Privacy Policy

Effective date: September 17, 2026  •  MinuteKeep, 2 Simcoe Street South, Oshawa, Ontario, L1H 8C1

MinuteKeep ("we," "our," or "us") is operated under the business name MinuteKeep, of 2 Simcoe Street South, Oshawa, Ontario, L1H 8C1, Canada. This Privacy Policy explains what personal information we collect through the MinuteKeep platform (the "Service"), why we collect it, how we use, share, store, and retain it, and what rights you have.

We handle personal information in a manner intended to meet the requirements of the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's Anti-Spam Legislation (CASL), and applicable provincial privacy legislation including British Columbia's and Alberta's Personal Information Protection Act and Quebec's Act respecting the protection of personal information in the private sector (Law 25).

This Privacy Policy forms part of, and is subject to, our Terms of Service — including the disclaimers of warranty in Section 16 and the limitations of liability in Section 17. By creating an account or using the Service you consent to the handling of personal information described here. If you do not agree, do not use the Service.

PLEASE READ THESE FIVE POINTS BEFORE YOU ENTER ANYTHING INTO MINUTEKEEP.

  • We cannot guarantee Canadian data residency. Our servers and database are in the United States. Your data — including directors' and shareholders' home addresses — leaves Canada and is subject to foreign law, including possible access by U.S. authorities. If you are subject to a Canadian data residency requirement, do not use the Service. (Section 8)
  • We cannot guarantee security. We describe the safeguards we use, but they are descriptions of practice, not warranties. No system is secure, and we do not warrant that yours will not be compromised. Security at your end is your responsibility. (Section 10)
  • Nothing you enter is privileged. MinuteKeep is not a law firm and provides no legal services. Solicitor-client privilege does not attach to anything in the Service, to support tickets, or to assistant conversations. (Section 2)
  • Some features send information to AI providers, including text you submit to an assistant and, only when an eligible owner explicitly starts AI organization, the selected PDF and its contents. AI processing may occur outside Canada. (Section 7)
  • You are responsible for other people's personal information that you enter. Directors, officers, and shareholders never agreed to this policy — you are the organization that collected their information, and it is your obligation to have the authority and consent to give it to us. (Section 6)

1. Definitions

2. Privacy Disclaimer — What This Policy Is and Is Not

This policy describes our current practices. It is not a warranty, guarantee, or condition, and it does not create any obligation beyond what applicable privacy law requires and what our Terms of Service provide.

3. Information We Collect

3.1 Account information

3.2 Corporate Data you enter

Corporate Data is used to operate the Service and to generate your documents. We do not sell, rent, or trade Corporate Data, and we do not disclose it to any third party for that party's own marketing or other independent purposes. It is disclosed only to the sub-processors listed in Section 5, for the purposes described there, and as required by law.

3.3 Payment information

Payments are processed by Stripe, Inc., a PCI-DSS Level 1 certified processor. Your card number, expiry, and CVC are collected and processed directly by Stripe and are never transmitted to or stored on our servers. We receive and store a Stripe customer and subscription identifier, and transaction records (amount, currency, date, status, invoice references, and any coupon applied) for billing, accounting, and tax purposes.

3.4 Technical and usage information

Collected automatically when you use the Service:

3.5 Communications with us

Support requests, bug reports, feedback, and correspondence, including your email address, the page you were on, the corporation involved, and the content of your message. Assistant conversations (Section 7) are stored.

3.6 Session replay, analytics, and advertising technologies

Where configured, we use Microsoft Clarity for session replay and heatmaps. This records a reconstruction of your interaction with the application — pointer movement, clicks, scrolling, navigation, rage-clicks, and page structure. Clarity's default configuration masks text entered into form fields, but we do not warrant that every field is masked in every circumstance, and you should assume that information displayed on screen may be captured.

We also use Google Analytics 4, the Meta (Facebook) Pixel, and Refgrow affiliate tracking. Details, purposes, and controls are in the Cookies & Tracking Policy.

3.7 Information from third-party sources

When you use the registry lookup, we query Innovation, Science and Economic Development Canada and, where supported, provincial registries, to retrieve publicly available corporate information for a corporation you identify. That information originates with the registry, may be incomplete or out of date, is not verified by us, and is used only to pre-populate your records.

3.8 What we ask you not to provide

Do not enter into the Service, or into any assistant or support message, any government identification number (including SIN), health information, biometric information, credit card number, banking password, or other sensitive information beyond what the Service asks for. The Service is not designed for it, and we do not want it.

3.9 Public ChatGPT corporate-records readiness check

MinuteKeep offers a public, read-only corporate-records readiness check that may be used through ChatGPT or another compatible client. The public check accepts only a supported jurisdiction, a high-level reason for organizing records, and optional broad record categories already on hand. It is designed not to accept a corporation name or number, business number, date, address, document, document link, account credential, payment information, or director, officer, or shareholder information.

We use those structured answers only to return a general-information checklist in the current request. MinuteKeep does not write the public-check inputs or result to its application database, corporate-record storage, support system, or product analytics. Technical service-provider logs may process network metadata as described above. Do not submit identifying information or documents to this public check.

4. How We Use Information

We do not sell personal information, we do not trade it, and we do not disclose it to any third party for that third party's own marketing purposes. Information submitted to an AI-assisted feature is processed as described in Section 7 and in the current Sub-processor list.

5. Legal Basis and Consent

Under PIPEDA we rely on:

You may withdraw consent at any time, subject to legal and contractual restrictions and on reasonable notice, by contacting support@minutekeep.ca. Withdrawal may prevent us from providing some or all of the Service, and may require your account to be closed. Withdrawal is not retroactive.

6. Personal Information About Other People

MinuteKeep is built to hold sensitive information about people who are not our users — most importantly the home addresses of directors, officers, and shareholders. Those individuals have not agreed to this policy. As between you and us, you are responsible for them.

When you enter or upload Third-Party Personal Information, send someone a questionnaire link that invites them to enter their own details, or choose AI organization for a PDF containing that information, you are the organization responsible for that information and we process it on your behalf and on your instructions. You represent and warrant that you have the authority, the lawful basis, and any required consent to collect it, disclose it to us, and have it processed by the listed sub-processors, and that you have given every notice required by law — including notice that the information may be stored and processed outside Canada (Section 8). This applies in particular to accountants and other professionals handling client or third-party documents.

If an individual whose information you entered contacts us with an access, correction, or deletion request, we will ordinarily refer them to you as the responsible organization, and we will assist you in responding. We will not delete or alter records within your account on a third party's instruction without your involvement, except where we are legally required to.

Questionnaire, invitation, badge, and download links are secured by unguessable tokens rather than by login. Anyone who obtains such a link may be able to view or submit the associated information. You choose who receives them and you bear the consequences of their forwarding or disclosure.

Detailed allocation of responsibility is in the Data Processing Terms, and you indemnify us in respect of Third-Party Personal Information under Terms, Section 18.

7. Artificial Intelligence

Some features use large language models operated by third parties outside Canada. In summary:

AI organization is optional for each PDF. The initial pilot is not available to other customers yet; ordinary manual placement remains available on Free and Pro. Choosing Not now sends nothing. Nothing moves unless the owner reviews the suggestion and chooses File here, and the suggestion does not verify the PDF's completeness, signatures, legal validity, or proper treatment.

An eligible owner can use Files & uploads > AI organization settings > Turn off AI organization to withdraw the saved permission used for future PDF reviews for that company. Turning it off does not change any file or manual placement. If the owner later chooses Organize with AI, MinuteKeep asks them to confirm again before the selected PDF is reviewed. This control does not change the retention rules in Section 9 or provider handling that already occurred.

Do not type anything into an assistant, or select a PDF for AI organization, unless you are prepared to have that information transmitted to the applicable provider and potentially processed outside Canada. AI output can be confidently wrong and is not legal advice. See the AI Disclosure & Disclaimer.

8. Where Your Data Is — No Canadian Residency Guarantee

We do not, and cannot, guarantee that your data stays in Canada. It does not. Our application servers and primary database are hosted in the United States, and most of our providers are United States companies operating global infrastructure.

8.1 The position, stated plainly

The current provider list and processing locations are at minutekeep.ca/subprocessors. We may change providers, regions, and configurations at any time, without notice. We give no commitment as to any current or future location.

8.2 Consequences you should understand

Information located outside Canada is subject to the law of the jurisdiction where it is located. It may be accessible to foreign courts, law enforcement, regulators, and national security authorities — including under United States legislation such as the CLOUD Act and the USA PATRIOT Act — potentially by compelled process, potentially without notice to you and, in some cases, without notice to us. We cannot prevent that and we do not warrant against it.

8.3 What we do, and what it is not

Consistent with PIPEDA Principle 4.1.3, we use contractual and other means intended to provide a comparable level of protection while information is processed by a provider: we contract on providers' data processing terms where available, we limit each provider to the minimum information needed for its function, and we consider providers' published privacy and security practices when selecting them. These are reasonable efforts, not a guarantee. Contractual protection does not displace foreign law and does not prevent lawful compelled disclosure.

8.4 Your consent and your decision

By using the Service you consent to the transfer, storage, and processing of Personal Information and Corporate Data outside Canada as described. You are responsible for deciding whether that is acceptable for you, your corporation, your clients, and the individuals whose information you enter, and for making any disclosure or obtaining any consent your own obligations require. If you are subject to a Canadian data residency requirement of any kind, you must not use the Service.

8.5 Quebec

For residents of Quebec: we have assessed the privacy-related factors of communicating personal information outside Quebec and use contractual means intended to afford adequate protection. Given the nature of the providers and the legal environment described in Section 8.2, you should not assume that protection is equivalent to that available in Quebec, and you should take that into account before entering personal information about Quebec residents.

9. Retention and Deletion

CategoryRetention
Account and Corporate Data (active account)For as long as the account is open
Generated documents and uploaded filesDuration of the account, then 90 days after closure, then deleted
A corporation you delete from within your accountRetained in a restorable archive for 90 days, then permanently deleted. During that period it is not visible or usable in the Service and can be reinstated only by us, at your request
Account personal information after closureDeleted within 30 days, except where retention is required by law or needed to establish or defend a legal claim
Billing and transaction records7 years, for tax and accounting purposes
Server and application logs (including IP addresses)90 days
Error monitoring recordsPer our provider's default retention, up to 90 days
Product analytics eventsUp to 24 months, then deleted or irreversibly aggregated
Session replay recordingsPer our provider's retention, presently up to 30 days
Assistant conversations (signed-in users)Up to 12 months
Assistant conversations (pre-signup visitors)Up to 12 months, keyed to an anonymous session identifier
Support and bug-report correspondence2 years after resolution, longer where needed for legal purposes
Aggregated and de-identified statisticsIndefinitely (not personal information)

When information is no longer needed for the purpose it was collected for, or the retention period has expired, we destroy, erase, or de-identify it in accordance with PIPEDA Principle 4.5. Where a retention period above provides for a restorable archive, you may ask us to reinstate the information during that period; we will make reasonable efforts to do so but do not guarantee that a reinstatement will succeed or be complete. Once a retention period has expired, deletion is permanent and irreversible and we are not able to recover the information. Copies may persist for a period in backups, logs, replicas, and provider systems after deletion from the live system, and we cannot guarantee simultaneous erasure everywhere. Retention periods stated as "up to" are maximums and may change; where a period depends on a provider's configuration, that provider's current default applies.

To close your account, email support@minutekeep.ca. Download anything you need first.

10. Security — Measures, Limits, and Your Responsibilities

The measures below are descriptions of current practice, not warranties or guarantees. No system is secure. We do not warrant the security of the Service or of your data, and we disclaim liability for security incidents to the fullest extent the law allows. Cybersecurity at your end is entirely your responsibility. See Terms, Section 9 and Section 17.

10.1 Measures we currently take

We have not obtained SOC 2, ISO 27001, or any comparable third-party security certification or audit report, and we do not hold one. We do not offer a security questionnaire response process, a penetration test report, or contractual security commitments. If you require any of those, the Service is not suitable for you.

10.2 The limits

No method of transmission or storage is completely secure. Compromise can occur through vulnerabilities in our code, in open-source dependencies, in our providers or their sub-providers, in the internet itself, or through credential theft, phishing, social engineering, insider action, or techniques not yet known. Email is inherently insecure and can be intercepted. We do not warrant that the Service, our providers, or your data are or will be secure, and we do not guarantee that any safeguard will prevent, detect, or mitigate any attack.

10.3 Your responsibilities

You are responsible for security at your end, including: the strength and secrecy of your credentials; enabling multi-factor authentication on your sign-in and email accounts; the security and patching of your devices, browsers, extensions, and networks; controlling who has access to your account and promptly removing access when it is no longer needed; the security of documents once you download, print, email, or forward them; and controlling the distribution of any tokenized link the Service generates. Compromise of your email account may allow a third party to take over your MinuteKeep account. Notify us immediately at support@minutekeep.ca if you suspect unauthorized access.

11. Sub-processors and Disclosure

We use a limited number of third-party providers, and share with each only the minimum information needed for its function. The authoritative, current list — naming each provider, what it receives, its purpose, and its processing location — is maintained at minutekeep.ca/subprocessors. As at the effective date it includes providers for hosting and database, object storage, payments, transactional email, authentication, error monitoring, product analytics, session replay, advertising measurement, affiliate tracking, artificial intelligence, and internal operational alerting.

We may add, remove, or change sub-processors at any time without notice to you. Continued use of the Service after a change constitutes acceptance of it.

We may also disclose personal information:

12. Cookies, Analytics, and Tracking

We use browser local storage and cookies for authentication and preferences, our own product analytics, Google Analytics 4, Microsoft Clarity session replay, the Meta (Facebook) Pixel, and Refgrow affiliate attribution. What each does, what it collects, how long it persists, and how to control or opt out of it is set out in the Cookies & Tracking Policy, which forms part of this policy.

Disabling non-essential cookies and tracking does not affect the core functionality of the Service. Disabling essential storage will sign you out and prevent the Service from working.

13. Breach Notification

If a breach of security safeguards involving personal information under our control creates a real risk of significant harm to an individual, we will notify affected individuals as soon as feasible, report to the Office of the Privacy Commissioner of Canada, notify other organizations or government institutions that may be able to reduce the risk of harm, and maintain records of every breach of security safeguards for at least 24 months, in accordance with PIPEDA. For Quebec residents we will also notify the Commission d'accès à l'information du Québec of any confidentiality incident presenting a risk of serious injury.

Notifications will describe the circumstances, the date or period, the information involved, the steps taken to reduce risk, steps you can take, and contact information. Notification is a statutory obligation, not an admission of liability, and it does not enlarge our liability beyond Terms, Section 17. Where a breach occurs at a provider, our ability to notify depends on that provider informing us.

14. Your Privacy Rights

14.1 Under PIPEDA

We may refuse a request where an exception under PIPEDA applies — including where disclosure would reveal personal information about another individual, where information is subject to solicitor-client privilege of ours, or where the request is vexatious or made in bad faith. We will explain any refusal.

14.2 Quebec residents (Law 25)

Additional rights: portability of computerized personal information you provided, in a structured, commonly used technological format; the right to be informed of and to submit observations on decisions based exclusively on automated processing; and de-indexation or cessation of dissemination in the circumstances the legislation provides. We do not make decisions about you based exclusively on automated processing that produce legal or similarly significant effects.

14.3 British Columbia and Alberta residents

Your personal information is also protected under the applicable provincial Personal Information Protection Act, which provides substantially similar rights.

14.4 Making a request

Email support@minutekeep.ca with enough information for us to verify your identity and locate your records. We respond within 30 days and will tell you if we need an extension and why. If your request concerns information entered by one of our customers about you — for example if you are a director or shareholder of a corporation administered by a customer — see Section 6; we will ordinarily refer you to that customer as the responsible organization.

15. Children

The Service is a business tool for adults. It is not directed at individuals under 18 and we do not knowingly collect their personal information for account purposes. If we learn that we have, we will delete it promptly. Note that corporate records you enter may lawfully include information about a minor (for example a minor shareholder or beneficiary); that information is Third-Party Personal Information and Section 6 applies to it.

16. Do Not Track and Global Privacy Control

There is no accepted standard for responding to browser "Do Not Track" signals, and we do not currently alter our practices in response to them. Where a browser or extension transmits a recognized opt-out preference signal, we will honour it to the extent applicable law requires and our tools support it. You can control tracking directly using the methods in the Cookies & Tracking Policy.

17. Links to Other Sites

The Service links to third-party websites and services, including our providers, our affiliate program, and material referenced in our blog and help content. This policy applies only to MinuteKeep. We are not responsible for third-party privacy practices and encourage you to review their policies.

18. Changes to This Policy

We may update this policy to reflect changes in practices, technology, providers, or legal requirements. For material changes we will update the effective date, notify you by email to your account address at least 30 days before they take effect, and, where required by applicable legislation, obtain renewed consent for any new use of personal information. Non-material changes — including routine updates to the sub-processor list — take effect on posting. Continued use after the effective date constitutes acceptance. Previous versions are available on request.

19. Privacy Officer

In accordance with PIPEDA Principle 4.1, we have designated an individual accountable for our compliance with this policy, reachable as follows:

Contacting the Privacy Officer is contacting MinuteKeep, a software business. It is not contacting a lawyer, and the correspondence is not privileged.

20. Complaints and Regulators

Please raise any privacy concern with us first at support@minutekeep.ca. We investigate and respond within 30 days. If you are not satisfied, you may contact: