Privacy Policy
Last updated: March 1, 2025
1. Information We Collect
We collect the following types of information:
- Account information: Email address, name, and password when you register
- Business data: Financial records, invoices, transactions, and other bookkeeping data you enter
- Bank connection data: Account names, balances, and transaction data via Plaid (we never store your bank login credentials)
- Payment information: Billing details processed securely by Stripe (we do not store card numbers)
- Usage data: Log data, IP addresses, browser type, and pages visited
2. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Service
- Process transactions and send billing-related communications
- Send transactional emails (invoice notifications, payment receipts)
- Respond to support requests
- Detect and prevent fraud or abuse
- Comply with legal obligations
We use AI (Claude by Anthropic) to classify your bank transactions automatically. Transaction descriptions are sent to Anthropic's API for this purpose only and are not used to train AI models.
3. Information Sharing
We do not sell your personal data. We share data only with:
- Supabase – database and authentication infrastructure
- Stripe – payment processing
- Plaid – bank account connection (if you use this feature)
- Resend – transactional email delivery
- Anthropic – AI-powered transaction classification
- Vercel – hosting infrastructure
- Law enforcement when required by valid legal process
4. Data Security
We implement industry-standard security measures including encrypted data transmission (TLS), encrypted data at rest, row-level security in our database, and access controls. However, no method of transmission over the internet is 100% secure. You are responsible for maintaining the security of your account credentials.
5. Data Retention
We retain your data for as long as your account is active. If you cancel your account, we will retain your data for 30 days to allow for re-activation or export, after which it will be permanently deleted. You can export your data at any time from the application.
6. Cookies
We use essential cookies to maintain your login session and remember your active business. We do not use advertising or tracking cookies.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and data
- Export your financial data in standard formats (CSV, QBO, IIF)
To exercise these rights, contact us at support@ibookk.com.
GDPR Lawful Basis (EEA Users)
If you are located in the European Economic Area (EEA), we process your personal data under the following lawful bases as defined by the General Data Protection Regulation (GDPR):
- Contractual obligation: We process your data based on our contractual obligation to provide the Service, including storing your financial records, processing payroll calculations, and generating reports.
- Explicit consent: For AI-powered transaction categorization and bank connection via Plaid, we process your data based on your explicit consent, which you may withdraw at any time.
- Legitimate interest: We process usage data for fraud prevention and service improvement.
- Legal obligation: We may process data to comply with applicable laws and regulations.
EEA users have additional rights including the right to data portability, the right to restrict processing, and the right to lodge a complaint with a supervisory authority.
California Consumer Privacy Act (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You may request details about the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale: You have the right to opt out of the sale of your personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
Do Not Sell My Personal Information
ibookk does not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration. We have never sold personal information and have no plans to do so. Your financial data is used solely to provide the Service to you.
8. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
9. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or an in-app notice at least 14 days before they take effect.
10. Contact
For privacy-related questions or requests, contact us at support@ibookk.com.