Who We Are
TaxSuite is operated by Amrin K Enterprises Ltd., a federally incorporated Canadian corporation (incorporated April 2019). Our registered office is located in Ottawa, Ontario, Canada.
TaxSuite (“we”, “us”, “our”) provides cloud-based bookkeeping and financial management software designed specifically for Canadian restaurant and food-service businesses. Our website is taxsuite.ca and our application is accessed at app.taxsuite.ca.
For privacy inquiries, contact our Privacy Officer at: privacy@taxsuite.ca
What We Collect
We collect different categories of information depending on how you interact with TaxSuite:
Account Information
- Full name and email address
- Password (stored as a cryptographic hash — we never store plaintext passwords)
- Business name, type, and location(s)
- CRA Business Number (if provided for HST filing features)
- Province of operation (affects HST/GST rates)
- Profile photo (optional)
Financial & Business Data
- Transaction records (revenue, expenses, payroll)
- POS sync data from Clover, Square, Toast, and Lightspeed
- Delivery platform payouts (Uber Eats, Skip the Dishes, DoorDash)
- Supplier invoice data (uploaded PDFs, CSV imports)
- Receipts uploaded for AI extraction
- HST/GST filing periods and calculated amounts
- Food cost percentages and inventory notes
Payment Information
- Billing name and address
- Payment method details — processed and stored by Stripe. We never store raw card numbers.
- Subscription plan, billing cycle, and payment history
Third-Party Authentication
- When you sign in with Google or GitHub, we receive your name, email address, and profile picture from that provider. We do not receive your password.
Usage & Technical Data
- IP address and approximate geographic location
- Browser type, operating system, and device type
- Pages visited, features used, and session duration
- Error logs and crash reports
- Cookies and similar tracking technologies (see Section 9)
We do not collect or store Social Insurance Numbers (SINs), personal CRA login credentials, or banking credentials beyond what Stripe requires for billing.
How We Use Your Information
We use your information only for the following purposes:
- Providing the service: Operating your account, syncing POS data, generating reports, calculating HST/GST, and all core TaxSuite functionality.
- AI receipt extraction: Uploaded receipt images are processed by OpenAI's API to extract vendor names, amounts, and categories. Extracted data is stored in your account. Raw image files are retained for 90 days, then permanently deleted.
- Billing and payments: Processing subscription charges, issuing invoices, and handling refund requests through Stripe.
- Account communications: Password reset emails, subscription renewal notices, important security alerts, and product updates. We do not send unsolicited marketing without your consent.
- Customer support: Diagnosing issues, responding to requests, and improving product quality.
- Security: Detecting and preventing fraud, unauthorized access, and abuse.
- Legal compliance: Meeting obligations under Canadian law, including PIPEDA and CRA reporting requirements where applicable.
- Product improvement: Aggregated, anonymized analytics to understand how features are used and where the product can improve. No individual transaction data is used for this purpose.
We do not sell, rent, or trade your personal or financial information to any third party for marketing, advertising, or commercial purposes.
Legal Basis (PIPEDA)
TaxSuite is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal private-sector privacy law, as well as applicable provincial privacy legislation.
We collect, use, and disclose personal information only with your knowledge and consent, except where the law permits or requires otherwise. Specifically:
- Account creation constitutes your consent to collect and use your information as described in this policy.
- Connecting a POS system or delivery platform constitutes your consent to receive and store data from that integration.
- Uploading a receipt constitutes your consent to process that image through our AI extraction service.
- You may withdraw consent at any time by deleting your account, subject to legal retention requirements.
Under PIPEDA's accountability principle, Amrin K Enterprises Ltd. is responsible for all personal information under our control, including information transferred to third-party processors.
Data Sharing & Third Parties
We share your information only in the following limited circumstances:
| Service Provider | Purpose | Data Shared |
|---|---|---|
| Stripe (USA) | Payment processing and subscription management | Billing name, email, payment card (tokenized) |
| Neon (USA) | PostgreSQL database hosting | All account and financial data (encrypted at rest) |
| Vercel (USA) | Application hosting and CDN | Web traffic, IP addresses (server logs) |
| OpenAI (USA) | AI receipt text extraction | Receipt image content only — no identifying info |
| Google (USA) | Optional OAuth sign-in | Name and email (only if you use Google sign-in) |
| GitHub (USA) | Optional OAuth sign-in | Name and email (only if you use GitHub sign-in) |
| Resend (USA) | Transactional email delivery | Your email address and email content |
All third-party processors are bound by data processing agreements and are required to protect your information in accordance with PIPEDA standards. We do not authorize any processor to use your data for their own purposes.
We may also disclose information: (a) to comply with a legal obligation, court order, or government authority request; (b) to protect the rights, property, or safety of TaxSuite, our users, or the public; or (c) in connection with a business transfer or acquisition, in which case the successor entity will be bound by this Privacy Policy.
Data Storage & Security
Your data is stored in encrypted PostgreSQL databases hosted by Neon. All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Our application is hosted on Vercel with Canadian-compatible data routing.
We implement the following security controls:
- Passwords hashed using bcrypt with a minimum work factor of 12
- All API endpoints require authentication via secure session tokens
- Row-level security to ensure users can only access their own organization's data
- Rate limiting on all authentication endpoints to prevent brute-force attacks
- Regular automated dependency scanning for known vulnerabilities
- HTTPS enforced across all domains with HSTS preloading
- Uploaded files stored in access-controlled Vercel Blob storage
- Stripe tokenization — we never receive or store raw card numbers
No system is 100% secure. If you suspect unauthorized access to your account, contact us immediately at security@taxsuite.ca. Under PIPEDA, we are required to notify you and the Office of the Privacy Commissioner of Canada if a breach creates a real risk of significant harm.
Data Retention
We retain your information as follows:
| Data Category | Retention Period |
|---|---|
| Active account data | Duration of your subscription + 90 days after cancellation |
| Financial transaction records | 7 years from the transaction date (CRA record-keeping requirements) |
| HST/GST filing records | 7 years from the filing date |
| Receipt images (raw) | 90 days from upload, then permanently deleted |
| AI extraction results | Retained as part of your transaction record (up to 7 years) |
| Usage logs / analytics | 90 days (rolling) |
| Security/access logs | 12 months |
| Billing records | 7 years (Canada Revenue Agency requirements) |
| Deleted account data | 30-day grace period, then permanently purged |
Financial records are retained for 7 years to comply with CRA's record-keeping requirements under the Income Tax Act and the Excise Tax Act, even after account deletion.
Your Privacy Rights
Under PIPEDA and applicable Canadian privacy law, you have the following rights regarding your personal information:
Right of Access
Request a copy of the personal information we hold about you. We will respond within 30 days.
Right to Correction
Request correction of inaccurate or incomplete personal information. You can update most information directly in Settings.
Right to Deletion
Request deletion of your account and personal data, subject to legal retention requirements (e.g., financial records must be kept 7 years).
Right to Data Portability
Export your financial data as CSV or PDF at any time from within your account — no request needed.
Right to Withdraw Consent
Withdraw consent to any non-essential processing at any time. Withdrawing consent to essential processing (e.g., storing your transactions) means you cannot use the service.
Right to Complain
File a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca if you believe we have not respected your privacy rights.
To exercise any right, email privacy@taxsuite.ca with your full name, account email address, and a description of your request. We will verify your identity before processing the request.
Children's Privacy
TaxSuite is a business software product intended for use by adults operating commercial food-service businesses. We do not knowingly collect personal information from individuals under the age of 18.
If we become aware that a person under 18 has created an account, we will promptly delete the account and all associated data. If you believe a minor has registered, contact us at privacy@taxsuite.ca.
Cross-Border Transfers
Some of our third-party service providers (including Stripe, Neon, Vercel, OpenAI, and Resend) are based in the United States. When we transfer your personal information to these providers, we do so under data processing agreements that require them to protect your information to a standard comparable to PIPEDA.
By creating an account and using TaxSuite, you consent to the transfer of your information to these U.S.-based processors as described in Section 5. You acknowledge that U.S. law may apply different standards to government access to personal data than Canadian law.
Your financial transaction data, account credentials, and core business data are stored in Neon's database infrastructure. We have contractually required that your data not be used for any purpose other than providing TaxSuite functionality.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will notify you of material changes by:
- Sending an email to your registered account address at least 14 days before the change takes effect
- Posting a prominent notice in the TaxSuite application
- Updating the 'Last updated' date at the top of this page
Continued use of TaxSuite after the effective date of a revised policy constitutes your acceptance of the changes. If you do not agree with the revised policy, you may delete your account before the effective date.
Contact & Complaints
For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy Officer:
Privacy Officer — TaxSuite
Amrin K Enterprises Ltd.
Ottawa, Ontario, Canada
Email: privacy@taxsuite.ca
Response time: within 30 days of receipt
If you are unsatisfied with our response to a privacy concern, you have the right to contact the Office of the Privacy Commissioner of Canada (OPC):
Office of the Privacy Commissioner of Canada
30 Victoria Street, Gatineau, Quebec K1A 1H3
Toll-free: 1-800-282-1376
Website: priv.gc.ca
Questions? Email support@taxsuite.ca