TRUST CENTRE

Seneca OneCard

Last updated September 25, 2025

Seneca OneCard

Privacy Policy of the Seneca OneCard App

We are committed to ensuring digital accessibility for people with disabilities. We are continually improving the user experience for everyone, and applying the relevant accessibility standards.

Measures to support accessibility

ITC Systems takes the following measures to ensure accessibility of netZcore Purchase:

  • Include accessibility as part of our mission statement.
  • Integrate accessibility into our procurement practices.
  • Maintain an appointed accessibility officer.
  • Provide continual accessibility training for our staff.
  • Consider individuals with disabilities in our design process.

Conformance status

The Web Content Accessibility Guidelines (WCAG) defines requirements for designers and developers to improve accessibility for people with disabilities. It defines three levels of conformance: Level A, Level AA, and Level AAA. Citylights WebStore is partially conformant with WCAG 2.1 level AA. Partially conformant means that some parts of the content do not fully conform to the accessibility standard.

Additional accessibility considerations

Although our goal is WCAG 2.1 Level AA conformance, we have also applied some Level AAA Success Criteria: Images of text are only used for decorative purposes. Re-authentication after a session expires does not cause loss of data. Some videos have sign language interpretation.

Feedback

We welcome your feedback on the accessibility of netZcore Purchase. Please let us know if you encounter accessibility barriers with netZcore Purchase:

We try to respond to feedback within 5 business days.

AVRO Mobile Privacy

ITC Systems manages and maintains your institutions’ privilege credentialing system as a 3rd party Data Processor. As such, the main responsibility for data privacy compliance lies with your institution as the Data Controller. Therefore, your institution’s privacy statement governs the use of your personal information (instead of ours). Your institution determines what information we collect through our products and services and how it is used, and we process your information according to your institution’s instructions and the terms of our contracts with your institution.

Information we collect

Our products and services integrate with your institution’s systems. This provides us with your information to set up and maintain your profile and account that enables us to provide the product or service. This includes information in the following data categories:

  • Palm Biometrics: ITC Systems offers a palm vein biometric solution (AVRO Palm) that replaces or is associated with an existing physical credential. AVRO Palm is designed to be anonymous in that your palm biometric is associated only with the access card credential used at the time of enrollment and, when used, scans your palm and outputs only the associated credential number registered at the time of enrollment. The AVRO Palm database is independent, does not contain any personal identifiable information (PII), and does not share data with or interface to any other systems. AVRO Palm does not analyze your biometric data for secondary purposes or share any data external to the service. Retained biometric data is revoked either on a set calendar date or on a real time revocation request from the credential issuer as defined by them.
  • Credentials: Our products and services often integrate with your institution’s systems and rely on the credentials your institution uses. Where this is not the case, we will collect passwords, password hints, and similar security information that we use for authentication and account access.
  • Payment data: We collect data necessary to process your payments within our system, usage of our services including purchases on your institution’s credential, plans, attendance, and events. We collect payment history for your reference and made available to you. We do not store any credit card details.
  • Support: When you or your institution contacts us for support, we may collect limited information about you that you or a representative of your institution provides to us. We use this information only to assist with client support cases on behalf of your institution. When you contact us, your phone conversations or chat sessions with our client support teams may be monitored and recorded for training and quality purposes.

Indirectly from you

We collect information on how you use our products and services. Depending on which product or service you use, this may include the following data categories:

  • Location and events data: For some of our products and services, such as access cards and attendance, we will collect information about which premises and events you have visited and attended on behalf of your institution, as well as the time and date of such visits. Additionally, we may collect precise geolocation data when you use the mobile apps for some of our products. You will be asked if you want to enable location data before we collect such information from your device.
  • Device and usage: We collect device and usage information when you access and use our products and services, including information that your browser or the mobile app sends when you are using it. This data may include your unique device identifier, Internet Protocol address, your browser type and configuration, the date and time of your use of the product or service, language preferences, and cookie data.

How we use this information

On behalf of your institution, we use your information under the instruction of your institution, which is the data controller. We use the information in accordance with our agreement with your institution to operate, maintain, and provide the features and functionality of the products and services. Your institution determines how your information is used.