Privacy Policy

Last updated August 9, 2026 · Version 2026-08-09 · Piste Blanche Consulting LLC (“Steer the Books”)

This policy explains how Piste Blanche Consulting LLC (“we”, “us”) handles personal information in connection with Steer the Books — our websites, web application, firm portal, mobile apps and related services (the “Service”). It should be read together with our Terms of Service. We do not sell personal information.

1. Who we are & scope

Steer the Books is fixed-asset, depreciation and business-records software for companies and accounting firms in Canada and the United States, operated by Piste Blanche Consulting LLC. Privacy contact: support@steerthebooks.com. This policy covers visitors to our public sites, account holders and their invited users, and personal information contained in customer data processed through the Service.

2. Our role: controller vs. processor

For account and site data (registration details, billing, security logs, demo requests, marketing-site analytics) we decide how and why data is processed — we act as the “controller” (or equivalent under your local law). For customer data — the business records, documents, client information and other content that customers and their users enter into the Service — the customer is responsible for the data and we process it only to provide the Service, as a processor/service provider. If your employer, company or accounting firm gave you access, direct requests about that data to them first; we will assist them as described in our data-processing terms.

3. Information we collect

  • Account & signup: name, company/firm name, work email, phone, password (hashed), country and province/state, position, avatar, language preference.
  • Customer data: the asset, financing, accounting, document, message and contact data you or your organization enter, including personal information it may contain about employees, clients or counterparties.
  • Billing: plan, subscription status, invoices and payment metadata. Card payments are processed by Stripe — we never see or store full card numbers.
  • Usage & security: sign-in events, IP addresses, device/browser information, two-factor codes and delivery, audit logs of actions in the Service, and records of your acceptance of our Terms (version, date, IP).
  • Communications: support requests, demo requests, and emails you exchange through the Service’s email features.
  • Signatures: where you use e-signature features, signature images and signing metadata (time, IP) needed to evidence the signing.

4. How we use information

We use personal information to: provide, operate and secure the Service (including authentication and 2FA); process billing through Stripe; provide support and respond to requests; send transactional and service notifications (with preferences you can manage in-app, and unsubscribe links where required); maintain audit trails and evidence of terms acceptance; monitor for abuse, fraud and security incidents; improve the Service; and comply with legal obligations. Where consent is the applicable basis (e.g., optional communications), you may withdraw it at any time.

5. Storage, residency & security

Customer data is currently stored and processed in the United States, on Microsoft Azure infrastructure. Each account is assigned a data region (Canada or United States) based on the jurisdiction chosen at signup. Canadian-region infrastructure is planned: when it is available, accounts assigned the Canadian data region will be migrated to it automatically and this policy will be updated. Until then, Canadian accounts’ data is hosted in the United States as described in Section 10. Limited data (e.g., billing via Stripe, email delivery) may be processed by subprocessors in other regions under contractual safeguards.

Data is encrypted in transit (TLS) and at rest. Access to accounts requires a password and, by default, a one-time code (2FA). Internal access to customer data is restricted to what is needed to operate and support the Service and is logged. We never ask for your password or one-time codes by email or phone. No system is perfectly secure; please use strong, unique passwords and protect your devices.

6. Subprocessors & sharing

We share personal information only with:

  • Stripe, Inc. — payment processing and subscription billing.
  • Email delivery providers (currently Resend, Inc.) — transactional email (codes, notifications, documents you choose to send).
  • Cloud hosting and infrastructure providers (currently Microsoft Azure) — hosting, storage and backups, currently located in the United States.
  • Your organization and the users/firms it authorizes — administrators of your account, and accounting firms or external accountants granted access by your organization, per the permissions your organization controls.
  • Authorities and advisors where required — to comply with law, enforce our terms, or protect rights, safety and security; and in connection with a business transaction (merger, acquisition), subject to this policy.

We do not sell or rent personal information, and we do not share it for cross-context behavioural advertising.

7. Cookies

We use strictly necessary cookies: session and security cookies (sign-in, activity/idle timeout, trusted-device for 2FA), preference cookies (active company, view options), and a first-party pageview counter on our public pages. We do not use third-party advertising or cross-site tracking cookies. Blocking necessary cookies will prevent sign-in.

8. Retention

We keep account data for the life of the account and for a reasonable period afterwards for legal, billing and audit purposes. Customer data of cancelled accounts remains exportable for the windows described in the Terms (30 days after cancellation in good standing; 90 days’ preservation during payment suspension), after which it may be permanently deleted. Backups roll off on a fixed schedule. Terms-acceptance records, invoices and audit logs may be kept longer where required for legal evidence or tax purposes.

9. Breach notification

If a breach of security safeguards affects personal information under our control and creates a real risk of significant harm (or meets the notification threshold of your applicable law), we will notify affected customers and the required authorities (e.g., the Office of the Privacy Commissioner of Canada, provincial regulators such as Quebec’s CAI, or U.S. state attorneys general) without undue delay, and keep records of the incident as required by law.

10. Your rights — Canada (PIPEDA, provincial laws, Quebec Law 25)

Where PIPEDA, Alberta/BC PIPA or Quebec’s Act respecting the protection of personal information in the private sector (as modernized by Law 25) applies, you may: request access to and correction of your personal information; withdraw consent (subject to legal/contractual restrictions); request information about how your data is handled and to whom it is disclosed; and complain to us and to the relevant regulator (OPC, or your provincial commissioner, including Quebec’s Commission d’accès à l’information). Quebec residents may also request cessation of dissemination (de-indexing) and data portability in a structured, commonly used technological format, where applicable. The person responsible for the protection of personal information is the operator’s privacy officer, reachable at support@steerthebooks.com.

Storage outside Canada. Personal information in the Service is currently stored and processed in the United States (Section 5). PIPEDA does not prohibit storing personal information outside Canada; it requires that information transferred for processing receive a comparable level of protection through contractual or other means, and that we be transparent about the transfer — this policy is that disclosure. We apply the same safeguards described in Section 5 regardless of location. While your information is stored in the United States, it may be subject to lawful access requests by U.S. courts and authorities under U.S. law. A Canadian hosting region is planned; accounts assigned the Canadian data region will be migrated to it automatically when it is available, and this policy will be updated at that time.

11. Your rights — United States (CCPA/CPRA & state laws)

Where the California Consumer Privacy Act (as amended by the CPRA) or a similar state privacy law (e.g., Virginia, Colorado, Connecticut, Texas) applies, you may request: to know/access the personal information we hold about you; correction; deletion; and portability. We do not sell or share personal information as those terms are defined in the CCPA, and we do not use sensitive personal information beyond what is necessary to provide the Service, so no opt-out is required. We will not discriminate against you for exercising rights. You may use an authorized agent where your law provides for one; we will verify requests before acting on them. Note that most data in the Service is business data processed on behalf of our business customers — where that is the case we will refer your request to the relevant customer and assist them.

12. Visitors from other regions

The Service is offered to businesses in Canada and the United States. If you nonetheless access it from a region with its own data-protection law (such as the EEA/UK under GDPR), we extend the same core rights as a courtesy — access, correction, deletion, portability and objection — via support@steerthebooks.com, and process personal information on the legal bases of contract performance, legitimate interests (service operation and security), consent where applicable, and legal obligation.

13. Children

The Service is for business use and not directed to children. We do not knowingly collect personal information from anyone under 18 as an account holder; if you believe a child has provided us personal information, contact us and we will delete it.

14. Changes to this policy

We may update this policy; the current version and date always appear at the top of this page. Material changes will be notified by email or in-app and, where the change affects the terms you accepted, we will ask you to review and re-accept.

15. Contact & requests

To exercise any right or ask a privacy question, email support@steerthebooks.com with the subject “Privacy request”. We will respond within the time required by your applicable law (30 days in most Canadian cases; 45 days under the CCPA, extendable as permitted). Mailing address: Piste Blanche Consulting LLC, [Operator Legal Address — to be completed by the owner].