Privacy policy
What this service collects, why it collects it, where it is stored, and the rights you have under Canadian privacy law.
Last updated August 3, 2026
1. Who is accountable
NorthVault is operated by NorthVault.
As required by the Personal Information Protection and Electronic Documents Act (PIPEDA), we have designated an individual accountable for our compliance:
- Privacy Officer: enquiries@northvault.ltd
If you are in Quebec, this person also serves as the Person in Charge of the Protection of Personal Information under Quebec's Law 25.
2. Which laws apply
We handle personal information in accordance with PIPEDA and, where applicable, the provincial private-sector privacy laws of Quebec (Law 25), Alberta (PIPA) and British Columbia (PIPA), together with Canada's Anti-Spam Legislation (CASL) for any commercial electronic messages we send you.
3. What we collect and why
We collect only what the service needs to function. We do not sell personal information, and we do not disclose it for a purpose you have not consented to.
Account information
- Your email address and display name — to identify your account and contact you about it.
- A scrypt hash of your password with a per-account salt. The password itself is never stored or logged.
- Display currency, theme and privacy preferences, and your role on the service.
- If you enable two-factor authentication: a shared secret used to verify your codes, and hashes of your unused recovery codes.
Wallet information
- Your balance in each supported asset.
- The transfer identifiers issued to your account.
- Every transaction: type, asset, amount, counterparty, any memo you write, and when it happened — needed to maintain an accurate ledger and to meet record-keeping obligations.
- Saved recipients in your address book, and your watchlist.
Identity verification information (KYC)
Verification is in three tiers, and we only collect what the tier you are applying for requires. Tier 1 is your declared information; tier 2 adds government identification; tier 3 adds evidence of the source of your funds. You choose how far to go — tier 2 is the point at which funds can move, and tier 3 only raises a limit.
Before you can send or swap, we are required to identify you. This is collected under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and its regulations, and consent is not required for a collection the law compels — but you are entitled to know exactly what it is:
- Your full legal name, date of birth and occupation or principal business.
- Your residential address in Canada.
- The method used to identify you, and — where the government photo identification method is used — the type of document, its number, the jurisdiction that issued it and its expiry date.
- The intended purpose of your account and the source of the funds or assets you expect to hold.
- Your answers to the determinations we are obliged to make: whether you are a politically exposed person or the head of an international organisation, and whether anyone else is instructing you or benefiting from the account.
- A record of each decision made about your verification, when it was made and which administrator made it, and a risk rating we assign.
- For tier 3: which kind of document you told us you would provide, and the reviewer's written record of what they examined — its issuer, its date, and what they confirmed from it.
- The files you upload at tiers 2 and 3 — photographs of your identification, and the financial statement — together with each one's size, format and checksum, and when it arrived.
Where your uploaded documents go. They are stored on our own server, outside the public web root, and are never reachable by URL alone — every request for one is checked against your session first. Only you and an administrator can open them, and they are excluded from backups that leave our infrastructure.
Upload them only through the verification pages. We will never ask for identification by email, and you should never send it that way: an emailed passport photograph sits in at least two mailboxes indefinitely, neither of which we control.
Refusing to provide this information is not a problem in itself — it simply limits what the account can do. Tier 1 alone lets you hold and view an account; sending, swapping and withdrawing need tier 2.
This information is visible only to administrators, is used only for identification, sanctions and anti-money-laundering purposes and to respond to lawful demands, and is never used for marketing.
Access and security information
- Active sessions, each recording the browser and operating system reported by your device, the IP address it connected from, and when it was last used.
- Sign-in attempts — successful and failed — with the outcome, IP address and time. This is what lets you spot access you do not recognise, and it is collected for security purposes as permitted under paragraph 7(1)(b) of PIPEDA.
Email we send you
- A welcome message when you open an account.
- Security alerts — a sign-in from a device we have not seen before, a password change, two-factor being turned off, and password reset links. These are sent to the address on your account and cannot be switched off: being told your password changed is not marketing, and an attacker who can silence the alert has already succeeded.
- Decisions about your verification or a withdrawal.
We keep a record of every message we attempt to send — the address, subject and whether it was delivered — so that a security alert that never arrived can be found. We do not send marketing email, and under CASL we would need your express consent before we did.
If you contact us
- Your name, email, subject, message and originating IP address.
4. Consent
By creating an account you consent to the collection, use and disclosure described here. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice — but withdrawing consent for information the service needs to operate means we can no longer provide you an account.
5. What we do not collect
- No advertising or analytics trackers. One exception, and it is not an advertising tag: the sign-up, sign-in and contact forms carry a Cloudflare Turnstile challenge to keep automated abuse off them. It loads a script from challenges.cloudflare.com on those three pages only, and Cloudflare receives your IP address and browser characteristics in order to decide whether you are a person. Turnstile is designed not to profile visitors or serve advertising, and we receive only a pass or fail. No other page loads it.
- No payment card or bank account details.
- No private keys or recovery phrases. The service does not hold cryptographic keys on your behalf.
- No images, scans or photographs of your identity documents — only the prescribed details described in section 3.
- No biometric information: no facial scans, no liveness recordings, no fingerprints.
- No credit report is pulled unless you choose the Canadian credit file verification method, and then only to confirm your name, address and date of birth. [Confirm this with your credit bureau agreement before you enable that method.]
6. Cookies
One cookie is set: a session token, so you stay signed in. It is httpOnly (unreadable by scripts), same-site, and marked Secure in production. Only a hash of it is stored on our side, so the session table is useless to anyone who obtains it. A second short-lived cookie appears during two-factor sign-in and is deleted immediately afterwards. Neither is used for tracking or advertising.
On the sign-up, sign-in and contact pages, Cloudflare Turnstile may set its own short-lived cookie as part of the anti-abuse check. It is set by Cloudflare, not by us, and only on those three pages.
7. Service providers and cross-border storage
PIPEDA requires us to tell you when your information may be processed outside Canada, and that while it is outside Canada it may be accessible to the courts, law enforcement and national security authorities of that country.
- Hosting: our hosting provider. Your account data is stored there.
- Market data — CoinGecko: price requests are made by our server, not your browser, so CoinGecko receives no information about you. Coin images are fetched and re-served by us for the same reason.
- Anti-abuse — Cloudflare (Turnstile): on the sign-up, sign-in and contact pages only. Your browser contacts Cloudflare directly, so Cloudflare sees your IP address and browser characteristics. Cloudflare is a US company and processes this outside Canada.
We remain accountable for personal information transferred to a service provider for processing, and use contractual means to require a comparable level of protection.
Disclosure to authorities. Separately from service providers, we may be required to report to FINTRAC — for example suspicious transactions, large virtual currency transactions, or a match against a terrorist property list — and to respond to a subpoena, production order or search warrant. Where a report of that kind is made, the law may prohibit us from telling you about it.
8. Retention
- Account, balance and transaction records: for as long as the account exists and then at least five years, which is the retention period the PCMLTFA regulations impose on transaction and client records.
- Identity verification records and the decisions made on them: at least five years after the account is closed. This is a legal obligation and it survives a request to delete your account — we will delete everything we are permitted to delete and tell you what we must keep, and why.
- Sessions: until you sign out, revoke them, or they expire after 7 days.
- Sign-in history: kept for as long as your account exists, and deleted with it.
- Contact messages: kept until we delete them. If you close your account afterwards the message itself remains, but it stops being linked to your account.
9. Your rights
Under PIPEDA and the provincial regimes you may:
- Access the personal information we hold about you, and be told how it has been used and to whom it has been disclosed. We respond within 30 days, as PIPEDA requires.
- Correct information that is inaccurate or incomplete. Name, currency and preferences are editable yourself in Settings.
- Withdraw consent and ask us to delete your account. Deletion removes your sessions, contacts and watchlist. Transaction and identity verification records are retained for the period described in section 8 because the law requires it; consent cannot be withdrawn from a collection the law compels.
- Portability — your full transaction history is downloadable as CSV from Settings → Your data. Quebec residents have a specific right to receive computerised personal information in a structured, commonly used format.
- Complain to us first. If you are not satisfied you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca, 1-800-282-1376), or to your provincial regulator: the Commission d'accès à l'information in Quebec, or the Information and Privacy Commissioner in Alberta or British Columbia.
10. Automated decisions
We do not use your personal information to make decisions about you based exclusively on automated processing. Identity verification decisions are made by a person, not by a system. You are told the outcome, and when it is not an approval you are told the reason and may submit again. Rate limiting temporarily slows repeated sign-in attempts from one address or against one account; it is a security control, not a decision about you, and it clears on a successful sign-in.
11. Safeguards
Passwords are hashed with scrypt and compared in constant time. Sessions are 256-bit random tokens, stored only as hashes. Sign-in is rate limited per account and per IP address. Suspending an account revokes its sessions immediately, and changing a password signs it out everywhere. The security guide describes this in more detail.
12. Breach reporting
If a breach of our security safeguards creates a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada, notify you as soon as feasible, and keep a record of the breach, as PIPEDA requires. Quebec residents will be notified in accordance with Law 25.
If you believe your account has been accessed without permission, change your password and revoke the other sessions from Settings → Security immediately, then tell us.
13. Children
The service is not directed at anyone under the age of majority in their province, and we do not knowingly collect their personal information.
14. Language
[If you serve Quebec residents, the Charter of the French Language requires a French version of this policy and of your contractual terms. Have one prepared.]
15. Changes
Material changes will be reflected in the date at the top of this page, and we will notify account holders where the law requires it.