How Ghumman Advisory Group Ltd. collects, uses, stores and protects information in Ghumman Advisory Books.
Last updated 23 September 2026.
Ghumman Advisory Group Ltd. (“we”) operates Ghumman Advisory Books, bookkeeping software used by our staff to keep books for our clients. This policy covers information handled in that software.
Two groups of people appear here: our clients, whose financial records we keep, and the individuals at those clients who sign in to see their own books. We are accountable for information in our custody under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta’s Personal Information Protection Act (PIPA).
Three kinds of information, for three different reasons.
We do not collect information about individuals who are not connected to a client’s books, and the software has no advertising, tracking pixels or analytics that follow people across other websites.
Where a client uses QuickBooks Online, we connect to it with that client’s permission, through Intuit’s authorisation process.
Bank activity reaches us either as a statement file a client or our staff uploads, or — where a client chooses to set it up — through a regulated account-aggregation provider.
We do not ask for, receive or store online banking credentials. Where an aggregator is used, the client enters those credentials with the aggregator, never with us, and we receive only transaction records.
We use software, including a third-party language model, to suggest which account a transaction belongs to. Being specific about this matters more than the usual phrasing about “improving our services”.
Client financial records are stored in Canada, in the ca-central-1 region. That was a deliberate choice: CRA Information Circular IC05-1 expects Canadian books and records to be kept in Canada unless permission is obtained otherwise.
Some processing necessarily happens outside Canada — the application is served from infrastructure with locations in the United States, and QuickBooks and the categorisation model are United States services. Information handled outside Canada may be accessible to authorities there under their laws. Clients are told this before a connection is made, and it is listed below.
| Provider | Role | Location |
|---|---|---|
| Supabase | Database and authenticationAll client financial data, user accounts | Canada (ca-central-1) |
| Vercel | Application hostingNo data at rest; processes requests in transit | United States |
| Intuit (QuickBooks Online) | Source of accounting recordsThe client's own books, under the client's own agreement with Intuit | United States |
| Anthropic | Transaction categorisationTransaction descriptions, amounts and dates sent for categorisation | United States |
| Infisical | Secrets managementApplication credentials only; no client data | United States |
We do not sell information, and we do not share it with anyone for their own marketing.
Books and records are kept for six years from the end of the tax year they relate to, which is the retention period the Income Tax Act and the Excise Tax Act require. We keep original documents rather than only what was extracted from them, because CRA expects the original to remain legible and available.
Account information is deleted when an account is closed. Audit records are kept for the same six years and cannot be altered or removed, by design.
No system is perfectly secure. If a breach creates a real risk of significant harm, we will notify the affected individuals and the Office of the Privacy Commissioner of Canada as PIPEDA requires, and keep a record of the breach.
Under PIPEDA and Alberta PIPA you may:
Write to info@ghummanadvisory.ca and we will respond within 30 days. If you are not satisfied with our answer, you may complain to the Office of the Privacy Commissioner of Canada, or to the Office of the Information and Privacy Commissioner of Alberta.
If this policy changes in a way that materially affects how information is handled, we will tell affected clients before the change takes effect. The date at the top shows when it was last revised.
Questions about this document: info@ghummanadvisory.ca