Payroll runs on sensitive information, so we'll be specific about what we collect, why, and what we do with it. This policy covers the payroar.ca website (including the paystub and employment-letter generators) and the PayRoar payroll application.
Last updated: August 29, 2026 · Contact: [email protected]
Your account. Sign-in is handled by Auth0, a dedicated identity service — your password never touches our servers. We store your email address as your account identifier.
Payroll data you enter. Employers enter their company details and their employees' information: names, addresses, dates of birth, wages, tax claim amounts, and Social Insurance Numbers. This is the data required to calculate payroll correctly and to produce the records the CRA requires.
Information employees enter themselves. The employee portal lets an employee enter or update their own address, SIN, and tax claim amounts directly — so their SIN can reach us without passing through their employer at all.
Document generator entries. Information typed into the paystub or employment-letter generator is used to produce your preview and purchased document, and is not stored on our servers. An encrypted copy is held in your own browser for up to two hours so a purchased download can complete.
Support conversations. If you report a problem, we keep the report, any screenshots you attach, and the reply thread.
Technical records. Standard server logs and error records, including IP addresses (used for abuse protection and troubleshooting). Payroll figures and SINs are never written to logs.
No analytics trackers, no advertising pixels, no selling or renting of data, no marketing lists. The only cookies we set are the ones PayRoar needs to work (signing you in, completing a generator purchase).
SINs get stricter treatment than everything else: encrypted at rest with a key held outside the database, never shown in lists or pages, never written to logs, and never sent to your browser — the one exception is the T4 working copy, where the CRA requires the SIN to appear, generated only for the company's owner on request. The generators never ask for a SIN at all.
Only the service providers needed to run PayRoar, only the data each one needs to do its job:
Beyond that, we disclose information only if the law requires it.
The CRA requires payroll records to be kept for six years from the end of the tax year they relate to, so processed pay runs and the records behind them are kept — unchanged — for that period, even if you cancel. Everything else is kept only as long as your account needs it.
Employers can see and correct their information in the app, download their payroll records (stubs, remittance summaries and a full data export from the Account page) at any time, including before cancelling, and can request account deletion from the Account page. Deletion requests are honoured within 30 days — except for the payroll records the law requires us to keep for the retention period above, which are deleted when it ends.
Employees of our customers: your employer runs the payroll and is your first stop for questions about your data. Through the portal you can see your own pay records and correct your own details. If something needs more than that, contact us and we'll work it out with you and your employer.
If a breach of our safeguards creates a real risk of significant harm, we will notify the Office of the Privacy Commissioner and the affected people, as PIPEDA requires, and tell you plainly what happened and what we're doing about it.
If this policy changes in a way that matters, we'll say so on this page and update the date at the top. Questions? Write to [email protected].