1. Overview
Kountr is operated by Hejazi Technology Inc. (“Kountr,” “we,” “us”), a company incorporated in Ontario, Canada. We provide accounting software for Canadian small businesses, freelancers, bookkeepers, and independent auto dealers. This policy explains what personal and financial information we collect when you use kountrfi.ca and the Kountr application at launch.kountrfi.ca (together, the “Service”), how we use it, who we share it with, and the choices you have.
It is written under the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec’s Law 25, and applicable provincial privacy laws. Where the EU/UK GDPR or the California Consumer Privacy Act (CCPA/CPRA) applies to you, the relevant provisions below apply too.
We do not sell your personal information. We never receive your online-banking password. We never receive your full card number. We do not use your books, receipts, or bank transactions to train AI models. Your database records and uploaded files are stored in Canada; some of the services that process them run in the United States, which we spell out in section 7.
2. What we collect
2.1 Information you give us
- Account data — your name, email address, and business name. Sign-in is handled by Firebase Authentication (Google); your password is set and verified there and is never stored on, or visible to, Kountr’s servers.
- Tax & business settings — your tax jurisdiction, HST/GST registration details, and mode settings (CPA mode, Dealer mode) — used to categorize and to produce correct reports.
- Content you upload — receipts, invoices, bills, signed bills of sale and vehicle contracts, vehicle and inventory records, journal entries, categories, rules, and any notes or attachments you add.
- Feedback and support correspondence — anything you send through the in-app feedback form or by email, including files you attach.
2.2 Information from services you connect
- Bank and credit-card data via Plaid — when you connect a financial institution we receive transactions, balances, account type, institution name, and a masked account number for the accounts you authorize. See section 4.
- Telegram (optional) — if you link the Kountr Telegram bot to send receipts from your phone, we receive the photos and documents you send it, the message metadata, and your Telegram user ID and username. You can unlink at any time in Connections.
- Billing data via Stripe — we receive your subscription status, plan, invoices, and the brand and last four digits of your card. Full card numbers are handled entirely by Stripe and never reach our servers.
2.3 Information we collect automatically
- Device & log data — IP address, user-agent, browser and OS, timestamps, pages viewed, and feature-usage events, collected through our product analytics (PostHog) and our server logs.
- Cookies and local storage — strictly-necessary storage that keeps you signed in, and first-party product analytics. We do not use cross-site advertising cookies and we do not run ad-network trackers.
3. How we use it
We use the information above to:
- Provide the Service — sync transactions, suggest categories, match receipts to transactions, maintain your ledger, and generate reports (profit & loss, HST/GST summary, cash flow, trial balance).
- Authenticate you, keep accounts secure, and detect abuse.
- Bill you through Stripe and send you service and account emails.
- Respond to feedback and support requests.
- Understand which features are used and where the product breaks, so we can fix and improve it.
- Comply with legal obligations and respond to valid legal requests.
Where the GDPR applies, our legal bases are: performance of a contract (delivering the Service you signed up for), legitimate interests (securing the Service, preventing abuse, improving the product), legal obligation (tax and accounting records), and consent (optional features and non-essential email, which you can withdraw at any time).
4. Bank connections via Plaid
When you link a bank account, you log in through Plaid Inc., not Kountr. Plaid passes your credentials directly to your bank. Kountr never sees, stores, or has access to your online-banking username or password.
4.1 What Plaid gives us
We use a single Plaid product — Transactions — so the data we receive is limited to what bookkeeping actually needs:
- Transaction history: description, amount, date, merchant, category hints, and pending status.
- Account balances, account type (chequing, savings, credit card), currency, and a masked account number.
- Account-holder name and institution name.
We do not request Plaid’s Auth, Identity, Income, Assets, or Liabilities products. That means we do not receive your full account number or your bank routing/transit number, and we cannot move money.
4.2 What Kountr does with Plaid data
- Displays your transactions and balances inside Kountr.
- Suggests categories, applies the rules you create, and matches receipts against transactions.
- Generates the reports you ask for and detects likely duplicates.
We fetch data only for institutions you connect, and only while that connection is active. Your Plaid access tokens are stored encrypted at rest (AES-256-GCM envelope encryption) so that a database leak alone does not expose a working bank connection. You can disconnect a bank at any time in Connections; we then stop fetching new data, and the history already imported stays in your books until you delete it or ask us to.
4.3 Plaid’s own role
Plaid is an independent data-access provider and processes data under its own privacy policy at plaid.com/legal (Canada: End User Privacy Policy). Kountr is a data recipient of Plaid. You can review and revoke Plaid connections at any time at my.plaid.com.
5. AI processing of your data
Kountr uses artificial intelligence to read the documents you upload and to suggest how transactions should be categorized. That processing is performed by Anthropic (the Claude API), which means the relevant content leaves Kountr’s systems and is processed in the United States. The rules below apply to all of it.
5.1 What we use AI for
- Receipt & document reading — extracting vendor, date, totals, tax, and line items from the images and PDFs you upload or send by Telegram.
- Bill-of-sale extraction — reading a signed vehicle contract and pulling out the deal terms, so a dealer doesn’t retype them.
- Categorization suggestions — proposing a category for a transaction, and proposing reusable rules based on patterns across your own transactions.
There is no chat assistant in Kountr today, and AI is not used to make payments, file anything, or contact anyone on your behalf.
5.2 What data the AI sees
Depending on the feature, the content sent for AI processing can include: the image or PDF you uploaded and the text within it; transaction descriptions, amounts, and dates; vendor names; and your list of categories. We do not send your password (we don’t have it), your banking credentials (we don’t have them), or full card numbers (we don’t have them).
5.3 Our rules for AI processing
- No training on your data. Under Anthropic’s commercial API terms, the inputs and outputs we submit are not used to train their models. We will not adopt an AI provider that reserves the right to train on your content.
- Limited provider-side retention. Anthropic may retain API inputs and outputs for a limited period for trust-and-safety purposes, under their published policies.
- Purpose limitation. Content is sent only to fulfil the specific action you triggered — uploading a receipt, importing a contract, asking for rule suggestions. We do not batch your books off to a model for unrelated purposes.
- One workspace per request. A request carries a single account’s data, so one customer’s records can’t be mixed into another customer’s result.
5.4 No model training on your books
We do not use your financial records, receipts, bank transactions, or customer and vendor data to train AI models — ours or anyone else’s.
5.5 Accuracy and your control
- AI output is a suggestion or a draft. Extracted receipt fields, imported deal terms, and suggested rules are all shown to you and can be edited or rejected before or after they land in your books.
- AI can be wrong. You are responsible for reviewing what ends up in your ledger and in anything you file.
- Kountr does not make solely automated decisions that produce legal or similarly significant effects about you within the meaning of GDPR Article 22.
- If you would rather not have a particular document processed by AI, don’t upload it — enter the transaction manually instead. If you want AI-derived content removed from your account, email us (see section 11).
6. Sub-processors
We rely on the service providers below to run Kountr. Each processes personal data on our behalf and under contract. The current list, with regions and the data each one handles, is published at /legal/subprocessors.
- Supabase — application database and storage of the files you upload (Canada).
- Render — hosting for the Kountr API server (United States).
- Netlify — hosting for the web app and this marketing site.
- Firebase Authentication (Google) — sign-in, password reset, email verification.
- Plaid Inc. — bank and credit-card connectivity.
- Stripe — subscription billing and card payments.
- Anthropic — AI document reading and categorization suggestions.
- Resend — transactional and account email delivery.
- Telegram — only if you choose to link the receipts bot.
- PostHog — first-party product analytics (US region).
7. Where your data is processed
We think you should know where your records physically sit, so we say it plainly rather than burying it:
- In Canada — your application database and every file you upload (receipts, contracts, attachments) are stored with Supabase in the Canada Central region.
- In the United States — the Kountr API server runs on Render in Virginia, and our AI processing (Anthropic), payments (Stripe), bank connectivity (Plaid), authentication (Firebase), email (Resend), and product analytics (PostHog) are all operated from the United States.
This means that your personal information is processed outside Canada and, while it is there, is subject to the laws of that jurisdiction — including lawful access by US courts, law enforcement, and national-security authorities. Where a transfer is subject to the GDPR or UK GDPR, we rely on the applicable contractual safeguards, including the EU Standard Contractual Clauses and the UK Addendum where required.
8. Sharing & disclosure
We share personal information only as described below:
- With the sub-processors in section 6, acting on our instructions under written agreements.
- With authorities, when legally required — in response to valid Canadian (or comparable foreign) legal process. We interpret requests narrowly, push back on overbroad ones, and notify you unless we are legally prohibited from doing so.
- In a corporate transaction — if Kountr is acquired, merged, or sells assets, your data may transfer to the successor, subject to this policy.
We do not sell personal information, and we do not “share” it for cross-context behavioural advertising as defined under the CCPA.
Kountr accounts are currently single-user: there is no team, invite, or shared-workspace feature, so we do not disclose your books to a bookkeeper, accountant, or anyone else unless you export the data and send it yourself, or you ask us in writing to do so.
9. Retention & deletion
- Active accounts — we keep your data for as long as your account is open.
- Closed accounts — because Kountr holds books and records, we retain accounting records for up to six (6) years after the end of the tax year they relate to, in line with Canada Revenue Agency record-keeping requirements, unless you ask us to delete them sooner and no legal obligation requires us to keep them.
- Uploaded files — kept with the transactions and deals they support, and deleted with them.
- Analytics and server logs — retained on a rolling basis for security, debugging, and product measurement.
- Backups — database backups are managed by Supabase and age out on their standard cycle; data you delete persists in backups until they roll over.
There is no self-serve account deletion in the app yet. To delete your account and data, email info@kountrfi.ca from your account email address. We action deletion requests within 30 days, subject to the retention rules above, and we’ll tell you what we kept and why. You can export your reports to CSV from inside the app at any time before you go — including after a trial has lapsed, when the account becomes read-only but exports keep working.
10. Security
We use TLS for all traffic, encryption at rest for the database and file storage, row-level security so a query can only reach the signed-in account’s rows, envelope encryption for Plaid access tokens, and least-privilege access to production. We are a small team and we don’t hold a formal certification such as SOC 2 or ISO 27001 — we say so here rather than implying otherwise. Details are on our Security page.
11. Your rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Delete your account and associated data, subject to the retention rules in section 9.
- Port your data — export your reports and ledger data to CSV.
- Object to or restrict certain processing, where the GDPR/UK GDPR applies.
- Withdraw consent for non-essential email and optional features at any time.
- Complain to the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, your provincial regulator, or your supervisory authority where the GDPR/UK GDPR applies.
- If you are a California resident, exercise your CCPA/CPRA rights, including the right not to be discriminated against for exercising them.
To exercise any of these, email info@kountrfi.ca. We may need to verify your identity before we act on the request, and we’ll respond within the time limits set by applicable law (30 days under PIPEDA).
12. Children
The Service is for businesses and is not directed at children under 16. We don’t knowingly collect personal information from children.
13. Changes
We may update this policy as the product changes. If a change is material, we’ll notify account holders by email or in-app before it takes effect, and we’ll always update the “last updated” date at the top of this page.
14. Contact
Hejazi Technology Inc. (operating as Kountr)
Privacy Officer — info@kountrfi.ca
Ontario, Canada
