Privacy policy
Last updated 5 October 2026.
1. What this covers
This policy explains what Ledgerwide collects when you use the website and the product, why, and what you can ask us to do with it. It applies to the platform operators who sign up, not to their customers; we never contact end customers of a connected account.
2. What we collect
Account data. Your name, email address and workspace, handled by our authentication provider, Clerk, so you can sign in. If you sign in with Google, Google gives Clerk your name, email address and profile picture and nothing else; we do not receive access to your Google account.
Stripe data you connect. With the restricted key you provide, we read and store payments, refunds, disputes, payouts, fraud reports, application fees and connected-account details from your Stripe platform. This includes the customer details Stripe exposes to you on a payment, such as a billing email, name and the card's brand, last four digits and fingerprint. We never receive full card numbers.
What we derive from it. Daily totals, per-account risk scores with the reasons behind them, a daily score history, dispute verdicts, margin figures and the alerts that follow. These are computed inside your workspace from your data only.
Settings and activity. Notification settings, the decisions and notes members record on disputes and on connected accounts (with the member who recorded them), and alert delivery logs.
Billing. If you subscribe, Stripe collects your card and billing address directly; we never see the card. We keep your Stripe customer id, the plan, its status and renewal date, and a copy of each invoice's amount and status.
Messages. What you send through the contact form, and replies you send to our alert emails, which go to our support inbox.
Technical logs. Our hosting provider records request logs, including IP addresses, which we keep briefly for security and debugging. We do not use them to profile anyone.
3. Why we collect it, and what we never do with it
To provide the service to you: computing risk scores, verdicts, margins and alerts for your platform; sending the notifications you configure; and answering your messages. We act as your service provider for this data and process it on your instructions.
We do not sell it, use it for advertising, or train machine-learning models on it. We do not combine your workspace's data with any other customer's, show it to any other customer, or use it to score anyone else's accounts. Stripe's own fraud ratings on a payment (its Radar risk level) are shown to you for context and are not used in our scoring. If we ever propose an opt-in shared fraud signal across platforms, it will be a separate choice you make, not a change to this policy.
4. Scores are not decisions
Risk scores and dispute verdicts are computed automatically from your payment data by published rules, and every point is explained next to the score. They are prompts for a person on your team to review an account or a dispute; the product records that review. We do not make decisions about your connected accounts or their customers, and we ask you (in the terms) not to treat a score as the sole basis for one. A connected account that has questions about a decision its platform made should contact the platform, which can see the reasons.
5. Who else handles it
Providers that run the service on our behalf: Clerk (authentication), Neon (database hosting, in AWS us-east-2, United States), Vercel (application hosting), Inngest (background jobs), Resend (email) and Stripe (our own billing, under Stripe's privacy policy). Separately, we read from Stripe's API with the key you provide; that is Stripe serving your request, under your agreement with Stripe. If you add a Slack webhook, alerts you choose are posted to Slack. Each provider processes data only to provide its service to us, and none of them receives your Stripe key in plain text.
6. Cookies
The only cookies are the session cookies Clerk sets so you stay signed in. There are no advertising cookies and no tracking across other sites. If we add page analytics to the public website we will use a cookieless, aggregate service and say so here.
7. How long we keep it
For as long as your workspace exists. Disconnecting Stripe deletes the stored key immediately. Ask us and we delete the synced Stripe history, the scores and reviews derived from it, or your whole workspace, promptly. Contact-form messages are kept for twelve months. Stripe can also ask us to delete data it returned to you, and we will.
8. Your choices
You can see and export the data we hold for your workspace, correct it, or have it deleted by writing to us through the contact page. You can revoke our access to Stripe at any time by expiring the key in your Stripe dashboard.
9. Security
Your Stripe key is a restricted, read-only key, envelope-encrypted with AES-256-GCM, decrypted only inside background jobs and never shown again after you paste it. Every record is tied to your workspace and every query filters on it. The full practice is described on the security page.
10. Your rights
If you are in the UK or EU, the platform operator is the controller of the Stripe data in its workspace and we are its processor; your rights under the GDPR are exercised with the platform, and we help it respond. For your own account data (name, email) we are the controller and you can ask us directly. Under the CCPA we act as a service provider to the platform and do not sell or share personal information. End customers of a connected account should contact the business they paid, or Stripe.
11. Changes
If this policy changes in a way that matters, we'll say so in the product and update the date above.