Privacy Policy

Last updated: March 1, 2026

Overview

Nora ("we", "us", "our") is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your personal information in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Canadian provincial privacy legislation.

Information We Collect

  • Account information: name, email address, business name, province
  • Business data: invoices, expenses, contacts, receipts, bank statements, tax rates, mileage logs
  • Usage data: feature usage, login times, device type (anonymized)
  • Payment information: processed securely by our payment provider — we never store credit card numbers

How We Use Your Information

  • To provide and improve the Nora service
  • To calculate taxes (GST/HST/PST) based on your province
  • To send invoices on your behalf via email
  • To generate financial reports and exports
  • To send service notifications (payment received, invoice overdue)
  • To provide customer support

Data Storage & Security

All business data is stored on servers located in Canada (AWS ca-central-1 region). Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). We implement industry-standard security measures including access controls, audit logging, and regular security reviews.

Data Sharing

We do not sell, rent, or share your personal information with third parties for marketing purposes. We may share data with:

  • Service providers who help us operate Nora (cloud hosting, email delivery) — bound by data processing agreements
  • Law enforcement when required by Canadian law

Your Rights

Under PIPEDA, you have the right to:

  • Access your personal information
  • Request correction of inaccurate data
  • Withdraw consent for data processing
  • Request deletion of your account and all associated data

Data Retention

We retain your data for as long as your account is active. When you delete your account, all personal and business data is permanently removed within 30 days. Anonymized usage statistics may be retained for service improvement.

Cookies

We use essential cookies for authentication and session management. We do not use tracking cookies or third-party advertising cookies.

Contact

For privacy inquiries or to exercise your rights, contact our Privacy Officer at privacy@getnora.ca.