Privacy Policy

Last updated: January 1, 2025 · Effective: January 1, 2025

This Privacy Policy explains how Booklet ("we," "us," or "our") collects, uses, and protects information about you when you use our business management platform. We take your privacy seriously: this document is written to be actually readable, not just legally dense.

1. Information We Collect

1.1 Information you provide directly

When you create an account, we collect your name, email address, company name, billing address, and payment information. When using the platform, you input business data including financial records, employee information, customer and supplier details, and inventory data.

1.2 Information from your use of our services

We automatically collect usage data including feature access logs, session timestamps, IP addresses, browser type, operating system, and pages visited within the application. We also collect performance data to diagnose issues and improve reliability.

1.3 Information from third parties

If you connect third-party integrations (such as payment gateways or bank feeds), we receive data from those services as authorized by you. We do not purchase data from third-party data brokers.

2. How We Use Your Information

2.1 Providing and improving the service

We use your data to operate, maintain, and improve Booklet. This includes processing transactions, generating reports, running AI agents on your behalf, and ensuring the platform functions correctly.

2.2 Communications

We send transactional emails (receipts, account notices, security alerts), product update emails (new features and improvements), and support communications. You can manage email preferences in your account settings.

2.3 Security and fraud prevention

We analyze usage patterns to detect suspicious activity, unauthorized access attempts, and potential fraud. Suspicious activity may result in temporary account suspension and notification.

2.4 Legal compliance

We process data as required by applicable law, including responding to lawful government requests, enforcing our terms, and resolving disputes.

3. Data Storage and Security

3.1 Encryption

All data in transit is encrypted using TLS 1.2 or higher.

3.2 Infrastructure

Booklet is hosted on enterprise-grade cloud infrastructure. We use redundant, geographically distributed data centers to ensure availability and data durability.

3.3 Access controls

Access to customer data by Booklet employees is restricted on a need-to-know basis, logged, and audited. No employee can access customer financial data without explicit authorization and a documented reason.

3.4 Security testing

We run an ongoing vulnerability disclosure program and welcome reports from independent security researchers.

4. Data Retention

4.1 Active accounts

We retain your data for the duration of your subscription plus 90 days following account closure, during which time you can request a complete export.

4.2 Financial records

Financial records required by applicable law (typically 7 years in most jurisdictions) are retained for the legally mandated period, then permanently and securely deleted.

4.3 Backup data

Encrypted backup copies of data may persist for up to 30 additional days beyond deletion requests as part of our disaster recovery infrastructure. These are not accessible for normal operations.

5. Your Rights

5.1 Access and portability

You have the right to access all personal data we hold about you and to receive a machine-readable export. You can export your complete business data at any time through the platform (Settings → Export Data) or by contacting support.

5.2 Correction and deletion

You may correct inaccurate personal data through your account settings. You may request deletion of your account and associated personal data at any time. Deletion requests are processed within 30 days, subject to legal retention requirements.

5.3 Restriction and objection

You have the right to restrict processing of your data in certain circumstances and to object to processing based on legitimate interests. Contact privacy@booklet.io to exercise these rights.

5.4 GDPR rights (EEA residents)

If you are located in the European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with your local supervisory authority.

6. Cookies

6.1 Essential cookies

We use essential cookies for session management, authentication, and security (CSRF protection). These cannot be disabled as they are required for the service to function.

6.2 Analytics cookies

With your consent, we use analytics cookies to understand how features are used, identify areas for improvement, and measure the effectiveness of our product changes. These are optional and can be disabled in your account settings.

6.3 No advertising cookies

We do not use advertising cookies, do not serve ads, and do not allow third-party advertising networks to place cookies on our platform.

7. Third-Party Services

7.1 Subprocessors

We use carefully selected third-party service providers (subprocessors) for cloud hosting, payment processing, email delivery, and customer support. All subprocessors are contractually bound to protect your data and are assessed for security compliance.

7.2 No data selling

We never sell your personal data or business data to third parties, period. We do not share your data with advertisers, data brokers, or any party without your explicit consent or legal obligation.

7.3 Integrations

When you connect third-party integrations (banks, payment processors), you control what data is shared. You can revoke any integration access at any time through Settings → Integrations.

8. International Data Transfers

8.1 Transfer mechanisms

If you are located in the EEA or UK, transfers of your personal data to countries outside these regions (including to our cloud infrastructure providers) are protected by appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission.

8.2 Data residency

Enterprise customers can request data residency in specific regions. Contact sales@booklet.io for information about regional data hosting options.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email and an in-app notification at least 30 days before taking effect. Your continued use of Booklet after the effective date constitutes acceptance of the updated policy. Previous versions of this policy are available on request.

10. Contact

Data Protection Officer

For privacy-related questions, data requests, or to exercise your rights, contact our Data Protection Officer at privacy@booklet.io. We aim to respond to all requests within 5 business days.

TL;DR: Privacy in plain English

We never sell your data
You own your data, always
Full export available anytime
TLS-encrypted in transit
No advertising or tracking cookies
GDPR rights honored worldwide
Delete your account anytime
Questions answered within 5 days

Questions about this policy? Email us at privacy@booklet.io