Effective Date: July 25, 2026 · Last Updated: July 25, 2026
Your privacy is fundamental to how we build LedgerPay. This policy explains what data we collect, why we collect it, how we protect it, and your rights as a user. We are committed to transparency and will never sell your data.
We never sell your data
Your financial data is never sold to third parties or used for advertising.
Bank-grade encryption
AES-256 at rest, TLS 1.3 in transit, with cryptographic audit trails.
Tenant isolation
Row-level security ensures your data is never accessible to other companies.
LedgerPay ("we," "our," or "us") is committed to protecting the privacy and security of your personal and business data. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our accounts payable management platform. This policy applies to all users of LedgerPay, including company administrators, AP clerks, CFOs, and other authorized personnel.
We collect the following categories of information: (a) Account Information: name, work email address, company name, job title, and role within your organization; (b) Company Data: vendor information, invoice data, payment records, audit logs, and financial data you input into the platform; (c) Usage Data: log files, IP addresses, browser type, pages visited, features used, and timestamps of actions; (d) Payment Information: billing details processed through Stripe — we do not store full credit card numbers; (e) Communications: support tickets, feedback, and correspondence with our team; (f) Device Information: device type, operating system, and browser information for security purposes.
We use collected information to: (a) provide, operate, and improve the LedgerPay platform; (b) process subscription payments and manage billing; (c) authenticate users and maintain account security; (d) generate AI-powered invoice priority scores and payment recommendations; (e) send transactional emails including payment notifications, invoice alerts, and account security notices; (f) provide customer support and respond to inquiries; (g) comply with legal obligations and enforce our Terms of Service; (h) detect and prevent fraud, abuse, and security incidents; (i) analyze usage patterns to improve platform performance and features.
LedgerPay is a multi-tenant platform. Each company's data is strictly isolated using row-level security (RLS) policies enforced at the database level. Your company's invoices, vendors, payment records, and user data are never accessible to other tenants. Our database architecture ensures that even in the event of a misconfiguration, cross-tenant data access is prevented by cryptographic and policy-level controls.
We do not sell your personal or business data to third parties. We share data only with: (a) Stripe: for payment processing and subscription management; (b) Supabase: our database and authentication infrastructure provider; (c) OpenAI: for AI-powered invoice scoring (invoice metadata only, no personally identifiable financial account information); (d) Resend: for transactional email delivery; (e) Legal authorities: when required by law, court order, or to protect our legal rights; (f) Business transfers: in the event of a merger, acquisition, or sale of assets, with appropriate data protection agreements.
We implement industry-standard security measures including: (a) AES-256 encryption for data at rest; (b) TLS 1.3 encryption for all data in transit; (c) Role-based access controls (RBAC) with principle of least privilege; (d) Immutable cryptographic audit logs for all payment authorization events; (e) Regular security assessments and penetration testing; (f) SOC 2 Type II-aligned security controls; (g) Multi-factor authentication support; (h) Automatic session expiration and secure token management. Despite these measures, no system is completely secure. We encourage you to use strong passwords and report any suspected security incidents immediately.
We retain your data for as long as your account is active or as needed to provide the Service. Upon subscription cancellation: (a) your data remains accessible for 30 days to allow export; (b) after 30 days, your data is permanently deleted from our systems; (c) audit logs may be retained for up to 7 years to comply with financial record-keeping requirements; (d) anonymized, aggregated usage statistics may be retained indefinitely. You may request deletion of your data at any time by contacting privacy@ledgerpay.io.
Depending on your location, you may have the following rights: (a) Right to Access: request a copy of the personal data we hold about you; (b) Right to Rectification: request correction of inaccurate data; (c) Right to Erasure: request deletion of your personal data ("right to be forgotten"); (d) Right to Portability: receive your data in a structured, machine-readable format; (e) Right to Object: object to processing of your data for certain purposes; (f) Right to Restrict Processing: request limitation of how we process your data; (g) CCPA Rights: California residents have the right to know, delete, and opt-out of sale of personal information (we do not sell personal information). To exercise these rights, contact privacy@ledgerpay.io.
LedgerPay uses essential cookies for authentication and session management. We do not use third-party advertising cookies or behavioral tracking cookies. Our analytics are limited to first-party usage data for platform improvement. You may disable cookies in your browser settings, but this may affect the functionality of the Service. We use Google Analytics in an anonymized, privacy-preserving configuration on our public marketing pages only.
LedgerPay uses OpenAI's API to generate invoice priority scores and payment recommendations. When processing invoices through our AI scoring engine, we send invoice metadata (amounts, due dates, vendor tiers) to OpenAI's API. We do not send personally identifiable financial account information (bank account numbers, routing numbers) to AI providers. AI-generated scores are recommendations only and do not constitute automated decisions that legally affect you. All payment authorizations require explicit human approval.
LedgerPay is a business-to-business platform intended for use by adults in professional settings. We do not knowingly collect personal information from individuals under the age of 18. If you believe a minor has provided us with personal information, please contact us immediately at privacy@ledgerpay.io.
LedgerPay is operated from the United States. If you are accessing the Service from outside the United States, your data may be transferred to and processed in the United States. We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses (SCCs) where required by applicable law.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy. We encourage you to review this policy periodically.
For privacy-related inquiries, data subject requests, or to report a security concern, please contact: Privacy Officer, LedgerPay · privacy@ledgerpay.io · 1209 Orange Street, Wilmington, Delaware 19801, United States. We will respond to all privacy requests within 30 days.