Back

Security

How we protect your data

At BudgetOwl, security is our top priority. We use industry-leading practices and trusted third-party providers to ensure your financial data is protected at every step. This page outlines our security measures and your rights regarding your data.

Data Encryption
  • All data transmitted between your browser and our servers is encrypted using TLS 1.3 (HTTPS).
  • All data stored in our database is encrypted at rest using AES-256 encryption.
  • Bank credentials are never stored. We use Plaid's secure tokenization system.
Infrastructure Security
  • BudgetOwl is hosted on Google Cloud Platform (Firebase), which maintains SOC 2 Type II, ISO 27001, and PCI DSS compliance.
  • Our infrastructure is monitored 24/7 with automatic threat detection.
  • All administrative access requires multi-factor authentication (MFA).
Access Controls
  • Access to production systems is limited to authorized personnel only.
  • Role-based access controls (RBAC) ensure employees only access data necessary for their role.
  • All access is logged and audited regularly.
Bank Connection Security
  • We use Plaid to securely connect to your bank, a service trusted by thousands of financial apps.
  • We never see or store your bank login credentials.
  • You can disconnect your bank at any time from your settings.
Incident Response
  • We have documented procedures for responding to security incidents.
  • In the event of a breach that creates a real risk of significant harm, we will notify affected users as soon as feasible and report to the Office of the Privacy Commissioner of Canada where required.
  • We maintain records of all security incidents for at least 24 months as required by PIPEDA.
Data Retention & Deletion
  • We retain your data only as long as your account is active, plus any period required for legal or regulatory obligations.
  • You can request deletion of all your data at any time by contacting support.
  • When you delete your account, all associated data is permanently removed within 30 days, except where retention is required by law.
Compliance & Your Rights
  • We comply with applicable data protection regulations, including PIPEDA (Canada).
  • We leverage third-party providers (Google Cloud, Plaid) that maintain certifications including SOC 2 Type II, ISO 27001, and PCI DSS.
  • You have the right to access, correct, or request deletion of your personal information. Contact us at security@budgetowl.ca.

Questions or concerns? Contact us at security@budgetowl.ca

Last updated: January 2026