BudgetMaid

Privacy Policy

Last updated: September 23, 2026 · Designed for PIPEDA accountability

1. Who we are

BudgetMaid (“we”, “us”) is a personal budgeting application that helps you import Canadian bank CSV statements, categorize spending, and track budgets. We act as the organization responsible for personal information under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.

2. What we collect

  • Account identity: name, email address, and password hash.
  • Financial data you upload or enter: account names, institutions, transaction dates, amounts, payees, memos, categories, and budgets.
  • Technical logs: IP address, user agent, and security audit events (login, export, account deletion).

We do not sell personal information. We do not connect directly to your bank; you control what CSV files you upload.

3. Why we collect it

We collect information only to provide budgeting features you request, secure your account, detect abuse, and meet legal obligations. Consent is obtained at registration and continues while you use the service. You may withdraw consent by deleting your account.

4. How we protect it

  • Sensitive fields (payee, memo, account name/institution, amounts, budgets, import filenames/maps) are encrypted at rest with application-level encryption keyed by APP_KEY.
  • Sessions are encrypted; passwords are hashed (bcrypt/argon).
  • Import deduplication uses a one-way HMAC - ciphertext cannot be used to reverse-engineer payees.
  • Transport security (HTTPS / HSTS) is enforced in production.
  • Security response headers harden browsers against common attacks.
  • Each user’s data is scoped by ownership checks (policies) so accounts cannot access each other’s records.

5. Your rights (PIPEDA)

  • Access: download a machine-readable export of your data from Profile.
  • Correction: update profile details and edit or delete transactions, accounts, and budgets in-app.
  • Deletion: permanently delete your account and associated data from Profile.
  • Complaint: contact us first; you may also contact the Office of the Privacy Commissioner of Canada.

6. Retention

We retain your data while your account is active. Soft-deleted records are purged on account deletion. Security audit logs may be retained for a limited period for accountability and fraud prevention.

7. Cross-border & processors

If you host BudgetMaid yourself, data stays on infrastructure you control. If we operate a hosted service, we will disclose subprocessors and locations and use contractual safeguards comparable to PIPEDA expectations.

8. Contact

Privacy inquiries: noreply@heyloonie.com

Terms of Use