Neo Privacy Policy

Last updated: June 23, 2025

Neo Financial Technologies Inc., Neo Mortgage Services Inc. and their subsidiaries and affiliates (collectively “Neo”, “us” and “we”) value your privacy. We are committed to safeguarding your personal information. This Privacy Policy sets out our policies and procedures for the collection, use, retention, and disclosure of your personal information.

This Privacy Policy applies to the privacy practices of Neo on our website, located at https://www.neofinancial.com/ and any subdomains (the “Website”), our “Neo Financial” web and mobile application (the “App”, and together with the Website, the “Platform”), to Neo products and services including our Money, Credit, Invest, and Mortgage products (the “Products”) and to our other interactions with you.

Neo is accountable for the collection, use, and disclosure of your personal information.
Our Privacy Officer oversees the protection of your personal information and ensures our compliance with our Privacy Policy and applicable privacy laws. Please see the contact details for our Privacy Officer at the end of this Privacy Policy, in section 8.

What Information is in this Privacy Policy?

This Privacy Policy covers the following topics:

  1. Personal Information We Collect
    1. a. Information You Provide Us
    2. b. Information We Collect Automatically
    3. c. Information We Collect from Third Parties
  2. How We Use Your Information
  3. Sharing of Personal Information
    1. a. Service Providers
    2. b. Products and Services Offered by Neo
    3. c. Legal and Compliance
  4. Your Choices
  5. Safeguarding and Retention of Personal Information
  6. Information About Our Privacy Governance Policies and Practices
  7. Updates to our Privacy Policy
  8. Contact Us

1. Personal Information We Collect

We may collect personal information to provide you with the Products you request. We do this by collecting information: (i) from you directly; (ii) automatically when you use the Platform; or (iii) from third parties when you authorize us or as otherwise permitted by applicable law.

(a) Information You Provide to Us

When you sign up for a Neo profile or apply for Products, you may be required to provide the following information:
  • Identity information: your full name, email address, phone number, password, date of birth, mailing and home address and address history, employment and educational information, social insurance number (providing your SIN for identity verification purposes is optional), tax information, and identity documents.
  • Financial information: your income information, information about your living situation, sources of income, credit information (including assets, liabilities, and payment information) account objectives, risk capacity, and investment timelines.
  • Biometric information: images of yourself and your photo identification documents.
  • Information about others: such as the full name, email address, and phone number of your spouse, family and household members, authorized users, or counterparties.
  • Survey information: responses and data obtained through our surveys and client research.

(b) Information We Collect Automatically

When you sign up for a Neo profile, apply for Products, or use the Neo Platform, we may automatically collect the following information on you:
  • App and device data: type of device hardware and operating system, language settings, and the date and time the App accesses our servers, web browser, time zone, IP address, unique device identifier, your device’s GPS coordinates
  • Usage data: search and Website history including cookie data, information regarding your use of the Platform, including your transactions, card and account usage, payment history and parties to transactions, and the Products that you use or are eligible for
  • Analytics: we use web analytics services such as Google Analytics to help us gather and analyze information about the areas visited on the Website (such as the pages most read, time spent, search terms and other engagement data)
  • Rewards data: age of your rewards account and information regarding your rewards points balance. We collect the details of your purchase on third-party platforms you already use (such as Neo’s partnered merchant platforms)
  • Additional Information: We will use commercially reasonable efforts, given the limitations imposed upon us by third party providers such as Apple and Google, to clearly disclose what, if any information is collected by the App, how it is used, and with whom it is shared. Please note, certain practices are outside of our control, for example, tracking by Google or Apple or your telecommunications carrier. We are not responsible for the actions of such third parties. You should always read and understand the policies of any third-party provider, such as Google with respect to Android apps and Apple with respect to iOS apps, and your telecommunications carrier, before making any purchase or downloading any app.

(c) Information We Collect from Third Parties

When you sign up for a Neo profile, apply for Products, or use the Neo Platform, we may collect the following information on you from third parties:
  • Identity information: name, address, date of birth, phone number, device information from telecommunications providers
  • Biometric information: identity service providers may collect biometric information (such as an image of your government-issued identification along with a real time image or video) to verify your identity; we collect the information from your identification (such as the ID number) and the final result of identity verification processes (i.e., verified or not verified)
  • Screening information: results of anti-money laundering checks from sanctions and fraud screening providers
  • Credit information: identity, financial, credit and transactional information from credit reporting agencies, such as TransUnion and/or Equifax
  • Third party account information: financial institution name and numbers, account number, balance from accounts linked via Plaid or Flinks

2. How We Use Your Information

In addition to purposes that may be identified to you before or at the time of collection, the personal information we collect may be used for the following purposes:

(a) Identity Verification

  • To verify your identity and other information you have provided to us
  • To complete a credit file identity verification
  • To detect and prevent fraud

(b) Credit Verification

  • To obtain additional credit, financial, personal and business information contained in your credit report for the purposes of verifying your creditworthiness. With your consent, we will run a credit check to help assess your eligibility for a credit card and the credit limits.
  • To assess and manage our credit risks, establish credit and hold limits
  • To qualify you for other products and services
  • To assist in determining your ongoing creditworthiness, update our records, and help us determine your eligibility for other products and services (such as pre-approved credit products, credit limit increase, and other offers).
  • To maintain accurate credit information within credit report agencies databases, we share credit information on an ongoing basis with credit reporting agencies

(c) Account and Product servicing

  • To contact you by mail, email, SMS message (message and data rates apply), in-App messaging and telephone to respond to your question or comment.
  • To deliver and improve the financial products and services you have with us, and provide you with relevant information about your application and/or account
  • To administer and authenticate your access to your Neo profile, to enable you to access products and services, and to update you about changes to the Platform, and to market products and services to you in accordance with this Privacy Policy.
  • To facilitate transactions from linked bank accounts
  • To confirm which products and services are most suitable for you
  • To train our personnel, and for quality assurance purposes.
  • To open, maintain, service, process, analyze, market, audit, collect or fulfill products or packages related to Neo Rewards™, Neo Premium Rewards Package or the Neo Store.

(d) Legal and Regulatory

To comply with applicable legal and regulatory obligations, including those relating to anti-money laundering and sanctions, tax reporting, mortgages, suitability, and investment suitability.

(e) Offers, marketing and advertising

  • To contact you by mail, email, SMS message (message and data rates may apply), push notification, and telephone to update you on changes to the Products, send you important updates about financial account opening disclosures, and important or useful messages about your financial accounts.
  • To provide you with personalized marketing communications. You can request that we not contact you for the purposes of advertising, marketing, promotions, rewards programs, research by updating your privacy preferences within the Platform.
  • To provide you with location-based services, including information about nearby Neo Rewards partners.
  • For more information, see section 4 - Your Choices.

(f) Analytics

  • To service insights that inform decision-making, including but not limited to, introducing new features or products, changing or removing existing features or products, improved credit adjudication, risk and resource optimization, and to manage our business.
  • To help us understand our clients and to enhance our product and service offerings.
  • To evaluate existing products and services, develop new products and services, optimize our Website, perform analytics, and improve the client experience we offer.
  • To evaluate and improve the user experience and the Website.
  • To help us understand the activity on the App, to monitor and improve the App, and to tailor your in-App experience. In addition, we may use third party service providers to collect analytical information about your use of the App, such as the App features used and time spent on the App, to help us tailor your in-App experience, improve our products and the quality of our App, and to manage and analyze data in order to better understand our users.
  • For more information, see section 4 - Your Choices.

(g) Automated decision making

When we process your personal information we may use automated decision making systems to help provide products and services to you (i.e. to verify identity, assess internal risk or creditworthiness, analytics), for security, anti-money laundering, and fraud detection/prevention purposes. You may contact us for information regarding our use of these systems, including challenging a decision, in section 8.

Personal Information We Process on Behalf of Third-Party Organizations

In addition to personal information that we collect and use for our own purposes, we sometimes act as a service provider to third-party partners to assist them in processing certain personal information on their behalf. For example, we may act as a service provider to entities that own your mortgage.Where we process personal information on behalf of our partners, we rely on such third-party organizations to comply with applicable privacy laws when collecting, using, or disclosing personal information, including by obtaining appropriate consent to collect, use, and disclose personal information. We require third parties to ensure that they have obtained all authority to provide personal information to us in accordance with applicable privacy laws. If you have any questions regarding the personal information we process on behalf of one of our partners, we encourage you to first contact the partner directly and/or review their applicable privacy policy.

3. Sharing of Personal Information

We do not sell, rent or disclose your personal information to third parties without your consent, except as described below or as permitted by applicable law.

(a) Service Providers

Your personal information will be transferred to, collected by, or otherwise made available to certain third parties that provide services on our behalf. These may include:
  • Client support: to provide support services to clients that reach out to us with questions about Neo or our products or services, including our financial, co-brand, or third party partners, we may share identity, financial and credit information.
  • Mortgage processing services: to administer your mortgage, including processing or servicing of mortgages, mortgage insurers, consumer reporting agencies, title custodian, and title insurance providers, we may share identity, financial, credit and biometric information.
  • Fraud detection services: to monitor your transaction information and identify fraudulent activity, we may share identity, financial, and biometric information.
  • Credit reporting agencies: to obtain information regarding your creditworthiness, where you have provided us with your consent to run a credit check, we may share identity information.
  • Sanctions screening providers: to ensure that you are not a sanctioned person subject to prohibitions under applicable money laundering, terrorist financing or other regulatory restrictions, we may share identity information.
  • Marketing and research companies: to understand and deliver products, services and offers that you, and others who are similar to you, may find useful or block offers you won’t find useful, we may share your app and device data, usage data and analytics, or anonymized and aggregated information to digital affiliates and companies like Google and Facebook.
  • Collections and law firms: to help us collect a debt owed to us by you, we may share your identity, financial, and credit information, and information about others, with our external legal representatives and debt collection providers.
  • Payment processing businesses: to process your transactions and payments, we may share identity, and financial information, and information about others.
  • Print and plastic suppliers: to issue and service card products, we may share your identity and financial information with suppliers to print and send cards and statements.
  • Referral program partners: to administer our rewards referral program we may share your full name and account status information (i.e. whether your application was completed).
  • Neo Rewards/Store: to provide rewards, products, attribution and fulfillment, we may share your identity, financial, online, transaction, counterparty and third party information with certain third parties as part of Neo Rewards™, Premium Rewards Package and Neo Store. To provide insights and analytics on rewards programs, we may share anonymized and aggregated information with third party merchants within our cashback program.
  • Cloud service providers: to store your information and provide the Platform and Products.
Our service providers are only provided with the information they need to perform their designated functions. Our service providers may be located in Canada or other foreign jurisdictions.Your personal information may be maintained and processed by us, our affiliates, and other third-party service providers in Canada or other jurisdictions. Such jurisdictions may not have the same data protection laws as the jurisdiction in which you provided the information. When we transfer your information to other jurisdictions, including to jurisdictions outside of the province in which you reside (which may include transfer outside of Quebec for Quebec residents) and outside of Canada, it will be subject to the laws of that jurisdiction and may be disclosed to or accessed by the courts, law enforcement and governmental authorities in accordance with those laws. By submitting your information to us, you agree to this transfer, storing, and processing.

(b) Products and Services Offered by Neo

Your personal information may be disclosed to certain third parties that jointly offer, underwrite, endorse, or sponsor elements of our products and services.
  • Financial and banking partners: When you apply for or open a Product, we may share your identity, financial, credit and screening information, and information about others, with financial and banking partners involved in offering or servicing the account. We provide this information to applicable account providers to open your account and for regulatory reporting and compliance purposes.
  • Credit card partners: We may share your identity information with our credit card program partners to administer rewards programs, perform analytics, deliver personalized offers and experiences to you, and facilitate display of information in third party applications.
  • Mortgage providers: When you apply for or open a Neo Mortgage, we may disclose your identity, financial, and credit information provided in connection with your mortgage application (as well as other information we receive from third parties, such as your credit history), to a prospective mortgage lender for the purpose of processing your mortgage, including administering and servicing your mortgage, preparing documentation, verifying your identity, protecting you and Neo from fraud and error, and complying with legal and regulatory requirements. We may also disclose such personal information to any assignee or proposed assignment of the mortgage commitment, to an entity that funds, purchases, invests, or takes an assignment of all or part of your mortgage loan, including to facilitate such sale, to mortgage insurers, to consumer reporting agencies, to the title custodian, or to title insurance providers.
  • Neo Rewards/Store: We may share your identity, financial, online, transaction, counterparty and third party information with certain third parties as part of Neo Rewards™, Premium Rewards Package and Neo Store products for the purposes of providing rewards, products, attribution and fulfillment. To provide insights and analytics on rewards programs, we may share anonymized and aggregated information with third party merchants within our cashback program.
  • Mobile wallet providers: If you choose to load your card into a mobile wallet, we may share your identity and financial information with the wallet provider, Mastercard, and other service providers. Please see the Mobile Wallet Terms and Conditions
  • Insurance product providers: We may share your identity information to administer certain insurance products or other benefit perks associated with your Product.

(c) Legal and Compliance

In response to a search warrant to other legally valid inquiry or order, or to another organization for the purposes of investigating a breach of an agreement or contravention of law or detecting, suppressing or preventing fraud, or as otherwise required or permitted by applicable law or legal process, we, and our service providers may share your information with regulatory bodies, courts, law enforcement, or other government institutions or payment networks. Your personal information may also be disclosed where necessary for the establishment, exercise or defence of legal claims and to investigate or prevent actual or suspected loss or harm to persons or property.

4. Your Choices

(a) Access and Accuracy

Subject to limited exceptions under applicable law, you have the right to access, update, correct inaccuracies in, or port your personal information in our custody and control, to withdraw consent to our collection, use and disclosure of your personal information and request deletion of your personal information. You may do so by contacting our Privacy Officer at the address set out below at section 8. We may request certain personal information for the purposes of verifying the identity of the individual seeking access to their personal information records.Neo strives to keep your personal information as accurate and complete as possible, based on the most recent information available to us. We will make reasonable efforts to minimize the use of inaccurate, incomplete or outdated personal information when making a decision about you. In order to ensure the accuracy of your personal information we may regularly review or update your information and keep records of when your personal information was changed or updated. We may verify the accuracy of your information when you contact us about your accounts.If your personal information changes, is inaccurate or incomplete, you have the right to correct or amend the personal information we have about you, subject to exceptions prescribed by law. You may find and amend your personal information through our Platform, or you can contact Neo’s Client Experience team at the number located on the back of your card, at https://www.neofinancial.com/contact, or by writing to our Privacy Officer using the contact details at the end of this Privacy Policy, in section 8. If necessary, we will disclose the revised personal information with third parties to whom we had disclosed inaccurate information.Where required and subject to exceptions by applicable law, upon your request, Neo will disclose what personal information we have in our possession, what it is being used for, and to whom it has been disclosed. To request this information, please contact our Privacy Officer using the contact details at the end of this Privacy Policy, in section 8.

(b) Analytics and Advertising

  • Google Analytics: For more information on Google Analytics or to opt-out using the Google Analytics opt-out browser add-on, see “How Google uses data when you use our partners’ sites or apps” and “Google Analytics and Privacy”.
  • Personalized Marketing: Personalized marketing is optional and you can manage your privacy preferences within the Platform. If you reside in Quebec, you are opted out of personalized marketing.
  • Location Tracking: You can opt-out of location tracking at any time by turning off your location services for the App in the settings of your mobile device.
  • Cookies: We use “cookies”, which are small computer files that a website’s server places on your computer so that we can recognize your computer or device when you return. You can set your browser to notify you when you receive a cookie or to reject cookies, but this may impair our ability to customize and test your experience, like remembering your preferred language or present location-specific information to you.
  • Marketing: We may use third parties such as ad exchanges and data companies to serve our advertisements on our Platform or other websites. These companies may use cookies, tracer tags or web beacons to report certain information about your visits to our Website, and other websites (such as web pages you visit and your response to ads) in order to measure the effectiveness of our marketing campaigns and to deliver ads that are more relevant and tailored to you, both on and off our Platform. To learn more about this behavioural advertising practice or to opt-out of this type of advertising, you can visit the Digital Advertising Alliance website here, or at the Digital Advertising Alliance of Canada website here.

5. Safeguarding and Retention of Personal Information

We use industry standard security practices and procedures to safeguard your personal information.

We use procedures, practices, and reasonable administrative, technical and physical measures appropriate to the sensitivity of personal information, to protect against loss, theft, unauthorized access, disclosure, duplication, use or modification.We restrict access to your personal information to those individuals and parties on a need-to-know basis and we regularly train our employees on best information-security and privacy practices.We use secure technical and physical security measures such as passwords, encryption, multiple step authentication, security monitoring software, and secure cloud storage and restricted access to our offices.When we transfer personal information to third parties for processing, we contract with these third parties to ensure that they safeguard personal information in a way that is consistent with our privacy principles, procedures, and practices. Third parties are given only the information necessary to perform the services set out in the contract.

We limit retention of your personal information.

Except as otherwise permitted or required by law, your personal information will be retained for so long as is reasonably necessary to fulfill the purposes for which it was collected. We may keep your personal information along with other information about you in our records, even after your account is closed, for the purposes of complying with legal and regulatory obligations.

6. Information About Our Privacy Governance Policies and Practices

We are committed to protecting personal information and have implemented a comprehensive set of policies and practices that govern our treatment of personal information. These policies and procedures include, among other things, the following:
  • We have implemented policies and procedures to protect personal information in our custody and control from unauthorized access, use or disclosure.
  • We follow a SOC 2 compliance program to ensure that our systems and infrastructures are securely controlled and effectively operated. Controls are reviewed regularly to ensure operating effectiveness and security.
  • We regularly redact data when transmitting outside of secure segments or applications within our private network. We use encryption where necessary to further secure our data both at rest and while in transmission. In the event of a data breach, encrypted data cannot be viewed or otherwise used, and keys cannot be exported (i.e., stolen, breached, etc.) from our key management service by design.
  • We have implemented processes to respond to data subject requests and complaints in a timely and effective manner.
  • We have implemented a framework for the retention and destruction of personal information to ensure compliance with legal obligations, and to securely destroy personal information once no longer required.
  • We have implemented a privacy framework that defines the roles and responsibilities for our employees with respect to the treatment of personal information. While all Neo employees share the responsibility of keeping your personal information safe, we have identified key internal leaders who are responsible for data within our business.
  • We have designated a Privacy Officer who is responsible for overseeing Neo’s compliance with privacy legislation, for advising Neo about our personal information and data protection obligations, as well as monitoring compliance. Our technical teams are responsible for the technical controls in place to manage your data and keep it safe, including implementing information security systems and secure data storage.
  • We provide our employees with regular privacy training and awareness.

7. Updates to our Privacy Policy

This Privacy Policy describes our current privacy procedures and practices. We may change this Privacy Policy from time to time. Any changes will become effective when the updated policy is published on our Platform. Individuals who have a relationship with Neo will be notified of any material changes that may impact them. Your use of our Products following any changes to the Privacy Policy indicates your acceptance of the revised Privacy Policy.

8. Contact Us

Our Privacy Officer is responsible for advising Neo about our personal information and data protection obligations, as well as monitoring compliance. Please contact our Privacy Officer if you have any questions, concerns, or complaints about how we handle your personal information or about this Privacy Policy, or to submit an access, correction or deletion request. Our Privacy Officer can be contacted at the following address:
Attention: Privacy OfficerNeo Financial Technologies Inc.2000 - 401 9 Ave SWCalgary AB, T2P 3C5privacy@neofinancial.com