1. Scope and accountability
This Privacy Policy applies to the DueSimple website, guided fictional demo, registered accounts, authenticated planning application, support channel, and related emails offered in Canada and the United States. DueSimple, based in Montreal, Quebec, Canada, is responsible for the personal information described here.
The public demo uses fixed fictional information and does not accept personal financial data. This Policy does not govern third-party websites linked from DueSimple.
2. Information we collect
- Account and identity information
- Email address, display name, verified-email state, authentication provider, encrypted authentication credentials managed by Supabase Auth, MFA status, recovery-code hashes, locale, timezone, age confirmation, session and security events, and accepted legal-document versions.
- Planning information you provide
- Opening balance, income, obligations, spending allowances, debts, interest rates, goals, categories, notes, recurrence schedules, due dates, priorities, manual allocations, locks, completion confirmations, remaining-money rules, plan results, and audit history. DueSimple stores monetary amounts as integer cents and does not ask you to choose or provide an ISO currency. This information may reveal sensitive details about your financial situation even though DueSimple does not connect to financial institutions.
- Imports, exports, messages, and notifications
- Metadata and validation status for a valid, signed, complete DueSimple JSON archive submitted for restore; requested complete JSON archive and categorized CSV export files; notification preferences and delivery status; and information submitted through support or contact forms.
- Technical and security information
- IP-derived rate-limit identifiers, request identifiers, browser and device information made available in hosting logs, authentication timestamps, security events, error diagnostics, and privacy-filtered performance information. DueSimple is designed not to place financial names, amounts, notes, CSV contents, passwords, tokens, or authentication codes in application logs or error-monitoring events.
3. Information we do not request
Do not enter bank usernames or passwords, payment-card or bank-account numbers, government or tax identifiers, credit-report credentials, authenticator codes, or information you are not authorized to provide. DueSimple does not collect transaction feeds, initiate payments, sell financial products, or obtain information from banks or credit bureaus.
4. Where information comes from
Most information comes directly from you through registration, onboarding, forms, planner commands, valid signed complete DueSimple JSON archives submitted for restore, and support messages. Authentication providers may supply verified identity details when you choose their service. Vercel, Supabase, Resend, and configured security providers generate limited technical, delivery, and security records while operating DueSimple.
5. Why we use information
- create, authenticate, secure, and support your account;
- calculate, explain, save, and display your paycheck plan;
- materialize recurring occurrences and maintain planning history;
- review valid, signed, complete DueSimple JSON archives submitted for restore and prepare user-requested exports;
- send mandatory security messages and notifications you enable;
- detect abuse, enforce rate limits, investigate incidents, and protect workspaces;
- respond to support, accessibility, privacy, and security requests;
- maintain backups, continuity, auditability, and legal records; and
- comply with law and enforce the Terms of Service.
For Canadian users, DueSimple relies on meaningful consent where required and limits collection, use, and disclosure to identified and reasonable purposes. You may withdraw consent, subject to legal or contractual restrictions and reasonable notice; withdrawal may require closing the account where the information is necessary to provide the service.
6. Service providers and disclosures
DueSimple uses providers that process information only to perform contracted services:
- Supabase — authentication, database hosting, access controls, and managed infrastructure in the configured US East region;
- Vercel — application hosting, delivery, operational logs, and private export storage when configured;
- Resend — authentication or product email delivery when the relevant email channel is enabled;
- Sentry — privacy-filtered error and performance monitoring when enabled; and
- Google — identity information only if you choose Google sign-in after that option is enabled.
We may disclose information when reasonably necessary to comply with valid law, protect a person or the service, investigate fraud or abuse, establish or defend legal claims, or complete a corporate reorganization. If ownership changes, the recipient must use the information consistently with this Policy unless it obtains any consent required by law.
DueSimple does not sell personal information, share it for cross-context behavioural advertising, use planning information for advertising, or rent contact lists. Marketing consent is separate and disabled unless you expressly opt in.
7. Cross-border processing
DueSimple is operated from Quebec, while core hosting and database infrastructure are configured in the United States. Information may therefore be processed and stored in Canada and the United States and may be accessible to courts, law-enforcement, or national-security authorities under the laws of those jurisdictions. DueSimple uses contractual, access-control, encryption, and provider-management measures appropriate to the sensitivity of the information.
8. Retention
| Information | Typical retention |
|---|---|
| Account and active planning data | For the account’s lifetime, then deleted after the seven-day cancellation period unless limited retention is legally required. |
| Legal acceptances and command audit history | For the account’s lifetime and, where necessary, for a reasonable period to document consent, security, disputes, or compliance. |
| DueSimple JSON archive restore review | A verified restore review for a valid, signed, complete DueSimple JSON archive expires after one hour. Categorized CSV is export-only and is never accepted for restore. |
| Export archives | Private download access expires after 24 hours; associated files and expired job data are removed through operational cleanup. |
| Rate-limit records | Up to eight days. |
| Signup authorization records | A pending authorization expires after ten minutes. Limited HMAC-protected security evidence may be retained to prevent replay and investigate abuse; plaintext email addresses are not stored in this authorization table. |
| Support and contact messages | Only as long as reasonably necessary to answer, secure, and document the request, normally no more than 12 months unless follow-up or law requires longer. |
| Encrypted logical backups | Up to 35 days under the backup schedule. Backups are not restored for routine account recovery and expire through controlled retention processes. |
| Provider and security logs | According to the shortest practical provider setting and only as long as reasonably necessary for security, reliability, and incident investigation. |
Retention may be shortened when information is no longer needed or extended when required by law, a security investigation, fraud prevention, backup integrity, or a legal claim. We use the nature, sensitivity, purpose, risk, and applicable legal requirements to set any period not stated above.
9. Security
DueSimple uses verified sessions, server-side authorization, Row Level Security, workspace isolation, encryption in transit, provider encryption at rest, restricted privileged credentials, rate limits, audit events, private export access, optional MFA, privacy-filtered logging, and documented backup and recovery controls. Access is limited according to operational need.
No online system is risk-free. You are responsible for using a unique password, protecting MFA and recovery codes, securing your device, and reporting suspected compromise to support@duesimple.app.
10. Your choices and privacy rights
You can correct profile and planning information, manage notifications, export a portable JSON and categorized CSV archive, and schedule account deletion from DueSimple settings. You may also contact privacy@duesimple.app to request access, correction, deletion, information about use or disclosure, or help exercising a privacy right.
Depending on where you live and whether the relevant law applies, you may have rights to know or access personal information, correct it, request deletion, obtain portability, withdraw consent, restrict certain uses, appeal a decision, or receive equal service without discrimination. Because DueSimple does not sell personal information or share it for targeted advertising, there is no sale or targeted-advertising opt-out to exercise.
We will verify the request before disclosing or changing account information. Authorized agents may submit requests where permitted by law, subject to proof of authority and identity verification. If we deny a request, we will explain the reason and available complaint or appeal path where required.
Canadian users may contact the Office of the Privacy Commissioner of Canada. Quebec users may contact the Commission d’accès à l’information du Québec. US residents may contact their state attorney general or privacy regulator where applicable.
11. Children
DueSimple is for adults aged 18 or older. We do not knowingly create accounts for children. Contact privacy@duesimple.app if you believe a child provided personal information.
12. Cookies and similar technologies
DueSimple uses essential session and security cookies required for authentication, fraud prevention, preferences, and service operation. We do not currently use advertising cookies or cross-site behavioural tracking. If non-essential analytics or marketing technologies are introduced, this Policy and any required consent controls will be updated before use.
13. Changes to this Policy
We may update this Policy when the product, providers, practices, or law change. The current effective date and version appear at the top. Material changes will be communicated to registered users and will require renewed consent where applicable.
14. Contact the person responsible for privacy
Email: privacy@duesimple.app Support: support@duesimple.app DueSimple Montreal, Quebec, CanadaDueSimple accepts privacy requests electronically and does not publish a residential street address.