Skip to content
AccountingKit
WorkflowsAPIUse casesPricingDocs
Log in
WorkflowsAPIUse casesPricingDocsLog in

Legal

Privacy Policy

AccountingKit is infrastructure between your software and your accounting system. It is built to hold as little of your data as the work requires, and to hold none of it when you choose a zero-retention connection.

Version
1.0
Effective
1 September 2026
Questions
privacy@accountingkit.dev

On this page

  1. Roles and scope
  2. Website visitors
  3. Console accounts
  4. Accounting data
  5. How long we keep it
  6. Where it is processed
  7. Who we share it with
  8. International transfers
  9. Security
  10. Your rights
  11. Children
  12. Changes
  13. Contact

Roles and scope

This policy covers two different relationships, and the distinction matters.

  • AccountingKit as controller. For visitors to accountingkit.dev and for the people who hold developer console accounts, AccountingKit decides why and how the data is processed. This policy is the notice for that processing.
  • AccountingKit as processor. For the accounting data we read and write on your instruction — your customers, suppliers, invoices, bills, and payments — you are the controller and AccountingKit is your processor. That processing is governed by the Data Processing Addendum, not by this policy, and we act only on your documented instructions.

AccountingKit is the controller for that processing, and privacy@accountingkit.dev is the contact point for every privacy question, rights request, and complaint. Subscriptions are sold through Dodo Payments as merchant of record, which is the seller shown on your receipt and the controller of the payment data it collects to complete the transaction.

Website visitors

This website sets no cookies. It runs no analytics, no advertising pixels, no session recording, and no third-party trackers. There is no consent banner because there is nothing to consent to.

Pages are static files served from Cloudflare's network. Cloudflare processes the request metadata any web server sees — IP address, user agent, requested URL, timestamp — to deliver the page and to protect the site from attack and abuse. That is our legitimate interest in operating a secure website. We do not build visitor profiles from it.

One piece of behaviour is worth naming explicitly: when you click a link from this site to the developer console, a small script appends the page you came from and any campaign parameters already present in your URL to the destination link. This travels in the URL, is capped in length, and is used to understand which pages lead to sign-ups. It sets no cookie and no identifier, and it happens only for links to the console.

See the Cookie Notice for the full picture across the website, the console, and the documentation site.

Console accounts

We process the following about the people who use the developer console:

DataWhyLawful basis
Name, email address, profile imageCreating your account, signing you in, showing who took an action in your teamPerformance of a contract
Organization and team membershipScoping every query to your organization and enforcing rolesPerformance of a contract
Session and authentication recordsKeeping you signed in, rate-limiting sign-in attempts, detecting abuseLegitimate interest in a secure service
Audit events — actor, action, target, request identifier, timestampGiving you and us an accountable record of who changed what, which is also a security control your own auditors will ask aboutLegitimate interest and legal obligation
Billing contact, country, and tax identifierSubscription checkout, invoicing, and tax compliance on a paid planPerformance of a contract and legal obligation
Support correspondenceAnswering the question you askedPerformance of a contract and legitimate interest

We send transactional email only — sign-in, invitations, and operational notices about your account. We do not send marketing email from the product.

Accounting data

When you connect an accounting organization, AccountingKit can read and write records that contain personal data about your contacts: names, email addresses, postal addresses, tax identifiers, bank details where the provider exposes them, and the content of invoices, bills, quotes, and payments. You decide what we touch, through the scopes you grant and the calls you make.

How much of it we hold is a decision you make per connection, when you create it:

ModeWhat is storedWhat you give up
Zero retentionNo accounting record data is written to our database. Reads pass through to the provider and are returned to you in the response.Cached list reads, background sync, and webhook-driven record projection, each of which requires storage to work
CachedNormalized records and encrypted raw provider payloads, so that list reads are fast, sync can run, and a failed workflow can be replayed Nothing functionally — but the data rests with us until it expires

A connection's retention mode is fixed once it exists. Changing it requires disconnecting and reconnecting, so the amount of your data we hold can never change quietly underneath you.

In both modes we keep a small operational record that contains no accounting record content: the workflow's step state, attempt counts, timing, and any terminal error, plus immutable usage counters for billing. This is what makes a run recoverable and an invoice auditable.

How long we keep it

DataRetention
Accounting records on a zero-retention connectionNot stored at all
Normalized records and encrypted raw provider payloads on a cached connection30 days from the last sync, then cleared by a scheduled retention job
Provider access and refresh tokensUntil the connection is disconnected, then deleted
Workflow and operation stateFor the life of the connection, then deleted with it
Audit eventsFor the life of the organization, so the record stays complete
Usage events and frozen statementsAs long as tax and accounting law requires us to keep billing records, typically seven years
Console account and organization recordsUntil deleted, then removed within thirty days
Support correspondenceTwo years from the last message

Deleting an organization cascades through the database to its environments, connections, accounting records, and operations. Backups roll off on their own schedule; data deleted from the live system is not restored into it.

Where it is processed

The API and the primary database run in Google Cloud's europe-west3 (Frankfurt, Germany) region. Encryption keys are held in Google Cloud KMS in the same region. Your accounting data rests in the European Union.

Static assets for this website and the console are served from Cloudflare's global network, which means request metadata is handled at the edge location nearest the visitor. No accounting data is stored at the edge.

Who we share it with

We share personal data only with the subprocessors listed on the subprocessors page, each engaged under a written contract that limits them to our instructions. The list is short and current, and we publish changes to it before they take effect.

Beyond that, we disclose data only where the law compels it, and then only to the extent required. If we receive a government or law-enforcement request for a customer's data, we will tell that customer unless we are legally prohibited from doing so. We do not sell personal data, do not share it for cross-context behavioural advertising, and do not use it to train machine-learning models. A change of control would transfer data as part of the business, under the same commitments, with notice to you.

International transfers

Accounting data stays in the EU. Two things can involve a transfer outside it: transactional email, which is delivered by a provider with US operations, and payment processing, which is handled by a merchant of record operating globally. Those transfers rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies, together with encryption in transit and data minimization — the email provider receives a recipient address and a message, not your ledger.

Security

Provider credentials and raw provider payloads are encrypted at rest with AES-256-GCM under keys wrapped by Google Cloud KMS. API keys are stored as keyed hashes and cannot be recovered. Every tenant-owned query proves organization ownership in the database rather than trusting a value supplied by a client. Secrets, tokens, authorization codes, and raw webhook bodies are never written to logs. The security page describes the controls in full, including the certifications we do not yet hold.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal data, to object to or restrict processing, to withdraw consent where we rely on it, and to complain to a supervisory authority. Under the GDPR you may complain to your local data protection authority; under India's Digital Personal Data Protection Act you may raise a grievance with us first and then with the Data Protection Board.

Write to privacy@accountingkit.dev to exercise a right. We answer within thirty days and will not charge you or treat you differently for asking.

If you are one of our customers' contacts and you found this page while looking for the business that holds your invoice: we process that data on their behalf, not our own. Contact the business you deal with directly. If you cannot reach them, write to us and we will forward your request to them.

Children

The service is for businesses. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe we have, write to us and we will delete it.

Changes

We will update this policy as the service changes. The effective date at the top of this page always reflects the current version. For a change that materially affects how we handle your personal data, we will give notice by email to account contacts before it takes effect.

Contact

Privacy questions, rights requests, and complaints all go to privacy@accountingkit.dev. A person reads that address.

Related

Terms of ServiceThe contract that governs access to the API, the console, and workflow execution.Data Processing AddendumArticle 28 processor terms, the processing record, security measures, and transfer safeguards.SubprocessorsEvery third party in the processing chain, what it touches, and where it runs.Acceptable Use PolicyWhat you may not run through AccountingKit, and what happens if you do.Cookie NoticeThe marketing site sets no cookies. The console sets one, and it is essential.SecurityThe controls behind the platform, stated plainly, including the ones not yet certified.
AccountingKit

Accounting workflows for the systems businesses already use.

hello@accountingkit.dev
ProductWorkflowsUnified APIUse casesPricing
DevelopersDocumentationDeveloper consolellms.txt
CompanyFAQSecurityReport a vulnerability
LegalTermsPrivacyDPASubprocessorsAcceptable useCookies
© 2026 AccountingKit. All rights reserved.AccountingKit is an independent product and is not affiliated with, endorsed by, or sponsored by any accounting software vendor. Xero is a trademark of Xero Limited. QuickBooks is a trademark of Intuit Inc. Sage and Sage Intacct are trademarks of The Sage Group plc. FreshBooks and Wave are trademarks of their respective owners, as are all other product names and marks used here for identification only.