1. Scope and Company Information
This Privacy Policy explains what personal information LedgerCraft collects, how we use and disclose it, how we protect it, how long we retain it, and the rights and choices available to you across our applications, APIs, and services (collectively, the "Service").
The legal entity responsible for your data is:
LedgerCraft Labs
support@ledgercrafthq.com
Email: LedgerCraft Legal <legal@ledgercrafthq.com>
2. Information We Collect
We collect information reasonably necessary to provide, secure, administer, and improve the Service. The information collected depends on how you use the Service.
Account & Authentication Information
When you create or use an account, we may collect and maintain:
- Your email address;
- Your first name or display name;
- Your workspace name, where provided;
- A securely stored password hash for accounts using password authentication;
- Your selected display currency;
- Authentication and account identifiers necessary to associate your account with its workspace;
- Account status, email-verification status, and login-related timestamps; and
- Other information reasonably necessary to administer account access and security.
We do not intentionally store your plaintext password. Password authentication uses a password hash maintained by the Service.
Google and Apple Authentication
You may choose to authenticate using third-party identity providers such as Google or Apple.
Depending on the provider and the information made available during authentication, we may receive and store information such as:
- Your provider-specific account identifier;
- Your email address;
- Your first or display name; and
- For providers that make one available, a profile image or avatar URL.
When you use Apple authentication, Apple may provide a private relay email address rather than your ordinary email address. We use the identity information provided through the authentication process to establish and authenticate your LedgerCraft account.
Third-party identity providers process information according to their own privacy policies and terms.
Financial & Ledger Records
You may voluntarily provide financial and economic information to populate your workspace ledger, including:
- Bank, credit card, brokerage, and investment account statements;
- CSV, PDF, and other supported financial files;
- Transaction information, historical activity, and account balances;
- Asset and liability information, including real estate, vehicles, collectibles, holding entities, and physical goods;
- Custom tags, classifications, categories, and notes; and
- Other information you choose to enter into your workspace.
The financial information you enter or upload may contain personal or financial information about you or other individuals. You should only provide information that you are authorized to provide and should avoid including unnecessary sensitive information.
Payment & Subscription Information
Subscription processing is managed by Stripe. When you subscribe to a paid plan, Stripe processes payment information necessary to complete and administer the transaction.
LedgerCraft retains billing and customer identifiers necessary to administer your workspace subscription, such as Stripe customer identifiers, subscription information, plan information, billing status, and related records. We do not store raw payment card numbers on our application servers.
Temporary Account-Process Information
Certain information may be stored temporarily while completing account operations. For example, during email verification, the Service may temporarily retain your email address, first name, password hash, workspace name, selected display currency, selected subscription tier, and applicable signup information until the verification process is completed or expires.
Password-recovery workflows may temporarily retain a password-reset token, associated account identifier, email address, creation timestamp, and expiration information so that a requested password reset can be completed securely.
3. Data Minimization
LedgerCraft is designed to minimize the personal information required to operate an account.
A basic account does not require you to provide information such as a residential address, telephone number, Social Security number, government identification number, or biometric identifier merely to create or maintain the account.
Additional information may be present in financial documents that you voluntarily upload or enter into the Service. Such information is treated as User Content and financial data under this Privacy Policy.
4. Uploaded Files and File Processing
The Service supports uploading financial files for processing and import into your workspace.
Uploaded files are temporarily stored in a processing queue so that they can be processed individually. During processing, the Service extracts supported and mapped financial fields according to the applicable import rules.
After the file has been processed, the temporary uploaded file is deleted according to the Service's file-processing procedures. The temporary presence of an uploaded file is therefore distinct from the financial records that may be created from the supported information extracted from that file.
The upload interface does not provide a general-purpose mechanism for mapping arbitrary source fields into your ledger. Information that is not mapped to a supported ledger field is not intentionally incorporated into the resulting ledger records.
For audit, diagnostics, processing analysis, and future enhancement of import capabilities, the Service may retain limited information about unmapped field names, import results, or processing outcomes. Such records may describe the structure or outcome of an import but are not intended to constitute a retained copy of the uploaded source file or its underlying data values.
Because an uploaded file may contain information that is not required by the Service, you should review files before uploading them and avoid intentionally including passwords, authentication credentials, Social Security numbers, government identification numbers, or other highly sensitive information that is unrelated to the financial records you want to process.
5. How We Use Information
We use personal information and User Content for purposes reasonably necessary to provide, secure, administer, and operate the Service, including to:
- Create and administer your workspace account;
- Authenticate access and maintain workspace and tenant isolation;
- Process, organize, categorize, reconcile, and aggregate financial records at your direction;
- Parse supported uploaded files and create ledger records from supported financial fields;
- Generate net worth reports, cash flow analytics, financial summaries, and audit visualizations;
- Administer subscriptions, billing, and account entitlements;
- Send transactional communications such as security alerts, verification messages, billing notifications, and password-reset communications;
- Monitor and investigate security events and unauthorized activity;
- Diagnose import and processing problems;
- Analyze limited import-processing information, including unmapped field names and processing outcomes, to improve supported import capabilities; and
- Comply with legal obligations and enforce our agreements.
6. How We Do Not Use Financial Data
LedgerCraft does not sell or rent your financial data to advertisers or data brokers.
We do not use financial records for cross-context behavioral advertising.
We do not intentionally use the financial records maintained in your workspace to create advertising profiles about you for unrelated third parties.
7. Workspace and Tenant Isolation
Financial records and workspace information are organized within a tenant or workspace context. Application access to financial information is scoped to the applicable workspace and its authorized members.
The Service is designed so that users and members of one workspace are not authorized to access the financial records belonging to another workspace.
Workspace membership and role information are used to determine the access and permissions available to authorized members of a workspace.
No system can eliminate every possible security risk, but tenant isolation and access controls are fundamental parts of the Service's security architecture.
8. Service Providers & Sub-Processors
We use third-party providers and infrastructure services that help us operate the Service. Depending on the feature you use, these providers may process information on our behalf.
- Cloud Infrastructure: Google Cloud Platform and Oracle Cloud Infrastructure;
- Payment Processing: Stripe;
- Transactional Email: Resend API;
- Authentication: Google and Apple, when you choose to authenticate using those providers; and
- Other Service Providers: Additional providers may be used as necessary to provide, secure, maintain, or operate specific Service features.
Third-party providers may process information according to their own privacy policies and contractual obligations. We seek to use providers appropriate for the services they perform and limit the information shared with them to what is reasonably necessary for the applicable function.
9. Security
We implement administrative, technical, and physical safeguards designed to protect personal information and financial data.
These measures include, as applicable:
- Workspace-level tenant isolation and access controls;
- TLS/HTTPS encryption for data transmitted to and from the Service;
- Encryption at rest provided by applicable infrastructure and storage systems;
- Protected password hashing for password-based accounts;
- Authentication and authorization controls;
- Restricted administrative access based on operational need;
- Security and audit logging; and
- Controlled processing and deletion of temporary uploaded files.
Although we use safeguards designed to protect information, no method of transmitting, processing, or storing information can be guaranteed to be completely secure. Accordingly, we cannot guarantee absolute security.
10. Data Retention
We retain personal information and financial records for as long as reasonably necessary to provide the Service, maintain your account, fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, enforce agreements, and maintain appropriate business and security records.
Temporary account-verification and password-recovery records are designed to expire or be deleted when they are no longer required for the associated security workflow.
Uploaded source files used for financial import are temporarily retained for processing and are deleted after processing in accordance with the Service's file-processing procedures.
Financial records created from supported uploaded information may remain in your workspace after the source upload has been deleted because those records are part of your ledger and are not merely temporary processing data.
When you close your account or request deletion, we may delete or de-identify applicable personal information and financial records in accordance with our retention procedures, subject to backup cycles, legal obligations, dispute resolution requirements, security records, and other circumstances where retention is permitted or required by law.
11. Your Rights and Choices
Depending on your location and applicable law, you may have rights concerning your personal information, which may include the right to:
- Request access to personal information we maintain about you;
- Request correction of inaccurate personal information;
- Request deletion of personal information, subject to applicable exceptions;
- Request a copy or export of certain information;
- Object to or restrict certain processing where applicable; and
- Withdraw consent where processing is based on consent and applicable law provides that right.
These rights vary depending on your jurisdiction and may be subject to legal exceptions or verification requirements.
To submit a privacy request, please contact LedgerCraft Legal <legal@ledgercrafthq.com>.
12. Account Deletion
You may request closure or deletion of your account by contacting us through the available account controls or by contacting the privacy address listed below.
Before deleting information, we may take reasonable steps to verify that the request was made by the account holder or another person authorized to make the request.
Deletion may not be immediate in every system. Information may remain temporarily in backups or other systems until those systems are overwritten or otherwise processed according to applicable retention procedures. We may also retain information where required or permitted by law.
13. Children's Privacy
The Service is not directed to children under the age at which they may lawfully enter into the applicable agreement in their jurisdiction. We do not knowingly collect personal information from children in violation of applicable law.
If you believe a child has provided personal information to us in violation of applicable requirements, please contact us so that we can investigate and take appropriate action.
14. International and Cross-Border Processing
Depending on where you access the Service and where our service providers operate, your information may be processed or stored in countries other than the country in which you reside.
Where applicable law requires specific safeguards for international transfers of personal information, we will use legally recognized mechanisms appropriate to the applicable transfer.
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in the Service, our data practices, applicable law, or our service providers.
We will update the "Last Updated" date when changes are made. Where required by applicable law, we will provide additional notice of material changes through the Service, by email, or through another reasonable method.
16. Contact Us
Questions, privacy requests, or legal inquiries should be directed to:
LedgerCraft Labs
support@ledgercrafthq.com
+1 (329) 200-2010
Privacy: LedgerCraft Legal <legal@ledgercrafthq.com>
Support: LedgerCraft Support <support@ledgercrafthq.com>