Privacy Policy

    Last updated: July 31, 2026

    Who we are and what this policy covers

    RivalQuest Health ("we", "us", "our") is a private-pay service that helps Canadian patients arrange diagnostic imaging at facilities in the United States and consultations with specialist physicians. To do that, we collect and handle personal health information.

    This policy describes our information practices in plain language: what we collect, how we use it, where it is stored, who we share it with, how we protect it, and the rights and choices you have. We handle your personal health information in accordance with Ontario's Personal Health Information Protection Act (PHIPA).

    Our Privacy Officer is responsible for our privacy practices and is your contact for any question, access request, correction request, or complaint. You can reach the Privacy Officer at support@rivalhealth.ca.

    The information we collect

    • Account and contact information. Your name, email address, mailing address, date of birth, and phone number. Your password is held by our authentication service in protected form; we never store it as readable text.
    • Health information you give us. The details of your imaging and consult requests — the type of scan, the body part, the reason for the exam, your referring physician's details, and any referral, medical history, or other documents you upload. Messages you send through the portal, including attachments.
    • Records created while coordinating your care. Requisition forms we prepare, signed requisitions and imaging reports returned to us by fax, consult notes from specialists, appointment records, and the status history of your requests.
    • Payment records. Your payment card details are entered directly with Stripe, our payment processor — full card numbers never touch our systems. We keep records of amounts, payment status, and payment references.
    • Consent records. Each time you give or withdraw a consent, we record which document version you saw, a digital fingerprint (hash) of its exact text, the date and time, and how you gave it.
    • Security records. Detailed audit logs of activity in your account (described under "How we protect your information"), and a one-way scrambled version (hash) of your email address that lets us investigate suspicious sign-in activity without exposing the address itself.
    • Contact form messages. If you use the public contact form, we receive the name, email address, subject, and message you type. These are emailed to our support inbox and are not stored in the application database. Please do not include health information in the contact form.

    How we use your information

    • To arrange the imaging appointments and specialist consultations you request, including preparing requisitions and sending them to your referring physician and the imaging facility.
    • To return your results to you through your secure account.
    • To communicate with you about your requests, your account, and your membership.
    • To process the payments you authorize.
    • To keep the service secure — verifying who is signed in, logging access to health records, and investigating suspicious activity.
    • To meet our legal obligations, including maintaining the records PHIPA requires.

    We do not sell your information. We do not use it for third-party advertising. We do not run third-party analytics or tracking scripts on this site.

    Where your information is stored

    Your records live on Amazon Web Services (AWS) infrastructure in the Canada (Central) region: our application database, our encrypted file storage (protected with an encryption key that we control), our sign-in service, and our email-sending service all reside in Canada. Data is encrypted in transit and at rest.

    Our public website pages (marketing content, pricing, this policy) are delivered through a content delivery network with servers in North America and Europe so pages load quickly. Only public website content travels through that network — your health information never does. When you use the portal, your records come directly from our Canadian servers over an encrypted connection.

    Who we share your information with

    Amazon Web Services — our infrastructure provider, in Canada

    All of our systems run on Amazon Web Services in the Canada (Central) region, as described under "Where your information is stored" above: the database holding your records, the encrypted storage holding your documents, the sign-in service holding your account credentials, and the service that sends our emails. AWS processes this information on our behalf, in Canada.

    U.S. imaging facilities and specialists — with your consent

    This is the core of what we do, and the most significant disclosure. When you submit an imaging request, we send the U.S. imaging facility what it needs to perform your scan: your name, date of birth, contact details, the type of scan and body part, the reason for the exam, and your referral. When you request a specialist consultation, your request and the medical history or imaging documents you attach are sent to the U.S.-based specialist.

    We only do this with your explicit consent, recorded when you join and confirmed with each request. Once a U.S. provider receives your information, it is handled under U.S. law (primarily HIPAA) and the provider's own records policies rather than PHIPA, and it may in some circumstances be accessible to U.S. authorities in ways that differ from Canadian law. U.S. providers keep their own records according to their own legal obligations — deleting your information from RivalQuest Health does not remove it from their files.

    Your referring physician — in Canada

    Diagnostic imaging requires a referral from a Canadian physician. We fax the requisition we prepare to your referring physician for review and signature, and your imaging report is also sent to that physician, who is your primary contact for follow-up care.

    SRFax — our Canadian fax provider

    Requisitions and results move between us, physicians, and imaging facilities by fax. We use SRFax, a Canadian fax service provider, to send and receive these documents. Faxed documents (which include health information) pass through and are held by SRFax in Canada as part of providing that service.

    Stripe — our payment processor, in the United States

    Payments are processed by Stripe. The billing details you enter in the payment form — your name, card number, and billing address — go directly to Stripe as the payment processor and are handled under Stripe's own security certifications. Separately from what you enter, we attach a limited set of request details to the payment: your account identifier (a random code, not your name or email), the type of exam being paid for (for example "MRI"), and a service description; for membership payments, the plan and its duration. Stripe is a U.S. company, so this payment information is processed and stored in the United States. This transfer is part of the cross-border consent you provide.

    Email notifications — sent from Canada, kept minimal

    We send transactional email (account setup, payment re-authorization requests, and "you have an update" notices) through Amazon's email service in Canada. Notification emails are deliberately minimal: they tell you that an update or message is waiting and never include your health details, which stay in the secure portal.

    Contact form relay

    Messages sent through the public contact form are emailed to our support address, which currently uses a third-party mail-forwarding service (ImprovMX) to relay messages to the mailbox we read. Your contact-form message therefore transits that forwarding service and remains in our support mailbox as our record of the conversation. This is why we ask you not to include health information in the contact form — signed-in members should use secure messaging instead.

    Physician registry lookup

    When you look up your referring physician while filling in a request, the name (and optionally postal code) you type is checked against the College of Physicians and Surgeons of Ontario's public register to find a match. The search is logged on your account. Only the physician details you typed are sent — none of your health information.

    When the law requires it

    We may disclose information where PHIPA or another law permits or requires it — for example, in response to a court order.

    Cross-border transfers and your consent

    Because sending your health information to U.S. providers is central to the service, we treat that consent carefully:

    • You give the cross-border consent when you create your account, and each imaging or consult request shows you the notice again and confirms the consent at submission time.
    • Every consent is recorded with the exact document version and a digital fingerprint of the text you saw, so there is never doubt about what you agreed to.
    • You can withdraw the cross-border consent at any time from your Account page. Withdrawal blocks any new imaging or consult requests, and any of your requests still in progress are cancelled. Results already delivered to your account stay available to you. Withdrawal cannot recall information already sent to a U.S. provider or to your physician.
    • You can give the consent again at any time from the same page.

    How we protect your information

    • Encryption. Data is encrypted in transit and at rest; uploaded documents are stored in a private bucket encrypted with a key we control.
    • Access controls. Database-level access rules ensure patients can only ever read their own records. Staff access is limited to what is needed to coordinate your care.
    • Audit logging. Every change to a health record is automatically logged, and we log staff access to patient records and documents — what happened, who did it, and when. These logs are retained and reviewed, and automated monitoring alerts us to unusual events.
    • Short-lived document links. Links for viewing or downloading your documents expire after five minutes and are generated fresh each time.
    • Session protections. Your sign-in lasts only as long as your browser tab: closing the tab ends the session, so the next person on a shared computer does not inherit your account. You are also signed out automatically after 10 minutes of inactivity, with a warning at 8 minutes.
    • Sign-in monitoring. Failed sign-in attempts are recorded using a one-way hash of the email address used, letting us detect credential-stuffing attacks without keeping readable addresses in security logs.

    How long we keep your information

    We keep your records while your account is open so we can coordinate your care and show you your history. You are in control of two deletion paths, described under "Your rights" below. When records and documents are deleted, they are removed from our live systems immediately, and residual copies in our backup and recovery layer clear within 90 days. Audit logs and consent records are kept even after health records are deleted — they are the accountability trail PHIPA expects us to maintain, and they record events (who accessed what, and when), not the content of your health records. Where a law requires us to keep a record for a minimum period, we keep it for that period. Records already in the hands of your physician or a U.S. provider are governed by their retention obligations, not ours.

    Your rights and choices

    • Access. You can see your requests, results, messages, and consent history in your account at any time, and you can ask the Privacy Officer for a copy of the information we hold about you.
    • Correction. You can update your profile information yourself from the Account page, and you can ask us to correct anything you believe is inaccurate or incomplete.
    • Deleting your health data. The Account page has a self-serve option that permanently deletes your health records from our systems — imaging results, requests, appointments, consults, messages, and every uploaded or faxed document — while keeping your account open.
    • Closing your account. To close your account entirely, contact us at support@rivalhealth.ca and we will delete your account, profile, and stored documents.
    • Withdrawing consent. See "Cross-border transfers and your consent" above.
    • Complaints. Raise any privacy concern with our Privacy Officer at support@rivalhealth.ca. You also have the right to complain to the Information and Privacy Commissioner of Ontario: 2 Bloor Street East, Suite 1400, Toronto, ON M4W 1A8; 1-800-387-0073; www.ipc.on.ca.

    Cookies and tracking

    We do not use advertising cookies, third-party analytics, or tracking pixels. The browser storage we use ourselves is the per-tab session storage that keeps you signed in while a tab is open; it is cleared when the tab closes. One exception to note: on payment screens, Stripe's own payment script runs and may set its own cookies, which Stripe uses for fraud prevention as described in Stripe's privacy policy.

    Changes to this policy

    When we change this policy, we will post the new version here with an updated date. If a change is significant — a new type of disclosure, a new processor handling health information — we will notify you and, where the change affects a consent you have given, ask you to review and accept the updated notice before it applies to you.

    Contact us

    Privacy Officer, RivalQuest Health — support@rivalhealth.ca. We will respond to access requests, correction requests, and complaints as PHIPA requires.