This privacy policy is a placeholder template. It reflects the product's actual data handling practices but has not yet been reviewed by legal counsel. The founder will refine it before public launch.
What data we collect
LedgerDock collects and stores the following categories of data:
- Account information: Name, email address, hashed password, MFA configuration, login history.
- Company financial data: Chart of accounts, ledger entries, commits, staging rows, vendors, customers, staff records, skills, and notes — all scoped to your company.
- Document uploads: Bank statements, receipts, invoices, and other evidence files uploaded through the platform, stored in managed object storage.
- Usage logs: Authentication events, audit log entries (actions taken within the platform), page views for error monitoring.
How it is used
Your data is used to operate the bookkeeping workflow: intake, staging, classification, review, evidence matching, finalization, and reporting. AI classification uses transaction descriptions and amounts to propose account assignments — no PII (SSNs, EINs, bank account numbers) is sent to AI providers.
Who has access
- You: Full access to your own account and any companies you are assigned to.
- Your firm members: Access controlled by role (owner, senior accountant, staff accountant, member). Firm owners and senior accountants can see all companies in the firm. Staff accountants see only assigned companies.
- LedgerDock staff: Access to your data only for support purposes and only with your explicit consent, except where required to maintain system integrity or comply with legal obligations.
Data retention
Your financial data is retained as long as your account is active. Deleted accounts are purged within 90 days, except where retention is required by law. Audit log entries are retained indefinitely for integrity purposes.
Your rights
- Export: You can export your ledger data, chart of accounts, and commit history at any time via CSV export.
- Deletion: You can request deletion of your account and all associated data by contacting us.
- Correction: You can update your profile information and correct financial data through the normal workflow (non-finalized lines are editable; finalized lines are corrected via reversing journal entries).
Cookies and tracking
LedgerDock uses minimal cookies:
- Session cookie: Server-side session identifier. Required for authentication.
- CSRF token: Prevents cross-site request forgery. Required for form submissions.
- MFA trust cookie: Optional, per-device, time-limited. Reduces MFA prompts on trusted devices.
We do not use tracking pixels, third-party analytics cookies, or advertising trackers.
Third-party services
- DigitalOcean: Managed PostgreSQL database and Spaces object storage.
- Email provider: Transactional email for account verification, MFA codes, and invitations.
- AI classification provider: Transaction descriptions and amounts only — no PII is transmitted.
Contact
For privacy questions or data requests, contact: privacy@ledgerdock.app