Privacy Policy.
How BooksEZ collects, uses, and protects data across three parties: your platform, your end customers, and our own organisation.
1. The summary
For those who prefer the essentials: BooksEZ never sells your data or your end customers' data, under any circumstances. End-customer financial data is processed solely to deliver the embedded accounting service to your platform. You can export everything through the API and delete it at any time. BooksEZ is SOC 2 Type II audited.
2. The categories of data we process
Platform data. Information your platform shares about itself, its team, and its commercial use of BooksEZ. Used to operate your account.
End-customer data. The financial records of the small businesses on your platform, including bank account metadata (institution name and last four digits only, never full numbers and never banking credentials), transactions, invoices, ledger entries, vendor and customer contact details, and messages exchanged with our bookkeepers. Processed solely to deliver the service to you, on your behalf, as your sub-processor.
Usage information. IP addresses, device and browser details, pages visited, and API call patterns. Used for analytics, security monitoring, and product improvement.
Third-party data. Information from banking-data providers (such as Plaid), payment processors (such as Stripe), payroll providers, and identity-verification vendors, supplied at your direction or your end customers' direction.
3. How end-customer financial data is used
BooksEZ processes end-customer financial data on your behalf as a sub-processor under your own privacy notices. The data is used to operate the embedded accounting service for the customer, to categorize transactions using our machine-learning models, to generate reports on demand, and to improve the underlying models in aggregate, de-identified form where contractually permitted.
4. The parties we share data with
- Sub-processors that provide infrastructure such as cloud hosting, observability, and email delivery, under contracts requiring confidentiality and security commitments equivalent to ours. The current list appears on our security page.
- Banking and payments partners that facilitate connections to financial institutions and processors.
- Professional advisors bound by confidentiality obligations.
- Authorities where required by valid legal process, following careful review and, where lawful, with prior notice to the affected platform.
- Acquirers in connection with a merger or acquisition, subject to standard transitional protections.
5. Cookies and tracking technologies
BooksEZ uses cookies for authentication, security, preferences, and analytics. We do not run cross-site advertising trackers on any application surface where end-customer financial data is displayed. The complete list is available in our Cookie Policy.
6. Security measures
SOC 2 Type II audited annually. PCI DSS Level 1. ISO 27001 certified. Encryption in transit via TLS 1.3 and at rest via AES-256. Field-level encryption for tax IDs and bank account numbers. Least-privilege access throughout. Further detail is available on the security page.
7. Data retention periods
BooksEZ retains platform and end-customer data for the duration of the platform's contract, plus 60 days after termination to support transition and export. Financial records may be retained longer where required by law, typically seven years in the US, eight in India, and six in the UK, within encrypted and access-controlled archive storage.
8. Your rights and your end customers' rights
Platforms can access, correct, export, or delete data at any time through the API. End customers exercise data-subject rights through the platform, and BooksEZ will support the platform's response. Where an end customer contacts us directly, we forward the request to the platform after verifying the relationship.
9. International data transfers
Data may be processed in the US, Canada, the UK, the EU, and India. For transfers originating in the EEA, the UK, and Switzerland, BooksEZ relies on Standard Contractual Clauses with the UK addendum. We never transfer data to a country lacking an adequate legal basis.
10. Data Processing Addendum (DPA)
Platforms processing personal data of EU, UK, or Swiss data subjects should execute our DPA, which incorporates Standard Contractual Clauses. The DPA is attached automatically to enterprise Order Forms, and smaller platforms can request it at privacy@booksez.com.
11. Children's data
The service is not directed to children under the age of 16, and BooksEZ does not knowingly collect their information.
12. Updates to this policy
Material changes receive at least 30 days of advance notice through email and an in-product banner.
13. Contacting us about privacy
Email privacy@booksez.com, or write to BooksEZ Inc., Attn: Privacy, 216 Wharton Avenue, Toronto ON M5V 2L4, Canada. EU representative: eu-rep@booksez.com. UK representative: uk-rep@booksez.com.
