We're giving away 10 lifetime membershipsClaim mine โ†’
Compliance & Data Protection

Privacy Center & Fiduciary Pledge

MapleRetire is built local-first: your planning numbers live in your browser, not our database. The only data we keep is what you explicitly send us โ€” and we never sell it.

Local-First by Design โ€” and Exactly What We Do Keep

Your Blueprint calculations โ€” portfolios, balances, tax schedules โ€” run inside your own browser and stay there. We have no database of your financial plan and cannot see it.

One honest exception: if you ask us to email you a free report from the retirement calculator, the details you submit with that request โ€” your email address, age, approximate savings, and planned spending โ€” are transmitted to us, stored securely on Cloudflare infrastructure, and used for exactly two things: sending you the report you asked for, and occasional retirement-planning emails you can leave with one click. Email privacy@mapleretire.com any time and we will delete every record of you, permanently.

Plans Never Leave Your Browser Report Data: Delete on Request Never Sold. Never Shared for Marketing.

PIPEDA: 10 Fair Information Principles Audit

We adhere strictly to the Personal Information Protection and Electronic Documents Act (PIPEDA), which establishes ten principles of fair information practices:

1 Accountability

We have appointed a designated Data Protection Officer (DPO) responsible for oversight of privacy structures and compliance audits.

2 Identifying Purposes

Before collecting information, we state the precise purpose: Clerk handles authentication; Stripe processes secure licensing; Microsoft 365 delivers the reports you request; optional GTag measures aggregate page flow (opt-out any time below).

3 Consent

Sensitive actions are strictly opt-in: reports are only emailed when you ask, and accounts are only created when you sign up. Anonymous, aggregate analytics run under implied consent with a one-click opt-out in our privacy banner ("Decline") or below โ€” choosing it disables analytics immediately.

4 Limiting Collection

We collect only what a feature strictly requires: your email to authenticate an account, billing via Stripe to process a purchase, and โ€” only if you request a free emailed report โ€” the email address and approximate figures you submit with that request.

5 Limiting Use, Disclosure, & Retention

We never rent, sell, or trade personal data to third parties. Customer subscription profiles are kept strictly as long as account access remains active.

6 Accuracy

Financial balances and statement ledger files are kept accurate because they live directly in your browser. You can clear or update them instantly.

7 Safeguards

All cloud transactions utilize HTTPS secure connections, and billing data is tokenized directly via Stripe's bank-grade payment processing vaults.

8 Openness

This comprehensive document represents our absolute transparency regarding the specific third-party tools, local memory loops, and security protocols in place.

9 Individual Access

You possess absolute access to your user account dashboard, email records, and custom local planning ledgers at any time.

10 Challenging Compliance

If you believe our architecture violates your privacy rights, contact our DPO immediately. We respond to all compliance inquiries within 30 days.

Quebec Law 25: Your Digital Rights

Under Quebec's modernized data privacy law (Law 25), consumers receive a robust set of rights concerning their personal profiles. We fully honor and implement these mechanisms:

Right to Portability

We allow you to instantly export your entire transaction ledger, assets database, and withdrawal sequences as a standardized JSON/CSV file from the Command Center settings.

Export Ledger Data

Right to Erasure (To Be Forgotten)

You possess absolute control to destroy your entire portfolio footprint. Simply click the "Wipe Local Sandbox" button in the Data Ingestion tab to purge all local browser cookies and data.

Wipe Local Sandbox

Explicit Consent / Opt-In

Non-essential analytical scripts (GTag) are strictly deactivated by default when you load MapleRetire. They are only initialized once you provide explicit, active consent.

Secured Fiduciary Infrastructure

We leverage premium, SOC-2 compliant technology partners to maintain robust security:

Clerk Security

Authenticates profiles using secure token exchanges, providing multi-factor authentication (MFA) and isolated session layers.

Stripe Compliance

Processes payment details within audited, PCI-DSS Level 1 compliant environments. MapleRetire never touches your billing card credentials.

Cloudflare Edge

Shields endpoints behind commercial-grade DDoS protections, SSL certificates, and isolated backend serverless runtimes.

Contact the Privacy Officer

For compliance challenges, formal individual access queries, or data portability requests under PIPEDA/Law 25, please contact:

privacy@mapleretire.com

Data Protection Officer ยท MapleRetire