Privacy Policy
Last updated July 2026
The short version
We collect what we need to run LedgerOS — your account details, your store's counts, and the photos of terminal reports you choose to upload. We don't sell your data. Each store's data is walled off from every other store.
What we collect
- Account: your name, email, and password (stored hashed).
- Store data: bins, books, games, clerks (name + a hashed PIN), and the counts they run.
- Terminal photos: if a clerk photographs a shift report for reading, we store the image to produce the number.
- Billing: handled by Stripe; we keep a customer reference, not your card number.
- Contact details for alerts: the phone and email you set for SMS and weekly summaries.
How we use it
- To run counts, compute variances, and send the alerts you turn on.
- To read a photographed terminal total into an editable number.
- To bill you and support your account.
Who we share it with
Only the service providers that make LedgerOS work: Supabase (database and storage), Stripe (billing), Twilio (SMS), Resend (email), and Anthropic (reading terminal-report photos). Each handles only what it needs. We don't sell your data or share it for advertising.
Isolation
Every store's records are separated at the database level. An owner can only ever read the stores they belong to, and clerks only reach their own store through the counting flow.
Retention
We keep your data while your account is active. If you cancel, we keep it available for 90 days for export, then delete it. Terminal photos are kept with the count they belong to.
Your choices
- Export your counts to CSV any time from the account page.
- Turn SMS and email alerts on or off in alert settings.
- Ask us to delete your account and data by emailing hello@ledgeros.app.
Contact
Privacy questions? Email hello@ledgeros.app.