Privacy Policy

Last Updated: January 15, 2025

At zoviantha, we know that trust matters when you're managing something as personal as your finances. This privacy policy explains how we handle information about you when you use our expense budgeting platform.

We're based in Victoria, BC, and operate under Canadian privacy laws—specifically PIPEDA (Personal Information Protection and Electronic Documents Act). That means we follow strict guidelines about collecting, using, and protecting your data.

What Information We Collect

Running an expense budgeting service means we need certain information to make the platform work for you. Here's what we gather and why:

Account Information

Your name, email address, phone number, and password. We need this to set up your account and communicate with you about your budgeting tools.

Financial Data

Expense categories, budget amounts, spending patterns, and transaction descriptions you enter. This is the core of what makes our budgeting service useful to you.

Usage Information

How you interact with our platform—which features you use, when you log in, what devices you're using. This helps us improve the experience and spot any technical issues.

Technical Data

IP addresses, browser types, device identifiers, and operating systems. Standard stuff that helps keep our service secure and functioning properly.

Information You Provide Directly

Most of what we collect comes straight from you. When you create an account, add expenses, set budget goals, or contact our support team, you're actively sharing that information with us. You're in control of what you enter into the system.

Automated Collection

Some data gets collected automatically through cookies and similar technologies. We use these to remember your preferences, keep you logged in, and understand how people use different features. You can control cookie settings through your browser, though some features might not work as smoothly if you block them entirely.

How We Use Your Information

We're pretty straightforward about this. Your information serves specific purposes related to providing and improving our budgeting service.

  • Running the actual expense tracking and budgeting features you signed up for
  • Sending you notifications about your account, budget alerts, and service updates
  • Responding when you reach out to our support team with questions or issues
  • Analyzing usage patterns to figure out what's working and what needs improvement
  • Protecting against fraud, unauthorized access, and other security threats
  • Meeting our legal obligations under Canadian financial and privacy regulations
  • Developing new features based on how people actually use the platform

We don't sell your personal information to advertisers or marketing companies. That's not our business model. We make money by providing a useful budgeting service, not by trading in your data.

Sharing and Disclosure

We keep your information within our organization whenever possible. But there are a few situations where we share data with others:

Service Providers

We work with companies that help us run the platform—cloud hosting providers, email services, customer support tools, and analytics platforms. These providers only get access to the information they need to do their specific jobs, and they're contractually required to protect your data and not use it for their own purposes.

Legal Requirements

Sometimes we're legally required to share information. If a court issues a valid order, if law enforcement makes a proper request, or if we need to comply with Canadian regulatory requirements, we'll share what's necessary. We'll notify you about these requests unless we're legally prohibited from doing so.

Business Transfers

If zoviantha gets acquired or merges with another company, your information would likely be part of that transaction. We'd notify you before your data gets transferred and becomes subject to a different privacy policy.

With Your Consent

For anything outside these categories, we'll ask your permission first. You'll always know when we're planning to share your information and for what purpose.

Your Privacy Rights Under Canadian Law

PIPEDA gives you specific rights regarding your personal information. These aren't just theoretical—you can actually exercise them, and we'll help you do it.

What You Can Do With Your Data

Access Your Information

Request a copy of all personal data we hold about you. We'll provide it in a readable format within 30 days. There's no charge for reasonable requests, though we might charge a small fee if you're making repeated or clearly excessive requests.

Correct Inaccuracies

If something in your profile or records is wrong, you can ask us to fix it. Most information you can update yourself through your account settings, but reach out if you need help with something you can't change directly.

Delete Your Data

Request that we delete your personal information. We'll do this unless we have a legitimate legal reason to keep it—like records we're required to maintain for tax purposes. We'll explain if there's anything we can't delete and why.

Withdraw Consent

If we're processing your data based on consent, you can take that consent back. This won't affect any processing that already happened, but we'll stop going forward. Keep in mind this might limit what features you can use.

Object to Processing

Challenge how we're using your information if you think it's not appropriate. We'll review your objection and either stop that processing or explain why we believe it's necessary and lawful.

Data Portability

Get your data in a structured, commonly used format that you can transfer to another service. Useful if you're switching to a different budgeting platform and want to take your history with you.

File a Complaint

If you're unhappy with how we've handled your information, you can complain to the Office of the Privacy Commissioner of Canada. We'd prefer you contact us first so we can try to resolve the issue, but you have the right to go directly to the regulator.

To exercise any of these rights, email us at contact@zoviantha.world with details about what you're requesting. We'll verify your identity—usually by confirming details associated with your account—and then process your request. Most requests get handled within 30 days.

How We Protect Your Information

Security isn't just about having the right technology. It's about processes, training, and taking protection seriously at every level.

Technical Safeguards

We encrypt data in transit using TLS protocols and at rest using industry-standard encryption algorithms. Our servers are housed in secure data centers with physical access controls. We use firewalls, intrusion detection systems, and regular security monitoring to watch for threats.

Passwords are hashed and salted—we never store them in plain text. Even our own staff can't see your actual password. If you forget it, we can only reset it, not retrieve the original.

Operational Practices

Access to user data is restricted based on role and necessity. Not everyone who works at zoviantha can see all user information. We log who accesses what and when, creating an audit trail.

Our team receives regular training on privacy practices and security protocols. We run background checks on employees who'll have access to sensitive systems. Contractors and partners sign agreements requiring them to protect data according to our standards.

What We Can't Protect Against

Let's be honest—no system is completely invulnerable. If you use a weak password, share your login credentials, or access your account on a compromised device, there are limits to what our security measures can do. We do our part, but account security is a shared responsibility.

If we ever experience a data breach that affects your information, we'll notify you promptly and let you know what happened, what data was involved, and what steps we're taking. We'll also report to the Privacy Commissioner as required by law.

How Long We Keep Your Data

We don't keep information longer than necessary. Different types of data have different retention periods based on legal requirements and practical needs.

Retention Periods

Active Account Data

While your account is active, we keep your profile information and financial data. This includes all the expenses, budgets, and categories you've created. You need this history to use the service effectively.

After Account Closure

When you close your account, we delete most personal information within 90 days. We might keep some records longer if required for legal, tax, or audit purposes—typically not more than seven years for financial records.

Communication Records

Support conversations and email correspondence are kept for three years. This helps us track ongoing issues and maintain service quality records.

Aggregated Analytics

We may keep anonymized, aggregated data indefinitely for statistical analysis and platform improvement. This data can't be traced back to individual users.

You can request deletion of your data at any time by contacting us. We'll honor that request subject to any legal obligations to retain certain records.

International Data Transfers

Our servers are located in Canada, and we process most data domestically. However, some of our service providers operate infrastructure in other countries, including the United States.

When data leaves Canada, we ensure appropriate safeguards are in place. This includes contractual commitments, participation in recognized data protection frameworks, and technical measures like encryption. Your data receives strong protection regardless of where it's physically stored.

Under PIPEDA, we're responsible for personal information even when it's being processed by third parties on our behalf. If a service provider mishandles your data, we're accountable for that.

Children's Privacy

zoviantha isn't designed for children under 13, and we don't knowingly collect information from them. Our service is intended for adults managing their own finances.

If we discover that we've accidentally collected information from a child under 13, we'll delete it promptly. If you're a parent and believe your child has provided us with personal information, please contact us so we can address it.

Changes to This Policy

Privacy practices and legal requirements evolve. We'll update this policy periodically to reflect changes in our practices or legal obligations.

When we make significant changes, we'll notify you by email or through a prominent notice in the platform before the changes take effect. We'll also update the "Last Updated" date at the top of this policy.

Continued use of zoviantha after changes become effective means you accept the updated policy. If you disagree with changes, your option is to stop using the service and close your account.

Cookies and Tracking Technologies

We use cookies—small text files stored on your device—to make the platform work properly and remember your preferences.

Types of Cookies We Use

Essential cookies keep you logged in and remember your settings. These are necessary for the service to function. Analytics cookies help us understand how people use different features. Preference cookies remember choices you've made, like display settings or notification preferences.

You can control cookie settings through your browser, though blocking essential cookies will prevent you from using certain features. Most browsers let you choose whether to accept cookies, delete existing cookies, and get notified when websites set new ones.

Questions or Concerns?

If something in this policy isn't clear, or if you have questions about how we handle your information, we're here to help. Privacy matters, and we want you to feel confident about how your data is being managed.

Mail: 3751 Grange Rd, Victoria, BC V8Z 4T2, Canada

We typically respond to privacy inquiries within 48 hours during business days. For urgent security concerns, mark your message as high priority.

Contact Our Team