Privacy Policy
Vegawize is bookkeeping software for small businesses in the United States. To keep your books, we need to see your business's bank and card transactions. This policy explains what we collect, why, how long we keep it, and how to delete it. We wrote it to be read, not skimmed past.
1. What we collect
Account information
- Your name, email address and password (stored hashed). If you turn on two-factor authentication, the secret used to verify your codes (stored encrypted).
- Your business's name, industry, address, entity type, fiscal year and the last four digits of its EIN, if you choose to enter them.
- People you invite to your business and the role you give them.
Financial data from your bank, through Plaid
When you connect a bank account, you do so through Plaid, a service that links financial institutions to applications like ours. You sign in to your bank inside Plaid's secure widget; we never see or store your online banking username or password. Plaid then gives us:
- Account names, types (checking, savings, credit card, loan), the last four digits of the account number and current balances.
- Transactions: date, amount, merchant or description, pending status, and the category Plaid suggests. We request up to 24 months of history at connection time and new transactions as they post.
- Institution name and a technical identifier for the connection so we can keep it in sync.
Plaid's own handling of your data is described in the Plaid End User Privacy Policy. By connecting an account you also agree to it.
Financial data you upload
If you import a CSV, OFX or QFX statement instead of connecting a bank, we store the transactions in that file the same way we store transactions from Plaid. The uploaded file itself is deleted after it is imported.
What you tell us about transactions
Answers to questions ("Was this personal?"), categories you pick, rules you create, notes and month-end summaries you edit. This is the part that makes your books yours.
Technical data
IP address, browser type and the pages you use, in ordinary server logs and in our error monitoring, so we can keep the service running and secure. We do not use advertising trackers or third-party analytics cookies. We use a session cookie to keep you signed in and one to remember your sidebar and appearance preferences.
2. How we use it
- To keep your books. Categorizing transactions, detecting transfers and duplicates, reconciling accounts, producing reports and month-end summaries, and exporting to accounting software you choose.
- To ask you questions. The weekly digest email lists the transactions we could not categorize confidently. Each answer link in it is signed, single-use and expires.
- To improve categorization for your business. Your past answers teach the system how your business works. Transaction descriptions and amounts from one business may be compared, in anonymized numerical form, with similar descriptions from other businesses to suggest a category; no business ever sees another business's transactions, merchants, or amounts.
- To run the service. Sign-in, security, support, notifications you asked for, and diagnosing errors.
Artificial intelligence
We use large language models and embedding models from third-party providers (currently Anthropic and Voyage AI) to categorize transactions and write plain-English month summaries. We send only what the task needs: the transaction description, amount, date, account type, your industry and your chart of accounts. We do not send your name, email, account numbers, or bank login. These providers process the data under contracts that prohibit using it to train their models.
3. Who we share it with
We do not sell personal or financial data, and we do not share it with advertisers or data brokers. We share data only with the service providers we need to operate, each bound by contract to use it solely for us:
| Provider | What | Why |
|---|---|---|
| Plaid Inc. | Bank connection and transactions | Linking to your financial institution |
| Anthropic, Voyage AI | Transaction text, amounts, your chart of accounts | Categorization and summaries |
| Our hosting and backup providers | Encrypted application data and backups | Running the service and disaster recovery |
| Email delivery provider | Your email address and the messages we send | Digest emails, invitations, password resets |
| Error monitoring provider | Technical error details | Finding and fixing bugs |
We may also disclose data when the law requires it, to protect the safety of people or the integrity of the service, or as part of a merger or acquisition (in which case this policy continues to apply to the data).
Within your business, the people you invite see the data their role allows. Bookkeeping firms you authorize can open your workspace to keep your books; they see the same data your bookkeeper role sees.
4. How we protect it
- All traffic is encrypted in transit (TLS). Data at rest is on encrypted disks; Plaid access tokens and two-factor secrets are additionally encrypted at the application level.
- Backups are encrypted before they leave the server and are kept on the schedule in section 5.
- Access to production systems is limited to named staff with two-factor authentication, and every change to your books is recorded in an audit log with who made it and when.
- Two-factor authentication is available to every user, required before anyone can connect a bank account, and required for our own staff.
Found a security problem? Email [email protected] with what you found and how to reproduce it. We acknowledge security reports within 2 business days. Please do not post it publicly before we have answered.
5. How long we keep it
- Transactions and books: for as long as your business has an account with us, because that is what bookkeeping is.
- Disconnected bank accounts: when you disconnect a bank, or revoke our access at your bank, we immediately revoke our access at Plaid and delete the access token. Transactions already in your books stay so your reports still balance.
- Closed accounts and businesses: access ends immediately and every bank connection is removed. Personal data (names, emails, address, EIN) is permanently deleted 30 days after closure. Financial records (transactions, ledger, reports and their audit trail) are kept in an inactive state for 7 years, as bookkeeping and tax law require, then permanently deleted. A nightly job carries this out and records what it removed.
- Uploaded statement files: deleted right after import.
- Server, security and application logs: 90 days.
- Backups: encrypted daily backups are kept 35 days and one monthly backup is kept 12 months; deleted data therefore leaves backups within 12 months at the latest.
The full schedule is our Data Retention and Disposal Policy; a copy is available on request.
6. Your choices and rights
- Disconnect a bank at any time from Bank connections. This revokes our access through Plaid.
- Export your data at any time: reports as PDF or CSV, and your full journal in QuickBooks, Xero or CSV format.
- Delete your account or business from Settings, or by emailing [email protected]. We confirm deletion by email.
- Stop the weekly digest with the unsubscribe link in any digest or in Settings → Notifications.
- You can also manage which applications have access to your bank data at my.plaid.com.
Residents of California and other states with privacy laws have the right to know what personal information we hold, to have it deleted, and to not be discriminated against for exercising those rights. We do not sell or share personal information for cross-context behavioral advertising. To exercise any right, email [email protected]: we acknowledge within 2 business days, verify that the request comes from the account holder, and answer within 30 days.
7. Children
Vegawize is for businesses and is not directed to anyone under 18. We do not knowingly collect data from children.
8. Changes
If we change this policy in a way that matters, we will email account owners before it takes effect and update the date at the top.
9. Contact
Sadeim Inc., Chicago, Illinois, USA
Privacy questions: [email protected]
Support: [email protected]
Security reports: [email protected]