Privacy Policy
Effective Date: January 1, 2024 • Last Revised: August 2026
1. Information We Collect
We collect personal information necessary to process your contractor onboarding application, verify regional eligibility, and facilitate partnership operations. This includes your legal name, email address, telephone number, province/state of residence, equipment diagnostics (network speed, operating system, hardware specifications), and professional background. Financial details (such as direct deposit payout preferences) are collected exclusively within the authenticated partner portal and are masked to prevent unauthorized exposure.
2. How We Use Your Information
Your information is used to process contractor applications, verify regulatory geographic eligibility (US and Canada), facilitate registration and affiliation with enterprise partner networks (Arise Platform), deliver transactional onboarding guides via email, provide 24/7 technical and operations support, and maintain partner records.
3. Third-Party Sub-Processors & International Data Transfers
We transfer data only to vetted technical service providers under strict data processing standards: • Supabase Inc.: Database and authentication hosting located in the AWS Canada (ca-central-1) region under PostgreSQL Row-Level Security. • Resend Inc.: Transactional email infrastructure for delivering official registration links and PDF onboarding guides. • Google LLC (Gemini API): Powers our interactive support assistant. Only minimized, non-sensitive context (first name, onboarding step, province) is transmitted; candidate emails and financial data are never provided to language models. • ipapi.co: Regional geofence verification to ensure compliance with jurisdictional worker-classification regulations. We do not sell, rent, or trade personal data to third parties.
4. Technical & Operational Data Security
We maintain robust technical and administrative safeguards to protect your personal data: • Encryption in Transit: All communications utilize TLS 1.3 / HTTPS. • Database Row-Level Security (RLS): Supabase PostgreSQL database tables strictly isolate contractor records, ensuring profiles, shifts, and earnings are accessible only by the authenticated account holder or authorized administrators. • Secure Session Authentication: Sessions are managed via HttpOnly, Secure, SameSite=Strict cookies with server-side token validation. • Rate Limiting & Abuse Prevention: Public endpoints and authentication gates are guarded by sliding-window rate limiters to prevent brute-force attacks and token harvesting.
5. Data Retention
We retain personal data for as long as your contractor account remains active or as required to fulfill operational, tax, or statutory compliance obligations. When records are no longer required, they are securely deleted or anonymized.
6. Your Statutory Rights & Data Intake
Under applicable privacy laws (including PIPEDA, Quebec Law 25, GDPR, and US state privacy acts), you have the right to access, rectify, port, or request the deletion of your personal data. We respond to all verified statutory requests within thirty (30) calendar days (or one month where applicable under GDPR/Law 25). To exercise your rights, please submit a request to privacy@wingmanetwork.com.
8. Age Eligibility & Children's Privacy
Wingman CX Network services and onboarding are strictly restricted to individuals aged 18 years and older. We do not knowingly collect information from minors.
9. Policy Updates & Governance
We periodically review this policy to reflect platform updates and evolving regulatory frameworks. Any material modifications will be posted to this page with an updated revision date.
10. Designated Privacy Officer & Contact
If you have questions, complaints, or data privacy requests, please contact our Designated Privacy & Data Protection Officer: Designated Privacy Officer Wingman CX Network Inc. 100 University Avenue, Toronto, ON M5J 1V6, Canada Direct Privacy Inquiries: privacy@wingmanetwork.com General Support: onboarding@wingmanetwork.com
