We believe in transparency. This policy explains exactly how we handle your personal and financial information.
Last updated: March 3, 2026
At ModuFi Inc. (“we,” “our,” or “us”), your privacy is important. This Privacy Policy explains how we collect, use, store, and share your personal and financial information when you use our budgeting app and website (the “Service”). By creating an account or using the Service, you agree to the practices described here. We only collect personal information that is necessary for the purposes identified in this policy.
On this page
ModuFi Inc.
1A, 153 Pembina Road
Sherwood Park, Alberta T8H 0B9
Canada
Krystina Garcha, Privacy Officer
Our Privacy Officer is responsible for overseeing compliance with this Privacy Policy and applicable privacy legislation, including PIPEDA, Alberta PIPA, and Quebec Law 25. You can contact our Privacy Officer with any questions, concerns, or requests related to your personal information.
The Service is intended for users 18 years or older. Users under 18 may only participate as part of a household account added by a parent or guardian. Minors cannot link bank accounts or provide financial information. Parents/guardians must provide express consent when adding minors.
Quebec Residents
Under Quebec Law 25, the age of consent for personal information is 14. Minors under 14 in Quebec require consent from a parent or tutor. Minors aged 14–17 may provide their own consent but may only access the Service via a household account.
US Residents
Under COPPA, children under 13 in the United States require verifiable parental consent before any personal information is collected. Parents may review, request deletion of, and prevent further collection of their child's information.
The Service is primarily available to residents of Canada and is subject to applicable provincial and federal privacy laws. US residents may also use the Service, subject to applicable US privacy laws.
We collect information necessary to provide the Service. The purposes for each category are identified at or before the time of collection. We will not use your information for purposes beyond those identified without obtaining your consent.
Account Information
Full name, email address, and date of birth. Your account is managed through AWS Cognito, which securely handles your password and authentication credentials — we do not store passwords in our database. If you sign in with Google, we receive your name and email from Google OAuth.
Consent: Express consent at account creation
Financial / Banking Data
Transaction history, account balances, credit card and investment accounts accessed via tokenized connections through Plaid. We do not store bank login credentials. Plaid access tokens are encrypted using AES-256-GCM encryption before storage.
Consent: Express consent when linking accounts
Payment Information
Subscriptions processed via Stripe. Credit card numbers are stored only by Stripe — we do not have access to your full card number.
Consent: Express consent at subscription
Technical & Analytics Data
IP address, device information, browser type, cookies, and usage data collected via MixPanel and Google Analytics. This data may be used to identify usage patterns and improve the Service.
Consent: Implied consent with opt-out available
Waitlist Information
Name, email address, referral source, and referral code collected when you join our waitlist.
Consent: Express consent at signup
Support Communications
Emails and chat logs from your interactions with our team.
Consent: Implied consent when contacting us
We obtain your consent before collecting, using, or disclosing your personal information. The type of consent depends on the sensitivity of the information:
Express Consent
Required for sensitive information, including financial and banking data, payment information, and marketing communications. You actively opt in through clear, affirmative actions.
Implied Consent
May apply for less sensitive information such as technical data, analytics cookies, and support communications where consent can reasonably be inferred from your actions.
Withdrawing Consent
You may withdraw your consent at any time by contacting us at privacy@modufi.ca. Please note that withdrawing consent may limit our ability to provide certain features of the Service. For example, withdrawing consent for financial data collection would prevent the Service from displaying your account balances and transactions. We will explain the consequences before processing your withdrawal.
We use your information to:
We will not use your personal information for new purposes beyond those listed above without first obtaining your consent.
Primary Data Storage: Canada
Your data is stored in AWS infrastructure located in the Canada (Central) region (ca-central-1). Our database, authentication services, and application hosting all reside in Canada.
Data Transferred to the United States
Some third-party providers process data in the United States, including Plaid (bank connections), Stripe (payments), Resend (email), MixPanel (analytics), and Google (analytics and OAuth). Data transferred to the US may be subject to US laws, including potential government access requests.
We ensure that contractual safeguards are in place with each provider to protect your information to a standard comparable to Canadian law. We conduct privacy impact assessments for cross-border transfers as required under Quebec Law 25.
We retain personal information only as long as necessary for the purposes for which it was collected:
When you delete your account, all associated personal and financial data is permanently removed from our database, including linked accounts, transactions, and encrypted Plaid tokens. Your authentication credentials are also deleted from AWS Cognito.
You may request deletion of your personal information at any time by contacting privacy@modufi.ca. We will respond to deletion requests within 30 days.
We implement administrative, technical, and physical safeguards appropriate to the sensitivity of the financial data we handle:
We strive to keep your personal information accurate, complete, and up-to-date. While no system is completely secure, we take reasonable measures to protect your data against unauthorized access, disclosure, alteration, or destruction.
Users under 18 may only access the Service via a household account controlled by a parent or guardian. When a parent or guardian adds a minor to their household account, they provide express consent on the minor's behalf.
Minors cannot link bank accounts, provide financial information, or make payments. Parents and guardians may review, request correction of, request deletion of, and prevent further collection of their minor's personal information at any time by contacting privacy@modufi.ca.
Quebec (Law 25)
The age of consent for personal information is 14. Minors under 14 require consent from a parent or tutor.
United States (COPPA)
Children under 13 require verifiable parental consent before any personal information is collected.
In the event of a breach of security safeguards involving your personal information that poses a real risk of significant harm, we will:
Under PIPEDA and Alberta PIPA, Canadian users have the right to:
We will respond to access and correction requests within 30 days.
Additional Rights for Quebec Residents (Law 25)
To exercise any of your rights, contact our Privacy Officer at privacy@modufi.ca.
If you are a resident of the United States, you may have additional privacy rights depending on your state of residence.
California Residents (CCPA/CPRA)
If you are a California resident, you have the right to:
Residents of other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Texas, and Oregon) may have similar rights to access, delete, and correct their personal information, as well as the right to opt out of targeted advertising. To exercise any of these rights, contact us at privacy@modufi.ca. We will respond to verifiable consumer requests within 45 days.
We comply with Canada's Anti-Spam Legislation (CASL) for all commercial electronic messages.
Transactional emails (account confirmations, security alerts, billing receipts) are not commercial messages under CASL and do not require separate consent.
If you believe your personal information has been handled in a manner that does not comply with this Privacy Policy or applicable privacy legislation, you may:
Step 1: Contact Us
Submit your complaint to our Privacy Officer at privacy@modufi.ca. We will acknowledge receipt and investigate. You can expect a response within 30 days.
Step 2: Escalate if Unresolved
If you are not satisfied with our response, you may escalate your complaint to the appropriate regulatory authority:
We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent version. For material changes that affect how we handle your personal information, we will notify you via email or through a prominent notice in the Service at least 30 days before the changes take effect.
By creating an account, you provide express consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy. For sensitive information such as financial data, we obtain additional express consent at the point of collection (e.g., when you link a bank account or subscribe to a paid plan).
Parents and guardians must accept this Privacy Policy and provide express consent on behalf of any minors added to a household account.
Questions?
If you have any questions about this Privacy Policy or want to exercise your privacy rights, reach out to our Privacy Officer.
privacy@modufi.ca