top of page

Privacy Policy

Privacy Policy

Effective date: September 6, 2026
Last updated: September 6, 2026

Frontline Roofing Company Ltd. (“Frontline,” “we,” “us,” or “our”) is responsible for the personal information under its control. This Privacy Policy explains how we collect, use, disclose, retain, protect, and provide access to personal information when you interact with Frontline, including through:

● our websites, forms, email, telephone, and other communications;

● our roofing, property, administrative, and related business services; and

● the Field1 service family, including Field1 Ledger and any other Field1 applications, features, interfaces, or systems that Frontline operates or expressly endorses (collectively, the “Services”).

Field1 is a broader operating and technology environment rather than a single application. References to Field1 in this Policy include its named applications and services as they develop. Field1 Ledger is presently a named Field1 application. Frontline Roofing Company Ltd. is the organization operating and endorsing the Field1 services covered by this Policy and is accountable for personal information under its control.

This Policy applies to customers, prospective customers, authorized business users, employees and contractors where applicable, suppliers, and other individuals whose personal information we process through the Services.

1. Accountability

Frontline Roofing Company Ltd. is the organization accountable for personal information under its control. Our Privacy Officer oversees this Policy, responds to privacy questions and requests, and reviews our privacy practices periodically.

Service providers that process information for us are required to use it only for authorized purposes and to protect it using appropriate safeguards. Some service providers, including Plaid, also have their own privacy notices describing information they process under their own authority.

2. Personal information we collect

The information we collect depends on how you interact with us and which Services you choose to use. It may include:

Contact, identity, and account information

Names, business names, addresses, email addresses, telephone numbers, account identifiers, user roles, authentication records, and information used to verify identity or authority.

Service and operational information

Property and project details, estimates, contracts, invoices, service orders, scheduling information, photos, documents, correspondence, notes, supplier or operator information, and records relating to the delivery of our services.

Financial and accounting information

Invoices, payments, refunds, expenses, receipts, accounting classifications, tax-related records, payment-provider records, and information associated with connected financial accounts.

If you choose to connect a financial account to Field1 Ledger through Plaid, the information made available to us may include:

● the financial institution and account name, type, subtype, and masked account identifier;

● current, available, and historical balances;

● transaction dates, amounts, descriptions, merchant or counterparty information, categories, pending or posted status, and related transaction details;

● account and connection status, consent scope, and synchronization metadata; and

● other financial information that is clearly disclosed and authorized in the Plaid Link consent flow.

The exact information available depends on the Plaid products enabled, the financial institution, the accounts you select, and the permission you grant. Field1 Ledger does not intentionally receive or store the online-banking username, password, security-answer, or one-time-passcode information that you enter within Plaid Link or your financial institution’s authorization page.

Communications and submitted content

Email, text, voice, support, uploaded statement, receipt, image, screenshot, and other content you choose to provide. Where a document or image contains personal or financial information, we process that content only for the purposes described in this Policy.

Technical, security, and usage information

Internet Protocol address, browser and device information, session and event records, timestamps, diagnostic information, security alerts, audit logs, cookie or similar-technology data, and information about how the Services are accessed and used.

3. How we collect information

We collect personal information:

● directly from you;

● from an organization or person that has authorized you to use the Services;

● from financial institutions and financial-data providers when you authorize a connection;

● from service providers used in our operations, such as Plaid, accounting, payment, communications, hosting, document-storage, and support providers;

● from our personnel in the course of providing services; and

● automatically when you use our websites or applications.

We limit collection to information reasonably required for identified purposes and collect it by fair and lawful means.

4. Why we use personal information

We may use personal information to:

● provide, administer, support, and improve the Services;

● prepare estimates, deliver work, manage service orders, communicate with customers, invoice, receive payments, and maintain business records;

● connect authorized financial accounts and provide cash-flow, transaction, budgeting, accounting, reporting, and operational views in Field1 Ledger;

● import, normalize, categorize, match, deduplicate, reconcile, enrich, and verify financial or operational records;

● distinguish preliminary or projected information from verified or accepted accounting information;

● authenticate users, authorize access, prevent fraud and misuse, maintain audit records, and protect the security and integrity of the Services;

● troubleshoot connections and respond to questions, access requests, correction requests, complaints, and support matters;

● comply with accounting, tax, employment, contractual, regulatory, court, and other legal obligations; and

● create aggregated or de-identified information that does not reasonably identify an individual.

We will not use personal information for a materially different purpose without obtaining additional consent unless the use is permitted or required by law.

5. Consent and choices

We obtain meaningful consent before or at the time personal information is collected, except where consent is not required or would be inappropriate under applicable law. We explain the nature of the information, the purposes for its use, and relevant disclosures in a form appropriate to the sensitivity of the information.

Connecting a financial account is optional. Before Plaid Link is opened, Field1 Ledger will explain why the connection is requested and the categories of financial information involved. Within Plaid Link, you choose the financial institution and account or accounts to connect and review the requested permissions. We collect financial-account information only after you authorize the connection.

You may decline to connect an account, disconnect an account, or withdraw consent to future collection and use, subject to legal or contractual restrictions and reasonable notice. Doing so may prevent us from providing features that depend on the connected information. Withdrawal does not invalidate processing that occurred before consent was withdrawn, and we may retain information where required by law or reasonably necessary for an authorized purpose.

6. Plaid-connected accounts

Field1 Ledger uses Plaid to help you connect and share information from financial accounts you select. Plaid may collect information directly from you, your device, and your financial institution and transmit authorized information to Frontline. Plaid’s processing is described in the Plaid End User Privacy Policy.

The categories of data requested through Plaid are limited to those needed for the disclosed Field1 Ledger functions. If we seek access to additional data or propose a materially different use, we will provide an additional notice and obtain any consent required before that access or use.

You may ask Frontline to disconnect a connected account. Where supported, you may also manage Plaid connections through Plaid Portal. Disconnecting stops future retrieval through that connection after the request is processed. Information already received may be retained or deleted in accordance with Section 10 below.

7. When we disclose personal information

We may disclose personal information:

● to personnel and authorized users who require it for their duties;

● to service providers that host, secure, support, analyze, communicate, store, process, or otherwise help deliver the Services, including financial-data, accounting, payment, cloud, and technology providers;

● to professional advisers, insurers, auditors, financial institutions, and counterparties where reasonably necessary for legitimate business or legal purposes;

● in connection with a proposed or completed financing, reorganization, sale, transfer, or other business transaction, subject to appropriate confidentiality and lawful-use restrictions;

● where you direct or authorize us to disclose it; or

● where permitted or required by law, including to protect rights, safety, property, the Services, or the public.

We do not sell or rent personal information. We do not disclose personal information to third parties for their own unrelated marketing without consent.

8. Service providers and processing outside Canada

We may use service providers located in Canada, the United States, or other jurisdictions. As a result, personal information may be processed or stored outside your province or outside Canada and may be accessible to courts, law-enforcement bodies, or regulators under the laws of those jurisdictions.

Frontline remains accountable for personal information transferred to service providers for processing on our behalf. We use contractual, organizational, and technical measures appropriate to the sensitivity of the information and the nature of the service.

You may contact our Privacy Officer for information about our use of service providers outside Canada.

9. Security safeguards

We apply safeguards appropriate to the sensitivity, amount, format, and use of personal information. These include, as applicable:

● encryption in transit using TLS 1.2 or better and encryption of stored consumer financial data;

● role-based access, least-privilege authorization, unique user accounts, and periodic access review;

● multi-factor authentication for access to critical systems that store or process consumer financial data and before access to the Plaid Link initiation capability;

● secure credential and secret management, with Plaid access tokens and API secrets restricted to authorized server-side processes;

● logging, monitoring, backup, change-management, vulnerability-management, and incident-response controls;

● contractual and security review of relevant service providers; and

● administrative policies, personnel responsibilities, and secure disposal practices.

No security method is absolute. We maintain procedures to identify, contain, investigate, document, remediate, and, where required by law, report and notify affected individuals of a breach of security safeguards.

10. Retention, disconnection, and deletion

We retain personal information only as long as reasonably necessary to fulfill the identified purposes, maintain appropriate business and audit records, resolve disputes, enforce agreements, and meet legal, accounting, tax, employment, insurance, or regulatory requirements.

Retention is determined by record category, sensitivity, purpose, legal requirement, and the status of the customer or account. Temporary import files and intermediate extraction data are deleted or de-identified when no longer needed. Records subject to an investigation, dispute, legal hold, or mandatory retention period are retained until that requirement ends.

When information is no longer required, we securely delete, destroy, or irreversibly de-identify it. Deletion from active systems may be followed by deletion from encrypted backups in accordance with the applicable backup lifecycle.

If you disconnect a financial account, we will disable future collection through that connection and deactivate or remove associated access credentials within our control. You may also request deletion of personal information we hold. We will comply subject to identity verification and any lawful exception or required retention period, and we will explain any material limitation on the request.

11. Access, correction, and privacy requests

Subject to applicable law, you may request that we:

● confirm whether we hold personal information about you;

● explain how it has been used and to whom it has been disclosed;

● provide access to your personal information;

● correct inaccurate or incomplete personal information;

● withdraw consent for future collection, use, or disclosure;

● disconnect a financial account; or

● delete personal information that is no longer required or legally retained.

Send requests to the Privacy Officer using the contact information below. We may ask for information reasonably necessary to verify your identity and authority. We will respond within the period required by applicable law. Access may be limited where disclosure would reveal another person’s information, confidential commercial information, information protected by legal privilege, or where another lawful exception applies. If we deny all or part of a request, we will provide reasons where required.

12. Cookies and similar technologies

Our websites and Services may use cookies or similar technologies that are necessary for authentication, security, preferences, performance, and operation. Where required, we obtain consent for non-essential cookies. Browser settings may allow you to block or delete cookies, but some functions may not operate correctly without necessary cookies.

13. Children

The Services are intended for businesses and adults and are not directed to children under 18. We do not knowingly use Plaid to collect financial information from children. If you believe a child has provided personal information without appropriate authorization, contact our Privacy Officer.

14. Questions and complaints

You may ask a question or challenge our compliance with this Policy by contacting our Privacy Officer. We will investigate privacy complaints fairly and take appropriate corrective action where warranted.

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada.

15. Changes to this Policy

We may update this Policy as our Services, providers, and legal obligations evolve. The current version will be posted at https://www.frontlineroofing.ca/policy with the effective or last-updated date. If a change materially affects how we use previously collected personal information, we will provide additional notice and obtain consent where required.

16. Contact the Privacy Officer

Frontline Roofing Company Ltd.
Attn: Privacy Officer
1-2929 Belisle Drive
Val Caron, Ontario P3N 1B3
Canada
Email: contact@frontlineroofing.ca
Telephone: +1 (705) 806-5418

bottom of page