Legal
Privacy policy
This policy explains what Setttle collects, why we collect it, who processes it, and how you can exercise your rights over it.
- Effective
- 1 September 2026
- Reviewed
- September 2026
1. What this covers
Countback Inc. operates Setttle. This policy covers the Setttle web app, the marketing site, and the Setttle API. It applies to the personal and financial information we process to run the service, and it is written for a Canadian context, including the Personal Information Protection and Electronic Documents Act (PIPEDA).
When you use Setttle for a business, your business is usually the controller of the financial records and we are the processor acting on its behalf.
2. What we collect
We collect only what the product needs to work:
- Account information — your name, email, and authentication details.
- Financial records you create or import — invoices, bills, receipts, journal entries, accounts, and their audit history.
- Bank activity — transactions from accounts you choose to connect, and the connection metadata needed to sync them.
- Payment information — handled by Stripe. We retain payment, fee, refund, and payout facts for reconciliation; we do not store full card numbers.
- Support and security data — messages you send us, and technical logs we need to operate and protect the service.
3. How we use it
We use your information to provide bookkeeping, reconciliation, billing, and support; to secure the service and investigate abuse; to meet legal and accounting obligations; and to send you service messages such as receipts, reminders you configure, and material changes to the product or these policies.
AI features process the information needed for the suggestion: uploaded receipts and customer invoices for extraction, and connected bank transactions with relevant account, rule, and transaction history for coding suggestions and short titles. Bank suggestions may run automatically after a sync. This information can include names, descriptions, dates, and amounts. Suggestions remain reviewable before they change your books.
We do not log financial contents merely to calculate product analytics. Where we need operational logs, we keep them free of access tokens, secrets, passwords, and unnecessary financial detail.
4. What we don't do
- We do not sell your personal or financial information.
- We do not use your financial records to train AI models.
- We do not run third-party advertising or tracking on the marketing site.
- We do not turn missing evidence into a confident default.
6. Bank connections
Bank connections use Plaid and Transactions only. Provider credentials are stored server-side, encrypted with authenticated AES-256-GCM, and are never returned to the browser or written to logs in plaintext.
When you disconnect a bank, the provider connection is removed and the stored credentials are deleted immediately. Imported transactions remain available for a 90-day review window. After that, scheduled cleanup removes unreviewed, unmatched transactions and provider-only connection details. For reviewed or matched transactions needed for your accounting history, we keep the date, description, amount, currency, and reconciliation links while removing raw provider data and external identifiers.
7. Security
Data is protected in transit with TLS and at rest by our providers. Access follows least privilege, with row-level security isolating each company's books and a service-role-only boundary around encrypted provider credentials.
The security page describes these controls in more detail, including how to report a vulnerability.
8. Retention and deletion
Cancelling a subscription leaves company records readable and exportable. The company owner can delete them after disconnecting bank and payment services, downloading a recent complete export that includes source documents and metadata, and entering its confirmation code. Deletion removes the company's database records and stored files; failed file removals are retried. Providers and backups may retain information under their own schedules or legal obligations.
We document deletion and retention exceptions and limit them to their required purpose.
9. Your rights
Subject to applicable law, you can request access to your personal information, ask us to correct it, ask for a portable export, and ask us to delete it or withdraw consent for optional processing.
Access, correction, deletion, and privacy complaints go to Countback Inc.'s privacy officer at hi@setttle.ca. We will verify the request, act within the time the law allows, and tell you what we did.
11. Where data is processed
Our providers may process data in Canada, the United States, and other countries where they operate. Where information crosses a border, we rely on the provider's contractual protections and our provider review process.
12. Changes and contact
We will tell you before a material change to this policy takes effect. Questions and requests go to hi@setttle.ca.
Get your books settled
If you have a privacy question, ask before you sign up.
7-day Max trial · no credit card required