Finance LedgerPrivacy Notice

Privacy Notice

This notice explains how Finance Ledger processes your personal data when you apply for the closed beta, create an account, and use the service.

Who is the controller

Finance Ledger is the controller responsible for Finance Ledger and the personal data processed through the service. For privacy questions or requests, contact support@financeledger.io.

What data we collect

  • Beta application data: name, email address, language, and the short description you provide about how you want to use Finance Ledger.
  • Account data: name, email address, account identifier, sign-in provider, and profile preferences. Authentication is managed through Supabase; Finance Ledger does not store or have access to your password in plain text.
  • Financial data: bank accounts and imported transactions, descriptions and counterparties, reporting periods, categories and rules, assets and investments, debts, subscriptions, upcoming expenses, and other records you add.
  • Technical data: secure browser session data, a language preference in local storage, IP address and request information needed for hosting and security, and limited diagnostics when errors occur. Default PII collection and session replay in Sentry are disabled.

We receive data directly from you, from files and records you add, and from Google if you choose Google sign-in. Your name, email, and authentication data are required to create and use an account; financial data is optional, but the relevant features cannot work without the data they analyse.

How we use your data

  • To review your closed-beta application and contact you about access.
  • To create and protect your account and authenticate you when you sign in.
  • To display, organise, and analyse the financial information you provide.
  • To provide imports, categorisation, calculations, reports, and other features you request.
  • For security, abuse prevention, diagnostics, and service reliability.
  • To comply with applicable legal obligations and protect legal claims.

We do not sell your personal data or use it for personalised advertising.

Legal bases

We process core account and financial data because it is necessary to perform our contract with you and to take steps at your request before entering into it. We process limited security and diagnostic data under our legitimate interest in protecting and maintaining the service, balanced against your rights. Where the law requires consent for a separate optional purpose, we will ask for it separately and you may withdraw it. We may also process data to comply with a legal obligation.

Service providers and international transfers

We use providers that process data on our behalf: Supabase for authentication and the PostgreSQL database; web and API hosting providers (currently Vercel and Render); an email provider for confirmation and recovery messages; Microsoft 365 for general operational email notifications; and Sentry for limited error and performance monitoring when enabled. The new beta-application alert does not contain the candidate's name, email, or application text. Providers receive only the data needed for their service and are subject to contractual and technical safeguards.

Some providers may process data outside the European Economic Area. Where applicable, we rely on an adequacy decision or appropriate safeguards such as the EU Standard Contractual Clauses.

How long we keep your data

Beta applications are kept while we review the request, but no longer than 12 months after the last submission, unless an account is created, you request earlier deletion, or the law requires otherwise.

Account and financial data are kept while your account exists. When you delete your account in Settings, data in the active database is deleted as part of the process. If a financial workspace is shared with other members, shared records remain available to them while your account, membership, imports, and audit references are removed.

Encrypted application backup artifacts are kept for up to 14 days. Copies in managed backup systems and limited security or error logs are kept for the shortest configured period needed for recovery, security, and legal obligations, then overwritten or deleted. Data may be kept longer only where required by law or needed for a legal claim.

Your GDPR rights

Depending on the circumstances, you have rights to information, access, rectification, erasure, restriction of processing, portability, and objection. You may withdraw consent where processing relies on consent, without affecting earlier lawful processing.

  • Access and portability: download a machine-readable JSON file from Settings → Download all data.
  • Rectification: edit your profile and financial data in the app or contact us.
  • Erasure: use Settings → Delete account or contact us.

We will respond without undue delay and generally within one month. We may request information needed to verify your identity.

You may lodge a complaint with Bulgaria's Commission for Personal Data Protection or the supervisory authority where you normally live or work.

Automated analysis

Finance Ledger calculates summaries, categories, and financial indicators to help you understand your own data. These features are informational and do not make decisions that produce legal or similarly significant effects about you.

Security

We use workspace isolation, access checks, secure sessions, request limits, security HTTP headers, and encrypted backups. In production, data is transmitted over HTTPS. No system can guarantee absolute security; contact us immediately if you suspect unauthorised access.

Changes and contact

We may update this notice when the service or legal requirements change. We will publish a new version and request a new acknowledgement where changes are material.

Questions and requests: support@financeledger.io