Ledgerpost privacy policy
DRAFT — to be replaced by counsel-approved text. This draft describes what the app actually stores and why, derived from the product's engineering documents. It is not legal advice and has not been reviewed by a lawyer. Bracketed items marked FOUNDER or COUNSEL must be completed, and this notice removed, before the page is listed on the Shopify App Store.
Last updated: [FOUNDER: date of publication]
Who we are
Ledgerpost is a Shopify app that records a store's Shopify sales, payments, refunds and payouts in the store's own QuickBooks Online company. It is operated by [FOUNDER: Libanto legal entity name and registered address] ("Libanto", "we") and served from app.getledgerpost.com. Questions about this policy: privacy@getledgerpost.com.
In this policy, "merchant" means the Shopify store that installs Ledgerpost, and "customer" means a person who bought from that store.
Our role
For the customer data described below, the merchant decides why and how it is used (the merchant is the controller), and Ledgerpost processes it on the merchant's behalf to provide the app. [COUNSEL: confirm the controller/processor wording and whether a separate data processing agreement is offered to merchants.]
What the app reads and stores
The app reads only what it needs to write accounting records. It does not request customer phone numbers or order notes, and it never receives or stores payment card details.
| Source | Data | Why |
|---|---|---|
| Shopify: the store | Shop domain, store name, store contact email, time zone, currency, Shopify plan name | Identify the store, date and price records correctly, send the store's notifications |
| Shopify: orders | Order number and dates, line items, quantities and prices, discounts, shipping, taxes, tips and duties, payment gateway and amounts, payment status and terms, refunds (including refund notes), returns, B2B company and location | Create the matching invoice, sales receipt, payment, credit memo or refund receipt in QuickBooks |
| Shopify: customers | Name, email address, billing and shipping addresses, customer tags, tax-exempt flag | Find or create the matching QuickBooks customer and fill the invoice's customer fields; apply the merchant's posting rules |
| Shopify: products | Product and variant titles, SKUs, prices | Match or create QuickBooks items |
| Shopify: payouts | Shopify Payments payout amounts, dates, fees and the transactions in each payout | Record the bank deposit and fees in QuickBooks |
| Shopify: staff | The name, email address and owner/collaborator status of the staff member using the app, from Shopify's session | Decide what each person may do in the app and record who made each change |
| QuickBooks Online | Company id and settings (home currency, sales tax, class and location tracking, closing date); the company's accounts, items, customers (names, emails, addresses), tax codes, terms and payment methods; the records the app wrote | Map Shopify data to the right QuickBooks accounts and records, avoid duplicates, and check that each record was written correctly |
| QuickBooks Online | Access and refresh tokens for the connection | Write to the company the merchant connected; encrypted with a key specific to the store |
| The merchant | Mappings, posting rules, decisions on held orders (including any reason typed), notification recipient email addresses | Operate the app as the merchant configured it |
| The merchant, on request | A settings file the merchant downloads (Settings, Backup): mappings, posting rules and notification preferences, with no customer data and no credentials | Kept by the merchant, not by us, to restore settings after a reinstall |
| The app | A posting ledger (which QuickBooks record came from which Shopify event), a sync log, an exception list, an activity log of who changed what | Prevent duplicate records, explain what did not post and why, and show an audit trail |
The app writes customer names, email addresses and addresses into the merchant's QuickBooks company as part of the records it creates there. Those records then belong to the merchant's QuickBooks company and are governed by Intuit's terms and privacy statement.
What we do not do
- We do not sell or rent personal data, and we do not use it for advertising.
- The app and its public pages use no advertising or analytics trackers.
- We do not use customer data for any purpose other than providing the app to the merchant who installed it.
- Application logs and error reports are written without customer names, email addresses, addresses or access tokens.
Service providers (subprocessors)
| Provider | Purpose | Data involved |
|---|---|---|
| Shopify | The platform the app runs in; billing for the app | The data listed above, read through Shopify's API |
| Intuit (QuickBooks Online) | The merchant's accounting system the app writes to | The records the app creates, including customer names, emails and addresses |
| [FOUNDER: hosting provider] | Runs the app's servers ([FOUNDER: region; planned US East]) | All data the app stores, in transit |
| [FOUNDER: managed Postgres provider] | Database and backups ([FOUNDER: region; planned US East]) | All data the app stores |
| Twilio SendGrid | Sends the app's notification emails, from alerts@getledgerpost.com, to the recipients the merchant chose; open and click tracking are turned off | Recipient email addresses; email contents carry counts, Shopify order numbers, dates and plan details, not customer data |
| [FOUNDER: error tracking provider, or remove this row if none is enabled] | Reports unexpected application errors | Error type, code location and technical labels; customer data, credentials and email addresses are removed before sending |
How long data is kept
While the app is installed, a daily clean-up deletes records once they reach the ages below. Each line names the code that enforces it.
| Data | While the app is installed | After the app is uninstalled |
|---|---|---|
| Shopify login sessions | Managed by Shopify's library | Deleted at uninstall (server/services/store-lifecycle.ts) |
| QuickBooks connection tokens | Kept while connected | Revoked at Intuit at uninstall; the tokens are deleted with the store's data (server/jobs/handlers/check-connections.ts, then server/jobs/handlers/retention-sweep.ts) |
| The posting ledger (which QuickBooks record came from which Shopify event), order, customer and product records, mappings and settings | Kept while installed, because the ledger is what prevents duplicate records in QuickBooks; a customer's personal data in them is erased when Shopify forwards that customer's deletion request (server/jobs/handlers/compliance.ts) | Deleted with the store's data |
| Sync log, decided exceptions, received webhooks and finished background jobs | Deleted 12 months after they were written or decided (server/jobs/handlers/retention-sweep.ts) | Deleted with the store's data |
| Activity (audit) log | Deleted after 24 months (server/jobs/handlers/retention-sweep.ts) | Deleted with the store's data |
| Usage counters (orders posted per month, QuickBooks calls per day) | Deleted after 13 months (server/jobs/handlers/retention-sweep.ts) | Deleted with the store's data |
| Notification emails the app sent or tried to send | Deleted after 90 days (server/jobs/handlers/retention-sweep.ts) | Deleted with the store's data |
| Dry runs and backfill requests | Deleted 12 months after they were created, except the store's latest cutover and any correction still in progress (server/jobs/handlers/retention-sweep.ts) | Deleted with the store's data |
| Support session records | Deleted 24 months after the session (server/jobs/handlers/retention-sweep.ts) | Deleted with the store's data |
| Customer privacy requests and data exports | Deleted 30 days after the request is completed (server/jobs/handlers/retention-sweep.ts) | Deleted with the store's data |
| All of the store's data | — | Deleted when Shopify sends its shop data deletion request (48 hours after uninstall), and in any case within 30 days of uninstall (server/jobs/handlers/compliance.ts, server/jobs/handlers/retention-sweep.ts) |
| Backups | [FOUNDER: confirm with the database provider; planned daily snapshots kept 30 days] | Deleted data leaves backups as they expire |
[FOUNDER: whether a reinstall can restore a store's history is undecided (CUTOVER_SPEC §7.4, DATA_MODEL §7); today the store's data is deleted when Shopify's shop data deletion request arrives, 48 hours after uninstall. Do not promise a restore until it is built. The merchant-held way to keep settings is built: Settings, Backup, Export settings downloads a file the merchant keeps, and Import settings on a new installation restores the mappings, posting rules and notification preferences; QuickBooks accounts and items are reused only in the company they came from, and in another company only where the merchant confirms a same-named match (LL-D121, LL-D132). Say so here once this policy is final.]
Customer privacy requests
Shopify forwards customers' privacy requests to the app:
- Data request: the app collects what it holds about that customer into a file the store owner can download from the app (Settings, Privacy requests) and pass on to the customer, within 30 days.
- Deletion request: the app erases the customer's name, email address, addresses and any free text mentioning them from its records, within 30 days, and keeps a marker so later updates from Shopify are stored without them. Amounts, dates and record identifiers are kept so the store's accounting history stays consistent.
- The app does not change the merchant's QuickBooks company when a customer asks for deletion. Records already written to QuickBooks are the merchant's to manage in QuickBooks.
Security
- Data travels over encrypted connections (TLS).
- QuickBooks and Shopify access tokens are encrypted at rest (AES-256-GCM, with a key specific to each store). [FOUNDER: confirm database and backup encryption at rest with the chosen provider.]
- Test and production data are kept in separate databases.
- Support staff can see a store's data only through a time-limited support session (4 hours by default) that is recorded and visible to the merchant in Settings, Activity, and that the merchant can revoke. Customer names and other free text stay masked in support sessions unless a specific exception needs them, and each viewed field is logged.
- [FOUNDER: security incident contact and response commitment, per Shopify's protected customer data requirements.]
Merchant choices
- A merchant can pause posting, disconnect QuickBooks, or uninstall the app at any time.
- A merchant can choose to post all sales under one generic QuickBooks customer instead of creating a QuickBooks customer per Shopify customer. The invoices and receipts themselves still carry the order's billing email and addresses.
Changes
We will update this page when what the app stores or how it is used changes, and change the "Last updated" date above. [COUNSEL: notice commitment for material changes.]
Contact
Privacy questions and requests: privacy@getledgerpost.com. Support: support@getledgerpost.com. [FOUNDER: postal address.]
Shopify is a trademark of Shopify Inc. Intuit and QuickBooks are trademarks of Intuit Inc., used to describe compatibility. Ledgerpost is not affiliated with, sponsored or approved by Intuit or Shopify.