Privacy Policy
Effective date: July 01, 2026
Last updated: July 01, 2026
This Privacy Policy describes how LedgerBoss (mobile and web applications at ledgerboss.app and app.ledgerboss.app, the "Service") collects, uses, discloses, retains, and protects information. The operator of the Service is referred to as "LedgerBoss", "we", "us", or "our".
By accessing or using the Service, you acknowledge that you have read this Privacy Policy. If you do not agree, do not use the Service.
This Privacy Policy should be read together with our Terms of Service.
1. Important roles: who controls what data
Understanding data roles limits misunderstandings and defines legal responsibilities.
1.1 We act as a data controller for
- Your account and authentication data (email, sign-in identifiers, account settings)
- Subscription and billing metadata processed through app stores or our systems (plan tier, entitlement status, trial usage — not full payment card data, which is handled by Google Play or Apple)
- Support and security communications you send to us
- Platform announcements and operational notices we publish
- Technical and security logs necessary to operate and protect the Service
1.2 You act as an independent data controller for
If you operate a business in the Service, you — not LedgerBoss — are the controller of personal data you enter about:
- Your clients (names, contacts, visit history, photos, notes)
- Your employees and contractors (names, roles, schedules, salary/payment records where used)
- Your suppliers, inventory, financial records, and other business content
You are solely responsible for having a lawful basis to collect and process that data, providing required notices to data subjects, obtaining consents where required, and responding to data subject requests relating to your business data.
1.3 We act as a data processor (service provider) for
When you enter business or client data into the Service, we process that data on your instructions solely to provide the Service (hosting, display, backup, access control, notifications you enable, and related functionality). We do not use your clients' personal data for our own marketing or unrelated purposes.
If you are an employee invited to a business account, your employer (the business owner/administrator) determines how your work-related data is processed.
2. Scope
This Policy applies to:
- The LedgerBoss Android and iOS applications
- The LedgerBoss web application
- The websites ledgerboss.app and app.ledgerboss.app
- Support channels listed in Section 18
This Policy does not apply to third-party websites, app stores, payment processors, or services linked from the Service. Their practices are governed by their own policies.
3. Information we collect
3.1 Information you provide directly
Account and profile
- Email address, display name, and password (stored via authentication systems; we do not store plaintext passwords)
- Profile settings, language preference, and notification preferences
- Communications you send to support
Business and operational data (controlled by you)
- Business name, address, settings, and metadata
- Client records, appointment history, and service definitions
- Employee accounts, roles, schedules, and payroll-related entries (PREMIUM)
- Inventory, materials, suppliers, expenses, receipts, and financial report inputs
- Photos uploaded to profiles or client records (where your plan allows)
- Business announcements and related content
Authentication providers
If you use Google or Apple sign-in, we receive identifiers and basic profile information permitted by those providers and your consent choices.
3.2 Information collected automatically
- Device type, operating system, app version, and general device settings
- IP address, approximate location derived from IP, timestamps, and session identifiers
- Firebase authentication session tokens and security event metadata
- Push notification tokens (mobile, if you enable notifications)
- Crash, diagnostic, and performance data reasonably necessary to maintain reliability
- In-app actions required for security, fraud prevention, and abuse detection
3.3 Information from third parties
- Google Play / Apple App Store: subscription status, product identifiers, purchase validation tokens, and renewal/cancellation signals (we do not receive your full payment card number)
- Google / Apple authentication: account identifiers and profile fields you authorize
- Firebase / Google Cloud: infrastructure and security processing as described below
3.4 Information we do not intentionally collect
- Government ID numbers, unless you voluntarily enter them in free-text business fields (not recommended)
- Sensitive categories of data under GDPR Article 9 (health, biometric, etc.) unless you voluntarily store them in business records — you are responsible for whether such storage is lawful
- Children's data — see Section 14
3.5 No sale of personal information
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. Where U.S. state privacy laws define "sale" or "sharing" broadly, our disclosures in this Policy describe the limited sharing necessary to operate the Service.
4. How we use information
We use information only as reasonably necessary to:
- Provide, operate, maintain, and improve the Service
- Authenticate users and enforce role-based permissions within businesses
- Process subscriptions, trials, restores, and entitlement verification
- Deliver notifications you or your business administrators enable
- Provide customer support and respond to inquiries
- Detect, prevent, and address fraud, abuse, security incidents, and Terms violations
- Comply with law, regulation, legal process, and enforce our agreements
- Generate aggregated or de-identified analytics that do not identify individuals
We do not use client personal data entered by your business for unrelated advertising profiles.
Legal bases (EEA/UK users)
Where GDPR or UK GDPR applies, our bases typically include:
| Purpose | Legal basis |
|---|---|
| Providing the Service you request | Performance of contract (Art. 6(1)(b)) |
| Security, fraud prevention, abuse enforcement | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance | Legal obligation (Art. 6(1)(c)) |
| Optional marketing to account holders (if ever offered) | Consent (Art. 6(1)(a)) |
Business owners must establish their own legal basis for client and employee data they control.
5. How we disclose information
We disclose information only in the circumstances below.
5.1 Within your business account
Data you enter may be visible to other users in the same business according to their role (owner, administrator, accountant, employee).
5.2 Service providers (sub-processors)
We use trusted providers that process data on our instructions, including:
- Google Firebase (Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging)
- Google Cloud Platform infrastructure underlying Firebase
- Google Play billing and subscription validation (Android)
- Apple authentication and, when applicable, App Store infrastructure
These providers are authorized to process data only as needed to deliver their services to us. Their practices are subject to their own terms and privacy policies.
A current list of core infrastructure providers is maintained in this Policy. We may update providers as the Service evolves.
5.3 Legal and safety disclosures
We may disclose information if we believe in good faith that disclosure is necessary to:
- Comply with applicable law, regulation, legal process, or governmental request
- Enforce our Terms of Service
- Protect the rights, property, or safety of LedgerBoss, our users, or the public
- Detect or prevent fraud or security issues
Where legally permitted, we will attempt to notify you before disclosing account content to authorities, except where prohibited or where delay would create risk.
5.4 Business transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction subject to standard confidentiality obligations. We will provide notice where required by law.
5.5 With your direction
We may disclose information when you explicitly request or authorize us to do so.
6. International data transfers
The Service is operated using cloud infrastructure that may process data in countries other than your own, including countries that may not provide the same level of data protection as your jurisdiction.
Where required, we rely on appropriate safeguards such as:
- Standard Contractual Clauses approved by the European Commission
- UK International Data Transfer Addendum mechanisms
- Other lawful transfer tools available at the time of transfer
You instruct us to transfer and process data as needed to provide the Service.
7. Data retention
We retain information only as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.
| Data category | Typical retention |
|---|---|
| Active account and business data | While your account (or employer's account) remains active |
| Deleted account data | Removed according to our in-app deletion workflow; residual backups may persist for a limited period |
| Security and audit logs | Limited period for incident investigation and integrity |
| Support correspondence | As needed to resolve issues and demonstrate compliance |
| Billing records via app stores | Per Google Play / Apple policies |
You control retention of business/client data while your account is active. You may delete records in-app or delete your account subject to business ownership rules described in the Service.
After deletion, we may retain anonymized or aggregated data that cannot reasonably identify you.
8. Security
We implement reasonable administrative, technical, and organizational measures designed to protect information, including:
- Encrypted connections (HTTPS/TLS)
- Firebase Authentication and role-based access controls
- Firestore and Storage security rules
- Access limitations for personnel and contractors
No security is perfect. We cannot guarantee absolute security. You are responsible for safeguarding your credentials, device security, and access you grant to employees.
You must notify us promptly at support@ledgerboss.app if you believe your account has been compromised.
9. Your privacy rights
Rights vary by location. We honor applicable rights to the extent required by law.
9.1 EEA / UK (GDPR)
If GDPR applies, you may have the right to:
- Access personal data we control about you
- Rectify inaccurate data
- Erase data (subject to exceptions)
- Restrict or object to certain processing
- Data portability where applicable
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority
For business/client data you control, direct requests from your clients to you as controller. We will assist you as processor where contractually and legally required.
9.2 United States — California (CCPA/CPRA)
California residents may have rights to know, access, correct, delete, and opt out of sale/sharing. As stated, we do not sell personal information. You may designate an authorized agent where permitted by law.
We do not discriminate against you for exercising privacy rights.
9.3 Other U.S. states
Residents of states with comprehensive privacy laws (Virginia, Colorado, Connecticut, Utah, and others as enacted) may have similar rights regarding personal data we control. Contact us to exercise applicable rights.
9.4 How to submit requests
Email support@ledgerboss.app with:
- Your account email
- The right you wish to exercise
- Sufficient information to verify your identity
We may request additional verification to prevent unauthorized disclosure. We will respond within timeframes required by applicable law.
10. Cookies and similar technologies (web)
The web application and marketing site may use:
- Essential cookies / local storage for authentication sessions and preferences
- Functional storage required for Firebase and app operation
We do not operate a third-party advertising cookie network on the marketing site. Browser settings may allow you to block cookies; blocking essential cookies may prevent the web app from functioning.
11. Push notifications
If you enable notifications on mobile devices, we process device tokens to deliver alerts about appointments and business events you configure. You may disable notifications in device or app settings.
12. Automated decision-making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects about you. Reports and analytics are informational tools; you remain responsible for business decisions.
13. Third-party links
The Service may link to third-party sites (e.g., app stores, authentication providers). We are not responsible for their privacy practices.
14. Children's privacy
The Service is intended for business use and is not directed to children under 16 (or the higher age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take reasonable steps to delete it.
If you store information about minors in client records (e.g., children's appointments), you are responsible for lawful processing and parental consents.
15. Changes to this Policy
We may update this Privacy Policy at any time. The "Last updated" date reflects the current version. Material changes may be communicated via the Service, email, or platform announcements where appropriate.
Continued use after changes become effective constitutes acceptance, except where applicable law requires explicit consent.
16. Limitation of liability (privacy)
To the maximum extent permitted by law, our liability arising from this Policy or privacy-related claims is subject to the limitations and exclusions in our Terms of Service, including warranty disclaimers, liability caps, and indemnification provisions.
Nothing in this Policy limits rights that cannot be waived under mandatory applicable law.
17. Data Processing Addendum (business customers)
Business owners who require a formal Data Processing Addendum (DPA) for GDPR Article 28 may request one at support@ledgerboss.app. Unless a separate signed DPA exists, this Privacy Policy and the Terms constitute the default processing terms for use of the Service.
18. Contact
Privacy inquiries: support@ledgerboss.app
Website: https://ledgerboss.app
Support page: https://ledgerboss.app/support
For complaints in the EEA/UK, you may also contact your local data protection authority.
Полный перевод документа будет добавлен позже. Действует англоязычная версия.