Privacy Policy

Last updated

CorbelBooks is bookkeeping software. That means the data you put in it is some of the most sensitive information a business has, and this policy explains plainly what we collect, why, and what we will never do with it.

What we collect

We store only what the product needs to work:

  • Account details — your name, email address, and business profile, provided through our sign-in provider (Clerk).
  • Your books — the clients, invoices, estimates, bills, budgets, ledger entries, and reports you create or import.
  • Bank data — when you connect an account through Plaid, we receive transactions and balances for that account. Plaid access tokens are encrypted at rest; we never see or store your bank login credentials.
  • Payment data — card payments are processed by Stripe. We keep only opaque Stripe identifiers plus the card brand and last four digits needed to show you which card is on file. Full card numbers never touch our servers.
  • Usage logs — standard server logs (IP address, browser, timestamps) used for security and debugging, retained for a limited period.

How we use it

  • To run the product: generate invoices, sync your bank feed, calculate cash flow and tax estimates, and produce reports.
  • To send the messages you configure — invoice reminders, receipts, and payment confirmations to your clients on your behalf.
  • To power optional AI features (the CFO assistant and receipt scanning). Only the data needed for the request you make is sent to the model provider, and it is not used to train models.
  • To keep the service secure and to comply with the law.

We do not sell your data, and we do not use your financial records for advertising.

Who can see your books

Your data is scoped to your account. Other people see it only when you choose to share it: team members you invite, an accountant you grant read-only access to, and clients who receive a payment, estimate, or portal link from you. Those links are unguessable and can be rotated or revoked from the app at any time.

Service providers

We rely on a small set of providers to run CorbelBooks, each bound by its own privacy commitments: hosting and database (Vercel, Neon), authentication (Clerk), payments (Stripe), bank connectivity (Plaid), email and SMS delivery (Resend, Twilio), file storage for receipts and attachments (Vercel Blob), and AI (Anthropic). They receive only the data required to perform their service.

Retention and deletion

We keep your books for as long as your account is active. You can export your data at any time from Settings, and you can ask us to delete your account by emailing support@corbelbooks.com. We remove your records within 30 days, except where we are legally required to retain transaction records.

Security

All traffic is encrypted in transit. Bank tokens are encrypted at rest with keys held separately from the database. Access to production systems is limited to the people who operate the service. If we ever learn of a breach affecting your data, we will tell you promptly.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, or to object to certain processing. Most of this you can do directly in the app; for anything else, email us and we will help.

Changes and contact

If this policy changes in a way that matters, we will note it here and notify account holders by email. Questions go to support@corbelbooks.com. See also our Terms of Service.