Privacy Policy

Effective Date: March 01, 2026
Last Updated: March 01, 2026

1. Introduction

Welcome to MapleExpense, operated by Joel & Nanz Inc. ("we," "us," or "our"). We are committed to protecting your personal information and your right to privacy in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and other applicable privacy laws.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our expense management platform.

2. Information We Collect

2.1 Personal Information

We collect information that you provide directly to us, including:

  • Account information (name, email address, password)
  • Organization information (business name, tax identification numbers)
  • Payment information (processed securely through Stripe)
  • Profile information (role, permissions within your organization)

2.2 Receipt and Transaction Data

When you use our service, we collect:

  • Receipt images and PDF files you upload
  • Transaction details (vendor names, dates, amounts, categories)
  • Bank transaction data you import
  • GIFI codes and tax categorizations

2.3 Usage Information

We automatically collect certain information when you use our platform:

  • Device information (IP address, browser type, operating system)
  • Usage data (features accessed, time spent, actions performed)
  • Log data (access times, pages viewed, errors encountered)

3. How We Use Your Information

We use your information for the following purposes:

  • Providing and maintaining our expense management service
  • Processing OCR (Optical Character Recognition) on receipts via OpenAI
  • Generating financial reports and tax summaries
  • Processing payments and managing subscriptions
  • Sending important service notifications and updates
  • Improving our platform and developing new features
  • Ensuring security and preventing fraud
  • Complying with legal obligations

4. Data Sharing and Disclosure

4.1 Third-Party Service Providers

We may share your information with trusted third-party service providers:

  • OpenAI: For receipt OCR processing (receipt images are sent to OpenAI's API)
  • Stripe: For payment processing (we do not store full credit card numbers)
  • Cloud Hosting Providers: For secure data storage and infrastructure

4.2 Legal Requirements

We may disclose your information if required by law, legal process, or government request, including to meet national security or law enforcement requirements.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal information:

  • Encryption of data in transit and at rest
  • Multi-tenant data isolation to prevent cross-organization access
  • Regular security audits and vulnerability assessments
  • Access controls and authentication requirements
  • Secure backup and disaster recovery procedures

6. Data Retention

We retain your personal information for as long as necessary to provide our services and comply with legal obligations:

  • Account data: Retained while your account is active
  • Receipt and transaction data: Retained for 7 years (CRA requirement for tax records)
  • Payment records: Retained as required by financial regulations
  • Audit logs: Retained for security and compliance purposes

You may request deletion of your data at any time using the "Purge My Data" feature in your account settings.

7. Your Rights (PIPEDA Compliance)

Under Canadian privacy law, you have the right to:

  • Access: Request a copy of your personal information
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion of your personal information
  • Portability: Export your data in a structured format
  • Withdrawal of Consent: Withdraw consent for data processing
  • Complaint: File a complaint with the Privacy Commissioner of Canada

To exercise these rights, please contact us using the information in Section 11.

8. Cookies and Tracking

We use essential cookies for authentication and session management. We do not use third-party tracking cookies or analytics services.

9. Children's Privacy

Our service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children.

10. International Data Transfers

Your information may be processed and stored in Canada and other jurisdictions where our service providers operate. When transferring data internationally, we ensure appropriate safeguards are in place in accordance with PIPEDA.

11. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

Joel & Nanz Inc.

MapleExpense Privacy Officer

Email: privacy@joelnanz.com

Website: https://joelnanz.com/#contact

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through a prominent notice on our platform. Your continued use of the service after such modifications constitutes your acceptance of the updated Privacy Policy.

This Privacy Policy is governed by the laws of Canada and the province of Ontario.

🤖

Tessa

Powered by Maple-AI

🤖 ...thinking...

Quick questions:

AI responses may take a moment