Data & Compliance
Last updated: September 19, 2026
LedgerBeaver handles your financial records — invoices, bank details, ledgers, and the transactions that run your business. This page is a plain-English summary of how we treat that data and how we honor the privacy laws that apply to you. It complements our Privacy Policy and Terms of Service; where the full policy governs, we link to it.
- Principles
- Your rights
- US state privacy laws
- Making a request
- Security & residency
- Financial-data safeguards
- Sub-processors
- Breach notification
- Contact
1. Our data principles
Three commitments sit underneath everything below. They are also written into our Privacy Policy and Terms so they are contractually binding, not just marketing:
- We never sell your data. Not to advertisers, data brokers, or anyone else — under any definition of "sale," including the broad definitions in California and other state laws.
- We never train AI models on your financial data. Your books are used to run your books. When you connect your own AI agent, it operates under tokens you control and scopes you set.
- You own your data. You can export it at any time and delete your account, subject only to the limited legal-retention rules described below.
2. Your privacy rights
Regardless of where you live, LedgerBeaver extends the following core rights to every account holder. In some states these are legal obligations; we choose to offer them everywhere.
| Right | What you can do |
|---|---|
| Access / Know | Get a copy of the personal information we hold about you and how it is used. |
| Correct | Fix inaccurate or incomplete personal information. |
| Delete | Ask us to delete your personal information, subject to legal record-keeping requirements. |
| Portability | Receive your data in a structured, machine-readable format you can take elsewhere. |
| Opt out | Opt out of any "sale" or "sharing" for targeted advertising — though we do neither. |
| Limit sensitive data | Limit the use of sensitive personal information to what is necessary to provide the Service. |
| Non-discrimination | Exercise any right without being denied service, charged more, or given lower quality. |
| Appeal | Where state law provides it, appeal a decision we make about your request. |
3. US state privacy laws
US state privacy laws continue to change and differ in applicability thresholds, definitions, response periods, appeals, and exemptions. LedgerBeaver applies the core rights above nationwide as an operational baseline and then applies any additional right or deadline required by the law governing a verified request. This summary is general information, not legal advice or a claim that every state law applies to every LedgerBeaver customer.
Because we already honor the core rights above for all users nationwide, you do not need to check whether your state is listed. If your state grants a right we do not mention, we will honor it too — email privacy@ledgerbeaver.com and reference your state law.
California (CCPA/CPRA) specifics
The categories of personal information we collect are detailed in Section 1 of our Privacy Policy. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding 12 months. California residents may exercise their rights, or designate an authorized agent to do so, by contacting privacy@ledgerbeaver.com.
GDPR & UK (EEA / United Kingdom)
LedgerBeaver is a US-operated service serving primarily US small and medium businesses. If you are in the EEA or UK, review the legal bases in our Privacy Policy. Our published Data Processing Agreement is a working draft pending qualified-counsel review. Customers who require an executed DPA or international-transfer terms must contact us before onboarding restricted data.
4. How to make a privacy request
Email privacy@ledgerbeaver.com with the right you want to exercise. For deletion, correction, and access requests we will:
- Verify your identity — typically by confirming control of the account email — before acting, so no one can request your data by impersonating you.
- Respond within 45 days, extendable once by another 45 days for complex requests, with notice to you.
- Honor authorized agents acting on your behalf where state law requires, with reasonable proof of authorization.
- Provide an appeal path where your state law grants one; appeal instructions are included in our response.
Account holders can also export most of their own data directly from the app at any time, and delete their account from account settings.
5. Security & data residency
Your data is processed and stored on US-based infrastructure. Our safeguards are described in full in Section 6 of the Privacy Policy; in short:
- Provider-managed encryption at rest and encryption in transit (TLS 1.2+).
- Tenant isolation enforced at the database layer with row-level security, so one company's data is never reachable by another.
- Scoped agent access — AI agents you connect act under per-capability tokens you issue and can revoke.
- Least-privilege operations — production access is limited by documented role and MFA requirements and reviewed through an evidence-based access-review process.
- SOC 2 — LedgerBeaver is not SOC 2 certified and does not currently have a completed SOC 2 audit report. We are building and evidencing the security program needed for a future independent assessment.
6. Financial-data safeguards
Because we handle bookkeeping data, a few points beyond general privacy law are worth stating plainly:
- We never store full payment-card numbers. Card processing is handled by Stripe, a PCI DSS Level 1 provider; we retain only the last four digits for reference.
- Bank connectivity, where used, is brokered by Plaid; we store account metadata and tokens, not your online-banking credentials.
- LedgerBeaver is a software tool, not an accounting firm, tax preparer, or financial advisor. You remain responsible for reviewing and approving payments, journal entries, and statements, as set out in our Terms.
- To the extent we act as a financial-data service provider, we handle nonpublic personal information consistent with applicable financial-privacy expectations, including under the Gramm-Leach-Bliley Act (GLBA) where it applies.
7. Sub-processors
We rely on a small set of vetted infrastructure providers to run the platform. The current list — including what each one processes and where — is maintained in Section 4 of our Privacy Policy. When we add or replace a sub-processor that handles Customer Data, we update that list; material changes are communicated to customers in advance.
8. Breach notification
If a security incident affects your personal information, we will notify affected customers without undue delay and within the timeframes required by applicable law, describe what happened and what data was involved, and tell you the steps we are taking and what you can do. Suspected vulnerabilities can be reported to security@ledgerbeaver.com; we practice coordinated disclosure.
9. Contact
- Privacy requests & questions: privacy@ledgerbeaver.com
- Security & vulnerability reports: security@ledgerbeaver.com
- General support: support@ledgerbeaver.com
If we cannot resolve a privacy concern to your satisfaction, you may contact your state attorney general's office or, if applicable, your local data protection authority.
This summary is provided for convenience and does not replace our Privacy Policy and Terms of Service, which govern in the event of any conflict.
