Privacy policy
This Privacy Policy describes how Ledger Delivery ("we," "us," or "our") collects, uses, and protects information when you use our service at ledgerdelivery.com. We take the privacy of financial data seriously and have written this policy to be specific and plain.
1. Who this policy applies to
This policy applies to bookkeepers and bookkeeping firms ("subscribers") who create a Ledger Delivery account, and to business owners ("recipients") who receive email summaries generated by the service. If you are a recipient, your bookkeeper has configured the service on your behalf.
2. Information we collect
Account information
When you create an account, we collect your name, email address, and the name of your bookkeeping firm. We use this information to operate your account and to communicate with you about the service.
QuickBooks data accessed via the accounting API
When you connect a QuickBooks Online company file, Ledger Delivery accesses the following data through Intuit's QuickBooks Accounting API, using read-only OAuth authorization:
- Invoice records: invoice number, date, due date, amount, and status
- Customer records: customer name and the invoices associated with each customer
- Accounts-receivable balance data: open balances, aging buckets, and payment history sufficient to compute changes between digests
We do not access payroll data, bank account data, expense data, vendor records, or any other QuickBooks data outside the scope described above.
QuickBooks credentials
We never receive or store your QuickBooks username or password. Authorization is handled entirely through Intuit's OAuth 2.0 system. We receive an access token and a refresh token, both of which are stored encrypted at rest. You can revoke our access at any time from within your QuickBooks Online account under Apps & Connections.
Recipient email addresses
Subscribers provide the email addresses of business owners who will receive summaries. We store these addresses to deliver the configured emails and for no other purpose.
3. How we use information
We use the information described above solely to:
- Generate and deliver accounts-receivable summary emails to configured recipients
- Generate and deliver same-day past-due alerts
- Operate, maintain, and improve the service
- Respond to support requests
- Send transactional account communications (billing receipts, service notices)
We do not use your QuickBooks data or your clients' financial data for any purpose other than generating the summaries you have configured.
4. Data retention
We retain periodic snapshots of accounts-receivable figures (the computed summary data, not raw QuickBooks records) for up to 90 days. This allows us to compute changes between digest emails. After 90 days, snapshot data is permanently deleted.
When you disconnect a company file or close your account, we delete all stored snapshot data for that company within 30 days and revoke the associated OAuth tokens. Account information is retained for up to 60 days after account closure for billing and legal compliance purposes, then permanently deleted.
5. Data sharing and third parties
We do not sell, rent, or share your data or your clients' financial data with any third party for marketing, advertising, or any commercial purpose. We share data only with the subprocessors listed below, and only to the extent necessary to operate the service.
Subprocessors
- Email delivery provider (Resend). We use a transactional email service to deliver summary emails and alerts. This provider receives the rendered email content and recipient addresses. They do not receive raw QuickBooks data.
- Cloud hosting provider (Netlify and Railway, United States). Our application and database are hosted on a US-based cloud infrastructure provider. Encrypted data at rest and data in transit (TLS 1.2 or higher) are standard requirements of our hosting arrangement.
6. Security
OAuth tokens are stored encrypted at rest. All data in transit is encrypted using TLS. Access to production systems is restricted to authorized personnel. We do not store QuickBooks credentials of any kind.
7. Your rights and choices
Disconnecting QuickBooks
You may disconnect a company file at any time from your Ledger Delivery account settings. You may also revoke access directly from within QuickBooks Online. Either action immediately stops data retrieval for that company.
Requesting deletion
To request deletion of your account and all associated data, email us at support@ledgerdelivery.com with the subject line "Data deletion request." We will confirm receipt within two business days and complete deletion within 30 days.
Recipients
If you are a business owner receiving summary emails and wish to stop receiving them, contact the bookkeeper who manages your account, or email us at support@ledgerdelivery.com and we will remove your address from all delivery lists.
8. Children's privacy
The service is intended for use by businesses and professionals. We do not knowingly collect information from anyone under the age of 18.
9. Changes to this policy
If we make material changes to this policy, we will notify subscribers by email at least 14 days before the changes take effect. The "last updated" date at the top of this page reflects the most recent revision.
10. Contact
Questions about this policy may be directed to:
support@ledgerdelivery.com
Ledger Delivery
Texas, United States