Skip to content

FundMyCourse.ca -- Privacy Policy

Effective Date: March 27, 2026 Last Updated: April 17, 2026 Version: 1.2


Plain-Language Summary

FundMyCourse.ca helps you find scholarships and education funding. To do that, we need to know some things about you -- like what you are studying and where you live. This policy explains what we collect, why, and what we do with it in straightforward terms.

The short version: We collect only what we need to match you with funding. We store it securely in Canada. We never sell it. You can delete it any time.


1. About This Policy

This Privacy Policy explains how FundMyCourse.ca ("we," "us," "our"), operated by BBN LABS INC, a Canadian federal corporation, collects, uses, discloses, and protects personal information. This policy applies to all users of the FundMyCourse.ca website and related services.

FundMyCourse.ca is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) and complies with all 10 Fair Information Principles established under that legislation. We also comply with Canada's Anti-Spam Legislation (CASL) for all commercial electronic messages.

For users in Quebec, we additionally comply with Law 25 (An Act to modernize legislative provisions as regards the protection of personal information). For users in Alberta and British Columbia, we comply with the respective Personal Information Protection Acts (PIPA).

Privacy Officer: The Director of BBN LABS INC serves as Privacy Officer. Contact: privacy@fundmycourse.ca


2. The 10 PIPEDA Fair Information Principles

Our privacy practices are built on the 10 Fair Information Principles required by Schedule 1 of PIPEDA. Each principle is addressed throughout this policy and summarized here.

Principle 1: Accountability

BBN LABS INC is responsible for all personal information in our possession or under our control. Our Privacy Officer (the Director of BBN LABS INC) is accountable for compliance with this policy and with PIPEDA. We maintain documented internal procedures and ensure that any third-party service providers we use are contractually bound to protect your information to standards equivalent to our own.

You may contact our Privacy Officer at privacy@fundmycourse.ca with any questions or concerns.

Principle 2: Identifying Purposes

We identify the purposes for collecting personal information at or before the time of collection. The specific purposes are detailed in Section 4 of this policy. If we ever need to use your information for a new purpose not previously identified, we will obtain your consent before doing so.

Principle 3: Consent

We obtain your meaningful, informed consent before collecting, using, or disclosing your personal information. We use plain language (not legal jargon) to explain what we are collecting and why. You can withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent may limit our ability to provide certain services (for example, scholarship matching requires knowing your province and education level).

For details on how consent works for minors, see Section 7.

Principle 4: Limiting Collection

We collect only the personal information necessary to fulfill the identified purposes. We do not collect Social Insurance Numbers, bank account details, detailed financial records, medical records, credit scores, biometric data, or precise geographic location. See Section 3 for a complete list of what we do and do not collect.

Principle 5: Limiting Use, Disclosure, and Retention

Personal information is used only for the purposes for which it was collected, as described in Section 4. We do not sell, rent, trade, or otherwise share personal information with third parties for their own marketing purposes. Ever. Data retention periods are described in Section 8.

Principle 6: Accuracy

We take reasonable steps to ensure personal information is accurate, complete, and up-to-date for the purposes for which it is used. You can review and update your information at any time through your account settings.

Principle 7: Safeguards

We protect personal information with security safeguards appropriate to the sensitivity of the information. Technical safeguards include encryption in transit (TLS 1.3) and role-based access controls. Organizational safeguards include documented security procedures and periodic internal security reviews. Physical safeguards are handled by our hosting provider (see Section 5). See Section 9 for full details.

Principle 8: Openness

This privacy policy is publicly available on our website. We provide clear information about our privacy practices to anyone who asks.

Principle 9: Individual Access

You have the right to access your personal information held by FundMyCourse.ca. You can view and export all of your data through your account settings at any time (self-serve data export in JSON and CSV formats). If you need assistance, contact privacy@fundmycourse.ca. We will respond to access requests within 30 calendar days.

Principle 10: Challenging Compliance

You have the right to challenge our compliance with this policy and with PIPEDA. Complaints should be directed to our Privacy Officer at privacy@fundmycourse.ca. We will investigate all complaints and respond within 30 calendar days. If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.


3. What Personal Information We Collect

3.1 Information You Provide Directly

Data Category Examples Why We Need It
Account information Name, email address, password (hashed) To create and maintain your account
Education profile Education level (high school, college, university, trades, etc.), province or territory of residence, field of study, institution name To match you with relevant scholarships and funding
Citizenship and residency Canadian citizen, permanent resident, refugee, international student, Indigenous identity (optional) Many scholarships have citizenship or residency eligibility requirements
Financial need indicator Self-reported financial need level (general category, not exact amounts) To match you with need-based funding
Demographic information (optional) Gender, visible minority status, disability status, first-generation student status, rural/remote community, single-parent household Only collected if you choose to provide it, used solely to match you with scholarships targeting specific demographics

3.2 Information Generated Through Your Use of the Service

Data Category Examples Why We Collect It
Bookmarks and saved scholarships Which scholarships you save to your tracker To power your application tracker and Kanban board
Search history Search queries, filters applied To improve search results and recommendations
Application status Whether you marked a scholarship as Interested, Applying, Applied, Won, or Lost To power your application tracker
Usage data Pages visited, features used, session duration To improve the platform (anonymized for analytics)

3.3 Information Collected Automatically

Data Category Examples Why We Collect It
Session data Session token (cookie), login timestamps To keep you logged in securely
Device and browser information Browser type, operating system, screen size To ensure the site works correctly on your device
Referral source How you found FundMyCourse.ca (search engine, social media, referral link) To understand how users find us

3.4 Information We Do NOT Collect

We do not collect and will never ask for:

  • Social Insurance Numbers (SIN)
  • Bank account numbers or financial account details
  • Credit card numbers (payment processing is handled entirely by our third-party payment processor; we never see or store your card number)
  • Detailed income or tax information
  • Medical records or health information
  • Credit scores
  • Biometric data (fingerprints, facial recognition, etc.)
  • Precise GPS location
  • Social media passwords or private messages

4. How We Use Your Information

We use your personal information for the following purposes, and no others:

  1. Scholarship and funding matching: Comparing your profile against eligibility criteria in our database to surface relevant opportunities.
  2. Account management: Creating, maintaining, and securing your account.
  3. Application tracking: Powering your Kanban board and deadline reminders.
  4. Service improvement: Analyzing aggregated, anonymized usage patterns to improve search, matching, and user experience.
  5. Communication: Sending you scholarship deadline reminders, new match notifications, and important service announcements (you can opt out of non-essential communications at any time).
  6. Legal compliance: Responding to lawful requests from government authorities as required by Canadian law.

We do NOT use your information for:

  • Targeted advertising
  • Selling to data brokers
  • Sharing with educational institutions without your explicit consent
  • Profiling for credit, insurance, or employment decisions
  • Any purpose not listed above without obtaining your consent first

5. How and Where We Store Your Information

5.1 Data Residency

All personal information is stored on servers physically located in Canada. Our database (PostgreSQL) runs on a Canadian-hosted Virtual Private Server (VPS) provided by Hostinger, with data centres in Canada. Your data does not leave Canada for storage purposes.

5.2 Encryption and Security

  • In transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3.
  • At rest: Database contents are encrypted using AES-256 encryption.
  • Passwords: Stored as salted, one-way cryptographic hashes. We cannot see your password and do not store it in readable form.
  • Access controls: Team access to the database and servers is restricted by role. Only authorized personnel can access personal information, and all access is logged.

5.3 Backups

Database backups are encrypted and stored on infrastructure physically located in Canada. Backups follow the same retention schedule as active data.


6. Who We Share Your Information With

6.1 The Short Answer

Nobody. We do not sell, rent, trade, lease, or otherwise disclose your personal information to any third party for their own purposes. This is a founding commitment of FundMyCourse.ca and will not change.

6.2 Third-Party Service Providers

We use a limited number of third-party services to operate the platform. These services process data on our behalf and are contractually bound to use it only for the purposes we specify:

Service Purpose What They Access Data Location
Google OAuth Sign-in only (if you choose "Sign in with Google") Your Google email address and display name, solely to authenticate your identity Google's servers (necessary for authentication protocol)
Cloudflare Content delivery network (CDN) and DDoS protection Requests pass through Cloudflare's network for performance and security Cloudflare edge servers (transient processing only; no personal data stored)
Telegram Bot API Admin analytics notifications (internal) Aggregate, anonymized platform statistics only (e.g., "12 new signups today"). NO individual user data is ever sent to Telegram. Telegram servers (no personal information transmitted)

We do not use any third-party analytics services that track individual users. Our usage analytics are collected and processed in-house using anonymized, aggregated data.

6.3 Legal Disclosure

We may disclose personal information if required to do so by law, regulation, or court order, or if we believe in good faith that disclosure is necessary to protect the safety of any person or to prevent illegal activity. We will notify the affected user of any such disclosure unless prohibited by law from doing so.

6.4 Business Transfer

If FundMyCourse.ca is acquired, merged, or undergoes a change of ownership, your personal information may be transferred as part of that transaction. We will notify you by email and by prominent notice on our website before your information is transferred and becomes subject to a different privacy policy. You will have the option to delete your account and data before any such transfer.


7. Children and Minors

FundMyCourse.ca serves students of all ages, including high school students in Grades 9-12 who are typically aged 13-17. We take the protection of young users seriously.

7.1 Children Under 13

We do not knowingly collect personal information from children under the age of 13. If a user indicates during registration that they are under 13, we advise them to involve a parent or guardian before continuing.

If we learn that we have collected personal information from a child under 13 without verified parental consent, we will delete that information promptly. If you are a parent or guardian and believe we have inadvertently collected information about your child, please contact us at privacy@fundmycourse.ca and we will delete the information within 30 days.

This approach aligns with PIPEDA requirements for meaningful consent from minors.

7.2 Users Aged 13-17

Under PIPEDA, individuals aged 13-17 can generally provide their own consent if they can reasonably be expected to understand the nature and consequences of the collection, use, or disclosure. Our approach:

  1. Registration uses plain, age-appropriate language to explain what information we collect and why.
  2. We recommend that users aged 13-17 discuss account creation with a parent or guardian.
  3. Consent forms are written at a reading level appropriate for the user's stated age.
  4. We do not collect sensitive financial information from users under 18 without parental consent.
  5. Users aged 13-17 have the same rights to access, correct, and delete their information as adult users.

7.3 Users 18 and Over

Standard informed consent processes apply.


8. Data Retention

Scenario Retention Period
Active account Data is retained for as long as your account is active and you continue to use the service.
Account deletion requested All personal information is deleted within 30 calendar days of the request. Anonymized, aggregated data that cannot identify you may be retained for analytics purposes.
Inactive account (no login for 24 consecutive months) We will send a notification to your registered email address 30 days before deletion. If no response is received, the account and all associated personal information will be deleted.
Backup data Deleted from backups within 90 days following deletion from the active database.
Legal hold If data is subject to a legal obligation or dispute, it may be retained beyond the normal retention period as required by law.

9. Security Measures

We implement the following safeguards to protect your personal information:

Technical Safeguards

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Salted, one-way hashing for passwords
  • Role-based access controls with audit logging
  • Automated security scanning and vulnerability monitoring
  • Regular third-party security audits (penetration testing)
  • Secure, encrypted database backups

Organizational Safeguards

  • Privacy training for all team members
  • Documented security procedures and incident response plan
  • Principle of least privilege for data access
  • Regular review of access permissions

Breach Response

In the event of a data breach that poses a real risk of significant harm, we will:

  1. Notify the Office of the Privacy Commissioner of Canada as soon as feasible.
  2. Notify affected users directly by email and by notice on our website.
  3. Describe the nature of the breach, the information involved, and the steps we are taking.
  4. Provide guidance on what affected users can do to protect themselves.

We maintain a documented breach response plan with a target notification timeline of 72 hours from discovery.


10. Cookies

10.1 What Cookies We Use

Cookie Type Purpose Duration
Session cookie Essential Keeps you logged in and maintains your session securely Expires when you close your browser, or after 7 days if you select "Remember me"
Preference cookie Optional Remembers your display preferences (dark mode, language, filter defaults) 12 months

10.2 What We Do Not Use

  • We do not use third-party tracking cookies.
  • We do not use advertising cookies.
  • We do not use cookies for cross-site tracking.
  • We do not use fingerprinting or any other covert tracking technology.

10.3 Your Cookie Choices

The session cookie is essential for the site to function when you are logged in. Preference cookies are optional; you can decline them and the site will still work (you will just need to re-set your preferences each visit). You can manage cookies through our cookie consent banner or through your browser settings at any time.

For more details, see our Cookie Consent Policy.


11. Your Rights

As a user of FundMyCourse.ca, you have the following rights regarding your personal information:

Right How to Exercise It
Access your data View and export all your data from your account settings, or email privacy@fundmycourse.ca
Correct your data Update your profile in account settings at any time, or contact us for assistance
Delete your data Delete your account from account settings, or email privacy@fundmycourse.ca. Deletion is completed within 30 days.
Withdraw consent Adjust your consent preferences in account settings, or email us. Note: withdrawing consent for essential data processing may require account deletion.
Data portability Export your data in JSON or CSV format from account settings
Opt out of communications Unsubscribe from non-essential emails using the link in any email, or adjust preferences in account settings
File a complaint Contact our Privacy Officer at privacy@fundmycourse.ca. If unsatisfied, contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca

We will respond to all rights requests within 30 calendar days. There is no fee for exercising these rights.


12. CASL Compliance (Canada's Anti-Spam Legislation)

FundMyCourse.ca complies with Canada's Anti-Spam Legislation (CASL) for all commercial electronic messages (CEMs).

12.1 Consent for Commercial Messages

We obtain your express consent before sending any commercial electronic messages, including:

  • Promotional emails about premium features
  • Partner scholarship highlights
  • Newsletter content
  • Feature announcements

Express consent is obtained through a clear, affirmative opt-in action (e.g., checking a box during registration that is unchecked by default). We never use pre-checked boxes. We never bundle consent for commercial messages with consent for essential service messages.

12.2 Implied Consent

We may rely on implied consent to send commercial messages only in the following limited circumstances, as permitted by CASL:

  • You have an existing business relationship with us (e.g., you are a paying Premium subscriber), for up to 2 years after your last purchase or interaction.
  • You have made an inquiry about our services within the past 6 months.

12.3 Transactional and Service Messages

The following messages are NOT commercial electronic messages under CASL and do not require express consent:

  • Scholarship deadline reminders for scholarships you have saved
  • Account security notifications (password reset, login alerts)
  • Service disruption notices
  • Responses to your support requests
  • Changes to our terms or privacy policy

12.4 Unsubscribe Mechanism

Every commercial electronic message we send includes:

  • A clear, prominently displayed unsubscribe link
  • An unsubscribe mechanism that works for at least 60 days after the message is sent
  • Processing of unsubscribe requests within 10 business days (CASL maximum)

12.5 Sender Identification

Every commercial electronic message we send includes:

  • The name of the sender (FundMyCourse.ca)
  • Our mailing address
  • A working contact method (email or web link)

12.6 Record-Keeping

We maintain records of:

  • When and how consent was obtained for each recipient
  • The content and sending date of each commercial message
  • All unsubscribe requests and the dates they were processed

13. Quebec Law 25 Compliance

For users who are residents of Quebec, the following additional provisions apply under Quebec's Act respecting the protection of personal information in the private sector (Law 25):

  • We have designated a person responsible for the protection of personal information (our Privacy Officer).
  • We conduct Privacy Impact Assessments (PIAs) before implementing any new system or project that involves personal information of Quebec residents.
  • We publish information about our privacy governance policies and practices.
  • We provide notice of any privacy incidents involving Quebec residents to the Commission d'acces a l'information du Quebec (CAI) and to the affected individuals.
  • Quebec residents have the right to data portability in a commonly used technological format.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we do:

  1. We will update the "Last Updated" date at the top of this document.
  2. For material changes, we will notify you by email at least 30 days before the changes take effect.
  3. For material changes, we will also display a prominent notice on the website.
  4. Continued use of the service after the effective date of changes constitutes acceptance of the updated policy.
  5. If you do not agree with the changes, you may delete your account before the effective date.

We will not retroactively change how we handle information collected under a previous version of this policy without your consent.


15. Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy or our privacy practices:

Privacy Officer FundMyCourse.ca Email: privacy@fundmycourse.ca

We will acknowledge receipt of your inquiry within 5 business days and provide a substantive response within 30 calendar days.

If you are not satisfied with our response, you may contact:

Office of the Privacy Commissioner of Canada Website: www.priv.gc.ca Phone: 1-800-282-1376

Commission d'acces a l'information du Quebec (for Quebec residents) Website: www.cai.gouv.qc.ca


This privacy policy is also available in French at fundmycourse.ca/fr/confidentialite.