At BudgetOwl, security is our top priority. We use industry-leading practices and trusted third-party providers to ensure your financial data is protected at every step. This page outlines our security measures and your rights regarding your data.
Data Encryption
- •All data transmitted between your browser and our servers is encrypted using TLS 1.3 (HTTPS).
- •All data stored in our database is encrypted at rest using AES-256 encryption.
- •Bank credentials are never stored. We use Plaid's secure tokenization system.
Infrastructure Security
- •BudgetOwl is hosted on Google Cloud Platform (Firebase), which maintains SOC 2 Type II, ISO 27001, and PCI DSS compliance.
- •Our infrastructure is monitored 24/7 with automatic threat detection.
- •All administrative access requires multi-factor authentication (MFA).
Access Controls
- •Access to production systems is limited to authorized personnel only.
- •Role-based access controls (RBAC) ensure employees only access data necessary for their role.
- •All access is logged and audited regularly.
Bank Connection Security
- •We use Plaid to securely connect to your bank, a service trusted by thousands of financial apps.
- •We never see or store your bank login credentials.
- •You can disconnect your bank at any time from your settings.
Incident Response
- •We have documented procedures for responding to security incidents.
- •In the event of a breach that creates a real risk of significant harm, we will notify affected users as soon as feasible and report to the Office of the Privacy Commissioner of Canada where required.
- •We maintain records of all security incidents for at least 24 months as required by PIPEDA.
Data Retention & Deletion
- •We retain your data only as long as your account is active, plus any period required for legal or regulatory obligations.
- •You can request deletion of all your data at any time by contacting support.
- •When you delete your account, all associated data is permanently removed within 30 days, except where retention is required by law.
Compliance & Your Rights
- •We comply with applicable data protection regulations, including PIPEDA (Canada).
- •We leverage third-party providers (Google Cloud, Plaid) that maintain certifications including SOC 2 Type II, ISO 27001, and PCI DSS.
- •You have the right to access, correct, or request deletion of your personal information. Contact us at security@budgetowl.ca.
Questions or concerns? Contact us at security@budgetowl.ca
Last updated: January 2026