This Privacy Policy explains how CPAReadyBooks ("we," "us," or "our") collects, uses, discloses, and safeguards information when you use our bookkeeping-cleanup service (the "Service"). The Service helps small businesses, freelancers, and other users organize transactions from uploaded bank and credit-card statements into reports suitable for an accountant or tax preparer. By creating an account or using the Service, you agree to the practices described in this Policy.
This Policy is not tax, legal, accounting, or financial advice. The Service organizes information you provide; it does not advise you on how to treat any transaction. You are responsible for reviewing all outputs and consulting a qualified professional before filing taxes or making financial decisions.
1. Information We Collect
We collect the following categories of information when you use the Service:
-
Account and identity information: the email address and authentication credentials you use to create and access your account.
-
Business profile information: details you provide about your business, such as business name, entity type, tax year, and similar setup information.
-
Financial content: the bank and credit-card statements you upload and the transaction data extracted from them, including dates, descriptions, amounts, balances, and related details.
-
Cleanup and interview content: your answers to the questions the Service asks while organizing your transactions, along with the categories and rules that result.
-
Payment and subscription information: records of purchases and entitlements associated with paid features. Payment-card details are handled by our payment-processing provider and are not stored on our systems.
-
Usage and audit records: security and audit logs that record actions taken in your account, including timestamps and the internet protocol (IP) addresses associated with those actions.
-
Diagnostic information: technical details automatically generated when the Service encounters an error, such as error messages, the page or operation involved, and browser or device type, used to diagnose and fix faults.
2. How We Use Your Information
We use the information we collect to:
-
Provide, operate, and maintain the Service, including extracting, organizing, and categorizing your transactions.
-
Generate cleanup questions, category suggestions, reports, and accountant packages.
-
Authenticate your access, secure your account, and maintain the integrity of your financial records.
-
Process payments and manage your subscription or one-time purchases.
-
Maintain audit and security records, detect and prevent fraud or abuse, and comply with legal obligations.
-
Diagnose and correct faults in the Service.
-
Communicate with you about your account, including service-related notices and support responses.
We do not sell your personal or financial information, and we do not use it for third-party advertising.
3. Service Providers and Data Processors
We rely on a limited set of third-party service providers to operate the Service. We describe these providers by function rather than by name. Each provider processes only the information needed to perform its function, under contractual obligations of confidentiality and data protection. The following table summarizes each function and the period for which the associated provider retains data:
| Service Provider Function | Purpose | Data Retention |
|---|---|---|
| Cloud infrastructure & data storage | Database, authentication, and secure file storage | Duration of service; deleted data expires from backups within 7 days |
| Application hosting & delivery | Serving the application and recording operational request logs | Short, provider-managed retention |
| Document extraction | Reading transactions from uploaded statements | Up to 24 hours |
| AI processing | Generating cleanup questions and category suggestions | Up to 30 days |
| Job orchestration | Coordinating background processing tasks | Up to 24 hours |
| Error monitoring | Detecting and diagnosing application faults | Provider-managed retention of diagnostic records only |
| Operational email delivery | Sending system alerts to our own operations address | Provider-managed retention of message delivery records |
| Payment processing | Billing and payment for paid features | As required by law and payment-industry rules |
Retention periods above describe how long a given provider holds data in the course of performing its function; they are separate from how long we retain your information within the Service, which is described in Section 4. These periods reflect our providers' published or configured practice as of the effective date of this Policy. Provider practices and plans can change; we review these periods when we become aware of a change and update this Policy accordingly.
Uploaded statements and extracted transaction data are transmitted to our document-extraction providers solely to read and organize your transactions.
Our AI-processing provider receives only merchant-level information from the transactions being reviewed — a merchant name, the number of transactions in the group, the group total, and a small number of transaction descriptions — for the sole purpose of generating a cleanup question and a suggested category. It does not receive account numbers, balances, per-transaction amounts, your business profile, or your answers to cleanup questions. Under our agreement with that provider, your information is not used to train its models.
Our error-monitoring and operational-email providers receive internal record identifiers, counts, and status information used to operate and troubleshoot the Service. They do not receive your statements, transaction descriptions, account numbers, or balances.
None of these providers receive your payment-card details, which are handled solely by our payment-processing provider.
4. Data Retention
We retain your account information and financial content for as long as your account is active or as needed to provide the Service to you. When data is deleted, the following applies:
-
Deleted data is removed from our active systems promptly and expires from our backup systems within 7 days.
-
Security and audit-log records, including associated IP addresses, are retained on an ongoing basis as part of the financial audit trail that supports the integrity and defensibility of your records. These records are maintained even after related financial content is deleted.
-
Payment and entitlement records are retained as required by law and payment-industry rules, which may require retention beyond the deletion of your other data.
You may export or delete your data as described in Section 5.
5. Your Rights and Choices
You have the following rights and choices with respect to your information:
-
Export: You can export your organized data at any time from your account settings, at no charge, using the Service's export feature.
-
Workspace deletion: You can delete a business workspace and its associated financial content directly from your account settings. This action is permanent and removes the workspace's data from our active systems, subject to the backup and audit-record provisions in Section 4.
-
Account deletion: To delete your user account entirely, contact us using the details in Section 8, and we will process your request. We will confirm your request and complete deletion subject to the retention obligations described in this Policy.
Depending on your jurisdiction, you may have additional rights regarding access to, correction of, or deletion of your personal information. To exercise any such right, contact us using the details in Section 8.
6. Cookies and Tracking
The Service uses a small number of strictly necessary, first-party cookies to keep you signed in and to remember which workspace you are viewing. We do not use advertising cookies, cross-site trackers, analytics services, or session recording. We do use an error-monitoring service that reports application faults from your browser — technical information such as an error message, the page where it occurred, and your browser type. It is configured not to transmit personal information, not to record your session, and not to collect performance or behavioral data, and it is never used for advertising or tracking. Because our cookies are essential to the operation of the Service, they are not used for tracking you across other websites.
7. Security
We treat your financial information as sensitive and apply safeguards designed to protect it, including tenant isolation between accounts, access controls, encrypted transmission, private file storage with time-limited access, and audit logging of sensitive actions. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your login credentials.
8. Children's Privacy
The Service is intended for use by businesses and adults. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.
9. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after an update constitutes acceptance of the revised Policy.
10. Governing Law
This Policy and any dispute arising out of or relating to it or the Service are governed by the laws of the State of Connecticut, without regard to its conflict-of-laws principles. This provision does not limit any non-waivable rights you may have under the laws of your own jurisdiction.
11. Contact Us
If you have questions about this Policy or wish to exercise any of your rights, including account deletion, contact us at:
CPAReadyBooks Email: info@cpareadybooks.com Address: P.O. Box 765, Simsbury, CT 06070