Draft — these documents are being finalized and have not yet been reviewed by a lawyer.
Privacy Policy
Last updated: July 14, 2026
1. Who we are
[Company] operates Owncroft. For the account and business data you enter, you are the controller of your own customers' personal data and we act as your processor — we handle it on your instructions to provide the Service. For your own account information, we are the controller. Contact: [contact-email].
2. What we collect
Account data: your name, email, a hashed password, and your business details.
Usage data: IP address, browser, and logs of activity in the Service, used to run and secure it.
Your Content: the records and files you upload, including receipts, invoices, bank statements, and the customer, appointment, and financial records you keep.
Payment data: processed by Stripe. We store only display details such as the card brand and last four digits; we do not store your full card number.
3. How we use it
To provide, maintain, secure, and improve the Service; to process payments; to send you service messages; and to meet legal obligations. We do not sell your data.
4. AI processing of your documents
When you use an AI feature, the document or text involved — for example a receipt, invoice, or bank statement — is sent to our AI sub-processor, Anthropic, to extract or categorize the information. This can include personal and financial data contained in those documents. We use Anthropic's commercial service, which does not train its models on this content. See our sub-processor list for details.
5. Who we share it with
We share data with the sub-processors that help us run the Service — for payments, AI, email, hosting, and backups — listed on our Sub-processors page. Each is bound to protect the data and to use it only to provide their service to us. We may also disclose data if the law requires it.
6. How long we keep it
We keep your data while your account is active and for as long as needed to provide the Service and meet legal obligations. After your account closes, we make your data available for export for a reasonable period and then delete it, subject to any retention the law requires.
7. Your rights
Depending on where you are, you may have the right to access, correct, delete, or export your personal data, or to object to certain processing. You can exercise these rights, or ask us to help you meet a request from one of your own customers, by writing to [contact-email]. We respond within the time the law requires.
8. Security
We protect data with encryption in transit, hashed passwords, strict separation between businesses, access controls, audit logging, optional two-factor authentication, and regular off-site backups. No system is perfectly secure, but we work to keep your data safe and to notify you promptly if a breach affects you.
9. Children
The Service is for businesses and is not directed to children. We do not knowingly collect personal data from anyone under 13.
10. Where your data is processed
We operate from the United States, and your data is processed there and by our sub-processors in the locations listed on our Sub-processors page.
11. Changes
We may update this policy. We will post the new version with its date and, for material changes, notify you.
12. Contact
Privacy questions: [contact-email].