Privacy Policy
Last Updated: September 2, 2026
This Privacy Policy explains how Roost Pay Inc. ("RoostPay," "we," "us," or "our") collects, uses, discloses, and protects personal information when you visit roostpay.ca, use our iOS or Android apps, or use our web application (together, the "Services").
1. Who we are
RoostPay is operated by Roost Pay Inc., a company based in British Columbia, Canada.
- Address: 2187 Shannon Ridge Dr, West Kelowna, BC V4T 2L1, Canada
- Privacy & legal inquiries: hello@roostpay.ca
We design the Services for household employers and domestic employees in Canada only.
2. Laws that apply
We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA), as applicable. Where other Canadian provincial privacy laws apply to your use of the Services, we will handle personal information in a manner consistent with those requirements.
3. Information we collect
What we collect depends on how you use RoostPay.
A. Website visitors & waitlist
- Email address and related details you submit via waitlist, contact, or similar forms.
- Technical and usage data (for example page views, device/browser type, and approximate location) via analytics tools described below.
- Referral or campaign codes used to attribute marketing leads.
- Security signals used to reduce spam and abuse (for example reCAPTCHA tokens on contact forms).
B. Household employers (App accounts)
- Account credentials and profile details (name, email, phone, mailing address).
- CRA Business Number and related payroll-program information you enter.
- Household and scheduling information needed to run payroll and compliance workflows.
- Co-employer or authorized-user invitations (limited to the subscription allowance of one additional employer account).
- Billing-related contact details needed to manage your subscription.
C. Employees / caregivers (App accounts)
- Legal name, preferred name, email, phone, and mailing address.
- Social Insurance Number (SIN), stored with heightened safeguards (see Section 7). We collect SIN because it is required for Canadian payroll tax reporting workflows you ask us to support.
- Tax forms and credits (for example TD1 information), work-authorization details you choose to enter, and emergency contacts.
- Time, attendance, leave, expenses (including receipt images), pay history, and documents generated for your employment relationship (pay stubs, T4s, ROEs, contracts).
D. What we do not collect
- We do not collect or store employee or employer bank account numbers for payroll disbursement. You pay employees and remit to the CRA through your own banking channels using amounts calculated in the App.
- We do not knowingly collect personal information from children under 13, and the Services are not directed to children.
4. How we use personal information
We use personal information to:
- Provide, operate, secure, and improve the Services.
- Calculate payroll amounts, deductions, remittance figures, leave entitlements, and related records based on information you and your household enter. These calculations are performed by RoostPay's own software in the App—we do not send your payroll data to a third-party tax calculation service.
- Generate and store employment and tax documents you request (for example contracts, pay stubs, T4s, ROEs).
- Authenticate users, prevent fraud and abuse, and enforce our Terms.
- Process subscriptions and respond to billing or product support requests.
- Send service, security, and account messages. We send marketing or launch emails only with appropriate consent, and you may unsubscribe at any time.
- Comply with law, respond to lawful requests, and establish, exercise, or defend legal claims.
5. Consent
We collect, use, and disclose personal information with your knowledge and consent, except where permitted or required by law. For sensitive information such as SIN and detailed income records, we rely on express consent given when you (or an authorized household administrator) submit that information for payroll purposes.
You may withdraw consent where the law allows, subject to legal or contractual restrictions and reasonable notice. Withdrawal may limit our ability to provide parts of the Services.
6. How we share information
We do not sell personal information. We share information only as needed to operate the Services or as required by law, including with:
- Supabase — database, authentication, file storage, and related infrastructure for the App.
- Stripe / Link (Managed Payments) — subscription billing. For eligible charges, Stripe may act as merchant of record via Link. Payment card details are handled by Stripe; we do not store full card numbers.
- Email & messaging providers — currently Loops (waitlist and launch communications) and Resend (transactional/contact email). We plan to consolidate email delivery on Resend over time.
- Google Analytics 4 and Vercel Analytics / Speed Insights — website analytics and performance.
- Vercel — website hosting and related edge infrastructure.
- Google reCAPTCHA — abuse prevention on certain forms.
- Government authorities — only when you instruct filing/export workflows (for example T4 filing) or when we are legally required to disclose information.
- Professional advisors or successors in a corporate transaction, under appropriate confidentiality protections.
Household employers and authorized co-employers can see employee information needed to manage that household. Employees see their own records.
7. Storage, transfers, and safeguards
Personal information we collect for the App is stored on infrastructure configured for Canada-based data residency for our primary application database and files. Some service providers (for example email, analytics, or payment processors) may process limited data on servers outside Canada. Where that occurs, we use reputable providers and contractual or technical measures appropriate to the sensitivity of the data.
Safeguards include, as applicable:
- Encryption in transit (TLS) and encryption at rest.
- Heightened protection for SINs and similarly sensitive fields (including vaulted / column-level encryption where implemented).
- Access controls and row-level security so users only access their household or personal records.
- Private document storage for pay stubs, TD1s, T4s, and similar files, with authenticated retrieval.
- Monitoring, backups, and operational practices described on our Data Security page.
8. Retention
Important: RoostPay is a software provider. We are not the household employer. CRA and provincial employment-standards record-keeping duties sit with the employer. Employers must keep their own copies of payroll and tax records for as long as the law requires (typically six (6) years). RoostPay provides download and export tools so employers can obtain those copies while their account is active. We do not retain household payroll as a long-term CRA archive on the employer's behalf after account deletion.
RoostPay acts as a service provider to household employers. In the event an employer terminates their account, employee access to historical pay statements hosted within RoostPay will terminate. Employees must obtain required historical wage statements directly from their employer.
When an employer confirms account deletion, we remove the employer's account credentials immediately, cancel any RoostPay subscription immediately, and retain employee wage archives for seven (7) days so employees can download a copy. After that period, remaining operational data is permanently deleted. We keep only an anonymized deletion audit log (date, verification method, platform) for fraud prevention and legal compliance under PIPEDA.
Subscription cancellation (without account deletion): If you cancel your RoostPay subscription through billing settings (Stripe) but do not delete your account, you retain access through the end of the then-current paid period. After the subscription ends, we keep RoostPay-hosted household data for twelve (12) months, then permanently delete it. We email the primary employer when this retention period starts and recommend downloading your data. You may request earlier erasure anytime via in-app or website account deletion. If you resubscribe before the twelve months end, we cancel the scheduled deletion.
While an account is active, we retain the personal and household information needed to operate the Services (including encrypted SIN where collected for payroll). Marketing and waitlist contacts are retained until you unsubscribe or we no longer need them for the stated purpose. Analytics data is retained according to each provider's settings and our operational needs. When retention ends, we delete or irreversibly de-identify information, subject to backups and legal holds.
9. Your rights & account deletion
Subject to applicable law, you may request to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete personal information.
- Withdraw consent for optional processing (such as marketing).
- Export available household or personal records from the App where we provide export tools.
- Delete your account and associated personal information we are not legally required to retain.
Account deletion: You may initiate deletion from within the App (required for App Store / Google Play). You can also use our public website path at /account-deletion if you no longer have the App installed. After email verification and acknowledgment, we delete or de-identify account credentials and personal data according to your role:
- Primary employer: credentials removed and any RoostPay subscription canceled immediately; employee wage archives remain downloadable for seven (7) days, then household operational data is permanently purged.
- Co-employer: only that person's login and profile are removed; the household continues for the primary employer and employees.
- Employee: that employee's account credentials and personal profile data are removed; the employer's household payroll records remain until the employer deletes or the retention rules above apply.
To exercise these rights, use the App or website deletion flow, or email hello@roostpay.ca . We may need to verify your identity before responding.
10. Marketing preferences
You can unsubscribe from marketing or waitlist emails using the link in those messages or by contacting us. Unsubscribing from marketing does not stop transactional or account-critical messages.
11. Cookies and similar technologies
Our website uses cookies and similar technologies for essential site function, analytics (Google Analytics 4 and Vercel Analytics), and performance measurement. You can control cookies through your browser settings. Disabling certain cookies may affect site functionality or analytics accuracy.
12. Security incidents
We take breaches of security safeguards seriously. Where required by PIPEDA or other applicable law, we will assess incidents, notify affected individuals and regulators, and take steps to mitigate harm.
13. Complaints
If you have a privacy concern, contact us first at hello@roostpay.ca . You may also contact the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia .
14. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last Updated" date. Material changes may also be communicated through the Services or by email where appropriate.
15. Contact
Questions about this Privacy Policy or our privacy practices: hello@roostpay.ca .