Why zero data collection matters for your review
Every calculator here runs entirely in the member’s browser. The TFSA and RRSP tools compute with plain JavaScript against CRA’s own published figures; the GIC tool works out simple or compound interest the same way and checks the result against CDIC’s and the relevant provincial deposit insurer’s coverage limits. Nothing a member types — a balance, an income, a deposit amount — is sent to us, to you, or to any server in between.
That matters for the question your review almost certainly asks: does this send personal information across a border, and if so, whose privacy law governs it? Under PIPEDA, that question only has something to attach to once personal information is actually transferred to a third party for processing — the Privacy Commissioner's own guidelines for processing personal data across borders frame a transfer as a “use” the transferring organization stays accountable for, protected through a contract. Because no personal figure ever leaves the browser here, there is no transfer for that framework to reach — not because a data-processing agreement permits one, but because the precondition never occurs. The one thing the wider site collects — an anonymous province-and-income-band tally, described in full on our privacy page — is opt-in, contains no typed figure, and is not part of any embed you would put on your site.
This is also the shape of arrangement both Canadian prudential frameworks treat as light-touch. Ontario's FSRA expects outsourcing risk to be “properly identified, assessed, and managed” while “accountability and ownership for any outsourced or co-sourced function is maintained by” your institution, never transferred to us. For the small number of federally regulated credit unions, OSFI's Guideline B-10 says the same in more explicit terms: due diligence, contract review and exit planning scale to an arrangement's risk and criticality, and a low-risk arrangement may not need all of them at once. A read-only widget that touches no member data is exactly what both frameworks describe as warranting the lighter review — see how the specific due-diligence questions your policy probably asks map onto what we can and can't answer at Countworthy Security and Privacy Practices.
We do not claim SOC 2, ISO 27001, or a penetration-test report — a two-person team does not have one, and we would rather say so than imply otherwise. What we do have is a page that describes the stack as it is actually built, quoting the real CSP, headers and Firestore rules rather than a marketing description of them: Countworthy Security and Privacy Practices.
The tools
TFSA Contribution Room
Cumulative room since 2009, built on CRA’s own contribution-room formula.
RRSP Refund
The refund an RRSP contribution produces in your member’s province, using the same tax engine as the take-home pay calculator.
GIC
New — dated 10 September 2026. Growth under annual compounding, or simple interest paid annually or at maturity, checked against CDIC and provincial deposit-insurance coverage limits.
- Formula last verified10 September 2026
- SourcesCRA, CDIC and the provincial deposit insurers
- Tests36 suites, run from one command
- FoundersMeet the team
- Client referencesnone published yet — we would rather show none than invent one
Rates
Most members’ sites need one or two of these; the suite price is here for completeness, not as the recommendation.
Questions
What is your security posture — do you have SOC 2?
No SOC 2 report, no ISO 27001 certification, no penetration-test attestation. What we do instead: every calculator runs entirely in the visitor’s browser, nothing typed is transmitted, and the security headers, content-security policy and Firestore rules that back that claim are quoted, not described, on our security and privacy practices page. If your procurement process requires SOC 2 specifically, we don’t have it yet and won’t pretend otherwise.
Are you a real vendor or a two-person side project?
A two-person team, named on About, not a company with a sales floor. That is exactly why the verification and disclosure standard here is stricter than a compliance review normally expects of a vendor this size — a dated citation per figure, a runnable test file, and a security page that says what does not exist as plainly as what does.
Why not an established vendor with a larger suite?
If your institution already has a calculator vendor, this page isn’t asking you to switch. What we offer is narrower and cheaper: three sourced, dated Canadian savings calculators, white-labelled, with no data-collection question to answer for your compliance team — a fit for a specific gap, not a financial-wellness platform.
What about incident response, business continuity and insurance?
Not published as a formal playbook today. There is no member data on our side to breach — the “What is stored” section of our security page is the actual attack surface, and it is small on purpose — but we have not written an incident-notification commitment, a business-continuity plan, or disclosed an insurance policy for the free embed. If a written commitment on any of those is a condition of your approval, ask us before you sign anything; a paid white-label build (see Rates, below) gets written terms you can negotiate.
Does this meet our AODA accessibility obligation?
That obligation is yours, not ours, and it extends to whatever you embed — Ontario's Integrated Accessibility Standards Regulation requires organizations with 50 or more Ontario employees, and every designated public-sector body, to conform their public web content to WCAG 2.0 Level AA, and 2026 is itself a filing year (organizations with 20 or more Ontario employees must submit an accessibility compliance report by 31 December 2026). There is no such thing as “AODA-certified” third-party content — the Act creates no certification and no body issues one — so any vendor claiming one is overclaiming. What we can honestly say, and what a formal audit would still need to confirm for your report, is at our security page's accessibility section.