Privacy Policy
Last updated: March 7, 2026
CDL Accounting Solutions ("we", "us", or "our") is committed to protecting the privacy of our clients and users. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information in connection with our bookkeeping services and our Receipt Control™ client portal (portal.cdlaccounting.ca).
By using our services or client portal, you agree to the collection and use of information as described in this policy.
1. Information We Collect
We collect the following types of information:
- Account information: Name, email address, and password (stored securely via Supabase authentication).
- Business profile information: Fiscal year end, HST/GST registration status, payroll status, and HST filing frequency — used to tailor your month-end checklist and CRA deadline reminders.
- Financial documents: Receipts, invoices, and other supporting documents you upload through Receipt Control™ or the client portal. These are stored in your dedicated Google Drive folder.
- Transaction data: With your authorization, we may access your QuickBooks Online account data (transactions, accounts, vendors) through the Intuit QuickBooks API to match receipts to transactions and identify missing documentation.
- Usage data: Basic analytics collected by Cloudflare Web Analytics (no cookies, no personal tracking) to help us improve the website.
2. How We Use Your Information
We use the information we collect to:
- Provide bookkeeping and accounting services to you
- Operate and maintain the Receipt Control™ portal and client dashboard
- Upload and organize your receipts and financial documents in Google Drive
- Match receipts to QuickBooks Online transactions (with your authorization)
- Generate month-end checklists and CRA deadline reminders based on your business profile
- Communicate with you about your account, missing documents, or service updates
- Comply with applicable Canadian tax and accounting regulations
3. Third-Party Services
We use the following third-party services to operate our platform. Each has its own privacy policy governing the data they handle:
- Supabase — Authentication and database hosting for the client portal. Data is stored in Canada/US regions. Supabase Privacy Policy.
- Google Drive & Google Workspace — Secure storage of your uploaded receipts and financial documents. Google Privacy Policy.
- Intuit QuickBooks Online — With your explicit authorization, we connect to your QuickBooks Online account via the Intuit API to retrieve transaction data and attach receipts. We do not store your QuickBooks credentials. Access can be revoked at any time through your Intuit account settings. Intuit Privacy Statement.
- Vercel — Hosting for the client portal. Vercel Privacy Policy.
- Netlify — Hosting for Receipt Control™ upload functions. Netlify Privacy Policy.
- Cloudflare — DNS, CDN, and privacy-preserving web analytics. Cloudflare Privacy Policy.
4. QuickBooks Online Integration
Our integration with Intuit QuickBooks Online is subject to Intuit's Privacy Statement. Specifically:
- We access your QuickBooks Online data only with your explicit authorization via Intuit's OAuth 2.0 flow.
- We request only the permissions necessary to match receipts to transactions and identify unmatched items.
- We do not sell, rent, or share your QuickBooks data with any third party other than as required to provide our bookkeeping services.
- You may revoke our QuickBooks access at any time through your Intuit account at accounts.intuit.com.
5. Data Retention
We retain your personal information and financial documents for as long as you are an active client, and for a minimum of 7 years after the end of the engagement to comply with CRA and MRQ record-keeping requirements. Upon request, we will securely delete account data that is not subject to legal retention obligations.
6. Data Security
We implement industry-standard security measures including:
- Encrypted connections (HTTPS/TLS) for all data in transit
- Secure authentication with hashed passwords (via Supabase)
- Access controls limiting data access to authorized personnel only
- Google Drive folder permissions restricted to your account and our team
7. Your Rights (PIPEDA / Quebec Law 25)
As a Canadian resident, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your personal information (subject to legal retention obligations)
- Withdraw consent for data processing where applicable
- File a complaint with the Office of the Privacy Commissioner of Canada
To exercise any of these rights, contact us at the address below.
8. Cookies
The client portal uses session cookies strictly necessary for authentication. We do not use tracking cookies or third-party advertising cookies. The main website uses Cloudflare Web Analytics, which is cookieless and does not track individuals.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify active clients of material changes by email. The "Last updated" date at the top of this page reflects the most recent revision.
10. Contact Us
For privacy-related questions or requests:
CDL Accounting Solutions
Montreal, Quebec, Canada
Contact form