Privacy Policy

Effective as of: July 4, 2026

Last updated: July 4, 2026

We value your trust and respect your privacy. We exist to support small business owners like you by offering a fast and easy way to manage your business finances.

We believe the only good policy is one you can understand without a lawyer by your side, so we've worked hard to explain—clearly and in plain English—what we do, what information we collect, and why, so you can feel confident about using our services.

⚠️ Important Legal Notice

This privacy policy is a comprehensive TEMPLATE based on Wave Accounting's approach and Canadian privacy law requirements. It MUST be reviewed by qualified legal counsel before use. Financial and payroll data processing requires compliance with PIPEDA (Canada), GDPR (if serving EU clients), and applicable provincial regulations (e.g., Québec's Law 25).

My Virtual Accounting Firm ("MVAF", "we", "us", or "our") operates the My Virtual Accounting Firm (MVAF) platform. This Privacy Policy explains how we collect, use, disclose, and protect your personal and financial information when you use our services. By using MVAF, you consent to the practices described in this policy.

What's Inside

Information We Collect
How We Use Your Information
Data Security Measures
Data Sharing and Third Parties
Data Retention Schedule
Your Privacy Rights
Cookie Policy
International Data Transfers
Children's Privacy
Changes to This Policy
Contact Information

1. Information We Collect

1.1 Personal Identification Information

  • Name, email address, phone number, and mailing address
  • Business name, CRA Business Number (BN), and tax identification numbers
  • HST/GST registration numbers and payroll account numbers
  • Date of birth (for payroll employees, as required by CRA)
  • Government-issued ID numbers (last 3 digits of SIN only for ROE generation)

1.2 Financial and Payroll Data

  • Bank account numbers, credit card information, and financial institution details
  • Transaction records, invoices, bills, receipts, and bank statements
  • Payroll records including employee names, salaries, wages, and deductions
  • Social Insurance Numbers (SIN) — we store ONLY the last 3 digits for ROE generation. Full SINs are NEVER stored or transmitted.
  • Employee date of birth, province of employment, and tax credit amounts (TD1 federal/provincial)
  • Vacation pay rates, overtime eligibility, and employment start/termination dates
  • Accounts receivable and payable records, customer and vendor information

1.3 Technical and Usage Data

  • IP address, browser type, device information, and operating system
  • Log files, access timestamps, and pages visited within the platform
  • Cookies and similar tracking technologies (see our Cookie Policy below)
  • Usage patterns and feature interaction data for platform improvement

In Simple Terms

We treat your personal information with the same respect we want our own to be treated with—and when you deal with finances like we do, there's a lot of personal information involved. We collect what's necessary to provide our services: your identity, your financial data, and some technical details about how you use our platform. Nothing more.

2. How We Use Your Information

2.1 To Provide Our Services

  • Provide accounting, bookkeeping, payroll processing, and tax preparation services
  • Generate financial statements, T4 slips, Records of Employment (ROE), and CRA-required filings
  • Process invoices, payments, and accounts receivable/payable transactions
  • Reconcile bank statements and categorize financial transactions using AI-assisted tools
  • Maintain general ledgers, trial balances, and chart of accounts
  • Calculate payroll deductions (CPP, EI, federal/provincial income tax) based on CRA tables

2.2 To Communicate With You

  • Send service-related notifications (payroll run confirmations, invoice reminders, filing deadlines)
  • Respond to service requests and provide customer support via "Accountant on Call"
  • Send monthly financial reports and AI-generated financial insights (you may unsubscribe at any time)
  • Notify you of important policy changes or security updates
  • Send educational content, tax tips, and regulatory updates (opt-in only)

2.3 To Meet Legal Obligations

  • Comply with the Income Tax Act (Canada), Excise Tax Act, and Employment Insurance Act
  • Meet recordkeeping requirements under the Canada Business Corporations Act
  • Respond to lawful requests from government authorities (CRA, Revenu Québec, Service Canada)
  • Detect, prevent, and investigate fraud, security breaches, or Terms of Service violations
  • Generate Reports of Employment (ROE) as required by Employment Insurance regulations

In Simple Terms

Many Wave services and features simply wouldn't work without some Personal Information. We use your data to do what you hired us to do: manage your finances, run payroll, file taxes, and keep you compliant. We also use it to communicate with you about your account and send you helpful tips (but only if you want them).

3. Data Security Measures

3.1 Technical Safeguards

  • All data is encrypted in transit using TLS 1.3 (HTTPS) with 256-bit SSL encryption
  • Data at rest is encrypted using AES-256 encryption on secure cloud infrastructure
  • Access controls enforce multi-tenant isolation — each client can access only their own data
  • One-Time Passcode (OTP) verification is required for sensitive operations (payroll changes, tax settings, bank account modifications)
  • Regular security audits and penetration testing of our platform and third-party integrations
  • Intrusion detection systems and 24/7 monitoring for unauthorized access attempts
  • Automatic session timeout after periods of inactivity
  • Password requirements: minimum 8 characters, complexity requirements, and periodic rotation prompts

3.2 Organizational Safeguards

  • Access to client financial data is restricted to authorized our staff on a need-to-know basis
  • All staff members sign confidentiality agreements and undergo privacy training
  • Background checks are conducted for employees with access to sensitive payroll data
  • Regular review of access logs and audit trails for suspicious activity
  • Role-based access control (RBAC): admin, staff accountant, and client roles with different permission levels

In Simple Terms

We use bank-level security to protect your data. Think of it like a vault with multiple locks: encryption, access controls, OTP verification, and constant monitoring. Your data is safe with us.

4. Data Sharing and Third Parties

4.1 Service Providers We Work With

  • PaySprint: For payroll payout processing and employee payment disbursements
  • Plaid: For secure bank connectivity and transaction imports
  • Resend: For transactional and marketing email delivery
  • Google Drive / Microsoft OneDrive: For document storage (if connected by you)
  • Shopify: For e-commerce transaction synchronization (if connected by you)
  • Zapier: For workflow automation (if enabled by you)
  • Base44: Platform infrastructure provider hosting the MVAF application

4.2 Government and Legal Requirements

  • Canada Revenue Agency (CRA): For tax filings, payroll remittances, and compliance reporting
  • Revenu Québec: For Québec-specific tax and payroll filings (if applicable)
  • Service Canada: For Records of Employment (ROE) and EI reporting
  • Provincial workers' compensation boards: As required by provincial legislation
  • Law enforcement or courts: In response to valid legal requests (warrants, subpoenas)

What We Do NOT Do

  • We do NOT sell your personal or financial information to third parties
  • We do NOT share your data with advertisers or marketing companies
  • We do NOT use your financial data to train AI models in a way that could identify your business
  • We do NOT transfer your data outside Canada unless adequate safeguards are in place

In Simple Terms

Sometimes, we work with other companies and organizations to bring our customers an unbeatable experience. When this happens, their privacy policies apply and they'll have access to some of your information, but only as much as is absolutely necessary to provide the service you want. We never sell your data. Ever.

5. Data Retention Schedule

5.1 CRA Requirements (7 Years)

  • Financial records (invoices, receipts, bank statements, ledgers): 7 years from the end of the last tax year
  • Payroll records (T4s, ROEs, pay stubs, deductions): 7 years from the end of the last tax year
  • Tax returns and supporting documents: 7 years from the date of filing
  • Corporate minute books and share registers: Indefinitely (or until 7 years after dissolution)
  • General ledgers and trial balances: 7 years minimum
  • Supporting documents for input tax credits (ITCs): 7 years

5.2 Platform Account Data

  • User account information (email, name, role): Retained while account is active + 7 years post-termination
  • Login logs and audit trails: 2 years from creation date
  • AI-generated insights and financial health scores: 3 years from generation date
  • Deleted transactions or records: Moved to archive for 90 days, then permanently deleted
  • Subscription and billing records: 7 years from last transaction

5.3 When You Leave

  • Upon service termination, you may request a full data export within 30 days
  • After 30 days, your account is deactivated but data is retained for CRA-mandated 7-year period
  • After 7 years, data is securely deleted using NIST 800-88 sanitization standards
  • You may request earlier deletion of non-legally-required data by contacting privacy@myvirtualaccountingfirm.com

In Simple Terms

The CRA requires us to keep your financial records for 7 years. We follow this rule strictly. After that, we delete everything securely. You can request your data back anytime in a format you can use (CSV, PDF, or JSON).

6. Your Privacy Rights

Access Your Data

You have the right to access the personal information we hold about you. Contact privacy@myvirtualaccountingfirm.com with proof of identity. We respond within 30 days.

Correct Your Data

You may request corrections to inaccurate, incomplete, or outdated information. We respond within 30 days. If we disagree, you may add a "note of disagreement" to your record.

Withdraw Consent

You may withdraw consent for non-essential communications (e.g., marketing emails) at any time using the "unsubscribe" link in emails.

Data Portability

You may request a machine-readable export of your data (CSV, JSON, or PDF format). Data exports are provided within 30 days of request.

Right to be Forgotten

You may request deletion of your personal data, subject to legal retention requirements. We cannot delete data that CRA requires us to retain for 7 years.

File a Complaint

If you believe we have violated your privacy rights, contact our Privacy Officer at privacy@myvirtualaccountingfirm.com. You may also contact the Office of the Privacy Commissioner of Canada.

In Simple Terms

Your data, your rights. You can see it, fix it, download it, or delete it (within legal limits). We make it easy. Just contact our Privacy Officer and we'll help you within 30 days.

7. Cookie Policy

What Are Cookies?

Cookies are small text files stored on your device when you visit our website. They help us remember your preferences, keep you logged in, and understand how you use the platform.

Types of Cookies We Use

  • Essential cookies: Required for platform functionality (session management, authentication)
  • Preference cookies: Remember your settings (language, currency, dashboard layout)
  • Analytics cookies: Help us understand usage patterns (e.g., Google Analytics, if enabled)
  • Security cookies: Protect against fraud and unauthorized access

Managing Cookies

  • You can control cookies through your browser settings
  • Blocking essential cookies may prevent the platform from functioning properly
  • Most browsers allow you to view, delete, and block cookies on a site-by-site basis
  • For more information, visit www.allaboutcookies.org

8. International Data Transfers

8.1 Data Location

  • MVAF is hosted in Canada on secure cloud infrastructure
  • Primary data centers are located in Canada to comply with Canadian data sovereignty requirements

8.2 Cross-Border Transfers

  • Some third-party service providers (e.g., Resend, Zapier) may process data outside Canada
  • We ensure adequate safeguards are in place: Standard Contractual Clauses (SCCs), GDPR compliance certifications, or Privacy Framework agreements
  • By using MVAF, you consent to the transfer of your data to these service providers for the limited purposes described in Section 4

8.3 GDPR Compliance (EU Clients)

  • If you are an EU resident, we comply with GDPR requirements for international data transfers
  • Our legal basis for processing includes: contract performance, legal obligations, and legitimate interests
  • You have GDPR rights including: access, rectification, erasure, restriction, portability, and objection

9. Children's Privacy

  • MVAF is not intended for individuals under the age of 18
  • We do not knowingly collect personal information from children
  • If we discover that we have collected data from a child without parental consent, we will delete it immediately

10. Changes to This Privacy Policy

10.1 Updates

  • We may update this Privacy Policy from time to time to reflect changes in law, technology, or business practices
  • Material changes will be communicated via email or prominent notice on the platform at least 30 days before they take effect
  • The "Last updated" date at the top of this policy indicates the most recent revision

10.2 Your Continued Use

  • Continued use of MVAF after changes constitutes acceptance of the updated Privacy Policy
  • If you do not agree with the changes, you may terminate your account before the effective date

11. Contact Information

Privacy Officer

For privacy-related questions, access requests, or complaints:

Email: privacy@myvirtualaccountingfirm.com

Mail: Privacy Officer, My Virtual Accounting Firm, 2131 Williams Parkway, Unit 20, Brampton, ON L6S 6B8, Canada

General Inquiries

Company: My Virtual Accounting Firm

Email: info@myvirtualaccountingfirm.com

Support: Available via the "Accountant on Call" feature within the platform

Regulatory Bodies

  • Office of the Privacy Commissioner of Canada:
    https://www.priv.gc.ca/ | 1-800-282-1376
  • Commission d'accès à l'information du Québec:
    https://www.cai.gouv.qc.ca/ | 1-888-528-7748
  • Canadian Radio-television and Telecommunications Commission (CRTC): For spam/unsubscribe issues

In Simple Terms

If you have any questions or concerns about your privacy, we have someone to listen and help. Here's how you can get in touch with that person. We're here for you.

⚖️ Legal Disclaimer (Critical Reminder)

This Privacy Policy is a TEMPLATE and starting point only. It is NOT legal advice and may not comply with all applicable laws in your jurisdiction. Financial services, payroll processing, and tax preparation are heavily regulated industries subject to:

Canadian Federal Laws: PIPEDA (Personal Information Protection and Electronic Documents Act), Income Tax Act, Excise Tax Act
Provincial Laws: Québec Law 25, Alberta PIPA, BC PIPA (if operating in these provinces)
International Laws: GDPR (if serving EU clients), CCPA/CPRA (if serving California residents)

You MUST consult with qualified legal counsel specializing in financial services, technology, and privacy law to review, customize, and ensure compliance before publishing this policy for your business. Non-compliance can result in significant fines (up to CAD $100,000 under PIPEDA, up to 4% of global revenue under GDPR).

© 2026 My Virtual Accounting Firm ·Terms of Service ·Data Retention Policy ·Privacy Officer