1. Scope and who is responsible
This draft applies to CloudBooksPro+Ai, including the public website and authenticated accounting workspace (together, the “Service”). In this draft, “CloudBooksPro,” “we,” “us,” and “our” refer to the business that operates the Service.
Insert the operator’s full legal name, trading name, registered address, country, company or tax registration number where applicable, and a privacy contact. Confirm whether the operator acts as a controller, processor, or both for each data category.
2. Information handled by the current product
The Service handles information that users provide directly, information created through use of the workspace, and limited provider or operational records.
Account and profile information
- Email address and password credentials used for account registration and sign-in. Authentication is provided through Supabase; the application does not contain code that stores readable passwords in its own business tables.
- First name or full name supplied during registration, and profile fields such as phone number or avatar if those fields are used.
- Authentication sessions and account identifiers needed to keep a user signed in and associate the user with company workspaces.
Company and business records
- Company name and, where entered, business email, phone, address, logo, tax identifier, currency, financial-year settings, and document-number settings.
- Workspace membership and role information, such as owner, administrator, or member.
- Customer and supplier names, email addresses, phone numbers, billing addresses, tax identifiers, status, and internal notes.
- Items and services, including codes, descriptions, selling prices, purchase costs, quantities, and categories.
- Invoices, supplier bills, purchase orders, line items, dates, payment amounts, payment method or reference fields, taxes, discounts, balances, statuses, adjustments, and notes.
- Files placed in configured private storage areas, such as a business logo or supported bill attachment, when upload features are used.
Subscription and email records
- If paid subscriptions are enabled: the user identifier sent with checkout, Lemon Squeezy customer and subscription identifiers, product and variant identifiers, subscription status, renewal date, and end date.
- For the transactional welcome email: recipient email, delivery status, attempt count, provider message identifier, delivery time, and a limited error message if delivery fails.
Browser and operational information
- The active company selection is stored in the user’s browser so the Service can reopen the selected workspace.
- Supabase authentication uses browser storage to maintain the signed-in session.
- Application logs may contain account identifiers, email-provider message identifiers, subscription event names, or error codes needed to diagnose delivery, authentication, or subscription problems.
The repository does not currently include an advertising network or product-analytics SDK.
Confirm production cookies, server logs, hosting/CDN logs, IP-address handling, device information, analytics, monitoring, backups, and any tools configured outside this repository before publishing this statement.
3. How information is used
The current product uses information to:
- create and secure accounts;
- create company workspaces and display the records a user enters;
- calculate balances and provide dashboard, report, and statement views based on recorded data;
- keep different companies’ records separated and apply workspace access controls;
- send account verification, password recovery, and welcome messages;
- record subscription status and decide whether CBP-Pro reports and statements are available;
- respond to support enquiries and troubleshoot errors; and
- protect the Service against unauthorized access or misuse.
Identify the lawful basis for each purpose in every jurisdiction where the Service is offered. Do not publish a consent, contract, legitimate-interest, or legal-obligation basis until counsel confirms it.
5. Security and company separation
The application uses authenticated access, row-level database rules, company membership checks, company-bound relationships, and private storage rules intended to restrict workspace records to authorized company members. Sensitive server credentials are designed to remain on the server.
No online service can promise absolute security. Users should use a unique password, protect access to their email account, sign out on shared devices, and contact support if they suspect unauthorized access.
Have counsel and a security professional confirm the final description of safeguards, incident response, breach notification, encryption, backups, access reviews, and vendor oversight. Do not add certifications or compliance claims unless independently verified.
6. Retention and deletion
The repository does not define a complete retention schedule or an in-product account-deletion workflow. Business records remain in the database until they are changed or deleted through available product or administrative processes. Some records use cascading deletion when a parent account or company is deleted at the database level.
Set retention periods for accounts, company records, attachments, subscription records, email-delivery logs, support messages, application logs, and backups. Define how users request export or deletion, how workspace ownership affects deletion, and what must be retained for tax, accounting, fraud-prevention, or legal reasons.
7. Privacy choices and rights
Users may update many business records inside their workspace and may contact info@cloudbookspro.online with a privacy question. The current product does not yet include a dedicated privacy-request or account-deletion form.
Insert the rights that apply to the operator’s actual users and jurisdictions, including any access, correction, deletion, portability, objection, restriction, appeal, or complaint rights. Define identity verification, authorized-agent, response-time, and regulator-contact procedures.
8. International processing
Identify where the operator and each production provider store or process data. Counsel must determine what international-transfer disclosures and safeguards apply.
9. Children
The current product is described as a business accounting workspace and is not designed in the code as a child-directed service.
Set a minimum user age and confirm whether the Service will be offered to minors or educational users. Counsel must approve the final children’s-privacy language.
10. Changes to this policy
A final policy should explain how material changes will be communicated and identify its effective date. This first draft is dated August 3, 2026 and is not yet approved for publication.
11. Contact
Current product contact: info@cloudbookspro.online.
Add the legal entity, postal address, privacy lead or data-protection officer where required, and any regulator or representative contact required by applicable law.