What a business can and cannot see
What a business can and cannot see
If a realtor, broker, or lawyer asked you to use my-id.ca, the reasonable first question is what they get to look at. Here is the boundary, precisely.
What they can see
Exactly two things.
- What you send in response to their request. They ask for specific documents or details; you approve; those go to them.
- What you attach in a conversation with them. A file you put in the chat is a file you sent.
That is the complete list. Both are actions you take deliberately.
What they cannot see
- Your profile. There is no view of it available to them. Not your address, not your identifiers, not your employment history — beyond whatever you sent in response to a request.
- Your Files. Uploads you have not sent are not visible.
- Your Documents. Anything you filled and did not send.
- Your Notes. Private to you, always.
- Your Calendar and Life Line.
- Your searches and your conversations with the AI assistant.
- Anything you shared with a different business. Shares are scoped to the recipient. There is no cross-business view.
- Your other accounts, family members, or documents about them — unless a specific one was part of what you sent.
Being connected is not access
This is the part worth internalising. A business appearing in your account — a request from them, a conversation with them — grants them nothing. It creates a channel. Data only moves along it when you send something.
The same is true in reverse: you cannot see their client list, their other clients, or their internal notes about you.
What is recorded
Every transfer is logged in Sharing history with the form name, the business, their contact details, the date, and a link to the document. That log is for your benefit — it is how you answer "did I already send that?" months later.
Guest links
If you are using a guest link rather than an account, the same boundary applies and is tighter still: the link is scoped to that one business and that one relationship, and it expires. See A guest link from a business.
Practical advice
- Send through the request flow, not chat. Both work, but the request flow is tracked, versioned, and appears in your sharing history. Chat attachments are harder to account for later.
- Do not paste identifiers into chat messages. A SIN typed into a conversation is a copy sitting in a thread. Send it as part of a request instead.
- Check what a request is asking for before you approve it. The approval is the moment of decision. See When you receive a request.
- If a request seems excessive, ask why. A legitimate professional will have a reason. See When a request feels wrong.
Related
Frequently asked questions
- Can a business see my whole profile?
- No. There is no view of your profile available to them. They see the documents and values you send in response to a specific request.
- Can one business see what I shared with another?
- No. Shares are scoped to the business you sent them to. There is no cross-business visibility.
- Can they see that I read their message?
- In a conversation, yes — messages are marked read as you view them, the same as any chat. That is the extent of it.