Legal

Privacy & Terms

What we do with your data — in plain language. Full legal documents are below for those who want them.

Our commitments
Read-only bank access
Au connects via Plaid. We see your transactions — we cannot move money, initiate transfers, or interact with your account in any other way. Your bank login is never stored by Au.
We don't sell your data
Your Personal Information is never sold. Au earns from subscriptions and affiliate commissions — not from monetising your financial data.
Delete anytime
Delete your account from settings and your data is removed from all Au systems. No waiting periods, no hoops. Email privacy@au79.app if you need help.
Encrypted in transit
All data is encrypted in transit. We maintain access controls, secure development practices, and incident response procedures appropriate to the sensitivity of your financial data.
Full legal documents
Privacy Policy effective June 23, 2026  ·  Terms of Use last updated May 23, 2026

Aurum Technologies Inc. ("we", "us" or "our") provides a consumer mobile and web application (the "Service"). This Privacy Policy describes how we collect, use, disclose, retain and protect Personal Information when you use the Service, visit our websites, or otherwise interact with us.

This Policy applies to individuals in Canada, the United States and other countries where the Service is available. It is intended to comply with PIPEDA, Law 25 (Quebec), the CCPA/CPRA, the Gramm-Leach-Bliley Act, US State Privacy Laws (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana), the EU GDPR, UK GDPR, Swiss FADP, Brazil's LGPD, and Australia's Privacy Act 1988.

By using the Service, you acknowledge that you have read and understood this Policy.

Personal Information means information about an identifiable individual, including "personal data" as defined under Applicable Privacy Laws.

Sensitive Personal Information includes government-issued identifiers, financial account information, precise geolocation, account credentials, racial or ethnic origin, health information, biometric data, and information concerning a known child.

Applicable Privacy Laws means PIPEDA, Law 25, the CCPA, GLBA, the US State Privacy Laws, EU GDPR, UK GDPR, Swiss FADP, Brazil's LGPD, Australia's Privacy Act 1988, and any other applicable privacy law.

Service Provider has the meaning given under the CCPA and includes processors and service providers as used in the US State Privacy Laws and PIPEDA.

  • Identifiers — name, email, mobile number, username, credentials, IP address, device identifiers.
  • Account and profile information — date of birth, profile photo, preferences, content you submit.
  • Commercial information — transaction history, subscription status, purchase records.
  • Financial information — payment card details (processed by our payment provider, not stored on our servers), billing address, bank account information where applicable.
  • Internet and network activity — device and browser type, OS, pages viewed, in-app actions, crash logs.
  • Geolocation data — approximate location from IP address; precise geolocation only with your consent.
  • Inferences — drawn from the above to create a profile of your preferences and behaviour.

We do not knowingly collect Sensitive Personal Information beyond what a requested feature requires. We do not use or disclose Sensitive Personal Information beyond purposes permitted under the CCPA without your consent.

  • Directly from you — when you create an account, complete forms, make a purchase, or contact us.
  • Automatically — through cookies, SDKs, pixels and similar technologies (see Section 12).
  • From third parties — identity verification providers, payment processors, analytics providers, advertising partners, social media platforms if you connect your account, and publicly available sources.
  • To provide, operate, maintain and improve the Service
  • To create and manage your account and authenticate your identity
  • To process transactions, including billing and refunds
  • To communicate with you — support, service announcements, security alerts
  • To personalise content, features and recommendations
  • To measure performance, conduct research and develop new features
  • To detect, prevent and investigate fraud, abuse and security incidents
  • To comply with legal obligations and enforce our legal rights
  • To send marketing communications where you have consented (see Section 13)

We rely on your consent, the necessity of processing to perform a contract with you, our legitimate interests in operating and improving the Service, and compliance with legal obligations.

  • Service Providers — hosting, payment processing, analytics, customer support, communications and identity verification, each bound by written agreements restricting their use of your information.
  • Professional advisors — legal counsel, auditors and insurers.
  • Governmental authorities — where required or permitted by law, including in response to a subpoena, court order or regulatory request.
  • Corporate transaction parties — in connection with a merger, acquisition, financing or sale of assets, subject to confidentiality obligations.
  • Other parties — with your consent or at your direction.
We do not sell your Personal Information for monetary consideration. Certain disclosures to advertising and analytics partners may constitute a "sale" or "sharing" under the CCPA or "targeted advertising" under US State Privacy Laws. You may opt out as described in Section 14.
Financial data and Plaid. Au uses Plaid Inc. ("Plaid") to connect your financial accounts and retrieve your financial data. By connecting an account, you authorise Plaid to access your account information, transaction history, balances and related financial data from your financial institution, and you agree to Plaid's End User Privacy Policy at plaid.com/legal. You may view and manage your Plaid connections, or request deletion of your data from Plaid's systems, at my.plaid.com, or by contacting Plaid directly at privacy@plaid.com. Disconnecting a bank account within the Application revokes Au's access to that data and triggers deletion of the associated Plaid connection.

The Company is based in Ontario, Canada. Personal Information may be stored and processed in Canada, the United States and other jurisdictions where we or our Service Providers operate. We use contractual, technical and organisational safeguards to protect transferred Personal Information.

Quebec residents: we conduct a privacy impact assessment before transferring Personal Information outside Quebec as required by Law 25. For transfers from the EEA, UK or Switzerland to countries without recognised adequate protection, we implement Standard Contractual Clauses or equivalent mechanisms. You may request a copy by contacting us at Section 19.

We retain Personal Information only as long as necessary to fulfil the purposes for which it was collected, to comply with legal, accounting and tax obligations, to resolve disputes and to enforce our agreements. When no longer required, we securely destroy, erase or de-identify it.

We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the Personal Information in our custody, including access controls, encryption in transit, secure development practices, employee training and incident response procedures.

No method of transmission over the internet is fully secure. If we become aware of a security incident affecting your Personal Information, we will notify you and applicable regulators as required by law.

If and to the extent the Company is a "financial institution" under GLBA, we collect nonpublic personal information from applications, transactions and interactions with our Service Providers. We disclose such information only as permitted by GLBA — to Service Providers performing services on our behalf, to complete authorised transactions, and as required by law. We do not disclose nonpublic personal information to non-affiliated third parties for their own marketing purposes.

The Service is not directed to children under 13 (under 14 in Quebec), or under any higher minimum age applicable in the child's jurisdiction (16 in the EEA and UK; 18 in India). If we learn we have collected Personal Information from a child without verified parental consent, we will delete it promptly. Parents or guardians may contact us at Section 19.

We and our Service Providers use cookies, SDKs, pixels, local storage and similar technologies to operate the Service, remember preferences, measure usage and, where required consent exists, deliver targeted advertising. You may control these through your browser settings, mobile device settings (including Limit Ad Tracking or App Tracking Transparency), and opt-out mechanisms within the Service. We honour Global Privacy Control signals where required by law.

Where required by law, we obtain your consent before sending commercial electronic messages. In Canada we comply with CASL. In the US we comply with the CAN-SPAM Act and, for telephone and SMS marketing, the TCPA and applicable state laws. You may withdraw consent or opt out at any time by following the unsubscribe instructions in any message, by updating your account settings, or by contacting us at Section 19. Withdrawal does not affect transactional or service-related communications.

Depending on your jurisdiction, you may have the right to access, correct, delete, or port your Personal Information; opt out of the sale, sharing or targeted advertising of your information; limit the use of Sensitive Personal Information; withdraw consent; and be free from unlawful discrimination for exercising these rights.

Quebec residents also have the right to data portability, to be informed of automated decision-making, and to request cessation of dissemination or de-indexing.

EEA, UK and Switzerland residents also have the right to object to processing, restrict processing, and lodge a complaint with your local supervisory authority.

California residents have the right to know the specific pieces of Personal Information collected, categories of sources, business purposes, and categories of third parties receiving your information.

To exercise any right, contact us at Section 19. We respond within applicable legal timeframes, verify your identity before acting, and will explain any denial. You may appeal any denial by writing to our Privacy Officer.

We process recognised opt-out preference signals, including the Global Privacy Control, as a valid request to opt out of the sale or sharing of Personal Information and targeted advertising where required by law. We do not otherwise respond to "Do Not Track" browser signals.

We may de-identify or aggregate Personal Information so it can no longer reasonably be used to identify an individual. We maintain and use de-identified information without attempting to re-identify it, except as permitted by law to test our de-identification processes.

The Company has appointed a Privacy Officer accountable for our compliance with this Policy and Applicable Privacy Laws. The Privacy Officer may be contacted as set out in Section 19.

We may amend this Policy from time to time. The amended Policy will be posted with a revised effective date. Where required by law, we will notify you of material changes and, if necessary, obtain your consent before those changes apply to you.

Questions, requests and complaints may be directed to:

Aurum Technologies Inc.

Attention: Privacy Officer

5685 Whittle Rd, Mississauga, Ontario L4Z 3P8

Email: privacy@au79.app

Telephone: 905-990-8243