TaxSuiteStart free

Legal

Privacy Policy

TaxSuite is committed to protecting the privacy and security of your personal and financial information. This policy explains our practices in plain language.

Last updated: April 23, 2026

1

Who We Are

TaxSuite is operated by Amrin K Enterprises Ltd., a federally incorporated Canadian corporation (incorporated April 2019). Our registered office is located in Ottawa, Ontario, Canada.

TaxSuite (“we”, “us”, “our”) provides cloud-based bookkeeping and financial management software designed specifically for Canadian restaurant and food-service businesses. Our website is taxsuite.ca and our application is accessed at app.taxsuite.ca.

For privacy inquiries, contact our Privacy Officer at: privacy@taxsuite.ca

2

What We Collect

We collect different categories of information depending on how you interact with TaxSuite:

Account Information

  • Full name and email address
  • Password (stored as a cryptographic hash — we never store plaintext passwords)
  • Business name, type, and location(s)
  • CRA Business Number (if provided for HST filing features)
  • Province of operation (affects HST/GST rates)
  • Profile photo (optional)

Financial & Business Data

  • Transaction records (revenue, expenses, payroll)
  • POS sync data from Clover, Square, Toast, and Lightspeed
  • Delivery platform payouts (Uber Eats, Skip the Dishes, DoorDash)
  • Supplier invoice data (uploaded PDFs, CSV imports)
  • Receipts uploaded for AI extraction
  • HST/GST filing periods and calculated amounts
  • Food cost percentages and inventory notes

Payment Information

  • Billing name and address
  • Payment method details — processed and stored by Stripe. We never store raw card numbers.
  • Subscription plan, billing cycle, and payment history

Third-Party Authentication

  • When you sign in with Google or GitHub, we receive your name, email address, and profile picture from that provider. We do not receive your password.

Usage & Technical Data

  • IP address and approximate geographic location
  • Browser type, operating system, and device type
  • Pages visited, features used, and session duration
  • Error logs and crash reports
  • Cookies and similar tracking technologies (see Section 9)

We do not collect or store Social Insurance Numbers (SINs), personal CRA login credentials, or banking credentials beyond what Stripe requires for billing.

3

How We Use Your Information

We use your information only for the following purposes:

  • Providing the service: Operating your account, syncing POS data, generating reports, calculating HST/GST, and all core TaxSuite functionality.
  • AI receipt extraction: Uploaded receipt images are processed by OpenAI's API to extract vendor names, amounts, and categories. Extracted data is stored in your account. Raw image files are retained for 90 days, then permanently deleted.
  • Billing and payments: Processing subscription charges, issuing invoices, and handling refund requests through Stripe.
  • Account communications: Password reset emails, subscription renewal notices, important security alerts, and product updates. We do not send unsolicited marketing without your consent.
  • Customer support: Diagnosing issues, responding to requests, and improving product quality.
  • Security: Detecting and preventing fraud, unauthorized access, and abuse.
  • Legal compliance: Meeting obligations under Canadian law, including PIPEDA and CRA reporting requirements where applicable.
  • Product improvement: Aggregated, anonymized analytics to understand how features are used and where the product can improve. No individual transaction data is used for this purpose.

We do not sell, rent, or trade your personal or financial information to any third party for marketing, advertising, or commercial purposes.

5

Data Sharing & Third Parties

We share your information only in the following limited circumstances:

Service ProviderPurposeData Shared
Stripe (USA)Payment processing and subscription managementBilling name, email, payment card (tokenized)
Neon (USA)PostgreSQL database hostingAll account and financial data (encrypted at rest)
Vercel (USA)Application hosting and CDNWeb traffic, IP addresses (server logs)
OpenAI (USA)AI receipt text extractionReceipt image content only — no identifying info
Google (USA)Optional OAuth sign-inName and email (only if you use Google sign-in)
GitHub (USA)Optional OAuth sign-inName and email (only if you use GitHub sign-in)
Resend (USA)Transactional email deliveryYour email address and email content

All third-party processors are bound by data processing agreements and are required to protect your information in accordance with PIPEDA standards. We do not authorize any processor to use your data for their own purposes.

We may also disclose information: (a) to comply with a legal obligation, court order, or government authority request; (b) to protect the rights, property, or safety of TaxSuite, our users, or the public; or (c) in connection with a business transfer or acquisition, in which case the successor entity will be bound by this Privacy Policy.

6

Data Storage & Security

Your data is stored in encrypted PostgreSQL databases hosted by Neon. All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Our application is hosted on Vercel with Canadian-compatible data routing.

We implement the following security controls:

  • Passwords hashed using bcrypt with a minimum work factor of 12
  • All API endpoints require authentication via secure session tokens
  • Row-level security to ensure users can only access their own organization's data
  • Rate limiting on all authentication endpoints to prevent brute-force attacks
  • Regular automated dependency scanning for known vulnerabilities
  • HTTPS enforced across all domains with HSTS preloading
  • Uploaded files stored in access-controlled Vercel Blob storage
  • Stripe tokenization — we never receive or store raw card numbers

No system is 100% secure. If you suspect unauthorized access to your account, contact us immediately at security@taxsuite.ca. Under PIPEDA, we are required to notify you and the Office of the Privacy Commissioner of Canada if a breach creates a real risk of significant harm.

7

Data Retention

We retain your information as follows:

Data CategoryRetention Period
Active account dataDuration of your subscription + 90 days after cancellation
Financial transaction records7 years from the transaction date (CRA record-keeping requirements)
HST/GST filing records7 years from the filing date
Receipt images (raw)90 days from upload, then permanently deleted
AI extraction resultsRetained as part of your transaction record (up to 7 years)
Usage logs / analytics90 days (rolling)
Security/access logs12 months
Billing records7 years (Canada Revenue Agency requirements)
Deleted account data30-day grace period, then permanently purged

Financial records are retained for 7 years to comply with CRA's record-keeping requirements under the Income Tax Act and the Excise Tax Act, even after account deletion.

8

Your Privacy Rights

Under PIPEDA and applicable Canadian privacy law, you have the following rights regarding your personal information:

  • Right of Access

    Request a copy of the personal information we hold about you. We will respond within 30 days.

  • Right to Correction

    Request correction of inaccurate or incomplete personal information. You can update most information directly in Settings.

  • Right to Deletion

    Request deletion of your account and personal data, subject to legal retention requirements (e.g., financial records must be kept 7 years).

  • Right to Data Portability

    Export your financial data as CSV or PDF at any time from within your account — no request needed.

  • Right to Withdraw Consent

    Withdraw consent to any non-essential processing at any time. Withdrawing consent to essential processing (e.g., storing your transactions) means you cannot use the service.

  • Right to Complain

    File a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca if you believe we have not respected your privacy rights.

To exercise any right, email privacy@taxsuite.ca with your full name, account email address, and a description of your request. We will verify your identity before processing the request.

9

Cookies & Tracking

TaxSuite uses cookies and similar technologies to operate the service and improve your experience. See our Cookie Policy for full details.

In summary, we use:

  • Session cookies: Keep you logged in during your browser session. Essential — cannot be disabled.
  • Authentication cookies: Persistent login tokens (up to 30 days). Set when you check 'Remember me'.
  • CSRF tokens: Protect against cross-site request forgery. Essential.
  • Analytics cookies: Anonymous usage data to understand feature adoption. You can opt out in Settings.

We do not use advertising, retargeting, or third-party tracking cookies.

10

Children's Privacy

TaxSuite is a business software product intended for use by adults operating commercial food-service businesses. We do not knowingly collect personal information from individuals under the age of 18.

If we become aware that a person under 18 has created an account, we will promptly delete the account and all associated data. If you believe a minor has registered, contact us at privacy@taxsuite.ca.

11

Cross-Border Transfers

Some of our third-party service providers (including Stripe, Neon, Vercel, OpenAI, and Resend) are based in the United States. When we transfer your personal information to these providers, we do so under data processing agreements that require them to protect your information to a standard comparable to PIPEDA.

By creating an account and using TaxSuite, you consent to the transfer of your information to these U.S.-based processors as described in Section 5. You acknowledge that U.S. law may apply different standards to government access to personal data than Canadian law.

Your financial transaction data, account credentials, and core business data are stored in Neon's database infrastructure. We have contractually required that your data not be used for any purpose other than providing TaxSuite functionality.

12

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will notify you of material changes by:

  • Sending an email to your registered account address at least 14 days before the change takes effect
  • Posting a prominent notice in the TaxSuite application
  • Updating the 'Last updated' date at the top of this page

Continued use of TaxSuite after the effective date of a revised policy constitutes your acceptance of the changes. If you do not agree with the revised policy, you may delete your account before the effective date.

13

Contact & Complaints

For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy Officer:

Privacy Officer — TaxSuite

Amrin K Enterprises Ltd.

Ottawa, Ontario, Canada

Email: privacy@taxsuite.ca

Response time: within 30 days of receipt

If you are unsatisfied with our response to a privacy concern, you have the right to contact the Office of the Privacy Commissioner of Canada (OPC):

Office of the Privacy Commissioner of Canada

30 Victoria Street, Gatineau, Quebec K1A 1H3

Toll-free: 1-800-282-1376

Website: priv.gc.ca