Opes Ledger
← Back to App

Privacy Policy

Last Updated: July 16, 2026

Opes Ledger ("we," "us," "our") operates the personal finance application available at opesledger.ca (the "Service"). We are committed to protecting your privacy and handling your personal information responsibly and transparently. This Privacy Policy explains what information we collect, how we use it, how we protect it, and what rights you have regarding your data.

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described here, please do not use the Service.

Our Core Promise: We do not sell, rent, or trade your personal or financial data to any third party. Your data belongs to you.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

1.2 Financial Data You Provide

As part of normal use of the Service, you may enter:

All of this data is entered voluntarily by you. We do not connect to your bank accounts, credit cards, or any external financial institution to pull data automatically.

1.3 Usage Data

We automatically collect limited technical data when you use the Service:

1.4 Information We Do Not Collect

We do not collect or store:

2. How We Use Your Information

We use the information we collect for the following purposes:

Purpose Data Used
Providing and operating the Service Account info, financial data
Authenticating your identity and securing your account Email, hashed password, IP address
Generating reports and exports (e.g., Accountant Report) Financial data you provide
Processing subscription payments Email, subscription tier (payment details handled by Stripe)
Communicating service updates, security alerts, or billing notices Email, name
Improving the Service through aggregate, anonymized analytics Usage data (never individual financial data)
Complying with legal obligations As required by law

We do not use your financial data for profiling, advertising, credit scoring, or any purpose unrelated to providing you with the Service.

3. How We Store and Protect Your Data

3.1 Infrastructure

Your data is stored on Supabase, a cloud database platform built on PostgreSQL. Supabase provides enterprise-grade infrastructure with the following security measures:

3.2 Authentication Security

User authentication is managed through Supabase Auth. Passwords are hashed using industry-standard bcrypt hashing. We never store, log, or have access to your plaintext password.

3.3 Access Controls

Access to production infrastructure is restricted to authorized personnel only, secured with multi-factor authentication, and logged for audit purposes.

4. Cookies and Local Storage

4.1 Cookies

We use a minimal number of cookies strictly necessary for the operation of the Service:

We do not use advertising cookies, tracking cookies, or any third-party cookies for marketing purposes.

4.2 Local Storage (localStorage)

The application may use your browser's localStorage to:

Financial data may be temporarily cached in localStorage to enable faster loading and offline functionality. This cache is automatically cleared when you log out. The authoritative copy of your data always resides in our secured database. We recommend logging out when using shared or public devices.

5. Third-Party Services

We use a limited number of third-party services to operate the Service. Each is bound by its own privacy and security obligations:

Service Purpose Data Shared
Supabase Database hosting, authentication, backend infrastructure All account and financial data (encrypted)
Stripe Payment processing for subscriptions Email, subscription tier; Stripe handles all payment card data directly and we never see or store your card number
Vercel Application hosting and serverless API infrastructure API requests pass through Vercel's network; no financial data is stored on Vercel's servers
Infrastructure Security Certifications: Our service providers maintain industry-recognized security standards. Supabase and Vercel are SOC 2 Type II certified, and Stripe is PCI DSS Level 1 certified (the highest level of payment security certification). These certifications are independently audited and require ongoing compliance with strict security controls covering data protection, access management, and incident response.

We do not share your data with any other third-party services, analytics platforms, advertisers, or data brokers.

6. Data Sharing and Disclosure

We do not sell, rent, lease, or trade your personal or financial information to any third party. We may disclose your information only in the following limited circumstances:

7. Your Rights

You have the following rights regarding your personal information:

7.1 Right to Access

You may request a complete copy of all personal and financial data we hold about you. We will provide this in a commonly used electronic format (such as CSV or JSON) within 30 days of your request.

7.2 Right to Export

You may export your data at any time through the application's built-in export functionality. The Accountant Report export feature provides a structured summary of your financial records.

7.3 Right to Correction

You may update or correct your personal and financial data at any time through the application. If you need assistance making corrections, contact us at privacy@opesledger.ca.

7.4 Right to Deletion

You may request the deletion of your account and all associated data at any time. Upon receiving a verified deletion request:

7.5 Right to Withdraw Consent

Where we rely on your consent to process your data, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

To exercise any of these rights, contact us at privacy@opesledger.ca. We will respond to all requests within 30 days.

8. Data Retention

We retain your data according to the following schedule:

9. Canadian Privacy Law Compliance (PIPEDA)

Opes Ledger complies with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. In accordance with PIPEDA, we adhere to the following ten fair information principles:

  1. Accountability: We are responsible for the personal information under our control and have designated a privacy officer to oversee compliance.
  2. Identifying Purposes: We identify the purposes for which personal information is collected at or before the time of collection, as outlined in this Privacy Policy.
  3. Consent: We obtain your express consent for the collection, use, and disclosure of sensitive personal information, including financial data such as mortgage balances, income, and debt conversion details. You provide this consent when you create an account and enter your financial information into the Service. You may withdraw your consent at any time by deleting your account or contacting our Privacy Officer.
  4. Limiting Collection: We limit the collection of personal information to that which is necessary for the purposes identified.
  5. Limiting Use, Disclosure, and Retention: We do not use or disclose personal information for purposes other than those for which it was collected, except with your consent or as required by law. We retain personal information only as long as necessary to fulfill those purposes.
  6. Accuracy: We keep personal information as accurate, complete, and up to date as necessary for the purposes for which it is used. You may update your information at any time through the application.
  7. Safeguards: We protect personal information with security safeguards appropriate to the sensitivity of the information, including encryption, access controls, and secure infrastructure.
  8. Openness: We make information about our policies and practices relating to the management of personal information readily available through this Privacy Policy.
  9. Individual Access: Upon request, we will inform you of the existence, use, and disclosure of your personal information and give you access to that information within 30 days.
  10. Challenging Compliance: You may challenge our compliance with this Privacy Policy by contacting our privacy officer at privacy@opesledger.ca. If you are not satisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada.

10. Provincial Privacy Laws

In addition to PIPEDA, Opes Ledger respects the privacy legislation of Canadian provinces with substantially similar private-sector privacy laws:

Because Opes Ledger uses cloud infrastructure that may process data outside of Canada, PIPEDA applies to all cross-border data transfers regardless of the client's province of residence.

Note: The Service is not currently available in Quebec. We will announce availability separately once our French-language Terms of Service and Privacy Policy are ready, in compliance with Quebec's language requirements under Law 25 and the Charter of the French Language.

11. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child under 18 has provided us with personal information, we will take steps to delete such information promptly. If you believe a child has provided us with personal information, please contact us at privacy@opesledger.ca.

12. International Data Transfers

Your data may be processed and stored on servers located outside of Canada, depending on the infrastructure used by our service providers (Supabase). Where your data is transferred outside of Canada, we ensure that adequate safeguards are in place to protect your information in accordance with PIPEDA and applicable Canadian law.

13. Security Breach Notification

In the event of a security breach involving your personal information that creates a real risk of significant harm, we will:

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes:

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Opes Ledger. Privacy Office
Email: privacy@opesledger.ca
Website: opesledger.ca

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.