Security and Data Practices

Effective and last updated: August 26, 2026

BenefitKey minimizes personal-information collection and does not provide a file-upload surface. Account credentials are hashed, sessions are server-managed, unsafe requests are origin-checked, and security-sensitive actions are logged. Payment-card data is entered with the payment processor rather than stored by BenefitKey.

Never enter a SIN, date of birth, banking credentials, government password, medical record, or unrequested sensitive information. Report suspected security issues through the security contact published before launch.


This operational text should be reviewed by qualified Ontario and Canadian privacy/legal counsel before public launch. No contract wording can eliminate statutory obligations or liability that cannot lawfully be excluded.