platform, certain technical information may also be collected as part of operating, securing and maintaining the service.
Depending on the technology being used, this may include:
IP address
Device information
Browser information
Operating system
Login and authentication information
Date and time of access
Platform activity
Technical and security logs
Session information
This information may be used to operate the platform, maintain security, investigate technical issues, prevent fraud and understand how our services are being used.
Brisk Pay may use personal information for purposes reasonably connected with operating our business, providing our services, protecting customers and complying with applicable law.
These purposes may include:
Providing Our Services
We may use information to:
Register and manage your Brisk Pay account
Provide payment and financial services
Process and manage transactions
Operate wallets or payment facilities where applicable
Calculate fees and exchange rates
Provide customer support
Communicate with you about transactions or your account
Maintain and improve the Brisk Pay platform
Verifying Customers and Businesses
We may use information to:
Verify identity
Verify companies and other legal entities
Confirm authorized representatives
Identify and verify beneficial owners
Prevent identity fraud and impersonation
Meeting Legal and Regulatory Requirements
We may process information where necessary to comply with applicable legal and regulatory obligations, including requirements relating to:
Customer identification and verification
Customer due diligence
Beneficial ownership
Financial crime prevention
Transaction monitoring
Sanctions
Fraud prevention
Regulatory record keeping
Regulatory reporting
Requests from courts, regulators, law-enforcement bodies or other competent authorities
More information about Brisk Pay’s financial crime prevention approach is available in our Compliance & AML Programme.
Security and Fraud Prevention
We may use information to:
Protect customer accounts
Detect unauthorized activity
Prevent and investigate fraud
Protect our systems and services
Investigate security incidents
Enforce our Terms and Conditions
Manage legal and operational risks
Brisk Pay collects, uses and discloses personal information in accordance with applicable Canadian privacy laws.
Depending on the circumstances, we may process personal information:
With your express or implied consent
For purposes that a reasonable person would consider appropriate in the circumstances
Where necessary to provide services you have requested
To administer our relationship with you
Where collection, use or disclosure is required or permitted by law
To meet regulatory or legal obligations
Where consent is required, we seek to identify the purposes for which information will be collected, used or disclosed.
You may withdraw consent to certain uses of your personal information, subject to applicable legal, regulatory and contractual restrictions.
Withdrawing consent may limit our ability to provide some or all of our services.
Certain information may need to be collected, used, disclosed or retained regardless of withdrawal of consent where Brisk Pay is required or permitted to do so by law.
Brisk Pay does not disclose personal information indiscriminately.
We may disclose information to third parties where reasonably necessary to provide our services, process transactions, operate our business, protect customers or comply with applicable legal requirements.
Financial and Payment Service Providers
Information may be shared with:
Banks
Payment service providers
Financial institutions
Wallet providers
Settlement partners
Other regulated financial services providers
Verification, Compliance and Fraud Prevention Providers
Information may be shared with providers that assist Brisk Pay with:
Identity verification
Business verification
Customer due diligence
Beneficial ownership verification
Screening
Fraud prevention
Transaction monitoring
Risk assessment
Regulatory compliance
Technology and Operational Service Providers
We may use third-party providers to support functions such as:
Hosting and infrastructure
Data storage
Cybersecurity
Communications
Customer support
Platform operations
Analytics
Service providers are expected to handle information only for authorized purposes and subject to applicable contractual, privacy and security requirements.
Professional Advisers
Where appropriate, information may be disclosed to professional advisers such as lawyers, accountants, auditors, consultants or insurers.
Government and Regulatory Authorities
We may disclose information to FINTRAC, law-enforcement agencies, courts, regulators, government authorities or other competent bodies where required or permitted by applicable law.
There may be circumstances where the law prevents Brisk Pay from informing you about a particular regulatory disclosure or investigation.
Corporate Transactions
If Brisk Pay becomes involved in a proposed or completed merger, acquisition, restructuring, financing, sale of assets or similar transaction, information may be disclosed where permitted by applicable law and subject to appropriate safeguards.
At Your Direction
We may also disclose information where you authorize or direct us to do so.
Brisk Pay may rely on licensed or otherwise appropriately authorized third-party financial service providers to deliver certain services.
As described in our Terms and Conditions, information necessary to provide those services may be shared with relevant partners.
For example, customer identity verification information and supporting documentation may need to be shared with providers involved in:
Customer verification
Opening or supporting a digital wallet
Processing payments
Holding or transferring customer funds
Providing other financial services available through Brisk Pay
We limit such disclosures to information reasonably required for the relevant purpose or as otherwise permitted or required by law.
Some third-party service providers may operate in jurisdictions outside the province or country in which you are located.
Where personal information is processed or stored outside your jurisdiction, it may become subject to the laws of that jurisdiction and may be accessible to courts, regulators, law-enforcement agencies or other authorities in accordance with applicable law.
Where Brisk Pay uses service providers to process personal information on its behalf, we take reasonable steps designed to ensure appropriate privacy and security protections are in place.
Brisk Pay does not sell personal information that identifies you.
Brisk Pay may create and use statistical, aggregated or de-identified information derived from the operation and use of its services.
Such information may be used for purposes including:
Business analysis
Service improvement
Understanding transaction and payment trends
Product development
Risk analysis
Regulatory analysis
Research
Commercial or statistical insights
Aggregated or de-identified information may be shared, offered or otherwise made available to third parties where it does not identify an individual customer or business and is handled in accordance with applicable law.
Brisk Pay recognizes the sensitivity of financial, identity and transaction information.
We maintain reasonable administrative, technical and organizational safeguards designed to protect personal information against risks such as:
Unauthorized access
Unauthorized disclosure
Loss
Theft
Misuse
Unauthorized modification
Unauthorized copying
Improper destruction
The safeguards applied depend on factors including the nature, sensitivity, volume, format and location of the information.
Access to personal information is restricted to individuals and service providers that require access for authorized business, operational, compliance or legal purposes.
No electronic system, storage method or transmission method can be guaranteed to be completely secure. Accordingly, Brisk Pay cannot guarantee that unauthorized access, cyber incidents or data loss will never occur.
Brisk Pay maintains processes for responding to suspected or confirmed privacy and information-security incidents.
Where an incident involving personal information occurs, we will assess the circumstances and take appropriate action.
Where required by applicable law, this may include notifying affected individuals, privacy regulators or other competent authorities.
Brisk Pay retains personal information only for as long as reasonably necessary for the purposes for which it was collected and to satisfy applicable legal, regulatory, contractual, fraud-prevention and record-keeping requirements.
Closing your Brisk Pay account does not necessarily result in the immediate deletion of information associated with your account.
As a Money Services Business, Brisk Pay is required to retain certain customer, verification, transaction and regulatory records for prescribed periods.
FINTRAC requirements generally require many applicable MSB records to be retained for at least five years, although the applicable retention period and the date from which that period begins depend on the type of record.
Brisk Pay may also retain information where reasonably necessary to:
Meet legal or regulatory obligations
Respond to complaints or disputes
Establish, exercise or defend legal claims
Prevent or investigate fraud
Meet audit or compliance requirements
Enforce contractual rights
When personal information is no longer required for an identified legal or business purpose, Brisk Pay will take appropriate steps to securely destroy, delete or de-identify it.
Customers are responsible for providing complete and accurate information to Brisk Pay.
We may periodically request updated information where necessary to maintain accurate customer records or comply with regulatory requirements.
You should notify us where material information changes, including changes to:
Contact information
Address
Business information
Directors or authorized representatives
Ownership or beneficial ownership
Other information relevant to your account or use of our services
Applicable British Columbia privacy law also provides individuals with rights concerning the accuracy and correction of personal information.
Depending on the privacy legislation applicable to your information and subject to applicable exceptions, you may have the right to:
Ask whether Brisk Pay holds personal information about you
Request access to your personal information
Request information about how your personal information has been used or disclosed
Challenge the accuracy or completeness of information
Request correction of inaccurate or incomplete personal information
Withdraw consent where the processing depends on consent
Raise a concern or complaint about our handling of personal information
British Columbia’s PIPA provides individuals with access and correction rights, and applicable federal privacy principles also provide rights regarding access and accuracy.
We may need to verify your identity before providing access to information or acting on a privacy request.
Requests to Delete Information
You may contact Brisk Pay regarding deletion of personal information.
However, there is no unrestricted right to require immediate deletion of all information in every circumstance.
Brisk Pay may be required or permitted to retain information for legal, regulatory, fraud-prevention, dispute-resolution, record-keeping or other legitimate purposes.
Where we are legally required to retain information, a request to delete that information cannot override the applicable retention obligation.
Where permitted by applicable law, Brisk Pay may communicate with customers about products, services, features or relevant company updates.
Where consent is required for marketing communications, we will obtain or rely on consent as permitted by law.
You may unsubscribe from marketing communications using the unsubscribe option provided in the communication or by contacting Brisk Pay.
Opting out of marketing communications will not prevent us from sending necessary:
Transaction notifications
Account communications
Security notices
Regulatory communications
Service-related information
Brisk Pay may analyze information generated through its platform to produce statistical, aggregated or de-identified information.
This may include information concerning transaction activity, payment trends, use of services, service performance, fraud prevention, regulatory compliance and general customer or platform activity.
Where such information is used or shared externally, Brisk Pay takes reasonable steps to ensure it does not identify individual customers or businesses.
This provision is intended to distinguish aggregated and de-identified information from identifiable personal information.
Brisk Pay services are intended only for individuals who are legally permitted to enter into contractual obligations and, in accordance with our Terms and Conditions, are 18 years of age or older.
Brisk Pay does not knowingly provide accounts to individuals under 18.
If we become aware that information has been provided in connection with an unauthorized account involving a minor, we will take appropriate action subject to applicable legal and regulatory requirements.
Brisk Pay’s website or platform may provide access to third-party websites, services or integrations.
Third parties may have their own privacy practices and policies.
This Privacy Policy does not govern personal information independently collected, used or controlled by a third party outside its provision of services to Brisk Pay.
We encourage customers to review the privacy policies of relevant third-party services where appropriate.
Brisk Pay may update this Privacy Policy from time to time to reflect:
Changes to our products or services
Changes in how we handle personal information
Changes in technology
Changes to service providers
Changes in applicable law or regulation
Regulatory guidance
Changes to our privacy, security or compliance practices
The Last Updated date at the beginning of this Privacy Policy identifies the date of the most recent revision.
Where required by applicable law, Brisk Pay will provide appropriate notice of material changes and obtain additional consent where required.
If you have questions about this Privacy Policy, want to request access to or correction of your personal information, or wish to raise a privacy concern or complaint, please contact:
Brisk Pay
22420 Dewdney Trunk Road, Suite 300
Maple Ridge, BC V2X 3J5
Canada
Email: support@briskpay.ca
Company Registration Number: BC1516153
FINTRAC MSB Registration Number: C100000711
We may request information reasonably necessary to verify your identity before responding to a privacy request.
If you are not satisfied with our response, you may also have the right to raise a complaint with the privacy regulator that has jurisdiction over the matter.
Brisk Pay is based in British Columbia, Canada.
British Columbia’s Personal Information Protection Act (PIPA) applies to private-sector organizations in British Columbia and governs the collection, use, disclosure and protection of personal information. PIPA also applies to organizations located in British Columbia in relation to personal information of individuals inside or outside the province.
The federal Personal Information Protection and Electronic Documents Act (PIPEDA) may also apply to certain activities, including circumstances involving personal information in interprovincial or international commercial activity.
Brisk Pay handles personal information in accordance with the privacy legislation applicable to its activities.
Nothing in this Privacy Policy is intended to limit any rights available to an individual under applicable law.
Cryptoasset products and services referenced on this website are not authorised or regulated by the UK Financial Conduct Authority (FCA). Information relating to cryptoasset products and services is intended only for eligible corporate clients outside the United Kingdom and other exempt persons permitted under applicable law, including high net worth companies and other entities falling within Article 49 of the Financial Services and Markets Act 2000 (Financial Promotion) Order 2005, including high net worth companies, unincorporated associations, and restricted B2B clients. This website and its content in relation to cryptoasset product are not directed at UK retail consumers.