Privacy Policy

Last updated: August 23, 2026

This policy explains what LedgerIz collects, why, and what control you have over your information. We sell software, not data — we never sell, rent, or trade your personal or financial information.

What We Collect

  • Account Data: Your name, email address, password hash, and optional multi-factor authentication settings.
  • Workspace Data: The accounting records you enter, including customer and vendor details, invoices, bills, journal entries, inventory, production orders, company details, and uploaded logos.
  • Billing Data: Subscription status, plan details, and transaction identifiers from our payment processor (Stripe). Card numbers are collected and handled by Stripe; they never reach or get stored on our servers.
  • Technical Data: Basic system logs, IP addresses, and device information needed to operate, secure, and troubleshoot the Service.

How We Use It

To provide the Service, maintain data availability across devices, authenticate user access, process subscriptions, prevent security threats or abuse, and respond to support requests. We do not use your accounting records for advertising, nor do we use your internal financial data to train AI models.

Who Can See Your Data

Data access is enforced per workspace at the database level. Only you and the users you explicitly invite can view your workspace records. We use third-party providers to operate the Service — Supabase for hosting, database and authentication, and Stripe for payments — which process data on our instructions and under their own confidentiality and security commitments.

Security

Data is transmitted over TLS and stored by our hosting provider with encryption at rest. Passwords are salted and hashed by our authentication provider, email verification is required at signup, and optional TOTP multi-factor authentication is available in Settings → Security. No online service can be absolutely secure, and we do not claim to be — we cannot guarantee that unauthorized access will never occur.

Backups

Backup in LedgerIz means a JSON file you download yourself from Settings → General, and which you can restore into your current workspace. We do not currently offer a customer-facing cloud backup, point-in-time restore, or disaster-recovery service, and we make no recovery guarantee. Keeping your own downloaded copies is recommended. Our hosting provider maintains its own operational backups for infrastructure purposes; these are not a customer restore feature.

Data Retention, Account and Workspace Deletion

We retain your workspace data for as long as your account remains active. You can delete your account yourself from Settings → Security. You must re-enter your current password to confirm it is you, and you must first delete every workspace you still own. Deleting a workspace can only be done by its owner; if the workspace has an active subscription, that subscription is canceled with the payment processor first, and the deletion is refused if the cancellation fails. Once a workspace is deleted, its accounting records are removed. Audit records for workspace, membership, period-lock and document events are stored separately and may be retained for integrity and compliance purposes.

Once no owned workspaces remain, deleting your account removes your memberships in workspaces owned by other people (those workspaces and their books stay with their owners), deletes your profile, and deletes your login from our authentication provider. Some records may persist temporarily in our providers' operational systems and logs until they age out on those providers' own schedules, and records we are required to keep for tax, accounting, or legal purposes are retained solely for those purposes.

Accounting, Tax and Legal Advice

LedgerIz is software. It does not provide accounting, bookkeeping, tax, legal, or financial advice, and it is not a substitute for a qualified professional.

Your Rights and Choices

You can download a full copy of your books at any time from Settings → General. You may request correction, access, or deletion of your personal data by contacting us. We aim to handle access, correction and portability requests consistently with Canada's PIPEDA and other applicable privacy laws; we hold no privacy certification and make no guarantee of compliance with any particular framework.

Cookies

We use strictly necessary storage items only to keep you securely signed in and remember interface preferences. No third-party tracking or advertising cookies are utilized.

Children

The Service is intended strictly for commercial business use and is not directed to anyone under the age of 16.

Changes

If material updates are made to this policy, we will announce them within the application or by email and update the effective date above.

Contact

Privacy questions, requests, or PIPEDA inquiries can be submitted to: newgenerationbookkeeping@gmail.com.