This Privacy Policy explains how Ledger (“Ledger,” “we,” “us”) collects, uses, shares, and protects information when you use our double-entry accounting application (the “Service”). By using the Service you agree to this Policy.
Information we collect
- Account information you provide: your name, email address, password (stored only as a salted hash by our auth provider), and organization details.
- Financial data you enter: invoices, bills, expenses, customers, vendors, chart of accounts, and related bookkeeping records.
- Bank connection data (via Plaid): if you choose to connect a bank or credit-card account, we use Plaid Inc. (“Plaid”) to retrieve your account and transaction information. We receive transaction details (date, amount, description, and account identifiers) and store them so you can review and categorize them. We do not receive or store your online-banking username or password — you enter those directly with Plaid.
- Technical data: basic logs and security metadata needed to operate the Service (e.g. timestamps, request metadata).
How we use your information
We use your information only to:
- provide, maintain, and secure the Service;
- import, display, categorize, match, and reconcile your bank transactions within your books;
- authenticate you and protect your account;
- communicate with you about the Service; and
- comply with legal and regulatory obligations.
We do not sell your personal or financial information, and we do not use your data for advertising.
Plaid
We use Plaid to connect your financial accounts. By connecting an account you also agree to Plaid’s End User Privacy Policy. Plaid’s handling of your credentials and data is governed by Plaid’s policies. You can revoke Plaid’s access at any time by disconnecting the bank in Ledger or via my.plaid.com.
How we share information
We share information only with the service providers that operate the Service on our behalf, under contractual confidentiality and security obligations: Supabase (database, authentication, and storage), Vercel (application hosting), and Plaid (bank connectivity). We may disclose information if required by law or to protect our rights and users.
Security
We protect your data with encryption in transit (TLS 1.2+) and at rest (AES-256), row-level security that isolates every organization’s data, least-privilege access controls, and secret management that keeps bank access tokens on the server only — never exposed to the browser. No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard safeguards.
Data retention and deletion
We retain your information for as long as your account is active or as needed to provide the Service and meet legal obligations. You may request access to, correction of, or deletion of your personal data by contacting us via our support page. When you disconnect a bank, we delete the associated Plaid access token. When you delete your account, we delete or de-identify your personal and financial data within 30 days, except where retention is required by law.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at the email below.
Children
The Service is not directed to children under 16, and we do not knowingly collect their information.
Changes to this policy
We may update this Policy from time to time. Material changes will be reflected by the “Last updated” date above and, where appropriate, additional notice.
Contact
Questions about this Policy or your data? Reach us via our support page.