Privacy policy

What this service collects, why it collects it, where it is stored, and the rights you have under Canadian privacy law.

Last updated August 3, 2026

Operator: have a Canadian privacy lawyer review this before you rely on it. It is drafted against PIPEDA and the provincial regimes and it accurately describes what the software stores — but it is not legal advice. Fill in every bracketed field, and get advice specifically on Quebec's Law 25 and on whether you are a FINTRAC-regulated money services business, because both carry obligations this document alone does not satisfy.

1. Who is accountable

NorthVault is operated by [operator legal name], a [province] [corporation / sole proprietorship] with its head office at [registered address].

As required by the Personal Information Protection and Electronic Documents Act (PIPEDA), we have designated an individual accountable for our compliance:

  • Privacy Officer: [name], [privacy@yourdomain.ca], [phone]

If you are in Quebec, this person also serves as the Person in Charge of the Protection of Personal Information under Quebec's Law 25.

2. Which laws apply

We handle personal information in accordance with PIPEDA and, where applicable, the provincial private-sector privacy laws of Quebec (Law 25), Alberta (PIPA) and British Columbia (PIPA), together with Canada's Anti-Spam Legislation (CASL) for any commercial electronic messages we send you.

3. What we collect and why

We collect only what the service needs to function. We do not sell personal information, and we do not disclose it for a purpose you have not consented to.

Account information

  • Your email address and display name — to identify your account and contact you about it.
  • A scrypt hash of your password with a per-account salt. The password itself is never stored or logged.
  • Display currency, theme and privacy preferences, and your role on the service.
  • If you enable two-factor authentication: a shared secret used to verify your codes, and hashes of your unused recovery codes.

Wallet information

  • Your balance in each supported asset.
  • The transfer identifiers issued to your account.
  • Every transaction: type, asset, amount, counterparty, any memo you write, and when it happened — needed to maintain an accurate ledger and to meet record-keeping obligations.
  • Saved recipients in your address book, and your watchlist.

Identity verification information (KYC)

Before you can send or swap, we are required to identify you. This is collected under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and its regulations, and consent is not required for a collection the law compels — but you are entitled to know exactly what it is:

  • Your full legal name, date of birth and occupation or principal business.
  • Your residential address in Canada.
  • The method used to identify you, and — where the government photo identification method is used — the type of document, its number, the jurisdiction that issued it and its expiry date.
  • The intended purpose of your account and the source of the funds or assets you expect to hold.
  • Your answers to the determinations we are obliged to make: whether you are a politically exposed person or the head of an international organisation, and whether anyone else is instructing you or benefiting from the account.
  • A record of each decision made about your verification, when it was made and which administrator made it, and a risk rating we assign.

We do not store images or scans of your documents. We record the prescribed details of the document and who confirmed them. Refusing to provide this information means we cannot let you send or swap; you can still hold and view an account.

This information is visible only to administrators, is used only for identification, sanctions and anti-money-laundering purposes and to respond to lawful demands, and is never used for marketing.

Access and security information

  • Active sessions, each recording the browser and operating system reported by your device, the IP address it connected from, and when it was last used.
  • Sign-in attempts — successful and failed — with the outcome, IP address and time. This is what lets you spot access you do not recognise, and it is collected for security purposes as permitted under paragraph 7(1)(b) of PIPEDA.

If you contact us

  • Your name, email, subject, message and originating IP address.

4. Consent

By creating an account you consent to the collection, use and disclosure described here. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice — but withdrawing consent for information the service needs to operate means we can no longer provide you an account.

5. What we do not collect

  • No advertising or analytics trackers, and no third-party cookies.
  • No payment card or bank account details.
  • No private keys or recovery phrases. The service does not hold cryptographic keys on your behalf.
  • No images, scans or photographs of your identity documents — only the prescribed details described in section 3.
  • No biometric information: no facial scans, no liveness recordings, no fingerprints.
  • No credit report is pulled unless you choose the Canadian credit file verification method, and then only to confirm your name, address and date of birth. [Confirm this with your credit bureau agreement before you enable that method.]

6. Cookies

One cookie is set: a session token, so you stay signed in. It is httpOnly (unreadable by scripts), same-site, and marked Secure in production. Only a hash of it is stored on our side, so the session table is useless to anyone who obtains it. A second short-lived cookie appears during two-factor sign-in and is deleted immediately afterwards. Neither is used for tracking or advertising.

7. Service providers and cross-border storage

PIPEDA requires us to tell you when your information may be processed outside Canada, and that while it is outside Canada it may be accessible to the courts, law enforcement and national security authorities of that country.

  • Hosting: [hosting provider], with servers located in [country/region]. Your account data is stored there.
  • Market data — CoinGecko: price requests are made by our server, not your browser, so CoinGecko receives no information about you. Coin images are fetched and re-served by us for the same reason.

We remain accountable for personal information transferred to a service provider for processing, and use contractual means to require a comparable level of protection.

Disclosure to authorities. Separately from service providers, we may be required to report to FINTRAC — for example suspicious transactions, large virtual currency transactions, or a match against a terrorist property list — and to respond to a subpoena, production order or search warrant. Where a report of that kind is made, the law may prohibit us from telling you about it.

8. Retention

  • Account, balance and transaction records: for as long as the account exists and then at least five years, which is the retention period the PCMLTFA regulations impose on transaction and client records.
  • Identity verification records and the decisions made on them: at least five years after the account is closed. This is a legal obligation and it survives a request to delete your account — we will delete everything we are permitted to delete and tell you what we must keep, and why.
  • Sessions: until you sign out, revoke them, or they expire after 7 days.
  • Sign-in history: [state your period]
  • Contact messages: [state your period]

9. Your rights

Under PIPEDA and the provincial regimes you may:

  • Access the personal information we hold about you, and be told how it has been used and to whom it has been disclosed. We respond within 30 days, as PIPEDA requires.
  • Correct information that is inaccurate or incomplete. Name, currency and preferences are editable yourself in Settings.
  • Withdraw consent and ask us to delete your account. Deletion removes your sessions, contacts and watchlist. Transaction and identity verification records are retained for the period described in section 8 because the law requires it; consent cannot be withdrawn from a collection the law compels.
  • Portability — your full transaction history is downloadable as CSV from Settings → Your data. Quebec residents have a specific right to receive computerised personal information in a structured, commonly used format.
  • Complain to us first. If you are not satisfied you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca, 1-800-282-1376), or to your provincial regulator: the Commission d'accès à l'information in Quebec, or the Information and Privacy Commissioner in Alberta or British Columbia.

10. Automated decisions

We do not use your personal information to make decisions about you based exclusively on automated processing. Identity verification decisions are made by a person, not by a system. You are told the outcome, and when it is not an approval you are told the reason and may submit again. Rate limiting temporarily slows repeated sign-in attempts from one address or against one account; it is a security control, not a decision about you, and it clears on a successful sign-in.

11. Safeguards

Passwords are hashed with scrypt and compared in constant time. Sessions are 256-bit random tokens, stored only as hashes. Sign-in is rate limited per account and per IP address. Suspending an account revokes its sessions immediately, and changing a password signs it out everywhere. The security guide describes this in more detail.

12. Breach reporting

If a breach of our security safeguards creates a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada, notify you as soon as feasible, and keep a record of the breach, as PIPEDA requires. Quebec residents will be notified in accordance with Law 25.

If you believe your account has been accessed without permission, change your password and revoke the other sessions from Settings → Security immediately, then tell us.

13. Children

The service is not directed at anyone under the age of majority in their province, and we do not knowingly collect their personal information.

14. Language

[If you serve Quebec residents, the Charter of the French Language requires a French version of this policy and of your contractual terms. Have one prepared.]

15. Changes

Material changes will be reflected in the date at the top of this page, and we will notify account holders where the law requires it.