How myCostBase Protects Your Data

Practical safeguards for myCostBase hosting, account access, payments, backups, and monitoring.

Last updated: July 2026

Investment records contain sensitive financial information. myCostBase uses practical safeguards across hosting, application access, payments, backups, and monitoring to protect the information entrusted to the service.

Canadian application hosting

The myCostBase application and primary database are hosted on OVHcloud infrastructure in Canada.

Some supporting providers, including payment, email, authentication, analytics, and monitoring services, may process limited information outside Canada. These providers and their purposes are identified in our Privacy Policy.

Protected connections

The myCostBase website and application are delivered over HTTPS. Traffic passes through Cloudflare before reaching the application infrastructure, providing an additional edge layer for encrypted connections and protection against malicious traffic.

Account and application security

myCostBase is built with Laravel and uses framework-supported security controls, including:

  • secure one-way password hashing;
  • optional multi-factor authentication (MFA) that users can enable for their account;
  • Google sign-in through OAuth;
  • authenticated sessions;
  • authorization checks;
  • request and form validation;
  • cross-site request-forgery protection; and
  • controlled access to account data and reports.

For accounts that use a password, passwords are never stored in readable form.

Payment information

Subscriptions are processed using Stripe Checkout.

Complete payment-card numbers are handled by Stripe and do not pass through or reside on myCostBase servers. myCostBase receives only the billing and subscription information needed to manage your plan.

No brokerage or CRA passwords

myCostBase works with files and records that you choose to enter or import.

We do not ask for your:

  • brokerage username or password;
  • CRA login credentials;
  • Social Insurance Number; or
  • complete payment-card number.

myCostBase does not connect directly to your brokerage account or gain permission to place trades, transfer funds, or change your investments.

Data collection boundaries

We collect the information needed to provide and support the service, including account details, investment records you enter or import, billing metadata, support communications, and operational logs.

We do not sell personal information.

Imported investment records are used to calculate, review, reconcile, and report your adjusted cost base and capital gains information.

Backups and operational monitoring

Production data is backed up daily.

Automated uptime and application-error monitoring alerts us to availability problems and processing errors so that operational issues can be investigated promptly.

Your records remain yours

You retain ownership of the investment information you enter or import into myCostBase.

Available reports and exports allow you to keep copies of your records for your own files or to share with your accountant or tax professional.

Responsible limits

No online service can guarantee absolute security. We continually review the safeguards used by myCostBase and update the application and infrastructure as risks and technology change.

You are also responsible for protecting your account password, securing your email account, and contacting us promptly if you suspect unauthorized access.

Security or privacy questions

For questions about security, privacy, account access, or deletion requests, contact the myCostBase team through our Contact page.