Privacy Policy
Last updated: April 2025
1. Who We Are
Claimable ("we", "us", "our") is a Canadian software service that helps self-employed Canadians identify tax-deductible expenses from their bank statements. We are subject to the Personal Information Protection and Electronic Documents Act (PIPEDA).
2. Information We Collect
- Account information: name, email address, and hashed password.
- Bank statement data: transaction descriptions, dates, and amounts from files you upload. We do not collect your account numbers or bank credentials.
- Occupation context: your stated occupation, employment type, and province — used solely to tailor CRA deduction analysis.
- Usage data: scan history, analysis results, and notes you add to expenses.
3. How We Use Your Information
- To provide the tax deduction analysis service.
- To send transactional emails (account verification, password reset).
- To process payments via Stripe (we never store your card details).
- To improve our merchant classification models using aggregated, anonymized data.
4. AI Processing
Transaction data is sent to Anthropic's Claude API for analysis. Anthropic does not use your data to train its models under our API agreement. You can enable the "Anonymize" option in the scan wizard to strip recognizable merchant names before transmission.
5. Data Retention
Your account and scan data is retained for as long as your account is active. You may delete your account at any time from Settings, which permanently deletes all associated data within 30 days.
6. Third-Party Services
- Neon (database hosting): data stored in US-East AWS region.
- Anthropic: AI analysis — data processed under API terms.
- Stripe: payment processing — subject to Stripe's privacy policy.
- Resend: transactional email delivery.
7. Your Rights Under PIPEDA
You have the right to access, correct, or request deletion of your personal information. To exercise these rights, email us at privacy@claimable.ca. We will respond within 30 days.
8. Security
We use HTTPS encryption in transit and bcrypt password hashing. Bank statement files are processed in memory and never written to disk.
9. Contact
Questions about this policy? Email privacy@claimable.ca.