Website information
Privacy Policy
How enquiries, the client portal, optional measurement and the website’s tools handle information.
Drafted September 24, 2026 · Operator approval required before public launch
About this policy
This policy describes the intended handling of information through this Versa website. For questions about your information, contact info@versallp.ca or call (905) 234-6925. Separate engagement documents and service-provider notices may apply to accounting work, the client portal or an external booking service.
Information you choose to provide
A contact-form enquiry may include your name, email, optional phone number and business name, the service you’re interested in, how you’d prefer a reply and a short message. The questions at /start also ask about your situation in general terms — for example a revenue band, your year-end month, how current your books are or what kind of CRA letter you received — so the first conversation can start where you are. We use these details to respond, to decide who at the firm is best placed to reply and how soon, and to prepare for that conversation. Do not include social insurance numbers, tax slips, passwords, banking information or other confidential records.
How enquiries are kept
Enquiries, answers to the /start questions and the firm’s notes are stored in the firm’s own database. Contact details, answers, messages and uploaded documents are encrypted before they are stored, and only signed-in staff can read them. To see which parts of the website bring in enquiries, and later clients, the firm also keeps a reporting record that links an enquiry to how the visitor found the site; that record holds your name, email and phone number so that a repeat enquiry is recognised as the same person. The firm also records how an enquiry was sent — the type of device, browser, the page and the site that referred you — but not your IP address or full browser details. With advertising measurement allowed, the ad-click identifier from your visit is kept with your enquiry so a resulting engagement can be reported back to the advertising platform as a conversion; with analytics allowed, the analytics client identifier is kept for the same purpose. Your answers produce a triage summary — which service is likely relevant and how quickly to follow up. It is a prompt for the firm, not an automated decision: a person reviews every enquiry, and no one is refused service by the summary.
Researching business enquiries
When you send an enquiry, the firm may use an AI research service to look up publicly available information about the business you represent — for example what it does, its size and its public filings — so the first conversation is better prepared. Only your name, the business name or website you gave us, your email domain and the text of your enquiry are used for this; your answers about your finances and any documents are never sent. The research runs through the Vercel AI Gateway and the model providers behind it, possibly outside your province or Canada, and the result is stored encrypted with your enquiry and visible only to the firm’s staff. It is a preparation aid, not a decision about you.
Follow-up emails
After you send an enquiry the firm may email you about it: a confirmation, a reminder if a consultation hasn’t been arranged, and messages from the team. These relate to your enquiry and stop when it is resolved or you ask. Occasional general tax-date reminders are sent only if you tick the box asking for them, and every one includes an unsubscribe link. Replies you send to the firm’s emails are stored with your enquiry.
Client portal
Once you engage the firm, you can sign in to the client portal with a single-use link sent to your email. Signing in sets a session cookie that expires after 12 hours. The portal shows the documents and information the firm has asked for, lets you upload files — up to 3 MB each — and exchange messages with the team. Tax slips, bank records, CRA authorizations and ID are requested only after engagement, through the portal. Uploaded files are encrypted before they are stored and are visible to the firm’s staff.
Service providers and delivery
A configured website host processes technical request information. Enquiries and the firm’s records are stored in a PostgreSQL database with a hosting provider the firm selects. The implementation supports Resend for sending and receiving email, Upstash Redis for abuse prevention and duplicate-request handling, and Cloudflare Turnstile for form-security checks. The deployed providers and their processing locations must be confirmed before this website is made public. External services may process information outside your province or Canada, according to their contracts and policies. Contact the firm for the applicable provider information.
Security and temporary records
Forms validate requests and use abuse-prevention controls. A network address, when available, is converted into a keyed hash for temporary rate-limit counters; the application does not intentionally log enquiry contents, contact information or captcha tokens. Duplicate-request records hold a hashed request fingerprint rather than the enquiry text. Links that open your enquiry or the portal contain a random token that is stored only as a hash. No website or email channel can guarantee absolute security.
Website chat assistant
The optional chat sends the messages you type, and the address of the page you are viewing, to an AI model through the Vercel AI Gateway so the assistant can reply. The gateway and model providers process them under their own terms, possibly outside your province or Canada. The assistant gives general information only, not tax, accounting or legal advice. This application does not intentionally log chat messages. If you send your details or request a call back from the chat, the conversation is included with your inquiry so you do not need to repeat it. If the firm turns on conversation summaries, a chat that ends without contact details may also be emailed to the firm. Do not share social insurance numbers, tax slips, passwords, banking information or other confidential records in the chat.
Cookies
Three cookies are needed for the site to work and are always set when you use the feature: one lets you return to your /start answers and booking for 30 days after sending them, one keeps you signed in to the client portal for up to 12 hours, and one keeps staff signed in. Everything else is optional and off until you opt in through cookie preferences. With analytics allowed, the site stores how you first found it (for up to 90 days), a 30-minute visit identifier and a device identifier (up to 400 days), and reports page views to the firm’s own reporting — contact fields and message contents are never part of it. With advertising measurement allowed, it also keeps an ad-click identifier for up to 90 days so a resulting enquiry can be credited to the ad. Optional configuration also supports Google Analytics, Google Ads measurement and Microsoft Clarity. Clarity records how pages are used — scrolling, clicks and session replays in which typed text, form fields and the chat are masked — and, like Analytics, loads only after you allow site analytics; it is never loaded on the /start questions, the client portal or the staff portal. Advertising personalization and enhanced conversions are not enabled by this implementation. You can reopen Cookie preferences in the footer and change your choices at any time; your choice is remembered for up to 180 days.
Free business tools
Cash-runway values are calculated in your browser and are not submitted through the calculator. The employee-or-contractor checker scores your answers in your browser and does not send or store them. The year-end checklist saves checked-item identifiers in local storage on your device, without attaching your name or email. Resetting the checklist clears its selection. A downloaded or printed copy is controlled by you. Clearing browser storage removes locally saved preferences and checklist progress.
Retention, access and questions
Enquiry information is kept as long as needed to respond, administer a resulting relationship, meet applicable professional and legal obligations and address legitimate business needs. The firm must approve its deployed retention and deletion schedule before launch; this policy does not invent a retention period. Contact info@versallp.ca to ask about access, corrections, deletion or privacy concerns. Requests are subject to identity verification and applicable requirements.
External links and updates
Booking services, Google Maps directions and other linked websites have their own terms and privacy practices. This policy may be updated when the site’s operation changes. Review the version shown here and contact the firm for clarification.