Privacy Policy
This policy explains what information FinLedgic collects, how we use it, and the choices you have. We designed FinLedgic to collect only what's needed to run your books.
Information we collect
- Account information: your name, email, and password (stored only as a salted hash).
- Financial data: transactions, balances, and account metadata retrieved from banks you connect through our data provider, Plaid.
- Content you create: categories, notes, invoices, quotes, and customer records you enter.
- Usage & device data: basic logs (IP address, browser type, timestamps) used to operate and secure the service.
How we use it
We use your information to provide the service: syncing and categorizing transactions, generating reports and invoices, authenticating you, preventing fraud and abuse, and providing support. We do not sell your personal or financial data, and we do not use your bank transaction data for advertising.
Bank connections (Plaid)
When you link a bank account, credentials are entered directly with Plaid. FinLedgic never sees or stores your online-banking username or password. Plaid returns a secure access token, which we hold encrypted (AES-256-GCM) and use only to retrieve your transactions and balances. Your use of Plaid is also governed by Plaid’s end-user privacy policy.
Payments
Subscription billing is handled by Stripe. Card details are provided directly to Stripe and are never stored on FinLedgic servers.
Data sharing
We share data only with service providers that help us operate FinLedgic (e.g., our database host, Plaid, Stripe, and our email provider), each bound by contractual confidentiality and security obligations, and when required by law.
Data retention & deletion
We keep your data only as long as we need it to provide the service or to meet legal obligations:
- While your account is active, we retain your account information, connected-bank data, and the content you create so the product works.
- Disconnecting a bank immediately revokes the Plaid access token and deletes that connection’s imported accounts and transactions.
- Account deletion: when you delete your account (or request deletion at the contact below), we delete your personal and financial data from our production systems within 30 days, and it is purged from encrypted backups within 90 days.
- Legal minimums: we may retain a limited set of records (for example, billing and tax records) for the period required by applicable law, after which they are deleted.
This retention and deletion policy is reviewed at least annually, and is designed to comply with applicable data-privacy laws. You can request access, export, correction, or deletion of your data at any time using the contact below.
Security
We encrypt data in transit (TLS) and encrypt sensitive tokens at rest. See our Security page for details.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Contact us to exercise them.
Contact
Questions about this policy? Email privacy@finledgic.com.