Privacy Policy
Effective Date: August 29, 2026
1. About This Policy
CareCard helps students and professionals understand, complete, manage, and validate requirements for clinical placements and employment. Users maintain a secure, portable CareCard Profile and decide which authorized organizations or individuals can access it.
This Privacy Policy explains how CareCard collects, uses, discloses, retains, and protects personal information when individuals create and manage a Care Portfolio and when educational institutions, placement organizations, employers, or other authorized users access CareCard services.
This Policy provides notice of CareCard’s information practices; it is not a request for blanket consent. CareCard seeks meaningful consent when CareCard is responsible for obtaining it. In other circumstances, CareCard processes information under instructions from an organization responsible for the information or as permitted or required by law.
2. Information We Collect
CareCard limits collection to information reasonably necessary for identified placement, employment, account, security, support, and service-delivery purposes. The information collected depends on the features used and the requirements configured for a user or authorized organization.
Account and profile information, such as name, contact information, authentication details, role, educational or professional affiliations, programs, placements, employment relationships, and communication preferences.
Care Portfolio information, such as credentials, uploaded documents, requirement details, review and validation results, status and expiry information, notes, sharing choices, messages, and related records. A Care Portfolio may contain personal health information and other sensitive personal information.
Technical, usage, support, and security information, such as device and browser details, IP address, cookies, access and audit logs, feature interactions, error and performance records, and information included in support requests.
Users and organizations should provide only information relevant to the applicable requirement or service. CareCard does not assume that every Care Portfolio item is personal health information; classification and legal obligations depend on the information, purpose, custody or control, information flow, and roles involved.
3. How We Use and Disclose Information
CareCard uses and discloses personal information for identified and lawful purposes: with consent when CareCard is responsible for obtaining it, under instructions from an organization with lawful authority, or as otherwise permitted or required by law. CareCard does not sell or rent personal information or personal health information to advertisers or data brokers.
CareCard may use or disclose information to:
Create and operate accounts and Care Portfolios; receive and store documents; present requirements; record reviews, validations, status, and expiry; and provide related support.
Carry out a user’s sharing choices and allow educational institutions, placement organizations, employers, or other authorized individuals to access the Care Portfolio information made available to them.
Support authorized program, placement, employment, and organization workflows; communicate about requirements and service activity; and maintain records of access and instructions.
Authenticate users, secure and maintain the Platform, detect and respond to misuse or incidents, meet legal and contractual obligations, and improve service reliability using aggregated or de-identified information where permitted.
CareCard does not:
Sell or rent personal information or personal health information for advertising or data-broker purposes.
Use Care Portfolio information for targeted advertising or unrelated profiling.
Permit access, use, or disclosure outside authorized service purposes, user sharing choices, governing agreements, or applicable law.
4. Security, Retention, and Disposal
CareCard uses administrative, technical, organizational, and infrastructure safeguards appropriate to the sensitivity of the information. CareCard retains information only as long as reasonably necessary for the identified purposes, applicable user or organization instructions, legal and contractual obligations, dispute resolution, and security. When information is no longer required, CareCard deletes or de-identifies it under its retention practices, subject to lawful holds and limited backup cycles.
Safeguards include:
Encryption in transit and at rest where appropriate to the information and system.
Secure authentication and access controls designed to prevent unauthorized account and system access.
Role-based access and least-privilege practices for authorized users, CareCard personnel, and service providers.
Logging, monitoring, security reviews, and controls proportionate to the nature and sensitivity of the information processed.
Incident-response and breach-management procedures, including notification to affected parties and regulators when required by law or contract.
5. Access and Sharing
Users remain in control of sharing through CareCard and decide which authorized organizations or individuals can access their Care Portfolio. Access is limited according to Platform permissions, authorized relationships, and applicable agreements.
Information may be accessed by:
The user who owns the Care Portfolio and any other individual the user authorizes through the Platform.
Educational institutions, placement organizations, employers, or other organizations to which the user grants access for an identified program, placement, employment, or related purpose.
Authorized CareCard personnel and service providers who need the information to operate, secure, maintain, or support the Platform and who are subject to confidentiality and data-protection obligations.
User control within CareCard does not displace a recipient’s legal duties or other lawful authority after information is received. CareCard may also disclose information where permitted or required by law, such as in response to a valid legal process, and will provide notice where legally permitted and appropriate.
6. Privacy Roles and Applicable Law
CareCard’s privacy role depends on the information and the circumstances, including the service provided, governing agreements, purpose, custody or control, and actual information flow. CareCard is responsible for the commitments and safeguards that apply to its role.
The following distinctions apply:
A Care Portfolio may contain personal health information and other personal information. Ontario’s Personal Health Information Protection Act (PHIPA) applies only where its statutory definitions and circumstances are met; an organization that views a portfolio is not automatically a health information custodian.
Depending on the context, CareCard may process information on its own behalf or as a service provider or agent for an organization under an agreement. PIPEDA or another applicable federal or provincial privacy law may govern other information or relationships.
Organizations that define requirements or receive Care Portfolio information remain responsible for their lawful authority, notices, decisions, access, use, disclosure, retention, and responses to formal rights requests for records in their custody or control.
7. Individual Choices and Privacy Rights
Subject to identity verification and any applicable legal, contractual, or technical limits, individuals may exercise the choices and rights available for their information.
These may include the ability to:
Access or obtain information about personal information CareCard controls, including how it has been used and disclosed, subject to applicable exceptions.
Correct inaccurate or incomplete profile information. Correcting a CareCard copy does not necessarily amend an issuer’s or health information custodian’s source record, which must be addressed with the organization that controls that record.
Change or withdraw a sharing choice or consent and request deletion or de-identification where available, subject to reasonable notice and legal, contractual, retention, backup, and transaction-record requirements. CareCard will explain material consequences where required.
Ask a privacy question or make a complaint to CareCard, the organization responsible for a record, or an applicable privacy regulator.
8. Changes to This Privacy Policy
CareCard may update this Privacy Policy to reflect changes in the Platform, information practices, law, security requirements, or business operations. The current version will display its effective date.
CareCard will provide notice of material changes as required by law or an applicable agreement and will seek consent if a new collection, use, or disclosure requires consent. An updated policy does not reduce rights that cannot lawfully be limited.
9. Contact CareCard
For privacy questions, access or correction requests concerning information controlled by CareCard, or complaints about CareCard’s practices, contact:
admin@carecard.ca581 Talbot StreetSt. Thomas, ONN5P 1C5