Privacy Policy
Effective June 8, 2026
Caipibara provides bookkeeping, reconciliation, and tax-preparation software for Canadian accounting firms. This policy explains what information we collect, how we use it, and the choices you have. It applies to our web application and related services.
Information we collect
- Account information — name, email, and firm details used to create and secure your account.
- Connected accounting data — when you connect an accounting platform (QuickBooks Online or Xero) via OAuth, we access transactions, chart of accounts, and account balances for the companies you authorize, solely to perform bookkeeping and tax-preparation on your behalf.
- Connected bank data— when a bank account is linked through our bank-aggregation provider (Plaid), we access that account’s transactions and balances to perform bookkeeping on your behalf. You authenticate with your bank inside Plaid; we never receive your online-banking credentials.
- Documents you upload — bank statements, invoices, receipts, ledgers, and similar records, and the data extracted from them.
- Usage information — logs and diagnostics needed to operate and secure the service.
How we use information
We use the information to categorize and reconcile transactions, prepare financial statements and tax filings, surface items for your review, and operate, secure, and improve the service. We do notsell your data or your clients’ data, and we do not use connected accounting data for advertising.
Third-party integrations
With your authorization we connect to Intuit QuickBooks Online and Xero through their official OAuth APIs, and to bank accounts through Plaid, our bank-aggregation provider. We request only the access needed to read accounting and bank data for the companies and accounts you link. Access tokens are encrypted at rest and can be revoked at any time by disconnecting the integration in your settings or from within QuickBooks/Xero. Your use of those platforms is also governed by their own privacy policies, including Plaid’s end-user privacy policy.
Data storage and security
Data is hosted in Canada (AWS ca-central-1) in support of PIPEDA. We use encryption in transit and at rest, scoped multi-tenant access controls, and least-privilege practices. OAuth tokens and other secrets are encrypted before storage.
Data retention and deletion
We retain data for as long as your account is active or as needed to provide the service and meet legal and professional record-keeping obligations. Disconnecting an integration stops further access to that platform. You may request deletion of your data by contacting us; some records may be retained where required by law.
Your rights
Subject to applicable law, you may access, correct, or request deletion of your personal information, and withdraw consent for integrations. Contact us to exercise these rights.
Changes to this policy
We may update this policy from time to time; we will revise the effective date above when we do.
Contact
Questions about this policy or our data practices: johnyin@synervex.ai.