Privacy Policy
The short version: we store your receipts and the data we read out of them, we send those receipts to AI providers in the United States and the European Union to be read, and we do not sell anything to anyone or run ad trackers. We hold no more of your information than the product needs. If your documents cannot live there, ask us about a private instance instead of using the shared service.
Effective Date: September 15, 2026
Contact Email: info@shinobimedia.ca
Domain: https://simpleloonie.ca
Applies to: the shared SimpleLoonie.ca cloud service. Private instances are covered in section 14.
SimpleLoonie ("we", "our", "us") is a receipt-scanning and expense-tracking service for Canadian small businesses, operated from Ontario, Canada. This policy explains what personal information we collect, why, who else touches it, where it goes, and what you can ask us to do with it. We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, including Quebec's Law 25 and the personal information protection acts of Alberta and British Columbia.
1. What Data We Collect
Account information. Your email address, your name, an optional avatar image, and an identifier from our authentication provider. We never receive or store a password — sign-in is handled entirely by WorkOS AuthKit.
The documents you upload and what we read from them. Receipts, invoices and any other file you upload, which routinely contain personal and financial information. For each document we also store the structured result of the AI scan — merchant, date, total, currency, tax rate and amount, category, project, line items — and the full recognised text of the document, so it can be searched.
Your business profile. If you use the invoice generator: business name, business address, bank or payment details you choose to print on invoices, and a logo.
Billing information. A Stripe customer identifier, which plan you are on, and when it expires. Card numbers go to Stripe directly and never reach our servers — we cannot see them.
Operational data. How many receipts you scanned this month, storage used, AI token counts, account timestamps, and server logs (including IP address) kept for security and debugging.
Messages you send us. Anything you write to our contact form or support address, and your address if you sign up for product updates.
What we deliberately do not collect:
- No third-party advertising trackers, data brokers, or cross-site behavioral ad networks
- No bank or credit-card account connections — we do not link to your financial institution
- No card numbers, no Social Insurance Numbers, and no CRA credentials
- No sale, rental, or trade of personal information about you to third parties
Usage Analytics & Session Telemetry (PIPEDA Compliance):
To understand user workflows, optimize performance, and detect interface errors on Canadian business devices, we collect anonymous usage telemetry via Google Analytics 4 and session replay diagnostics via Microsoft Clarity. All sensitive form fields (such as passwords, credit card inputs, or uploaded document details) are automatically masked and excluded from session replay telemetry. This data is collected solely for service improvement and diagnostic telemetry under PIPEDA, and is never used for advertising profiling or sold to third parties.
2. Why We Use It
We use your information only to run the service you signed up for:
- To create your account and let you sign in
- To store your documents and read them with AI so you do not have to type them in
- To build your ledger, reports and exports, and to generate invoices you ask for
- To bill you, enforce plan limits, and tell you when you are near them
- To answer your support messages and send service notices about your account
- To keep the service secure, diagnose faults, and meet our own legal obligations
Under PIPEDA we rely on your consent, which you give when you create an account, upload a document, or ask us for a feature that needs the data. We do not use your documents or your ledger for any purpose beyond those listed above: we do not train models on them, we do not build advertising profiles, and we do not sell, rent or trade personal information. You can withdraw consent at any time (see section 10), though doing so may mean we can no longer provide the service.
3. AI Processing
Reading your documents is done by third-party AI providers. Each scan sends the uploaded document — rendered as images, up to the first four pages — together with a prompt containing the field, category and project names in your account. It does not send your transaction history, your other files, your email address or your billing details. Documents are sent as they are, without redaction.
Our AI Use Disclosure sets out which providers and models we use, the default order we try them in, what we keep afterwards, and how to avoid AI processing altogether. Please read it — it is the detailed version of this section.
4. Who Else Handles Your Data
We use a small number of service providers. Each receives only what it needs to do its job:
| Provider | Purpose | What it receives | Where |
|---|---|---|---|
| WorkOS | Sign-in and session management (AuthKit) | Email, name, avatar, sign-in events | United States |
| Google Cloud | Application hosting and database | Everything the application stores | United States |
| Cloudflare R2 | Storage of uploaded files and previews | Your uploaded documents | Distributed |
| AI providers | Reading documents (see AI disclosure) | The document images and the extraction prompt | United States, EU |
| Stripe | Subscriptions, payment and billing portal | Email, payment details you give Stripe directly | United States |
| Email delivery | Sign-in codes, account notices, replies | Your email address and the message | United States |
| Sentry | Error monitoring, when enabled in our deployment | Error traces, browser and request metadata | United States |
| XE | Historical exchange rates for multi-currency transactions | A currency pair and a date — no personal information | — |
| Google Drive | Optional receipt import integration | Only files located inside your designated “SimpleLoonie Receipts” folder | United States |
| Google Analytics 4 | Anonymous usage metrics and conversion telemetry | Pseudonymised page paths, browser user-agent, conversion events | United States |
| Microsoft Clarity | Session replay diagnostics and UX friction detection | Masked user interaction recordings (clicks, scrolls, errors; sensitive inputs excluded) | United States |
Google Drive Integration & Limited Use Disclosure
If you choose to connect Google Drive for automated receipt syncing:
“Google requires this permission so we can automatically monitor your receipt folder in the background. SimpleLoonie is strictly programmed to only read and process files inside your dedicated ‘SimpleLoonie Receipts’ folder. We never touch, view, or read your personal documents.”
SimpleLoonie's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train or fine-tune artificial intelligence models.
We may also disclose personal information where the law requires it — for example, in response to a valid legal order — or to protect our rights and the security of the service. If the business is ever sold or merged, your information may transfer with it, and we will tell you before that happens.
5. Where Your Data Lives (Cross-Border Processing)
SimpleLoonie is run from Ontario, but the infrastructure is not in Canada. The application and database run on Google Cloud in the United States; uploaded files sit in Cloudflare R2 object storage; AI processing happens in the United States and the European Union. Sign-in, payments and email delivery are likewise handled by providers in the United States.
While your information is outside Canada it is subject to the laws of the country it is in, and may be accessible to that country's courts and government authorities under their own legal processes. We tell you this plainly, as PIPEDA expects, so you can decide before you upload. If your records must stay in Canada, or in a database you control, ask us about a private instance (see section 14).
6. Security — and Its Limits
What we do:
- All traffic runs over HTTPS, and credentials are held in a managed secret store, not in our code
- Uploaded files are stored under per-account keys and served only through an authenticated route — there are no public or guessable file links
- Sign-in is delegated to WorkOS, so no password of yours exists on our systems to be stolen; sessions are held in an encrypted cookie
- Payments are delegated to Stripe, so no card number of yours exists on our systems either
- Access to production data is limited to the people who operate the service, for support and debugging
What we do not do, so you are not surprised:
- We do not add our own encryption layer on top of the storage provider's. Your documents are encrypted at rest by the provider, but they are not end-to-end encrypted, and they are not encrypted with a key only you hold — meaning we can technically read them, and so could anyone who compromised our credentials.
- We hold no SOC 2, ISO 27001 or similar certification, and we do not claim to.
No system is perfectly secure. Weigh that against the sensitivity of what you upload, and ask us about a private instance if your obligations to your own clients demand more than the above.
7. How Long We Keep It
- Your documents, ledger and settings are kept for as long as your account exists. We do not delete your records on a timer.
- Deleting a transaction or a file in the app removes it from the database and the stored object. Deletion is immediate, not reversible, and not a "trash" you can restore from.
- On the Free plan, transactions older than 30 days are hidden from your list and exports. They are not deleted — they reappear if you upgrade.
- When you ask us to close your account, we delete your account, documents and ledger. Copies may persist briefly in infrastructure backups and in server logs before they age out.
- Records we need for tax, accounting or legal reasons — invoices we issued you — are kept as required.
Export before you close. The CRA generally expects you to keep business records for six years from the end of the last tax year they relate to, and your originals remain your record of account. Use the Excel or CSV export, and keep your own copies of your receipts, before asking us to delete anything.
8. Email You Receive From Us
We send two kinds of email. Service email — sign-in codes, billing and account notices, replies to your support messages — is part of the service and is not marketing. Product updates are sent only if you asked for them, and you can stop them at any time by emailing info@shinobimedia.ca, which we action promptly as required by Canada's anti-spam legislation (CASL).
Addresses given for product updates are kept in our own mailbox for that purpose. We do not load them into an advertising platform and we do not share them.
9. Cookies
We use one essential cookie, for your sign-in session, and no tracking or advertising cookies at all. The details are in our Cookie Policy.
10. Your Rights and How to Use Them
Under PIPEDA and applicable provincial law you may:
- Ask what personal information we hold about you and how it has been used or disclosed
- Correct information that is wrong or incomplete
- Get a copy of your data — the Excel and CSV exports in the app do this yourself, immediately
- Withdraw your consent, subject to legal and contractual limits
- Ask us to delete your account and its contents
- Complain about how we handled your information
Most of this is self-service in the app. For access requests, corrections we cannot make for you, or account deletion — which is not currently a button in the dashboard — email info@shinobimedia.ca from the address on your account. We respond within 30 days, the timeline PIPEDA sets, and we do not charge for it.
If our answer does not satisfy you, you can complain to the Office of the Privacy Commissioner of Canada, or to the Commission d'accès à l'information du Québec, the Office of the Information and Privacy Commissioner of Alberta, or the Office of the Information and Privacy Commissioner for British Columbia if you are in one of those provinces.
11. If There Is a Breach
If personal information in our care is lost or accessed without authorization and there is a real risk of significant harm to you, we will report the breach to the Office of the Privacy Commissioner of Canada and notify you directly, as PIPEDA requires, and we will keep a record of the incident. Our notice will tell you what happened, what information was involved, and what you can do about it.
12. Automated Processing
The AI reads your documents and proposes values; you approve, edit or discard them before anything is recorded. We make no decision about you by automated means — nothing here affects your eligibility, credit, pricing or access to a service, and we do not profile you. Quebec's Law 25 requires that you be told when a decision is based exclusively on automated processing; no such decision is made here.
13. Children
SimpleLoonie is a business tool intended for people 18 or older. We do not knowingly collect personal information from minors. If you believe a minor has created an account, tell us and we will remove it.
14. Private Instances
We also deploy and operate dedicated instances for a single organisation, running against a database, object storage and an AI provider key that organisation owns. This policy describes the shared service and does not describe those deployments: where the data sits, which providers touch it and who is responsible for what are set out in the written agreement for that engagement. Where the customer owns the database and the storage, the records stay in their accounts and we do not hold a copy. See simpleloonie.ca/private-instance.
15. Changes to This Policy
We update this page when what we collect, who processes it, or where it goes changes. The Effective Date above reflects the current version, and we will email account holders before a change that materially affects how their information is handled takes effect. Questions about any of it go to info@shinobimedia.ca.