Countworthy

Home/For Business/Credit Unions

Countworthy for credit unions and small fintechs

Savings calculators for your member site that never send a single number anywhere.

TFSA room, RRSP refund and GIC growth — sourced, dated and themed to your brand — with no data question for your compliance team to answer.

Live. A $25,000 TFSA GIC at a BC credit union. Nothing you type leaves the page.

Why zero data collection matters for your review

Every calculator here runs entirely in the member’s browser. The TFSA and RRSP tools compute with plain JavaScript against CRA’s own published figures; the GIC tool works out simple or compound interest the same way and checks the result against CDIC’s and the relevant provincial deposit insurer’s coverage limits. Nothing a member types — a balance, an income, a deposit amount — is sent to us, to you, or to any server in between.

That matters for the question your review almost certainly asks: does this send personal information across a border, and if so, whose privacy law governs it? Under PIPEDA, that question only has something to attach to once personal information is actually transferred to a third party for processing — the Privacy Commissioner's own guidelines for processing personal data across borders frame a transfer as a “use” the transferring organization stays accountable for, protected through a contract. Because no personal figure ever leaves the browser here, there is no transfer for that framework to reach — not because a data-processing agreement permits one, but because the precondition never occurs. The one thing the wider site collects — an anonymous province-and-income-band tally, described in full on our privacy page — is opt-in, contains no typed figure, and is not part of any embed you would put on your site.

This is also the shape of arrangement both Canadian prudential frameworks treat as light-touch. Ontario's FSRA expects outsourcing risk to be “properly identified, assessed, and managed” while “accountability and ownership for any outsourced or co-sourced function is maintained by” your institution, never transferred to us. For the small number of federally regulated credit unions, OSFI's Guideline B-10 says the same in more explicit terms: due diligence, contract review and exit planning scale to an arrangement's risk and criticality, and a low-risk arrangement may not need all of them at once. A read-only widget that touches no member data is exactly what both frameworks describe as warranting the lighter review — see how the specific due-diligence questions your policy probably asks map onto what we can and can't answer at Countworthy Security and Privacy Practices.

We do not claim SOC 2, ISO 27001, or a penetration-test report — a two-person team does not have one, and we would rather say so than imply otherwise. What we do have is a page that describes the stack as it is actually built, quoting the real CSP, headers and Firestore rules rather than a marketing description of them: Countworthy Security and Privacy Practices.

The tools

Rates

Most members’ sites need one or two of these; the suite price is here for completeness, not as the recommendation.

Questions

What is your security posture — do you have SOC 2?

No SOC 2 report, no ISO 27001 certification, no penetration-test attestation. What we do instead: every calculator runs entirely in the visitor’s browser, nothing typed is transmitted, and the security headers, content-security policy and Firestore rules that back that claim are quoted, not described, on our security and privacy practices page. If your procurement process requires SOC 2 specifically, we don’t have it yet and won’t pretend otherwise.

Are you a real vendor or a two-person side project?

A two-person team, named on About, not a company with a sales floor. That is exactly why the verification and disclosure standard here is stricter than a compliance review normally expects of a vendor this size — a dated citation per figure, a runnable test file, and a security page that says what does not exist as plainly as what does.

Why not an established vendor with a larger suite?

If your institution already has a calculator vendor, this page isn’t asking you to switch. What we offer is narrower and cheaper: three sourced, dated Canadian savings calculators, white-labelled, with no data-collection question to answer for your compliance team — a fit for a specific gap, not a financial-wellness platform.

What about incident response, business continuity and insurance?

Not published as a formal playbook today. There is no member data on our side to breach — the “What is stored” section of our security page is the actual attack surface, and it is small on purpose — but we have not written an incident-notification commitment, a business-continuity plan, or disclosed an insurance policy for the free embed. If a written commitment on any of those is a condition of your approval, ask us before you sign anything; a paid white-label build (see Rates, below) gets written terms you can negotiate.

Does this meet our AODA accessibility obligation?

That obligation is yours, not ours, and it extends to whatever you embed — Ontario's Integrated Accessibility Standards Regulation requires organizations with 50 or more Ontario employees, and every designated public-sector body, to conform their public web content to WCAG 2.0 Level AA, and 2026 is itself a filing year (organizations with 20 or more Ontario employees must submit an accessibility compliance report by 31 December 2026). There is no such thing as “AODA-certified” third-party content — the Act creates no certification and no body issues one — so any vendor claiming one is overclaiming. What we can honestly say, and what a formal audit would still need to confirm for your report, is at our security page's accessibility section.

Talk to us