1. Introduction
Guardian Wallet is built to help people understand, control, and reduce unwanted subscription billing. We provide tools that may include subscription tracking, merchant-specific virtual-card controls, email aliases, renewal alerts, cancellation-assistance workflows, privacy controls, and related account-management features.
This Privacy Policy explains how Guardian Wallet Inc. and its affiliates, subsidiaries, and service providers, where applicable, collect, use, disclose, retain, protect, and otherwise handle personal information.
In this Privacy Policy, "Guardian Wallet," "we," "us," and "our" mean Guardian Wallet Inc. and, where applicable, its affiliates.
"Services" means our websites, mobile applications, browser extensions, dashboards, APIs, email-alias tools, subscription-management tools, merchant-specific virtual-card controls, cancellation-assistance workflows, notifications, analytics, customer-support channels, and related services.
"Personal Information" means information about an identifiable individual, including information that can identify an individual alone or in combination with other information.
"Issuer/Payment Partner" means the regulated bank, card issuer, payment service provider, processor, program manager, card network, account-linking provider, or other partner that provides card, payment, account-linking, transaction-processing, settlement, chargeback, or regulated financial services.
This Privacy Policy is designed to comply with applicable Canadian private-sector privacy laws, including the Personal Information Protection and Electronic Documents Act, substantially similar provincial privacy laws, Quebec privacy law, and other applicable privacy, consumer, electronic-commerce, payment, and anti-spam requirements.
2. Key Privacy Points
- Guardian Wallet handles sensitive information, including account, subscription, merchant, wallet, payment-control, alias, support, fraud-prevention, and connected-account information.
- Some features require sensitive permissions. If you connect a bank account, email account, payment account, app-store account, merchant account, or other third-party account, we or our authorized providers may access information from that account only as disclosed to you and authorized by you.
- Payment and card services are provided by partners. Guardian Wallet is not a bank or card issuer. If you use virtual-card or payment-control features, personal information may be collected and processed by the Issuer/Payment Partner under its own privacy policy and agreements.
- Email data is limited to Guardian Wallet features. If you connect an email account or use aliases, we use email data only to provide user-facing features such as subscription discovery, merchant identification, renewal alerts, cancellation assistance, alias forwarding, and account support. We do not sell email data or use email content for advertising.
- We do not sell your personal information to data brokers or third parties for their independent marketing purposes.
- Marketing is optional. You can unsubscribe from promotional emails, SMS, and push notifications. You may still receive operational, security, legal, transaction, subscription, cancellation, and account-related messages.
- You have privacy rights. You can request access to, correction of, or deletion of your personal information, subject to legal, security, fraud-prevention, contractual, and regulatory limits. Quebec residents may have additional rights, including portability and rights relating to automated decisions.
- You can withdraw consent to certain uses or disclosures, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent may limit or disable some Services.
3. Scope of This Privacy Policy
This Privacy Policy applies when you visit our website, use our app or browser extension, create or manage an account, connect third-party accounts, create or manage email aliases, create or manage virtual-card controls, submit or track cancellation requests, receive alerts or reports, contact support, participate in surveys or research, apply for a job, or otherwise interact with Guardian Wallet.
This Privacy Policy does not apply to third-party services that we do not control, including merchants, banks, card issuers, card networks, payment processors, account-linking providers, email providers, app stores, identity-verification providers, analytics platforms, or websites linked from the Services. Those third parties may have their own privacy policies.
4. Accountability and Privacy Officer
Guardian Wallet is responsible for personal information under its control. We have designated a Privacy Officer responsible for overseeing our privacy program, responding to privacy questions and requests, and monitoring compliance with this Privacy Policy and applicable privacy laws.
Privacy Officer: Privacy Officer, Guardian Wallet Inc.
Email: privacy@guardianwallet.ca
Mail: Guardian Wallet Inc., Toronto, Ontario, Canada. Full registered-office mailing details should be confirmed by founder/legal review before public launch.
For Quebec purposes, the title and contact information of the person responsible for the protection of personal information are published above.
5. Consent
We collect, use, and disclose personal information with your consent, or as otherwise permitted or required by law. Consent may be express or implied depending on the sensitivity of the information, the context, the purpose, your reasonable expectations, and applicable law.
We seek express consent where required or appropriate, including for sensitive information, connected-account access, email-account access, precise location access, identity verification, biometric verification, marketing communications, and other non-essential uses.
You may withdraw consent at any time, subject to legal, contractual, security, fraud-prevention, regulatory, and operational restrictions. If you withdraw consent for information necessary to provide a feature, we may no longer be able to provide that feature.
6. Personal Information We Collect
We collect personal information from information you provide to us, information collected automatically when you use the Services, and information we receive from Issuer/Payment Partners, service providers, connected accounts, merchants, and other third parties. The exact information collected depends on which features you use.
7. Information You Provide to Us
7.1 Account and Contact Information
This may include name, email address, phone number, mailing address, province or territory of residence, date of birth or age-confirmation information, username, password or authentication credentials, language preference, notification preferences, account settings, and customer-support preferences.
7.2 Identity and Verification Information
Depending on the feature, legal requirements, fraud risk, and Issuer/Payment Partner requirements, we or our providers may collect date of birth, address history, government-issued identification details, images of identification documents, selfie, liveness-check, or biometric-verification data, verification status, fraud-screening results, sanctions-screening results, device-risk information, authentication records, and other information needed to confirm identity or eligibility.
Guardian Wallet does not require your Social Insurance Number for basic subscription-management Services. Do not provide your Social Insurance Number unless it is specifically requested through a secure flow by us or by an Issuer/Payment Partner and the purpose is clearly disclosed.
7.3 Subscription and Merchant Information
You may provide merchant names, subscription names, renewal dates, cancellation dates, plan types, billing amounts, billing frequency, merchant account identifiers, screenshots or documents relating to subscriptions, merchant login hints or account details you choose to provide, notes, tags, labels, categories, and cancellation preferences.
7.4 Email Alias and Communication Information
If you use Guardian Wallet email aliases, we may collect alias addresses created for you, forwarding destination, sender and recipient information, message timestamps, subject lines, merchant names, delivery logs, bounce, spam, and abuse signals, user rules or forwarding preferences, and message content where necessary to provide forwarding, subscription detection, cancellation assistance, fraud prevention, security, abuse prevention, or support.
7.5 Cancellation-Assistance Information
If you ask us to help cancel a subscription, we may collect the merchant name, your account identifier with the merchant, cancellation instructions, template communications, authorization to submit a cancellation request, cancellation status, merchant responses, refund or confirmation details, screenshots, documents, or communications you provide, support notes, and resolution history.
7.6 Payment and Billing Information for Guardian Wallet Plans
If you subscribe to a paid Guardian Wallet plan, we or our billing provider may collect billing name, billing address, payment method token, partial card details such as last four digits and expiry date, transaction confirmation, invoice history, tax-related information, and subscription-plan information.
Guardian Wallet does not intentionally collect or store full card numbers or card verification values through ordinary support channels. Do not send full card numbers, CVV codes, passwords, recovery codes, or identity documents through email or chat unless we provide a secure upload method.
7.7 Support, Complaints, and Communications
When you contact us, we may collect your name and contact details, account email, issue description, screenshots or documents you provide, support messages, call recordings or chat transcripts where disclosed, complaint details, privacy-request details, security reports, and resolution notes.
7.8 Surveys, Research, Referrals, and Promotions
If you participate, we may collect survey responses, product feedback, referral details, contest or promotion entries, eligibility information, prize-delivery information, user-research recordings or notes where disclosed, and consent records.
7.9 Information About Other People
You may provide information about another person, such as a family-plan member, authorized user, referred person, household member, or merchant contact. You must have lawful authority and any required consent before providing another person's personal information to Guardian Wallet.
8. Information Collected Automatically
When you use the Services, we may automatically collect information such as IP address, device type, operating system, browser type, app version, device identifiers, advertising or analytics identifiers where permitted, language and time-zone settings, pages or screens viewed, buttons clicked, features used, session duration, crash reports, performance logs, referral URLs, approximate location inferred from IP address, authentication events, login history, security and fraud signals, notification-delivery status, and cookie and similar-technology data.
We use this information to operate, secure, debug, improve, personalize, measure, and protect the Services.
9. Information From Connected Accounts and Third-Party Integrations
9.1 Bank-Account or Payment-Account Linking
If you connect a bank account, card account, payment account, or financial account through an account-linking provider, we may receive account owner name, account type, financial institution name, account nickname, masked account number, balances, transaction history, merchant names, payment amounts, transaction dates, recurring-payment indicators, account status, income or deposit indicators, subscription-related transaction patterns, and other account information disclosed during the connection flow.
Account credentials may be collected and stored by the account-linking provider, not Guardian Wallet, depending on the provider and connection method.
9.2 Email-Account Integrations
If you connect an email account, such as Gmail, Google Workspace, Outlook, Microsoft 365, or another email provider, we may access only the categories of email data disclosed in the authorization flow and privacy notice. Depending on the permissions you grant, this may include email address, mailbox labels or folders, message metadata, sender and recipient information, timestamps, subject lines, subscription receipts, renewal notices, cancellation confirmations, merchant support messages, message content relevant to subscription identification, renewal alerts, cancellation assistance, alias forwarding, fraud prevention, or support, and permission tokens needed to maintain the connection.
We do not use Gmail, Google Workspace, Outlook, or Microsoft email data for advertising, data-brokerage, creditworthiness, lending, or sale to third parties.
9.3 App-Store and Merchant-Account Integrations
If you connect an app-store account, merchant account, subscription platform, or similar service, we may receive merchant account identifiers, subscription lists, plan details, trial information, renewal dates, cancellation status, payment method status, refund or credit status, purchase history, merchant communications, and account-status information.
9.4 Issuer/Payment Partner Information
If you use virtual-card or payment-control features, we may receive information from the Issuer/Payment Partner, such as verification status, virtual-card status, tokenized card identifiers, last four digits, card label, card creation, pause, resume, or closure status, transaction authorization metadata, merchant name, merchant category code, transaction amount, transaction date and time, currency, transaction status, decline reason or error code, dispute or chargeback status, refund or reversal status, and account or compliance-status information.
The Issuer/Payment Partner may independently collect and process personal information under its own privacy policy and legal obligations.
10. Information From Other Third Parties
We may receive personal information from Issuer/Payment Partners, account-linking providers, identity-verification providers, fraud-prevention providers, sanctions-screening providers, card networks, banks and payment processors, merchants, app stores, email providers, analytics providers, advertising and attribution providers, customer-support providers, cloud-hosting providers, communications providers, affiliates, referral partners, public sources, regulators, courts, law-enforcement agencies, government authorities, and other persons or organizations with your consent or as permitted or required by law.
11. Sensitive Personal Information
Some information handled by Guardian Wallet may be sensitive, including financial data, transaction metadata, subscription history, identity documents, biometric verification data, precise location, merchant communications, email content, fraud signals, and information that reveals private preferences or behaviours.
We use heightened safeguards for sensitive personal information. We seek express consent where required or appropriate, limit access on a need-to-know basis, apply security controls, and restrict use to disclosed and appropriate purposes.
12. Children and Minors
Guardian Wallet is designed for users who can legally enter into binding agreements and meet the eligibility requirements in our Terms and Conditions. We do not knowingly collect personal information from children under 13. For Quebec users under 14, consent must be provided by the person having parental authority or by the tutor, unless collection is clearly for the minor's benefit and permitted by law.
If we offer youth, student, family, or parent-supervised features, we will provide additional disclosures and obtain parental or guardian consent where required.
13. How We Use Personal Information
13.1 Provide and Manage Your Account
We use personal information to create and manage accounts, authenticate you, maintain account security, provide dashboards, manage preferences, personalize account settings, process account closure requests, provide support, maintain records, and communicate with you about your account.
13.2 Provide Subscription-Management Features
We use personal information to identify subscriptions, detect recurring charges, classify merchants, estimate renewal dates, track price changes, detect duplicate or unused subscriptions, display subscription history, provide renewal alerts, create spending summaries, generate estimated savings insights, identify failed or unusual charges, and improve subscription-detection accuracy.
13.3 Provide Virtual-Card Controls
We use personal information to display virtual cards issued or supported by the Issuer/Payment Partner, create labels or merchant associations, show card status, support pause, resume, limit, or closure requests, display transaction metadata, route requests to the Issuer/Payment Partner, troubleshoot declines, support chargeback or dispute routing, and maintain fraud, risk, and compliance controls.
13.4 Provide Email Aliases
We use personal information to create and manage aliases, forward merchant messages, block abusive or unwanted messages, identify merchant communications, associate alias messages with subscriptions, support cancellation workflows, deliver account notifications, detect spam, fraud, phishing, abuse, or misuse, troubleshoot delivery issues, and maintain logs needed for security and support.
13.5 Provide Cancellation-Assistance Tools
We use personal information to generate cancellation steps, prepare cancellation templates, submit cancellation requests where authorized, send merchant communications, track cancellation status, receive merchant responses, remind you of follow-up steps, support refund or confirmation tracking, maintain records of your instructions, and respond to disputes or complaints.
13.6 Verify Identity, Prevent Fraud, and Protect the Services
We use personal information to verify identity, authenticate logins, prevent account takeover, detect fraud or unauthorized activity, detect misuse of aliases or virtual-card controls, enforce Terms and Conditions, screen for sanctions or prohibited activity where required, manage security risk, investigate suspicious activity, protect users and partners, and comply with legal, regulatory, contractual, card-network, and partner obligations.
13.7 Communicate With You
We use personal information to send account messages, security alerts, subscription alerts, renewal reminders, cancellation-status updates, virtual-card status notices, billing notices, legal notices, privacy notices, service announcements, support responses, complaint responses, survey or research invitations, and marketing messages where permitted.
13.8 Process Guardian Wallet Billing
We use personal information to process subscription fees, issue invoices and receipts, calculate taxes, manage renewals, handle failed payments, process refunds where applicable, administer promotions or trials, and maintain billing records.
13.9 Improve, Develop, and Measure the Services
We use personal information to debug and troubleshoot, analyze feature performance, improve user experience, train support teams, test new features, measure product engagement, assess reliability, monitor system health, improve subscription-detection logic, improve merchant classification, improve cancellation workflows, and conduct internal reporting and analytics. Where possible, we use aggregated, de-identified, or anonymized information for analytics and product improvement.
13.10 Marketing and Personalization
With consent or where otherwise permitted by law, we may use personal information to send promotional messages, recommend features, provide offers or discounts, measure marketing campaigns, personalize website or app content, invite you to participate in surveys, beta programs, or research, and show non-sensitive contextual recommendations. We do not use Gmail, Google Workspace, Outlook, Microsoft 365, email content, identity-verification data, or sensitive payment data for advertising. Quebec residents are opted out of personalized marketing or profiling for marketing purposes by default where required by applicable law, unless they choose to opt in.
13.11 Legal, Compliance, and Dispute Purposes
We use personal information to comply with laws, comply with lawful requests, cooperate with regulators, respond to legal process, enforce agreements, protect legal rights, establish, exercise, or defend legal claims, resolve complaints, maintain corporate records, complete audits, support business continuity, complete business transactions, and meet tax, accounting, security, and regulatory obligations.
14. AI, Automation, and Profiling
Guardian Wallet may use rules-based systems, automation, machine learning, or artificial-intelligence tools to classify subscriptions, identify recurring charges, detect duplicate subscriptions, identify merchants, estimate renewal dates, detect anomalies, generate cancellation templates, summarize merchant instructions, route support requests, detect fraud or account-takeover risk, improve security, improve search, alerts, and dashboards, and support customer-service workflows.
Automated outputs may be inaccurate or incomplete. You should verify important subscription, billing, cancellation, refund, and merchant-account information directly with the merchant or payment provider.
We do not use sensitive email content, payment-card data, identity documents, or biometric verification data to train general-purpose AI models unless we provide a separate notice and obtain consent where required. Where we use third-party AI providers, they process information on our behalf under contractual restrictions.
If we make a decision based exclusively on automated processing that produces legal effects or similarly significant effects, we will provide notice where required. Quebec residents may request information about the personal information used, the reasons and principal factors that led to the decision, correction of the information used, and an opportunity to submit observations to a person who can review the decision.
15. When We Disclose Personal Information
We disclose personal information only as described in this Privacy Policy, with your consent, or as otherwise permitted or required by law.
16. Issuer/Payment Partners
If you use virtual-card, payment-control, account-linking, or transaction-related features, we may disclose personal information to Issuer/Payment Partners to verify identity, determine eligibility, issue or manage virtual cards, process card-control requests, authorize or decline transactions, display transaction metadata, manage fraud and risk, provide support, investigate disputes, process chargebacks, comply with card-network rules, comply with legal and regulatory requirements, and maintain program records.
Issuer/Payment Partners may be independently responsible for personal information they collect and process. Their privacy policies and agreements apply to their services.
17. Service Providers
We may disclose personal information to service providers that perform services on our behalf, including cloud hosting, database storage, cybersecurity, identity verification, fraud prevention, account linking, email delivery and alias infrastructure, payment processing, billing, customer support, analytics, error monitoring, marketing operations, communications, legal, accounting, audit, compliance support, product research, data processing, AI-assisted support or analytics, document storage, and business-continuity services.
We provide service providers only the information reasonably needed to perform their services. We require service providers to protect personal information and restrict use to authorized purposes.
18. Email Providers and Connected-Account Providers
If you connect Gmail, Google Workspace, Outlook, Microsoft 365, a bank account, payment account, app-store account, or merchant account, we disclose and receive information through those providers as necessary to provide the connected feature. You can usually revoke connection permissions through Guardian Wallet, the third-party provider, your device settings, your email provider, your bank, your app store, or the merchant. Revoking access may limit or disable related features.
19. Merchants
If you ask us to help with a merchant cancellation, refund, billing, or account request, we may disclose information to the merchant as needed to submit or support the request, including your name, email alias or contact email, merchant account identifier, subscription details, cancellation instructions, authorization statement, relevant screenshots or documents you provide, template messages, and follow-up communications.
We disclose only what is reasonably necessary for the merchant workflow you request.
20. Fraud, Security, and Abuse Prevention
We may disclose personal information to fraud-prevention, cybersecurity, identity-verification, sanctions-screening, payment-risk, and abuse-prevention providers to protect users, Guardian Wallet, Issuer/Payment Partners, merchants, and the public. We may also disclose information to other organizations where reasonable to investigate or prevent fraud, abuse, unauthorized transactions, account takeover, phishing, spam, security incidents, or other unlawful activity.
21. Affiliates and Corporate Group
We may disclose personal information to affiliates or related companies for the purposes described in this Privacy Policy, including account administration, support, security, compliance, analytics, product development, and internal operations. If we share information within our corporate group, we remain responsible for protecting it according to this Privacy Policy and applicable law.
22. Business Transactions
We may disclose personal information in connection with a proposed or completed business transaction, including a merger, acquisition, financing, reorganization, sale of assets, transfer of business, insolvency, bankruptcy, or change of control. Where required, we will use safeguards and contractual restrictions to protect personal information during the transaction.
23. Legal, Regulatory, and Safety Disclosures
We may disclose personal information if we believe in good faith that disclosure is permitted or required to comply with law, respond to lawful requests, comply with legal process, cooperate with regulators or law enforcement, comply with Issuer/Payment Partner or card-network obligations, enforce our Terms and Conditions, investigate suspected unlawful activity, protect safety, security, rights, or property, prevent fraud, collect amounts owed, respond to complaints or disputes, or establish, exercise, or defend legal claims.
24. De-Identified, Aggregated, and Anonymized Information
We may use and disclose de-identified, aggregated, or anonymized information for analytics, reporting, benchmarking, product improvement, research, security, marketing measurement, and business purposes. We take reasonable measures to reduce the risk of re-identification. Where de-identified information remains personal information under applicable law, we protect it accordingly.
We do not attempt to re-identify anonymized information except where permitted or required by law, such as to test whether anonymization measures remain effective.
25. Google, Gmail, and Google Workspace Data
If you connect a Google account, Guardian Wallet's use and transfer of information received from Google APIs will comply with applicable Google API Services User Data Policy requirements, including limited-use requirements.
- We request only permissions needed for disclosed Guardian Wallet features.
- We use the data only to provide or improve user-facing features you request.
- We do not sell Google user data, use it for advertising, use it to determine creditworthiness or for lending, transfer it to data brokers, or allow humans to read email content except where necessary for support, security, abuse prevention, compliance, troubleshooting, or with your consent.
- We store only what is reasonably necessary for the Services and delete or de-identify Google user data when it is no longer needed, subject to legal and security-retention requirements.
- You may revoke access through your Google account permissions or Guardian Wallet settings.
- Material changes to our use of Google user data will be disclosed and, where required, subject to renewed consent.
26. Microsoft, Outlook, and Microsoft 365 Data
If you connect a Microsoft account, Guardian Wallet requests only the Microsoft permissions needed for disclosed features. We use delegated access where appropriate, apply least-privilege permissions where practicable, use the data only for disclosed Guardian Wallet features, do not sell Microsoft account data, do not use email content for advertising, store only what is reasonably necessary, allow revocation through Microsoft account settings or Guardian Wallet settings, and disclose material changes where required.
27. Cookies and Similar Technologies
We and our providers may use cookies, pixels, SDKs, local storage, device identifiers, and similar technologies to operate the website and app, keep you signed in, remember settings, secure sessions, detect fraud, analyze usage, measure performance, debug errors, personalize content, measure marketing campaigns, and deliver or measure advertising where permitted.
You can manage cookies through your browser or device settings. Disabling some cookies may affect website or app functionality. Where required, we will provide a cookie banner or preference centre that allows you to manage non-essential cookies.
28. Interest-Based Advertising and Analytics
We may use analytics and advertising providers to understand usage, improve the Services, and measure marketing campaigns. We do not use sensitive financial data, email content, identity-verification data, or precise subscription details for third-party interest-based advertising.
Where applicable, you can adjust preferences through Guardian Wallet privacy settings, cookie preferences, device advertising settings, browser settings, app-store privacy settings, push-notification settings, and marketing unsubscribe links. Quebec users are not enrolled in personalized marketing based on profiling unless permitted by law and supported by valid consent.
29. Communications and CASL
We may send operational messages, including account notices, login alerts, security alerts, subscription alerts, renewal reminders, cancellation updates, virtual-card status updates, payment or billing notices, legal notices, privacy notices, service announcements, and support messages. These messages are part of the Services and may not include an unsubscribe option.
We may send promotional electronic messages only with consent or where otherwise permitted by law. Promotional messages will identify Guardian Wallet and include an unsubscribe mechanism. You may unsubscribe from marketing messages at any time. Unsubscribing from marketing does not stop operational, transactional, legal, security, subscription, cancellation, or account-related messages.
30. Push Notifications
If you enable push notifications, we may send subscription alerts, renewal reminders, security alerts, cancellation updates, virtual-card alerts, and other messages to your device. Push notifications may reveal personal information on your lock screen or shared devices. You can manage push notifications through Guardian Wallet settings and your device settings.
31. Location Information
We may infer approximate location from IP address for security, localization, analytics, fraud prevention, and legal-compliance purposes. We collect precise location only if the feature requires it, we disclose the purpose, and you grant permission through the app or device. You may disable location permissions through your device settings, but some features may not work properly.
32. Security Safeguards
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the personal information. Safeguards may include encryption in transit, encryption at rest where appropriate, tokenization, access controls, multi-factor authentication for internal systems, least-privilege access, logging and monitoring, secure software-development practices, vulnerability management, vendor due diligence, contractual safeguards, employee confidentiality obligations, privacy and security training, incident-response procedures, backup and recovery controls, fraud detection, segregation of production data where appropriate, and periodic security reviews.
No system is completely secure. You are responsible for protecting your device, password, email account, two-factor authentication methods, and connected accounts. Contact security@guardianwallet.ca immediately if you believe your account, device, email account, or Guardian Wallet credentials have been compromised.
33. Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Privacy Policy, or as otherwise permitted or required by law. Retention periods depend on the nature of the information, sensitivity, purpose, account status, legal obligations, fraud risk, dispute risk, regulatory obligations, and technical requirements.
| Category | Intended retention approach |
|---|---|
| Account profile information | For the life of the account, then for a reasonable period after closure for legal, security, fraud-prevention, audit, and dispute purposes. |
| Subscription and merchant metadata | For the life of the account, then deleted, de-identified, or anonymized according to our retention schedule. |
| Email alias logs | Retained only as long as needed for delivery, abuse prevention, security, support, and compliance. |
| Email content processed from connected accounts | Minimized and retained only where needed for user-facing features, support, legal, or security purposes. |
| Cancellation-request records | Retained while the request is active and for a reasonable period afterward for support, audit, dispute, and legal purposes. |
| Transaction metadata received from Issuer/Payment Partners | Retained as needed to provide the Services and meet legal, contractual, audit, security, and dispute obligations. |
| Identity-verification records | Retained according to legal, fraud-prevention, partner, and security requirements; biometric data, if any, is minimized and handled under heightened safeguards. |
| Support tickets and complaints | Retained for a reasonable period to resolve issues, improve support, and maintain legal and audit records. |
| Security logs | Retained for security, fraud prevention, incident response, and audit purposes. |
| Marketing preferences and unsubscribe records | Retained as needed to honour preferences and comply with law. |
| Legal and compliance records | Retained as required or advisable under applicable limitation periods, regulatory obligations, and legal duties. |
| Job applicant records | Retained as needed for recruitment, legal, and HR purposes. |
When information is no longer needed, we destroy it, erase it, de-identify it, or anonymize it according to our retention and destruction procedures.
34. Account Closure and Deletion
You may request account closure through the Help & Support dashboard, the privacy and data request flow, or by contacting support@guardianwallet.ca.
Closing your account may disable dashboards, aliases, connected accounts, subscription monitoring, cancellation workflows, virtual-card controls through Guardian Wallet, most operational notices, billing, and support history. We may retain some personal information after account closure where required or permitted for legal, security, fraud-prevention, audit, complaint, tax, accounting, dispute, or regulatory purposes.
If your request relates to Issuer/Payment Partner data, bank data, email-provider data, merchant data, app-store data, or other third-party data, you may also need to contact the relevant third party directly.
35. Cross-Border Processing and Storage
Guardian Wallet and its service providers may process and store personal information in Canada, the United States, the European Union, the United Kingdom, and other jurisdictions. Personal information processed outside your province, territory, or country may be subject to the laws of that jurisdiction, including lawful access by courts, law-enforcement agencies, regulators, national-security authorities, or government bodies.
We use contractual, technical, organizational, and vendor-management safeguards designed to protect personal information processed by service providers. For Quebec personal information communicated or entrusted outside Quebec, we conduct privacy assessments and use written agreements where required by Quebec law.
36. Accuracy
We take reasonable steps to keep personal information as accurate, complete, and up to date as necessary for the purposes for which it is used. You are responsible for keeping your account information current. You may update certain information through Guardian Wallet settings or by contacting support. If you believe information we hold about you is inaccurate, incomplete, or outdated, contact privacy@guardianwallet.ca.
37. Your Privacy Rights
Subject to applicable law and limited exceptions, you may have the right to request access to personal information we hold about you, request correction of inaccurate or incomplete information, request deletion of certain information, withdraw consent, request information about our privacy practices, challenge our compliance, complain to our Privacy Officer, opt out of marketing communications, manage cookies and tracking preferences, disconnect connected accounts, revoke email or account-linking permissions, request portability where required by law, request information about automated decisions where required by law, and submit observations or request review of certain automated decisions where required by law.
To make a request, contact privacy@guardianwallet.ca. We may need to verify your identity before responding. We will respond within the timeframe required by applicable law. In some circumstances, we may refuse or limit access, correction, deletion, portability, or other requests where permitted or required by law.
38. Quebec Privacy Rights
If you reside in Quebec, you may have additional rights, including the right to clear information about collection, use, disclosure, retention, access, and your rights; the right to know whether personal information may be communicated outside Quebec; the right to request access and rectification; the right to request computerized personal information collected from you in a structured, commonly used technological format where required and subject to exceptions; rights relating to profiling, identification, and location technologies; rights relating to decisions based exclusively on automated processing; the right to request de-indexation or cessation of dissemination in certain legally defined circumstances; and the right to submit a complaint to the Commission d'acces a l'information.
Requests should be sent to the Privacy Officer at privacy@guardianwallet.ca.
39. Alberta and British Columbia Privacy Rights
If you reside in Alberta or British Columbia, substantially similar provincial private-sector privacy laws may apply to certain personal information handling within those provinces. You may have rights to access and correct personal information, withdraw consent subject to legal or contractual restrictions, and complain to the applicable privacy regulator. Requests should be sent to the Privacy Officer at privacy@guardianwallet.ca.
40. Withdrawing Consent and Managing Preferences
You can manage many privacy choices through Guardian Wallet settings, including connected accounts, email integrations, email aliases, notification settings, push notifications, marketing preferences, cookie settings, location permissions, personalization settings, cancellation-workflow permissions, and account closure.
You can also withdraw consent or submit a privacy request by contacting privacy@guardianwallet.ca. Withdrawing consent may limit or disable features such as transaction-based subscription detection, receipt-based subscription detection, alias forwarding, renewal alerts, virtual-card or payment features, and other Services that require the relevant data.
41. Data Portability
Where required by law, including for Quebec residents, you may request that computerized personal information collected from you be provided to you, or to another person or organization authorized by law, in a structured, commonly used technological format, subject to legal exceptions and technical limitations.
This right may not apply to information created or inferred by Guardian Wallet, such as internal risk scores, derived insights, fraud classifications, or subscription-detection models, except where required by law.
42. Privacy Breaches and Confidentiality Incidents
We maintain procedures to identify, assess, contain, investigate, record, and respond to privacy breaches and confidentiality incidents. Where required by law, we will notify affected individuals, regulators, Issuer/Payment Partners, service providers, or other organizations that may reduce risk of harm. We maintain breach records as required by law.
43. Third-Party Websites and Services
The Services may link to third-party websites, apps, merchants, banks, card issuers, processors, account-linking providers, email providers, app stores, analytics providers, advertising providers, or social media platforms. We are not responsible for the privacy practices of third parties we do not control. You should review their privacy policies before providing personal information or using their services.
44. App Stores and Device Platforms
If you download Guardian Wallet through an app store, the app store operator may collect information about your download, device, account, purchases, crashes, and app usage according to its own privacy policy. Your device operating system may also provide privacy controls for location, notifications, identifiers, camera, photos, contacts, email accounts, and tracking. Your choices in device settings may affect Guardian Wallet features.
45. Employment and Contractor Information
If you apply for a job, contractor role, advisory role, or similar opportunity with Guardian Wallet, we may collect name, contact information, resume, cover letter, employment history, education, references, interview notes, assessment results, background-check information where permitted, work authorization information, and other information you provide or that is collected with your consent or as permitted by law.
We use this information to assess applications, communicate with candidates, conduct interviews, verify information, make hiring decisions, maintain recruitment records, and comply with legal obligations.
46. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, data practices, legal requirements, technology, partners, or business operations. When we update the Privacy Policy, we will revise the "Last updated" date. If changes are material, we will provide notice as required by law, which may include in-app notice, email notice, website notice, or renewed consent.
If we materially change how we use sensitive information, connected-account data, Google user data, Microsoft account data, email content, or personal information for new purposes, we will provide notice and seek consent where required.
47. Contact Us
For privacy questions, requests, or complaints:
Privacy Officer
Guardian Wallet Inc.
Toronto, Ontario, Canada
Full registered-office mailing details should be confirmed by founder/legal review before public launch.
Email: privacy@guardianwallet.ca
For account support: support@guardianwallet.ca
For security reports: security@guardianwallet.ca
For complaints: complaints@guardianwallet.ca
If you are not satisfied with our response, you may have the right to contact the privacy regulator in your jurisdiction, including the Office of the Privacy Commissioner of Canada, the Commission d'acces a l'information in Quebec, the Office of the Information and Privacy Commissioner of Alberta, or the Office of the Information and Privacy Commissioner for British Columbia.