GridDock
Draft template — not legal advice. This document was generated as a starting point and has not been reviewed by a licensed attorney. Privacy law varies significantly by jurisdiction (e.g. GDPR in the EU, CCPA/CPRA in California, and state-specific financial data rules in the U.S.). Have this reviewed by a lawyer before relying on it to handle real customers' financial and bank data, and fill in the placeholder fields below.

Privacy Policy

Last updated: [DATE]

1. Information We Collect

Account information: email address, hashed password, business type.

Business & financial data you enter: invoices, estimates, whitelist rules, mileage logs, tax settings, employee/payroll records you create, and any logo or business contact details you upload.

Bank transaction data: if you connect a bank account, we receive transaction records (merchant name, amount, date, category) from Plaid. We do not receive or store your bank login credentials — those are handled entirely by Plaid.

Payment data: subscription and invoice payments are processed by Stripe. We do not store full card numbers; Stripe provides us a customer/subscription reference only.

Receipt images: when you use the receipt scanner, the image is sent to OpenAI for processing and is not retained by us beyond what's needed to extract and store the resulting transaction data.

Usage data: standard technical logs (IP address, browser type, access times) for security and debugging.

2. How We Use Information

We use collected information to:

  • Provide, maintain, and improve the Service
  • Process payments and manage subscriptions
  • Sync and categorize your bank transactions and receipts
  • Send transactional emails (verification, password reset, invoice reminders, payment receipts)
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

We do not sell your personal or financial data to third parties.

3. Third-Party Service Providers

We share data with the following processors only as necessary to provide the Service:

  • Plaid — bank account connection and transaction data
  • Stripe — payment processing and subscription billing
  • OpenAI — receipt image analysis
  • Resend — transactional email delivery
  • Supabase — database hosting
  • Vercel — application hosting

Each provider processes data under its own privacy policy and, where applicable, a data processing agreement with us.

4. Data Security

We use industry-standard measures to protect your data, including encrypted database connections, hashed passwords (never stored in plaintext), and application-layer encryption of sensitive tokens such as your bank connection credentials, in addition to encryption provided by our infrastructure providers. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

5. Data Retention

We retain your data for as long as your account is active, or as needed to provide the Service. You may request deletion of your account and associated data at any time by contacting us, subject to any legal retention requirements (e.g. financial records we may be obligated to retain for a period after account closure).

6. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, or to object to certain processing. To exercise these rights, contact us at [CONTACT EMAIL]. California residents may have additional rights under the CCPA/CPRA; EU/UK residents may have additional rights under the GDPR — this section should be expanded with jurisdiction-specific detail by counsel before real-world use.

7. Accountant Access

If you invite an accountant via the Accountant Access feature, that person can view a read-only summary of your financial data through a private link. We log when that link is accessed. You can revoke access at any time from your Profile.

8. Children's Privacy

The Service is not directed to individuals under 18, and we do not knowingly collect data from them.

9. International Users

If you access the Service from outside [COUNTRY], your data may be transferred to and processed in [COUNTRY], which may have different data protection laws than your own jurisdiction.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice.

11. Contact

Questions about this Privacy Policy can be sent to [CONTACT EMAIL].