Legal

Privacy Policy

Last updated:

At visyoner ("we", "us", or "our"), your privacy is a core commitment — not an afterthought. This Privacy Policy explains what personal information we collect, how we use it, with whom we share it, and the choices you have. By using visyoner, you agree to the practices described below.

Scope: visyoner is currently offered to residents of Canada. This policy is written primarily to comply with the Canadian framework — the federal Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec’s Act respecting the protection of personal information in the private sector (Law 25), and the substantially-similar provincial laws of British Columbia (PIPA) and Alberta (PIPA). Section 10 below contains additional disclosures for U.S. residents and Section 11 contains additional disclosures for residents of the European Union, the European Economic Area, the United Kingdom, and Switzerland — both will be in effect when we open the Service to users from those regions.

1. Information We Collect

1.1 Information You Provide

  • Account information — name, email address, password (stored as a one-way bcrypt hash), country, province, time zone, and (if you enable it) a two-factor authentication secret.
  • Authentication via Google or Facebook — when you sign in through these providers we receive your name, email address, and a provider-issued user identifier. We do not receive your social-network password.
  • Financial institution data — when you connect a bank or brokerage via Plaid, we receive transaction history, account balances, holdings, and institution metadata. We never receive or store your banking credentials; you enter those directly with Plaid.
  • Manual entries — planned transactions, category rules, envelopes, assets, liabilities, tags, and notes you create directly in the app.
  • AI chat content — the questions you send to our AI assistant and any transaction context the assistant retrieves to answer them.
  • Support communications — messages, attachments, and ticket metadata you send to our support team.
  • Billing information — for paid plans, your billing name, email, billing address, and a Stripe customer identifier. Card numbers are entered into Stripe's hosted fields and are never transmitted to or stored on our servers.

1.2 Information Collected Automatically

  • Usage data — pages visited, features used, and interaction patterns, to help us improve the product.
  • Device and log data — IP address, browser type, operating system, and error logs, used for security and debugging. Error reports are configured to strip personal information before transmission.
  • Cookies and local storage — session tokens, CSRF tokens, and UI preferences (e.g., theme, collapsed panels). We do not use third-party advertising or tracking cookies.

2. How We Use Your Information

  • Provide, maintain, and improve the visyoner service.
  • Sync your financial institution data and generate spending insights and forecasts.
  • Send transactional emails (account verification, password reset, sync alerts, data-export delivery, household invitations).
  • Send service announcements and — only if you opt in — occasional product updates. Every commercial electronic message contains an unsubscribe link as required by Canada's Anti-Spam Legislation (CASL).
  • Power AI-generated spending insights and chat responses via a large language model provider. The model provider is contractually prohibited from using your data to train its models.
  • Detect fraud, abuse, and security incidents.
  • Comply with legal obligations and respond to lawful requests from public authorities.

3. Service Providers and Subprocessors

We do not sell your personal information. We rely on a small number of service providers to operate visyoner. Each is bound by a written data-processing agreement and is named below so you can review their own privacy practices.

  • Plaid Inc. (United States) — financial-institution connectivity. Receives the banking credentials you enter at the Plaid Link prompt and returns transactions, balances, and holdings to us. Governed by Plaid's Privacy Policy.
  • Stripe, Inc. (United States, with Canadian processing through Stripe Payments Canada, Ltd.) — subscription billing and payment-method storage. Receives your billing name, email, address, and card details directly from your browser.
  • OpenAI, L.L.C. (United States) — AI chat and spending-insight generation. Receives your chat messages and the transaction context required to answer them. Bound by the OpenAI API data-processing agreement; data is not used to train OpenAI's models.
  • Functional Software, Inc. d/b/a Sentry (United States) — application error monitoring. Receives stack traces and request metadata; personal data is scrubbed client- and server-side before transmission.
  • Laravel Nightwatch (Tighten LLC, United States) — application performance and queue/job observability. Receives request paths, response timing, queue job outcomes, and database-query shape (no parameter values by default).
  • Zendesk, Inc. (United States) — customer-support ticketing. Receives support messages, attachments, and your name and email when you contact support.
  • Laravel Forge / Laravel VPS (Tighten LLC, United States) — server provisioning, deployment, and operational management. Production runs on Forge’s “Laravel VPS” product, delivered through Tighten’s infrastructure partnership with DigitalOcean.
  • DigitalOcean, LLC (US-incorporated; production droplet hosted in DigitalOcean’s Toronto data centre) — underlying cloud-compute provider. The application database, file storage, queue, and runtime live on a DigitalOcean droplet that Tighten provisions on our behalf. Your primary data store is physically located in Canada.
  • Mailtrap (Railsware Products Inc., European Union) — transactional and (when you opt in) marketing email delivery.
  • Conva Ventures Inc. d/b/a Fathom Analytics (Canada, with data processing through a global CDN that includes United States regions) — privacy-first marketing analytics. Receives pageview and CTA-click event metadata (URL path, referrer, approximate country, device type, event name). Does not use cookies, does not store personally identifiable information, and hashes IP addresses with a daily-rotating salt so visitors cannot be tracked across days. Governed by Fathom’s Data Policy.

The current authoritative list lives on our Subprocessors page, which is updated whenever a vendor changes.

4. Cross-Border Transfers of Personal Information

Your primary data store — the application database, file storage, and queue — is hosted on a DigitalOcean droplet in DigitalOcean’s Toronto data centre, so the bulk of your personal information is physically located in Canada at rest. However, several of the service providers listed in Section 3 process personal information in the United States or the European Union for specific purposes — financial-institution connectivity (Plaid), billing (Stripe), AI assistance (OpenAI), error monitoring (Sentry), performance/queue observability (Laravel Nightwatch), support ticketing (Zendesk), email delivery (Mailtrap), marketing analytics (Fathom), and deployment orchestration (Laravel Forge). In addition, DigitalOcean itself is a US-incorporated company, which means US authorities may have legal reach over the parent entity under laws such as the CLOUD Act, even though the servers are on Canadian soil. While your information is in another jurisdiction or subject to another jurisdiction’s authorities, it may be subject to that jurisdiction’s laws. We have assessed each transfer and rely on the data-processing agreements with each provider, technical safeguards (encryption in transit and at rest), and data-minimization (we send the smallest viable subset of your data to each provider) to protect your information. By creating an account you consent to these transfers; you may withdraw this consent at any time by deleting your account (see Section 6).

5. Household Accounts

If you create or join a household, the financial data scoped to that household — including transactions on shared accounts, shared categories, envelopes, and net-worth contributions — becomes visible to other household members. Personal data (your password, two-factor secret, private support tickets, and AI chat sessions) is never shared. You can leave a household at any time from Settings → Household; when you leave, household-scoped data is re-scoped to your personal account only.

6. Data Retention, Export, and Deletion

We retain your personal information for as long as your account is active. Audit-history records (transaction changes, category rules applied, etc.) are retained for the same period to provide you with an accurate timeline of your finances.

You may export a complete copy of your data at any time from Profile → Export My Data. The export is delivered as a ZIP archive of pretty-printed JSON files via a one-time signed link that expires after 24 hours.

You may delete your account yourself at any time from Profile → Delete Account. The flow asks for your password (or, for OAuth sign-ins, an explicit confirmation), cancels any active subscription, revokes every linked institution's Plaid access, dissolves your household ownership, and permanently erases your personal information from our systems. If you would rather have us run the deletion for you, contact our Privacy Officer at [not configured] — we process those requests within 30 days.

We may retain a limited subset of information where required by law (for example, billing records under the Income Tax Act) or to resolve disputes. We also write a PII-minimal audit row recording the fact that the deletion happened (date, method, originating IP) so we can demonstrate compliance if asked. Any retained data is segregated and access-restricted.

7. Security Safeguards

We apply technical, organisational, and physical safeguards proportionate to the sensitivity of the information we hold. In particular:

  • All traffic between your browser and visyoner is encrypted in transit using TLS 1.2 or higher.
  • Plaid access tokens, which authorize ongoing read access to your financial institutions, are encrypted at rest in our database using AES via Laravel's encryption service and a key held outside the database.
  • Passwords are stored as one-way bcrypt hashes; we cannot recover them.
  • Two-factor authentication is available and recommended for all accounts.
  • Access to production systems is limited to designated personnel under the principle of least privilege and is logged.
  • We perform regular dependency and security reviews and follow industry best practices for application security.

No system is perfectly secure. If we become aware of a breach of security safeguards involving your personal information that creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada (and, for Quebec residents, the Commission d'accès à l'information) without unreasonable delay, as required by law.

8. Automated Processing

visyoner generates spending insights, recurring-transaction forecasts, and AI chat responses through automated processing. These outputs are suggestions for your review, not decisions made about you. visyoner does not make any decision producing a legal or similarly significant effect on you solely on the basis of automated processing. You can disable AI features at any time from Settings → AI & Privacy.

9. Your Rights

Subject to the conditions and exceptions set out in applicable Canadian privacy law, you have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete information directly via your Profile page or by contacting us.
  • Receive a portable copy of the information you provided to us, in a structured, commonly used machine-readable format, via the data-export feature in Section 6 (Quebec Law 25, art. 27).
  • Request deletion of your account and personal information.
  • Withdraw consent to the processing of your personal information at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent may mean we can no longer provide the Service.
  • Object to or restrict certain processing activities, including disabling AI features.
  • Request de-indexation of content that contains your personal information, where permitted by Quebec Law 25 art. 28.1.
  • Lodge a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, for Quebec residents, the Commission d'accès à l'information du Québec (cai.gouv.qc.ca) if you believe your rights have not been respected. Residents of Alberta and British Columbia may complain to their respective provincial Information and Privacy Commissioners.

To exercise any of these rights, contact our Privacy Officer at [not configured]. We will respond within 30 days.

10. Additional Disclosures for U.S. Residents

visyoner primarily serves Canadian residents (see the scope banner at the top of this policy). The disclosures below apply to U.S. residents and supplement the rights described in Section 9 — they are in addition to, not in place of, the general rights enumerated above.

10.1 We Do Not Sell or Share Your Personal Information

visyoner does not sell your personal information. We also do not “share” your personal information for the purposes of cross-context behavioural advertising (as that term is defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, the “CCPA”). We do not engage in targeted advertising of any kind, on any platform. If we ever change this practice we will update this policy and provide you with an opportunity to opt out before any sale or sharing takes place.

10.2 Sensitive Personal Information

Some of the personal information we collect qualifies as “sensitive personal information” under U.S. state privacy laws — specifically, the last four digits of your financial-institution account numbers (received from Plaid) and your account-access credentials (your password hash and any two-factor authentication secret). We use this information only for the purposes of providing the Service to you (financial-account aggregation, authentication, and security) and not for any of the secondary purposes that would trigger your right to limit its use and disclosure under CCPA § 7027.

10.3 California Residents (CCPA / CPRA)

If you are a California resident, the CCPA grants you the rights listed below, in addition to the general rights in Section 9:

  • Right to know the categories of personal information we have collected, the categories of sources, the business or commercial purposes for collecting it, and the categories of third parties with whom we share it. Sections 1, 2, and 3 of this policy provide these disclosures.
  • Right to access the specific pieces of personal information we hold about you. Exercisable through the data-export feature described in Section 6.
  • Right to correct inaccurate personal information.
  • Right to delete personal information we have collected from you. Exercisable through the self-serve account-deletion flow described in Section 6.
  • Right to opt out of sale or sharing — not applicable in practice, because we do not sell or share (see Section 10.1).
  • Right to limit use and disclosure of sensitive personal information — we use sensitive personal information only for the service purposes described in Section 10.2 and do not need to offer this opt-out under CCPA § 7027(m).
  • Right to non-discrimination — we will not deny service, charge different prices, or provide a different level of quality because you exercised any of your CCPA rights.

How to exercise California rights. Submit a request to our Privacy Officer at [not configured]. We will respond within 45 days, with one additional 45-day extension if reasonably necessary (we will notify you of any extension and the reason). We may need to verify your identity using the minimum information necessary before processing a request. You may designate an authorised agent to act on your behalf; the agent must provide written authorisation signed by you.

Global Privacy Control (GPC). When we open the Service to California residents, a GPC opt-out preference signal received from your browser will be treated as a valid opt-out request under the CCPA. Even though we do not currently sell or share personal information, we will honour the GPC signal for any future processing that could fall within the CCPA’s definitions of sale or sharing.

10.4 Residents of Other U.S. States

Residents of Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, and Virginia (and other states that enact comprehensive consumer-privacy legislation) have rights to access, correct, delete, and obtain a portable copy of their personal information; to opt out of the sale of personal data, targeted advertising, and certain profiling decisions; and to non-discrimination for exercising those rights. To exercise any of these rights, contact our Privacy Officer at [not configured]. If we deny your request, you may appeal the decision by replying to the denial within a reasonable time; we will inform you of the outcome of the appeal in writing and, if denied, provide information about how to contact your state attorney general.

10.5 Children Under 13 (COPPA)

Section 12 below sets out our general age floor of 14. For U.S. users, that floor also satisfies the federal Children’s Online Privacy Protection Act (COPPA): we do not knowingly collect personal information from children under 13.

11. Additional Disclosures for EU / EEA / UK Residents

visyoner primarily serves Canadian residents (see the scope banner at the top of this policy). The disclosures below apply to residents of the European Union, the wider European Economic Area, and the United Kingdom, and supplement — they do not replace — the rights described in Section 9. Residents of Switzerland have equivalent rights under the Federal Act on Data Protection (FADP) and may exercise them via the same channels described here.

11.1 Controller

For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) and the UK GDPR, visyoner is the “controller” of your personal data. Contact details are in Section 14.

11.2 Lawful Basis for Processing

We process your personal data on the following bases under GDPR Article 6:

  • Performance of a contract (Art. 6(1)(b)) — for the core service: providing your account, syncing your connected financial institutions, generating your dashboards and analyses, sending transactional emails (verification, password reset, sync alerts, household invitations, billing receipts), and processing billing through Stripe.
  • Consent (Art. 6(1)(a)) — for AI chat and AI-generated spending insights (a separate explicit consent recorded at first use, described in Section 8), and for product-update and re-engagement emails (a separate opt-in described in Section 2 and exercisable from Settings → AI & Privacy).
  • Legitimate interests (Art. 6(1)(f)) — for fraud detection and security monitoring (Sentry error capture, Nightwatch performance telemetry, login audit). Our legitimate interest is keeping the Service operating safely. You may object to legitimate-interest processing — see Section 11.3 below.
  • Compliance with legal obligation (Art. 6(1)(c)) — for retention of billing records under applicable tax law, and for responding to lawful requests from public authorities.

11.3 Your Rights Under the GDPR

The general rights enumerated in Section 9 satisfy most of your GDPR / UK GDPR rights. The full list, mapped to the relevant articles:

  • Right of access (Art. 15) — exercisable via the data-export feature described in Section 6.
  • Right to rectification (Art. 16) — most fields are editable in your Profile; the rest by contacting the Privacy Officer.
  • Right to erasure / “right to be forgotten” (Art. 17) — exercisable through the self-serve deletion flow at Profile → Delete Account (Section 6).
  • Right to restriction of processing (Art. 18) — contact the Privacy Officer; we can pause processing of specific categories pending resolution of a dispute.
  • Right to data portability (Art. 20) — exercisable via the data-export feature (Section 6); the export is a machine-readable JSON archive.
  • Right to object (Art. 21) — particularly to processing based on legitimate interests (Section 11.2); contact the Privacy Officer.
  • Right not to be subject to automated decision-making producing legal or similarly significant effects (Art. 22) — see Section 8: visyoner’s automated processing produces suggestions for your review, not decisions about you.
  • Right to withdraw consent at any time (Art. 7(3)) — for AI features via Settings → AI & Privacy; for marketing emails via the toggle in the same place or the one-click unsubscribe link in any product-update email. Withdrawal does not affect the lawfulness of processing before the withdrawal.
  • Right to lodge a complaint with a supervisory authority (Art. 77) — typically the data-protection authority of the EU/EEA Member State where you live, work, or where the alleged infringement occurred. UK residents may complain to the Information Commissioner’s Office (ico.org.uk). Swiss residents may contact the Federal Data Protection and Information Commissioner (edoeb.admin.ch).

To exercise any of these rights, contact our Privacy Officer (Section 14). We will respond within one month under Art. 12(3); this period may be extended by a further two months where necessary, taking into account the complexity and number of requests, in which case we will notify you within the first month.

11.4 International Transfers

Your personal data is stored at rest in Canada (see Section 4). The European Commission has issued an adequacy decision for Canadian commercial organizations subject to PIPEDA (Commission Decision 2002/2/EC), which means transfers of your personal data from the EU/EEA to our Canadian data store rely on that adequacy decision and do not require additional safeguards.

Several of the service providers listed in Section 3 are located in the United States, which the European Commission considers adequate only for entities certified under the EU-U.S. Data Privacy Framework. For transfers to U.S. providers, we rely on the Data Privacy Framework certification where the provider is certified, and on Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as a fallback transfer mechanism otherwise. Mailtrap (EU) processes mail within the European Economic Area and does not constitute an international transfer.

11.5 Data Protection Officer and EU Representative

visyoner is not currently required to appoint a Data Protection Officer under GDPR Art. 37: we are not a public authority, our core activity is not the large-scale monitoring of data subjects, and we do not process the special categories of data listed in Art. 9 on a large scale. Privacy-related inquiries are handled by our Privacy Officer (Section 14).

Because we have no establishment in the EU / EEA or the UK, before we open the Service to users in those regions we will appoint an EU representative (Art. 27) and a UK representative (UK GDPR Art. 27) whose contact details will be added to this section. Until then, please direct all GDPR / UK GDPR inquiries to the Privacy Officer.

11.6 Automated Decision-Making

See Section 8. visyoner’s AI features generate suggestions for your review rather than decisions about you, so the right under Art. 22 does not restrict you from using the Service — but you may still object to or withdraw consent from AI processing as described in Sections 8 and 11.3.

12. Children's Privacy

visyoner is not directed at children. We do not knowingly collect personal information from anyone under the age of 14. If you become aware that a child under 14 has provided us with personal information without verifiable parental consent, please contact our Privacy Officer and we will delete it promptly. Users between 14 and the age of majority in their province should review this policy with a parent or guardian.

13. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes by email or via an in-app notice at least 14 days before they take effect. The "Last updated" date at the top of this page always reflects the current version. Continued use of visyoner after the effective date constitutes acceptance of the updated policy.

14. Contact Us — Privacy Officer

visyoner has designated a Privacy Officer responsible for compliance with this policy and with applicable Canadian privacy law. Questions, concerns, complaints, or rights requests should be directed to:

Privacy Officer, visyoner
Email: [not configured]