Privacy policy
We read the fewest fields an audit needs - and nothing else.
Preview build. No live connections exist yet, no real payments are collected, and no personal data is processed. This policy, under controller Nuvent66 LLC, takes effect when live service begins.
Who is responsible
The data controller is LedgerClear, operated by Nuvent66 LLC. Contact: support@ledgerclear.io. Until launch, no controller relationship exists because no data is collected.
What we read
When you connect Shopify and QuickBooks Online, the scan reads amounts, taxes, quantities, currencies, dates, and order/refund/payout/transaction identifiers - only. Field minimization is structural: we never request customer names, emails, addresses, or payment card details from either system, so we cannot see, store, or lose them.
Why, and on what basis
The data above is processed to run the discrepancy scan you request and to propose corrections you individually approve. The lawful basis is performance of a contract with you (GDPR Art. 6(1)(b)); we do not use your books for advertising, profiling, or training. Nightly re-scanning is a planned monitoring feature and is not running - no processing happens on that basis today.
Retention
Cached scan data is kept only as long as needed to serve you: free-scan data is deleted after the scan session, and cleanup data is retained while your account is active. The audit log of reads, proposals, approvals, and posts is retained as a record of what LedgerClear did to your books.
Shared reports
If you choose to create a “share with your bookkeeper” link, that is the one case where scan data is stored beyond the session. We keep the derived findings - order names, amounts, tax figures, confidence tiers, and the plain-English explanations - for 30 days, so the person you send it to can open it. We never store the CSV files you uploaded; those are still parsed in memory and discarded with the request, and the snapshot contains nothing the scan did not already read.
The link is an unguessable 256-bit token and is not indexed, archived, or linked from anywhere on this site. You can revoke it at any time from the results page that created it, and it expires on its own after 30 days. You may also hide your store name from the shared copy when you create it.
Shared-report snapshots are stored with Supabase (Postgres hosting), acting as a processor on our behalf. That is the only sub-processor that ever receives scan-derived data.
Deletion and revoking access
One click in the app revokes both OAuth tokens and deletes your cached data. You can also revoke LedgerClear from the Shopify and Intuit sides at any time, or request deletion by email at support@ledgerclear.io.
Sub-processors
At launch the expected sub-processors are: [hosting - e.g. Vercel], [payments - Stripe; card details go to Stripe directly and never touch LedgerClear], and [AI processing - e.g. Anthropic, if enabled]. The definitive list, with locations and transfer safeguards, is published here before launch.
Your rights
If you are in the UK or EU, you have the rights of access, rectification, erasure, restriction, portability, and objection under GDPR, and the right to complain to your supervisory authority. Requests go to support@ledgerclear.io.
Cookies
No advertising or analytics cookies. The site uses at most functional cookies strictly necessary to keep you signed in and run the app; nothing that requires a consent banner.
Draft for launch (demo build) - no company details are stated here because none are final. See also Terms of service and Security & trust.