Privacy policy
Last updated 30 September 2026
LedgerFinch (ABN 90 397 855 095, "we") converts bank statement PDFs into data you can import into your accounting software. This policy explains what personal information we handle, why, where it goes and how long we keep it. It is written to meet the Australian Privacy Principles and, for customers in the United Kingdom, the UK GDPR.
What we collect
- Your account: your email address, a securely hashed password (we never see or store the password itself), and anything you add to your profile - name, business name, country and ABN or VAT number.
- Your statements: the PDFs you upload and the transactions we read from them. These contain your (or your client's) financial information. See "Your statements" below for how briefly we keep them.
- Your page history: a record of each conversion (the file name, a fingerprint of the file, the page count and the date), each purchase and each free-page grant.
- Your export layouts: any custom export formats you save.
- Payments: the amount, currency and date of each purchase and a reference to it at Stripe. Your card details go straight to Stripe and never reach our servers.
- Emails you send us, if you contact support.
We don't use advertising or tracking cookies. The site sets only the cookies it needs to work: one that keeps you logged in, and one that protects forms against forgery. Your light or dark theme choice is remembered in your own browser and never sent to us.
Your statements
- An uploaded PDF is written to a temporary file while it is converted and deleted as soon as the conversion finishes, whether or not it succeeds.
- The transactions read from it are kept in your login session so you can download the export. Sessions expire 8 hours after your last upload or login, and expired sessions are deleted within the hour.
- Statement data is never included in our backups.
- After that, the only trace of a statement is the page-history entry described above.
Why we use it
- To provide the service: converting statements, keeping your page balance and history, and sending the files you ask for.
- To take payments and keep the business and tax records the law requires.
- To send account emails: address verification, password resets and receipts. We don't send marketing emails unless you've asked for them, and every one has an unsubscribe link.
- To keep the service secure, for example by limiting how often an account can upload or start a payment.
For UK GDPR purposes, our lawful bases are performing our contract with you (running your account and conversions), legal obligation (tax and accounting records) and legitimate interests (security and fraud prevention).
Who we share it with
We don't sell personal information. We share it only with the providers that run parts of the service for us:
- IONOS hosts our servers and database, in the United States.
- Stripe processes payments. Stripe is responsible for your card details under its own privacy policy.
- Postmark (ActiveCampaign) sends our emails, from the United States.
- Our encrypted off-site backup storage. Backups are encrypted before they leave our server and don't contain statement data.
We may also disclose information where the law requires it.
Information sent overseas
Our servers and several of our providers are in the United States, so your information is stored and processed there. We choose providers that protect personal information to a standard comparable to the Australian Privacy Principles. For UK customers, transfers rely on the UK's adequacy regulations for the US (the UK-US data bridge) where the provider is certified, and otherwise on the UK International Data Transfer Addendum.
How long we keep it
- Uploaded PDFs: deleted as soon as they have been converted.
- Converted transactions: up to 8 hours, in your session.
- Account, profile and export layouts: until you close your account.
- Page history and payment records: as long as tax law requires, currently five years in Australia and six in the UK, even after your account is closed.
- Backups: overwritten on a rolling 14-day cycle on our server. The encrypted off-site copies are deleted on the same cycle.
Security
The site is served only over encrypted connections (HTTPS). Passwords are stored as one-way hashes, accounts need a verified email address, and uploads and payments are rate-limited. Our backups are encrypted. No system is perfectly secure, but if a breach is likely to cause you serious harm, we will tell you and the regulator as the law requires.
Your rights
You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to close your account and delete it (apart from the records we must keep for tax). UK customers can also object to our processing, ask us to restrict it, or ask for their data in a portable format. Email support@ledgerfinch.com and we'll respond within 30 days.
If you're unhappy with how we've handled your information, please tell us first. You can also complain to the Office of the Australian Information Commissioner (oaic.gov.au) or, in the UK, the Information Commissioner's Office (ico.org.uk).
Changes to this policy
If we change this policy in a way that affects you, we'll update the date at the top. For significant changes, we'll also email account holders before the change takes effect.
LedgerFinch · ABN 90 397 855 095 · support@ledgerfinch.com · Privacy · Terms · Refunds