Privacy Policy
VetLedger.io ("VetLedger", "we", "our", or "us") is a bookkeeping and financial-readiness platform built for Active Duty service members, National Guard and Reserve, Veterans, military families, and veteran-owned businesses. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over your data. By using VetLedger.io you agree to the terms below.
§1Information We Collect
We collect only what we need to run the service:
- Account information — email, full name, business name, military branch, service era, and veteran/business certifications (SDVOSB, VOSB, etc.) that you provide during registration.
- Financial data you enter — invoices, expenses, transactions, receipts, client records, tax filings, payroll roster (name, pay rate, filing status, state), and pay-period history.
- Uploaded files — receipt images, brand logos, and CSV bank exports you upload.
- Bank & payment data — collected through Plaid when you link a bank account, and through Stripe when you accept payments or subscribe to a paid tier (see Section 3).
- Usage data — IP address, browser type, device information, page views, referral codes, and error logs used to operate and secure the service.
- Cookies — a single session token (JWT) stored in your browser's localStorage to keep you signed in. We do not use tracking cookies for advertising.
§2How We Use Your Information
- Provide, maintain, and improve the VetLedger.io service.
- Process invoices, subscriptions, payroll runs, and receipt matching.
- Categorize transactions and generate financial insights using AI (see Section 4).
- Send transactional emails — invoice reminders, weekly digests, payroll notifications, payment confirmations.
- Detect fraud, abuse, and secure the platform.
- Comply with tax, accounting, and other legal obligations.
- Communicate service updates and — only with your consent — occasional product news.
We do not sell your personal data. We do not use your financial data to train third-party AI models. We do not share your data with advertisers.
§3Third-Party Service Providers
We rely on the following trusted service providers to deliver VetLedger.io. Each is bound by their own privacy policy and by data-processing agreements with us:
Plaid Inc. — Bank Account Connections
When you connect a bank or credit card account through VetLedger.io, we use Plaid Inc. ("Plaid") to securely retrieve information about the accounts you choose to link. Specifically, Plaid may collect and share with us: account and routing numbers, account balances, transaction history, account holder identity information, and authorization data. VetLedger uses this information solely to power the features you have requested — importing transactions for bookkeeping, categorizing expenses, matching receipts, generating cash-flow reports, and (for Command N Staff subscribers) initiating payroll direct-deposit runs.
By connecting a bank account through VetLedger.io, you expressly consent to (i) VetLedger accessing your financial data via Plaid, and (ii) Plaid collecting, storing, and sharing that data with VetLedger in accordance with the Plaid End User Privacy Policy, available at https://plaid.com/legal/#end-user-privacy-policy. You should read the Plaid End User Privacy Policy carefully before linking any account, as it governs Plaid's use of your data independently of this Privacy Policy.
You may withdraw this consent at any time by disconnecting the linked account from the VetLedger.io Transactions page or by contacting Plaid directly through my.plaid.com. Withdrawing consent stops future data collection but does not delete transaction records already imported into your VetLedger account — those you can delete from within the Transactions page.
VetLedger does not receive or store your online banking login credentials — usernames, passwords, and multi-factor tokens are transmitted directly from your browser to Plaid via bank-grade encryption and never touch VetLedger servers. Plaid is SOC 2 Type II certified and its network is scrutinized by the same regulators that oversee U.S. financial institutions.
Stripe, Inc. — Payments & Payroll Direct Deposit
We use Stripe, Inc. ("Stripe") to process all payments on VetLedger.io. This includes:
- Subscription billing for our paid tiers (Boots, Professional, Professional Plus, Command N Staff, Personal Finance).
- Client-facing invoice payment links.
- Payroll direct deposits via Stripe Connect Express for W-2 and 1099 workers on Command N Staff plans.
Stripe collects and processes cardholder data, banking information, and identity-verification data (KYC) directly from you or your employees in accordance with the Stripe Privacy Policy. VetLedger receives only tokenized identifiers, transaction status, and non-sensitive metadata (last-4 of card, receipt URLs) from Stripe — we never see or store full card numbers, CVCs, or bank credentials. Stripe is PCI DSS Level 1 certified.
Other Service Providers
- Resend — transactional email delivery (invoice reminders, digests, payroll notifications).
- Anthropic (Claude Sonnet 4.6) — AI transaction categorization and financial insights.
- OpenAI (GPT-4o vision) — Optical Character Recognition (OCR) on receipt images.
- Google (Gemini Nano Banana) — application-icon generation only; no user data is sent.
- MongoDB Atlas — encrypted primary data store (US region).
- SAM.gov — public federal contracting opportunity feed (no user data is submitted; we only read the public opportunity index).
All AI providers used by VetLedger process your data under zero-retention, no-training contracts.
§4Artificial Intelligence
VetLedger.io uses AI to categorize transactions, generate financial briefings, extract receipt data, and answer bookkeeping questions. When you use these features, the relevant transaction or receipt text is sent to the appropriate AI provider listed in Section 3 through the Emergent LLM Key gateway. AI providers are contractually prohibited from retaining your data or using it to train models. AI outputs are estimates, not certified accounting advice — always review before filing.
§5Data Security
- All connections use TLS 1.2+ encryption.
- Passwords are hashed with bcrypt and never stored in plaintext.
- Database is encrypted at rest and access-restricted by IP allowlist.
- Session tokens (JWT) expire and are invalidated on sign-out.
- Uploaded files are stored in isolated per-user directories.
- Regular automated backups, retained for 30 days.
No system is completely secure. If we ever discover a data breach that affects you, we will notify you by email within 72 hours of confirmation and cooperate with any state or federal notification requirements.
§6Data Retention
We retain your account data for as long as you have an active account and for up to 7 years after account closure in order to comply with U.S. tax, accounting, and payroll record-keeping laws (IRS Publication 583, DOL FLSA requirements). You may request earlier deletion of non-mandatory records (see Section 8).
§7Sharing and Disclosure
We disclose your information only in these circumstances:
- Service providers listed in Section 3, under strict contractual limits.
- Legal requests — subpoenas, court orders, or requests from law-enforcement backed by proper legal process.
- Fraud or safety — to protect users, our platform, or the public from imminent harm.
- Business transfer — if VetLedger is acquired or merged, we will notify you and preserve the same privacy protections.
§8Your Rights
Regardless of state, you may:
- Access — download all your VetLedger data via Settings → Export.
- Correct — edit personal information in Settings.
- Delete — email privacy@vetledger.io to request deletion of non-mandatory records.
- Portability — export your transactions, invoices, and payroll data in CSV or JSON at any time.
- Disconnect Plaid — revoke bank access from within the Transactions page.
- Opt out of marketing — unsubscribe from any product email; transactional emails required for service delivery cannot be opted out.
California residents (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and EU/EEA users (GDPR) have additional rights. We honor those under the applicable regulation and generally extend them to all users regardless of residence.
§9Children
VetLedger.io is not directed to children under 13. Family Bundle Personal-Finance seats require members to be at least 16 years old. We do not knowingly collect personal information from anyone under 13. If we discover such data has been collected, we will delete it promptly.
§10International Users
VetLedger.io is operated from the United States. If you access the service from outside the U.S., you consent to transfer of your data to and processing within the U.S., where privacy laws may differ from your jurisdiction.
§11Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced by email to registered users at least 30 days before taking effect. The "Effective" date at the top will always reflect the most recent revision.
§12Contact Us
Questions, requests, or complaints about this Privacy Policy? Reach us at privacy@vetledger.io. For general support, email support@vetledger.io.
VetLedger.io
Veteran-owned & operated
United States
