Your Data Stays in Canada

Customer Data and account credentials are stored in Canada. A small, named set of third-party processors handles narrow flows — payment processing, address autocomplete, edge caching — and is fully disclosed below.

Toronto + Montreal
TLS 1.2+ in transit
PIPEDA-aligned
Why it matters

Data residency is more than infrastructure

Where data lives shapes who can compel access to it, who oversees how it's handled, and how voters perceive the campaigns asking for it.

Predictable jurisdiction

When voter and donor data is held in Canada, it is governed by Canadian law. There is less ambiguity about which court has jurisdiction, less risk of conflicting legal obligations, and a clearer path to respond to government data requests.

Voter trust

Voters share personal information with campaigns — addresses, political opinions, donation history. Storing it in Canada signals that your campaign takes data stewardship seriously.

Regulatory alignment

Federal and provincial privacy commissioners increasingly scrutinise cross-border data transfers. Keeping personal information in Canada simplifies compliance with PIPEDA, Quebec's Law 25, and provincial PIPA acts.

Democratic sovereignty

Political-campaign data reflects the democratic engagement of Canadian citizens. Keeping it within Canadian borders is a matter of democratic sovereignty as much as legal compliance.

Infrastructure

Where the platform actually runs

The honest map of every system that touches your data.

Application serveriDigital Internet Inc., Toronto, Ontario — Canadian-owned and operated
Primary databasePostgreSQL on the same Toronto host, accessible only on the host's private network
Bulk + transactional emailAWS Simple Email Service in the Canada (Central) region (Montreal, Quebec)
Database backupsOn-host backups today; encrypted off-site backups to a Canadian region are on the roadmap
Encryption in transitTLS 1.2 or higher, HSTS preloaded, Let's Encrypt SSL via Nginx
DNS + edgeCloudflare for DNS and static-asset CDN — no Customer Data is stored at the edge
Payment processingStripe, Inc. (US) — handles card data only; never stored on RidingDesk servers
Address autocompleteMapbox, Inc. (US) — receives only address text typed by users; no other PII
Sub-processors

Every third party that touches data

Two of these are headquartered in Canada-region infrastructure; three are US-headquartered companies handling narrowly-scoped data flows. We disclose them rather than hide them.

iDigital Internet Inc.

Application hosting and primary database

CanadianToronto, Ontario

Amazon Web Services (Canada Central region)

Bulk and transactional email delivery

Non-CanadianMontreal, Quebec

AWS is a US company; the ca-central-1 region keeps the email content on Canadian soil

Stripe, Inc.

Subscription billing and donation payment processing

Non-CanadianUnited States

Card data is collected directly by Stripe, never stored on our servers

Mapbox, Inc.

Address autocomplete on address fields

Non-CanadianUnited States

Only the free-form address text typed by a user is sent — no account ID or other personal data

Cloudflare, Inc.

DNS and CDN for static assets

Non-CanadianGlobally distributed (US-headquartered)

Routes traffic to our Canadian servers; does not store Customer Data

A note on US-headquartered processors

Stripe and Mapbox are US-headquartered companies. Where we engage them, the data flow is narrow and disclosed. Replacing them with Canadian alternatives is on the roadmap; our priority is correctness today, not maximum theoretical purity, and we prefer to be honest about it rather than gloss over the reality. AWS is a US company, but the AWS Canada (Central) region keeps email content on Canadian soil.

Privacy law

Designed around Canadian privacy legislation

Federal, provincial, and Quebec-specific. We design for the strictest applicable law in any campaign's jurisdiction.

Federal

PIPEDA

Personal Information Protection and Electronic Documents Act

Canada's federal private-sector privacy law. RidingDesk is designed around its ten fair-information principles, with mandatory breach notification per s.10.1.

Quebec

Law 25

Act respecting the protection of personal information in the private sector

Quebec's modernised privacy law, with strict requirements for privacy impact assessments, consent, and breach notification. Our practices are designed around Law 25 for campaigns operating in Quebec.

Alberta

PIPA Alberta

Personal Information Protection Act

Alberta's substantially similar legislation. Our access, correction, and consent mechanisms align with PIPA Alberta requirements.

British Columbia

PIPA BC

Personal Information Protection Act

BC's privacy legislation for provincially regulated organisations. Our consent, access, and security safeguards align with PIPA BC.

Ontario

FIPPA

Freedom of Information and Protection of Privacy Act

For campaigns interacting with Ontario government data, our access and disclosure controls map to FIPPA expectations.

Elections Canada

Designed around the Canada Elections Act

The platform supports campaign workflows; your official agent and party headquarters remain authoritative for filings.

Voters list handling

Elections Canada provides the official voters list to registered political parties. RidingDesk imports that list into your campaign and applies access controls and audit logging on top. Disposal at the end of the campaign cycle is the campaign’s responsibility under the Canada Elections Act.

Contribution records

Donation records are stored with audit trails and retained for at least seven years to support post-campaign Elections Canada filings and Income Tax Act record-keeping requirements.

Privacy policy requirements

Registered political parties must publish and comply with a privacy policy under Elections Canada’s 2019 amendments. RidingDesk supports your campaign’s compliance with consent capture, an audit log, and a data-export tool. Publishing your campaign’s privacy policy remains something your campaign or party does directly with Elections Canada.

Questions about how your data is handled?

We’re happy to walk through the data-flow map with prospective customers, compliance leads, and privacy lawyers.