Legal
Privacy Policy
Last updated: July 10, 2026
1. Introduction
Booksmrt ("Booksmrt," "we," "us," or "our") provides done-for-you bookkeeping services to online businesses. This Privacy Policy explains how we collect, use, disclose, and protect personal and financial information when you use our website and services.
By using our services, you agree to the practices described in this policy. If you disagree, please discontinue use and contact us at the address below.
2. Information we collect
2.1 Information you provide directly
- Contact information: name, email address, business name, phone number (optional).
- Financial documents: bank statements, credit card statements, invoices, receipts, and other financial records you upload or share with us.
- Accounting data: transaction records, chart of accounts data, and any information exported from your accounting software (QuickBooks Online, Xero).
- Payment information: billing details processed through Stripe. We do not store full card numbers — Stripe handles all payment card data.
- Business information: industry, revenue range, and other details you provide during onboarding or in communications with our team.
2.2 Information collected automatically
- Security data: timestamps, action history, and keyed network/browser fingerprints for portal security events. The portal does not retain full IP addresses or full browser user-agent strings in its audit history.
- Usage data: which features you use in the portal, file upload activity, and message history between you and our team.
- Cookies and public-site analytics: session cookies are required for authentication. Public marketing pages may use PostHog, Google Analytics/Ads, Meta Pixel, and AdFlint for analytics, replay, attribution, and advertising measurement. Those tools are excluded from client portal and admin routes in application code.
3. How we use your information
We use the information we collect solely to deliver and improve our bookkeeping services:
- Providing monthly bookkeeping, cleanup, and catch-up services described in your engagement.
- Reconciling accounts, categorising transactions, and preparing financial reports.
- Communicating with you about your books, deliverables, and outstanding items.
- Processing payments for your monthly retainer and cleanup fees via Stripe.
- Sending service-related emails (delivery confirmations, document requests, billing receipts).
- Improving our internal processes and quality-control procedures.
- Complying with applicable legal obligations.
We do not sell client financial documents. Public-site usage and campaign data may be disclosed to the analytics and advertising providers listed below; those providers are blocked from portal and admin routes by application policy.
4. Storage and security
Client uploads are handed off to Google Drive for controlled document storage, while the portal stores an encrypted Drive reference, bookkeeping metadata, messages, and audit history. The application does not currently claim that every connected system or portal account enforces two-factor authentication.
Specifically:
- Client-uploaded financial files are sent to restricted Google Drive folders shared with configured Booksmrt operations accounts and, when intentionally enabled, the client.
- The portal does not store a second copy of a newly uploaded bank statement or delivered report in the website database or application file storage.
- File bytes are held temporarily in server memory while the application inspects, transfers, and parses an upload.
- The complete portal-state payload is encrypted with AES-256-GCM before being written to Supabase.
- Production responses are configured for HTTPS, HSTS, restrictive security headers, authenticated private routes, and no-store caching on portal, admin, and API responses.
- Production portal credential storage is disabled; clients should use OAuth, accountant invites, named read-only access, or an approved external password vault.
5. Third-party service providers
We use third-party providers to operate the service. Their handling of information is governed by their terms and privacy documentation and, where applicable, Booksmrt's account settings and agreements with them.
| Provider | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing | Billing details, subscription status |
| Supabase | Encrypted portal application state | Encrypted portal payload and service metadata |
| QuickBooks Online | Client-authorized accounting connection | Transaction data, reports, and chart of accounts |
| Google Workspace (Drive) | Restricted client document storage | Financial documents and reports |
| Resend | Service and booking emails | Name, email address, and email content |
| PostHog, Google, Meta, and AdFlint | Public-site analytics, replay, attribution, and ad measurement | Public-site usage, device/browser data, and campaign identifiers |
| Anthropic (only when explicitly enabled) | Optional financial-document extraction or grounded assistance | The financial context required for that request |
6. Data retention
Portal records and Google Drive documents are retained while needed to provide the service, maintain security and accounting records, resolve disputes, or satisfy applicable legal obligations. Booksmrt does not currently represent that every category follows one automatic deletion period.
You may request access, export, correction, or deletion by contacting us. We will verify the request, explain any information that must be retained, and respond within the period required by applicable law. A formal category-by-category retention schedule is being established before broader production use of sensitive documents.
7. Your rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your personal information (subject to legal retention obligations).
- Withdraw consent to processing where consent is the legal basis.
- Request a portable copy of your data.
To exercise any of these rights, contact us at the email address below. We will verify and respond to the request as required by applicable law.
8. Children's privacy
Our services are intended for business owners and are not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors.
9. Changes to this policy
We may update this policy to reflect changes in our practices or applicable law. We will notify active clients of material changes by email at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
10. Contact us
Questions about this policy or how we handle your data? Reach out at any time:
See how we protect your data in practice.
View our security practices