Your data, your rights

Privacy Policy

We believe in transparency. This policy explains exactly how we handle your personal and financial information.

Last updated: March 3, 2026

At ModuFi Inc. (“we,” “our,” or “us”), your privacy is important. This Privacy Policy explains how we collect, use, store, and share your personal and financial information when you use our budgeting app and website (the “Service”). By creating an account or using the Service, you agree to the practices described here. We only collect personal information that is necessary for the purposes identified in this policy.

1. Accountability

ModuFi Inc.

1A, 153 Pembina Road

Sherwood Park, Alberta T8H 0B9

Canada

Krystina Garcha, Privacy Officer

Our Privacy Officer is responsible for overseeing compliance with this Privacy Policy and applicable privacy legislation, including PIPEDA, Alberta PIPA, and Quebec Law 25. You can contact our Privacy Officer with any questions, concerns, or requests related to your personal information.

2. Who Can Use Our Service

The Service is intended for users 18 years or older. Users under 18 may only participate as part of a household account added by a parent or guardian. Minors cannot link bank accounts or provide financial information. Parents/guardians must provide express consent when adding minors.

Quebec Residents

Under Quebec Law 25, the age of consent for personal information is 14. Minors under 14 in Quebec require consent from a parent or tutor. Minors aged 14–17 may provide their own consent but may only access the Service via a household account.

US Residents

Under COPPA, children under 13 in the United States require verifiable parental consent before any personal information is collected. Parents may review, request deletion of, and prevent further collection of their child's information.

The Service is primarily available to residents of Canada and is subject to applicable provincial and federal privacy laws. US residents may also use the Service, subject to applicable US privacy laws.

3. Information We Collect

We collect information necessary to provide the Service. The purposes for each category are identified at or before the time of collection. We will not use your information for purposes beyond those identified without obtaining your consent.

Account Information

Full name, email address, and date of birth. Your account is managed through AWS Cognito, which securely handles your password and authentication credentials — we do not store passwords in our database. If you sign in with Google, we receive your name and email from Google OAuth.

Consent: Express consent at account creation

Financial / Banking Data

Transaction history, account balances, credit card and investment accounts accessed via tokenized connections through Plaid. We do not store bank login credentials. Plaid access tokens are encrypted using AES-256-GCM encryption before storage.

Consent: Express consent when linking accounts

Payment Information

Subscriptions processed via Stripe. Credit card numbers are stored only by Stripe — we do not have access to your full card number.

Consent: Express consent at subscription

Technical & Analytics Data

IP address, device information, browser type, cookies, and usage data collected via MixPanel and Google Analytics. This data may be used to identify usage patterns and improve the Service.

Consent: Implied consent with opt-out available

Waitlist Information

Name, email address, referral source, and referral code collected when you join our waitlist.

Consent: Express consent at signup

Support Communications

Emails and chat logs from your interactions with our team.

Consent: Implied consent when contacting us

5. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain the Service
  • Authenticate your identity via AWS Cognito and Google OAuth
  • Process payments and subscriptions via Stripe
  • Aggregate and display financial data from linked bank accounts via Plaid
  • Respond to support requests
  • Analyze usage patterns to improve and personalize the Service
  • Send transactional emails (account confirmations, billing receipts)
  • Send optional marketing communications via Resend (express opt-in only)

We will not use your personal information for new purposes beyond those listed above without first obtaining your consent.

6. Sharing Your Information

We do not sell personal or financial information.

We share information with trusted third-party service providers (processors) to operate the Service. ModuFi acts as the data controller — these providers process your data only on our behalf and under our instructions.

ProviderPurpose
AWS CognitoAuthentication & identity management
Google OAuthSocial sign-in
StripePayment processing
PlaidTokenized bank connections
AWS (ca-central-1)Cloud hosting & database
MixPanelProduct analytics
Google AnalyticsWebsite analytics
ResendTransactional & marketing emails

We may also disclose your personal information if required by law, regulation, legal process, or enforceable governmental request, or to protect the rights, property, or safety of ModuFi, our users, or the public.

7. Cross-Border Data Transfers

Primary Data Storage: Canada

Your data is stored in AWS infrastructure located in the Canada (Central) region (ca-central-1). Our database, authentication services, and application hosting all reside in Canada.

Data Transferred to the United States

Some third-party providers process data in the United States, including Plaid (bank connections), Stripe (payments), Resend (email), MixPanel (analytics), and Google (analytics and OAuth). Data transferred to the US may be subject to US laws, including potential government access requests.

We ensure that contractual safeguards are in place with each provider to protect your information to a standard comparable to Canadian law. We conduct privacy impact assessments for cross-border transfers as required under Quebec Law 25.

8. Data Retention & Deletion

We retain personal information only as long as necessary for the purposes for which it was collected:

Account & financial dataUntil you delete your account
Plaid access tokensUntil you unlink the account or delete your account
Transaction historyUntil you delete your account
Support communications3 years after last interaction
Analytics dataAs per MixPanel and Google Analytics retention settings
Waitlist entriesUntil the waitlist is closed or you request removal
Database backups7 days (automated, then permanently deleted)

When you delete your account, all associated personal and financial data is permanently removed from our database, including linked accounts, transactions, and encrypted Plaid tokens. Your authentication credentials are also deleted from AWS Cognito.

You may request deletion of your personal information at any time by contacting privacy@modufi.ca. We will respond to deletion requests within 30 days.

9. Security

We implement administrative, technical, and physical safeguards appropriate to the sensitivity of the financial data we handle:

  • All data is encrypted in transit using TLS/SSL
  • Plaid access tokens are encrypted at rest using AES-256-GCM encryption
  • Passwords are managed by AWS Cognito with industry-standard hashing — we never store or have access to your password
  • Database access is restricted and secured within AWS infrastructure
  • Authentication supports multi-factor authentication (MFA) via AWS Cognito
  • Payment card data is handled exclusively by Stripe and never touches our servers

We strive to keep your personal information accurate, complete, and up-to-date. While no system is completely secure, we take reasonable measures to protect your data against unauthorized access, disclosure, alteration, or destruction.

10. Cookies & Tracking

We use cookies and similar technologies on the Service. These fall into the following categories:

Essential Cookies

Required for the Service to function. These maintain your login session and authentication state via AWS Cognito. They cannot be disabled.

Analytics Cookies

Used by MixPanel and Google Analytics to understand how users interact with the Service, identify usage patterns, and improve features. These may identify, locate, or profile users based on browsing behaviour.

Marketing Cookies

Used to track engagement for marketing purposes and to measure the effectiveness of campaigns.

You can manage or disable analytics and marketing cookies through your browser settings. You may also opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on. Opting out of non-essential cookies does not affect the core functionality of the Service.

11. Minors

Users under 18 may only access the Service via a household account controlled by a parent or guardian. When a parent or guardian adds a minor to their household account, they provide express consent on the minor's behalf.

Minors cannot link bank accounts, provide financial information, or make payments. Parents and guardians may review, request correction of, request deletion of, and prevent further collection of their minor's personal information at any time by contacting privacy@modufi.ca.

Quebec (Law 25)

The age of consent for personal information is 14. Minors under 14 require consent from a parent or tutor.

United States (COPPA)

Children under 13 require verifiable parental consent before any personal information is collected.

12. Breach Notification

In the event of a breach of security safeguards involving your personal information that poses a real risk of significant harm, we will:

  • Notify affected individuals as soon as feasible, describing the nature of the breach, the information involved, and steps we are taking
  • Report the breach to the Office of the Privacy Commissioner of Canada (OPC)
  • Report the breach to the Office of the Information and Privacy Commissioner of Alberta (OIPC) where applicable
  • Notify the Commission d'accès à l'information du Québec (CAI) where Quebec residents are affected
  • Maintain records of all breaches for a minimum of 24 months, regardless of whether they meet the notification threshold

13. Your Privacy Rights (Canada)

Under PIPEDA and Alberta PIPA, Canadian users have the right to:

  • Access their personal information held by ModuFi
  • Request correction of inaccurate or incomplete information
  • Withdraw consent for the collection, use, or disclosure of their information
  • Request deletion of their account and personal information

We will respond to access and correction requests within 30 days.

Additional Rights for Quebec Residents (Law 25)

  • Right to data portability — receive your personal information in a structured, commonly used, machine-readable format (e.g., CSV or JSON)
  • Right to request anonymization or de-identification of your personal information as an alternative to deletion
  • Right to be informed about automated decision-making and profiling, including the logic involved
  • Right to understand how your personal information is used and the specific purposes for each use

To exercise any of your rights, contact our Privacy Officer at privacy@modufi.ca.

14. Your Privacy Rights (US)

If you are a resident of the United States, you may have additional privacy rights depending on your state of residence.

California Residents (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose
  • Request deletion of your personal information
  • Opt out of the sale or sharing of your personal information — we do not sell your data
  • Request correction of inaccurate personal information
  • Not be discriminated against for exercising your privacy rights

Residents of other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Texas, and Oregon) may have similar rights to access, delete, and correct their personal information, as well as the right to opt out of targeted advertising. To exercise any of these rights, contact us at privacy@modufi.ca. We will respond to verifiable consumer requests within 45 days.

15. Email Communications (CASL)

We comply with Canada's Anti-Spam Legislation (CASL) for all commercial electronic messages.

  • Marketing emails are only sent with your express opt-in consent
  • Every marketing email includes a clear and functional unsubscribe mechanism
  • Unsubscribe requests are processed within 10 business days
  • Unsubscribe links remain functional for at least 60 days after the message is sent
  • All emails identify ModuFi Inc. as the sender and include our mailing address
  • We maintain records of consent for commercial messages

Transactional emails (account confirmations, security alerts, billing receipts) are not commercial messages under CASL and do not require separate consent.

16. Complaints

If you believe your personal information has been handled in a manner that does not comply with this Privacy Policy or applicable privacy legislation, you may:

Step 1: Contact Us

Submit your complaint to our Privacy Officer at privacy@modufi.ca. We will acknowledge receipt and investigate. You can expect a response within 30 days.

Step 2: Escalate if Unresolved

If you are not satisfied with our response, you may escalate your complaint to the appropriate regulatory authority:

17. Changes to This Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent version. For material changes that affect how we handle your personal information, we will notify you via email or through a prominent notice in the Service at least 30 days before the changes take effect.

18. Acceptance

By creating an account, you provide express consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy. For sensitive information such as financial data, we obtain additional express consent at the point of collection (e.g., when you link a bank account or subscribe to a paid plan).

Parents and guardians must accept this Privacy Policy and provide express consent on behalf of any minors added to a household account.

Questions?

We're here to help with your privacy

If you have any questions about this Privacy Policy or want to exercise your privacy rights, reach out to our Privacy Officer.

privacy@modufi.ca