Privacy Policy
How we handle the information you put into Blink, who else touches it, how long we keep it, and what you can ask us to do with it.
Last updated 27 August 2026.
Who we are
Blink is operated by Theta Advisory Inc., a corporation registered in Alberta, Canada. For the purposes of Canadian privacy law (PIPEDA) and, where it applies, the GDPR, Theta Advisory Inc. is the organization accountable for the personal information described on this page.
The service is still listed as PostLedger, published by DanTron Inc.; the rename to Blink and the transfer to Theta Advisory Inc. are in progress. Responsibility for the data described here rests with Theta Advisory Inc., and nothing about how that data is handled changed in the transfer.
What we collect
Information you give us
- Your name and email address, when you register.
- Your organization’s name and the entities you configure.
- Billing details, handled by Stripe. We never see or store your card number.
Information created by using Blink
- Schedule configurations and the journal entries calculated from them.
- Approval records: who submitted, who reviewed, what they decided, and when.
- Workbook cell values referenced by a journal entry, captured at the moment of submission so the entry can be audited later.
- Supporting documents you attach to a journal entry.
- An audit trail entry for every calculation, change, approval and posting.
Information from your accounting system
- An encrypted OAuth token for each connection you authorise. We never store your Xero or QuickBooks Online password.
- Only the accounts, contacts and transactions needed for the schedules you run.
How we use it
Solely to provide the service: authenticating you, running your schedules, routing approvals, posting journals to your accounting system on your instruction, and keeping the audit trail that makes those actions reviewable.
We do not sell your data, share it for advertising, or use it to train machine learning models. We do not use it to build a product for anyone other than you.
Where it is stored
All data is hosted on Microsoft Azure in the Canada Central region. It is encrypted in transit (TLS) and at rest. Sessions expire after 30 minutes of inactivity.
Who else processes it
We use a small number of sub-processors. Each one is bound by contract to use the data only to deliver its service to us.
| Sub-processor | Purpose | Where |
|---|---|---|
| Microsoft Azure | Application hosting, database, document storage | Canada |
| Stripe, Inc. | Subscription billing and payment processing | United States |
| Microsoft Entra ID | Single sign-on, where your organization uses it | Global |
| Xero · Intuit (QuickBooks Online) | The accounting system you connect, at your instruction | Per vendor |
We will update this list before adding a sub-processor that handles personal information.
How long we keep it
- Supporting documents attached to a journal entry are deleted from our storage once the entry has posted to your accounting system.
- Audit trail entries are kept for the life of your account plus 90 days. They are append-only by design — that is what makes them useful as evidence.
- Everything else is kept while your account is open, then for 90 days after termination so you can retrieve it, after which it is permanently deleted.
Your rights
You can ask us to show you the personal information we hold about you, correct it, export it, or delete it. Write to privacy@thetaadvisory.ca and we will respond within 30 days.
Deletion has one limit worth stating plainly: we cannot remove entries from an audit trail your organization is relying on for its own compliance obligations without that organization’s instruction. If that affects your request, we will tell you which records are involved and why.
If you are unhappy with how we have handled a request, you can complain to the Office of the Privacy Commissioner of Canada.
Cookies and tracking
This website sets no cookies and runs no analytics, no tracking pixels and no third-party scripts. Fonts are served from this domain rather than a font network.
The Blink application itself uses a session token to keep you signed in. That is functional, not analytical.
Changes to this policy
We will post any change on this page and update the date above. If a change materially affects how we handle your information, we will tell you by email at least 30 days before it takes effect.
Privacy questions
Questions about this policy, or a request about your own data.