Legal
Privacy Policy
Effective date: August 13, 2026
1. Overview
This Privacy Policy explains how Canadian PRLedger ("PRLedger", "we", "us") collects, uses, and protects information when you use our website and dashboard (the "Service"). PRLedger is an independent, currently volunteer-run tool for tracking Canadian Experience Class (CEC) hours, CRS scores, and document readiness — it is not affiliated with, and does not act on behalf of, Immigration, Refugees and Citizenship Canada (IRCC) or the Government of Canada. By using the Service, you agree to the practices described here. Questions can be sent through the contact form.
2. Information we collect
Account information. When you sign up through Firebase Authentication, we receive your email address and, if you sign in with Google, your name and profile photo as provided by Google.
Profile data you enter. The CEC hours you log, your CRS calculator inputs and scores, and your document checklist status and notes. This is stored in a private Firestore document tied to your account — only you can read or write it.
Document files — not collected. See Section 4 below. We never receive the bytes of any file you upload from the checklist page.
Guest / local-only use. If you use the public CRS or hours calculators without signing in, your inputs stay in your browser's local storage and are never sent to us.
Automatically collected information. Our hosting and database infrastructure (Firebase / Google Cloud) logs standard technical data such as IP address and browser type for security and abuse prevention. We may also load Google advertising scripts when AdSense is enabled (see below).
Advertising (Google AdSense). PRLedger is a free project. To help cover hosting and development costs, we may show a small number of clearly labeled (“Sponsored”) display ads via Google AdSense on selected public pages (for example the home page, News, Guides, and the public Calculators page). AdSense and Google may set cookies or use similar technologies to serve and measure ads. Google’s policies apply to those ads; you can learn more and manage ad personalization at Google Ad Settings. We do not sell your profile data to advertisers. Dashboard and signed-in app pages do not show AdSense units.
3. Caching, cookies & local storage
A first-visit notice on the site explains the storage below; dismissing it only remembers that you saw the notice (in this browser).
- Browser / CDN cache. Scripts, styles, and photos are cached on your device (and at Cloudflare) so repeat visits load faster. Hashed app files may be stored for up to a year; photos and icons are rechecked about weekly. HTML pages are not long-cached, so a deploy shows up on the next load.
- Local storage. Guest calculator inputs, your signed-in dashboard copy on this device, notification dismissals, and the cache-notice flag stay in the browser until you clear site data.
- Account cookies. Firebase Auth may set cookies required to keep you signed in. Those are functional, not advertising.
- Advertising cookies (Google AdSense). When AdSense is active, Google may set advertising cookies or use similar technologies on pages that include an ad unit. See Section 2 and Google Ad Settings for controls.
Clearing this site's data in your browser removes the local copy. Signed-in cloud profiles remain until you request account deletion (Section 7).
4. Your Google Drive connection
PRLedger's document checklist can connect to a folder in your own Google Drive. This connection uses Google's drive.file scope — the most restrictive OAuth scope Google offers — which only lets us see the one folder you create or pick, nothing else already in your Drive.
When you upload a document, it goes directly from your browser to Google's Drive API. It is never routed through, or stored on, our servers. We only save the resulting file name and link in your Firestore profile so the checklist can show you it's there. The temporary access token used for the upload lives in your browser's memory only, is never sent to us, and expires automatically — it is not stored anywhere.
Disconnecting Drive in the app, or unlinking a single file, only removes that reference from your PRLedger profile. It never deletes or modifies anything inside your actual Google Drive. Likewise, deleting your PRLedger account (Section 7) has no effect on files already sitting in your Drive.
5. How we use information
We use the information above to:
- operate your account and sync your dashboard across devices;
- calculate CEC hour progress, CRS scores, and readiness estimates;
- maintain the security and integrity of the Service;
- respond to support requests you send us; and
- send optional product emails about new Express Entry draws to verified account holders (you can turn these off in Account or at /unsubscribe).
We do not sell your profile data or build advertising profiles from your hours, scores, or documents. Site display ads (when enabled) are served by Google AdSense on selected public pages only — see Section 2.
7. Data retention & deletion
We retain your account and profile data for as long as your account exists. To request deletion of your account and associated Firestore data, use the contact form from the address on your account. We'll confirm once it's done. As noted above, account deletion never touches files already stored in your own Google Drive.
8. Security
Your profile data is protected by Firestore security rules that restrict access to your own signed-in account only, and is encrypted in transit and at rest by Google Cloud's infrastructure. No method of transmission or storage is perfectly secure, so while we work to protect your information, we can't guarantee absolute security.
9. Children's privacy
The Service is intended for people at least 18 years old who are working toward permanent residence in Canada. We do not knowingly collect information from anyone under 18. If you believe a minor has provided us information, contact us and we will remove it.
10. International users
The Service is built for temporary residents of Canada, and your data is processed using Google Cloud / Firebase infrastructure. By using the Service, you consent to your information being processed in the regions those providers operate.
11. Changes to this policy
We may update this Policy from time to time. Material changes will update the effective date at the top of this page. Continued use of the Service after a change means you accept the updated Policy.
12. Contact
Questions about this Policy or your data can be sent through the contact form.