Last updated: February 2, 2026
This page is a basic template meant to be adapted to your situation. It does not constitute legal advice.
1. Data controller
Piastro (“we”) is responsible for the processing of personal information collected via the app and the website.
2. Information we collect
- Account information (e.g., email, encrypted password, preferences).
- User-entered financial data (e.g., transactions, categories, budgets).
- Minimal technical data (e.g., truncated/anonymized IP address, device and browser type).
- Aggregated, anonymized usage data (e.g., pages viewed, traffic volume).
3. Purposes
- Provide and operate the service (authentication, dashboards, analytics).
- Improve performance, security, and user experience.
- Communicate with you (support, service notifications).
- Privacy-respecting audience measurement, without cookies or individual tracking.
4. Sharing
We use service providers that are strictly necessary for running the website and the application (hosting, security, and audience measurement). These providers are bound by confidentiality and security obligations. Shared data is limited to what is strictly necessary.
Piastro’s primary hosting is in Québec (Beauharnois) with OVHcloud. Data is stored on servers located in Québec.
5. Audience measurement (no cookies)
Piastro uses a privacy-respecting audience measurement tool (Rybbit). This tool does not set cookies, does not use local storage (localStorage or equivalent), and does not enable individual tracking of users across websites or sessions.
Technical information transmitted is limited to what is strictly necessary and may be processed by the provider in the jurisdiction where it operates. Under applicable frameworks (GDPR and Québec’s Law 25), this type of anonymized audience measurement does not require displaying a cookie consent banner.
6. Retention
We keep data as long as necessary to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements.
7. Security
We implement reasonable safeguards (access controls, encryption in transit, monitoring) to protect your personal information. No system is completely foolproof.
8. Your rights
- Access and correct your information.
- Withdraw consent where applicable.
- Request deletion of your account, subject to legal obligations.
- Request information about the technologies used for audience measurement.
9. Contact
For any questions or requests related to privacy, contact us via the Contact page.