Privacy Policy
What we collect, why we collect it, and what we do not do with it. Written for the person running the business, not for a filing cabinet.
The short version
Your customers, jobs, invoices and books are yours. We hold them so we can run the product for you. We do not sell them, we do not share them with other customers, and we do not use them to advertise to anyone.
What we collect
- Account details. Your name, email address, the name of your business, and who you invite into the workspace.
- The records you put in. Customers, properties, jobs, visits, estimates, invoices, payments, expenses, bank transactions and the accounting entries behind them.
- Product usage events. A small stream of markers such as finished setup, created an estimate, sent an invoice. Each one records which workspace, which person, and when. No names, no amounts and no free text ever go into them.
- Error reports and session replays. When something breaks we get a report with the technical detail we need to fix it, and a replay of what the screen was doing. Every piece of text in a replay is masked before it leaves your browser, and images and files are blocked entirely, so we see the shape of the page and where you clicked, not your customers or your numbers.
- Ordinary server logs. Requests, timings and errors, kept for a short while so we can keep the service up.
Why we collect it
Account details identify who is signing in. Your records are the product. Usage events tell us whether people are getting through setup, and where they get stuck, which is how we decide what to build next. Error reports and replays are how a bug you hit on a Tuesday gets fixed by Thursday instead of waiting for somebody to reproduce it.
Your financial documents are yours
The contents of your estimates, invoices, receipts, bills and ledger entries belong to your business. We store and process them on your behalf, and that is the only reason we hold them. We do not read them for our own purposes and we do not use them to train an AI model. Nobody outside your workspace sees them except where something you do sends them out: emailing an invoice to your customer, and the AI features listed below.
Those AI features are the part worth spelling out, because each one sends some of your data to an outside model provider. Every one of them runs only when somebody in your workspace asks for it:
- Scanning a receipt. When you photograph a receipt to fill in an expense, the photo itself is sent to the model provider so it can read the vendor, the amount, the tax and the date off it. That is a picture of a real receipt, which may show more than those four things, so it is worth knowing before you scan one.
- Asking the AI consultant for a report. A summary of your workspace's figures is sent to the provider that writes the report.
- Asking for a growth plan. Same again: the projection and the assumptions behind it go to the provider that writes the plan up.
- Using the in-app assistant. What you type, and whatever records the assistant looks up to answer you, are sent to the provider. So is a short running summary of the conversation, so it can follow what you are talking about.
- Talking to the assistant out loud. If you speak to it, the recording of your voice goes to a second provider to be turned into text. If you have it read answers back, the text of the answer goes to that provider to be turned into speech.
Each of these sends only what that particular job needs, and only at the moment it is asked for. None of it is used to train anything of ours. These features are switched on for a whole installation rather than workspace by workspace, so if you would rather they were not available in yours, that is a conversation to have with us rather than a setting you can change yourself today.
Bank connections
If you connect a bank account, the connection is made through Plaid. You sign in to your bank on Plaid's screen, not ours: we never see your online banking username or password. Plaid gives us a token for the connection and, through it, the account's transactions and balances, which we use for one purpose: to show your bank activity beside your books, match deposits to invoices and purchases to expenses, and reconcile. The token is kept encrypted in a vault and never appears in a plain database column or a log.
You can disconnect a bank at any time from Money → Banking. That removes the connection at Plaid the same moment and destroys the token; a connection that has been failing for 30 days is removed automatically. By connecting a bank you also agree to Plaid's own End User Privacy Policy, which describes what Plaid itself collects and keeps.
We do not sell your data
Not to advertisers, not to data brokers, not to anyone. We have no business model that involves selling what is in your workspace, and we are not planning one.
Who else touches it
Running the product means using a few suppliers, each of whom sees only the part they need, and each bound to use it only to provide their service to us:
- Supabase: the database, file storage and sign-in, hosted in Canada.
- Vercel: runs the application itself, in the United States.
- Plaid: bank connections, as described above.
- Stripe: card payments your customers make to you.
- Resend: sends the email the product sends on your behalf.
- Sentry: collects error reports and the masked session replays.
- Anthropic, and OpenRouter as a gateway to model providers, behind the AI features described above.
How long we keep it
Your records stay while your workspace is open, because accounting records have to be kept. After a workspace closes, the financial records that bookkeeping law requires us to keep (invoices, payments, the ledger and the documents behind them) are retained for seven years from the end of the financial year they belong to, then deleted; everything else is deleted within 30 days of your request. Bank connection tokens are destroyed the moment a bank is disconnected. Usage events are kept for 24 months, error reports for 90 days and session replays for 30, server logs for no more than 30 days, and daily backups for 7 days. The full schedule is in our data retention and disposal policy, which we will send you on request.
Getting your data out, or deleted
You can export your workspace from the settings inside the product at any time. Owners can also log a deletion request there, and we handle those by hand rather than with a one-click button, because deleting financial records is not something anybody should be able to do by mistake.
Keeping it safe
Every workspace is separated from every other at the database level, so one customer's query cannot reach another customer's rows. Data is encrypted in transit. Changes to anything financial are written to an audit trail that records who did it and when. Our own staff can see a workspace's plan and activity counts so they can answer a support question, and when a member of our staff opens your workspace's own records, we log who did it, when, and which screen they opened. Where a member of our staff changes something in your workspace, that change lands in your audit trail like any other.
Where it lives
Your records, files and backups are stored in Canada (Supabase on AWS, Montréal region), encrypted at rest. The application that reads and writes them runs in the United States (Vercel), so your data passes through the United States while a page is being served, and the suppliers named above process the part they handle in the United States. Nothing is stored in the European Union.
Talking to us
Email dev@vantagebusinesses.com to ask what we hold about you, to correct it, or to have it deleted. A person reads it. The Terms of Service cover the rest of the arrangement.