What this policy covers
This policy explains how we handle data in AqarBooks. There are two kinds of data, and the distinction matters:
- Your account data: your details as a user (name, email, sign-in history). We are the controller of this.
- Your ledger data: what you enter about your owners, units, and journal entries. Here we are only a processor, and you are the controller.
What we collect
- Registration details: name, email, organisation name, country and currency.
- Sign-in data: timestamp, IP address, and browser type, for security and audit purposes.
- Action logs: who posted an entry, who closed a cashbox, who changed a permission. This is a core part of accounting audit.
- Payment data: handled directly by payment providers. We do not store card numbers.
- Your ledger content: what you enter yourself. We do not look at it unless you request support that requires it.
Why we collect it
- To run the platform and give you access to your account.
- To secure your account and detect unauthorised access attempts.
- To maintain a sound audit trail, an accounting requirement rather than a choice.
- To send operational email (email confirmation, password reset, billing notices).
- To improve the service using aggregated, anonymised usage patterns.
We do not sell your data, we do not use it for advertising, and we do not share it with anyone beyond the processors listed below.
Isolation between entities
Each entity's data is isolated inside the database itself using Row-Level Security policies at the PostgreSQL level, not merely by filtering in application code.
That means even if an application bug occurs, the database itself refuses to hand one entity's data to another.
Who processes data with us
We use a small set of technical providers, each with a defined role:
- Supabase: database hosting and authentication.
- Cloudflare: application hosting, content delivery, and attack protection.
- Resend: sending operational email (confirmation, password reset).
- Payment providers: processing subscriptions and online payments.
These providers access data only as needed to perform their role and are contractually bound to protect it.
Storage and international transfers
Data is stored on cloud infrastructure that may be located outside your country. Where data crosses borders we rely on appropriate contractual safeguards with our providers. If you have a regulatory requirement to keep data within a specific country, that is available on enterprise plans. Talk to us.
How long we keep it
We keep your data while your account is active. After termination it remains available for export for 30 days, then is removed from operational systems within a reasonable period.
One important exception: audit logs and posted journal entries may need to be retained longer where accounting or tax law in your jurisdiction requires it.
Your rights
You have the right to:
- Request a copy of your personal data.
- Correct anything inaccurate.
- Request deletion, within what the law allows.
- Object to or restrict certain processing.
- Export your data in a readable format.
To exercise any of these: privacy@aqarbooks.com. We respond within a reasonable period, usually within 30 days.
Security
- Encryption in transit (TLS) and at rest.
- Passwords are stored hashed, never in plain text.
- Database-level RLS isolation between all entities.
- An immutable audit trail for every sensitive financial action.
- Two-factor authentication support (TOTP).
Not intended for children
The platform is intended for professional and business use and is not designed for anyone under 18. If we find an account was opened by a minor, we will close it.
Contact
Any privacy question, or to exercise your rights: privacy@aqarbooks.com