Legal
Privacy policy
Last updated: 27 September 2026
Who is responsible for your information
PicoLedger is the controller of personal information used to provide PicoLedger.
Contact us through the support page.
Information we collect
We collect account and contact details, business profile information, subscription and billing records, and the accounting information you enter. That can include customers, suppliers, quotes, jobs, invoices, bills, payments, expenses, receipt images, logos and support requests.
We also collect essential technical records such as sign-in, security, error and audit events. We do not use PicoLedger customer records for advertising.
Why we use it
We use information to create and secure accounts, deliver the service, calculate and display accounting records, process subscriptions and payment links, send documents you request, provide support, prevent fraud, maintain backups, investigate errors and meet legal obligations.
Our main lawful bases are performance of our contract with you, compliance with legal obligations, and our legitimate interests in operating, securing and improving the service. Where consent is legally required, you may withdraw it.
Service providers and transfers
We use service providers for hosting and storage, authentication, payments and email delivery. These currently include OpenAI Sites and Cloudflare, Supabase, Stripe and Resend. They process information only for the relevant service and under their own data-protection commitments.
Some providers may process information outside the UK. Where that happens, we rely on an approved transfer mechanism or another lawful safeguard.
Retention and security
Business and accounting records are kept while your account is active and for a reasonable period afterwards where needed for recovery, disputes or legal obligations. Support and security records are retained only as long as reasonably necessary. Daily workspace backups are retained on a rolling 30-snapshot basis.
We use account authentication, business-level data separation, restricted access, encryption provided by our infrastructure, audit records and monitored errors. No online service can promise absolute security.
Your choices and rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction, portability or object to processing. You can also withdraw consent where it is the basis used. We may need to verify your identity before acting on a request.
You can complain to the UK Information Commissioner’s Office at ico.org.uk. Please contact us first if you would like us to try to resolve the issue.
Customers and suppliers entered by users
PicoLedger users decide what customer and supplier information they enter. For that information, the user’s business is normally the controller and PicoLedger acts as its service provider. If a business has entered your details, contact that business first about how it uses them.
Changes
We may update this policy when the service or law changes. Material changes will be brought to account holders’ attention.