Privacy Policy
Effective date: [DATE] · Last updated: [DATE]
This Privacy Policy explains how [LEGAL ENTITY NAME] operating as eTracer (“eTracer”, “we”, “us”) collects, uses, stores, and shares information when you use etracer.ca and the eTracer application (the “Service”). eTracer matches Interac e-Transfer® notification emails to invoices in your accounting software. We are a Canadian company and design the Service to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA).
1. Information we collect
- Account information — your name, email address, business name and type, and password (stored as a salted hash) or your Google / Microsoft sign-in identity.
- Email data (read-only) — when you connect an inbox, we access it read-only. We programmatically identify and process only Interac e-Transfer notification emails (sender name, amount, date, reference and message text). We do not read, store, send, delete, or modify any other email. We store only the extracted payment fields and a short excerpt of the matched notification for your audit trail.
- Accounting data — with your authorization, we read open invoices and customer names from your connected accounting platform (QuickBooks Online, Xero, FreshBooks, or Wave) and write payment applications you approve or that match automatically under your settings.
- Billing information — payments are processed by our payment processor ([PROCESSOR, e.g. Stripe]). We store only your card’s last four digits and expiry; full card numbers never touch our servers.
- Usage and log data — device, browser, IP address, and actions taken in the Service, used for security and product improvement.
2. How we use information
We use the information above solely to provide and improve user-facing features of the Service: detecting incoming e-transfers, proposing and booking invoice matches, sending receipts and notifications you have enabled, remembering payer–customer relationships you confirm, and providing your audit trail. We do not use your data for advertising, and we never sell it.
3. Google API disclosure (Limited Use)
eTracer’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Gmail data to provide the user-facing e-transfer matching features described above.
- We do not transfer Gmail data to others except as necessary to provide those features, with your consent, for security purposes, or to comply with law.
- We do not use Gmail data for advertising.
- No humans read your Gmail data, except with your explicit consent for support, for security investigation and abuse prevention, to comply with law, or where the data has been aggregated and anonymized for internal operations.
Our access uses the gmail.readonly scope and undergoes Google’s restricted-scope verification, including an annual independent security assessment.
4. Microsoft and other email providers
When you connect an Outlook / Microsoft 365 inbox, we access it via Microsoft Graph with the read-only Mail.Read permission and apply the same standards described in Section 3: read-only access, processing limited to Interac e-Transfer notifications, no advertising use, no sale, and no human access except as described above. The same applies to any other supported provider (e.g., Yahoo Mail).
5. Accounting platform data (Intuit, Xero, FreshBooks, Wave)
We access your accounting data only as needed to list open invoices, propose matches, apply payments you authorize, and send receipts. We honour each platform’s developer and data policies, including Intuit’s security requirements. Disconnecting a platform in Settings stops all access immediately; you can also revoke access from the platform’s own connected-apps settings.
6. Sharing and subprocessors
We share data only with subprocessors necessary to run the Service — cloud hosting ([HOST, e.g. AWS Canada region]), our payment processor, and transactional email delivery — each bound by data-protection agreements. We never sell or rent personal information, and we do not share it for advertising. We may disclose information if required by law.
7. Retention and deletion
We retain extracted payment records while your account is active so your audit trail stays complete. If you disconnect an inbox or integration, we stop collecting immediately. If you delete your account, we delete your personal data and stored email excerpts within [30] days (backups purge within [90] days), except records we must keep by law. You may also request deletion at any time at privacy@etracer.ca.
8. Security
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). OAuth tokens are stored encrypted and are never exposed to your browser. Access is restricted by role, logged, and reviewed. We undergo an annual third-party security assessment as part of Google’s restricted-scope program and notify affected users and the Office of the Privacy Commissioner of Canada of any breach creating a real risk of significant harm, as PIPEDA requires.
9. Your rights
You may access, correct, or export your personal information, withdraw consent, and close your account at any time. Contact our privacy officer at privacy@etracer.ca — we respond within 30 days. You may also complain to the Office of the Privacy Commissioner of Canada.
10. Cookies
We use only essential cookies (sign-in sessions) and privacy-respecting analytics on our marketing site. We do not use advertising cookies or cross-site tracking.
11. Children
The Service is for businesses and is not directed to individuals under 18. We do not knowingly collect information from minors.
12. Changes
We will post any changes here and, for material changes, notify you by email before they take effect.
13. Contact
[LEGAL ENTITY NAME] · [BUSINESS ADDRESS] · Privacy officer: privacy@etracer.ca · Support: support@etracer.ca
Highlighted [placeholders] must be completed and the full text reviewed by your lawyer before publishing.