Privacy
Privacy policy.
Effective: August 24, 2026
Last updated: August 25, 2026 — what changed
The short version
We collect only what we need to answer you, estimate a fee and deliver the work you engage us for. We never sell personal information. We do measure where visitors come from and which pages and guides they read, using HubSpot's analytics — a banner on your first visit lets you turn that off, and we honour Global Privacy Control if your browser sends it. We send no marketing email unless you expressly ask for it.
Who is responsible
Cadence Tax & Accounting Inc. is responsible for the personal information it collects. Privacy questions, requests and complaints go tohello@cadencetax.ca — put "privacy" in the subject line and the person responsible for privacy at Cadence will handle it.
What we collect, surface by surface
Browsing this site
As this is written, cadencetax.ca carries no advertising trackers and no ad networks. If we start running paid ads and that changes, this page will say so before any such tag goes live. What the site does load is HubSpot's analytics script, which sets cookies in your browser so we can see how many people visit, where they came from, which pages and guides they read, and which of those lead to someone asking for an estimate. That is why we measure anything: to know which writing is worth doing more of, and which channels are worth paying for.
You can refuse. A banner appears on your first visit with the option to turn tracking off, and we honour Global Privacy Control — if your browser sends that signal we treat it as a refusal without you having to click anything. Our hosting provider (Google's Firebase Hosting) keeps standard technical logs — IP address, pages requested, browser type — to deliver pages and protect the service, whatever you choose here.
The estimate form
When you ask us to schedule a fit and fee estimate, we ask for three things: your name, your email and your business name. A phone number and anything you add in the notes are optional. Where you file, how the business is structured, what you want handled and how current your records are are not asked here — they moved to the optional follow-up on the confirmation page, after a call is booked. If you arrived through a link carrying campaign tags (utm codes or an ad click id — the kind a newsletter or an ad appends), your browser keeps those tags, the page you landed on, the referring site and when that visit happened, and sends them with your request so we can tell which channel brought you. Visits without campaign tags record nothing. They describe the visit, not you; they stay in your own browser unless you submit the form, and once submitted they are kept for no longer than the request itself. We use what you send to answer one question: whether we're a fit, and at what fee. A phone number, if you leave one, is used only to reply to you about the estimate — never to send marketing texts. Please keep tax slips, SINs and account numbers out of the form — the estimate doesn't need them.
When you send the form, we set two cookies in your browser. The first holds the email address you just typed, so the confirmation page can show it back to you and a mistyped address is caught while you are still looking at the screen; it is readable only by this site, it deletes itself after ten minutes, and it is used for nothing else. The second does not contain your email address or anything else about you. It holds a random reference — a string of characters that means nothing on its own — which only our server can match back to your request. It exists so that if you answer the optional follow-up questions on the confirmation page, we can attach your answers to the request you just made without asking you to type your address again. It is sent only when you submit those answers, cannot be read by any script, can be used only once, and deletes itself after thirty minutes whether it is used or not. We also send a confirmation email to the address you gave us straight away — if it never arrives, that is your sign the address was mistyped, and you can email us to correct it.
The follow-up questions are entirely optional and the request is already complete without them. They ask about the shape of the business — how many entities, investment income, payroll size, GST/HST filing frequency, year-end and what the books are kept in — so we can scope the fee before we speak, and, separately and labelled as such, what the business does, where things stand today and whether you are leaning toward a package. That last group does not affect your fee. We use all of it for the same single purpose as the form itself.
The client portal
Signing in to portal.cadencetax.ca — with Google, with a sign-in link we email you, or with a code we text to a mobile number you have verified in the portal (Microsoft sign-in is planned) — shares your name, email address and sign-in identifiers with us through Google's Firebase Authentication. If you set up sign-in by text, your verified mobile number is one of those identifiers. We use these to secure your account and know who is who. Documents you share for your engagement live in the portal, under your engagement terms.
Once you are signed in, you can upload documents for your engagement in the portal. What you upload is stored in your portal account, and the portal shows you everything in that account, so you can check what arrived. Anything that reaches us outside the portal appears there only once we've added it to your account. We are building further ways to send documents in — by email and by text — and will describe them here before either goes live.
Email you send us stays with the conversation it belongs to. Our policy is to keep tax slips and SINs out of ordinary email — sensitive documents move through the portal instead.
Why we collect it
Four purposes, identified here so there are no surprises: to reply to you; to assess fit and prepare your estimate; to deliver the services you engage us for; and to meet the legal and professional obligations that come with tax work. If we ever want your information for a new purpose, we ask first.
Marketing is separate and opt-in only. We email guides or updates only to people who expressly checked the box asking for them, every such email includes an unsubscribe link, and you can withdraw that consent at any time.
Who we share it with, and where it lives
We do not sell or rent personal information. We share it only with service providers who process it on our behalf, under contracts that require them to protect it:
- Google (Firebase) — hosts this site and runs the portal's sign-in. Google may store and process data on infrastructure outside Canada, including in the United States, where it is subject to the laws of those jurisdictions, including lawful access by courts and authorities there.
- Cloudflare — runs the domain's DNS and forwards email sent tohello@cadencetax.ca to the inbox we read it in, so a message you send us passes through Cloudflare on its way. It also handles the redirect from the www address to this one, which means it sees the network address of that request. Cloudflare processes this on infrastructure outside Canada, including in the United States.
- HubSpot — customer-relationship software, hosted in the United States. It receives and stores your estimate request, sends the confirmation email that follows it, and provides the analytics described above. Your request reaches HubSpot one way only: our own server passes it on after you press send. The analytics script on the page does not read what you type into the form — that capability is switched off in HubSpot itself. Where you accepted tracking, HubSpot links the pages you read to the estimate request you send, so we can tell which of our writing actually helps people.
On storage location, plainly: documents you upload through the portal are stored in Google Cloud's Canadian region (Montreal). The rest of the personal information described above sits on infrastructure that is not limited to Canada. Sign-in account records cannot be limited to a Canadian region under the portal's current architecture — we say so here rather than promise otherwise.
How long we keep it
An estimate request that doesn't become an engagement is kept for 24 months from the last time you engaged with us, and is then deleted. Getting back in touch starts that period again. Client engagement records are kept for as long as the engagement and the retention periods tax law imposes — records supporting a filing generally must be kept for six years — and are then securely destroyed.
We should be straightforward about how this runs today: Cadence is not yet serving clients, and the deletion above is carried out by a person on a schedule rather than by an automated job. That is enough for the volume we hold now, and it is being built out properly before it needs to be. If you want your information deleted sooner, ask us and we will do it — you do not have to wait for a retention period to run out.
How we protect it
Connections to this site and to the portal are encrypted in transit, and data held with our providers is encrypted at rest. Access is limited to the people who need it to work on your file. No safeguard is perfect, which is why the next section exists.
If something goes wrong
If a breach of security safeguards creates a real risk of significant harm to you, we will notify you, report it to the appropriate privacy regulators, and keep a record of the incident, as the law requires.
Your access, corrections and choices
You can ask what personal information we hold about you, ask us to correct it, or withdraw consent to our handling of it (withdrawal may limit what we can do for you, and some records must be kept by law). Write to hello@cadencetax.ca, or by post at Floor 4, 325 Front St W, Toronto, ON M5V 2Y1, and we will respond promptly. If you're not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada or your provincial privacy regulator.
Changes to this policy
When our practices change, this page changes with them, and the effective date at the top of this page moves. Material changes get called out, not slipped in — every amendment we have made is listed here.
What has changed, and whenevery change since August 6, 2026
— one path, said plainly. Your estimate request now reaches HubSpot only through our own server: HubSpot's script used to be able to read the form from the page as a second copy of the same submission, and that capability is now switched off in HubSpot itself. The campaign tags described in the August 24 entry now arrive on your request record rather than only in the short-lived processing record — still kept no longer than the request itself, exactly as described. What we collect has not changed.
— two changes. A more precise sentence about what the portal shows you: everything in your portal account, rather than "everything we hold" — a document that reaches us outside the portal appears there only once we've added it to your account. And the estimate form now sends any campaign tags your visit arrived with (utm codes, ad click ids, the landing page and referring site) along with your request, so we can tell which channel brought you — described in "The estimate form" above. The tags stay in your own browser unless you submit the form.
— the estimate form now books a conversation, and asks for three things up front: your name, your email and your business name. Where you file, how the business is structured, what you want handled and how current your records are all moved to the optional follow-up on the confirmation page. The confirmation page also shows your address back to you again, so a mistyped address is caught on the spot — which means the form once more sets two cookies: one holding the address you typed (readable only by this site, gone after ten minutes, used for nothing else) and one holding a random reference that identifies your request without containing anything about you. The confirmation page loads no third-party code.
— retention got a number: if you ask for an estimate and we never end up working together, we keep that request for 24 months from our last exchange, then delete it. Deletion is done by a person on a schedule, not yet by an automated job, and this page says so plainly. The same day, the cookies the form set were reduced to a single random reference that contained nothing about you (the address-echo cookie returned two days later — see the entry above), and our mailing address was added beside our email under "Your access, corrections and choices", so you can reach us by post.
— the estimate form now asks for less. We no longer ask what the business does, what your current situation is, which package you are leaning toward, or how you would rather be reached; we do now ask, optionally, how current your records are. The confirmation page now offers an optional set of follow-up questions, described above, and a second short-lived cookie exists only to attach those answers to your request. Nothing else about what we collect has changed — no new provider, no new purpose.
— the portal now collects documents you upload after signing in, and those documents are stored in Canada. The portal also offers two more ways to sign in: a link we email you, and a code we text to a mobile number you verify — so a verified mobile number is now among the sign-in details Firebase holds. This page describes that. Nothing about the website's own collection has changed.
— Cloudflare is now named as a service provider: it runs our DNS and forwards email sent to hello@cadencetax.ca to the inbox we read it in. Nothing about what we collect has changed.
— the estimate form now sends to HubSpot, the confirmation page sets one short-lived cookie, and the site now measures page visits and where they came from with HubSpot's analytics, which you can decline.
— first published.