Privacy Policy
What Hypertax collects, why, who else processes it, where it is stored, how long it is kept, and the rights you have over it.
- Effective
- Last updated
Hypertax prepares Canadian tax returns. To do that it necessarily handles some of the most sensitive information you have: your Social Insurance Number, what you earned, who you work for, who lives in your household, and often your bank account details. This policy sets out what we do with it.
It is written to be read. Where a term of art is unavoidable we say what it means.
Pending counsel review · CR-PRIV-01
Who we are
Hypertax is operated by [ to be completed: registered legal entity name and address ], referred to here as "Hypertax", "we" or "us". Our service is at hypertax.ca.
Under Canadian privacy law we are the organisation accountable for the personal information described below. We are also a preparer of tax returns, which brings with it record-keeping obligations under the Income Tax Act that an ordinary website does not have. Those two things together are the reason parts of this policy are stricter than you may be used to — and the reason we cannot delete quite everything the moment you ask.
What this policy covers
This policy covers the Hypertax website, the return preparation service, and the emails we send you about them. It does not cover any third party's own site or product, including the Canada Revenue Agency's website.
Two things are governed by separate documents:
- Consent to disclose or use your tax return information. Sending any part of your return information to a third party — in particular to an AI vendor outside Canada — is a disclosure you have to agree to first, separately, and in terms specific enough to be meaningful. A privacy policy is not the place to obtain that agreement, and an "I agree to the terms" checkbox is not meaningful consent to it. Those consents live at /legal/consent.
- Retention and deletion. How long each kind of record is kept, and what "delete my account" actually deletes, is set out at /legal/retention; How long we keep it below summarises why it is a separate document.
What we collect
Account information
Your email address, and your name if you give it. If you sign in with Google, Microsoft or Apple, we receive your email address and basic profile information from that provider, not your password. If you turn on two-factor authentication we store the secret needed to verify your codes.
Tax return information
Everything you enter or confirm in order to prepare a return. Depending on your situation that includes:
- Your name, date of birth, address, marital status, and the names, dates of birth and identification numbers of your spouse and dependants.
- Your Social Insurance Number, and those of the people listed on your return.
- Amounts from your income slips: your T4, including employment income, income tax deducted, and the CPP, CPP2, EI and pension adjustment boxes.
- Deduction and credit information you supply, and your residency and province or territory of residence.
- Bank account details, if you ask for a refund by direct deposit or arrange a payment by direct debit.
Documents you upload
The image or PDF of your T4. We keep the file, its type and size, when it was uploaded, and the structured result of reading it, including which fields you corrected.
Payment information
If you buy a return, our payment processor collects your card details directly. We never receive or store your full card number. We receive and store a record of the transaction: the amount, the currency, the date, the last four digits and card brand, the billing country, and the processor's identifiers for the payment and for you as a customer.
Technical information
Server logs recording IP address, user agent, the pages requested and the time, security events such as sign-ins and failed sign-in attempts, and errors. We keep an audit record of every occasion on which a member of our staff views a customer's data.
Support correspondence
What you write to us, and what we write back.
Why we collect it, and on what basis
Pending counsel review · CR-PRIV-02
We use your information to:
- Prepare, compute and produce your return. This is the service you asked for, and it is the reason for essentially everything in the list above.
- Create and secure your account, verify it is you, and detect and stop abuse.
- Take payment and give you a receipt, and handle refunds and chargebacks.
- Support you when you ask us something, and investigate when something goes wrong.
- Meet our own legal obligations, including the records the Income Tax Act requires us to keep, tax and accounting obligations on our own revenue, and responding to lawful requests.
Our basis is your consent, together with the limited circumstances in which PIPEDA permits collection, use or disclosure without consent, such as complying with a legal requirement. Giving us your information in order to have a return prepared is consent to use it for that purpose, and for no other purpose. Anything beyond preparing your return — in particular sending part of it to someone else — needs a separate, specific yes from you.
We do not sell your personal information. We do not share it for targeted advertising. We do not use your tax return information to train any AI model, and no vendor we use is permitted to train on it. We do not use it to market other products to you.
Pending counsel review · CR-PRIV-03
Who else processes your information
We are self-hosted, which means we run our own application rather than assembling it out of other people's services. The processors we do rely on are these, by category. Each acts on our instructions, for the purpose listed, and for no other.
Cloud hosting and object storage
Amazon Web Services, outside Canada. AWS hosts the application, the database in which your return is stored, the encrypted object storage that holds the documents you upload, and our encrypted backups. AWS is where your information physically sits; see Where your information is stored.
Transactional email
Amazon Simple Email Service (AWS SES), outside Canada. Sign-in links, receipts, and notices about your return. SES receives your email address and the content of the message we send you. We do not send your return, your Social Insurance Number or your figures by email.
Payment processing
Stripe, Inc., outside Canada. Stripe collects and processes your card details directly and is responsible for them as its own controller as well as our processor. We send Stripe your name, your email address, the amount and what you bought. We do not send Stripe your return, your figures or your Social Insurance Number — it never receives tax return information, and keeping it that way is a deliberate constraint on how our billing code is written, not an accident of what Stripe happens to ask for.
Large-language-model vendors
Anthropic and OpenAI. These are the AI vendors behind the features described in our AI-use disclosure: reading the T4 you upload, rephrasing interview questions, and answering support questions from our published help content.
None of this is switched on today. The consents these features depend on are still in draft and awaiting legal review, so nothing is being sent to either vendor by anyone, and every AI feature is running the manual path described in the AI-use disclosure. What follows describes how it would work once those consents are approved.
Unlike the three categories above, we cannot yet tell you where these two would process your information. Neither has contractually committed to us that inference runs in any particular country, so we are not willing to print a location as a fact. Until that commitment exists we treat the disclosure as one that leaves Canada, and the consent form you would be asked to sign says so on its face.
This category is different from the three above, in three ways that matter:
- Nothing goes to them unless you have consented. Sending your return information to a model vendor is a disclosure to a third party, and it is a disclosure across the border. It requires your prior, specific, opt-in consent, given on the separate document at /legal/consent before anything is sent. If you have not consented, no part of your return, and no document you have uploaded, is transmitted to Anthropic or OpenAI.
- Declining costs you nothing but typing. Every AI feature has a manual equivalent. You can enter your T4 by hand and receive exactly the same completed return.
- They receive a part, not the whole. What is sent is scoped to the feature: the image of a slip for extraction, the text of a question for rephrasing, your support question together with our published help articles for support. Your account identity is not sent with it, and the model is never given your assembled return.
Pending counsel review · CR-PRIV-04
Analytics and advertising
We use no third-party analytics service, no advertising network, and no tracking pixels. Any usage measurement is performed by software running on our own infrastructure.
Pending counsel review · CR-PRIV-05
Others
We may disclose information where the law requires it — to a court, a regulator or law enforcement acting under valid authority — and, if the business is ever sold or merged, to the acquirer, subject to the same restrictions and to the consents you have given or withheld, which continue to bind a successor.
Where your information is stored, and what that means
Hypertax runs on infrastructure located outside Canada.
This means your personal information — your name, your SIN, the amounts on your T4, the documents you upload, and any bank details you give us — is transferred to, stored in and processed in another country.
You should understand what follows from that:
- PIPEDA permits an organisation to transfer personal information to a service provider in another country for processing. It does not require separate consent for the transfer, but it does require that we tell you clearly, which is the purpose of this section.
- While your information is outside Canada it is subject to the law of the country it is in. It may be accessible to foreign courts, law enforcement agencies and national-security authorities under that country's lawful-access powers, and it may be accessible without notice to you. The protections available to you in that situation are not the same as those under Canadian law.
- We remain accountable for your information under PIPEDA while it is with a processor. We are required to use contractual and other means to give it a comparable level of protection to what it would receive here, and we are required to answer for it if that fails.
Pending counsel review · CR-PRIV-06
How long we keep it
Retention is genuinely complicated here, and we would rather say so than give you a number that is wrong.
Two obligations pull in opposite directions. As a preparer of returns we are required by the Income Tax Act to retain records of the returns we prepare for six years. As the custodian of your personal information we are required to delete it when it is no longer needed and, in many cases, when you ask us to. Those cannot both be satisfied for the same record, and the resolution has to be written down rather than improvised the first time someone asks.
That resolution — a period for each category of record, what "delete my account" removes immediately, what is retained because the law requires it, and what is reduced to a tombstone rather than kept — is set out in our retention policy at /legal/retention.
Read it rather than this section. We are not going to restate it here from memory, because two descriptions of the same retention rule are two things that can disagree, and the one you would be relying on is the wrong one.
How we protect it
The measures below are the ones we operate. They are stated as facts, not as reassurance, and we have deliberately not claimed anything we cannot point at.
- Traffic between you and Hypertax is encrypted in transit with TLS.
- Social Insurance Numbers and bank account details are stored encrypted, in dedicated ciphertext columns, with a separate searchable index derived from the value rather than the value itself. There is no column anywhere in our database holding a plaintext SIN.
- Backups and uploaded documents are encrypted at rest.
- Access to production data by our staff is restricted by role, is logged as an audit record on every read, and any impersonation of a customer account for support purposes is time-limited, visible to the user and expires by itself.
- The audit log is append-only, enforced by the database rather than by convention.
- Two-factor authentication is available on your account and required for staff accounts.
- We operate a written information security program with a named individual responsible for it, a written risk assessment, vendor oversight and an incident response plan. PIPEDA requires safeguards appropriate to the sensitivity of the information; a tax return is about as sensitive as personal information gets, so the program is written down rather than held in someone's head.
No system is impossible to breach, and we do not claim ours is. What we can say is what we do, what we log, and what we will tell you if something goes wrong.
Pending counsel review · CR-PRIV-07
If there is a breach
If your personal information is lost, or accessed or disclosed without authorisation, we assess whether the breach creates a real risk of significant harm to you. That is the test PIPEDA sets, and it turns on how sensitive the information is and how likely it is to be misused — for a Social Insurance Number and a T4, both of those point the same way.
Where that threshold is met:
- We report the breach to the Office of the Privacy Commissioner of Canada as soon as feasible.
- We notify you directly, as soon as feasible, with enough detail to let you reduce the harm — what happened, what information was involved, what we have done about it, and what you can do.
- We notify any other organisation that can reduce the risk to you.
Whether or not the threshold is met, we keep a record of every breach of security safeguards for 24 months, and the Privacy Commissioner is entitled to ask us for those records. We do not wait for a particular number of people to be affected before any of this happens: Canadian law sets no such threshold, and neither do we.
Your rights
Under PIPEDA you have the right to:
- Know what personal information we hold about you, how we use it, and to whom we have disclosed it.
- Access it, and receive a copy.
- Correct it if it is inaccurate or incomplete.
- Withdraw your consent, subject to legal and contractual restrictions and on reasonable notice. Withdrawing consent to a disclosure to an AI vendor is always available and never prevents you from completing a return.
- Complain — to us first, and then to the Office of the Privacy Commissioner of Canada, whose findings we are required to respond to.
If you are in Alberta, British Columbia or Quebec, your provincial privacy statute may give you further rights, and your complaint may go to your provincial commissioner — in Quebec, the Commission d'accès à l'information — rather than the federal one.
How to exercise a right
Write to [ to be completed: privacy contact email address ], or to the postal address in How to contact us, and tell us what you want. We will verify that the request comes from you — for an account holder, ordinarily by requiring you to make the request from the signed-in account or from the address on it — and we will respond within 30 days, or tell you why we need longer where the law permits an extension.
There is no charge. If we refuse a request in whole or in part we will tell you why, and how to escalate.
An authorised agent may act for you where the law provides for it, on proof of authority.
Children
Hypertax is for adults filing their own return. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. A return may include information about a dependent child, which the adult filer supplies; that information is handled under this policy like the rest of the return.
Changes to this policy
If we change this policy we will publish the new version here with a new version number and effective date, and the change history at the foot of this page will say what changed. If a change is material — if it widens what we collect, what we use it for, or who receives it — we will tell you before it takes effect and, where consent is the basis, we will ask for it again rather than assume it.
We will never apply a change retroactively to a disclosure that has already happened, and we will never treat a consent you have already given as covering something broader than what it described when you gave it.
How to contact us
Contact details for privacy questions, requests and complaints: [ to be completed: privacy contact email, postal address, and the name or title of the individual accountable for privacy ].
Pending counsel review · CR-PRIV-08
Change history
| Version | Date | What changed |
|---|---|---|
| 1.2.0-draft | Hypertax is now a Canada-only service. Removed the United States basis throughout and restated every obligation on its Canadian footing: PIPEDA for the handling, the Income Tax Act for the six-year retention period, PIPEDA s. 10.1 and the Privacy Commissioner for breach notification, and meaningful consent under PIPEDA and Law 25 for a disclosure to a model vendor outside Canada. | |
| 1.1.2-draft | Named Stripe's processing location, which the provider register verifies, so every processor category states one or explains why it cannot. | |
| 1.1.1-draft | Stopped stating the model vendors' processing location as fact: it is recorded as assumed and unverified in the provider register, and the consent to disclose is issued on the offshore basis. Counsel notes cross-referenced to the compliance register. | |
| 1.1.0-draft | Retention policy published; removed the condition making this policy contingent on it and pointed the two cross-references at the live document. | |
| 1.0.0-draft | Initial draft prepared for counsel review. Not in force. |