Privacy Policy - TFSA Tracker

Effective date: October 5, 2026
Operated by: Eric Leslie, sole proprietor ("we", "us"), Ontario, Canada
Contact: support@mytfsa.app

What TFSA Tracker does

TFSA Tracker helps Canadians track their TFSA contribution room. You can enter contributions and withdrawals manually, or connect financial accounts so deposits and withdrawals are imported automatically.

Information we collect

Account information: your email address and a hashed password (managed by our authentication provider, Supabase). If you sign in with Google, we receive your email address from Google.

Profile information: your date of birth and the first year you became a Canadian tax resident. We use these only to calculate your TFSA contribution room.

Transaction information: contributions and withdrawals you enter manually, and transactions imported from accounts you connect (amounts, dates, and account identifiers).

Connected-account information: if you connect accounts, we store the institution name, account name, account type, and masked account number (last digits only), plus a secure access token used to keep the connection updated.

We do not collect your bank login credentials. Account connections are handled by Plaid (see below); your credentials go to your financial institution through Plaid and never touch our servers or the app.

How we use your information

To calculate and display your TFSA contribution room, excess warnings, and related estimates.

To import and display your transaction history from accounts you connect.

To operate, secure, and improve the app.

We do not sell your personal information. We do not use your information for advertising, and the app contains no advertising or third-party analytics SDKs.

Plaid

We use Plaid Inc. ("Plaid") to connect your financial accounts. By using TFSA Tracker to connect an account, you grant Plaid the right, power, and authority to act on your behalf to access and transmit your personal and financial information from the relevant financial institution, in accordance with Plaid's privacy policy: https://plaid.com/legal/#end-user-privacy-policy

Information we receive from Plaid about connected accounts is used only as described in this policy.

Service providers

We use Supabase (database and authentication hosting, data stored in Canada) and Apple (app distribution). These providers process information only to provide their services to us.

Data retention and deletion

You can disconnect a connected account at any time in Settings. Disconnecting deletes the Plaid connection and the transactions it imported. Manually entered transactions are not affected.

To delete your account and all associated data, contact us at support@mytfsa.app and we will delete it within 30 days, except where retention is required by law.

Access tokens for disconnected accounts are deleted and revoked with Plaid.

Security

Plaid secrets and account access tokens are stored server-side only, in access-controlled storage; they are never present in the app. Data is transmitted over TLS.

Your rights

You may access, correct, or request deletion of your personal information by contacting support@mytfsa.app. This policy is governed by the laws of Ontario and Canada, including PIPEDA.

Changes

We will post changes to this policy at this URL and update the effective date.

Contact

Eric Leslie - support@mytfsa.app