← Back to Terms of use

Privacy at getowed

Last updated: October 9, 2026

getowed is made by Zook Design & Marketing in Toronto, the design practice of Arlindo Codinha. Zook builds web applications for disabled people. That is the whole mission, not a side project.

If you have a disability, you are asked for private information constantly — by forms, by programs, by people deciding whether you qualify. You have handed over enough. So getowed asks for as little as it can, and tells you plainly what happens to it.

The short version

  • You do not need an account to use getowed.
  • We do not ask for your name, your health information, or your diagnosis.
  • We do not sell your information. Not to anyone, ever.
  • If you give us your email, we use it only to write to you about getowed.
  • You can ask us to delete anything we hold about you, and we will.

What we collect

If you use the eligibility check: we keep your answers so the tool can work out what you may qualify for. These answers are anonymous — they are not attached to your name or your email, because we never ask for them.

We ask about what you can and cannot do day to day. We do not ask for a diagnosis, a medical condition, or a doctor’s name, and you should not type them in. These answers are deleted after 90 days.

If you ask us to tell you when the rules change: we keep your email address and the language you chose.

If your organization fills in our questionnaire: we keep the answers, your name, your work email, and your role, so we can follow up. We also record which browser you used and which page you came from, so we can fix the form when it goes wrong.

If you write to us: your message is sent to our mailbox as an email and is never saved to our database. People often mention their condition when they explain a problem, and this is how we keep our promise not to collect health information: the message lives in the inbox, exactly as if you had written from your own mail app.

If you work for an organization that uses the getowed console: we keep your work email, your role, and the name and professional title you choose to enter — you enter them yourself, and nobody at your organization can set them for you. We also keep a record of every change made to a case: which field, what it was, what it became, who made it, and when.

Your organization’s cases hold no information about the people they are about. A case carries a file reference your organization chose, a province, a stage, some dates and an amount. There is no name, no date of birth, no address, no contact detail and no diagnosis — there is no field for one, and a check on every build refuses to let one be added. The list connecting that reference to a person stays in your organization’s own system, and we cannot read it.

Your sheet stays on this computer. getowed never receives it. In the console, “Your sheet” lets your staff open your own spreadsheet — with names in it, if it has them — to find a client by name and see their row beside their case. It is read and held in that browser tab only: it is never sent to us and never written to the browser’s storage, and it is gone when the tab is closed or they sign out. We cannot see it, so it is not information we collect.

Automatically, when you visit: our host keeps basic technical logs — the type of browser and the page requested. Your address (IP) is used for a few seconds to stop one computer from flooding a form, and is not stored with your answers. We do not use advertising trackers.

When something goes wrong: if a page fails or a step can’t be completed, we count it, by the page and the kind of problem, so we can fix it. We don’t record what was on the screen, what you typed, or which person it was. We keep these counts for no longer than 12 months, and error details for 90 days.

Which language you see first: on every page, we follow the language your browser asks for. We never use your location to choose it. If you pick English or Français, your choice is remembered in the lang cookie.

Nothing about your visit is sent to another company to measure you or to advertise to you. Every request does pass through Cloudflare, which sits in front of the site to protect it; it is on our list of companies, with what it can see. There is no Google Analytics tag, no advertising tracker, and no measurement script from anyone else on this site. Everything in the next paragraph is counted on our own server, by us. A Google tag was on the public pages between 26 and 31 August 2026. It ran with consent set to denied, so it never placed a cookie on your device. We removed it because it could not measure a site that refuses to identify its readers, and because keeping it meant loosening a security rule on every page in return for nothing.

We count three things, and they are counts, not records of you. First: how many times each page was opened, on a given day, in a given language. Second: searches on this site that found nothing — the words you typed, so we can add the page you were looking for or learn to recognize your word for it. Third: the name of the website that sent you here, if your browser tells us — for example google.com, or an organization’s site. Only the website’s name, never the address of the page you came from, and counted per day. We cannot tell one visitor from another, and we do not try to. This counting stores no internet address and makes no code from one, nothing is placed on your device, and nothing links one page you read to another — so we count pages, never people.

The find box on this page is different. What you type into it is not counted, not stored, and not kept anywhere. We answer it and forget it. A privacy policy should be the last page that keeps a record of what you were worried enough to look up.

Two honest limits. The words you type show up in the address bar, so they will be in your own browser’s history — worth knowing if you are on a shared or library computer. And like every page you ask for, that address passes through the technical logs described above, which are deleted after 30 days.

Cookies

A cookie is a small file a site leaves on your device. getowed uses nine, and each one is set only when you do something that needs it. Most people ever receive three. None of them follow you anywhere.

CookieWhat it doesHow long it lasts
displayRemembers your display choices — theme, text size, motion, contrast. Set only when you choose them.1 year
langRemembers the language you picked, so we stop guessing.1 year
seenRemembers that you have already seen the short opening animation, so it plays once instead of every time.Until you close your browser
gcHolds your answers to the eligibility check, in your own browser, while you answer. Set only if you start the check. When you finish, a copy with no name or email attached is kept for 90 days, as described above.6 hours
gqHolds your place in the organization questionnaire, so nothing is lost between sections.7 days
gosSigns a caseworker in to their organization’s console. Only if you work at an organization that uses getowed.30 days; 12 hours with two-step sign-in, and 10 minutes while it waits for the code
gsSigns our own staff in to the admin console. You will never be given one.14 days
ccSigns our own operators in to the getowed command centre. You will never be given one. Their accounts also hold, encrypted, the secret behind the codes their authenticator app shows, and one-time recovery codes stored as hashes, until the account is closed or its two-step sign-in is reset.8 hours, or 14 days if they ask to stay signed in
cc_emailRemembers one of our own operators’ email address on their own computer, and whether they asked to stay signed in, so the command centre sign-in page is not blank every time. It holds nothing else, it cannot sign anybody in, and a “Not you?” button on that page deletes it. You will never be given one.90 days

Your display choices say something about you — that you need bigger text, or less movement on the screen. That stays on your device. It is never sent to our database, never shared with anyone, and we never build a picture of you from it.

There is no cookie pop-up, and here is why. We set no advertising cookies and no analytics cookies, and no other company sets one either — there is no script from anyone else on this site that could. The cookies we do set are the ones listed above, and every one of them is there because you did something that needs it — asking permission for those would be one more box between you and the help, and you meet enough of those already.

Why we collect it

  • Eligibility answers — to tell you what benefits you may qualify for, and to see which questions confuse people so we can rewrite them.
  • Email address — to tell you when the Disability Tax Credit rules change, and nothing else.
  • Questionnaire answers — to understand what organizations need, and to apply for funding. If we quote you in a funding application, we only do it if you ticked the box allowing it, and we remove your name.
  • Page counts — to know which pages are actually used, so we spend our time on those.
  • Searches that found nothing — this is the one that helps you directly. If twenty people search for a word we do not recognize, that is twenty people we failed, and it is the only way we find out. We would rather learn it from a list than from someone giving up.
  • Which websites send people here — to know whether our letters to organizations reached anyone, and whether people find us through search.
  • Your name and title on a case history — because your own profession asks for them, not because we do. Ontario’s College of Social Workers requires a record to carry the identity and designation of whoever made an entry, and the College of Nurses requires every entry to be signed with a unique identifier and a designated title. A history that read j.tremblay@clinic.ca would satisfy neither.

We do not monitor you at work. There is no record of when you signed in, how long you stayed, which pages you opened, how many cases you got through, or how fast. We do not log your address, we do not fingerprint your device, and we do not measure how much you do. That is a written decision, not an oversight — and it holds for your employer too: there is no screen anywhere in getowed that shows your manager your activity, because building one could make your employer’s own “we do not electronically monitor” policy untrue under Ontario’s Employment Standards Act.

What the case history records is the work: a field on a case changed, and by whom. Nothing about the person.

Nothing in getowed makes a decision about you. The eligibility check tells you what the rules say and shows you the law it rests on. For the federal credit, the Canada Revenue Agency decides; we do not, and neither does an organization’s copy of getowed.

Who else sees it

Nobody buys it, and nobody gets it for marketing.

A small number of companies handle information on our behalf, because they run the technology we use: Railway hosts the site and the database, Cloudflare sits in front of it, HostPapa runs our own mailboxes and sends our email, Postmark sends it when HostPapa cannot, and Stripe takes payment from organizations on a paid plan. They are only allowed to use it to provide that service to us. All five are named here, with what each one can see.

We will only give information to a government or the police if the law requires it.

Where it is kept

Email you send us is stored in Canada, including its backups. The database is in the United States. It is built with no place for a client’s name, date of birth or diagnosis — a case is identified by your organisation’s own file reference and, if you add one, your own client number, and nothing else — and what it holds about you is what you gave us yourself, such as an email address.

We would rather it were in Canada, and we looked. Our hosting company, Railway, does not offer a Canadian location — checked again on 12 September 2026, when the only four regions offered were Amsterdam, California, Singapore and Virginia. Ours is Virginia. We chose them anyway because the alternative was a slower, more expensive site — and a site this audience cannot load is not a private site, it is a useless one.

So the database is in the United States. Email you send us is a separate thing in a separate place: it goes to mailboxes run by HostPapa on a server in Toronto, Canada, and the backups of those mailboxes are kept on that same server. HostPapa confirmed both in writing on 13 September 2026. We said we would tell you once we had it in writing, and this is that. Email we send you, such as a notice that a rule has changed, goes out through HostPapa’s mail service; if that fails, Postmark, in the United States, sends it instead.

A few fields are free text — a support ticket, the file reference, the client number — and no design can stop somebody typing a client’s name into one. We do not need it and we ask you not to. Tell us and we will delete the case and its history, which is the only way to remove it.

Here is what that honestly means for you:

  • The company that stores the data is bound by contract to protect it and may only use it to run getowed for us.
  • A United States court or government agency could, in some situations, order Railway to hand over what the database holds. Canadian law cannot stop that.
  • This is why we collect so little. The eligibility answers describe what a person can and cannot do day to day, which is sensitive — so nothing in them links them to a name, an email or anyone else, and there is very little to hand over.

If this concerns you, you can use getowed without giving us anything that identifies you: the eligibility check needs no account, no name and no email. And you can write to us at any time to ask what we hold or to have it deleted.

If we ever move to a Canadian host, we will say so here and tell everyone who asked about rule changes.

If your organization is in Quebec, remember that under Quebec’s law both our database in the United States and our mailboxes in Toronto are outside Quebec. Our list of companies says who handles what and where, and if your privacy impact assessment has questions, write to us and we will answer them.

How long we keep it

WhatHow long
Eligibility answers90 days, then deleted
Email for rule changesUntil you unsubscribe — after which we keep only enough to be sure we never email you again
Questionnaire answers3 years, or until you ask us to delete them
Questionnaires you started but never sent30 days — an unfinished form is not consent
Technical logs30 days
A record of messages we sent you — your address, which message it was, and what your mail server answered. Never what the message said.30 days
If we wrote to your organization to introduce getowed: the work address we wrote to, which letter it was, and when. Never what you replied. We keep this one indefinitely, because the law that governs sending it puts the burden on us to prove we had a reason to — so deleting it would destroy our own evidence. Ask us to stop and we record that too, permanently, which is what stops it happening twice.Indefinitely
Page counts, searches that found nothing, and the websites that sent people here30 days
A caseworker’s account — work email, the name and title they entered, role. If they turn on two-step sign-in: its secret, kept encrypted, and their recovery codes, kept only as one-way hashesUntil their organization removes them, or closes its account. Two-step’s secret and codes go as soon as it is reset or replaced
An organization’s cases, and the history of who changed whatAs long as the organization keeps the case. Delete a case and its history goes with it, in the same instant — never one without the other. A deleted case is gone from the live database at once; our database backups still hold it for up to 89 days, then it is gone from those too
An organization’s client numbers — the number or code it chose to join one person’s cases. Never a name. A case’s history records that its client number changed, never what it wasAs long as a case uses it. When no case uses it any more, it is removed in the same instant. Our database backups still hold it for up to 89 days after that, then it is gone from those too
A record of each time an organization’s data was taken out — a download of its cases, the full copy, an import undone, a case deleted: who did it, when, and how many cases. Never which cases, and nothing from inside one. Only the organization’s administrator can see it24 months (730 days), or until the organization closes its account

We do not delete an organization’s cases on a schedule, and that is deliberate. Their professional colleges set the clock — Ontario’s College of Social Workers requires ten years from the last entry — and a tool that quietly deleted a record its owner was obliged to keep would be worse than useless to them. So they decide, and we do as we are told.

A case history cannot be edited or deleted, entry by entry, by anybody. Not by the caseworker who wrote it, not by their organization’s owner, and not by us. On 4 October 2026, before any organization had opened a case, we added a rule that stops a case history from storing the reference a case was opened with. It changed no entries, because none existed. From then on, nobody can edit a case history, including us. A correction is a later entry that says what was corrected. That is what the professional standards require of the record, and it is the only way the record can be trusted afterwards.

Your rights

You can ask us to:

  • tell you what we hold about you
  • correct anything that is wrong
  • delete it
  • give you what we hold about you in a common file format, such as CSV, or send it to another organization the law allows to receive it
  • stop using something you agreed to — rule-change emails, or being quoted in a funding application — from the day you tell us

Your answers to the eligibility check are the exception: nothing links them to you, so we cannot find them to give you or delete them early. They are deleted after 90 days in any case.

Write to hello@getowed.ca. We will reply within 30 days. You do not have to explain why, and asking costs nothing.

If you are unhappy with how we handle your information, you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca or 1-800-282-1376.

If you live in Quebec, you have additional rights under Quebec’s privacy law (Law 25), and you can also complain to the Commission d’accès à l’information du Québec at cai.gouv.qc.ca.

Person in charge of the protection of personal information: Arlindo Codinha, owner of Zook Design & Marketing, which makes getowed. hello@getowed.ca.

If you have a complaint about how we handle your information, write to that address. We acknowledge it, look into it, and answer you in writing within 30 days, and we tell you where to go if you are not satisfied.

If something goes wrong

If information we hold is ever lost, stolen, or seen by someone who should not have seen it, this is what we do.

We stop it if we can, work out what was affected and whose it was, and take steps so it does not happen again. If there is a risk that it could seriously harm you, we tell you as soon as we can, in plain words: what happened, what it means for you, and what you can do. If we have no way to reach you — the eligibility check never asks who you are — we say so publicly instead. We report it promptly to the Privacy Commissioner of Canada, and, if it involves people in Quebec, to the Commission d’accès à l’information. If an organization’s cases are involved, its account owner hears from us within 72 hours of our confirming it, as the licence promises.

We keep a record of every incident, serious or not, for at least five years. The record began on 17 September 2026, and nothing has been entered in it.

If getowed stops

An organization trusting getowed with records it has to keep for years is entitled to know what happens to them if getowed changes or stops.

An organization’s cases belong to it, not to us. Its staff can download every case, and the full history of who changed what, from the console at any time, as a spreadsheet file or as one complete file. That works without our help, and the licence keeps it working for 90 days after the agreement ends, however it ends.

If we shut the service down, the licence has us pay back the part of the year an organization has not used. After those 90 days we delete an organization’s cases when it asks us to. If getowed is sold, the licence can only go to a company set up to carry on the same business, and its promises go with it — including this one.

Children

getowed is not designed for children to use on their own. A parent or guardian can use it on behalf of a child.

Changes

If we change this policy, we will change the date at the top, add a line here saying what changed, and, if the change is significant, tell everyone who asked about rule changes by email. If a change matters to an organization under licence, we write to its account owner at least 30 days before it takes effect.

  • September 12, 2026 — Removed the visitor estimate. We no longer store anything derived from your internet address or browser.
  • September 13, 2026 — Began counting the name of the website that sent you here. HostPapa confirmed in writing where the mail is stored; we said we would tell you when we knew.
  • September 17, 2026 — The French version was checked against the English with language tools and references, and its note now says so. It has still not been professionally reviewed; the accessibility statement says when the note comes off. Corrected three things in this policy: Cloudflare is on the path of every visit, which the policy had not said; the companies are now named, with Railway listed once as host and database; and email we send you goes through Postmark in the United States. Added who is responsible for your personal information and how a complaint is handled; what we do if something goes wrong, and the record we keep; what happens to an organization’s cases if getowed stops; that nothing in getowed makes a decision about you; and your right to a copy of your information in a common format. Corrected the cookie table: finished eligibility answers are kept, without a name, for 90 days.
  • October 4, 2026 — Added the record of exports: each time an organization’s data is taken out — a download of its cases, the full copy, an import undone, a case deleted — we keep who did it, when and how many cases, never which cases, for 24 months; only the organization’s administrator can see it. Said how long a deleted case survives in our database backups: up to 89 days. On 4 October 2026, before any organization had opened a case, we added a rule that stops a case history from storing the reference a case was opened with. It changed no entries, because none existed. From then on, nobody can edit a case history, including us. Our own command-centre staff now sign in with a code from an authenticator app as well; we keep that app’s secret encrypted, and nothing about the people organizations help.
  • October 6, 2026 — Stripe: this policy now says Stripe takes payment from organizations on a paid plan, where it said it would once billing was switched on. What Stripe can see is unchanged: billing details only, never casework.
  • October 9, 2026 — Added client numbers. An organization can now give several cases the same number of its own, so that one person’s cases — a DTC application, an RDSP, an objection — are shown together. It is the organization’s own number, never a name; getowed warns if one looks like a name or a Social Insurance Number. A case’s history records that its client number changed, never what it was. A number no case uses any more is removed at once. Caseworkers can now turn on two-step sign-in; we keep its secret encrypted and their recovery codes only as one-way hashes, and nothing about the people they help.

Contact

hello@getowed.ca
Arlindo Codinha, operating as Zook Design & Marketing
Toronto, Ontario, Canada

Back to top