1. Who this policy covers
This policy applies when you contact, inquire about, or receive services from Wealthy Wave Accounting Inc. or WealthPillar Inc. (together, “we,” “us,” or “our”), including through our websites, Meta lead ads, Facebook or Instagram, Messenger, WhatsApp, email, phone, referrals, events, and our customer relationship management system (“CRM”).
The company identified on the form, advertisement, page, message, proposal, or engagement is responsible for that interaction. Wealthy Wave Accounting and WealthPillar maintain separate business records and use access controls intended to preserve that separation.
2. Information we collect
Depending on your interaction and the service requested, we may collect:
- identity and contact information, such as name, email address, telephone number, preferred contact method, city, and business name;
- inquiry and lead information, such as the service requested, form answers, campaign, ad, page, source, consent choices, communication history, appointment details, and follow-up status;
- client and service information you choose to provide, which may include business, accounting, tax, insurance-planning, family, financial, identification, and supporting-document information;
- technical and security information required to receive and protect a submission, such as timestamps, provider event identifiers, delivery status, device/browser information, and security logs; and
- information from Meta or another platform when you submit a lead form, message us, or authorize a connection, limited to the fields and permissions shown to you by that platform.
Do not send account passwords, Meta access tokens, payment-card PINs, or other authentication secrets through a lead form, chat, or ordinary email.
3. Sources and purposes
We collect information directly from you, from a person you authorize, from Meta and other communication providers you use to contact us, and from lawful referral or public-business sources where appropriate.
We use personal information to:
- respond to your inquiry, identify the appropriate business and service, schedule meetings, and provide requested follow-up;
- assess suitability, prepare proposals or engagement steps, deliver authorized services, maintain client records, and meet professional or legal obligations;
- record consent, contact preferences, do-not-contact choices, and unsubscribe requests;
- protect people, accounts, documents, systems, and integrations; detect abuse, fraud, duplicate submissions, or unauthorized access; and investigate incidents;
- measure service and campaign performance using aggregated or appropriately limited information; and
- send promotional electronic messages only where permitted by law and consistent with the consent or other lawful basis we rely on.
We will identify any materially new purpose and obtain additional consent when required.
4. Consent and communications
Submitting a form authorizes us to use the information to respond to that specific inquiry and coordinate the requested service. It does not automatically create a client, accountant, adviser, broker, or other professional relationship.
Where Canadian anti-spam law applies to a commercial email, SMS, or similar message, we rely on valid express consent, permitted implied consent, or another lawful exception. Our messages identify the sender and provide an unsubscribe method when required. You may withdraw marketing consent at any time by using the unsubscribe method, replying STOP to eligible text messages, or contacting the relevant privacy address above. Service, security, legal, and transaction messages may still be sent when necessary.
6. Retention and deletion
We retain personal information only as long as reasonably needed for the identified purpose, a continuing relationship, security and audit needs, dispute resolution, or legal, tax, insurance, professional, and regulatory obligations. Retention depends on the record type and context.
- Lead and inquiry records that do not become client records are periodically reviewed and are normally deleted or de-identified after they are no longer reasonably required.
- Consent, unsubscribe, do-not-contact, security, and audit evidence may be retained longer where needed to honour your choice, demonstrate compliance, or prevent abuse.
- Client and transaction records are retained for the period required by the applicable engagement, law, regulator, insurer, professional obligation, or limitation period.
When retention is no longer required, information is securely deleted, destroyed, or de-identified. Deletion from active systems may not immediately remove protected backup copies; those copies remain access-restricted and expire through the backup lifecycle.
7. Security safeguards
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information. These may include encrypted transport, encrypted or masked integration secrets, role-based access, separate business and privacy boundaries, multi-factor authentication, session controls, audit and security logging, backups, restricted hosting access, staff confidentiality, vendor review, and incident response procedures.
No internet or storage system is completely secure. If a breach creates a real risk of significant harm, we will investigate, take reasonable containment steps, keep required records, and notify affected individuals and regulators as required by law.
8. Your choices and privacy rights
Subject to applicable law and limited exceptions, you may ask us to:
- explain whether we hold your personal information and how it has been used or disclosed;
- provide access to your personal information;
- correct information that is inaccurate or incomplete;
- withdraw consent for future uses that rely on consent;
- delete or de-identify information that is no longer required; or
- review a concern about our privacy practices.
We may need to verify your identity before acting. We will respond within the time required by applicable law and explain any lawful limitation. For Meta-originated information, follow our Data Deletion Instructions.
If we do not resolve a privacy concern, you may contact the Office of the Privacy Commissioner of Canada.
10. Children and policy changes
Our lead-generation and professional services are not directed to children under 18. A parent or legal guardian should contact us before providing a minor’s information for a legitimate family-planning or service purpose.
We may update this policy when our practices, services, integrations, or legal obligations change. The current version and effective date will remain available at this URL. Material changes will be communicated when required.
