TaxMaker
Back to Home
Privacy Policy

Last updated: January 2026

Your Privacy Matters

At TaxMaker, we understand that your financial information is among the most sensitive personal data you possess. This Privacy Policy explains in detail how we collect, use, protect, and handle your information when you use our tax preparation services, financial calculators, and educational resources. We are committed to maintaining the highest standards of data protection and transparency.

Our Privacy Commitment

  • We never sell your personal information to third parties
  • Calculator inputs stay in your browser — we cannot see them
  • Your tax data is encrypted with bank-level security
  • You can request deletion of your data at any time
  • We are transparent about how we use your information

1. Information We Collect

We collect different types of information depending on how you interact with TaxMaker. Understanding what information we collect helps you make informed decisions about using our services. We follow the principle of data minimization, meaning we only collect information that is necessary to provide our services.

1.1 Account Information

When you create a TaxMaker account, we collect basic information necessary to identify you and provide our services:

  • Email Address: Used as your unique identifier, for account recovery, and to send important notifications about your tax returns and account security
  • Password: Stored using industry-standard bcrypt hashing with salt. We never store your password in plain text and cannot retrieve it
  • Name: Used to personalize your experience and pre-fill tax return information where applicable
  • Account Preferences: Your chosen currency, language preferences, and notification settings

1.2 Tax Return Information (For Tax Filing Services)

If you use our tax filing services for Canadian T1 (personal) or T2 (corporate) returns, we collect detailed financial information required by the Canada Revenue Agency:

  • Personal Identifiers: Social Insurance Number (SIN), date of birth, current and previous addresses, marital status, and citizenship status
  • Income Information: Employment income (T4 slips), self-employment income, investment income (T3, T5 slips), rental income, pension income, government benefits, and other sources of income
  • Deductions and Credits: RRSP contributions, childcare expenses, medical expenses, charitable donations, tuition fees, home office expenses, and other eligible deductions
  • Banking Information: If you opt for direct deposit of refunds, we collect your banking institution number, transit number, and account number
  • Dependent Information: Names, dates of birth, and relationships of dependents claimed on your return
  • Corporate Information (T2): Business number, corporation name, fiscal year end, shareholder information, financial statements, and corporate tax elections

1.3 Calculator Usage (No Collection)

Our financial calculators are designed with privacy in mind. When you use our compound interest calculator, budget calculator, retirement calculator, or any other financial tool:

  • All calculations are performed entirely in your browser using JavaScript
  • Your inputs are never transmitted to our servers
  • We do not track, store, or analyze any numbers you enter
  • Clearing your browser or closing the tab completely erases your calculations
  • We have no technical capability to access your calculator inputs

1.4 Automatically Collected Information

Like most websites, we automatically collect certain technical information when you visit TaxMaker:

  • Device Information: Browser type and version, operating system, screen resolution, and device type (desktop, mobile, tablet)
  • Usage Data: Pages visited, time spent on pages, links clicked, and general navigation patterns (anonymized)
  • IP Address: Used for security monitoring, fraud prevention, and approximate geographic location (country/region level only)
  • Referral Source: How you arrived at our website (search engine, direct link, referral)

2. How We Use Your Information

We use the information we collect for specific, legitimate purposes. We do not use your data in ways that are incompatible with the purposes for which it was collected, and we do not use your financial data for advertising or marketing purposes.

2.1 Providing Our Services

  • Calculate your tax obligations and potential refunds accurately
  • Generate completed tax return forms (T1, T2, and supporting schedules)
  • Enable NETFILE electronic filing with the Canada Revenue Agency
  • Store your tax returns securely for future reference and prior-year data import
  • Provide year-over-year comparisons and tax planning insights

2.2 Account Management and Security

  • Authenticate your identity when you log in
  • Send password reset emails when requested
  • Alert you to suspicious account activity or unauthorized access attempts
  • Maintain audit logs for security and compliance purposes
  • Protect against fraud, abuse, and unauthorized transactions

2.3 Communication

  • Send transactional emails (account confirmations, tax filing receipts, password resets)
  • Notify you of important tax deadlines relevant to your returns
  • Inform you of changes to our services or policies that affect you
  • Respond to your support requests and inquiries
  • Send our newsletter if you have explicitly opted in (you can unsubscribe anytime)

2.4 Service Improvement

  • Analyze anonymized, aggregated usage patterns to improve our platform
  • Identify and fix bugs, errors, and usability issues
  • Develop new features based on user needs and feedback
  • Optimize website performance and load times

3. Data Storage and Security

Protecting your financial information is our highest priority. We implement multiple layers of security to ensure your data remains safe from unauthorized access, breaches, and other security threats.

3.1 Encryption

  • In Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3, the latest and most secure transport protocol
  • At Rest: Your stored data is encrypted using AES-256 encryption, the same standard used by banks and government agencies
  • Sensitive Fields: Social Insurance Numbers and banking information receive additional encryption with separate encryption keys

3.2 Infrastructure Security

  • Our application is hosted on Vercel with enterprise-grade security certifications (SOC 2 Type II)
  • Database services are provided by Supabase with automatic backups and point-in-time recovery
  • All infrastructure is located in secure data centers with physical access controls
  • Regular security audits and penetration testing by independent third parties
  • DDoS protection and Web Application Firewall (WAF) to prevent attacks

3.3 Access Controls

  • Strict role-based access control limits employee access to user data
  • All access to production systems is logged and monitored
  • Multi-factor authentication required for all administrative access
  • Regular access reviews to ensure employees only have necessary permissions
  • Automatic session timeouts and secure session management

3.4 Incident Response

We maintain a comprehensive incident response plan. In the unlikely event of a security breach affecting your personal information, we will notify you within 72 hours as required by law and provide guidance on protective steps you can take.

4. Cookies and Tracking Technologies

We use a minimal set of cookies necessary to provide our services. We do not use invasive tracking technologies or share cookie data with advertisers.

4.1 Essential Cookies

These cookies are strictly necessary for the website to function and cannot be disabled:

  • Session Cookie: Keeps you logged in while using our service
  • Security Cookie: Helps prevent cross-site request forgery (CSRF) attacks
  • Preference Cookie: Remembers your selected currency and region

4.2 Analytics (Optional)

We use privacy-focused analytics to understand how our website is used. This helps us improve our services:

  • Analytics are anonymized and do not track individual users
  • We do not use Google Analytics or similar invasive tracking tools
  • No data is shared with advertising networks
  • You can opt out of analytics in your account settings

4.3 What We Do Not Use

  • No third-party advertising cookies or pixels
  • No social media tracking pixels (Facebook Pixel, etc.)
  • No cross-site tracking or fingerprinting
  • No sale of tracking data to data brokers

5. Third-Party Services

We use trusted third-party services to provide our platform. Each of these services has been evaluated for their security practices and compliance with privacy regulations.

  • Supabase (Database & Authentication): Provides secure database storage and user authentication. SOC 2 Type II certified. Data is stored in secure data centers with encryption at rest.
  • Vercel (Hosting): Hosts our web application with enterprise-grade security. SOC 2 Type II certified. Provides DDoS protection and edge network security.
  • Payment Processor (if applicable): Payment information is processed directly by our PCI-DSS compliant payment processor. We never store full credit card numbers on our servers.
  • Email Service: Transactional emails are sent through a secure email provider. Email content is encrypted in transit.

We have Data Processing Agreements (DPAs) with all third-party services that process personal data on our behalf. These agreements ensure they maintain the same high standards of data protection that we do.

6. Data Retention

We retain your data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required by law.

  • Account Information: Retained for as long as you maintain an active account
  • Tax Returns: Retained for 7 years after the tax year to comply with CRA record-keeping requirements and to allow you to access historical data
  • Deleted Account Data: Permanently deleted within 30 days of account deletion request, except where retention is required by law
  • Security Logs: Retained for 2 years for fraud prevention and security purposes
  • Communication Records: Support tickets and communications retained for 3 years to provide continuity of service

7. Your Rights

We respect your rights over your personal data. Depending on your location, you may have the following rights under applicable privacy laws including PIPEDA (Canada), GDPR (European Union), and CCPA (California):

  • Right to Access: Request a copy of all personal information we hold about you. We will provide this within 30 days of your request.
  • Right to Correction: Request correction of any inaccurate or incomplete personal information. You can also update most information directly in your account settings.
  • Right to Deletion: Request permanent deletion of your personal data. Note that we may need to retain certain information for legal compliance (e.g., tax records for CRA requirements).
  • Right to Data Portability: Export your tax return data in a machine-readable format (PDF, CSV) for use with other services.
  • Right to Withdraw Consent: Where processing is based on consent, you can withdraw that consent at any time. This does not affect the lawfulness of processing before withdrawal.
  • Right to Object: Object to processing of your personal data for certain purposes, including direct marketing.
  • Right to Restrict Processing: Request that we limit how we use your data while we address your concerns.

To exercise any of these rights, please contact us at privacy@taxmaker.ca. We will respond to your request within 30 days. We may ask you to verify your identity before processing certain requests.

8. Children's Privacy

TaxMaker is designed for adults and is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@taxmaker.ca. If we discover that we have collected personal information from a child under 18, we will delete that information promptly.

9. International Data Transfers

TaxMaker is based in Canada and our servers are primarily located in North America. If you access our services from outside Canada, please be aware that your information may be transferred to, stored, and processed in Canada.

We ensure that any international data transfers comply with applicable data protection laws. Where required, we use appropriate safeguards such as Standard Contractual Clauses approved by regulatory authorities to protect data transferred internationally.

10. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Notify you via email if you have an account with us
  • Display a prominent notice on our website
  • For significant changes affecting your rights, request your acknowledgment before continued use

We encourage you to review this Privacy Policy periodically. Your continued use of TaxMaker after any changes indicates your acceptance of the updated Privacy Policy.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, we are here to help. You can reach us through the following channels:

Privacy Inquiries: privacy@taxmaker.ca

General Support: hello@taxmaker.ca

Data Protection Officer: dpo@taxmaker.ca

Response Time: We aim to respond to all privacy-related inquiries within 5 business days

If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC) or your local data protection authority.

12. Regulatory Compliance

TaxMaker is committed to complying with all applicable privacy and data protection laws, including:

  • PIPEDA (Personal Information Protection and Electronic Documents Act): Canada's federal privacy law governing how private sector organizations collect, use, and disclose personal information
  • Provincial Privacy Laws: Including PIPA (Alberta), PIPEDA (British Columbia), and Quebec's Act Respecting the Protection of Personal Information in the Private Sector
  • GDPR (General Data Protection Regulation): For users accessing our services from the European Economic Area
  • CCPA (California Consumer Privacy Act): For California residents, providing additional privacy rights and consumer protections