Schachnow Law

Legal

Privacy Policy

This privacy policy has been compiled to better serve those who are concerned with how their ‘Personally Identifiable Information’ (PII) is being used online. PII, as described in US privacy law and information security, is information that can be used on its own or with other information to identify, contact, or locate a single person, or to identify an individual in context. Please read our privacy policy carefully to get a clear understanding of how we collect, use, protect or otherwise handle your Personally Identifiable Information in accordance with our website.

What personal information do we collect from the people that visit our blog, website or app?

When ordering or registering on our site, as appropriate, you may be asked to enter your name, email address, phone number or other details to help you with your experience.

If you book or pay for a consultation, you are also asked for your payment card details. Those details are entered directly into our payment provider’s secure fields and are never seen or stored by us — see “How do we protect your information?” below.

When do we collect information?

We collect information from you when you fill out a form or enter information on our site.

How do we use your information?

We may use the information we collect from you when you register, make a purchase, sign up for our newsletter, respond to a survey or marketing communication, surf the website, or use certain other site features in the following ways:

  • To follow up with them after correspondence (live chat, email or phone inquiries)

How do we protect your information?

We do not use vulnerability scanning and/or scanning to PCI standards.

We accept payment for consultations through our website. Card details are collected in payment fields hosted by Stripe, our payment processor, and are transmitted directly to Stripe — we never receive, see, or store your full card number.

We do not use Malware Scanning.

Your personal information is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. In addition, all sensitive/credit information you supply is encrypted via Secure Socket Layer (SSL) technology.

We implement a variety of security measures when a user enters, submits, or accesses their information to maintain the safety of your personal information.

All transactions are processed through a gateway provider and are not stored or processed on our servers.

Do we use ‘cookies’?

Yes. We use cookies and similar technologies for two purposes:

  • Measurement. We load Google Tag Manager, which in turn loads Google Analytics. These set cookies that help us understand how many people visit the site and which pages they find useful, in aggregate. We do not use them to serve advertising to you.
  • Payments and booking. On pages where you book or pay for a consultation, our payment provider (Stripe) and our scheduling provider (Calendly) set cookies that are necessary to process the transaction and to protect against fraud.

You can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookies. You do this through your browser settings. Since every browser is a little different, look at your browser’s Help Menu to learn the correct way to modify your cookies.

If you turn cookies off, the informational parts of the site will continue to work normally. Booking and payment pages may not function correctly, because the cookies those providers set are required to complete a transaction securely.

Third-party disclosure

We do not sell, trade, or otherwise transfer to outside parties your Personally Identifiable Information. We do share it with the service providers we rely on to run the firm — such as our payment, scheduling, email, and hosting providers — but only to the extent they need it to perform that service for us, and only under obligations of confidentiality.

Third-party links

We do not advertise or sell third-party products on our website. We do embed services we use to operate it — Stripe for payments, Calendly for scheduling consultations, and Google Tag Manager and Google Analytics for measurement. Those providers handle your information under their own privacy policies, and we encourage you to read them.

Google

We do not run Google AdSense, DoubleClick, or any other advertising network on this website, and we do not serve ads on it.

We do use Google Tag Manager and Google Analytics to measure how the site is used — for example, how many people read a given page. Google Analytics collects information such as the pages you visit, the approximate region you visit from, and the type of device and browser you use. We use it in aggregate to improve the site; we do not use it to build advertising profiles.

Opting out:
You can prevent Google Analytics from collecting information about your visit by installing the Google Analytics Opt-out Browser Add-on, or by blocking analytics cookies in your browser settings. You can also review how Google handles data from sites that use its services at policies.google.com/technologies/partner-sites.

California Online Privacy Protection Act

CalOPPA is the first state law in the nation to require commercial websites and online services to post a privacy policy. The law’s reach stretches well beyond California to require any person or company in the United States (and conceivably the world) that operates websites collecting Personally Identifiable Information from California consumers to post a conspicuous privacy policy on its website stating exactly the information being collected and those individuals or companies with whom it is being shared. - See more at: http://consumercal.org/california-online-privacy-protection-act-caloppa/#sthash.0FdRbT51.dpuf

According to CalOPPA, we agree to the following:

Users can visit our site anonymously.

Once this privacy policy is created, we will add a link to it on our home page or as a minimum, on the first significant page after entering our website.

Our Privacy Policy link includes the word ‘Privacy’ and can easily be found on the page specified above.

You will be notified of any Privacy Policy changes:

  • On our Privacy Policy Page

Can change your personal information:

  • By logging in to your account

How does our site handle Do Not Track signals?

Our site does not currently change its behaviour in response to a Do Not Track (DNT) browser signal, because there is still no agreed industry standard for how sites should respond to one. If you do not want to be included in our analytics measurement, you can opt out using the browser add-on or cookie settings described under “Google” above.

Does our site allow third-party behavioral tracking?

We do not allow advertising networks or behavioural-advertising trackers on our site, and we do not permit any third party to track you across other websites for advertising purposes. The only third-party measurement we allow is the Google Analytics usage measurement described above.

COPPA (Children Online Privacy Protection Act)

When it comes to the collection of personal information from children under the age of 13 years old, the Children’s Online Privacy Protection Act (COPPA) puts parents in control. The Federal Trade Commission, United States’ consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children’s privacy and safety online.

We do not specifically market to children under the age of 13 years old.

Fair Information Practices

The Fair Information Practices Principles form the backbone of privacy law in the United States and the concepts they include have played a significant role in the development of data protection laws around the globe. Understanding the Fair Information Practice Principles and how they should be implemented is critical to comply with the various privacy laws that protect personal information.

In order to be in line with Fair Information Practices we will take the following responsive action, should a data breach occur:

We will notify you via email

  • Within 7 business days

We also agree to the Individual Redress Principle which requires that individuals have the right to legally pursue enforceable rights against data collectors and processors who fail to adhere to the law. This principle requires not only that individuals have enforceable rights against data users, but also that individuals have recourse to courts or government agencies to investigate and/or prosecute non-compliance by data processors.

CAN SPAM Act

The CAN-SPAM Act is a law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped from being sent to them, and spells out tough penalties for violations.

We collect your email address in order to:

  • Send information, respond to inquiries, and/or other requests or questions

To be in accordance with CANSPAM, we agree to the following:

  • Not use false or misleading subjects or email addresses.
  • Identify the message as an advertisement in some reasonable way.
  • Include the physical address of our business or site headquarters.
  • Monitor third-party email marketing services for compliance, if one is used.
  • Honor opt-out/unsubscribe requests quickly.
  • Allow users to unsubscribe by using the link at the bottom of each email.

If at any time you would like to unsubscribe from receiving future emails, you can email us at

  • Follow the instructions at the bottom of each email.

and we will promptly remove you from ALL correspondence.

Our Web Extension

This section describes the private web extension we use internally (the “Extension”). The Extension is an internal work tool for the firm’s own lawyers and staff, distributed privately to them. It requires a Schachnow Law staff account, and it does nothing at all until a member of the firm signs in to it. It is not offered to, and cannot be used by, members of the public. It operates only on Gmail (mail.google.com) and on the Government of Canada IRCC application portals (onlineservices-servicesenligne.cic.gc.ca and prson-srpel.apps.cic.gc.ca). Apart from the third-party Gmail integration library described under “How the Extension shares that data” below, it communicates only with our own backend at api.joshuaschachnowlaw.com. Because the Extension is used to work on client files, the information it handles includes confidential and, in many cases, solicitor-client privileged client information, and it is treated accordingly under the firm’s professional obligations of confidentiality.

What user data the Extension collects

The Extension collects only the following categories of data:

  • Account and authentication information.The work email address of the firm staff member signing in, the one-time sign-in code emailed to that address, and, once verified, a sign-in token and the staff member’s first name.
  • Email addresses and names of correspondents (Gmail only).When a firm staff member has an email thread or a compose window open in Gmail, the Extension reads the email addresses and display names of the people on that thread or in the “To” field, the Gmail thread identifier, and the address of the firm mailbox in use. It sends these to our backend so it can tell whether that person is already a lead or client of the firm.
  • Personal communications. The Extension does not read, collect, store, or transmit the body, subject line, or attachments of any email message. Only the addresses and names in the message headers are used, and only for matching a correspondent to an existing file.
  • Information a staff member types into the Extension. Notes, call logs, lead details, and any instructions or context typed in when asking the Extension to prepare a draft email.
  • Website content on IRCC portal pages.When a signed-in staff member opens the Extension, it reads the web address of the active browser tab in order to tell whether that tab is a supported IRCC application page. That address is sent to our backend only when the tab is one of the two IRCC portals listed above. On those pages, and only after the staff member picks a client, matter, and person, the Extension retrieves that client’s existing application information from our backend and types it into the corresponding government form fields, and reads back the fields it filled in order to confirm the form was completed correctly.
  • Client and matter information.Lead, client, matter, task, and activity records already held in the firm’s own case-management system, retrieved so they can be displayed to the signed-in staff member.

The Extension does notcollect browsing history, does not monitor pages outside Gmail and the two IRCC portals, does not collect health, financial account, or authentication credentials for any third-party service, and contains no advertising or behavioural-tracking code. Aside from the diagnostic reporting built into the Gmail integration library described below, it contains no analytics code. It collects no information from members of the public — only from the firm’s own signed-in staff, about the firm’s own leads and clients.

How the Extension uses that data

The data described above is used solely to provide the Extension’s features to the signed-in staff member:

  • To sign the staff member in and keep them signed in.
  • To identify whether a person the firm is corresponding with is an existing lead or client, and to display that person’s file, status, matters, and history in a panel beside Gmail.
  • To record notes, call logs, status changes, and reminder settings against the correct lead or client file.
  • To prepare a draft email for the staff member to review, edit, and send themselves. Drafts are never sent automatically.
  • To fill in Government of Canada immigration forms on the client’s behalf using information the client has already provided to the firm.

We do not use Extension data for advertising, for building profiles, for any form of behavioural tracking, or for any purpose unrelated to providing legal services to the firm’s clients. We do not sell, rent, or trade it.

How the Extension stores and protects that data

  • On your device.The Extension uses the browser’s local extension storage to hold the sign-in token, the staff member’s first name, the last client, matter, and person selected for form autofill, and — for up to ten minutes during sign-in — the email address a sign-in code was sent to. Nothing else is stored on the device. The sign-in token expires after 90 days and is deleted immediately when the staff member signs out, when the token is rejected by our servers, or when the Extension is uninstalled.
  • On our servers.Lead, client, matter, and activity records are stored in the firm’s case-management system on secure, access-controlled servers. Access is limited to firm personnel who need it to do their work and who are bound by professional obligations of confidentiality. All communication between the Extension and our servers is encrypted in transit over HTTPS, and every request for firm data must carry a valid, unexpired sign-in token.
  • Retention. Client and lead records are retained for as long as the firm is required to retain client file information under its professional and legal obligations, and are then deleted or destroyed. Data held on the device is retained only for as long as described above.

How the Extension shares that data

We do not sell, trade, or otherwise transfer Extension data to outside parties for their own purposes. Data is disclosed only to the following service providers, only to the extent needed to operate the Extension, and only under contractual confidentiality obligations:

  • Google. The firm’s email runs on Google Workspace. When a staff member has a Gmail thread open, our backend uses the Gmail API — with the firm’s own Google Workspace authorization, over the firm’s own mailboxes — to read the From, To, Cc, and Reply-To headers of that thread so correspondents can be matched to a file. Message bodies and attachments are not requested or received.
  • Google Cloud Vertex AI.When a staff member asks the Extension to prepare a draft email, the relevant lead or matter details and the staff member’s instructions are sent to Google Cloud’s Vertex AI service to generate the draft text, which is returned to the staff member for review. This data is processed to produce the requested draft and for no other purpose of ours.
  • InboxSDK.The Extension uses InboxSDK, a third-party library, to render its panel inside the Gmail interface. The library reports its own errors and load events to its provider. Those reports contain technical diagnostic information — a session identifier, the Extension’s identifier, and a one-way hash of the signed-in Gmail address. They do not contain lead, client, matter, or message data.
  • Government of Canada (IRCC).When form autofill is used, client information is entered into the IRCC portal form at the staff member’s direction — the same information that would otherwise be typed in by hand as part of the client’s application.

We may also disclose information where we are required to do so by law, by court order, or by the rules of the Law Society of Ontario.

Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Your choices regarding the Extension

A staff member can sign out of the Extension at any time from its popup, which deletes the stored sign-in token and name from the device, or remove the Extension entirely through the browser’s extensions page, which deletes all data the Extension has stored locally. To ask about, access, correct, or request deletion of information the firm holds about you, contact us using the details below.

Contacting Us

If there are any questions regarding this privacy policy, you may contact us using the information below.

[email protected]

Last Edited on 2026-09-02