Privacy Policy

The Flockr Inc.

Effective August 15, 2026 · Last updated August 15, 2026 · Version 1.1

This Privacy Policy explains how The Flockr Inc. ("Koup," "we," "us," or "our") collects, uses, discloses, and protects your Personal Information when you use the Koup platform. It forms part of, and is incorporated by reference into, the Koup Terms and Conditions of Use. Koup is operated from Canada and is governed primarily by the Personal Information Protection Act (PIPA), S.B.C. 2003, c. 63, and by the Personal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 5. By creating an Account or using the Platform, you acknowledge that you have read and understood this Privacy Policy. Capitalized terms not defined here have the meaning given to them in the Terms and Conditions.

1. Who We Are and Scope of This Policy

1.1 The Flockr Inc. is a company incorporated under the Canada Business Corporations Act (CBCA) that operates Koup, a verified student social platform for participating Canadian post-secondary institutions, currently including the University of British Columbia (Vancouver campus) and Simon Fraser University. This Privacy Policy applies to all Personal Information that Koup collects through the Koup mobile application, the website at koup.ca, and all associated software, APIs, features, tools, and services (collectively, the "Platform").

1.2 This Privacy Policy applies to Personal Information about Users of the Platform, including Verified Students, guests, applicants for verification, campus ambassadors and partners, and individuals who contact us with enquiries. It does not apply to information collected by third parties whose services are linked to or integrated with the Platform, whose handling of your information is governed by their own privacy policies.

1.3 Koup is an independent private company. It is not affiliated with, endorsed by, or acting as an agent of any post-secondary institution. Verifying your student status using institutional email or domain-based eligibility checks does not create any data-sharing arrangement between Koup and your institution beyond what is described in this Policy or in any applicable institutional agreement.

1.4 In this Policy, "Personal Information" has the meaning given under PIPA and PIPEDA and generally means information about an identifiable individual. "Sensitive Personal Information" means Personal Information about race or ethnic origin, religious beliefs, political opinions, mental or physical health, sexual orientation or gender identity, financial circumstances, or other categories designated as sensitive under Applicable Law.

2. Legislation Governing Our Practices

Koup collects, uses, and discloses Personal Information in accordance with:

  • The Personal Information Protection Act (PIPA), S.B.C. 2003, c. 63, as amended, which is the primary statute applicable to our activities in British Columbia;
  • The Personal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 5, as amended, which applies to inter-provincial and cross-border data flows and to commercial activities not fully covered by PIPA;
  • Canada's Anti-Spam Legislation (CASL), S.C. 2010, c. 23, in respect of commercial electronic messages;
  • Any successor federal privacy legislation, including any successor to, or replacement of, PIPEDA and any equivalent federal privacy statute enacted from time to time; and
  • All other Applicable Law relating to the protection of Personal Information and privacy. Where this Policy and the Terms and Conditions conflict on a matter concerning the collection, use, or disclosure of Personal Information, this Policy governs.

3. Personal Information We Collect

3.1 We collect the following categories of Personal Information, consistent with the categories described in the Terms and Conditions:

  • Identity and verification information: your full legal name and institutional email address (verification is based on institutional email or domain-based eligibility checks);
  • Profile information you provide: biography, academic program, year of study, declared interests, profile photograph, and other optional profile fields;
  • User Content: posts, messages, photographs, Marketplace and Nest Finder listings, event submissions, reactions, reviews, and other content you create or make available through features including Spotlight, Marketplace, Nest Finder, The Chirp, The Flock, FlyBy, Messages, and The Perch;
  • Communications and messages sent through the Platform's messaging features, stored solely to deliver those messages and provide the messaging service;
  • Device and technical information: IP address, operating system type and version, browser type and version, network type and carrier, device model, and screen resolution;
  • Usage and behavioural data: features accessed, content viewed, session time and duration, interactions with other users and content, search queries, and in-app navigation patterns;
  • Koup does not currently offer payment processing for in-app purchases, ticketing, or promotional boosts. If a payment feature is introduced in the future, we will process payment-related information only where that feature is available and enabled, and we will update this Policy accordingly;
  • Communications you send us: support requests, feedback, reports, appeals, and survey or research responses; and
  • Information received from third-party sources: student verification providers, social authentication services (if offered), and campus partner institutions.

3.2 We do not intentionally collect Sensitive Personal Information except where you voluntarily include it in your profile or User Content, or where it is strictly necessary and you have provided any additional consent required under Applicable Law. All Public Content, including your profile information, is visible to every Verified Student on the Platform, and we do not currently offer settings that restrict its visibility to particular users or groups. You are responsible for any Sensitive Personal Information you choose to disclose in your profile or Public Content.

3.3 The Chirp supports both anonymous and attributed posting. If a post is displayed without name attribution, it is shown anonymously to other users, but Koup retains internal records for moderation, safety, and legal compliance. Chirp posts are classified by category tags as described in the Community Guidelines. Anonymity within the Platform applies only to the display layer; it does not exempt you from legal obligations and does not prevent us from identifying you internally or in response to lawful legal process.

4. How We Use Your Personal Information

We collect and use your Personal Information for the following purposes:

  • To create and maintain your Account and verify your eligibility and student status;
  • To provide, operate, maintain, improve, and personalize the Platform and its features;
  • To facilitate communications between users, including messages, notifications, and event invitations;
  • To display and distribute your Public Content to other Verified Students, and to deliver your Private Content to the recipients you select, in accordance with the Terms and Conditions;
  • To send you administrative communications, including account confirmations, password resets, and policy updates;
  • To send you commercial electronic messages and marketing communications where you have consented, in accordance with CASL;
  • To analyze Platform usage and conduct research for product development, feature improvement, and academic or industry research;
  • To enforce the Terms and Conditions, Community Guidelines, and Applicable Law, including investigating complaints and taking enforcement action;
  • To protect the safety, security, and integrity of the Platform and its users;
  • To detect, prevent, and report content that sexually exploits or endangers a child, and to comply with our mandatory reporting and preservation obligations as described in Section 15A;
  • To review content for safety, moderation, quality, and enforcement purposes, including through automated tools and third-party service providers as described in Section 8; and
  • To comply with legal obligations, respond to legal processes, and cooperate with law enforcement and regulatory authorities.

5. Consent

5.1 By registering for and using the Platform, you consent to the collection, use, and disclosure of your Personal Information as described in this Policy. Where Applicable Law requires a higher standard of consent for a particular use, we obtain express consent for that use before it begins.

5.2 We rely on the form of consent appropriate to the sensitivity of the information and your reasonable expectations. In some cases, consent may be implied — for example, where you voluntarily provide information for an obvious purpose. Sensitive Personal Information, and any future use of your information for interest-based advertising, require a higher standard of consent.

5.3 You may withdraw your consent to certain uses or disclosures at any time, subject to legal and contractual restrictions and reasonable notice. We will inform you of the likely consequences of withdrawing consent before it takes effect. Withdrawing consent may limit or prevent your use of certain features. Withdrawal does not apply retroactively to processing already carried out and does not affect administrative or transactional communications necessary to operate your Account.

6. Advertising, Analytics, and Tracking Technologies

6.1 Advertising

The Platform is currently free to Verified Students and does not display advertising. Koup does not use your Personal Information for interest-based, behavioural, or targeted advertising, and does not use device identifiers for advertising purposes.

If Koup introduces advertising in the future, we will update this Policy before doing so and will describe the categories of information used, the advertising partners involved, the standard of consent applicable to each use, and the controls available to you. Any use of your Personal Information for interest-based advertising will require your express consent, obtained in accordance with PIPA and PIPEDA. On iOS devices, any use of device identifiers for advertising purposes would additionally require your permission through Apple's App Tracking Transparency framework.

6.2 No Disclosure for Third-Party Marketing

Koup does not disclose Personal Information that identifies you to campus partners, advertisers, or other third parties for marketing purposes. Reports we provide to campus partners regarding Platform reach and engagement are compiled at a level of aggregation that does not permit identification of any individual user, and no such report describes a group of fewer than twenty-five users.

6.3 Cookies and Similar Technologies

We use cookies and similar technologies that are necessary for the Platform to function, and to remember your preferences. Strictly necessary cookies cannot be disabled, as the Platform cannot operate without them. Where technically feasible, we provide in-app controls allowing you to manage non-essential cookies and tracking preferences, and most web browsers allow you to control or block cookies through browser settings; blocking certain cookies may affect your ability to use some features.

We do not currently use advertising or targeting cookies, and we do not use tracking technologies that follow your activity across other websites or applications. If we introduce advertising in the future, we will update this Policy and describe any such technologies and the controls available to you before they are used.

Because there is no industry standard for how platforms should respond to "Do Not Track" signals, we do not currently alter our data collection practices in response to them. We will revisit this position if a standardized approach is established.

Cookie TypePurposeCan you disable it?
Strictly necessaryLog-in state, security tokens, load balancing.No — essential to operation.
FunctionalRemembering preferences, language, notification settings.Yes — may reduce functionality.
Analytics / performanceUnderstanding feature use, errors, and navigation. We use Cloudflare Web Analytics, which does not use cookies or device fingerprinting and collects aggregated data only.Not applicable — no cookies set.
Advertising / targetingNot currently used.Not applicable.

6.4 Device Permissions

With your consent, the Koup app may request access to certain device features to provide Platform functionality. You may grant or revoke each permission at any time through your device's operating-system settings; revoking a permission may disable the related feature. We use data obtained through these permissions only for the purposes described below and in this Policy:

  • Camera: to capture photos for FlyBy uploads and profile photographs;
  • Photo library: to upload images you select from your device;
  • Notifications: to deliver push notifications you have enabled;
  • Microphone: only if audio features are introduced, and only where you grant permission; and
  • Contacts: only if social-import features are introduced, and only where you grant permission.

7. Disclosure, Service Providers, and Cross-Border Transfers

7.1 Disclosures

We do not sell your Personal Information, and we do not disclose Personal Information that identifies you to advertisers or campus partners for marketing purposes. We disclose Personal Information only as described in this Policy, including to other Verified Students as described in the Terms and Conditions, to service providers acting on our behalf as described in Section 7.2, in connection with a business transaction as described in Section 7.4, and as required or permitted by Applicable Law, including where reporting is required under Section 15A.

7.2 Service Providers

We use third-party service providers to operate the Platform, including cloud hosting, analytics, customer support, and student verification. These providers are bound by contractual obligations to protect your Personal Information consistent with PIPA and PIPEDA and to use it only for the purposes we specify. Koup does not currently offer payment processing; if a payment feature is introduced in the future, any payment processing will be handled by a third-party payment processor and this Policy will be updated to describe it.

7.3 Cross-Border Transfers

Some service providers may store or process Personal Information outside British Columbia or Canada. Where this occurs, we require contractual protections consistent with PIPA and PIPEDA. You acknowledge that Personal Information transferred outside Canada may be subject to the laws of the receiving jurisdiction, and that foreign governments, courts, or regulators may have lawful access to it. For a current list of our material third-party processors and their jurisdictions, contact privacy@koup.ca.

7.4 Business Transactions

If Koup is involved in a merger, amalgamation, acquisition, financing, reorganization, or sale of all or substantially all of its assets, Personal Information may be disclosed to or transferred to the counterparty as part of that transaction, subject to appropriate confidentiality protections and Applicable Law.

8. Aggregated, De-Identified, and Anonymized Data

8.1 Aggregate Data

We may derive, compile, analyze, use, publish, license, and disclose aggregated, de-identified, or anonymized information derived from use of the Platform ("Aggregate Data"), provided it cannot reasonably be used, alone or in combination with other information, to identify any individual. Aggregate Data does not constitute Personal Information. We retain all rights in Aggregate Data and may use it for research and analytics, product development, industry benchmarking, campus partnership reports, monetization through data and insights services (subject to PIPEDA and PIPA), and academic or commercial publication. Where Aggregate Data is disclosed to a campus partner, advertiser, or other third party, it is compiled at a level of aggregation that does not permit identification of any individual user, and no such disclosure describes a group of fewer than twenty-five users.

8.2 Artificial Intelligence and Machine Learning

We do not use Personal Information that identifies you to train, fine-tune, or develop any artificial intelligence or machine learning model. Any use of your information for those purposes is limited to de-identified, aggregated, or anonymized data. We do not sell, license, or otherwise make available to any third party any model trained on User Content, and we do not disclose User Content to any third party for the purpose of training that party's models, without your express consent.

8.3 Automated Content Review

We use automated tools, and may use third-party service providers, to review content for safety, moderation, quality, and enforcement purposes, including automated screening and classification of user-generated content. This processing is used to operate the Platform and to reduce harmful or unlawful content. It is distinct from the training or sale of AI models described in Section 8.2. Where enforcement action is taken against you or your content solely on the basis of an automated determination, we will identify the action as automated and you may request review by a person, as described in the Terms and Conditions.

9. Data Retention

We retain Personal Information only for as long as reasonably necessary to fulfil the purposes for which it was collected, subject to longer periods required or permitted by Applicable Law. In general:

  • Account information is retained for the duration of your active Account and for a defined period following deletion, as required for legal, compliance, and fraud-prevention purposes;
  • User Content may be retained for a period following deletion where it exists in backups, has been shared with other users who have not deleted it, or must be retained for legal reasons;
  • Transaction records are retained for the period required under applicable tax and financial-reporting laws;
  • CASL consent records are retained for at least three (3) years following the end of the commercial relationship or withdrawal of consent, whichever is later; and
  • Server logs and technical data are retained in accordance with standard operational and security practices. Upon deletion of your Account, we take commercially reasonable steps to delete or anonymize your Personal Information within 90 days, subject to the retention obligations above and to Section 9.1. Residual copies may persist in backup archives for a limited period and are overwritten through standard backup rotation. We remove Personal Information from active systems as soon as reasonably practicable following Account deletion, subject to legal retention obligations.

9.1 Legal Holds and Preservation Obligations

  • Certain information is excluded from our standard deletion cycle where we are required or permitted by law to retain it. Information is placed under legal hold, and retained notwithstanding any deletion request or Account deletion, where:
  • We have received a notice of claimed copyright infringement under sections 41.25 to 41.27 of the Copyright Act, in which case records permitting identification of the User responsible for the identified location are retained for six months from receipt of the notice, or one year where proceedings are commenced and we are notified before the end of that six-month period;
  • We have received a report concerning a non-consensual intimate image, or an order made under the Intimate Images Protection Act, S.B.C. 2023, c. 11 or equivalent legislation;
  • We are required to preserve data under An Act respecting the mandatory reporting of Internet child pornography by persons who provide an Internet service, S.C. 2011, c. 4;
  • We are subject to a court order, search warrant, production order, preservation demand, or other lawful legal process; or
  • Information is reasonably required in connection with an active investigation, a legal claim, or the enforcement of our Terms and Conditions.
  • Information under legal hold is retained only for as long as the applicable obligation or process requires, and is deleted or anonymized once the hold ends, subject to any other applicable retention period.
Category of Personal InformationRetention Period
Account & profile information (name, institutional email, profile fields)Duration of the active Account, then up to 24 months after deletion for legal, compliance, and fraud-prevention purposes, unless a longer period is required by law.
Identity / student-verification recordsRetained while the Account is active. Verification is based on institutional email or domain-based eligibility checks; Koup does not require identity-document uploads for routine account creation.
Public User Content (The Chirp, The Flock, FlyBy, Marketplace, Nest Finder, The Perch, reviews)Until you delete it or your Account is deleted; residual copies may persist in backups and with other users who have saved or reshared it. FlyBy content follows its ephemeral display setting.
Private Content (direct and group messages)Retained to deliver and display the message; deleted or anonymized within 90 days of Account deletion, subject to legal-hold and moderation obligations.
CASL consent recordsAt least 3 years following the end of the commercial relationship or withdrawal of consent, whichever is later.
Device, technical & usage / log dataRetained in accordance with standard operational and security practices, typically up to 24 months, then deleted or aggregated.
Copyright notice recordsRecords permitting identification of the User responsible for a reported location are retained for 6 months from receipt of a valid notice, or 1 year where proceedings are commenced and we are notified within that period.
Non-consensual intimate image reportsReport records, associated content identifiers, and actions taken are retained for 24 months to demonstrate compliance under the Intimate Images Protection Act and to respond to orders made under it. Reported content itself is removed.
Mandatory reporting and preservation recordsRetained for the period required under An Act respecting the mandatory reporting of Internet child pornography by persons who provide an Internet service, and thereafter as required by law or an active investigation.
Privacy complaint & moderation recordsRetained as required to demonstrate compliance under PIPA and PIPEDA and to identify systemic issues.

The periods above are general maximums. We may retain information for shorter periods where possible, or longer where required by law, a legal hold, or an active investigation. When information is no longer needed, we securely delete or irreversibly anonymize it.

10. Your Privacy Rights

Subject to Applicable Law, you have the following rights with respect to your Personal Information:

  • Right of Access: to confirm whether we hold Personal Information about you and to obtain access to it, information about how it is used, and the third parties to whom it has been disclosed;
  • Right to Correction: to request correction of inaccurate, incomplete, or misleading Personal Information, with notice of corrections to third parties where we have disclosed the information to them;
  • Right to Withdraw Consent: to withdraw consent to certain uses or disclosures, subject to legal and contractual restrictions and reasonable notice;
  • Right to Deletion: to request deletion of your Personal Information, subject to our legal retention obligations and the rights of other users who have interacted with your content;
  • Right to Data Portability: to request a copy of your Personal Information and User Content in a commonly used, machine-readable format, as described in Section 11;
  • Right to Challenge Compliance (PIPEDA Principle 10): to challenge our compliance with the fair information principles; and
  • Right to Complain to Regulators: to complain to the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) at www.oipc.bc.ca or the Office of the Privacy Commissioner of Canada (OPC) at www.priv.gc.ca. To exercise any of these rights, contact our Privacy Officer at privacy@koup.ca. We will acknowledge your request promptly and respond substantively within 30 days of receipt, as required under PIPA. If we require more time, we will notify you of the delay, the reasons, and the expected response date. If we decline access or a correction, we will give reasons and advise you of your right to complain to the applicable regulator.

11. Data Portability and Account Export

11.1

You may request a copy of the Personal Information and User Content associated with your Account by writing to privacy@koup.ca and including your full name, registered email address, Account username, and proof of identity satisfactory to us. We will provide a copy in a commonly used, machine-readable format (such as JSON or CSV) within 30 calendar days of a valid request, subject to permitted extensions.

11.2

An export will include, to the extent technically feasible, your profile information, User Content you have posted, a record of your Account activity, your privacy and notification preferences, and other Personal Information subject to access under PIPA. It will not include Private Content (messages) sent to you by other users where disclosure would violate their privacy rights, our internal operational or moderation records, derived data that is not Personal Information, or information we are legally prohibited from disclosing.

11.3

We may decline or limit a request that is manifestly unfounded or excessive (including by its repetitive character), that would adversely affect the rights of others, or that falls within a category we are not required to disclose. Where we decline or limit a request, we will explain why and advise you of your right to complain to the OIPC BC. We may charge a reasonable fee for manifestly excessive or repetitive requests, consistent with PIPA.

12. Security of Personal Information

We implement and maintain commercially reasonable technical, organizational, and administrative safeguards designed to protect Personal Information from unauthorized access, use, disclosure, alteration, loss, or destruction. These include encryption of data in transit (TLS/SSL) and at rest; access controls including role-based access, multi-factor authentication for administrative systems, and least-privilege principles; regular security assessments and vulnerability testing; network monitoring and intrusion detection; employee training and screening; and formal incident-response and business-continuity plans. No security system is impenetrable, and we cannot guarantee absolute security. You are responsible for maintaining the security of your own device and Account credentials, and you provide Personal Information at your own risk.

13. Data Breach Notification

If we become aware of a security breach involving Personal Information that, in our assessment, creates a real risk of significant harm to one or more individuals, we will notify affected individuals and the applicable regulator (OIPC BC and/or OPC) in accordance with PIPA and PIPEDA. Notification will be provided as soon as reasonably practicable after we confirm the breach and will include, to the extent known, a description of the breach, the categories and approximate number of individuals affected, the categories and approximate volume of Personal Information involved, the likely consequences, the measures taken or proposed to address it, and contact information for our Privacy Officer. We maintain records of all security breaches, including those that do not meet the notification threshold, as required under PIPA.

14. Protection of Minors

The Platform is designed exclusively for post-secondary students and is not directed at individuals under 17. We do not knowingly create Accounts for or collect Personal Information from individuals under 17. Student enrollment verification serves as our primary age-assurance mechanism. If we become aware that an Account holder does not meet the minimum age requirement, we will promptly suspend or terminate the Account and delete associated Personal Information in accordance with Applicable Law. If you are a parent or guardian who believes a minor has created an Account without authorization, contact privacy@koup.ca and we will investigate promptly. Separately from the age-assurance measures described above, we are subject to mandatory reporting obligations in respect of content that sexually exploits a child, regardless of the age of the person who posted it. Those obligations are described in Section 15A.1.

15. Law Enforcement and Government Requests

We disclose Personal Information to government authorities, law enforcement, courts, or regulators where compelled by a valid court order, search warrant, subpoena, production order, or other lawful process; where required by Applicable Law, including the reporting obligations described in Section 15A; where necessary to prevent or respond to an imminent threat to the life or safety of any individual; or where otherwise required or permitted under PIPA, PIPEDA, or other Applicable Law. Apart from the circumstances described above, we do not voluntarily disclose Personal Information to government authorities or law enforcement. We reserve the right to require that requests be made through proper legal channels and to challenge requests we believe are unlawful or overbroad. Where legally permitted, we will endeavour to notify you before disclosing your Personal Information so that you may seek legal advice. We may be prohibited from providing such notice, and will not provide notice where doing so is prohibited by Applicable Law or would compromise an investigation, including in the circumstances described in Section 15A.

15A. Mandatory Reporting and Safety Obligations

15A.1 Child Sexual Exploitation

We are subject to An Act respecting the mandatory reporting of Internet child pornography by persons who provide an Internet service, S.C. 2011, c. 4. Where we are advised of an internet address at which child pornography may be available to the public, we report that address to the organization designated under that Act. Where we have reasonable grounds to believe that our service is being or has been used to commit a child pornography offence, we notify law enforcement and preserve the associated data for the period required by that Act.

Reporting and preservation under this Section are carried out regardless of any other provision of this Policy, including provisions relating to consent, notice, data retention, deletion, or the confidentiality of Private Content. We will not notify you of a report made under this Section where doing so is prohibited by Applicable Law or would compromise an investigation.

15A.2 Non-Consensual Intimate Images

The Intimate Images Protection Act, S.B.C. 2023, c. 11 provides an expedited process, available through the Civil Resolution Tribunal, for individuals seeking removal of intimate images distributed without their consent, and permits orders to be made against internet intermediaries such as Koup. We comply with orders made under that Act and retain the records necessary to identify, restrict, and remove reported content and to respond to such orders. Information about that process is available at takebackyourimages.gov.bc.ca.

Reports of non-consensual intimate images may be submitted through the in-app reporting tool or to safety@koup.ca and are prioritized ahead of other reports. You are not required to identify yourself to make such a report, and we will not disclose the identity of a reporting individual to the person reported except where required by Applicable Law.

15A.3 Imminent Risk to Safety

Where we have reasonable grounds to believe that there is an imminent risk to the life, health, or safety of any individual, we may disclose Personal Information to law enforcement, emergency services, or another person in a position to prevent or reduce that risk, as permitted under PIPA and PIPEDA. Such disclosure is limited to what is reasonably necessary in the circumstances.

16. Institutional Data and FIPPA

Koup is not a public body under the Freedom of Information and Protection of Privacy Act (FIPPA), R.S.B.C. 1996, c. 165, and its own operations are governed by PIPA, not FIPPA. Student records, grades, enrollment data, and other educational records held by your institution remain subject to FIPPA and are the institution's responsibility. We do not access, collect, or store your academic records, grades, course enrolment, or other educational records held by your institution. We respond to requests from institutions only where you have provided express written consent, the institution provides a valid legal basis, or disclosure is necessary to prevent an imminent threat to campus safety.

17. Accountability, Openness, and Privacy Complaints

17.1 Privacy Officer

We have designated a Privacy Officer who is accountable for our compliance with PIPA, PIPEDA, and this Policy. The Privacy Officer can be reached at privacy@koup.ca.

17.2 Openness

We make this Policy, the Terms and Conditions, and the Community Guidelines available within the Platform and on our website, provide updated versions promptly following material changes, and respond to enquiries about our privacy practices, including from individuals who do not hold an Account.

17.3 Complaints Procedure

If you have a privacy concern, we encourage you to follow our internal complaints procedure before contacting a regulator: (Step 1) submit your complaint in writing to privacy@koup.ca with your name, contact information, a description of your concern, and any supporting documentation; (Step 2) we acknowledge receipt within 5 business days and assign a qualified reviewer; (Step 3) we investigate impartially and in good faith; (Step 4) we provide a written response within 30 calendar days setting out our findings and any remedial steps; and (Step 5) if you are not satisfied, you may escalate to the OIPC BC (www.oipc.bc.ca) or the OPC (www.priv.gc.ca). We maintain a record of all privacy complaints and review them periodically to improve our practices.

18. Changes to This Privacy Policy

We may amend this Privacy Policy from time to time to reflect changes in the Platform, Applicable Law, or our practices. When we make material changes, we will post the revised Policy with an updated "Last Updated" date and version number, and provide notice through one or more of an in-app notification, push notification, email to your registered address, or a notice on next login. Where required by Applicable Law, we will obtain fresh consent before the changes take effect. Your continued use of the Platform after the effective date of any change constitutes acceptance of the revised Policy.

19. How to Contact Us

For any question, concern, complaint, or request relating to this Privacy Policy or your Personal Information, please contact us: