Privacy Policy
Last updated: August 21, 2026
1. Scope
This policy explains what LedgerJob (“we”) does with personal data when you use our web application and website. It covers two different relationships, and the difference matters:
- Your own account data — the information about you and your company. We decide how this is used, so we are the controller for it.
- The data you put into the product — your clients, their properties, quotes, invoices and photos. That belongs to you. We only process it to run the service on your behalf, under your instructions. You are the controller; we are the processor.
2. What we collect
- Account: company name and type, your name, email, phone, password (stored only as a bcrypt hash), timezone.
- Business data you enter: leads, clients, properties, quotes, projects, invoices, time entries, expenses, and any files you upload.
- Client portal: if you invite a client, we store their email and a password hash so they can sign in, plus a log of when they viewed, signed or approved a document.
- Payments: subscription status and billing history. Card details are entered directly with Stripe and never touch our servers.
- Technical: IP address, browser, pages and actions inside the app, and error reports.
3. How we use it
- Run the service: authentication, sending quotes and invoices, reminders, generating PDFs.
- Bill your subscription and prevent abuse of trials.
- Provide support, and investigate errors and security incidents.
- Send service messages (billing, security, product changes). We do not sell your data or share it with advertisers.
4. Who else touches your data
We use a small set of service providers. They may only process data to provide their service to us:
- Stripe — Subscription billing and card payments. Card numbers never reach our servers.
- Cloudflare R2 — Storage for files you upload (photos, PDFs, spreadsheets) and encrypted database backups.
- Sentry — Error monitoring. Receives technical error data, which can include your email address and the URL where an error happened.
- Email delivery (SMTP) — Sending quotes, invoices, invites and notifications. If you connect your own email account, messages go out through your provider instead of ours.
- Hosting provider — Runs the application servers and the database in the United States.
If you connect your own Stripe account to collect payments from your clients, those transactions happen in your Stripe account under Stripe’s terms with you. We store your API keys encrypted and use them only to create payment links and read payment status for your invoices.
5. Security
- Traffic is encrypted with HTTPS; the database is not reachable from the public internet.
- Passwords are stored as bcrypt hashes; third-party keys (Stripe, email) are stored encrypted.
- Access to your data is scoped to your company account and controlled by user roles.
- The database is backed up daily and restores are tested.
- Errors are monitored so we notice failures quickly.
No system is perfectly secure. If a breach affects your data, we will notify you without undue delay.
6. How long we keep it
We keep your data while your account is active. After you cancel, your data stays available for 30 days so you can come back or export it, and is then deleted from the live system. Encrypted backups roll off within 14 days after that. We may keep billing records longer where tax law requires it.
7. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to withdraw consent. Under California law (CCPA/CPRA) you may also ask what we collected and request deletion — and we do not sell or share personal information for cross-context behavioral advertising. Under the GDPR, our legal bases are performing our contract with you, our legitimate interest in securing and improving the service, and complying with the law.
You can export or delete most data yourself inside the app. For anything else, write to us and we will respond within 30 days. We will not discriminate against you for exercising these rights. If you are one of our customers’ clients, contact that company directly — they control their own records.
8. Cookies and local storage
We do not use advertising or tracking cookies. The app stores your session tokens and a few interface preferences in your browser’s local storage; clearing it simply signs you out.
9. Children
LedgerJob is a business tool and is not directed to anyone under 16. We do not knowingly collect data from children.
10. Changes and contact
If we make a material change to this policy, we will update the date above and notify account owners by email before it takes effect.
Questions or privacy requests: privacy@ledgerjob.com