Privacy Policy
Last updated: February 16, 2026
1. Overview
Mithril Law (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit mithril.law (the “Site”) or use our services.
We are subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
2. Information We Collect
Information You Provide
- Contact information: Name, email address, phone number when you submit a contact form or intake form.
- Legal matter details: Information about your legal issue submitted through intake forms.
- Account information: Email and authentication credentials when you create an account.
- Documents: Files you upload to your client portal.
- Payment information: Billing details processed by our third-party payment provider (Stripe). We do not store your credit card numbers.
Information Collected Automatically
- Usage data: Pages visited, time spent, referring URL, browser type, and device information.
- Cookies: We use essential cookies for authentication and optional analytics cookies (Google Analytics) with your consent.
- IP address: Used for rate limiting and security purposes. Not stored long-term.
3. How We Use Your Information
- To provide and manage legal services
- To communicate with you about your matter
- To process payments and generate invoices
- To operate self-service legal tools
- To improve the Site and our services
- To comply with legal and regulatory obligations
- To detect and prevent fraud or abuse
4. Solicitor-Client Privilege
Information shared with us in the context of a solicitor-client relationship is protected by solicitor-client privilege. This is the highest form of legal protection for communications and cannot be overridden except in very limited circumstances defined by law.
We will never voluntarily disclose privileged information without your consent, except as required by law or professional obligations.
5. Data Sharing
We do not sell your personal information. We may share information with:
- Service providers: Cloud hosting (Vercel, Supabase), payment processing (Stripe), email services (Resend) — only as necessary to provide our services.
- Legal requirements: If required by law, court order, or regulatory obligation.
- With your consent: When you explicitly authorize disclosure.
6. Data Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. Our database uses Row Level Security (RLS) policies to ensure data isolation between clients.
7. Data Retention
We retain client files and records for a minimum of ten (10) years after the matter is closed, in accordance with the Law Society of Ontario's record retention requirements. After this period, records are securely destroyed.
You may request deletion of your account and non-privileged personal information at any time by contacting us. Note that we may be required to retain certain information for legal and regulatory compliance.
8. Your Rights
Under applicable privacy law, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your information (subject to legal retention requirements)
- Withdraw consent for optional data processing (e.g., analytics cookies)
- File a complaint with the Office of the Privacy Commissioner of Canada
9. Cookies
We use essential cookies for authentication and session management. Analytics cookies (Google Analytics) are only set with your consent via our cookie banner. You can manage cookie preferences at any time through your browser settings or our cookie consent tool.
10. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. We encourage you to review this page periodically.
12. Contact Us
For privacy-related inquiries or to exercise your rights, contact our Privacy Officer at privacy@mithril.law or info@mithril.law.