Legal
Privacy Policy
Last updated 1 August 2026
This policy explains what personal data we collect, why we collect it, how long we keep it, and the choices you have.
Data we collect
Account data: name, email address, company details and authentication identifiers, including identifiers supplied by your identity provider when you sign in with SSO.
Financial data: the ledger entries, invoices, payroll records and bank transactions you or your connected providers enter into the platform.
Usage data: log records, device and browser information, and security events such as sign-in attempts.
How we use it
To operate the platform, authenticate users, process payments, provide support, prevent abuse and meet legal obligations.
We do not sell personal data and we do not use your financial records to train third-party models without an explicit, separate agreement.
Bank connections
When you link a bank account through an aggregation provider, credentials are entered with that provider and never reach our servers. We receive read-only account and transaction data scoped to the accounts you select.
Sharing
We share data with processors that host our infrastructure, process payments, deliver email and provide bank aggregation. Each is bound by contractual confidentiality and data-protection obligations.
Retention
Numbers records are retained for as long as your workspace is active and for a further seven years where required by accounting and tax law. Logs are retained for 12 months.
Your rights
Depending on where you live you may request access, correction, export, restriction or deletion of your personal data. Write to privacy@ledger.example and we will respond within 30 days.
International transfers
Where data is transferred outside your region we rely on approved safeguards such as standard contractual clauses.
Security
Data is encrypted in transit and at rest. Access is scoped per company through row-level security, and administrative access is logged.
Questions about this document? Email legal@ledger.example.