← Back to sign up
FHO+ RADAR

Privacy Policy & Terms of Service

Last updated: July 19, 2026 · Effective date: July 2, 2026


Part 1, Privacy Policy

FHO+ RADAR ("the Service", "we", "us", "our") respects your privacy and is committed to protecting the personal information you entrust to us. This Privacy Policy explains what we collect, why, how we use and protect it, and the rights you have. It is written to comply with Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") and the ten fair information principles set out in its Schedule 1.

1. Accountability and who we are

FHO+ RADAR is a billing-insights dashboard for Ontario FHO+ physicians, operated by J. Kwan, sole proprietor, based in Ontario, Canada (the "operator"). The operator is accountable for personal information under its control, including information transferred to the service providers listed in Section 8.

We have designated a Privacy Contact responsible for our compliance with this policy and applicable privacy law. You can reach the Privacy Contact, and make any request or complaint described below, through the in-app contact form, the "?" button at the bottom-left of your dashboard. (We route privacy contact through this form rather than publishing an email address to reduce spam and automated harvesting; we respond to verified requests within a reasonable time, and in any event within the timelines required by PIPEDA.)

2. The legal framework that applies to your data

  • PIPEDA applies. The Service handles personal information in the course of commercial activity, so PIPEDA governs how we collect, use, disclose, and safeguard it.
  • PHIPA, current scope. Ontario's Personal Health Information Protection Act, 2004 ("PHIPA") governs "personal health information" held by "health information custodians." As the Service is designed and operated today, the data you upload is your own billing and administrative information, Remittance Advice (RA) figures, payment streams, roster and demographic counts, and cap utilization. It is not the identifiable clinical record of any patient, and the operator is not acting as a health information custodian or its agent. On that basis, PHIPA does not currently apply to the Service.
  • Patient identifiers are never stored. Standard RA files can include per-patient claim lines. Your RA is read and de-identified locally in your browser, and only the de-identified copy is ever sent to us. Removed before anything leaves your device: the health card number, the patient name, the health-card version code, and the accounting reference your billing software or EMR attaches to a claim. What remains on each claim line is the service date, the fee code, the number of units, the amounts submitted and paid, the ministry's reason code, and the ministry's own claim reference. That claim reference is assigned by the ministry, contains no patient identifier, and is what lets you find a specific claim again in your own billing software.

    We keep those de-identified claim lines so the Service can tell you whether the hours you tracked were actually submitted and paid, which is not answerable from the summary figures alone.

    Two automatic checks gate every upload: the de-identified copy must contain none of the health card numbers read from the original, and it must reproduce the same billing figures as the original. If either check fails the upload is refused outright and nothing is stored. Because the Service is not built to be a PHIPA-compliant repository, you must not upload any other record that contains identifiable patient health information (for example, chart notes, patient lists, or claim-level exports from your EMR). See Terms of Service Section 6 (Acceptable use).
  • Future change. If we later introduce a feature that intentionally ingests identifiable patient health information, PHIPA (and potentially a different legal relationship, such as our acting as an agent of a health information custodian under a written agreement) would apply to that feature. We will not enable any such feature without first updating this policy, putting the required safeguards and agreements in place, and obtaining your express consent.

3. The purposes for which we collect your data

We collect and use personal information only for the following identified purposes, and we limit collection to what is necessary for them:

  • To create and operate your account and authenticate you.
  • To parse your uploaded RA files and present the derived billing insights, trends, flags, and forecasts that are the core function of the Service.
  • To let you record and track your FHO+ after-hours and hourly-code time through the Hours Tracker, and, where you sign in, to back up that log and sync it across your devices.
  • To provide, support, troubleshoot, and improve the Service (including fixing parser errors).
  • To administer subscriptions and billing.
  • Where you have opted in, to compute anonymized peer-benchmarking aggregates (Section 7).
  • To meet legal, regulatory, security, and fraud-prevention obligations.

We will not use your personal information for a new purpose materially different from these without notifying you and, where required, obtaining your consent.

4. What data we collect

When you use the Service, we collect and store:

  • Account/profile information: your name, email address, and the practice-identifying details you enter during setup, provider ID, group billing number, group code, practice/group name, FHO+ transition date, and your Hard Cap / Special Premium configuration ("Profile Data").
  • RA upload data: a redacted copy of each Remittance Advice (RA) .txt file you upload ("Redacted RA Data"), and the structured billing figures our parser extracts from it, payment amounts, FFS premiums, roster/demographic counts, cap usage, and similar line items ("Parsed Billing Data"). Your RA is parsed and de-identified locally in your browser; the full file is never transmitted to or stored on our servers. The health card numbers, patient names, version codes and EMR accounting references it contains are removed on your device and never reach us. The de-identified per-claim lines that remain (service date, fee code, units, amounts, ministry reason code and ministry claim reference) are stored as part of Redacted RA Data, and are what the hours reconciliation is built on (see Section 2).
  • Hours Log Data: if you use the FHO+ Hours Tracker, the after-hours and hourly-code time you record (for example, Q310 to Q313 entries), the dates you log, and any short activity notes you add ("Hours Log Data"). The Hours Tracker works without an account. By default this information is stored only on your own device, in your browser's local storage, and is not transmitted to us. It is sent to and stored on our servers only if you choose to sign in to back up your log and sync it across your devices, at which point we store and protect it in the same way as your other data (Section 6).
  • Subscription/billing information: your subscription tier and status (free / active / cancelled, etc.) and renewal dates. We do not collect or store your payment card details, those are handled entirely by Stripe, our payment processor (see Section 8).
  • Basic technical data: standard web server/application logs (e.g., timestamps, IP address, error messages, and similar request metadata) generated by our hosting providers in the course of operating and securing the Service.

Redacted RA Data and Parsed Billing Data are, by their nature, identifiable financial information about your medical practice. We treat both as sensitive and handle them accordingly throughout this policy.

5. Consent

  • How we obtain consent. By creating an account and uploading RA files, you consent to the collection, use, and disclosure of your personal information for the purposes described in Section 3. For the optional peer-benchmarking feature, we rely on express opt-in consent (Section 7). Given the sensitivity of billing data, we treat your consent as informed and meaningful, and we do not make consent to non-essential uses a condition of using the core Service.
  • Withdrawing consent. You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent for essential processing may mean we can no longer provide the Service, in which case you may delete your account (Section 10). You can withdraw consent for peer benchmarking at any time without affecting the rest of the Service.

6. How your data is stored and protected (Safeguards)

  • Location and encryption. All Profile Data, Redacted RA Data, Parsed Billing Data, and any Hours Log Data you have chosen to sync are stored in a Postgres database hosted by Supabase in the Canada (Central) region (Montreal). Data is encrypted at rest (AES-256) and in transit (TLS).
  • Access controls. The database enforces Row-Level Security (RLS) so that every query is restricted to rows matching your own account, for every table that holds Profile Data, Redacted RA Data, Parsed Billing Data, and synced Hours Log Data. Administrative access is limited to what is necessary to operate the Service (see Section 9).
  • Redacted RA Data retention. The de-identified copy of an uploaded RA is retained for 12 months from upload, after which it is automatically deleted, while the parsed figures derived from it (Parsed Billing Data) are retained for as long as your account is active. This balances being able to re-process an RA if we improve our parser against not holding billing text indefinitely. The full, unredacted RA file is never stored.
  • Claim-line retention. The de-identified per-claim lines described in Section 2 are retained for as long as your account is active, because the reconciliation they support is a year-over-year view and older service dates stay relevant to it. They are deleted when you delete your account, and when you delete that RA month from the Upload page. One consequence worth stating: after 12 months we still hold these claim lines but no longer hold the RA text they were derived from, so they cannot be rebuilt from our copy after that point. If you would rather not have claim-level detail stored at all, upload the summary export from your billing software instead of the MCEDT download, which has no claim layer in it.
  • No sale or marketing disclosure. We do not sell, rent, or trade your Profile Data, Redacted RA Data, or Parsed Billing Data, and we do not disclose it to any third party for marketing. The only disclosures we make are those described in Section 8 (service providers acting on our behalf), Section 9 (limited access circumstances), and where required by law.

7. Aggregated / anonymized data for peer benchmarking

A planned feature ("peer benchmarking") will show you how your numbers (e.g., FFS premium rate, overhead %, Q-cap utilization, cost-of-care) compare to an anonymized average across other physicians using the Service.

  • Opt-in only. Your individual data is included in these aggregates only if you explicitly turn on a "benchmarking participation" setting in your account. The default is off.
  • Aggregation safeguards. Aggregate statistics are only computed and shown once enough participating physicians' data is available that no individual's figures can reasonably be identified from the aggregate (a minimum participant-count threshold). Your own data is never shown to other users individually, in any form.
  • Withdrawing consent. You can turn off benchmarking participation at any time; this stops your data from being included in future aggregate calculations. Because aggregate statistics are computed across many users and not stored per-contributor, we cannot retroactively "remove" your past contribution to an already-computed historical aggregate, but no individually identifying record of your contribution is kept in the first place.

8. Service providers (sub-processors) and cross-border processing

We use the following third-party service providers to operate FHO+ RADAR. Each processes a limited subset of data, under their own privacy and security terms, and is permitted to use it only to provide services to us:

ProviderWhat it handlesData location / notes
SupabaseDatabase (all Profile/RA/Billing data, plus any synced Hours Log Data), authenticationStored in the Canada (Central) region (Montreal)
StripePayment processing, subscription billingWe never see or store your card details; Stripe may process billing data outside Canada (incl. the United States)
VercelApplication hosting (frontend + serverless functions)Processes requests in transit; does not persist physician billing data; processing may occur outside Canada

Cross-border processing. Your stored billing data resides in Canada. However, some providers (notably Stripe and Vercel) may process certain data, such as payment/subscription details or in-transit requests, on servers located outside Canada, including in the United States. While data is in another country, it may be accessible to that country's courts, law-enforcement, and national-security authorities under that country's laws. Under PIPEDA, the operator remains accountable for your information and uses contractual and technical measures to require a comparable level of protection wherever it is processed. If you would like more detail about our service providers' handling of your data, contact us (Section 1).

9. Who can access your data

  • You can access your own data through the Service, and only your own (enforced by the RLS controls described in Section 6).
  • We (the operator) do not access individual users' Redacted RA Data or Parsed Billing Data as part of normal operation. The only circumstances in which we would access it are:
    • Troubleshooting a reported problem at your request (e.g., "my numbers look wrong for March"), and only the specific data needed to diagnose that issue.
    • Parser failures: if your upload fails to parse, a generic error is logged for us to debug (which RA and which section/field couldn't be read) so we can fix the parser, you'll only ever see a generic, non-technical message, never the raw error.
    • Legal obligation: if required to by law (e.g., a valid court order, subpoena, or other lawful demand). Where permitted, we will limit any such disclosure to what is legally required.
  • A small number of administrative operations (e.g., subscription status updates from Stripe webhooks) are performed by automated server-side processes using elevated database access, but these processes only update subscription-related fields, they do not read or expose Redacted RA Data or Parsed Billing Data.

10. Data retention and what happens if you cancel

  • While your account is active: Profile Data and Parsed Billing Data are retained so the dashboard continues to work; Redacted RA Data is retained per the 12-month policy in Section 6.
  • If you cancel your subscription (downgrade to free tier): your account and historical data remain intact, cancelling stops billing and access to paid features; it does not delete your data. You can keep using the free tier or delete your account entirely (below).
  • If you delete your account: all Profile Data, Redacted RA Data, and Parsed Billing Data associated with your account are permanently deleted, except for the minimum records we are required to keep by law (e.g., tax or transaction records held by our payment processor) and routine backups, which are deleted on their normal rotation cycle. (If you previously opted into benchmarking, see Section 7 regarding aggregate data that was already computed.)
  • Hours Log Data: if you have not signed in, your Hours Log Data stays only on your device and is never held by us; you can remove it by clearing your browser storage or uninstalling the tracker. If you have signed in to sync it, it is retained while your account is active and permanently deleted when you delete your account, on the same basis as the data above.
  • Data export / portability: you can request an export of your own Parsed Billing Data (e.g., as JSON or CSV) at any time, useful if you're cancelling and want to keep your history, or simply to verify what we hold.

11. Accuracy

We rely on the Profile Data and configuration you provide. You can review and update your profile and configuration at any time through the Service, and we encourage you to keep it accurate so the figures the dashboard derives remain correct. See also the accuracy disclaimer in Terms of Service Section 3.

12. Security-breach notification

We maintain safeguards designed to prevent unauthorized access to your data. If a breach of those safeguards occurs that creates a real risk of significant harm to you, we will, as required by PIPEDA: notify you as soon as feasible; report the breach to the Office of the Privacy Commissioner of Canada; notify any other organization or institution that may help reduce the risk of harm; and keep a record of the breach. Our notice will describe what happened, the information involved, what we are doing about it, and steps you can take to protect yourself.

13. Cookies and analytics

The Service uses cookies and similar technologies that are strictly necessary to operate it, primarily the session cookies set by Supabase Auth to keep you securely logged in. These are required for the Service to function and cannot be switched off without disabling login. We do not use advertising or cross-site tracking cookies. If we introduce optional analytics in the future, we will update this section to describe what is collected and offer an opt-out where required.

14. Children's privacy

The Service is intended for licensed physicians and is not directed at, or intended for use by, children. We do not knowingly collect data from minors.

15. Your rights and how to exercise them

Under PIPEDA you have the right to:

  • Access the personal information we hold about you and be told how it has been used and to whom it has been disclosed;
  • Correct information that is inaccurate or incomplete;
  • Withdraw consent (subject to Section 5) and request deletion of your account and data; and
  • Request a copy of your data in a portable format (Section 10).

To exercise any of these rights, contact us through the form referenced in Section 1. We may need to verify your identity before acting on a request. We will respond within the time required by law (generally within 30 days for access requests).

Complaints. If you have a concern about how we handle your personal information, please contact us first so we can try to resolve it. You also have the right to complain to the Office of the Privacy Commissioner of Canada (www.priv.gc.ca · 1-800-282-1376).

16. Changes to this policy

We may update this policy from time to time. Material changes will be communicated to active users (e.g., by email or an in-app notice) before they take effect. The "Last updated" date above reflects the current version.


Part 2, Terms of Service

1. Acceptance of terms

By creating an account and using FHO+ RADAR (the "Service"), you agree to these Terms of Service and the Privacy Policy above.

2. Description of the Service

FHO+ RADAR is an informational dashboard that ingests your Ontario FHO+ Remittance Advice (RA) data and presents derived figures, payment stream breakdowns, FFS trends, Hard Cap/CoC tracking, flags, forecasts, and (where enabled) anonymized peer benchmarking, to help you understand your billing.

3. Accuracy disclaimer, important

FHO+ RADAR is provided for informational purposes only. It is not a substitute for your official Ministry of Health Remittance Advice, your FHO's records, or professional billing/accounting advice.

While we aim for accuracy, the Service relies on automated parsing of RA files and on configuration you provide (e.g., Hard Cap thresholds, FHO+ transition date). Parsing errors, RA format changes, or configuration mistakes can produce incorrect figures. Always verify any figure shown in the Service against your own official RA before relying on it, and consult a qualified billing professional or accountant before making any financial decision based on information from this Service.

To the maximum extent permitted by law, the operator disclaims liability for any financial loss or decision made in reliance on figures, forecasts, or comparisons presented by the Service.

4. Accounts and eligibility

  • You must provide accurate information when creating your account and keep your login credentials confidential.
  • The Service is intended for use by the physician whose billing data is being analyzed, or someone they've authorized to manage their account (e.g., an office administrator), you're responsible for activity on your account.

5. Subscriptions and billing

  • The Service offers a free tier and a paid tier (monthly/annual), as described at signup. Paid subscriptions are billed via Stripe and renew automatically until cancelled.
  • You can cancel at any time via the account/billing page; cancellation takes effect at the end of the current billing period, after which your account reverts to the free tier (see Privacy Policy Section 10 for what happens to your data).
  • Refunds. Except where required by applicable consumer-protection law, subscription fees are non-refundable, and cancelling stops future renewals rather than refunding the current period. Any refund we do provide is at our discretion and processed through Stripe.

6. Acceptable use

You agree not to:

  • Upload RA data that does not belong to you or that you are not authorized to process (e.g., another physician's RA, except with that physician's explicit permission, such as during invited beta testing).
  • Upload any file other than your own RA that contains identifiable patient health information (e.g., chart notes, patient lists, or claim-level exports from your EMR). Your own RA files are handled safely by design: they are parsed in your browser and only a redacted copy, with per-patient claim detail and health card numbers removed, is ever stored (see Privacy Policy Section 2).
  • Attempt to access another user's data, circumvent access controls, or interfere with the Service's operation or security.
  • Use the Service for any unlawful purpose.

7. Intellectual property

The Service, including its design, dashboards, and underlying software, is the property of the operator. You retain ownership of the RA data you upload and the figures derived from it for your own account.

8. Termination

We may suspend or terminate accounts that violate these Terms. You may delete your account at any time (Privacy Policy Section 10).

9. Limitation of liability

To the maximum extent permitted by law, the operator's total liability arising from your use of the Service is limited to the amount you paid for the Service in the 12 months preceding the claim. The Service is provided "as is" without warranties of any kind, express or implied, including fitness for a particular purpose. Nothing in these Terms limits liability that cannot be limited or excluded under applicable law.

10. Governing law

These Terms are governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein. You agree to the exclusive jurisdiction of the courts of Ontario for any dispute arising out of or relating to the Service, subject to any non-waivable rights you have under applicable consumer-protection law.

11. Changes to these Terms

We may update these Terms from time to time; continued use of the Service after changes take effect constitutes acceptance of the updated Terms.

12. Contact

Questions about these Terms can be sent through the in-app contact form, the "?" button at the bottom-left of your dashboard.