Privacy Policy

Effective July 14, 2026
Last updated July 14, 2026

This Privacy Policy explains how Accounting Orbit (“Accounting Orbit,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information when you visit our websites and applications, use our accounting and financial-record management, platform, applications, APIs, integrations, and related services, or otherwise interact with us (collectively, the “Service”).

This Policy does not apply to information processed under a separate privacy, notice, such as a dedicated applicant or workforce notice, or to third-party services that maintain their own privacy policies. It also does not replace a customer’s privacy notice for Customer Data the customer controls.

1. Our Role

For individual consumer accounts, account registration, billing, website operation, marketing, direct, communications, and other processing we, determine, we generally decide why and how personal information is processed and act as a business or controller.

When a business customer uploads or connects information concerning its employees, customers, vendors, contractors, or other individuals (“Customer Data”), we generally process that information on the customer’s behalf as a service provider or processor. The customer controls that Customer Data and is responsible for providing required, notices, obtaining required, permissions, and responding to privacy requests. Individuals should ordinarily direct requests concerning Customer Data to the relevant customer.

For personal, accounts, we generally act as controller for information the individual enters or connects for personal or household financial recordkeeping. For organizational accounts, our role may differ by data category: we may be controller for account, billing, security, and relationship information while acting as processor or service provider for Customer Data controlled by the organization.

Additional processor obligations may be stated in our Data Processing Addendum at Available on request.

2. Personal Information We Collect

Depending on how you use the Service, we may collect the following categories of information.

A. Account and contact information

  • Name, business, name, job, title, email, address, telephone, number, mailing, address, and preferred language.
  • Login identifiers, hashed or otherwise protected, passwords, authentication records, account roles, permissions, and multifactor-authentication information.
  • Communications preferences and records of acceptance of our agreements.

B. Business, accounting, and financial records

  • Chart-of-account information, journal entries, ledgers, balances, budgets, tax-related classifications, and reconciliation records.
  • Invoices, bills, purchase orders, receipts, expense records, payment records, and supporting documents.
  • Customer, supplier, vendor, employee, and contractor records entered by or for a customer.
  • Bank-transaction data, account names, masked account, numbers, balances, transaction, descriptions, and imported statement files.
  • Images and files from receipts, invoices, checks, statements, and supporting, documents, including text and fields extracted through optical-character-recognition or similar document-processing tools.
  • Approval records, audit trails, comments, attachments, reports, exports, and information generated through use of the Service.

The Service is not intended to collect full payment-card numbers or online-banking passwords directly unless an interface expressly states otherwise. If bank connectivity or payment processing is enabled, a third-party provider may collect credentials and provide us with tokens, account, metadata, or transaction information under its own privacy policy.

C. Billing information

  • Subscription plan, invoices, transaction amount, billing status, tax information, and limited payment-method details.
  • Our payment processor generally handles payment-card information. We receive confirmation and limited transaction details rather than the complete card number.

Current payment processor: Stripe

D. Device, usage, and log information

  • IP address, browser type, device type, operating system, language, approximate location derived from IP address, referring pages, and identifiers.
  • Dates and times of access, pages and features used, API calls, session information, error reports, diagnostic data, and security events.
  • Actions taken within an account, including, creation, modification, approval, export, deletion, and administrative activity.
  • API keys, webhook configuration, integration tokens, delivery status, and metadata associated with connected systems. Secret values may be encrypted, hashed, or otherwise protected where appropriate.

E. Cookies and similar technologies

We may use cookies, local storage, pixels, and similar technologies to keep you signed in remember preferences, protect the Service, understand, performance, and if enabled, measure use or marketing effectiveness.

Analytics tools currently used: None
Advertising tools currently used: None

Where required, we obtain consent before using nonessential cookies. Browser settings may block some technologies, but doing so may impair Service functionality. Our cookie controls are available at Browser settings.

Some browsers transmit “Do Not Track” signals, for which no single uniform response is required in every jurisdiction. We respond to legally recognized opt-out preference signals, such as the Global Privacy Control, when applicable to our processing. A preference signal generally applies to the browser or device that sends it and may not opt you out of processing performed solely in our role as a processor for a customer.

F. Support, sales, and communications

We collect information you provide in support requests, demonstrations, surveys, calls, emails, chats, and other communications, including attachments and troubleshooting details.

G. Information from other sources

We may receive information from:

  • Your employer, organization, account administrator, or another authorized user.
  • Connected accounting, systems, banks, payment, services, file-import, sources, and integrations you direct us to use.
  • Payment processors, fraud-prevention providers, identity and authentication providers, and business partners.
  • Publicly available sources where permitted by law.

If a customer provides information about another person, we may not have a direct relationship with that person. The customer is responsible for providing any notice required at collection, subject to any notice obligations that apply directly to us.

When we act as a controller and obtain personal information from a source other than the individual, we will provide any notice required by applicable law within the required period unless a lawful exception applies.

3. How We Use Personal Information

We use personal information to:

  1. Provide, operate, maintain, and improve the Service.
  2. Create and administer accounts, authenticate users, and enforce permissions.
  3. Process accounting, records, imports, reconciliations, approvals, reports, and other customer-directed operations.
  4. Process subscriptions, invoices, payments, cancellations, and refunds.
  5. Provide support, respond to requests, and communicate about the Service.
  6. Monitor availability, diagnose errors, conduct testing, and develop features.
  7. Protect accounts, detect fraud or abuse, investigate, incidents, and enforce our agreements.
  8. Maintain audit trails and records required for accounting, security, compliance, and dispute resolution.
  9. Send service notices, and where permitted, product or marketing communications.
  10. Comply with law, legal, process, and lawful government requests.
  11. Establish, exercise, or defend legal claims and protect the rights and safety of users, customers, us, and others.
  12. Create aggregated or de-identified information that we do not reasonably use to identify an individual.

We may use automated tools to extract receipt or invoice, fields, suggest classifications or matches, detect, anomalies, and assist with workflows. These tools are intended to support human review and are not designed to make decisions producing legal or similarly significant effects about an individual.

We do not use Customer Data to train a general-purpose artificial-intelligence model unless the customer has expressly agreed to that use in writing.

4. Legal Bases for Processing

Where laws such as the UK GDPR or EU GDPR, apply, we process personal information as necessary to:

  • Perform a contract or take requested precontract steps.
  • Pursue legitimate interests such as operating, securing, supporting, and improving the Service, provided those interests are not overridden by applicable individual rights.
  • Comply with legal obligations.
  • Protect vital interests or establish, exercise, or defend legal claims.
  • Act with consent where consent is required; consent may be withdrawn as permitted by law.

When we process Customer Data as a processor, the customer determines the applicable legal basis.

5. Information You Must Provide

Account identifiers, authentication information, and information required to administer a paid subscription are contractual or operational requirements. If you do not provide them, we may be unable to create or secure an account, process, payment, provide requested functions, or communicate necessary notices. Other information is optional unless an interface identifies it as required.

6. How We Disclose Personal Information

We may disclose personal information to the following recipients for the purposes described in this Policy:

  • Service providers and processors: hosting, infrastructure, database, authentication, security, communications, customer support, analytics, payment, optical-character-recognition, artificial-intelligence or document-processing, and professional-service providers.
  • Customer organizations and administrators: account owners and administrators may access user profiles, activity, permissions, and Customer Data associated with their organization.
  • Customer-directed integrations: third parties you or your organization direct us to connect with or disclose information to.
  • Professional advisers: lawyers, auditors, accountants, insurers, and financial advisers subject to appropriate duties.
  • Authorities and other parties for legal reasons: when reasonably necessary to comply with law, protect rights or safety, investigate, misuse, or establish or defend claims.
  • Business transaction participants: actual or prospective buyers, investors, lenders, and advisers involved in a merger, financing, reorganization, sale, bankruptcy, or transfer of all or part of our business, subject to appropriate safeguards.
  • With consent or direction: other recipients when you or the relevant customer directs or authorizes the disclosure.

Current material service providers and locations: Available on request.

7. Sale, Sharing, and Targeted Advertising

We do not sell personal information for money.

We do not sell or share personal information for cross-context behavioral advertising and do not process personal information for targeted advertising as those terms are defined by applicable U.S. state privacy laws. We have not sold or shared personal information for those purposes during the preceding 12 months.

We do not knowingly sell or share personal information of individuals under 16.

8. De-Identified and Aggregated Information

When we maintain information as de-identified, we will take reasonable measures designed to prevent it from being associated with an individual, publicly commit to maintain and use it in de-identified form, and not attempt to re-identify it except where permitted by law to test whether de-identification processes are effective.

9. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, comply with legal and accounting obligations, resolve disputes, maintain security and audit, records, and enforce agreements.

10. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. Depending on the system and risk, safeguards may include access controls, authentication, encryption in transit, encryption at rest, logging, backups, vulnerability, management, personnel, controls, and incident-response procedures.

No method of transmission or storage is completely secure. You are responsible for maintaining appropriate account, credentials, configuring permissions, protecting devices, and promptly notifying us of suspected unauthorized access at [email protected].

If we confirm a security incident affecting personal information, we will investigate, contain, remediate, and provide legally required notifications to affected customers, individuals, or authorities. Notification timing and content depend on the facts, our role, contractual, commitments, and applicable law.

11. International Data Transfers

We and our service providers may process information in countries other than where you live. Where required, we use recognized transfer, safeguards, such as adequacy decisions, standard contractual, clauses, or another lawful transfer mechanism. Information about applicable safeguards may be requested using the contact information below.

Primary hosting locations: United States

12. Your Privacy Rights

Depending on your location and applicable law, you may have the right to:

  • Know or access personal information we process about you.
  • Correct inaccurate personal information.
  • Delete personal information.
  • Receive a portable copy of certain information.
  • Restrict or object to certain processing.
  • Opt out of sale, sharing, targeted advertising, or certain profiling.
  • Withdraw consent without affecting prior lawful processing.
  • Appeal a refusal to act on a request.
  • Lodge a complaint with a privacy or data-protection authority.
  • Receive equal service and pricing without unlawful discrimination for exercising privacy rights.

Submit requests at /settings or [email protected]. We may need to verify your identity and authority. An authorized agent may submit a request where permitted by law, subject to verification.

We will respond within the period required by applicable law. If we deny a request, we will explain the basis where required and provide instructions for an available appeal. We do not charge a fee unless permitted by law, such as when a request is manifestly unfounded, excessive, or repetitive. Verification information will be used only to process and document the request, protect against fraud, and satisfy legal obligations.

If your information is Customer Data controlled by one of our customers, contact that customer first. We will assist the customer as required by contract and law.

You may unsubscribe from marketing email using the link in the message. Administrative and transactional communications may continue while you maintain an account.

13. Additional U.S. State Disclosures

For residents of states with comprehensive privacy laws, the categories collected during the preceding 12 months are described in Section, 2, the purposes are described in Section, 3, and recipient categories are described in Section 6.

We use and disclose sensitive personal information only as reasonably necessary to provide requested, services, secure accounts, process authorized transactions and records, resist, fraud, and perform other purposes permitted without a right to limit, unless we provide a separate notice and choice. We do not use sensitive personal information to infer characteristics about individuals except as disclosed and permitted by law.

Our treatment of sale, sharing, and targeted advertising is stated in Section 7. We will recognize legally required browser-based opt-out preference signals where applicable to our processing.

14. Children

The Service is intended for businesses and individuals who are at least 18 years old or the age of legal majority where they live. It is not directed to children under, 13, and we do not knowingly collect personal information directly from children under 13. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.

15. Third-Party Services

The Service may link to or integrate with third-party websites, banks, payment services, applications, and platforms. Their privacy practices are governed by their own notices. We are not responsible for a third party’s independent privacy practices.

16. Changes to This Policy

We may update this Policy to reflect changes in the Service, our practices, or applicable law. We will post the updated version and revise the “Last updated” date. If required, we will provide additional notice or obtain consent before a material change takes effect.

17. Contact Us

Accounting Orbit
Attn: Privacy
Email: [email protected]
Telephone: Not provided

Data Protection Officer or representative, if applicable: Not applicable

If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority.


Questions about this document? Contact support from the Legal section in the app.