Privacy Policy
Last updated and source-reviewed: July 11, 2026
1. Scope and accountability
GoodLedger ("we," "us," or "our") is responsible for personal information under its control. This policy explains our practices for goodledger.ca, inquiries, and client services. Canadian private-sector privacy laws apply according to the circumstances, including PIPEDA and applicable provincial laws. Contractual terms and professional obligations may add requirements for client information.
Our privacy contact is: Privacy Officer, our email address .
2. Information we collect
- Inquiry information: name, email address, organization, organization type, revenue band, accounting software, city or province, and message content submitted through the contact form or by email.
- Resource-request information: first name, email address, optional organization, referral and campaign attribution, and whether you separately consented to ongoing handbook updates.
- Client information: financial records, transaction data, donor or stakeholder information, credentials or access information, governance records, and other information required by the engagement.
- Website and analytics information: Google Analytics may collect or derive a cookie or client identifier, pages and events, referral information, approximate location, and device, operating-system, browser, and language information. Google may use an Internet Protocol address during collection and processing. Analytics identifiers are pseudonymous and may still be personal information.
3. How information is collected and used
We collect information directly from you, from a client organization that authorizes access, from service providers operating the website, and automatically through Google Analytics. We use it to:
- respond to inquiries and assess a potential engagement;
- deliver requested resources and, only where separately consented, send handbook corrections and related charity-finance updates;
- provide agreed bookkeeping, accounting, reporting, filing-support, and advisory services;
- operate, secure, troubleshoot, and improve the website and services;
- maintain records, bill for services, and meet legal, regulatory, contractual, insurance, and professional obligations; and
- create aggregate reporting where reasonably possible.
Where consent is the legal basis, the form and timing of consent depend on the sensitivity of the information and reasonable expectations. Using the website is not, by itself, treated as blanket consent to every practice.
4. Analytics and cookies
Google Analytics loads automatically on our pages and uses cookies or similar browser storage to distinguish browsers and measure use. We do not use an on-site consent banner. You can limit analytics by blocking or deleting cookies in your browser, using privacy controls or content blockers, or installing the Google Analytics Opt-out Browser Add-on. Blocking analytics does not prevent access to the site's core content.
Google processes analytics data under its own terms and privacy practices. We do not use advertising cookies on this website.
5. Service providers and cross-border processing
We do not sell personal information. We disclose it when reasonably necessary for the purposes above, with authorization, or as required or permitted by law. Website providers include:
- Netlify: hosts the website and processes and stores contact-form submissions on our behalf. See Netlify's privacy statement.
- MailerLite: processes resource-delivery and optional update subscriptions on our behalf. Resource delivery and ongoing updates use separate subscriber groups; requesting a resource is not treated as consent to ongoing email. See MailerLite's privacy policy.
- Google Analytics: processes website measurement data. See Google's Analytics data safeguards and Google's privacy policy.
These and other authorized providers may process information outside Canada, including in the United States. Information processed in another country may be accessible to its courts, law-enforcement bodies, and regulators under local law. Client-specific providers are addressed in the applicable engagement and service arrangements.
6. Retention
We retain information only as long as reasonably required for the identified purpose and applicable legal, tax, corporate, contractual, insurance, limitation-period, and professional obligations. Typical categories include:
- unconverted inquiries: ordinarily up to 12 months after the last substantive contact;
- resource-delivery records: ordinarily up to 12 months after delivery unless the address remains subscribed to updates, is needed to document consent or withdrawal, or a longer period is required by law;
- analytics data: according to the configured Google Analytics retention setting and Google's applicable processing rules;
- client engagement, billing, working-paper, and financial records: according to the engagement and the requirement applicable to that record category; and
- governing, ownership, long-term gift, and other permanent or extended-retention records: for the longer period required by the applicable rule.
There is no single six-year retention rule that applies to every charity, privacy, corporate, or client record.
7. Safeguards
We use administrative, technical, and physical safeguards appropriate to the sensitivity and context of the information, including access controls and encrypted transmission where supported. No system or transmission method is completely secure.
8. Access, correction, withdrawal, and complaints
You may request access to personal information under our control, request a correction, ask about our practices, or withdraw consent where consent is the legal basis, subject to legal and contractual limits. Every ongoing update email includes an unsubscribe method. Withdrawing update consent does not prevent delivery of a resource you already requested. We may verify identity before responding.
Under PIPEDA, we generally respond to a personal-information access request within 30 days unless a permitted extension applies. That statutory period does not apply to every general inquiry or complaint. Contact the Privacy Officer at our email address .
If a concern is not resolved, you may contact the Office of the Privacy Commissioner of Canada or the applicable provincial privacy regulator.
9. Changes
We may revise this policy to reflect changes in services, providers, law, or practice. The date above identifies the current version. A material change will be communicated in a manner appropriate to its significance.