Privacy Policy - BeanFlow

Privacy Policy

Last updated: December 2024

Introduction

BeanFlow ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered bookkeeping service. Please read this policy carefully to understand our practices regarding your personal data.

Information We Collect

Account Information

When you create an account using Google authentication, we receive your name, email address, and profile picture from Google. We do not have access to your Google password.

Financial Data

You may choose to upload financial documents (invoices, receipts, bank statements) for processing. This data is stored securely in your personal Google Drive, not on our servers. We process this information temporarily to provide AI-assisted bookkeeping services.

Usage Data

We collect information about how you interact with our service, including pages visited, features used, and time spent on the platform. This helps us improve our services.

Cookies & Tracking

We use cookies and similar tracking technologies to analyze site traffic and improve your experience. You can control your cookie preferences at any time.

Essential Cookies

Required for the website to function properly. These cannot be disabled and include session management and authentication cookies.

Always Active

Analytics Cookies (Google Analytics)

Help us understand how visitors interact with our website by collecting and reporting information anonymously. These cookies track page views, session duration, and traffic sources.

Requires Consent

Third-Party Services (Tawk.to)

We use Tawk.to for live chat support. This service may set cookies to maintain chat sessions and improve support quality.

Requires Consent

How We Use Your Information

  • Provide and maintain our AI-powered bookkeeping service
  • Process and analyze your financial documents
  • Generate invoices and financial reports
  • Improve our services based on usage patterns
  • Send important service updates and notifications
  • Provide customer support

Data Security

We implement industry-standard security measures to protect your data:

Encryption

All data transmission is encrypted using TLS 1.3. Sensitive data is encrypted at rest.

Secure Storage

Your financial data is stored in your personal Google Drive, giving you full control.

Authentication

We use OAuth 2.0 via Google for secure authentication without storing passwords.

Access Control

Strict access controls ensure only authorized personnel can access system data.

Your Rights

Under Canadian privacy laws (PIPEDA) and Quebec's Law 25, you have the following rights:

Right to Access

Request a copy of the personal information we hold about you.

Right to Correction

Request correction of inaccurate or incomplete personal information.

Right to Deletion

Request deletion of your personal information, subject to legal retention requirements.

Right to Withdraw Consent

Withdraw consent for non-essential data processing at any time.

Data Retention

We retain your personal information only for as long as necessary to provide our services and fulfill the purposes described in this policy. Account information is retained while your account is active. Financial data stored in your Google Drive remains under your control. Analytics data is retained for up to 26 months to identify trends and improve our services.

Third-Party Services

We use the following third-party services:

  • Google Cloud: Authentication and cloud infrastructure
  • Google Drive: Storage of your financial data
  • Google Analytics: Website traffic analysis (with your consent)
  • Tawk.to: Live chat support
  • OpenAI/Anthropic: AI processing for document analysis

Each of these services has their own privacy policies, and we encourage you to review them.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically for any changes.